Report - 44264.5606934027.dat.exe

ScreenShot
Created 2021.03.10 14:28 Machine s1_win7_x6401
Filename 44264.5606934027.dat.exe
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
8
Behavior Score
0.8
ZERO API file : clean
VT API (file)
md5 94239a0c707ebb277edc24068284889c
sha256 1f21f07b251a931a18abafd31077d7090284afd429aee36dd70230008b9ce9c9
ssdeep 12288:plTxdlYUTXacR/927cw6nlsL8IQayFixyGgBfMdK6Uwh1/6aMCxtd:vFgkau97wUsTsFiMGEfUK4Lx
imphash 982089e07eedebb62c392042401154fa
impfuzzy 192:f3TNk1QBbuuSrSUvK9RZooqE6pCPbOQWO:f3y1sSA9ckPbOQ5
  Network IP location

Signature (3cnts)

Level Description
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (11cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info borland_delphi_dll Borland Delphi DLL binaries (upload)
info HasDigitalSignature DigitalSignature Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info keylogger Run a keylogger binaries (upload)
info screenshot Take screenshot binaries (upload)
info win_files_operation Affect private profile binaries (upload)
info win_registry Affect system registries binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x468140 DeleteCriticalSection
 0x468144 LeaveCriticalSection
 0x468148 EnterCriticalSection
 0x46814c InitializeCriticalSection
 0x468150 VirtualFree
 0x468154 VirtualAlloc
 0x468158 LocalFree
 0x46815c LocalAlloc
 0x468160 GetVersion
 0x468164 GetCurrentThreadId
 0x468168 InterlockedDecrement
 0x46816c InterlockedIncrement
 0x468170 VirtualQuery
 0x468174 WideCharToMultiByte
 0x468178 MultiByteToWideChar
 0x46817c lstrlenA
 0x468180 lstrcpynA
 0x468184 LoadLibraryExA
 0x468188 GetThreadLocale
 0x46818c GetStartupInfoA
 0x468190 GetProcAddress
 0x468194 GetModuleHandleA
 0x468198 GetModuleFileNameA
 0x46819c GetLocaleInfoA
 0x4681a0 GetCommandLineA
 0x4681a4 FreeLibrary
 0x4681a8 FindFirstFileA
 0x4681ac FindClose
 0x4681b0 ExitProcess
 0x4681b4 WriteFile
 0x4681b8 UnhandledExceptionFilter
 0x4681bc RtlUnwind
 0x4681c0 RaiseException
 0x4681c4 GetStdHandle
user32.dll
 0x4681cc GetKeyboardType
 0x4681d0 LoadStringA
 0x4681d4 MessageBoxA
 0x4681d8 CharNextA
advapi32.dll
 0x4681e0 RegQueryValueExA
 0x4681e4 RegOpenKeyExA
 0x4681e8 RegCloseKey
oleaut32.dll
 0x4681f0 SysFreeString
 0x4681f4 SysReAllocStringLen
 0x4681f8 SysAllocStringLen
kernel32.dll
 0x468200 TlsSetValue
 0x468204 TlsGetValue
 0x468208 TlsFree
 0x46820c TlsAlloc
 0x468210 LocalFree
 0x468214 LocalAlloc
advapi32.dll
 0x46821c RegQueryValueExA
 0x468220 RegOpenKeyExA
 0x468224 RegCloseKey
 0x468228 GetUserNameW
kernel32.dll
 0x468230 lstrcpyA
 0x468234 WriteFile
 0x468238 WaitForSingleObject
 0x46823c VirtualQuery
 0x468240 VirtualAllocEx
 0x468244 VirtualAlloc
 0x468248 Sleep
 0x46824c SizeofResource
 0x468250 SetThreadLocale
 0x468254 SetFilePointer
 0x468258 SetEvent
 0x46825c SetErrorMode
 0x468260 SetEndOfFile
 0x468264 ResetEvent
 0x468268 ReadFile
 0x46826c MultiByteToWideChar
 0x468270 MulDiv
 0x468274 LockResource
 0x468278 LoadResource
 0x46827c LoadLibraryA
 0x468280 LeaveCriticalSection
 0x468284 InitializeCriticalSection
 0x468288 GlobalUnlock
 0x46828c GlobalReAlloc
 0x468290 GlobalHandle
 0x468294 GlobalLock
 0x468298 GlobalFree
 0x46829c GlobalFindAtomA
 0x4682a0 GlobalDeleteAtom
 0x4682a4 GlobalAlloc
 0x4682a8 GlobalAddAtomA
 0x4682ac GetVersionExA
 0x4682b0 GetVersion
 0x4682b4 GetTickCount
 0x4682b8 GetThreadLocale
 0x4682bc GetSystemInfo
 0x4682c0 GetStringTypeExA
 0x4682c4 GetStdHandle
 0x4682c8 GetProcAddress
 0x4682cc GetModuleHandleA
 0x4682d0 GetModuleFileNameA
 0x4682d4 GetLocaleInfoA
 0x4682d8 GetLocalTime
 0x4682dc GetLastError
 0x4682e0 GetFullPathNameA
 0x4682e4 GetDiskFreeSpaceA
 0x4682e8 GetDateFormatA
 0x4682ec GetCurrentThreadId
 0x4682f0 GetCurrentProcessId
 0x4682f4 GetCPInfo
 0x4682f8 GetACP
 0x4682fc FreeResource
 0x468300 InterlockedExchange
 0x468304 FreeLibrary
 0x468308 FormatMessageA
 0x46830c FindResourceA
 0x468310 EnumCalendarInfoA
 0x468314 EnterCriticalSection
 0x468318 DeleteCriticalSection
 0x46831c CreateThread
 0x468320 CreateFileA
 0x468324 CreateEventA
 0x468328 CompareStringA
 0x46832c CloseHandle
version.dll
 0x468334 VerQueryValueA
 0x468338 GetFileVersionInfoSizeA
 0x46833c GetFileVersionInfoA
gdi32.dll
 0x468344 UnrealizeObject
 0x468348 StretchBlt
 0x46834c SetWindowOrgEx
 0x468350 SetViewportOrgEx
 0x468354 SetTextColor
 0x468358 SetStretchBltMode
 0x46835c SetROP2
 0x468360 SetPixel
 0x468364 SetDIBColorTable
 0x468368 SetBrushOrgEx
 0x46836c SetBkMode
 0x468370 SetBkColor
 0x468374 SelectPalette
 0x468378 SelectObject
 0x46837c SaveDC
 0x468380 RestoreDC
 0x468384 RectVisible
 0x468388 RealizePalette
 0x46838c PatBlt
 0x468390 MoveToEx
 0x468394 MaskBlt
 0x468398 LineTo
 0x46839c IntersectClipRect
 0x4683a0 GetWindowOrgEx
 0x4683a4 GetTextMetricsA
 0x4683a8 GetTextExtentPoint32A
 0x4683ac GetSystemPaletteEntries
 0x4683b0 GetStockObject
 0x4683b4 GetPixel
 0x4683b8 GetPaletteEntries
 0x4683bc GetObjectA
 0x4683c0 GetDeviceCaps
 0x4683c4 GetDIBits
 0x4683c8 GetDIBColorTable
 0x4683cc GetDCOrgEx
 0x4683d0 GetCurrentPositionEx
 0x4683d4 GetClipBox
 0x4683d8 GetBrushOrgEx
 0x4683dc GetBitmapBits
 0x4683e0 ExcludeClipRect
 0x4683e4 DeleteObject
 0x4683e8 DeleteDC
 0x4683ec CreateSolidBrush
 0x4683f0 CreatePenIndirect
 0x4683f4 CreatePalette
 0x4683f8 CreateHalftonePalette
 0x4683fc CreateFontIndirectA
 0x468400 CreateDIBitmap
 0x468404 CreateDIBSection
 0x468408 CreateCompatibleDC
 0x46840c CreateCompatibleBitmap
 0x468410 CreateBrushIndirect
 0x468414 CreateBitmap
 0x468418 BitBlt
user32.dll
 0x468420 CreateWindowExA
 0x468424 WindowFromPoint
 0x468428 WinHelpA
 0x46842c WaitMessage
 0x468430 UpdateWindow
 0x468434 UnregisterClassA
 0x468438 UnhookWindowsHookEx
 0x46843c TranslateMessage
 0x468440 TranslateMDISysAccel
 0x468444 TrackPopupMenu
 0x468448 SystemParametersInfoA
 0x46844c ShowWindow
 0x468450 ShowScrollBar
 0x468454 ShowOwnedPopups
 0x468458 ShowCursor
 0x46845c SetWindowsHookExA
 0x468460 SetWindowPos
 0x468464 SetWindowPlacement
 0x468468 SetWindowLongA
 0x46846c SetTimer
 0x468470 SetScrollRange
 0x468474 SetScrollPos
 0x468478 SetScrollInfo
 0x46847c SetRect
 0x468480 SetPropA
 0x468484 SetParent
 0x468488 SetMenuItemInfoA
 0x46848c SetMenu
 0x468490 SetForegroundWindow
 0x468494 SetFocus
 0x468498 SetCursor
 0x46849c SetClassLongA
 0x4684a0 SetCapture
 0x4684a4 SetActiveWindow
 0x4684a8 SendMessageA
 0x4684ac ScrollWindow
 0x4684b0 ScreenToClient
 0x4684b4 RemovePropA
 0x4684b8 RemoveMenu
 0x4684bc ReleaseDC
 0x4684c0 ReleaseCapture
 0x4684c4 RegisterWindowMessageA
 0x4684c8 RegisterClipboardFormatA
 0x4684cc RegisterClassA
 0x4684d0 RedrawWindow
 0x4684d4 PtInRect
 0x4684d8 PostQuitMessage
 0x4684dc PostMessageA
 0x4684e0 PeekMessageA
 0x4684e4 OffsetRect
 0x4684e8 OemToCharA
 0x4684ec MessageBoxA
 0x4684f0 MapWindowPoints
 0x4684f4 MapVirtualKeyA
 0x4684f8 LoadStringA
 0x4684fc LoadKeyboardLayoutA
 0x468500 LoadIconW
 0x468504 LoadIconA
 0x468508 LoadCursorFromFileW
 0x46850c LoadCursorA
 0x468510 LoadBitmapA
 0x468514 KillTimer
 0x468518 IsZoomed
 0x46851c IsWindowVisible
 0x468520 IsWindowEnabled
 0x468524 IsWindow
 0x468528 IsRectEmpty
 0x46852c IsIconic
 0x468530 IsDialogMessageA
 0x468534 IsChild
 0x468538 InvalidateRect
 0x46853c IntersectRect
 0x468540 InsertMenuItemA
 0x468544 InsertMenuA
 0x468548 InflateRect
 0x46854c GetWindowThreadProcessId
 0x468550 GetWindowTextA
 0x468554 GetWindowRect
 0x468558 GetWindowPlacement
 0x46855c GetWindowLongA
 0x468560 GetWindowDC
 0x468564 GetTopWindow
 0x468568 GetSystemMetrics
 0x46856c GetSystemMenu
 0x468570 GetSysColorBrush
 0x468574 GetSysColor
 0x468578 GetSubMenu
 0x46857c GetScrollRange
 0x468580 GetScrollPos
 0x468584 GetScrollInfo
 0x468588 GetPropA
 0x46858c GetParent
 0x468590 GetWindow
 0x468594 GetMenuStringA
 0x468598 GetMenuState
 0x46859c GetMenuItemInfoA
 0x4685a0 GetMenuItemID
 0x4685a4 GetMenuItemCount
 0x4685a8 GetMenu
 0x4685ac GetLastActivePopup
 0x4685b0 GetKeyboardState
 0x4685b4 GetKeyboardLayoutList
 0x4685b8 GetKeyboardLayout
 0x4685bc GetKeyState
 0x4685c0 GetKeyNameTextA
 0x4685c4 GetIconInfo
 0x4685c8 GetForegroundWindow
 0x4685cc GetFocus
 0x4685d0 GetDesktopWindow
 0x4685d4 GetDCEx
 0x4685d8 GetDC
 0x4685dc GetCursorPos
 0x4685e0 GetCursor
 0x4685e4 GetClientRect
 0x4685e8 GetClassNameA
 0x4685ec GetClassInfoA
 0x4685f0 GetCapture
 0x4685f4 GetActiveWindow
 0x4685f8 FrameRect
 0x4685fc FindWindowA
 0x468600 FillRect
 0x468604 EqualRect
 0x468608 EnumWindows
 0x46860c EnumThreadWindows
 0x468610 EndPaint
 0x468614 EnableWindow
 0x468618 EnableScrollBar
 0x46861c EnableMenuItem
 0x468620 DrawTextA
 0x468624 DrawMenuBar
 0x468628 DrawIconEx
 0x46862c DrawIcon
 0x468630 DrawFrameControl
 0x468634 DrawEdge
 0x468638 DispatchMessageA
 0x46863c DestroyWindow
 0x468640 DestroyMenu
 0x468644 DestroyIcon
 0x468648 DestroyCursor
 0x46864c DeleteMenu
 0x468650 DefWindowProcA
 0x468654 DefMDIChildProcA
 0x468658 DefFrameProcA
 0x46865c CreatePopupMenu
 0x468660 CreateMenu
 0x468664 CreateIcon
 0x468668 ClientToScreen
 0x46866c CheckMenuItem
 0x468670 CallWindowProcA
 0x468674 CallNextHookEx
 0x468678 BeginPaint
 0x46867c CharNextA
 0x468680 CharLowerA
 0x468684 CharUpperBuffA
 0x468688 CharToOemA
 0x46868c AdjustWindowRectEx
 0x468690 ActivateKeyboardLayout
kernel32.dll
 0x468698 Sleep
oleaut32.dll
 0x4686a0 SafeArrayPtrOfIndex
 0x4686a4 SafeArrayPutElement
 0x4686a8 SafeArrayGetElement
 0x4686ac SafeArrayUnaccessData
 0x4686b0 SafeArrayAccessData
 0x4686b4 SafeArrayGetUBound
 0x4686b8 SafeArrayGetLBound
 0x4686bc SafeArrayCreate
 0x4686c0 VariantChangeType
 0x4686c4 VariantCopyInd
 0x4686c8 VariantCopy
 0x4686cc VariantClear
 0x4686d0 VariantInit
ole32.dll
 0x4686d8 CoCreateInstance
 0x4686dc CoUninitialize
 0x4686e0 CoInitialize
oleaut32.dll
 0x4686e8 CreateErrorInfo
 0x4686ec GetErrorInfo
 0x4686f0 SetErrorInfo
 0x4686f4 SysFreeString
comctl32.dll
 0x4686fc ImageList_SetIconSize
 0x468700 ImageList_GetIconSize
 0x468704 ImageList_Write
 0x468708 ImageList_Read
 0x46870c ImageList_GetDragImage
 0x468710 ImageList_DragShowNolock
 0x468714 ImageList_SetDragCursorImage
 0x468718 ImageList_DragMove
 0x46871c ImageList_DragLeave
 0x468720 ImageList_DragEnter
 0x468724 ImageList_EndDrag
 0x468728 ImageList_BeginDrag
 0x46872c ImageList_Remove
 0x468730 ImageList_DrawEx
 0x468734 ImageList_Draw
 0x468738 ImageList_GetBkColor
 0x46873c ImageList_SetBkColor
 0x468740 ImageList_ReplaceIcon
 0x468744 ImageList_Add
 0x468748 ImageList_GetImageCount
 0x46874c ImageList_Destroy
 0x468750 ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure