Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-May-25 18:10:23 |
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
D:\a\sfsu\sfsu\target\i686-pc-windows-msvc\release\deps\sfsu.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 31/71 (Scanned on 2023-05-26 21:34:04) |
MicroWorld-eScan:
Gen:Variant.Zusy.465520
McAfee: GenericRXAA-AA!73F4914A93A1 Malwarebytes: Malware.AI.3869784776 VIPRE: Gen:Variant.Zusy.465520 Sangfor: Trojan.Win32.Zusy.Va4w Cyren: W32/Zusy.QV.gen!Eldorado Symantec: ML.Attribute.HighConfidence Elastic: malicious (high confidence) BitDefender: Gen:Variant.Zusy.465520 Avast: Win32:TrojanX-gen [Trj] McAfee-GW-Edition: BehavesLike.Win32.Dropper.th FireEye: Gen:Variant.Zusy.465520 Emsisoft: Gen:Variant.Zusy.465520 (B) GData: Gen:Variant.Zusy.465520 Jiangmin: Trojan.DllHijacker.bj Antiy-AVL: Trojan/Win32.SGeneric Arcabit: Trojan.Zusy.D71A70 ViRobot: Trojan.Win.Z.Zusy.1935872.A Microsoft: Trojan:Win32/Sabsik.FL.B!ml Google: Detected AhnLab-V3: Trojan/Win.Generic.R580561 ALYac: Gen:Variant.Zusy.465520 MAX: malware (ai score=89) VBA32: BScope.Trojan.Agent Cylance: unsafe Panda: Trj/Genetic.gen TrendMicro-HouseCall: TROJ_GEN.R002H09EP23 Rising: Trojan.Generic@AI.100 (RDML:nPlif50iabbwOGgiJp/tbg) Fortinet: W32/PossibleThreat AVG: Win32:TrojanX-gen [Trj] DeepInstinct: MALICIOUS |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2023-May-25 18:10:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x158200 |
SizeOfInitializedData | 0x80800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00151A22 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x15a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1dc000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ole32.dll |
CoTaskMemFree
|
---|---|
kernel32.dll |
ReleaseMutex
FindClose ReleaseSRWLockShared AddVectoredExceptionHandler SetThreadStackGuarantee SwitchToThread GetCurrentThread RtlCaptureContext SetLastError GetCurrentDirectoryW GetEnvironmentVariableW SystemTimeToTzSpecificLocalTime GetCommandLineW SetFilePointerEx FileTimeToSystemTime SystemTimeToFileTime WaitForSingleObject GetTimeZoneInformation FormatMessageW HeapAlloc SleepConditionVariableSRW GetLastError GetCurrentProcessId TerminateProcess WakeAllConditionVariable WakeConditionVariable QueryPerformanceCounter GetFileType HeapReAlloc AcquireSRWLockShared WaitForSingleObjectEx CreateMutexA IsProcessorFeaturePresent GetModuleHandleA FindNextFileW CreateFileW GetFileInformationByHandle FindFirstFileW GetFinalPathNameByHandleW LoadLibraryA HeapFree GetProcessHeap GetModuleHandleW GetModuleFileNameW ExitProcess GetFullPathNameW GetCurrentProcess MultiByteToWideChar WriteConsoleW CreateThread InitOnceBeginInitialize TlsAlloc InitOnceComplete TlsFree GetSystemTimeAsFileTime GetFileInformationByHandleEx SetConsoleMode GetConsoleMode GetStdHandle TlsGetValue TlsSetValue lstrlenW GetConsoleScreenBufferInfo SetConsoleTextAttribute GetProcAddress GetCurrentThreadId TryAcquireSRWLockExclusive CloseHandle ReleaseSRWLockExclusive AcquireSRWLockExclusive InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetSystemInfo |
shell32.dll |
SHGetKnownFolderPath
|
advapi32.dll |
SystemFunction036
|
bcrypt.dll |
BCryptGenRandom
|
VCRUNTIME140.dll |
memmove
_except_handler4_common __current_exception_context __current_exception _CxxThrowException __CxxFrameHandler3 memset memcmp memcpy |
api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_initterm _configure_narrow_argv _exit __p___argc _initialize_narrow_environment __p___argv _cexit _c_exit exit _register_thread_local_exe_atexit_callback _get_initial_narrow_environment _seh_filter_exe _initialize_onexit_table _register_onexit_function _crt_atexit _controlfp_s terminate _initterm_e |
api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-May-25 18:10:23 |
Version | 0.0 |
SizeofData | 89 |
AddressOfRawData | 0x1be39c |
PointerToRawData | 0x1bc99c |
Referenced File | D:\a\sfsu\sfsu\target\i686-pc-windows-msvc\release\deps\sfsu.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-May-25 18:10:23 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x1be3f8 |
PointerToRawData | 0x1bc9f8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-May-25 18:10:23 |
Version | 0.0 |
SizeofData | 812 |
AddressOfRawData | 0x1be40c |
PointerToRawData | 0x1bca0c |
StartAddressOfRawData | 0x5be748 |
---|---|
EndAddressOfRawData | 0x5be749 |
AddressOfIndex | 0x5ce280 |
AddressOfCallbacks | 0x55a21c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
Callbacks |
0x0053B420
|
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x5ce164 |
SEHandlerTable | 0x5bd6a0 |
SEHandlerCount | 806 |
XOR Key | 0x78158704 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 12 |
Imports (31935) | 2 |
C objects (30795) | 1 |
C++ objects (31935) | 24 |
C objects (31935) | 12 |
ASM objects (31935) | 6 |
Imports (30148) | 14 |
Imports (30795) | 3 |
Total imports | 200 |
C objects (32217) | 1 |
Unmarked objects (#2) | 43 |
Linker (32217) | 1 |