Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Aug-30 17:16:30 |
Detected languages |
English - United States
|
FileDescription | |
FileVersion | 1.1.30.01 |
InternalName | |
LegalCopyright | |
OriginalFilename | |
ProductName | |
ProductVersion | 1.1.30.01 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 1 is possibly compressed or encrypted. |
Malicious | VirusTotal score: 27/70 (Scanned on 2019-10-29 00:08:16) |
MicroWorld-eScan:
Gen:Variant.Strictor.219451
FireEye: Gen:Variant.Strictor.219451 CAT-QuickHeal: Trojan.Riskware McAfee: Artemis!2B5ADC75D0F3 K7GW: Riskware ( 0040eff71 ) K7AntiVirus: Riskware ( 0040eff71 ) Arcabit: Trojan.Strictor.D3593B Symantec: Trojan.Gen.2 APEX: Malicious BitDefender: Gen:Variant.Strictor.219451 NANO-Antivirus: Trojan.Win32.Taskun.gayftt Ad-Aware: Gen:Variant.Strictor.219451 Emsisoft: Gen:Variant.Strictor.219451 (B) Zillya: Trojan.DiscoStealer.Win32.10 McAfee-GW-Edition: BehavesLike.Win32.Dropper.th Jiangmin: Trojan.Banker.ClipBanker.fq Webroot: W32.Malware.Gen MAX: malware (ai score=85) Antiy-AVL: Trojan[Banker]/Win32.ClipBanker Microsoft: Trojan:Win32/Generic!BV AegisLab: Trojan.Win32.Strictor.4!c VBA32: BScope.TrojanPSW.MSIL.DiscoStealer ALYac: Gen:Variant.Strictor.219451 TrendMicro-HouseCall: TROJ_GEN.R002H09IS19 Rising: Trojan.Generic@ML.91 (RDMK:X5c6JJqa4wD80pcqrlM+4A) GData: Gen:Variant.Strictor.219451 AVG: FileRepMalware |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2019-Aug-30 17:16:30 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0xdc800 |
SizeOfInitializedData | 0x3c600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000C70AD (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xde000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x123000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WSOCK32.dll |
#116
#11 #52 #57 #115 |
---|---|
WINMM.dll |
mixerSetControlDetails
waveOutGetVolume joyGetPosEx mixerGetControlDetailsW mixerOpen mixerGetDevCapsW mixerGetLineControlsW waveOutSetVolume mixerClose mciSendStringW joyGetDevCapsW mixerGetLineInfoW |
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
COMCTL32.dll |
ImageList_Create
CreateStatusWindowW ImageList_ReplaceIcon InitCommonControlsEx ImageList_GetIconSize ImageList_Destroy ImageList_AddMasked |
PSAPI.DLL |
GetModuleBaseNameW
GetModuleFileNameExW |
KERNEL32.dll |
FindClose
FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW TerminateProcess WaitForSingleObject GetExitCodeProcess PeekNamedPipe ReadFile WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW GetDiskFreeSpaceW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW CreateDirectoryW WriteFile DeleteFileW FindResourceW LoadResource LockResource SizeofResource SetFileAttributesW LocalFileTimeToFileTime SetFileTime GetFileSizeEx GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetWindowsDirectoryW GetTempPathW GetFullPathNameW GetShortPathNameW FindNextFileW LeaveCriticalSection VirtualProtect QueryDosDeviceW CompareStringW RemoveDirectoryW CopyFileW FormatMessageW GetACP CreatePipe GetStdHandle GetPrivateProfileStringW GetVersion GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetFileType SetFilePointerEx SetFilePointer SystemTimeToFileTime FileTimeToSystemTime GetFileSize VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize GetFileInformationByHandle CreateFileMappingW MapViewOfFile UnmapViewOfFile InterlockedDecrement InterlockedIncrement GetStartupInfoW HeapSetInformation GetCommandLineW HeapQueryInformation HeapSize HeapReAlloc HeapFree ExitProcess HeapAlloc TlsSetValue TlsFree UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent HeapCreate InitializeCriticalSectionAndSpinCount FindFirstFileW GetModuleFileNameW DeleteCriticalSection GetCPInfo WideCharToMultiByte MultiByteToWideChar FreeLibrary GetModuleHandleW GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread GetStringTypeExW lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock GetCurrentDirectoryW SetErrorMode InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount MulDiv GetVersionExW GetModuleHandleA GetProcAddress LoadLibraryW GetSystemTimeAsFileTime GetCurrentProcess GetProcessTimes GetOEMCP IsValidCodePage TlsAlloc SetHandleCount IsProcessorFeaturePresent GetStringTypeW LCMapStringW RaiseException RtlUnwind GetConsoleCP GetConsoleMode FreeEnvironmentStringsW TlsGetValue GetEnvironmentStringsW QueryPerformanceCounter FlushFileBuffers WriteConsoleW SetStdHandle GetProcessHeap EnterCriticalSection VirtualQuery |
USER32.dll |
GetMenuStringW
ExitWindowsEx SetMenu FlashWindow GetPropW SetPropW RemovePropW MapWindowPoints RedrawWindow SetParent GetClassInfoExW GetAncestor UpdateWindow GetMessagePos GetClassLongW DefDlgProcW CallWindowProcW CheckRadioButton IntersectRect GetUpdateRect PtInRect CreateDialogIndirectParamW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu GetMenuItemInfoW CreateMenu CreatePopupMenu SetMenuInfo AppendMenuW DestroyMenu TrackPopupMenuEx DrawIcon PrintWindow GetDesktopWindow CopyImage CreateIconIndirect CreateIconFromResourceEx EnumClipboardFormats GetWindow BringWindowToTop MessageBoxW GetTopWindow SetRect GetIconInfo SetWindowTextW IsWindowVisible CheckMenuItem LoadImageW GetSubMenu SetClipboardViewer LoadAcceleratorsW EnableMenuItem GetMenu CreateWindowExW LoadCursorW DestroyIcon DestroyWindow IsCharAlphaW FillRect VkKeyScanExW MapVirtualKeyExW GetKeyboardLayoutNameW ActivateKeyboardLayout GetGUIThreadInfo GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW ReleaseDC GetDC OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow GetMenuItemID GetMenuItemCount GetSystemMenu GetLastInputInfo GetCursor ClientToScreen MessageBeep SetDlgItemTextW GetDlgItem SendDlgItemMessageW DialogBoxParamW SetForegroundWindow ChangeClipboardChain DefWindowProcW CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW IsIconic IsZoomed EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetLayeredWindowAttributes SetWindowPos SetWindowRgn SetFocus SetActiveWindow EnumChildWindows MoveWindow GetQueueStatus GetWindowRect GetClientRect SystemParametersInfoW PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable AdjustWindowRectEx MapVirtualKeyW DrawTextW RegisterClassExW |
GDI32.dll |
GetCharABCWidthsW
SetBkMode GetClipBox CreatePatternBrush SetBrushOrgEx GetCurrentObject CreateBitmap CreateDIBSection GetPixel SetDIBits EnumFontFamiliesExW GdiFlush FillRgn GetClipRgn BitBlt ExcludeClipRect SetTextColor SetBkColor GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush CreateFontW CreateCompatibleBitmap GetDeviceCaps DeleteObject |
COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW CommDlgExtendedError |
ADVAPI32.dll |
RegDeleteKeyW
RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW RegDeleteValueW |
SHELL32.dll |
DragQueryPoint
SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW ExtractIconW |
ole32.dll |
OleInitialize
OleUninitialize CoCreateInstance CoInitialize CoUninitialize CLSIDFromString CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
OLEAUT32.dll |
#20
#35 #418 #24 #18 #23 #22 #148 #21 #17 #16 #19 #11 #27 #2 #12 #9 #15 #6 #7 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.1.30.1 |
ProductVersion | 1.1.30.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | |
FileVersion (#2) | 1.1.30.01 |
InternalName | |
LegalCopyright | |
OriginalFilename | |
ProductName | |
ProductVersion (#2) | 1.1.30.01 |
Resource LangID | English - United States |
---|
XOR Key | 0xbb16a54c |
---|---|
Unmarked objects | 0 |
C++ objects (VS2010 build 30319) | 55 |
C objects (VS2010 build 30319) | 150 |
C objects (VS2008 SP1 build 30729) | 7 |
Imports (VS2008 SP1 build 30729) | 27 |
Total imports | 464 |
ASM objects (VS2010 build 30319) | 35 |
175 (VS2010 build 30319) | 53 |
Resource objects (52519) | 1 |
Linker (VS2010 build 30319) | 1 |