Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2011-Mar-11 10:55:44 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Installer VISE Custom
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 24/72 (Scanned on 2020-05-08 22:40:42) |
CAT-QuickHeal:
Trojan.IGENERIC
Cylance: Unsafe Zillya: Downloader.Agent.Win32.291715 Sangfor: Malware Alibaba: Trojan:Win32/Generic.278e6526 Baidu: Win32.Trojan.Agent.apq Symantec: Trojan.Gen.MBT ESET-NOD32: Win32/Agent.WOI APEX: Malicious NANO-Antivirus: Trojan.Win32.Agent.dvyioc Avast: Win32:Malware-gen Comodo: Malware@#1z26xgwy7wzrb DrWeb: Trojan.Siggen8.36839 VIPRE: Trojan.Win32.Generic!BT Webroot: W32.Malware.Gen Antiy-AVL: Trojan/Win32.BTSGeneric Microsoft: Trojan:Win32/Bluteal!rfn AegisLab: Trojan.Win32.Generic.4!c GData: Win32.Trojan.Agent.0LD235 VBA32: BScope.Adware.Presenoker Rising: Trojan.Agent!8.B1E (CLOUD) Ikarus: not-a-virus:Monitor.Win32.KeyKey Fortinet: W32/Agent.WOI!tr AVG: Win32:Malware-gen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2011-Mar-11 10:55:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x3000 |
SizeOfInitializedData | 0x3000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001090 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x4000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x7000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
StartServiceA
OpenServiceA CreateServiceA OpenSCManagerA ControlService |
---|---|
KERNEL32.dll |
GetModuleHandleA
GetStartupInfoA GetCommandLineA GetVersion ExitProcess TerminateProcess GetCurrentProcess UnhandledExceptionFilter GetModuleFileNameA FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW SetHandleCount GetStdHandle GetFileType HeapDestroy HeapCreate VirtualFree HeapFree RtlUnwind WriteFile GetCPInfo GetACP GetOEMCP HeapAlloc VirtualAlloc HeapReAlloc GetProcAddress LoadLibraryA MultiByteToWideChar LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW |
RegWriterApp |
Hello World! |
REGWRITERAPP |
XOR Key | 0xa5513598 |
---|---|
Unmarked objects | 0 |
C objects (VS98 build 8168) | 22 |
14 (7299) | 9 |
Total imports | 42 |
19 (8034) | 5 |
Resource objects (VS98 cvtres build 1720) | 1 |
C++ objects (VS98 build 8168) | 3 |