Report - 66d48e1330a01_stealcuniq.exe

Malicious Library UPX PE File PE32 MZP Format OS Processor Check
ScreenShot
Created 2024.09.17 14:11 Machine s1_win7_x6401
Filename 66d48e1330a01_stealcuniq.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
3.2
ZERO API file : mailcious
VT API (file) 55 detected (AIDetectMalware, Stealerc, Malicious, score, Artemis, GenericKD, Unsafe, Stealc, Vium, confidence, 100%, Attribute, HighConfidence, high confidence, MalwareX, TrojanPSW, rfwal, DownLoader47, PRIVATELOADER, YXEIBZ, moderate, Detected, Injuke, AMAI, ABTrojan, CANQ, R664703, Limpopo, QBot, Gencirc, Q6vVQos8M3I, susgen, PossibleThreat, PALLASNET)
md5 4670f205038b0092911122bac4cca281
sha256 0bbc52f9f65b3e155b144c362e1164c31e88db940758ba6a752de64681915528
ssdeep 98304:7+sv/t4BT7/Z/U6NVQFamv1oOgEoYYkTOhv:7+it4x7RcsmFxv+OgEoYvTO9
imphash ec5c46b4dd8e1f4068fc688eaca680b2
impfuzzy 96:8cfpHYU3O0MJ4kXepVU8zS1i+YIbuu2DrSUvK9LVqo1GqE6nDwPOQP8N:f30qk1aIbuuSrSUvK9RqooqE6EPOQPO
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 55 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x459140 DeleteCriticalSection
 0x459144 LeaveCriticalSection
 0x459148 EnterCriticalSection
 0x45914c InitializeCriticalSection
 0x459150 VirtualFree
 0x459154 VirtualAlloc
 0x459158 LocalFree
 0x45915c LocalAlloc
 0x459160 GetVersion
 0x459164 GetCurrentThreadId
 0x459168 InterlockedDecrement
 0x45916c InterlockedIncrement
 0x459170 VirtualQuery
 0x459174 WideCharToMultiByte
 0x459178 MultiByteToWideChar
 0x45917c lstrlenA
 0x459180 lstrcpynA
 0x459184 LoadLibraryExA
 0x459188 GetThreadLocale
 0x45918c GetStartupInfoA
 0x459190 GetProcAddress
 0x459194 GetModuleHandleA
 0x459198 GetModuleFileNameA
 0x45919c GetLocaleInfoA
 0x4591a0 GetCommandLineA
 0x4591a4 FreeLibrary
 0x4591a8 FindFirstFileA
 0x4591ac FindClose
 0x4591b0 ExitProcess
 0x4591b4 WriteFile
 0x4591b8 UnhandledExceptionFilter
 0x4591bc RtlUnwind
 0x4591c0 RaiseException
 0x4591c4 GetStdHandle
user32.dll
 0x4591cc GetKeyboardType
 0x4591d0 LoadStringA
 0x4591d4 MessageBoxA
 0x4591d8 CharNextA
advapi32.dll
 0x4591e0 RegQueryValueExA
 0x4591e4 RegOpenKeyExA
 0x4591e8 RegCloseKey
oleaut32.dll
 0x4591f0 SysFreeString
 0x4591f4 SysReAllocStringLen
 0x4591f8 SysAllocStringLen
kernel32.dll
 0x459200 TlsSetValue
 0x459204 TlsGetValue
 0x459208 LocalAlloc
 0x45920c GetModuleHandleA
advapi32.dll
 0x459214 RegQueryValueExA
 0x459218 RegOpenKeyExA
 0x45921c RegCloseKey
kernel32.dll
 0x459224 lstrcpyA
 0x459228 WriteFile
 0x45922c WaitForSingleObject
 0x459230 VirtualQuery
 0x459234 VirtualAlloc
 0x459238 Sleep
 0x45923c SizeofResource
 0x459240 SetThreadLocale
 0x459244 SetFilePointer
 0x459248 SetEvent
 0x45924c SetErrorMode
 0x459250 SetEndOfFile
 0x459254 ResetEvent
 0x459258 ReadFile
 0x45925c MultiByteToWideChar
 0x459260 MulDiv
 0x459264 LockResource
 0x459268 LoadResource
 0x45926c LoadLibraryA
 0x459270 LeaveCriticalSection
 0x459274 InitializeCriticalSection
 0x459278 GlobalUnlock
 0x45927c GlobalReAlloc
 0x459280 GlobalHandle
 0x459284 GlobalLock
 0x459288 GlobalFree
 0x45928c GlobalFindAtomA
 0x459290 GlobalDeleteAtom
 0x459294 GlobalAlloc
 0x459298 GlobalAddAtomA
 0x45929c GetVersionExA
 0x4592a0 GetVersion
 0x4592a4 GetTickCount
 0x4592a8 GetThreadLocale
 0x4592ac GetTempPathA
 0x4592b0 GetSystemInfo
 0x4592b4 GetStringTypeExA
 0x4592b8 GetStdHandle
 0x4592bc GetProcAddress
 0x4592c0 GetModuleHandleA
 0x4592c4 GetModuleFileNameA
 0x4592c8 GetLocaleInfoA
 0x4592cc GetLocalTime
 0x4592d0 GetLastError
 0x4592d4 GetFullPathNameA
 0x4592d8 GetFileSize
 0x4592dc GetDiskFreeSpaceA
 0x4592e0 GetDateFormatA
 0x4592e4 GetCurrentThreadId
 0x4592e8 GetCurrentProcessId
 0x4592ec GetCPInfo
 0x4592f0 GetACP
 0x4592f4 FreeResource
 0x4592f8 InterlockedExchange
 0x4592fc FreeLibrary
 0x459300 FormatMessageA
 0x459304 FindResourceA
 0x459308 FindFirstFileA
 0x45930c FindClose
 0x459310 FileTimeToLocalFileTime
 0x459314 FileTimeToDosDateTime
 0x459318 EnumCalendarInfoA
 0x45931c EnterCriticalSection
 0x459320 DeleteCriticalSection
 0x459324 CreateThread
 0x459328 CreateFileA
 0x45932c CreateEventA
 0x459330 CompareStringA
 0x459334 CloseHandle
version.dll
 0x45933c VerQueryValueA
 0x459340 GetFileVersionInfoSizeA
 0x459344 GetFileVersionInfoA
gdi32.dll
 0x45934c UnrealizeObject
 0x459350 StrokePath
 0x459354 StretchBlt
 0x459358 SetWindowOrgEx
 0x45935c SetViewportOrgEx
 0x459360 SetTextColor
 0x459364 SetStretchBltMode
 0x459368 SetROP2
 0x45936c SetPixel
 0x459370 SetDIBColorTable
 0x459374 SetBrushOrgEx
 0x459378 SetBkMode
 0x45937c SetBkColor
 0x459380 SelectPalette
 0x459384 SelectObject
 0x459388 SaveDC
 0x45938c RestoreDC
 0x459390 RectVisible
 0x459394 RealizePalette
 0x459398 PatBlt
 0x45939c MoveToEx
 0x4593a0 MaskBlt
 0x4593a4 LineTo
 0x4593a8 IntersectClipRect
 0x4593ac GetWindowOrgEx
 0x4593b0 GetTextMetricsA
 0x4593b4 GetTextExtentPoint32A
 0x4593b8 GetTextAlign
 0x4593bc GetSystemPaletteEntries
 0x4593c0 GetStockObject
 0x4593c4 GetPixel
 0x4593c8 GetPaletteEntries
 0x4593cc GetObjectA
 0x4593d0 GetDeviceCaps
 0x4593d4 GetDIBits
 0x4593d8 GetDIBColorTable
 0x4593dc GetDCOrgEx
 0x4593e0 GetCurrentPositionEx
 0x4593e4 GetClipBox
 0x4593e8 GetBrushOrgEx
 0x4593ec GetBitmapBits
 0x4593f0 ExcludeClipRect
 0x4593f4 DeleteObject
 0x4593f8 DeleteDC
 0x4593fc CreateSolidBrush
 0x459400 CreatePenIndirect
 0x459404 CreatePalette
 0x459408 CreateHalftonePalette
 0x45940c CreateFontIndirectA
 0x459410 CreateDIBitmap
 0x459414 CreateDIBSection
 0x459418 CreateCompatibleDC
 0x45941c CreateCompatibleBitmap
 0x459420 CreateBrushIndirect
 0x459424 CreateBitmap
 0x459428 BitBlt
user32.dll
 0x459430 CreateWindowExA
 0x459434 WindowFromPoint
 0x459438 WinHelpA
 0x45943c WaitMessage
 0x459440 UpdateWindow
 0x459444 UnregisterClassA
 0x459448 UnhookWindowsHookEx
 0x45944c TranslateMessage
 0x459450 TranslateMDISysAccel
 0x459454 TrackPopupMenu
 0x459458 SystemParametersInfoA
 0x45945c ShowWindow
 0x459460 ShowScrollBar
 0x459464 ShowOwnedPopups
 0x459468 ShowCursor
 0x45946c SetWindowsHookExA
 0x459470 SetWindowPos
 0x459474 SetWindowPlacement
 0x459478 SetWindowLongA
 0x45947c SetTimer
 0x459480 SetScrollRange
 0x459484 SetScrollPos
 0x459488 SetScrollInfo
 0x45948c SetRect
 0x459490 SetPropA
 0x459494 SetParent
 0x459498 SetMenuItemInfoA
 0x45949c SetMenu
 0x4594a0 SetForegroundWindow
 0x4594a4 SetFocus
 0x4594a8 SetCursor
 0x4594ac SetClassLongA
 0x4594b0 SetCapture
 0x4594b4 SetActiveWindow
 0x4594b8 SendMessageA
 0x4594bc ScrollWindow
 0x4594c0 ScreenToClient
 0x4594c4 RemovePropA
 0x4594c8 RemoveMenu
 0x4594cc ReleaseDC
 0x4594d0 ReleaseCapture
 0x4594d4 RegisterWindowMessageA
 0x4594d8 RegisterClipboardFormatA
 0x4594dc RegisterClassA
 0x4594e0 RedrawWindow
 0x4594e4 PtInRect
 0x4594e8 PostQuitMessage
 0x4594ec PostMessageA
 0x4594f0 PeekMessageA
 0x4594f4 OffsetRect
 0x4594f8 OemToCharA
 0x4594fc MessageBoxA
 0x459500 MapWindowPoints
 0x459504 MapVirtualKeyA
 0x459508 LoadStringA
 0x45950c LoadKeyboardLayoutA
 0x459510 LoadIconA
 0x459514 LoadCursorA
 0x459518 LoadBitmapA
 0x45951c KillTimer
 0x459520 IsZoomed
 0x459524 IsWindowVisible
 0x459528 IsWindowEnabled
 0x45952c IsWindow
 0x459530 IsRectEmpty
 0x459534 IsIconic
 0x459538 IsDialogMessageA
 0x45953c IsChild
 0x459540 InvalidateRect
 0x459544 IntersectRect
 0x459548 InsertMenuItemA
 0x45954c InsertMenuA
 0x459550 InflateRect
 0x459554 GetWindowThreadProcessId
 0x459558 GetWindowTextA
 0x45955c GetWindowRect
 0x459560 GetWindowPlacement
 0x459564 GetWindowLongA
 0x459568 GetWindowDC
 0x45956c GetTopWindow
 0x459570 GetSystemMetrics
 0x459574 GetSystemMenu
 0x459578 GetSysColorBrush
 0x45957c GetSysColor
 0x459580 GetSubMenu
 0x459584 GetScrollRange
 0x459588 GetScrollPos
 0x45958c GetScrollInfo
 0x459590 GetPropA
 0x459594 GetParent
 0x459598 GetWindow
 0x45959c GetMenuStringA
 0x4595a0 GetMenuState
 0x4595a4 GetMenuItemInfoA
 0x4595a8 GetMenuItemID
 0x4595ac GetMenuItemCount
 0x4595b0 GetMenu
 0x4595b4 GetLastActivePopup
 0x4595b8 GetKeyboardState
 0x4595bc GetKeyboardLayoutList
 0x4595c0 GetKeyboardLayout
 0x4595c4 GetKeyState
 0x4595c8 GetKeyNameTextA
 0x4595cc GetIconInfo
 0x4595d0 GetForegroundWindow
 0x4595d4 GetFocus
 0x4595d8 GetDesktopWindow
 0x4595dc GetDCEx
 0x4595e0 GetDC
 0x4595e4 GetCursorPos
 0x4595e8 GetCursor
 0x4595ec GetClientRect
 0x4595f0 GetClassNameA
 0x4595f4 GetClassInfoA
 0x4595f8 GetCapture
 0x4595fc GetActiveWindow
 0x459600 FrameRect
 0x459604 FindWindowA
 0x459608 FillRect
 0x45960c EqualRect
 0x459610 EnumWindows
 0x459614 EnumThreadWindows
 0x459618 EndPaint
 0x45961c EnableWindow
 0x459620 EnableScrollBar
 0x459624 EnableMenuItem
 0x459628 DrawTextA
 0x45962c DrawMenuBar
 0x459630 DrawIconEx
 0x459634 DrawIcon
 0x459638 DrawFrameControl
 0x45963c DrawEdge
 0x459640 DispatchMessageA
 0x459644 DestroyWindow
 0x459648 DestroyMenu
 0x45964c DestroyIcon
 0x459650 DestroyCursor
 0x459654 DeleteMenu
 0x459658 DefWindowProcA
 0x45965c DefMDIChildProcA
 0x459660 DefFrameProcA
 0x459664 CreatePopupMenu
 0x459668 CreateMenu
 0x45966c CreateIcon
 0x459670 ClientToScreen
 0x459674 CheckMenuItem
 0x459678 CallWindowProcA
 0x45967c CallNextHookEx
 0x459680 BeginPaint
 0x459684 CharNextA
 0x459688 CharLowerA
 0x45968c CharToOemA
 0x459690 AdjustWindowRectEx
 0x459694 ActivateKeyboardLayout
kernel32.dll
 0x45969c Sleep
oleaut32.dll
 0x4596a4 SafeArrayPtrOfIndex
 0x4596a8 SafeArrayGetUBound
 0x4596ac SafeArrayGetLBound
 0x4596b0 SafeArrayCreate
 0x4596b4 VariantChangeType
 0x4596b8 VariantCopy
 0x4596bc VariantClear
 0x4596c0 VariantInit
ole32.dll
 0x4596c8 CLSIDFromProgID
 0x4596cc CoCreateInstance
 0x4596d0 CoUninitialize
 0x4596d4 CoInitialize
oleaut32.dll
 0x4596dc GetErrorInfo
 0x4596e0 SysFreeString
comctl32.dll
 0x4596e8 ImageList_SetIconSize
 0x4596ec ImageList_GetIconSize
 0x4596f0 ImageList_Write
 0x4596f4 ImageList_Read
 0x4596f8 ImageList_GetDragImage
 0x4596fc ImageList_DragShowNolock
 0x459700 ImageList_SetDragCursorImage
 0x459704 ImageList_DragMove
 0x459708 ImageList_DragLeave
 0x45970c ImageList_DragEnter
 0x459710 ImageList_EndDrag
 0x459714 ImageList_BeginDrag
 0x459718 ImageList_Remove
 0x45971c ImageList_DrawEx
 0x459720 ImageList_Draw
 0x459724 ImageList_GetBkColor
 0x459728 ImageList_SetBkColor
 0x45972c ImageList_ReplaceIcon
 0x459730 ImageList_Add
 0x459734 ImageList_GetImageCount
 0x459738 ImageList_Destroy
 0x45973c ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure