Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
Indonesian - Indonesia (Bahasa)
|
Suspicious | PEiD Signature: | ASPack v2.12 |
Suspicious | The PE is packed with Aspack or Armadillo |
Unusual section name found: .aspack
Unusual section name found: .adata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource BBABORT is possibly compressed or encrypted. Resource BBALL is possibly compressed or encrypted. Resource BBCANCEL is possibly compressed or encrypted. Resource BBCLOSE is possibly compressed or encrypted. Resource BBHELP is possibly compressed or encrypted. Resource BBIGNORE is possibly compressed or encrypted. Resource BBNO is possibly compressed or encrypted. The resource timestamps differ from the PE header:
|
Malicious | VirusTotal score: 45/66 (Scanned on 2018-05-22 09:43:28) |
MicroWorld-eScan:
Gen:Trojan.Heur.jOWbrnEJu@pGe
CMC: Generic.Win32.0e95e07579!MD McAfee: W32/Pesin.worm.gen Zillya: Virus.Pesin.Win32.2 TheHacker: Trojan/Hami K7GW: Trojan ( 0047f80c1 ) K7AntiVirus: Trojan ( 0047f80c1 ) Arcabit: Trojan.Heur.E53AAB F-Prot: W32/Delf.IA Symantec: W32.HLLW.Pesin TrendMicro-HouseCall: WORM_PESIN.C Avast: Win32:Trojan-gen ClamAV: Win.Trojan.Ag-6 Kaspersky: Virus.Win32.HLLW.Delf.b BitDefender: Gen:Trojan.Heur.jOWbrnEJu@pGe NANO-Antivirus: Virus.Win32.HLLW.gjjl Paloalto: generic.ml AegisLab: W32.HLLW.Delf.b!c Tencent: Win32.Virus.Hllw.Isr Ad-Aware: Gen:Trojan.Heur.jOWbrnEJu@pGe Emsisoft: Gen:Trojan.Heur.jOWbrnEJu@pGe (B) Comodo: Win32.Pesin.C DrWeb: Trojan.PWS.Mob TrendMicro: WORM_PESIN.C McAfee-GW-Edition: W32/Pesin.worm.gen Sophos: Troj/Pesin-C Ikarus: Virus.Win32.Pesin Cyren: W32/Delf.MPRZ-3816 Jiangmin: Trojan/HLLP.s Webroot: W32.Trojan.Trojan.gen Avira: W32/Pesin Antiy-AVL: Virus/Win32.Delf Microsoft: Worm:Win32/Pesin.C ZoneAlarm: Virus.Win32.HLLW.Delf.b ALYac: Trojan.Vir.HLL MAX: malware (ai score=100) VBA32: Trojan.Worm.Delf Cylance: Unsafe ESET-NOD32: Win32/Pesin.C Rising: Win32.Delf.et (CLASSIC) Yandex: Win32.HLLW.Delf GData: Gen:Trojan.Heur.jOWbrnEJu@pGe AVG: Win32:Trojan-gen Panda: Trj/Delf.AE Qihoo-360: Malware.Radar01.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x4f000 |
SizeOfInitializedData | 0xf000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00064001 (Section: .aspack) |
BaseOfCode | 0x1000 |
BaseOfData | 0x50000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x67000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetProcAddress
GetModuleHandleA LoadLibraryA |
---|---|
user32.dll |
GetKeyboardType
|
advapi32.dll |
RegQueryValueExA
|
oleaut32.dll |
SysFreeString
|
advapi32.dll (#2) |
RegQueryValueExA
|
version.dll |
VerQueryValueA
|
gdi32.dll |
UnrealizeObject
|
user32.dll (#2) |
GetKeyboardType
|
oleaut32.dll (#2) |
SysFreeString
|
comctl32.dll |
ImageList_SetIconSize
|
污穩佥橢捥t 牃慥整楗摮睯硅A 慓敦牁慲偹牴晏湉敤x 浉条䱥獩彴敓䥴潣卮穩e †˨ တĨ 〰٨ ( 0 ` Ҁ 耀 耀 肀 샀À肀 ÿ ÿÿ ÿÿ ÿ 蜀睷睷睷睷睷睷睷ࡷ 缈烿x マ耇 マ耇 マ耇 マ /耇 マ耇 マ /耇 マ耇 マ耇 マ耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ耇 マ耇 マ /耇 マ耇 マ耇 マ耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ ÿ 耇 マ耇 マ耇 マ耇 マ耇 マ耇 耀 炏烿烿烿烿烿烿烿烿耏 炏烿烿烿烿烿烿烿烿耏 瀈炈炈炈炈炈炈炈炈 ܀܀܀܀܀܀܀܀܀ þ 缀 ü 㼀 ø ἀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ø ἀ ⋾∢㼢 ( À ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ 瞇睷睷 マ マ マ マ マ マ マ ྏ༏༏ ྀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ྀ 忕 ( @ ʀ ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ ࠀ睷睷睷睷睷灰 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀༀ߷ 輀߷ 輀߷ 輀߷ 輀߸ 輀߸ ࠀ迸袏迸肏 ðἀàༀÀ܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀àༀ䧲뼤 |
耇 マ耇 マ耇 マ /耇 マ耇 マ /耇 マ耇 マ耇 マ耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ耇 マ耇 マ /耇 マ耇 マ耇 マ耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ ÿ 耇 マ耇 マ耇 マ耇 マ耇 マ耇 耀 炏烿烿烿烿烿烿烿烿耏 炏烿烿烿烿烿烿烿烿耏 瀈炈炈炈炈炈炈炈炈 ܀܀܀܀܀܀܀܀܀ þ 缀 ü 㼀 ø ἀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ø ἀ ⋾∢㼢 ( À ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ 瞇睷睷 マ マ マ マ マ マ マ ྏ༏༏ ྀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ྀ 忕 ( @ ʀ ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ ࠀ睷睷睷睷睷灰 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀༀ߷ 輀߷ 輀߷ 輀߷ 輀߸ 輀߸ ࠀ迸袏迸肏 ðἀàༀÀ܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀àༀ䧲뼤 |
耇 マ耇 マ耇 マ /耇 マ耇 マ耇 マ耇 マ耇 マ 耇 マ耇 マ 耇 マ耇 マ ÿ 耇 マ耇 マ耇 マ耇 マ耇 マ耇 耀 炏烿烿烿烿烿烿烿烿耏 炏烿烿烿烿烿烿烿烿耏 瀈炈炈炈炈炈炈炈炈 ܀܀܀܀܀܀܀܀܀ þ 缀 ü 㼀 ø ἀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ð ༀ ø ἀ ⋾∢㼢 ( À ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ 瞇睷睷 マ マ マ マ マ マ マ ྏ༏༏ ྀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ܀ ྀ 忕 ( @ ʀ ¿뼀 뼀¿¿ ¿¿뾿 샀À肀 ÿ ÿÿ ÿÿ ÿ ࠀ睷睷睷睷睷灰 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀ð ༀ߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀߷ 輀߷ 輀ðༀ߷ 輀߷ 輀ðༀༀ߷ 輀߷ 輀߷ 輀߷ 輀߸ 輀߸ ࠀ迸袏迸肏 ðἀàༀÀ܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀À܀àༀ䧲뼤 |