Report - TMS_C004.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:13 Machine s1_win7_x6403
Filename TMS_C004.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : clean
VT API (file) 10 detected (Midie, malicious, ai score=87)
md5 5073ab7e1f6081e81b056deb0799a165
sha256 44b84b99778fc25e9606c4c83334557b326b7a8e4e2c3a38dfe7565493bafa15
ssdeep 24576:8MkbTpGV41y4VVqPA8g0Ny6gxUeratgoI7AU/nuYGH4UtfWX/CUY29jgyVBYn2Wd:8zYuuAN0fJgIcOtfWvvSRwKD
imphash 2921be952fbfe596894ebe00a9ad214f
impfuzzy 192:f3z9G1Glc0tHeuuNaSUvK9u6oaq8maf7sPbOQadg:f3I1qeNz98pRPbOQV
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5ad190 DeleteCriticalSection
 0x5ad194 LeaveCriticalSection
 0x5ad198 EnterCriticalSection
 0x5ad19c InitializeCriticalSection
 0x5ad1a0 VirtualFree
 0x5ad1a4 VirtualAlloc
 0x5ad1a8 LocalFree
 0x5ad1ac LocalAlloc
 0x5ad1b0 GetVersion
 0x5ad1b4 GetCurrentThreadId
 0x5ad1b8 InterlockedDecrement
 0x5ad1bc InterlockedIncrement
 0x5ad1c0 VirtualQuery
 0x5ad1c4 WideCharToMultiByte
 0x5ad1c8 MultiByteToWideChar
 0x5ad1cc lstrlenA
 0x5ad1d0 lstrcpynA
 0x5ad1d4 LoadLibraryExA
 0x5ad1d8 GetThreadLocale
 0x5ad1dc GetStartupInfoA
 0x5ad1e0 GetProcAddress
 0x5ad1e4 GetModuleHandleA
 0x5ad1e8 GetModuleFileNameA
 0x5ad1ec GetLocaleInfoA
 0x5ad1f0 GetCommandLineA
 0x5ad1f4 FreeLibrary
 0x5ad1f8 FindFirstFileA
 0x5ad1fc FindClose
 0x5ad200 ExitProcess
 0x5ad204 ExitThread
 0x5ad208 CreateThread
 0x5ad20c WriteFile
 0x5ad210 UnhandledExceptionFilter
 0x5ad214 RtlUnwind
 0x5ad218 RaiseException
 0x5ad21c GetStdHandle
user32.dll
 0x5ad224 GetKeyboardType
 0x5ad228 LoadStringA
 0x5ad22c MessageBoxA
 0x5ad230 CharNextA
advapi32.dll
 0x5ad238 RegQueryValueExA
 0x5ad23c RegOpenKeyExA
 0x5ad240 RegCloseKey
oleaut32.dll
 0x5ad248 SysFreeString
 0x5ad24c SysReAllocStringLen
 0x5ad250 SysAllocStringLen
kernel32.dll
 0x5ad258 TlsSetValue
 0x5ad25c TlsGetValue
 0x5ad260 LocalAlloc
 0x5ad264 GetModuleHandleA
advapi32.dll
 0x5ad26c RegSetValueExA
 0x5ad270 RegQueryValueExA
 0x5ad274 RegQueryValueA
 0x5ad278 RegOpenKeyExA
 0x5ad27c RegFlushKey
 0x5ad280 RegCreateKeyExA
 0x5ad284 RegCloseKey
kernel32.dll
 0x5ad28c lstrcpyA
 0x5ad290 WriteFile
 0x5ad294 WaitForSingleObject
 0x5ad298 VirtualQuery
 0x5ad29c VirtualAlloc
 0x5ad2a0 Sleep
 0x5ad2a4 SizeofResource
 0x5ad2a8 SetThreadLocale
 0x5ad2ac SetFilePointer
 0x5ad2b0 SetEvent
 0x5ad2b4 SetErrorMode
 0x5ad2b8 SetEndOfFile
 0x5ad2bc ResumeThread
 0x5ad2c0 ResetEvent
 0x5ad2c4 ReleaseMutex
 0x5ad2c8 ReadFile
 0x5ad2cc MultiByteToWideChar
 0x5ad2d0 MulDiv
 0x5ad2d4 LockResource
 0x5ad2d8 LoadResource
 0x5ad2dc LoadLibraryA
 0x5ad2e0 LeaveCriticalSection
 0x5ad2e4 InitializeCriticalSection
 0x5ad2e8 GlobalUnlock
 0x5ad2ec GlobalSize
 0x5ad2f0 GlobalReAlloc
 0x5ad2f4 GlobalHandle
 0x5ad2f8 GlobalLock
 0x5ad2fc GlobalFree
 0x5ad300 GlobalFindAtomA
 0x5ad304 GlobalDeleteAtom
 0x5ad308 GlobalAlloc
 0x5ad30c GlobalAddAtomA
 0x5ad310 GetVersionExA
 0x5ad314 GetVersion
 0x5ad318 GetTimeZoneInformation
 0x5ad31c GetTickCount
 0x5ad320 GetThreadLocale
 0x5ad324 GetTempPathA
 0x5ad328 GetSystemInfo
 0x5ad32c GetStringTypeExA
 0x5ad330 GetStdHandle
 0x5ad334 GetProcAddress
 0x5ad338 GetModuleHandleA
 0x5ad33c GetModuleFileNameA
 0x5ad340 GetLocaleInfoA
 0x5ad344 GetLocalTime
 0x5ad348 GetLastError
 0x5ad34c GetFullPathNameA
 0x5ad350 GetFileSize
 0x5ad354 GetExitCodeThread
 0x5ad358 GetDiskFreeSpaceA
 0x5ad35c GetDateFormatA
 0x5ad360 GetCurrentThreadId
 0x5ad364 GetCurrentProcessId
 0x5ad368 GetCPInfo
 0x5ad36c GetACP
 0x5ad370 FreeResource
 0x5ad374 InterlockedIncrement
 0x5ad378 InterlockedExchange
 0x5ad37c InterlockedDecrement
 0x5ad380 FreeLibrary
 0x5ad384 FormatMessageA
 0x5ad388 FindResourceA
 0x5ad38c FindFirstFileA
 0x5ad390 FindClose
 0x5ad394 FileTimeToLocalFileTime
 0x5ad398 FileTimeToDosDateTime
 0x5ad39c EnumCalendarInfoA
 0x5ad3a0 EnterCriticalSection
 0x5ad3a4 DeleteCriticalSection
 0x5ad3a8 CreateThread
 0x5ad3ac CreateMutexA
 0x5ad3b0 CreateFileA
 0x5ad3b4 CreateEventA
 0x5ad3b8 CompareStringA
 0x5ad3bc CloseHandle
version.dll
 0x5ad3c4 VerQueryValueA
 0x5ad3c8 GetFileVersionInfoSizeA
 0x5ad3cc GetFileVersionInfoA
gdi32.dll
 0x5ad3d4 UnrealizeObject
 0x5ad3d8 StretchBlt
 0x5ad3dc SetWindowOrgEx
 0x5ad3e0 SetWindowExtEx
 0x5ad3e4 SetWinMetaFileBits
 0x5ad3e8 SetViewportOrgEx
 0x5ad3ec SetViewportExtEx
 0x5ad3f0 SetTextColor
 0x5ad3f4 SetStretchBltMode
 0x5ad3f8 SetROP2
 0x5ad3fc SetPixel
 0x5ad400 SetMapMode
 0x5ad404 SetEnhMetaFileBits
 0x5ad408 SetDIBColorTable
 0x5ad40c SetBrushOrgEx
 0x5ad410 SetBkMode
 0x5ad414 SetBkColor
 0x5ad418 SelectPalette
 0x5ad41c SelectObject
 0x5ad420 SelectClipRgn
 0x5ad424 SaveDC
 0x5ad428 RoundRect
 0x5ad42c RestoreDC
 0x5ad430 Rectangle
 0x5ad434 RectVisible
 0x5ad438 RealizePalette
 0x5ad43c Polyline
 0x5ad440 Polygon
 0x5ad444 PolyPolyline
 0x5ad448 PlayEnhMetaFile
 0x5ad44c PatBlt
 0x5ad450 MoveToEx
 0x5ad454 MaskBlt
 0x5ad458 LineTo
 0x5ad45c LPtoDP
 0x5ad460 IntersectClipRect
 0x5ad464 GetWindowOrgEx
 0x5ad468 GetWinMetaFileBits
 0x5ad46c GetTextMetricsA
 0x5ad470 GetTextExtentPointA
 0x5ad474 GetTextExtentPoint32A
 0x5ad478 GetSystemPaletteEntries
 0x5ad47c GetStockObject
 0x5ad480 GetPixel
 0x5ad484 GetPaletteEntries
 0x5ad488 GetOutlineTextMetricsA
 0x5ad48c GetObjectA
 0x5ad490 GetNearestColor
 0x5ad494 GetEnhMetaFilePaletteEntries
 0x5ad498 GetEnhMetaFileHeader
 0x5ad49c GetEnhMetaFileBits
 0x5ad4a0 GetDeviceCaps
 0x5ad4a4 GetDIBits
 0x5ad4a8 GetDIBColorTable
 0x5ad4ac GetDCOrgEx
 0x5ad4b0 GetCurrentPositionEx
 0x5ad4b4 GetCurrentObject
 0x5ad4b8 GetClipRgn
 0x5ad4bc GetClipBox
 0x5ad4c0 GetBrushOrgEx
 0x5ad4c4 GetBitmapBits
 0x5ad4c8 GdiFlush
 0x5ad4cc ExtTextOutA
 0x5ad4d0 ExtSelectClipRgn
 0x5ad4d4 ExtCreatePen
 0x5ad4d8 ExcludeClipRect
 0x5ad4dc Ellipse
 0x5ad4e0 DeleteObject
 0x5ad4e4 DeleteEnhMetaFile
 0x5ad4e8 DeleteDC
 0x5ad4ec CreateSolidBrush
 0x5ad4f0 CreateRectRgn
 0x5ad4f4 CreatePolygonRgn
 0x5ad4f8 CreatePenIndirect
 0x5ad4fc CreatePalette
 0x5ad500 CreateHalftonePalette
 0x5ad504 CreateFontIndirectA
 0x5ad508 CreateDIBitmap
 0x5ad50c CreateDIBSection
 0x5ad510 CreateCompatibleDC
 0x5ad514 CreateCompatibleBitmap
 0x5ad518 CreateBrushIndirect
 0x5ad51c CreateBitmap
 0x5ad520 CopyEnhMetaFileA
 0x5ad524 BitBlt
user32.dll
 0x5ad52c CreateWindowExA
 0x5ad530 WindowFromPoint
 0x5ad534 WinHelpA
 0x5ad538 WaitMessage
 0x5ad53c ValidateRect
 0x5ad540 UpdateWindow
 0x5ad544 UnregisterClassA
 0x5ad548 UnionRect
 0x5ad54c UnhookWindowsHookEx
 0x5ad550 TranslateMessage
 0x5ad554 TranslateMDISysAccel
 0x5ad558 TrackPopupMenu
 0x5ad55c SystemParametersInfoA
 0x5ad560 ShowWindow
 0x5ad564 ShowScrollBar
 0x5ad568 ShowOwnedPopups
 0x5ad56c ShowCursor
 0x5ad570 ShowCaret
 0x5ad574 SetWindowRgn
 0x5ad578 SetWindowsHookExA
 0x5ad57c SetWindowTextA
 0x5ad580 SetWindowPos
 0x5ad584 SetWindowPlacement
 0x5ad588 SetWindowLongA
 0x5ad58c SetTimer
 0x5ad590 SetScrollRange
 0x5ad594 SetScrollPos
 0x5ad598 SetScrollInfo
 0x5ad59c SetRect
 0x5ad5a0 SetPropA
 0x5ad5a4 SetParent
 0x5ad5a8 SetMenuItemInfoA
 0x5ad5ac SetMenu
 0x5ad5b0 SetKeyboardState
 0x5ad5b4 SetForegroundWindow
 0x5ad5b8 SetFocus
 0x5ad5bc SetCursor
 0x5ad5c0 SetClipboardData
 0x5ad5c4 SetClassLongA
 0x5ad5c8 SetCaretPos
 0x5ad5cc SetCapture
 0x5ad5d0 SetActiveWindow
 0x5ad5d4 SendMessageA
 0x5ad5d8 ScrollWindowEx
 0x5ad5dc ScrollWindow
 0x5ad5e0 ScreenToClient
 0x5ad5e4 RemovePropA
 0x5ad5e8 RemoveMenu
 0x5ad5ec ReleaseDC
 0x5ad5f0 ReleaseCapture
 0x5ad5f4 RegisterWindowMessageA
 0x5ad5f8 RegisterClipboardFormatA
 0x5ad5fc RegisterClassA
 0x5ad600 RedrawWindow
 0x5ad604 PtInRect
 0x5ad608 PostQuitMessage
 0x5ad60c PostMessageA
 0x5ad610 PeekMessageA
 0x5ad614 OpenClipboard
 0x5ad618 OffsetRect
 0x5ad61c OemToCharA
 0x5ad620 MsgWaitForMultipleObjects
 0x5ad624 MoveWindow
 0x5ad628 MessageBoxA
 0x5ad62c MessageBeep
 0x5ad630 MapWindowPoints
 0x5ad634 MapVirtualKeyA
 0x5ad638 LoadStringA
 0x5ad63c LoadKeyboardLayoutA
 0x5ad640 LoadIconA
 0x5ad644 LoadCursorA
 0x5ad648 LoadBitmapA
 0x5ad64c KillTimer
 0x5ad650 IsZoomed
 0x5ad654 IsWindowVisible
 0x5ad658 IsWindowEnabled
 0x5ad65c IsWindow
 0x5ad660 IsRectEmpty
 0x5ad664 IsIconic
 0x5ad668 IsDialogMessageA
 0x5ad66c IsClipboardFormatAvailable
 0x5ad670 IsChild
 0x5ad674 IsCharAlphaNumericA
 0x5ad678 IsCharAlphaA
 0x5ad67c InvalidateRect
 0x5ad680 IntersectRect
 0x5ad684 InsertMenuItemA
 0x5ad688 InsertMenuA
 0x5ad68c InflateRect
 0x5ad690 HideCaret
 0x5ad694 GetWindowThreadProcessId
 0x5ad698 GetWindowTextA
 0x5ad69c GetWindowRect
 0x5ad6a0 GetWindowPlacement
 0x5ad6a4 GetWindowLongA
 0x5ad6a8 GetWindowDC
 0x5ad6ac GetTopWindow
 0x5ad6b0 GetSystemMetrics
 0x5ad6b4 GetSystemMenu
 0x5ad6b8 GetSysColorBrush
 0x5ad6bc GetSysColor
 0x5ad6c0 GetSubMenu
 0x5ad6c4 GetScrollRange
 0x5ad6c8 GetScrollPos
 0x5ad6cc GetScrollInfo
 0x5ad6d0 GetPropA
 0x5ad6d4 GetParent
 0x5ad6d8 GetWindow
 0x5ad6dc GetMessageTime
 0x5ad6e0 GetMenuStringA
 0x5ad6e4 GetMenuState
 0x5ad6e8 GetMenuItemInfoA
 0x5ad6ec GetMenuItemID
 0x5ad6f0 GetMenuItemCount
 0x5ad6f4 GetMenu
 0x5ad6f8 GetLastActivePopup
 0x5ad6fc GetKeyboardState
 0x5ad700 GetKeyboardLayoutList
 0x5ad704 GetKeyboardLayout
 0x5ad708 GetKeyState
 0x5ad70c GetKeyNameTextA
 0x5ad710 GetIconInfo
 0x5ad714 GetForegroundWindow
 0x5ad718 GetFocus
 0x5ad71c GetDoubleClickTime
 0x5ad720 GetDlgItem
 0x5ad724 GetDesktopWindow
 0x5ad728 GetDCEx
 0x5ad72c GetDC
 0x5ad730 GetCursorPos
 0x5ad734 GetCursor
 0x5ad738 GetClipboardData
 0x5ad73c GetClientRect
 0x5ad740 GetClassNameA
 0x5ad744 GetClassInfoA
 0x5ad748 GetCaretPos
 0x5ad74c GetCapture
 0x5ad750 GetActiveWindow
 0x5ad754 FrameRect
 0x5ad758 FindWindowA
 0x5ad75c FillRect
 0x5ad760 EqualRect
 0x5ad764 EnumWindows
 0x5ad768 EnumThreadWindows
 0x5ad76c EnumClipboardFormats
 0x5ad770 EndPaint
 0x5ad774 EnableWindow
 0x5ad778 EnableScrollBar
 0x5ad77c EnableMenuItem
 0x5ad780 EmptyClipboard
 0x5ad784 DrawTextExA
 0x5ad788 DrawTextA
 0x5ad78c DrawMenuBar
 0x5ad790 DrawIconEx
 0x5ad794 DrawIcon
 0x5ad798 DrawFrameControl
 0x5ad79c DrawFocusRect
 0x5ad7a0 DrawEdge
 0x5ad7a4 DispatchMessageA
 0x5ad7a8 DestroyWindow
 0x5ad7ac DestroyMenu
 0x5ad7b0 DestroyIcon
 0x5ad7b4 DestroyCursor
 0x5ad7b8 DestroyCaret
 0x5ad7bc DeleteMenu
 0x5ad7c0 DefWindowProcA
 0x5ad7c4 DefMDIChildProcA
 0x5ad7c8 DefFrameProcA
 0x5ad7cc CreatePopupMenu
 0x5ad7d0 CreateMenu
 0x5ad7d4 CreateIcon
 0x5ad7d8 CreateCaret
 0x5ad7dc CloseClipboard
 0x5ad7e0 ClientToScreen
 0x5ad7e4 CheckMenuItem
 0x5ad7e8 CallWindowProcA
 0x5ad7ec CallNextHookEx
 0x5ad7f0 BeginPaint
 0x5ad7f4 CharNextA
 0x5ad7f8 CharLowerBuffA
 0x5ad7fc CharLowerA
 0x5ad800 CharUpperBuffA
 0x5ad804 CharToOemA
 0x5ad808 AdjustWindowRectEx
 0x5ad80c ActivateKeyboardLayout
ole32.dll
 0x5ad814 CoTaskMemFree
 0x5ad818 StringFromCLSID
kernel32.dll
 0x5ad820 Sleep
oleaut32.dll
 0x5ad828 SafeArrayPtrOfIndex
 0x5ad82c SafeArrayPutElement
 0x5ad830 SafeArrayGetElement
 0x5ad834 SafeArrayUnaccessData
 0x5ad838 SafeArrayAccessData
 0x5ad83c SafeArrayGetUBound
 0x5ad840 SafeArrayGetLBound
 0x5ad844 SafeArrayRedim
 0x5ad848 SafeArrayCreate
 0x5ad84c VariantChangeType
 0x5ad850 VariantCopyInd
 0x5ad854 VariantCopy
 0x5ad858 VariantClear
 0x5ad85c VariantInit
ole32.dll
 0x5ad864 CoCreateInstance
 0x5ad868 CoGetMalloc
 0x5ad86c CoUninitialize
 0x5ad870 CoInitialize
 0x5ad874 IsEqualGUID
oleaut32.dll
 0x5ad87c CreateErrorInfo
 0x5ad880 GetErrorInfo
 0x5ad884 SetErrorInfo
 0x5ad888 SafeArrayCopy
 0x5ad88c SafeArrayUnaccessData
 0x5ad890 SafeArrayAccessData
 0x5ad894 SafeArrayGetUBound
 0x5ad898 SafeArrayDestroy
 0x5ad89c SafeArrayCreate
 0x5ad8a0 SysFreeString
comctl32.dll
 0x5ad8a8 ImageList_SetIconSize
 0x5ad8ac ImageList_GetIconSize
 0x5ad8b0 ImageList_Write
 0x5ad8b4 ImageList_Read
 0x5ad8b8 ImageList_GetDragImage
 0x5ad8bc ImageList_DragShowNolock
 0x5ad8c0 ImageList_SetDragCursorImage
 0x5ad8c4 ImageList_DragMove
 0x5ad8c8 ImageList_DragLeave
 0x5ad8cc ImageList_DragEnter
 0x5ad8d0 ImageList_EndDrag
 0x5ad8d4 ImageList_BeginDrag
 0x5ad8d8 ImageList_Remove
 0x5ad8dc ImageList_DrawEx
 0x5ad8e0 ImageList_Replace
 0x5ad8e4 ImageList_Draw
 0x5ad8e8 ImageList_GetBkColor
 0x5ad8ec ImageList_SetBkColor
 0x5ad8f0 ImageList_ReplaceIcon
 0x5ad8f4 ImageList_Add
 0x5ad8f8 ImageList_GetImageCount
 0x5ad8fc ImageList_Destroy
 0x5ad900 ImageList_Create
 0x5ad904 InitCommonControls
comdlg32.dll
 0x5ad90c GetSaveFileNameA
 0x5ad910 GetOpenFileNameA
kernel32.dll
 0x5ad918 MulDiv
kernel32.dll
 0x5ad920 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure