Report - 66e096a0354a7_Burn.exe

Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer UPX PE File PE32 MZP Format OS Processor Check
ScreenShot
Created 2024.09.12 13:11 Machine s1_win7_x6401
Filename 66e096a0354a7_Burn.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
1.4
ZERO API file : mailcious
VT API (file) 22 detected (AIDetectMalware, Vd58, GenericKD, Attribute, HighConfidence, LummaStealer, FileRepMalware, ai score=85, Detected, Stealc, MALICIOUS, Lumma)
md5 9577e48285b66a841485df16c155628f
sha256 2a3dc406419165a8dcb97d082f333b18f69dd185a0062afb7fc1de6fc355dd1f
ssdeep 49152:sHcUNVV6G2f8SHnu/lVTz1B5wjdhjHV08pTm3HVD29IiO:QZVzX5wjdhJ08E31DviO
imphash 1b6c71ca10f5c60d934f551b445736f7
impfuzzy 192:gW7Ne5ErhsQKy+xe6wI1uvUTmmf4QdOhz/c6VFgTFLQwS/33m28:gIwmrC86w24QdOd/c0ep1UG28
  Network IP location

Signature (3cnts)

Level Description
warning File has been identified by 22 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (8cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

shlwapi.dll
 0x8719b4 PathMatchSpecW
 0x8719b8 StrRetToStrW
winspool.drv
 0x8719c0 DocumentPropertiesW
 0x8719c4 ClosePrinter
 0x8719c8 OpenPrinterW
 0x8719cc GetDefaultPrinterW
 0x8719d0 EnumPrintersW
comdlg32.dll
 0x8719d8 ChooseColorW
 0x8719dc GetOpenFileNameW
comctl32.dll
 0x8719e4 FlatSB_SetScrollInfo
 0x8719e8 InitCommonControls
 0x8719ec ImageList_DragMove
 0x8719f0 ImageList_Destroy
 0x8719f4 _TrackMouseEvent
 0x8719f8 ImageList_DragShowNolock
 0x8719fc ImageList_Add
 0x871a00 ImageList_GetDragImage
 0x871a04 FlatSB_SetScrollProp
 0x871a08 ImageList_Create
 0x871a0c ImageList_EndDrag
 0x871a10 ImageList_DrawEx
 0x871a14 ImageList_SetImageCount
 0x871a18 FlatSB_GetScrollPos
 0x871a1c FlatSB_SetScrollPos
 0x871a20 InitializeFlatSB
 0x871a24 ImageList_Copy
 0x871a28 FlatSB_GetScrollInfo
 0x871a2c ImageList_Write
 0x871a30 ImageList_SetBkColor
 0x871a34 ImageList_GetBkColor
 0x871a38 ImageList_BeginDrag
 0x871a3c ImageList_GetIcon
 0x871a40 ImageList_Replace
 0x871a44 ImageList_GetImageCount
 0x871a48 ImageList_DragEnter
 0x871a4c ImageList_GetIconSize
 0x871a50 ImageList_SetIconSize
 0x871a54 ImageList_Read
 0x871a58 ImageList_DragLeave
 0x871a5c ImageList_Draw
 0x871a60 ImageList_Remove
 0x871a64 ImageList_ReplaceIcon
 0x871a68 ImageList_SetOverlayImage
shell32.dll
 0x871a70 SHBindToParent
 0x871a74 DragQueryFileW
 0x871a78 SHGetSpecialFolderLocation
 0x871a7c ILCombine
 0x871a80 Shell_NotifyIconW
 0x871a84 SHCreateShellItem
 0x871a88 SHGetDataFromIDListW
 0x871a8c SHGetPathFromIDListW
 0x871a90 ILFindLastID
 0x871a94 ILGetNext
 0x871a98 SHChangeNotifyDeregister
 0x871a9c ILCreateFromPathW
 0x871aa0 ILFindChild
 0x871aa4 SHGetFileInfoW
 0x871aa8 SHGetDesktopFolder
 0x871aac ILRemoveLastID
 0x871ab0 ILFree
 0x871ab4 ILClone
 0x871ab8 IsUserAnAdmin
 0x871abc SHChangeNotification_Unlock
 0x871ac0 ShellExecuteW
user32.dll
 0x871ac8 CopyImage
 0x871acc SetMenuItemInfoW
 0x871ad0 GetMenuItemInfoW
 0x871ad4 DefFrameProcW
 0x871ad8 GetDlgCtrlID
 0x871adc FrameRect
 0x871ae0 RegisterWindowMessageW
 0x871ae4 GetMenuStringW
 0x871ae8 FillRect
 0x871aec SendMessageA
 0x871af0 EnumWindows
 0x871af4 ShowOwnedPopups
 0x871af8 GetClassInfoExW
 0x871afc GetClassInfoW
 0x871b00 GetScrollRange
 0x871b04 SetActiveWindow
 0x871b08 GetActiveWindow
 0x871b0c DrawEdge
 0x871b10 GetKeyboardLayoutList
 0x871b14 LoadBitmapW
 0x871b18 EnumChildWindows
 0x871b1c GetScrollBarInfo
 0x871b20 UnhookWindowsHookEx
 0x871b24 SetCapture
 0x871b28 GetCapture
 0x871b2c ShowCaret
 0x871b30 CreatePopupMenu
 0x871b34 GetMenuItemID
 0x871b38 CharLowerBuffW
 0x871b3c PostMessageW
 0x871b40 SetWindowLongW
 0x871b44 IsZoomed
 0x871b48 SetParent
 0x871b4c DrawMenuBar
 0x871b50 GetClientRect
 0x871b54 IsChild
 0x871b58 IsIconic
 0x871b5c CallNextHookEx
 0x871b60 ShowWindow
 0x871b64 GetWindowTextW
 0x871b68 SetForegroundWindow
 0x871b6c IsDialogMessageW
 0x871b70 DestroyWindow
 0x871b74 RegisterClassW
 0x871b78 EndMenu
 0x871b7c CharNextW
 0x871b80 GetFocus
 0x871b84 GetDC
 0x871b88 SetFocus
 0x871b8c ReleaseDC
 0x871b90 ExitWindowsEx
 0x871b94 GetClassLongW
 0x871b98 SetScrollRange
 0x871b9c DrawTextW
 0x871ba0 PeekMessageA
 0x871ba4 MessageBeep
 0x871ba8 SetClassLongW
 0x871bac RemovePropW
 0x871bb0 GetSubMenu
 0x871bb4 DestroyIcon
 0x871bb8 IsWindowVisible
 0x871bbc PtInRect
 0x871bc0 DispatchMessageA
 0x871bc4 UnregisterClassW
 0x871bc8 GetTopWindow
 0x871bcc SendMessageW
 0x871bd0 GetComboBoxInfo
 0x871bd4 LoadStringW
 0x871bd8 CreateMenu
 0x871bdc CharLowerW
 0x871be0 SetWindowPos
 0x871be4 SetWindowRgn
 0x871be8 GetMenuItemCount
 0x871bec GetSysColorBrush
 0x871bf0 GetWindowDC
 0x871bf4 DrawTextExW
 0x871bf8 GetScrollInfo
 0x871bfc SetWindowTextW
 0x871c00 GetMessageExtraInfo
 0x871c04 GetSysColor
 0x871c08 EnableScrollBar
 0x871c0c TrackPopupMenu
 0x871c10 DrawIconEx
 0x871c14 GetClassNameW
 0x871c18 GetMessagePos
 0x871c1c GetIconInfo
 0x871c20 SetScrollInfo
 0x871c24 GetKeyNameTextW
 0x871c28 GetDesktopWindow
 0x871c2c SetCursorPos
 0x871c30 GetCursorPos
 0x871c34 SetMenu
 0x871c38 GetMenuState
 0x871c3c GetMenu
 0x871c40 SetRect
 0x871c44 GetKeyState
 0x871c48 IsRectEmpty
 0x871c4c GetCursor
 0x871c50 KillTimer
 0x871c54 WaitMessage
 0x871c58 TranslateMDISysAccel
 0x871c5c GetWindowPlacement
 0x871c60 GetMenuItemRect
 0x871c64 CreateIconIndirect
 0x871c68 CreateWindowExW
 0x871c6c ChildWindowFromPoint
 0x871c70 GetDCEx
 0x871c74 PeekMessageW
 0x871c78 MonitorFromWindow
 0x871c7c GetUpdateRect
 0x871c80 MessageBoxA
 0x871c84 SetTimer
 0x871c88 WindowFromPoint
 0x871c8c BeginPaint
 0x871c90 RegisterClipboardFormatW
 0x871c94 MapVirtualKeyW
 0x871c98 OffsetRect
 0x871c9c IsWindowUnicode
 0x871ca0 DispatchMessageW
 0x871ca4 DefMDIChildProcW
 0x871ca8 GetSystemMenu
 0x871cac SetScrollPos
 0x871cb0 GetScrollPos
 0x871cb4 InflateRect
 0x871cb8 DrawFocusRect
 0x871cbc ReleaseCapture
 0x871cc0 LoadCursorW
 0x871cc4 ScrollWindow
 0x871cc8 GetLastActivePopup
 0x871ccc GetSystemMetrics
 0x871cd0 CharUpperBuffW
 0x871cd4 SetClipboardData
 0x871cd8 GetClipboardData
 0x871cdc ClientToScreen
 0x871ce0 SetWindowPlacement
 0x871ce4 GetMonitorInfoW
 0x871ce8 CheckMenuItem
 0x871cec CharUpperW
 0x871cf0 DefWindowProcW
 0x871cf4 GetForegroundWindow
 0x871cf8 EnableWindow
 0x871cfc GetWindowThreadProcessId
 0x871d00 RedrawWindow
 0x871d04 EndPaint
 0x871d08 MsgWaitForMultipleObjectsEx
 0x871d0c LoadKeyboardLayoutW
 0x871d10 ActivateKeyboardLayout
 0x871d14 GetParent
 0x871d18 InsertMenuItemW
 0x871d1c GetPropW
 0x871d20 MessageBoxW
 0x871d24 SetPropW
 0x871d28 UpdateWindow
 0x871d2c MsgWaitForMultipleObjects
 0x871d30 DestroyMenu
 0x871d34 SetWindowsHookExW
 0x871d38 EmptyClipboard
 0x871d3c GetDlgItem
 0x871d40 AdjustWindowRectEx
 0x871d44 IsWindow
 0x871d48 DrawIcon
 0x871d4c EnumThreadWindows
 0x871d50 InvalidateRect
 0x871d54 GetKeyboardState
 0x871d58 ScreenToClient
 0x871d5c DrawFrameControl
 0x871d60 SetCursor
 0x871d64 CreateIcon
 0x871d68 RemoveMenu
 0x871d6c GetKeyboardLayoutNameW
 0x871d70 OpenClipboard
 0x871d74 TranslateMessage
 0x871d78 MapWindowPoints
 0x871d7c EnumDisplayMonitors
 0x871d80 CallWindowProcW
 0x871d84 CloseClipboard
 0x871d88 DestroyCursor
 0x871d8c PostQuitMessage
 0x871d90 ShowScrollBar
 0x871d94 EnableMenuItem
 0x871d98 HideCaret
 0x871d9c FindWindowExW
 0x871da0 MonitorFromPoint
 0x871da4 LoadIconW
 0x871da8 SystemParametersInfoW
 0x871dac GetWindow
 0x871db0 GetWindowRect
 0x871db4 GetWindowLongW
 0x871db8 InsertMenuW
 0x871dbc IsWindowEnabled
 0x871dc0 IsDialogMessageA
 0x871dc4 FindWindowW
 0x871dc8 GetKeyboardLayout
 0x871dcc DeleteMenu
version.dll
 0x871dd4 GetFileVersionInfoSizeW
 0x871dd8 VerQueryValueW
 0x871ddc GetFileVersionInfoW
oleaut32.dll
 0x871de4 SysFreeString
 0x871de8 VariantClear
 0x871dec VariantInit
 0x871df0 GetErrorInfo
 0x871df4 SysReAllocStringLen
 0x871df8 SafeArrayCreate
 0x871dfc SysAllocStringLen
 0x871e00 SafeArrayPtrOfIndex
 0x871e04 SafeArrayGetUBound
 0x871e08 SafeArrayGetLBound
 0x871e0c VariantCopy
 0x871e10 VariantChangeType
advapi32.dll
 0x871e18 CheckTokenMembership
 0x871e1c RegFlushKey
 0x871e20 RegQueryValueExW
 0x871e24 AdjustTokenPrivileges
 0x871e28 LookupPrivilegeValueW
 0x871e2c RegCloseKey
 0x871e30 OpenProcessToken
 0x871e34 RegOpenKeyExW
 0x871e38 AllocateAndInitializeSid
 0x871e3c FreeSid
netapi32.dll
 0x871e44 NetWkstaGetInfo
 0x871e48 NetApiBufferFree
msvcrt.dll
 0x871e50 memcpy
 0x871e54 memset
kernel32.dll
 0x871e5c GetACP
 0x871e60 LocalFree
 0x871e64 CloseHandle
 0x871e68 GetCurrentProcessId
 0x871e6c SizeofResource
 0x871e70 VirtualProtect
 0x871e74 TerminateThread
 0x871e78 QueryPerformanceFrequency
 0x871e7c IsDebuggerPresent
 0x871e80 FindNextFileW
 0x871e84 GetFullPathNameW
 0x871e88 VirtualFree
 0x871e8c ExitProcess
 0x871e90 HeapAlloc
 0x871e94 GetCPInfoExW
 0x871e98 GetLongPathNameW
 0x871e9c RtlUnwind
 0x871ea0 GetCPInfo
 0x871ea4 GetStdHandle
 0x871ea8 FileTimeToLocalFileTime
 0x871eac GetModuleHandleW
 0x871eb0 FreeLibrary
 0x871eb4 HeapDestroy
 0x871eb8 FileTimeToDosDateTime
 0x871ebc ReadFile
 0x871ec0 GetLastError
 0x871ec4 GetModuleFileNameW
 0x871ec8 SetLastError
 0x871ecc GlobalAlloc
 0x871ed0 GlobalUnlock
 0x871ed4 FindResourceW
 0x871ed8 CreateThread
 0x871edc CompareStringW
 0x871ee0 LoadLibraryA
 0x871ee4 ResetEvent
 0x871ee8 MulDiv
 0x871eec FreeResource
 0x871ef0 GetDriveTypeW
 0x871ef4 GetVersion
 0x871ef8 SetThreadExecutionState
 0x871efc RaiseException
 0x871f00 GlobalAddAtomW
 0x871f04 FormatMessageW
 0x871f08 SwitchToThread
 0x871f0c GetExitCodeThread
 0x871f10 OutputDebugStringW
 0x871f14 GetCurrentThread
 0x871f18 GetLogicalDrives
 0x871f1c GetFileAttributesExW
 0x871f20 ExpandEnvironmentStringsW
 0x871f24 LoadLibraryExW
 0x871f28 LockResource
 0x871f2c GetCurrentThreadId
 0x871f30 UnhandledExceptionFilter
 0x871f34 VirtualQuery
 0x871f38 GlobalFindAtomW
 0x871f3c VirtualQueryEx
 0x871f40 GlobalFree
 0x871f44 Sleep
 0x871f48 EnterCriticalSection
 0x871f4c SetFilePointer
 0x871f50 LoadResource
 0x871f54 SuspendThread
 0x871f58 GetTickCount
 0x871f5c WritePrivateProfileStringW
 0x871f60 GetStartupInfoW
 0x871f64 GlobalDeleteAtom
 0x871f68 GetFileAttributesW
 0x871f6c InitializeCriticalSection
 0x871f70 GetThreadPriority
 0x871f74 GetCurrentProcess
 0x871f78 SetThreadPriority
 0x871f7c GlobalLock
 0x871f80 VirtualAlloc
 0x871f84 GetSystemInfo
 0x871f88 GetCommandLineW
 0x871f8c LeaveCriticalSection
 0x871f90 GetProcAddress
 0x871f94 ResumeThread
 0x871f98 GetVersionExW
 0x871f9c VerifyVersionInfoW
 0x871fa0 HeapCreate
 0x871fa4 GetWindowsDirectoryW
 0x871fa8 DeviceIoControl
 0x871fac GetDiskFreeSpaceW
 0x871fb0 VerSetConditionMask
 0x871fb4 FindFirstFileW
 0x871fb8 GetUserDefaultUILanguage
 0x871fbc GetModuleFileNameA
 0x871fc0 lstrlenW
 0x871fc4 QueryPerformanceCounter
 0x871fc8 SetEndOfFile
 0x871fcc lstrcpyW
 0x871fd0 lstrcmpW
 0x871fd4 HeapFree
 0x871fd8 WideCharToMultiByte
 0x871fdc FindClose
 0x871fe0 MultiByteToWideChar
 0x871fe4 LoadLibraryW
 0x871fe8 SetEvent
 0x871fec CreateFileW
 0x871ff0 GetLocaleInfoW
 0x871ff4 EnumResourceNamesW
 0x871ff8 GetEnvironmentVariableW
 0x871ffc GetLocalTime
 0x872000 WaitForSingleObject
 0x872004 WriteFile
 0x872008 ExitThread
 0x87200c DeleteCriticalSection
 0x872010 GetDateFormatW
 0x872014 TlsGetValue
 0x872018 SetErrorMode
 0x87201c IsValidLocale
 0x872020 TlsSetValue
 0x872024 CreateDirectoryW
 0x872028 GetSystemDefaultUILanguage
 0x87202c EnumCalendarInfoW
 0x872030 LocalAlloc
 0x872034 CreateEventW
 0x872038 GetPrivateProfileStringW
 0x87203c WaitForMultipleObjectsEx
 0x872040 SetThreadLocale
 0x872044 GetThreadLocale
ole32.dll
 0x87204c RevokeDragDrop
 0x872050 CreateBindCtx
 0x872054 CoCreateInstance
 0x872058 CoUninitialize
 0x87205c ReleaseStgMedium
 0x872060 RegisterDragDrop
 0x872064 IsEqualGUID
 0x872068 OleInitialize
 0x87206c OleUninitialize
 0x872070 CoInitializeEx
 0x872074 CoInitialize
 0x872078 CoTaskMemFree
 0x87207c CoTaskMemAlloc
gdi32.dll
 0x872084 Pie
 0x872088 SetPaletteEntries
 0x87208c SetBkMode
 0x872090 CreateCompatibleBitmap
 0x872094 GetEnhMetaFileHeader
 0x872098 RectVisible
 0x87209c AngleArc
 0x8720a0 ResizePalette
 0x8720a4 SetAbortProc
 0x8720a8 SetTextColor
 0x8720ac GetTextColor
 0x8720b0 StretchBlt
 0x8720b4 RoundRect
 0x8720b8 RestoreDC
 0x8720bc SetRectRgn
 0x8720c0 GetTextMetricsW
 0x8720c4 GetWindowOrgEx
 0x8720c8 SetPixelV
 0x8720cc CreatePalette
 0x8720d0 CreateDCW
 0x8720d4 PolyBezierTo
 0x8720d8 CreateICW
 0x8720dc GetStockObject
 0x8720e0 CreateSolidBrush
 0x8720e4 GetBkMode
 0x8720e8 Polygon
 0x8720ec MoveToEx
 0x8720f0 PlayEnhMetaFile
 0x8720f4 Ellipse
 0x8720f8 StartPage
 0x8720fc GetBitmapBits
 0x872100 StartDocW
 0x872104 GetSystemPaletteEntries
 0x872108 GetEnhMetaFileBits
 0x87210c GetEnhMetaFilePaletteEntries
 0x872110 CreatePenIndirect
 0x872114 SetMapMode
 0x872118 CreateFontIndirectW
 0x87211c PolyBezier
 0x872120 EndDoc
 0x872124 GetObjectW
 0x872128 GetCurrentObject
 0x87212c GetWinMetaFileBits
 0x872130 SetROP2
 0x872134 GetEnhMetaFileDescriptionW
 0x872138 ArcTo
 0x87213c Arc
 0x872140 SelectPalette
 0x872144 SetGraphicsMode
 0x872148 ExcludeClipRect
 0x87214c MaskBlt
 0x872150 SetWindowOrgEx
 0x872154 EndPage
 0x872158 DeleteEnhMetaFile
 0x87215c Chord
 0x872160 SetDIBits
 0x872164 GetViewportOrgEx
 0x872168 SetViewportOrgEx
 0x87216c CreateRectRgn
 0x872170 RealizePalette
 0x872174 SetDIBColorTable
 0x872178 GetDIBColorTable
 0x87217c CreateBrushIndirect
 0x872180 PatBlt
 0x872184 SetEnhMetaFileBits
 0x872188 Rectangle
 0x87218c SaveDC
 0x872190 DeleteDC
 0x872194 BitBlt
 0x872198 SetWorldTransform
 0x87219c FrameRgn
 0x8721a0 GetDeviceCaps
 0x8721a4 GetTextExtentPoint32W
 0x8721a8 GetClipBox
 0x8721ac IntersectClipRect
 0x8721b0 Polyline
 0x8721b4 CreateBitmap
 0x8721b8 CombineRgn
 0x8721bc SetWinMetaFileBits
 0x8721c0 GetStretchBltMode
 0x8721c4 CreateDIBitmap
 0x8721c8 CreateDIBSection
 0x8721cc SetStretchBltMode
 0x8721d0 GetDIBits
 0x8721d4 ExtCreateRegion
 0x8721d8 LineTo
 0x8721dc GetRgnBox
 0x8721e0 EnumFontsW
 0x8721e4 CreateHalftonePalette
 0x8721e8 SelectObject
 0x8721ec DeleteObject
 0x8721f0 ExtFloodFill
 0x8721f4 UnrealizeObject
 0x8721f8 CopyEnhMetaFileW
 0x8721fc SetBkColor
 0x872200 CreateCompatibleDC
 0x872204 GetBrushOrgEx
 0x872208 GetCurrentPositionEx
 0x87220c GetNearestPaletteIndex
 0x872210 CreateRoundRectRgn
 0x872214 GetTextExtentPointW
 0x872218 ExtTextOutW
 0x87221c SetBrushOrgEx
 0x872220 GetPixel
 0x872224 GdiFlush
 0x872228 SetPixel
 0x87222c EnumFontFamiliesExW
 0x872230 StretchDIBits
 0x872234 GetPaletteEntries

EAT(Export Address Table) Library

0x4b7ba4 TMethodImplementationIntercept
0x40fb58 __dbk_fcall_wrapper
0x70663c dbkFCallWrapperAddr


Similarity measure (PE file only) - Checking for service failure