Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-May-10 18:30:01 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
MASM/TASM - sig2(h)
MASM/TASM - sig1(h) |
Info | The PE contains common functions which appear in legitimate applications. |
Can access the registry:
|
Suspicious | VirusTotal score: 2/66 (Scanned on 2018-05-26 20:48:20) |
Cylance:
Unsafe
Ikarus: Trojan.Win32.Equdrug |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2017-May-10 18:30:01 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x6200 |
SizeOfInitializedData | 0x4e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000102D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x8000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x11000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.DLL |
ReadFileEx
WriteFile CloseHandle CreateFileA SleepEx FreeLibrary VirtualQuery ReadConsoleA FindFirstFileA FindClose GetLastError GetStdHandle GetProcessHeap HeapFree HeapAlloc GetModuleHandleW GetStartupInfoW InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter WideCharToMultiByte MultiByteToWideChar RaiseException IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter GetProcAddress |
---|---|
ADVAPI32.dll |
RegEnumValueA
RegEnumKeyExA RegCloseKey RegOpenKeyExA |
ucrtbased.dll |
__p___argv
_cexit _c_exit _register_thread_local_exe_atexit_callback _configthreadlocale _set_new_mode __p__commode __stdio_common_vsprintf_s _seh_filter_dll _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _crt_at_quick_exit _controlfp_s __p___argc _wmakepath_s _wsplitpath_s wcscpy_s _set_app_type _seh_filter_exe _CrtDbgReportW _CrtDbgReport strncmp __stdio_common_vfprintf __acrt_iob_func malloc free strlen strcpy strcat _set_fmode __setusermatherr exit _initterm_e _initterm _initialize_narrow_environment _get_initial_narrow_environment terminate _configure_narrow_argv _exit |
USER32.dll |
CharUpperA
|
VCRUNTIME140D.dll |
memset
_except_handler4_common __vcrt_GetModuleFileNameW __vcrt_GetModuleHandleW __vcrt_LoadLibraryExW __std_type_info_destroy_list |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40b728 |
SEHandlerTable | 0x4096d0 |
SEHandlerCount | 1 |
XOR Key | 0xab816046 |
---|---|
Unmarked objects | 0 |
239 (40116) | 2 |
Imports (VS2015 UPD3 build 24123) | 2 |
C++ objects (VS2015 UPD3 build 24123) | 23 |
C objects (VS2015 UPD3 build 24123) | 13 |
Imports (65501) | 7 |
Total imports | 84 |
C objects (VS2015 UPD3.1 build 24215) | 3 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |