Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2014-Aug-27 02:27:48 |
TLS Callbacks | 2 callback(s) detected. |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 36/57 (Scanned on 2016-04-30 23:26:10) |
MicroWorld-eScan:
Gen:Variant.Razy.40473
CAT-QuickHeal: TrojanSpy.Nivdort.WR8 ALYac: Gen:Variant.Razy.40473 VIPRE: Trojan.Win32.Generic!BT BitDefender: Gen:Variant.Razy.40473 K7GW: Trojan ( 004e2ee21 ) K7AntiVirus: Trojan ( 004e2ee21 ) F-Prot: W32/Nivdort.K.gen!Eldorado Symantec: Trojan.Gen ESET-NOD32: a variant of Win32/Bayrob.BR TrendMicro-HouseCall: TROJ_BAYROB.SMX Avast: Win32:Malware-gen Kaspersky: HEUR:Trojan.Win32.Bayrob.gen Tencent: Win32.Trojan.Bayrob.Duy Ad-Aware: Gen:Variant.Razy.40473 Sophos: Troj/Bayrob-CM Comodo: UnclassifiedMalware F-Secure: Gen:Variant.Razy.40473 DrWeb: Trojan.Bayrob.58 McAfee-GW-Edition: BehavesLike.Win32.PWSZbot.dh Emsisoft: Gen:Variant.Razy.40473 (B) Cyren: W32/Nivdort.K.gen!Eldorado Avira: TR/Nivdort.ceyr Fortinet: W32/Bayrob.BR!tr Arcabit: Trojan.Razy.D9E19 AhnLab-V3: Trojan/Win32.Agent Microsoft: TrojanSpy:Win32/Nivdort McAfee: Trojan-FIIE!00AC639338CA AVware: Trojan.Win32.Generic!BT VBA32: BScope.Trojan.Diple Panda: Trj/Genetic.gen Rising: Trojan.Bayrob!8.FB-crb12Y1aWlM (Cloud) Ikarus: Trojan.Inject GData: Gen:Variant.Razy.40473 AVG: Win32/Cryptor Qihoo-360: HEUR/QVM20.1.0000.Malware.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2014-Aug-27 02:27:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x3c200 |
SizeOfInitializedData | 0x44c00 |
SizeOfUninitializedData | 0x7200 |
AddressOfEntryPoint | 0x000014C0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x3e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 1.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x53000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x200000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
GetBkColor
GetClipRgn GetCurrentObject GetDCPenColor GetDeviceCaps GetFontLanguageInfo GetFontUnicodeRanges GetGraphicsMode GetMapMode GetNearestColor GetNearestPaletteIndex GetObjectType GetPixelFormat GetRandomRgn GetStretchBltMode GetSystemPaletteUse GetTextCharacterExtra GetTextCharsetInfo GetTextColor SetPixel SetSystemPaletteUse SetTextAlign SetTextColor UpdateColors |
---|---|
KERNEL32.dll |
DeleteCriticalSection
DeleteFileA EnterCriticalSection FreeLibrary GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetDriveTypeA GetFileTime GetLastError GetModuleHandleA GetModuleHandleW GetProcAddress GetProcessHeap GetStartupInfoA GetStdHandle GetSystemTimeAsFileTime GetTickCount GetVersion GlobalAlloc GlobalFlags GlobalHandle GlobalSize InitializeCriticalSection IsDebuggerPresent IsProcessorFeaturePresent LeaveCriticalSection LoadLibraryA LoadResource LocalFlags LockResource MoveFileA QueryPerformanceCounter SetFilePointer SetUnhandledExceptionFilter SizeofResource Sleep TerminateProcess TlsGetValue UnhandledExceptionFilter VirtualProtect VirtualQuery |
msvcrt.dll |
__dllonexit
__getmainargs __initenv __lconv_init __set_app_type __setusermatherr _acmdln _amsg_exit _cexit _chgsign _ecvt _errno _fgetchar _fileno _fileno _finite _fmode _fputwchar _getmaxstdio _fcvt _getw _initterm _iob _itoa _lock _ltoa _makepath _memccpy _nextafter _onexit _putenv _rmtmp _rmtmp _scalb _searchenv _seterrormode _setmaxstdio _stat _strcmpi _strlwr _strnicmp _strnset _strset _swab _tempnam _tempnam _tzset _unlink _unlock _vsnprintf _wasctime _wcsicmp _wcsicoll _wcslwr _wcsnicmp _wcsnicoll _wcsset _wcsupr _wfopen _wctime _wfreopen _wstrdate _wtmpnam _wtol abort asctime atoi calloc clock exit fclose fflush fopen fprintf fputs fputwc fread free freopen frexp fseek fwrite fwscanf isalpha isleadbyte islower isprint ispunct isupper iswalnum iswcntrl iswdigit localeconv localtime iswpunct iswspace ldiv log10 malloc mblen mbstowcs memcmp memmove memset mktime mbtowc memcpy rand realloc remove rename rewind signal sprintf srand strcat strcmp strcpy strerror strftime strlen strncat strncmp strstr strtok strtol system time tmpfile tmpnam toupper towupper vfprintf |
USER32.dll |
BeginPaint
CallWindowProcA CheckDlgButton DrawTextA EnableWindow EndDialog EndPaint GetCursor GetDC GetDialogBaseUnits GetDlgItem GetDlgItemInt GetForegroundWindow GetInputState GetMenu GetMenuCheckMarkDimensions GetMenuContextHelpId GetMenuItemCount GetMenuItemID GetMenuState GetPropA GetQueueStatus GetScrollPos GetWindowContextHelpId GetWindowLongA IsWindowEnabled IsWindowUnicode MoveWindow PostMessageA RemovePropA SendMessageA SetDlgItemTextA SetFocus SetWindowTextA ShowWindow WindowFromDC |
StartAddressOfRawData | 0x452000 |
---|---|
EndAddressOfRawData | 0x45201c |
AddressOfIndex | 0x44d690 |
AddressOfCallbacks | 0x451020 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x00437E50
0x00437E00 |