Report - 16.exe

Generic Malware Malicious Library Malicious Packer ASPack UPX PE File DllRegisterServer dll PE32 OS Processor Check
ScreenShot
Created 2024.10.20 09:52 Machine s1_win7_x6401
Filename 16.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
10
Behavior Score
2.6
ZERO API file : mailcious
VT API (file) 40 detected (AIDetectMalware, lwTm, Malicious, score, Unsafe, Save, confidence, high confidence, FlyStudio, TrojanX, Kryptik@AI, RDML, paE169QP9RSGxlQymbZfug, Real Protect, moderate, Static AI, Malicious PE, aobu, Detected, GrayWare, Wacapew, RA@1qraug, Sabsik, 1MVF8WB, Eldorado, GenericRXAA, Outbreak, Dinwod, frindll, FlyApplication, C9nj)
md5 9a8d140364c483b41609196ab3cc4552
sha256 bf8569659bf69ae79d9c713f601e2d8ad78fc4d694878b88f75b2ce74825502d
ssdeep 24576:9NZtBw1mjaHHhhQIeQmyJV/IzJvAhs3mYmzzzcqczcJJYY83INAm3P7hw7zc3II3:9RaJeQR/IFvA23mYmzzzcqczcJJYY83I
imphash b6afb509ec2bd1036f91eb94d862a170
impfuzzy 192:RJQwq09UqT0myT54zStsgYcpcncAAHhPb1AFNPQt1:JqAT+IIa8by7PQt1
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 40 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (9cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x4b4180 GetLocalTime
 0x4b4184 GetSystemTime
 0x4b4188 GetTimeZoneInformation
 0x4b418c RtlUnwind
 0x4b4190 GetStartupInfoA
 0x4b4194 GetOEMCP
 0x4b4198 GetCPInfo
 0x4b419c GetProcessVersion
 0x4b41a0 SetErrorMode
 0x4b41a4 GlobalFlags
 0x4b41a8 GetCurrentThread
 0x4b41ac GetFileTime
 0x4b41b0 RaiseException
 0x4b41b4 TlsGetValue
 0x4b41b8 LocalReAlloc
 0x4b41bc TlsSetValue
 0x4b41c0 TlsFree
 0x4b41c4 GlobalHandle
 0x4b41c8 TlsAlloc
 0x4b41cc LocalAlloc
 0x4b41d0 lstrcmpA
 0x4b41d4 GetVersion
 0x4b41d8 GlobalGetAtomNameA
 0x4b41dc GlobalAddAtomA
 0x4b41e0 GlobalFindAtomA
 0x4b41e4 GlobalDeleteAtom
 0x4b41e8 lstrcmpiA
 0x4b41ec SetEndOfFile
 0x4b41f0 UnlockFile
 0x4b41f4 LockFile
 0x4b41f8 FlushFileBuffers
 0x4b41fc SetFilePointer
 0x4b4200 GetCurrentProcess
 0x4b4204 DuplicateHandle
 0x4b4208 lstrcpynA
 0x4b420c SetLastError
 0x4b4210 FileTimeToLocalFileTime
 0x4b4214 FileTimeToSystemTime
 0x4b4218 LocalFree
 0x4b421c InterlockedDecrement
 0x4b4220 InterlockedIncrement
 0x4b4224 TerminateProcess
 0x4b4228 HeapSize
 0x4b422c GetACP
 0x4b4230 UnhandledExceptionFilter
 0x4b4234 FreeEnvironmentStringsA
 0x4b4238 FreeEnvironmentStringsW
 0x4b423c GetEnvironmentStrings
 0x4b4240 GetEnvironmentStringsW
 0x4b4244 SetHandleCount
 0x4b4248 GetStdHandle
 0x4b424c GetFileType
 0x4b4250 GetEnvironmentVariableA
 0x4b4254 HeapDestroy
 0x4b4258 HeapCreate
 0x4b425c VirtualFree
 0x4b4260 SetEnvironmentVariableA
 0x4b4264 LCMapStringA
 0x4b4268 LCMapStringW
 0x4b426c VirtualAlloc
 0x4b4270 IsBadWritePtr
 0x4b4274 GetStringTypeA
 0x4b4278 GetStringTypeW
 0x4b427c SetUnhandledExceptionFilter
 0x4b4280 CompareStringA
 0x4b4284 CompareStringW
 0x4b4288 IsBadReadPtr
 0x4b428c IsBadCodePtr
 0x4b4290 SetStdHandle
 0x4b4294 SuspendThread
 0x4b4298 ReleaseMutex
 0x4b429c CreateMutexA
 0x4b42a0 TerminateThread
 0x4b42a4 CreateSemaphoreA
 0x4b42a8 ResumeThread
 0x4b42ac ReleaseSemaphore
 0x4b42b0 EnterCriticalSection
 0x4b42b4 LeaveCriticalSection
 0x4b42b8 GetProfileStringA
 0x4b42bc WriteFile
 0x4b42c0 WaitForMultipleObjects
 0x4b42c4 CreateFileA
 0x4b42c8 SetEvent
 0x4b42cc FindResourceA
 0x4b42d0 LoadResource
 0x4b42d4 LockResource
 0x4b42d8 ReadFile
 0x4b42dc lstrlenW
 0x4b42e0 GetModuleFileNameA
 0x4b42e4 WideCharToMultiByte
 0x4b42e8 MultiByteToWideChar
 0x4b42ec GetCurrentThreadId
 0x4b42f0 ExitProcess
 0x4b42f4 GlobalSize
 0x4b42f8 GlobalFree
 0x4b42fc DeleteCriticalSection
 0x4b4300 InitializeCriticalSection
 0x4b4304 lstrcatA
 0x4b4308 lstrlenA
 0x4b430c CloseHandle
 0x4b4310 WinExec
 0x4b4314 lstrcpyA
 0x4b4318 FindNextFileA
 0x4b431c GlobalReAlloc
 0x4b4320 HeapFree
 0x4b4324 HeapReAlloc
 0x4b4328 GetProcessHeap
 0x4b432c HeapAlloc
 0x4b4330 GetUserDefaultLCID
 0x4b4334 GetFullPathNameA
 0x4b4338 FreeLibrary
 0x4b433c LoadLibraryA
 0x4b4340 GetLastError
 0x4b4344 GetVersionExA
 0x4b4348 WritePrivateProfileStringA
 0x4b434c CreateThread
 0x4b4350 CreateEventA
 0x4b4354 Sleep
 0x4b4358 GlobalAlloc
 0x4b435c GlobalLock
 0x4b4360 GlobalUnlock
 0x4b4364 FindFirstFileA
 0x4b4368 FindClose
 0x4b436c GetFileAttributesA
 0x4b4370 SetCurrentDirectoryA
 0x4b4374 GetVolumeInformationA
 0x4b4378 GetModuleHandleA
 0x4b437c GetProcAddress
 0x4b4380 MulDiv
 0x4b4384 GetCommandLineA
 0x4b4388 GetTickCount
 0x4b438c WaitForSingleObject
 0x4b4390 GetFileSize
USER32.dll
 0x4b43f4 LoadIconA
 0x4b43f8 TranslateMessage
 0x4b43fc DrawFrameControl
 0x4b4400 DrawEdge
 0x4b4404 DrawFocusRect
 0x4b4408 WindowFromPoint
 0x4b440c GetMessageA
 0x4b4410 DispatchMessageA
 0x4b4414 SetRectEmpty
 0x4b4418 RegisterClipboardFormatA
 0x4b441c CreateIconFromResourceEx
 0x4b4420 CreateIconFromResource
 0x4b4424 DrawIconEx
 0x4b4428 CreatePopupMenu
 0x4b442c AppendMenuA
 0x4b4430 ModifyMenuA
 0x4b4434 CreateMenu
 0x4b4438 CreateAcceleratorTableA
 0x4b443c GetDlgCtrlID
 0x4b4440 GetSubMenu
 0x4b4444 EnableMenuItem
 0x4b4448 ClientToScreen
 0x4b444c EnumDisplaySettingsA
 0x4b4450 LoadImageA
 0x4b4454 SystemParametersInfoA
 0x4b4458 ShowWindow
 0x4b445c IsWindowEnabled
 0x4b4460 TranslateAcceleratorA
 0x4b4464 GetKeyState
 0x4b4468 CopyAcceleratorTableA
 0x4b446c PostQuitMessage
 0x4b4470 IsZoomed
 0x4b4474 GetClassInfoA
 0x4b4478 DefWindowProcA
 0x4b447c GetSystemMenu
 0x4b4480 DeleteMenu
 0x4b4484 GetMenu
 0x4b4488 SetMenu
 0x4b448c PeekMessageA
 0x4b4490 IsIconic
 0x4b4494 SetFocus
 0x4b4498 GetActiveWindow
 0x4b449c GetWindow
 0x4b44a0 DestroyAcceleratorTable
 0x4b44a4 SetWindowRgn
 0x4b44a8 GetMessagePos
 0x4b44ac ScreenToClient
 0x4b44b0 ChildWindowFromPointEx
 0x4b44b4 CopyRect
 0x4b44b8 LoadBitmapA
 0x4b44bc WinHelpA
 0x4b44c0 KillTimer
 0x4b44c4 SetTimer
 0x4b44c8 ReleaseCapture
 0x4b44cc GetCapture
 0x4b44d0 SetCapture
 0x4b44d4 GetScrollRange
 0x4b44d8 SetScrollRange
 0x4b44dc SetScrollPos
 0x4b44e0 SetRect
 0x4b44e4 InflateRect
 0x4b44e8 IntersectRect
 0x4b44ec DestroyIcon
 0x4b44f0 PtInRect
 0x4b44f4 OffsetRect
 0x4b44f8 IsWindowVisible
 0x4b44fc EnableWindow
 0x4b4500 UnregisterClassA
 0x4b4504 GetWindowLongA
 0x4b4508 SetWindowLongA
 0x4b450c GetSysColor
 0x4b4510 SetActiveWindow
 0x4b4514 SetCursorPos
 0x4b4518 LoadCursorA
 0x4b451c SetCursor
 0x4b4520 GetDC
 0x4b4524 FillRect
 0x4b4528 IsRectEmpty
 0x4b452c ReleaseDC
 0x4b4530 IsChild
 0x4b4534 DestroyMenu
 0x4b4538 SetForegroundWindow
 0x4b453c GetWindowRect
 0x4b4540 EqualRect
 0x4b4544 UpdateWindow
 0x4b4548 ValidateRect
 0x4b454c InvalidateRect
 0x4b4550 GetClientRect
 0x4b4554 GetFocus
 0x4b4558 GetParent
 0x4b455c GetTopWindow
 0x4b4560 PostMessageA
 0x4b4564 IsWindow
 0x4b4568 SetParent
 0x4b456c DestroyCursor
 0x4b4570 SendMessageA
 0x4b4574 SetWindowPos
 0x4b4578 GetWindowTextA
 0x4b457c GetWindowTextLengthA
 0x4b4580 CharUpperA
 0x4b4584 GetWindowDC
 0x4b4588 BeginPaint
 0x4b458c EndPaint
 0x4b4590 TabbedTextOutA
 0x4b4594 DrawTextA
 0x4b4598 GrayStringA
 0x4b459c GetDlgItem
 0x4b45a0 DestroyWindow
 0x4b45a4 CreateDialogIndirectParamA
 0x4b45a8 EndDialog
 0x4b45ac GetNextDlgTabItem
 0x4b45b0 GetWindowPlacement
 0x4b45b4 RegisterWindowMessageA
 0x4b45b8 GetForegroundWindow
 0x4b45bc GetLastActivePopup
 0x4b45c0 GetMessageTime
 0x4b45c4 RemovePropA
 0x4b45c8 CallWindowProcA
 0x4b45cc GetPropA
 0x4b45d0 UnhookWindowsHookEx
 0x4b45d4 SetPropA
 0x4b45d8 GetClassLongA
 0x4b45dc CallNextHookEx
 0x4b45e0 SetWindowsHookExA
 0x4b45e4 CreateWindowExA
 0x4b45e8 GetMenuItemID
 0x4b45ec GetMenuItemCount
 0x4b45f0 RegisterClassA
 0x4b45f4 GetScrollPos
 0x4b45f8 AdjustWindowRectEx
 0x4b45fc MapWindowPoints
 0x4b4600 SendDlgItemMessageA
 0x4b4604 ScrollWindowEx
 0x4b4608 IsDialogMessageA
 0x4b460c SetWindowTextA
 0x4b4610 MoveWindow
 0x4b4614 CheckMenuItem
 0x4b4618 SetMenuItemBitmaps
 0x4b461c GetMenuState
 0x4b4620 GetMenuCheckMarkDimensions
 0x4b4624 GetClassNameA
 0x4b4628 GetDesktopWindow
 0x4b462c LoadStringA
 0x4b4630 GetSysColorBrush
 0x4b4634 MessageBoxA
 0x4b4638 GetCursorPos
 0x4b463c GetSystemMetrics
 0x4b4640 EmptyClipboard
 0x4b4644 SetClipboardData
 0x4b4648 OpenClipboard
 0x4b464c GetClipboardData
 0x4b4650 CloseClipboard
 0x4b4654 wsprintfA
 0x4b4658 RedrawWindow
GDI32.dll
 0x4b4034 GetTextMetricsA
 0x4b4038 ExtTextOutA
 0x4b403c TextOutA
 0x4b4040 RectVisible
 0x4b4044 PtVisible
 0x4b4048 GetViewportExtEx
 0x4b404c Escape
 0x4b4050 ExtSelectClipRgn
 0x4b4054 SetBkColor
 0x4b4058 CreateRectRgnIndirect
 0x4b405c SetStretchBltMode
 0x4b4060 GetClipRgn
 0x4b4064 CreatePolygonRgn
 0x4b4068 SelectClipRgn
 0x4b406c DeleteObject
 0x4b4070 CreateDIBitmap
 0x4b4074 GetSystemPaletteEntries
 0x4b4078 CreatePalette
 0x4b407c StretchBlt
 0x4b4080 SelectPalette
 0x4b4084 RealizePalette
 0x4b4088 GetDIBits
 0x4b408c GetWindowExtEx
 0x4b4090 GetViewportOrgEx
 0x4b4094 GetWindowOrgEx
 0x4b4098 BeginPath
 0x4b409c EndPath
 0x4b40a0 PathToRegion
 0x4b40a4 CreateEllipticRgn
 0x4b40a8 CreateRoundRectRgn
 0x4b40ac GetTextColor
 0x4b40b0 GetBkMode
 0x4b40b4 GetBkColor
 0x4b40b8 GetROP2
 0x4b40bc GetStretchBltMode
 0x4b40c0 GetPolyFillMode
 0x4b40c4 CreateCompatibleBitmap
 0x4b40c8 CreateDCA
 0x4b40cc CreateBitmap
 0x4b40d0 SelectObject
 0x4b40d4 CreatePen
 0x4b40d8 PatBlt
 0x4b40dc ScaleViewportExtEx
 0x4b40e0 SetViewportExtEx
 0x4b40e4 OffsetViewportOrgEx
 0x4b40e8 SetViewportOrgEx
 0x4b40ec SetMapMode
 0x4b40f0 SetTextColor
 0x4b40f4 SetROP2
 0x4b40f8 SetPolyFillMode
 0x4b40fc SetBkMode
 0x4b4100 RestoreDC
 0x4b4104 SaveDC
 0x4b4108 CombineRgn
 0x4b410c CreateRectRgn
 0x4b4110 FillRgn
 0x4b4114 CreateSolidBrush
 0x4b4118 CreateFontIndirectA
 0x4b411c GetStockObject
 0x4b4120 GetObjectA
 0x4b4124 EndPage
 0x4b4128 EndDoc
 0x4b412c DeleteDC
 0x4b4130 StartDocA
 0x4b4134 StartPage
 0x4b4138 BitBlt
 0x4b413c CreateCompatibleDC
 0x4b4140 Ellipse
 0x4b4144 Rectangle
 0x4b4148 LPtoDP
 0x4b414c DPtoLP
 0x4b4150 GetCurrentObject
 0x4b4154 RoundRect
 0x4b4158 GetTextExtentPoint32A
 0x4b415c GetDeviceCaps
 0x4b4160 LineTo
 0x4b4164 MoveToEx
 0x4b4168 ExcludeClipRect
 0x4b416c GetClipBox
 0x4b4170 ScaleWindowExtEx
 0x4b4174 SetWindowExtEx
 0x4b4178 SetWindowOrgEx
WINMM.dll
 0x4b4660 waveOutUnprepareHeader
 0x4b4664 waveOutPrepareHeader
 0x4b4668 waveOutWrite
 0x4b466c waveOutPause
 0x4b4670 waveOutReset
 0x4b4674 waveOutClose
 0x4b4678 waveOutGetNumDevs
 0x4b467c waveOutOpen
 0x4b4680 midiOutUnprepareHeader
 0x4b4684 midiStreamOpen
 0x4b4688 midiStreamProperty
 0x4b468c midiOutPrepareHeader
 0x4b4690 midiStreamOut
 0x4b4694 waveOutRestart
 0x4b4698 midiStreamStop
 0x4b469c midiOutReset
 0x4b46a0 midiStreamClose
 0x4b46a4 midiStreamRestart
WINSPOOL.DRV
 0x4b46ac OpenPrinterA
 0x4b46b0 DocumentPropertiesA
 0x4b46b4 ClosePrinter
ADVAPI32.dll
 0x4b4000 RegCloseKey
 0x4b4004 RegOpenKeyExA
 0x4b4008 RegSetValueExA
 0x4b400c RegQueryValueA
 0x4b4010 RegCreateKeyExA
SHELL32.dll
 0x4b43e8 ShellExecuteA
 0x4b43ec Shell_NotifyIconA
ole32.dll
 0x4b46fc CLSIDFromProgID
 0x4b4700 OleRun
 0x4b4704 CoCreateInstance
 0x4b4708 CLSIDFromString
 0x4b470c OleUninitialize
 0x4b4710 OleInitialize
OLEAUT32.dll
 0x4b4398 SafeArrayGetElement
 0x4b439c VariantCopyInd
 0x4b43a0 VariantInit
 0x4b43a4 SysAllocString
 0x4b43a8 SafeArrayDestroy
 0x4b43ac SafeArrayCreate
 0x4b43b0 SafeArrayPutElement
 0x4b43b4 RegisterTypeLib
 0x4b43b8 LHashValOfNameSys
 0x4b43bc LoadTypeLib
 0x4b43c0 UnRegisterTypeLib
 0x4b43c4 SafeArrayAccessData
 0x4b43c8 SafeArrayUnaccessData
 0x4b43cc SafeArrayGetDim
 0x4b43d0 SafeArrayGetLBound
 0x4b43d4 SafeArrayGetUBound
 0x4b43d8 VariantChangeType
 0x4b43dc VariantClear
 0x4b43e0 VariantCopy
COMCTL32.dll
 0x4b4018 ImageList_Read
 0x4b401c ImageList_Duplicate
 0x4b4020 ImageList_Destroy
 0x4b4024 None
 0x4b4028 ImageList_SetBkColor
 0x4b402c ImageList_GetImageCount
WS2_32.dll
 0x4b46bc inet_ntoa
 0x4b46c0 WSACleanup
 0x4b46c4 ntohl
 0x4b46c8 accept
 0x4b46cc getpeername
 0x4b46d0 recv
 0x4b46d4 ioctlsocket
 0x4b46d8 recvfrom
 0x4b46dc closesocket
 0x4b46e0 WSAAsyncSelect
comdlg32.dll
 0x4b46e8 ChooseColorA
 0x4b46ec GetOpenFileNameA
 0x4b46f0 GetSaveFileNameA
 0x4b46f4 GetFileTitleA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure