Report - 0703_uac_doc.exe

Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check
ScreenShot
Created 2024.09.30 11:47 Machine s1_win7_x6401
Filename 0703_uac_doc.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
1
Behavior Score
1.4
ZERO API file : mailcious
VT API (file) 50 detected (AIDetectMalware, Rozena, Malicious, score, GenericKD, Unsafe, Attribute, HighConfidence, high confidence, Agentb, kyyr, uvbww, SWRORT, YXEGIZ, Detected, Malware@#f88h7b8i3lj3, Cobaltstrike, ABTrojan, BOEA, Neshta, FileInfector, GdSda, Gencirc, susgen)
md5 18ad834f5a8779d88d5db1ee291ddb26
sha256 45b6a1a61dc109144cf44111b6733d3fa5024aa7952815ae8742ba2f81e874ea
ssdeep 24576:P80asHo2BEYHMRZheuTa7LEeSIMdvcszE7CW:EpsHo/uuTaHEeSIav3
imphash 892fb11f4f455486c700e33f63a3d442
impfuzzy 192:opKYmNx3F4FGAwpGWV95mKrfUl4e5bV9Pq:gKYmb14IRzf4VbPq
  Network IP location

Signature (2cnts)

Level Description
danger File has been identified by 50 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (7cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

COMCTL32.dll
 0x1400e80b8 ImageList_Create
 0x1400e80c0 CreateStatusWindowW
 0x1400e80c8 ImageList_ReplaceIcon
 0x1400e80d0 ImageList_GetIconSize
 0x1400e80d8 ImageList_Destroy
 0x1400e80e0 ImageList_AddMasked
PSAPI.DLL
 0x1400e80f0 GetModuleFileNameExW
 0x1400e80f8 GetProcessImageFileNameW
 0x1400e8100 GetModuleBaseNameW
KERNEL32.dll
 0x1400e8110 FindClose
 0x1400e8118 FileTimeToLocalFileTime
 0x1400e8120 SetEnvironmentVariableW
 0x1400e8128 Beep
 0x1400e8130 MoveFileW
 0x1400e8138 OutputDebugStringW
 0x1400e8140 CreateProcessW
 0x1400e8148 GetFileAttributesW
 0x1400e8150 WideCharToMultiByte
 0x1400e8158 MultiByteToWideChar
 0x1400e8160 GetExitCodeProcess
 0x1400e8168 WriteProcessMemory
 0x1400e8170 ReadProcessMemory
 0x1400e8178 GetCurrentProcessId
 0x1400e8180 OpenProcess
 0x1400e8188 TerminateProcess
 0x1400e8190 SetPriorityClass
 0x1400e8198 SetLastError
 0x1400e81a0 GetEnvironmentVariableW
 0x1400e81a8 GetLocalTime
 0x1400e81b0 GetDateFormatW
 0x1400e81b8 GetTimeFormatW
 0x1400e81c0 GetDiskFreeSpaceW
 0x1400e81c8 SetVolumeLabelW
 0x1400e81d0 CreateFileW
 0x1400e81d8 DeviceIoControl
 0x1400e81e0 GetDriveTypeW
 0x1400e81e8 GetVolumeInformationW
 0x1400e81f0 CreateDirectoryW
 0x1400e81f8 ReadFile
 0x1400e8200 WriteFile
 0x1400e8208 DeleteFileW
 0x1400e8210 SetFileAttributesW
 0x1400e8218 LocalFileTimeToFileTime
 0x1400e8220 SetFileTime
 0x1400e8228 GetFileSizeEx
 0x1400e8230 GetSystemTime
 0x1400e8238 GetSystemDefaultUILanguage
 0x1400e8240 GetComputerNameW
 0x1400e8248 GetWindowsDirectoryW
 0x1400e8250 GetTempPathW
 0x1400e8258 GetFullPathNameW
 0x1400e8260 GetShortPathNameW
 0x1400e8268 LoadLibraryW
 0x1400e8270 FreeLibrary
 0x1400e8278 EnterCriticalSection
 0x1400e8280 LeaveCriticalSection
 0x1400e8288 VirtualProtect
 0x1400e8290 FindNextFileW
 0x1400e8298 CompareStringW
 0x1400e82a0 RemoveDirectoryW
 0x1400e82a8 CopyFileW
 0x1400e82b0 GetCurrentProcess
 0x1400e82b8 FormatMessageW
 0x1400e82c0 GetPrivateProfileStringW
 0x1400e82c8 GetPrivateProfileSectionW
 0x1400e82d0 GetPrivateProfileSectionNamesW
 0x1400e82d8 WritePrivateProfileStringW
 0x1400e82e0 WritePrivateProfileSectionW
 0x1400e82e8 SetEndOfFile
 0x1400e82f0 GetACP
 0x1400e82f8 GetFileType
 0x1400e8300 GetStdHandle
 0x1400e8308 SetFilePointerEx
 0x1400e8310 SystemTimeToFileTime
 0x1400e8318 FileTimeToSystemTime
 0x1400e8320 GetFileSize
 0x1400e8328 IsWow64Process
 0x1400e8330 VirtualAllocEx
 0x1400e8338 VirtualFreeEx
 0x1400e8340 EnumResourceNamesW
 0x1400e8348 LoadLibraryExW
 0x1400e8350 GlobalSize
 0x1400e8358 TlsGetValue
 0x1400e8360 TlsAlloc
 0x1400e8368 InitializeCriticalSectionAndSpinCount
 0x1400e8370 RtlUnwindEx
 0x1400e8378 RaiseException
 0x1400e8380 EncodePointer
 0x1400e8388 RtlPcToFileHeader
 0x1400e8390 InitializeSListHead
 0x1400e8398 QueryPerformanceCounter
 0x1400e83a0 IsProcessorFeaturePresent
 0x1400e83a8 GetStartupInfoW
 0x1400e83b0 SetUnhandledExceptionFilter
 0x1400e83b8 UnhandledExceptionFilter
 0x1400e83c0 IsDebuggerPresent
 0x1400e83c8 RtlVirtualUnwind
 0x1400e83d0 RtlLookupFunctionEntry
 0x1400e83d8 RtlCaptureContext
 0x1400e83e0 CreateEventW
 0x1400e83e8 WaitForSingleObjectEx
 0x1400e83f0 ResetEvent
 0x1400e83f8 SetEvent
 0x1400e8400 GetCommandLineW
 0x1400e8408 ExitProcess
 0x1400e8410 GetModuleHandleExW
 0x1400e8418 HeapSize
 0x1400e8420 HeapReAlloc
 0x1400e8428 HeapQueryInformation
 0x1400e8430 HeapFree
 0x1400e8438 HeapAlloc
 0x1400e8440 FindFirstFileW
 0x1400e8448 LockResource
 0x1400e8450 LoadResource
 0x1400e8458 SizeofResource
 0x1400e8460 FindResourceW
 0x1400e8468 GetSystemTimeAsFileTime
 0x1400e8470 GetModuleFileNameW
 0x1400e8478 DeleteCriticalSection
 0x1400e8480 GetCPInfo
 0x1400e8488 GetVersionExW
 0x1400e8490 GetModuleHandleW
 0x1400e8498 GetProcAddress
 0x1400e84a0 GetLastError
 0x1400e84a8 CreateMutexW
 0x1400e84b0 CloseHandle
 0x1400e84b8 GetExitCodeThread
 0x1400e84c0 SetThreadPriority
 0x1400e84c8 CreateThread
 0x1400e84d0 lstrcmpiW
 0x1400e84d8 GetCurrentThreadId
 0x1400e84e0 GlobalUnlock
 0x1400e84e8 GlobalFree
 0x1400e84f0 GlobalAlloc
 0x1400e84f8 GlobalLock
 0x1400e8500 GetCurrentDirectoryW
 0x1400e8508 SetErrorMode
 0x1400e8510 InitializeCriticalSection
 0x1400e8518 SetCurrentDirectoryW
 0x1400e8520 Sleep
 0x1400e8528 GetTickCount
 0x1400e8530 MulDiv
 0x1400e8538 TlsSetValue
 0x1400e8540 TlsFree
 0x1400e8548 LCMapStringW
 0x1400e8550 GetStringTypeW
 0x1400e8558 GetConsoleCP
 0x1400e8560 GetConsoleMode
 0x1400e8568 GetProcessHeap
 0x1400e8570 FindFirstFileExW
 0x1400e8578 GetCommandLineA
 0x1400e8580 IsValidCodePage
 0x1400e8588 GetOEMCP
 0x1400e8590 GetEnvironmentStringsW
 0x1400e8598 FreeEnvironmentStringsW
 0x1400e85a0 SetStdHandle
 0x1400e85a8 FlushFileBuffers
 0x1400e85b0 WriteConsoleW
 0x1400e85b8 QueryDosDeviceW
 0x1400e85c0 ReadConsoleW
 0x1400e85c8 VirtualAlloc
 0x1400e85d0 VirtualFree
 0x1400e85d8 GetConsoleOutputCP
 0x1400e85e0 WaitForSingleObject
USER32.dll
 0x1400e85f0 SetParent
 0x1400e85f8 GetClassInfoExW
 0x1400e8600 GetAncestor
 0x1400e8608 UpdateWindow
 0x1400e8610 GetMessagePos
 0x1400e8618 GetClassLongPtrW
 0x1400e8620 DefDlgProcW
 0x1400e8628 CallWindowProcW
 0x1400e8630 CheckRadioButton
 0x1400e8638 IntersectRect
 0x1400e8640 PtInRect
 0x1400e8648 CreateDialogIndirectParamW
 0x1400e8650 GetWindowLongPtrW
 0x1400e8658 CreateAcceleratorTableW
 0x1400e8660 DestroyAcceleratorTable
 0x1400e8668 InsertMenuItemW
 0x1400e8670 SetMenuDefaultItem
 0x1400e8678 RemoveMenu
 0x1400e8680 SetMenuItemInfoW
 0x1400e8688 IsMenu
 0x1400e8690 GetMenuItemInfoW
 0x1400e8698 CreateMenu
 0x1400e86a0 CreatePopupMenu
 0x1400e86a8 SetMenuInfo
 0x1400e86b0 AppendMenuW
 0x1400e86b8 DestroyMenu
 0x1400e86c0 TrackPopupMenuEx
 0x1400e86c8 CreateIconIndirect
 0x1400e86d0 GetDesktopWindow
 0x1400e86d8 CopyImage
 0x1400e86e0 CreateIconFromResourceEx
 0x1400e86e8 EnumClipboardFormats
 0x1400e86f0 GetWindow
 0x1400e86f8 BringWindowToTop
 0x1400e8700 GetTopWindow
 0x1400e8708 SetActiveWindow
 0x1400e8710 EnumChildWindows
 0x1400e8718 MoveWindow
 0x1400e8720 GetQueueStatus
 0x1400e8728 GetWindowRect
 0x1400e8730 GetClientRect
 0x1400e8738 SystemParametersInfoW
 0x1400e8740 AdjustWindowRectEx
 0x1400e8748 DrawTextW
 0x1400e8750 SetRect
 0x1400e8758 GetIconInfo
 0x1400e8760 SetWindowLongPtrW
 0x1400e8768 IsWindowVisible
 0x1400e8770 MessageBoxW
 0x1400e8778 LoadImageW
 0x1400e8780 ChangeClipboardChain
 0x1400e8788 SetClipboardViewer
 0x1400e8790 LoadAcceleratorsW
 0x1400e8798 EnableMenuItem
 0x1400e87a0 GetMenu
 0x1400e87a8 CreateWindowExW
 0x1400e87b0 RegisterClassExW
 0x1400e87b8 LoadCursorW
 0x1400e87c0 DestroyIcon
 0x1400e87c8 DestroyWindow
 0x1400e87d0 IsCharAlphaW
 0x1400e87d8 GetCursor
 0x1400e87e0 MapVirtualKeyExW
 0x1400e87e8 VkKeyScanExW
 0x1400e87f0 GetWindowTextW
 0x1400e87f8 mouse_event
 0x1400e8800 WindowFromPoint
 0x1400e8808 GetSystemMetrics
 0x1400e8810 keybd_event
 0x1400e8818 SetKeyboardState
 0x1400e8820 GetKeyboardState
 0x1400e8828 GetCursorPos
 0x1400e8830 GetAsyncKeyState
 0x1400e8838 AttachThreadInput
 0x1400e8840 SendInput
 0x1400e8848 UnregisterHotKey
 0x1400e8850 RegisterHotKey
 0x1400e8858 PostQuitMessage
 0x1400e8860 SendMessageTimeoutW
 0x1400e8868 UnhookWindowsHookEx
 0x1400e8870 SetWindowsHookExW
 0x1400e8878 PostThreadMessageW
 0x1400e8880 IsCharUpperW
 0x1400e8888 IsCharLowerW
 0x1400e8890 IsCharAlphaNumericW
 0x1400e8898 ToUnicodeEx
 0x1400e88a0 GetKeyboardLayout
 0x1400e88a8 CallNextHookEx
 0x1400e88b0 CharLowerW
 0x1400e88b8 ReleaseDC
 0x1400e88c0 GetDC
 0x1400e88c8 OpenClipboard
 0x1400e88d0 GetClipboardData
 0x1400e88d8 GetClipboardFormatNameW
 0x1400e88e0 RedrawWindow
 0x1400e88e8 MapWindowPoints
 0x1400e88f0 RemovePropW
 0x1400e88f8 SetPropW
 0x1400e8900 GetPropW
 0x1400e8908 FlashWindow
 0x1400e8910 SetMenu
 0x1400e8918 ExitWindowsEx
 0x1400e8920 GetMenuStringW
 0x1400e8928 GetSubMenu
 0x1400e8930 GetMenuItemID
 0x1400e8938 GetMenuItemCount
 0x1400e8940 SetWindowTextW
 0x1400e8948 GetLastInputInfo
 0x1400e8950 CloseClipboard
 0x1400e8958 SetClipboardData
 0x1400e8960 EmptyClipboard
 0x1400e8968 PostMessageW
 0x1400e8970 FindWindowW
 0x1400e8978 EndDialog
 0x1400e8980 IsWindow
 0x1400e8988 DispatchMessageW
 0x1400e8990 TranslateMessage
 0x1400e8998 ShowWindow
 0x1400e89a0 ClientToScreen
 0x1400e89a8 MessageBeep
 0x1400e89b0 SetDlgItemTextW
 0x1400e89b8 GetDlgItem
 0x1400e89c0 SendDlgItemMessageW
 0x1400e89c8 DialogBoxParamW
 0x1400e89d0 SetForegroundWindow
 0x1400e89d8 DefWindowProcW
 0x1400e89e0 FillRect
 0x1400e89e8 DrawIconEx
 0x1400e89f0 GetSysColorBrush
 0x1400e89f8 GetSysColor
 0x1400e8a00 RegisterWindowMessageW
 0x1400e8a08 IsIconic
 0x1400e8a10 IsZoomed
 0x1400e8a18 EnumWindows
 0x1400e8a20 GetWindowTextLengthW
 0x1400e8a28 EnableWindow
 0x1400e8a30 InvalidateRect
 0x1400e8a38 SetLayeredWindowAttributes
 0x1400e8a40 SetWindowPos
 0x1400e8a48 CountClipboardFormats
 0x1400e8a50 SetWindowLongW
 0x1400e8a58 ScreenToClient
 0x1400e8a60 IsDialogMessageW
 0x1400e8a68 SendMessageW
 0x1400e8a70 IsWindowEnabled
 0x1400e8a78 GetWindowLongW
 0x1400e8a80 GetKeyState
 0x1400e8a88 TranslateAcceleratorW
 0x1400e8a90 KillTimer
 0x1400e8a98 PeekMessageW
 0x1400e8aa0 GetFocus
 0x1400e8aa8 GetClassNameW
 0x1400e8ab0 GetWindowThreadProcessId
 0x1400e8ab8 GetForegroundWindow
 0x1400e8ac0 GetMessageW
 0x1400e8ac8 SetTimer
 0x1400e8ad0 GetParent
 0x1400e8ad8 GetDlgCtrlID
 0x1400e8ae0 CharUpperW
 0x1400e8ae8 IsClipboardFormatAvailable
 0x1400e8af0 SetWindowRgn
 0x1400e8af8 SetFocus
 0x1400e8b00 MapVirtualKeyW
 0x1400e8b08 GetGUIThreadInfo
 0x1400e8b10 CheckMenuItem
GDI32.dll
 0x1400e8b20 GetPixel
 0x1400e8b28 GetClipRgn
 0x1400e8b30 GetCharABCWidthsW
 0x1400e8b38 SetBkMode
 0x1400e8b40 CreatePatternBrush
 0x1400e8b48 SetBrushOrgEx
 0x1400e8b50 EnumFontFamiliesExW
 0x1400e8b58 CreateDIBSection
 0x1400e8b60 GdiFlush
 0x1400e8b68 SetBkColor
 0x1400e8b70 ExcludeClipRect
 0x1400e8b78 SetTextColor
 0x1400e8b80 GetClipBox
 0x1400e8b88 BitBlt
 0x1400e8b90 CreateCompatibleBitmap
 0x1400e8b98 GetSystemPaletteEntries
 0x1400e8ba0 GetDIBits
 0x1400e8ba8 CreateCompatibleDC
 0x1400e8bb0 CreatePolygonRgn
 0x1400e8bb8 CreateRectRgn
 0x1400e8bc0 CreateRoundRectRgn
 0x1400e8bc8 CreateEllipticRgn
 0x1400e8bd0 DeleteDC
 0x1400e8bd8 GetObjectW
 0x1400e8be0 GetTextMetricsW
 0x1400e8be8 GetTextFaceW
 0x1400e8bf0 SelectObject
 0x1400e8bf8 GetStockObject
 0x1400e8c00 CreateDCW
 0x1400e8c08 CreateSolidBrush
 0x1400e8c10 CreateFontW
 0x1400e8c18 FillRgn
 0x1400e8c20 GetDeviceCaps
 0x1400e8c28 DeleteObject
COMDLG32.dll
 0x1400e8c38 CommDlgExtendedError
 0x1400e8c40 GetSaveFileNameW
 0x1400e8c48 GetOpenFileNameW
ADVAPI32.dll
 0x1400e8c58 RegDeleteKeyW
 0x1400e8c60 RegSetValueExW
 0x1400e8c68 RegCreateKeyExW
 0x1400e8c70 RegQueryValueExW
 0x1400e8c78 AdjustTokenPrivileges
 0x1400e8c80 LookupPrivilegeValueW
 0x1400e8c88 OpenProcessToken
 0x1400e8c90 CloseServiceHandle
 0x1400e8c98 UnlockServiceDatabase
 0x1400e8ca0 LockServiceDatabase
 0x1400e8ca8 OpenSCManagerW
 0x1400e8cb0 GetUserNameW
 0x1400e8cb8 RegEnumKeyExW
 0x1400e8cc0 RegEnumValueW
 0x1400e8cc8 RegQueryInfoKeyW
 0x1400e8cd0 RegOpenKeyExW
 0x1400e8cd8 RegCloseKey
 0x1400e8ce0 RegConnectRegistryW
 0x1400e8ce8 RegDeleteValueW
SHELL32.dll
 0x1400e8cf8 DragQueryPoint
 0x1400e8d00 SHEmptyRecycleBinW
 0x1400e8d08 SHFileOperationW
 0x1400e8d10 SHGetPathFromIDListW
 0x1400e8d18 SHBrowseForFolderW
 0x1400e8d20 SHGetDesktopFolder
 0x1400e8d28 SHGetMalloc
 0x1400e8d30 SHGetFolderPathW
 0x1400e8d38 ShellExecuteExW
 0x1400e8d40 Shell_NotifyIconW
 0x1400e8d48 DragFinish
 0x1400e8d50 DragQueryFileW
 0x1400e8d58 ExtractIconW
ole32.dll
 0x1400e8d68 OleInitialize
 0x1400e8d70 OleUninitialize
 0x1400e8d78 CoCreateInstance
 0x1400e8d80 CoInitialize
 0x1400e8d88 CoUninitialize
 0x1400e8d90 CLSIDFromString
 0x1400e8d98 CoGetObject
 0x1400e8da0 StringFromGUID2
 0x1400e8da8 CreateStreamOnHGlobal
OLEAUT32.dll
 0x1400e8db8 SafeArrayGetLBound
 0x1400e8dc0 GetActiveObject
 0x1400e8dc8 SysStringLen
 0x1400e8dd0 OleLoadPicture
 0x1400e8dd8 SafeArrayUnaccessData
 0x1400e8de0 SafeArrayGetElemsize
 0x1400e8de8 SafeArrayAccessData
 0x1400e8df0 SafeArrayUnlock
 0x1400e8df8 SafeArrayPtrOfIndex
 0x1400e8e00 SafeArrayLock
 0x1400e8e08 SafeArrayGetDim
 0x1400e8e10 SafeArrayDestroy
 0x1400e8e18 SafeArrayGetUBound
 0x1400e8e20 VariantCopyInd
 0x1400e8e28 SafeArrayCopy
 0x1400e8e30 SysAllocString
 0x1400e8e38 VariantChangeType
 0x1400e8e40 VariantClear
 0x1400e8e48 SafeArrayCreate
 0x1400e8e50 SysFreeString

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure