| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Nov-11 20:13:14 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\Users\User\Documents\Visual Studio 2008\Projects\DAZXCFGTYUNI\Release\DAZXCFGTYUNI.pdb
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 55/64 (Scanned on 2026-03-03 17:16:44) |
ALYac:
Dump:Generic.ShellCode.RDI.Marte.1.99A97195
APEX: Malicious AhnLab-V3: Trojan/Win32.Emotet.R294637 Alibaba: Trojan:Win32/Emotet.9d47c22c Antiy-AVL: Trojan[Banker]/Win32.Emotet Arcabit: Dump:Generic.ShellCode.RDI.Marte.1.99A97195 Avira: HEUR/AGEN.1318123 BitDefender: Dump:Generic.ShellCode.RDI.Marte.1.99A97195 Bkav: W32.AIDetectMalware CAT-QuickHeal: TrojanBanker.Emotet CTX: exe.trojan.emotet ClamAV: Win.Trojan.Emotet-7338391-0 CrowdStrike: win/malicious_confidence_100% (D) Cylance: Unsafe Cynet: Malicious (score: 99) DrWeb: Trojan.Emotet.762 ESET-NOD32: Win32/Emotet.BN trojan Elastic: malicious (high confidence) Emsisoft: Trojan.Emotet (A) F-Secure: Heuristic.HEUR/AGEN.1318123 Fortinet: W32/Kryptik.GXIK!tr GData: Dump:Generic.ShellCode.RDI.Marte.1.99A97195 Google: Detected Gridinsoft: Malware.Win32.Emotet.tr Ikarus: Trojan-Banker.Emotet Jiangmin: Trojan.Banker.Emotet.lfs K7AntiVirus: Trojan ( 0055d5751 ) K7GW: Trojan ( 0055d5751 ) Kingsoft: Win32.Trojan-Banker.Emotet.gen Lionic: Trojan.Win32.Emotet.L!c Malwarebytes: Malware.AI.2311593780 MaxSecure: Trojan.Malware.74690904.susgen McAfeeD: ti!0507575641D2 MicroWorld-eScan: Dump:Generic.ShellCode.RDI.Marte.1.99A97195 Microsoft: Trojan:Win32/Emotet.PG!MTB NANO-Antivirus: Trojan.Win32.Emotet.gditho Paloalto: generic.ml Panda: Trj/GdSda.A Sangfor: Spyware.Win32.Emotet.Vgbd Sophos: Mal/Generic-S Symantec: Trojan.Emotet Tencent: Malware.Win32.Gencirc.14632168 Trapmine: suspicious.low.ml.score TrendMicro: TrojanSpy.Win32.EMOTET.SMB.hp TrendMicro-HouseCall: TrojanSpy.Win32.EMOTET.SMB.hp VIPRE: Dump:Generic.ShellCode.RDI.Marte.1.99A97195 Varist: W32/Emotet.ZY.gen!Eldorado ViRobot: Trojan.Win.Z.Emotet.178688.B VirIT: Trojan.Win32.Emotet.BNB Webroot: W32.Trojan.Emotet Yandex: Trojan.GenAsa!RiYntR8m+lY Zillya: Trojan.Emotet.Win32.18172 Zoner: Trojan.Win32.85612 alibabacloud: Trojan[stealer]:Win/Emotet.76707dcf huorong: VirTool/Obfuscator.dp |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2017-Nov-11 20:13:14 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x11800 |
| SizeOfInitializedData | 0x1ba00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00003228 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x13000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x31000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x32446 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
LoadStringW
|
|---|---|
| KERNEL32.dll |
HeapAlloc
GetModuleHandleW Sleep GetProcAddress ExitProcess GetCommandLineA GetStartupInfoA TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent EnterCriticalSection LeaveCriticalSection SetHandleCount GetStdHandle GetFileType DeleteCriticalSection RtlUnwind GetLastError HeapFree CloseHandle RaiseException VirtualFree VirtualAlloc HeapReAlloc HeapCreate WriteFile GetModuleFileNameA GetCPInfo InterlockedIncrement InterlockedDecrement GetACP GetOEMCP IsValidCodePage TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError GetCurrentThreadId LCMapStringW LoadLibraryA InitializeCriticalSectionAndSpinCount FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime MultiByteToWideChar CreateFileA SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers HeapSize LCMapStringA GetStringTypeA GetStringTypeW GetLocaleInfoA GetModuleHandleA SetFilePointer WriteConsoleA GetConsoleOutputCP WriteConsoleW |
| Ordinal | 1 |
|---|---|
| Address | 0x14c0 |
| 1260387982 |
| っャジ私ャすたェェャきたジス意のでた愛いもててい任すャもはも愛っ愛のスス愛て |
| 3487774651 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Oct-06 19:45:36 |
| Version | 0.0 |
| SizeofData | 114 |
| AddressOfRawData | 0x29e50 |
| PointerToRawData | 0x28a50 |
| Referenced File | c:\Users\User\Documents\Visual Studio 2008\Projects\DAZXCFGTYUNI\Release\DAZXCFGTYUNI.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x42c02c |
| SEHandlerTable | 0x42a0e0 |
| SEHandlerCount | 12 |
| XOR Key | 0x95b215f8 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2008 build 21022) | 53 |
| ASM objects (VS2008 build 21022) | 28 |
| C objects (VS2008 build 21022) | 142 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 5 |
| Total imports | 89 |
| 138 (VS2008 build 21022) | 2 |
| Exports (VS2008 build 21022) | 1 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 build 21022) | 1 |
No comments yet.