Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Feb-05 08:20:39 |
Detected languages |
English - United States
|
ProductVersion | 3.0.940 |
FileVersion | 3.0.940 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Abacus Research AG
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Suspicious | VirusTotal score: 2/70 (Scanned on 2023-05-11 06:56:48) |
tehtris:
Generic.Malware
CrowdStrike: win/grayware_confidence_60% (D) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2020-Feb-05 08:20:39 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x42a00 |
SizeOfInitializedData | 0x3a400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001CF3E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x44000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x80000 |
SizeOfHeaders | 0x400 |
Checksum | 0x8f0e5 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
VirtualQuery
WriteConsoleW GetSystemInfo CreateFileW ReadConsoleW SetStdHandle GlobalMemoryStatusEx GetCurrentProcessId GetCurrentProcess SetConsoleCtrlHandler WideCharToMultiByte SetDllDirectoryW LoadLibraryW GetProcAddress GetModuleHandleW FreeLibrary SetErrorMode GetLastError HeapSize GetModuleFileNameW GetProcessHeap MultiByteToWideChar GetStringTypeW EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetLastError InitializeCriticalSectionAndSpinCount CreateEventW SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime EncodePointer DecodePointer CompareStringW LCMapStringW GetLocaleInfoW GetCPInfo CloseHandle SetEvent ResetEvent WaitForSingleObjectEx UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentThreadId InitializeSListHead RaiseException RtlUnwind LoadLibraryExW ExitProcess GetModuleHandleExW GetDriveTypeW GetFullPathNameW SetEnvironmentVariableW SetCurrentDirectoryW GetCurrentDirectoryW FindClose FindFirstFileExW FindNextFileW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime GetStdHandle WriteFile HeapFree GetFileType GetFileSizeEx SetFilePointerEx FlushFileBuffers GetConsoleCP GetConsoleMode ReadFile HeapAlloc IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapReAlloc GetTimeZoneInformation IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEndOfFile |
---|---|
USER32.dll |
MessageBoxW
CreateWindowExW DestroyWindow |
ADVAPI32.dll |
RegQueryValueExW
RegOpenKeyExW RegEnumKeyExW RegCloseKey StartServiceCtrlDispatcherW SetServiceStatus RegisterServiceCtrlHandlerW |
SHELL32.dll |
CommandLineToArgvW
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0 |
FileVersion | 3.0.940.0 |
ProductVersion | 3.0.940.0 |
FileFlags | (EMPTY) |
FileOs | (EMPTY) |
FileType |
VFT_APP
|
Language | English - United States |
ProductVersion (#2) | 3.0.940 |
FileVersion (#2) | 3.0.940 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Feb-05 08:20:39 |
Version | 0.0 |
SizeofData | 920 |
AddressOfRawData | 0x54070 |
PointerToRawData | 0x52e70 |
StartAddressOfRawData | 0x454418 |
---|---|
EndAddressOfRawData | 0x454420 |
AddressOfIndex | 0x459d1c |
AddressOfCallbacks | 0x4442d0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa4 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4585c4 |
SEHandlerTable | 0x453eb0 |
SEHandlerCount | 112 |
XOR Key | 0x9c211626 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v14.15 compiler 26715) | 14 |
C++ objects (VS2017 v14.15 compiler 26715) | 180 |
C objects (VS2017 v14.15 compiler 26715) | 22 |
C objects (26504) | 18 |
ASM objects (26504) | 22 |
C++ objects (26504) | 80 |
Imports (VS2017 v14.15 compiler 26715) | 9 |
Total imports | 118 |
C++ objects (VS2019 Update 2 (16.2) compiler 27905) | 13 |
Resource objects (VS2019 Update 2 (16.2) compiler 27905) | 1 |
151 | 1 |
Linker (VS2019 Update 2 (16.2) compiler 27905) | 1 |