Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2005-Feb-10 16:58:29 |
Detected languages |
Russian - Russia
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 127 is possibly compressed or encrypted. |
Suspicious | The file contains overlay data. | 6 bytes of data starting at offset 0x64c00. |
Malicious | VirusTotal score: 9/67 (Scanned on 2021-07-28 18:08:54) |
FireEye:
Generic.mg.4663bba7172a24a9
ESET-NOD32: a variant of Win64/TrojanDownloader.Agent.LG Paloalto: generic.ml Kaspersky: UDS:Backdoor.Win32.Bazdor Jiangmin: Trojan.Shelma.izt Kingsoft: Win32.Troj.Undef.(kcloud) Microsoft: Trojan:Win32/Wacatac.B!ml Cynet: Malicious (score: 100) MaxSecure: Trojan.Malware.300983.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2005-Feb-10 16:58:29 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 219.0 |
SizeOfCode | 0x21200 |
SizeOfInitializedData | 0x44a00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000001845C (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x6a000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FindFirstFileA
FindNextFileA CreateFileA CreatePipe GetProcessHeap GetProcAddress ExitProcess CreateFileW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW RtlUnwindEx InterlockedFlushSList RtlPcToFileHeader RaiseException GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW GetCurrentProcess TerminateProcess GetModuleHandleExW GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte HeapAlloc HeapFree FindClose FindFirstFileExA IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW LCMapStringW GetStdHandle GetFileType GetStringTypeW HeapSize HeapReAlloc SetStdHandle WriteFile FlushFileBuffers GetConsoleCP GetConsoleMode SetFilePointerEx WriteConsoleW CloseHandle |
---|
Ordinal | 1 |
---|---|
Address | 0x9570 |
Ordinal | 2 |
---|---|
Address | 0xa9a0 |
Ordinal | 3 |
---|---|
Address | 0xb350 |
Ordinal | 4 |
---|---|
Address | 0xab90 |
Ordinal | 5 |
---|---|
Address | 0xb2d0 |
Ordinal | 6 |
---|---|
Address | 0xb010 |
Ordinal | 7 |
---|---|
Address | 0xb450 |
Ordinal | 8 |
---|---|
Address | 0xb2e0 |
Ordinal | 9 |
---|---|
Address | 0xa9c0 |
Ordinal | 10 |
---|---|
Address | 0xa9b0 |
Ordinal | 11 |
---|---|
Address | 0xad70 |
Ordinal | 12 |
---|---|
Address | 0xb8b0 |
Ordinal | 13 |
---|---|
Address | 0xaaa0 |
Ordinal | 14 |
---|---|
Address | 0xb540 |
Ordinal | 15 |
---|---|
Address | 0xb6e0 |
Ordinal | 16 |
---|---|
Address | 0xb100 |
Ordinal | 17 |
---|---|
Address | 0xb6f0 |
Ordinal | 18 |
---|---|
Address | 0xb020 |
Ordinal | 19 |
---|---|
Address | 0xb2f0 |
Ordinal | 20 |
---|---|
Address | 0xac80 |
Ordinal | 21 |
---|---|
Address | 0xb430 |
Ordinal | 22 |
---|---|
Address | 0xb110 |
Ordinal | 23 |
---|---|
Address | 0xb610 |
Ordinal | 24 |
---|---|
Address | 0xb330 |
Ordinal | 25 |
---|---|
Address | 0xb2c0 |
Ordinal | 26 |
---|---|
Address | 0xae60 |
Ordinal | 27 |
---|---|
Address | 0xb890 |
Ordinal | 28 |
---|---|
Address | 0xb030 |
Ordinal | 29 |
---|---|
Address | 0xad80 |
Ordinal | 30 |
---|---|
Address | 0xb460 |
Ordinal | 31 |
---|---|
Address | 0xb1e0 |
Ordinal | 32 |
---|---|
Address | 0xaab0 |
Ordinal | 33 |
---|---|
Address | 0xb310 |
Ordinal | 34 |
---|---|
Address | 0xb470 |
Ordinal | 35 |
---|---|
Address | 0xac70 |
Ordinal | 36 |
---|---|
Address | 0xaf40 |
Ordinal | 37 |
---|---|
Address | 0xb7c0 |
Ordinal | 38 |
---|---|
Address | 0xb300 |
Ordinal | 39 |
---|---|
Address | 0xaa90 |
Ordinal | 40 |
---|---|
Address | 0xac90 |
Ordinal | 41 |
---|---|
Address | 0xb320 |
Ordinal | 42 |
---|---|
Address | 0xb8a0 |
Ordinal | 43 |
---|---|
Address | 0xb440 |
Ordinal | 44 |
---|---|
Address | 0xb340 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jul-28 08:53:59 |
Version | 0.0 |
SizeofData | 708 |
AddressOfRawData | 0x2d674 |
PointerToRawData | 0x2bc74 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jul-28 08:53:59 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x100 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x180030790 |
XOR Key | 0xcdfb2b18 |
---|---|
Unmarked objects | 0 |
C objects (23917) | 13 |
ASM objects (23917) | 5 |
C++ objects (23917) | 120 |
C++ objects (VS 2015/2017 runtime 26706) | 32 |
C objects (VS 2015/2017 runtime 26706) | 14 |
ASM objects (VS 2015/2017 runtime 26706) | 8 |
Imports (23917) | 3 |
Total imports | 90 |
Unmarked objects (#2) | 9 |
Exports (27045) | 1 |
Resource objects (27045) | 1 |
Linker (27045) | 1 |