| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2013-Mar-13 22:11:48 |
| Detected languages |
English - United States
|
| FileVersion | 1.1.09.04 |
| ProductVersion | 1.1.09.04 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/61 (Scanned on 2020-10-26 05:02:53) | VBA32: Trojan.Downloader |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2013-Mar-13 22:11:48 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x98a00 |
| SizeOfInitializedData | 0x8d800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0008BDB3 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x9a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x130000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xd72bf |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WSOCK32.dll |
WSACleanup
inet_addr gethostbyname gethostname WSAStartup |
|---|---|
| WINMM.dll |
mixerSetControlDetails
waveOutGetVolume joyGetPosEx mixerGetControlDetailsW mixerOpen mixerGetDevCapsW mixerGetLineControlsW waveOutSetVolume mixerClose mciSendStringW joyGetDevCapsW mixerGetLineInfoW |
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
| COMCTL32.dll |
ImageList_Create
CreateStatusWindowW ImageList_ReplaceIcon #17 ImageList_GetIconSize ImageList_Destroy ImageList_AddMasked |
| PSAPI.DLL |
GetModuleBaseNameW
GetModuleFileNameExW |
| KERNEL32.dll |
FindNextFileW
FindClose FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW WideCharToMultiByte MultiByteToWideChar GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess TerminateProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW SetErrorMode GetDiskFreeSpaceW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW CreateDirectoryW ReadFile WriteFile GlobalSize DeleteFileW SetFileAttributesW LocalFileTimeToFileTime SetFileTime GetSystemTime GetComputerNameW GetWindowsDirectoryW GetTempPathW GetFullPathNameW GetShortPathNameW FindFirstFileW FreeLibrary EnterCriticalSection LeaveCriticalSection VirtualProtect QueryDosDeviceW CompareStringW RemoveDirectoryW CopyFileW GetCurrentProcess FormatMessageW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType SetFilePointerEx GetFileSizeEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW IsValidCodePage GetOEMCP InterlockedDecrement InterlockedIncrement GetStartupInfoW HeapSetInformation GetCommandLineW HeapQueryInformation HeapSize HeapFree HeapReAlloc ExitProcess HeapAlloc UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetStdHandle HeapCreate InitializeCriticalSectionAndSpinCount LockResource LoadResource SizeofResource FindResourceW GetSystemTimeAsFileTime MulDiv GetModuleFileNameW DeleteCriticalSection GetCPInfo GetVersionExW GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock GetModuleHandleW GetProcAddress GetCurrentDirectoryW InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount TlsAlloc TlsGetValue TlsSetValue SetHandleCount IsProcessorFeaturePresent GetStringTypeW LCMapStringW RaiseException RtlUnwind GetConsoleCP GetConsoleMode FreeEnvironmentStringsW GetEnvironmentStringsW TlsFree QueryPerformanceCounter SetFilePointer FlushFileBuffers WriteConsoleW SetStdHandle GetProcessHeap LoadLibraryW VirtualQuery |
| USER32.dll |
GetMenuStringW
IsWindowEnabled ExitWindowsEx SetMenu FlashWindow MapWindowPoints RedrawWindow SetParent UpdateWindow GetMessagePos GetClassLongW DefDlgProcW CallWindowProcW CheckRadioButton IntersectRect PtInRect CreateAcceleratorTableW DestroyAcceleratorTable AppendMenuW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu CreateMenu CreatePopupMenu SetMenuInfo DestroyMenu TrackPopupMenuEx CreateIconIndirect GetDesktopWindow CopyImage LookupIconIdFromDirectoryEx CreateIconFromResourceEx GetWindow BringWindowToTop GetTopWindow SetRect GetIconInfo SetWindowTextW IsWindowVisible CheckMenuItem MessageBoxW SetClipboardViewer LoadAcceleratorsW ReleaseDC GetSubMenu EnableMenuItem GetMenu RegisterClassExW LoadCursorW LoadImageW ChangeClipboardChain DestroyIcon DestroyWindow IsCharAlphaW MapVirtualKeyW DefWindowProcW GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharUpperW IsCharLowerW IsCharAlphaNumericW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW EndDialog IsWindow GetMenuItemID GetMenuItemCount GetCursor ClientToScreen GetCaretPos EnumClipboardFormats MessageBeep SetDlgItemTextW GetDlgItem SendDlgItemMessageW DialogBoxParamW GetDC SetForegroundWindow DispatchMessageW TranslateMessage ShowWindow CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW SendMessageW GetWindowLongW GetKeyState FillRect DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW IsIconic IsZoomed EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetWindowPos SetWindowRgn SetFocus SetActiveWindow EnumChildWindows MoveWindow GetQueueStatus GetWindowRect GetClientRect SystemParametersInfoW TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable AdjustWindowRectEx VkKeyScanExW DrawTextW CreateWindowExW |
| GDI32.dll |
FillRgn
GetClipBox SetBkMode EnumFontFamiliesExW CreateDIBSection GdiFlush ExcludeClipRect SetTextColor SetBkColor GetPixel BitBlt CreateCompatibleBitmap GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush GetDeviceCaps GetClipRgn DeleteObject CreateFontW |
| COMDLG32.dll |
GetOpenFileNameW
CommDlgExtendedError GetSaveFileNameW |
| ADVAPI32.dll |
RegDeleteKeyW
RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW RegDeleteValueW |
| SHELL32.dll |
DragQueryPoint
SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW ExtractIconW |
| ole32.dll |
OleInitialize
OleUninitialize CoInitialize CoCreateInstance CoUninitialize CLSIDFromString CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
| OLEAUT32.dll |
SafeArrayGetDim
GetActiveObject OleLoadPicture SafeArrayUnaccessData SafeArrayAccessData SafeArrayUnlock VariantCopy SafeArrayGetElemsize SafeArrayPtrOfIndex SafeArrayLock SafeArrayDestroy SafeArrayGetLBound SafeArrayGetUBound SafeArrayCopy SysAllocString VariantChangeType VariantClear SafeArrayCreate SysFreeString SysStringLen |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.9.4 |
| ProductVersion | 1.1.9.4 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 1.1.09.04 |
| ProductVersion (#2) | 1.1.09.04 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x80c965d3 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 SP1 build 40219) | 51 |
| C objects (VS2010 SP1 build 40219) | 139 |
| C objects (VS2008 SP1 build 30729) | 7 |
| Imports (VS2008 SP1 build 30729) | 27 |
| Total imports | 428 |
| ASM objects (VS2010 SP1 build 40219) | 29 |
| 175 (VS2010 SP1 build 40219) | 42 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.