Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Mar-30 12:28:33 |
Debug artifacts |
C:\cubik hevuxitece55-lovel\hufabisavoximu66_witibip38\piduket.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 38/72 (Scanned on 2022-11-26 09:06:20) |
Bkav:
W32.AIDetect.malware1
Lionic: Trojan.Win32.Zenpak.4!c Cynet: Malicious (score: 100) Sangfor: Trojan.Win32.Save.a K7AntiVirus: Trojan ( 0059b9cf1 ) K7GW: Trojan ( 0059b9cf1 ) Cybereason: malicious.0d42e2 Cyren: W32/Kryptik.ICN.gen!Eldorado Symantec: ML.Attribute.HighConfidence Elastic: malicious (high confidence) ESET-NOD32: a variant of Win32/Kryptik.HRSG APEX: Malicious Kaspersky: HEUR:Trojan.Win32.Zenpak.gen BitDefender: Trojan.GenericKD.63870904 MicroWorld-eScan: Trojan.GenericKD.63870904 Avast: Win32:CrypterX-gen [Trj] Ad-Aware: Trojan.GenericKD.63870904 DrWeb: Trojan.Pitou.17 TrendMicro: Trojan.Win32.PRIVATELOADER.YXCKZZ McAfee-GW-Edition: BehavesLike.Win32.Lockbit.cc Trapmine: malicious.moderate.ml.score FireEye: Generic.mg.2051267833c8e6c2 Sophos: Mal/Generic-S + Troj/Krypt-QV Ikarus: Trojan-Spy.Agent Kingsoft: Win32.Troj.Generic_a.a.(kcloud) Microsoft: Trojan:Win32/SmokeLoader.JCK!MTB GData: Win32.Backdoor.Tofsee.3JTMHI Google: Detected Acronis: suspicious McAfee: Artemis!2051267833C8 MAX: malware (ai score=82) TrendMicro-HouseCall: Trojan.Win32.PRIVATELOADER.YXCKZZ Rising: Malware.Obscure!1.A3BB (CLASSIC) SentinelOne: Static AI - Suspicious PE Fortinet: W32/Kryptik.HRSE!tr AVG: Win32:CrypterX-gen [Trj] Panda: Trj/Genetic.gen CrowdStrike: win/malicious_confidence_100% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2022-Mar-30 12:28:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x14a00 |
SizeOfInitializedData | 0x2f7600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00003A07 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x16000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x30b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x39415 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
OpenMutexA
GetConsoleAliasExesLengthW CopyFileExW ReadConsoleOutputCharacterA GetEnvironmentStrings MapUserPhysicalPages QueryDosDeviceA EnumCalendarInfoExA SetProcessPriorityBoost LocalSize AddConsoleAliasW CreateFileA GetMailslotInfo GetWindowsDirectoryA GetModuleHandleW VirtualFree CreateDirectoryExA GetLogicalDriveStringsW ReadConsoleInputA FindNextVolumeMountPointW OpenWaitableTimerA GetVersionExA SearchPathA RequestWakeupLatency CallNamedPipeA GetCurrentDirectoryW GetDriveTypeA CreateMailslotW BuildCommDCBAndTimeoutsA GetProcAddress LoadLibraryA LocalAlloc MoveFileWithProgressW TerminateThread SearchPathW EnumDateFormatsA FindFirstChangeNotificationA VerifyVersionInfoA DeleteTimerQueue FindFirstVolumeW GlobalFlags WritePrivateProfileStringW InterlockedDecrement GetTickCount GetACP GlobalWire GetTapeParameters HeapLock GetConsoleTitleW InterlockedExchangeAdd EnumCalendarInfoA InterlockedExchange GetNamedPipeHandleStateA GetModuleHandleA TerminateProcess MoveFileA AddAtomW FreeEnvironmentStringsW SetConsoleTitleW SetVolumeMountPointA VirtualProtect SetConsoleActiveScreenBuffer GetCPInfo GetProcessIoCounters GlobalFindAtomA CloseHandle EnumSystemCodePagesA LoadLibraryW GetVolumeInformationA GetCommandLineW UnhandledExceptionFilter SetUnhandledExceptionFilter GetLastError DeleteFileA GetCommandLineA GetStartupInfoA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId Sleep ExitProcess WriteFile GetStdHandle GetModuleFileNameA EnterCriticalSection LeaveCriticalSection SetHandleCount GetFileType DeleteCriticalSection GetCurrentProcess IsDebuggerPresent FreeEnvironmentStringsA WideCharToMultiByte GetEnvironmentStringsW HeapCreate HeapFree QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime GetOEMCP IsValidCodePage RtlUnwind InitializeCriticalSectionAndSpinCount SetFilePointer GetConsoleCP GetConsoleMode MultiByteToWideChar HeapAlloc VirtualAlloc HeapReAlloc LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA RaiseException HeapSize FlushFileBuffers SetStdHandle WriteConsoleA GetConsoleOutputCP WriteConsoleW ReadFile |
---|---|
USER32.dll |
GetComboBoxInfo
CharUpperBuffA GetListBoxInfo |
GDI32.dll |
GetCharABCWidthsA
|
ADVAPI32.dll |
AbortSystemShutdownW
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Oct-27 13:20:34 |
Version | 0.0 |
SizeofData | 91 |
AddressOfRawData | 0x28d0 |
PointerToRawData | 0x1cd0 |
Referenced File | C:\cubik hevuxitece55-lovel\hufabisavoximu66_witibip38\piduket.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0xe59a27f1 |
---|---|
Unmarked objects | 0 |
150 (20413) | 1 |
ASM objects (VS2008 build 21022) | 24 |
C objects (VS2008 build 21022) | 121 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 9 |
Total imports | 147 |
C++ objects (VS2008 build 21022) | 36 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 build 21022) | 1 |