Report - 2.exe

Malicious Library Antivirus UPX PE File PE32 OS Processor Check
ScreenShot
Created 2025.01.03 17:58 Machine s1_win7_x6403
Filename 2.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
2.6
ZERO API file : clean
VT API (file) 50 detected (AIDetectMalware, XWorm, Malicious, score, Ghanarava, Infected, GenericKD, Unsafe, V9r2, confidence, 100%, Genus, Attribute, HighConfidence, high confidence, GenKryptik, HFBD, MalwareX, CLOUD, Redcap, yddhj, R002C0DLQ24, Artemis, Outbreak, Chgt, Runshell, susgen, PossibleThreat)
md5 119a00350e1a20e1a3ea01153b91001b
sha256 f8d8066380ecd1341441dd2b0b8562c5ec662148c86376cbc5da494af8434cee
ssdeep 49152:9ORCQxgswnpPJDps5v/FyqnL0t9sSeO6ONSuA7MjsfdVx7X+0YRYs:9nQxgswpPJDpS9bL0t9sS2ONSuA73DVA
imphash 2412baa1f91d30db11660ad19c16100b
impfuzzy 192:i89w+wqFkUVlUmwetuPr3dsNsTQ8pFkcFcRcVL0mK/W6QP+88:i89wKdc9z3JQhaERmcW6QP+88
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 50 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
notice Searches running processes potentially to identify processes for sandbox evasion
notice The binary likely contains encrypted or compressed data indicative of a packer
info This executable has a PDB path

Rules (6cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x5191e0 IsValidCodePage
 0x5191e4 GetStdHandle
 0x5191e8 LCMapStringW
 0x5191ec FreeEnvironmentStringsW
 0x5191f0 GetEnvironmentStringsW
 0x5191f4 SetHandleCount
 0x5191f8 QueryPerformanceCounter
 0x5191fc GetStringTypeW
 0x519200 CompareStringW
 0x519204 GetTimeZoneInformation
 0x519208 GetConsoleCP
 0x51920c GetConsoleMode
 0x519210 WriteConsoleW
 0x519214 CreateFileW
 0x519218 FindResourceW
 0x51921c HeapCreate
 0x519220 IsProcessorFeaturePresent
 0x519224 IsDebuggerPresent
 0x519228 SetUnhandledExceptionFilter
 0x51922c UnhandledExceptionFilter
 0x519230 TerminateProcess
 0x519234 GetFileType
 0x519238 SetStdHandle
 0x51923c GetSystemTimeAsFileTime
 0x519240 HeapSize
 0x519244 HeapQueryInformation
 0x519248 HeapReAlloc
 0x51924c VirtualQuery
 0x519250 GetSystemInfo
 0x519254 LoadResource
 0x519258 LockResource
 0x51925c SizeofResource
 0x519260 WideCharToMultiByte
 0x519264 CreateThread
 0x519268 TerminateThread
 0x51926c Sleep
 0x519270 Process32Next
 0x519274 Process32First
 0x519278 CreateToolhelp32Snapshot
 0x51927c FreeLibrary
 0x519280 VirtualAlloc
 0x519284 RaiseException
 0x519288 ExitThread
 0x51928c RtlUnwind
 0x519290 GetStartupInfoW
 0x519294 HeapSetInformation
 0x519298 GetCommandLineA
 0x51929c ExitProcess
 0x5192a0 HeapAlloc
 0x5192a4 HeapFree
 0x5192a8 DecodePointer
 0x5192ac EncodePointer
 0x5192b0 FindResourceExW
 0x5192b4 SearchPathA
 0x5192b8 GetProfileIntA
 0x5192bc GetTickCount
 0x5192c0 InitializeCriticalSectionAndSpinCount
 0x5192c4 GetNumberFormatA
 0x5192c8 GetWindowsDirectoryA
 0x5192cc GetTempPathA
 0x5192d0 GetTempFileNameA
 0x5192d4 GetFileTime
 0x5192d8 GetFileSizeEx
 0x5192dc GetFileAttributesA
 0x5192e0 FileTimeToLocalFileTime
 0x5192e4 GetFileAttributesExA
 0x5192e8 SetErrorMode
 0x5192ec GetOEMCP
 0x5192f0 GetCPInfo
 0x5192f4 FileTimeToSystemTime
 0x5192f8 GetACP
 0x5192fc GetFullPathNameA
 0x519300 GetVolumeInformationA
 0x519304 FindFirstFileA
 0x519308 FindClose
 0x51930c GetCurrentProcess
 0x519310 DuplicateHandle
 0x519314 GetFileSize
 0x519318 SetEndOfFile
 0x51931c UnlockFile
 0x519320 LockFile
 0x519324 FlushFileBuffers
 0x519328 SetFilePointer
 0x51932c WriteFile
 0x519330 SetEnvironmentVariableA
 0x519334 ReadFile
 0x519338 lstrcmpiA
 0x51933c lstrcpyA
 0x519340 DeleteFileA
 0x519344 InterlockedIncrement
 0x519348 TlsFree
 0x51934c DeleteCriticalSection
 0x519350 LocalReAlloc
 0x519354 TlsSetValue
 0x519358 TlsAlloc
 0x51935c InitializeCriticalSection
 0x519360 GlobalHandle
 0x519364 GlobalReAlloc
 0x519368 EnterCriticalSection
 0x51936c TlsGetValue
 0x519370 LeaveCriticalSection
 0x519374 LocalAlloc
 0x519378 GlobalFlags
 0x51937c GetCurrentDirectoryA
 0x519380 GlobalGetAtomNameA
 0x519384 GlobalFindAtomA
 0x519388 GetVersionExA
 0x51938c LoadLibraryW
 0x519390 lstrcmpW
 0x519394 InterlockedDecrement
 0x519398 GetModuleFileNameW
 0x51939c ReleaseActCtx
 0x5193a0 CreateActCtxW
 0x5193a4 CopyFileA
 0x5193a8 GlobalSize
 0x5193ac FormatMessageA
 0x5193b0 LocalFree
 0x5193b4 lstrlenW
 0x5193b8 MulDiv
 0x5193bc GlobalUnlock
 0x5193c0 GlobalFree
 0x5193c4 FindResourceA
 0x5193c8 FreeResource
 0x5193cc GetCurrentProcessId
 0x5193d0 GlobalAddAtomA
 0x5193d4 GetPrivateProfileStringA
 0x5193d8 WritePrivateProfileStringA
 0x5193dc GetPrivateProfileIntA
 0x5193e0 lstrlenA
 0x5193e4 WaitForSingleObject
 0x5193e8 ResumeThread
 0x5193ec SetThreadPriority
 0x5193f0 GlobalDeleteAtom
 0x5193f4 GetCurrentThread
 0x5193f8 GetCurrentThreadId
 0x5193fc MultiByteToWideChar
 0x519400 GetUserDefaultUILanguage
 0x519404 ConvertDefaultLocale
 0x519408 GetSystemDefaultUILanguage
 0x51940c GetModuleFileNameA
 0x519410 GetLocaleInfoA
 0x519414 CompareStringA
 0x519418 ActivateActCtx
 0x51941c LoadLibraryA
 0x519420 GetLastError
 0x519424 DeactivateActCtx
 0x519428 SetLastError
 0x51942c InterlockedExchange
 0x519430 GlobalLock
 0x519434 lstrcmpA
 0x519438 GlobalAlloc
 0x51943c GetModuleHandleW
 0x519440 GetProcAddress
 0x519444 CloseHandle
 0x519448 VirtualProtect
 0x51944c CreateFileA
 0x519450 GetModuleHandleA
USER32.dll
 0x5194e0 IsDialogMessageA
 0x5194e4 SetWindowTextA
 0x5194e8 MoveWindow
 0x5194ec ShowWindow
 0x5194f0 CharUpperA
 0x5194f4 IntersectRect
 0x5194f8 OffsetRect
 0x5194fc LoadMenuW
 0x519500 SetWindowRgn
 0x519504 RedrawWindow
 0x519508 MessageBeep
 0x51950c NotifyWinEvent
 0x519510 GetAsyncKeyState
 0x519514 IsZoomed
 0x519518 IsRectEmpty
 0x51951c UnionRect
 0x519520 EnableScrollBar
 0x519524 SetCapture
 0x519528 MonitorFromPoint
 0x51952c IsMenu
 0x519530 CreatePopupMenu
 0x519534 SetMenuDefaultItem
 0x519538 GetMenuDefaultItem
 0x51953c UnregisterClassA
 0x519540 TranslateAcceleratorA
 0x519544 BringWindowToTop
 0x519548 InsertMenuItemA
 0x51954c LoadAcceleratorsA
 0x519550 LoadImageA
 0x519554 LoadMenuA
 0x519558 ReuseDDElParam
 0x51955c SetParent
 0x519560 DestroyAcceleratorTable
 0x519564 SetClassLongA
 0x519568 DrawIconEx
 0x51956c DrawEdge
 0x519570 DrawFocusRect
 0x519574 CopyAcceleratorTableA
 0x519578 ToAsciiEx
 0x51957c MapVirtualKeyA
 0x519580 GetKeyboardLayout
 0x519584 GetKeyboardState
 0x519588 LoadAcceleratorsW
 0x51958c CreateAcceleratorTableA
 0x519590 SetRect
 0x519594 SetCursorPos
 0x519598 LockWindowUpdate
 0x51959c InvertRect
 0x5195a0 HideCaret
 0x5195a4 GetIconInfo
 0x5195a8 CopyImage
 0x5195ac GetNextDlgGroupItem
 0x5195b0 OpenClipboard
 0x5195b4 SetClipboardData
 0x5195b8 CloseClipboard
 0x5195bc EmptyClipboard
 0x5195c0 LoadImageW
 0x5195c4 RegisterClipboardFormatA
 0x5195c8 FrameRect
 0x5195cc CopyIcon
 0x5195d0 CharUpperBuffA
 0x5195d4 PostThreadMessageA
 0x5195d8 GetKeyNameTextA
 0x5195dc DefFrameProcA
 0x5195e0 DefMDIChildProcA
 0x5195e4 DrawMenuBar
 0x5195e8 TranslateMDISysAccel
 0x5195ec CreateMenu
 0x5195f0 IsClipboardFormatAvailable
 0x5195f4 GetUpdateRect
 0x5195f8 GetDoubleClickTime
 0x5195fc IsCharLowerA
 0x519600 MapVirtualKeyExA
 0x519604 SubtractRect
 0x519608 DestroyCursor
 0x51960c MapDialogRect
 0x519610 CheckDlgButton
 0x519614 RegisterWindowMessageA
 0x519618 DeleteMenu
 0x51961c WaitMessage
 0x519620 RealChildWindowFromPoint
 0x519624 LoadIconA
 0x519628 SendDlgItemMessageA
 0x51962c WinHelpA
 0x519630 SetTimer
 0x519634 KillTimer
 0x519638 SetRectEmpty
 0x51963c EnumDisplayMonitors
 0x519640 IsChild
 0x519644 SetLayeredWindowAttributes
 0x519648 GetSysColorBrush
 0x51964c DrawFrameControl
 0x519650 DestroyIcon
 0x519654 GetWindowRgn
 0x519658 WindowFromPoint
 0x51965c LoadCursorW
 0x519660 LoadCursorA
 0x519664 UpdateLayeredWindow
 0x519668 ReleaseCapture
 0x51966c EnableWindow
 0x519670 DrawIcon
 0x519674 GetClientRect
 0x519678 GetSystemMetrics
 0x51967c IsIconic
 0x519680 SendMessageA
 0x519684 AppendMenuA
 0x519688 GetSystemMenu
 0x51968c LoadIconW
 0x519690 UnpackDDElParam
 0x519694 PostMessageA
 0x519698 PostQuitMessage
 0x51969c CheckMenuItem
 0x5196a0 EnableMenuItem
 0x5196a4 GetMenuState
 0x5196a8 ModifyMenuA
 0x5196ac GetParent
 0x5196b0 GetFocus
 0x5196b4 LoadBitmapW
 0x5196b8 GetMenuCheckMarkDimensions
 0x5196bc SetMenuItemBitmaps
 0x5196c0 ValidateRect
 0x5196c4 GetCursorPos
 0x5196c8 PeekMessageA
 0x5196cc GetKeyState
 0x5196d0 IsWindowVisible
 0x5196d4 GetActiveWindow
 0x5196d8 DispatchMessageA
 0x5196dc TranslateMessage
 0x5196e0 GetMessageA
 0x5196e4 CallNextHookEx
 0x5196e8 SetWindowsHookExA
 0x5196ec SetCursor
 0x5196f0 ShowOwnedPopups
 0x5196f4 MessageBoxA
 0x5196f8 IsWindowEnabled
 0x5196fc GetLastActivePopup
 0x519700 GetWindowLongA
 0x519704 GetWindowThreadProcessId
 0x519708 DrawStateA
 0x51970c FillRect
 0x519710 UpdateWindow
 0x519714 InvalidateRect
 0x519718 GetClassNameA
 0x51971c EndDialog
 0x519720 GetNextDlgTabItem
 0x519724 GetDlgItem
 0x519728 IsWindow
 0x51972c DestroyWindow
 0x519730 CreateDialogIndirectParamA
 0x519734 SetActiveWindow
 0x519738 GetDesktopWindow
 0x51973c RemoveMenu
 0x519740 GetSubMenu
 0x519744 GetMenuItemCount
 0x519748 InsertMenuA
 0x51974c GetMenuItemID
 0x519750 GetMenuStringA
 0x519754 TabbedTextOutA
 0x519758 DrawTextA
 0x51975c DrawTextExA
 0x519760 GrayStringA
 0x519764 ScreenToClient
 0x519768 ClientToScreen
 0x51976c GetDC
 0x519770 ReleaseDC
 0x519774 GetWindowDC
 0x519778 BeginPaint
 0x51977c EndPaint
 0x519780 GetSysColor
 0x519784 PtInRect
 0x519788 GetWindowRect
 0x51978c UnhookWindowsHookEx
 0x519790 CopyRect
 0x519794 InflateRect
 0x519798 GetMenuItemInfoA
 0x51979c DestroyMenu
 0x5197a0 SystemParametersInfoA
 0x5197a4 GetWindow
 0x5197a8 SetWindowPos
 0x5197ac SetWindowLongA
 0x5197b0 GetMenu
 0x5197b4 CallWindowProcA
 0x5197b8 DefWindowProcA
 0x5197bc GetDlgCtrlID
 0x5197c0 GetWindowPlacement
 0x5197c4 SetWindowPlacement
 0x5197c8 SetScrollInfo
 0x5197cc GetScrollInfo
 0x5197d0 DeferWindowPos
 0x5197d4 EqualRect
 0x5197d8 AdjustWindowRectEx
 0x5197dc RegisterClassA
 0x5197e0 GetClassInfoA
 0x5197e4 GetClassInfoExA
 0x5197e8 CreateWindowExA
 0x5197ec ShowScrollBar
 0x5197f0 SetForegroundWindow
 0x5197f4 GetScrollPos
 0x5197f8 SetScrollPos
 0x5197fc GetScrollRange
 0x519800 SetScrollRange
 0x519804 SetMenu
 0x519808 TrackPopupMenu
 0x51980c ScrollWindow
 0x519810 MapWindowPoints
 0x519814 GetMonitorInfoA
 0x519818 MonitorFromWindow
 0x51981c GetMessagePos
 0x519820 GetMessageTime
 0x519824 GetTopWindow
 0x519828 EndDeferWindowPos
 0x51982c BeginDeferWindowPos
 0x519830 GetForegroundWindow
 0x519834 GetWindowTextA
 0x519838 GetWindowTextLengthA
 0x51983c SetFocus
 0x519840 RemovePropA
 0x519844 GetPropA
 0x519848 SetPropA
 0x51984c GetClassLongA
 0x519850 GetCapture
GDI32.dll
 0x519040 SetPixelV
 0x519044 CreateBitmap
 0x519048 DeleteObject
 0x51904c CreateSolidBrush
 0x519050 GetObjectA
 0x519054 GetStockObject
 0x519058 GetDeviceCaps
 0x51905c CopyMetaFileA
 0x519060 CreateDCA
 0x519064 SaveDC
 0x519068 RestoreDC
 0x51906c SetBkColor
 0x519070 SetBkMode
 0x519074 SetPolyFillMode
 0x519078 SetROP2
 0x51907c SetTextColor
 0x519080 SetMapMode
 0x519084 GetClipBox
 0x519088 ExcludeClipRect
 0x51908c IntersectClipRect
 0x519090 LineTo
 0x519094 MoveToEx
 0x519098 SetTextAlign
 0x51909c GetLayout
 0x5190a0 SetLayout
 0x5190a4 SelectClipRgn
 0x5190a8 CreateRectRgn
 0x5190ac GetViewportExtEx
 0x5190b0 GetWindowExtEx
 0x5190b4 BitBlt
 0x5190b8 GetPixel
 0x5190bc PtVisible
 0x5190c0 RectVisible
 0x5190c4 TextOutA
 0x5190c8 ExtTextOutA
 0x5190cc Escape
 0x5190d0 SelectObject
 0x5190d4 SetViewportOrgEx
 0x5190d8 OffsetViewportOrgEx
 0x5190dc SetViewportExtEx
 0x5190e0 ScaleViewportExtEx
 0x5190e4 SetWindowOrgEx
 0x5190e8 OffsetWindowOrgEx
 0x5190ec SetWindowExtEx
 0x5190f0 ScaleWindowExtEx
 0x5190f4 ExtSelectClipRgn
 0x5190f8 DeleteDC
 0x5190fc CreatePatternBrush
 0x519100 CreateCompatibleDC
 0x519104 SelectPalette
 0x519108 GetObjectType
 0x51910c CreatePen
 0x519110 CreateHatchBrush
 0x519114 CreateFontIndirectA
 0x519118 GetTextExtentPoint32A
 0x51911c CreateDIBitmap
 0x519120 CreateCompatibleBitmap
 0x519124 CreateRectRgnIndirect
 0x519128 GetTextMetricsA
 0x51912c EnumFontFamiliesA
 0x519130 GetTextCharsetInfo
 0x519134 SetRectRgn
 0x519138 CombineRgn
 0x51913c PatBlt
 0x519140 DPtoLP
 0x519144 CreateRoundRectRgn
 0x519148 CreateDIBSection
 0x51914c CreatePolygonRgn
 0x519150 GetBkColor
 0x519154 GetTextColor
 0x519158 CreateEllipticRgn
 0x51915c Polyline
 0x519160 Ellipse
 0x519164 Polygon
 0x519168 CreatePalette
 0x51916c GetPaletteEntries
 0x519170 GetNearestPaletteIndex
 0x519174 RealizePalette
 0x519178 GetSystemPaletteEntries
 0x51917c OffsetRgn
 0x519180 GetRgnBox
 0x519184 SetDIBColorTable
 0x519188 StretchBlt
 0x51918c SetPixel
 0x519190 Rectangle
 0x519194 EnumFontFamiliesExA
 0x519198 ExtFloodFill
 0x51919c SetPaletteEntries
 0x5191a0 LPtoDP
 0x5191a4 GetWindowOrgEx
 0x5191a8 GetViewportOrgEx
 0x5191ac PtInRegion
 0x5191b0 FillRgn
 0x5191b4 FrameRgn
 0x5191b8 GetBoundsRect
 0x5191bc GetTextFaceA
MSIMG32.dll
 0x519458 AlphaBlend
 0x51945c TransparentBlt
COMDLG32.dll
 0x519038 GetFileTitleA
WINSPOOL.DRV
 0x519860 ClosePrinter
 0x519864 DocumentPropertiesA
 0x519868 OpenPrinterA
ADVAPI32.dll
 0x519000 RegOpenKeyExA
 0x519004 RegCreateKeyExA
 0x519008 RegCloseKey
 0x51900c RegQueryValueExA
 0x519010 RegSetValueExA
 0x519014 RegDeleteValueA
 0x519018 RegEnumKeyA
 0x51901c RegQueryValueA
 0x519020 RegEnumValueA
 0x519024 RegEnumKeyExA
 0x519028 RegDeleteKeyA
SHELL32.dll
 0x5194a0 SHGetFileInfoA
 0x5194a4 DragFinish
 0x5194a8 DragQueryFileA
 0x5194ac SHGetDesktopFolder
 0x5194b0 SHGetPathFromIDListA
 0x5194b4 SHGetSpecialFolderLocation
 0x5194b8 ShellExecuteA
 0x5194bc SHAppBarMessage
 0x5194c0 SHBrowseForFolderA
COMCTL32.dll
 0x519030 ImageList_GetIconSize
SHLWAPI.dll
 0x5194c8 PathFindExtensionA
 0x5194cc PathFindFileNameA
 0x5194d0 PathStripToRootA
 0x5194d4 PathIsUNCA
 0x5194d8 PathRemoveFileSpecW
ole32.dll
 0x5198d8 RevokeDragDrop
 0x5198dc CoLockObjectExternal
 0x5198e0 RegisterDragDrop
 0x5198e4 OleGetClipboard
 0x5198e8 OleLockRunning
 0x5198ec IsAccelerator
 0x5198f0 OleTranslateAccelerator
 0x5198f4 OleDestroyMenuDescriptor
 0x5198f8 OleCreateMenuDescriptor
 0x5198fc DoDragDrop
 0x519900 CreateStreamOnHGlobal
 0x519904 CoInitializeEx
 0x519908 CoInitialize
 0x51990c CoCreateInstance
 0x519910 CoUninitialize
 0x519914 OleDuplicateData
 0x519918 CoTaskMemAlloc
 0x51991c ReleaseStgMedium
 0x519920 CoTaskMemFree
 0x519924 CoCreateGuid
OLEAUT32.dll
 0x519474 VariantClear
 0x519478 VariantChangeType
 0x51947c VariantInit
 0x519480 SysStringLen
 0x519484 SysAllocStringLen
 0x519488 SysFreeString
 0x51948c SysAllocString
 0x519490 VarBstrFromDate
 0x519494 SystemTimeToVariantTime
 0x519498 VariantTimeToSystemTime
gdiplus.dll
 0x51987c GdipCreateBitmapFromStream
 0x519880 GdipGetImagePalette
 0x519884 GdipGetImagePaletteSize
 0x519888 GdipGetImagePixelFormat
 0x51988c GdipGetImageHeight
 0x519890 GdipGetImageWidth
 0x519894 GdipCloneImage
 0x519898 GdipDrawImageRectI
 0x51989c GdipSetInterpolationMode
 0x5198a0 GdipCreateFromHDC
 0x5198a4 GdiplusShutdown
 0x5198a8 GdiplusStartup
 0x5198ac GdipCreateBitmapFromHBITMAP
 0x5198b0 GdipDisposeImage
 0x5198b4 GdipDeleteGraphics
 0x5198b8 GdipAlloc
 0x5198bc GdipFree
 0x5198c0 GdipCreateBitmapFromScan0
 0x5198c4 GdipBitmapLockBits
 0x5198c8 GdipDrawImageI
 0x5198cc GdipGetImageGraphicsContext
 0x5198d0 GdipBitmapUnlockBits
IPHLPAPI.DLL
 0x5191d4 GetTcpTable2
 0x5191d8 SetTcpEntry
WS2_32.dll
 0x519870 inet_ntop
 0x519874 htonl
OLEACC.dll
 0x519464 AccessibleObjectFromWindow
 0x519468 LresultFromObject
 0x51946c CreateStdAccessibleObject
IMM32.dll
 0x5191c4 ImmGetContext
 0x5191c8 ImmGetOpenStatus
 0x5191cc ImmReleaseContext
WINMM.dll
 0x519858 PlaySoundA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure