5179e840022fc9abf6c07d01af776725cfe6905f85d8ad7b3010f91c72f5e859

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2009-Jul-05 02:50:45

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • apache.org
  • http://www.apache.org
  • http://www.apache.org/
  • http://www.apache.org/licenses/LICENSE-2.0
  • http://www.zeustech.net
  • http://www.zeustech.net/
  • www.apache.org
  • www.zeustech.net
  • zeustech.net
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Suspicious The file contains overlay data. 73 bytes of data starting at offset 0x12000.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 4ff35491acaced26d278d482c0a0df12 🔍
SHA1 d9bc6d50cfd06cdfbae72875519cff7272033a6d 🔍
SHA256 5179e840022fc9abf6c07d01af776725cfe6905f85d8ad7b3010f91c72f5e859 🔍
SHA3 b61ea3ae9c15b2030b03ebfbc50a06d7f8a629a1fbe735da12e31692b0351787 🔍
SSDeep 1536:IAv3EyYq+hgDZJk5sR2xZacHMb+KRfNc8QsJq39:Z1csGYYefNc8QsC9 🔍
Imports Hash 481f47bbb2c9c21e108d65f52b04c448 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2009-Jul-05 02:50:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0xb000
SizeOfInitializedData 0xa000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000AA27 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xc000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x16000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 61054ead1bce469f8380d5b55f62edf0 🔍
SHA1 dc55b695d353f8a8544248f0960293f76ddc04d5 🔍
SHA256 21a437333a7b76b297e172cf8ac3c50c4b18ebfdda8f4faf1cb9045fc87feb39 🔍
SHA3 1a5f263396890799314c63b961028f7a5405a70decd3df52f033b5e9d7e0988c 🔍
VirtualSize 0xa966
VirtualAddress 0x1000
SizeOfRawData 0xb000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.01773

.rdata

MD5 25d7ceee3aa85bb3e8c5174736f6f830 🔍
SHA1 2d1b3b256819734be18a5171828f544f2fe3c678 🔍
SHA256 c9c158955ada53055c12e5d0c4060730470167d0059b1f02aafcf886370d57e0 🔍
SHA3 da6fb56135ed03a247ebd4b2173b4e9871b1a9f5cd2867b977a36af64b3c9954 🔍
VirtualSize 0xfe6
VirtualAddress 0xc000
SizeOfRawData 0x1000
PointerToRawData 0xc000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.31839

.data

MD5 1d2d3954f1aceaaae276990a82f40f3b 🔍
SHA1 ccaa1ffc708f16bd43303d8e810fb5f00eaecf1a 🔍
SHA256 3c2155acaded24710a5de38c6fe3c652f1352f89836391d37ad4648154cdd1bf 🔍
SHA3 6a0a0e8b28123e90788830baffdf255f9f994366531dc5c6cdb1e47dff45236c 🔍
VirtualSize 0x705c
VirtualAddress 0xd000
SizeOfRawData 0x4000
PointerToRawData 0xd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.40917

.rsrc

MD5 3361608814c27b2b11b76a0df19016bb 🔍
SHA1 d51d12225dab0d2a6562cb312e1b1d81d433482e 🔍
SHA256 bbbd72ec14c8fd48b08f4c13d1e8256d7dd785a320d1ed43931bac1d24d561cf 🔍
SHA3 67451c05bb17f90ddcc951be0f5701a4bed514f3b4e2e9513695f305abc4f148 🔍
VirtualSize 0x7c8
VirtualAddress 0x15000
SizeOfRawData 0x1000
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.96028

Imports

MSVCRT.dll _iob
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
__setusermatherr
_initterm
__getmainargs
__p___initenv
_XcptFilter
_exit
_onexit
__dllonexit
strrchr
wcsncmp
_close
wcslen
wcscpy
strerror
modf
strspn
realloc
__p__environ
__p__wenviron
_errno
free
strncmp
strstr
strncpy
_ftol
qsort
fopen
perror
fclose
fflush
calloc
malloc
signal
printf
_isctype
atoi
exit
__mb_cur_max
_pctype
strchr
fprintf
_controlfp
_strdup
_strnicmp
KERNEL32.dll PeekNamedPipe
ReadFile
WriteFile
LoadLibraryA
GetProcAddress
GetVersionExA
GetExitCodeProcess
TerminateProcess
LeaveCriticalSection
SetEvent
ReleaseMutex
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSection
CreateMutexA
GetFileType
SetLastError
FreeEnvironmentStringsW
GetEnvironmentStringsW
GlobalFree
GetCommandLineW
TlsAlloc
TlsFree
DuplicateHandle
GetCurrentProcess
SetHandleInformation
CloseHandle
GetSystemTimeAsFileTime
FileTimeToSystemTime
GetTimeZoneInformation
FileTimeToLocalFileTime
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
Sleep
FormatMessageA
GetLastError
WaitForSingleObject
CreateEventA
SetStdHandle
SetFilePointer
CreateFileA
CreateFileW
GetOverlappedResult
DeviceIoControl
GetFileInformationByHandle
LocalFree
ADVAPI32.dll FreeSid
AllocateAndInitializeSid
WSOCK32.dll getsockopt
connect
htons
gethostbyname
ntohl
inet_ntoa
setsockopt
socket
closesocket
select
ioctlsocket
__WSAFDIsSet
WSAStartup
WSACleanup
WSAGetLastError
WS2_32.dll WSARecv
WSASend

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x859e59d7
Unmarked objects 0
12 (7291) 4
14 (7299) 9
C objects (8047) 11
Linker (8047) 3
Total imports 201
Imports (2179) 8
48 (9044) 40
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[!] Error: The PE's resource section exceeds the parsing limits. Resources will not be parsed. [!] Error: Could not read PDB file information of invalid magic number.
Leave a comment

No comments yet.