Report - TMS_C020.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:35 Machine s1_win7_x6403
Filename TMS_C020.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 11 detected (Strictor, GenericKD, malicious, ai score=82, R014H09HI24)
md5 2fea7433bc9da61258ef5e0856271420
sha256 080341823d2fdc0977e2f30947b5bbfafe2c8f6fe808f06e1a7859d88359de8d
ssdeep 49152:uDg5BKHqR+ZPYnqJxLXJJRTk7WHAFjjdjjA/YiY0Y0Y0Y0YI:uD6sC+yqJ1XJnk7WHAFjjdjjA/YiY0YC
imphash 92c2ee4988f0629ae080b641fbef84f6
impfuzzy 192:f3zuG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3H1q/Ez9YPpPbOQc
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5de190 DeleteCriticalSection
 0x5de194 LeaveCriticalSection
 0x5de198 EnterCriticalSection
 0x5de19c InitializeCriticalSection
 0x5de1a0 VirtualFree
 0x5de1a4 VirtualAlloc
 0x5de1a8 LocalFree
 0x5de1ac LocalAlloc
 0x5de1b0 GetVersion
 0x5de1b4 GetCurrentThreadId
 0x5de1b8 InterlockedDecrement
 0x5de1bc InterlockedIncrement
 0x5de1c0 VirtualQuery
 0x5de1c4 WideCharToMultiByte
 0x5de1c8 MultiByteToWideChar
 0x5de1cc lstrlenA
 0x5de1d0 lstrcpynA
 0x5de1d4 LoadLibraryExA
 0x5de1d8 GetThreadLocale
 0x5de1dc GetStartupInfoA
 0x5de1e0 GetProcAddress
 0x5de1e4 GetModuleHandleA
 0x5de1e8 GetModuleFileNameA
 0x5de1ec GetLocaleInfoA
 0x5de1f0 GetCommandLineA
 0x5de1f4 FreeLibrary
 0x5de1f8 FindFirstFileA
 0x5de1fc FindClose
 0x5de200 ExitProcess
 0x5de204 ExitThread
 0x5de208 CreateThread
 0x5de20c WriteFile
 0x5de210 UnhandledExceptionFilter
 0x5de214 RtlUnwind
 0x5de218 RaiseException
 0x5de21c GetStdHandle
user32.dll
 0x5de224 GetKeyboardType
 0x5de228 LoadStringA
 0x5de22c MessageBoxA
 0x5de230 CharNextA
advapi32.dll
 0x5de238 RegQueryValueExA
 0x5de23c RegOpenKeyExA
 0x5de240 RegCloseKey
oleaut32.dll
 0x5de248 SysFreeString
 0x5de24c SysReAllocStringLen
 0x5de250 SysAllocStringLen
kernel32.dll
 0x5de258 TlsSetValue
 0x5de25c TlsGetValue
 0x5de260 LocalAlloc
 0x5de264 GetModuleHandleA
advapi32.dll
 0x5de26c RegSetValueExA
 0x5de270 RegQueryValueExA
 0x5de274 RegQueryValueA
 0x5de278 RegOpenKeyExA
 0x5de27c RegFlushKey
 0x5de280 RegCreateKeyExA
 0x5de284 RegCloseKey
kernel32.dll
 0x5de28c lstrcpyA
 0x5de290 WriteFile
 0x5de294 WaitForSingleObject
 0x5de298 VirtualQuery
 0x5de29c VirtualAlloc
 0x5de2a0 Sleep
 0x5de2a4 SizeofResource
 0x5de2a8 SetThreadLocale
 0x5de2ac SetFilePointer
 0x5de2b0 SetEvent
 0x5de2b4 SetErrorMode
 0x5de2b8 SetEndOfFile
 0x5de2bc ResumeThread
 0x5de2c0 ResetEvent
 0x5de2c4 ReleaseMutex
 0x5de2c8 ReadFile
 0x5de2cc MultiByteToWideChar
 0x5de2d0 MulDiv
 0x5de2d4 LockResource
 0x5de2d8 LoadResource
 0x5de2dc LoadLibraryA
 0x5de2e0 LeaveCriticalSection
 0x5de2e4 IsBadReadPtr
 0x5de2e8 InitializeCriticalSection
 0x5de2ec GlobalUnlock
 0x5de2f0 GlobalSize
 0x5de2f4 GlobalReAlloc
 0x5de2f8 GlobalHandle
 0x5de2fc GlobalLock
 0x5de300 GlobalFree
 0x5de304 GlobalFindAtomA
 0x5de308 GlobalDeleteAtom
 0x5de30c GlobalAlloc
 0x5de310 GlobalAddAtomA
 0x5de314 GetVersionExA
 0x5de318 GetVersion
 0x5de31c GetTimeZoneInformation
 0x5de320 GetTickCount
 0x5de324 GetThreadLocale
 0x5de328 GetTempPathA
 0x5de32c GetSystemInfo
 0x5de330 GetStringTypeExA
 0x5de334 GetStdHandle
 0x5de338 GetProcAddress
 0x5de33c GetModuleHandleA
 0x5de340 GetModuleFileNameA
 0x5de344 GetLocaleInfoA
 0x5de348 GetLocalTime
 0x5de34c GetLastError
 0x5de350 GetFullPathNameA
 0x5de354 GetFileSize
 0x5de358 GetExitCodeThread
 0x5de35c GetDiskFreeSpaceA
 0x5de360 GetDateFormatA
 0x5de364 GetCurrentThreadId
 0x5de368 GetCurrentProcessId
 0x5de36c GetCPInfo
 0x5de370 GetACP
 0x5de374 FreeResource
 0x5de378 InterlockedIncrement
 0x5de37c InterlockedExchange
 0x5de380 InterlockedDecrement
 0x5de384 FreeLibrary
 0x5de388 FormatMessageA
 0x5de38c FindResourceA
 0x5de390 FindFirstFileA
 0x5de394 FindClose
 0x5de398 FileTimeToLocalFileTime
 0x5de39c FileTimeToDosDateTime
 0x5de3a0 EnumCalendarInfoA
 0x5de3a4 EnterCriticalSection
 0x5de3a8 DeleteCriticalSection
 0x5de3ac CreateThread
 0x5de3b0 CreateMutexA
 0x5de3b4 CreateFileA
 0x5de3b8 CreateEventA
 0x5de3bc CompareStringA
 0x5de3c0 CloseHandle
version.dll
 0x5de3c8 VerQueryValueA
 0x5de3cc GetFileVersionInfoSizeA
 0x5de3d0 GetFileVersionInfoA
gdi32.dll
 0x5de3d8 UnrealizeObject
 0x5de3dc StretchBlt
 0x5de3e0 SetWindowOrgEx
 0x5de3e4 SetWindowExtEx
 0x5de3e8 SetWinMetaFileBits
 0x5de3ec SetViewportOrgEx
 0x5de3f0 SetViewportExtEx
 0x5de3f4 SetTextColor
 0x5de3f8 SetStretchBltMode
 0x5de3fc SetROP2
 0x5de400 SetPixel
 0x5de404 SetMapMode
 0x5de408 SetEnhMetaFileBits
 0x5de40c SetDIBColorTable
 0x5de410 SetBrushOrgEx
 0x5de414 SetBkMode
 0x5de418 SetBkColor
 0x5de41c SelectPalette
 0x5de420 SelectObject
 0x5de424 SelectClipRgn
 0x5de428 SaveDC
 0x5de42c RoundRect
 0x5de430 RestoreDC
 0x5de434 Rectangle
 0x5de438 RectVisible
 0x5de43c RealizePalette
 0x5de440 Polyline
 0x5de444 Polygon
 0x5de448 PolyPolyline
 0x5de44c PlayEnhMetaFile
 0x5de450 PatBlt
 0x5de454 MoveToEx
 0x5de458 MaskBlt
 0x5de45c LineTo
 0x5de460 LPtoDP
 0x5de464 IntersectClipRect
 0x5de468 GetWindowOrgEx
 0x5de46c GetWinMetaFileBits
 0x5de470 GetViewportOrgEx
 0x5de474 GetTextMetricsA
 0x5de478 GetTextExtentPointA
 0x5de47c GetTextExtentPoint32A
 0x5de480 GetSystemPaletteEntries
 0x5de484 GetStockObject
 0x5de488 GetPixel
 0x5de48c GetPaletteEntries
 0x5de490 GetOutlineTextMetricsA
 0x5de494 GetObjectA
 0x5de498 GetNearestColor
 0x5de49c GetEnhMetaFilePaletteEntries
 0x5de4a0 GetEnhMetaFileHeader
 0x5de4a4 GetEnhMetaFileBits
 0x5de4a8 GetDeviceCaps
 0x5de4ac GetDIBits
 0x5de4b0 GetDIBColorTable
 0x5de4b4 GetDCOrgEx
 0x5de4b8 GetCurrentPositionEx
 0x5de4bc GetCurrentObject
 0x5de4c0 GetClipRgn
 0x5de4c4 GetClipBox
 0x5de4c8 GetBrushOrgEx
 0x5de4cc GetBitmapBits
 0x5de4d0 GdiFlush
 0x5de4d4 ExtTextOutA
 0x5de4d8 ExtSelectClipRgn
 0x5de4dc ExtCreateRegion
 0x5de4e0 ExtCreatePen
 0x5de4e4 ExcludeClipRect
 0x5de4e8 Ellipse
 0x5de4ec DeleteObject
 0x5de4f0 DeleteEnhMetaFile
 0x5de4f4 DeleteDC
 0x5de4f8 CreateSolidBrush
 0x5de4fc CreateRectRgn
 0x5de500 CreatePolygonRgn
 0x5de504 CreatePenIndirect
 0x5de508 CreatePen
 0x5de50c CreatePalette
 0x5de510 CreateHalftonePalette
 0x5de514 CreateFontIndirectA
 0x5de518 CreateDIBitmap
 0x5de51c CreateDIBSection
 0x5de520 CreateCompatibleDC
 0x5de524 CreateCompatibleBitmap
 0x5de528 CreateBrushIndirect
 0x5de52c CreateBitmap
 0x5de530 CopyEnhMetaFileA
 0x5de534 CombineRgn
 0x5de538 BitBlt
user32.dll
 0x5de540 CreateWindowExA
 0x5de544 WindowFromPoint
 0x5de548 WinHelpA
 0x5de54c WaitMessage
 0x5de550 ValidateRect
 0x5de554 UpdateWindow
 0x5de558 UnregisterClassA
 0x5de55c UnionRect
 0x5de560 UnhookWindowsHookEx
 0x5de564 TranslateMessage
 0x5de568 TranslateMDISysAccel
 0x5de56c TrackPopupMenu
 0x5de570 SystemParametersInfoA
 0x5de574 ShowWindow
 0x5de578 ShowScrollBar
 0x5de57c ShowOwnedPopups
 0x5de580 ShowCursor
 0x5de584 ShowCaret
 0x5de588 SetWindowRgn
 0x5de58c SetWindowsHookExA
 0x5de590 SetWindowTextA
 0x5de594 SetWindowPos
 0x5de598 SetWindowPlacement
 0x5de59c SetWindowLongW
 0x5de5a0 SetWindowLongA
 0x5de5a4 SetTimer
 0x5de5a8 SetScrollRange
 0x5de5ac SetScrollPos
 0x5de5b0 SetScrollInfo
 0x5de5b4 SetRect
 0x5de5b8 SetPropA
 0x5de5bc SetParent
 0x5de5c0 SetMenuItemInfoA
 0x5de5c4 SetMenu
 0x5de5c8 SetKeyboardState
 0x5de5cc SetForegroundWindow
 0x5de5d0 SetFocus
 0x5de5d4 SetCursor
 0x5de5d8 SetClipboardData
 0x5de5dc SetClassLongA
 0x5de5e0 SetCaretPos
 0x5de5e4 SetCapture
 0x5de5e8 SetActiveWindow
 0x5de5ec SendMessageA
 0x5de5f0 ScrollWindowEx
 0x5de5f4 ScrollWindow
 0x5de5f8 ScreenToClient
 0x5de5fc RemovePropA
 0x5de600 RemoveMenu
 0x5de604 ReleaseDC
 0x5de608 ReleaseCapture
 0x5de60c RegisterWindowMessageA
 0x5de610 RegisterClipboardFormatA
 0x5de614 RegisterClassA
 0x5de618 RedrawWindow
 0x5de61c PtInRect
 0x5de620 PostQuitMessage
 0x5de624 PostMessageA
 0x5de628 PeekMessageA
 0x5de62c OpenClipboard
 0x5de630 OffsetRect
 0x5de634 OemToCharA
 0x5de638 MsgWaitForMultipleObjects
 0x5de63c MoveWindow
 0x5de640 MessageBoxA
 0x5de644 MessageBeep
 0x5de648 MapWindowPoints
 0x5de64c MapVirtualKeyA
 0x5de650 LoadStringA
 0x5de654 LoadKeyboardLayoutA
 0x5de658 LoadIconA
 0x5de65c LoadCursorA
 0x5de660 LoadBitmapA
 0x5de664 KillTimer
 0x5de668 IsZoomed
 0x5de66c IsWindowVisible
 0x5de670 IsWindowUnicode
 0x5de674 IsWindowEnabled
 0x5de678 IsWindow
 0x5de67c IsRectEmpty
 0x5de680 IsIconic
 0x5de684 IsDialogMessageA
 0x5de688 IsClipboardFormatAvailable
 0x5de68c IsChild
 0x5de690 IsCharAlphaNumericA
 0x5de694 IsCharAlphaA
 0x5de698 InvalidateRect
 0x5de69c IntersectRect
 0x5de6a0 InsertMenuItemA
 0x5de6a4 InsertMenuA
 0x5de6a8 InflateRect
 0x5de6ac HideCaret
 0x5de6b0 GetWindowThreadProcessId
 0x5de6b4 GetWindowTextLengthW
 0x5de6b8 GetWindowTextW
 0x5de6bc GetWindowTextA
 0x5de6c0 GetWindowRect
 0x5de6c4 GetWindowPlacement
 0x5de6c8 GetWindowLongW
 0x5de6cc GetWindowLongA
 0x5de6d0 GetWindowDC
 0x5de6d4 GetTopWindow
 0x5de6d8 GetSystemMetrics
 0x5de6dc GetSystemMenu
 0x5de6e0 GetSysColorBrush
 0x5de6e4 GetSysColor
 0x5de6e8 GetSubMenu
 0x5de6ec GetScrollRange
 0x5de6f0 GetScrollPos
 0x5de6f4 GetScrollInfo
 0x5de6f8 GetPropA
 0x5de6fc GetParent
 0x5de700 GetWindow
 0x5de704 GetMessageTime
 0x5de708 GetMenuStringA
 0x5de70c GetMenuState
 0x5de710 GetMenuItemInfoA
 0x5de714 GetMenuItemID
 0x5de718 GetMenuItemCount
 0x5de71c GetMenu
 0x5de720 GetLastActivePopup
 0x5de724 GetKeyboardState
 0x5de728 GetKeyboardLayoutList
 0x5de72c GetKeyboardLayout
 0x5de730 GetKeyState
 0x5de734 GetKeyNameTextA
 0x5de738 GetIconInfo
 0x5de73c GetForegroundWindow
 0x5de740 GetFocus
 0x5de744 GetDoubleClickTime
 0x5de748 GetDlgItem
 0x5de74c GetDlgCtrlID
 0x5de750 GetDesktopWindow
 0x5de754 GetDCEx
 0x5de758 GetDC
 0x5de75c GetCursorPos
 0x5de760 GetCursor
 0x5de764 GetClipboardData
 0x5de768 GetClientRect
 0x5de76c GetClassNameA
 0x5de770 GetClassInfoA
 0x5de774 GetCaretPos
 0x5de778 GetCapture
 0x5de77c GetActiveWindow
 0x5de780 FrameRect
 0x5de784 FindWindowExA
 0x5de788 FindWindowA
 0x5de78c FillRect
 0x5de790 EqualRect
 0x5de794 EnumWindows
 0x5de798 EnumThreadWindows
 0x5de79c EnumClipboardFormats
 0x5de7a0 EndPaint
 0x5de7a4 EnableWindow
 0x5de7a8 EnableScrollBar
 0x5de7ac EnableMenuItem
 0x5de7b0 EmptyClipboard
 0x5de7b4 DrawTextExA
 0x5de7b8 DrawTextW
 0x5de7bc DrawTextA
 0x5de7c0 DrawMenuBar
 0x5de7c4 DrawIconEx
 0x5de7c8 DrawIcon
 0x5de7cc DrawFrameControl
 0x5de7d0 DrawFocusRect
 0x5de7d4 DrawEdge
 0x5de7d8 DispatchMessageA
 0x5de7dc DestroyWindow
 0x5de7e0 DestroyMenu
 0x5de7e4 DestroyIcon
 0x5de7e8 DestroyCursor
 0x5de7ec DestroyCaret
 0x5de7f0 DeleteMenu
 0x5de7f4 DefWindowProcA
 0x5de7f8 DefMDIChildProcA
 0x5de7fc DefFrameProcA
 0x5de800 CreatePopupMenu
 0x5de804 CreateMenu
 0x5de808 CreateIcon
 0x5de80c CreateCaret
 0x5de810 CopyImage
 0x5de814 CloseClipboard
 0x5de818 ClientToScreen
 0x5de81c CheckMenuItem
 0x5de820 CallWindowProcA
 0x5de824 CallNextHookEx
 0x5de828 BeginPaint
 0x5de82c CharNextA
 0x5de830 CharLowerBuffA
 0x5de834 CharLowerA
 0x5de838 CharUpperBuffA
 0x5de83c CharToOemA
 0x5de840 AdjustWindowRectEx
 0x5de844 ActivateKeyboardLayout
ole32.dll
 0x5de84c CoTaskMemFree
 0x5de850 StringFromCLSID
kernel32.dll
 0x5de858 Sleep
oleaut32.dll
 0x5de860 SafeArrayPtrOfIndex
 0x5de864 SafeArrayPutElement
 0x5de868 SafeArrayGetElement
 0x5de86c SafeArrayUnaccessData
 0x5de870 SafeArrayAccessData
 0x5de874 SafeArrayGetUBound
 0x5de878 SafeArrayGetLBound
 0x5de87c SafeArrayRedim
 0x5de880 SafeArrayCreate
 0x5de884 VariantChangeType
 0x5de888 VariantCopyInd
 0x5de88c VariantCopy
 0x5de890 VariantClear
 0x5de894 VariantInit
ole32.dll
 0x5de89c CoCreateInstance
 0x5de8a0 CoGetMalloc
 0x5de8a4 CoUninitialize
 0x5de8a8 CoInitialize
 0x5de8ac IsEqualGUID
oleaut32.dll
 0x5de8b4 CreateErrorInfo
 0x5de8b8 GetErrorInfo
 0x5de8bc SetErrorInfo
 0x5de8c0 SafeArrayCopy
 0x5de8c4 SafeArrayUnaccessData
 0x5de8c8 SafeArrayAccessData
 0x5de8cc SafeArrayGetUBound
 0x5de8d0 SafeArrayDestroy
 0x5de8d4 SafeArrayCreate
 0x5de8d8 SysFreeString
comctl32.dll
 0x5de8e0 ImageList_SetIconSize
 0x5de8e4 ImageList_GetIconSize
 0x5de8e8 ImageList_Write
 0x5de8ec ImageList_Read
 0x5de8f0 ImageList_GetDragImage
 0x5de8f4 ImageList_DragShowNolock
 0x5de8f8 ImageList_SetDragCursorImage
 0x5de8fc ImageList_DragMove
 0x5de900 ImageList_DragLeave
 0x5de904 ImageList_DragEnter
 0x5de908 ImageList_EndDrag
 0x5de90c ImageList_BeginDrag
 0x5de910 ImageList_LoadImageA
 0x5de914 ImageList_Remove
 0x5de918 ImageList_DrawEx
 0x5de91c ImageList_Replace
 0x5de920 ImageList_Draw
 0x5de924 ImageList_GetBkColor
 0x5de928 ImageList_SetBkColor
 0x5de92c ImageList_ReplaceIcon
 0x5de930 ImageList_Add
 0x5de934 ImageList_GetImageCount
 0x5de938 ImageList_Destroy
 0x5de93c ImageList_Create
 0x5de940 InitCommonControls
comdlg32.dll
 0x5de948 GetSaveFileNameA
 0x5de94c GetOpenFileNameA
kernel32.dll
 0x5de954 MulDiv
kernel32.dll
 0x5de95c MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure