Report - 11111111.exe

Generic Malware Malicious Library ASPack UPX PE File DllRegisterServer dll PE32 OS Processor Check
ScreenShot
Created 2024.09.27 13:49 Machine s1_win7_x6403
Filename 11111111.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
10
Behavior Score
2.2
ZERO API file : mailcious
VT API (file) 39 detected (AIDetectMalware, Malicious, score, Unsafe, Vxs3, confidence, Attribute, HighConfidence, high confidence, FlyStudio, MalwareX, Real Protect, Generic Reputation PUA, Static AI, Suspicious PE, aobu, Detected, RA@1qraug, 4AIOBO, Eldorado, Artemis, BScope, Blamon, Genetic, Dinwod, frindll, Wacapew, C9nj)
md5 d42a19b547b8a8f16738fe082c205f2b
sha256 5d6cf9032bcdff01e1e1bf2dc0c2166375fe2b33412247f1912bfe4be1e31cc6
ssdeep 24576:vBo13ShtoKd3PY3tg1fTjDt68fXGUGYAp3WT:vBo1xKdqtgtTjR6fYApmT
imphash 26b8c047d0dcd78f83a0633c138b7cfa
impfuzzy 192:UqbfNP/M0JCUIStWIbT01TYe4ycCcRcIAHhnBBC:UqNMCTkDPEuC
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 39 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x4cb6ac FreeLibrary
 0x4cb6b0 GetProcAddress
 0x4cb6b4 CloseHandle
 0x4cb6b8 FlushFileBuffers
 0x4cb6bc SetStdHandle
 0x4cb6c0 LCMapStringW
 0x4cb6c4 IsBadCodePtr
 0x4cb6c8 SetUnhandledExceptionFilter
 0x4cb6cc SetFilePointer
 0x4cb6d0 GetStringTypeW
 0x4cb6d4 GetStringTypeA
 0x4cb6d8 MultiByteToWideChar
 0x4cb6dc InterlockedIncrement
 0x4cb6e0 InterlockedDecrement
 0x4cb6e4 GetOEMCP
 0x4cb6e8 GetACP
 0x4cb6ec GetCPInfo
 0x4cb6f0 LeaveCriticalSection
 0x4cb6f4 EnterCriticalSection
 0x4cb6f8 InitializeCriticalSection
 0x4cb6fc IsBadWritePtr
 0x4cb700 VirtualAlloc
 0x4cb704 RaiseException
 0x4cb708 WriteFile
 0x4cb70c VirtualFree
 0x4cb710 HeapCreate
 0x4cb714 HeapDestroy
 0x4cb718 GetVersionExA
 0x4cb71c GetEnvironmentVariableA
 0x4cb720 GetEnvironmentStringsW
 0x4cb724 GetEnvironmentStrings
 0x4cb728 WideCharToMultiByte
 0x4cb72c IsBadReadPtr
 0x4cb730 HeapFree
 0x4cb734 HeapReAlloc
 0x4cb738 HeapAlloc
 0x4cb73c ExitProcess
 0x4cb740 GetProcessHeap
 0x4cb744 GetModuleHandleA
 0x4cb748 LoadLibraryA
 0x4cb74c FreeEnvironmentStringsW
 0x4cb750 FreeEnvironmentStringsA
 0x4cb754 GetModuleFileNameA
 0x4cb758 DeleteCriticalSection
 0x4cb75c GetStartupInfoA
 0x4cb760 LCMapStringA
 0x4cb764 GetCommandLineA
 0x4cb768 GetVersion
 0x4cb76c RtlUnwind
 0x4cb770 TerminateProcess
 0x4cb774 GetCurrentProcess
 0x4cb778 GetCurrentThreadId
 0x4cb77c TlsSetValue
 0x4cb780 TlsAlloc
 0x4cb784 TlsFree
 0x4cb788 SetLastError
 0x4cb78c TlsGetValue
 0x4cb790 GetLastError
 0x4cb794 SetHandleCount
 0x4cb798 GetStdHandle
 0x4cb79c GetFileType
 0x4cb7a0 RtlMoveMemory
user32.dll
 0x4cb7b8 MessageBoxA
 0x4cb7bc wsprintfA
KERNEL32.dll
 0x4cb180 GetProfileStringA
 0x4cb184 LeaveCriticalSection
 0x4cb188 EnterCriticalSection
 0x4cb18c ReleaseSemaphore
 0x4cb190 ResumeThread
 0x4cb194 CreateSemaphoreA
 0x4cb198 SetStdHandle
 0x4cb19c IsBadCodePtr
 0x4cb1a0 IsBadReadPtr
 0x4cb1a4 CompareStringW
 0x4cb1a8 CompareStringA
 0x4cb1ac SetUnhandledExceptionFilter
 0x4cb1b0 GetStringTypeW
 0x4cb1b4 GetStringTypeA
 0x4cb1b8 IsBadWritePtr
 0x4cb1bc VirtualAlloc
 0x4cb1c0 LCMapStringW
 0x4cb1c4 LCMapStringA
 0x4cb1c8 SetEnvironmentVariableA
 0x4cb1cc VirtualFree
 0x4cb1d0 HeapCreate
 0x4cb1d4 HeapDestroy
 0x4cb1d8 GetEnvironmentVariableA
 0x4cb1dc GetFileType
 0x4cb1e0 GetStdHandle
 0x4cb1e4 SetHandleCount
 0x4cb1e8 GetEnvironmentStringsW
 0x4cb1ec GetEnvironmentStrings
 0x4cb1f0 FreeEnvironmentStringsW
 0x4cb1f4 FreeEnvironmentStringsA
 0x4cb1f8 UnhandledExceptionFilter
 0x4cb1fc GetACP
 0x4cb200 HeapSize
 0x4cb204 TerminateProcess
 0x4cb208 GetLocalTime
 0x4cb20c GetSystemTime
 0x4cb210 GetTimeZoneInformation
 0x4cb214 RaiseException
 0x4cb218 RtlUnwind
 0x4cb21c GetStartupInfoA
 0x4cb220 GetOEMCP
 0x4cb224 GetCPInfo
 0x4cb228 GetProcessVersion
 0x4cb22c SetErrorMode
 0x4cb230 GlobalFlags
 0x4cb234 GetCurrentThread
 0x4cb238 GetFileTime
 0x4cb23c GetFileSize
 0x4cb240 TlsGetValue
 0x4cb244 LocalReAlloc
 0x4cb248 TlsSetValue
 0x4cb24c TlsFree
 0x4cb250 GlobalHandle
 0x4cb254 TlsAlloc
 0x4cb258 LocalAlloc
 0x4cb25c lstrcmpA
 0x4cb260 GetVersion
 0x4cb264 GlobalGetAtomNameA
 0x4cb268 GlobalAddAtomA
 0x4cb26c GlobalFindAtomA
 0x4cb270 GlobalDeleteAtom
 0x4cb274 lstrcmpiA
 0x4cb278 SetEndOfFile
 0x4cb27c UnlockFile
 0x4cb280 LockFile
 0x4cb284 FlushFileBuffers
 0x4cb288 SetFilePointer
 0x4cb28c GetCurrentProcess
 0x4cb290 DuplicateHandle
 0x4cb294 lstrcpynA
 0x4cb298 SetLastError
 0x4cb29c FileTimeToLocalFileTime
 0x4cb2a0 FileTimeToSystemTime
 0x4cb2a4 LocalFree
 0x4cb2a8 MultiByteToWideChar
 0x4cb2ac WideCharToMultiByte
 0x4cb2b0 InterlockedDecrement
 0x4cb2b4 InterlockedIncrement
 0x4cb2b8 CloseHandle
 0x4cb2bc WaitForSingleObject
 0x4cb2c0 GetTickCount
 0x4cb2c4 GetCommandLineA
 0x4cb2c8 MulDiv
 0x4cb2cc GetProcAddress
 0x4cb2d0 GetModuleHandleA
 0x4cb2d4 GetVolumeInformationA
 0x4cb2d8 SetCurrentDirectoryA
 0x4cb2dc CreateDirectoryA
 0x4cb2e0 InterlockedExchange
 0x4cb2e4 WriteFile
 0x4cb2e8 WaitForMultipleObjects
 0x4cb2ec CreateFileA
 0x4cb2f0 SetEvent
 0x4cb2f4 FindResourceA
 0x4cb2f8 LoadResource
 0x4cb2fc LockResource
 0x4cb300 ReadFile
 0x4cb304 GetModuleFileNameA
 0x4cb308 GetCurrentThreadId
 0x4cb30c ExitProcess
 0x4cb310 GlobalSize
 0x4cb314 GlobalFree
 0x4cb318 DeleteCriticalSection
 0x4cb31c InitializeCriticalSection
 0x4cb320 lstrcatA
 0x4cb324 lstrlenA
 0x4cb328 WinExec
 0x4cb32c lstrcpyA
 0x4cb330 FindNextFileA
 0x4cb334 GlobalReAlloc
 0x4cb338 HeapFree
 0x4cb33c HeapReAlloc
 0x4cb340 GetProcessHeap
 0x4cb344 HeapAlloc
 0x4cb348 GetFullPathNameA
 0x4cb34c FreeLibrary
 0x4cb350 LoadLibraryA
 0x4cb354 GetLastError
 0x4cb358 GetVersionExA
 0x4cb35c WritePrivateProfileStringA
 0x4cb360 GetPrivateProfileStringA
 0x4cb364 CreateThread
 0x4cb368 CreateEventA
 0x4cb36c Sleep
 0x4cb370 GlobalAlloc
 0x4cb374 GlobalLock
 0x4cb378 GlobalUnlock
 0x4cb37c FindFirstFileA
 0x4cb380 FindClose
 0x4cb384 GetFileAttributesA
USER32.dll
 0x4cb3a8 AppendMenuA
 0x4cb3ac CreatePopupMenu
 0x4cb3b0 DrawIconEx
 0x4cb3b4 CreateIconFromResource
 0x4cb3b8 CreateIconFromResourceEx
 0x4cb3bc RegisterClipboardFormatA
 0x4cb3c0 SetRectEmpty
 0x4cb3c4 DispatchMessageA
 0x4cb3c8 GetMessageA
 0x4cb3cc WindowFromPoint
 0x4cb3d0 DrawFocusRect
 0x4cb3d4 DrawEdge
 0x4cb3d8 DrawFrameControl
 0x4cb3dc TranslateMessage
 0x4cb3e0 LoadIconA
 0x4cb3e4 UnhookWindowsHookEx
 0x4cb3e8 SetPropA
 0x4cb3ec GetClassLongA
 0x4cb3f0 CallNextHookEx
 0x4cb3f4 SetWindowsHookExA
 0x4cb3f8 CreateWindowExA
 0x4cb3fc GetMenuItemID
 0x4cb400 GetMenuItemCount
 0x4cb404 RegisterClassA
 0x4cb408 GetScrollPos
 0x4cb40c AdjustWindowRectEx
 0x4cb410 MapWindowPoints
 0x4cb414 SendDlgItemMessageA
 0x4cb418 UnregisterClassA
 0x4cb41c ModifyMenuA
 0x4cb420 CreateMenu
 0x4cb424 CreateAcceleratorTableA
 0x4cb428 GetDlgCtrlID
 0x4cb42c GetSubMenu
 0x4cb430 EnableMenuItem
 0x4cb434 GetSysColorBrush
 0x4cb438 LoadStringA
 0x4cb43c GetDesktopWindow
 0x4cb440 GetClassNameA
 0x4cb444 GetMenuCheckMarkDimensions
 0x4cb448 GetMenuState
 0x4cb44c SetMenuItemBitmaps
 0x4cb450 CheckMenuItem
 0x4cb454 MoveWindow
 0x4cb458 SetWindowTextA
 0x4cb45c IsDialogMessageA
 0x4cb460 ScrollWindowEx
 0x4cb464 ClientToScreen
 0x4cb468 EnumDisplaySettingsA
 0x4cb46c LoadImageA
 0x4cb470 SystemParametersInfoA
 0x4cb474 ShowWindow
 0x4cb478 IsWindowEnabled
 0x4cb47c TranslateAcceleratorA
 0x4cb480 GetKeyState
 0x4cb484 CopyAcceleratorTableA
 0x4cb488 PostQuitMessage
 0x4cb48c IsZoomed
 0x4cb490 GetClassInfoA
 0x4cb494 DefWindowProcA
 0x4cb498 GetSystemMenu
 0x4cb49c DeleteMenu
 0x4cb4a0 GetMenu
 0x4cb4a4 SetMenu
 0x4cb4a8 PeekMessageA
 0x4cb4ac IsIconic
 0x4cb4b0 SetFocus
 0x4cb4b4 GetActiveWindow
 0x4cb4b8 GetWindow
 0x4cb4bc DestroyAcceleratorTable
 0x4cb4c0 SetWindowRgn
 0x4cb4c4 GetMessagePos
 0x4cb4c8 ScreenToClient
 0x4cb4cc ChildWindowFromPointEx
 0x4cb4d0 CopyRect
 0x4cb4d4 LoadBitmapA
 0x4cb4d8 WinHelpA
 0x4cb4dc KillTimer
 0x4cb4e0 SetTimer
 0x4cb4e4 ReleaseCapture
 0x4cb4e8 GetCapture
 0x4cb4ec SetCapture
 0x4cb4f0 GetScrollRange
 0x4cb4f4 SetScrollRange
 0x4cb4f8 SetScrollPos
 0x4cb4fc SetRect
 0x4cb500 InflateRect
 0x4cb504 IntersectRect
 0x4cb508 DestroyIcon
 0x4cb50c PtInRect
 0x4cb510 OffsetRect
 0x4cb514 IsWindowVisible
 0x4cb518 EnableWindow
 0x4cb51c RedrawWindow
 0x4cb520 GetWindowLongA
 0x4cb524 SetWindowLongA
 0x4cb528 GetSysColor
 0x4cb52c SetActiveWindow
 0x4cb530 SetCursorPos
 0x4cb534 LoadCursorA
 0x4cb538 SetCursor
 0x4cb53c GetDC
 0x4cb540 FillRect
 0x4cb544 IsRectEmpty
 0x4cb548 ReleaseDC
 0x4cb54c IsChild
 0x4cb550 TrackPopupMenu
 0x4cb554 DestroyMenu
 0x4cb558 SetForegroundWindow
 0x4cb55c GetWindowRect
 0x4cb560 EqualRect
 0x4cb564 UpdateWindow
 0x4cb568 ValidateRect
 0x4cb56c InvalidateRect
 0x4cb570 GetClientRect
 0x4cb574 GetFocus
 0x4cb578 GetParent
 0x4cb57c GetTopWindow
 0x4cb580 PostMessageA
 0x4cb584 IsWindow
 0x4cb588 SetParent
 0x4cb58c DestroyCursor
 0x4cb590 SendMessageA
 0x4cb594 SetWindowPos
 0x4cb598 MessageBoxA
 0x4cb59c GetCursorPos
 0x4cb5a0 GetSystemMetrics
 0x4cb5a4 EmptyClipboard
 0x4cb5a8 SetClipboardData
 0x4cb5ac OpenClipboard
 0x4cb5b0 GetClipboardData
 0x4cb5b4 CloseClipboard
 0x4cb5b8 wsprintfA
 0x4cb5bc GetWindowTextA
 0x4cb5c0 GetWindowTextLengthA
 0x4cb5c4 CharUpperA
 0x4cb5c8 GetWindowDC
 0x4cb5cc BeginPaint
 0x4cb5d0 EndPaint
 0x4cb5d4 TabbedTextOutA
 0x4cb5d8 DrawTextA
 0x4cb5dc GrayStringA
 0x4cb5e0 GetDlgItem
 0x4cb5e4 DestroyWindow
 0x4cb5e8 CreateDialogIndirectParamA
 0x4cb5ec EndDialog
 0x4cb5f0 GetNextDlgTabItem
 0x4cb5f4 GetWindowPlacement
 0x4cb5f8 RegisterWindowMessageA
 0x4cb5fc GetForegroundWindow
 0x4cb600 GetLastActivePopup
 0x4cb604 GetMessageTime
 0x4cb608 RemovePropA
 0x4cb60c CallWindowProcA
 0x4cb610 GetPropA
GDI32.dll
 0x4cb034 SetViewportOrgEx
 0x4cb038 SetMapMode
 0x4cb03c SetTextColor
 0x4cb040 SetROP2
 0x4cb044 Escape
 0x4cb048 ExtTextOutA
 0x4cb04c TextOutA
 0x4cb050 SetPolyFillMode
 0x4cb054 PtVisible
 0x4cb058 GetViewportExtEx
 0x4cb05c ExtSelectClipRgn
 0x4cb060 LineTo
 0x4cb064 MoveToEx
 0x4cb068 SetBkMode
 0x4cb06c RestoreDC
 0x4cb070 RectVisible
 0x4cb074 SaveDC
 0x4cb078 GetTextMetricsA
 0x4cb07c CreateRectRgn
 0x4cb080 OffsetViewportOrgEx
 0x4cb084 SetViewportExtEx
 0x4cb088 ScaleViewportExtEx
 0x4cb08c SetWindowOrgEx
 0x4cb090 SetWindowExtEx
 0x4cb094 ScaleWindowExtEx
 0x4cb098 GetClipBox
 0x4cb09c ExcludeClipRect
 0x4cb0a0 SetBkColor
 0x4cb0a4 CreateRectRgnIndirect
 0x4cb0a8 SetStretchBltMode
 0x4cb0ac GetClipRgn
 0x4cb0b0 CreatePolygonRgn
 0x4cb0b4 SelectClipRgn
 0x4cb0b8 DeleteObject
 0x4cb0bc CreateDIBitmap
 0x4cb0c0 GetSystemPaletteEntries
 0x4cb0c4 CreatePalette
 0x4cb0c8 StretchBlt
 0x4cb0cc SelectPalette
 0x4cb0d0 RealizePalette
 0x4cb0d4 GetDIBits
 0x4cb0d8 GetWindowExtEx
 0x4cb0dc GetViewportOrgEx
 0x4cb0e0 GetWindowOrgEx
 0x4cb0e4 BeginPath
 0x4cb0e8 EndPath
 0x4cb0ec PathToRegion
 0x4cb0f0 CreateEllipticRgn
 0x4cb0f4 CreateRoundRectRgn
 0x4cb0f8 GetTextColor
 0x4cb0fc GetBkMode
 0x4cb100 GetBkColor
 0x4cb104 GetROP2
 0x4cb108 GetStretchBltMode
 0x4cb10c GetPolyFillMode
 0x4cb110 CreateCompatibleBitmap
 0x4cb114 CreateDCA
 0x4cb118 CreateBitmap
 0x4cb11c SelectObject
 0x4cb120 GetObjectA
 0x4cb124 CreatePen
 0x4cb128 PatBlt
 0x4cb12c CombineRgn
 0x4cb130 FillRgn
 0x4cb134 CreateSolidBrush
 0x4cb138 GetStockObject
 0x4cb13c CreateFontIndirectA
 0x4cb140 EndPage
 0x4cb144 EndDoc
 0x4cb148 DeleteDC
 0x4cb14c StartDocA
 0x4cb150 StartPage
 0x4cb154 BitBlt
 0x4cb158 CreateCompatibleDC
 0x4cb15c Ellipse
 0x4cb160 Rectangle
 0x4cb164 LPtoDP
 0x4cb168 DPtoLP
 0x4cb16c GetCurrentObject
 0x4cb170 RoundRect
 0x4cb174 GetTextExtentPoint32A
 0x4cb178 GetDeviceCaps
WINMM.dll
 0x4cb618 waveOutUnprepareHeader
 0x4cb61c waveOutPrepareHeader
 0x4cb620 waveOutWrite
 0x4cb624 waveOutPause
 0x4cb628 waveOutReset
 0x4cb62c waveOutClose
 0x4cb630 waveOutGetNumDevs
 0x4cb634 waveOutOpen
 0x4cb638 midiOutUnprepareHeader
 0x4cb63c midiStreamOpen
 0x4cb640 midiStreamProperty
 0x4cb644 midiOutPrepareHeader
 0x4cb648 midiStreamOut
 0x4cb64c midiStreamStop
 0x4cb650 midiOutReset
 0x4cb654 midiStreamClose
 0x4cb658 midiStreamRestart
WINSPOOL.DRV
 0x4cb660 ClosePrinter
 0x4cb664 OpenPrinterA
 0x4cb668 DocumentPropertiesA
ADVAPI32.dll
 0x4cb000 RegCloseKey
 0x4cb004 RegOpenKeyExA
 0x4cb008 RegSetValueExA
 0x4cb00c RegCreateKeyExA
 0x4cb010 RegQueryValueA
SHELL32.dll
 0x4cb39c ShellExecuteA
 0x4cb3a0 Shell_NotifyIconA
ole32.dll
 0x4cb7a8 OleInitialize
 0x4cb7ac CLSIDFromString
 0x4cb7b0 OleUninitialize
OLEAUT32.dll
 0x4cb38c LoadTypeLib
 0x4cb390 RegisterTypeLib
 0x4cb394 UnRegisterTypeLib
COMCTL32.dll
 0x4cb018 None
 0x4cb01c ImageList_SetBkColor
 0x4cb020 ImageList_GetImageCount
 0x4cb024 ImageList_Duplicate
 0x4cb028 ImageList_Read
 0x4cb02c ImageList_Destroy
WS2_32.dll
 0x4cb670 WSAAsyncSelect
 0x4cb674 closesocket
 0x4cb678 WSACleanup
 0x4cb67c inet_ntoa
 0x4cb680 recvfrom
 0x4cb684 ioctlsocket
 0x4cb688 recv
 0x4cb68c getpeername
 0x4cb690 accept
comdlg32.dll
 0x4cb698 GetSaveFileNameA
 0x4cb69c GetOpenFileNameA
 0x4cb6a0 ChooseColorA
 0x4cb6a4 GetFileTitleA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure