Report - WebMailTester.exe

Generic Malware Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2024.10.16 15:42 Machine s1_win7_x6402
Filename WebMailTester.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
2.0
ZERO API file : clean
VT API (file) 2 detected (Generic@AI, RDML, nJx+mZKnaLR6jsBqppgMjg, susgen)
md5 c3509310546d5a0de9f11fefe3410a9e
sha256 aff388f01d5aa3eaa64d4c3b4e389337e45fad2cc13c1671b0e9c27bf16c195d
ssdeep 12288:uWNHRVEfTKybMJmBZWpS2FURq7gW5QNhi/CgU9oB8HBtKlmU888888888888W88c:1RRQTKwMJmTDkMW5QNg/CgBB8H3a
imphash 8aaf6d97a0c28eb2806a13680c75e06a
impfuzzy 192:oc7NSRuujDEUh99neobNe0KGK35q1XH4POQMxpF:RNej79Fm01XYPOQMxD
  Network IP location

Signature (7cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
smtp Unknown clean

Suricata ids

PE API

IAT(Import Address Table) Library

oleaut32.dll
 0x4cc804 SysFreeString
 0x4cc808 SysReAllocStringLen
 0x4cc80c SysAllocStringLen
advapi32.dll
 0x4cc814 RegQueryValueExW
 0x4cc818 RegOpenKeyExW
 0x4cc81c RegCloseKey
user32.dll
 0x4cc824 GetKeyboardType
 0x4cc828 LoadStringW
 0x4cc82c MessageBoxA
 0x4cc830 CharNextW
kernel32.dll
 0x4cc838 GetACP
 0x4cc83c Sleep
 0x4cc840 VirtualFree
 0x4cc844 VirtualAlloc
 0x4cc848 GetSystemInfo
 0x4cc84c GetTickCount
 0x4cc850 QueryPerformanceCounter
 0x4cc854 GetVersion
 0x4cc858 GetCurrentThreadId
 0x4cc85c VirtualQuery
 0x4cc860 WideCharToMultiByte
 0x4cc864 MultiByteToWideChar
 0x4cc868 lstrlenW
 0x4cc86c lstrcpynW
 0x4cc870 LoadLibraryExW
 0x4cc874 GetThreadLocale
 0x4cc878 GetStartupInfoA
 0x4cc87c GetProcAddress
 0x4cc880 GetModuleHandleW
 0x4cc884 GetModuleFileNameW
 0x4cc888 GetLocaleInfoW
 0x4cc88c GetCommandLineW
 0x4cc890 FreeLibrary
 0x4cc894 FindFirstFileW
 0x4cc898 FindClose
 0x4cc89c ExitProcess
 0x4cc8a0 ExitThread
 0x4cc8a4 CreateThread
 0x4cc8a8 CompareStringW
 0x4cc8ac WriteFile
 0x4cc8b0 UnhandledExceptionFilter
 0x4cc8b4 RtlUnwind
 0x4cc8b8 RaiseException
 0x4cc8bc GetStdHandle
 0x4cc8c0 CloseHandle
kernel32.dll
 0x4cc8c8 TlsSetValue
 0x4cc8cc TlsGetValue
 0x4cc8d0 LocalAlloc
 0x4cc8d4 GetModuleHandleW
user32.dll
 0x4cc8dc CreateWindowExW
 0x4cc8e0 WindowFromPoint
 0x4cc8e4 WaitMessage
 0x4cc8e8 UpdateWindow
 0x4cc8ec UnregisterClassW
 0x4cc8f0 UnhookWindowsHookEx
 0x4cc8f4 TranslateMessage
 0x4cc8f8 TranslateMDISysAccel
 0x4cc8fc TrackPopupMenu
 0x4cc900 SystemParametersInfoW
 0x4cc904 ShowWindow
 0x4cc908 ShowScrollBar
 0x4cc90c ShowOwnedPopups
 0x4cc910 SetWindowsHookExW
 0x4cc914 SetWindowTextW
 0x4cc918 SetWindowPos
 0x4cc91c SetWindowPlacement
 0x4cc920 SetWindowLongW
 0x4cc924 SetTimer
 0x4cc928 SetScrollRange
 0x4cc92c SetScrollPos
 0x4cc930 SetScrollInfo
 0x4cc934 SetRect
 0x4cc938 SetPropW
 0x4cc93c SetParent
 0x4cc940 SetMenuItemInfoW
 0x4cc944 SetMenu
 0x4cc948 SetForegroundWindow
 0x4cc94c SetFocus
 0x4cc950 SetCursor
 0x4cc954 SetClipboardData
 0x4cc958 SetClassLongW
 0x4cc95c SetCapture
 0x4cc960 SetActiveWindow
 0x4cc964 SendMessageA
 0x4cc968 SendMessageW
 0x4cc96c ScrollWindow
 0x4cc970 ScreenToClient
 0x4cc974 RemovePropW
 0x4cc978 RemoveMenu
 0x4cc97c ReleaseDC
 0x4cc980 ReleaseCapture
 0x4cc984 RegisterWindowMessageW
 0x4cc988 RegisterClipboardFormatW
 0x4cc98c RegisterClassW
 0x4cc990 RedrawWindow
 0x4cc994 PostQuitMessage
 0x4cc998 PostMessageW
 0x4cc99c PeekMessageA
 0x4cc9a0 PeekMessageW
 0x4cc9a4 OpenClipboard
 0x4cc9a8 OffsetRect
 0x4cc9ac MsgWaitForMultipleObjectsEx
 0x4cc9b0 MsgWaitForMultipleObjects
 0x4cc9b4 MessageBoxW
 0x4cc9b8 MessageBeep
 0x4cc9bc MapWindowPoints
 0x4cc9c0 MapVirtualKeyW
 0x4cc9c4 LoadStringW
 0x4cc9c8 LoadKeyboardLayoutW
 0x4cc9cc LoadIconW
 0x4cc9d0 LoadCursorW
 0x4cc9d4 LoadBitmapW
 0x4cc9d8 KillTimer
 0x4cc9dc IsZoomed
 0x4cc9e0 IsWindowVisible
 0x4cc9e4 IsWindowUnicode
 0x4cc9e8 IsWindowEnabled
 0x4cc9ec IsWindow
 0x4cc9f0 IsIconic
 0x4cc9f4 IsDialogMessageA
 0x4cc9f8 IsDialogMessageW
 0x4cc9fc IsChild
 0x4cca00 InvalidateRect
 0x4cca04 IntersectRect
 0x4cca08 InsertMenuItemW
 0x4cca0c InsertMenuW
 0x4cca10 InflateRect
 0x4cca14 GetWindowThreadProcessId
 0x4cca18 GetWindowTextW
 0x4cca1c GetWindowRect
 0x4cca20 GetWindowPlacement
 0x4cca24 GetWindowLongW
 0x4cca28 GetWindowDC
 0x4cca2c GetTopWindow
 0x4cca30 GetSystemMetrics
 0x4cca34 GetSystemMenu
 0x4cca38 GetSysColorBrush
 0x4cca3c GetSysColor
 0x4cca40 GetSubMenu
 0x4cca44 GetScrollRange
 0x4cca48 GetScrollPos
 0x4cca4c GetScrollInfo
 0x4cca50 GetPropW
 0x4cca54 GetParent
 0x4cca58 GetWindow
 0x4cca5c GetMessagePos
 0x4cca60 GetMenuStringW
 0x4cca64 GetMenuState
 0x4cca68 GetMenuItemInfoW
 0x4cca6c GetMenuItemID
 0x4cca70 GetMenuItemCount
 0x4cca74 GetMenu
 0x4cca78 GetLastActivePopup
 0x4cca7c GetKeyboardState
 0x4cca80 GetKeyboardLayoutNameW
 0x4cca84 GetKeyboardLayoutList
 0x4cca88 GetKeyboardLayout
 0x4cca8c GetKeyState
 0x4cca90 GetKeyNameTextW
 0x4cca94 GetIconInfo
 0x4cca98 GetForegroundWindow
 0x4cca9c GetFocus
 0x4ccaa0 GetDesktopWindow
 0x4ccaa4 GetDCEx
 0x4ccaa8 GetDC
 0x4ccaac GetCursorPos
 0x4ccab0 GetCursor
 0x4ccab4 GetClipboardData
 0x4ccab8 GetClientRect
 0x4ccabc GetClassLongW
 0x4ccac0 GetClassInfoW
 0x4ccac4 GetCapture
 0x4ccac8 GetActiveWindow
 0x4ccacc FrameRect
 0x4ccad0 FindWindowExW
 0x4ccad4 FindWindowW
 0x4ccad8 FillRect
 0x4ccadc EnumWindows
 0x4ccae0 EnumThreadWindows
 0x4ccae4 EnumChildWindows
 0x4ccae8 EndPaint
 0x4ccaec EnableWindow
 0x4ccaf0 EnableScrollBar
 0x4ccaf4 EnableMenuItem
 0x4ccaf8 EmptyClipboard
 0x4ccafc DrawTextExW
 0x4ccb00 DrawTextW
 0x4ccb04 DrawMenuBar
 0x4ccb08 DrawIconEx
 0x4ccb0c DrawIcon
 0x4ccb10 DrawFrameControl
 0x4ccb14 DrawFocusRect
 0x4ccb18 DrawEdge
 0x4ccb1c DispatchMessageA
 0x4ccb20 DispatchMessageW
 0x4ccb24 DestroyWindow
 0x4ccb28 DestroyMenu
 0x4ccb2c DestroyIcon
 0x4ccb30 DestroyCursor
 0x4ccb34 DeleteMenu
 0x4ccb38 DefWindowProcW
 0x4ccb3c DefMDIChildProcW
 0x4ccb40 DefFrameProcW
 0x4ccb44 CreatePopupMenu
 0x4ccb48 CreateMenu
 0x4ccb4c CreateIcon
 0x4ccb50 CloseClipboard
 0x4ccb54 ClientToScreen
 0x4ccb58 CheckMenuItem
 0x4ccb5c CharUpperBuffW
 0x4ccb60 CharNextW
 0x4ccb64 CharLowerBuffW
 0x4ccb68 CharLowerW
 0x4ccb6c CallWindowProcW
 0x4ccb70 CallNextHookEx
 0x4ccb74 BeginPaint
 0x4ccb78 AdjustWindowRectEx
 0x4ccb7c ActivateKeyboardLayout
msimg32.dll
 0x4ccb84 AlphaBlend
gdi32.dll
 0x4ccb8c UnrealizeObject
 0x4ccb90 StretchBlt
 0x4ccb94 SetWindowOrgEx
 0x4ccb98 SetWinMetaFileBits
 0x4ccb9c SetViewportOrgEx
 0x4ccba0 SetTextColor
 0x4ccba4 SetStretchBltMode
 0x4ccba8 SetROP2
 0x4ccbac SetPixel
 0x4ccbb0 SetEnhMetaFileBits
 0x4ccbb4 SetDIBColorTable
 0x4ccbb8 SetBrushOrgEx
 0x4ccbbc SetBkMode
 0x4ccbc0 SetBkColor
 0x4ccbc4 SelectPalette
 0x4ccbc8 SelectObject
 0x4ccbcc SaveDC
 0x4ccbd0 RestoreDC
 0x4ccbd4 Rectangle
 0x4ccbd8 RectVisible
 0x4ccbdc RealizePalette
 0x4ccbe0 PlayEnhMetaFile
 0x4ccbe4 PatBlt
 0x4ccbe8 MoveToEx
 0x4ccbec MaskBlt
 0x4ccbf0 LineTo
 0x4ccbf4 IntersectClipRect
 0x4ccbf8 GetWindowOrgEx
 0x4ccbfc GetWinMetaFileBits
 0x4ccc00 GetTextMetricsW
 0x4ccc04 GetTextExtentPointW
 0x4ccc08 GetTextExtentPoint32W
 0x4ccc0c GetSystemPaletteEntries
 0x4ccc10 GetStockObject
 0x4ccc14 GetRgnBox
 0x4ccc18 GetPixel
 0x4ccc1c GetPaletteEntries
 0x4ccc20 GetObjectW
 0x4ccc24 GetEnhMetaFilePaletteEntries
 0x4ccc28 GetEnhMetaFileHeader
 0x4ccc2c GetEnhMetaFileBits
 0x4ccc30 GetDeviceCaps
 0x4ccc34 GetDIBits
 0x4ccc38 GetDIBColorTable
 0x4ccc3c GetDCOrgEx
 0x4ccc40 GetCurrentPositionEx
 0x4ccc44 GetClipBox
 0x4ccc48 GetBrushOrgEx
 0x4ccc4c GetBitmapBits
 0x4ccc50 FrameRgn
 0x4ccc54 ExtTextOutW
 0x4ccc58 ExcludeClipRect
 0x4ccc5c DeleteObject
 0x4ccc60 DeleteEnhMetaFile
 0x4ccc64 DeleteDC
 0x4ccc68 CreateSolidBrush
 0x4ccc6c CreateRectRgn
 0x4ccc70 CreatePenIndirect
 0x4ccc74 CreatePalette
 0x4ccc78 CreateHalftonePalette
 0x4ccc7c CreateFontIndirectW
 0x4ccc80 CreateDIBitmap
 0x4ccc84 CreateDIBSection
 0x4ccc88 CreateCompatibleDC
 0x4ccc8c CreateCompatibleBitmap
 0x4ccc90 CreateBrushIndirect
 0x4ccc94 CreateBitmap
 0x4ccc98 CopyEnhMetaFileW
 0x4ccc9c BitBlt
version.dll
 0x4ccca4 VerQueryValueW
 0x4ccca8 GetFileVersionInfoSizeW
 0x4cccac GetFileVersionInfoW
kernel32.dll
 0x4cccb4 lstrcpyW
 0x4cccb8 WriteFile
 0x4cccbc WideCharToMultiByte
 0x4cccc0 WaitForSingleObject
 0x4cccc4 WaitForMultipleObjectsEx
 0x4cccc8 VirtualQueryEx
 0x4ccccc VirtualQuery
 0x4cccd0 VirtualAlloc
 0x4cccd4 SwitchToThread
 0x4cccd8 Sleep
 0x4cccdc SizeofResource
 0x4ccce0 SignalObjectAndWait
 0x4ccce4 SetThreadLocale
 0x4ccce8 SetLastError
 0x4cccec SetFilePointer
 0x4cccf0 SetEvent
 0x4cccf4 SetErrorMode
 0x4cccf8 SetEndOfFile
 0x4cccfc ResumeThread
 0x4ccd00 ResetEvent
 0x4ccd04 ReadFile
 0x4ccd08 MultiByteToWideChar
 0x4ccd0c MulDiv
 0x4ccd10 LockResource
 0x4ccd14 LoadResource
 0x4ccd18 LoadLibraryW
 0x4ccd1c LeaveCriticalSection
 0x4ccd20 InitializeCriticalSection
 0x4ccd24 GlobalUnlock
 0x4ccd28 GlobalLock
 0x4ccd2c GlobalFree
 0x4ccd30 GlobalFindAtomW
 0x4ccd34 GlobalDeleteAtom
 0x4ccd38 GlobalAlloc
 0x4ccd3c GlobalAddAtomW
 0x4ccd40 GetVersionExW
 0x4ccd44 GetVersion
 0x4ccd48 GetTimeZoneInformation
 0x4ccd4c GetTickCount
 0x4ccd50 GetThreadLocale
 0x4ccd54 GetTempPathW
 0x4ccd58 GetStdHandle
 0x4ccd5c GetProcAddress
 0x4ccd60 GetModuleHandleW
 0x4ccd64 GetModuleFileNameW
 0x4ccd68 GetLocaleInfoW
 0x4ccd6c GetLocalTime
 0x4ccd70 GetLastError
 0x4ccd74 GetFullPathNameW
 0x4ccd78 GetFileSize
 0x4ccd7c GetFileAttributesW
 0x4ccd80 GetExitCodeThread
 0x4ccd84 GetEnvironmentVariableW
 0x4ccd88 GetDiskFreeSpaceW
 0x4ccd8c GetDateFormatW
 0x4ccd90 GetCurrentThreadId
 0x4ccd94 GetCurrentThread
 0x4ccd98 GetCurrentProcessId
 0x4ccd9c GetCurrentProcess
 0x4ccda0 GetComputerNameW
 0x4ccda4 GetCPInfo
 0x4ccda8 FreeResource
 0x4ccdac InterlockedIncrement
 0x4ccdb0 InterlockedExchangeAdd
 0x4ccdb4 InterlockedExchange
 0x4ccdb8 InterlockedDecrement
 0x4ccdbc InterlockedCompareExchange
 0x4ccdc0 FreeLibrary
 0x4ccdc4 FormatMessageW
 0x4ccdc8 FindResourceW
 0x4ccdcc FindFirstFileW
 0x4ccdd0 FindClose
 0x4ccdd4 EnumCalendarInfoW
 0x4ccdd8 EnterCriticalSection
 0x4ccddc DeleteFileW
 0x4ccde0 DeleteCriticalSection
 0x4ccde4 CreateThread
 0x4ccde8 CreateFileW
 0x4ccdec CreateEventW
 0x4ccdf0 CopyFileW
 0x4ccdf4 CompareStringW
 0x4ccdf8 CloseHandle
advapi32.dll
 0x4cce00 RegQueryValueExW
 0x4cce04 RegOpenKeyExW
 0x4cce08 RegFlushKey
 0x4cce0c RegCloseKey
ole32.dll
 0x4cce14 OleUninitialize
 0x4cce18 OleInitialize
 0x4cce1c CoTaskMemFree
 0x4cce20 CoTaskMemAlloc
kernel32.dll
 0x4cce28 Sleep
oleaut32.dll
 0x4cce30 SafeArrayPtrOfIndex
 0x4cce34 SafeArrayGetUBound
 0x4cce38 SafeArrayGetLBound
 0x4cce3c SafeArrayCreate
 0x4cce40 VariantChangeType
 0x4cce44 VariantCopy
 0x4cce48 VariantClear
 0x4cce4c VariantInit
comctl32.dll
 0x4cce54 InitializeFlatSB
 0x4cce58 FlatSB_SetScrollProp
 0x4cce5c FlatSB_SetScrollPos
 0x4cce60 FlatSB_SetScrollInfo
 0x4cce64 FlatSB_GetScrollPos
 0x4cce68 FlatSB_GetScrollInfo
 0x4cce6c _TrackMouseEvent
 0x4cce70 ImageList_SetIconSize
 0x4cce74 ImageList_GetIconSize
 0x4cce78 ImageList_Write
 0x4cce7c ImageList_Read
 0x4cce80 ImageList_GetDragImage
 0x4cce84 ImageList_DragShowNolock
 0x4cce88 ImageList_DragMove
 0x4cce8c ImageList_DragLeave
 0x4cce90 ImageList_DragEnter
 0x4cce94 ImageList_EndDrag
 0x4cce98 ImageList_BeginDrag
 0x4cce9c ImageList_Remove
 0x4ccea0 ImageList_DrawEx
 0x4ccea4 ImageList_Draw
 0x4ccea8 ImageList_GetBkColor
 0x4cceac ImageList_SetBkColor
 0x4cceb0 ImageList_Add
 0x4cceb4 ImageList_SetImageCount
 0x4cceb8 ImageList_GetImageCount
 0x4ccebc ImageList_Destroy
 0x4ccec0 ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure