Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2015-Sep-24 04:27:55 |
Detected languages |
Russian - Russia
|
FileVersion | 1, 23, 19, 125 |
CreateCopyright | SecInc |
ProductVersion | 1, 23, 19, 129 |
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: "IKO-PROF"
Issuer: COMODO RSA Code Signing CA |
Malicious | VirusTotal score: 22/57 (Scanned on 2015-09-27 10:07:18) |
MicroWorld-eScan:
Gen:Variant.Adware.Strictor.85078
ALYac: Gen:Variant.Adware.Strictor.85078 K7GW: Trojan ( 004cfc0f1 ) K7AntiVirus: Trojan ( 004cfc0f1 ) Kaspersky: not-a-virus:Downloader.Win32.LMN.ajz BitDefender: Gen:Variant.Adware.Strictor.85078 Ad-Aware: Gen:Variant.Adware.Strictor.85078 Sophos: Generic PUA BD (PUA) F-Secure: Gen:Variant.Adware.Strictor DrWeb: Trojan.LoadMoney.958 VIPRE: Trojan.Win32.Generic!BT Emsisoft: Gen:Variant.Adware.Strictor.85078 (B) Antiy-AVL: RiskWare[Downloader:not-a-virus]/Win32.LMN Arcabit: Trojan.Adware.Strictor.D14C56 GData: Gen:Variant.Adware.Strictor.85078 AVware: Trojan.Win32.Generic!BT VBA32: Signed-Downware.LMN Rising: PE:Malware.Obscure!1.9C59[F1] Ikarus: Trojan.Win32.Crypt AVG: Generic.E9C Panda: Generic Suspicious Qihoo-360: Win32/Virus.Downloader.d68 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2015-Sep-24 04:27:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x7000 |
SizeOfInitializedData | 0x93000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000021C2 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x8000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x9d000 |
SizeOfHeaders | 0x1000 |
Checksum | 0xa0eb8 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
OpenEventW
SystemTimeToFileTime CreateThread GetLocalTime OpenMutexA CreateEventA OpenSemaphoreW GetProcAddress LoadLibraryW GetModuleHandleW GetModuleHandleA ExitProcess VirtualFree VirtualAlloc GetCurrentProcess TerminateProcess DeleteCriticalSection InitializeCriticalSection GetSystemInfo VirtualProtect GetLocaleInfoA SetStdHandle GetStringTypeW GetStringTypeA LCMapStringW MultiByteToWideChar LCMapStringA HeapSize GetSystemTimeAsFileTime GetCurrentProcessId GetStartupInfoA GetCommandLineA GetVersionExA WriteFile GetStdHandle GetModuleFileNameA UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetLastError GetEnvironmentStringsW SetHandleCount GetFileType HeapDestroy HeapCreate HeapFree HeapAlloc LoadLibraryA GetACP GetOEMCP GetCPInfo HeapReAlloc RtlUnwind InterlockedExchange VirtualQuery FlushFileBuffers SetFilePointer QueryPerformanceCounter GetTickCount GetCurrentThreadId CloseHandle |
---|---|
USER32.dll |
DestroyWindow
EnableWindow GetThreadDesktop PostMessageW SendMessageA LoadCursorW |
SHELL32.dll |
#195
|
ole32.dll |
CoInitialize
CoUninitialize |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.19.125 |
ProductVersion | 1.0.19.125 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS_OS232_PM32
VOS__PM32
VOS__WINDOWS16
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Russian - Russia |
FileVersion (#2) | 1, 23, 19, 125 |
CreateCopyright | SecInc |
ProductVersion (#2) | 1, 23, 19, 129 |
Resource LangID | Russian - Russia |
---|
XOR Key | 0xb7fd2d47 |
---|---|
Unmarked objects | 0 |
C objects (VS2003 (.NET) build 3077) | 59 |
ASM objects (VS2003 (.NET) build 3077) | 12 |
Imports (9210) | 2 |
Imports (2067) | 2 |
Imports (2179) | 5 |
Total imports | 73 |
C++ objects (VS2003 (.NET) build 3077) | 4 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |