Report - POS_C079.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:06 Machine s1_win7_x6403
Filename POS_C079.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 11 detected (Strictor, malicious, ai score=86, susgen)
md5 e0172234f8bfbf6caab3256f36999589
sha256 48da39c0d4c4d3fe391b54582b044e34924bd1778da7f4b4a9e0e6ef53865813
ssdeep 24576:DHm1GV2ScFdrrS6vzTtsojdd9en5cP4Qg6rf1kDIABaGiHRlcCcLYr0MMfWR2e4o:DH8NT9G5CgzPMfmPDTxi
imphash 92c2ee4988f0629ae080b641fbef84f6
impfuzzy 192:f3zuG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3H1q/Ez9YPpPbOQc
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5c6190 DeleteCriticalSection
 0x5c6194 LeaveCriticalSection
 0x5c6198 EnterCriticalSection
 0x5c619c InitializeCriticalSection
 0x5c61a0 VirtualFree
 0x5c61a4 VirtualAlloc
 0x5c61a8 LocalFree
 0x5c61ac LocalAlloc
 0x5c61b0 GetVersion
 0x5c61b4 GetCurrentThreadId
 0x5c61b8 InterlockedDecrement
 0x5c61bc InterlockedIncrement
 0x5c61c0 VirtualQuery
 0x5c61c4 WideCharToMultiByte
 0x5c61c8 MultiByteToWideChar
 0x5c61cc lstrlenA
 0x5c61d0 lstrcpynA
 0x5c61d4 LoadLibraryExA
 0x5c61d8 GetThreadLocale
 0x5c61dc GetStartupInfoA
 0x5c61e0 GetProcAddress
 0x5c61e4 GetModuleHandleA
 0x5c61e8 GetModuleFileNameA
 0x5c61ec GetLocaleInfoA
 0x5c61f0 GetCommandLineA
 0x5c61f4 FreeLibrary
 0x5c61f8 FindFirstFileA
 0x5c61fc FindClose
 0x5c6200 ExitProcess
 0x5c6204 ExitThread
 0x5c6208 CreateThread
 0x5c620c WriteFile
 0x5c6210 UnhandledExceptionFilter
 0x5c6214 RtlUnwind
 0x5c6218 RaiseException
 0x5c621c GetStdHandle
user32.dll
 0x5c6224 GetKeyboardType
 0x5c6228 LoadStringA
 0x5c622c MessageBoxA
 0x5c6230 CharNextA
advapi32.dll
 0x5c6238 RegQueryValueExA
 0x5c623c RegOpenKeyExA
 0x5c6240 RegCloseKey
oleaut32.dll
 0x5c6248 SysFreeString
 0x5c624c SysReAllocStringLen
 0x5c6250 SysAllocStringLen
kernel32.dll
 0x5c6258 TlsSetValue
 0x5c625c TlsGetValue
 0x5c6260 LocalAlloc
 0x5c6264 GetModuleHandleA
advapi32.dll
 0x5c626c RegSetValueExA
 0x5c6270 RegQueryValueExA
 0x5c6274 RegQueryValueA
 0x5c6278 RegOpenKeyExA
 0x5c627c RegFlushKey
 0x5c6280 RegCreateKeyExA
 0x5c6284 RegCloseKey
kernel32.dll
 0x5c628c lstrcpyA
 0x5c6290 WriteFile
 0x5c6294 WaitForSingleObject
 0x5c6298 VirtualQuery
 0x5c629c VirtualAlloc
 0x5c62a0 Sleep
 0x5c62a4 SizeofResource
 0x5c62a8 SetThreadLocale
 0x5c62ac SetFilePointer
 0x5c62b0 SetEvent
 0x5c62b4 SetErrorMode
 0x5c62b8 SetEndOfFile
 0x5c62bc ResumeThread
 0x5c62c0 ResetEvent
 0x5c62c4 ReleaseMutex
 0x5c62c8 ReadFile
 0x5c62cc MultiByteToWideChar
 0x5c62d0 MulDiv
 0x5c62d4 LockResource
 0x5c62d8 LoadResource
 0x5c62dc LoadLibraryA
 0x5c62e0 LeaveCriticalSection
 0x5c62e4 IsBadReadPtr
 0x5c62e8 InitializeCriticalSection
 0x5c62ec GlobalUnlock
 0x5c62f0 GlobalSize
 0x5c62f4 GlobalReAlloc
 0x5c62f8 GlobalHandle
 0x5c62fc GlobalLock
 0x5c6300 GlobalFree
 0x5c6304 GlobalFindAtomA
 0x5c6308 GlobalDeleteAtom
 0x5c630c GlobalAlloc
 0x5c6310 GlobalAddAtomA
 0x5c6314 GetVersionExA
 0x5c6318 GetVersion
 0x5c631c GetTimeZoneInformation
 0x5c6320 GetTickCount
 0x5c6324 GetThreadLocale
 0x5c6328 GetTempPathA
 0x5c632c GetSystemInfo
 0x5c6330 GetStringTypeExA
 0x5c6334 GetStdHandle
 0x5c6338 GetProcAddress
 0x5c633c GetModuleHandleA
 0x5c6340 GetModuleFileNameA
 0x5c6344 GetLocaleInfoA
 0x5c6348 GetLocalTime
 0x5c634c GetLastError
 0x5c6350 GetFullPathNameA
 0x5c6354 GetFileSize
 0x5c6358 GetExitCodeThread
 0x5c635c GetDiskFreeSpaceA
 0x5c6360 GetDateFormatA
 0x5c6364 GetCurrentThreadId
 0x5c6368 GetCurrentProcessId
 0x5c636c GetCPInfo
 0x5c6370 GetACP
 0x5c6374 FreeResource
 0x5c6378 InterlockedIncrement
 0x5c637c InterlockedExchange
 0x5c6380 InterlockedDecrement
 0x5c6384 FreeLibrary
 0x5c6388 FormatMessageA
 0x5c638c FindResourceA
 0x5c6390 FindFirstFileA
 0x5c6394 FindClose
 0x5c6398 FileTimeToLocalFileTime
 0x5c639c FileTimeToDosDateTime
 0x5c63a0 EnumCalendarInfoA
 0x5c63a4 EnterCriticalSection
 0x5c63a8 DeleteCriticalSection
 0x5c63ac CreateThread
 0x5c63b0 CreateMutexA
 0x5c63b4 CreateFileA
 0x5c63b8 CreateEventA
 0x5c63bc CompareStringA
 0x5c63c0 CloseHandle
version.dll
 0x5c63c8 VerQueryValueA
 0x5c63cc GetFileVersionInfoSizeA
 0x5c63d0 GetFileVersionInfoA
gdi32.dll
 0x5c63d8 UnrealizeObject
 0x5c63dc StretchBlt
 0x5c63e0 SetWindowOrgEx
 0x5c63e4 SetWindowExtEx
 0x5c63e8 SetWinMetaFileBits
 0x5c63ec SetViewportOrgEx
 0x5c63f0 SetViewportExtEx
 0x5c63f4 SetTextColor
 0x5c63f8 SetStretchBltMode
 0x5c63fc SetROP2
 0x5c6400 SetPixel
 0x5c6404 SetMapMode
 0x5c6408 SetEnhMetaFileBits
 0x5c640c SetDIBColorTable
 0x5c6410 SetBrushOrgEx
 0x5c6414 SetBkMode
 0x5c6418 SetBkColor
 0x5c641c SelectPalette
 0x5c6420 SelectObject
 0x5c6424 SelectClipRgn
 0x5c6428 SaveDC
 0x5c642c RoundRect
 0x5c6430 RestoreDC
 0x5c6434 Rectangle
 0x5c6438 RectVisible
 0x5c643c RealizePalette
 0x5c6440 Polyline
 0x5c6444 Polygon
 0x5c6448 PolyPolyline
 0x5c644c PlayEnhMetaFile
 0x5c6450 PatBlt
 0x5c6454 MoveToEx
 0x5c6458 MaskBlt
 0x5c645c LineTo
 0x5c6460 LPtoDP
 0x5c6464 IntersectClipRect
 0x5c6468 GetWindowOrgEx
 0x5c646c GetWinMetaFileBits
 0x5c6470 GetViewportOrgEx
 0x5c6474 GetTextMetricsA
 0x5c6478 GetTextExtentPointA
 0x5c647c GetTextExtentPoint32A
 0x5c6480 GetSystemPaletteEntries
 0x5c6484 GetStockObject
 0x5c6488 GetPixel
 0x5c648c GetPaletteEntries
 0x5c6490 GetOutlineTextMetricsA
 0x5c6494 GetObjectA
 0x5c6498 GetNearestColor
 0x5c649c GetEnhMetaFilePaletteEntries
 0x5c64a0 GetEnhMetaFileHeader
 0x5c64a4 GetEnhMetaFileBits
 0x5c64a8 GetDeviceCaps
 0x5c64ac GetDIBits
 0x5c64b0 GetDIBColorTable
 0x5c64b4 GetDCOrgEx
 0x5c64b8 GetCurrentPositionEx
 0x5c64bc GetCurrentObject
 0x5c64c0 GetClipRgn
 0x5c64c4 GetClipBox
 0x5c64c8 GetBrushOrgEx
 0x5c64cc GetBitmapBits
 0x5c64d0 GdiFlush
 0x5c64d4 ExtTextOutA
 0x5c64d8 ExtSelectClipRgn
 0x5c64dc ExtCreateRegion
 0x5c64e0 ExtCreatePen
 0x5c64e4 ExcludeClipRect
 0x5c64e8 Ellipse
 0x5c64ec DeleteObject
 0x5c64f0 DeleteEnhMetaFile
 0x5c64f4 DeleteDC
 0x5c64f8 CreateSolidBrush
 0x5c64fc CreateRectRgn
 0x5c6500 CreatePolygonRgn
 0x5c6504 CreatePenIndirect
 0x5c6508 CreatePen
 0x5c650c CreatePalette
 0x5c6510 CreateHalftonePalette
 0x5c6514 CreateFontIndirectA
 0x5c6518 CreateDIBitmap
 0x5c651c CreateDIBSection
 0x5c6520 CreateCompatibleDC
 0x5c6524 CreateCompatibleBitmap
 0x5c6528 CreateBrushIndirect
 0x5c652c CreateBitmap
 0x5c6530 CopyEnhMetaFileA
 0x5c6534 CombineRgn
 0x5c6538 BitBlt
user32.dll
 0x5c6540 CreateWindowExA
 0x5c6544 WindowFromPoint
 0x5c6548 WinHelpA
 0x5c654c WaitMessage
 0x5c6550 ValidateRect
 0x5c6554 UpdateWindow
 0x5c6558 UnregisterClassA
 0x5c655c UnionRect
 0x5c6560 UnhookWindowsHookEx
 0x5c6564 TranslateMessage
 0x5c6568 TranslateMDISysAccel
 0x5c656c TrackPopupMenu
 0x5c6570 SystemParametersInfoA
 0x5c6574 ShowWindow
 0x5c6578 ShowScrollBar
 0x5c657c ShowOwnedPopups
 0x5c6580 ShowCursor
 0x5c6584 ShowCaret
 0x5c6588 SetWindowRgn
 0x5c658c SetWindowsHookExA
 0x5c6590 SetWindowTextA
 0x5c6594 SetWindowPos
 0x5c6598 SetWindowPlacement
 0x5c659c SetWindowLongW
 0x5c65a0 SetWindowLongA
 0x5c65a4 SetTimer
 0x5c65a8 SetScrollRange
 0x5c65ac SetScrollPos
 0x5c65b0 SetScrollInfo
 0x5c65b4 SetRect
 0x5c65b8 SetPropA
 0x5c65bc SetParent
 0x5c65c0 SetMenuItemInfoA
 0x5c65c4 SetMenu
 0x5c65c8 SetKeyboardState
 0x5c65cc SetForegroundWindow
 0x5c65d0 SetFocus
 0x5c65d4 SetCursor
 0x5c65d8 SetClipboardData
 0x5c65dc SetClassLongA
 0x5c65e0 SetCaretPos
 0x5c65e4 SetCapture
 0x5c65e8 SetActiveWindow
 0x5c65ec SendMessageA
 0x5c65f0 ScrollWindowEx
 0x5c65f4 ScrollWindow
 0x5c65f8 ScreenToClient
 0x5c65fc RemovePropA
 0x5c6600 RemoveMenu
 0x5c6604 ReleaseDC
 0x5c6608 ReleaseCapture
 0x5c660c RegisterWindowMessageA
 0x5c6610 RegisterClipboardFormatA
 0x5c6614 RegisterClassA
 0x5c6618 RedrawWindow
 0x5c661c PtInRect
 0x5c6620 PostQuitMessage
 0x5c6624 PostMessageA
 0x5c6628 PeekMessageA
 0x5c662c OpenClipboard
 0x5c6630 OffsetRect
 0x5c6634 OemToCharA
 0x5c6638 MsgWaitForMultipleObjects
 0x5c663c MoveWindow
 0x5c6640 MessageBoxA
 0x5c6644 MessageBeep
 0x5c6648 MapWindowPoints
 0x5c664c MapVirtualKeyA
 0x5c6650 LoadStringA
 0x5c6654 LoadKeyboardLayoutA
 0x5c6658 LoadIconA
 0x5c665c LoadCursorA
 0x5c6660 LoadBitmapA
 0x5c6664 KillTimer
 0x5c6668 IsZoomed
 0x5c666c IsWindowVisible
 0x5c6670 IsWindowUnicode
 0x5c6674 IsWindowEnabled
 0x5c6678 IsWindow
 0x5c667c IsRectEmpty
 0x5c6680 IsIconic
 0x5c6684 IsDialogMessageA
 0x5c6688 IsClipboardFormatAvailable
 0x5c668c IsChild
 0x5c6690 IsCharAlphaNumericA
 0x5c6694 IsCharAlphaA
 0x5c6698 InvalidateRect
 0x5c669c IntersectRect
 0x5c66a0 InsertMenuItemA
 0x5c66a4 InsertMenuA
 0x5c66a8 InflateRect
 0x5c66ac HideCaret
 0x5c66b0 GetWindowThreadProcessId
 0x5c66b4 GetWindowTextLengthW
 0x5c66b8 GetWindowTextW
 0x5c66bc GetWindowTextA
 0x5c66c0 GetWindowRect
 0x5c66c4 GetWindowPlacement
 0x5c66c8 GetWindowLongW
 0x5c66cc GetWindowLongA
 0x5c66d0 GetWindowDC
 0x5c66d4 GetTopWindow
 0x5c66d8 GetSystemMetrics
 0x5c66dc GetSystemMenu
 0x5c66e0 GetSysColorBrush
 0x5c66e4 GetSysColor
 0x5c66e8 GetSubMenu
 0x5c66ec GetScrollRange
 0x5c66f0 GetScrollPos
 0x5c66f4 GetScrollInfo
 0x5c66f8 GetPropA
 0x5c66fc GetParent
 0x5c6700 GetWindow
 0x5c6704 GetMessageTime
 0x5c6708 GetMenuStringA
 0x5c670c GetMenuState
 0x5c6710 GetMenuItemInfoA
 0x5c6714 GetMenuItemID
 0x5c6718 GetMenuItemCount
 0x5c671c GetMenu
 0x5c6720 GetLastActivePopup
 0x5c6724 GetKeyboardState
 0x5c6728 GetKeyboardLayoutList
 0x5c672c GetKeyboardLayout
 0x5c6730 GetKeyState
 0x5c6734 GetKeyNameTextA
 0x5c6738 GetIconInfo
 0x5c673c GetForegroundWindow
 0x5c6740 GetFocus
 0x5c6744 GetDoubleClickTime
 0x5c6748 GetDlgItem
 0x5c674c GetDlgCtrlID
 0x5c6750 GetDesktopWindow
 0x5c6754 GetDCEx
 0x5c6758 GetDC
 0x5c675c GetCursorPos
 0x5c6760 GetCursor
 0x5c6764 GetClipboardData
 0x5c6768 GetClientRect
 0x5c676c GetClassNameA
 0x5c6770 GetClassInfoA
 0x5c6774 GetCaretPos
 0x5c6778 GetCapture
 0x5c677c GetActiveWindow
 0x5c6780 FrameRect
 0x5c6784 FindWindowExA
 0x5c6788 FindWindowA
 0x5c678c FillRect
 0x5c6790 EqualRect
 0x5c6794 EnumWindows
 0x5c6798 EnumThreadWindows
 0x5c679c EnumClipboardFormats
 0x5c67a0 EndPaint
 0x5c67a4 EnableWindow
 0x5c67a8 EnableScrollBar
 0x5c67ac EnableMenuItem
 0x5c67b0 EmptyClipboard
 0x5c67b4 DrawTextExA
 0x5c67b8 DrawTextW
 0x5c67bc DrawTextA
 0x5c67c0 DrawMenuBar
 0x5c67c4 DrawIconEx
 0x5c67c8 DrawIcon
 0x5c67cc DrawFrameControl
 0x5c67d0 DrawFocusRect
 0x5c67d4 DrawEdge
 0x5c67d8 DispatchMessageA
 0x5c67dc DestroyWindow
 0x5c67e0 DestroyMenu
 0x5c67e4 DestroyIcon
 0x5c67e8 DestroyCursor
 0x5c67ec DestroyCaret
 0x5c67f0 DeleteMenu
 0x5c67f4 DefWindowProcA
 0x5c67f8 DefMDIChildProcA
 0x5c67fc DefFrameProcA
 0x5c6800 CreatePopupMenu
 0x5c6804 CreateMenu
 0x5c6808 CreateIcon
 0x5c680c CreateCaret
 0x5c6810 CopyImage
 0x5c6814 CloseClipboard
 0x5c6818 ClientToScreen
 0x5c681c CheckMenuItem
 0x5c6820 CallWindowProcA
 0x5c6824 CallNextHookEx
 0x5c6828 BeginPaint
 0x5c682c CharNextA
 0x5c6830 CharLowerBuffA
 0x5c6834 CharLowerA
 0x5c6838 CharUpperBuffA
 0x5c683c CharToOemA
 0x5c6840 AdjustWindowRectEx
 0x5c6844 ActivateKeyboardLayout
ole32.dll
 0x5c684c CoTaskMemFree
 0x5c6850 StringFromCLSID
kernel32.dll
 0x5c6858 Sleep
oleaut32.dll
 0x5c6860 SafeArrayPtrOfIndex
 0x5c6864 SafeArrayPutElement
 0x5c6868 SafeArrayGetElement
 0x5c686c SafeArrayUnaccessData
 0x5c6870 SafeArrayAccessData
 0x5c6874 SafeArrayGetUBound
 0x5c6878 SafeArrayGetLBound
 0x5c687c SafeArrayRedim
 0x5c6880 SafeArrayCreate
 0x5c6884 VariantChangeType
 0x5c6888 VariantCopyInd
 0x5c688c VariantCopy
 0x5c6890 VariantClear
 0x5c6894 VariantInit
ole32.dll
 0x5c689c CoCreateInstance
 0x5c68a0 CoGetMalloc
 0x5c68a4 CoUninitialize
 0x5c68a8 CoInitialize
 0x5c68ac IsEqualGUID
oleaut32.dll
 0x5c68b4 CreateErrorInfo
 0x5c68b8 GetErrorInfo
 0x5c68bc SetErrorInfo
 0x5c68c0 SafeArrayCopy
 0x5c68c4 SafeArrayUnaccessData
 0x5c68c8 SafeArrayAccessData
 0x5c68cc SafeArrayGetUBound
 0x5c68d0 SafeArrayDestroy
 0x5c68d4 SafeArrayCreate
 0x5c68d8 SysFreeString
comctl32.dll
 0x5c68e0 ImageList_SetIconSize
 0x5c68e4 ImageList_GetIconSize
 0x5c68e8 ImageList_Write
 0x5c68ec ImageList_Read
 0x5c68f0 ImageList_GetDragImage
 0x5c68f4 ImageList_DragShowNolock
 0x5c68f8 ImageList_SetDragCursorImage
 0x5c68fc ImageList_DragMove
 0x5c6900 ImageList_DragLeave
 0x5c6904 ImageList_DragEnter
 0x5c6908 ImageList_EndDrag
 0x5c690c ImageList_BeginDrag
 0x5c6910 ImageList_LoadImageA
 0x5c6914 ImageList_Remove
 0x5c6918 ImageList_DrawEx
 0x5c691c ImageList_Replace
 0x5c6920 ImageList_Draw
 0x5c6924 ImageList_GetBkColor
 0x5c6928 ImageList_SetBkColor
 0x5c692c ImageList_ReplaceIcon
 0x5c6930 ImageList_Add
 0x5c6934 ImageList_GetImageCount
 0x5c6938 ImageList_Destroy
 0x5c693c ImageList_Create
 0x5c6940 InitCommonControls
comdlg32.dll
 0x5c6948 GetSaveFileNameA
 0x5c694c GetOpenFileNameA
kernel32.dll
 0x5c6954 MulDiv
kernel32.dll
 0x5c695c MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure