Report - %E8%99%9A%E6%8B%9F%E6%9C%BA%E9%9A%8F%E6%9C%BAMAC.exe

Generic Malware Malicious Library ASPack UPX PE File DllRegisterServer dll PE32 OS Processor Check
ScreenShot
Created 2024.09.30 09:53 Machine s1_win7_x6403
Filename %E8%99%9A%E6%8B%9F%E6%9C%BA%E9%9A%8F%E6%9C%BAMAC.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
11
Behavior Score
2.0
ZERO API file : mailcious
VT API (file) 47 detected (AIDetectMalware, muUy, Malicious, score, Hacktool, Flystudio, Mikey, Unsafe, Save, confidence, Attribute, HighConfidence, high confidence, FakeInstall, Real Protect, high, Static AI, Malicious PE, Detected, RA@1qraug, Wacatac, 10ODIJ9, Eldorado, GenericRXAA, Outbreak, GenAsa, 3nrLpeEQWWY, Dinwod, frindll, FlyApplication)
md5 8a060e06880e61f9eb9d2d8ef96a48f6
sha256 9fc4251fdd8639dea3335ba27063cc60904bd54fac7e1f0ba5ffca79c14cd10a
ssdeep 12288:ZZzOmPumUkotxLorXfJ6/O8I9+7uOvmpI:Zx1UkgxUrXf2/S+COvm6
imphash e1dfd53cc288da24e001618c92a60cad
impfuzzy 192:K7PJM0gCehjUqT0E4z/tsRcRcpcaKSZtQJh:4MJHTpEUSh
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 47 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x480170 SetEndOfFile
 0x480174 UnlockFile
 0x480178 LockFile
 0x48017c FlushFileBuffers
 0x480180 SetFilePointer
 0x480184 GetCurrentProcess
 0x480188 DuplicateHandle
 0x48018c lstrcpynA
 0x480190 SetLastError
 0x480194 FileTimeToLocalFileTime
 0x480198 FileTimeToSystemTime
 0x48019c LocalFree
 0x4801a0 InterlockedDecrement
 0x4801a4 CreateSemaphoreA
 0x4801a8 ResumeThread
 0x4801ac ReleaseSemaphore
 0x4801b0 EnterCriticalSection
 0x4801b4 LeaveCriticalSection
 0x4801b8 GetProfileStringA
 0x4801bc SetStdHandle
 0x4801c0 IsBadCodePtr
 0x4801c4 IsBadReadPtr
 0x4801c8 CompareStringW
 0x4801cc CompareStringA
 0x4801d0 SetUnhandledExceptionFilter
 0x4801d4 GetStringTypeW
 0x4801d8 GetStringTypeA
 0x4801dc IsBadWritePtr
 0x4801e0 VirtualAlloc
 0x4801e4 LCMapStringW
 0x4801e8 LCMapStringA
 0x4801ec SetEnvironmentVariableA
 0x4801f0 VirtualFree
 0x4801f4 HeapCreate
 0x4801f8 HeapDestroy
 0x4801fc GetEnvironmentVariableA
 0x480200 GetFileType
 0x480204 GetStdHandle
 0x480208 SetHandleCount
 0x48020c GetEnvironmentStringsW
 0x480210 GetEnvironmentStrings
 0x480214 FreeEnvironmentStringsW
 0x480218 FreeEnvironmentStringsA
 0x48021c UnhandledExceptionFilter
 0x480220 GetACP
 0x480224 HeapSize
 0x480228 TerminateProcess
 0x48022c GetLocalTime
 0x480230 GetSystemTime
 0x480234 GetTimeZoneInformation
 0x480238 WriteFile
 0x48023c WaitForMultipleObjects
 0x480240 CreateFileA
 0x480244 SetEvent
 0x480248 FindResourceA
 0x48024c LoadResource
 0x480250 LockResource
 0x480254 ReadFile
 0x480258 GetModuleFileNameA
 0x48025c WideCharToMultiByte
 0x480260 MultiByteToWideChar
 0x480264 GetCurrentThreadId
 0x480268 ExitProcess
 0x48026c GlobalSize
 0x480270 GlobalFree
 0x480274 DeleteCriticalSection
 0x480278 InitializeCriticalSection
 0x48027c lstrcatA
 0x480280 lstrlenA
 0x480284 WinExec
 0x480288 lstrcpyA
 0x48028c FindNextFileA
 0x480290 GlobalReAlloc
 0x480294 HeapFree
 0x480298 HeapReAlloc
 0x48029c GetProcessHeap
 0x4802a0 HeapAlloc
 0x4802a4 GetFullPathNameA
 0x4802a8 FreeLibrary
 0x4802ac LoadLibraryA
 0x4802b0 GetLastError
 0x4802b4 GetVersionExA
 0x4802b8 WritePrivateProfileStringA
 0x4802bc CreateThread
 0x4802c0 CreateEventA
 0x4802c4 Sleep
 0x4802c8 GlobalAlloc
 0x4802cc GlobalLock
 0x4802d0 GlobalUnlock
 0x4802d4 FindFirstFileA
 0x4802d8 FindClose
 0x4802dc GetFileAttributesA
 0x4802e0 RaiseException
 0x4802e4 RtlUnwind
 0x4802e8 GetStartupInfoA
 0x4802ec GetOEMCP
 0x4802f0 GetCPInfo
 0x4802f4 GetProcessVersion
 0x4802f8 SetErrorMode
 0x4802fc GlobalFlags
 0x480300 GetCurrentThread
 0x480304 GetFileTime
 0x480308 GetFileSize
 0x48030c TlsGetValue
 0x480310 LocalReAlloc
 0x480314 TlsSetValue
 0x480318 TlsFree
 0x48031c GlobalHandle
 0x480320 SetCurrentDirectoryA
 0x480324 GetVolumeInformationA
 0x480328 GetModuleHandleA
 0x48032c GetProcAddress
 0x480330 TlsAlloc
 0x480334 LocalAlloc
 0x480338 lstrcmpA
 0x48033c GetVersion
 0x480340 GlobalGetAtomNameA
 0x480344 GlobalAddAtomA
 0x480348 GlobalFindAtomA
 0x48034c GlobalDeleteAtom
 0x480350 lstrcmpiA
 0x480354 MulDiv
 0x480358 GetCommandLineA
 0x48035c GetTickCount
 0x480360 WaitForSingleObject
 0x480364 CloseHandle
 0x480368 InterlockedIncrement
USER32.dll
 0x48038c OpenClipboard
 0x480390 SetClipboardData
 0x480394 EmptyClipboard
 0x480398 GetSystemMetrics
 0x48039c GetCursorPos
 0x4803a0 MessageBoxA
 0x4803a4 SetWindowPos
 0x4803a8 SendMessageA
 0x4803ac DestroyCursor
 0x4803b0 SetParent
 0x4803b4 GetClipboardData
 0x4803b8 PostMessageA
 0x4803bc GetTopWindow
 0x4803c0 GetParent
 0x4803c4 CloseClipboard
 0x4803c8 wsprintfA
 0x4803cc GetFocus
 0x4803d0 GetClientRect
 0x4803d4 InvalidateRect
 0x4803d8 ValidateRect
 0x4803dc UpdateWindow
 0x4803e0 EqualRect
 0x4803e4 GetWindowRect
 0x4803e8 SetForegroundWindow
 0x4803ec IsWindow
 0x4803f0 RegisterClassA
 0x4803f4 DestroyMenu
 0x4803f8 IsChild
 0x4803fc ReleaseDC
 0x480400 IsRectEmpty
 0x480404 FillRect
 0x480408 GetDC
 0x48040c SetCursor
 0x480410 LoadCursorA
 0x480414 SetCursorPos
 0x480418 SetActiveWindow
 0x48041c GetSysColor
 0x480420 SetWindowLongA
 0x480424 GetWindowLongA
 0x480428 RedrawWindow
 0x48042c EnableWindow
 0x480430 IsWindowVisible
 0x480434 OffsetRect
 0x480438 PtInRect
 0x48043c DestroyIcon
 0x480440 IntersectRect
 0x480444 InflateRect
 0x480448 SetRect
 0x48044c SetScrollPos
 0x480450 SetScrollRange
 0x480454 GetScrollRange
 0x480458 SetCapture
 0x48045c LoadIconA
 0x480460 TranslateMessage
 0x480464 DrawFrameControl
 0x480468 DrawEdge
 0x48046c DrawFocusRect
 0x480470 WindowFromPoint
 0x480474 GetMessageA
 0x480478 DispatchMessageA
 0x48047c SetRectEmpty
 0x480480 RegisterClipboardFormatA
 0x480484 CreateIconFromResourceEx
 0x480488 CreateIconFromResource
 0x48048c DrawIconEx
 0x480490 CreatePopupMenu
 0x480494 AppendMenuA
 0x480498 ModifyMenuA
 0x48049c CreateMenu
 0x4804a0 CreateAcceleratorTableA
 0x4804a4 GetDlgCtrlID
 0x4804a8 GetSubMenu
 0x4804ac EnableMenuItem
 0x4804b0 ClientToScreen
 0x4804b4 EnumDisplaySettingsA
 0x4804b8 LoadImageA
 0x4804bc SystemParametersInfoA
 0x4804c0 ShowWindow
 0x4804c4 IsWindowEnabled
 0x4804c8 TranslateAcceleratorA
 0x4804cc GetKeyState
 0x4804d0 CopyAcceleratorTableA
 0x4804d4 PostQuitMessage
 0x4804d8 IsZoomed
 0x4804dc GetClassInfoA
 0x4804e0 DefWindowProcA
 0x4804e4 GetSystemMenu
 0x4804e8 DeleteMenu
 0x4804ec GetMenu
 0x4804f0 SetMenu
 0x4804f4 PeekMessageA
 0x4804f8 GetWindowTextA
 0x4804fc GetWindowTextLengthA
 0x480500 CharUpperA
 0x480504 GetWindowDC
 0x480508 BeginPaint
 0x48050c EndPaint
 0x480510 TabbedTextOutA
 0x480514 DrawTextA
 0x480518 GrayStringA
 0x48051c GetDlgItem
 0x480520 DestroyWindow
 0x480524 CreateDialogIndirectParamA
 0x480528 EndDialog
 0x48052c GetNextDlgTabItem
 0x480530 GetWindowPlacement
 0x480534 RegisterWindowMessageA
 0x480538 GetForegroundWindow
 0x48053c GetLastActivePopup
 0x480540 GetMessageTime
 0x480544 RemovePropA
 0x480548 CallWindowProcA
 0x48054c GetPropA
 0x480550 UnhookWindowsHookEx
 0x480554 SetPropA
 0x480558 GetClassLongA
 0x48055c CallNextHookEx
 0x480560 SetWindowsHookExA
 0x480564 CreateWindowExA
 0x480568 GetMenuItemID
 0x48056c GetMenuItemCount
 0x480570 UnregisterClassA
 0x480574 GetScrollPos
 0x480578 AdjustWindowRectEx
 0x48057c MapWindowPoints
 0x480580 SendDlgItemMessageA
 0x480584 ScrollWindowEx
 0x480588 IsDialogMessageA
 0x48058c SetWindowTextA
 0x480590 MoveWindow
 0x480594 CheckMenuItem
 0x480598 SetMenuItemBitmaps
 0x48059c GetMenuState
 0x4805a0 GetMenuCheckMarkDimensions
 0x4805a4 GetClassNameA
 0x4805a8 GetDesktopWindow
 0x4805ac LoadStringA
 0x4805b0 GetSysColorBrush
 0x4805b4 IsIconic
 0x4805b8 SetFocus
 0x4805bc GetActiveWindow
 0x4805c0 GetWindow
 0x4805c4 DestroyAcceleratorTable
 0x4805c8 SetWindowRgn
 0x4805cc GetMessagePos
 0x4805d0 ScreenToClient
 0x4805d4 ChildWindowFromPointEx
 0x4805d8 CopyRect
 0x4805dc LoadBitmapA
 0x4805e0 WinHelpA
 0x4805e4 KillTimer
 0x4805e8 SetTimer
 0x4805ec ReleaseCapture
 0x4805f0 GetCapture
GDI32.dll
 0x480024 GetClipRgn
 0x480028 CreatePolygonRgn
 0x48002c SelectClipRgn
 0x480030 DeleteObject
 0x480034 CreateDIBitmap
 0x480038 GetSystemPaletteEntries
 0x48003c CreatePalette
 0x480040 StretchBlt
 0x480044 SelectPalette
 0x480048 RealizePalette
 0x48004c GetDIBits
 0x480050 GetWindowExtEx
 0x480054 GetViewportOrgEx
 0x480058 GetWindowOrgEx
 0x48005c BeginPath
 0x480060 EndPath
 0x480064 PathToRegion
 0x480068 CreateEllipticRgn
 0x48006c CreateRoundRectRgn
 0x480070 GetTextColor
 0x480074 GetBkMode
 0x480078 GetBkColor
 0x48007c GetROP2
 0x480080 GetStretchBltMode
 0x480084 GetPolyFillMode
 0x480088 CreateCompatibleBitmap
 0x48008c CreateDCA
 0x480090 CreateBitmap
 0x480094 SelectObject
 0x480098 GetObjectA
 0x48009c CreatePen
 0x4800a0 PatBlt
 0x4800a4 SetStretchBltMode
 0x4800a8 CreateRectRgn
 0x4800ac FillRgn
 0x4800b0 CreateSolidBrush
 0x4800b4 GetStockObject
 0x4800b8 CreateFontIndirectA
 0x4800bc EndPage
 0x4800c0 EndDoc
 0x4800c4 DeleteDC
 0x4800c8 StartDocA
 0x4800cc StartPage
 0x4800d0 BitBlt
 0x4800d4 CreateCompatibleDC
 0x4800d8 Ellipse
 0x4800dc Rectangle
 0x4800e0 LPtoDP
 0x4800e4 DPtoLP
 0x4800e8 GetCurrentObject
 0x4800ec RoundRect
 0x4800f0 GetTextExtentPoint32A
 0x4800f4 GetDeviceCaps
 0x4800f8 SaveDC
 0x4800fc RestoreDC
 0x480100 SetBkMode
 0x480104 SetPolyFillMode
 0x480108 SetROP2
 0x48010c SetTextColor
 0x480110 SetMapMode
 0x480114 SetViewportOrgEx
 0x480118 OffsetViewportOrgEx
 0x48011c SetViewportExtEx
 0x480120 ScaleViewportExtEx
 0x480124 SetWindowOrgEx
 0x480128 SetWindowExtEx
 0x48012c ScaleWindowExtEx
 0x480130 GetClipBox
 0x480134 ExcludeClipRect
 0x480138 MoveToEx
 0x48013c LineTo
 0x480140 CreateRectRgnIndirect
 0x480144 SetBkColor
 0x480148 CombineRgn
 0x48014c GetTextMetricsA
 0x480150 Escape
 0x480154 ExtTextOutA
 0x480158 TextOutA
 0x48015c RectVisible
 0x480160 PtVisible
 0x480164 GetViewportExtEx
 0x480168 ExtSelectClipRgn
WINMM.dll
 0x4805f8 midiStreamRestart
 0x4805fc midiStreamClose
 0x480600 midiOutReset
 0x480604 midiStreamStop
 0x480608 midiStreamOut
 0x48060c midiOutPrepareHeader
 0x480610 midiStreamProperty
 0x480614 midiStreamOpen
 0x480618 midiOutUnprepareHeader
 0x48061c waveOutOpen
 0x480620 waveOutGetNumDevs
 0x480624 waveOutClose
 0x480628 waveOutReset
 0x48062c waveOutPause
 0x480630 waveOutWrite
 0x480634 waveOutPrepareHeader
 0x480638 waveOutUnprepareHeader
WINSPOOL.DRV
 0x480640 ClosePrinter
 0x480644 DocumentPropertiesA
 0x480648 OpenPrinterA
ADVAPI32.dll
 0x480000 RegCloseKey
 0x480004 RegOpenKeyExA
 0x480008 RegSetValueExA
 0x48000c RegQueryValueA
 0x480010 RegCreateKeyExA
SHELL32.dll
 0x480380 ShellExecuteA
 0x480384 Shell_NotifyIconA
ole32.dll
 0x48068c OleInitialize
 0x480690 OleUninitialize
 0x480694 CLSIDFromString
OLEAUT32.dll
 0x480370 UnRegisterTypeLib
 0x480374 RegisterTypeLib
 0x480378 LoadTypeLib
COMCTL32.dll
 0x480018 ImageList_Destroy
 0x48001c None
WS2_32.dll
 0x480650 ioctlsocket
 0x480654 recv
 0x480658 getpeername
 0x48065c accept
 0x480660 recvfrom
 0x480664 WSAAsyncSelect
 0x480668 closesocket
 0x48066c inet_ntoa
 0x480670 WSACleanup
comdlg32.dll
 0x480678 ChooseColorA
 0x48067c GetSaveFileNameA
 0x480680 GetOpenFileNameA
 0x480684 GetFileTitleA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure