Report - POS_C180.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:09 Machine s1_win7_x6401
Filename POS_C180.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : clean
VT API (file) 3 detected (AIDetectMalware, Malicious, susgen)
md5 d03e7f80a3ad69af54a082c1ebf202ea
sha256 6255614a84b38a43c97504cdcce770df9f3a5d6f23290ce8cfb9354f6a3ce846
ssdeep 24576:Q3zxdAN3NK5lg5l4f3h5plzuJC07xa8q1HNIzlRT+ncOBxnykUvNl4PD8v:Q3YEmEvIlX3+XHPnPDS
imphash e515c8485679aef83f03eab9526daab2
impfuzzy 192:f3zOG1Glc03meuuEaSUvK9ugoaqTBD57CPbOQadR:f3P1q9Ez9YPcPbOQC
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x55717c DeleteCriticalSection
 0x557180 LeaveCriticalSection
 0x557184 EnterCriticalSection
 0x557188 InitializeCriticalSection
 0x55718c VirtualFree
 0x557190 VirtualAlloc
 0x557194 LocalFree
 0x557198 LocalAlloc
 0x55719c GetVersion
 0x5571a0 GetCurrentThreadId
 0x5571a4 InterlockedDecrement
 0x5571a8 InterlockedIncrement
 0x5571ac VirtualQuery
 0x5571b0 WideCharToMultiByte
 0x5571b4 MultiByteToWideChar
 0x5571b8 lstrlenA
 0x5571bc lstrcpynA
 0x5571c0 LoadLibraryExA
 0x5571c4 GetThreadLocale
 0x5571c8 GetStartupInfoA
 0x5571cc GetProcAddress
 0x5571d0 GetModuleHandleA
 0x5571d4 GetModuleFileNameA
 0x5571d8 GetLocaleInfoA
 0x5571dc GetCommandLineA
 0x5571e0 FreeLibrary
 0x5571e4 FindFirstFileA
 0x5571e8 FindClose
 0x5571ec ExitProcess
 0x5571f0 ExitThread
 0x5571f4 CreateThread
 0x5571f8 WriteFile
 0x5571fc UnhandledExceptionFilter
 0x557200 RtlUnwind
 0x557204 RaiseException
 0x557208 GetStdHandle
user32.dll
 0x557210 GetKeyboardType
 0x557214 LoadStringA
 0x557218 MessageBoxA
 0x55721c CharNextA
advapi32.dll
 0x557224 RegQueryValueExA
 0x557228 RegOpenKeyExA
 0x55722c RegCloseKey
oleaut32.dll
 0x557234 SysFreeString
 0x557238 SysReAllocStringLen
 0x55723c SysAllocStringLen
kernel32.dll
 0x557244 TlsSetValue
 0x557248 TlsGetValue
 0x55724c LocalAlloc
 0x557250 GetModuleHandleA
advapi32.dll
 0x557258 RegSetValueExA
 0x55725c RegQueryValueExA
 0x557260 RegQueryValueA
 0x557264 RegOpenKeyExA
 0x557268 RegFlushKey
 0x55726c RegCreateKeyExA
 0x557270 RegCloseKey
kernel32.dll
 0x557278 lstrcpyA
 0x55727c WriteFile
 0x557280 WaitForSingleObject
 0x557284 VirtualQuery
 0x557288 VirtualAlloc
 0x55728c Sleep
 0x557290 SizeofResource
 0x557294 SetThreadLocale
 0x557298 SetFilePointer
 0x55729c SetEvent
 0x5572a0 SetErrorMode
 0x5572a4 SetEndOfFile
 0x5572a8 ResumeThread
 0x5572ac ResetEvent
 0x5572b0 ReleaseMutex
 0x5572b4 ReadFile
 0x5572b8 MultiByteToWideChar
 0x5572bc MulDiv
 0x5572c0 LockResource
 0x5572c4 LoadResource
 0x5572c8 LoadLibraryA
 0x5572cc LeaveCriticalSection
 0x5572d0 IsBadReadPtr
 0x5572d4 InitializeCriticalSection
 0x5572d8 GlobalUnlock
 0x5572dc GlobalReAlloc
 0x5572e0 GlobalHandle
 0x5572e4 GlobalLock
 0x5572e8 GlobalFree
 0x5572ec GlobalFindAtomA
 0x5572f0 GlobalDeleteAtom
 0x5572f4 GlobalAlloc
 0x5572f8 GlobalAddAtomA
 0x5572fc GetVersionExA
 0x557300 GetVersion
 0x557304 GetTimeZoneInformation
 0x557308 GetTickCount
 0x55730c GetThreadLocale
 0x557310 GetTempPathA
 0x557314 GetSystemInfo
 0x557318 GetStringTypeExA
 0x55731c GetStdHandle
 0x557320 GetProcAddress
 0x557324 GetModuleHandleA
 0x557328 GetModuleFileNameA
 0x55732c GetLocaleInfoA
 0x557330 GetLocalTime
 0x557334 GetLastError
 0x557338 GetFullPathNameA
 0x55733c GetFileSize
 0x557340 GetExitCodeThread
 0x557344 GetDiskFreeSpaceA
 0x557348 GetDateFormatA
 0x55734c GetCurrentThreadId
 0x557350 GetCurrentProcessId
 0x557354 GetCPInfo
 0x557358 GetACP
 0x55735c FreeResource
 0x557360 InterlockedIncrement
 0x557364 InterlockedExchange
 0x557368 InterlockedDecrement
 0x55736c FreeLibrary
 0x557370 FormatMessageA
 0x557374 FindResourceA
 0x557378 FindFirstFileA
 0x55737c FindClose
 0x557380 FileTimeToLocalFileTime
 0x557384 FileTimeToDosDateTime
 0x557388 EnumCalendarInfoA
 0x55738c EnterCriticalSection
 0x557390 DeleteCriticalSection
 0x557394 CreateThread
 0x557398 CreateMutexA
 0x55739c CreateFileA
 0x5573a0 CreateEventA
 0x5573a4 CompareStringA
 0x5573a8 CloseHandle
version.dll
 0x5573b0 VerQueryValueA
 0x5573b4 GetFileVersionInfoSizeA
 0x5573b8 GetFileVersionInfoA
gdi32.dll
 0x5573c0 UnrealizeObject
 0x5573c4 StretchBlt
 0x5573c8 SetWindowOrgEx
 0x5573cc SetWindowExtEx
 0x5573d0 SetWinMetaFileBits
 0x5573d4 SetViewportOrgEx
 0x5573d8 SetViewportExtEx
 0x5573dc SetTextColor
 0x5573e0 SetStretchBltMode
 0x5573e4 SetROP2
 0x5573e8 SetPixel
 0x5573ec SetMapMode
 0x5573f0 SetEnhMetaFileBits
 0x5573f4 SetDIBColorTable
 0x5573f8 SetBrushOrgEx
 0x5573fc SetBkMode
 0x557400 SetBkColor
 0x557404 SelectPalette
 0x557408 SelectObject
 0x55740c SelectClipRgn
 0x557410 SaveDC
 0x557414 RoundRect
 0x557418 RestoreDC
 0x55741c Rectangle
 0x557420 RectVisible
 0x557424 RealizePalette
 0x557428 Polyline
 0x55742c Polygon
 0x557430 PolyPolyline
 0x557434 PlayEnhMetaFile
 0x557438 PatBlt
 0x55743c MoveToEx
 0x557440 MaskBlt
 0x557444 LineTo
 0x557448 IntersectClipRect
 0x55744c GetWindowOrgEx
 0x557450 GetWinMetaFileBits
 0x557454 GetViewportOrgEx
 0x557458 GetTextMetricsA
 0x55745c GetTextExtentPointA
 0x557460 GetTextExtentPoint32A
 0x557464 GetSystemPaletteEntries
 0x557468 GetStockObject
 0x55746c GetPixel
 0x557470 GetPaletteEntries
 0x557474 GetObjectA
 0x557478 GetEnhMetaFilePaletteEntries
 0x55747c GetEnhMetaFileHeader
 0x557480 GetEnhMetaFileBits
 0x557484 GetDeviceCaps
 0x557488 GetDIBits
 0x55748c GetDIBColorTable
 0x557490 GetDCOrgEx
 0x557494 GetCurrentPositionEx
 0x557498 GetCurrentObject
 0x55749c GetClipBox
 0x5574a0 GetBrushOrgEx
 0x5574a4 GetBitmapBits
 0x5574a8 GdiFlush
 0x5574ac ExtTextOutA
 0x5574b0 ExtCreateRegion
 0x5574b4 ExtCreatePen
 0x5574b8 ExcludeClipRect
 0x5574bc DeleteObject
 0x5574c0 DeleteEnhMetaFile
 0x5574c4 DeleteDC
 0x5574c8 CreateSolidBrush
 0x5574cc CreateRectRgn
 0x5574d0 CreatePenIndirect
 0x5574d4 CreatePen
 0x5574d8 CreatePalette
 0x5574dc CreateHalftonePalette
 0x5574e0 CreateFontIndirectA
 0x5574e4 CreateDIBitmap
 0x5574e8 CreateDIBSection
 0x5574ec CreateCompatibleDC
 0x5574f0 CreateCompatibleBitmap
 0x5574f4 CreateBrushIndirect
 0x5574f8 CreateBitmap
 0x5574fc CopyEnhMetaFileA
 0x557500 CombineRgn
 0x557504 BitBlt
user32.dll
 0x55750c CreateWindowExA
 0x557510 WindowFromPoint
 0x557514 WinHelpA
 0x557518 WaitMessage
 0x55751c ValidateRect
 0x557520 UpdateWindow
 0x557524 UnregisterClassA
 0x557528 UnionRect
 0x55752c UnhookWindowsHookEx
 0x557530 TranslateMessage
 0x557534 TranslateMDISysAccel
 0x557538 TrackPopupMenu
 0x55753c SystemParametersInfoA
 0x557540 ShowWindow
 0x557544 ShowScrollBar
 0x557548 ShowOwnedPopups
 0x55754c ShowCursor
 0x557550 ShowCaret
 0x557554 SetWindowRgn
 0x557558 SetWindowsHookExA
 0x55755c SetWindowTextA
 0x557560 SetWindowPos
 0x557564 SetWindowPlacement
 0x557568 SetWindowLongW
 0x55756c SetWindowLongA
 0x557570 SetTimer
 0x557574 SetScrollRange
 0x557578 SetScrollPos
 0x55757c SetScrollInfo
 0x557580 SetRect
 0x557584 SetPropA
 0x557588 SetParent
 0x55758c SetMenuItemInfoA
 0x557590 SetMenu
 0x557594 SetKeyboardState
 0x557598 SetForegroundWindow
 0x55759c SetFocus
 0x5575a0 SetCursor
 0x5575a4 SetClipboardData
 0x5575a8 SetClassLongA
 0x5575ac SetCaretPos
 0x5575b0 SetCapture
 0x5575b4 SetActiveWindow
 0x5575b8 SendMessageA
 0x5575bc ScrollWindowEx
 0x5575c0 ScrollWindow
 0x5575c4 ScreenToClient
 0x5575c8 RemovePropA
 0x5575cc RemoveMenu
 0x5575d0 ReleaseDC
 0x5575d4 ReleaseCapture
 0x5575d8 RegisterWindowMessageA
 0x5575dc RegisterClipboardFormatA
 0x5575e0 RegisterClassA
 0x5575e4 RedrawWindow
 0x5575e8 PtInRect
 0x5575ec PostQuitMessage
 0x5575f0 PostMessageA
 0x5575f4 PeekMessageA
 0x5575f8 OpenClipboard
 0x5575fc OffsetRect
 0x557600 OemToCharA
 0x557604 MsgWaitForMultipleObjects
 0x557608 MoveWindow
 0x55760c MessageBoxA
 0x557610 MessageBeep
 0x557614 MapWindowPoints
 0x557618 MapVirtualKeyA
 0x55761c LoadStringA
 0x557620 LoadKeyboardLayoutA
 0x557624 LoadIconA
 0x557628 LoadCursorA
 0x55762c LoadBitmapA
 0x557630 KillTimer
 0x557634 IsZoomed
 0x557638 IsWindowVisible
 0x55763c IsWindowUnicode
 0x557640 IsWindowEnabled
 0x557644 IsWindow
 0x557648 IsRectEmpty
 0x55764c IsIconic
 0x557650 IsDialogMessageA
 0x557654 IsClipboardFormatAvailable
 0x557658 IsChild
 0x55765c IsCharAlphaNumericA
 0x557660 IsCharAlphaA
 0x557664 InvalidateRect
 0x557668 IntersectRect
 0x55766c InsertMenuItemA
 0x557670 InsertMenuA
 0x557674 InflateRect
 0x557678 HideCaret
 0x55767c GetWindowThreadProcessId
 0x557680 GetWindowTextLengthW
 0x557684 GetWindowTextW
 0x557688 GetWindowTextA
 0x55768c GetWindowRect
 0x557690 GetWindowPlacement
 0x557694 GetWindowLongW
 0x557698 GetWindowLongA
 0x55769c GetWindowDC
 0x5576a0 GetTopWindow
 0x5576a4 GetSystemMetrics
 0x5576a8 GetSystemMenu
 0x5576ac GetSysColorBrush
 0x5576b0 GetSysColor
 0x5576b4 GetSubMenu
 0x5576b8 GetScrollRange
 0x5576bc GetScrollPos
 0x5576c0 GetScrollInfo
 0x5576c4 GetPropA
 0x5576c8 GetParent
 0x5576cc GetWindow
 0x5576d0 GetMessageTime
 0x5576d4 GetMenuStringA
 0x5576d8 GetMenuState
 0x5576dc GetMenuItemInfoA
 0x5576e0 GetMenuItemID
 0x5576e4 GetMenuItemCount
 0x5576e8 GetMenu
 0x5576ec GetLastActivePopup
 0x5576f0 GetKeyboardState
 0x5576f4 GetKeyboardLayoutList
 0x5576f8 GetKeyboardLayout
 0x5576fc GetKeyState
 0x557700 GetKeyNameTextA
 0x557704 GetIconInfo
 0x557708 GetForegroundWindow
 0x55770c GetFocus
 0x557710 GetDoubleClickTime
 0x557714 GetDlgItem
 0x557718 GetDlgCtrlID
 0x55771c GetDesktopWindow
 0x557720 GetDCEx
 0x557724 GetDC
 0x557728 GetCursorPos
 0x55772c GetCursor
 0x557730 GetClipboardData
 0x557734 GetClientRect
 0x557738 GetClassNameA
 0x55773c GetClassInfoA
 0x557740 GetCaretPos
 0x557744 GetCapture
 0x557748 GetActiveWindow
 0x55774c FrameRect
 0x557750 FindWindowExA
 0x557754 FindWindowA
 0x557758 FillRect
 0x55775c EqualRect
 0x557760 EnumWindows
 0x557764 EnumThreadWindows
 0x557768 EnumClipboardFormats
 0x55776c EndPaint
 0x557770 EnableWindow
 0x557774 EnableScrollBar
 0x557778 EnableMenuItem
 0x55777c EmptyClipboard
 0x557780 DrawTextW
 0x557784 DrawTextA
 0x557788 DrawMenuBar
 0x55778c DrawIconEx
 0x557790 DrawIcon
 0x557794 DrawFrameControl
 0x557798 DrawFocusRect
 0x55779c DrawEdge
 0x5577a0 DispatchMessageA
 0x5577a4 DestroyWindow
 0x5577a8 DestroyMenu
 0x5577ac DestroyIcon
 0x5577b0 DestroyCursor
 0x5577b4 DestroyCaret
 0x5577b8 DeleteMenu
 0x5577bc DefWindowProcA
 0x5577c0 DefMDIChildProcA
 0x5577c4 DefFrameProcA
 0x5577c8 CreatePopupMenu
 0x5577cc CreateMenu
 0x5577d0 CreateIcon
 0x5577d4 CreateCaret
 0x5577d8 CopyImage
 0x5577dc CloseClipboard
 0x5577e0 ClientToScreen
 0x5577e4 CheckMenuItem
 0x5577e8 CallWindowProcA
 0x5577ec CallNextHookEx
 0x5577f0 BeginPaint
 0x5577f4 CharNextA
 0x5577f8 CharLowerBuffA
 0x5577fc CharLowerA
 0x557800 CharUpperBuffA
 0x557804 CharToOemA
 0x557808 AdjustWindowRectEx
 0x55780c ActivateKeyboardLayout
ole32.dll
 0x557814 CoTaskMemFree
 0x557818 StringFromCLSID
kernel32.dll
 0x557820 Sleep
oleaut32.dll
 0x557828 SafeArrayPtrOfIndex
 0x55782c SafeArrayPutElement
 0x557830 SafeArrayGetElement
 0x557834 SafeArrayUnaccessData
 0x557838 SafeArrayAccessData
 0x55783c SafeArrayGetUBound
 0x557840 SafeArrayGetLBound
 0x557844 SafeArrayCreate
 0x557848 VariantChangeType
 0x55784c VariantCopyInd
 0x557850 VariantCopy
 0x557854 VariantClear
 0x557858 VariantInit
ole32.dll
 0x557860 CoCreateInstance
 0x557864 CoGetMalloc
 0x557868 CoUninitialize
 0x55786c CoInitialize
 0x557870 IsEqualGUID
oleaut32.dll
 0x557878 CreateErrorInfo
 0x55787c GetErrorInfo
 0x557880 SetErrorInfo
 0x557884 SafeArrayCopy
 0x557888 SafeArrayUnaccessData
 0x55788c SafeArrayAccessData
 0x557890 SafeArrayGetUBound
 0x557894 SafeArrayDestroy
 0x557898 SafeArrayCreate
 0x55789c SysFreeString
comctl32.dll
 0x5578a4 ImageList_SetIconSize
 0x5578a8 ImageList_GetIconSize
 0x5578ac ImageList_Write
 0x5578b0 ImageList_Read
 0x5578b4 ImageList_GetDragImage
 0x5578b8 ImageList_DragShowNolock
 0x5578bc ImageList_SetDragCursorImage
 0x5578c0 ImageList_DragMove
 0x5578c4 ImageList_DragLeave
 0x5578c8 ImageList_DragEnter
 0x5578cc ImageList_EndDrag
 0x5578d0 ImageList_BeginDrag
 0x5578d4 ImageList_LoadImageA
 0x5578d8 ImageList_Remove
 0x5578dc ImageList_DrawEx
 0x5578e0 ImageList_Draw
 0x5578e4 ImageList_GetBkColor
 0x5578e8 ImageList_SetBkColor
 0x5578ec ImageList_ReplaceIcon
 0x5578f0 ImageList_Add
 0x5578f4 ImageList_GetImageCount
 0x5578f8 ImageList_Destroy
 0x5578fc ImageList_Create
comdlg32.dll
 0x557904 GetSaveFileNameA
 0x557908 GetOpenFileNameA
kernel32.dll
 0x557910 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure