Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jan-02 13:49:10 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 47/66 (Scanned on 2018-04-27 01:15:03) |
MicroWorld-eScan:
Trojan.Generic.22846892
CAT-QuickHeal: Worm.Dorkbot.ZZ4 McAfee: Artemis!43552A97AD0A K7AntiVirus: Spyware ( 00505c591 ) K7GW: Spyware ( 00505c591 ) TrendMicro: Ransom_Foreign.R004C0RA718 Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9977 Babable: Malware.HighConfidence Cyren: W32/Trojan.EDHI-6702 Symantec: Packed.Generic.521 TrendMicro-HouseCall: Ransom_Foreign.R004C0RA718 Avast: Win32:Malware-gen Kaspersky: Trojan-Ransom.Win32.Foreign.nxgn BitDefender: Trojan.Generic.22846892 NANO-Antivirus: Trojan.Win32.Kryptik.ewvbph Paloalto: generic.ml AegisLab: Troj.Ransom.W32.Foreign!c Tencent: Win32.Trojan.Foreign.Pavl Ad-Aware: Trojan.Generic.22846892 Emsisoft: Trojan.Generic.22846892 (B) Comodo: UnclassifiedMalware F-Secure: Trojan.Generic.22846892 VIPRE: Trojan.Win32.Generic!BT Invincea: heuristic McAfee-GW-Edition: BehavesLike.Win32.Generic.gh Sophos: Mal/Lethic-L Ikarus: Trojan.Win32.Crypt Jiangmin: Trojan.Foreign.ebn Webroot: W32.Trojan.Gen Avira: TR/Crypt.Xpack.qwmba Antiy-AVL: Trojan[Ransom]/Win32.Foreign Microsoft: TrojanSpy:Win32/Ursnif Endgame: malicious (high confidence) Arcabit: Trojan.Generic.D15C9DAC ZoneAlarm: Trojan-Ransom.Win32.Foreign.nxgn GData: Trojan.Generic.22846892 AhnLab-V3: Spyware/Win32.Ursnif.C2342508 VBA32: TrojanRansom.Foreign AVware: Trojan.Win32.Generic!BT Cylance: Unsafe ESET-NOD32: Win32/Spy.Ursnif.AO Yandex: Trojan.Foreign!uoelU78LXw4 SentinelOne: static engine - malicious Fortinet: W32/Kryptik.GCLM!tr AVG: Win32:Malware-gen Panda: Trj/GdSda.A CrowdStrike: malicious_confidence_100% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2018-Jan-02 13:49:10 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 33.0 |
SizeOfCode | 0x11200 |
SizeOfInitializedData | 0x8ee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00007AA3 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x13000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xa3000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
GetAsyncKeyState
IsDlgButtonChecked ScreenToClient GetMessagePos CallWindowProcW IsWindowVisible LoadBitmapW CloseClipboard SetClipboardData EmptyClipboard OpenClipboard TrackPopupMenu GetWindowRect AppendMenuW CreatePopupMenu GetSystemMetrics EndDialog EnableMenuItem GetSystemMenu SetClassLongW IsWindowEnabled SetWindowPos DialogBoxParamW CheckDlgButton CreateWindowExW SystemParametersInfoW |
---|---|
KERNEL32.dll |
TlsAlloc
SetEnvironmentVariableA CompareStringW CompareStringA CreateFileA SetStdHandle WriteConsoleW GetConsoleOutputCP WriteConsoleA CloseHandle HeapSize SetFilePointer GetLocaleInfoA GetStringTypeW GetStringTypeA LCMapStringW MultiByteToWideChar LCMapStringA FlushFileBuffers GetConsoleMode GetConsoleCP GetProcAddress GetSystemTimeAsFileTime GetCommandLineA GetStartupInfoA EnterCriticalSection LeaveCriticalSection TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent HeapAlloc GetModuleHandleW Sleep ExitProcess WriteFile GetStdHandle GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetLastError GetEnvironmentStringsW SetHandleCount GetFileType DeleteCriticalSection TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapCreate VirtualFree HeapFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetCPInfo GetACP GetOEMCP IsValidCodePage RtlUnwind GetTimeZoneInformation VirtualAlloc HeapReAlloc LoadLibraryA InitializeCriticalSectionAndSpinCount |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4731a8 |
SEHandlerTable | 0x414440 |
SEHandlerCount | 3 |
XOR Key | 0x52986571 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2008 build 21022) | 19 |
C objects (VS2008 build 21022) | 99 |
Imports (VS2008 SP1 build 30729) | 5 |
Total imports | 109 |
C++ objects (VS2008 build 21022) | 32 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 build 21022) | 1 |