Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2011-Nov-24 00:41:46 |
Detected languages |
English - United States
|
FileVersion | 3.0.0.5 |
ProductVersion | 3.0.0.5 |
FileDescription | A Simple Unlocker - HadiK IT |
CompanyName | - |
LegalCopyright | - |
ProductName | Qualcomm Tool - HadiK IT |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. | Resources amount for 80.4224% of the executable. |
Suspicious | The file contains overlay data. | 1069 bytes of data starting at offset 0x52000. |
Malicious | The program tries to mislead users about its origins. | The PE pretends to be from Qualcomm but is not signed! |
Malicious | VirusTotal score: 8/71 (Scanned on 2023-06-05 18:30:48) |
Cybereason:
malicious.003abd
VirIT: Trojan.Win32.AVKill.BKFM APEX: Malicious Rising: Trojan.Win32.Fednu.ujp (CLASSIC) Trapmine: malicious.high.ml.score Gridinsoft: Ransom.Win32.Wacatac.oa!s1 BitDefenderTheta: Gen:NN.ZexaE.36250.uq1@aqqMpYhi DeepInstinct: MALICIOUS |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2011-Nov-24 00:41:46 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xc000 |
SizeOfInitializedData | 0x45000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005C8E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xd000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xa28000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x5c5b7 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTempPathA
GetStdHandle GetModuleFileNameA Sleep SetConsoleCursorInfo SetConsoleCursorPosition SetConsoleTextAttribute GetTickCount LCMapStringA SetEndOfFile ExitProcess TerminateProcess GetCurrentProcess GetCommandLineA GetVersion GetLastError GetFileAttributesA HeapFree CloseHandle SetFilePointer SetHandleCount GetFileType GetStartupInfoA WriteFile ReadFile GetProcAddress GetModuleHandleA UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree RtlUnwind HeapAlloc GetExitCodeProcess WaitForSingleObject CreateProcessA VirtualAlloc HeapReAlloc SetStdHandle FlushFileBuffers CreateFileA MultiByteToWideChar GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP LoadLibraryA CompareStringA CompareStringW SetEnvironmentVariableA LCMapStringW |
---|---|
WINMM.dll |
timeGetTime
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.0.0.5 |
ProductVersion | 3.0.0.5 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | UNKNOWN |
FileVersion (#2) | 3.0.0.5 |
ProductVersion (#2) | 3.0.0.5 |
FileDescription | A Simple Unlocker - HadiK IT |
CompanyName | - |
LegalCopyright | - |
ProductName | Qualcomm Tool - HadiK IT |
Resource LangID | UNKNOWN |
---|
XOR Key | 0x991839a5 |
---|---|
Unmarked objects | 0 |
C++ objects (VS98 build 8168) | 1 |
14 (7299) | 15 |
19 (8034) | 5 |
Total imports | 59 |
C objects (VS98 build 8168) | 93 |
Resource objects (VS98 cvtres build 1720) | 1 |