Report - POS_C020.exe

Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.20 09:28 Machine s1_win7_x6401
Filename POS_C020.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : clean
VT API (file) 8 detected (GenericKD, ai score=85)
md5 404d481d35148c5a12e60cba83d6d034
sha256 0989b5a5ea777939499176af0c5d74dd19d8019314ef503f9d14c397a058e29f
ssdeep 49152:EZGA7Xdks5RdBrTKhPDCAFjjdjjA/YiY0Y0Y0Y0YI:E4A7txHdB/sCAFjjdjjA/YiY0Y0Y0Y01
imphash db46137b9231666f484445851ac033ef
impfuzzy 192:f3zuG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQhd9:f3H1q/Ez9YPpPbOQ1
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 8 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5d4190 DeleteCriticalSection
 0x5d4194 LeaveCriticalSection
 0x5d4198 EnterCriticalSection
 0x5d419c InitializeCriticalSection
 0x5d41a0 VirtualFree
 0x5d41a4 VirtualAlloc
 0x5d41a8 LocalFree
 0x5d41ac LocalAlloc
 0x5d41b0 GetVersion
 0x5d41b4 GetCurrentThreadId
 0x5d41b8 InterlockedDecrement
 0x5d41bc InterlockedIncrement
 0x5d41c0 VirtualQuery
 0x5d41c4 WideCharToMultiByte
 0x5d41c8 MultiByteToWideChar
 0x5d41cc lstrlenA
 0x5d41d0 lstrcpynA
 0x5d41d4 LoadLibraryExA
 0x5d41d8 GetThreadLocale
 0x5d41dc GetStartupInfoA
 0x5d41e0 GetProcAddress
 0x5d41e4 GetModuleHandleA
 0x5d41e8 GetModuleFileNameA
 0x5d41ec GetLocaleInfoA
 0x5d41f0 GetCommandLineA
 0x5d41f4 FreeLibrary
 0x5d41f8 FindFirstFileA
 0x5d41fc FindClose
 0x5d4200 ExitProcess
 0x5d4204 ExitThread
 0x5d4208 CreateThread
 0x5d420c WriteFile
 0x5d4210 UnhandledExceptionFilter
 0x5d4214 RtlUnwind
 0x5d4218 RaiseException
 0x5d421c GetStdHandle
user32.dll
 0x5d4224 GetKeyboardType
 0x5d4228 LoadStringA
 0x5d422c MessageBoxA
 0x5d4230 CharNextA
advapi32.dll
 0x5d4238 RegQueryValueExA
 0x5d423c RegOpenKeyExA
 0x5d4240 RegCloseKey
oleaut32.dll
 0x5d4248 SysFreeString
 0x5d424c SysReAllocStringLen
 0x5d4250 SysAllocStringLen
kernel32.dll
 0x5d4258 TlsSetValue
 0x5d425c TlsGetValue
 0x5d4260 LocalAlloc
 0x5d4264 GetModuleHandleA
advapi32.dll
 0x5d426c RegSetValueExA
 0x5d4270 RegQueryValueExA
 0x5d4274 RegQueryValueA
 0x5d4278 RegOpenKeyExA
 0x5d427c RegFlushKey
 0x5d4280 RegCreateKeyExA
 0x5d4284 RegCloseKey
kernel32.dll
 0x5d428c lstrcpyA
 0x5d4290 WriteFile
 0x5d4294 WaitForSingleObject
 0x5d4298 VirtualQuery
 0x5d429c VirtualAlloc
 0x5d42a0 Sleep
 0x5d42a4 SizeofResource
 0x5d42a8 SetThreadLocale
 0x5d42ac SetFilePointer
 0x5d42b0 SetEvent
 0x5d42b4 SetErrorMode
 0x5d42b8 SetEndOfFile
 0x5d42bc ResumeThread
 0x5d42c0 ResetEvent
 0x5d42c4 ReleaseMutex
 0x5d42c8 ReadFile
 0x5d42cc MultiByteToWideChar
 0x5d42d0 MulDiv
