Report - POS_C159.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:11 Machine s1_win7_x6401
Filename POS_C159.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
2.0
ZERO API file : mailcious
VT API (file) 10 detected (Strictor, malicious, ai score=89)
md5 3b8bb2df50ce9e36afc960a3b5bc463f
sha256 9f4be8a53daefae9d731557d237c3a213efbbe8412722db3f4cd99339fae057c
ssdeep 49152:s1F448KOFqV3Du+lEmsJP70nlJPDB7AFjjdjjA/YiY0Y0Y0Y0YI:sL44FUqfIJP7GB7AFjjdjjA/YiY0Y0Ys
imphash 92c2ee4988f0629ae080b641fbef84f6
impfuzzy 192:f3zuG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3H1q/Ez9YPpPbOQc
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5d2190 DeleteCriticalSection
 0x5d2194 LeaveCriticalSection
 0x5d2198 EnterCriticalSection
 0x5d219c InitializeCriticalSection
 0x5d21a0 VirtualFree
 0x5d21a4 VirtualAlloc
 0x5d21a8 LocalFree
 0x5d21ac LocalAlloc
 0x5d21b0 GetVersion
 0x5d21b4 GetCurrentThreadId
 0x5d21b8 InterlockedDecrement
 0x5d21bc InterlockedIncrement
 0x5d21c0 VirtualQuery
 0x5d21c4 WideCharToMultiByte
 0x5d21c8 MultiByteToWideChar
 0x5d21cc lstrlenA
 0x5d21d0 lstrcpynA
 0x5d21d4 LoadLibraryExA
 0x5d21d8 GetThreadLocale
 0x5d21dc GetStartupInfoA
 0x5d21e0 GetProcAddress
 0x5d21e4 GetModuleHandleA
 0x5d21e8 GetModuleFileNameA
 0x5d21ec GetLocaleInfoA
 0x5d21f0 GetCommandLineA
 0x5d21f4 FreeLibrary
 0x5d21f8 FindFirstFileA
 0x5d21fc FindClose
 0x5d2200 ExitProcess
 0x5d2204 ExitThread
 0x5d2208 CreateThread
 0x5d220c WriteFile
 0x5d2210 UnhandledExceptionFilter
 0x5d2214 RtlUnwind
 0x5d2218 RaiseException
 0x5d221c GetStdHandle
user32.dll
 0x5d2224 GetKeyboardType
 0x5d2228 LoadStringA
 0x5d222c MessageBoxA
 0x5d2230 CharNextA
advapi32.dll
 0x5d2238 RegQueryValueExA
 0x5d223c RegOpenKeyExA
 0x5d2240 RegCloseKey
oleaut32.dll
 0x5d2248 SysFreeString
 0x5d224c SysReAllocStringLen
 0x5d2250 SysAllocStringLen
kernel32.dll
 0x5d2258 TlsSetValue
 0x5d225c TlsGetValue
 0x5d2260 LocalAlloc
 0x5d2264 GetModuleHandleA
advapi32.dll
 0x5d226c RegSetValueExA
 0x5d2270 RegQueryValueExA
 0x5d2274 RegQueryValueA
 0x5d2278 RegOpenKeyExA
 0x5d227c RegFlushKey
 0x5d2280 RegCreateKeyExA
 0x5d2284 RegCloseKey
kernel32.dll
 0x5d228c lstrcpyA
 0x5d2290 WriteFile
 0x5d2294 WaitForSingleObject
 0x5d2298 VirtualQuery
 0x5d229c VirtualAlloc
 0x5d22a0 Sleep
 0x5d22a4 SizeofResource
 0x5d22a8 SetThreadLocale
 0x5d22ac SetFilePointer
 0x5d22b0 SetEvent
 0x5d22b4 SetErrorMode
 0x5d22b8 SetEndOfFile
 0x5d22bc ResumeThread
 0x5d22c0 ResetEvent
 0x5d22c4 ReleaseMutex
 0x5d22c8 ReadFile
 0x5d22cc MultiByteToWideChar
 0x5d22d0 MulDiv
 0x5d22d4 LockResource
 0x5d22d8 LoadResource
 0x5d22dc LoadLibraryA
 0x5d22e0 LeaveCriticalSection
 0x5d22e4 IsBadReadPtr
 0x5d22e8 InitializeCriticalSection
 0x5d22ec GlobalUnlock
 0x5d22f0 GlobalSize
 0x5d22f4 GlobalReAlloc
 0x5d22f8 GlobalHandle
 0x5d22fc GlobalLock
 0x5d2300 GlobalFree
 0x5d2304 GlobalFindAtomA
 0x5d2308 GlobalDeleteAtom
 0x5d230c GlobalAlloc
 0x5d2310 GlobalAddAtomA
 0x5d2314 GetVersionExA
 0x5d2318 GetVersion
 0x5d231c GetTimeZoneInformation
 0x5d2320 GetTickCount
 0x5d2324 GetThreadLocale
 0x5d2328 GetTempPathA
 0x5d232c GetSystemInfo
 0x5d2330 GetStringTypeExA
 0x5d2334 GetStdHandle
 0x5d2338 GetProcAddress
 0x5d233c GetModuleHandleA
 0x5d2340 GetModuleFileNameA
 0x5d2344 GetLocaleInfoA
 0x5d2348 GetLocalTime
 0x5d234c GetLastError
 0x5d2350 GetFullPathNameA
 0x5d2354 GetFileSize
 0x5d2358 GetExitCodeThread
 0x5d235c GetDiskFreeSpaceA
 0x5d2360 GetDateFormatA
 0x5d2364 GetCurrentThreadId
 0x5d2368 GetCurrentProcessId
 0x5d236c GetCPInfo
 0x5d2370 GetACP
 0x5d2374 FreeResource
 0x5d2378 InterlockedIncrement
 0x5d237c InterlockedExchange
 0x5d2380 InterlockedDecrement
 0x5d2384 FreeLibrary
 0x5d2388 FormatMessageA
 0x5d238c FindResourceA
 0x5d2390 FindFirstFileA
 0x5d2394 FindClose
 0x5d2398 FileTimeToLocalFileTime
 0x5d239c FileTimeToDosDateTime
 0x5d23a0 EnumCalendarInfoA
 0x5d23a4 EnterCriticalSection
 0x5d23a8 DeleteCriticalSection
 0x5d23ac CreateThread
 0x5d23b0 CreateMutexA
 0x5d23b4 CreateFileA
 0x5d23b8 CreateEventA
 0x5d23bc CompareStringA
 0x5d23c0 CloseHandle
version.dll
 0x5d23c8 VerQueryValueA
 0x5d23cc GetFileVersionInfoSizeA
 0x5d23d0 GetFileVersionInfoA
gdi32.dll
 0x5d23d8 UnrealizeObject
 0x5d23dc StretchBlt
 0x5d23e0 SetWindowOrgEx
 0x5d23e4 SetWindowExtEx
 0x5d23e8 SetWinMetaFileBits
 0x5d23ec SetViewportOrgEx
 0x5d23f0 SetViewportExtEx
 0x5d23f4 SetTextColor
 0x5d23f8 SetStretchBltMode
 0x5d23fc SetROP2
 0x5d2400 SetPixel
 0x5d2404 SetMapMode
 0x5d2408 SetEnhMetaFileBits
 0x5d240c SetDIBColorTable
 0x5d2410 SetBrushOrgEx
 0x5d2414 SetBkMode
 0x5d2418 SetBkColor
 0x5d241c SelectPalette
 0x5d2420 SelectObject
 0x5d2424 SelectClipRgn
 0x5d2428 SaveDC
 0x5d242c RoundRect
 0x5d2430 RestoreDC
 0x5d2434 Rectangle
 0x5d2438 RectVisible
 0x5d243c RealizePalette
 0x5d2440 Polyline
 0x5d2444 Polygon
 0x5d2448 PolyPolyline
 0x5d244c PlayEnhMetaFile
 0x5d2450 PatBlt
 0x5d2454 MoveToEx
 0x5d2458 MaskBlt
 0x5d245c LineTo
 0x5d2460 LPtoDP
 0x5d2464 IntersectClipRect
 0x5d2468 GetWindowOrgEx
 0x5d246c GetWinMetaFileBits
 0x5d2470 GetViewportOrgEx
 0x5d2474 GetTextMetricsA
 0x5d2478 GetTextExtentPointA
 0x5d247c GetTextExtentPoint32A
 0x5d2480 GetSystemPaletteEntries
 0x5d2484 GetStockObject
 0x5d2488 GetPixel
 0x5d248c GetPaletteEntries
 0x5d2490 GetOutlineTextMetricsA
 0x5d2494 GetObjectA
 0x5d2498 GetNearestColor
 0x5d249c GetEnhMetaFilePaletteEntries
 0x5d24a0 GetEnhMetaFileHeader
 0x5d24a4 GetEnhMetaFileBits
 0x5d24a8 GetDeviceCaps
 0x5d24ac GetDIBits
 0x5d24b0 GetDIBColorTable
 0x5d24b4 GetDCOrgEx
 0x5d24b8 GetCurrentPositionEx
 0x5d24bc GetCurrentObject
 0x5d24c0 GetClipRgn
 0x5d24c4 GetClipBox
 0x5d24c8 GetBrushOrgEx
 0x5d24cc GetBitmapBits
 0x5d24d0 GdiFlush
 0x5d24d4 ExtTextOutA
 0x5d24d8 ExtSelectClipRgn
 0x5d24dc ExtCreateRegion
 0x5d24e0 ExtCreatePen
 0x5d24e4 ExcludeClipRect
 0x5d24e8 Ellipse
 0x5d24ec DeleteObject
 0x5d24f0 DeleteEnhMetaFile
 0x5d24f4 DeleteDC
 0x5d24f8 CreateSolidBrush
 0x5d24fc CreateRectRgn
 0x5d2500 CreatePolygonRgn
 0x5d2504 CreatePenIndirect
 0x5d2508 CreatePen
 0x5d250c CreatePalette
 0x5d2510 CreateHalftonePalette
 0x5d2514 CreateFontIndirectA
 0x5d2518 CreateDIBitmap
 0x5d251c CreateDIBSection
 0x5d2520 CreateCompatibleDC
 0x5d2524 CreateCompatibleBitmap
 0x5d2528 CreateBrushIndirect
 0x5d252c CreateBitmap
 0x5d2530 CopyEnhMetaFileA
 0x5d2534 CombineRgn
 0x5d2538 BitBlt
user32.dll
 0x5d2540 CreateWindowExA
 0x5d2544 WindowFromPoint
 0x5d2548 WinHelpA
 0x5d254c WaitMessage
 0x5d2550 ValidateRect
 0x5d2554 UpdateWindow
 0x5d2558 UnregisterClassA
 0x5d255c UnionRect
 0x5d2560 UnhookWindowsHookEx
 0x5d2564 TranslateMessage
 0x5d2568 TranslateMDISysAccel
 0x5d256c TrackPopupMenu
 0x5d2570 SystemParametersInfoA
 0x5d2574 ShowWindow
 0x5d2578 ShowScrollBar
 0x5d257c ShowOwnedPopups
 0x5d2580 ShowCursor
 0x5d2584 ShowCaret
 0x5d2588 SetWindowRgn
 0x5d258c SetWindowsHookExA
 0x5d2590 SetWindowTextA
 0x5d2594 SetWindowPos
 0x5d2598 SetWindowPlacement
 0x5d259c SetWindowLongW
 0x5d25a0 SetWindowLongA
 0x5d25a4 SetTimer
 0x5d25a8 SetScrollRange
 0x5d25ac SetScrollPos
 0x5d25b0 SetScrollInfo
 0x5d25b4 SetRect
 0x5d25b8 SetPropA
 0x5d25bc SetParent
 0x5d25c0 SetMenuItemInfoA
 0x5d25c4 SetMenu
 0x5d25c8 SetKeyboardState
 0x5d25cc SetForegroundWindow
 0x5d25d0 SetFocus
 0x5d25d4 SetCursor
 0x5d25d8 SetClipboardData
 0x5d25dc SetClassLongA
 0x5d25e0 SetCaretPos
 0x5d25e4 SetCapture
 0x5d25e8 SetActiveWindow
 0x5d25ec SendMessageA
 0x5d25f0 ScrollWindowEx
 0x5d25f4 ScrollWindow
 0x5d25f8 ScreenToClient
 0x5d25fc RemovePropA
 0x5d2600 RemoveMenu
 0x5d2604 ReleaseDC
 0x5d2608 ReleaseCapture
 0x5d260c RegisterWindowMessageA
 0x5d2610 RegisterClipboardFormatA
 0x5d2614 RegisterClassA
 0x5d2618 RedrawWindow
 0x5d261c PtInRect
 0x5d2620 PostQuitMessage
 0x5d2624 PostMessageA
 0x5d2628 PeekMessageA
 0x5d262c OpenClipboard
 0x5d2630 OffsetRect
 0x5d2634 OemToCharA
 0x5d2638 MsgWaitForMultipleObjects
 0x5d263c MoveWindow
 0x5d2640 MessageBoxA
 0x5d2644 MessageBeep
 0x5d2648 MapWindowPoints
 0x5d264c MapVirtualKeyA
 0x5d2650 LoadStringA
 0x5d2654 LoadKeyboardLayoutA
 0x5d2658 LoadIconA
 0x5d265c LoadCursorA
 0x5d2660 LoadBitmapA
 0x5d2664 KillTimer
 0x5d2668 IsZoomed
 0x5d266c IsWindowVisible
 0x5d2670 IsWindowUnicode
 0x5d2674 IsWindowEnabled
 0x5d2678 IsWindow
 0x5d267c IsRectEmpty
 0x5d2680 IsIconic
 0x5d2684 IsDialogMessageA
 0x5d2688 IsClipboardFormatAvailable
 0x5d268c IsChild
 0x5d2690 IsCharAlphaNumericA
 0x5d2694 IsCharAlphaA
 0x5d2698 InvalidateRect
 0x5d269c IntersectRect
 0x5d26a0 InsertMenuItemA
 0x5d26a4 InsertMenuA
 0x5d26a8 InflateRect
 0x5d26ac HideCaret
 0x5d26b0 GetWindowThreadProcessId
 0x5d26b4 GetWindowTextLengthW
 0x5d26b8 GetWindowTextW
 0x5d26bc GetWindowTextA
 0x5d26c0 GetWindowRect
 0x5d26c4 GetWindowPlacement
 0x5d26c8 GetWindowLongW
 0x5d26cc GetWindowLongA
 0x5d26d0 GetWindowDC
 0x5d26d4 GetTopWindow
 0x5d26d8 GetSystemMetrics
 0x5d26dc GetSystemMenu
 0x5d26e0 GetSysColorBrush
 0x5d26e4 GetSysColor
 0x5d26e8 GetSubMenu
 0x5d26ec GetScrollRange
 0x5d26f0 GetScrollPos
 0x5d26f4 GetScrollInfo
 0x5d26f8 GetPropA
 0x5d26fc GetParent
 0x5d2700 GetWindow
 0x5d2704 GetMessageTime
 0x5d2708 GetMenuStringA
 0x5d270c GetMenuState
 0x5d2710 GetMenuItemInfoA
 0x5d2714 GetMenuItemID
 0x5d2718 GetMenuItemCount
 0x5d271c GetMenu
 0x5d2720 GetLastActivePopup
 0x5d2724 GetKeyboardState
 0x5d2728 GetKeyboardLayoutList
 0x5d272c GetKeyboardLayout
 0x5d2730 GetKeyState
 0x5d2734 GetKeyNameTextA
 0x5d2738 GetIconInfo
 0x5d273c GetForegroundWindow
 0x5d2740 GetFocus
 0x5d2744 GetDoubleClickTime
 0x5d2748 GetDlgItem
 0x5d274c GetDlgCtrlID
 0x5d2750 GetDesktopWindow
 0x5d2754 GetDCEx
 0x5d2758 GetDC
 0x5d275c GetCursorPos
 0x5d2760 GetCursor
 0x5d2764 GetClipboardData
 0x5d2768 GetClientRect
 0x5d276c GetClassNameA
 0x5d2770 GetClassInfoA
 0x5d2774 GetCaretPos
 0x5d2778 GetCapture
 0x5d277c GetActiveWindow
 0x5d2780 FrameRect
 0x5d2784 FindWindowExA
 0x5d2788 FindWindowA
 0x5d278c FillRect
 0x5d2790 EqualRect
 0x5d2794 EnumWindows
 0x5d2798 EnumThreadWindows
 0x5d279c EnumClipboardFormats
 0x5d27a0 EndPaint
 0x5d27a4 EnableWindow
 0x5d27a8 EnableScrollBar
 0x5d27ac EnableMenuItem
 0x5d27b0 EmptyClipboard
 0x5d27b4 DrawTextExA
 0x5d27b8 DrawTextW
 0x5d27bc DrawTextA
 0x5d27c0 DrawMenuBar
 0x5d27c4 DrawIconEx
 0x5d27c8 DrawIcon
 0x5d27cc DrawFrameControl
 0x5d27d0 DrawFocusRect
 0x5d27d4 DrawEdge
 0x5d27d8 DispatchMessageA
 0x5d27dc DestroyWindow
 0x5d27e0 DestroyMenu
 0x5d27e4 DestroyIcon
 0x5d27e8 DestroyCursor
 0x5d27ec DestroyCaret
 0x5d27f0 DeleteMenu
 0x5d27f4 DefWindowProcA
 0x5d27f8 DefMDIChildProcA
 0x5d27fc DefFrameProcA
 0x5d2800 CreatePopupMenu
 0x5d2804 CreateMenu
 0x5d2808 CreateIcon
 0x5d280c CreateCaret
 0x5d2810 CopyImage
 0x5d2814 CloseClipboard
 0x5d2818 ClientToScreen
 0x5d281c CheckMenuItem
 0x5d2820 CallWindowProcA
 0x5d2824 CallNextHookEx
 0x5d2828 BeginPaint
 0x5d282c CharNextA
 0x5d2830 CharLowerBuffA
 0x5d2834 CharLowerA
 0x5d2838 CharUpperBuffA
 0x5d283c CharToOemA
 0x5d2840 AdjustWindowRectEx
 0x5d2844 ActivateKeyboardLayout
ole32.dll
 0x5d284c CoTaskMemFree
 0x5d2850 StringFromCLSID
kernel32.dll
 0x5d2858 Sleep
oleaut32.dll
 0x5d2860 SafeArrayPtrOfIndex
 0x5d2864 SafeArrayPutElement
 0x5d2868 SafeArrayGetElement
 0x5d286c SafeArrayUnaccessData
 0x5d2870 SafeArrayAccessData
 0x5d2874 SafeArrayGetUBound
 0x5d2878 SafeArrayGetLBound
 0x5d287c SafeArrayRedim
 0x5d2880 SafeArrayCreate
 0x5d2884 VariantChangeType
 0x5d2888 VariantCopyInd
 0x5d288c VariantCopy
 0x5d2890 VariantClear
 0x5d2894 VariantInit
ole32.dll
 0x5d289c CoCreateInstance
 0x5d28a0 CoGetMalloc
 0x5d28a4 CoUninitialize
 0x5d28a8 CoInitialize
 0x5d28ac IsEqualGUID
oleaut32.dll
 0x5d28b4 CreateErrorInfo
 0x5d28b8 GetErrorInfo
 0x5d28bc SetErrorInfo
 0x5d28c0 SafeArrayCopy
 0x5d28c4 SafeArrayUnaccessData
 0x5d28c8 SafeArrayAccessData
 0x5d28cc SafeArrayGetUBound
 0x5d28d0 SafeArrayDestroy
 0x5d28d4 SafeArrayCreate
 0x5d28d8 SysFreeString
comctl32.dll
 0x5d28e0 ImageList_SetIconSize
 0x5d28e4 ImageList_GetIconSize
 0x5d28e8 ImageList_Write
 0x5d28ec ImageList_Read
 0x5d28f0 ImageList_GetDragImage
 0x5d28f4 ImageList_DragShowNolock
 0x5d28f8 ImageList_SetDragCursorImage
 0x5d28fc ImageList_DragMove
 0x5d2900 ImageList_DragLeave
 0x5d2904 ImageList_DragEnter
 0x5d2908 ImageList_EndDrag
 0x5d290c ImageList_BeginDrag
 0x5d2910 ImageList_LoadImageA
 0x5d2914 ImageList_Remove
 0x5d2918 ImageList_DrawEx
 0x5d291c ImageList_Replace
 0x5d2920 ImageList_Draw
 0x5d2924 ImageList_GetBkColor
 0x5d2928 ImageList_SetBkColor
 0x5d292c ImageList_ReplaceIcon
 0x5d2930 ImageList_Add
 0x5d2934 ImageList_GetImageCount
 0x5d2938 ImageList_Destroy
 0x5d293c ImageList_Create
 0x5d2940 InitCommonControls
comdlg32.dll
 0x5d2948 GetSaveFileNameA
 0x5d294c GetOpenFileNameA
kernel32.dll
 0x5d2954 MulDiv
kernel32.dll
 0x5d295c MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure