Report - setup.exe

Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2025.03.26 11:29 Machine s1_win7_x6401
Filename setup.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
2.6
ZERO API
VT API (file) 51 detected (AIDetectMalware, mxGG, Malicious, score, DealPly, Bundler, Unsafe, Save, grayware, confidence, 100%, Attribute, HighConfidence, high confidence, duzogl, Bitrep, xLToyuYeu0P, AGEN, Tool, R002C0RCB25, Real Protect, Generic Reputation PUA, b@5xdvtf, Bitrepeyp, Eldorado, Artemis, FZR2Gg4m0, susgen)
md5 4a7a12a9e10dff157ee2b2bd9d8853ba
sha256 9d3373fb5fa7e9dbc382c18f7e26fd85f1279598e88edfe76bef94053c9f7278
ssdeep 12288:91naFROcKytK+kJ4ewy4wGLnrZlLc4j2mFjmPrS2Q6ObyK:9hqOqK+i45IGjrTLhjh0O2Q6RK
imphash 6449ca82714ecccc916c3a676abc3223
impfuzzy 192:t31W31QdbuuS9SUvK9RqQoqE6qebOQRBEj9:t3+1kSu9fKebOQc
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 51 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
46.246.80.65 SE GleSYS AB 46.246.80.65

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x48d12c DeleteCriticalSection
 0x48d130 LeaveCriticalSection
 0x48d134 EnterCriticalSection
 0x48d138 InitializeCriticalSection
 0x48d13c VirtualFree
 0x48d140 VirtualAlloc
 0x48d144 LocalFree
 0x48d148 LocalAlloc
 0x48d14c GetCurrentThreadId
 0x48d150 InterlockedDecrement
 0x48d154 InterlockedIncrement
 0x48d158 VirtualQuery
 0x48d15c WideCharToMultiByte
 0x48d160 MultiByteToWideChar
 0x48d164 lstrlenA
 0x48d168 lstrcpynA
 0x48d16c LoadLibraryExA
 0x48d170 GetThreadLocale
 0x48d174 GetStartupInfoA
 0x48d178 GetProcAddress
 0x48d17c GetModuleHandleA
 0x48d180 GetModuleFileNameA
 0x48d184 GetLocaleInfoA
 0x48d188 GetLastError
 0x48d18c GetCommandLineA
 0x48d190 FreeLibrary
 0x48d194 FindFirstFileA
 0x48d198 FindClose
 0x48d19c ExitProcess
 0x48d1a0 WriteFile
 0x48d1a4 UnhandledExceptionFilter
 0x48d1a8 SetFilePointer
 0x48d1ac SetEndOfFile
 0x48d1b0 RtlUnwind
 0x48d1b4 ReadFile
 0x48d1b8 RaiseException
 0x48d1bc GetStdHandle
 0x48d1c0 GetFileSize
 0x48d1c4 GetSystemTime
 0x48d1c8 GetFileType
 0x48d1cc CreateFileA
 0x48d1d0 CloseHandle
user32.dll
 0x48d1d8 GetKeyboardType
 0x48d1dc LoadStringA
 0x48d1e0 MessageBoxA
 0x48d1e4 CharNextA
advapi32.dll
 0x48d1ec RegQueryValueExA
 0x48d1f0 RegOpenKeyExA
 0x48d1f4 RegCloseKey
oleaut32.dll
 0x48d1fc SysFreeString
 0x48d200 SysReAllocStringLen
 0x48d204 SysAllocStringLen
kernel32.dll
 0x48d20c TlsSetValue
 0x48d210 TlsGetValue
 0x48d214 LocalAlloc
 0x48d218 GetModuleHandleA
advapi32.dll
 0x48d220 RegQueryValueExA
 0x48d224 RegOpenKeyExA
 0x48d228 RegCloseKey
kernel32.dll
 0x48d230 lstrcpyA
 0x48d234 WriteFile
 0x48d238 WaitForSingleObject
 0x48d23c VirtualQuery
 0x48d240 VirtualAlloc
 0x48d244 Sleep
 0x48d248 SizeofResource
 0x48d24c SetThreadLocale
 0x48d250 SetFilePointer
 0x48d254 SetEvent
 0x48d258 SetErrorMode
 0x48d25c SetEndOfFile
 0x48d260 ResetEvent
 0x48d264 ReadFile
 0x48d268 MulDiv
 0x48d26c LockResource
 0x48d270 LoadResource
 0x48d274 LoadLibraryA
 0x48d278 LeaveCriticalSection
 0x48d27c InitializeCriticalSection
 0x48d280 GlobalUnlock
 0x48d284 GlobalReAlloc
 0x48d288 GlobalHandle
 0x48d28c GlobalLock
 0x48d290 GlobalFree
 0x48d294 GlobalFindAtomA
 0x48d298 GlobalDeleteAtom
 0x48d29c GlobalAlloc
 0x48d2a0 GlobalAddAtomA
 0x48d2a4 GetVersionExA
 0x48d2a8 GetVersion
 0x48d2ac GetTickCount
 0x48d2b0 GetThreadLocale
 0x48d2b4 GetSystemInfo
 0x48d2b8 GetStringTypeExA
 0x48d2bc GetStdHandle
 0x48d2c0 GetProcAddress
 0x48d2c4 GetModuleHandleA
 0x48d2c8 GetModuleFileNameA
 0x48d2cc GetLocaleInfoA
 0x48d2d0 GetLastError
 0x48d2d4 GetDiskFreeSpaceA
 0x48d2d8 GetCurrentThreadId
 0x48d2dc GetCurrentProcessId
 0x48d2e0 GetCPInfo
 0x48d2e4 GetACP
 0x48d2e8 FreeResource
 0x48d2ec FreeLibrary
 0x48d2f0 FormatMessageA
 0x48d2f4 FindResourceA
 0x48d2f8 EnumCalendarInfoA
 0x48d2fc EnterCriticalSection
 0x48d300 DeleteCriticalSection
 0x48d304 CreateThread
 0x48d308 CreateFileA
 0x48d30c CreateEventA
 0x48d310 CompareStringA
 0x48d314 CloseHandle
gdi32.dll
 0x48d31c UnrealizeObject
 0x48d320 StretchBlt
 0x48d324 SetWindowOrgEx
 0x48d328 SetViewportOrgEx
 0x48d32c SetTextColor
 0x48d330 SetStretchBltMode
 0x48d334 SetROP2
 0x48d338 SetPixel
 0x48d33c SetDIBColorTable
 0x48d340 SetBrushOrgEx
 0x48d344 SetBkMode
 0x48d348 SetBkColor
 0x48d34c SelectPalette
 0x48d350 SelectObject
 0x48d354 SaveDC
 0x48d358 RestoreDC
 0x48d35c RectVisible
 0x48d360 RealizePalette
 0x48d364 PatBlt
 0x48d368 MoveToEx
 0x48d36c MaskBlt
 0x48d370 LineTo
 0x48d374 IntersectClipRect
 0x48d378 GetWindowOrgEx
 0x48d37c GetTextMetricsA
 0x48d380 GetTextExtentPoint32A
 0x48d384 GetSystemPaletteEntries
 0x48d388 GetStockObject
 0x48d38c GetPixel
 0x48d390 GetPaletteEntries
 0x48d394 GetObjectA
 0x48d398 GetDeviceCaps
 0x48d39c GetDIBits
 0x48d3a0 GetDIBColorTable
 0x48d3a4 GetDCOrgEx
 0x48d3a8 GetCurrentPositionEx
 0x48d3ac GetClipBox
 0x48d3b0 GetBrushOrgEx
 0x48d3b4 GetBitmapBits
 0x48d3b8 ExcludeClipRect
 0x48d3bc DeleteObject
 0x48d3c0 DeleteDC
 0x48d3c4 CreateSolidBrush
 0x48d3c8 CreatePenIndirect
 0x48d3cc CreatePalette
 0x48d3d0 CreateHalftonePalette
 0x48d3d4 CreateFontIndirectA
 0x48d3d8 CreateDIBitmap
 0x48d3dc CreateDIBSection
 0x48d3e0 CreateCompatibleDC
 0x48d3e4 CreateCompatibleBitmap
 0x48d3e8 CreateBrushIndirect
 0x48d3ec CreateBitmap
 0x48d3f0 BitBlt
user32.dll
 0x48d3f8 WindowFromPoint
 0x48d3fc WinHelpA
 0x48d400 WaitMessage
 0x48d404 UpdateWindow
 0x48d408 UnregisterClassA
 0x48d40c UnhookWindowsHookEx
 0x48d410 TranslateMessage
 0x48d414 TranslateMDISysAccel
 0x48d418 TrackPopupMenu
 0x48d41c SystemParametersInfoA
 0x48d420 ShowWindow
 0x48d424 ShowScrollBar
 0x48d428 ShowOwnedPopups
 0x48d42c ShowCursor
 0x48d430 SetWindowsHookExA
 0x48d434 SetWindowPos
 0x48d438 SetWindowPlacement
 0x48d43c SetWindowLongA
 0x48d440 SetTimer
 0x48d444 SetScrollRange
 0x48d448 SetScrollPos
 0x48d44c SetScrollInfo
 0x48d450 SetRect
 0x48d454 SetPropA
 0x48d458 SetMenuItemInfoA
 0x48d45c SetMenu
 0x48d460 SetForegroundWindow
 0x48d464 SetFocus
 0x48d468 SetCursor
 0x48d46c SetClassLongA
 0x48d470 SetCapture
 0x48d474 SetActiveWindow
 0x48d478 SendMessageA
 0x48d47c ScrollWindow
 0x48d480 ScreenToClient
 0x48d484 RemovePropA
 0x48d488 RemoveMenu
 0x48d48c ReleaseDC
 0x48d490 ReleaseCapture
 0x48d494 RegisterWindowMessageA
 0x48d498 RegisterClipboardFormatA
 0x48d49c RegisterClassA
 0x48d4a0 RedrawWindow
 0x48d4a4 PtInRect
 0x48d4a8 PostQuitMessage
 0x48d4ac PostMessageA
 0x48d4b0 PeekMessageA
 0x48d4b4 OffsetRect
 0x48d4b8 OemToCharA
 0x48d4bc MessageBoxA
 0x48d4c0 MapWindowPoints
 0x48d4c4 MapVirtualKeyA
 0x48d4c8 LoadStringA
 0x48d4cc LoadKeyboardLayoutA
 0x48d4d0 LoadIconA
 0x48d4d4 LoadCursorA
 0x48d4d8 LoadBitmapA
 0x48d4dc KillTimer
 0x48d4e0 IsZoomed
 0x48d4e4 IsWindowVisible
 0x48d4e8 IsWindowEnabled
 0x48d4ec IsWindow
 0x48d4f0 IsRectEmpty
 0x48d4f4 IsIconic
 0x48d4f8 IsDialogMessageA
 0x48d4fc IsChild
 0x48d500 InvalidateRect
 0x48d504 IntersectRect
 0x48d508 InsertMenuItemA
 0x48d50c InsertMenuA
 0x48d510 InflateRect
 0x48d514 GetWindowThreadProcessId
 0x48d518 GetWindowTextA
 0x48d51c GetWindowRect
 0x48d520 GetWindowPlacement
 0x48d524 GetWindowLongA
 0x48d528 GetWindowDC
 0x48d52c GetTopWindow
 0x48d530 GetSystemMetrics
 0x48d534 GetSystemMenu
 0x48d538 GetSysColor
 0x48d53c GetSubMenu
 0x48d540 GetScrollRange
 0x48d544 GetScrollPos
 0x48d548 GetScrollInfo
 0x48d54c GetPropA
 0x48d550 GetParent
 0x48d554 GetWindow
 0x48d558 GetMenuStringA
 0x48d55c GetMenuState
 0x48d560 GetMenuItemInfoA
 0x48d564 GetMenuItemID
 0x48d568 GetMenuItemCount
 0x48d56c GetMenu
 0x48d570 GetLastActivePopup
 0x48d574 GetKeyboardState
 0x48d578 GetKeyboardLayoutList
 0x48d57c GetKeyboardLayout
 0x48d580 GetKeyState
 0x48d584 GetKeyNameTextA
 0x48d588 GetIconInfo
 0x48d58c GetForegroundWindow
 0x48d590 GetFocus
 0x48d594 GetDesktopWindow
 0x48d598 GetDCEx
 0x48d59c GetDC
 0x48d5a0 GetCursorPos
 0x48d5a4 GetCursor
 0x48d5a8 GetClientRect
 0x48d5ac GetClassNameA
 0x48d5b0 GetClassInfoA
 0x48d5b4 GetCapture
 0x48d5b8 GetActiveWindow
 0x48d5bc FrameRect
 0x48d5c0 FindWindowA
 0x48d5c4 FillRect
 0x48d5c8 EqualRect
 0x48d5cc EnumWindows
 0x48d5d0 EnumThreadWindows
 0x48d5d4 EndPaint
 0x48d5d8 EnableWindow
 0x48d5dc EnableScrollBar
 0x48d5e0 EnableMenuItem
 0x48d5e4 DrawTextA
 0x48d5e8 DrawMenuBar
 0x48d5ec DrawIconEx
 0x48d5f0 DrawIcon
 0x48d5f4 DrawFrameControl
 0x48d5f8 DrawEdge
 0x48d5fc DispatchMessageA
 0x48d600 DestroyWindow
 0x48d604 DestroyMenu
 0x48d608 DestroyIcon
 0x48d60c DestroyCursor
 0x48d610 DeleteMenu
 0x48d614 DefWindowProcA
 0x48d618 DefMDIChildProcA
 0x48d61c DefFrameProcA
 0x48d620 CreateWindowExA
 0x48d624 CreatePopupMenu
 0x48d628 CreateMenu
 0x48d62c CreateIcon
 0x48d630 ClientToScreen
 0x48d634 CheckMenuItem
 0x48d638 CallWindowProcA
 0x48d63c CallNextHookEx
 0x48d640 BeginPaint
 0x48d644 CharNextA
 0x48d648 CharLowerA
 0x48d64c AdjustWindowRectEx
 0x48d650 ActivateKeyboardLayout
kernel32.dll
 0x48d658 Sleep
oleaut32.dll
 0x48d660 SafeArrayPtrOfIndex
 0x48d664 SafeArrayPutElement
 0x48d668 SafeArrayGetElement
 0x48d66c SafeArrayGetUBound
 0x48d670 SafeArrayGetLBound
 0x48d674 SafeArrayRedim
 0x48d678 SafeArrayCreate
 0x48d67c VariantChangeTypeEx
 0x48d680 VariantCopyInd
 0x48d684 VariantCopy
 0x48d688 VariantClear
 0x48d68c VariantInit
comctl32.dll
 0x48d694 ImageList_SetIconSize
 0x48d698 ImageList_GetIconSize
 0x48d69c ImageList_Write
 0x48d6a0 ImageList_Read
 0x48d6a4 ImageList_GetDragImage
 0x48d6a8 ImageList_DragShowNolock
 0x48d6ac ImageList_SetDragCursorImage
 0x48d6b0 ImageList_DragMove
 0x48d6b4 ImageList_DragLeave
 0x48d6b8 ImageList_DragEnter
 0x48d6bc ImageList_EndDrag
 0x48d6c0 ImageList_BeginDrag
 0x48d6c4 ImageList_Remove
 0x48d6c8 ImageList_DrawEx
 0x48d6cc ImageList_Draw
 0x48d6d0 ImageList_GetBkColor
 0x48d6d4 ImageList_SetBkColor
 0x48d6d8 ImageList_ReplaceIcon
 0x48d6dc ImageList_Add
 0x48d6e0 ImageList_GetImageCount
 0x48d6e4 ImageList_Destroy
 0x48d6e8 ImageList_Create
kernel32.dll
 0x48d6f0 CreateEventA
 0x48d6f4 ClearCommError
 0x48d6f8 GetProfileIntA
 0x48d6fc GlobalFindAtomA
 0x48d700 GetCurrentThreadId
 0x48d704 GetOEMCP
 0x48d708 BuildCommDCBW
 0x48d70c SearchPathA
 0x48d710 CreateDirectoryW
 0x48d714 GetModuleHandleA
 0x48d718 GetProcAddress
 0x48d71c LoadLibraryA
user32.dll
 0x48d724 GetDialogBaseUnits
 0x48d728 SetActiveWindow
 0x48d72c ShowScrollBar
 0x48d730 GetFocus
 0x48d734 RegisterShellHookWindow
 0x48d738 DestroyCaret

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure