Report - POS_C072.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:05 Machine s1_win7_x6401
Filename POS_C072.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
2.0
ZERO API file : clean
VT API (file) 11 detected (AIDetectMalware, Strictor, malicious, ai score=88)
md5 0a236bdebd71e66a6145b5438ccd7833
sha256 e952266312e5e9f5051e918f76a9fc677f8e16eec4c6cf73f9227b80c1750817
ssdeep 24576:tLbe/vHy/GfM9UNvKO75sWUYPM1XRfo2/3AXK2nbsjeonR6xtt5137XfLlFPivd7:tXtAMedXUYPSRfoKQX3Sop3TcubPDS
imphash 68ee8b1e519c03d71f97bc14a0319ef9
impfuzzy 192:f3JuG1Glc0FGeuuEaSUvK9ugoHqTB+J7sPbOQad9:f3Z1q/Ez9YgFPbOQc
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5ca190 DeleteCriticalSection
 0x5ca194 LeaveCriticalSection
 0x5ca198 EnterCriticalSection
 0x5ca19c InitializeCriticalSection
 0x5ca1a0 VirtualFree
 0x5ca1a4 VirtualAlloc
 0x5ca1a8 LocalFree
 0x5ca1ac LocalAlloc
 0x5ca1b0 GetVersion
 0x5ca1b4 GetCurrentThreadId
 0x5ca1b8 InterlockedDecrement
 0x5ca1bc InterlockedIncrement
 0x5ca1c0 VirtualQuery
 0x5ca1c4 WideCharToMultiByte
 0x5ca1c8 MultiByteToWideChar
 0x5ca1cc lstrlenA
 0x5ca1d0 lstrcpynA
 0x5ca1d4 LoadLibraryExA
 0x5ca1d8 GetThreadLocale
 0x5ca1dc GetStartupInfoA
 0x5ca1e0 GetProcAddress
 0x5ca1e4 GetModuleHandleA
 0x5ca1e8 GetModuleFileNameA
 0x5ca1ec GetLocaleInfoA
 0x5ca1f0 GetCommandLineA
 0x5ca1f4 FreeLibrary
 0x5ca1f8 FindFirstFileA
 0x5ca1fc FindClose
 0x5ca200 ExitProcess
 0x5ca204 ExitThread
 0x5ca208 CreateThread
 0x5ca20c WriteFile
 0x5ca210 UnhandledExceptionFilter
 0x5ca214 RtlUnwind
 0x5ca218 RaiseException
 0x5ca21c GetStdHandle
user32.dll
 0x5ca224 GetKeyboardType
 0x5ca228 LoadStringA
 0x5ca22c MessageBoxA
 0x5ca230 CharNextA
advapi32.dll
 0x5ca238 RegQueryValueExA
 0x5ca23c RegOpenKeyExA
 0x5ca240 RegCloseKey
oleaut32.dll
 0x5ca248 SysFreeString
 0x5ca24c SysReAllocStringLen
 0x5ca250 SysAllocStringLen
kernel32.dll
 0x5ca258 TlsSetValue
 0x5ca25c TlsGetValue
 0x5ca260 LocalAlloc
 0x5ca264 GetModuleHandleA
advapi32.dll
 0x5ca26c RegSetValueExA
 0x5ca270 RegQueryValueExA
 0x5ca274 RegQueryValueA
 0x5ca278 RegOpenKeyExA
 0x5ca27c RegFlushKey
 0x5ca280 RegCreateKeyExA
 0x5ca284 RegCloseKey
kernel32.dll
 0x5ca28c lstrcpyA
 0x5ca290 lstrcmpA
 0x5ca294 WriteFile
 0x5ca298 WaitForSingleObject
 0x5ca29c VirtualQuery
 0x5ca2a0 VirtualAlloc
 0x5ca2a4 Sleep
 0x5ca2a8 SizeofResource
 0x5ca2ac SetThreadLocale
 0x5ca2b0 SetFilePointer
 0x5ca2b4 SetEvent
 0x5ca2b8 SetErrorMode
 0x5ca2bc SetEndOfFile
 0x5ca2c0 ResumeThread
 0x5ca2c4 ResetEvent
 0x5ca2c8 ReleaseMutex
 0x5ca2cc ReadFile
 0x5ca2d0 MultiByteToWideChar
 0x5ca2d4 MulDiv
 0x5ca2d8 LockResource
 0x5ca2dc LoadResource
 0x5ca2e0 LoadLibraryA
 0x5ca2e4 LeaveCriticalSection
 0x5ca2e8 IsBadReadPtr
 0x5ca2ec InitializeCriticalSection
 0x5ca2f0 GlobalUnlock
 0x5ca2f4 GlobalSize
 0x5ca2f8 GlobalReAlloc
 0x5ca2fc GlobalHandle
 0x5ca300 GlobalLock
 0x5ca304 GlobalFree
 0x5ca308 GlobalFindAtomA
 0x5ca30c GlobalDeleteAtom
 0x5ca310 GlobalAlloc
 0x5ca314 GlobalAddAtomA
 0x5ca318 GetVersionExA
 0x5ca31c GetVersion
 0x5ca320 GetTimeZoneInformation
 0x5ca324 GetTickCount
 0x5ca328 GetThreadLocale
 0x5ca32c GetTempPathA
 0x5ca330 GetSystemInfo
 0x5ca334 GetStringTypeExA
 0x5ca338 GetStdHandle
 0x5ca33c GetProcAddress
 0x5ca340 GetModuleHandleA
 0x5ca344 GetModuleFileNameA
 0x5ca348 GetLocaleInfoA
 0x5ca34c GetLocalTime
 0x5ca350 GetLastError
 0x5ca354 GetFullPathNameA
 0x5ca358 GetFileSize
 0x5ca35c GetExitCodeThread
 0x5ca360 GetDiskFreeSpaceA
 0x5ca364 GetDateFormatA
 0x5ca368 GetCurrentThreadId
 0x5ca36c GetCurrentProcessId
 0x5ca370 GetCPInfo
 0x5ca374 GetACP
 0x5ca378 FreeResource
 0x5ca37c InterlockedIncrement
 0x5ca380 InterlockedExchange
 0x5ca384 InterlockedDecrement
 0x5ca388 FreeLibrary
 0x5ca38c FormatMessageA
 0x5ca390 FindResourceA
 0x5ca394 FindFirstFileA
 0x5ca398 FindClose
 0x5ca39c FileTimeToLocalFileTime
 0x5ca3a0 FileTimeToDosDateTime
 0x5ca3a4 EnumCalendarInfoA
 0x5ca3a8 EnterCriticalSection
 0x5ca3ac DeleteCriticalSection
 0x5ca3b0 CreateThread
 0x5ca3b4 CreateMutexA
 0x5ca3b8 CreateFileA
 0x5ca3bc CreateEventA
 0x5ca3c0 CompareStringA
 0x5ca3c4 CloseHandle
version.dll
 0x5ca3cc VerQueryValueA
 0x5ca3d0 GetFileVersionInfoSizeA
 0x5ca3d4 GetFileVersionInfoA
gdi32.dll
 0x5ca3dc UnrealizeObject
 0x5ca3e0 StretchBlt
 0x5ca3e4 SetWindowOrgEx
 0x5ca3e8 SetWindowExtEx
 0x5ca3ec SetWinMetaFileBits
 0x5ca3f0 SetViewportOrgEx
 0x5ca3f4 SetViewportExtEx
 0x5ca3f8 SetTextColor
 0x5ca3fc SetStretchBltMode
 0x5ca400 SetROP2
 0x5ca404 SetPixel
 0x5ca408 SetMapMode
 0x5ca40c SetEnhMetaFileBits
 0x5ca410 SetDIBColorTable
 0x5ca414 SetBrushOrgEx
 0x5ca418 SetBkMode
 0x5ca41c SetBkColor
 0x5ca420 SelectPalette
 0x5ca424 SelectObject
 0x5ca428 SelectClipRgn
 0x5ca42c SaveDC
 0x5ca430 RoundRect
 0x5ca434 RestoreDC
 0x5ca438 Rectangle
 0x5ca43c RectVisible
 0x5ca440 RealizePalette
 0x5ca444 Polyline
 0x5ca448 Polygon
 0x5ca44c PolyPolyline
 0x5ca450 PlayEnhMetaFile
 0x5ca454 PatBlt
 0x5ca458 MoveToEx
 0x5ca45c MaskBlt
 0x5ca460 LineTo
 0x5ca464 LPtoDP
 0x5ca468 IntersectClipRect
 0x5ca46c GetWindowOrgEx
 0x5ca470 GetWinMetaFileBits
 0x5ca474 GetViewportOrgEx
 0x5ca478 GetTextMetricsA
 0x5ca47c GetTextExtentPointA
 0x5ca480 GetTextExtentPoint32A
 0x5ca484 GetSystemPaletteEntries
 0x5ca488 GetStockObject
 0x5ca48c GetPixel
 0x5ca490 GetPaletteEntries
 0x5ca494 GetOutlineTextMetricsA
 0x5ca498 GetObjectA
 0x5ca49c GetNearestColor
 0x5ca4a0 GetEnhMetaFilePaletteEntries
 0x5ca4a4 GetEnhMetaFileHeader
 0x5ca4a8 GetEnhMetaFileBits
 0x5ca4ac GetDeviceCaps
 0x5ca4b0 GetDIBits
 0x5ca4b4 GetDIBColorTable
 0x5ca4b8 GetDCOrgEx
 0x5ca4bc GetCurrentPositionEx
 0x5ca4c0 GetCurrentObject
 0x5ca4c4 GetClipRgn
 0x5ca4c8 GetClipBox
 0x5ca4cc GetBrushOrgEx
 0x5ca4d0 GetBitmapBits
 0x5ca4d4 GdiFlush
 0x5ca4d8 ExtTextOutA
 0x5ca4dc ExtSelectClipRgn
 0x5ca4e0 ExtCreateRegion
 0x5ca4e4 ExtCreatePen
 0x5ca4e8 ExcludeClipRect
 0x5ca4ec Ellipse
 0x5ca4f0 DeleteObject
 0x5ca4f4 DeleteEnhMetaFile
 0x5ca4f8 DeleteDC
 0x5ca4fc CreateSolidBrush
 0x5ca500 CreateRectRgn
 0x5ca504 CreatePolygonRgn
 0x5ca508 CreatePenIndirect
 0x5ca50c CreatePen
 0x5ca510 CreatePalette
 0x5ca514 CreateHalftonePalette
 0x5ca518 CreateFontIndirectA
 0x5ca51c CreateDIBitmap
 0x5ca520 CreateDIBSection
 0x5ca524 CreateCompatibleDC
 0x5ca528 CreateCompatibleBitmap
 0x5ca52c CreateBrushIndirect
 0x5ca530 CreateBitmap
 0x5ca534 CopyEnhMetaFileA
 0x5ca538 CombineRgn
 0x5ca53c BitBlt
user32.dll
 0x5ca544 CreateWindowExA
 0x5ca548 WindowFromPoint
 0x5ca54c WinHelpA
 0x5ca550 WaitMessage
 0x5ca554 ValidateRect
 0x5ca558 UpdateWindow
 0x5ca55c UnregisterClassA
 0x5ca560 UnionRect
 0x5ca564 UnhookWindowsHookEx
 0x5ca568 TranslateMessage
 0x5ca56c TranslateMDISysAccel
 0x5ca570 TrackPopupMenu
 0x5ca574 SystemParametersInfoA
 0x5ca578 ShowWindow
 0x5ca57c ShowScrollBar
 0x5ca580 ShowOwnedPopups
 0x5ca584 ShowCursor
 0x5ca588 ShowCaret
 0x5ca58c SetWindowRgn
 0x5ca590 SetWindowsHookExA
 0x5ca594 SetWindowTextA
 0x5ca598 SetWindowPos
 0x5ca59c SetWindowPlacement
 0x5ca5a0 SetWindowLongW
 0x5ca5a4 SetWindowLongA
 0x5ca5a8 SetTimer
 0x5ca5ac SetScrollRange
 0x5ca5b0 SetScrollPos
 0x5ca5b4 SetScrollInfo
 0x5ca5b8 SetRect
 0x5ca5bc SetPropA
 0x5ca5c0 SetParent
 0x5ca5c4 SetMenuItemInfoA
 0x5ca5c8 SetMenu
 0x5ca5cc SetKeyboardState
 0x5ca5d0 SetForegroundWindow
 0x5ca5d4 SetFocus
 0x5ca5d8 SetCursor
 0x5ca5dc SetClipboardData
 0x5ca5e0 SetClassLongA
 0x5ca5e4 SetCaretPos
 0x5ca5e8 SetCapture
 0x5ca5ec SetActiveWindow
 0x5ca5f0 SendMessageA
 0x5ca5f4 ScrollWindowEx
 0x5ca5f8 ScrollWindow
 0x5ca5fc ScreenToClient
 0x5ca600 RemovePropA
 0x5ca604 RemoveMenu
 0x5ca608 ReleaseDC
 0x5ca60c ReleaseCapture
 0x5ca610 RegisterWindowMessageA
 0x5ca614 RegisterClipboardFormatA
 0x5ca618 RegisterClassA
 0x5ca61c RedrawWindow
 0x5ca620 PtInRect
 0x5ca624 PostQuitMessage
 0x5ca628 PostMessageA
 0x5ca62c PeekMessageA
 0x5ca630 OpenClipboard
 0x5ca634 OffsetRect
 0x5ca638 OemToCharA
 0x5ca63c MsgWaitForMultipleObjects
 0x5ca640 MoveWindow
 0x5ca644 MessageBoxA
 0x5ca648 MessageBeep
 0x5ca64c MapWindowPoints
 0x5ca650 MapVirtualKeyA
 0x5ca654 LoadStringA
 0x5ca658 LoadKeyboardLayoutA
 0x5ca65c LoadIconA
 0x5ca660 LoadCursorA
 0x5ca664 LoadBitmapA
 0x5ca668 KillTimer
 0x5ca66c IsZoomed
 0x5ca670 IsWindowVisible
 0x5ca674 IsWindowUnicode
 0x5ca678 IsWindowEnabled
 0x5ca67c IsWindow
 0x5ca680 IsRectEmpty
 0x5ca684 IsIconic
 0x5ca688 IsDialogMessageA
 0x5ca68c IsClipboardFormatAvailable
 0x5ca690 IsChild
 0x5ca694 IsCharAlphaNumericA
 0x5ca698 IsCharAlphaA
 0x5ca69c InvalidateRect
 0x5ca6a0 IntersectRect
 0x5ca6a4 InsertMenuItemA
 0x5ca6a8 InsertMenuA
 0x5ca6ac InflateRect
 0x5ca6b0 HideCaret
 0x5ca6b4 GetWindowThreadProcessId
 0x5ca6b8 GetWindowTextLengthW
 0x5ca6bc GetWindowTextW
 0x5ca6c0 GetWindowTextA
 0x5ca6c4 GetWindowRect
 0x5ca6c8 GetWindowPlacement
 0x5ca6cc GetWindowLongW
 0x5ca6d0 GetWindowLongA
 0x5ca6d4 GetWindowDC
 0x5ca6d8 GetTopWindow
 0x5ca6dc GetSystemMetrics
 0x5ca6e0 GetSystemMenu
 0x5ca6e4 GetSysColorBrush
 0x5ca6e8 GetSysColor
 0x5ca6ec GetSubMenu
 0x5ca6f0 GetScrollRange
 0x5ca6f4 GetScrollPos
 0x5ca6f8 GetScrollInfo
 0x5ca6fc GetPropA
 0x5ca700 GetParent
 0x5ca704 GetWindow
 0x5ca708 GetMessageTime
 0x5ca70c GetMessagePos
 0x5ca710 GetMenuStringA
 0x5ca714 GetMenuState
 0x5ca718 GetMenuItemInfoA
 0x5ca71c GetMenuItemID
 0x5ca720 GetMenuItemCount
 0x5ca724 GetMenu
 0x5ca728 GetLastActivePopup
 0x5ca72c GetKeyboardState
 0x5ca730 GetKeyboardLayoutList
 0x5ca734 GetKeyboardLayout
 0x5ca738 GetKeyState
 0x5ca73c GetKeyNameTextA
 0x5ca740 GetIconInfo
 0x5ca744 GetForegroundWindow
 0x5ca748 GetFocus
 0x5ca74c GetDoubleClickTime
 0x5ca750 GetDlgItem
 0x5ca754 GetDlgCtrlID
 0x5ca758 GetDesktopWindow
 0x5ca75c GetDCEx
 0x5ca760 GetDC
 0x5ca764 GetCursorPos
 0x5ca768 GetCursor
 0x5ca76c GetClipboardData
 0x5ca770 GetClientRect
 0x5ca774 GetClassNameA
 0x5ca778 GetClassInfoA
 0x5ca77c GetCaretPos
 0x5ca780 GetCapture
 0x5ca784 GetActiveWindow
 0x5ca788 FrameRect
 0x5ca78c FindWindowExA
 0x5ca790 FindWindowA
 0x5ca794 FillRect
 0x5ca798 EqualRect
 0x5ca79c EnumWindows
 0x5ca7a0 EnumThreadWindows
 0x5ca7a4 EnumClipboardFormats
 0x5ca7a8 EndPaint
 0x5ca7ac EnableWindow
 0x5ca7b0 EnableScrollBar
 0x5ca7b4 EnableMenuItem
 0x5ca7b8 EmptyClipboard
 0x5ca7bc DrawTextExA
 0x5ca7c0 DrawTextW
 0x5ca7c4 DrawTextA
 0x5ca7c8 DrawMenuBar
 0x5ca7cc DrawIconEx
 0x5ca7d0 DrawIcon
 0x5ca7d4 DrawFrameControl
 0x5ca7d8 DrawFocusRect
 0x5ca7dc DrawEdge
 0x5ca7e0 DispatchMessageA
 0x5ca7e4 DestroyWindow
 0x5ca7e8 DestroyMenu
 0x5ca7ec DestroyIcon
 0x5ca7f0 DestroyCursor
 0x5ca7f4 DestroyCaret
 0x5ca7f8 DeleteMenu
 0x5ca7fc DefWindowProcA
 0x5ca800 DefMDIChildProcA
 0x5ca804 DefFrameProcA
 0x5ca808 CreatePopupMenu
 0x5ca80c CreateMenu
 0x5ca810 CreateIcon
 0x5ca814 CreateCaret
 0x5ca818 CopyImage
 0x5ca81c CloseClipboard
 0x5ca820 ClientToScreen
 0x5ca824 ChildWindowFromPoint
 0x5ca828 CheckMenuItem
 0x5ca82c CallWindowProcA
 0x5ca830 CallNextHookEx
 0x5ca834 BeginPaint
 0x5ca838 CharNextA
 0x5ca83c CharLowerBuffA
 0x5ca840 CharLowerA
 0x5ca844 CharUpperBuffA
 0x5ca848 CharToOemA
 0x5ca84c AdjustWindowRectEx
 0x5ca850 ActivateKeyboardLayout
ole32.dll
 0x5ca858 CoTaskMemFree
 0x5ca85c StringFromCLSID
kernel32.dll
 0x5ca864 Sleep
oleaut32.dll
 0x5ca86c SafeArrayPtrOfIndex
 0x5ca870 SafeArrayPutElement
 0x5ca874 SafeArrayGetElement
 0x5ca878 SafeArrayUnaccessData
 0x5ca87c SafeArrayAccessData
 0x5ca880 SafeArrayGetUBound
 0x5ca884 SafeArrayGetLBound
 0x5ca888 SafeArrayRedim
 0x5ca88c SafeArrayCreate
 0x5ca890 VariantChangeType
 0x5ca894 VariantCopyInd
 0x5ca898 VariantCopy
 0x5ca89c VariantClear
 0x5ca8a0 VariantInit
ole32.dll
 0x5ca8a8 CoTaskMemAlloc
 0x5ca8ac CoCreateInstance
 0x5ca8b0 CoGetMalloc
 0x5ca8b4 CoUninitialize
 0x5ca8b8 CoInitialize
 0x5ca8bc IsEqualGUID
oleaut32.dll
 0x5ca8c4 CreateErrorInfo
 0x5ca8c8 GetErrorInfo
 0x5ca8cc SetErrorInfo
 0x5ca8d0 SafeArrayCopy
 0x5ca8d4 SafeArrayUnaccessData
 0x5ca8d8 SafeArrayAccessData
 0x5ca8dc SafeArrayGetUBound
 0x5ca8e0 SafeArrayDestroy
 0x5ca8e4 SafeArrayCreate
 0x5ca8e8 SysFreeString
comctl32.dll
 0x5ca8f0 ImageList_SetIconSize
 0x5ca8f4 ImageList_GetIconSize
 0x5ca8f8 ImageList_Write
 0x5ca8fc ImageList_Read
 0x5ca900 ImageList_GetDragImage
 0x5ca904 ImageList_DragShowNolock
 0x5ca908 ImageList_SetDragCursorImage
 0x5ca90c ImageList_DragMove
 0x5ca910 ImageList_DragLeave
 0x5ca914 ImageList_DragEnter
 0x5ca918 ImageList_EndDrag
 0x5ca91c ImageList_BeginDrag
 0x5ca920 ImageList_LoadImageA
 0x5ca924 ImageList_Remove
 0x5ca928 ImageList_DrawEx
 0x5ca92c ImageList_Replace
 0x5ca930 ImageList_Draw
 0x5ca934 ImageList_GetBkColor
 0x5ca938 ImageList_SetBkColor
 0x5ca93c ImageList_ReplaceIcon
 0x5ca940 ImageList_Add
 0x5ca944 ImageList_GetImageCount
 0x5ca948 ImageList_Destroy
 0x5ca94c ImageList_Create
 0x5ca950 InitCommonControls
comdlg32.dll
 0x5ca958 GetSaveFileNameA
 0x5ca95c GetOpenFileNameA
kernel32.dll
 0x5ca964 MulDiv
kernel32.dll
 0x5ca96c MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure