Report - POS_C093.exe

Malicious Library Downloader UPX PE File DllRegisterServer dll PE32 MZP Format OS Processor Check
ScreenShot
Created 2024.08.19 15:20 Machine s1_win7_x6401
Filename POS_C093.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 4 detected (AIDetectMalware, Malicious, susgen, confidence)
md5 d13c1ebc4923c0603b836f74330b78de
sha256 9aaf9af2fc9c531bae300bcad8eb6539ffb987b9471d72ab93f39c95cdf43154
ssdeep 24576:2WxRVwM76WDYveZSv9OoiPmYCDf5uK2HXpbiG9aN0F/Xaewsr1mU5H6KDtvkyDCy:RJtXzuOHJ9FDr1+KDtSM3PD
imphash 1145eaa36b869280ed469aa391025f3e
impfuzzy 192:33ugG1sTlc0FGbuuEjSUvK9ugoaqlBtc7aPbOQad3U:33S1spAEo9YRPPbOQiU
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 4 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (8cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Network_Downloader File Downloader binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5f817c DeleteCriticalSection
 0x5f8180 LeaveCriticalSection
 0x5f8184 EnterCriticalSection
 0x5f8188 InitializeCriticalSection
 0x5f818c VirtualFree
 0x5f8190 VirtualAlloc
 0x5f8194 LocalFree
 0x5f8198 LocalAlloc
 0x5f819c GetTickCount
 0x5f81a0 QueryPerformanceCounter
 0x5f81a4 GetVersion
 0x5f81a8 GetCurrentThreadId
 0x5f81ac InterlockedDecrement
 0x5f81b0 InterlockedIncrement
 0x5f81b4 VirtualQuery
 0x5f81b8 WideCharToMultiByte
 0x5f81bc MultiByteToWideChar
 0x5f81c0 lstrlenA
 0x5f81c4 lstrcpynA
 0x5f81c8 LoadLibraryExA
 0x5f81cc GetThreadLocale
 0x5f81d0 GetStartupInfoA
 0x5f81d4 GetProcAddress
 0x5f81d8 GetModuleHandleA
 0x5f81dc GetModuleFileNameA
 0x5f81e0 GetLocaleInfoA
 0x5f81e4 GetCommandLineA
 0x5f81e8 FreeLibrary
 0x5f81ec FindFirstFileA
 0x5f81f0 FindClose
 0x5f81f4 ExitProcess
 0x5f81f8 ExitThread
 0x5f81fc CreateThread
 0x5f8200 WriteFile
 0x5f8204 UnhandledExceptionFilter
 0x5f8208 RtlUnwind
 0x5f820c RaiseException
 0x5f8210 GetStdHandle
user32.dll
 0x5f8218 GetKeyboardType
 0x5f821c LoadStringA
 0x5f8220 MessageBoxA
 0x5f8224 CharNextA
advapi32.dll
 0x5f822c RegQueryValueExA
 0x5f8230 RegOpenKeyExA
 0x5f8234 RegCloseKey
oleaut32.dll
 0x5f823c SysFreeString
 0x5f8240 SysReAllocStringLen
 0x5f8244 SysAllocStringLen
kernel32.dll
 0x5f824c TlsSetValue
 0x5f8250 TlsGetValue
 0x5f8254 LocalAlloc
 0x5f8258 GetModuleHandleA
advapi32.dll
 0x5f8260 RegQueryValueExA
 0x5f8264 RegQueryValueA
 0x5f8268 RegOpenKeyExA
 0x5f826c RegCloseKey
kernel32.dll
 0x5f8274 lstrcpyA
 0x5f8278 WriteFile
 0x5f827c WaitForSingleObject
 0x5f8280 VirtualQuery
 0x5f8284 VirtualAlloc
 0x5f8288 Sleep
 0x5f828c SizeofResource
 0x5f8290 SetThreadLocale
 0x5f8294 SetFilePointer
 0x5f8298 SetEvent
 0x5f829c SetErrorMode
 0x5f82a0 SetEndOfFile
 0x5f82a4 ResumeThread
 0x5f82a8 ResetEvent
 0x5f82ac ReadFile
 0x5f82b0 MultiByteToWideChar
 0x5f82b4 MulDiv
 0x5f82b8 LockResource
 0x5f82bc LoadResource
 0x5f82c0 LoadLibraryA
 0x5f82c4 LeaveCriticalSection
 0x5f82c8 IsBadReadPtr
 0x5f82cc InitializeCriticalSection
 0x5f82d0 GlobalUnlock
 0x5f82d4 GlobalSize
 0x5f82d8 GlobalReAlloc
 0x5f82dc GlobalHandle
 0x5f82e0 GlobalLock
 0x5f82e4 GlobalFree
 0x5f82e8 GlobalFindAtomA
 0x5f82ec GlobalDeleteAtom
 0x5f82f0 GlobalAlloc
 0x5f82f4 GlobalAddAtomA
 0x5f82f8 GetVersionExA
 0x5f82fc GetVersion
 0x5f8300 GetTimeZoneInformation
 0x5f8304 GetTickCount
 0x5f8308 GetThreadLocale
 0x5f830c GetTempPathA
 0x5f8310 GetSystemInfo
 0x5f8314 GetStringTypeExA
 0x5f8318 GetStdHandle
 0x5f831c GetProcAddress
 0x5f8320 GetModuleHandleA
 0x5f8324 GetModuleFileNameA
 0x5f8328 GetLocaleInfoA
 0x5f832c GetLocalTime
 0x5f8330 GetLastError
 0x5f8334 GetFullPathNameA
 0x5f8338 GetFileSize
 0x5f833c GetExitCodeThread
 0x5f8340 GetDiskFreeSpaceA
 0x5f8344 GetDateFormatA
 0x5f8348 GetCurrentThreadId
 0x5f834c GetCurrentProcessId
 0x5f8350 GetCPInfo
 0x5f8354 GetACP
 0x5f8358 FreeResource
 0x5f835c InterlockedIncrement
 0x5f8360 InterlockedExchange
 0x5f8364 InterlockedDecrement
 0x5f8368 FreeLibrary
 0x5f836c FormatMessageA
 0x5f8370 FindResourceA
 0x5f8374 FindFirstFileA
 0x5f8378 FindClose
 0x5f837c FileTimeToLocalFileTime
 0x5f8380 FileTimeToDosDateTime
 0x5f8384 EnumCalendarInfoA
 0x5f8388 EnterCriticalSection
 0x5f838c DeleteFileA
 0x5f8390 DeleteCriticalSection
 0x5f8394 CreateThread
 0x5f8398 CreateFileA
 0x5f839c CreateEventA
 0x5f83a0 CompareStringA
 0x5f83a4 CloseHandle
version.dll
 0x5f83ac VerQueryValueA
 0x5f83b0 GetFileVersionInfoSizeA
 0x5f83b4 GetFileVersionInfoA
gdi32.dll
 0x5f83bc UnrealizeObject
 0x5f83c0 StretchBlt
 0x5f83c4 SetWindowOrgEx
 0x5f83c8 SetWindowExtEx
 0x5f83cc SetWinMetaFileBits
 0x5f83d0 SetViewportOrgEx
 0x5f83d4 SetViewportExtEx
 0x5f83d8 SetTextColor
 0x5f83dc SetStretchBltMode
 0x5f83e0 SetROP2
 0x5f83e4 SetPixel
 0x5f83e8 SetMapMode
 0x5f83ec SetEnhMetaFileBits
 0x5f83f0 SetDIBColorTable
 0x5f83f4 SetBrushOrgEx
 0x5f83f8 SetBkMode
 0x5f83fc SetBkColor
 0x5f8400 SelectPalette
 0x5f8404 SelectObject
 0x5f8408 SelectClipRgn
 0x5f840c SaveDC
 0x5f8410 RoundRect
 0x5f8414 RestoreDC
 0x5f8418 Rectangle
 0x5f841c RectVisible
 0x5f8420 RealizePalette
 0x5f8424 Polyline
 0x5f8428 Polygon
 0x5f842c PolyPolyline
 0x5f8430 PlayEnhMetaFile
 0x5f8434 PatBlt
 0x5f8438 MoveToEx
 0x5f843c MaskBlt
 0x5f8440 LineTo
 0x5f8444 LPtoDP
 0x5f8448 IntersectClipRect
 0x5f844c GetWindowOrgEx
 0x5f8450 GetWinMetaFileBits
 0x5f8454 GetViewportOrgEx
 0x5f8458 GetTextMetricsA
 0x5f845c GetTextExtentPointA
 0x5f8460 GetTextExtentPoint32A
 0x5f8464 GetSystemPaletteEntries
 0x5f8468 GetStockObject
 0x5f846c GetPixel
 0x5f8470 GetPaletteEntries
 0x5f8474 GetOutlineTextMetricsA
 0x5f8478 GetObjectA
 0x5f847c GetNearestColor
 0x5f8480 GetEnhMetaFilePaletteEntries
 0x5f8484 GetEnhMetaFileHeader
 0x5f8488 GetEnhMetaFileBits
 0x5f848c GetDeviceCaps
 0x5f8490 GetDIBits
 0x5f8494 GetDIBColorTable
 0x5f8498 GetDCOrgEx
 0x5f849c GetCurrentPositionEx
 0x5f84a0 GetCurrentObject
 0x5f84a4 GetClipRgn
 0x5f84a8 GetClipBox
 0x5f84ac GetBrushOrgEx
 0x5f84b0 GetBitmapBits
 0x5f84b4 GdiFlush
 0x5f84b8 ExtTextOutA
 0x5f84bc ExtSelectClipRgn
 0x5f84c0 ExtCreateRegion
 0x5f84c4 ExtCreatePen
 0x5f84c8 ExcludeClipRect
 0x5f84cc Ellipse
 0x5f84d0 DeleteObject
 0x5f84d4 DeleteEnhMetaFile
 0x5f84d8 DeleteDC
 0x5f84dc CreateSolidBrush
 0x5f84e0 CreateRectRgn
 0x5f84e4 CreatePolygonRgn
 0x5f84e8 CreatePenIndirect
 0x5f84ec CreatePen
 0x5f84f0 CreatePalette
 0x5f84f4 CreateHalftonePalette
 0x5f84f8 CreateFontIndirectA
 0x5f84fc CreateDIBitmap
 0x5f8500 CreateDIBSection
 0x5f8504 CreateCompatibleDC
 0x5f8508 CreateCompatibleBitmap
 0x5f850c CreateBrushIndirect
 0x5f8510 CreateBitmap
 0x5f8514 CopyEnhMetaFileA
 0x5f8518 CombineRgn
 0x5f851c BitBlt
user32.dll
 0x5f8524 CreateWindowExA
 0x5f8528 WindowFromPoint
 0x5f852c WinHelpA
 0x5f8530 WaitMessage
 0x5f8534 ValidateRect
 0x5f8538 UpdateWindow
 0x5f853c UnregisterClassA
 0x5f8540 UnhookWindowsHookEx
 0x5f8544 TranslateMessage
 0x5f8548 TranslateMDISysAccel
 0x5f854c TrackPopupMenu
 0x5f8550 SystemParametersInfoA
 0x5f8554 ShowWindow
 0x5f8558 ShowScrollBar
 0x5f855c ShowOwnedPopups
 0x5f8560 ShowCursor
 0x5f8564 ShowCaret
 0x5f8568 SetWindowRgn
 0x5f856c SetWindowsHookExA
 0x5f8570 SetWindowTextA
 0x5f8574 SetWindowPos
 0x5f8578 SetWindowPlacement
 0x5f857c SetWindowLongW
 0x5f8580 SetWindowLongA
 0x5f8584 SetTimer
 0x5f8588 SetScrollRange
 0x5f858c SetScrollPos
 0x5f8590 SetScrollInfo
 0x5f8594 SetRect
 0x5f8598 SetPropA
 0x5f859c SetParent
 0x5f85a0 SetMenuItemInfoA
 0x5f85a4 SetMenu
 0x5f85a8 SetKeyboardState
 0x5f85ac SetForegroundWindow
 0x5f85b0 SetFocus
 0x5f85b4 SetCursor
 0x5f85b8 SetClipboardData
 0x5f85bc SetClassLongA
 0x5f85c0 SetCapture
 0x5f85c4 SetActiveWindow
 0x5f85c8 SendMessageA
 0x5f85cc ScrollWindowEx
 0x5f85d0 ScrollWindow
 0x5f85d4 ScreenToClient
 0x5f85d8 RemovePropA
 0x5f85dc RemoveMenu
 0x5f85e0 ReleaseDC
 0x5f85e4 ReleaseCapture
 0x5f85e8 RegisterWindowMessageA
 0x5f85ec RegisterClipboardFormatA
 0x5f85f0 RegisterClassA
 0x5f85f4 RedrawWindow
 0x5f85f8 PtInRect
 0x5f85fc PostQuitMessage
 0x5f8600 PostMessageA
 0x5f8604 PeekMessageA
 0x5f8608 OpenClipboard
 0x5f860c OffsetRect
 0x5f8610 OemToCharA
 0x5f8614 MsgWaitForMultipleObjects
 0x5f8618 MoveWindow
 0x5f861c MessageBoxA
 0x5f8620 MessageBeep
 0x5f8624 MapWindowPoints
 0x5f8628 MapVirtualKeyA
 0x5f862c LoadStringA
 0x5f8630 LoadKeyboardLayoutA
 0x5f8634 LoadIconA
 0x5f8638 LoadCursorA
 0x5f863c LoadBitmapA
 0x5f8640 KillTimer
 0x5f8644 IsZoomed
 0x5f8648 IsWindowVisible
 0x5f864c IsWindowUnicode
 0x5f8650 IsWindowEnabled
 0x5f8654 IsWindow
 0x5f8658 IsRectEmpty
 0x5f865c IsIconic
 0x5f8660 IsDialogMessageA
 0x5f8664 IsClipboardFormatAvailable
 0x5f8668 IsChild
 0x5f866c IsCharAlphaNumericA
 0x5f8670 IsCharAlphaA
 0x5f8674 InvalidateRect
 0x5f8678 IntersectRect
 0x5f867c InsertMenuItemA
 0x5f8680 InsertMenuA
 0x5f8684 InflateRect
 0x5f8688 HideCaret
 0x5f868c GetWindowThreadProcessId
 0x5f8690 GetWindowTextLengthW
 0x5f8694 GetWindowTextW
 0x5f8698 GetWindowTextA
 0x5f869c GetWindowRect
 0x5f86a0 GetWindowPlacement
 0x5f86a4 GetWindowLongW
 0x5f86a8 GetWindowLongA
 0x5f86ac GetWindowDC
 0x5f86b0 GetTopWindow
 0x5f86b4 GetSystemMetrics
 0x5f86b8 GetSystemMenu
 0x5f86bc GetSysColorBrush
 0x5f86c0 GetSysColor
 0x5f86c4 GetSubMenu
 0x5f86c8 GetScrollRange
 0x5f86cc GetScrollPos
 0x5f86d0 GetScrollInfo
 0x5f86d4 GetPropA
 0x5f86d8 GetParent
 0x5f86dc GetWindow
 0x5f86e0 GetMessageTime
 0x5f86e4 GetMenuStringA
 0x5f86e8 GetMenuState
 0x5f86ec GetMenuItemInfoA
 0x5f86f0 GetMenuItemID
 0x5f86f4 GetMenuItemCount
 0x5f86f8 GetMenu
 0x5f86fc GetLastActivePopup
 0x5f8700 GetKeyboardState
 0x5f8704 GetKeyboardLayoutList
 0x5f8708 GetKeyboardLayout
 0x5f870c GetKeyState
 0x5f8710 GetKeyNameTextA
 0x5f8714 GetIconInfo
 0x5f8718 GetForegroundWindow
 0x5f871c GetFocus
 0x5f8720 GetDoubleClickTime
 0x5f8724 GetDlgCtrlID
 0x5f8728 GetDesktopWindow
 0x5f872c GetDCEx
 0x5f8730 GetDC
 0x5f8734 GetCursorPos
 0x5f8738 GetCursor
 0x5f873c GetClipboardData
 0x5f8740 GetClientRect
 0x5f8744 GetClassNameA
 0x5f8748 GetClassInfoA
 0x5f874c GetCaretPos
 0x5f8750 GetCapture
 0x5f8754 GetActiveWindow
 0x5f8758 FrameRect
 0x5f875c FindWindowExA
 0x5f8760 FindWindowA
 0x5f8764 FillRect
 0x5f8768 EqualRect
 0x5f876c EnumWindows
 0x5f8770 EnumThreadWindows
 0x5f8774 EnumClipboardFormats
 0x5f8778 EndPaint
 0x5f877c EnableWindow
 0x5f8780 EnableScrollBar
 0x5f8784 EnableMenuItem
 0x5f8788 EmptyClipboard
 0x5f878c DrawTextExA
 0x5f8790 DrawTextW
 0x5f8794 DrawTextA
 0x5f8798 DrawMenuBar
 0x5f879c DrawIconEx
 0x5f87a0 DrawIcon
 0x5f87a4 DrawFrameControl
 0x5f87a8 DrawFocusRect
 0x5f87ac DrawEdge
 0x5f87b0 DispatchMessageA
 0x5f87b4 DestroyWindow
 0x5f87b8 DestroyMenu
 0x5f87bc DestroyIcon
 0x5f87c0 DestroyCursor
 0x5f87c4 DeleteMenu
 0x5f87c8 DefWindowProcA
 0x5f87cc DefMDIChildProcA
 0x5f87d0 DefFrameProcA
 0x5f87d4 CreatePopupMenu
 0x5f87d8 CreateMenu
 0x5f87dc CreateIcon
 0x5f87e0 CopyImage
 0x5f87e4 CloseClipboard
 0x5f87e8 ClientToScreen
 0x5f87ec CheckMenuItem
 0x5f87f0 CallWindowProcA
 0x5f87f4 CallNextHookEx
 0x5f87f8 BeginPaint
 0x5f87fc CharNextA
 0x5f8800 CharLowerBuffA
 0x5f8804 CharLowerA
 0x5f8808 CharUpperBuffA
 0x5f880c CharToOemA
 0x5f8810 AdjustWindowRectEx
 0x5f8814 ActivateKeyboardLayout
ole32.dll
 0x5f881c IsEqualGUID
 0x5f8820 CoTaskMemFree
 0x5f8824 StringFromCLSID
 0x5f8828 CoCreateGuid
kernel32.dll
 0x5f8830 Sleep
oleaut32.dll
 0x5f8838 SafeArrayPtrOfIndex
 0x5f883c SafeArrayPutElement
 0x5f8840 SafeArrayGetElement
 0x5f8844 SafeArrayUnaccessData
 0x5f8848 SafeArrayAccessData
 0x5f884c SafeArrayGetUBound
 0x5f8850 SafeArrayGetLBound
 0x5f8854 SafeArrayRedim
 0x5f8858 SafeArrayCreate
 0x5f885c VariantChangeType
 0x5f8860 VariantCopyInd
 0x5f8864 VariantCopy
 0x5f8868 VariantClear
 0x5f886c VariantInit
ole32.dll
 0x5f8874 CoCreateInstance
 0x5f8878 CoGetMalloc
 0x5f887c CoUninitialize
 0x5f8880 CoInitialize
 0x5f8884 IsEqualGUID
oleaut32.dll
 0x5f888c CreateErrorInfo
 0x5f8890 GetErrorInfo
 0x5f8894 SetErrorInfo
 0x5f8898 SafeArrayCopy
 0x5f889c SafeArrayUnaccessData
 0x5f88a0 SafeArrayAccessData
 0x5f88a4 SafeArrayGetUBound
 0x5f88a8 SafeArrayDestroy
 0x5f88ac SafeArrayCreate
 0x5f88b0 SysFreeString
comctl32.dll
 0x5f88b8 ImageList_SetIconSize
 0x5f88bc ImageList_GetIconSize
 0x5f88c0 ImageList_Write
 0x5f88c4 ImageList_Read
 0x5f88c8 ImageList_GetDragImage
 0x5f88cc ImageList_DragShowNolock
 0x5f88d0 ImageList_SetDragCursorImage
 0x5f88d4 ImageList_DragMove
 0x5f88d8 ImageList_DragLeave
 0x5f88dc ImageList_DragEnter
 0x5f88e0 ImageList_EndDrag
 0x5f88e4 ImageList_BeginDrag
 0x5f88e8 ImageList_LoadImageA
 0x5f88ec ImageList_Remove
 0x5f88f0 ImageList_DrawEx
 0x5f88f4 ImageList_Replace
 0x5f88f8 ImageList_Draw
 0x5f88fc ImageList_GetBkColor
 0x5f8900 ImageList_SetBkColor
 0x5f8904 ImageList_ReplaceIcon
 0x5f8908 ImageList_Add
 0x5f890c ImageList_GetImageCount
 0x5f8910 ImageList_Destroy
 0x5f8914 ImageList_Create
 0x5f8918 InitCommonControls
wininet.dll
 0x5f8920 HttpSendRequestExA
 0x5f8924 InternetAttemptConnect
 0x5f8928 HttpEndRequestA
 0x5f892c InternetWriteFile
 0x5f8930 InternetSetOptionA
 0x5f8934 InternetReadFile
 0x5f8938 InternetQueryOptionA
 0x5f893c InternetQueryDataAvailable
 0x5f8940 InternetOpenA
 0x5f8944 InternetErrorDlg
 0x5f8948 InternetCrackUrlA
 0x5f894c InternetConnectA
 0x5f8950 InternetCloseHandle
 0x5f8954 HttpSendRequestA
 0x5f8958 HttpQueryInfoA
 0x5f895c HttpOpenRequestA
 0x5f8960 HttpAddRequestHeadersA
kernel32.dll
 0x5f8968 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure