| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2005-Jan-30 07:50:29 |
| Detected languages |
Process Default Language
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C 5.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .clean
Section .clean is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
| Malicious | VirusTotal score: 44/72 (Scanned on 2026-04-04 10:00:57) |
AVG:
FileRepMalware [Misc]
AhnLab-V3: Trojan/Win32.Agent.C731784 Alibaba: Trojan:Win32/Hesv.3ea178da Avast: FileRepMalware [Misc] Avira: TR/Agent.BHZI.479232 CAT-QuickHeal: InfoStealer.AuroraCiR CTX: exe.trojan.hesv ClamAV: Win.Malware.Agent-6388751-0 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS DrWeb: Win32.Polipos.6 ESET-NOD32: Generik.FNTHHJW trojan F-Secure: Trojan.TR/Agent.BHZI.479232 Fortinet: GenericRXCP.OP!tr Google: Detected Gridinsoft: Malware.Win32.Gen.cc!s1 K7AntiVirus: Trojan ( 000f224b1 ) K7GW: Trojan ( 000f224b1 ) Kaspersky: Trojan.Win32.Hesv.dgzi Lionic: Worm.Win32.Polip.tndl Malwarebytes: Malware.AI.3168916104 MaxSecure: Trojan.Malware.12191244.susgen McAfeeD: ti!034AB6771E69 Microsoft: Trojan:Win32/Tiggre!rfn NANO-Antivirus: Trojan.Win32.Agent.criaa Paloalto: generic.ml Rising: Trojan.Undefined!8.1327C (KTSE) Sangfor: Trojan.Win32.Hesv.Vb2y Skyhigh: BehavesLike.Win32.Dropper.gm Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Win32.Trojan.Hesv.Nzfl Trapmine: malicious.moderate.ml.score TrellixENS: GenericRXTR-SU!F125ED1B34BD VBA32: Trojan.Hesv Varist: W32/Fuery.I.gen!Eldorado VirIT: Backdoor.Win32.Siggen.SVQ Webroot: Xcitium: Backdoor.Win32.Agent.~dy070@1xbov3 Yandex: Trojan.Agent!WU3yHnSAwWE alibabacloud: Trojan:Win/Tiggre huorong: Trojan/Generic!6D528EAF12527C07 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2005-Jan-30 07:50:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 5.0 |
| SizeOfCode | 0x58e00 |
| SizeOfInitializedData | 0x2f200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000271B0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x4b000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WINMM.dll |
PlaySoundA
|
|---|---|
| KERNEL32.dll |
GetSystemTime
GetLocalTime GetFileType GetStartupInfoA GetCommandLineA RtlUnwind RaiseException ExitProcess TerminateProcess GetACP HeapDestroy HeapCreate VirtualFree VirtualAlloc GetDriveTypeA GetTimeZoneInformation LCMapStringA LCMapStringW UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW SetUnhandledExceptionFilter GetStringTypeA GetStringTypeW IsBadCodePtr GetLocaleInfoA GetLocaleInfoW CompareStringA CompareStringW SetEnvironmentVariableA HeapSize HeapReAlloc HeapAlloc HeapFree GetOEMCP GetCPInfo GlobalGetAtomNameA GlobalAddAtomA GetFileTime GetFileSize GetFileAttributesA GetCurrentDirectoryA WritePrivateProfileStringA GetProcessVersion GlobalFlags TlsGetValue LocalReAlloc TlsSetValue EnterCriticalSection GlobalReAlloc LeaveCriticalSection GlobalHandle DeleteCriticalSection TlsAlloc InitializeCriticalSection GetFullPathNameA GetVolumeInformationA SetEndOfFile UnlockFile LockFile CloseHandle FlushFileBuffers SetFilePointer WriteFile ReadFile CreateFileA GetCurrentProcess DuplicateHandle lstrcpyA SetErrorMode FormatMessageA GlobalDeleteAtom lstrcmpiA GetCurrentThread GetThreadLocale FileTimeToLocalFileTime FileTimeToSystemTime IsBadReadPtr IsBadWritePtr lstrcmpA MultiByteToWideChar WideCharToMultiByte lstrlenA lstrcatA GetCurrentThreadId GlobalLock GlobalUnlock GetModuleFileNameA GetVersion MulDiv RemoveDirectoryA CreateDirectoryA DeleteFileA CopyFileA SetConsoleTextAttribute SetStdHandle AllocConsole SetConsoleCtrlHandler GetConsoleTitleA GetCurrentProcessId GetTickCount SetConsoleTitleA Sleep GetConsoleScreenBufferInfo FillConsoleOutputCharacterA FillConsoleOutputAttribute SetConsoleCursorPosition GetDateFormatA SizeofResource PeekConsoleInputA ReadConsoleInputA FlushConsoleInputBuffer LoadLibraryA GetProcAddress FreeLibrary GetStdHandle WriteConsoleA FreeConsole FindNextFileA FindFirstFileA GetLastError SetLastError FindClose GlobalAlloc GlobalFree GetVersionExA lstrcpynA FindResourceA LoadResource LockResource LocalUnlock LocalAlloc LocalLock LocalFree InterlockedDecrement InterlockedIncrement GetModuleHandleA SetHandleCount |
| USER32.dll |
ReleaseCapture
ReuseDDElParam UnpackDDElParam IsIconic RegisterClipboardFormatA PostThreadMessageA IsClipboardFormatAvailable GetTabbedTextExtentA SetRect LoadStringA ShowOwnedPopups GetSysColorBrush GetDesktopWindow PtInRect GetMessageA ValidateRect GetCursorPos CharUpperA PostQuitMessage CharNextA DestroyMenu MapDialogRect GrayStringA DrawTextA TabbedTextOutA EndPaint BeginPaint GetWindowDC GetMenuCheckMarkDimensions LoadBitmapA GetMenuState ModifyMenuA SetMenuItemBitmaps ShowWindow MoveWindow SetWindowTextA SetDlgItemTextA GetNextDlgTabItem EndDialog GetActiveWindow CreateDialogIndirectParamA SendDlgItemMessageA SystemParametersInfoA MapWindowPoints GetFocus SetFocus AdjustWindowRectEx EqualRect DeferWindowPos BeginDeferWindowPos EndDeferWindowPos ScrollWindow SetScrollInfo ShowScrollBar IsWindowEnabled IsChild GetCapture WinHelpA GetClassInfoA TranslateAcceleratorA GetMenuItemCount GetMenuItemID TrackPopupMenu GetDlgItem GetWindowTextA GetKeyState DefWindowProcA DestroyWindow CreateWindowExA SetWindowsHookExA CallNextHookEx SetPropA UnhookWindowsHookEx GetLastActivePopup GetForegroundWindow SetForegroundWindow GetPropA CallWindowProcA RemovePropA GetMessageTime GetMessagePos GetWindow SetWindowPos RegisterWindowMessageA GetCaretPos SetWindowLongA GetWindowLongA RemoveMenu GetSubMenu OpenClipboard EnumClipboardFormats CloseClipboard CreatePopupMenu ClientToScreen CheckMenuItem EnableMenuItem DestroyCursor DestroyIcon DrawIcon GetScrollRange SetScrollRange GetScrollPos GetClassNameA SetScrollPos KillTimer SetTimer GetMenu InsertMenuA LoadMenuA CreateMenu AppendMenuA SetMenu DrawMenuBar GetTopWindow PeekMessageA TranslateMessage DispatchMessageA WaitMessage IsDialogMessageA FindWindowA BringWindowToTop GetAsyncKeyState wsprintfA MessageBoxA LoadIconA SetCursor IsWindow DefFrameProcA GetParent DefMDIChildProcA RedrawWindow InvalidateRect LoadAcceleratorsA SetRectEmpty CopyAcceleratorTableA GetNextDlgGroupItem RegisterClassA MessageBeep UpdateWindow GetUpdateRect IsWindowVisible GetWindowRect ScreenToClient GetClientRect SetActiveWindow LoadCursorA GetDC ReleaseDC IsRectEmpty IntersectRect GetDlgCtrlID PostMessageA EnableWindow CopyRect GetSystemMetrics InflateRect OffsetRect DrawFrameControl DrawStateA SendMessageA LoadImageA GetSysColor GetWindowTextLengthA |
| GDI32.dll |
GetClipBox
ExcludeClipRect IntersectClipRect MoveToEx LineTo SetTextAlign SetPixelV GetViewportExtEx GetWindowExtEx PtVisible ScaleWindowExtEx TextOutA ExtTextOutA GetMapMode DPtoLP CreateDCA LPtoDP GetCharWidthA SetAbortProc GetPixel CreatePen GetStockObject PatBlt SetBoundsRect CreateCompatibleBitmap GetCurrentPositionEx GetCurrentObject CreatePenIndirect GetBkMode GetBkColor GetROP2 GetBoundsRect BitBlt AbortDoc CreateFontIndirectA GetTextMetricsA CreateCompatibleDC SelectObject GetDIBColorTable SetWindowExtEx SetWindowOrgEx ScaleViewportExtEx SetViewportExtEx OffsetViewportOrgEx SetViewportOrgEx SetROP2 SetBkMode RestoreDC SaveDC CreateBitmap SetBkColor SetTextColor SetMapMode DeleteEnhMetaFile PlayEnhMetaFile GetEnhMetaFileA ExtFloodFill Ellipse CreateSolidBrush GetTextExtentPointA RectVisible DeleteObject DeleteDC SelectPalette RealizePalette GetDIBits Escape SetStretchBltMode StretchDIBits GetDeviceCaps StartDocA StartPage EndPage EndDoc GetObjectA Rectangle GetTextColor |
| comdlg32.dll |
CommDlgExtendedError
FindTextA ReplaceTextA GetFileTitleA GetOpenFileNameA GetSaveFileNameA ChooseFontA PrintDlgA ChooseColorA |
| WINSPOOL.DRV |
EndDocPrinter
DocumentPropertiesA WritePrinter EndPagePrinter OpenPrinterA StartDocPrinterA StartPagePrinter ClosePrinter |
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegCreateKeyExA RegSetValueExA RegQueryValueExA |
| SHELL32.dll |
DragQueryFileA
DragFinish ShellExecuteA |
| COMCTL32.dll |
#17
ImageList_Destroy |
| oledlg.dll |
#8
|
| ole32.dll |
CoTaskMemAlloc
CLSIDFromString CLSIDFromProgID CoTaskMemFree OleInitialize OleUninitialize CreateStreamOnHGlobal CreateILockBytesOnHGlobal StgCreateDocfileOnILockBytes OleIsCurrentClipboard OleFlushClipboard CoRevokeClassObject CoRegisterMessageFilter CoFreeUnusedLibraries CoGetClassObject StgOpenStorageOnILockBytes |
| OLEAUT32.dll |
VariantClear
SysStringLen OleCreateFontIndirect SysAllocStringLen SafeArrayGetDim SafeArrayGetElemsize SafeArrayGetLBound SafeArrayGetUBound SafeArrayAccessData SafeArrayUnaccessData VariantChangeType SysFreeString SysAllocStringByteLen SysAllocString VariantCopy OleLoadPicture |
No comments yet.