Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1999-Sep-18 14:56:27 |
Detected languages |
English - United States
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Suspicious | This PE is packed with Ramnit |
Unusual section name found: .itext
Unusual section name found: .didata Section .rsrc is both writable and executable. Unusual section name found: .rmnet Section .rmnet is both writable and executable. |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 62/69 (Scanned on 2021-05-17 13:19:15) |
Bkav:
W32.RammitNNA.PE
Lionic: Virus.Win32.Renamer.lCUC Elastic: malicious (high confidence) ClamAV: Win.Virus.Tainp-1 CAT-QuickHeal: W32.Ramnit.A McAfee: W32/Ramnit.q Cylance: Unsafe VIPRE: Virus.Win32.Ramnit.a (v) Sangfor: Win.Trojan.Ramnit-1847 K7AntiVirus: Virus ( 0040f9341 ) BitDefender: Trojan.GenericKD.36861208 K7GW: Virus ( 0040f9341 ) CrowdStrike: win/malicious_confidence_100% (W) Baidu: Win32.Virus.Nimnul.a Cyren: W32/Ramnit.B!Generic Symantec: W32.Tapin ESET-NOD32: Win32/Ramnit.A APEX: Malicious Paloalto: generic.ml Cynet: Malicious (score: 100) Kaspersky: Virus.Win32.Nimnul.a Alibaba: Virus:Win32/Ramnit.gen2 NANO-Antivirus: Virus.Win32.Ramnit.eslalb MicroWorld-eScan: Trojan.GenericKD.36861208 Avast: Win32:RmnDrp [Inf] Tencent: Virus.Win32.Nimnul.d Ad-Aware: Trojan.GenericKD.36861208 Emsisoft: Trojan.GenericKD.36861208 (B) Comodo: Virus.Win32.Ramnit.A@1xq65p DrWeb: Trojan.DownLoad4.10434 Zillya: Virus.Nimnul.Win32.1 TrendMicro: PE_RAMNIT.H McAfee-GW-Edition: BehavesLike.Win32.Ramnit.ch FireEye: Generic.mg.4449499ea8961c76 Sophos: Mal/Generic-R + W32/Patched-I Ikarus: Virus.Win32.Renamer GData: Win32.Virus.Ramnit.C Jiangmin: Win32/PatchFile.et Avira: W32/Ramnit.CD Kingsoft: Win32.Infected.Ramnit.sr.(kcloud) Gridinsoft: Trojan.Win32.Delf.ko!s1 Arcabit: Trojan.Generic.D2327518 ViRobot: Win32.Ramnit.E ZoneAlarm: Virus.Win32.Nimnul.a Microsoft: Virus:Win32/Grenam.B TACHYON: Virus/W32.Ramnit.B AhnLab-V3: Win32/Ramnit.B Acronis: suspicious BitDefenderTheta: AI:FileInfector.EAEEA7850C ALYac: Trojan.GenericKD.36861208 MAX: malware (ai score=81) VBA32: Virus.Win32.Nimnul.a Malwarebytes: Renamer.Virus.FileInfector.DDS Zoner: Trojan.Win32.66255 TrendMicro-HouseCall: PE_RAMNIT.H Rising: Trojan.Win32.StealIcon!1.6A68 (CLOUD) SentinelOne: Static AI - Malicious PE Fortinet: W32/Autorun.LV!tr MaxSecure: Virus.Nimnul.A AVG: Win32:RmnDrp [Inf] Cybereason: malicious.ea8961 Panda: W32/Cosmu.gen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 11 |
TimeDateStamp | 1999-Sep-18 14:56:27 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0xaaa00 |
SizeOfInitializedData | 0x23400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000DB000 (Section: .rmnet) |
BaseOfCode | 0x1000 |
BaseOfData | 0xac000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xea000 |
SizeOfHeaders | 0x400 |
Checksum | 0xdedee |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
---|---|
advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
user32.dll |
LoadStringW
MessageBoxA CharNextW |
kernel32.dll |
lstrcmpiA
LoadLibraryA LocalFree LocalAlloc GetACP Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW IsValidLocale GetSystemDefaultUILanguage GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetUserDefaultUILanguage GetLocaleInfoW GetLastError GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection CreateFileW CloseHandle |
kernel32.dll (#2) |
lstrcmpiA
LoadLibraryA LocalFree LocalAlloc GetACP Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW IsValidLocale GetSystemDefaultUILanguage GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetUserDefaultUILanguage GetLocaleInfoW GetLastError GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection CreateFileW CloseHandle |
user32.dll (#2) |
LoadStringW
MessageBoxA CharNextW |
msimg32.dll |
AlphaBlend
|
gdi32.dll |
UnrealizeObject
StretchDIBits StretchBlt StartPage StartDocW SetWindowOrgEx SetViewportOrgEx SetTextColor SetStretchBltMode SetROP2 SetPixel SetDIBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SetAbortProc SelectPalette SelectObject SaveDC RoundRect RestoreDC Rectangle RectVisible RealizePalette Polyline Polygon PolyBezierTo PolyBezier Pie PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetTextMetricsW GetTextExtentPoint32W GetSystemPaletteEntries GetStockObject GetRgnBox GetPixel GetPaletteEntries GetObjectW GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits FrameRgn ExtTextOutW ExtFloodFill ExcludeClipRect EnumFontsW EnumFontFamiliesExW EndPage EndDoc Ellipse DeleteObject DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateICW CreateHalftonePalette CreateFontIndirectW CreateDIBitmap CreateDIBSection CreateDCW CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap Chord BitBlt Arc AbortDoc |
version.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
kernel32.dll (#3) |
lstrcmpiA
LoadLibraryA LocalFree LocalAlloc GetACP Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW IsValidLocale GetSystemDefaultUILanguage GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetUserDefaultUILanguage GetLocaleInfoW GetLastError GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection CreateFileW CloseHandle |
advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
ole32.dll |
OleUninitialize
OleInitialize CoTaskMemFree StringFromCLSID CoCreateInstance CoUninitialize CoInitialize |
comctl32.dll |
InitializeFlatSB
FlatSB_SetScrollProp FlatSB_SetScrollPos FlatSB_SetScrollInfo FlatSB_GetScrollPos FlatSB_GetScrollInfo _TrackMouseEvent ImageList_GetImageInfo ImageList_SetIconSize ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Copy ImageList_LoadImageW ImageList_GetIcon ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_SetOverlayImage ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_SetImageCount ImageList_GetImageCount ImageList_Destroy ImageList_Create |
kernel32.dll (#4) |
lstrcmpiA
LoadLibraryA LocalFree LocalAlloc GetACP Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW IsValidLocale GetSystemDefaultUILanguage GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetUserDefaultUILanguage GetLocaleInfoW GetLastError GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection CreateFileW CloseHandle |
oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
shell32.dll |
ShellExecuteW
ExtractIconW |
shell32.dll (#2) |
ShellExecuteW
ExtractIconW |
winspool.drv |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
winspool.drv (#2) |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
There is no default printer currently selected |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
Error loading dock zone from the stream. Expecting version %d, but found %d. |
OLE error %.8x |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
Dispatch methods do not support more than 64 parameters |
Space |
PgUp |
PgDn |
End |
Home |
Left |
Up |
Right |
Down |
Ins |
Del |
Shift+ |
Ctrl+ |
Alt+ |
Clipboard does not support Icons |
Operation not supported on selected printer |
&Yes |
&No |
OK |
Cancel |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
Yes to &All |
&Close |
BkSp |
Tab |
Esc |
Enter |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
Printer is not currently printing |
Printing in progress |
Printer index out of range |
Printer selected is not valid |
%s on %s |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
Cannot drag a form |
Warning |
Error |
Information |
Confirm |
Canvas does not allow drawing |
Invalid image size |
Invalid ImageList |
Unable to Replace Image |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Parent given is not a parent of '%s' |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Cannot make a visible window modal |
Menu index out of range |
No help viewer that supports filters |
Invalid Timeout value: %s |
''%s'' is not a valid integer value |
No context-sensitive help installed |
No help found for context |
Unable to open Index |
Unable to open Search |
Unable to find a Table of Contents |
No topic-based help system installed |
No help found for %s |
Bitmap image is not valid |
Icon image is not valid |
Invalid pixel format |
Cannot change the size of an icon |
Unsupported clipboard format |
Out of system resources |
Property is read-only |
Failed to create key %s |
Failed to get data for '%s' |
Failed to set data for '%s' |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
%s not in a class registration group |
Property %s does not exist |
Stream write error |
Thread creation error: %s |
Thread Error: %s (%d) |
Cannot terminate an externally created thread |
Cannot wait for an externally created thread |
Cannot call Start on a running or suspended thread |
The specified file was not found |
Cannot create file "%s". %s |
Cannot open file "%s". %s |
Invalid file name - %s |
Invalid stream format |
''%s'' is not a valid component name |
Invalid property value |
Invalid property path |
Invalid property value |
Invalid data type for '%s' |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
%s has not been registered as a COM class |
Error reading %s%s%s: %s |
Stream read error |
Invalid destination array |
Character index out of bounds (%d) |
Start index out of bounds (%d) |
Invalid count (%d) |
Invalid destination index (%d) |
Invalid code page |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Can't write to a read-only resource stream |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Invalid source array |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
Interface not supported |
Exception in safecall method |
Object lock not owned |
Monitor support function not initialized |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Invalid variant operation |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Custom variant type (%s%.4x) is out of range |
Custom variant type (%s%.4x) already used by %s |
Custom variant type (%s%.4x) is not usable |
Too many custom variant types have been registered |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
Invalid variant type conversion |
Out of memory |
I/O error %d |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
StartAddressOfRawData | 0x4ba000 |
---|---|
EndAddressOfRawData | 0x4ba03c |
AddressOfIndex | 0x4aca34 |
AddressOfCallbacks | 0x4bb010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |