Report - POS_C028.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.20 09:30 Machine s1_win7_x6401
Filename POS_C028.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : clean
VT API (file) 8 detected (AIDetectMalware, GenericKD, ai score=80)
md5 8b2ae18d721ae95719598ca0369e94af
sha256 f69a66d1b8e3539d47ccfab3d1d5e391e0ae33b05a40229755a7b03012bf9eba
ssdeep 49152:Arymwfg47jww06anvPD6AFjjdjjA/YiY0Y0Y0Y0YI:ArqY4XaD6AFjjdjjA/YiY0Y0Y0Y0YI
imphash c4248c9c368dfb6cac01d697fd8da93a
impfuzzy 192:f3ugG1Glc0FGbuuEjSUvK9ugoaqlBtc7sPbOQadx:f3S1qAEo9YRnPbOQ4
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 8 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x56f168 DeleteCriticalSection
 0x56f16c LeaveCriticalSection
 0x56f170 EnterCriticalSection
 0x56f174 InitializeCriticalSection
 0x56f178 VirtualFree
 0x56f17c VirtualAlloc
 0x56f180 LocalFree
 0x56f184 LocalAlloc
 0x56f188 GetVersion
 0x56f18c GetCurrentThreadId
 0x56f190 InterlockedDecrement
 0x56f194 InterlockedIncrement
 0x56f198 VirtualQuery
 0x56f19c WideCharToMultiByte
 0x56f1a0 MultiByteToWideChar
 0x56f1a4 lstrlenA
 0x56f1a8 lstrcpynA
 0x56f1ac LoadLibraryExA
 0x56f1b0 GetThreadLocale
 0x56f1b4 GetStartupInfoA
 0x56f1b8 GetProcAddress
 0x56f1bc GetModuleHandleA
 0x56f1c0 GetModuleFileNameA
 0x56f1c4 GetLocaleInfoA
 0x56f1c8 GetCommandLineA
 0x56f1cc FreeLibrary
 0x56f1d0 FindFirstFileA
 0x56f1d4 FindClose
 0x56f1d8 ExitProcess
 0x56f1dc ExitThread
 0x56f1e0 CreateThread
 0x56f1e4 WriteFile
 0x56f1e8 UnhandledExceptionFilter
 0x56f1ec RtlUnwind
 0x56f1f0 RaiseException
 0x56f1f4 GetStdHandle
user32.dll
 0x56f1fc GetKeyboardType
 0x56f200 LoadStringA
 0x56f204 MessageBoxA
 0x56f208 CharNextA
advapi32.dll
 0x56f210 RegQueryValueExA
 0x56f214 RegOpenKeyExA
 0x56f218 RegCloseKey
oleaut32.dll
 0x56f220 SysFreeString
 0x56f224 SysReAllocStringLen
 0x56f228 SysAllocStringLen
kernel32.dll
 0x56f230 TlsSetValue
 0x56f234 TlsGetValue
 0x56f238 LocalAlloc
 0x56f23c GetModuleHandleA
advapi32.dll
 0x56f244 RegQueryValueExA
 0x56f248 RegQueryValueA
 0x56f24c RegOpenKeyExA
 0x56f250 RegCloseKey
kernel32.dll
 0x56f258 lstrcpyA
 0x56f25c WriteFile
 0x56f260 WaitForSingleObject
 0x56f264 VirtualQuery
 0x56f268 VirtualAlloc
 0x56f26c Sleep
 0x56f270 SizeofResource
 0x56f274 SetThreadLocale
 0x56f278 SetFilePointer
 0x56f27c SetEvent
 0x56f280 SetErrorMode
 0x56f284 SetEndOfFile
 0x56f288 ResumeThread
 0x56f28c ResetEvent
 0x56f290 ReadFile
 0x56f294 MultiByteToWideChar
 0x56f298 MulDiv
 0x56f29c LockResource
 0x56f2a0 LoadResource
 0x56f2a4 LoadLibraryA
 0x56f2a8 LeaveCriticalSection
 0x56f2ac IsBadReadPtr
 0x56f2b0 InitializeCriticalSection
 0x56f2b4 GlobalUnlock
 0x56f2b8 GlobalSize
 0x56f2bc GlobalReAlloc
 0x56f2c0 GlobalHandle
 0x56f2c4 GlobalLock
 0x56f2c8 GlobalFree
 0x56f2cc GlobalFindAtomA
 0x56f2d0 GlobalDeleteAtom
 0x56f2d4 GlobalAlloc
 0x56f2d8 GlobalAddAtomA
 0x56f2dc GetVersionExA
 0x56f2e0 GetVersion
 0x56f2e4 GetTimeZoneInformation
 0x56f2e8 GetTickCount
 0x56f2ec GetThreadLocale
 0x56f2f0 GetTempPathA
 0x56f2f4 GetSystemInfo
 0x56f2f8 GetStringTypeExA
 0x56f2fc GetStdHandle
 0x56f300 GetProcAddress
 0x56f304 GetModuleHandleA
 0x56f308 GetModuleFileNameA
 0x56f30c GetLocaleInfoA
 0x56f310 GetLocalTime
 0x56f314 GetLastError
 0x56f318 GetFullPathNameA
 0x56f31c GetFileSize
 0x56f320 GetExitCodeThread
 0x56f324 GetDiskFreeSpaceA
 0x56f328 GetDateFormatA
 0x56f32c GetCurrentThreadId
 0x56f330 GetCurrentProcessId
 0x56f334 GetCPInfo
 0x56f338 GetACP
 0x56f33c FreeResource
 0x56f340 InterlockedIncrement
 0x56f344 InterlockedExchange
 0x56f348 InterlockedDecrement
 0x56f34c FreeLibrary
 0x56f350 FormatMessageA
 0x56f354 FindResourceA
 0x56f358 FindFirstFileA
 0x56f35c FindClose
 0x56f360 FileTimeToLocalFileTime
 0x56f364 FileTimeToDosDateTime
 0x56f368 EnumCalendarInfoA
 0x56f36c EnterCriticalSection
 0x56f370 DeleteCriticalSection
 0x56f374 CreateThread
 0x56f378 CreateMutexA
 0x56f37c CreateFileA
 0x56f380 CreateEventA
 0x56f384 CompareStringA
 0x56f388 CloseHandle
version.dll
 0x56f390 VerQueryValueA
 0x56f394 GetFileVersionInfoSizeA
 0x56f398 GetFileVersionInfoA
gdi32.dll
 0x56f3a0 UnrealizeObject
 0x56f3a4 StretchBlt
 0x56f3a8 SetWindowOrgEx
 0x56f3ac SetWindowExtEx
 0x56f3b0 SetWinMetaFileBits
 0x56f3b4 SetViewportOrgEx
 0x56f3b8 SetViewportExtEx
 0x56f3bc SetTextColor
 0x56f3c0 SetStretchBltMode
 0x56f3c4 SetROP2
 0x56f3c8 SetPixel
 0x56f3cc SetMapMode
 0x56f3d0 SetEnhMetaFileBits
 0x56f3d4 SetDIBColorTable
 0x56f3d8 SetBrushOrgEx
 0x56f3dc SetBkMode
 0x56f3e0 SetBkColor
 0x56f3e4 SelectPalette
 0x56f3e8 SelectObject
 0x56f3ec SelectClipRgn
 0x56f3f0 SaveDC
 0x56f3f4 RoundRect
 0x56f3f8 RestoreDC
 0x56f3fc Rectangle
 0x56f400 RectVisible
 0x56f404 RealizePalette
 0x56f408 Polyline
 0x56f40c Polygon
 0x56f410 PolyPolyline
 0x56f414 PlayEnhMetaFile
 0x56f418 PatBlt
 0x56f41c MoveToEx
 0x56f420 MaskBlt
 0x56f424 LineTo
 0x56f428 LPtoDP
 0x56f42c IntersectClipRect
 0x56f430 GetWindowOrgEx
 0x56f434 GetWinMetaFileBits
 0x56f438 GetViewportOrgEx
 0x56f43c GetTextMetricsA
 0x56f440 GetTextExtentPointA
 0x56f444 GetTextExtentPoint32A
 0x56f448 GetSystemPaletteEntries
 0x56f44c GetStockObject
 0x56f450 GetPixel
 0x56f454 GetPaletteEntries
 0x56f458 GetOutlineTextMetricsA
 0x56f45c GetObjectA
 0x56f460 GetNearestColor
 0x56f464 GetEnhMetaFilePaletteEntries
 0x56f468 GetEnhMetaFileHeader
 0x56f46c GetEnhMetaFileBits
 0x56f470 GetDeviceCaps
 0x56f474 GetDIBits
 0x56f478 GetDIBColorTable
 0x56f47c GetDCOrgEx
 0x56f480 GetCurrentPositionEx
 0x56f484 GetCurrentObject
 0x56f488 GetClipRgn
 0x56f48c GetClipBox
 0x56f490 GetBrushOrgEx
 0x56f494 GetBitmapBits
 0x56f498 GdiFlush
 0x56f49c ExtTextOutA
 0x56f4a0 ExtSelectClipRgn
 0x56f4a4 ExtCreateRegion
 0x56f4a8 ExtCreatePen
 0x56f4ac ExcludeClipRect
 0x56f4b0 Ellipse
 0x56f4b4 DeleteObject
 0x56f4b8 DeleteEnhMetaFile
 0x56f4bc DeleteDC
 0x56f4c0 CreateSolidBrush
 0x56f4c4 CreateRectRgn
 0x56f4c8 CreatePolygonRgn
 0x56f4cc CreatePenIndirect
 0x56f4d0 CreatePen
 0x56f4d4 CreatePalette
 0x56f4d8 CreateHalftonePalette
 0x56f4dc CreateFontIndirectA
 0x56f4e0 CreateDIBitmap
 0x56f4e4 CreateDIBSection
 0x56f4e8 CreateCompatibleDC
 0x56f4ec CreateCompatibleBitmap
 0x56f4f0 CreateBrushIndirect
 0x56f4f4 CreateBitmap
 0x56f4f8 CopyEnhMetaFileA
 0x56f4fc CombineRgn
 0x56f500 BitBlt
user32.dll
 0x56f508 CreateWindowExA
 0x56f50c WindowFromPoint
 0x56f510 WinHelpA
 0x56f514 WaitMessage
 0x56f518 ValidateRect
 0x56f51c UpdateWindow
 0x56f520 UnregisterClassA
 0x56f524 UnhookWindowsHookEx
 0x56f528 TranslateMessage
 0x56f52c TranslateMDISysAccel
 0x56f530 TrackPopupMenu
 0x56f534 SystemParametersInfoA
 0x56f538 ShowWindow
 0x56f53c ShowScrollBar
 0x56f540 ShowOwnedPopups
 0x56f544 ShowCursor
 0x56f548 ShowCaret
 0x56f54c SetWindowRgn
 0x56f550 SetWindowsHookExA
 0x56f554 SetWindowTextA
 0x56f558 SetWindowPos
 0x56f55c SetWindowPlacement
 0x56f560 SetWindowLongW
 0x56f564 SetWindowLongA
 0x56f568 SetTimer
 0x56f56c SetScrollRange
 0x56f570 SetScrollPos
 0x56f574 SetScrollInfo
 0x56f578 SetRect
 0x56f57c SetPropA
 0x56f580 SetParent
 0x56f584 SetMenuItemInfoA
 0x56f588 SetMenu
 0x56f58c SetKeyboardState
 0x56f590 SetForegroundWindow
 0x56f594 SetFocus
 0x56f598 SetCursor
 0x56f59c SetClipboardData
 0x56f5a0 SetClassLongA
 0x56f5a4 SetCapture
 0x56f5a8 SetActiveWindow
 0x56f5ac SendMessageA
 0x56f5b0 ScrollWindowEx
 0x56f5b4 ScrollWindow
 0x56f5b8 ScreenToClient
 0x56f5bc RemovePropA
 0x56f5c0 RemoveMenu
 0x56f5c4 ReleaseDC
 0x56f5c8 ReleaseCapture
 0x56f5cc RegisterWindowMessageA
 0x56f5d0 RegisterClipboardFormatA
 0x56f5d4 RegisterClassA
 0x56f5d8 RedrawWindow
 0x56f5dc PtInRect
 0x56f5e0 PostQuitMessage
 0x56f5e4 PostMessageA
 0x56f5e8 PeekMessageA
 0x56f5ec OpenClipboard
 0x56f5f0 OffsetRect
 0x56f5f4 OemToCharA
 0x56f5f8 MsgWaitForMultipleObjects
 0x56f5fc MoveWindow
 0x56f600 MessageBoxA
 0x56f604 MessageBeep
 0x56f608 MapWindowPoints
 0x56f60c MapVirtualKeyA
 0x56f610 LoadStringA
 0x56f614 LoadKeyboardLayoutA
 0x56f618 LoadIconA
 0x56f61c LoadCursorA
 0x56f620 LoadBitmapA
 0x56f624 KillTimer
 0x56f628 IsZoomed
 0x56f62c IsWindowVisible
 0x56f630 IsWindowUnicode
 0x56f634 IsWindowEnabled
 0x56f638 IsWindow
 0x56f63c IsRectEmpty
 0x56f640 IsIconic
 0x56f644 IsDialogMessageA
 0x56f648 IsClipboardFormatAvailable
 0x56f64c IsChild
 0x56f650 IsCharAlphaNumericA
 0x56f654 IsCharAlphaA
 0x56f658 InvalidateRect
 0x56f65c IntersectRect
 0x56f660 InsertMenuItemA
 0x56f664 InsertMenuA
 0x56f668 InflateRect
 0x56f66c HideCaret
 0x56f670 GetWindowThreadProcessId
 0x56f674 GetWindowTextLengthW
 0x56f678 GetWindowTextW
 0x56f67c GetWindowTextA
 0x56f680 GetWindowRect
 0x56f684 GetWindowPlacement
 0x56f688 GetWindowLongW
 0x56f68c GetWindowLongA
 0x56f690 GetWindowDC
 0x56f694 GetTopWindow
 0x56f698 GetSystemMetrics
 0x56f69c GetSystemMenu
 0x56f6a0 GetSysColorBrush
 0x56f6a4 GetSysColor
 0x56f6a8 GetSubMenu
 0x56f6ac GetScrollRange
 0x56f6b0 GetScrollPos
 0x56f6b4 GetScrollInfo
 0x56f6b8 GetPropA
 0x56f6bc GetParent
 0x56f6c0 GetWindow
 0x56f6c4 GetMessageTime
 0x56f6c8 GetMenuStringA
 0x56f6cc GetMenuState
 0x56f6d0 GetMenuItemInfoA
 0x56f6d4 GetMenuItemID
 0x56f6d8 GetMenuItemCount
 0x56f6dc GetMenu
 0x56f6e0 GetLastActivePopup
 0x56f6e4 GetKeyboardState
 0x56f6e8 GetKeyboardLayoutList
 0x56f6ec GetKeyboardLayout
 0x56f6f0 GetKeyState
 0x56f6f4 GetKeyNameTextA
 0x56f6f8 GetIconInfo
 0x56f6fc GetForegroundWindow
 0x56f700 GetFocus
 0x56f704 GetDoubleClickTime
 0x56f708 GetDlgCtrlID
 0x56f70c GetDesktopWindow
 0x56f710 GetDCEx
 0x56f714 GetDC
 0x56f718 GetCursorPos
 0x56f71c GetCursor
 0x56f720 GetClipboardData
 0x56f724 GetClientRect
 0x56f728 GetClassNameA
 0x56f72c GetClassInfoA
 0x56f730 GetCaretPos
 0x56f734 GetCapture
 0x56f738 GetActiveWindow
 0x56f73c FrameRect
 0x56f740 FindWindowExA
 0x56f744 FindWindowA
 0x56f748 FillRect
 0x56f74c EqualRect
 0x56f750 EnumWindows
 0x56f754 EnumThreadWindows
 0x56f758 EnumClipboardFormats
 0x56f75c EndPaint
 0x56f760 EnableWindow
 0x56f764 EnableScrollBar
 0x56f768 EnableMenuItem
 0x56f76c EmptyClipboard
 0x56f770 DrawTextExA
 0x56f774 DrawTextW
 0x56f778 DrawTextA
 0x56f77c DrawMenuBar
 0x56f780 DrawIconEx
 0x56f784 DrawIcon
 0x56f788 DrawFrameControl
 0x56f78c DrawFocusRect
 0x56f790 DrawEdge
 0x56f794 DispatchMessageA
 0x56f798 DestroyWindow
 0x56f79c DestroyMenu
 0x56f7a0 DestroyIcon
 0x56f7a4 DestroyCursor
 0x56f7a8 DeleteMenu
 0x56f7ac DefWindowProcA
 0x56f7b0 DefMDIChildProcA
 0x56f7b4 DefFrameProcA
 0x56f7b8 CreatePopupMenu
 0x56f7bc CreateMenu
 0x56f7c0 CreateIcon
 0x56f7c4 CopyImage
 0x56f7c8 CloseClipboard
 0x56f7cc ClientToScreen
 0x56f7d0 CheckMenuItem
 0x56f7d4 CallWindowProcA
 0x56f7d8 CallNextHookEx
 0x56f7dc BeginPaint
 0x56f7e0 CharNextA
 0x56f7e4 CharLowerBuffA
 0x56f7e8 CharLowerA
 0x56f7ec CharUpperBuffA
 0x56f7f0 CharToOemA
 0x56f7f4 AdjustWindowRectEx
 0x56f7f8 ActivateKeyboardLayout
ole32.dll
 0x56f800 CoTaskMemFree
 0x56f804 StringFromCLSID
kernel32.dll
 0x56f80c Sleep
oleaut32.dll
 0x56f814 SafeArrayPtrOfIndex
 0x56f818 SafeArrayPutElement
 0x56f81c SafeArrayGetElement
 0x56f820 SafeArrayUnaccessData
 0x56f824 SafeArrayAccessData
 0x56f828 SafeArrayGetUBound
 0x56f82c SafeArrayGetLBound
 0x56f830 SafeArrayRedim
 0x56f834 SafeArrayCreate
 0x56f838 VariantChangeType
 0x56f83c VariantCopyInd
 0x56f840 VariantCopy
 0x56f844 VariantClear
 0x56f848 VariantInit
ole32.dll
 0x56f850 CoCreateInstance
 0x56f854 CoGetMalloc
 0x56f858 CoUninitialize
 0x56f85c CoInitialize
 0x56f860 IsEqualGUID
oleaut32.dll
 0x56f868 CreateErrorInfo
 0x56f86c GetErrorInfo
 0x56f870 SetErrorInfo
 0x56f874 SafeArrayCopy
 0x56f878 SafeArrayUnaccessData
 0x56f87c SafeArrayAccessData
 0x56f880 SafeArrayGetUBound
 0x56f884 SafeArrayDestroy
 0x56f888 SafeArrayCreate
 0x56f88c SysFreeString
comctl32.dll
 0x56f894 ImageList_SetIconSize
 0x56f898 ImageList_GetIconSize
 0x56f89c ImageList_Write
 0x56f8a0 ImageList_Read
 0x56f8a4 ImageList_GetDragImage
 0x56f8a8 ImageList_DragShowNolock
 0x56f8ac ImageList_SetDragCursorImage
 0x56f8b0 ImageList_DragMove
 0x56f8b4 ImageList_DragLeave
 0x56f8b8 ImageList_DragEnter
 0x56f8bc ImageList_EndDrag
 0x56f8c0 ImageList_BeginDrag
 0x56f8c4 ImageList_LoadImageA
 0x56f8c8 ImageList_Remove
 0x56f8cc ImageList_DrawEx
 0x56f8d0 ImageList_Replace
 0x56f8d4 ImageList_Draw
 0x56f8d8 ImageList_GetBkColor
 0x56f8dc ImageList_SetBkColor
 0x56f8e0 ImageList_ReplaceIcon
 0x56f8e4 ImageList_Add
 0x56f8e8 ImageList_GetImageCount
 0x56f8ec ImageList_Destroy
 0x56f8f0 ImageList_Create
 0x56f8f4 InitCommonControls
kernel32.dll
 0x56f8fc MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure