| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2010-Feb-14 06:46:07 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 8
MSVC++ v.8 (procedure 1 recognized - h) |
| Suspicious | PEiD Signature: |
FASM 1.5x
FASM v1.5x |
| Suspicious | The PE is possibly packed. |
Section .text is both writable and executable.
Section .rsrc is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 87.0746% of the executable. |
| Suspicious | The file contains overlay data. | 1 bytes of data starting at offset 0x49206. |
| Malicious | VirusTotal score: 64/72 (Scanned on 2023-11-06 12:47:52) |
ALYac:
Win32.Worm.Autorun.VN
APEX: Malicious AVG: Win32:AutoRun-BPH [Wrm] AhnLab-V3: Trojan/Win32.Cosmu.R1380 Alibaba: Malware:Win32/km_24901.None Antiy-AVL: Trojan/Win32.Unknown Arcabit: Win32.Worm.Autorun.VN Avast: Win32:AutoRun-BPH [Wrm] Avira: WORM/Autorun.hfp Baidu: Win32.Worm.Agent.as BitDefender: Win32.Worm.Autorun.VN BitDefenderTheta: Gen:NN.ZexaF.36792.sqX@a0CZ48ni Bkav: W32.AIDetectMalware CAT-QuickHeal: Worm.Autorun.WT ClamAV: Win.Trojan.VB-73727 CrowdStrike: win/malicious_confidence_100% (W) Cybereason: malicious.4b9288 Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.MulDrop6.39712 ESET-NOD32: Win32/AutoRun.Agent.VS Elastic: malicious (high confidence) Emsisoft: Win32.Worm.Autorun.VN (B) F-Secure: Worm.WORM/Autorun.hfp FireEye: Generic.mg.0919ef1961261226 Fortinet: W32/AutoRun.GP!worm GData: Win32.Worm.Autorun.VN Google: Detected Gridinsoft: Virus.Win32.Ramnit.rc!i Ikarus: Worm.Win32.AutoRun Jiangmin: Worm/AutoRun.uuv K7AntiVirus: EmailWorm ( 0017c39f1 ) K7GW: EmailWorm ( 0017c39f1 ) Kaspersky: Worm.Win32.AutoRun.hfp Lionic: Trojan.Win32.Generic.lrbN MAX: malware (ai score=100) Malwarebytes: Generic.Malware.AI.DDS MaxSecure: Worm.W32.AutoRun.hfp McAfee: W32/Autorun.worm.aaav MicroWorld-eScan: Win32.Worm.Autorun.VN Microsoft: Worm:Win32/Wecykler.A NANO-Antivirus: Trojan.Win32.Autoruner1.csgwlt Panda: Trj/Hexas.HEU Rising: Worm.Win32.Fednu.k (CLASSIC) SUPERAntiSpyware: Trojan.Agent/Gen-WinAlert Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Generic.dz Sophos: W32/Autorun-BDV Symantec: W32.SillyFDC Tencent: Worm.Win32.Autorun.afe TrendMicro: WORM_OTORUN.SMXY TrendMicro-HouseCall: WORM_OTORUN.SMXY VBA32: Worm.AutoRun.Silly VIPRE: Win32.Worm.Autorun.VN Varist: W32/Risk.DYPU-6082 ViRobot: Worm.Win32.AutoRun.364544.A VirIT: Worm.Win32.Generic.BDKN Webroot: W32.Autorun.Gen Xcitium: TrojWare.Win32.Autorun.KVS@4uwbxy Zillya: Worm.Autorun.Win32.81673 ZoneAlarm: Worm.Win32.AutoRun.hfp Zoner: Trojan.Win32.14005 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2010-Feb-14 06:46:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x5000 |
| SizeOfInitializedData | 0x44000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00005581 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x6000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4a000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
MapViewOfFile
VirtualQuery UnmapViewOfFile GetLastError SetFileAttributesW DeleteFileW WriteFile CreateDirectoryW CopyFileW GetCurrentProcess GetSystemDirectoryW FindFirstVolumeW GetVolumePathNamesForVolumeNameW GetDriveTypeW FindNextVolumeW FindVolumeClose Sleep SetPriorityClass SetErrorMode CreateMutexW WaitForSingleObject CreateThread CreateFileMappingW GetComputerNameW GetSystemTime CreateToolhelp32Snapshot Process32FirstW OpenProcess TerminateProcess Process32NextW Module32FirstW ReleaseMutex GlobalAlloc FindFirstFileW FindNextFileW GetFileAttributesW ExitProcess GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter IsDebuggerPresent SetUnhandledExceptionFilter CloseHandle HeapFree GetFileSize HeapCreate CreateFileW GetModuleFileNameW ReadFile SetFilePointer HeapAlloc ResumeThread UnhandledExceptionFilter GetStartupInfoW InterlockedCompareExchange InterlockedExchange |
|---|---|
| USER32.dll |
GetKeyState
GetKeyNameTextW CharLowerW GetAsyncKeyState MapVirtualKeyW |
| ADVAPI32.dll |
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegCloseKey RegSetValueExW RegOpenKeyExW LookupPrivilegeValueW SetKernelObjectSecurity AdjustTokenPrivileges OpenProcessToken |
| SHELL32.dll |
ShellExecuteW
|
| MSVCR80.dll |
__p__fmode
wcscpy_s wcscat_s _vsnwprintf_s rand_s _wfopen perror fwprintf fflush _wcsicmp malloc free _amsg_exit __wgetmainargs _cexit _exit _XcptFilter exit _wcmdln _initterm _initterm_e _configthreadlocale __setusermatherr _adjust_fdiv __p__commode memset _encode_pointer __set_app_type _crt_debugger_hook _unlock __dllonexit _lock _onexit _decode_pointer _except_handler4_common _invoke_watson _controlfp_s |
| vsafe |
| VSAFE |
| XOR Key | 0xdb79d4fd |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 20 |
| C objects (VS2003 (.NET) build 4035) | 1 |
| Imports (VS2003 (.NET) build 4035) | 11 |
| Total imports | 115 |
| 114 (VS2012 build 50727 / VS2005 build 50727) | 2 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |