Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2009-Jul-02 15:51:08 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 Microsoft Visual C++ MSVC++ v.8 (procedure 1 recognized - h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Suspicious | The PE is possibly packed. |
Unusual section name found: .text1
Unusual section name found: .trace |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/57 (Scanned on 2016-04-18 15:45:11) | Ikarus: Backdoor.Win32.HacDef |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2009-Jul-02 15:51:08 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0x8f000 |
SizeOfInitializedData | 0x2b000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0006D73A (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x90000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2038000 |
SizeOfHeaders | 0x1000 |
Checksum | 0xc0d46 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FormatMessageA
LoadLibraryA GetThreadLocale FreeLibrary CloseHandle GetLastError GetStdHandle GetProcAddress GetModuleHandleA WriteFile SetFilePointer CreateFileA IsDebuggerPresent GetFileType WaitForSingleObject Sleep InterlockedExchange TlsSetValue TlsGetValue SetLastError TlsAlloc TlsFree VirtualFree VirtualAlloc GetCurrentThreadId ReleaseMutex CreateMutexA SetEndOfFile GetCommandLineA GetACP SetErrorMode SetConsoleCtrlHandler LeaveCriticalSection EnterCriticalSection SetEvent ExitThread CreateEventA InitializeCriticalSection DeleteCriticalSection TerminateThread ReadFile GetFileInformationByHandle GetTempFileNameA GetTempPathA GetFullPathNameA DeleteFileA GetVersionExA SetThreadPriority CreateProcessA FlushFileBuffers HeapFree HeapAlloc GetProcessHeap ExitProcess UnhandledExceptionFilter SetUnhandledExceptionFilter HeapReAlloc WideCharToMultiByte GetConsoleCP GetConsoleMode SetStdHandle GetCurrentProcessId GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetStartupInfoA InterlockedIncrement InterlockedDecrement GetCurrentThread HeapDestroy HeapCreate QueryPerformanceCounter GetTickCount GetSystemTimeAsFileTime TerminateProcess GetCurrentProcess RtlUnwind GetCPInfo GetOEMCP LCMapStringA MultiByteToWideChar LCMapStringW HeapSize GetFileAttributesA WriteConsoleA GetConsoleOutputCP WriteConsoleW CompareStringA CompareStringW SetEnvironmentVariableA GetLocaleInfoA GetStringTypeA GetStringTypeW GetExitCodeProcess VirtualQuery |
---|---|
imagehlp.dll |
SymCleanup
SymInitialize StackWalk |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4b4420 |
SEHandlerTable | 0x4af8f0 |
SEHandlerCount | 4 |
XOR Key | 0x6fcb6320 |
---|---|
Unmarked objects | 0 |
Imports (VS2003 (.NET) build 4035) | 5 |
Total imports | 118 |
ASM objects (VS2003 (.NET) build 3077) | 3 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 27 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 41 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 149 |
Unmarked objects (#2) | 121 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |