Report - POS_C091.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:45 Machine s1_win7_x6403
Filename POS_C091.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 9 detected (Strictor, ai score=80)
md5 4542643b447f61d5b323ccb555eec06c
sha256 9df00b2fae882736f0cf6fcf3f59e9007db8cbc2f96ff7eb02affdf121b385a6
ssdeep 24576:2Mhdd6nEcDZSlh5wmj68EB5fI1lswi+6fu/Pwotqz05YiarRs7mrnaA3Ur5a/OB9:2u4ZSl/1gvAzPPYjUmHU9a6P/gFTwPD
imphash a2392071f5f0f83ee838fa07e4301b15
impfuzzy 192:f3o7BmJ1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQzd9:f3F1q/Ez9YPpPbOQj
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 9 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5d2190 DeleteCriticalSection
 0x5d2194 LeaveCriticalSection
 0x5d2198 EnterCriticalSection
 0x5d219c InitializeCriticalSection
 0x5d21a0 VirtualFree
 0x5d21a4 VirtualAlloc
 0x5d21a8 LocalFree
 0x5d21ac LocalAlloc
 0x5d21b0 GetVersion
 0x5d21b4 GetCurrentThreadId
 0x5d21b8 InterlockedDecrement
 0x5d21bc InterlockedIncrement
 0x5d21c0 VirtualQuery
 0x5d21c4 WideCharToMultiByte
 0x5d21c8 MultiByteToWideChar
 0x5d21cc lstrlenA
 0x5d21d0 lstrcpynA
 0x5d21d4 LoadLibraryExA
 0x5d21d8 GetThreadLocale
 0x5d21dc GetStartupInfoA
 0x5d21e0 GetProcAddress
 0x5d21e4 GetModuleHandleA
 0x5d21e8 GetModuleFileNameA
 0x5d21ec GetLocaleInfoA
 0x5d21f0 GetCommandLineA
 0x5d21f4 FreeLibrary
 0x5d21f8 FindFirstFileA
 0x5d21fc FindClose
 0x5d2200 ExitProcess
 0x5d2204 ExitThread
 0x5d2208 CreateThread
 0x5d220c WriteFile
 0x5d2210 UnhandledExceptionFilter
 0x5d2214 RtlUnwind
 0x5d2218 RaiseException
 0x5d221c GetStdHandle
user32.dll
 0x5d2224 GetKeyboardType
 0x5d2228 LoadStringA
 0x5d222c MessageBoxA
 0x5d2230 CharNextA
advapi32.dll
 0x5d2238 RegQueryValueExA
 0x5d223c RegOpenKeyExA
 0x5d2240 RegCloseKey
oleaut32.dll
 0x5d2248 SysFreeString
 0x5d224c SysReAllocStringLen
 0x5d2250 SysAllocStringLen
kernel32.dll
 0x5d2258 TlsSetValue
 0x5d225c TlsGetValue
 0x5d2260 LocalAlloc
 0x5d2264 GetModuleHandleA
advapi32.dll
 0x5d226c RegSetValueExA
 0x5d2270 RegQueryValueExA
 0x5d2274 RegQueryValueA
 0x5d2278 RegOpenKeyExA
 0x5d227c RegFlushKey
 0x5d2280 RegCreateKeyExA
 0x5d2284 RegCloseKey
kernel32.dll
 0x5d228c lstrcpyA
 0x5d2290 WritePrivateProfileStringA
 0x5d2294 WriteFile
 0x5d2298 WaitForSingleObject
 0x5d229c VirtualQuery
 0x5d22a0 VirtualAlloc
 0x5d22a4 Sleep
 0x5d22a8 SizeofResource
 0x5d22ac SetThreadLocale
 0x5d22b0 SetFilePointer
 0x5d22b4 SetEvent
 0x5d22b8 SetErrorMode
 0x5d22bc SetEndOfFile
 0x5d22c0 ResumeThread
 0x5d22c4 ResetEvent
 0x5d22c8 ReleaseMutex
 0x5d22cc ReadFile
 0x5d22d0 MultiByteToWideChar
 0x5d22d4 MulDiv
 0x5d22d8 LockResource
 0x5d22dc LoadResource
 0x5d22e0 LoadLibraryA
 0x5d22e4 LeaveCriticalSection
 0x5d22e8 IsBadReadPtr
 0x5d22ec InitializeCriticalSection
 0x5d22f0 GlobalUnlock
 0x5d22f4 GlobalSize
 0x5d22f8 GlobalReAlloc
 0x5d22fc GlobalHandle
 0x5d2300 GlobalLock
 0x5d2304 GlobalFree
 0x5d2308 GlobalFindAtomA
 0x5d230c GlobalDeleteAtom
 0x5d2310 GlobalAlloc
 0x5d2314 GlobalAddAtomA
 0x5d2318 GetVersionExA
 0x5d231c GetVersion
 0x5d2320 GetTimeZoneInformation
 0x5d2324 GetTickCount
 0x5d2328 GetThreadLocale
 0x5d232c GetTempPathA
 0x5d2330 GetSystemInfo
 0x5d2334 GetStringTypeExA
 0x5d2338 GetStdHandle
 0x5d233c GetProcAddress
 0x5d2340 GetPrivateProfileStringA
 0x5d2344 GetModuleHandleA
 0x5d2348 GetModuleFileNameA
 0x5d234c GetLocaleInfoA
 0x5d2350 GetLocalTime
 0x5d2354 GetLastError
 0x5d2358 GetFullPathNameA
 0x5d235c GetFileSize
 0x5d2360 GetExitCodeThread
 0x5d2364 GetDiskFreeSpaceA
 0x5d2368 GetDateFormatA
 0x5d236c GetCurrentThreadId
 0x5d2370 GetCurrentProcessId
 0x5d2374 GetComputerNameA
 0x5d2378 GetCPInfo
 0x5d237c GetACP
 0x5d2380 FreeResource
 0x5d2384 InterlockedIncrement
 0x5d2388 InterlockedExchange
 0x5d238c InterlockedDecrement
 0x5d2390 FreeLibrary
 0x5d2394 FormatMessageA
 0x5d2398 FindResourceA
 0x5d239c FindFirstFileA
 0x5d23a0 FindClose
 0x5d23a4 FileTimeToLocalFileTime
 0x5d23a8 FileTimeToDosDateTime
 0x5d23ac EnumCalendarInfoA
 0x5d23b0 EnterCriticalSection
 0x5d23b4 DeleteCriticalSection
 0x5d23b8 CreateThread
 0x5d23bc CreateMutexA
 0x5d23c0 CreateFileA
 0x5d23c4 CreateEventA
 0x5d23c8 CompareStringA
 0x5d23cc CloseHandle
version.dll
 0x5d23d4 VerQueryValueA
 0x5d23d8 GetFileVersionInfoSizeA
 0x5d23dc GetFileVersionInfoA
gdi32.dll
 0x5d23e4 UnrealizeObject
 0x5d23e8 StretchBlt
 0x5d23ec SetWindowOrgEx
 0x5d23f0 SetWindowExtEx
 0x5d23f4 SetWinMetaFileBits
 0x5d23f8 SetViewportOrgEx
 0x5d23fc SetViewportExtEx
 0x5d2400 SetTextColor
 0x5d2404 SetStretchBltMode
 0x5d2408 SetROP2
 0x5d240c SetPixel
 0x5d2410 SetMapMode
 0x5d2414 SetEnhMetaFileBits
 0x5d2418 SetDIBColorTable
 0x5d241c SetBrushOrgEx
 0x5d2420 SetBkMode
 0x5d2424 SetBkColor
 0x5d2428 SelectPalette
 0x5d242c SelectObject
 0x5d2430 SelectClipRgn
 0x5d2434 SaveDC
 0x5d2438 RoundRect
 0x5d243c RestoreDC
 0x5d2440 Rectangle
 0x5d2444 RectVisible
 0x5d2448 RealizePalette
 0x5d244c Polyline
 0x5d2450 Polygon
 0x5d2454 PolyPolyline
 0x5d2458 PlayEnhMetaFile
 0x5d245c PatBlt
 0x5d2460 MoveToEx
 0x5d2464 MaskBlt
 0x5d2468 LineTo
 0x5d246c LPtoDP
 0x5d2470 IntersectClipRect
 0x5d2474 GetWindowOrgEx
 0x5d2478 GetWinMetaFileBits
 0x5d247c GetViewportOrgEx
 0x5d2480 GetTextMetricsA
 0x5d2484 GetTextExtentPointA
 0x5d2488 GetTextExtentPoint32A
 0x5d248c GetSystemPaletteEntries
 0x5d2490 GetStockObject
 0x5d2494 GetPixel
 0x5d2498 GetPaletteEntries
 0x5d249c GetOutlineTextMetricsA
 0x5d24a0 GetObjectA
 0x5d24a4 GetNearestColor
 0x5d24a8 GetEnhMetaFilePaletteEntries
 0x5d24ac GetEnhMetaFileHeader
 0x5d24b0 GetEnhMetaFileBits
 0x5d24b4 GetDeviceCaps
 0x5d24b8 GetDIBits
 0x5d24bc GetDIBColorTable
 0x5d24c0 GetDCOrgEx
 0x5d24c4 GetCurrentPositionEx
 0x5d24c8 GetCurrentObject
 0x5d24cc GetClipRgn
 0x5d24d0 GetClipBox
 0x5d24d4 GetBrushOrgEx
 0x5d24d8 GetBitmapBits
 0x5d24dc GdiFlush
 0x5d24e0 ExtTextOutA
 0x5d24e4 ExtSelectClipRgn
 0x5d24e8 ExtCreateRegion
 0x5d24ec ExtCreatePen
 0x5d24f0 ExcludeClipRect
 0x5d24f4 Ellipse
 0x5d24f8 DeleteObject
 0x5d24fc DeleteEnhMetaFile
 0x5d2500 DeleteDC
 0x5d2504 CreateSolidBrush
 0x5d2508 CreateRectRgn
 0x5d250c CreatePolygonRgn
 0x5d2510 CreatePenIndirect
 0x5d2514 CreatePen
 0x5d2518 CreatePalette
 0x5d251c CreateHalftonePalette
 0x5d2520 CreateFontIndirectA
 0x5d2524 CreateDIBitmap
 0x5d2528 CreateDIBSection
 0x5d252c CreateCompatibleDC
 0x5d2530 CreateCompatibleBitmap
 0x5d2534 CreateBrushIndirect
 0x5d2538 CreateBitmap
 0x5d253c CopyEnhMetaFileA
 0x5d2540 CombineRgn
 0x5d2544 BitBlt
user32.dll
 0x5d254c CreateWindowExA
 0x5d2550 WindowFromPoint
 0x5d2554 WinHelpA
 0x5d2558 WaitMessage
 0x5d255c ValidateRect
 0x5d2560 UpdateWindow
 0x5d2564 UnregisterClassA
 0x5d2568 UnionRect
 0x5d256c UnhookWindowsHookEx
 0x5d2570 TranslateMessage
 0x5d2574 TranslateMDISysAccel
 0x5d2578 TrackPopupMenu
 0x5d257c SystemParametersInfoA
 0x5d2580 ShowWindow
 0x5d2584 ShowScrollBar
 0x5d2588 ShowOwnedPopups
 0x5d258c ShowCursor
 0x5d2590 ShowCaret
 0x5d2594 SetWindowRgn
 0x5d2598 SetWindowsHookExA
 0x5d259c SetWindowTextA
 0x5d25a0 SetWindowPos
 0x5d25a4 SetWindowPlacement
 0x5d25a8 SetWindowLongW
 0x5d25ac SetWindowLongA
 0x5d25b0 SetTimer
 0x5d25b4 SetScrollRange
 0x5d25b8 SetScrollPos
 0x5d25bc SetScrollInfo
 0x5d25c0 SetRect
 0x5d25c4 SetPropA
 0x5d25c8 SetParent
 0x5d25cc SetMenuItemInfoA
 0x5d25d0 SetMenu
 0x5d25d4 SetKeyboardState
 0x5d25d8 SetForegroundWindow
 0x5d25dc SetFocus
 0x5d25e0 SetCursor
 0x5d25e4 SetClipboardData
 0x5d25e8 SetClassLongA
 0x5d25ec SetCaretPos
 0x5d25f0 SetCapture
 0x5d25f4 SetActiveWindow
 0x5d25f8 SendMessageA
 0x5d25fc ScrollWindowEx
 0x5d2600 ScrollWindow
 0x5d2604 ScreenToClient
 0x5d2608 RemovePropA
 0x5d260c RemoveMenu
 0x5d2610 ReleaseDC
 0x5d2614 ReleaseCapture
 0x5d2618 RegisterWindowMessageA
 0x5d261c RegisterClipboardFormatA
 0x5d2620 RegisterClassA
 0x5d2624 RedrawWindow
 0x5d2628 PtInRect
 0x5d262c PostQuitMessage
 0x5d2630 PostMessageA
 0x5d2634 PeekMessageA
 0x5d2638 OpenClipboard
 0x5d263c OffsetRect
 0x5d2640 OemToCharA
 0x5d2644 MsgWaitForMultipleObjects
 0x5d2648 MoveWindow
 0x5d264c MessageBoxA
 0x5d2650 MessageBeep
 0x5d2654 MapWindowPoints
 0x5d2658 MapVirtualKeyA
 0x5d265c LoadStringA
 0x5d2660 LoadKeyboardLayoutA
 0x5d2664 LoadIconA
 0x5d2668 LoadCursorA
 0x5d266c LoadBitmapA
 0x5d2670 KillTimer
 0x5d2674 IsZoomed
 0x5d2678 IsWindowVisible
 0x5d267c IsWindowUnicode
 0x5d2680 IsWindowEnabled
 0x5d2684 IsWindow
 0x5d2688 IsRectEmpty
 0x5d268c IsIconic
 0x5d2690 IsDialogMessageA
 0x5d2694 IsClipboardFormatAvailable
 0x5d2698 IsChild
 0x5d269c IsCharAlphaNumericA
 0x5d26a0 IsCharAlphaA
 0x5d26a4 InvalidateRect
 0x5d26a8 IntersectRect
 0x5d26ac InsertMenuItemA
 0x5d26b0 InsertMenuA
 0x5d26b4 InflateRect
 0x5d26b8 HideCaret
 0x5d26bc GetWindowThreadProcessId
 0x5d26c0 GetWindowTextLengthW
 0x5d26c4 GetWindowTextW
 0x5d26c8 GetWindowTextA
 0x5d26cc GetWindowRect
 0x5d26d0 GetWindowPlacement
 0x5d26d4 GetWindowLongW
 0x5d26d8 GetWindowLongA
 0x5d26dc GetWindowDC
 0x5d26e0 GetTopWindow
 0x5d26e4 GetSystemMetrics
 0x5d26e8 GetSystemMenu
 0x5d26ec GetSysColorBrush
 0x5d26f0 GetSysColor
 0x5d26f4 GetSubMenu
 0x5d26f8 GetScrollRange
 0x5d26fc GetScrollPos
 0x5d2700 GetScrollInfo
 0x5d2704 GetPropA
 0x5d2708 GetParent
 0x5d270c GetWindow
 0x5d2710 GetMessageTime
 0x5d2714 GetMenuStringA
 0x5d2718 GetMenuState
 0x5d271c GetMenuItemInfoA
 0x5d2720 GetMenuItemID
 0x5d2724 GetMenuItemCount
 0x5d2728 GetMenu
 0x5d272c GetLastActivePopup
 0x5d2730 GetKeyboardState
 0x5d2734 GetKeyboardLayoutList
 0x5d2738 GetKeyboardLayout
 0x5d273c GetKeyState
 0x5d2740 GetKeyNameTextA
 0x5d2744 GetIconInfo
 0x5d2748 GetForegroundWindow
 0x5d274c GetFocus
 0x5d2750 GetDoubleClickTime
 0x5d2754 GetDlgItem
 0x5d2758 GetDlgCtrlID
 0x5d275c GetDesktopWindow
 0x5d2760 GetDCEx
 0x5d2764 GetDC
 0x5d2768 GetCursorPos
 0x5d276c GetCursor
 0x5d2770 GetClipboardData
 0x5d2774 GetClientRect
 0x5d2778 GetClassNameA
 0x5d277c GetClassInfoA
 0x5d2780 GetCaretPos
 0x5d2784 GetCapture
 0x5d2788 GetActiveWindow
 0x5d278c FrameRect
 0x5d2790 FindWindowExA
 0x5d2794 FindWindowA
 0x5d2798 FillRect
 0x5d279c EqualRect
 0x5d27a0 EnumWindows
 0x5d27a4 EnumThreadWindows
 0x5d27a8 EnumClipboardFormats
 0x5d27ac EndPaint
 0x5d27b0 EnableWindow
 0x5d27b4 EnableScrollBar
 0x5d27b8 EnableMenuItem
 0x5d27bc EmptyClipboard
 0x5d27c0 DrawTextExA
 0x5d27c4 DrawTextW
 0x5d27c8 DrawTextA
 0x5d27cc DrawMenuBar
 0x5d27d0 DrawIconEx
 0x5d27d4 DrawIcon
 0x5d27d8 DrawFrameControl
 0x5d27dc DrawFocusRect
 0x5d27e0 DrawEdge
 0x5d27e4 DispatchMessageA
 0x5d27e8 DestroyWindow
 0x5d27ec DestroyMenu
 0x5d27f0 DestroyIcon
 0x5d27f4 DestroyCursor
 0x5d27f8 DestroyCaret
 0x5d27fc DeleteMenu
 0x5d2800 DefWindowProcA
 0x5d2804 DefMDIChildProcA
 0x5d2808 DefFrameProcA
 0x5d280c CreatePopupMenu
 0x5d2810 CreateMenu
 0x5d2814 CreateIcon
 0x5d2818 CreateCaret
 0x5d281c CopyImage
 0x5d2820 CloseClipboard
 0x5d2824 ClientToScreen
 0x5d2828 CheckMenuItem
 0x5d282c CallWindowProcA
 0x5d2830 CallNextHookEx
 0x5d2834 BeginPaint
 0x5d2838 CharNextA
 0x5d283c CharLowerBuffA
 0x5d2840 CharLowerA
 0x5d2844 CharUpperBuffA
 0x5d2848 CharToOemA
 0x5d284c AdjustWindowRectEx
 0x5d2850 ActivateKeyboardLayout
ole32.dll
 0x5d2858 CoTaskMemFree
 0x5d285c StringFromCLSID
kernel32.dll
 0x5d2864 Sleep
oleaut32.dll
 0x5d286c SafeArrayPtrOfIndex
 0x5d2870 SafeArrayPutElement
 0x5d2874 SafeArrayGetElement
 0x5d2878 SafeArrayUnaccessData
 0x5d287c SafeArrayAccessData
 0x5d2880 SafeArrayGetUBound
 0x5d2884 SafeArrayGetLBound
 0x5d2888 SafeArrayRedim
 0x5d288c SafeArrayCreate
 0x5d2890 VariantChangeType
 0x5d2894 VariantCopyInd
 0x5d2898 VariantCopy
 0x5d289c VariantClear
 0x5d28a0 VariantInit
ole32.dll
 0x5d28a8 CoTaskMemFree
 0x5d28ac ProgIDFromCLSID
 0x5d28b0 StringFromCLSID
 0x5d28b4 CoCreateInstance
 0x5d28b8 CoGetMalloc
 0x5d28bc CoUninitialize
 0x5d28c0 CoInitialize
 0x5d28c4 IsEqualGUID
oleaut32.dll
 0x5d28cc CreateErrorInfo
 0x5d28d0 GetErrorInfo
 0x5d28d4 SetErrorInfo
 0x5d28d8 GetActiveObject
 0x5d28dc SafeArrayCopy
 0x5d28e0 SafeArrayUnaccessData
 0x5d28e4 SafeArrayAccessData
 0x5d28e8 SafeArrayGetUBound
 0x5d28ec SafeArrayDestroy
 0x5d28f0 SafeArrayCreate
 0x5d28f4 SysFreeString
comctl32.dll
 0x5d28fc ImageList_SetIconSize
 0x5d2900 ImageList_GetIconSize
 0x5d2904 ImageList_Write
 0x5d2908 ImageList_Read
 0x5d290c ImageList_GetDragImage
 0x5d2910 ImageList_DragShowNolock
 0x5d2914 ImageList_SetDragCursorImage
 0x5d2918 ImageList_DragMove
 0x5d291c ImageList_DragLeave
 0x5d2920 ImageList_DragEnter
 0x5d2924 ImageList_EndDrag
 0x5d2928 ImageList_BeginDrag
 0x5d292c ImageList_LoadImageA
 0x5d2930 ImageList_Remove
 0x5d2934 ImageList_DrawEx
 0x5d2938 ImageList_Replace
 0x5d293c ImageList_Draw
 0x5d2940 ImageList_GetBkColor
 0x5d2944 ImageList_SetBkColor
 0x5d2948 ImageList_ReplaceIcon
 0x5d294c ImageList_Add
 0x5d2950 ImageList_GetImageCount
 0x5d2954 ImageList_Destroy
 0x5d2958 ImageList_Create
 0x5d295c InitCommonControls
comdlg32.dll
 0x5d2964 GetSaveFileNameA
 0x5d2968 GetOpenFileNameA
kernel32.dll
 0x5d2970 MulDiv
kernel32.dll
 0x5d2978 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure