| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2010-Jun-19 17:59:16 |
| Detected languages |
English - United States
|
| Comments | username=pc_name;server=demo.echovnc.com;password=demo2010 |
| CompanyName | Echogent Systems, Inc. |
| FileDescription | InstantVNC |
| FileVersion | 1, 42, 0, 0 |
| InternalName | InstantVNC |
| LegalCopyright | Copyright 2005-2010; Echogent Systems, Inc. |
| OriginalFilename | InstantVNC.exe |
| ProductName | InstantVNC |
| ProductVersion | 1, 42, 0, 0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 80.009% of the executable. |
| Suspicious | The file contains overlay data. |
4294 bytes of data starting at offset 0x9da00.
The overlay data has an entropy of 7.518 and is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 5/72 (Scanned on 2025-09-29 14:17:13) |
APEX:
Malicious
Bkav: W32.AIDetectMalware CrowdStrike: win/malicious_confidence_70% (W) DeepInstinct: MALICIOUS Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2010-Jun-19 17:59:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x17400 |
| SizeOfInitializedData | 0x86200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000CEBD (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x19000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa8988 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteFile
CreateFileA LockResource LoadResource SizeofResource FindResourceA GetLogicalDrives FindClose FindFirstFileA lstrcpyA lstrlenA SetFileAttributesA GetFileAttributesA GetModuleFileNameA GetFileSize GetVersionExA CreateDirectoryA WaitForSingleObject CreateProcessA GetProcAddress LoadLibraryA FreeLibrary CloseHandle SetFilePointer GetLastError GetComputerNameA SystemTimeToFileTime LocalFileTimeToFileTime GetCurrentDirectoryA SetFileTime Sleep DeleteFileA WritePrivateProfileStringA WritePrivateProfileSectionA GetStringTypeW GetStringTypeA WriteConsoleW ReadFile FreeResource GetConsoleOutputCP WriteConsoleA GetLocaleInfoA HeapFree HeapAlloc TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RaiseException RtlUnwind HeapReAlloc FileTimeToSystemTime FileTimeToLocalFileTime GetDriveTypeA GetCommandLineA GetStartupInfoA HeapCreate VirtualFree DeleteCriticalSection LeaveCriticalSection EnterCriticalSection VirtualAlloc GetModuleHandleW ExitProcess GetStdHandle SetHandleCount GetFileType TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapSize GetFullPathNameA WideCharToMultiByte FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime InitializeCriticalSectionAndSpinCount SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers GetCPInfo GetACP GetOEMCP IsValidCodePage GetTimeZoneInformation LCMapStringA MultiByteToWideChar LCMapStringW CompareStringA CompareStringW SetEnvironmentVariableA |
|---|---|
| USER32.dll |
MessageBoxA
CharUpperA wsprintfA GetKeyState |
| ADVAPI32.dll |
GetUserNameA
|
| SHELL32.dll |
ShellExecuteExA
SHFileOperationA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.42.0.0 |
| ProductVersion | 1.42.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | username=pc_name;server=demo.echovnc.com;password=demo2010 |
| CompanyName | Echogent Systems, Inc. |
| FileDescription | InstantVNC |
| FileVersion (#2) | 1, 42, 0, 0 |
| InternalName | InstantVNC |
| LegalCopyright | Copyright 2005-2010; Echogent Systems, Inc. |
| OriginalFilename | InstantVNC.exe |
| ProductName | InstantVNC |
| ProductVersion (#2) | 1, 42, 0, 0 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x41f100 |
| SEHandlerTable | 0x41cc40 |
| SEHandlerCount | 29 |
| XOR Key | 0x38da846c |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 SP1 build 30729) | 20 |
| C objects (VS2008 SP1 build 30729) | 121 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 9 |
| Total imports | 133 |
| C++ objects (VS2008 SP1 build 30729) | 58 |
| Linker (VS2008 SP1 build 30729) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.