Report - POS_C110.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.20 09:32 Machine s1_win7_x6403
Filename POS_C110.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
2.0
ZERO API file : clean
VT API (file) 10 detected (Fragtor, malicious, ai score=81)
md5 86de5cffa568d6a2392d576fc6535b3b
sha256 0f165fb1adf68683c2a9d89f51d9db0c533bb26c29e6a303af748942f8a1511c
ssdeep 24576:4T2o2ln+HxdLKJgPB90O8sHh4ZGsg+QaC55gM2:4T24H7kO7mGkCDh
imphash b23bcc6be44079051b22d1a35b0798bc
impfuzzy 192:f3uvG1alcDtPbuuNjSUvK9u6oaqSmJo7sPbOQads:f3V1G2No98PLPbOQJ
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x52c168 DeleteCriticalSection
 0x52c16c LeaveCriticalSection
 0x52c170 EnterCriticalSection
 0x52c174 InitializeCriticalSection
 0x52c178 VirtualFree
 0x52c17c VirtualAlloc
 0x52c180 LocalFree
 0x52c184 LocalAlloc
 0x52c188 GetVersion
 0x52c18c GetCurrentThreadId
 0x52c190 InterlockedDecrement
 0x52c194 InterlockedIncrement
 0x52c198 VirtualQuery
 0x52c19c WideCharToMultiByte
 0x52c1a0 MultiByteToWideChar
 0x52c1a4 lstrlenA
 0x52c1a8 lstrcpynA
 0x52c1ac LoadLibraryExA
 0x52c1b0 GetThreadLocale
 0x52c1b4 GetStartupInfoA
 0x52c1b8 GetProcAddress
 0x52c1bc GetModuleHandleA
 0x52c1c0 GetModuleFileNameA
 0x52c1c4 GetLocaleInfoA
 0x52c1c8 GetCommandLineA
 0x52c1cc FreeLibrary
 0x52c1d0 FindFirstFileA
 0x52c1d4 FindClose
 0x52c1d8 ExitProcess
 0x52c1dc ExitThread
 0x52c1e0 CreateThread
 0x52c1e4 WriteFile
 0x52c1e8 UnhandledExceptionFilter
 0x52c1ec RtlUnwind
 0x52c1f0 RaiseException
 0x52c1f4 GetStdHandle
user32.dll
 0x52c1fc GetKeyboardType
 0x52c200 LoadStringA
 0x52c204 MessageBoxA
 0x52c208 CharNextA
advapi32.dll
 0x52c210 RegQueryValueExA
 0x52c214 RegOpenKeyExA
 0x52c218 RegCloseKey
oleaut32.dll
 0x52c220 SysFreeString
 0x52c224 SysReAllocStringLen
 0x52c228 SysAllocStringLen
kernel32.dll
 0x52c230 TlsSetValue
 0x52c234 TlsGetValue
 0x52c238 LocalAlloc
 0x52c23c GetModuleHandleA
advapi32.dll
 0x52c244 RegQueryValueExA
 0x52c248 RegQueryValueA
 0x52c24c RegOpenKeyExA
 0x52c250 RegCloseKey
kernel32.dll
 0x52c258 lstrcpyA
 0x52c25c WriteFile
 0x52c260 WaitForSingleObject
 0x52c264 VirtualQuery
 0x52c268 VirtualAlloc
 0x52c26c Sleep
 0x52c270 SizeofResource
 0x52c274 SetThreadLocale
 0x52c278 SetFilePointer
 0x52c27c SetEvent
 0x52c280 SetErrorMode
 0x52c284 SetEndOfFile
 0x52c288 ResumeThread
 0x52c28c ResetEvent
 0x52c290 ReadFile
 0x52c294 MultiByteToWideChar
 0x52c298 MulDiv
 0x52c29c LockResource
 0x52c2a0 LoadResource
 0x52c2a4 LoadLibraryA
 0x52c2a8 LeaveCriticalSection
 0x52c2ac InitializeCriticalSection
 0x52c2b0 GlobalUnlock
 0x52c2b4 GlobalSize
 0x52c2b8 GlobalReAlloc
 0x52c2bc GlobalHandle
 0x52c2c0 GlobalLock
 0x52c2c4 GlobalFree
 0x52c2c8 GlobalFindAtomA
 0x52c2cc GlobalDeleteAtom
 0x52c2d0 GlobalAlloc
 0x52c2d4 GlobalAddAtomA
 0x52c2d8 GetVersionExA
 0x52c2dc GetVersion
 0x52c2e0 GetTimeZoneInformation
 0x52c2e4 GetTickCount
 0x52c2e8 GetThreadLocale
 0x52c2ec GetTempPathA
 0x52c2f0 GetSystemInfo
 0x52c2f4 GetStringTypeExA
 0x52c2f8 GetStdHandle
 0x52c2fc GetProcAddress
 0x52c300 GetModuleHandleA
 0x52c304 GetModuleFileNameA
 0x52c308 GetLocaleInfoA
 0x52c30c GetLocalTime
 0x52c310 GetLastError
 0x52c314 GetFullPathNameA
 0x52c318 GetFileSize
 0x52c31c GetExitCodeThread
 0x52c320 GetDiskFreeSpaceA
 0x52c324 GetDateFormatA
 0x52c328 GetCurrentThreadId
 0x52c32c GetCurrentProcessId
 0x52c330 GetCPInfo
 0x52c334 GetACP
 0x52c338 FreeResource
 0x52c33c InterlockedIncrement
 0x52c340 InterlockedExchange
 0x52c344 InterlockedDecrement
 0x52c348 FreeLibrary
 0x52c34c FormatMessageA
 0x52c350 FindResourceA
 0x52c354 FindFirstFileA
 0x52c358 FindClose
 0x52c35c FileTimeToLocalFileTime
 0x52c360 FileTimeToDosDateTime
 0x52c364 EnumCalendarInfoA
 0x52c368 EnterCriticalSection
 0x52c36c DeleteCriticalSection
 0x52c370 CreateThread
 0x52c374 CreateFileA
 0x52c378 CreateEventA
 0x52c37c CompareStringA
 0x52c380 CloseHandle
version.dll
 0x52c388 VerQueryValueA
 0x52c38c GetFileVersionInfoSizeA
 0x52c390 GetFileVersionInfoA
gdi32.dll
 0x52c398 UnrealizeObject
 0x52c39c StretchBlt
 0x52c3a0 SetWindowOrgEx
 0x52c3a4 SetWindowExtEx
 0x52c3a8 SetWinMetaFileBits
 0x52c3ac SetViewportOrgEx
 0x52c3b0 SetViewportExtEx
 0x52c3b4 SetTextColor
 0x52c3b8 SetStretchBltMode
 0x52c3bc SetROP2
 0x52c3c0 SetPixel
 0x52c3c4 SetMapMode
 0x52c3c8 SetEnhMetaFileBits
 0x52c3cc SetDIBColorTable
 0x52c3d0 SetBrushOrgEx
 0x52c3d4 SetBkMode
 0x52c3d8 SetBkColor
 0x52c3dc SelectPalette
 0x52c3e0 SelectObject
 0x52c3e4 SelectClipRgn
 0x52c3e8 SaveDC
 0x52c3ec RoundRect
 0x52c3f0 RestoreDC
 0x52c3f4 Rectangle
 0x52c3f8 RectVisible
 0x52c3fc RealizePalette
 0x52c400 Polyline
 0x52c404 PolyPolyline
 0x52c408 PlayEnhMetaFile
 0x52c40c PatBlt
 0x52c410 MoveToEx
 0x52c414 MaskBlt
 0x52c418 LineTo
 0x52c41c LPtoDP
 0x52c420 IntersectClipRect
 0x52c424 GetWindowOrgEx
 0x52c428 GetWinMetaFileBits
 0x52c42c GetTextMetricsA
 0x52c430 GetTextExtentPointA
 0x52c434 GetTextExtentPoint32A
 0x52c438 GetSystemPaletteEntries
 0x52c43c GetStockObject
 0x52c440 GetPixel
 0x52c444 GetPaletteEntries
 0x52c448 GetOutlineTextMetricsA
 0x52c44c GetObjectA
 0x52c450 GetNearestColor
 0x52c454 GetEnhMetaFilePaletteEntries
 0x52c458 GetEnhMetaFileHeader
 0x52c45c GetEnhMetaFileBits
 0x52c460 GetDeviceCaps
 0x52c464 GetDIBits
 0x52c468 GetDIBColorTable
 0x52c46c GetDCOrgEx
 0x52c470 GetCurrentPositionEx
 0x52c474 GetClipRgn
 0x52c478 GetClipBox
 0x52c47c GetBrushOrgEx
 0x52c480 GetBitmapBits
 0x52c484 ExtTextOutA
 0x52c488 ExtSelectClipRgn
 0x52c48c ExtCreatePen
 0x52c490 ExcludeClipRect
 0x52c494 Ellipse
 0x52c498 DeleteObject
 0x52c49c DeleteEnhMetaFile
 0x52c4a0 DeleteDC
 0x52c4a4 CreateSolidBrush
 0x52c4a8 CreateRectRgn
 0x52c4ac CreatePolygonRgn
 0x52c4b0 CreatePenIndirect
 0x52c4b4 CreatePalette
 0x52c4b8 CreateHalftonePalette
 0x52c4bc CreateFontIndirectA
 0x52c4c0 CreateDIBitmap
 0x52c4c4 CreateDIBSection
 0x52c4c8 CreateCompatibleDC
 0x52c4cc CreateCompatibleBitmap
 0x52c4d0 CreateBrushIndirect
 0x52c4d4 CreateBitmap
 0x52c4d8 CopyEnhMetaFileA
 0x52c4dc BitBlt
user32.dll
 0x52c4e4 CreateWindowExA
 0x52c4e8 WindowFromPoint
 0x52c4ec WinHelpA
 0x52c4f0 WaitMessage
 0x52c4f4 ValidateRect
 0x52c4f8 UpdateWindow
 0x52c4fc UnregisterClassA
 0x52c500 UnhookWindowsHookEx
 0x52c504 TranslateMessage
 0x52c508 TranslateMDISysAccel
 0x52c50c TrackPopupMenu
 0x52c510 SystemParametersInfoA
 0x52c514 ShowWindow
 0x52c518 ShowScrollBar
 0x52c51c ShowOwnedPopups
 0x52c520 ShowCursor
 0x52c524 ShowCaret
 0x52c528 SetWindowRgn
 0x52c52c SetWindowsHookExA
 0x52c530 SetWindowTextA
 0x52c534 SetWindowPos
 0x52c538 SetWindowPlacement
 0x52c53c SetWindowLongA
 0x52c540 SetTimer
 0x52c544 SetScrollRange
 0x52c548 SetScrollPos
 0x52c54c SetScrollInfo
 0x52c550 SetRect
 0x52c554 SetPropA
 0x52c558 SetParent
 0x52c55c SetMenuItemInfoA
 0x52c560 SetMenu
 0x52c564 SetKeyboardState
 0x52c568 SetForegroundWindow
 0x52c56c SetFocus
 0x52c570 SetCursor
 0x52c574 SetClipboardData
 0x52c578 SetClassLongA
 0x52c57c SetCapture
 0x52c580 SetActiveWindow
 0x52c584 SendMessageA
 0x52c588 ScrollWindowEx
 0x52c58c ScrollWindow
 0x52c590 ScreenToClient
 0x52c594 RemovePropA
 0x52c598 RemoveMenu
 0x52c59c ReleaseDC
 0x52c5a0 ReleaseCapture
 0x52c5a4 RegisterWindowMessageA
 0x52c5a8 RegisterClipboardFormatA
 0x52c5ac RegisterClassA
 0x52c5b0 RedrawWindow
 0x52c5b4 PtInRect
 0x52c5b8 PostQuitMessage
 0x52c5bc PostMessageA
 0x52c5c0 PeekMessageA
 0x52c5c4 OpenClipboard
 0x52c5c8 OffsetRect
 0x52c5cc OemToCharA
 0x52c5d0 MsgWaitForMultipleObjects
 0x52c5d4 MoveWindow
 0x52c5d8 MessageBoxA
 0x52c5dc MessageBeep
 0x52c5e0 MapWindowPoints
 0x52c5e4 MapVirtualKeyA
 0x52c5e8 LoadStringA
 0x52c5ec LoadKeyboardLayoutA
 0x52c5f0 LoadIconA
 0x52c5f4 LoadCursorA
 0x52c5f8 LoadBitmapA
 0x52c5fc KillTimer
 0x52c600 IsZoomed
 0x52c604 IsWindowVisible
 0x52c608 IsWindowEnabled
 0x52c60c IsWindow
 0x52c610 IsRectEmpty
 0x52c614 IsIconic
 0x52c618 IsDialogMessageA
 0x52c61c IsClipboardFormatAvailable
 0x52c620 IsChild
 0x52c624 IsCharAlphaNumericA
 0x52c628 IsCharAlphaA
 0x52c62c InvalidateRect
 0x52c630 IntersectRect
 0x52c634 InsertMenuItemA
 0x52c638 InsertMenuA
 0x52c63c InflateRect
 0x52c640 HideCaret
 0x52c644 GetWindowThreadProcessId
 0x52c648 GetWindowTextA
 0x52c64c GetWindowRect
 0x52c650 GetWindowPlacement
 0x52c654 GetWindowLongA
 0x52c658 GetWindowDC
 0x52c65c GetTopWindow
 0x52c660 GetSystemMetrics
 0x52c664 GetSystemMenu
 0x52c668 GetSysColorBrush
 0x52c66c GetSysColor
 0x52c670 GetSubMenu
 0x52c674 GetScrollRange
 0x52c678 GetScrollPos
 0x52c67c GetScrollInfo
 0x52c680 GetPropA
 0x52c684 GetParent
 0x52c688 GetWindow
 0x52c68c GetMessageTime
 0x52c690 GetMenuStringA
 0x52c694 GetMenuState
 0x52c698 GetMenuItemInfoA
 0x52c69c GetMenuItemID
 0x52c6a0 GetMenuItemCount
 0x52c6a4 GetMenu
 0x52c6a8 GetLastActivePopup
 0x52c6ac GetKeyboardState
 0x52c6b0 GetKeyboardLayoutList
 0x52c6b4 GetKeyboardLayout
 0x52c6b8 GetKeyState
 0x52c6bc GetKeyNameTextA
 0x52c6c0 GetIconInfo
 0x52c6c4 GetForegroundWindow
 0x52c6c8 GetFocus
 0x52c6cc GetDoubleClickTime
 0x52c6d0 GetDesktopWindow
 0x52c6d4 GetDCEx
 0x52c6d8 GetDC
 0x52c6dc GetCursorPos
 0x52c6e0 GetCursor
 0x52c6e4 GetClipboardData
 0x52c6e8 GetClientRect
 0x52c6ec GetClassNameA
 0x52c6f0 GetClassInfoA
 0x52c6f4 GetCaretPos
 0x52c6f8 GetCapture
 0x52c6fc GetActiveWindow
 0x52c700 FrameRect
 0x52c704 FindWindowA
 0x52c708 FillRect
 0x52c70c EqualRect
 0x52c710 EnumWindows
 0x52c714 EnumThreadWindows
 0x52c718 EnumClipboardFormats
 0x52c71c EndPaint
 0x52c720 EnableWindow
 0x52c724 EnableScrollBar
 0x52c728 EnableMenuItem
 0x52c72c EmptyClipboard
 0x52c730 DrawTextExA
 0x52c734 DrawTextA
 0x52c738 DrawMenuBar
 0x52c73c DrawIconEx
 0x52c740 DrawIcon
 0x52c744 DrawFrameControl
 0x52c748 DrawFocusRect
 0x52c74c DrawEdge
 0x52c750 DispatchMessageA
 0x52c754 DestroyWindow
 0x52c758 DestroyMenu
 0x52c75c DestroyIcon
 0x52c760 DestroyCursor
 0x52c764 DeleteMenu
 0x52c768 DefWindowProcA
 0x52c76c DefMDIChildProcA
 0x52c770 DefFrameProcA
 0x52c774 CreatePopupMenu
 0x52c778 CreateMenu
 0x52c77c CreateIcon
 0x52c780 CloseClipboard
 0x52c784 ClientToScreen
 0x52c788 CheckMenuItem
 0x52c78c CallWindowProcA
 0x52c790 CallNextHookEx
 0x52c794 BeginPaint
 0x52c798 CharNextA
 0x52c79c CharLowerBuffA
 0x52c7a0 CharLowerA
 0x52c7a4 CharUpperBuffA
 0x52c7a8 CharToOemA
 0x52c7ac AdjustWindowRectEx
 0x52c7b0 ActivateKeyboardLayout
ole32.dll
 0x52c7b8 CoTaskMemFree
 0x52c7bc StringFromCLSID
kernel32.dll
 0x52c7c4 Sleep
oleaut32.dll
 0x52c7cc SafeArrayPtrOfIndex
 0x52c7d0 SafeArrayPutElement
 0x52c7d4 SafeArrayGetElement
 0x52c7d8 SafeArrayUnaccessData
 0x52c7dc SafeArrayAccessData
 0x52c7e0 SafeArrayGetUBound
 0x52c7e4 SafeArrayGetLBound
 0x52c7e8 SafeArrayRedim
 0x52c7ec SafeArrayCreate
 0x52c7f0 VariantChangeType
 0x52c7f4 VariantCopyInd
 0x52c7f8 VariantCopy
 0x52c7fc VariantClear
 0x52c800 VariantInit
ole32.dll
 0x52c808 CoCreateInstance
 0x52c80c CoGetMalloc
 0x52c810 CoUninitialize
 0x52c814 CoInitialize
 0x52c818 IsEqualGUID
oleaut32.dll
 0x52c820 CreateErrorInfo
 0x52c824 GetErrorInfo
 0x52c828 SetErrorInfo
 0x52c82c SafeArrayCopy
 0x52c830 SafeArrayUnaccessData
 0x52c834 SafeArrayAccessData
 0x52c838 SafeArrayGetUBound
 0x52c83c SafeArrayDestroy
 0x52c840 SafeArrayCreate
 0x52c844 SysFreeString
comctl32.dll
 0x52c84c ImageList_SetIconSize
 0x52c850 ImageList_GetIconSize
 0x52c854 ImageList_Write
 0x52c858 ImageList_Read
 0x52c85c ImageList_GetDragImage
 0x52c860 ImageList_DragShowNolock
 0x52c864 ImageList_SetDragCursorImage
 0x52c868 ImageList_DragMove
 0x52c86c ImageList_DragLeave
 0x52c870 ImageList_DragEnter
 0x52c874 ImageList_EndDrag
 0x52c878 ImageList_BeginDrag
 0x52c87c ImageList_Remove
 0x52c880 ImageList_DrawEx
 0x52c884 ImageList_Replace
 0x52c888 ImageList_Draw
 0x52c88c ImageList_GetBkColor
 0x52c890 ImageList_SetBkColor
 0x52c894 ImageList_ReplaceIcon
 0x52c898 ImageList_Add
 0x52c89c ImageList_GetImageCount
 0x52c8a0 ImageList_Destroy
 0x52c8a4 ImageList_Create
 0x52c8a8 InitCommonControls
kernel32.dll
 0x52c8b0 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure