Report - 66bf6d1018bb1_deskman.exe

Generic Malware Malicious Library Malicious Packer UPX PE File PE64 DllRegisterServer dll MSOffice File OS Processor Check
ScreenShot
Created 2024.08.21 13:47 Machine s1_win7_x6401
Filename 66bf6d1018bb1_deskman.exe
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
AI Score Not founds Behavior Score
1.0
ZERO API file : mailcious
VT API (file) 37 detected (AIDetectMalware, malicious, high confidence, Artemis, Unsafe, V6rq, Attribute, HighConfidence, a variant of WinGo, qwiuzr, GenKryptik, AGEN, LUMMASTEALER, YXEHQZ, Detected, Wacatac, Acll, I5GZ4R, Eldorado, R635432, WinGo, Gencirc, susgen, B9nj)
md5 9b3fcb53cc12bc68eb44db3e55ad4731
sha256 bcad9c21500bf00e52eba9d790a68507d4027eb31a16d40ff41b99de11d7cd54
ssdeep 98304:xHaC2FWf2YTdfiz/aBxnIL3jz9hds0NmYhfNE7L0TNyfo6QGqcC9:sM2cdfiEQ1hfe7oTcFQGqr9
imphash 5337a536d7037104682f1805fcc9fefb
impfuzzy 96:kFnOJexMCyS5pmvxHS42xQ2H3XiXF2X1PgApTJGQ666myqTVdebMpFg3m6RaUDfT:kFnOgryS52/e3SoFotQ6NmTVk+g3m6Rf
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 37 AntiVirus engines on VirusTotal as malicious

Rules (9cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE64 (no description) binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

GDI32.dll
 0x14170d8f0 ChoosePixelFormat
 0x14170d8f8 CreateBitmap
 0x14170d900 CreateDCW
 0x14170d908 CreateDIBSection
 0x14170d910 CreateRectRgn
 0x14170d918 DeleteDC
 0x14170d920 DeleteObject
 0x14170d928 DescribePixelFormat
 0x14170d930 GetDeviceCaps
 0x14170d938 GetDeviceGammaRamp
 0x14170d940 SetDeviceGammaRamp
 0x14170d948 SetPixelFormat
 0x14170d950 SwapBuffers
KERNEL32.dll
 0x14170d960 AddAtomA
 0x14170d968 AddVectoredContinueHandler
 0x14170d970 AddVectoredExceptionHandler
 0x14170d978 CloseHandle
 0x14170d980 CreateEventA
 0x14170d988 CreateFileA
 0x14170d990 CreateIoCompletionPort
 0x14170d998 CreateMutexA
 0x14170d9a0 CreateSemaphoreA
 0x14170d9a8 CreateThread
 0x14170d9b0 CreateWaitableTimerExW
 0x14170d9b8 DeleteAtom
 0x14170d9c0 DeleteCriticalSection
 0x14170d9c8 DuplicateHandle
 0x14170d9d0 EnterCriticalSection
 0x14170d9d8 ExitProcess
 0x14170d9e0 FindAtomA
 0x14170d9e8 FormatMessageA
 0x14170d9f0 FormatMessageW
 0x14170d9f8 FreeEnvironmentStringsW
 0x14170da00 FreeLibrary
 0x14170da08 GetAtomNameA
 0x14170da10 GetConsoleMode
 0x14170da18 GetCurrentProcess
 0x14170da20 GetCurrentProcessId
 0x14170da28 GetCurrentThread
 0x14170da30 GetCurrentThreadId
 0x14170da38 GetEnvironmentStringsW
 0x14170da40 GetErrorMode
 0x14170da48 GetHandleInformation
 0x14170da50 GetLastError
 0x14170da58 GetModuleHandleExW
 0x14170da60 GetModuleHandleW
 0x14170da68 GetProcAddress
 0x14170da70 GetProcessAffinityMask
 0x14170da78 GetQueuedCompletionStatusEx
 0x14170da80 GetStartupInfoA
 0x14170da88 GetStdHandle
 0x14170da90 GetSystemDirectoryA
 0x14170da98 GetSystemInfo
 0x14170daa0 GetSystemTimeAsFileTime
 0x14170daa8 GetThreadContext
 0x14170dab0 GetThreadPriority
 0x14170dab8 GetTickCount
 0x14170dac0 GlobalAlloc
 0x14170dac8 GlobalFree
 0x14170dad0 GlobalLock
 0x14170dad8 GlobalUnlock
 0x14170dae0 InitializeCriticalSection
 0x14170dae8 IsDBCSLeadByteEx
 0x14170daf0 IsDebuggerPresent
 0x14170daf8 LeaveCriticalSection
 0x14170db00 LoadLibraryA
 0x14170db08 LoadLibraryExW
 0x14170db10 LoadLibraryW
 0x14170db18 LocalFree
 0x14170db20 MultiByteToWideChar
 0x14170db28 OpenProcess
 0x14170db30 OutputDebugStringA
 0x14170db38 PostQueuedCompletionStatus
 0x14170db40 QueryPerformanceCounter
 0x14170db48 QueryPerformanceFrequency
 0x14170db50 RaiseException
 0x14170db58 RaiseFailFastException
 0x14170db60 ReleaseMutex
 0x14170db68 ReleaseSemaphore
 0x14170db70 RemoveVectoredExceptionHandler
 0x14170db78 ResetEvent
 0x14170db80 ResumeThread
 0x14170db88 RtlLookupFunctionEntry
 0x14170db90 RtlVirtualUnwind
 0x14170db98 SetConsoleCtrlHandler
 0x14170dba0 SetErrorMode
 0x14170dba8 SetEvent
 0x14170dbb0 SetLastError
 0x14170dbb8 SetProcessAffinityMask
 0x14170dbc0 SetProcessPriorityBoost
 0x14170dbc8 SetThreadContext
 0x14170dbd0 SetThreadExecutionState
 0x14170dbd8 SetThreadPriority
 0x14170dbe0 SetUnhandledExceptionFilter
 0x14170dbe8 SetWaitableTimer
 0x14170dbf0 Sleep
 0x14170dbf8 SuspendThread
 0x14170dc00 SwitchToThread
 0x14170dc08 TlsAlloc
 0x14170dc10 TlsFree
 0x14170dc18 TlsGetValue
 0x14170dc20 TlsSetValue
 0x14170dc28 TryEnterCriticalSection
 0x14170dc30 VerSetConditionMask
 0x14170dc38 VirtualAlloc
 0x14170dc40 VirtualFree
 0x14170dc48 VirtualProtect
 0x14170dc50 VirtualQuery
 0x14170dc58 WaitForMultipleObjects
 0x14170dc60 WaitForSingleObject
 0x14170dc68 WerGetFlags
 0x14170dc70 WerSetFlags
 0x14170dc78 WideCharToMultiByte
 0x14170dc80 WriteConsoleW
 0x14170dc88 WriteFile
 0x14170dc90 __C_specific_handler
msvcrt.dll
 0x14170dca0 ___lc_codepage_func
 0x14170dca8 ___mb_cur_max_func
 0x14170dcb0 __getmainargs
 0x14170dcb8 __initenv
 0x14170dcc0 __iob_func
 0x14170dcc8 __lconv_init
 0x14170dcd0 __set_app_type
 0x14170dcd8 __setusermatherr
 0x14170dce0 _acmdln
 0x14170dce8 _amsg_exit
 0x14170dcf0 _beginthread
 0x14170dcf8 _beginthreadex
 0x14170dd00 _cexit
 0x14170dd08 _commode
 0x14170dd10 _endthreadex
 0x14170dd18 _errno
 0x14170dd20 _fmode
 0x14170dd28 _initterm
 0x14170dd30 _lock
 0x14170dd38 _memccpy
 0x14170dd40 _onexit
 0x14170dd48 _setjmp
 0x14170dd50 _strdup
 0x14170dd58 _ultoa
 0x14170dd60 _unlock
 0x14170dd68 _wassert
 0x14170dd70 abort
 0x14170dd78 calloc
 0x14170dd80 exit
 0x14170dd88 fprintf
 0x14170dd90 fputc
 0x14170dd98 free
 0x14170dda0 fwrite
 0x14170dda8 getc
 0x14170ddb0 islower
 0x14170ddb8 isspace
 0x14170ddc0 isupper
 0x14170ddc8 isxdigit
 0x14170ddd0 localeconv
 0x14170ddd8 longjmp
 0x14170dde0 malloc
 0x14170dde8 memcpy
 0x14170ddf0 memmove
 0x14170ddf8 memset
 0x14170de00 printf
 0x14170de08 qsort
 0x14170de10 realloc
 0x14170de18 signal
 0x14170de20 strcmp
 0x14170de28 strcpy
 0x14170de30 strcspn
 0x14170de38 strerror
 0x14170de40 strlen
 0x14170de48 strncmp
 0x14170de50 strncpy
 0x14170de58 strspn
 0x14170de60 strstr
 0x14170de68 strtok
 0x14170de70 strtol
 0x14170de78 strtoul
 0x14170de80 tolower
 0x14170de88 ungetc
 0x14170de90 vfprintf
 0x14170de98 wcscmp
 0x14170dea0 wcscpy
 0x14170dea8 wcslen
SHELL32.dll
 0x14170deb8 DragAcceptFiles
 0x14170dec0 DragFinish
 0x14170dec8 DragQueryFileW
 0x14170ded0 DragQueryPoint
USER32.dll
 0x14170dee0 AdjustWindowRectEx
 0x14170dee8 BringWindowToTop
 0x14170def0 ChangeDisplaySettingsExW
 0x14170def8 ClientToScreen
 0x14170df00 ClipCursor
 0x14170df08 CloseClipboard
 0x14170df10 CreateIconIndirect
 0x14170df18 CreateWindowExW
 0x14170df20 DefWindowProcW
 0x14170df28 DestroyIcon
 0x14170df30 DestroyWindow
 0x14170df38 DispatchMessageW
 0x14170df40 EmptyClipboard
 0x14170df48 EnumDisplayDevicesW
 0x14170df50 EnumDisplayMonitors
 0x14170df58 EnumDisplaySettingsExW
 0x14170df60 EnumDisplaySettingsW
 0x14170df68 FlashWindow
 0x14170df70 GetActiveWindow
 0x14170df78 GetClassLongPtrW
 0x14170df80 GetClientRect
 0x14170df88 GetClipboardData
 0x14170df90 GetCursorPos
 0x14170df98 GetDC
 0x14170dfa0 GetKeyState
 0x14170dfa8 GetLayeredWindowAttributes
 0x14170dfb0 GetMessageTime
 0x14170dfb8 GetMonitorInfoW
 0x14170dfc0 GetPropW
 0x14170dfc8 GetRawInputData
 0x14170dfd0 GetRawInputDeviceInfoA
 0x14170dfd8 GetRawInputDeviceList
 0x14170dfe0 GetSystemMetrics
 0x14170dfe8 GetWindowLongW
 0x14170dff0 GetWindowPlacement
 0x14170dff8 GetWindowRect
 0x14170e000 IsIconic
 0x14170e008 IsWindowVisible
 0x14170e010 IsZoomed
 0x14170e018 LoadCursorW
 0x14170e020 LoadImageW
 0x14170e028 MapVirtualKeyW
 0x14170e030 MonitorFromWindow
 0x14170e038 MoveWindow
 0x14170e040 MsgWaitForMultipleObjects
 0x14170e048 OffsetRect
 0x14170e050 OpenClipboard
 0x14170e058 PeekMessageW
 0x14170e060 PostMessageW
 0x14170e068 PtInRect
 0x14170e070 RegisterClassExW
 0x14170e078 RegisterDeviceNotificationW
 0x14170e080 RegisterRawInputDevices
 0x14170e088 ReleaseCapture
 0x14170e090 ReleaseDC
 0x14170e098 RemovePropW
 0x14170e0a0 ScreenToClient
 0x14170e0a8 SendMessageW
 0x14170e0b0 SetCapture
 0x14170e0b8 SetClipboardData
 0x14170e0c0 SetCursor
 0x14170e0c8 SetCursorPos
 0x14170e0d0 SetFocus
 0x14170e0d8 SetForegroundWindow
 0x14170e0e0 SetLayeredWindowAttributes
 0x14170e0e8 SetPropW
 0x14170e0f0 SetRect
 0x14170e0f8 SetWindowLongW
 0x14170e100 SetWindowPlacement
 0x14170e108 SetWindowPos
 0x14170e110 SetWindowTextW
 0x14170e118 ShowWindow
 0x14170e120 SystemParametersInfoW
 0x14170e128 ToUnicode
 0x14170e130 TrackMouseEvent
 0x14170e138 TranslateMessage
 0x14170e140 UnregisterClassW
 0x14170e148 UnregisterDeviceNotification
 0x14170e150 WaitMessage
 0x14170e158 WindowFromPoint

EAT(Export Address Table) Library

0x14170a390 _cgo_dummy_export
0x14087c200 goCharCB
0x14087c250 goCharModsCB
0x14087c0d0 goCursorEnterCB
0x14087c060 goCursorPosCB
0x14087c2b0 goDropCB
0x14087bf50 goErrorCB
0x14087c430 goFramebufferSizeCB
0x14087bfb0 goJoystickCB
0x14087c190 goKeyCB
0x14087c320 goMonitorCB
0x14087c000 goMouseButtonCB
0x14087c120 goScrollCB
0x14087c490 goWindowCloseCB
0x14087c620 goWindowContentScaleCB
0x14087c580 goWindowFocusCB
0x14087c5d0 goWindowIconifyCB
0x14087c4e0 goWindowMaximizeCB
0x14087c370 goWindowPosCB
0x14087c530 goWindowRefreshCB
0x14087c3d0 goWindowSizeCB


Similarity measure (PE file only) - Checking for service failure