Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2012-Mar-08 15:59:48 |
Detected languages |
English - United States
French - France |
Debug artifacts |
C:\Projets\vbsedit_source\script2exe\Release\mywscript.pdb
|
FileVersion | 1, 0, 0, 0 |
ProductVersion | 1, 0, 0, 0 |
LegalCopyright | Copyright (C) 2018 |
FileDescription | |
ProductName | NisWatchII |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 129 is possibly compressed or encrypted. |
Malicious | VirusTotal score: 25/71 (Scanned on 2019-11-01 18:33:35) |
VBA32:
TrojanDropper.MSIL.Agent
CrowdStrike: win/malicious_confidence_60% (W) Invincea: heuristic ClamAV: Win.Malware.Dexel-6910198-0 Kaspersky: Trojan.Win32.Agent.xaaimm NANO-Antivirus: Trojan.Win32.Dapato.cqtyqs Paloalto: generic.ml Sophos: Mal/Generic-S Comodo: TrojWare.Win32.TrojanDropper.Dexel.A@6k1yft Zillya: Dropper.Agent.Win32.104010 CMC: Trojan-Downloader.Win32.Gamarue.2!O SentinelOne: DFI - Suspicious PE Cyren: W32/Trojan.ORZX-4617 eGambit: Trojan.Generic Microsoft: Trojan:Win32/Zpevdo.B AegisLab: Trojan.Win32.Generic.4!c ZoneAlarm: Trojan.Win32.Agent.xaaimm AhnLab-V3: Malware/Win32.Generic.C3278571 Zoner: Trojan.Win32.34274 Rising: Trojan.Generic@ML.100 (RDML:mkkSB5BIiRBNb801CO6/ew) Yandex: Trojan.Agent!4xFGLKGgIf4 BitDefenderTheta: Gen:NN.ZexaE.31176.su0@aWohjOom AVG: FileRepMalware Cybereason: malicious.15259f Qihoo-360: Win32/Trojan.IM.3d2 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2012-Mar-08 15:59:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x29400 |
SizeOfInitializedData | 0x1fa00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00017C69 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2b000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x51000 |
SizeOfHeaders | 0x400 |
Checksum | 0x44a01 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetFileAttributesW
GetFileSizeEx GetFileTime GetStartupInfoW HeapAlloc HeapFree RtlUnwind HeapReAlloc RaiseException VirtualProtect VirtualAlloc GetSystemInfo VirtualQuery HeapSize SetUnhandledExceptionFilter GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoA HeapCreate VirtualFree QueryPerformanceCounter GetSystemTimeAsFileTime TerminateProcess UnhandledExceptionFilter IsDebuggerPresent GetCPInfo GetACP GetOEMCP IsValidCodePage InitializeCriticalSectionAndSpinCount GetTimeZoneInformation GetConsoleCP GetConsoleMode LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA SetStdHandle WriteConsoleA GetConsoleOutputCP CreateFileA SetEnvironmentVariableA FileTimeToLocalFileTime CreateFileW GetFullPathNameW GetVolumeInformationW FindFirstFileW FindClose GetCurrentProcess DuplicateHandle GetFileSize SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer WriteFile ReadFile WritePrivateProfileStringW GetModuleHandleA GlobalFlags TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection GlobalHandle GlobalReAlloc EnterCriticalSection TlsGetValue LeaveCriticalSection LocalAlloc FileTimeToSystemTime GetCurrentProcessId SetErrorMode GetCurrentThread ConvertDefaultLocale EnumResourceLanguagesW GetLocaleInfoW LoadLibraryExW CompareStringA InterlockedExchange InterlockedIncrement lstrlenA lstrcmpA CloseHandle GetCurrentThreadId GlobalAddAtomW GlobalFindAtomW GlobalDeleteAtom LoadLibraryW CompareStringW LoadLibraryA lstrcmpW GetVersionExA FreeLibrary InterlockedDecrement GetProcAddress GetLastError SetLastError GlobalFree GlobalAlloc GlobalLock GlobalUnlock FormatMessageW LocalFree lstrlenW WideCharToMultiByte WriteConsoleW ExitProcess GetModuleFileNameW ExpandEnvironmentStringsW GetStdHandle Sleep GetModuleHandleW GetCommandLineW MultiByteToWideChar FindResourceW LoadResource LockResource GetTickCount SizeofResource |
---|---|
USER32.dll |
CharUpperW
SetCursor GrayStringW DrawTextExW DrawTextW TabbedTextOutW ClientToScreen DestroyMenu ShowWindow SetWindowTextW LoadCursorW GetDC ReleaseDC GetSysColorBrush GetWindowThreadProcessId IsWindowEnabled PostQuitMessage SetMenuItemBitmaps LoadBitmapW ModifyMenuW CheckMenuItem GetMessageW TranslateMessage GetCursorPos ValidateRect RegisterWindowMessageW LoadIconW WinHelpW GetCapture SetWindowsHookExW CallNextHookEx GetClassLongW GetClassNameW SetPropW GetPropW RemovePropW GetFocus IsWindow GetWindowTextW GetForegroundWindow GetLastActivePopup DispatchMessageW GetDlgItem GetTopWindow DestroyWindow GetMessageTime GetMessagePos PeekMessageW MapWindowPoints MessageBoxW GetActiveWindow GetSubMenu GetKeyState SetMenu EnableWindow SetForegroundWindow IsWindowVisible GetClientRect PostMessageW GetMenuCheckMarkDimensions GetMenuItemCount GetMenuItemID GetMenuState UnhookWindowsHookEx GetWindow GetSystemMetrics GetWindowRect GetWindowPlacement IsIconic SystemParametersInfoA SetWindowPos SetWindowLongW GetWindowLongW GetMenu PtInRect CopyRect CallWindowProcW DefWindowProcW SendMessageW CreateWindowExW GetClassInfoExW GetClassInfoW RegisterClassW GetSysColor AdjustWindowRectEx GetParent GetDlgCtrlID EnableMenuItem |
GDI32.dll |
DeleteDC
GetStockObject ScaleWindowExtEx SetWindowExtEx ScaleViewportExtEx SetViewportExtEx OffsetViewportOrgEx SetViewportOrgEx SelectObject Escape TextOutW RectVisible GetDeviceCaps SetMapMode RestoreDC SaveDC DeleteObject ExtTextOutW CreateBitmap SetBkColor SetTextColor GetClipBox PtVisible |
COMDLG32.dll |
GetFileTitleW
|
WINSPOOL.DRV |
DocumentPropertiesW
OpenPrinterW ClosePrinter |
ADVAPI32.dll |
RegSetValueExW
RegEnumKeyW RegDeleteKeyW RegQueryValueW RegOpenKeyW RegCreateKeyExW RegCloseKey RegQueryValueExW RegEnumKeyExW RegOpenKeyExW |
SHLWAPI.dll |
PathStripToRootW
PathIsUNCW PathFindFileNameW PathFindExtensionW |
ole32.dll |
CoDisconnectObject
StringFromGUID2 CoGetObject CoCreateInstance CLSIDFromProgID CoInitialize |
OLEAUT32.dll |
#6
#8 #10 #9 #4 #12 #183 #162 #2 #7 #161 |
OLEACC.dll (delay-loaded) |
LresultFromObject
CreateStdAccessibleObject |
Attributes | 0x1 |
---|---|
Name | OLEACC.dll |
ModuleHandle | 0x3aef0 |
DelayImportAddressTable | 0x383f8 |
DelayImportNameTable | 0x34238 |
BoundDelayImportTable | 0x34274 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
mywscript2 |
MYWSCRIPT2 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags |
VS_FF_DEBUG
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileVersion (#2) | 1, 0, 0, 0 |
ProductVersion (#2) | 1, 0, 0, 0 |
LegalCopyright | Copyright (C) 2018 |
FileDescription | |
ProductName | NisWatchII |
Resource LangID | UNKNOWN |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2012-Mar-08 15:59:48 |
Version | 0.0 |
SizeofData | 83 |
AddressOfRawData | 0x306c0 |
PointerToRawData | 0x2eec0 |
Referenced File | C:\Projets\vbsedit_source\script2exe\Release\mywscript.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x436ddc |
SEHandlerTable | 0x431e80 |
SEHandlerCount | 106 |
XOR Key | 0x647ee5a7 |
---|---|
Unmarked objects | 0 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 8 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 21 |
Total imports | 516 |
ASM objects (VS2008 SP1 build 30729) | 25 |
C objects (VS2008 SP1 build 30729) | 151 |
C++ objects (VS2008 SP1 build 30729) | 130 |
C++ objects (VS2008 build 21022) | 3 |
138 (VS2008 SP1 build 30729) | 8 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |