Report - POS_C106.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 14:14 Machine s1_win7_x6401
Filename POS_C106.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.0
ZERO API file : mailcious
VT API (file) 10 detected (Fragtor, malicious, ai score=89)
md5 c06fce8d6c9c7221c9e4389c202b98ba
sha256 904ca762a6ba7bc43709afcaaa994e83f9bfd2e072c1d393639b44eb35f9c3d9
ssdeep 24576:b/zpp7gukU9AzTbGBJH03MOTj/KJKW4jPOfxYZt9DQiHz5Ow54PD:b/dWUyzDjKKWE2xoz5cPD
imphash b8450491b0fe7f25803a5b786bacb697
impfuzzy 192:f3ugG1alc0FGbuuEjSUvK9ugoaqlBtc7sPbOQadi:f3S1GAEo9YRnPbOQF
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x55b168 DeleteCriticalSection
 0x55b16c LeaveCriticalSection
 0x55b170 EnterCriticalSection
 0x55b174 InitializeCriticalSection
 0x55b178 VirtualFree
 0x55b17c VirtualAlloc
 0x55b180 LocalFree
 0x55b184 LocalAlloc
 0x55b188 GetVersion
 0x55b18c GetCurrentThreadId
 0x55b190 InterlockedDecrement
 0x55b194 InterlockedIncrement
 0x55b198 VirtualQuery
 0x55b19c WideCharToMultiByte
 0x55b1a0 MultiByteToWideChar
 0x55b1a4 lstrlenA
 0x55b1a8 lstrcpynA
 0x55b1ac LoadLibraryExA
 0x55b1b0 GetThreadLocale
 0x55b1b4 GetStartupInfoA
 0x55b1b8 GetProcAddress
 0x55b1bc GetModuleHandleA
 0x55b1c0 GetModuleFileNameA
 0x55b1c4 GetLocaleInfoA
 0x55b1c8 GetCommandLineA
 0x55b1cc FreeLibrary
 0x55b1d0 FindFirstFileA
 0x55b1d4 FindClose
 0x55b1d8 ExitProcess
 0x55b1dc ExitThread
 0x55b1e0 CreateThread
 0x55b1e4 WriteFile
 0x55b1e8 UnhandledExceptionFilter
 0x55b1ec RtlUnwind
 0x55b1f0 RaiseException
 0x55b1f4 GetStdHandle
user32.dll
 0x55b1fc GetKeyboardType
 0x55b200 LoadStringA
 0x55b204 MessageBoxA
 0x55b208 CharNextA
advapi32.dll
 0x55b210 RegQueryValueExA
 0x55b214 RegOpenKeyExA
 0x55b218 RegCloseKey
oleaut32.dll
 0x55b220 SysFreeString
 0x55b224 SysReAllocStringLen
 0x55b228 SysAllocStringLen
kernel32.dll
 0x55b230 TlsSetValue
 0x55b234 TlsGetValue
 0x55b238 LocalAlloc
 0x55b23c GetModuleHandleA
advapi32.dll
 0x55b244 RegQueryValueExA
 0x55b248 RegQueryValueA
 0x55b24c RegOpenKeyExA
 0x55b250 RegCloseKey
kernel32.dll
 0x55b258 lstrcpyA
 0x55b25c WriteFile
 0x55b260 WaitForSingleObject
 0x55b264 VirtualQuery
 0x55b268 VirtualAlloc
 0x55b26c Sleep
 0x55b270 SizeofResource
 0x55b274 SetThreadLocale
 0x55b278 SetFilePointer
 0x55b27c SetEvent
 0x55b280 SetErrorMode
 0x55b284 SetEndOfFile
 0x55b288 ResumeThread
 0x55b28c ResetEvent
 0x55b290 ReadFile
 0x55b294 MultiByteToWideChar
 0x55b298 MulDiv
 0x55b29c LockResource
 0x55b2a0 LoadResource
 0x55b2a4 LoadLibraryA
 0x55b2a8 LeaveCriticalSection
 0x55b2ac IsBadReadPtr
 0x55b2b0 InitializeCriticalSection
 0x55b2b4 GlobalUnlock
 0x55b2b8 GlobalSize
 0x55b2bc GlobalReAlloc
 0x55b2c0 GlobalHandle
 0x55b2c4 GlobalLock
 0x55b2c8 GlobalFree
 0x55b2cc GlobalFindAtomA
 0x55b2d0 GlobalDeleteAtom
 0x55b2d4 GlobalAlloc
 0x55b2d8 GlobalAddAtomA
 0x55b2dc GetVersionExA
 0x55b2e0 GetVersion
 0x55b2e4 GetTimeZoneInformation
 0x55b2e8 GetTickCount
 0x55b2ec GetThreadLocale
 0x55b2f0 GetTempPathA
 0x55b2f4 GetSystemInfo
 0x55b2f8 GetStringTypeExA
 0x55b2fc GetStdHandle
 0x55b300 GetProcAddress
 0x55b304 GetModuleHandleA
 0x55b308 GetModuleFileNameA
 0x55b30c GetLocaleInfoA
 0x55b310 GetLocalTime
 0x55b314 GetLastError
 0x55b318 GetFullPathNameA
 0x55b31c GetFileSize
 0x55b320 GetExitCodeThread
 0x55b324 GetDiskFreeSpaceA
 0x55b328 GetDateFormatA
 0x55b32c GetCurrentThreadId
 0x55b330 GetCurrentProcessId
 0x55b334 GetCPInfo
 0x55b338 GetACP
 0x55b33c FreeResource
 0x55b340 InterlockedIncrement
 0x55b344 InterlockedExchange
 0x55b348 InterlockedDecrement
 0x55b34c FreeLibrary
 0x55b350 FormatMessageA
 0x55b354 FindResourceA
 0x55b358 FindFirstFileA
 0x55b35c FindClose
 0x55b360 FileTimeToLocalFileTime
 0x55b364 FileTimeToDosDateTime
 0x55b368 EnumCalendarInfoA
 0x55b36c EnterCriticalSection
 0x55b370 DeleteCriticalSection
 0x55b374 CreateThread
 0x55b378 CreateFileA
 0x55b37c CreateEventA
 0x55b380 CompareStringA
 0x55b384 CloseHandle
version.dll
 0x55b38c VerQueryValueA
 0x55b390 GetFileVersionInfoSizeA
 0x55b394 GetFileVersionInfoA
gdi32.dll
 0x55b39c UnrealizeObject
 0x55b3a0 StretchBlt
 0x55b3a4 SetWindowOrgEx
 0x55b3a8 SetWindowExtEx
 0x55b3ac SetWinMetaFileBits
 0x55b3b0 SetViewportOrgEx
 0x55b3b4 SetViewportExtEx
 0x55b3b8 SetTextColor
 0x55b3bc SetStretchBltMode
 0x55b3c0 SetROP2
 0x55b3c4 SetPixel
 0x55b3c8 SetMapMode
 0x55b3cc SetEnhMetaFileBits
 0x55b3d0 SetDIBColorTable
 0x55b3d4 SetBrushOrgEx
 0x55b3d8 SetBkMode
 0x55b3dc SetBkColor
 0x55b3e0 SelectPalette
 0x55b3e4 SelectObject
 0x55b3e8 SelectClipRgn
 0x55b3ec SaveDC
 0x55b3f0 RoundRect
 0x55b3f4 RestoreDC
 0x55b3f8 Rectangle
 0x55b3fc RectVisible
 0x55b400 RealizePalette
 0x55b404 Polyline
 0x55b408 Polygon
 0x55b40c PolyPolyline
 0x55b410 PlayEnhMetaFile
 0x55b414 PatBlt
 0x55b418 MoveToEx
 0x55b41c MaskBlt
 0x55b420 LineTo
 0x55b424 LPtoDP
 0x55b428 IntersectClipRect
 0x55b42c GetWindowOrgEx
 0x55b430 GetWinMetaFileBits
 0x55b434 GetViewportOrgEx
 0x55b438 GetTextMetricsA
 0x55b43c GetTextExtentPointA
 0x55b440 GetTextExtentPoint32A
 0x55b444 GetSystemPaletteEntries
 0x55b448 GetStockObject
 0x55b44c GetPixel
 0x55b450 GetPaletteEntries
 0x55b454 GetOutlineTextMetricsA
 0x55b458 GetObjectA
 0x55b45c GetNearestColor
 0x55b460 GetEnhMetaFilePaletteEntries
 0x55b464 GetEnhMetaFileHeader
 0x55b468 GetEnhMetaFileBits
 0x55b46c GetDeviceCaps
 0x55b470 GetDIBits
 0x55b474 GetDIBColorTable
 0x55b478 GetDCOrgEx
 0x55b47c GetCurrentPositionEx
 0x55b480 GetCurrentObject
 0x55b484 GetClipRgn
 0x55b488 GetClipBox
 0x55b48c GetBrushOrgEx
 0x55b490 GetBitmapBits
 0x55b494 GdiFlush
 0x55b498 ExtTextOutA
 0x55b49c ExtSelectClipRgn
 0x55b4a0 ExtCreateRegion
 0x55b4a4 ExtCreatePen
 0x55b4a8 ExcludeClipRect
 0x55b4ac Ellipse
 0x55b4b0 DeleteObject
 0x55b4b4 DeleteEnhMetaFile
 0x55b4b8 DeleteDC
 0x55b4bc CreateSolidBrush
 0x55b4c0 CreateRectRgn
 0x55b4c4 CreatePolygonRgn
 0x55b4c8 CreatePenIndirect
 0x55b4cc CreatePen
 0x55b4d0 CreatePalette
 0x55b4d4 CreateHalftonePalette
 0x55b4d8 CreateFontIndirectA
 0x55b4dc CreateDIBitmap
 0x55b4e0 CreateDIBSection
 0x55b4e4 CreateCompatibleDC
 0x55b4e8 CreateCompatibleBitmap
 0x55b4ec CreateBrushIndirect
 0x55b4f0 CreateBitmap
 0x55b4f4 CopyEnhMetaFileA
 0x55b4f8 CombineRgn
 0x55b4fc BitBlt
user32.dll
 0x55b504 CreateWindowExA
 0x55b508 WindowFromPoint
 0x55b50c WinHelpA
 0x55b510 WaitMessage
 0x55b514 ValidateRect
 0x55b518 UpdateWindow
 0x55b51c UnregisterClassA
 0x55b520 UnhookWindowsHookEx
 0x55b524 TranslateMessage
 0x55b528 TranslateMDISysAccel
 0x55b52c TrackPopupMenu
 0x55b530 SystemParametersInfoA
 0x55b534 ShowWindow
 0x55b538 ShowScrollBar
 0x55b53c ShowOwnedPopups
 0x55b540 ShowCursor
 0x55b544 ShowCaret
 0x55b548 SetWindowRgn
 0x55b54c SetWindowsHookExA
 0x55b550 SetWindowTextA
 0x55b554 SetWindowPos
 0x55b558 SetWindowPlacement
 0x55b55c SetWindowLongW
 0x55b560 SetWindowLongA
 0x55b564 SetTimer
 0x55b568 SetScrollRange
 0x55b56c SetScrollPos
 0x55b570 SetScrollInfo
 0x55b574 SetRect
 0x55b578 SetPropA
 0x55b57c SetParent
 0x55b580 SetMenuItemInfoA
 0x55b584 SetMenu
 0x55b588 SetKeyboardState
 0x55b58c SetForegroundWindow
 0x55b590 SetFocus
 0x55b594 SetCursor
 0x55b598 SetClipboardData
 0x55b59c SetClassLongA
 0x55b5a0 SetCapture
 0x55b5a4 SetActiveWindow
 0x55b5a8 SendMessageA
 0x55b5ac ScrollWindowEx
 0x55b5b0 ScrollWindow
 0x55b5b4 ScreenToClient
 0x55b5b8 RemovePropA
 0x55b5bc RemoveMenu
 0x55b5c0 ReleaseDC
 0x55b5c4 ReleaseCapture
 0x55b5c8 RegisterWindowMessageA
 0x55b5cc RegisterClipboardFormatA
 0x55b5d0 RegisterClassA
 0x55b5d4 RedrawWindow
 0x55b5d8 PtInRect
 0x55b5dc PostQuitMessage
 0x55b5e0 PostMessageA
 0x55b5e4 PeekMessageA
 0x55b5e8 OpenClipboard
 0x55b5ec OffsetRect
 0x55b5f0 OemToCharA
 0x55b5f4 MsgWaitForMultipleObjects
 0x55b5f8 MoveWindow
 0x55b5fc MessageBoxA
 0x55b600 MessageBeep
 0x55b604 MapWindowPoints
 0x55b608 MapVirtualKeyA
 0x55b60c LoadStringA
 0x55b610 LoadKeyboardLayoutA
 0x55b614 LoadIconA
 0x55b618 LoadCursorA
 0x55b61c LoadBitmapA
 0x55b620 KillTimer
 0x55b624 IsZoomed
 0x55b628 IsWindowVisible
 0x55b62c IsWindowUnicode
 0x55b630 IsWindowEnabled
 0x55b634 IsWindow
 0x55b638 IsRectEmpty
 0x55b63c IsIconic
 0x55b640 IsDialogMessageA
 0x55b644 IsClipboardFormatAvailable
 0x55b648 IsChild
 0x55b64c IsCharAlphaNumericA
 0x55b650 IsCharAlphaA
 0x55b654 InvalidateRect
 0x55b658 IntersectRect
 0x55b65c InsertMenuItemA
 0x55b660 InsertMenuA
 0x55b664 InflateRect
 0x55b668 HideCaret
 0x55b66c GetWindowThreadProcessId
 0x55b670 GetWindowTextLengthW
 0x55b674 GetWindowTextW
 0x55b678 GetWindowTextA
 0x55b67c GetWindowRect
 0x55b680 GetWindowPlacement
 0x55b684 GetWindowLongW
 0x55b688 GetWindowLongA
 0x55b68c GetWindowDC
 0x55b690 GetTopWindow
 0x55b694 GetSystemMetrics
 0x55b698 GetSystemMenu
 0x55b69c GetSysColorBrush
 0x55b6a0 GetSysColor
 0x55b6a4 GetSubMenu
 0x55b6a8 GetScrollRange
 0x55b6ac GetScrollPos
 0x55b6b0 GetScrollInfo
 0x55b6b4 GetPropA
 0x55b6b8 GetParent
 0x55b6bc GetWindow
 0x55b6c0 GetMessageTime
 0x55b6c4 GetMenuStringA
 0x55b6c8 GetMenuState
 0x55b6cc GetMenuItemInfoA
 0x55b6d0 GetMenuItemID
 0x55b6d4 GetMenuItemCount
 0x55b6d8 GetMenu
 0x55b6dc GetLastActivePopup
 0x55b6e0 GetKeyboardState
 0x55b6e4 GetKeyboardLayoutList
 0x55b6e8 GetKeyboardLayout
 0x55b6ec GetKeyState
 0x55b6f0 GetKeyNameTextA
 0x55b6f4 GetIconInfo
 0x55b6f8 GetForegroundWindow
 0x55b6fc GetFocus
 0x55b700 GetDoubleClickTime
 0x55b704 GetDlgCtrlID
 0x55b708 GetDesktopWindow
 0x55b70c GetDCEx
 0x55b710 GetDC
 0x55b714 GetCursorPos
 0x55b718 GetCursor
 0x55b71c GetClipboardData
 0x55b720 GetClientRect
 0x55b724 GetClassNameA
 0x55b728 GetClassInfoA
 0x55b72c GetCaretPos
 0x55b730 GetCapture
 0x55b734 GetActiveWindow
 0x55b738 FrameRect
 0x55b73c FindWindowExA
 0x55b740 FindWindowA
 0x55b744 FillRect
 0x55b748 EqualRect
 0x55b74c EnumWindows
 0x55b750 EnumThreadWindows
 0x55b754 EnumClipboardFormats
 0x55b758 EndPaint
 0x55b75c EnableWindow
 0x55b760 EnableScrollBar
 0x55b764 EnableMenuItem
 0x55b768 EmptyClipboard
 0x55b76c DrawTextExA
 0x55b770 DrawTextW
 0x55b774 DrawTextA
 0x55b778 DrawMenuBar
 0x55b77c DrawIconEx
 0x55b780 DrawIcon
 0x55b784 DrawFrameControl
 0x55b788 DrawFocusRect
 0x55b78c DrawEdge
 0x55b790 DispatchMessageA
 0x55b794 DestroyWindow
 0x55b798 DestroyMenu
 0x55b79c DestroyIcon
 0x55b7a0 DestroyCursor
 0x55b7a4 DeleteMenu
 0x55b7a8 DefWindowProcA
 0x55b7ac DefMDIChildProcA
 0x55b7b0 DefFrameProcA
 0x55b7b4 CreatePopupMenu
 0x55b7b8 CreateMenu
 0x55b7bc CreateIcon
 0x55b7c0 CopyImage
 0x55b7c4 CloseClipboard
 0x55b7c8 ClientToScreen
 0x55b7cc CheckMenuItem
 0x55b7d0 CallWindowProcA
 0x55b7d4 CallNextHookEx
 0x55b7d8 BeginPaint
 0x55b7dc CharNextA
 0x55b7e0 CharLowerBuffA
 0x55b7e4 CharLowerA
 0x55b7e8 CharUpperBuffA
 0x55b7ec CharToOemA
 0x55b7f0 AdjustWindowRectEx
 0x55b7f4 ActivateKeyboardLayout
ole32.dll
 0x55b7fc CoTaskMemFree
 0x55b800 StringFromCLSID
kernel32.dll
 0x55b808 Sleep
oleaut32.dll
 0x55b810 SafeArrayPtrOfIndex
 0x55b814 SafeArrayPutElement
 0x55b818 SafeArrayGetElement
 0x55b81c SafeArrayUnaccessData
 0x55b820 SafeArrayAccessData
 0x55b824 SafeArrayGetUBound
 0x55b828 SafeArrayGetLBound
 0x55b82c SafeArrayRedim
 0x55b830 SafeArrayCreate
 0x55b834 VariantChangeType
 0x55b838 VariantCopyInd
 0x55b83c VariantCopy
 0x55b840 VariantClear
 0x55b844 VariantInit
ole32.dll
 0x55b84c CoCreateInstance
 0x55b850 CoGetMalloc
 0x55b854 CoUninitialize
 0x55b858 CoInitialize
 0x55b85c IsEqualGUID
oleaut32.dll
 0x55b864 CreateErrorInfo
 0x55b868 GetErrorInfo
 0x55b86c SetErrorInfo
 0x55b870 SafeArrayCopy
 0x55b874 SafeArrayUnaccessData
 0x55b878 SafeArrayAccessData
 0x55b87c SafeArrayGetUBound
 0x55b880 SafeArrayDestroy
 0x55b884 SafeArrayCreate
 0x55b888 SysFreeString
comctl32.dll
 0x55b890 ImageList_SetIconSize
 0x55b894 ImageList_GetIconSize
 0x55b898 ImageList_Write
 0x55b89c ImageList_Read
 0x55b8a0 ImageList_GetDragImage
 0x55b8a4 ImageList_DragShowNolock
 0x55b8a8 ImageList_SetDragCursorImage
 0x55b8ac ImageList_DragMove
 0x55b8b0 ImageList_DragLeave
 0x55b8b4 ImageList_DragEnter
 0x55b8b8 ImageList_EndDrag
 0x55b8bc ImageList_BeginDrag
 0x55b8c0 ImageList_LoadImageA
 0x55b8c4 ImageList_Remove
 0x55b8c8 ImageList_DrawEx
 0x55b8cc ImageList_Replace
 0x55b8d0 ImageList_Draw
 0x55b8d4 ImageList_GetBkColor
 0x55b8d8 ImageList_SetBkColor
 0x55b8dc ImageList_ReplaceIcon
 0x55b8e0 ImageList_Add
 0x55b8e4 ImageList_SetImageCount
 0x55b8e8 ImageList_GetImageCount
 0x55b8ec ImageList_Destroy
 0x55b8f0 ImageList_Create
 0x55b8f4 InitCommonControls
kernel32.dll
 0x55b8fc MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure