Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Jul-11 18:26:59 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 DLL (Debug) Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ 6.0 DLL |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 39/66 (Scanned on 2019-09-08 22:57:39) |
MicroWorld-eScan:
Gen:Variant.Zusy.290462
FireEye: Generic.mg.3edce4d49a2f31b8 ALYac: Gen:Variant.Zusy.290462 Cylance: Unsafe BitDefender: Gen:Variant.Zusy.290462 K7GW: Trojan ( 0052cf421 ) CrowdStrike: win/malicious_confidence_100% (W) Arcabit: Trojan.Zusy.D46E9E TrendMicro: TROJ_GEN.R002C0DI819 ESET-NOD32: a variant of Win32/NukeSped.AU Paloalto: generic.ml Kaspersky: HEUR:Trojan.Win32.Generic Alibaba: Trojan:Win32/Autophyte.172408e5 AegisLab: Trojan.Win32.Generic.4!c Avast: FileRepMalware Tencent: Win32.Trojan.Generic.Lpce Ad-Aware: Gen:Variant.Zusy.290462 Sophos: Mal/Generic-S Invincea: heuristic McAfee-GW-Edition: Trojan-HidCobra Trapmine: suspicious.low.ml.score Emsisoft: Gen:Variant.Zusy.290462 (B) SentinelOne: DFI - Suspicious PE Jiangmin: Trojan.Generic.bllix Avira: TR/NukeSped.bqdkl Endgame: malicious (high confidence) Microsoft: Trojan:Win32/Autophyte.E!dha ZoneAlarm: HEUR:Trojan.Win32.Generic GData: Gen:Variant.Zusy.290462 AhnLab-V3: Trojan/Win32.Akdoor.R206569 McAfee: Trojan-HidCobra MAX: malware (ai score=84) TrendMicro-HouseCall: TROJ_GEN.R002C0DI819 Rising: Trojan.Agent!8.B1E (TFE:6:TEbwi7SsEO) Ikarus: Trojan.Win32.NukeSped Fortinet: W32/Generic.AU!tr AVG: FileRepMalware Panda: Trj/GdSda.A Qihoo-360: Win32/Trojan.e6d |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2017-Jul-11 18:26:59 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x1d000 |
SizeOfInitializedData | 0x9000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001D83A (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1e000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x27000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetProcessHeap
VirtualAlloc VirtualProtect VirtualFree IsBadReadPtr HeapFree FreeLibrary CloseHandle CreateThread LocalFree FreeLibraryAndExitThread Sleep ReadFile LocalAlloc GetFileSize CreateFileW GetSystemDirectoryW HeapAlloc GetVolumeInformationW Module32FirstW CreateToolhelp32Snapshot FileTimeToLocalFileTime GetTickCount GetSystemInfo GetVersionExW WideCharToMultiByte CreateDirectoryW CopyFileW FileTimeToSystemTime GetACP lstrlenW FindFirstFileW LoadLibraryA GetModuleHandleW GetProcAddress FindNextFileW GetLastError FindClose UnmapViewOfFile WriteFile GetCurrentProcess DuplicateHandle CreateFileMappingW MapViewOfFile GetFileType GetFileInformationByHandle GetSystemTime GetLocalTime SystemTimeToFileTime SetFilePointer FileTimeToDosDateTime |
---|---|
USER32.dll |
GetSystemMetrics
|
ADVAPI32.dll |
SetServiceStatus
RegisterServiceCtrlHandlerW |
SHLWAPI.dll |
SHDeleteKeyW
|
MSVCRT.dll |
_wcsicmp
rand srand __CxxFrameHandler fclose fwprintf _wfopen wcsrchr wcstombs memcpy strlen memset memmove memcmp malloc strstr sscanf localtime time mktime ??2@YAPAXI@Z _EH_prolog strcat strcpy _stricmp _tzset __dllonexit _onexit _initterm _adjust_fdiv wcscat wcsncpy swprintf _wtoi _waccess wcscpy wcslen _vsnwprintf wcscmp wcsncmp free realloc strncmp ??3@YAXPAX@Z wcschr |
Ordinal | 1 |
---|---|
Address | 0x7b30 |
Ordinal | 2 |
---|---|
Address | 0x7a90 |
Ordinal | 3 |
---|---|
Address | 0x7bb0 |
XOR Key | 0x7073cdf1 |
---|---|
Unmarked objects | 0 |
14 (7299) | 5 |
12 (7291) | 3 |
Imports (VS2003 (.NET) build 4035) | 9 |
Total imports | 115 |
C objects (VS98 build 8168) | 19 |
C++ objects (VS98 build 8168) | 10 |
Linker (VS98 build 8168) | 3 |