Report - TMS_C009.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:26 Machine s1_win7_x6401
Filename TMS_C009.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 10 detected (Midie, malicious, ai score=85)
md5 36c9de5666a5ef5b6f7a27f23538f5bb
sha256 f83c587bc0fd405e5bc8264f3bff8cd7a5704b7116c35ea18b83a1866cb171bc
ssdeep 49152:5xj6d2mHXpwXX5Eb6vCt5zPDC+HAFjjdjjA/YiY0Y0Y0Y0YI:5xjC2yZspEb6u53C+HAFjjdjjA/YiY0z
imphash 0f7133b6b604bd6fc63d33541d2dcf73
impfuzzy 192:f3o7BmG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3a1q/Ez9YPpPbOQc
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5df190 DeleteCriticalSection
 0x5df194 LeaveCriticalSection
 0x5df198 EnterCriticalSection
 0x5df19c InitializeCriticalSection
 0x5df1a0 VirtualFree
 0x5df1a4 VirtualAlloc
 0x5df1a8 LocalFree
 0x5df1ac LocalAlloc
 0x5df1b0 GetVersion
 0x5df1b4 GetCurrentThreadId
 0x5df1b8 InterlockedDecrement
 0x5df1bc InterlockedIncrement
 0x5df1c0 VirtualQuery
 0x5df1c4 WideCharToMultiByte
 0x5df1c8 MultiByteToWideChar
 0x5df1cc lstrlenA
 0x5df1d0 lstrcpynA
 0x5df1d4 LoadLibraryExA
 0x5df1d8 GetThreadLocale
 0x5df1dc GetStartupInfoA
 0x5df1e0 GetProcAddress
 0x5df1e4 GetModuleHandleA
 0x5df1e8 GetModuleFileNameA
 0x5df1ec GetLocaleInfoA
 0x5df1f0 GetCommandLineA
 0x5df1f4 FreeLibrary
 0x5df1f8 FindFirstFileA
 0x5df1fc FindClose
 0x5df200 ExitProcess
 0x5df204 ExitThread
 0x5df208 CreateThread
 0x5df20c WriteFile
 0x5df210 UnhandledExceptionFilter
 0x5df214 RtlUnwind
 0x5df218 RaiseException
 0x5df21c GetStdHandle
user32.dll
 0x5df224 GetKeyboardType
 0x5df228 LoadStringA
 0x5df22c MessageBoxA
 0x5df230 CharNextA
advapi32.dll
 0x5df238 RegQueryValueExA
 0x5df23c RegOpenKeyExA
 0x5df240 RegCloseKey
oleaut32.dll
 0x5df248 SysFreeString
 0x5df24c SysReAllocStringLen
 0x5df250 SysAllocStringLen
kernel32.dll
 0x5df258 TlsSetValue
 0x5df25c TlsGetValue
 0x5df260 LocalAlloc
 0x5df264 GetModuleHandleA
advapi32.dll
 0x5df26c RegSetValueExA
 0x5df270 RegQueryValueExA
 0x5df274 RegQueryValueA
 0x5df278 RegOpenKeyExA
 0x5df27c RegFlushKey
 0x5df280 RegCreateKeyExA
 0x5df284 RegCloseKey
kernel32.dll
 0x5df28c lstrcpyA
 0x5df290 WritePrivateProfileStringA
 0x5df294 WriteFile
 0x5df298 WaitForSingleObject
 0x5df29c VirtualQuery
 0x5df2a0 VirtualAlloc
 0x5df2a4 Sleep
 0x5df2a8 SizeofResource
 0x5df2ac SetThreadLocale
 0x5df2b0 SetFilePointer
 0x5df2b4 SetEvent
 0x5df2b8 SetErrorMode
 0x5df2bc SetEndOfFile
 0x5df2c0 ResumeThread
 0x5df2c4 ResetEvent
 0x5df2c8 ReleaseMutex
 0x5df2cc ReadFile
 0x5df2d0 MultiByteToWideChar
 0x5df2d4 MulDiv
 0x5df2d8 LockResource
 0x5df2dc LoadResource
 0x5df2e0 LoadLibraryA
 0x5df2e4 LeaveCriticalSection
 0x5df2e8 IsBadReadPtr
 0x5df2ec InitializeCriticalSection
 0x5df2f0 GlobalUnlock
 0x5df2f4 GlobalSize
 0x5df2f8 GlobalReAlloc
 0x5df2fc GlobalHandle
 0x5df300 GlobalLock
 0x5df304 GlobalFree
 0x5df308 GlobalFindAtomA
 0x5df30c GlobalDeleteAtom
 0x5df310 GlobalAlloc
 0x5df314 GlobalAddAtomA
 0x5df318 GetVersionExA
 0x5df31c GetVersion
 0x5df320 GetTimeZoneInformation
 0x5df324 GetTickCount
 0x5df328 GetThreadLocale
 0x5df32c GetTempPathA
 0x5df330 GetSystemInfo
 0x5df334 GetStringTypeExA
 0x5df338 GetStdHandle
 0x5df33c GetProcAddress
 0x5df340 GetPrivateProfileStringA
 0x5df344 GetModuleHandleA
 0x5df348 GetModuleFileNameA
 0x5df34c GetLocaleInfoA
 0x5df350 GetLocalTime
 0x5df354 GetLastError
 0x5df358 GetFullPathNameA
 0x5df35c GetFileSize
 0x5df360 GetExitCodeThread
 0x5df364 GetDiskFreeSpaceA
 0x5df368 GetDateFormatA
 0x5df36c GetCurrentThreadId
 0x5df370 GetCurrentProcessId
 0x5df374 GetCPInfo
 0x5df378 GetACP
 0x5df37c FreeResource
 0x5df380 InterlockedIncrement
 0x5df384 InterlockedExchange
 0x5df388 InterlockedDecrement
 0x5df38c FreeLibrary
 0x5df390 FormatMessageA
 0x5df394 FindResourceA
 0x5df398 FindFirstFileA
 0x5df39c FindClose
 0x5df3a0 FileTimeToLocalFileTime
 0x5df3a4 FileTimeToDosDateTime
 0x5df3a8 EnumCalendarInfoA
 0x5df3ac EnterCriticalSection
 0x5df3b0 DeleteCriticalSection
 0x5df3b4 CreateThread
 0x5df3b8 CreateMutexA
 0x5df3bc CreateFileA
 0x5df3c0 CreateEventA
 0x5df3c4 CompareStringA
 0x5df3c8 CloseHandle
version.dll
 0x5df3d0 VerQueryValueA
 0x5df3d4 GetFileVersionInfoSizeA
 0x5df3d8 GetFileVersionInfoA
gdi32.dll
 0x5df3e0 UnrealizeObject
 0x5df3e4 StretchBlt
 0x5df3e8 SetWindowOrgEx
 0x5df3ec SetWindowExtEx
 0x5df3f0 SetWinMetaFileBits
 0x5df3f4 SetViewportOrgEx
 0x5df3f8 SetViewportExtEx
 0x5df3fc SetTextColor
 0x5df400 SetStretchBltMode
 0x5df404 SetROP2
 0x5df408 SetPixel
 0x5df40c SetMapMode
 0x5df410 SetEnhMetaFileBits
 0x5df414 SetDIBColorTable
 0x5df418 SetBrushOrgEx
 0x5df41c SetBkMode
 0x5df420 SetBkColor
 0x5df424 SelectPalette
 0x5df428 SelectObject
 0x5df42c SelectClipRgn
 0x5df430 SaveDC
 0x5df434 RoundRect
 0x5df438 RestoreDC
 0x5df43c Rectangle
 0x5df440 RectVisible
 0x5df444 RealizePalette
 0x5df448 Polyline
 0x5df44c Polygon
 0x5df450 PolyPolyline
 0x5df454 PlayEnhMetaFile
 0x5df458 PatBlt
 0x5df45c MoveToEx
 0x5df460 MaskBlt
 0x5df464 LineTo
 0x5df468 LPtoDP
 0x5df46c IntersectClipRect
 0x5df470 GetWindowOrgEx
 0x5df474 GetWinMetaFileBits
 0x5df478 GetViewportOrgEx
 0x5df47c GetTextMetricsA
 0x5df480 GetTextExtentPointA
 0x5df484 GetTextExtentPoint32A
 0x5df488 GetSystemPaletteEntries
 0x5df48c GetStockObject
 0x5df490 GetPixel
 0x5df494 GetPaletteEntries
 0x5df498 GetOutlineTextMetricsA
 0x5df49c GetObjectA
 0x5df4a0 GetNearestColor
 0x5df4a4 GetEnhMetaFilePaletteEntries
 0x5df4a8 GetEnhMetaFileHeader
 0x5df4ac GetEnhMetaFileBits
 0x5df4b0 GetDeviceCaps
 0x5df4b4 GetDIBits
 0x5df4b8 GetDIBColorTable
 0x5df4bc GetDCOrgEx
 0x5df4c0 GetCurrentPositionEx
 0x5df4c4 GetCurrentObject
 0x5df4c8 GetClipRgn
 0x5df4cc GetClipBox
 0x5df4d0 GetBrushOrgEx
 0x5df4d4 GetBitmapBits
 0x5df4d8 GdiFlush
 0x5df4dc ExtTextOutA
 0x5df4e0 ExtSelectClipRgn
 0x5df4e4 ExtCreateRegion
 0x5df4e8 ExtCreatePen
 0x5df4ec ExcludeClipRect
 0x5df4f0 Ellipse
 0x5df4f4 DeleteObject
 0x5df4f8 DeleteEnhMetaFile
 0x5df4fc DeleteDC
 0x5df500 CreateSolidBrush
 0x5df504 CreateRectRgn
 0x5df508 CreatePolygonRgn
 0x5df50c CreatePenIndirect
 0x5df510 CreatePen
 0x5df514 CreatePalette
 0x5df518 CreateHalftonePalette
 0x5df51c CreateFontIndirectA
 0x5df520 CreateDIBitmap
 0x5df524 CreateDIBSection
 0x5df528 CreateCompatibleDC
 0x5df52c CreateCompatibleBitmap
 0x5df530 CreateBrushIndirect
 0x5df534 CreateBitmap
 0x5df538 CopyEnhMetaFileA
 0x5df53c CombineRgn
 0x5df540 BitBlt
user32.dll
 0x5df548 CreateWindowExA
 0x5df54c WindowFromPoint
 0x5df550 WinHelpA
 0x5df554 WaitMessage
 0x5df558 ValidateRect
 0x5df55c UpdateWindow
 0x5df560 UnregisterClassA
 0x5df564 UnionRect
 0x5df568 UnhookWindowsHookEx
 0x5df56c TranslateMessage
 0x5df570 TranslateMDISysAccel
 0x5df574 TrackPopupMenu
 0x5df578 SystemParametersInfoA
 0x5df57c ShowWindow
 0x5df580 ShowScrollBar
 0x5df584 ShowOwnedPopups
 0x5df588 ShowCursor
 0x5df58c ShowCaret
 0x5df590 SetWindowRgn
 0x5df594 SetWindowsHookExA
 0x5df598 SetWindowTextA
 0x5df59c SetWindowPos
 0x5df5a0 SetWindowPlacement
 0x5df5a4 SetWindowLongW
 0x5df5a8 SetWindowLongA
 0x5df5ac SetTimer
 0x5df5b0 SetScrollRange
 0x5df5b4 SetScrollPos
 0x5df5b8 SetScrollInfo
 0x5df5bc SetRect
 0x5df5c0 SetPropA
 0x5df5c4 SetParent
 0x5df5c8 SetMenuItemInfoA
 0x5df5cc SetMenu
 0x5df5d0 SetKeyboardState
 0x5df5d4 SetForegroundWindow
 0x5df5d8 SetFocus
 0x5df5dc SetCursor
 0x5df5e0 SetClipboardData
 0x5df5e4 SetClassLongA
 0x5df5e8 SetCaretPos
 0x5df5ec SetCapture
 0x5df5f0 SetActiveWindow
 0x5df5f4 SendMessageA
 0x5df5f8 ScrollWindowEx
 0x5df5fc ScrollWindow
 0x5df600 ScreenToClient
 0x5df604 RemovePropA
 0x5df608 RemoveMenu
 0x5df60c ReleaseDC
 0x5df610 ReleaseCapture
 0x5df614 RegisterWindowMessageA
 0x5df618 RegisterClipboardFormatA
 0x5df61c RegisterClassA
 0x5df620 RedrawWindow
 0x5df624 PtInRect
 0x5df628 PostQuitMessage
 0x5df62c PostMessageA
 0x5df630 PeekMessageA
 0x5df634 OpenClipboard
 0x5df638 OffsetRect
 0x5df63c OemToCharA
 0x5df640 MsgWaitForMultipleObjects
 0x5df644 MoveWindow
 0x5df648 MessageBoxA
 0x5df64c MessageBeep
 0x5df650 MapWindowPoints
 0x5df654 MapVirtualKeyA
 0x5df658 LoadStringA
 0x5df65c LoadKeyboardLayoutA
 0x5df660 LoadIconA
 0x5df664 LoadCursorA
 0x5df668 LoadBitmapA
 0x5df66c KillTimer
 0x5df670 IsZoomed
 0x5df674 IsWindowVisible
 0x5df678 IsWindowUnicode
 0x5df67c IsWindowEnabled
 0x5df680 IsWindow
 0x5df684 IsRectEmpty
 0x5df688 IsIconic
 0x5df68c IsDialogMessageA
 0x5df690 IsClipboardFormatAvailable
 0x5df694 IsChild
 0x5df698 IsCharAlphaNumericA
 0x5df69c IsCharAlphaA
 0x5df6a0 InvalidateRect
 0x5df6a4 IntersectRect
 0x5df6a8 InsertMenuItemA
 0x5df6ac InsertMenuA
 0x5df6b0 InflateRect
 0x5df6b4 HideCaret
 0x5df6b8 GetWindowThreadProcessId
 0x5df6bc GetWindowTextLengthW
 0x5df6c0 GetWindowTextW
 0x5df6c4 GetWindowTextA
 0x5df6c8 GetWindowRect
 0x5df6cc GetWindowPlacement
 0x5df6d0 GetWindowLongW
 0x5df6d4 GetWindowLongA
 0x5df6d8 GetWindowDC
 0x5df6dc GetTopWindow
 0x5df6e0 GetSystemMetrics
 0x5df6e4 GetSystemMenu
 0x5df6e8 GetSysColorBrush
 0x5df6ec GetSysColor
 0x5df6f0 GetSubMenu
 0x5df6f4 GetScrollRange
 0x5df6f8 GetScrollPos
 0x5df6fc GetScrollInfo
 0x5df700 GetPropA
 0x5df704 GetParent
 0x5df708 GetWindow
 0x5df70c GetMessageTime
 0x5df710 GetMenuStringA
 0x5df714 GetMenuState
 0x5df718 GetMenuItemInfoA
 0x5df71c GetMenuItemID
 0x5df720 GetMenuItemCount
 0x5df724 GetMenu
 0x5df728 GetLastActivePopup
 0x5df72c GetKeyboardState
 0x5df730 GetKeyboardLayoutList
 0x5df734 GetKeyboardLayout
 0x5df738 GetKeyState
 0x5df73c GetKeyNameTextA
 0x5df740 GetIconInfo
 0x5df744 GetForegroundWindow
 0x5df748 GetFocus
 0x5df74c GetDoubleClickTime
 0x5df750 GetDlgItem
 0x5df754 GetDlgCtrlID
 0x5df758 GetDesktopWindow
 0x5df75c GetDCEx
 0x5df760 GetDC
 0x5df764 GetCursorPos
 0x5df768 GetCursor
 0x5df76c GetClipboardData
 0x5df770 GetClientRect
 0x5df774 GetClassNameA
 0x5df778 GetClassInfoA
 0x5df77c GetCaretPos
 0x5df780 GetCapture
 0x5df784 GetActiveWindow
 0x5df788 FrameRect
 0x5df78c FindWindowExA
 0x5df790 FindWindowA
 0x5df794 FillRect
 0x5df798 EqualRect
 0x5df79c EnumWindows
 0x5df7a0 EnumThreadWindows
 0x5df7a4 EnumClipboardFormats
 0x5df7a8 EndPaint
 0x5df7ac EnableWindow
 0x5df7b0 EnableScrollBar
 0x5df7b4 EnableMenuItem
 0x5df7b8 EmptyClipboard
 0x5df7bc DrawTextExA
 0x5df7c0 DrawTextW
 0x5df7c4 DrawTextA
 0x5df7c8 DrawMenuBar
 0x5df7cc DrawIconEx
 0x5df7d0 DrawIcon
 0x5df7d4 DrawFrameControl
 0x5df7d8 DrawFocusRect
 0x5df7dc DrawEdge
 0x5df7e0 DispatchMessageA
 0x5df7e4 DestroyWindow
 0x5df7e8 DestroyMenu
 0x5df7ec DestroyIcon
 0x5df7f0 DestroyCursor
 0x5df7f4 DestroyCaret
 0x5df7f8 DeleteMenu
 0x5df7fc DefWindowProcA
 0x5df800 DefMDIChildProcA
 0x5df804 DefFrameProcA
 0x5df808 CreatePopupMenu
 0x5df80c CreateMenu
 0x5df810 CreateIcon
 0x5df814 CreateCaret
 0x5df818 CopyImage
 0x5df81c CloseClipboard
 0x5df820 ClientToScreen
 0x5df824 CheckMenuItem
 0x5df828 CallWindowProcA
 0x5df82c CallNextHookEx
 0x5df830 BeginPaint
 0x5df834 CharNextA
 0x5df838 CharLowerBuffA
 0x5df83c CharLowerA
 0x5df840 CharUpperBuffA
 0x5df844 CharToOemA
 0x5df848 AdjustWindowRectEx
 0x5df84c ActivateKeyboardLayout
ole32.dll
 0x5df854 CoTaskMemFree
 0x5df858 StringFromCLSID
kernel32.dll
 0x5df860 Sleep
oleaut32.dll
 0x5df868 SafeArrayPtrOfIndex
 0x5df86c SafeArrayPutElement
 0x5df870 SafeArrayGetElement
 0x5df874 SafeArrayUnaccessData
 0x5df878 SafeArrayAccessData
 0x5df87c SafeArrayGetUBound
 0x5df880 SafeArrayGetLBound
 0x5df884 SafeArrayRedim
 0x5df888 SafeArrayCreate
 0x5df88c VariantChangeType
 0x5df890 VariantCopyInd
 0x5df894 VariantCopy
 0x5df898 VariantClear
 0x5df89c VariantInit
ole32.dll
 0x5df8a4 CoCreateInstance
 0x5df8a8 CoGetMalloc
 0x5df8ac CoUninitialize
 0x5df8b0 CoInitialize
 0x5df8b4 IsEqualGUID
oleaut32.dll
 0x5df8bc CreateErrorInfo
 0x5df8c0 GetErrorInfo
 0x5df8c4 SetErrorInfo
 0x5df8c8 SafeArrayCopy
 0x5df8cc SafeArrayUnaccessData
 0x5df8d0 SafeArrayAccessData
 0x5df8d4 SafeArrayGetUBound
 0x5df8d8 SafeArrayDestroy
 0x5df8dc SafeArrayCreate
 0x5df8e0 SysFreeString
comctl32.dll
 0x5df8e8 ImageList_SetIconSize
 0x5df8ec ImageList_GetIconSize
 0x5df8f0 ImageList_Write
 0x5df8f4 ImageList_Read
 0x5df8f8 ImageList_GetDragImage
 0x5df8fc ImageList_DragShowNolock
 0x5df900 ImageList_SetDragCursorImage
 0x5df904 ImageList_DragMove
 0x5df908 ImageList_DragLeave
 0x5df90c ImageList_DragEnter
 0x5df910 ImageList_EndDrag
 0x5df914 ImageList_BeginDrag
 0x5df918 ImageList_LoadImageA
 0x5df91c ImageList_Remove
 0x5df920 ImageList_DrawEx
 0x5df924 ImageList_Replace
 0x5df928 ImageList_Draw
 0x5df92c ImageList_GetBkColor
 0x5df930 ImageList_SetBkColor
 0x5df934 ImageList_ReplaceIcon
 0x5df938 ImageList_Add
 0x5df93c ImageList_GetImageCount
 0x5df940 ImageList_Destroy
 0x5df944 ImageList_Create
 0x5df948 InitCommonControls
comdlg32.dll
 0x5df950 GetSaveFileNameA
 0x5df954 GetOpenFileNameA
kernel32.dll
 0x5df95c MulDiv
kernel32.dll
 0x5df964 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure