Report - POS_C014.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:46 Machine s1_win7_x6403
Filename POS_C014.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 3 detected (AIDetectMalware, R002V01K623)
md5 81ebdfd489183d94dc5b77c6e29a9876
sha256 f3472e78ba72d0e383115f2ddedc40464c1bfb34cb0544b1b291c53f561ee29d
ssdeep 49152:TnIET2wic782sPDgAFjjdjjA/YiY0Y0Y0Y0YI:TIOV3IgAFjjdjjA/YiY0Y0Y0Y0YI
imphash c4248c9c368dfb6cac01d697fd8da93a
impfuzzy 192:f3ugG1Glc0FGbuuEjSUvK9ugoaqlBtc7sPbOQadx:f3S1qAEo9YRnPbOQ4
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x570168 DeleteCriticalSection
 0x57016c LeaveCriticalSection
 0x570170 EnterCriticalSection
 0x570174 InitializeCriticalSection
 0x570178 VirtualFree
 0x57017c VirtualAlloc
 0x570180 LocalFree
 0x570184 LocalAlloc
 0x570188 GetVersion
 0x57018c GetCurrentThreadId
 0x570190 InterlockedDecrement
 0x570194 InterlockedIncrement
 0x570198 VirtualQuery
 0x57019c WideCharToMultiByte
 0x5701a0 MultiByteToWideChar
 0x5701a4 lstrlenA
 0x5701a8 lstrcpynA
 0x5701ac LoadLibraryExA
 0x5701b0 GetThreadLocale
 0x5701b4 GetStartupInfoA
 0x5701b8 GetProcAddress
 0x5701bc GetModuleHandleA
 0x5701c0 GetModuleFileNameA
 0x5701c4 GetLocaleInfoA
 0x5701c8 GetCommandLineA
 0x5701cc FreeLibrary
 0x5701d0 FindFirstFileA
 0x5701d4 FindClose
 0x5701d8 ExitProcess
 0x5701dc ExitThread
 0x5701e0 CreateThread
 0x5701e4 WriteFile
 0x5701e8 UnhandledExceptionFilter
 0x5701ec RtlUnwind
 0x5701f0 RaiseException
 0x5701f4 GetStdHandle
user32.dll
 0x5701fc GetKeyboardType
 0x570200 LoadStringA
 0x570204 MessageBoxA
 0x570208 CharNextA
advapi32.dll
 0x570210 RegQueryValueExA
 0x570214 RegOpenKeyExA
 0x570218 RegCloseKey
oleaut32.dll
 0x570220 SysFreeString
 0x570224 SysReAllocStringLen
 0x570228 SysAllocStringLen
kernel32.dll
 0x570230 TlsSetValue
 0x570234 TlsGetValue
 0x570238 LocalAlloc
 0x57023c GetModuleHandleA
advapi32.dll
 0x570244 RegQueryValueExA
 0x570248 RegQueryValueA
 0x57024c RegOpenKeyExA
 0x570250 RegCloseKey
kernel32.dll
 0x570258 lstrcpyA
 0x57025c WriteFile
 0x570260 WaitForSingleObject
 0x570264 VirtualQuery
 0x570268 VirtualAlloc
 0x57026c Sleep
 0x570270 SizeofResource
 0x570274 SetThreadLocale
 0x570278 SetFilePointer
 0x57027c SetEvent
 0x570280 SetErrorMode
 0x570284 SetEndOfFile
 0x570288 ResumeThread
 0x57028c ResetEvent
 0x570290 ReadFile
 0x570294 MultiByteToWideChar
 0x570298 MulDiv
 0x57029c LockResource
 0x5702a0 LoadResource
 0x5702a4 LoadLibraryA
 0x5702a8 LeaveCriticalSection
 0x5702ac IsBadReadPtr
 0x5702b0 InitializeCriticalSection
 0x5702b4 GlobalUnlock
 0x5702b8 GlobalSize
 0x5702bc GlobalReAlloc
 0x5702c0 GlobalHandle
 0x5702c4 GlobalLock
 0x5702c8 GlobalFree
 0x5702cc GlobalFindAtomA
 0x5702d0 GlobalDeleteAtom
 0x5702d4 GlobalAlloc
 0x5702d8 GlobalAddAtomA
 0x5702dc GetVersionExA
 0x5702e0 GetVersion
 0x5702e4 GetTimeZoneInformation
 0x5702e8 GetTickCount
 0x5702ec GetThreadLocale
 0x5702f0 GetTempPathA
 0x5702f4 GetSystemInfo
 0x5702f8 GetStringTypeExA
 0x5702fc GetStdHandle
 0x570300 GetProcAddress
 0x570304 GetModuleHandleA
 0x570308 GetModuleFileNameA
 0x57030c GetLocaleInfoA
 0x570310 GetLocalTime
 0x570314 GetLastError
 0x570318 GetFullPathNameA
 0x57031c GetFileSize
 0x570320 GetExitCodeThread
 0x570324 GetDiskFreeSpaceA
 0x570328 GetDateFormatA
 0x57032c GetCurrentThreadId
 0x570330 GetCurrentProcessId
 0x570334 GetCPInfo
 0x570338 GetACP
 0x57033c FreeResource
 0x570340 InterlockedIncrement
 0x570344 InterlockedExchange
 0x570348 InterlockedDecrement
 0x57034c FreeLibrary
 0x570350 FormatMessageA
 0x570354 FindResourceA
 0x570358 FindFirstFileA
 0x57035c FindClose
 0x570360 FileTimeToLocalFileTime
 0x570364 FileTimeToDosDateTime
 0x570368 EnumCalendarInfoA
 0x57036c EnterCriticalSection
 0x570370 DeleteCriticalSection
 0x570374 CreateThread
 0x570378 CreateMutexA
 0x57037c CreateFileA
 0x570380 CreateEventA
 0x570384 CompareStringA
 0x570388 CloseHandle
version.dll
 0x570390 VerQueryValueA
 0x570394 GetFileVersionInfoSizeA
 0x570398 GetFileVersionInfoA
gdi32.dll
 0x5703a0 UnrealizeObject
 0x5703a4 StretchBlt
 0x5703a8 SetWindowOrgEx
 0x5703ac SetWindowExtEx
 0x5703b0 SetWinMetaFileBits
 0x5703b4 SetViewportOrgEx
 0x5703b8 SetViewportExtEx
 0x5703bc SetTextColor
 0x5703c0 SetStretchBltMode
 0x5703c4 SetROP2
 0x5703c8 SetPixel
 0x5703cc SetMapMode
 0x5703d0 SetEnhMetaFileBits
 0x5703d4 SetDIBColorTable
 0x5703d8 SetBrushOrgEx
 0x5703dc SetBkMode
 0x5703e0 SetBkColor
 0x5703e4 SelectPalette
 0x5703e8 SelectObject
 0x5703ec SelectClipRgn
 0x5703f0 SaveDC
 0x5703f4 RoundRect
 0x5703f8 RestoreDC
 0x5703fc Rectangle
 0x570400 RectVisible
 0x570404 RealizePalette
 0x570408 Polyline
 0x57040c Polygon
 0x570410 PolyPolyline
 0x570414 PlayEnhMetaFile
 0x570418 PatBlt
 0x57041c MoveToEx
 0x570420 MaskBlt
 0x570424 LineTo
 0x570428 LPtoDP
 0x57042c IntersectClipRect
 0x570430 GetWindowOrgEx
 0x570434 GetWinMetaFileBits
 0x570438 GetViewportOrgEx
 0x57043c GetTextMetricsA
 0x570440 GetTextExtentPointA
 0x570444 GetTextExtentPoint32A
 0x570448 GetSystemPaletteEntries
 0x57044c GetStockObject
 0x570450 GetPixel
 0x570454 GetPaletteEntries
 0x570458 GetOutlineTextMetricsA
 0x57045c GetObjectA
 0x570460 GetNearestColor
 0x570464 GetEnhMetaFilePaletteEntries
 0x570468 GetEnhMetaFileHeader
 0x57046c GetEnhMetaFileBits
 0x570470 GetDeviceCaps
 0x570474 GetDIBits
 0x570478 GetDIBColorTable
 0x57047c GetDCOrgEx
 0x570480 GetCurrentPositionEx
 0x570484 GetCurrentObject
 0x570488 GetClipRgn
 0x57048c GetClipBox
 0x570490 GetBrushOrgEx
 0x570494 GetBitmapBits
 0x570498 GdiFlush
 0x57049c ExtTextOutA
 0x5704a0 ExtSelectClipRgn
 0x5704a4 ExtCreateRegion
 0x5704a8 ExtCreatePen
 0x5704ac ExcludeClipRect
 0x5704b0 Ellipse
 0x5704b4 DeleteObject
 0x5704b8 DeleteEnhMetaFile
 0x5704bc DeleteDC
 0x5704c0 CreateSolidBrush
 0x5704c4 CreateRectRgn
 0x5704c8 CreatePolygonRgn
 0x5704cc CreatePenIndirect
 0x5704d0 CreatePen
 0x5704d4 CreatePalette
 0x5704d8 CreateHalftonePalette
 0x5704dc CreateFontIndirectA
 0x5704e0 CreateDIBitmap
 0x5704e4 CreateDIBSection
 0x5704e8 CreateCompatibleDC
 0x5704ec CreateCompatibleBitmap
 0x5704f0 CreateBrushIndirect
 0x5704f4 CreateBitmap
 0x5704f8 CopyEnhMetaFileA
 0x5704fc CombineRgn
 0x570500 BitBlt
user32.dll
 0x570508 CreateWindowExA
 0x57050c WindowFromPoint
 0x570510 WinHelpA
 0x570514 WaitMessage
 0x570518 ValidateRect
 0x57051c UpdateWindow
 0x570520 UnregisterClassA
 0x570524 UnhookWindowsHookEx
 0x570528 TranslateMessage
 0x57052c TranslateMDISysAccel
 0x570530 TrackPopupMenu
 0x570534 SystemParametersInfoA
 0x570538 ShowWindow
 0x57053c ShowScrollBar
 0x570540 ShowOwnedPopups
 0x570544 ShowCursor
 0x570548 ShowCaret
 0x57054c SetWindowRgn
 0x570550 SetWindowsHookExA
 0x570554 SetWindowTextA
 0x570558 SetWindowPos
 0x57055c SetWindowPlacement
 0x570560 SetWindowLongW
 0x570564 SetWindowLongA
 0x570568 SetTimer
 0x57056c SetScrollRange
 0x570570 SetScrollPos
 0x570574 SetScrollInfo
 0x570578 SetRect
 0x57057c SetPropA
 0x570580 SetParent
 0x570584 SetMenuItemInfoA
 0x570588 SetMenu
 0x57058c SetKeyboardState
 0x570590 SetForegroundWindow
 0x570594 SetFocus
 0x570598 SetCursor
 0x57059c SetClipboardData
 0x5705a0 SetClassLongA
 0x5705a4 SetCapture
 0x5705a8 SetActiveWindow
 0x5705ac SendMessageA
 0x5705b0 ScrollWindowEx
 0x5705b4 ScrollWindow
 0x5705b8 ScreenToClient
 0x5705bc RemovePropA
 0x5705c0 RemoveMenu
 0x5705c4 ReleaseDC
 0x5705c8 ReleaseCapture
 0x5705cc RegisterWindowMessageA
 0x5705d0 RegisterClipboardFormatA
 0x5705d4 RegisterClassA
 0x5705d8 RedrawWindow
 0x5705dc PtInRect
 0x5705e0 PostQuitMessage
 0x5705e4 PostMessageA
 0x5705e8 PeekMessageA
 0x5705ec OpenClipboard
 0x5705f0 OffsetRect
 0x5705f4 OemToCharA
 0x5705f8 MsgWaitForMultipleObjects
 0x5705fc MoveWindow
 0x570600 MessageBoxA
 0x570604 MessageBeep
 0x570608 MapWindowPoints
 0x57060c MapVirtualKeyA
 0x570610 LoadStringA
 0x570614 LoadKeyboardLayoutA
 0x570618 LoadIconA
 0x57061c LoadCursorA
 0x570620 LoadBitmapA
 0x570624 KillTimer
 0x570628 IsZoomed
 0x57062c IsWindowVisible
 0x570630 IsWindowUnicode
 0x570634 IsWindowEnabled
 0x570638 IsWindow
 0x57063c IsRectEmpty
 0x570640 IsIconic
 0x570644 IsDialogMessageA
 0x570648 IsClipboardFormatAvailable
 0x57064c IsChild
 0x570650 IsCharAlphaNumericA
 0x570654 IsCharAlphaA
 0x570658 InvalidateRect
 0x57065c IntersectRect
 0x570660 InsertMenuItemA
 0x570664 InsertMenuA
 0x570668 InflateRect
 0x57066c HideCaret
 0x570670 GetWindowThreadProcessId
 0x570674 GetWindowTextLengthW
 0x570678 GetWindowTextW
 0x57067c GetWindowTextA
 0x570680 GetWindowRect
 0x570684 GetWindowPlacement
 0x570688 GetWindowLongW
 0x57068c GetWindowLongA
 0x570690 GetWindowDC
 0x570694 GetTopWindow
 0x570698 GetSystemMetrics
 0x57069c GetSystemMenu
 0x5706a0 GetSysColorBrush
 0x5706a4 GetSysColor
 0x5706a8 GetSubMenu
 0x5706ac GetScrollRange
 0x5706b0 GetScrollPos
 0x5706b4 GetScrollInfo
 0x5706b8 GetPropA
 0x5706bc GetParent
 0x5706c0 GetWindow
 0x5706c4 GetMessageTime
 0x5706c8 GetMenuStringA
 0x5706cc GetMenuState
 0x5706d0 GetMenuItemInfoA
 0x5706d4 GetMenuItemID
 0x5706d8 GetMenuItemCount
 0x5706dc GetMenu
 0x5706e0 GetLastActivePopup
 0x5706e4 GetKeyboardState
 0x5706e8 GetKeyboardLayoutList
 0x5706ec GetKeyboardLayout
 0x5706f0 GetKeyState
 0x5706f4 GetKeyNameTextA
 0x5706f8 GetIconInfo
 0x5706fc GetForegroundWindow
 0x570700 GetFocus
 0x570704 GetDoubleClickTime
 0x570708 GetDlgCtrlID
 0x57070c GetDesktopWindow
 0x570710 GetDCEx
 0x570714 GetDC
 0x570718 GetCursorPos
 0x57071c GetCursor
 0x570720 GetClipboardData
 0x570724 GetClientRect
 0x570728 GetClassNameA
 0x57072c GetClassInfoA
 0x570730 GetCaretPos
 0x570734 GetCapture
 0x570738 GetActiveWindow
 0x57073c FrameRect
 0x570740 FindWindowExA
 0x570744 FindWindowA
 0x570748 FillRect
 0x57074c EqualRect
 0x570750 EnumWindows
 0x570754 EnumThreadWindows
 0x570758 EnumClipboardFormats
 0x57075c EndPaint
 0x570760 EnableWindow
 0x570764 EnableScrollBar
 0x570768 EnableMenuItem
 0x57076c EmptyClipboard
 0x570770 DrawTextExA
 0x570774 DrawTextW
 0x570778 DrawTextA
 0x57077c DrawMenuBar
 0x570780 DrawIconEx
 0x570784 DrawIcon
 0x570788 DrawFrameControl
 0x57078c DrawFocusRect
 0x570790 DrawEdge
 0x570794 DispatchMessageA
 0x570798 DestroyWindow
 0x57079c DestroyMenu
 0x5707a0 DestroyIcon
 0x5707a4 DestroyCursor
 0x5707a8 DeleteMenu
 0x5707ac DefWindowProcA
 0x5707b0 DefMDIChildProcA
 0x5707b4 DefFrameProcA
 0x5707b8 CreatePopupMenu
 0x5707bc CreateMenu
 0x5707c0 CreateIcon
 0x5707c4 CopyImage
 0x5707c8 CloseClipboard
 0x5707cc ClientToScreen
 0x5707d0 CheckMenuItem
 0x5707d4 CallWindowProcA
 0x5707d8 CallNextHookEx
 0x5707dc BeginPaint
 0x5707e0 CharNextA
 0x5707e4 CharLowerBuffA
 0x5707e8 CharLowerA
 0x5707ec CharUpperBuffA
 0x5707f0 CharToOemA
 0x5707f4 AdjustWindowRectEx
 0x5707f8 ActivateKeyboardLayout
ole32.dll
 0x570800 CoTaskMemFree
 0x570804 StringFromCLSID
kernel32.dll
 0x57080c Sleep
oleaut32.dll
 0x570814 SafeArrayPtrOfIndex
 0x570818 SafeArrayPutElement
 0x57081c SafeArrayGetElement
 0x570820 SafeArrayUnaccessData
 0x570824 SafeArrayAccessData
 0x570828 SafeArrayGetUBound
 0x57082c SafeArrayGetLBound
 0x570830 SafeArrayRedim
 0x570834 SafeArrayCreate
 0x570838 VariantChangeType
 0x57083c VariantCopyInd
 0x570840 VariantCopy
 0x570844 VariantClear
 0x570848 VariantInit
ole32.dll
 0x570850 CoCreateInstance
 0x570854 CoGetMalloc
 0x570858 CoUninitialize
 0x57085c CoInitialize
 0x570860 IsEqualGUID
oleaut32.dll
 0x570868 CreateErrorInfo
 0x57086c GetErrorInfo
 0x570870 SetErrorInfo
 0x570874 SafeArrayCopy
 0x570878 SafeArrayUnaccessData
 0x57087c SafeArrayAccessData
 0x570880 SafeArrayGetUBound
 0x570884 SafeArrayDestroy
 0x570888 SafeArrayCreate
 0x57088c SysFreeString
comctl32.dll
 0x570894 ImageList_SetIconSize
 0x570898 ImageList_GetIconSize
 0x57089c ImageList_Write
 0x5708a0 ImageList_Read
 0x5708a4 ImageList_GetDragImage
 0x5708a8 ImageList_DragShowNolock
 0x5708ac ImageList_SetDragCursorImage
 0x5708b0 ImageList_DragMove
 0x5708b4 ImageList_DragLeave
 0x5708b8 ImageList_DragEnter
 0x5708bc ImageList_EndDrag
 0x5708c0 ImageList_BeginDrag
 0x5708c4 ImageList_LoadImageA
 0x5708c8 ImageList_Remove
 0x5708cc ImageList_DrawEx
 0x5708d0 ImageList_Replace
 0x5708d4 ImageList_Draw
 0x5708d8 ImageList_GetBkColor
 0x5708dc ImageList_SetBkColor
 0x5708e0 ImageList_ReplaceIcon
 0x5708e4 ImageList_Add
 0x5708e8 ImageList_GetImageCount
 0x5708ec ImageList_Destroy
 0x5708f0 ImageList_Create
 0x5708f4 InitCommonControls
kernel32.dll
 0x5708fc MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure