Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2021-Aug-20 16:07:50 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\nicov\OneDrive\Desktop\User\x64\Release\User.pdb
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 46/70 (Scanned on 2022-04-03 14:13:51) |
Lionic:
Trojan.Win32.DelShad.4!c
Cynet: Malicious (score: 100) McAfee: Artemis!6AFB0D25685E Cylance: Unsafe Sangfor: Trojan.Win32.DelShad.grq K7AntiVirus: Riskware ( 0040eff71 ) BitDefender: Gen:Variant.Bulz.651108 K7GW: Riskware ( 0040eff71 ) Symantec: Trojan.Gen.MBT Elastic: malicious (high confidence) ESET-NOD32: a variant of Win64/GenKryptik.FJSS APEX: Malicious Paloalto: generic.ml Kaspersky: Trojan.Win32.DelShad.grq Alibaba: Trojan:Win32/DelShad.53720acf MicroWorld-eScan: Gen:Variant.Bulz.651108 Avast: Win64:Malware-gen Tencent: Win32.Trojan.Delshad.Wteh Ad-Aware: Gen:Variant.Bulz.651108 Emsisoft: Gen:Variant.Bulz.651108 (B) F-Secure: Trojan.TR/AD.RansomHeur.trars DrWeb: Trojan.MulDrop19.12038 Zillya: Trojan.GenKryptik.Win64.2145 McAfee-GW-Edition: Artemis!Trojan FireEye: Gen:Variant.Bulz.651108 Sophos: Mal/Generic-S Ikarus: Trojan.Win64.Meterpreter Jiangmin: Trojan.DelShad.btr Avira: TR/AD.RansomHeur.trars MAX: malware (ai score=88) Antiy-AVL: Trojan/Win32.DelShad Microsoft: Ransom:Win32/Aicat.A!ml Gridinsoft: Ransom.Win64.DelShad.sa Arcabit: Trojan.Bulz.D9EF64 ZoneAlarm: Trojan.Win32.DelShad.grq GData: Gen:Variant.Bulz.651108 AhnLab-V3: Trojan/Win.Generic.C4683663 VBA32: Trojan.DelShad ALYac: Gen:Variant.Bulz.651108 Malwarebytes: Trojan.Agent Rising: Trojan.DelShad!8.107D7 (CLOUD) MaxSecure: Trojan.Malware.300983.susgen Fortinet: W32/DelShad.GRQ!tr AVG: Win64:Malware-gen Panda: Trj/CI.A CrowdStrike: win/malicious_confidence_60% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2021-Aug-20 16:07:50 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x14600 |
SizeOfInitializedData | 0xec00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000001D14 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x28000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetLastError
CreateFileW FindClose GetCurrentProcess FindNextFileW GetTickCount GetModuleHandleW GetProcAddress LoadLibraryW CloseHandle Process32FirstW Process32NextW CreateToolhelp32Snapshot OpenProcess WriteConsoleW TerminateProcess HeapReAlloc HeapSize SetFilePointerEx GetFileSizeEx GetConsoleMode GetConsoleOutputCP RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapAlloc HeapFree CompareStringW LCMapStringW GetFileType WaitForSingleObject GetExitCodeProcess CreateProcessW GetFileAttributesExW GetStringTypeW FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetProcessHeap FlushFileBuffers |
---|---|
ADVAPI32.dll |
LookupPrivilegeValueW
AdjustTokenPrivileges RegSetValueExW OpenProcessToken RegQueryValueExW RegCloseKey RegEnumKeyExW RegOpenKeyExW |
SHLWAPI.dll |
SHDeleteValueW
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Aug-20 16:07:50 |
Version | 0.0 |
SizeofData | 82 |
AddressOfRawData | 0x1ee80 |
PointerToRawData | 0x1d880 |
Referenced File | C:\Users\nicov\OneDrive\Desktop\User\x64\Release\User.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Aug-20 16:07:50 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x1eed4 |
PointerToRawData | 0x1d8d4 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Aug-20 16:07:50 |
Version | 0.0 |
SizeofData | 696 |
AddressOfRawData | 0x1eee8 |
PointerToRawData | 0x1d8e8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Aug-20 16:07:50 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140021008 |
XOR Key | 0xa21ddd89 |
---|---|
Unmarked objects | 0 |
C objects (27412) | 11 |
ASM objects (27412) | 5 |
C++ objects (27412) | 148 |
C++ objects (VS 2015/2017/2019 runtime 29913) | 37 |
C objects (VS 2015/2017/2019 runtime 29913) | 17 |
ASM objects (VS 2015/2017/2019 runtime 29913) | 9 |
Imports (27412) | 11 |
Total imports | 119 |
C objects (LTCG) (VS2019 Update 9 (16.9.5) compiler 29915) | 2 |
Resource objects (VS2019 Update 9 (16.9.5) compiler 29915) | 1 |
Linker (VS2019 Update 9 (16.9.5) compiler 29915) | 1 |