Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Jan-30 07:51:05 |
Detected languages |
English - United Kingdom
|
Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. |
Resource 7 is possibly compressed or encrypted.
Resource 8 is possibly compressed or encrypted. Resource 9 is possibly compressed or encrypted. Resource 10 is possibly compressed or encrypted. Resource 11 is possibly compressed or encrypted. Resource 12 is possibly compressed or encrypted. Resource 313 is possibly compressed or encrypted. Resource SCRIPT is possibly compressed or encrypted. |
Malicious | VirusTotal score: 20/66 (Scanned on 2019-08-11 03:04:33) |
MicroWorld-eScan:
Trojan.GenericKD.32231849
FireEye: Trojan.GenericKD.32231849 McAfee: Artemis!115A69488E9E BitDefender: Trojan.GenericKD.32231849 APEX: Malicious Paloalto: generic.ml Avast: Win32:Malware-gen Ad-Aware: Trojan.GenericKD.32231849 Emsisoft: Trojan.GenericKD.32231849 (B) Invincea: heuristic McAfee-GW-Edition: BehavesLike.Win32.Downloader.gc Jiangmin: Trojan.Agent.bztk Antiy-AVL: Trojan[Dropper]/Win32.Sysn Arcabit: Trojan.Generic.D1EBD1A9 Acronis: suspicious ALYac: Trojan.GenericKD.32231849 GData: Trojan.GenericKD.32231849 AVG: Win32:Malware-gen CrowdStrike: win/malicious_confidence_70% (D) MaxSecure: Trojan.Malware.300983.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2019-Jan-30 07:51:05 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x57000 |
SizeOfInitializedData | 0x22000 |
SizeOfUninitializedData | 0xa3000 |
AddressOfEntryPoint | 0x000FA020 (Section: UPX1) |
BaseOfCode | 0xa4000 |
BaseOfData | 0xfb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x11d000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x400000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.DLL |
LoadLibraryA
GetProcAddress VirtualProtect VirtualAlloc VirtualFree ExitProcess |
---|---|
ADVAPI32.dll |
GetAce
|
COMCTL32.dll |
ImageList_Remove
|
COMDLG32.dll |
GetOpenFileNameW
|
GDI32.dll |
LineTo
|
IPHLPAPI.DLL |
IcmpSendEcho
|
MPR.dll |
WNetUseConnectionW
|
ole32.dll |
CoGetObject
|
OLEAUT32.dll |
#8
|
PSAPI.DLL |
GetProcessMemoryInfo
|
SHELL32.dll |
DragFinish
|
USER32.dll |
GetDC
|
USERENV.dll |
LoadUserProfileW
|
UxTheme.dll |
IsThemeActive
|
VERSION.dll |
VerQueryValueW
|
WININET.dll |
FtpOpenFileW
|
WINMM.dll |
timeGetTime
|
WSOCK32.dll |
#4
|
㰉獡敳扭祬摉湥楴祴琠灹㵥眢湩㈳•慮敭∽楍牣獯景楗摮睯潃浭湯䌭湯牴汯≳瘠牥楳湯∽⸶⸰⸰∰氠湡畧条㵥⨢•牰捯獥潳䅲捲楨整瑣牵㵥⨢•異汢捩敋呹歯湥∽㔶㔹㙢ㄴ㐴捣ㅦ晤⼢ാ उ⼼敤数摮湥䅴獳浥汢㹹ठ⼼敤数摮湥祣ാ 㰉牴獵䥴普浸湬㵳產湲猺档浥獡洭捩潲潳瑦挭浯愺浳瘮∳ാ उ猼捥牵瑩㹹ठउ爼煥敵瑳摥牐癩汩来獥ാ उउ爼煥敵瑳摥硅捥瑵潩䱮癥汥氠癥汥∽獡湉潶敫≲甠䅩捣獥㵳昢污敳⼢ാ उ㰉爯煥敵瑳摥牐癩汩来獥ാ उ⼼敳畣楲祴ാ 㰉琯畲瑳湉潦ാऊ挼浯慰楴楢楬祴砠汭獮∽牵㩮捳敨慭業牣獯景潣㩭潣灭瑡扩汩瑩ㅶ㸢ठ㰉灡汰捩瑡潩㹮ठउ猼灵潰瑲摥协䤠㵤笢㉥㐱㜵ㄭ㐵ⴶ㌴㕣愭昵ⵥ〰搸敥㍥㍤て≽㸯उ㰉畳灰牯整佤⁓摉∽㍻ㄵ㠳㥢ⵡ搵㘹㐭扦ⵤ攸搲愭㐲〴㈲昵㌹絡⼢ാऊउ猼灵潰瑲摥协䤠㵤笢愴昲㠲㍥㔭戳ⴹ㐴ㄴ戭㥡ⵣ㙤搹愴愴收㠳≽㸯उ㰉畳灰牯整佤⁓摉∽ㅻ㙦㘷㝣ⴶ〸ㅥ㐭㌲ⴹ㔹扢㠭搳昰搶搰㝡紸⼢ാऊउ猼灵潰瑲摥协䤠㵤笢攸昰愷㈱戭扦ⴳ昴㡥戭愹ⴵ㠴摦〵ㅡ愵愹≽㸯उ⼼灡汰捩瑡潩㹮ठ⼼潣灭瑡扩汩瑩㹹⼼獡敳扭祬ാ倊 줬좈 줹좤 쥆좬 쥓좴 쥠좼 쥪죄 쥷죌 쥿죔 즉죜 즖죤 즠죬 즬죴 즷주 짃줄 짏줌 짛줔 짧줜 짱줤 짼쨊쨚쨪쨸쩆 쩔 쩜 쩮 쪀 쪈 쪖 쪪 耀 쪸 쫎 쫚 쫢 쫴 쬄 쬔 쬢 耀 䕋乒䱅㈳䐮䱌䄀噄偁㍉⸲汤l佃䍍䱔㈳搮汬䌀䵏䱄㍇⸲汤l䑇㍉⸲汤l偉䱈䅐䥐䐮䱌䴀剐搮汬漀敬㈳搮汬伀䕌啁㍔⸲汤l卐偁⹉䱄L䡓䱅㍌⸲汤l单剅㈳搮汬唀䕓䕒噎搮汬唀呸敨敭搮汬嘀剅䥓乏搮汬圀义义呅搮汬圀义䵍搮汬圀体䭃㈳搮汬 潌摡楌牢牡䅹 敇側潲䅣摤敲獳 楖瑲慵偬潲整瑣 楖瑲慵䅬汬捯 楖瑲慵䙬敲e 硅瑩牐捯獥s 敇䅴散 浉条䱥獩彴敒潭敶 敇佴数䙮汩乥浡坥 楌敮潔 捉灭敓摮捅潨 乗瑥獕䍥湯敮瑣潩坮 潃敇佴橢捥t 敇側潲散獳敍潭祲湉潦 牄条楆楮桳 敇䑴C 潌摡獕牥牐景汩坥 獉桔浥䅥瑣癩e 敖兲敵祲慖畬坥 瑆佰数䙮汩坥 楴敭敇呴浩eꀀ 〢㉀ |
偉䱈䅐䥐䐮䱌䴀剐搮汬漀敬㈳搮汬伀䕌啁㍔⸲汤l卐偁⹉䱄L䡓䱅㍌⸲汤l单剅㈳搮汬唀䕓䕒噎搮汬唀呸敨敭搮汬嘀剅䥓乏搮汬圀义义呅搮汬圀义䵍搮汬圀体䭃㈳搮汬 潌摡楌牢牡䅹 敇側潲䅣摤敲獳 楖瑲慵偬潲整瑣 楖瑲慵䅬汬捯 楖瑲慵䙬 |
e 硅瑩牐捯獥s 敇䅴散 浉条䱥獩彴敒潭敶 敇佴数䙮汩乥浡坥 楌敮潔 捉灭敓摮捅潨 乗瑥獕䍥湯敮瑣潩坮 潃敇佴橢捥t 敇側潲散獳敍潭祲湉潦 牄条楆楮桳 敇䑴C 潌摡獕牥牐景汩坥 獉桔浥䅥瑣癩e 敖兲敵祲慖畬坥 瑆佰数䙮汩坥 楴敭敇呴浩eꀀ 〢㉀ |