Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Nov-14 10:50:47 |
Detected languages |
English - United States
|
Debug artifacts |
c:\Road\discuss\Than\Make\neighbor\Earlyrock.pdb
|
CompanyName | SportsSignup Radio |
FileDescription | Togetherpound |
InternalName | typematerial.exe |
LegalCopyright | Copyright© 2015 - 2017 SportsSignup Radio, Inc. |
OriginalFilename | typematerial.exe |
ProductName | Togetherpound |
ProductVersion | 9.3.57.92 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 39/67 (Scanned on 2018-11-21 22:16:12) |
MicroWorld-eScan:
Trojan.Ranapama.ABT
McAfee: RDN/Generic.grp Cylance: Unsafe BitDefender: Trojan.Ranapama.ABT TrendMicro: TROJ_GEN.R00AC0PKH18 F-Prot: W32/S-a328b1bd!Eldorado Symantec: Trojan.Gen.MBT ESET-NOD32: a variant of Win32/Kryptik.GMTU TrendMicro-HouseCall: TROJ_GEN.R00AC0PKH18 Paloalto: generic.ml NANO-Antivirus: Trojan.Win32.Kryptik.fkjjlm Avast: Win32:Malware-gen Ad-Aware: Trojan.Ranapama.ABT Sophos: Mal/Generic-S F-Secure: Trojan.Ranapama.ABT Invincea: heuristic McAfee-GW-Edition: RDN/Generic.grp Emsisoft: Trojan.Ranapama.ABT (B) SentinelOne: static engine - malicious Cyren: W32/Trojan.SVJS-2048 Webroot: W32.Trojan.Gen Avira: TR/AD.Ursnif.tje Antiy-AVL: Trojan/Win32.GenKryptik Microsoft: Trojan:Win32/Emotet!rfn Endgame: malicious (high confidence) Arcabit: Trojan.Ranapama.ABT AegisLab: Trojan.Win32.Ranapama.4!c GData: Trojan.Ranapama.ABT TACHYON: Trojan/W32.Agent.500224.DW AhnLab-V3: Trojan/Win32.Ursnif.R244864 ALYac: Spyware.Ursnif MAX: malware (ai score=81) Malwarebytes: Trojan.Ursnif Rising: Trojan.Kryptik!1.B4E9 (CLASSIC) Ikarus: Trojan-Banker.IcedID Fortinet: W32/GenKryptij.CRRJ!tr AVG: Win32:Malware-gen Panda: Trj/GdSda.A CrowdStrike: malicious_confidence_90% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2016-Nov-14 10:50:47 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x34000 |
SizeOfInitializedData | 0x4fc00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00008AF1 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x35000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x88000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetCurrentDirectoryA
DuplicateHandle GetModuleHandleA OpenProcess Sleep GetTempPathA CopyFileA OpenMutexA CreateFileA GetCurrentThread GetSystemDirectoryA GetVolumeInformationA GetVersionExA LockResource DeleteFileA GetDateFormatA ResetEvent GetProcAddress FindFirstChangeNotificationA CreateDirectoryA GetSystemTime QueryPerformanceCounter GetExitCodeProcess CreateMutexA GetEnvironmentVariableA PeekNamedPipe VirtualAlloc DeviceIoControl VirtualFree GetCurrentProcess LoadLibraryA CreateFileW HeapSize ReadConsoleW WriteConsoleW SetStdHandle FindNextFileA FindFirstFileExA FindClose WideCharToMultiByte EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar SetLastError InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetModuleHandleW CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo CloseHandle SetEvent WaitForSingleObjectEx UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId GetCurrentThreadId InitializeSListHead RaiseException RtlUnwind GetLastError FreeLibrary LoadLibraryExW GetModuleFileNameW HeapAlloc HeapReAlloc HeapFree ExitProcess GetModuleHandleExW GetStdHandle WriteFile GetModuleFileNameA GetACP GetFileType GetDateFormatW GetTimeFormatW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetTimeZoneInformation FlushFileBuffers GetConsoleCP GetConsoleMode ReadFile SetFilePointerEx GetProcessHeap IsValidCodePage GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableA GetCommandLineA GetCommandLineW VirtualProtect |
---|---|
COMCTL32.dll |
ImageList_Destroy
ImageList_SetIconSize ImageList_GetImageCount ImageList_SetBkColor ImageList_AddMasked ImageList_Remove |
ole32.dll |
OleInitialize
CoRegisterClassObject CoUninitialize OleSetContainedObject CoInitialize OleUninitialize CoRegisterSurrogate |
SHLWAPI.dll |
PathGetDriveNumberA
PathFindFileNameA wnsprintfA PathIsUNCA AssocQueryStringA |
ADVAPI32.dll |
SystemFunction036
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 9.3.57.92 |
ProductVersion | 9.3.57.92 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | SportsSignup Radio |
FileDescription | Togetherpound |
InternalName | typematerial.exe |
LegalCopyright | Copyright© 2015 - 2017 SportsSignup Radio, Inc. |
OriginalFilename | typematerial.exe |
ProductName | Togetherpound |
ProductVersion (#2) | 9.3.57.92 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Nov-14 10:50:47 |
Version | 0.0 |
SizeofData | 73 |
AddressOfRawData | 0x4929c |
PointerToRawData | 0x4869c |
Referenced File | c:\Road\discuss\Than\Make\neighbor\Earlyrock.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-14 10:50:46 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x492e8 |
PointerToRawData | 0x486e8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-14 10:50:46 |
Version | 0.0 |
SizeofData | 1052 |
AddressOfRawData | 0x492fc |
PointerToRawData | 0x486fc |
StartAddressOfRawData | 0x458000 |
---|---|
EndAddressOfRawData | 0x458008 |
AddressOfIndex | 0x44d730 |
AddressOfCallbacks | 0x435270 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x44c1bc |
SEHandlerTable | 0x449130 |
SEHandlerCount | 46 |
XOR Key | 0xb0bbd221 |
---|---|
Unmarked objects | 0 |
241 (40116) | 11 |
243 (40116) | 147 |
242 (40116) | 27 |
ASM objects (23406) | 23 |
C++ objects (23406) | 58 |
C objects (23406) | 64 |
Imports (VS2008 SP1 build 30729) | 11 |
Total imports | 138 |
265 (VS2015 UPD1 build 23506) | 1 |
Resource objects (VS2015 UPD1 build 23506) | 1 |
Linker (VS2015 UPD1 build 23506) | 1 |