 0x5d42d4 LockResource
 0x5d42d8 LoadResource
 0x5d42dc LoadLibraryA
 0x5d42e0 LeaveCriticalSection
 0x5d42e4 IsBadReadPtr
 0x5d42e8 InitializeCriticalSection
 0x5d42ec GlobalUnlock
 0x5d42f0 GlobalSize
 0x5d42f4 GlobalReAlloc
 0x5d42f8 GlobalHandle
 0x5d42fc GlobalLock
 0x5d4300 GlobalFree
 0x5d4304 GlobalFindAtomA
 0x5d4308 GlobalDeleteAtom
 0x5d430c GlobalAlloc
 0x5d4310 GlobalAddAtomA
 0x5d4314 GetVersionExA
 0x5d4318 GetVersion
 0x5d431c GetTimeZoneInformation
 0x5d4320 GetTickCount
 0x5d4324 GetThreadLocale
 0x5d4328 GetTempPathA
 0x5d432c GetSystemInfo
 0x5d4330 GetStringTypeExA
 0x5d4334 GetStdHandle
 0x5d4338 GetProcAddress
 0x5d433c GetModuleHandleA
 0x5d4340 GetModuleFileNameA
 0x5d4344 GetLocaleInfoA
 0x5d4348 GetLocalTime
 0x5d434c GetLastError
 0x5d4350 GetFullPathNameA
 0x5d4354 GetFileSize
 0x5d4358 GetExitCodeThread
 0x5d435c GetDiskFreeSpaceA
 0x5d4360 GetDateFormatA
 0x5d4364 GetCurrentThreadId
 0x5d4368 GetCurrentProcessId
 0x5d436c GetCPInfo
 0x5d4370 GetACP
 0x5d4374 FreeResource
 0x5d4378 InterlockedIncrement
 0x5d437c InterlockedExchange
 0x5d4380 InterlockedDecrement
 0x5d4384 FreeLibrary
 0x5d4388 FormatMessageA
 0x5d438c FindResourceA
 0x5d4390 FindFirstFileA
 0x5d4394 FindClose
 0x5d4398 FileTimeToLocalFileTime
 0x5d439c FileTimeToDosDateTime
 0x5d43a0 EnumCalendarInfoA
 0x5d43a4 EnterCriticalSection
 0x5d43a8 DeleteCriticalSection
 0x5d43ac CreateThread
 0x5d43b0 CreateMutexA
 0x5d43b4 CreateFileA
 0x5d43b8 CreateEventA
 0x5d43bc CompareStringA
 0x5d43c0 CloseHandle
version.dll
 0x5d43c8 VerQueryValueA
 0x5d43cc GetFileVersionInfoSizeA
 0x5d43d0 GetFileVersionInfoA
gdi32.dll
 0x5d43d8 UnrealizeObject
 0x5d43dc StretchBlt
 0x5d43e0 SetWindowOrgEx
 0x5d43e4 SetWindowExtEx
 0x5d43e8 SetWinMetaFileBits
 0x5d43ec SetViewportOrgEx
 0x5d43f0 SetViewportExtEx
 0x5d43f4 SetTextColor
 0x5d43f8 SetStretchBltMode
 0x5d43fc SetROP2
 0x5d4400 SetPixel
 0x5d4404 SetMapMode
 0x5d4408 SetEnhMetaFileBits
 0x5d440c SetDIBColorTable
 0x5d4410 SetBrushOrgEx
 0x5d4414 SetBkMode
 0x5d4418 SetBkColor
 0x5d441c SelectPalette
 0x5d4420 SelectObject
 0x5d4424 SelectClipRgn
 0x5d4428 SaveDC
 0x5d442c RoundRect
 0x5d4430 RestoreDC
 0x5d4434 Rectangle
 0x5d4438 RectVisible
 0x5d443c RealizePalette
 0x5d4440 Polyline
 0x5d4444 Polygon
 0x5d4448 PolyPolyline
 0x5d444c PlayEnhMetaFile
 0x5d4450 PatBlt
 0x5d4454 MoveToEx
 0x5d4458 MaskBlt
 0x5d445c LineTo
 0x5d4460 LPtoDP
 0x5d4464 IntersectClipRect
 0x5d4468 GetWindowOrgEx
 0x5d446c GetWinMetaFileBits
 0x5d4470 GetViewportOrgEx
 0x5d4474 GetTextMetricsA
 0x5d4478 GetTextExtentPointA
 0x5d447c GetTextExtentPoint32A
 0x5d4480 GetSystemPaletteEntries
 0x5d4484 GetStockObject
 0x5d4488 GetPixel
 0x5d448c GetPaletteEntries
 0x5d4490 GetOutlineTextMetricsA
 0x5d4494 GetObjectA
 0x5d4498 GetNearestColor
 0x5d449c GetEnhMetaFilePaletteEntries
 0x5d44a0 GetEnhMetaFileHeader
 0x5d44a4 GetEnhMetaFileBits
 0x5d44a8 GetDeviceCaps
 0x5d44ac GetDIBits
 0x5d44b0 GetDIBColorTable
 0x5d44b4 GetDCOrgEx
 0x5d44b8 GetCurrentPositionEx
 0x5d44bc GetCurrentObject
 0x5d44c0 GetClipRgn
 0x5d44c4 GetClipBox
 0x5d44c8 GetBrushOrgEx
 0x5d44cc GetBitmapBits
 0x5d44d0 GdiFlush
 0x5d44d4 ExtTextOutA
 0x5d44d8 ExtSelectClipRgn
 0x5d44dc ExtCreateRegion
 0x5d44e0 ExtCreatePen
 0x5d44e4 ExcludeClipRect
 0x5d44e8 Ellipse
 0x5d44ec DeleteObject
 0x5d44f0 DeleteEnhMetaFile
 0x5d44f4 DeleteDC
 0x5d44f8 CreateSolidBrush
 0x5d44fc CreateRectRgn
 0x5d4500 CreatePolygonRgn
 0x5d4504 CreatePenIndirect
 0x5d4508 CreatePen
 0x5d450c CreatePalette
 0x5d4510 CreateHalftonePalette
 0x5d4514 CreateFontIndirectA
 0x5d4518 CreateDIBitmap
 0x5d451c CreateDIBSection
 0x5d4520 CreateCompatibleDC
 0x5d4524 CreateCompatibleBitmap
 0x5d4528 CreateBrushIndirect
 0x5d452c CreateBitmap
 0x5d4530 CopyEnhMetaFileA
 0x5d4534 CombineRgn
 0x5d4538 BitBlt
user32.dll
 0x5d4540 CreateWindowExA
 0x5d4544 WindowFromPoint
 0x5d4548 WinHelpA
 0x5d454c WaitMessage
 0x5d4550 ValidateRect
 0x5d4554 UpdateWindow
 0x5d4558 UnregisterClassA
 0x5d455c UnionRect
 0x5d4560 UnhookWindowsHookEx
 0x5d4564 TranslateMessage
 0x5d4568 TranslateMDISysAccel
 0x5d456c TrackPopupMenu
 0x5d4570 SystemParametersInfoA
 0x5d4574 ShowWindow
 0x5d4578 ShowScrollBar
 0x5d457c ShowOwnedPopups
 0x5d4580 ShowCursor
 0x5d4584 ShowCaret
 0x5d4588 SetWindowRgn
 0x5d458c SetWindowsHookExA
 0x5d4590 SetWindowTextA
 0x5d4594 SetWindowPos
 0x5d4598 SetWindowPlacement
 0x5d459c SetWindowLongW
 0x5d45a0 SetWindowLongA
 0x5d45a4 SetTimer
 0x5d45a8 SetScrollRange
 0x5d45ac SetScrollPos
 0x5d45b0 SetScrollInfo
 0x5d45b4 SetRect
 0x5d45b8 SetPropA
 0x5d45bc SetParent
 0x5d45c0 SetMenuItemInfoA
 0x5d45c4 SetMenu
 0x5d45c8 SetKeyboardState
 0x5d45cc SetForegroundWindow
 0x5d45d0 SetFocus
 0x5d45d4 SetCursor
 0x5d45d8 SetClipboardData
 0x5d45dc SetClassLongA
 0x5d45e0 SetCaretPos
 0x5d45e4 SetCapture
 0x5d45e8 SetActiveWindow
 0x5d45ec SendMessageA
 0x5d45f0 ScrollWindowEx
 0x5d45f4 ScrollWindow
 0x5d45f8 ScreenToClient
 0x5d45fc RemovePropA
 0x5d4600 RemoveMenu
 0x5d4604 ReleaseDC
 0x5d4608 ReleaseCapture
 0x5d460c RegisterWindowMessageA
 0x5d4610 RegisterClipboardFormatA
 0x5d4614 RegisterClassA
 0x5d4618 RedrawWindow
 0x5d461c PtInRect
 0x5d4620 PostQuitMessage
 0x5d4624 PostMessageA
 0x5d4628 PeekMessageA
 0x5d462c OpenClipboard
 0x5d4630 OffsetRect
 0x5d4634 OemToCharA
 0x5d4638 MsgWaitForMultipleObjects
 0x5d463c MoveWindow
 0x5d4640 MessageBoxA
 0x5d4644 MessageBeep
 0x5d4648 MapWindowPoints
 0x5d464c MapVirtualKeyA
 0x5d4650 LoadStringA
 0x5d4654 LoadKeyboardLayoutA
 0x5d4658 LoadIconA
 0x5d465c LoadCursorA
 0x5d4660 LoadBitmapA
 0x5d4664 KillTimer
 0x5d4668 IsZoomed
 0x5d466c IsWindowVisible
 0x5d4670 IsWindowUnicode
 0x5d4674 IsWindowEnabled
 0x5d4678 IsWindow
 0x5d467c IsRectEmpty
 0x5d4680 IsIconic
 0x5d4684 IsDialogMessageA
 0x5d4688 IsClipboardFormatAvailable
 0x5d468c IsChild
 0x5d4690 IsCharAlphaNumericA
 0x5d4694 IsCharAlphaA
 0x5d4698 InvalidateRect
 0x5d469c IntersectRect
 0x5d46a0 InsertMenuItemA
 0x5d46a4 InsertMenuA
 0x5d46a8 InflateRect
 0x5d46ac HideCaret
 0x5d46b0 GetWindowThreadProcessId
 0x5d46b4 GetWindowTextLengthW
 0x5d46b8 GetWindowTextW
 0x5d46bc GetWindowTextA
 0x5d46c0 GetWindowRect
 0x5d46c4 GetWindowPlacement
 0x5d46c8 GetWindowLongW
 0x5d46cc GetWindowLongA
 0x5d46d0 GetWindowDC
 0x5d46d4 GetTopWindow
 0x5d46d8 GetSystemMetrics
 0x5d46dc GetSystemMenu
 0x5d46e0 GetSysColorBrush
 0x5d46e4 GetSysColor
 0x5d46e8 GetSubMenu
 0x5d46ec GetScrollRange
 0x5d46f0 GetScrollPos
 0x5d46f4 GetScrollInfo
 0x5d46f8 GetPropA
 0x5d46fc GetParent
 0x5d4700 GetWindow
 0x5d4704 GetMessageTime
 0x5d4708 GetMenuStringA
 0x5d470c GetMenuState
 0x5d4710 GetMenuItemInfoA
 0x5d4714 GetMenuItemID
 0x5d4718 GetMenuItemCount
 0x5d471c GetMenu
 0x5d4720 GetLastActivePopup
 0x5d4724 GetKeyboardState
 0x5d4728 GetKeyboardLayoutList
 0x5d472c GetKeyboardLayout
 0x5d4730 GetKeyState
 0x5d4734 GetKeyNameTextA
 0x5d4738 GetIconInfo
 0x5d473c GetForegroundWindow
 0x5d4740 GetFocus
 0x5d4744 GetDoubleClickTime
 0x5d4748 GetDlgItem
 0x5d474c GetDlgCtrlID
 0x5d4750 GetDesktopWindow
 0x5d4754 GetDCEx
 0x5d4758 GetDC
 0x5d475c GetCursorPos
 0x5d4760 GetCursor
 0x5d4764 GetClipboardData
 0x5d4768 GetClientRect
 0x5d476c GetClassNameA
 0x5d4770 GetClassInfoA
 0x5d4774 GetCaretPos
 0x5d4778 GetCapture
 0x5d477c GetActiveWindow
 0x5d4780 FrameRect
 0x5d4784 FindWindowExA
 0x5d4788 FindWindowA
 0x5d478c FillRect
 0x5d4790 EqualRect
 0x5d4794 EnumWindows
 0x5d4798 EnumThreadWindows
 0x5d479c EnumClipboardFormats
 0x5d47a0 EndPaint
 0x5d47a4 EnableWindow
 0x5d47a8 EnableScrollBar
 0x5d47ac EnableMenuItem
 0x5d47b0 EmptyClipboard
 0x5d47b4 DrawTextExA
 0x5d47b8 DrawTextW
 0x5d47bc DrawTextA
 0x5d47c0 DrawMenuBar
 0x5d47c4 DrawIconEx
 0x5d47c8 DrawIcon
 0x5d47cc DrawFrameControl
 0x5d47d0 DrawFocusRect
 0x5d47d4 DrawEdge
 0x5d47d8 DispatchMessageA
 0x5d47dc DestroyWindow
 0x5d47e0 DestroyMenu
 0x5d47e4 DestroyIcon
 0x5d47e8 DestroyCursor
 0x5d47ec DestroyCaret
 0x5d47f0 DeleteMenu
 0x5d47f4 DefWindowProcA
 0x5d47f8 DefMDIChildProcA
 0x5d47fc DefFrameProcA
 0x5d4800 CreatePopupMenu
 0x5d4804 CreateMenu
 0x5d4808 CreateIcon
 0x5d480c CreateCaret
 0x5d4810 CopyImage
 0x5d4814 CloseClipboard
 0x5d4818 ClientToScreen
 0x5d481c CheckMenuItem
 0x5d4820 CallWindowProcA
 0x5d4824 CallNextHookEx
 0x5d4828 BeginPaint
 0x5d482c CharNextA
 0x5d4830 CharLowerBuffA
 0x5d4834 CharLowerA
 0x5d4838 CharUpperBuffA
 0x5d483c CharToOemA
 0x5d4840 AdjustWindowRectEx
 0x5d4844 ActivateKeyboardLayout
ole32.dll
 0x5d484c CoTaskMemFree
 0x5d4850 StringFromCLSID
kernel32.dll
 0x5d4858 Sleep
oleaut32.dll
 0x5d4860 SafeArrayPtrOfIndex
 0x5d4864 SafeArrayPutElement
 0x5d4868 SafeArrayGetElement
 0x5d486c SafeArrayUnaccessData
 0x5d4870 SafeArrayAccessData
 0x5d4874 SafeArrayGetUBound
 0x5d4878 SafeArrayGetLBound
 0x5d487c SafeArrayRedim
 0x5d4880 SafeArrayCreate
 0x5d4884 VariantChangeType
 0x5d4888 VariantCopyInd
 0x5d488c VariantCopy
 0x5d4890 VariantClear
 0x5d4894 VariantInit
ole32.dll
 0x5d489c CLSIDFromProgID
 0x5d48a0 CoCreateInstance
 0x5d48a4 CoGetMalloc
 0x5d48a8 CoUninitialize
 0x5d48ac CoInitialize
 0x5d48b0 IsEqualGUID
oleaut32.dll
 0x5d48b8 CreateErrorInfo
 0x5d48bc GetErrorInfo
 0x5d48c0 SetErrorInfo
 0x5d48c4 SafeArrayCopy
 0x5d48c8 SafeArrayUnaccessData
 0x5d48cc SafeArrayAccessData
 0x5d48d0 SafeArrayGetUBound
 0x5d48d4 SafeArrayDestroy
 0x5d48d8 SafeArrayCreate
 0x5d48dc SysFreeString
comctl32.dll
 0x5d48e4 ImageList_SetIconSize
 0x5d48e8 ImageList_GetIconSize
 0x5d48ec ImageList_Write
 0x5d48f0 ImageList_Read
 0x5d48f4 ImageList_GetDragImage
 0x5d48f8 ImageList_DragShowNolock
 0x5d48fc ImageList_SetDragCursorImage
 0x5d4900 ImageList_DragMove
 0x5d4904 ImageList_DragLeave
 0x5d4908 ImageList_DragEnter
 0x5d490c ImageList_EndDrag
 0x5d4910 ImageList_BeginDrag
 0x5d4914 ImageList_LoadImageA
 0x5d4918 ImageList_Remove
 0x5d491c ImageList_DrawEx
 0x5d4920 ImageList_Replace
 0x5d4924 ImageList_Draw
 0x5d4928 ImageList_GetBkColor
 0x5d492c ImageList_SetBkColor
 0x5d4930 ImageList_ReplaceIcon
 0x5d4934 ImageList_Add
 0x5d4938 ImageList_GetImageCount
 0x5d493c ImageList_Destroy
 0x5d4940 ImageList_Create
 0x5d4944 InitCommonControls
comdlg32.dll
 0x5d494c GetSaveFileNameA
 0x5d4950 GetOpenFileNameA
kernel32.dll
 0x5d4958 MulDiv
kernel32.dll
 0x5d4960 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure