Report - PhonerLite.exe

Generic Malware Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2025.03.12 11:32 Machine s1_win7_x6403
Filename PhonerLite.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.2
ZERO API file : clean
VT API (file) 9 detected (GenHeur, Attribute, HighConfidence, FileRepMalware, Misc, Lazzzy, LESS, bWQ1Og6wKL3, L99owq91QCDCIRU, Amonetize)
md5 0eb028bdff2fdf68c2af754020c22115
sha256 e7995b48dc422414a4d71dfade2a83f016f13765d05d5848f700fc3f1eec8097
ssdeep 49152:qnRRxEykWcQsCDI9gYoLTikFu98w8njwbf80:qnxyXLCDVLTtjE80
imphash 26ffa850ecec7dfbdec189ae045b205b
impfuzzy 192:P3l+euu7oSUvfK9B/YopqL8J1fc7XcDuCF9O6Z11gLZbUtaPOQB97k2:P397p9BXboIZ1gLZ5POQ/x
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 9 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (6cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x58021c DeleteCriticalSection
 0x580220 LeaveCriticalSection
 0x580224 EnterCriticalSection
 0x580228 InitializeCriticalSection
 0x58022c VirtualFree
 0x580230 VirtualAlloc
 0x580234 LocalFree
 0x580238 LocalAlloc
 0x58023c GetVersion
 0x580240 GetCurrentThreadId
 0x580244 InterlockedDecrement
 0x580248 InterlockedIncrement
 0x58024c VirtualQuery
 0x580250 WideCharToMultiByte
 0x580254 MultiByteToWideChar
 0x580258 lstrlenA
 0x58025c lstrcpynA
 0x580260 LoadLibraryExA
 0x580264 GetThreadLocale
 0x580268 GetStartupInfoA
 0x58026c GetProcAddress
 0x580270 GetModuleHandleA
 0x580274 GetModuleFileNameA
 0x580278 GetLocaleInfoA
 0x58027c GetLastError
 0x580280 GetCommandLineA
 0x580284 FreeLibrary
 0x580288 FindFirstFileA
 0x58028c FindClose
 0x580290 ExitProcess
 0x580294 ExitThread
 0x580298 CreateThread
 0x58029c WriteFile
 0x5802a0 UnhandledExceptionFilter
 0x5802a4 SetFilePointer
 0x5802a8 SetEndOfFile
 0x5802ac RtlUnwind
 0x5802b0 ReadFile
 0x5802b4 RaiseException
 0x5802b8 GetStdHandle
 0x5802bc GetFileSize
 0x5802c0 GetFileType
 0x5802c4 CreateFileA
 0x5802c8 CloseHandle
user32.dll
 0x5802d0 GetKeyboardType
 0x5802d4 LoadStringA
 0x5802d8 MessageBoxA
 0x5802dc CharNextA
advapi32.dll
 0x5802e4 RegQueryValueExA
 0x5802e8 RegOpenKeyExA
 0x5802ec RegCloseKey
oleaut32.dll
 0x5802f4 SysFreeString
 0x5802f8 SysReAllocStringLen
 0x5802fc SysAllocStringLen
kernel32.dll
 0x580304 TlsSetValue
 0x580308 TlsGetValue
 0x58030c LocalAlloc
 0x580310 GetModuleHandleA
user32.dll
 0x580318 CreateWindowExW
 0x58031c CreateWindowExA
 0x580320 WindowFromPoint
 0x580324 WinHelpA
 0x580328 WaitMessage
 0x58032c VkKeyScanW
 0x580330 ValidateRect
 0x580334 UpdateWindow
 0x580338 UnregisterClassW
 0x58033c UnregisterClassA
 0x580340 UnionRect
 0x580344 UnhookWindowsHookEx
 0x580348 TranslateMessage
 0x58034c TranslateMDISysAccel
 0x580350 TrackPopupMenu
 0x580354 SystemParametersInfoA
 0x580358 ShowWindow
 0x58035c ShowScrollBar
 0x580360 ShowOwnedPopups
 0x580364 ShowCursor
 0x580368 SetWindowsHookExW
 0x58036c SetWindowsHookExA
 0x580370 SetWindowTextW
 0x580374 SetWindowTextA
 0x580378 SetWindowPos
 0x58037c SetWindowPlacement
 0x580380 SetWindowLongW
 0x580384 SetWindowLongA
 0x580388 SetTimer
 0x58038c SetScrollRange
 0x580390 SetScrollPos
 0x580394 SetScrollInfo
 0x580398 SetRect
 0x58039c SetPropA
 0x5803a0 SetParent
 0x5803a4 SetMenuItemInfoW
 0x5803a8 SetMenuItemInfoA
 0x5803ac SetMenu
 0x5803b0 SetKeyboardState
 0x5803b4 SetForegroundWindow
 0x5803b8 SetFocus
 0x5803bc SetCursor
 0x5803c0 SetClipboardData
 0x5803c4 SetClassLongA
 0x5803c8 SetCapture
 0x5803cc SetActiveWindow
 0x5803d0 SendMessageW
 0x5803d4 SendMessageA
 0x5803d8 ScrollWindowEx
 0x5803dc ScrollWindow
 0x5803e0 ScreenToClient
 0x5803e4 RemovePropA
 0x5803e8 RemoveMenu
 0x5803ec ReleaseDC
 0x5803f0 ReleaseCapture
 0x5803f4 RegisterWindowMessageA
 0x5803f8 RegisterClipboardFormatA
 0x5803fc RegisterClassW
 0x580400 RegisterClassA
 0x580404 RedrawWindow
 0x580408 PtInRect
 0x58040c PostQuitMessage
 0x580410 PostMessageW
 0x580414 PostMessageA
 0x580418 PeekMessageA
 0x58041c OpenClipboard
 0x580420 OffsetRect
 0x580424 OemToCharA
 0x580428 MsgWaitForMultipleObjects
 0x58042c MessageBoxA
 0x580430 MessageBeep
 0x580434 MapWindowPoints
 0x580438 MapVirtualKeyW
 0x58043c MapVirtualKeyA
 0x580440 LoadStringW
 0x580444 LoadStringA
 0x580448 LoadKeyboardLayoutA
 0x58044c LoadIconA
 0x580450 LoadCursorA
 0x580454 LoadBitmapA
 0x580458 KillTimer
 0x58045c IsZoomed
 0x580460 IsWindowVisible
 0x580464 IsWindowUnicode
 0x580468 IsWindowEnabled
 0x58046c IsWindow
 0x580470 IsRectEmpty
 0x580474 IsIconic
 0x580478 IsDialogMessageW
 0x58047c IsDialogMessageA
 0x580480 IsClipboardFormatAvailable
 0x580484 IsChild
 0x580488 IsCharAlphaNumericA
 0x58048c IsCharAlphaA
 0x580490 InvalidateRect
 0x580494 IntersectRect
 0x580498 InsertMenuItemA
 0x58049c InsertMenuA
 0x5804a0 InflateRect
 0x5804a4 GetWindowThreadProcessId
 0x5804a8 GetWindowTextLengthW
 0x5804ac GetWindowTextW
 0x5804b0 GetWindowTextA
 0x5804b4 GetWindowRect
 0x5804b8 GetWindowPlacement
 0x5804bc GetWindowLongW
 0x5804c0 GetWindowLongA
 0x5804c4 GetWindowDC
 0x5804c8 GetTopWindow
 0x5804cc GetSystemMetrics
 0x5804d0 GetSystemMenu
 0x5804d4 GetSysColorBrush
 0x5804d8 GetSysColor
 0x5804dc GetSubMenu
 0x5804e0 GetScrollRange
 0x5804e4 GetScrollPos
 0x5804e8 GetScrollInfo
 0x5804ec GetPropA
 0x5804f0 GetParent
 0x5804f4 GetWindow
 0x5804f8 GetMessageTime
 0x5804fc GetMessagePos
 0x580500 GetMenuStringW
 0x580504 GetMenuStringA
 0x580508 GetMenuState
 0x58050c GetMenuItemInfoW
 0x580510 GetMenuItemInfoA
 0x580514 GetMenuItemID
 0x580518 GetMenuItemCount
 0x58051c GetMenu
 0x580520 GetLastActivePopup
 0x580524 GetKeyboardState
 0x580528 GetKeyboardLayoutList
 0x58052c GetKeyboardLayout
 0x580530 GetKeyState
 0x580534 GetKeyNameTextW
 0x580538 GetKeyNameTextA
 0x58053c GetIconInfo
 0x580540 GetForegroundWindow
 0x580544 GetFocus
 0x580548 GetDoubleClickTime
 0x58054c GetDlgItem
 0x580550 GetDesktopWindow
 0x580554 GetDCEx
 0x580558 GetDC
 0x58055c GetCursorPos
 0x580560 GetCursor
 0x580564 GetClipboardData
 0x580568 GetClientRect
 0x58056c GetClassNameW
 0x580570 GetClassNameA
 0x580574 GetClassInfoW
 0x580578 GetClassInfoA
 0x58057c GetCaretPos
 0x580580 GetCapture
 0x580584 GetActiveWindow
 0x580588 FrameRect
 0x58058c FindWindowA
 0x580590 FillRect
 0x580594 EqualRect
 0x580598 EnumWindows
 0x58059c EnumThreadWindows
 0x5805a0 EnumClipboardFormats
 0x5805a4 EndPaint
 0x5805a8 EndDeferWindowPos
 0x5805ac EnableWindow
 0x5805b0 EnableScrollBar
 0x5805b4 EnableMenuItem
 0x5805b8 EmptyClipboard
 0x5805bc DrawTextW
 0x5805c0 DrawTextA
 0x5805c4 DrawStateA
 0x5805c8 DrawMenuBar
 0x5805cc DrawIconEx
 0x5805d0 DrawIcon
 0x5805d4 DrawFrameControl
 0x5805d8 DrawFocusRect
 0x5805dc DrawEdge
 0x5805e0 DispatchMessageW
 0x5805e4 DispatchMessageA
 0x5805e8 DestroyWindow
 0x5805ec DestroyMenu
 0x5805f0 DestroyIcon
 0x5805f4 DestroyCursor
 0x5805f8 DeleteMenu
 0x5805fc DeferWindowPos
 0x580600 DefWindowProcW
 0x580604 DefWindowProcA
 0x580608 DefMDIChildProcW
 0x58060c DefMDIChildProcA
 0x580610 DefFrameProcW
 0x580614 DefFrameProcA
 0x580618 CreatePopupMenu
 0x58061c CreateMenu
 0x580620 CreateMDIWindowW
 0x580624 CreateIcon
 0x580628 CopyIcon
 0x58062c CloseClipboard
 0x580630 ClientToScreen
 0x580634 ChildWindowFromPoint
 0x580638 CheckMenuItem
 0x58063c CallWindowProcW
 0x580640 CallWindowProcA
 0x580644 CallNextHookEx
 0x580648 BeginPaint
 0x58064c BeginDeferWindowPos
 0x580650 CharNextA
 0x580654 CharLowerBuffA
 0x580658 CharLowerA
 0x58065c CharUpperBuffA
 0x580660 CharToOemA
 0x580664 AdjustWindowRectEx
 0x580668 ActivateKeyboardLayout
gdi32.dll
 0x580670 UnrealizeObject
 0x580674 StretchBlt
 0x580678 SetWindowOrgEx
 0x58067c SetWindowExtEx
 0x580680 SetWinMetaFileBits
 0x580684 SetViewportOrgEx
 0x580688 SetViewportExtEx
 0x58068c SetTextColor
 0x580690 SetStretchBltMode
 0x580694 SetROP2
 0x580698 SetPixel
 0x58069c SetMapMode
 0x5806a0 SetEnhMetaFileBits
 0x5806a4 SetDIBColorTable
 0x5806a8 SetBrushOrgEx
 0x5806ac SetBkMode
 0x5806b0 SetBkColor
 0x5806b4 SelectPalette
 0x5806b8 SelectObject
 0x5806bc SelectClipRgn
 0x5806c0 SaveDC
 0x5806c4 RoundRect
 0x5806c8 RestoreDC
 0x5806cc Rectangle
 0x5806d0 RectVisible
 0x5806d4 RealizePalette
 0x5806d8 Polyline
 0x5806dc PolyPolyline
 0x5806e0 PlayEnhMetaFile
 0x5806e4 PatBlt
 0x5806e8 MoveToEx
 0x5806ec MaskBlt
 0x5806f0 LineTo
 0x5806f4 IntersectClipRect
 0x5806f8 GetWindowOrgEx
 0x5806fc GetWinMetaFileBits
 0x580700 GetTextMetricsA
 0x580704 GetTextExtentPointA
 0x580708 GetTextExtentPoint32W
 0x58070c GetTextExtentPoint32A
 0x580710 GetSystemPaletteEntries
 0x580714 GetStockObject
 0x580718 GetRgnBox
 0x58071c GetPixel
 0x580720 GetPaletteEntries
 0x580724 GetObjectA
 0x580728 GetNearestColor
 0x58072c GetMapMode
 0x580730 GetEnhMetaFilePaletteEntries
 0x580734 GetEnhMetaFileHeader
 0x580738 GetEnhMetaFileBits
 0x58073c GetDeviceCaps
 0x580740 GetDIBits
 0x580744 GetDIBColorTable
 0x580748 GetDCOrgEx
 0x58074c GetCurrentPositionEx
 0x580750 GetClipRgn
 0x580754 GetClipBox
 0x580758 GetBrushOrgEx
 0x58075c GetBitmapBits
 0x580760 GdiFlush
 0x580764 ExtTextOutW
 0x580768 ExtTextOutA
 0x58076c ExtCreatePen
 0x580770 ExcludeClipRect
 0x580774 DeleteObject
 0x580778 DeleteEnhMetaFile
 0x58077c DeleteDC
 0x580780 CreateSolidBrush
 0x580784 CreateRectRgn
 0x580788 CreatePenIndirect
 0x58078c CreatePalette
 0x580790 CreateHalftonePalette
 0x580794 CreateFontIndirectA
 0x580798 CreateDIBitmap
 0x58079c CreateDIBSection
 0x5807a0 CreateCompatibleDC
 0x5807a4 CreateCompatibleBitmap
 0x5807a8 CreateBrushIndirect
 0x5807ac CreateBitmap
 0x5807b0 CopyEnhMetaFileA
 0x5807b4 CombineRgn
 0x5807b8 BitBlt
version.dll
 0x5807c0 VerQueryValueA
 0x5807c4 GetFileVersionInfoSizeA
 0x5807c8 GetFileVersionInfoA
kernel32.dll
 0x5807d0 lstrcpynA
 0x5807d4 lstrcpyA
 0x5807d8 lstrcmpW
 0x5807dc lstrcmpA
 0x5807e0 WriteProcessMemory
 0x5807e4 WriteFile
 0x5807e8 WideCharToMultiByte
 0x5807ec WaitForSingleObject
 0x5807f0 VirtualQuery
 0x5807f4 VirtualProtectEx
 0x5807f8 VirtualProtect
 0x5807fc VirtualFree
 0x580800 VirtualAlloc
 0x580804 UnmapViewOfFile
 0x580808 TerminateThread
 0x58080c SuspendThread
 0x580810 Sleep
 0x580814 SizeofResource
 0x580818 SetUnhandledExceptionFilter
 0x58081c SetThreadPriority
 0x580820 SetThreadLocale
 0x580824 SetLastError
 0x580828 SetFileTime
 0x58082c SetFilePointer
 0x580830 SetFileAttributesW
 0x580834 SetFileAttributesA
 0x580838 SetEvent
 0x58083c SetErrorMode
 0x580840 SetEndOfFile
 0x580844 ResumeThread
 0x580848 ResetEvent
 0x58084c ReleaseMutex
 0x580850 ReadProcessMemory
 0x580854 ReadFile
 0x580858 QueryPerformanceFrequency
 0x58085c QueryPerformanceCounter
 0x580860 OutputDebugStringA
 0x580864 OpenMutexA
 0x580868 OpenFileMappingA
 0x58086c MultiByteToWideChar
 0x580870 MulDiv
 0x580874 MoveFileA
 0x580878 MapViewOfFile
 0x58087c LockResource
 0x580880 LoadResource
 0x580884 LoadLibraryExA
 0x580888 LoadLibraryA
 0x58088c LeaveCriticalSection
 0x580890 IsBadReadPtr
 0x580894 InitializeCriticalSection
 0x580898 GlobalUnlock
 0x58089c GlobalSize
 0x5808a0 GlobalReAlloc
 0x5808a4 GlobalHandle
 0x5808a8 GlobalLock
 0x5808ac GlobalFree
 0x5808b0 GlobalFindAtomA
 0x5808b4 GlobalDeleteAtom
 0x5808b8 GlobalAlloc
 0x5808bc GlobalAddAtomA
 0x5808c0 GetVersionExA
 0x5808c4 GetVersion
 0x5808c8 GetUserDefaultLCID
 0x5808cc GetTimeZoneInformation
 0x5808d0 GetTickCount
 0x5808d4 GetThreadLocale
 0x5808d8 GetTempPathA
 0x5808dc GetSystemInfo
 0x5808e0 GetStringTypeExA
 0x5808e4 GetStdHandle
 0x5808e8 GetShortPathNameW
 0x5808ec GetShortPathNameA
 0x5808f0 GetProcAddress
 0x5808f4 GetModuleHandleA
 0x5808f8 GetModuleFileNameW
 0x5808fc GetModuleFileNameA
 0x580900 GetLocaleInfoA
 0x580904 GetLocalTime
 0x580908 GetLastError
 0x58090c GetFullPathNameW
 0x580910 GetFullPathNameA
 0x580914 GetFileTime
 0x580918 GetFileSize
 0x58091c GetFileInformationByHandle
 0x580920 GetFileAttributesW
 0x580924 GetFileAttributesA
 0x580928 GetExitCodeThread
 0x58092c GetExitCodeProcess
 0x580930 GetEnvironmentVariableA
 0x580934 GetDiskFreeSpaceA
 0x580938 GetDateFormatA
 0x58093c GetCurrentThreadId
 0x580940 GetCurrentProcessId
 0x580944 GetCurrentProcess
 0x580948 GetComputerNameA
 0x58094c GetCommandLineW
 0x580950 GetCPInfo
 0x580954 GetACP
 0x580958 FreeResource
 0x58095c InterlockedIncrement
 0x580960 InterlockedExchange
 0x580964 InterlockedDecrement
 0x580968 InterlockedCompareExchange
 0x58096c FreeLibrary
 0x580970 FormatMessageW
 0x580974 FormatMessageA
 0x580978 FlushInstructionCache
 0x58097c FlushFileBuffers
 0x580980 FindResourceA
 0x580984 FindNextFileW
 0x580988 FindNextFileA
 0x58098c FindFirstFileW
 0x580990 FindFirstFileA
 0x580994 FindClose
 0x580998 FileTimeToLocalFileTime
 0x58099c FileTimeToDosDateTime
 0x5809a0 EnumCalendarInfoA
 0x5809a4 EnterCriticalSection
 0x5809a8 DeleteFileW
 0x5809ac DeleteFileA
 0x5809b0 DeleteCriticalSection
 0x5809b4 CreateThread
 0x5809b8 CreateProcessW
 0x5809bc CreateProcessA
 0x5809c0 CreatePipe
 0x5809c4 CreateMutexA
 0x5809c8 CreateFileMappingA
 0x5809cc CreateFileW
 0x5809d0 CreateFileA
 0x5809d4 CreateEventA
 0x5809d8 CopyFileA
 0x5809dc CompareStringW
 0x5809e0 CompareStringA
 0x5809e4 CloseHandle
advapi32.dll
 0x5809ec SetSecurityDescriptorDacl
 0x5809f0 RegSetValueExA
 0x5809f4 RegQueryValueExW
 0x5809f8 RegQueryValueExA
 0x5809fc RegQueryInfoKeyA
 0x580a00 RegOpenKeyExW
 0x580a04 RegOpenKeyExA
 0x580a08 RegFlushKey
 0x580a0c RegEnumKeyExA
 0x580a10 RegDeleteKeyA
 0x580a14 RegCreateKeyExA
 0x580a18 RegCloseKey
 0x580a1c InitializeSecurityDescriptor
kernel32.dll
 0x580a24 Sleep
ole32.dll
 0x580a2c CLSIDFromString
user32.dll
 0x580a34 wsprintfA
oleaut32.dll
 0x580a3c SafeArrayPtrOfIndex
 0x580a40 SafeArrayGetUBound
 0x580a44 SafeArrayGetLBound
 0x580a48 SafeArrayCreate
 0x580a4c VariantChangeType
 0x580a50 VariantCopy
 0x580a54 VariantClear
 0x580a58 VariantInit
oleaut32.dll
 0x580a60 GetErrorInfo
 0x580a64 GetActiveObject
 0x580a68 SysFreeString
ole32.dll
 0x580a70 CoTaskMemFree
 0x580a74 CoTaskMemAlloc
 0x580a78 ProgIDFromCLSID
 0x580a7c StringFromCLSID
 0x580a80 CoCreateInstance
 0x580a84 CoUninitialize
 0x580a88 CoInitialize
 0x580a8c IsEqualGUID
comctl32.dll
 0x580a94 ImageList_SetIconSize
 0x580a98 ImageList_GetIconSize
 0x580a9c ImageList_Write
 0x580aa0 ImageList_Read
 0x580aa4 ImageList_GetDragImage
 0x580aa8 ImageList_DragShowNolock
 0x580aac ImageList_SetDragCursorImage
 0x580ab0 ImageList_DragMove
 0x580ab4 ImageList_DragLeave
 0x580ab8 ImageList_DragEnter
 0x580abc ImageList_EndDrag
 0x580ac0 ImageList_BeginDrag
 0x580ac4 ImageList_Remove
 0x580ac8 ImageList_DrawEx
 0x580acc ImageList_Replace
 0x580ad0 ImageList_Draw
 0x580ad4 ImageList_GetBkColor
 0x580ad8 ImageList_SetBkColor
 0x580adc ImageList_ReplaceIcon
 0x580ae0 ImageList_Add
 0x580ae4 ImageList_GetImageCount
 0x580ae8 ImageList_Destroy
 0x580aec ImageList_Create
 0x580af0 InitCommonControls
shell32.dll
 0x580af8 ShellExecuteW
 0x580afc ShellExecuteA
 0x580b00 DragQueryPoint
 0x580b04 DragQueryFileW
 0x580b08 DragQueryFileA
 0x580b0c DragAcceptFiles
wininet.dll
 0x580b14 InternetQueryOptionA
shell32.dll
 0x580b1c SHGetPathFromIDListW
 0x580b20 SHGetMalloc
 0x580b24 SHGetDesktopFolder
 0x580b28 SHBrowseForFolderW
comdlg32.dll
 0x580b30 ChooseColorA
 0x580b34 GetOpenFileNameW
 0x580b38 GetOpenFileNameA
kernel32.dll
 0x580b40 MulDiv
hhctrl.ocx
 0x580b48 HtmlHelpA
KERNEL32
 0x580b50 GetCPInfoExA
dsound.dll
 0x580b58 DirectSoundEnumerateA
 0x580b5c DirectSoundCreate
kernel32.dll
 0x580b64 GetVersionExA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure