Report - POS_C161.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:00 Machine s1_win7_x6403
Filename POS_C161.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.0
ZERO API file : clean
VT API (file) 11 detected (Midie, malicious, moderate, score, ai score=82, confidence)
md5 e2f7f7f6f81f4b39cc106356db4b8770
sha256 abd5b6b36f5f55bf71e2c97d23b97dcb69cf964da5d2c447be26b976faac1b7d
ssdeep 24576:ovSPtxCmmswEfwIJPzXu87b0ZX0cCNeSp9U/0ToEOwogllNAdJXrk1w8sLf3f4PD:ochjwiwku7Z8U/JS/NWhk1w8sL4PD
imphash 649373440eb9c6c6b9aef768374d55c2
impfuzzy 192:f3ugG1alc0FGbuuEjSUvK9ugoaqlBtc7sPbOQadx:f3S1GAEo9YRnPbOQ4
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x562168 DeleteCriticalSection
 0x56216c LeaveCriticalSection
 0x562170 EnterCriticalSection
 0x562174 InitializeCriticalSection
 0x562178 VirtualFree
 0x56217c VirtualAlloc
 0x562180 LocalFree
 0x562184 LocalAlloc
 0x562188 GetVersion
 0x56218c GetCurrentThreadId
 0x562190 InterlockedDecrement
 0x562194 InterlockedIncrement
 0x562198 VirtualQuery
 0x56219c WideCharToMultiByte
 0x5621a0 MultiByteToWideChar
 0x5621a4 lstrlenA
 0x5621a8 lstrcpynA
 0x5621ac LoadLibraryExA
 0x5621b0 GetThreadLocale
 0x5621b4 GetStartupInfoA
 0x5621b8 GetProcAddress
 0x5621bc GetModuleHandleA
 0x5621c0 GetModuleFileNameA
 0x5621c4 GetLocaleInfoA
 0x5621c8 GetCommandLineA
 0x5621cc FreeLibrary
 0x5621d0 FindFirstFileA
 0x5621d4 FindClose
 0x5621d8 ExitProcess
 0x5621dc ExitThread
 0x5621e0 CreateThread
 0x5621e4 WriteFile
 0x5621e8 UnhandledExceptionFilter
 0x5621ec RtlUnwind
 0x5621f0 RaiseException
 0x5621f4 GetStdHandle
user32.dll
 0x5621fc GetKeyboardType
 0x562200 LoadStringA
 0x562204 MessageBoxA
 0x562208 CharNextA
advapi32.dll
 0x562210 RegQueryValueExA
 0x562214 RegOpenKeyExA
 0x562218 RegCloseKey
oleaut32.dll
 0x562220 SysFreeString
 0x562224 SysReAllocStringLen
 0x562228 SysAllocStringLen
kernel32.dll
 0x562230 TlsSetValue
 0x562234 TlsGetValue
 0x562238 LocalAlloc
 0x56223c GetModuleHandleA
advapi32.dll
 0x562244 RegQueryValueExA
 0x562248 RegQueryValueA
 0x56224c RegOpenKeyExA
 0x562250 RegCloseKey
kernel32.dll
 0x562258 lstrcpyA
 0x56225c WriteFile
 0x562260 WaitForSingleObject
 0x562264 VirtualQuery
 0x562268 VirtualAlloc
 0x56226c Sleep
 0x562270 SizeofResource
 0x562274 SetThreadLocale
 0x562278 SetFilePointer
 0x56227c SetEvent
 0x562280 SetErrorMode
 0x562284 SetEndOfFile
 0x562288 ResumeThread
 0x56228c ResetEvent
 0x562290 ReadFile
 0x562294 MultiByteToWideChar
 0x562298 MulDiv
 0x56229c LockResource
 0x5622a0 LoadResource
 0x5622a4 LoadLibraryA
 0x5622a8 LeaveCriticalSection
 0x5622ac IsBadReadPtr
 0x5622b0 InitializeCriticalSection
 0x5622b4 GlobalUnlock
 0x5622b8 GlobalSize
 0x5622bc GlobalReAlloc
 0x5622c0 GlobalHandle
 0x5622c4 GlobalLock
 0x5622c8 GlobalFree
 0x5622cc GlobalFindAtomA
 0x5622d0 GlobalDeleteAtom
 0x5622d4 GlobalAlloc
 0x5622d8 GlobalAddAtomA
 0x5622dc GetVersionExA
 0x5622e0 GetVersion
 0x5622e4 GetTimeZoneInformation
 0x5622e8 GetTickCount
 0x5622ec GetThreadLocale
 0x5622f0 GetTempPathA
 0x5622f4 GetSystemInfo
 0x5622f8 GetStringTypeExA
 0x5622fc GetStdHandle
 0x562300 GetProcAddress
 0x562304 GetModuleHandleA
 0x562308 GetModuleFileNameA
 0x56230c GetLocaleInfoA
 0x562310 GetLocalTime
 0x562314 GetLastError
 0x562318 GetFullPathNameA
 0x56231c GetFileSize
 0x562320 GetExitCodeThread
 0x562324 GetDiskFreeSpaceA
 0x562328 GetDateFormatA
 0x56232c GetCurrentThreadId
 0x562330 GetCurrentProcessId
 0x562334 GetCPInfo
 0x562338 GetACP
 0x56233c FreeResource
 0x562340 InterlockedIncrement
 0x562344 InterlockedExchange
 0x562348 InterlockedDecrement
 0x56234c FreeLibrary
 0x562350 FormatMessageA
 0x562354 FindResourceA
 0x562358 FindFirstFileA
 0x56235c FindClose
 0x562360 FileTimeToLocalFileTime
 0x562364 FileTimeToDosDateTime
 0x562368 EnumCalendarInfoA
 0x56236c EnterCriticalSection
 0x562370 DeleteCriticalSection
 0x562374 CreateThread
 0x562378 CreateFileA
 0x56237c CreateEventA
 0x562380 CompareStringA
 0x562384 CloseHandle
version.dll
 0x56238c VerQueryValueA
 0x562390 GetFileVersionInfoSizeA
 0x562394 GetFileVersionInfoA
gdi32.dll
 0x56239c UnrealizeObject
 0x5623a0 StretchBlt
 0x5623a4 SetWindowOrgEx
 0x5623a8 SetWindowExtEx
 0x5623ac SetWinMetaFileBits
 0x5623b0 SetViewportOrgEx
 0x5623b4 SetViewportExtEx
 0x5623b8 SetTextColor
 0x5623bc SetStretchBltMode
 0x5623c0 SetROP2
 0x5623c4 SetPixel
 0x5623c8 SetMapMode
 0x5623cc SetEnhMetaFileBits
 0x5623d0 SetDIBColorTable
 0x5623d4 SetBrushOrgEx
 0x5623d8 SetBkMode
 0x5623dc SetBkColor
 0x5623e0 SelectPalette
 0x5623e4 SelectObject
 0x5623e8 SelectClipRgn
 0x5623ec SaveDC
 0x5623f0 RoundRect
 0x5623f4 RestoreDC
 0x5623f8 Rectangle
 0x5623fc RectVisible
 0x562400 RealizePalette
 0x562404 Polyline
 0x562408 Polygon
 0x56240c PolyPolyline
 0x562410 PlayEnhMetaFile
 0x562414 PatBlt
 0x562418 MoveToEx
 0x56241c MaskBlt
 0x562420 LineTo
 0x562424 LPtoDP
 0x562428 IntersectClipRect
 0x56242c GetWindowOrgEx
 0x562430 GetWinMetaFileBits
 0x562434 GetViewportOrgEx
 0x562438 GetTextMetricsA
 0x56243c GetTextExtentPointA
 0x562440 GetTextExtentPoint32A
 0x562444 GetSystemPaletteEntries
 0x562448 GetStockObject
 0x56244c GetPixel
 0x562450 GetPaletteEntries
 0x562454 GetOutlineTextMetricsA
 0x562458 GetObjectA
 0x56245c GetNearestColor
 0x562460 GetEnhMetaFilePaletteEntries
 0x562464 GetEnhMetaFileHeader
 0x562468 GetEnhMetaFileBits
 0x56246c GetDeviceCaps
 0x562470 GetDIBits
 0x562474 GetDIBColorTable
 0x562478 GetDCOrgEx
 0x56247c GetCurrentPositionEx
 0x562480 GetCurrentObject
 0x562484 GetClipRgn
 0x562488 GetClipBox
 0x56248c GetBrushOrgEx
 0x562490 GetBitmapBits
 0x562494 GdiFlush
 0x562498 ExtTextOutA
 0x56249c ExtSelectClipRgn
 0x5624a0 ExtCreateRegion
 0x5624a4 ExtCreatePen
 0x5624a8 ExcludeClipRect
 0x5624ac Ellipse
 0x5624b0 DeleteObject
 0x5624b4 DeleteEnhMetaFile
 0x5624b8 DeleteDC
 0x5624bc CreateSolidBrush
 0x5624c0 CreateRectRgn
 0x5624c4 CreatePolygonRgn
 0x5624c8 CreatePenIndirect
 0x5624cc CreatePen
 0x5624d0 CreatePalette
 0x5624d4 CreateHalftonePalette
 0x5624d8 CreateFontIndirectA
 0x5624dc CreateDIBitmap
 0x5624e0 CreateDIBSection
 0x5624e4 CreateCompatibleDC
 0x5624e8 CreateCompatibleBitmap
 0x5624ec CreateBrushIndirect
 0x5624f0 CreateBitmap
 0x5624f4 CopyEnhMetaFileA
 0x5624f8 CombineRgn
 0x5624fc BitBlt
user32.dll
 0x562504 CreateWindowExA
 0x562508 WindowFromPoint
 0x56250c WinHelpA
 0x562510 WaitMessage
 0x562514 ValidateRect
 0x562518 UpdateWindow
 0x56251c UnregisterClassA
 0x562520 UnhookWindowsHookEx
 0x562524 TranslateMessage
 0x562528 TranslateMDISysAccel
 0x56252c TrackPopupMenu
 0x562530 SystemParametersInfoA
 0x562534 ShowWindow
 0x562538 ShowScrollBar
 0x56253c ShowOwnedPopups
 0x562540 ShowCursor
 0x562544 ShowCaret
 0x562548 SetWindowRgn
 0x56254c SetWindowsHookExA
 0x562550 SetWindowTextA
 0x562554 SetWindowPos
 0x562558 SetWindowPlacement
 0x56255c SetWindowLongW
 0x562560 SetWindowLongA
 0x562564 SetTimer
 0x562568 SetScrollRange
 0x56256c SetScrollPos
 0x562570 SetScrollInfo
 0x562574 SetRect
 0x562578 SetPropA
 0x56257c SetParent
 0x562580 SetMenuItemInfoA
 0x562584 SetMenu
 0x562588 SetKeyboardState
 0x56258c SetForegroundWindow
 0x562590 SetFocus
 0x562594 SetCursor
 0x562598 SetClipboardData
 0x56259c SetClassLongA
 0x5625a0 SetCapture
 0x5625a4 SetActiveWindow
 0x5625a8 SendMessageA
 0x5625ac ScrollWindowEx
 0x5625b0 ScrollWindow
 0x5625b4 ScreenToClient
 0x5625b8 RemovePropA
 0x5625bc RemoveMenu
 0x5625c0 ReleaseDC
 0x5625c4 ReleaseCapture
 0x5625c8 RegisterWindowMessageA
 0x5625cc RegisterClipboardFormatA
 0x5625d0 RegisterClassA
 0x5625d4 RedrawWindow
 0x5625d8 PtInRect
 0x5625dc PostQuitMessage
 0x5625e0 PostMessageA
 0x5625e4 PeekMessageA
 0x5625e8 OpenClipboard
 0x5625ec OffsetRect
 0x5625f0 OemToCharA
 0x5625f4 MsgWaitForMultipleObjects
 0x5625f8 MoveWindow
 0x5625fc MessageBoxA
 0x562600 MessageBeep
 0x562604 MapWindowPoints
 0x562608 MapVirtualKeyA
 0x56260c LoadStringA
 0x562610 LoadKeyboardLayoutA
 0x562614 LoadIconA
 0x562618 LoadCursorA
 0x56261c LoadBitmapA
 0x562620 KillTimer
 0x562624 IsZoomed
 0x562628 IsWindowVisible
 0x56262c IsWindowUnicode
 0x562630 IsWindowEnabled
 0x562634 IsWindow
 0x562638 IsRectEmpty
 0x56263c IsIconic
 0x562640 IsDialogMessageA
 0x562644 IsClipboardFormatAvailable
 0x562648 IsChild
 0x56264c IsCharAlphaNumericA
 0x562650 IsCharAlphaA
 0x562654 InvalidateRect
 0x562658 IntersectRect
 0x56265c InsertMenuItemA
 0x562660 InsertMenuA
 0x562664 InflateRect
 0x562668 HideCaret
 0x56266c GetWindowThreadProcessId
 0x562670 GetWindowTextLengthW
 0x562674 GetWindowTextW
 0x562678 GetWindowTextA
 0x56267c GetWindowRect
 0x562680 GetWindowPlacement
 0x562684 GetWindowLongW
 0x562688 GetWindowLongA
 0x56268c GetWindowDC
 0x562690 GetTopWindow
 0x562694 GetSystemMetrics
 0x562698 GetSystemMenu
 0x56269c GetSysColorBrush
 0x5626a0 GetSysColor
 0x5626a4 GetSubMenu
 0x5626a8 GetScrollRange
 0x5626ac GetScrollPos
 0x5626b0 GetScrollInfo
 0x5626b4 GetPropA
 0x5626b8 GetParent
 0x5626bc GetWindow
 0x5626c0 GetMessageTime
 0x5626c4 GetMenuStringA
 0x5626c8 GetMenuState
 0x5626cc GetMenuItemInfoA
 0x5626d0 GetMenuItemID
 0x5626d4 GetMenuItemCount
 0x5626d8 GetMenu
 0x5626dc GetLastActivePopup
 0x5626e0 GetKeyboardState
 0x5626e4 GetKeyboardLayoutList
 0x5626e8 GetKeyboardLayout
 0x5626ec GetKeyState
 0x5626f0 GetKeyNameTextA
 0x5626f4 GetIconInfo
 0x5626f8 GetForegroundWindow
 0x5626fc GetFocus
 0x562700 GetDoubleClickTime
 0x562704 GetDlgCtrlID
 0x562708 GetDesktopWindow
 0x56270c GetDCEx
 0x562710 GetDC
 0x562714 GetCursorPos
 0x562718 GetCursor
 0x56271c GetClipboardData
 0x562720 GetClientRect
 0x562724 GetClassNameA
 0x562728 GetClassInfoA
 0x56272c GetCaretPos
 0x562730 GetCapture
 0x562734 GetActiveWindow
 0x562738 FrameRect
 0x56273c FindWindowExA
 0x562740 FindWindowA
 0x562744 FillRect
 0x562748 EqualRect
 0x56274c EnumWindows
 0x562750 EnumThreadWindows
 0x562754 EnumClipboardFormats
 0x562758 EndPaint
 0x56275c EnableWindow
 0x562760 EnableScrollBar
 0x562764 EnableMenuItem
 0x562768 EmptyClipboard
 0x56276c DrawTextExA
 0x562770 DrawTextW
 0x562774 DrawTextA
 0x562778 DrawMenuBar
 0x56277c DrawIconEx
 0x562780 DrawIcon
 0x562784 DrawFrameControl
 0x562788 DrawFocusRect
 0x56278c DrawEdge
 0x562790 DispatchMessageA
 0x562794 DestroyWindow
 0x562798 DestroyMenu
 0x56279c DestroyIcon
 0x5627a0 DestroyCursor
 0x5627a4 DeleteMenu
 0x5627a8 DefWindowProcA
 0x5627ac DefMDIChildProcA
 0x5627b0 DefFrameProcA
 0x5627b4 CreatePopupMenu
 0x5627b8 CreateMenu
 0x5627bc CreateIcon
 0x5627c0 CopyImage
 0x5627c4 CloseClipboard
 0x5627c8 ClientToScreen
 0x5627cc CheckMenuItem
 0x5627d0 CallWindowProcA
 0x5627d4 CallNextHookEx
 0x5627d8 BeginPaint
 0x5627dc CharNextA
 0x5627e0 CharLowerBuffA
 0x5627e4 CharLowerA
 0x5627e8 CharUpperBuffA
 0x5627ec CharToOemA
 0x5627f0 AdjustWindowRectEx
 0x5627f4 ActivateKeyboardLayout
ole32.dll
 0x5627fc CoTaskMemFree
 0x562800 StringFromCLSID
kernel32.dll
 0x562808 Sleep
oleaut32.dll
 0x562810 SafeArrayPtrOfIndex
 0x562814 SafeArrayPutElement
 0x562818 SafeArrayGetElement
 0x56281c SafeArrayUnaccessData
 0x562820 SafeArrayAccessData
 0x562824 SafeArrayGetUBound
 0x562828 SafeArrayGetLBound
 0x56282c SafeArrayRedim
 0x562830 SafeArrayCreate
 0x562834 VariantChangeType
 0x562838 VariantCopyInd
 0x56283c VariantCopy
 0x562840 VariantClear
 0x562844 VariantInit
ole32.dll
 0x56284c CoCreateInstance
 0x562850 CoGetMalloc
 0x562854 CoUninitialize
 0x562858 CoInitialize
 0x56285c IsEqualGUID
oleaut32.dll
 0x562864 CreateErrorInfo
 0x562868 GetErrorInfo
 0x56286c SetErrorInfo
 0x562870 SafeArrayCopy
 0x562874 SafeArrayUnaccessData
 0x562878 SafeArrayAccessData
 0x56287c SafeArrayGetUBound
 0x562880 SafeArrayDestroy
 0x562884 SafeArrayCreate
 0x562888 SysFreeString
comctl32.dll
 0x562890 ImageList_SetIconSize
 0x562894 ImageList_GetIconSize
 0x562898 ImageList_Write
 0x56289c ImageList_Read
 0x5628a0 ImageList_GetDragImage
 0x5628a4 ImageList_DragShowNolock
 0x5628a8 ImageList_SetDragCursorImage
 0x5628ac ImageList_DragMove
 0x5628b0 ImageList_DragLeave
 0x5628b4 ImageList_DragEnter
 0x5628b8 ImageList_EndDrag
 0x5628bc ImageList_BeginDrag
 0x5628c0 ImageList_LoadImageA
 0x5628c4 ImageList_Remove
 0x5628c8 ImageList_DrawEx
 0x5628cc ImageList_Replace
 0x5628d0 ImageList_Draw
 0x5628d4 ImageList_GetBkColor
 0x5628d8 ImageList_SetBkColor
 0x5628dc ImageList_ReplaceIcon
 0x5628e0 ImageList_Add
 0x5628e4 ImageList_GetImageCount
 0x5628e8 ImageList_Destroy
 0x5628ec ImageList_Create
 0x5628f0 InitCommonControls
kernel32.dll
 0x5628f8 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure