Report - mmspol.dll

Generic Malware PE File PE64 DLL
ScreenShot
Created 2025.04.21 13:33 Machine s1_win7_x6403
Filename mmspol.dll
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
AI Score
5
Behavior Score
2.2
ZERO API file : malware
VT API (file) 39 detected (HackTool, Mimikatz, S33893082, FWXX, Mimi, DQYA, malicious, high confidence, CVE-2021-1675, Z7hKCBfrpcB, Tool, HKTL, MIMIKATZ64, Detected, Wacapew, R445129, GdSda, eQ4ZXKbwWQE)
md5 5737ef577c12225563d2c55f133bcaf5
sha256 f20e0114c8038b9d66bd45049c9396254586f307390479746a6c67f5e1abce2d
ssdeep 384:fJxgWFlVZ50C0uolsbpwKNsdu5CJR6CBT1/wfT3ir2WSx7bLta:xxgWFln5B0uolsIdASRA3iPmbLc
imphash c38ebbf4627ca2303746c77210e5a12e
impfuzzy 12:otNPKjDBIz0sLkJMyVt8Fsu8wQTZBzhPPXJ1XJHGJ030smMH/sJqXI:oK6z0sLkJMA65Q1Bz9L4Ja0TMAqY
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 39 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info One or more processes crashed

Rules (4cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
196.251.118.210 ZA xneelo 196.251.118.210 malware

Suricata ids

PE API

IAT(Import Address Table) Library

ADVAPI32.dll
 0x180002000 CreateProcessAsUserW
 0x180002008 SetTokenInformation
 0x180002010 DuplicateTokenEx
 0x180002018 OpenProcessToken
USERENV.dll
 0x1800020a8 DestroyEnvironmentBlock
 0x1800020b0 CreateEnvironmentBlock
WINSTA.dll
 0x1800020c0 WinStationEnumerateW
 0x1800020c8 WinStationFreeMemory
KERNEL32.dll
 0x180002028 GetCurrentProcessId
 0x180002030 GetCurrentThreadId
 0x180002038 GetTickCount
 0x180002040 QueryPerformanceCounter
 0x180002048 SetUnhandledExceptionFilter
 0x180002050 UnhandledExceptionFilter
 0x180002058 Sleep
 0x180002060 GetCurrentProcess
 0x180002068 SetLastError
 0x180002070 CloseHandle
 0x180002078 TerminateProcess
 0x180002080 RtlCaptureContext
 0x180002088 RtlLookupFunctionEntry
 0x180002090 RtlVirtualUnwind
 0x180002098 GetSystemTimeAsFileTime
msvcrt.dll
 0x1800020d8 memset
 0x1800020e0 __C_specific_handler
 0x1800020e8 _XcptFilter
 0x1800020f0 malloc
 0x1800020f8 free
 0x180002100 _amsg_exit
 0x180002108 _initterm

EAT(Export Address Table) Library

0x180001020 DrvDisableDriver
0x180001064 DrvEnableDriver
0x180001024 DrvQueryDriverInfo
0x180001020 DrvResetConfigCache
0x1800010a0 GenerateCopyFilePaths
0x1800010a4 SpoolerCopyFileEvent


Similarity measure (PE file only) - Checking for service failure