Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2003-Apr-20 15:01:12 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C 5.0 Microsoft Visual C++ |
Suspicious | PEiD Signature: | PeStubOEP v1.x |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. | Resources amount for 79.0699% of the executable. |
Safe | VirusTotal score: 0/68 (Scanned on 2021-04-20 06:04:34) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2003-Apr-20 15:01:12 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x16200 |
SizeOfInitializedData | 0xb0400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00012060 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x18000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xcb000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
COMCTL32.dll |
ImageList_Create
#17 ImageList_AddMasked ImageList_Destroy |
---|---|
KERNEL32.dll |
GetCurrentProcess
GetCurrentThread ResumeThread CreateProcessA CloseHandle WriteFile CreateFileA SetPriorityClass GetModuleFileNameA GetCommandLineA lstrcmpiA GlobalLock GlobalUnlock FindResourceA LoadResource LockResource SizeofResource lstrlenA GetWindowsDirectoryA CreateDirectoryA GetLastError CopyFileA RemoveDirectoryA LoadLibraryA FreeLibrary MultiByteToWideChar lstrcatA lstrcpyA GlobalAlloc DeleteFileA SetThreadPriority GetStringTypeA RtlUnwind GetFileType GetStdHandle SetHandleCount GetOEMCP GetACP GetCPInfo WideCharToMultiByte GetEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter HeapSize TerminateProcess ExitProcess HeapReAlloc VirtualAlloc VirtualFree HeapCreate HeapDestroy GetVersion GetStartupInfoA GetModuleHandleA SetFilePointer GetSystemTime GetTimeZoneInformation GetLocalTime HeapFree GetStringTypeW HeapAlloc SetStdHandle FlushFileBuffers GetProcAddress CompareStringW SetEnvironmentVariableA CompareStringA LCMapStringW LCMapStringA |
USER32.dll |
OpenClipboard
EmptyClipboard DialogBoxParamA CloseClipboard GetFocus SetFocus GetDlgItemTextA ShowWindow SetClipboardData LoadBitmapA SendDlgItemMessageA GetDlgItem SetDlgItemTextA SendMessageA LoadCursorA SetCursor IsDlgButtonChecked MessageBoxA wsprintfA SetWindowTextA ScreenToClient DestroyCursor GetCapture SetCapture PtInRect ReleaseCapture SetWindowLongA RegisterClassA UnregisterClassA GetParent DefWindowProcA GetMenuItemCount DrawTextA BeginPaint GetClientRect CreateDialogParamA EndPaint GetMenuItemInfoA DestroyMenu GetCursorPos TrackPopupMenu GetDlgCtrlID GetWindowLongA CreatePopupMenu InsertMenuItemA SetClassLongA MapWindowPoints InvalidateRect DestroyWindow SetWindowPos GetWindowRect SetScrollPos GetSysColor GetSysColorBrush CheckDlgButton EnableMenuItem DestroyIcon LoadIconA IsWindowEnabled UpdateWindow EndDialog EnableWindow GetDesktopWindow ClientToScreen |
GDI32.dll |
GetStockObject
SetBkColor SetTextColor SetBkMode Ellipse DeleteObject LineTo MoveToEx CreatePen SelectObject CreateFontIndirectA CreateSolidBrush GetObjectA |
ADVAPI32.dll |
RegCloseKey
RegSetValueExA RegCreateKeyExA RegOpenKeyExA RegQueryValueExA RegDeleteKeyA |
SHELL32.dll |
SHGetSpecialFolderLocation
SHBrowseForFolderA CommandLineToArgvW SHGetPathFromIDListA ShellExecuteA |
ole32.dll |
CoInitialize
CoUninitialize CoCreateInstance |
WINMM.dll |
PlaySoundA
|
Acid |
1000 |
Cocaine |
20000 |
Crack |
2000 |
Ecstacy |
1000 |
Hashish |
1000 |
Heroin |
1000 |
Ice |
1000 |
Kat |
1000 |
MDA |
1000 |
Morphine |
1000 |
Mushrooms |
1000 |
Opium |
1000 |
Peyote |
1000 |
Special K |
1000 |
Speed |
1000 |
Weed |
1000 |