Report - ra02W4S.exe

Admin Tool (Sysinternals etc ...) Malicious Library UPX PE File MZP Format PE32 OS Processor Check
ScreenShot
Created 2025.05.06 21:41 Machine s1_win7_x6403
Filename ra02W4S.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
3.4
ZERO API file : clean
VT API (file) 35 detected (AIDetectMalware, GCleaner, Malicious, score, Unsafe, confidence, 100%, Attribute, HighConfidence, high confidence, GenKryptik, HITC, MalwareX, Misc, Tepfer, Kryptik@AI, RDML, BRQ8b7j46pePiDEyPJ0fgg, Nekark, gnlzl, moderate, Static AI, Malicious PE, Detected, Dapato, Kryptik, JWN0LJ, ABRisk, PINS, Artemis, QBot, Yylw, susgen, Wacatac, B9nj)
md5 8b6c4551fc1d73e9151c2daecec86da7
sha256 c4f5b49e2c04fe3060b59f4e3297f5f25962c2b4ae63f6ff5f94cb5323f39c5d
ssdeep 49152:85SSvq3llll07srAo8QHmEEF3cs3RLt1WdPePtvx9BXN7WJ3x0zem:855vq3l3XAoCDxcyRLtcdPMN7WJ3x03
imphash 138b1bf4678cc4fc64388499438cd99a
impfuzzy 192:f30qk1sTCbuuSrSUvK9RqooqE6pCPbOQPO:f3e1s8SA9LkPbOQm
  Network IP location

Signature (9cnts)

Level Description
danger File has been identified by 35 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
157.20.104.252 Unknown 157.20.104.252 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x469140 DeleteCriticalSection
 0x469144 LeaveCriticalSection
 0x469148 EnterCriticalSection
 0x46914c InitializeCriticalSection
 0x469150 VirtualFree
 0x469154 VirtualAlloc
 0x469158 LocalFree
 0x46915c LocalAlloc
 0x469160 GetVersion
 0x469164 GetCurrentThreadId
 0x469168 InterlockedDecrement
 0x46916c InterlockedIncrement
 0x469170 VirtualQuery
 0x469174 WideCharToMultiByte
 0x469178 MultiByteToWideChar
 0x46917c lstrlenA
 0x469180 lstrcpynA
 0x469184 LoadLibraryExA
 0x469188 GetThreadLocale
 0x46918c GetStartupInfoA
 0x469190 GetProcAddress
 0x469194 GetModuleHandleA
 0x469198 GetModuleFileNameA
 0x46919c GetLocaleInfoA
 0x4691a0 GetCommandLineA
 0x4691a4 FreeLibrary
 0x4691a8 FindFirstFileA
 0x4691ac FindClose
 0x4691b0 ExitProcess
 0x4691b4 WriteFile
 0x4691b8 UnhandledExceptionFilter
 0x4691bc RtlUnwind
 0x4691c0 RaiseException
 0x4691c4 GetStdHandle
user32.dll
 0x4691cc GetKeyboardType
 0x4691d0 LoadStringA
 0x4691d4 MessageBoxA
 0x4691d8 CharNextA
advapi32.dll
 0x4691e0 RegQueryValueExA
 0x4691e4 RegOpenKeyExA
 0x4691e8 RegCloseKey
oleaut32.dll
 0x4691f0 SysFreeString
 0x4691f4 SysReAllocStringLen
 0x4691f8 SysAllocStringLen
kernel32.dll
 0x469200 TlsSetValue
 0x469204 TlsGetValue
 0x469208 LocalAlloc
 0x46920c GetModuleHandleA
advapi32.dll
 0x469214 RegQueryValueExA
 0x469218 RegOpenKeyExA
 0x46921c RegCloseKey
kernel32.dll
 0x469224 lstrcpyA
 0x469228 WriteFile
 0x46922c WaitForSingleObject
 0x469230 VirtualQuery
 0x469234 VirtualAlloc
 0x469238 Sleep
 0x46923c SizeofResource
 0x469240 SetThreadLocale
 0x469244 SetFilePointer
 0x469248 SetEvent
 0x46924c SetErrorMode
 0x469250 SetEndOfFile
 0x469254 ResetEvent
 0x469258 ReadFile
 0x46925c MultiByteToWideChar
 0x469260 MulDiv
 0x469264 LockResource
 0x469268 LoadResource
 0x46926c LoadLibraryA
 0x469270 LeaveCriticalSection
 0x469274 InitializeCriticalSection
 0x469278 GlobalUnlock
 0x46927c GlobalReAlloc
 0x469280 GlobalHandle
 0x469284 GlobalLock
 0x469288 GlobalFree
 0x46928c GlobalFindAtomA
 0x469290 GlobalDeleteAtom
 0x469294 GlobalAlloc
 0x469298 GlobalAddAtomA
 0x46929c GetVersionExA
 0x4692a0 GetVersion
 0x4692a4 GetTickCount
 0x4692a8 GetThreadLocale
 0x4692ac GetTempPathA
 0x4692b0 GetSystemInfo
 0x4692b4 GetStringTypeExA
 0x4692b8 GetStdHandle
 0x4692bc GetProcAddress
 0x4692c0 GetModuleHandleA
 0x4692c4 GetModuleFileNameA
 0x4692c8 GetLocaleInfoA
 0x4692cc GetLocalTime
 0x4692d0 GetLastError
 0x4692d4 GetFullPathNameA
 0x4692d8 GetFileSize
 0x4692dc GetDiskFreeSpaceA
 0x4692e0 GetDateFormatA
 0x4692e4 GetCurrentThreadId
 0x4692e8 GetCurrentProcessId
 0x4692ec GetCPInfo
 0x4692f0 GetACP
 0x4692f4 FreeResource
 0x4692f8 InterlockedExchange
 0x4692fc FreeLibrary
 0x469300 FormatMessageA
 0x469304 FindResourceA
 0x469308 FindFirstFileA
 0x46930c FindClose
 0x469310 FileTimeToLocalFileTime
 0x469314 FileTimeToDosDateTime
 0x469318 EnumCalendarInfoA
 0x46931c EnterCriticalSection
 0x469320 DeleteFileA
 0x469324 DeleteCriticalSection
 0x469328 CreateThread
 0x46932c CreateFileA
 0x469330 CreateEventA
 0x469334 CompareStringA
 0x469338 CloseHandle
version.dll
 0x469340 VerQueryValueA
 0x469344 GetFileVersionInfoSizeA
 0x469348 GetFileVersionInfoA
gdi32.dll
 0x469350 UnrealizeObject
 0x469354 StretchBlt
 0x469358 SetWindowOrgEx
 0x46935c SetViewportOrgEx
 0x469360 SetTextColor
 0x469364 SetStretchBltMode
 0x469368 SetROP2
 0x46936c SetPixel
 0x469370 SetDIBColorTable
 0x469374 SetBrushOrgEx
 0x469378 SetBkMode
 0x46937c SetBkColor
 0x469380 SelectPalette
 0x469384 SelectObject
 0x469388 SaveDC
 0x46938c RestoreDC
 0x469390 RectVisible
 0x469394 RealizePalette
 0x469398 PatBlt
 0x46939c MoveToEx
 0x4693a0 MaskBlt
 0x4693a4 LineTo
 0x4693a8 IntersectClipRect
 0x4693ac GetWindowOrgEx
 0x4693b0 GetTextMetricsA
 0x4693b4 GetTextExtentPoint32A
 0x4693b8 GetSystemPaletteEntries
 0x4693bc GetStockObject
 0x4693c0 GetPixel
 0x4693c4 GetPaletteEntries
 0x4693c8 GetObjectA
 0x4693cc GetDeviceCaps
 0x4693d0 GetDIBits
 0x4693d4 GetDIBColorTable
 0x4693d8 GetDCOrgEx
 0x4693dc GetCurrentPositionEx
 0x4693e0 GetClipBox
 0x4693e4 GetBrushOrgEx
 0x4693e8 GetBkColor
 0x4693ec GetBitmapBits
 0x4693f0 ExcludeClipRect
 0x4693f4 DeleteObject
 0x4693f8 DeleteDC
 0x4693fc CreateSolidBrush
 0x469400 CreatePenIndirect
 0x469404 CreatePalette
 0x469408 CreateHalftonePalette
 0x46940c CreateFontIndirectA
 0x469410 CreateDIBitmap
 0x469414 CreateDIBSection
 0x469418 CreateCompatibleDC
 0x46941c CreateCompatibleBitmap
 0x469420 CreateBrushIndirect
 0x469424 CreateBitmap
 0x469428 BitBlt
user32.dll
 0x469430 CreateWindowExA
 0x469434 WindowFromPoint
 0x469438 WinHelpA
 0x46943c WaitMessage
 0x469440 UpdateWindow
 0x469444 UnregisterClassA
 0x469448 UnhookWindowsHookEx
 0x46944c TranslateMessage
 0x469450 TranslateMDISysAccel
 0x469454 TrackPopupMenu
 0x469458 SystemParametersInfoA
 0x46945c ShowWindow
 0x469460 ShowScrollBar
 0x469464 ShowOwnedPopups
 0x469468 ShowCursor
 0x46946c SetWindowsHookExA
 0x469470 SetWindowPos
 0x469474 SetWindowPlacement
 0x469478 SetWindowLongA
 0x46947c SetTimer
 0x469480 SetScrollRange
 0x469484 SetScrollPos
 0x469488 SetScrollInfo
 0x46948c SetRect
 0x469490 SetPropA
 0x469494 SetParent
 0x469498 SetMenuItemInfoA
 0x46949c SetMenu
 0x4694a0 SetForegroundWindow
 0x4694a4 SetFocus
 0x4694a8 SetCursor
 0x4694ac SetClassLongA
 0x4694b0 SetCapture
 0x4694b4 SetActiveWindow
 0x4694b8 SendMessageA
 0x4694bc ScrollWindow
 0x4694c0 ScreenToClient
 0x4694c4 RemovePropA
 0x4694c8 RemoveMenu
 0x4694cc ReleaseDC
 0x4694d0 ReleaseCapture
 0x4694d4 RegisterWindowMessageA
 0x4694d8 RegisterClipboardFormatA
 0x4694dc RegisterClassA
 0x4694e0 RedrawWindow
 0x4694e4 PtInRect
 0x4694e8 PostQuitMessage
 0x4694ec PostMessageA
 0x4694f0 PeekMessageA
 0x4694f4 OffsetRect
 0x4694f8 OemToCharA
 0x4694fc MessageBoxA
 0x469500 MapWindowPoints
 0x469504 MapVirtualKeyA
 0x469508 LoadStringA
 0x46950c LoadKeyboardLayoutA
 0x469510 LoadIconA
 0x469514 LoadCursorA
 0x469518 LoadBitmapA
 0x46951c KillTimer
 0x469520 IsZoomed
 0x469524 IsWindowVisible
 0x469528 IsWindowEnabled
 0x46952c IsWindow
 0x469530 IsRectEmpty
 0x469534 IsIconic
 0x469538 IsDialogMessageA
 0x46953c IsChild
 0x469540 InvalidateRect
 0x469544 IntersectRect
 0x469548 InsertMenuItemA
 0x46954c InsertMenuA
 0x469550 InflateRect
 0x469554 GetWindowThreadProcessId
 0x469558 GetWindowTextA
 0x46955c GetWindowRect
 0x469560 GetWindowPlacement
 0x469564 GetWindowLongA
 0x469568 GetWindowDC
 0x46956c GetTopWindow
 0x469570 GetSystemMetrics
 0x469574 GetSystemMenu
 0x469578 GetSysColorBrush
 0x46957c GetSysColor
 0x469580 GetSubMenu
 0x469584 GetScrollRange
 0x469588 GetScrollPos
 0x46958c GetScrollInfo
 0x469590 GetPropA
 0x469594 GetParent
 0x469598 GetWindow
 0x46959c GetMenuStringA
 0x4695a0 GetMenuState
 0x4695a4 GetMenuItemInfoA
 0x4695a8 GetMenuItemID
 0x4695ac GetMenuItemCount
 0x4695b0 GetMenu
 0x4695b4 GetLastActivePopup
 0x4695b8 GetKeyboardState
 0x4695bc GetKeyboardLayoutList
 0x4695c0 GetKeyboardLayout
 0x4695c4 GetKeyState
 0x4695c8 GetKeyNameTextA
 0x4695cc GetIconInfo
 0x4695d0 GetForegroundWindow
 0x4695d4 GetFocus
 0x4695d8 GetDesktopWindow
 0x4695dc GetDCEx
 0x4695e0 GetDC
 0x4695e4 GetCursorPos
 0x4695e8 GetCursor
 0x4695ec GetClientRect
 0x4695f0 GetClassNameA
 0x4695f4 GetClassInfoA
 0x4695f8 GetCapture
 0x4695fc GetActiveWindow
 0x469600 FrameRect
 0x469604 FindWindowA
 0x469608 FillRect
 0x46960c EqualRect
 0x469610 EnumWindows
 0x469614 EnumThreadWindows
 0x469618 EndPaint
 0x46961c EnableWindow
 0x469620 EnableScrollBar
 0x469624 EnableMenuItem
 0x469628 DrawTextA
 0x46962c DrawMenuBar
 0x469630 DrawIconEx
 0x469634 DrawIcon
 0x469638 DrawFrameControl
 0x46963c DrawEdge
 0x469640 DispatchMessageA
 0x469644 DestroyWindow
 0x469648 DestroyMenu
 0x46964c DestroyIcon
 0x469650 DestroyCursor
 0x469654 DeleteMenu
 0x469658 DefWindowProcA
 0x46965c DefMDIChildProcA
 0x469660 DefFrameProcA
 0x469664 CreatePopupMenu
 0x469668 CreateMenu
 0x46966c CreateIcon
 0x469670 ClientToScreen
 0x469674 CheckMenuItem
 0x469678 CallWindowProcA
 0x46967c CallNextHookEx
 0x469680 BeginPaint
 0x469684 CharNextA
 0x469688 CharLowerA
 0x46968c CharUpperBuffA
 0x469690 CharToOemA
 0x469694 AdjustWindowRectEx
 0x469698 ActivateKeyboardLayout
kernel32.dll
 0x4696a0 Sleep
oleaut32.dll
 0x4696a8 SafeArrayPtrOfIndex
 0x4696ac SafeArrayPutElement
 0x4696b0 SafeArrayGetElement
 0x4696b4 SafeArrayUnaccessData
 0x4696b8 SafeArrayAccessData
 0x4696bc SafeArrayGetUBound
 0x4696c0 SafeArrayGetLBound
 0x4696c4 SafeArrayCreate
 0x4696c8 VariantChangeType
 0x4696cc VariantCopyInd
 0x4696d0 VariantCopy
 0x4696d4 VariantClear
 0x4696d8 VariantInit
ole32.dll
 0x4696e0 CLSIDFromProgID
 0x4696e4 CoCreateInstance
 0x4696e8 CoUninitialize
 0x4696ec CoInitialize
oleaut32.dll
 0x4696f4 GetErrorInfo
 0x4696f8 SysFreeString
comctl32.dll
 0x469700 ImageList_SetIconSize
 0x469704 ImageList_GetIconSize
 0x469708 ImageList_Write
 0x46970c ImageList_Read
 0x469710 ImageList_GetDragImage
 0x469714 ImageList_DragShowNolock
 0x469718 ImageList_SetDragCursorImage
 0x46971c ImageList_DragMove
 0x469720 ImageList_DragLeave
 0x469724 ImageList_DragEnter
 0x469728 ImageList_EndDrag
 0x46972c ImageList_BeginDrag
 0x469730 ImageList_Remove
 0x469734 ImageList_DrawEx
 0x469738 ImageList_Draw
 0x46973c ImageList_GetBkColor
 0x469740 ImageList_SetBkColor
 0x469744 ImageList_ReplaceIcon
 0x469748 ImageList_Add
 0x46974c ImageList_GetImageCount
 0x469750 ImageList_Destroy
 0x469754 ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure