Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-May-19 20:44:05 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 9/60 (Scanned on 2017-05-24 02:47:23) |
MicroWorld-eScan:
Gen:Variant.Graftor.372078
ALYac: Gen:Variant.Graftor.372078 AegisLab: Gen.Variant.Graftor!c Arcabit: Trojan.Graftor.D5AD6E BitDefender: Gen:Variant.Graftor.372078 Ad-Aware: Gen:Variant.Graftor.372078 Emsisoft: Gen:Variant.Graftor.372078 (B) F-Secure: Gen:Variant.Graftor.372078 GData: Gen:Variant.Graftor.372078 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2017-May-19 20:44:05 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1e4a00 |
SizeOfInitializedData | 0x9e600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000CC0EB (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1e6000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x28f000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.DLL |
CloseHandle
CreateToolhelp32Snapshot Process32First Process32Next Thread32First Thread32Next WideCharToMultiByte ReadProcessMemory CreateDirectoryA GetModuleHandleA GetThreadContext SetThreadContext SuspendThread ResumeThread WaitForDebugEvent ContinueDebugEvent DebugActiveProcess DebugActiveProcessStop DebugSetProcessKillOnExit ReleaseMutex WaitForSingleObject CreateMutexA GetSystemTime CreateProcessA DeleteFileA Beep GetModuleHandleW SetConsoleCtrlHandler OpenProcess VirtualProtectEx VirtualFreeEx FindNextFileA FindFirstFileA LoadLibraryA FindClose Sleep GetCurrentThreadId TerminateProcess GetCurrentProcess MultiByteToWideChar GlobalFree GlobalAlloc GetModuleFileNameA InitializeCriticalSection LoadLibraryExA HeapSize SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA WriteProcessMemory IsValidCodePage FindFirstFileExA GetProcessHeap SetStdHandle MoveFileExW DeleteFileW GetTimeZoneInformation CreatePipe GetFileAttributesExW GetExitCodeProcess SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetTimeFormatW GetDateFormatW GetACP WriteFile ExitThread SystemTimeToFileTime TzSpecificLocalTimeToSystemTime SetFileTime CreateFileW WriteConsoleW GetFileType GetStdHandle GetModuleHandleExW GetLastError GetProcAddress ExitProcess GetTempPathW ReadFile RtlUnwind RaiseException LoadLibraryW UnregisterWaitEx QueryDepthSList GetOEMCP OpenThread InterlockedFlushSList InterlockedPushEntrySList FreeLibrary SetEndOfFile FormatMessageA DuplicateHandle WaitForSingleObjectEx GetCurrentThread GetExitCodeThread EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection DeleteCriticalSection QueryPerformanceCounter QueryPerformanceFrequency EncodePointer DecodePointer SetLastError InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo SetEvent ResetEvent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcessId InitializeSListHead GlobalLock GlobalUnlock GlobalMemoryStatusEx LocalFree TerminateThread SetCurrentDirectoryA GetCurrentDirectoryA SetDllDirectoryA RemoveDirectoryA SetFileAttributesA GetFileAttributesA GetVolumeInformationA GetComputerNameA IsWow64Process AllocConsole FreeConsole Module32First Module32Next VirtualProtect VirtualQuery VirtualAllocEx CreateRemoteThread AddVectoredExceptionHandler HeapAlloc HeapReAlloc HeapFree VirtualAlloc VirtualFree CreateTimerQueue SignalObjectAndWait SwitchToThread CreateThread SetThreadPriority GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait OutputDebugStringW GetThreadTimes FreeLibraryAndExitThread GetModuleFileNameW LoadLibraryExW GetVersionExW ReleaseSemaphore InterlockedPopEntrySList GetSystemInfo |
---|---|
ADVAPI32.dll |
GetTokenInformation
CryptGenRandom CryptReleaseContext CryptAcquireContextW RegQueryValueExA RegOpenKeyExA GetCurrentHwProfileA LookupPrivilegeValueA AdjustTokenPrivileges OpenProcessToken |
COMCTL32.dll |
#17
|
COMDLG32.dll |
GetOpenFileNameA
|
GDI32.dll |
CreateFontA
|
IMM32.dll |
ImmSetCompositionWindow
ImmGetContext |
IPHLPAPI.DLL |
GetAdaptersInfo
|
ole32.dll |
OleInitialize
CoGetClassObject OleSetContainedObject |
OLEAUT32.dll |
#9
#8 #2 |
PSAPI.DLL |
GetModuleFileNameExA
GetProcessMemoryInfo |
SHELL32.dll |
ShellExecuteA
|
USER32.dll |
FlashWindow
DefWindowProcA RegisterClassExA CreateWindowExA ShowWindow GetSystemMetrics UpdateWindow GetClientRect GetWindowLongA SetWindowLongA SendMessageA SetWindowPos GetWindowRect IsWindowVisible GetDlgItem SendDlgItemMessageA SetCursorPos EnumDisplayDevicesA DialogBoxParamA CreateDialogParamA GetMessageA LoadImageA GetClassNameA GetKeyState GetFocus KillTimer SetTimer keybd_event PostMessageA SetForegroundWindow LoadCursorA ClientToScreen SetLayeredWindowAttributes DestroyWindow UnregisterClassA GetWindowThreadProcessId DispatchMessageA TranslateMessage SetFocus EndDialog PostQuitMessage SetDlgItemTextA GetForegroundWindow PeekMessageA SendMessageW GetDlgItemTextA OpenClipboard CloseClipboard SetClipboardData GetClipboardData EmptyClipboard mouse_event EnableWindow GetWindowTextA GetWindowTextLengthA MessageBoxA EnumWindows |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
WS2_32.dll |
#9
#11 #13 #52 #116 #115 freeaddrinfo #3 #4 #10 #16 #18 #19 #21 #23 #111 #1 #2 getaddrinfo |
libcef.dll (delay-loaded) |
cef_get_min_log_level
cef_string_utf16_clear cef_string_utf8_to_utf16 cef_string_utf16_to_utf8 cef_string_userfree_utf16_free cef_string_utf16_set cef_string_utf8_clear cef_string_utf16_cmp cef_log cef_string_list_alloc cef_string_list_free cef_browser_host_create_browser cef_currently_on cef_post_task cef_execute_process cef_initialize cef_shutdown cef_run_message_loop cef_quit_message_loop cef_enable_highdpi_support cef_api_hash cef_string_map_alloc cef_string_map_free cef_urlrequest_create cef_string_list_size cef_string_list_value cef_string_list_append cef_string_map_size cef_string_map_key cef_string_map_value cef_string_map_append cef_string_multimap_size cef_string_multimap_key cef_string_multimap_value cef_string_multimap_append cef_string_multimap_alloc cef_string_multimap_free cef_string_list_copy |
Attributes | 0x1 |
---|---|
Name | libcef.dll |
ModuleHandle | 0x2540b4 |
DelayImportAddressTable | 0x2520dc |
DelayImportNameTable | 0x2441cc |
BoundDelayImportTable | 0x244600 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
StartAddressOfRawData | 0x65b000 |
---|---|
EndAddressOfRawData | 0x65c3a0 |
AddressOfIndex | 0x653d5c |
AddressOfCallbacks | 0x5e6790 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x64b2d4 |
SEHandlerTable | 0x631660 |
SEHandlerCount | 779 |
XOR Key | 0xd8351655 |
---|---|
Unmarked objects | 0 |
241 (40116) | 47 |
243 (40116) | 208 |
242 (40116) | 40 |
ASM objects (VS2015 UPD3 build 24123) | 28 |
C objects (VS2015 UPD3 build 24123) | 41 |
C++ objects (VS2015 UPD3 build 24123) | 124 |
C objects (VS2008 SP1 build 30729) | 5 |
Imports (VS2008 SP1 build 30729) | 31 |
Total imports | 451 |
C objects (VS2015 UPD3.1 build 24215) | 69 |
C++ objects (VS2015 UPD3.1 build 24215) | 149 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
151 | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |