Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2014-Dec-04 06:07:41 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\Malware\Desktop\kaizen\November\cryptorLv1_1\Release\cryptorLv1_w.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains a base64-encoded executable:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/66 (Scanned on 2018-02-26 16:03:25) |
Invincea:
heuristic
Endgame: malicious (moderate confidence) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2014-Dec-04 06:07:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x13000 |
SizeOfInitializedData | 0x13000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000651B (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x14000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x2a000 |
SizeOfHeaders | 0x400 |
Checksum | 0x2e6df |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LoadLibraryW
Sleep InterlockedIncrement InterlockedDecrement InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection EncodePointer DecodePointer GetLastError HeapFree GetCommandLineW HeapSetInformation RaiseException RtlUnwind HeapAlloc WideCharToMultiByte LCMapStringW MultiByteToWideChar GetCPInfo TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent IsProcessorFeaturePresent HeapSize GetProcAddress GetModuleHandleW ExitProcess GetACP GetOEMCP IsValidCodePage TlsAlloc TlsGetValue TlsSetValue TlsFree SetLastError GetCurrentThreadId HeapCreate SetHandleCount GetStdHandle InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW WriteFile GetConsoleCP GetConsoleMode SetFilePointer ReadFile FlushFileBuffers CloseHandle GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetUserDefaultLCID GetLocaleInfoW GetLocaleInfoA EnumSystemLocalesA IsValidLocale GetStringTypeW HeapReAlloc WriteConsoleW SetStdHandle CreateFileA CreateFileW SetEndOfFile GetProcessHeap |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2014-Dec-04 06:07:41 |
Version | 0.0 |
SizeofData | 103 |
AddressOfRawData | 0x17130 |
PointerToRawData | 0x16530 |
Referenced File | C:\Users\Malware\Desktop\kaizen\November\cryptorLv1_1\Release\cryptorLv1_w.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x419494 |
SEHandlerTable | 0x417a40 |
SEHandlerCount | 29 |
XOR Key | 0xd95ad367 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2010 SP1 build 40219) | 17 |
C++ objects (VS2010 SP1 build 40219) | 44 |
C objects (VS2010 SP1 build 40219) | 116 |
Imports (VS2008 SP1 build 30729) | 3 |
Total imports | 79 |
175 (VS2010 SP1 build 40219) | 3 |
Linker (VS2010 SP1 build 40219) | 1 |