| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2019-Jan-07 03:05:16 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
C:\vmagent_new\bin\joblist\319990\out\Release\Release\360AP.pdb
|
| CompanyName | 360.cn |
| FileDescription | 360WiFi |
| FileVersion | 5, 3, 0, 5000 |
| InternalName | 360AP.exe |
| LegalCopyright | (C) 360.cn Inc. All Rights Reserved. |
| OriginalFilename | 360AP.exe |
| ProductName | 360WiFi |
| ProductVersion | 5, 3, 0, 5000 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA256 Uses constants related to AES Uses constants related to DES Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource 367 is possibly compressed or encrypted. |
| Info | The PE is digitally signed. |
Signer: Beijing Qihu Technology Co.
Issuer: VeriSign Class 3 Code Signing 2010 CA |
| Safe | VirusTotal score: 0/72 (Scanned on 2024-03-31 02:43:39) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2019-Jan-07 03:05:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x374800 |
| SizeOfInitializedData | 0x2f3c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00321505 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x376000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x674000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x67b15c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
|---|---|
| wke.dll |
wkeToStringW
wkeCreateWebView wkeShutdown wkeInit |
| IMM32.dll |
ImmGetContext
ImmReleaseContext ImmSetCandidateWindow |
| KERNEL32.dll |
lstrcmpW
UnlockFile LockFile GetModuleHandleExW GetModuleFileNameA GetFileTime ResetEvent LocalFileTimeToFileTime TerminateThread GetCurrentThread FileTimeToLocalFileTime ResumeThread InterlockedExchange InterlockedExchangeAdd FormatMessageW GetVersionExA SetEnvironmentVariableA CompareStringA GetConsoleOutputCP WriteConsoleA GetLocaleInfoW GetStringTypeA IsValidLocale EnumSystemLocalesA GetLocaleInfoA GetUserDefaultLCID QueryPerformanceCounter GetEnvironmentStringsW FreeEnvironmentStringsW CompareStringW FlushFileBuffers GetStartupInfoA SetHandleCount GetConsoleMode LockResource HeapCreate InitializeCriticalSectionAndSpinCount GetDateFormatA GetTimeFormatA IsValidCodePage GetOEMCP GetACP GetTimeZoneInformation GetStringTypeW LCMapStringW LCMapStringA GetCPInfo SetStdHandle SystemTimeToFileTime WriteConsoleW VirtualQuery GlobalFree MoveFileA ExitProcess ExitThread IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter RtlUnwind TlsFree DeleteAtom FindAtomW TlsAlloc ReleaseMutex AddAtomW OpenThread GetAtomNameW TlsSetValue TlsGetValue GetSystemTime GetFileSizeEx SetFilePointerEx CreateFileA HeapSize HeapReAlloc HeapDestroy IsProcessorFeaturePresent LoadLibraryA GetSystemTimeAsFileTime DeleteCriticalSection InitializeCriticalSection LoadLibraryW FreeLibrary SetThreadExecutionState FindResourceW SizeofResource LoadResource GlobalAlloc GlobalLock GlobalUnlock FreeResource WaitForSingleObject GetModuleFileNameW TerminateProcess GetCommandLineW LocalFree CreateThread OutputDebugStringW GetTickCount GetProcAddress OpenProcess CloseHandle LeaveCriticalSection EnterCriticalSection MulDiv GetCurrentProcess GetPrivateProfileStringA IsBadReadPtr SetCurrentDirectoryW CreateMutexW lstrcmpiW OpenMutexW InterlockedIncrement LoadLibraryExW GetFileType GetSystemWindowsDirectoryW FileTimeToSystemTime CompareFileTime GetStdHandle SetEndOfFile FlushInstructionCache RaiseException GetFileInformationByHandle GetLogicalDriveStringsW GetCurrentThreadId SetLastError FindFirstChangeNotificationW FindCloseChangeNotification GetTempFileNameW SearchPathW GetCurrentDirectoryW GetShortPathNameW SetFileTime GetWindowsDirectoryW GetTempPathW LocalAlloc lstrcpyW CreatePipe SetHandleInformation InterlockedDecrement InterlockedCompareExchange CreateEventW SetEvent GetProcessHeap HeapAlloc HeapFree DeviceIoControl GetPrivateProfileIntW GetPrivateProfileStringW FindClose FindNextFileW FindFirstFileW GetFullPathNameW GetVersion AttachConsole FreeConsole GetStartupInfoW CreateProcessW OutputDebugStringA GetLocalTime GetCurrentProcessId WritePrivateProfileStringW RemoveDirectoryW GetFileAttributesW SetFileAttributesW GetFileAttributesExW GetFileSize ReadFile VerSetConditionMask VerifyVersionInfoW GetVersionExW GetModuleHandleA GetSystemInfo lstrlenW lstrlenA VirtualAlloc VirtualFree GetSystemDirectoryW GetLastError MoveFileW MoveFileExW CreateToolhelp32Snapshot Process32FirstW Process32NextW WideCharToMultiByte MultiByteToWideChar lstrcatW Sleep CopyFileW CreateDirectoryW CreateFileW SetFilePointer GetModuleHandleW WriteFile DeleteFileW VirtualProtect FindResourceExW lstrcmpA lstrcmpiA GetConsoleCP |
| USER32.dll |
DialogBoxParamW
CharUpperW CharToOemW CopyRect UnregisterClassA SetForegroundWindow SetActiveWindow DispatchMessageW TranslateMessage SetFocus GetMessageW IsWindow EnableWindow GetSystemMetrics SystemParametersInfoW PostMessageW SetCursor LoadCursorW SystemParametersInfoA SetWindowRgn TrackMouseEvent RegisterClassW TranslateAcceleratorW DestroyWindow DefWindowProcW CreateWindowExW CallWindowProcW PtInRect SetRect SetWindowLongW GetWindowLongW MoveWindow GetClientRect ScreenToClient ShowWindow GetClassInfoExW RegisterClassExW GetWindowRect WindowFromPoint GetWindowThreadProcessId GetDesktopWindow GetForegroundWindow GetAncestor EnumDisplaySettingsW GetMonitorInfoW MonitorFromPoint GetWindowInfo GetWindow GetShellWindow RegisterWindowMessageW SetWindowPos SetTimer IsWindowVisible KillTimer SetWindowTextW SendMessageW FindWindowW PostQuitMessage GetCursorPos IsIconic ClientToScreen SendMessageTimeoutW CreateDialogParamW LoadImageW ExitWindowsEx MessageBoxW GetActiveWindow AdjustWindowRectEx RedrawWindow GetDlgItem MapWindowPoints MonitorFromWindow GetParent BeginPaint EndPaint FillRect GetClassLongW IntersectRect SetCapture GetCapture ReleaseCapture UpdateWindow InvalidateRect OffsetRect ReleaseDC GetDC DrawTextW UpdateLayeredWindow wsprintfW GetWindowDC GetWindowRgn SetRectEmpty FindWindowExW PeekMessageW CharNextW AttachThreadInput AllowSetForegroundWindow keybd_event GetKeyboardState BringWindowToTop IsDialogMessageW InflateRect IsZoomed InvalidateRgn CreateAcceleratorTableW GetClassNameW IsChild GetFocus GetSysColor DestroyAcceleratorTable GetClassNameA SetLayeredWindowAttributes GetAsyncKeyState GetWindowTextLengthW GetWindowTextW GetKeyState EndDialog WaitForInputIdle EqualRect |
| GDI32.dll |
GetCharWidth32A
GetGlyphOutlineW GetTextMetricsA GetFontData GetGlyphIndicesW SetMapMode GetOutlineTextMetricsA SaveDC SetTextAlign RestoreDC ExtCreateRegion ExtSelectClipRgn GetGraphicsMode GetWorldTransform ModifyWorldTransform SetGraphicsMode SetWorldTransform GdiFlush CreateDCW GetDIBits CreateFontW CreateRectRgnIndirect CombineRgn CreateFontA SetStretchBltMode StretchBlt CreateRoundRectRgn CreatePatternBrush GdiAlphaBlend CreateDCA GetFontUnicodeRanges SelectClipRgn GetDeviceCaps CreateRectRgn PtInRegion CreatePen SetBkColor ExtTextOutW LineTo MoveToEx CreateDIBSection GetBitmapBits CreateSolidBrush CreateFontIndirectW GetTextExtentPoint32W GetObjectW GetStockObject PatBlt DeleteObject CreateCompatibleBitmap CreateCompatibleDC DeleteDC GetTextColor SetBkMode SelectObject SetTextColor TextOutW IntersectClipRect OffsetViewportOrgEx SetViewportOrgEx ExcludeClipRect BitBlt GetClipBox StretchDIBits GetClipRgn |
| ADVAPI32.dll |
StartServiceW
RevertToSelf ImpersonateLoggedOnUser QueryServiceStatusEx RegEnumKeyExA RegQueryValueExA RegOpenKeyW RegEnumKeyW RegOpenKeyExA RegSetValueExA RegOpenKeyExW RegCloseKey RegQueryValueExW LookupPrivilegeValueW OpenProcessToken InitiateSystemShutdownW SetNamedSecurityInfoW SetEntriesInAclW BuildExplicitAccessWithNameW GetNamedSecurityInfoW GetUserNameW CloseServiceHandle ControlService QueryServiceStatus OpenServiceW OpenSCManagerW ChangeServiceConfigW QueryServiceConfigW RegDeleteValueW RegCreateKeyExW RegSetValueExW RegEnumKeyExW CryptAcquireContextW CryptReleaseContext CryptDestroyKey CryptGenRandom CryptContextAddRef CryptSetKeyParam CryptImportKey CryptEncrypt CryptDecrypt RegDeleteKeyW RegQueryInfoKeyW GetTokenInformation AdjustTokenPrivileges |
| SHELL32.dll |
CommandLineToArgvW
ShellExecuteExW ShellExecuteW SHGetFolderPathW SHAppBarMessage #680 SHGetSpecialFolderPathW #165 SHCreateDirectoryExW |
| ole32.dll |
CreateStreamOnHGlobal
CoUninitialize CoInitialize CoCreateInstance CoInitializeEx CoSetProxyBlanket CoInitializeSecurity CoTaskMemFree CoTaskMemAlloc CoTaskMemRealloc OleUninitialize OleInitialize CoGetClassObject OleLockRunning StringFromGUID2 CLSIDFromProgID CLSIDFromString |
| OLEAUT32.dll |
SysStringLen
SysAllocString SysFreeString VarDateFromStr VariantTimeToSystemTime LoadTypeLib SafeArrayCopy SafeArrayGetVartype VariantClear SafeArrayGetLBound SystemTimeToVariantTime SafeArrayCreate SafeArrayDestroy SafeArrayLock SafeArrayUnlock SysAllocStringByteLen VariantCopy VarUI4FromStr SysStringByteLen VariantChangeType SysAllocStringLen DispCallFunc OleCreateFontIndirect LoadRegTypeLib SafeArrayGetUBound VarBstrCmp VariantInit |
| SHLWAPI.dll |
StrCmpIW
PathFindFileNameW PathFileExistsW SHSetValueW PathCombineW SHGetValueW PathAppendW PathRemoveFileSpecW PathIsDirectoryW PathMakePrettyW PathFindExtensionW StrStrIW #176 StrChrW StrStrW SHSetValueA SHEnumKeyExW SHGetValueA SHEnumValueA |
| COMCTL32.dll |
_TrackMouseEvent
|
| MSIMG32.dll |
AlphaBlend
|
| gdiplus.dll |
GdipGetFontStyle
GdipGetFontSize GdipGetFamily GdipGetPathWorldBounds GdipAddPathString GdipDeletePath GdipCreatePath GdipSetStringFormatFlags GdipCreateFontFromDC GdipCreateFontFromLogfontW GdipCreateHBITMAPFromBitmap GdipBitmapGetPixel GdipBitmapSetPixel GdipCreateBitmapFromFile GdipCreateBitmapFromFileICM GdipDrawArcI GdipFillRectangle GdipCloneBitmapAreaI GdipCreateBitmapFromStreamICM GdipCreateBitmapFromStream GdipGetPropertyItem GdipGetPropertyItemSize GdipImageSelectActiveFrame GdipImageGetFrameCount GdipImageGetFrameDimensionsList GdipImageGetFrameDimensionsCount GdiplusStartup GdiplusShutdown GdipDrawImageRectRect GdipFillEllipse GdipGetImageEncoders GdipGetImageEncodersSize GdipCreateBitmapFromScan0 GdipGetImageHeight GdipGetImageWidth GdipSaveImageToFile GdipCloneImage GdipDisposeImage GdipLoadImageFromStreamICM GdipLoadImageFromStream GdipDrawImageRectRectI GdipSetInterpolationMode GdipGetImageGraphicsContext GdipCloneFont GdipReleaseDC GdipGetDC GdipSetStringFormatTrimming GdipSetStringFormatAlign GdipSetSolidFillColor GdipTranslateMatrix GdipMultiplyMatrix GdipGetMatrixElements GdipDeleteMatrix GdipCreateMatrix2 GdipCreateMatrix GdipDeleteFont GdipDeleteFontFamily GdipGetGenericFontFamilySansSerif GdipCreateFontFamilyFromName GdipCreateFont GdipDrawString GdipFillRectangleI GdipDrawLineI GdipSetSmoothingMode GdipDeleteGraphics GdipCreateFromHDC GdipSetStringFormatLineAlign GdipDeleteStringFormat GdipCreateStringFormat GdipDeletePen GdipCreatePen1 GdipCloneBrush GdipDeleteBrush GdipCreateSolidFill GdipAlloc GdipFree |
| CRYPT32.dll |
CryptStringToBinaryW
CryptUnprotectData CertGetNameStringW |
| IPHLPAPI.DLL |
GetAdaptersAddresses
DeleteIPAddress GetBestInterfaceEx GetBestInterface SendARP GetIpNetTable GetIfTable GetNetworkParams GetAdaptersInfo |
| SETUPAPI.dll |
CM_Get_Device_IDW
SetupIterateCabinetW CM_Get_DevNode_Status CM_Locate_DevNodeW CM_Request_Device_EjectW SetupDiDestroyDeviceInfoList SetupDiGetDeviceInstanceIdW SetupDiEnumDeviceInfo SetupDiGetClassDevsW SetupDiEnumDeviceInterfaces SetupDiGetDeviceInterfaceDetailW SetupDiCallClassInstaller CM_Get_Sibling CM_Get_Parent CM_Get_Child CM_Reenumerate_DevNode SetupDiGetDeviceInstallParamsW SetupDiGetDeviceRegistryPropertyW SetupDiSetClassInstallParamsW |
| WININET.dll |
InternetCloseHandle
HttpQueryInfoW InternetOpenW InternetOpenUrlW InternetReadFile |
| WS2_32.dll |
select
inet_addr ntohl inet_ntoa htonl ntohs WSAStartup setsockopt ioctlsocket socket WSACloseEvent closesocket bind htons getsockopt WSAGetLastError connect listen accept send recv WSAEnumNetworkEvents WSAWaitForMultipleEvents WSAEventSelect WSACreateEvent recvfrom sendto gethostbyname gethostname WSACleanup getsockname __WSAFDIsSet |
| PSAPI.DLL |
EnumProcesses
GetModuleFileNameExW GetModuleBaseNameW EnumProcessModules |
| WINTRUST.dll |
WinVerifyTrust
WTHelperProvDataFromStateData |
| WINMM.dll |
timeKillEvent
timeEndPeriod timeGetDevCaps timeBeginPeriod timeSetEvent |
| NETAPI32.dll |
Netbios
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.3.0.5000 |
| ProductVersion | 5.3.0.5000 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | Chinese - PRC |
| CompanyName | 360.cn |
| FileDescription | 360WiFi |
| FileVersion (#2) | 5, 3, 0, 5000 |
| InternalName | 360AP.exe |
| LegalCopyright | (C) 360.cn Inc. All Rights Reserved. |
| OriginalFilename | 360AP.exe |
| ProductName | 360WiFi |
| ProductVersion (#2) | 5, 3, 0, 5000 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Jan-07 03:05:16 |
| Version | 0.0 |
| SizeofData | 88 |
| AddressOfRawData | 0x3dfe58 |
| PointerToRawData | 0x3dea58 |
| Referenced File | C:\vmagent_new\bin\joblist\319990\out\Release\Release\360AP.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x83ca5c |
| SEHandlerTable | 0x7ec0b0 |
| SEHandlerCount | 2721 |
| XOR Key | 0xa9657543 |
|---|---|
| Unmarked objects | 0 |
| 150 (20413) | 8 |
| ASM objects (VS2008 SP1 build 30729) | 61 |
| C++ objects (VS2008 build 21022) | 4 |
| 138 (VS2008 SP1 build 30729) | 32 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 136 |
| C objects (VS2012 UPD3 build 60610) | 6 |
| C objects (VS2008 SP1 build 30729) | 270 |
| Imports (VS2008 SP1 build 30729) | 47 |
| Total imports | 682 |
| C++ objects (VS2008 SP1 build 30729) | 413 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.