| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2015-Feb-25 06:12:17 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 31/71 (Scanned on 2023-02-12 09:52:20) |
Lionic:
Trojan.Win32.Ursu.4!c
Cynet: Malicious (score: 100) ALYac: Gen:Variant.Ursu.749657 Malwarebytes: Malware.AI.3840348866 VIPRE: Gen:Variant.Ursu.749657 Sangfor: Trojan.Win32.AGEN.1040592 Alibaba: Trojan:Win64/Genric.77ae27ba Cybereason: malicious.6d0e12 Symantec: ML.Attribute.HighConfidence Elastic: malicious (high confidence) APEX: Malicious Paloalto: generic.ml BitDefender: Gen:Variant.Ursu.749657 MicroWorld-eScan: Gen:Variant.Ursu.749657 Avast: Win64:Malware-gen Rising: Trojan.Zpevdo!8.F912 (CLOUD) Emsisoft: Gen:Variant.Ursu.749657 (B) McAfee-GW-Edition: BehavesLike.Win64.NetLoader.nm FireEye: Generic.mg.2a8668a6d0e12c73 Sophos: Generic Reputation PUA (PUA) MAX: malware (ai score=99) Microsoft: PUA:Win32/Presenoker Gridinsoft: Ransom.Win64.Wacatac.oa!s1 Arcabit: Trojan.Ursu.DB7059 GData: Gen:Variant.Ursu.749657 AhnLab-V3: Malware/Win64.Generic.C3488826 McAfee: Artemis!2A8668A6D0E1 Cylance: Unsafe TrendMicro-HouseCall: TROJ_GEN.R002H09HG22 MaxSecure: Trojan.Malware.74754451.susgen AVG: Win64:Malware-gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2015-Feb-25 06:12:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x5400 |
| SizeOfInitializedData | 0x5400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001740 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateProcessA
GetTempFileNameA IsDebuggerPresent GetTempPathA HeapAlloc GetStringTypeW GetCommandLineA GetStartupInfoW TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetProcAddress GetModuleHandleW ExitProcess DecodePointer WriteFile GetStdHandle GetModuleFileNameW RtlUnwindEx GetModuleFileNameA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType DeleteCriticalSection EncodePointer FlsGetValue FlsSetValue FlsFree SetLastError GetCurrentThreadId GetLastError FlsAlloc HeapSetInformation GetVersion HeapCreate QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime LeaveCriticalSection EnterCriticalSection LoadLibraryW GetCPInfo GetACP GetOEMCP IsValidCodePage HeapFree Sleep HeapSize LCMapStringW MultiByteToWideChar HeapReAlloc |
|---|---|
| urlmon.dll |
URLDownloadToFileA
|
| XOR Key | 0x509c44a6 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 build 30319) | 10 |
| C objects (VS2010 build 30319) | 52 |
| ASM objects (VS2010 build 30319) | 8 |
| Imports (VS2008 SP1 build 30729) | 5 |
| Total imports | 66 |
| 175 (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |