21877a78cda11e2cd72bc495b2aff681

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2011-Oct-26 17:26:11
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++
Microsoft Visual C++ v6.0
Microsoft Visual C++ v5.0/v6.0 (MFC)
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Miscellaneous malware strings:
  • cmd.exe
Suspicious The PE is packed or was manually edited. The number of imports reported in the RICH header is inconsistent.
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCloseKey
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegQueryValueExW
  • RegFlushKey
  • RegOpenKeyExW
  • RegEnumValueW
  • RegEnumKeyExW
  • RegCreateKeyExW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessA
Can create temporary files:
  • GetTempPathW
  • CreateFileA
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Info The PE is digitally signed. Signer: Enthusiastic Software
Issuer: Thawte Code Signing CA - G2
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 21877a78cda11e2cd72bc495b2aff681
SHA1 2248ed13c0503d721552ddb5e2b630f881f7b9ee
SHA256 f0e8b708def802f0c4992d1f65ffbcc6336a46592bb03b8542bee6fc6aab70a2
SHA3 ae3afa834a1bae87f50134b362756ea71fd7f6e7227e09e50f7952de71addfc6
SSDeep 12288:lcbqxfoRxFZabmVBDzZMfH5+fAoR0sUe9SPn+9/Xy1wXb5SxMAcsl5DTiGvFZg9r:CqRoRN2QDzZ3R0H9jviKG7o3y9
Imports Hash 83f9102628c70292e15b6e886d210dc1

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2011-Oct-26 17:26:11
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x7d000
SizeOfInitializedData 0x40000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00067964 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x7e000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xbe000
SizeOfHeaders 0x1000
Checksum 0xb41fe
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x1000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x1000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f8e6cdecf91060b055d6b4d2c3687be2
SHA1 dd493bee3f17a5ee10aebdd576dea253df31fb25
SHA256 1e0b817d8aff44ef47854ee464accd45ac9727457ad5a5eb8289f825db2146f8
SHA3 01b46e64226bfcbe190db4804de2459da7289122a5339ff144076d747e995d94
VirtualSize 0x7c7b4
VirtualAddress 0x1000
SizeOfRawData 0x7d000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.24181

.rdata

MD5 edf499eadc876b716a65c8a4d8a38ef8
SHA1 432c8b8a90af6f70cca79f3c3001a8d07cd7729b
SHA256 3654063f6c4f85dbb45b29894b4a0ef70f226e3e403513650f8f189a08599d0b
SHA3 660c5a5ee43fd5aa90c61a683cc49da682df4ac87d1cad3c7e03bda2a5ada45b
VirtualSize 0xed1e
VirtualAddress 0x7e000
SizeOfRawData 0xf000
PointerToRawData 0x7e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.46503

.data

MD5 550be76d7d4f3488a241cdf5d4baf26e
SHA1 1b94f1bd3e5d8a8d7a18560795646b574132d8fd
SHA256 a5b74c1173ee2845ce2cccb4b6c59cf8c5c1c3b040cfbc3657f903dd329d9092
SHA3 9856c4b2b0af43667aa04ad6d50dd91c6e7d14ee8a26656e7e2816a238739329
VirtualSize 0x29db8
VirtualAddress 0x8d000
SizeOfRawData 0x1b000
PointerToRawData 0x8d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.45558

.rsrc

MD5 2292150605c4eee4e8a3bc434a590bbd
SHA1 9ab4778a1517165469a3015c63afb7531977c19f
SHA256 760c51f3185a270505e8d14bf206f6706130e82eb0beb45912e149426bb494eb
SHA3 ab894364d3a87f70dd21f75ab3c3f6c41f41dcaf03884b53e1da8b6ff5482bf9
VirtualSize 0x6198
VirtualAddress 0xb7000
SizeOfRawData 0x7000
PointerToRawData 0xa8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.16041

Imports

USER32.dll GetWindowRect
GetDialogBaseUnits
TrackPopupMenu
LoadBitmapW
KillTimer
SetTimer
GetKeyState
GetNextDlgTabItem
GetClassNameW
EnumChildWindows
EnumThreadWindows
CallWindowProcA
GetDlgItemTextW
GetWindowTextLengthW
GetWindowTextW
CallWindowProcW
MessageBeep
CheckDlgButton
IsDlgButtonChecked
DrawIcon
DrawFocusRect
SendDlgItemMessageW
BeginPaint
EndPaint
ReleaseDC
GetFocus
GetParent
GetForegroundWindow
SetForegroundWindow
EndDialog
GetDlgCtrlID
WinHelpW
CreateDialogIndirectParamW
DialogBoxIndirectParamW
ScreenToClient
SetDlgItemTextW
GetDlgItem
GetClassInfoW
GetSysColor
EnableWindow
ModifyMenuW
GetClientRect
SetWindowTextW
SetParent
InvalidateRect
LoadIconW
SetClassLongW
GetClassLongW
SetMenu
ClientToScreen
RegisterWindowMessageW
DefWindowProcW
SetScrollRange
SetScrollPos
BeginDeferWindowPos
DeferWindowPos
EndDeferWindowPos
GetWindowLongW
ShowWindow
GetSystemMenu
DrawMenuBar
RegisterClassW
SetWindowLongW
UpdateWindow
UnregisterClassW
GetSysColorBrush
AppendMenuW
TrackPopupMenuEx
CreateMenu
DispatchMessageW
EnableMenuItem
CheckMenuItem
DestroyMenu
CreatePopupMenu
DestroyWindow
PostMessageW
GetDC
GetCursor
LoadCursorW
SetCursor
MsgWaitForMultipleObjects
PeekMessageW
GetMessageW
TranslateMessage
PostQuitMessage
MessageBoxW
GetSystemMetrics
CreateWindowExW
SendMessageW
SetFocus
SetWindowPos
ADVAPI32.dll RegDeleteValueW
RegDeleteKeyW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
OpenProcessToken
CopySid
GetLengthSid
GetTokenInformation
RegCloseKey
RegSetValueExW
RegQueryInfoKeyW
RegQueryValueExW
RegFlushKey
RegOpenKeyExW
RegEnumValueW
RegEnumKeyExW
RegCreateKeyExW
GDI32.dll CreatePatternBrush
BitBlt
CreateDIBSection
CreateBitmap
GetMapMode
SetMapMode
DPtoLP
Polyline
GetTextExtentPoint32W
ExtTextOutW
RoundRect
CreatePen
Rectangle
SetBkColor
DeleteDC
SetTextColor
CreateSolidBrush
CreateCompatibleBitmap
GetStockObject
SelectObject
DeleteObject
GetObjectW
GetTextMetricsW
CreateFontIndirectW
GetTextFaceW
CreateCompatibleDC
COMCTL32.dll #17
CreateToolbarEx
CreateStatusWindowW
PropertySheetW
CreatePropertySheetPageW
ImageList_Create
ImageList_Destroy
ImageList_Add
comdlg32.dll GetOpenFileNameW
GetSaveFileNameW
Msi.dll #20
#125
#163
#118
#32
#17
#159
#160
#115
#158
#92
#24
#7
#8
ole32.dll CoInitializeEx
CoTaskMemAlloc
CoTaskMemFree
CoUninitialize
OLEAUT32.dll #149
#150
#6
RPCRT4.dll UuidCreate
UuidToStringW
RpcStringFreeW
SHELL32.dll SHGetPathFromIDListW
ShellExecuteW
Shell_NotifyIconW
SHGetSpecialFolderLocation
SHGetMalloc
SHGetDesktopFolder
SHBrowseForFolderW
KERNEL32.dll GetStartupInfoA
GetModuleHandleA
RaiseException
TerminateProcess
RtlUnwind
GetCommandLineA
LocalFree
InterlockedIncrement
InterlockedExchange
FindFirstFileW
FindNextFileW
FindClose
WritePrivateProfileStringW
GetPrivateProfileIntW
GetPrivateProfileStringW
UnlockFile
GetTempFileNameW
GetTempPathW
SetEndOfFile
GetFileSize
MoveFileExW
MoveFileW
GetLogicalDrives
LockFile
GetShortPathNameW
FlushFileBuffers
SetFilePointer
TlsSetValue
GetVersion
HeapSize
FileTimeToLocalFileTime
FileTimeToSystemTime
CreateDirectoryW
GetFileAttributesW
GetFullPathNameW
lstrcpynW
ReadFile
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetFileAttributesA
IsValidLocale
IsValidCodePage
GetLocaleInfoA
EnumSystemLocalesA
GetUserDefaultLCID
GetStringTypeA
GetStringTypeW
IsBadReadPtr
IsBadCodePtr
GetACP
GetVersionExW
CreateThread
HeapReAlloc
ExitThread
GetTimeZoneInformation
LCMapStringW
LCMapStringA
CompareStringW
GetCPInfo
CompareStringA
RemoveDirectoryW
TlsAlloc
SetUnhandledExceptionFilter
TlsGetValue
GetModuleFileNameA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
GetFileTime
DeleteFileW
UnhandledExceptionFilter
GetOEMCP
LoadLibraryA
SetStdHandle
CreateFileA
GetExitCodeProcess
CreateProcessA
SetEnvironmentVariableA
GetLocaleInfoW
WriteFile
CreateFileW
GetExitCodeThread
GetProcAddress
Sleep
GetTimeFormatW
ReleaseMutex
WaitForSingleObject
CloseHandle
CreateMutexW
ExitProcess
OpenMutexW
WideCharToMultiByte
MultiByteToWideChar
OutputDebugStringW
LeaveCriticalSection
EnterCriticalSection
GetCurrentProcess
ResumeThread
GetThreadPriority
SetThreadPriority
SetPriorityClass
SetEvent
ResetEvent
ReleaseSemaphore
CreateSemaphoreW
OpenSemaphoreW
CreateEventW
GetCurrentThreadId
SetLastError
lstrlenW
InterlockedDecrement
GetProcessHeap
HeapAlloc
HeapFree
GetLocalTime
GetDateFormatW
IsDebuggerPresent
GetCommandLineW
FindResourceW
GetModuleFileNameW
GetLastError
SetCurrentDirectoryW
GetCurrentDirectoryW
LockResource
SizeofResource
LoadResource
DebugBreak
IsBadWritePtr
GetSystemTime
GetComputerNameW
GetModuleHandleW
InitializeCriticalSection
DeleteCriticalSection
FreeLibrary
LoadLibraryW

Delayed Imports

?TrackMouseEvent@ESXToolTipTrack@@AAGHPAUtagTRACKMOUSEEVENT@@@Z

Ordinal 1
Address 0xb726

CTESTAR.GIF

Type BINRES
Language English - United States
Codepage UNKNOWN
Size 0x5d75
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.83967
Detected Filetype GIF graphic file
MD5 1ac0dce8fd451b1dfc2d725dcdb440db
SHA1 bddba78bbee124043631ccebfb1da1b0480cae1c
SHA256 13c40287f930d979bb7123d8eb1d23e579e985f5616f3ca349684024b7660538
SHA3 bdc09e3d53c53b4a38487fb3a72b0be15ae52045e6aed036204a267226ac4bdd

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.63422
MD5 1375fc99ebde421885dd91a6c2c172b5
SHA1 5d4baf84c5fa7b3c751b2c048409a3dc3bd15deb
SHA256 f017d7bca77cc7637a36eb08be828b24f823e399b92e46eddfc16e5290177d33
SHA3 79aaaa37e8b15db7413382344bcf971e67797de24d4608918be2541b78351e24

A

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xff205a7f
Unmarked objects 0
14 (7299) 31
C++ objects (8798) 2
C++ objects (8047) 22
C objects (8047) 177
19 (8022) 11
Unmarked objects (#2) 26
Total imports 298
19 (8034) 17
Resource objects (VS98 SP6 cvtres build 1736) 1
C++ objects (VC++ 6.0 SP5 build 8804) 34
Linker (VC++ 6.0 SP5 imp/exp build 8447) 1

Errors