Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 1999-Oct-12 13:06:06 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/71 (Scanned on 2024-11-29 12:27:36) |
MaxSecure:
Trojan.Malware.300983.susgen
VBA32: TrojanRansom.Medusa |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 1999-Oct-12 13:06:06 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x6b000 |
SizeOfInitializedData | 0x18000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0003C0DB (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x6c000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x84000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetCurrentProcess
GetVolumeInformationA GetDriveTypeA GlobalFree GetProcessTimes GlobalAlloc FindFirstFileA FindNextFileA FindClose OpenSemaphoreA CreateSemaphoreA GetCurrentThread CreateFileA ReleaseSemaphore SetThreadPriority ReadFile WriteFile DeviceIoControl SleepEx QueryPerformanceCounter QueryPerformanceFrequency GetPrivateProfileStringA GetPrivateProfileIntA GetTimeZoneInformation GetSystemTime GetLocalTime GetCommandLineA ExitProcess HeapAlloc InterlockedDecrement InterlockedIncrement HeapFree MultiByteToWideChar ResumeThread CreateThread TlsSetValue ExitThread TerminateProcess EnterCriticalSection LeaveCriticalSection FileTimeToSystemTime FileTimeToLocalFileTime CreateDirectoryA GetFileAttributesA DeleteFileA UnhandledExceptionFilter GetModuleFileNameA FreeEnvironmentStringsA GetWindowsDirectoryA GetTickCount GetEnvironmentStrings GetEnvironmentStringsW SetHandleCount GetStdHandle GetFileType GetStartupInfoA DeleteCriticalSection GetCurrentThreadId TlsAlloc SetLastError TlsGetValue HeapDestroy HeapCreate GetVersionExA RtlUnwind InitializeCriticalSection VirtualAlloc HeapReAlloc GetStringTypeA GetStringTypeW LCMapStringA LCMapStringW FlushFileBuffers SetEnvironmentVariableW SetEnvironmentVariableA GetFullPathNameA GetCurrentDirectoryA SetFilePointer HeapSize GetCPInfo GetACP GetOEMCP SetStdHandle CompareStringA CompareStringW SetEndOfFile SetConsoleTitleA SetErrorMode LoadLibraryA GetProcAddress FindResourceA GetModuleHandleA SetEvent CreateEventA WaitForSingleObject ResetEvent FreeLibrary CloseHandle Sleep GetVersion GetLastError WideCharToMultiByte FreeEnvironmentStringsW VirtualFree DuplicateHandle GetCurrentProcessId SetFileTime MoveFileA UnlockFile LockFile LocalFileTimeToFileTime SystemTimeToFileTime |
---|---|
USER32.dll |
GetDlgItem
GetWindowRect ShowWindow SendMessageA wsprintfA GetParent GetDlgItemTextA SetDlgItemTextA DestroyWindow MessageBoxA PostMessageA GetFocus CreateDialogParamA MessageBeep WinHelpA EnableWindow ScreenToClient MoveWindow |
NETAPI32.dll |
Netbios
|
ADVAPI32.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyExA DeregisterEventSource ReportEventA RegisterEventSourceA RegSetValueExA RegDeleteValueA RegCreateKeyExA RegEnumValueA GetUserNameA RegQueryValueA RegOpenKeyA |
comdlg32.dll |
GetOpenFileNameA
|
COMCTL32.dll |
PropertySheetA
#17 |
XOR Key | 0xdd285d39 |
---|---|
Unmarked objects | 0 |
19 (8034) | 11 |
Total imports | 155 |
12 (7291) | 12 |
C++ objects (VS98 build 8168) | 1 |
14 (7299) | 25 |
Unmarked objects (#2) | 170 |
C objects (VS98 build 8168) | 151 |