Report - POS_C169.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:41 Machine s1_win7_x6403
Filename POS_C169.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 11 detected (Midie, malicious, ai score=81, susgen)
md5 9eadf86f56f6423e3c952be255631746
sha256 296a8a4dee7159972da7eece2ef8c6447a88c3ae481c5c1ad931a2a252955832
ssdeep 49152:7vMq8zc64Knv3ZQlSCZbfPDSzbtAFjjdjjA/YiY0Y0Y0Y0YI:7vszcDKn+SC9SzbtAFjjdjjA/YiY0Y05
imphash 0f7133b6b604bd6fc63d33541d2dcf73
impfuzzy 192:f3o7BmG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3a1q/Ez9YPpPbOQc
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5e1190 DeleteCriticalSection
 0x5e1194 LeaveCriticalSection
 0x5e1198 EnterCriticalSection
 0x5e119c InitializeCriticalSection
 0x5e11a0 VirtualFree
 0x5e11a4 VirtualAlloc
 0x5e11a8 LocalFree
 0x5e11ac LocalAlloc
 0x5e11b0 GetVersion
 0x5e11b4 GetCurrentThreadId
 0x5e11b8 InterlockedDecrement
 0x5e11bc InterlockedIncrement
 0x5e11c0 VirtualQuery
 0x5e11c4 WideCharToMultiByte
 0x5e11c8 MultiByteToWideChar
 0x5e11cc lstrlenA
 0x5e11d0 lstrcpynA
 0x5e11d4 LoadLibraryExA
 0x5e11d8 GetThreadLocale
 0x5e11dc GetStartupInfoA
 0x5e11e0 GetProcAddress
 0x5e11e4 GetModuleHandleA
 0x5e11e8 GetModuleFileNameA
 0x5e11ec GetLocaleInfoA
 0x5e11f0 GetCommandLineA
 0x5e11f4 FreeLibrary
 0x5e11f8 FindFirstFileA
 0x5e11fc FindClose
 0x5e1200 ExitProcess
 0x5e1204 ExitThread
 0x5e1208 CreateThread
 0x5e120c WriteFile
 0x5e1210 UnhandledExceptionFilter
 0x5e1214 RtlUnwind
 0x5e1218 RaiseException
 0x5e121c GetStdHandle
user32.dll
 0x5e1224 GetKeyboardType
 0x5e1228 LoadStringA
 0x5e122c MessageBoxA
 0x5e1230 CharNextA
advapi32.dll
 0x5e1238 RegQueryValueExA
 0x5e123c RegOpenKeyExA
 0x5e1240 RegCloseKey
oleaut32.dll
 0x5e1248 SysFreeString
 0x5e124c SysReAllocStringLen
 0x5e1250 SysAllocStringLen
kernel32.dll
 0x5e1258 TlsSetValue
 0x5e125c TlsGetValue
 0x5e1260 LocalAlloc
 0x5e1264 GetModuleHandleA
advapi32.dll
 0x5e126c RegSetValueExA
 0x5e1270 RegQueryValueExA
 0x5e1274 RegQueryValueA
 0x5e1278 RegOpenKeyExA
 0x5e127c RegFlushKey
 0x5e1280 RegCreateKeyExA
 0x5e1284 RegCloseKey
kernel32.dll
 0x5e128c lstrcpyA
 0x5e1290 WritePrivateProfileStringA
 0x5e1294 WriteFile
 0x5e1298 WaitForSingleObject
 0x5e129c VirtualQuery
 0x5e12a0 VirtualAlloc
 0x5e12a4 Sleep
 0x5e12a8 SizeofResource
 0x5e12ac SetThreadLocale
 0x5e12b0 SetFilePointer
 0x5e12b4 SetEvent
 0x5e12b8 SetErrorMode
 0x5e12bc SetEndOfFile
 0x5e12c0 ResumeThread
 0x5e12c4 ResetEvent
 0x5e12c8 ReleaseMutex
 0x5e12cc ReadFile
 0x5e12d0 MultiByteToWideChar
 0x5e12d4 MulDiv
 0x5e12d8 LockResource
 0x5e12dc LoadResource
 0x5e12e0 LoadLibraryA
 0x5e12e4 LeaveCriticalSection
 0x5e12e8 IsBadReadPtr
 0x5e12ec InitializeCriticalSection
 0x5e12f0 GlobalUnlock
 0x5e12f4 GlobalSize
 0x5e12f8 GlobalReAlloc
 0x5e12fc GlobalHandle
 0x5e1300 GlobalLock
 0x5e1304 GlobalFree
 0x5e1308 GlobalFindAtomA
 0x5e130c GlobalDeleteAtom
 0x5e1310 GlobalAlloc
 0x5e1314 GlobalAddAtomA
 0x5e1318 GetVersionExA
 0x5e131c GetVersion
 0x5e1320 GetTimeZoneInformation
 0x5e1324 GetTickCount
 0x5e1328 GetThreadLocale
 0x5e132c GetTempPathA
 0x5e1330 GetSystemInfo
 0x5e1334 GetStringTypeExA
 0x5e1338 GetStdHandle
 0x5e133c GetProcAddress
 0x5e1340 GetPrivateProfileStringA
 0x5e1344 GetModuleHandleA
 0x5e1348 GetModuleFileNameA
 0x5e134c GetLocaleInfoA
 0x5e1350 GetLocalTime
 0x5e1354 GetLastError
 0x5e1358 GetFullPathNameA
 0x5e135c GetFileSize
 0x5e1360 GetExitCodeThread
 0x5e1364 GetDiskFreeSpaceA
 0x5e1368 GetDateFormatA
 0x5e136c GetCurrentThreadId
 0x5e1370 GetCurrentProcessId
 0x5e1374 GetCPInfo
 0x5e1378 GetACP
 0x5e137c FreeResource
 0x5e1380 InterlockedIncrement
 0x5e1384 InterlockedExchange
 0x5e1388 InterlockedDecrement
 0x5e138c FreeLibrary
 0x5e1390 FormatMessageA
 0x5e1394 FindResourceA
 0x5e1398 FindFirstFileA
 0x5e139c FindClose
 0x5e13a0 FileTimeToLocalFileTime
 0x5e13a4 FileTimeToDosDateTime
 0x5e13a8 EnumCalendarInfoA
 0x5e13ac EnterCriticalSection
 0x5e13b0 DeleteCriticalSection
 0x5e13b4 CreateThread
 0x5e13b8 CreateMutexA
 0x5e13bc CreateFileA
 0x5e13c0 CreateEventA
 0x5e13c4 CompareStringA
 0x5e13c8 CloseHandle
version.dll
 0x5e13d0 VerQueryValueA
 0x5e13d4 GetFileVersionInfoSizeA
 0x5e13d8 GetFileVersionInfoA
gdi32.dll
 0x5e13e0 UnrealizeObject
 0x5e13e4 StretchBlt
 0x5e13e8 SetWindowOrgEx
 0x5e13ec SetWindowExtEx
 0x5e13f0 SetWinMetaFileBits
 0x5e13f4 SetViewportOrgEx
 0x5e13f8 SetViewportExtEx
 0x5e13fc SetTextColor
 0x5e1400 SetStretchBltMode
 0x5e1404 SetROP2
 0x5e1408 SetPixel
 0x5e140c SetMapMode
 0x5e1410 SetEnhMetaFileBits
 0x5e1414 SetDIBColorTable
 0x5e1418 SetBrushOrgEx
 0x5e141c SetBkMode
 0x5e1420 SetBkColor
 0x5e1424 SelectPalette
 0x5e1428 SelectObject
 0x5e142c SelectClipRgn
 0x5e1430 SaveDC
 0x5e1434 RoundRect
 0x5e1438 RestoreDC
 0x5e143c Rectangle
 0x5e1440 RectVisible
 0x5e1444 RealizePalette
 0x5e1448 Polyline
 0x5e144c Polygon
 0x5e1450 PolyPolyline
 0x5e1454 PlayEnhMetaFile
 0x5e1458 PatBlt
 0x5e145c MoveToEx
 0x5e1460 MaskBlt
 0x5e1464 LineTo
 0x5e1468 LPtoDP
 0x5e146c IntersectClipRect
 0x5e1470 GetWindowOrgEx
 0x5e1474 GetWinMetaFileBits
 0x5e1478 GetViewportOrgEx
 0x5e147c GetTextMetricsA
 0x5e1480 GetTextExtentPointA
 0x5e1484 GetTextExtentPoint32A
 0x5e1488 GetSystemPaletteEntries
 0x5e148c GetStockObject
 0x5e1490 GetPixel
 0x5e1494 GetPaletteEntries
 0x5e1498 GetOutlineTextMetricsA
 0x5e149c GetObjectA
 0x5e14a0 GetNearestColor
 0x5e14a4 GetEnhMetaFilePaletteEntries
 0x5e14a8 GetEnhMetaFileHeader
 0x5e14ac GetEnhMetaFileBits
 0x5e14b0 GetDeviceCaps
 0x5e14b4 GetDIBits
 0x5e14b8 GetDIBColorTable
 0x5e14bc GetDCOrgEx
 0x5e14c0 GetCurrentPositionEx
 0x5e14c4 GetCurrentObject
 0x5e14c8 GetClipRgn
 0x5e14cc GetClipBox
 0x5e14d0 GetBrushOrgEx
 0x5e14d4 GetBitmapBits
 0x5e14d8 GdiFlush
 0x5e14dc ExtTextOutA
 0x5e14e0 ExtSelectClipRgn
 0x5e14e4 ExtCreateRegion
 0x5e14e8 ExtCreatePen
 0x5e14ec ExcludeClipRect
 0x5e14f0 Ellipse
 0x5e14f4 DeleteObject
 0x5e14f8 DeleteEnhMetaFile
 0x5e14fc DeleteDC
 0x5e1500 CreateSolidBrush
 0x5e1504 CreateRectRgn
 0x5e1508 CreatePolygonRgn
 0x5e150c CreatePenIndirect
 0x5e1510 CreatePen
 0x5e1514 CreatePalette
 0x5e1518 CreateHalftonePalette
 0x5e151c CreateFontIndirectA
 0x5e1520 CreateDIBitmap
 0x5e1524 CreateDIBSection
 0x5e1528 CreateCompatibleDC
 0x5e152c CreateCompatibleBitmap
 0x5e1530 CreateBrushIndirect
 0x5e1534 CreateBitmap
 0x5e1538 CopyEnhMetaFileA
 0x5e153c CombineRgn
 0x5e1540 BitBlt
user32.dll
 0x5e1548 CreateWindowExA
 0x5e154c WindowFromPoint
 0x5e1550 WinHelpA
 0x5e1554 WaitMessage
 0x5e1558 ValidateRect
 0x5e155c UpdateWindow
 0x5e1560 UnregisterClassA
 0x5e1564 UnionRect
 0x5e1568 UnhookWindowsHookEx
 0x5e156c TranslateMessage
 0x5e1570 TranslateMDISysAccel
 0x5e1574 TrackPopupMenu
 0x5e1578 SystemParametersInfoA
 0x5e157c ShowWindow
 0x5e1580 ShowScrollBar
 0x5e1584 ShowOwnedPopups
 0x5e1588 ShowCursor
 0x5e158c ShowCaret
 0x5e1590 SetWindowRgn
 0x5e1594 SetWindowsHookExA
 0x5e1598 SetWindowTextA
 0x5e159c SetWindowPos
 0x5e15a0 SetWindowPlacement
 0x5e15a4 SetWindowLongW
 0x5e15a8 SetWindowLongA
 0x5e15ac SetTimer
 0x5e15b0 SetScrollRange
 0x5e15b4 SetScrollPos
 0x5e15b8 SetScrollInfo
 0x5e15bc SetRect
 0x5e15c0 SetPropA
 0x5e15c4 SetParent
 0x5e15c8 SetMenuItemInfoA
 0x5e15cc SetMenu
 0x5e15d0 SetKeyboardState
 0x5e15d4 SetForegroundWindow
 0x5e15d8 SetFocus
 0x5e15dc SetCursor
 0x5e15e0 SetClipboardData
 0x5e15e4 SetClassLongA
 0x5e15e8 SetCaretPos
 0x5e15ec SetCapture
 0x5e15f0 SetActiveWindow
 0x5e15f4 SendMessageA
 0x5e15f8 ScrollWindowEx
 0x5e15fc ScrollWindow
 0x5e1600 ScreenToClient
 0x5e1604 RemovePropA
 0x5e1608 RemoveMenu
 0x5e160c ReleaseDC
 0x5e1610 ReleaseCapture
 0x5e1614 RegisterWindowMessageA
 0x5e1618 RegisterClipboardFormatA
 0x5e161c RegisterClassA
 0x5e1620 RedrawWindow
 0x5e1624 PtInRect
 0x5e1628 PostQuitMessage
 0x5e162c PostMessageA
 0x5e1630 PeekMessageA
 0x5e1634 OpenClipboard
 0x5e1638 OffsetRect
 0x5e163c OemToCharA
 0x5e1640 MsgWaitForMultipleObjects
 0x5e1644 MoveWindow
 0x5e1648 MessageBoxA
 0x5e164c MessageBeep
 0x5e1650 MapWindowPoints
 0x5e1654 MapVirtualKeyA
 0x5e1658 LoadStringA
 0x5e165c LoadKeyboardLayoutA
 0x5e1660 LoadIconA
 0x5e1664 LoadCursorA
 0x5e1668 LoadBitmapA
 0x5e166c KillTimer
 0x5e1670 IsZoomed
 0x5e1674 IsWindowVisible
 0x5e1678 IsWindowUnicode
 0x5e167c IsWindowEnabled
 0x5e1680 IsWindow
 0x5e1684 IsRectEmpty
 0x5e1688 IsIconic
 0x5e168c IsDialogMessageA
 0x5e1690 IsClipboardFormatAvailable
 0x5e1694 IsChild
 0x5e1698 IsCharAlphaNumericA
 0x5e169c IsCharAlphaA
 0x5e16a0 InvalidateRect
 0x5e16a4 IntersectRect
 0x5e16a8 InsertMenuItemA
 0x5e16ac InsertMenuA
 0x5e16b0 InflateRect
 0x5e16b4 HideCaret
 0x5e16b8 GetWindowThreadProcessId
 0x5e16bc GetWindowTextLengthW
 0x5e16c0 GetWindowTextW
 0x5e16c4 GetWindowTextA
 0x5e16c8 GetWindowRect
 0x5e16cc GetWindowPlacement
 0x5e16d0 GetWindowLongW
 0x5e16d4 GetWindowLongA
 0x5e16d8 GetWindowDC
 0x5e16dc GetTopWindow
 0x5e16e0 GetSystemMetrics
 0x5e16e4 GetSystemMenu
 0x5e16e8 GetSysColorBrush
 0x5e16ec GetSysColor
 0x5e16f0 GetSubMenu
 0x5e16f4 GetScrollRange
 0x5e16f8 GetScrollPos
 0x5e16fc GetScrollInfo
 0x5e1700 GetPropA
 0x5e1704 GetParent
 0x5e1708 GetWindow
 0x5e170c GetMessageTime
 0x5e1710 GetMenuStringA
 0x5e1714 GetMenuState
 0x5e1718 GetMenuItemInfoA
 0x5e171c GetMenuItemID
 0x5e1720 GetMenuItemCount
 0x5e1724 GetMenu
 0x5e1728 GetLastActivePopup
 0x5e172c GetKeyboardState
 0x5e1730 GetKeyboardLayoutList
 0x5e1734 GetKeyboardLayout
 0x5e1738 GetKeyState
 0x5e173c GetKeyNameTextA
 0x5e1740 GetIconInfo
 0x5e1744 GetForegroundWindow
 0x5e1748 GetFocus
 0x5e174c GetDoubleClickTime
 0x5e1750 GetDlgItem
 0x5e1754 GetDlgCtrlID
 0x5e1758 GetDesktopWindow
 0x5e175c GetDCEx
 0x5e1760 GetDC
 0x5e1764 GetCursorPos
 0x5e1768 GetCursor
 0x5e176c GetClipboardData
 0x5e1770 GetClientRect
 0x5e1774 GetClassNameA
 0x5e1778 GetClassInfoA
 0x5e177c GetCaretPos
 0x5e1780 GetCapture
 0x5e1784 GetActiveWindow
 0x5e1788 FrameRect
 0x5e178c FindWindowExA
 0x5e1790 FindWindowA
 0x5e1794 FillRect
 0x5e1798 EqualRect
 0x5e179c EnumWindows
 0x5e17a0 EnumThreadWindows
 0x5e17a4 EnumClipboardFormats
 0x5e17a8 EndPaint
 0x5e17ac EnableWindow
 0x5e17b0 EnableScrollBar
 0x5e17b4 EnableMenuItem
 0x5e17b8 EmptyClipboard
 0x5e17bc DrawTextExA
 0x5e17c0 DrawTextW
 0x5e17c4 DrawTextA
 0x5e17c8 DrawMenuBar
 0x5e17cc DrawIconEx
 0x5e17d0 DrawIcon
 0x5e17d4 DrawFrameControl
 0x5e17d8 DrawFocusRect
 0x5e17dc DrawEdge
 0x5e17e0 DispatchMessageA
 0x5e17e4 DestroyWindow
 0x5e17e8 DestroyMenu
 0x5e17ec DestroyIcon
 0x5e17f0 DestroyCursor
 0x5e17f4 DestroyCaret
 0x5e17f8 DeleteMenu
 0x5e17fc DefWindowProcA
 0x5e1800 DefMDIChildProcA
 0x5e1804 DefFrameProcA
 0x5e1808 CreatePopupMenu
 0x5e180c CreateMenu
 0x5e1810 CreateIcon
 0x5e1814 CreateCaret
 0x5e1818 CopyImage
 0x5e181c CloseClipboard
 0x5e1820 ClientToScreen
 0x5e1824 CheckMenuItem
 0x5e1828 CallWindowProcA
 0x5e182c CallNextHookEx
 0x5e1830 BeginPaint
 0x5e1834 CharNextA
 0x5e1838 CharLowerBuffA
 0x5e183c CharLowerA
 0x5e1840 CharUpperBuffA
 0x5e1844 CharToOemA
 0x5e1848 AdjustWindowRectEx
 0x5e184c ActivateKeyboardLayout
ole32.dll
 0x5e1854 CoTaskMemFree
 0x5e1858 StringFromCLSID
kernel32.dll
 0x5e1860 Sleep
oleaut32.dll
 0x5e1868 SafeArrayPtrOfIndex
 0x5e186c SafeArrayPutElement
 0x5e1870 SafeArrayGetElement
 0x5e1874 SafeArrayUnaccessData
 0x5e1878 SafeArrayAccessData
 0x5e187c SafeArrayGetUBound
 0x5e1880 SafeArrayGetLBound
 0x5e1884 SafeArrayRedim
 0x5e1888 SafeArrayCreate
 0x5e188c VariantChangeType
 0x5e1890 VariantCopyInd
 0x5e1894 VariantCopy
 0x5e1898 VariantClear
 0x5e189c VariantInit
ole32.dll
 0x5e18a4 CoCreateInstance
 0x5e18a8 CoGetMalloc
 0x5e18ac CoUninitialize
 0x5e18b0 CoInitialize
 0x5e18b4 IsEqualGUID
oleaut32.dll
 0x5e18bc CreateErrorInfo
 0x5e18c0 GetErrorInfo
 0x5e18c4 SetErrorInfo
 0x5e18c8 SafeArrayCopy
 0x5e18cc SafeArrayUnaccessData
 0x5e18d0 SafeArrayAccessData
 0x5e18d4 SafeArrayGetUBound
 0x5e18d8 SafeArrayDestroy
 0x5e18dc SafeArrayCreate
 0x5e18e0 SysFreeString
comctl32.dll
 0x5e18e8 ImageList_SetIconSize
 0x5e18ec ImageList_GetIconSize
 0x5e18f0 ImageList_Write
 0x5e18f4 ImageList_Read
 0x5e18f8 ImageList_GetDragImage
 0x5e18fc ImageList_DragShowNolock
 0x5e1900 ImageList_SetDragCursorImage
 0x5e1904 ImageList_DragMove
 0x5e1908 ImageList_DragLeave
 0x5e190c ImageList_DragEnter
 0x5e1910 ImageList_EndDrag
 0x5e1914 ImageList_BeginDrag
 0x5e1918 ImageList_LoadImageA
 0x5e191c ImageList_Remove
 0x5e1920 ImageList_DrawEx
 0x5e1924 ImageList_Replace
 0x5e1928 ImageList_Draw
 0x5e192c ImageList_GetBkColor
 0x5e1930 ImageList_SetBkColor
 0x5e1934 ImageList_ReplaceIcon
 0x5e1938 ImageList_Add
 0x5e193c ImageList_GetImageCount
 0x5e1940 ImageList_Destroy
 0x5e1944 ImageList_Create
 0x5e1948 InitCommonControls
comdlg32.dll
 0x5e1950 GetSaveFileNameA
 0x5e1954 GetOpenFileNameA
kernel32.dll
 0x5e195c MulDiv
kernel32.dll
 0x5e1964 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure