Report - ImageEditorforWP.exe

Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2025.02.03 13:03 Machine s1_win7_x6403
Filename ImageEditorforWP.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
1.4
ZERO API file : mailcious
VT API (file)
md5 3fd8e54afc2f9019e0274702c61733ee
sha256 a7ac8d5c34ccbb6df4c3d2420a6df1e79222c3ece6101a8d8fd58d5a18fc86e7
ssdeep 49152:mg/XnVX5SvbgtcZwZUGvFx4jaGIYfVjgjpHT0lh0IgwR6NE83nWKqTy3cP6RkqF+:mgfVX0c9ofujpzRgV8Wqcpj
imphash e0013b7fe0ee29e8ce337f35810ef63c
impfuzzy 192:f3NSGNG1sT1qpbuuaxSUvK9/3o4qEZo72POQUxU:f3K1sEaq9AKPOQf
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x48c168 DeleteCriticalSection
 0x48c16c LeaveCriticalSection
 0x48c170 EnterCriticalSection
 0x48c174 InitializeCriticalSection
 0x48c178 VirtualFree
 0x48c17c VirtualAlloc
 0x48c180 LocalFree
 0x48c184 LocalAlloc
 0x48c188 GetVersion
 0x48c18c GetCurrentThreadId
 0x48c190 InterlockedDecrement
 0x48c194 InterlockedIncrement
 0x48c198 VirtualQuery
 0x48c19c WideCharToMultiByte
 0x48c1a0 MultiByteToWideChar
 0x48c1a4 lstrlenA
 0x48c1a8 lstrcpynA
 0x48c1ac LoadLibraryExA
 0x48c1b0 GetThreadLocale
 0x48c1b4 GetStartupInfoA
 0x48c1b8 GetProcAddress
 0x48c1bc GetModuleHandleA
 0x48c1c0 GetModuleFileNameA
 0x48c1c4 GetLocaleInfoA
 0x48c1c8 GetCommandLineA
 0x48c1cc FreeLibrary
 0x48c1d0 FindFirstFileA
 0x48c1d4 FindClose
 0x48c1d8 ExitProcess
 0x48c1dc ExitThread
 0x48c1e0 CreateThread
 0x48c1e4 WriteFile
 0x48c1e8 UnhandledExceptionFilter
 0x48c1ec RtlUnwind
 0x48c1f0 RaiseException
 0x48c1f4 GetStdHandle
user32.dll
 0x48c1fc GetKeyboardType
 0x48c200 LoadStringA
 0x48c204 MessageBoxA
 0x48c208 CharNextA
advapi32.dll
 0x48c210 RegQueryValueExA
 0x48c214 RegOpenKeyExA
 0x48c218 RegCloseKey
oleaut32.dll
 0x48c220 SysFreeString
 0x48c224 SysReAllocStringLen
 0x48c228 SysAllocStringLen
kernel32.dll
 0x48c230 TlsSetValue
 0x48c234 TlsGetValue
 0x48c238 LocalAlloc
 0x48c23c GetModuleHandleA
advapi32.dll
 0x48c244 ReportEventA
 0x48c248 RegisterEventSourceA
 0x48c24c RegQueryValueExA
 0x48c250 RegOpenKeyExA
 0x48c254 RegCloseKey
 0x48c258 DeregisterEventSource
kernel32.dll
 0x48c260 lstrcpyA
 0x48c264 lstrcmpA
 0x48c268 WriteFile
 0x48c26c WaitForSingleObject
 0x48c270 VirtualQuery
 0x48c274 VirtualAlloc
 0x48c278 SuspendThread
 0x48c27c Sleep
 0x48c280 SizeofResource
 0x48c284 SetThreadLocale
 0x48c288 SetFilePointer
 0x48c28c SetEvent
 0x48c290 SetErrorMode
 0x48c294 SetEndOfFile
 0x48c298 ResumeThread
 0x48c29c ResetEvent
 0x48c2a0 ReadFile
 0x48c2a4 MultiByteToWideChar
 0x48c2a8 MulDiv
 0x48c2ac LockResource
 0x48c2b0 LoadResource
 0x48c2b4 LoadLibraryA
 0x48c2b8 LeaveCriticalSection
 0x48c2bc InitializeCriticalSection
 0x48c2c0 GlobalUnlock
 0x48c2c4 GlobalReAlloc
 0x48c2c8 GlobalHandle
 0x48c2cc GlobalLock
 0x48c2d0 GlobalFree
 0x48c2d4 GlobalFindAtomA
 0x48c2d8 GlobalDeleteAtom
 0x48c2dc GlobalAlloc
 0x48c2e0 GlobalAddAtomA
 0x48c2e4 GetVersionExA
 0x48c2e8 GetVersion
 0x48c2ec GetTickCount
 0x48c2f0 GetThreadLocale
 0x48c2f4 GetTempPathA
 0x48c2f8 GetSystemInfo
 0x48c2fc GetSystemDirectoryA
 0x48c300 GetStringTypeExA
 0x48c304 GetStdHandle
 0x48c308 GetProcAddress
 0x48c30c GetModuleHandleA
 0x48c310 GetModuleFileNameA
 0x48c314 GetLocaleInfoA
 0x48c318 GetLocalTime
 0x48c31c GetLastError
 0x48c320 GetFullPathNameA
 0x48c324 GetFileSize
 0x48c328 GetExitCodeThread
 0x48c32c GetDiskFreeSpaceA
 0x48c330 GetDateFormatA
 0x48c334 GetCurrentThreadId
 0x48c338 GetCurrentProcessId
 0x48c33c GetCPInfo
 0x48c340 GetACP
 0x48c344 FreeResource
 0x48c348 InterlockedIncrement
 0x48c34c InterlockedExchange
 0x48c350 InterlockedDecrement
 0x48c354 FreeLibrary
 0x48c358 FormatMessageA
 0x48c35c FindResourceA
 0x48c360 FindFirstFileA
 0x48c364 FindClose
 0x48c368 FileTimeToLocalFileTime
 0x48c36c FileTimeToDosDateTime
 0x48c370 EnumCalendarInfoA
 0x48c374 EnterCriticalSection
 0x48c378 DeleteFileA
 0x48c37c DeleteCriticalSection
 0x48c380 CreateThread
 0x48c384 CreateFileA
 0x48c388 CreateEventA
 0x48c38c CompareStringA
 0x48c390 CloseHandle
version.dll
 0x48c398 VerQueryValueA
 0x48c39c GetFileVersionInfoSizeA
 0x48c3a0 GetFileVersionInfoA
gdi32.dll
 0x48c3a8 UnrealizeObject
 0x48c3ac StretchBlt
 0x48c3b0 SetWindowOrgEx
 0x48c3b4 SetWinMetaFileBits
 0x48c3b8 SetViewportOrgEx
 0x48c3bc SetTextColor
 0x48c3c0 SetStretchBltMode
 0x48c3c4 SetROP2
 0x48c3c8 SetPixel
 0x48c3cc SetEnhMetaFileBits
 0x48c3d0 SetDIBColorTable
 0x48c3d4 SetBrushOrgEx
 0x48c3d8 SetBkMode
 0x48c3dc SetBkColor
 0x48c3e0 SelectPalette
 0x48c3e4 SelectObject
 0x48c3e8 SaveDC
 0x48c3ec RestoreDC
 0x48c3f0 Rectangle
 0x48c3f4 RectVisible
 0x48c3f8 RealizePalette
 0x48c3fc Polyline
 0x48c400 Polygon
 0x48c404 PlayEnhMetaFile
 0x48c408 PatBlt
 0x48c40c MoveToEx
 0x48c410 MaskBlt
 0x48c414 LineTo
 0x48c418 IntersectClipRect
 0x48c41c GetWindowOrgEx
 0x48c420 GetWinMetaFileBits
 0x48c424 GetTextMetricsA
 0x48c428 GetTextExtentPointA
 0x48c42c GetTextExtentPoint32A
 0x48c430 GetSystemPaletteEntries
 0x48c434 GetStockObject
 0x48c438 GetROP2
 0x48c43c GetPolyFillMode
 0x48c440 GetPixel
 0x48c444 GetPaletteEntries
 0x48c448 GetObjectA
 0x48c44c GetEnhMetaFilePaletteEntries
 0x48c450 GetEnhMetaFileHeader
 0x48c454 GetEnhMetaFileBits
 0x48c458 GetDeviceCaps
 0x48c45c GetDIBits
 0x48c460 GetDIBColorTable
 0x48c464 GetDCOrgEx
 0x48c468 GetCurrentPositionEx
 0x48c46c GetClipBox
 0x48c470 GetBrushOrgEx
 0x48c474 GetBitmapBits
 0x48c478 GdiFlush
 0x48c47c ExcludeClipRect
 0x48c480 DeleteObject
 0x48c484 DeleteEnhMetaFile
 0x48c488 DeleteDC
 0x48c48c CreateSolidBrush
 0x48c490 CreatePenIndirect
 0x48c494 CreatePalette
 0x48c498 CreateHalftonePalette
 0x48c49c CreateFontIndirectA
 0x48c4a0 CreateDIBitmap
 0x48c4a4 CreateDIBSection
 0x48c4a8 CreateCompatibleDC
 0x48c4ac CreateCompatibleBitmap
 0x48c4b0 CreateBrushIndirect
 0x48c4b4 CreateBitmap
 0x48c4b8 CopyEnhMetaFileA
 0x48c4bc BitBlt
user32.dll
 0x48c4c4 CreateWindowExA
 0x48c4c8 WindowFromPoint
 0x48c4cc WinHelpA
 0x48c4d0 WaitMessage
 0x48c4d4 UpdateWindow
 0x48c4d8 UnregisterClassA
 0x48c4dc UnhookWindowsHookEx
 0x48c4e0 TranslateMessage
 0x48c4e4 TranslateMDISysAccel
 0x48c4e8 TrackPopupMenu
 0x48c4ec SystemParametersInfoA
 0x48c4f0 ShowWindow
 0x48c4f4 ShowScrollBar
 0x48c4f8 ShowOwnedPopups
 0x48c4fc ShowCursor
 0x48c500 ShowCaret
 0x48c504 SetWindowsHookExA
 0x48c508 SetWindowTextA
 0x48c50c SetWindowPos
 0x48c510 SetWindowPlacement
 0x48c514 SetWindowLongA
 0x48c518 SetTimer
 0x48c51c SetScrollRange
 0x48c520 SetScrollPos
 0x48c524 SetScrollInfo
 0x48c528 SetRect
 0x48c52c SetPropA
 0x48c530 SetParent
 0x48c534 SetMenuItemInfoA
 0x48c538 SetMenu
 0x48c53c SetForegroundWindow
 0x48c540 SetFocus
 0x48c544 SetCursor
 0x48c548 SetClipboardData
 0x48c54c SetClassLongA
 0x48c550 SetCapture
 0x48c554 SetActiveWindow
 0x48c558 SendMessageA
 0x48c55c ScrollWindow
 0x48c560 ScreenToClient
 0x48c564 RemovePropA
 0x48c568 RemoveMenu
 0x48c56c ReleaseDC
 0x48c570 ReleaseCapture
 0x48c574 RegisterWindowMessageA
 0x48c578 RegisterClipboardFormatA
 0x48c57c RegisterClassA
 0x48c580 RedrawWindow
 0x48c584 PtInRect
 0x48c588 PostQuitMessage
 0x48c58c PostMessageA
 0x48c590 PeekMessageA
 0x48c594 OpenClipboard
 0x48c598 OffsetRect
 0x48c59c OemToCharA
 0x48c5a0 MsgWaitForMultipleObjects
 0x48c5a4 MessageBoxA
 0x48c5a8 MessageBeep
 0x48c5ac MapWindowPoints
 0x48c5b0 MapVirtualKeyA
 0x48c5b4 LoadStringA
 0x48c5b8 LoadKeyboardLayoutA
 0x48c5bc LoadIconA
 0x48c5c0 LoadCursorA
 0x48c5c4 LoadBitmapA
 0x48c5c8 KillTimer
 0x48c5cc IsZoomed
 0x48c5d0 IsWindowVisible
 0x48c5d4 IsWindowEnabled
 0x48c5d8 IsWindow
 0x48c5dc IsRectEmpty
 0x48c5e0 IsIconic
 0x48c5e4 IsDialogMessageA
 0x48c5e8 IsChild
 0x48c5ec InvalidateRect
 0x48c5f0 IntersectRect
 0x48c5f4 InsertMenuItemA
 0x48c5f8 InsertMenuA
 0x48c5fc InflateRect
 0x48c600 HideCaret
 0x48c604 GetWindowThreadProcessId
 0x48c608 GetWindowTextA
 0x48c60c GetWindowRect
 0x48c610 GetWindowPlacement
 0x48c614 GetWindowLongA
 0x48c618 GetWindowDC
 0x48c61c GetTopWindow
 0x48c620 GetSystemMetrics
 0x48c624 GetSystemMenu
 0x48c628 GetSysColorBrush
 0x48c62c GetSysColor
 0x48c630 GetSubMenu
 0x48c634 GetScrollRange
 0x48c638 GetScrollPos
 0x48c63c GetScrollInfo
 0x48c640 GetPropA
 0x48c644 GetParent
 0x48c648 GetWindow
 0x48c64c GetMessageA
 0x48c650 GetMenuStringA
 0x48c654 GetMenuState
 0x48c658 GetMenuItemInfoA
 0x48c65c GetMenuItemID
 0x48c660 GetMenuItemCount
 0x48c664 GetMenu
 0x48c668 GetLastActivePopup
 0x48c66c GetKeyboardState
 0x48c670 GetKeyboardLayoutList
 0x48c674 GetKeyboardLayout
 0x48c678 GetKeyState
 0x48c67c GetKeyNameTextA
 0x48c680 GetIconInfo
 0x48c684 GetForegroundWindow
 0x48c688 GetFocus
 0x48c68c GetDesktopWindow
 0x48c690 GetDCEx
 0x48c694 GetDC
 0x48c698 GetCursorPos
 0x48c69c GetCursor
 0x48c6a0 GetClipboardData
 0x48c6a4 GetClientRect
 0x48c6a8 GetClassNameA
 0x48c6ac GetClassInfoA
 0x48c6b0 GetCapture
 0x48c6b4 GetAsyncKeyState
 0x48c6b8 GetActiveWindow
 0x48c6bc FrameRect
 0x48c6c0 FindWindowA
 0x48c6c4 FillRect
 0x48c6c8 EqualRect
 0x48c6cc EnumWindows
 0x48c6d0 EnumThreadWindows
 0x48c6d4 EndPaint
 0x48c6d8 EnableWindow
 0x48c6dc EnableScrollBar
 0x48c6e0 EnableMenuItem
 0x48c6e4 EmptyClipboard
 0x48c6e8 DrawTextA
 0x48c6ec DrawStateA
 0x48c6f0 DrawMenuBar
 0x48c6f4 DrawIconEx
 0x48c6f8 DrawIcon
 0x48c6fc DrawFrameControl
 0x48c700 DrawEdge
 0x48c704 DispatchMessageA
 0x48c708 DestroyWindow
 0x48c70c DestroyMenu
 0x48c710 DestroyIcon
 0x48c714 DestroyCursor
 0x48c718 DeleteMenu
 0x48c71c DefWindowProcA
 0x48c720 DefMDIChildProcA
 0x48c724 DefFrameProcA
 0x48c728 CreatePopupMenu
 0x48c72c CreateMenu
 0x48c730 CreateIcon
 0x48c734 CloseClipboard
 0x48c738 ClientToScreen
 0x48c73c CheckMenuItem
 0x48c740 CallWindowProcA
 0x48c744 CallNextHookEx
 0x48c748 BeginPaint
 0x48c74c CharNextA
 0x48c750 CharLowerBuffA
 0x48c754 CharLowerA
 0x48c758 CharUpperBuffA
 0x48c75c CharToOemA
 0x48c760 AdjustWindowRectEx
 0x48c764 ActivateKeyboardLayout
kernel32.dll
 0x48c76c Sleep
oleaut32.dll
 0x48c774 SafeArrayPtrOfIndex
 0x48c778 SafeArrayGetUBound
 0x48c77c SafeArrayGetLBound
 0x48c780 SafeArrayCreate
 0x48c784 VariantChangeType
 0x48c788 VariantCopy
 0x48c78c VariantClear
 0x48c790 VariantInit
ole32.dll
 0x48c798 CoTaskMemAlloc
 0x48c79c CoCreateInstance
 0x48c7a0 CoUninitialize
 0x48c7a4 CoInitialize
oleaut32.dll
 0x48c7ac GetErrorInfo
 0x48c7b0 SysFreeString
comctl32.dll
 0x48c7b8 ImageList_SetIconSize
 0x48c7bc ImageList_GetIconSize
 0x48c7c0 ImageList_Write
 0x48c7c4 ImageList_Read
 0x48c7c8 ImageList_GetDragImage
 0x48c7cc ImageList_DragShowNolock
 0x48c7d0 ImageList_SetDragCursorImage
 0x48c7d4 ImageList_DragMove
 0x48c7d8 ImageList_DragLeave
 0x48c7dc ImageList_DragEnter
 0x48c7e0 ImageList_EndDrag
 0x48c7e4 ImageList_BeginDrag
 0x48c7e8 ImageList_Remove
 0x48c7ec ImageList_DrawEx
 0x48c7f0 ImageList_Replace
 0x48c7f4 ImageList_Draw
 0x48c7f8 ImageList_GetBkColor
 0x48c7fc ImageList_SetBkColor
 0x48c800 ImageList_ReplaceIcon
 0x48c804 ImageList_Add
 0x48c808 ImageList_GetImageCount
 0x48c80c ImageList_Destroy
 0x48c810 ImageList_Create
 0x48c814 InitCommonControls
advapi32.dll
 0x48c81c StartServiceCtrlDispatcherA
 0x48c820 SetServiceStatus
 0x48c824 RegisterServiceCtrlHandlerA
 0x48c828 OpenServiceA
 0x48c82c OpenSCManagerA
 0x48c830 DeleteService
 0x48c834 CreateServiceA
 0x48c838 CloseServiceHandle
winmm.dll
 0x48c840 sndPlaySoundA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure