Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Jul-03 17:04:48 |
Detected languages |
English - Canada
|
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Valid Technic bandwidth |
FileVersion | 6.2.9200.20789 |
InternalName | mvtband.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | mvtband.dll |
ProductName | Microsoft Valid Technic bandwidth |
ProductVersion | 7.6.7200.24614 |
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
Malicious | VirusTotal score: 46/64 (Scanned on 2017-08-25 04:36:35) |
MicroWorld-eScan:
Gen:Variant.Razy.163623
CAT-QuickHeal: Trojan.Sofacy McAfee: RDN/Generic.dx Cylance: Unsafe AegisLab: Gen.Variant.Razy!c K7AntiVirus: Trojan ( 005123a31 ) K7GW: Trojan ( 005123a31 ) Invincea: heuristic Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9543 Cyren: W32/Trojan.IBSH-5630 Symantec: Trojan.Gen.2 TrendMicro-HouseCall: TROJ_SEDNIT.AUSB Paloalto: generic.ml Kaspersky: HEUR:Trojan.Win32.Sofacy.gen BitDefender: Gen:Variant.Razy.163623 NANO-Antivirus: Trojan.Win32.Sofacy.erbysh Avast: Win32:Malware-gen Rising: Trojan.Sednit!8.632 (cloud:vWpuGMobpmE) Ad-Aware: Gen:Variant.Razy.163623 Sophos: Mal/Generic-S Comodo: UnclassifiedMalware F-Secure: Gen:Variant.Razy.163623 DrWeb: Trojan.Sednit.37 VIPRE: Trojan.Win32.Generic!BT TrendMicro: TROJ_SEDNIT.AUSB McAfee-GW-Edition: BehavesLike.Win32.Miuref.mh Emsisoft: Gen:Variant.Razy.163623 (B) Avira: TR/Sednit.bpkwu Fortinet: W32/Sednit.BN!tr Endgame: malicious (high confidence) Arcabit: Trojan.Razy.D27F27 ZoneAlarm: HEUR:Trojan.Win32.Sofacy.gen Microsoft: Trojan:Win32/Foosace!rfn AhnLab-V3: Trojan/Win32.Sofacy.R205182 ALYac: Gen:Variant.Razy.163623 AVware: Trojan.Win32.Generic!BT MAX: malware (ai score=81) ESET-NOD32: a variant of Win32/Sednit.BN Tencent: Win32.Trojan.Sofacy.Dvft Yandex: Trojan.Sednit!kOlYGmJ/+Do Ikarus: Trojan.Win32.Sednit GData: Gen:Variant.Razy.163623 AVG: Win32:Malware-gen Panda: Trj/GdSda.A CrowdStrike: malicious_confidence_100% (W) Qihoo-360: Win32/Trojan.96f |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2017-Jul-03 17:04:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5800 |
SizeOfInitializedData | 0x1c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00006692 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xc000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
CRYPT32.dll |
CryptBinaryToStringA
CryptStringToBinaryA |
---|---|
gdiplus.dll |
GdipGetImageEncoders
GdipGetImageEncodersSize GdipCreateBitmapFromHBITMAP GdipSaveImageToStream GdipDisposeImage GdipCloneImage GdiplusShutdown GdiplusStartup GdipFree GdipAlloc |
IPHLPAPI.DLL |
GetAdaptersAddresses
|
SHLWAPI.dll |
#213
#184 #214 |
urlmon.dll |
ObtainUserAgentString
|
WININET.dll |
InternetOpenA
InternetCloseHandle InternetConnectA InternetReadFile HttpQueryInfoA HttpSendRequestA HttpOpenRequestA InternetSetOptionA InternetQueryOptionA |
WS2_32.dll |
#52
#116 #115 #57 |
KERNEL32.dll |
VirtualAlloc
GetPrivateProfileStringW VirtualFree DisableThreadLibraryCalls lstrcmpiA Process32Next Process32First CreateToolhelp32Snapshot VerifyVersionInfoW lstrlenW GetVersionExA GetSystemInfo GetCurrentProcess GetVolumeInformationW VerSetConditionMask GetTickCount GetSystemTimeAsFileTime QueryPerformanceCounter LoadLibraryW FreeLibrary CreateProcessW SetLastError WriteFile ReadFile GetFileSize CloseHandle Sleep MapViewOfFile UnmapViewOfFile CreateFileMappingA OpenFileMappingA WaitForSingleObject GetExitCodeProcess CreateThread CreateRemoteThread GetExitCodeThread HeapAlloc HeapReAlloc HeapFree GetProcessHeap IsWow64Process GetLastError CreateMutexA lstrlenA MultiByteToWideChar WideCharToMultiByte ExpandEnvironmentStringsW CreateDirectoryW CreateFileW DeleteFileW |
USER32.dll |
GetClipboardData
CloseClipboard keybd_event wsprintfA wsprintfW GetSystemMetrics GetMessageA TranslateMessage DispatchMessageA OpenClipboard |
ADVAPI32.dll |
RegOpenKeyExA
RegQueryValueExA RegSetValueExA RegCreateKeyExA RegCloseKey |
SHELL32.dll |
SHGetSpecialFolderPathW
|
ole32.dll |
CreateStreamOnHGlobal
|
Ordinal | 1 |
---|---|
Address | 0x66ab |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.2.9200.20789 |
ProductVersion | 7.6.7200.24614 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - Canada |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Valid Technic bandwidth |
FileVersion (#2) | 6.2.9200.20789 |
InternalName | mvtband.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | mvtband.dll |
ProductName | Microsoft Valid Technic bandwidth |
ProductVersion (#2) | 7.6.7200.24614 |
Resource LangID | English - Canada |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Jul-03 17:04:48 |
Version | 0.0 |
SizeofData | 236 |
AddressOfRawData | 0x76b8 |
PointerToRawData | 0x62b8 |
XOR Key | 0x3ef5c8da |
---|---|
Unmarked objects | 0 |
Imports (65501) | 25 |
Total imports | 99 |
C objects (VS2015 UPD3 build 24210) | 1 |
C++ objects (VS2015 UPD3 build 24210) | 19 |
Exports (VS2015 UPD3 build 24210) | 1 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3 build 24210) | 1 |