Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-Jan-31 16:36:28 |
Detected languages |
English - United States
|
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
C:\Users\Unstable\Documents\al-khaser\Release\al-khaser.pdb
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 3/61 (Scanned on 2017-06-09 19:58:30) |
Bkav:
W32.eHeur.Malware03
Paloalto: generic.ml Rising: Malware.Undefined!8.C (cloud:kOofpIqGiGB) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2017-Jan-31 16:36:28 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1aa00 |
SizeOfInitializedData | 0xe400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005C01 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1c000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x2e000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
IsDebuggerPresent
VirtualProtect VirtualFree GetSystemInfo Sleep SetLastError GetLastError OutputDebugStringW VerSetConditionMask VerifyVersionInfoW GetModuleHandleW OpenProcess SetHandleInformation CreateMutexW RaiseException SetUnhandledExceptionFilter DeviceIoControl LocalAlloc CreateFileW GetDiskFreeSpaceExW LocalFree GlobalMemoryStatusEx GetTickCount ExpandEnvironmentStringsW GetWindowsDirectoryW WaitForSingleObject ReadFile GetConsoleScreenBufferInfo SetConsoleTextAttribute lstrlenW AddVectoredExceptionHandler MultiByteToWideChar FormatMessageW HeapAlloc LocalSize GetProcessHeap GetConsoleWindow SetConsoleTitleW HeapFree GetFileAttributesW CreateToolhelp32Snapshot Process32NextW Process32FirstW CreateEventW DecodePointer SetEndOfFile WriteConsoleW HeapReAlloc HeapSize SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleCP FlushFileBuffers GetStringTypeW SetStdHandle RemoveVectoredExceptionHandler GetThreadContext GetCurrentThread VirtualAlloc GetProcAddress LoadLibraryW CloseHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP IsValidCodePage FindNextFileA VirtualQuery FindFirstFileExA FindClose GetStdHandle GetCurrentProcess GetTimeZoneInformation GetCPInfo GetFileType LCMapStringW CompareStringW GetACP GetCommandLineW GetCommandLineA GetModuleHandleExW ExitProcess GetModuleFileNameA WriteFile WideCharToMultiByte QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead UnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent TerminateProcess RtlUnwind EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW |
---|---|
USER32.dll |
KillTimer
GetSystemMetrics GetShellWindow GetWindowThreadProcessId TranslateMessage MessageBoxW GetCursorPos FindWindowW MoveWindow GetMessageW DispatchMessageW SetTimer |
ADVAPI32.dll |
RegCloseKey
GetTokenInformation OpenProcessToken RegOpenKeyExW RegQueryValueExW |
SHELL32.dll |
SHGetSpecialFolderPathW
|
ole32.dll |
CoCreateInstance
CoSetProxyBlanket CoInitializeEx CoInitializeSecurity CoUninitialize |
OLEAUT32.dll |
#25
#19 #9 #23 #20 |
IPHLPAPI.DLL |
GetAdaptersInfo
|
SHLWAPI.dll |
StrCmpW
StrStrIW StrCmpIW PathCombineW |
MPR.dll |
WNetGetProviderNameW
|
SETUPAPI.dll |
SetupDiGetClassDevsW
SetupDiGetDeviceRegistryPropertyW SetupDiDestroyDeviceInfoList SetupDiEnumDeviceInfo |
WINMM.dll |
timeEndPeriod
timeKillEvent timeGetDevCaps timeSetEvent |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Jan-31 16:36:28 |
Version | 0.0 |
SizeofData | 84 |
AddressOfRawData | 0x256c0 |
PointerToRawData | 0x244c0 |
Referenced File | C:\Users\Unstable\Documents\al-khaser\Release\al-khaser.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Jan-31 16:36:28 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x25714 |
PointerToRawData | 0x24514 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Jan-31 16:36:28 |
Version | 0.0 |
SizeofData | 812 |
AddressOfRawData | 0x25728 |
PointerToRawData | 0x24528 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Jan-31 16:36:28 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x429000 |
---|---|
EndAddressOfRawData | 0x429001 |
AddressOfIndex | 0x427960 |
AddressOfCallbacks | 0x41c2b4 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
Callbacks |
0x00402840
|
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x427018 |
SEHandlerTable | 0x4256b0 |
SEHandlerCount | 4 |
XOR Key | 0xe7e3f8ac |
---|---|
Unmarked objects | 0 |
241 (40116) | 10 |
243 (40116) | 139 |
242 (40116) | 24 |
ASM objects (VS2015 UPD3 build 24123) | 20 |
C++ objects (VS2015 UPD3 build 24123) | 35 |
C objects (VS2015 UPD3 build 24123) | 20 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 SP1 build 30729) | 25 |
Total imports | 188 |
265 (VS2015 UPD3.1 build 24215) | 48 |
ASM objects (VS2015 UPD3 build 24210) | 1 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |