Report - bIBnZA9851zj.exe

Emotet Gen1 Generic Malware Malicious Library Malicious Packer ASPack UPX PE File DllRegisterServer dll PE32 OS Processor Check DLL
ScreenShot
Created 2024.09.17 13:51 Machine s1_win7_x6401
Filename bIBnZA9851zj.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
10
Behavior Score
3.0
ZERO API file : mailcious
VT API (file) 45 detected (AIDetectMalware, Malicious, score, Zusy, Unsafe, Save, confidence, Attribute, HighConfidence, Windows, Threat, FlyStudio, MalwareX, Trojanx, Blamon, Real Protect, Generic ML PUA, Static AI, Malicious PE, HackTool, Detected, OSCF@5rs7jr, Wacapew, 11U3QNE, Eldorado, R601455, GenericRXSH, BScope, Occamy, susgen, CoinMiner)
md5 1afd58e3f054a7792007060ed612a7a9
sha256 f0cddb254626a7ad3850d27c4e6e2e526e2959b5fc1e785de615daf2d49af7e2
ssdeep 98304:tdX+qo+or2V/wybMgK6ZjL25HinyNxskjcfh38ZEwjSUErYuMVQsoXiL2nl:nlo+or2VrogK6ZjL25HinyNxskjcfh3Z
imphash 14ac16b6ab41482a6dec812b524ddab4
impfuzzy 192:CsABKcARHNAA0Jh1iT6SxWq/T0JTYnUkj7cRcecxkE/kVE:CQAAiiTOiEj+ki/
  Network IP location

Signature (7cnts)

Level Description
danger File has been identified by 45 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Drops an executable to the user AppData folder
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (20cnts)

Level Name Description Collection
danger Win32_Trojan_Emotet_1_Zero Win32 Trojan Emotet binaries (upload)
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (download)
warning Generic_Malware_Zero Generic Malware binaries (download)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (download)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (download)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (download)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (download)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (download)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

MSVFW32.dll
 0x77b470 DrawDibDraw
AVIFIL32.dll
 0x77b024 AVIStreamGetFrame
 0x77b028 AVIStreamInfoA
iphlpapi.dll
 0x77b850 GetAdaptersInfo
WINMM.dll
 0x77b774 waveOutRestart
 0x77b778 midiStreamRestart
 0x77b77c midiStreamClose
 0x77b780 midiOutReset
 0x77b784 midiStreamStop
 0x77b788 PlaySoundA
 0x77b78c waveOutUnprepareHeader
 0x77b790 waveOutPrepareHeader
 0x77b794 waveOutWrite
 0x77b798 waveOutPause
 0x77b79c waveOutReset
 0x77b7a0 waveOutClose
 0x77b7a4 midiStreamOut
 0x77b7a8 midiOutPrepareHeader
 0x77b7ac midiStreamProperty
 0x77b7b0 midiStreamOpen
 0x77b7b4 midiOutUnprepareHeader
 0x77b7b8 waveOutOpen
 0x77b7bc waveOutGetNumDevs
WS2_32.dll
 0x77b7dc inet_addr
 0x77b7e0 inet_ntoa
 0x77b7e4 gethostbyname
 0x77b7e8 WSAStartup
 0x77b7ec WSACleanup
 0x77b7f0 select
 0x77b7f4 send
 0x77b7f8 closesocket
 0x77b7fc htons
 0x77b800 socket
 0x77b804 setsockopt
 0x77b808 recvfrom
 0x77b80c ioctlsocket
 0x77b810 WSAAsyncSelect
 0x77b814 connect
 0x77b818 recv
 0x77b81c getpeername
 0x77b820 ntohl
 0x77b824 WSAGetLastError
 0x77b828 ntohs
 0x77b82c getservbyname
 0x77b830 shutdown
 0x77b834 accept
RASAPI32.dll
 0x77b488 RasGetConnectStatusA
 0x77b48c RasHangUpA
KERNEL32.dll
 0x77b1f8 GetTimeZoneInformation
 0x77b1fc GetLocaleInfoA
 0x77b200 GetVersion
 0x77b204 TerminateThread
 0x77b208 CreateMutexA
 0x77b20c ReleaseMutex
 0x77b210 SuspendThread
 0x77b214 InterlockedIncrement
 0x77b218 InterlockedDecrement
 0x77b21c MapViewOfFile
 0x77b220 UnmapViewOfFile
 0x77b224 GetSystemInfo
 0x77b228 IsProcessorFeaturePresent
 0x77b22c lstrcmpiA
 0x77b230 SetNamedPipeHandleState
 0x77b234 WaitNamedPipeA
 0x77b238 OpenFileMappingA
 0x77b23c OpenEventA
 0x77b240 TlsAlloc
 0x77b244 TlsFree
 0x77b248 TlsSetValue
 0x77b24c TlsGetValue
 0x77b250 LocalFree
 0x77b254 FileTimeToLocalFileTime
 0x77b258 lstrcpynA
 0x77b25c DuplicateHandle
 0x77b260 FlushFileBuffers
 0x77b264 LockFile
 0x77b268 UnlockFile
 0x77b26c SetEndOfFile
 0x77b270 GlobalDeleteAtom
 0x77b274 GlobalFindAtomA
 0x77b278 GlobalAddAtomA
 0x77b27c GlobalGetAtomNameA
 0x77b280 lstrcmpA
 0x77b284 LocalAlloc
 0x77b288 GlobalHandle
 0x77b28c LocalReAlloc
 0x77b290 GetFileTime
 0x77b294 GetCurrentThread
 0x77b298 GlobalFlags
 0x77b29c SetErrorMode
 0x77b2a0 GetProcessVersion
 0x77b2a4 GetCPInfo
 0x77b2a8 GetOEMCP
 0x77b2ac GetStartupInfoA
 0x77b2b0 RtlUnwind
 0x77b2b4 GetSystemTime
 0x77b2b8 GetLocalTime
 0x77b2bc RaiseException
 0x77b2c0 HeapSize
 0x77b2c4 GetACP
 0x77b2c8 SetStdHandle
 0x77b2cc GetFileType
 0x77b2d0 UnhandledExceptionFilter
 0x77b2d4 FreeEnvironmentStringsA
 0x77b2d8 FreeEnvironmentStringsW
 0x77b2dc GetEnvironmentStrings
 0x77b2e0 GetEnvironmentStringsW
 0x77b2e4 SetHandleCount
 0x77b2e8 GetStdHandle
 0x77b2ec GetEnvironmentVariableA
 0x77b2f0 HeapDestroy
 0x77b2f4 HeapCreate
 0x77b2f8 VirtualFree
 0x77b2fc SetEnvironmentVariableW
 0x77b300 SetEnvironmentVariableA
 0x77b304 LCMapStringA
 0x77b308 LCMapStringW
 0x77b30c VirtualAlloc
 0x77b310 IsBadWritePtr
 0x77b314 SetUnhandledExceptionFilter
 0x77b318 GetStringTypeA
 0x77b31c GetStringTypeW
 0x77b320 IsValidLocale
 0x77b324 IsValidCodePage
 0x77b328 EnumSystemLocalesA
 0x77b32c CompareStringA
 0x77b330 CompareStringW
 0x77b334 IsBadReadPtr
 0x77b338 IsBadCodePtr
 0x77b33c GetLocaleInfoW
 0x77b340 SetLastError
 0x77b344 TerminateProcess
 0x77b348 GetFileSize
 0x77b34c SetFilePointer
 0x77b350 GetCurrentProcess
 0x77b354 GetWindowsDirectoryA
 0x77b358 GetSystemDirectoryA
 0x77b35c CreateSemaphoreA
 0x77b360 ResumeThread
 0x77b364 ReleaseSemaphore
 0x77b368 EnterCriticalSection
 0x77b36c LeaveCriticalSection
 0x77b370 GetProfileStringA
 0x77b374 WriteFile
 0x77b378 WaitForMultipleObjects
 0x77b37c CreateFileA
 0x77b380 SetEvent
 0x77b384 FindResourceA
 0x77b388 LoadResource
 0x77b38c LockResource
 0x77b390 ReadFile
 0x77b394 GetModuleFileNameA
 0x77b398 WideCharToMultiByte
 0x77b39c MultiByteToWideChar
 0x77b3a0 GetCurrentThreadId
 0x77b3a4 ExitProcess
 0x77b3a8 GlobalSize
 0x77b3ac GlobalFree
 0x77b3b0 DeleteCriticalSection
 0x77b3b4 InitializeCriticalSection
 0x77b3b8 lstrcatA
 0x77b3bc lstrlenA
 0x77b3c0 WinExec
 0x77b3c4 lstrcpyA
 0x77b3c8 FindNextFileA
 0x77b3cc GetDriveTypeA
 0x77b3d0 GlobalReAlloc
 0x77b3d4 HeapFree
 0x77b3d8 HeapReAlloc
 0x77b3dc GetProcessHeap
 0x77b3e0 HeapAlloc
 0x77b3e4 GetUserDefaultLCID
 0x77b3e8 GetFullPathNameA
 0x77b3ec FreeLibrary
 0x77b3f0 LoadLibraryA
 0x77b3f4 GetLastError
 0x77b3f8 GetVersionExA
 0x77b3fc WritePrivateProfileStringA
 0x77b400 GetPrivateProfileStringA
 0x77b404 CreateThread
 0x77b408 CreateEventA
 0x77b40c Sleep
 0x77b410 ExpandEnvironmentStringsA
 0x77b414 GlobalAlloc
 0x77b418 GlobalLock
 0x77b41c GlobalUnlock
 0x77b420 FindFirstFileA
 0x77b424 FindClose
 0x77b428 GetFileAttributesA
 0x77b42c DeleteFileA
 0x77b430 GetCurrentDirectoryA
 0x77b434 SetCurrentDirectoryA
 0x77b438 GetVolumeInformationA
 0x77b43c GetModuleHandleA
 0x77b440 GetProcAddress
 0x77b444 MulDiv
 0x77b448 GetCommandLineA
 0x77b44c GetTickCount
 0x77b450 CreateProcessA
 0x77b454 WaitForSingleObject
 0x77b458 CloseHandle
 0x77b45c InterlockedExchange
 0x77b460 FileTimeToSystemTime
USER32.dll
 0x77b4b0 GetSysColorBrush
 0x77b4b4 GetMenuCheckMarkDimensions
 0x77b4b8 SetMenuItemBitmaps
 0x77b4bc CheckMenuItem
 0x77b4c0 IsDialogMessageA
 0x77b4c4 ScrollWindowEx
 0x77b4c8 SendDlgItemMessageA
 0x77b4cc MapWindowPoints
 0x77b4d0 AdjustWindowRectEx
 0x77b4d4 GetScrollPos
 0x77b4d8 RegisterClassA
 0x77b4dc GetClassLongA
 0x77b4e0 RemovePropA
 0x77b4e4 GetMessageTime
 0x77b4e8 GetLastActivePopup
 0x77b4ec RegisterWindowMessageA
 0x77b4f0 GetWindowPlacement
 0x77b4f4 EndDialog
 0x77b4f8 CreateDialogIndirectParamA
 0x77b4fc DestroyWindow
 0x77b500 EndPaint
 0x77b504 BeginPaint
 0x77b508 CharUpperA
 0x77b50c GetWindowTextLengthA
 0x77b510 GetDlgItem
 0x77b514 GetClassNameA
 0x77b518 GetDesktopWindow
 0x77b51c UnregisterHotKey
 0x77b520 RegisterHotKey
 0x77b524 CreateWindowExA
 0x77b528 GetWindowTextA
 0x77b52c SetWindowTextA
 0x77b530 GetMenuItemCount
 0x77b534 GetMenuItemID
 0x77b538 GetMenuStringA
 0x77b53c GetMenuState
 0x77b540 GetTabbedTextExtentA
 0x77b544 GrayStringA
 0x77b548 TabbedTextOutA
 0x77b54c WindowFromDC
 0x77b550 EnumChildWindows
 0x77b554 GetWindowDC
 0x77b558 UnhookWindowsHookEx
 0x77b55c CallNextHookEx
 0x77b560 SetWindowsHookExA
 0x77b564 GetPropA
 0x77b568 MoveWindow
 0x77b56c CallWindowProcA
 0x77b570 SetPropA
 0x77b574 DrawTextA
 0x77b578 GetCursor
 0x77b57c DrawStateA
 0x77b580 FrameRect
 0x77b584 GetNextDlgTabItem
 0x77b588 GetForegroundWindow
 0x77b58c LoadIconA
 0x77b590 TranslateMessage
 0x77b594 DrawFrameControl
 0x77b598 DrawEdge
 0x77b59c DrawFocusRect
 0x77b5a0 WindowFromPoint
 0x77b5a4 GetMessageA
 0x77b5a8 DispatchMessageA
 0x77b5ac SetRectEmpty
 0x77b5b0 CreateIconFromResourceEx
 0x77b5b4 CreateIconFromResource
 0x77b5b8 DrawIconEx
 0x77b5bc CreatePopupMenu
 0x77b5c0 AppendMenuA
 0x77b5c4 ModifyMenuA
 0x77b5c8 CreateMenu
 0x77b5cc CreateAcceleratorTableA
 0x77b5d0 GetDlgCtrlID
 0x77b5d4 GetSubMenu
 0x77b5d8 EnableMenuItem
 0x77b5dc ClientToScreen
 0x77b5e0 EnumDisplaySettingsA
 0x77b5e4 LoadImageA
 0x77b5e8 SystemParametersInfoA
 0x77b5ec ShowWindow
 0x77b5f0 IsWindowEnabled
 0x77b5f4 TranslateAcceleratorA
 0x77b5f8 GetKeyState
 0x77b5fc CopyAcceleratorTableA
 0x77b600 PostQuitMessage
 0x77b604 IsZoomed
 0x77b608 GetClassInfoA
 0x77b60c DefWindowProcA
 0x77b610 GetSystemMenu
 0x77b614 DeleteMenu
 0x77b618 GetMenu
 0x77b61c SetMenu
 0x77b620 PeekMessageA
 0x77b624 IsIconic
 0x77b628 SetFocus
 0x77b62c GetActiveWindow
 0x77b630 GetWindow
 0x77b634 DestroyAcceleratorTable
 0x77b638 SetWindowRgn
 0x77b63c GetMessagePos
 0x77b640 ScreenToClient
 0x77b644 ChildWindowFromPointEx
 0x77b648 CopyRect
 0x77b64c LoadBitmapA
 0x77b650 WinHelpA
 0x77b654 KillTimer
 0x77b658 SetTimer
 0x77b65c ReleaseCapture
 0x77b660 GetCapture
 0x77b664 SetCapture
 0x77b668 GetScrollRange
 0x77b66c SetScrollRange
 0x77b670 SetScrollPos
 0x77b674 SetRect
 0x77b678 InflateRect
 0x77b67c IntersectRect
 0x77b680 DestroyIcon
 0x77b684 PtInRect
 0x77b688 OffsetRect
 0x77b68c EnableWindow
 0x77b690 RedrawWindow
 0x77b694 GetWindowLongA
 0x77b698 SetWindowLongA
 0x77b69c GetSysColor
 0x77b6a0 SetActiveWindow
 0x77b6a4 SetCursorPos
 0x77b6a8 LoadCursorA
 0x77b6ac SetCursor
 0x77b6b0 GetDC
 0x77b6b4 FillRect
 0x77b6b8 IsRectEmpty
 0x77b6bc ReleaseDC
 0x77b6c0 IsChild
 0x77b6c4 TrackPopupMenu
 0x77b6c8 DestroyMenu
 0x77b6cc SetForegroundWindow
 0x77b6d0 GetWindowRect
 0x77b6d4 EqualRect
 0x77b6d8 UpdateWindow
 0x77b6dc ValidateRect
 0x77b6e0 InvalidateRect
 0x77b6e4 GetClientRect
 0x77b6e8 GetFocus
 0x77b6ec GetParent
 0x77b6f0 GetTopWindow
 0x77b6f4 PostMessageA
 0x77b6f8 IsWindow
 0x77b6fc SetParent
 0x77b700 DestroyCursor
 0x77b704 SendMessageA
 0x77b708 SetWindowPos
 0x77b70c MessageBoxA
 0x77b710 GetCursorPos
 0x77b714 GetSystemMetrics
 0x77b718 EmptyClipboard
 0x77b71c SetClipboardData
 0x77b720 OpenClipboard
 0x77b724 GetClipboardData
 0x77b728 CloseClipboard
 0x77b72c wsprintfA
 0x77b730 WaitForInputIdle
 0x77b734 LoadStringA
 0x77b738 RegisterClipboardFormatA
 0x77b73c IsWindowVisible
 0x77b740 UnregisterClassA
GDI32.dll
 0x77b084 FillRgn
 0x77b088 CreateRectRgn
 0x77b08c CombineRgn
 0x77b090 PatBlt
 0x77b094 CreatePen
 0x77b098 SelectObject
 0x77b09c CreatePatternBrush
 0x77b0a0 CreateBitmap
 0x77b0a4 CreateBrushIndirect
 0x77b0a8 CreateDCA
 0x77b0ac CreateCompatibleBitmap
 0x77b0b0 GetPolyFillMode
 0x77b0b4 GetStretchBltMode
 0x77b0b8 GetROP2
 0x77b0bc GetBkColor
 0x77b0c0 GetBkMode
 0x77b0c4 GetTextColor
 0x77b0c8 CreateRoundRectRgn
 0x77b0cc CreateEllipticRgn
 0x77b0d0 PathToRegion
 0x77b0d4 EndPath
 0x77b0d8 BeginPath
 0x77b0dc GetWindowOrgEx
 0x77b0e0 GetViewportOrgEx
 0x77b0e4 GetWindowExtEx
 0x77b0e8 ExtTextOutA
 0x77b0ec Escape
 0x77b0f0 TranslateCharsetInfo
 0x77b0f4 CreateSolidBrush
 0x77b0f8 SetPolyFillMode
 0x77b0fc SetROP2
 0x77b100 SetMapMode
 0x77b104 SetViewportOrgEx
 0x77b108 OffsetViewportOrgEx
 0x77b10c SetViewportExtEx
 0x77b110 ScaleViewportExtEx
 0x77b114 SetWindowExtEx
 0x77b118 ScaleWindowExtEx
 0x77b11c GetClipBox
 0x77b120 ExcludeClipRect
 0x77b124 CreateFontIndirectA
 0x77b128 MoveToEx
 0x77b12c LineTo
 0x77b130 ExtSelectClipRgn
 0x77b134 GetViewportExtEx
 0x77b138 GetTextMetricsA
 0x77b13c CreateFontA
 0x77b140 SetDIBitsToDevice
 0x77b144 SetTextColor
 0x77b148 SetBkMode
 0x77b14c TextOutA
 0x77b150 SetBkColor
 0x77b154 CreateRectRgnIndirect
 0x77b158 CreateDIBSection
 0x77b15c SetPixel
 0x77b160 SetStretchBltMode
 0x77b164 GetClipRgn
 0x77b168 CreatePolygonRgn
 0x77b16c SelectClipRgn
 0x77b170 DeleteObject
 0x77b174 CreateDIBitmap
 0x77b178 GetSystemPaletteEntries
 0x77b17c CreatePalette
 0x77b180 StretchBlt
 0x77b184 SelectPalette
 0x77b188 RealizePalette
 0x77b18c GetDIBits
 0x77b190 RectVisible
 0x77b194 PtVisible
 0x77b198 CreatePenIndirect
 0x77b19c RestoreDC
 0x77b1a0 Ellipse
 0x77b1a4 Rectangle
 0x77b1a8 LPtoDP
 0x77b1ac DPtoLP
 0x77b1b0 GetCurrentObject
 0x77b1b4 RoundRect
 0x77b1b8 SaveDC
 0x77b1bc SetWindowOrgEx
 0x77b1c0 GetStockObject
 0x77b1c4 GetObjectA
 0x77b1c8 EndPage
 0x77b1cc EndDoc
 0x77b1d0 DeleteDC
 0x77b1d4 StartDocA
 0x77b1d8 StartPage
 0x77b1dc BitBlt
 0x77b1e0 GetPixel
 0x77b1e4 CreateCompatibleDC
 0x77b1e8 GetTextExtentPoint32A
 0x77b1ec SetPixelV
 0x77b1f0 GetDeviceCaps
MSIMG32.dll
 0x77b468 GradientFill
WINSPOOL.DRV
 0x77b7c4 OpenPrinterA
 0x77b7c8 DocumentPropertiesA
 0x77b7cc ClosePrinter
comdlg32.dll
 0x77b83c ChooseColorA
 0x77b840 GetOpenFileNameA
 0x77b844 GetSaveFileNameA
 0x77b848 GetFileTitleA
ADVAPI32.dll
 0x77b000 RegCreateKeyExA
 0x77b004 RegOpenKeyA
 0x77b008 RegQueryValueA
 0x77b00c RegSetValueExA
 0x77b010 RegOpenKeyExA
 0x77b014 RegQueryValueExA
 0x77b018 RegCloseKey
 0x77b01c RegEnumValueA
SHELL32.dll
 0x77b494 SHGetFileInfoA
 0x77b498 DragAcceptFiles
 0x77b49c DragFinish
 0x77b4a0 ShellExecuteA
 0x77b4a4 Shell_NotifyIconA
 0x77b4a8 DragQueryFileA
ole32.dll
 0x77b858 ReleaseStgMedium
 0x77b85c RevokeDragDrop
 0x77b860 RegisterDragDrop
 0x77b864 OleUninitialize
 0x77b868 CLSIDFromString
 0x77b86c CoCreateInstance
 0x77b870 OleInitialize
OLEAUT32.dll
 0x77b478 RegisterTypeLib
 0x77b47c LoadTypeLib
 0x77b480 UnRegisterTypeLib
COMCTL32.dll
 0x77b030 ImageList_DragLeave
 0x77b034 ImageList_DragEnter
 0x77b038 ImageList_Destroy
 0x77b03c ImageList_Create
 0x77b040 ImageList_BeginDrag
 0x77b044 ImageList_Add
 0x77b048 ImageList_DragMove
 0x77b04c ImageList_Draw
 0x77b050 _TrackMouseEvent
 0x77b054 ImageList_SetBkColor
 0x77b058 ImageList_GetImageCount
 0x77b05c ImageList_GetImageInfo
 0x77b060 ImageList_GetIcon
 0x77b064 ImageList_DragShowNolock
 0x77b068 ImageList_EndDrag
 0x77b06c None
 0x77b070 ImageList_Read
 0x77b074 ImageList_DrawIndirect
 0x77b078 ImageList_AddMasked
 0x77b07c ImageList_Duplicate
WLDAP32.dll
 0x77b7d4 None
WININET.dll
 0x77b748 InternetSetOptionA
 0x77b74c InternetCrackUrlA
 0x77b750 HttpOpenRequestA
 0x77b754 HttpSendRequestA
 0x77b758 HttpQueryInfoA
 0x77b75c InternetReadFile
 0x77b760 InternetOpenA
 0x77b764 InternetCloseHandle
 0x77b768 InternetConnectA
 0x77b76c InternetCanonicalizeUrlA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure