Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
Compilation Date | 2016-Sep-27 16:51:39 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
E:\temp\trunk\output\LcScience64.pdb
|
FileVersion | 0.4.0.130 |
LegalCopyright | Copyright (C) 2016 |
ProductVersion | 0.4.0.130 |
Suspicious | The PE is possibly packed. | Section INIT is both writable and executable. |
Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
Info | The PE is digitally signed. |
Signer: Baidu (China) Co.
Issuer: GlobalSign CodeSigning CA - G2 |
Malicious | VirusTotal score: 16/68 (Scanned on 2019-12-10 11:18:16) |
McAfee:
Artemis!7D67CE19947D
Zillya: Adware.Agent.Win32.134536 Sangfor: Malware Alibaba: AdWare:Win32/Agent.bce74585 Kaspersky: not-a-virus:AdWare.Win32.Agent.kdbv TrendMicro: PUA_JUZIHAO.component McAfee-GW-Edition: Artemis!PUP Jiangmin: Trojan/IE.startpage.b Webroot: Pua.Gen Antiy-AVL: Trojan/Win32.TGeneric ZoneAlarm: not-a-virus:AdWare.Win32.Agent.kdbv VBA32: AdWare.Agent MAX: malware (ai score=93) TrendMicro-HouseCall: PUA_JUZIHAO.component Fortinet: Riskware/JUZIHAO Qihoo-360: Trojan.Generic |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2016-Sep-27 16:51:39 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 12.3 |
SizeOfCode | 0x8600 |
SizeOfInitializedData | 0x2000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000000D000 (Section: INIT) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.3 |
ImageVersion | 6.3 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x10000 |
SizeOfHeaders | 0x400 |
Checksum | 0x16a94 |
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntoskrnl.exe |
KeInitializeEvent
ExAllocatePool ExFreePoolWithTag ExAcquireFastMutex ExReleaseFastMutex __C_specific_handler _local_unwind _wcslwr ZwClose _wcsicmp KeSetEvent KeWaitForSingleObject IoAllocateWorkItem IoFreeWorkItem IoQueueWorkItem _stricmp RtlInitUnicodeString ExAllocatePoolWithTag IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice IoDeleteSymbolicLink ObfDereferenceObject ZwOpenKey ZwQueryValueKey PsSetCreateProcessNotifyRoutine PsGetCurrentProcessId PsLookupProcessByProcessId PsGetProcessImageFileName RtlAnsiStringToUnicodeString RtlUnicodeStringToAnsiString RtlFreeUnicodeString RtlFreeAnsiString RtlCopyUnicodeString DbgPrint IoCreateFile ObReferenceObjectByHandle MmIsAddressValid IoQueryFileDosDeviceName ObOpenObjectByPointer ZwQueryInformationProcess IoFileObjectType tolower CmRegisterCallback ObQueryNameString wcsncpy RtlGetVersion KeInitializeMutex KeReleaseMutex ZwCreateFile ZwQueryInformationFile ZwCreateSection ZwMapViewOfSection ZwUnmapViewOfSection PsSetLoadImageNotifyRoutine PsRemoveLoadImageNotifyRoutine ZwQuerySystemInformation ZwQueryInformationToken ZwOpenProcessTokenEx ZwAllocateVirtualMemory PsGetProcessSessionId KeStackAttachProcess KeUnstackDetachProcess KeBugCheckEx |
---|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 0.4.0.130 |
ProductVersion | 0.4.0.130 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
FileVersion (#2) | 0.4.0.130 |
LegalCopyright | Copyright (C) 2016 |
ProductVersion (#2) | 0.4.0.130 |
Resource LangID | Chinese - PRC |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Sep-27 16:51:39 |
Version | 0.0 |
SizeofData | 61 |
AddressOfRawData | 0x96f4 |
PointerToRawData | 0x86f4 |
Referenced File | E:\temp\trunk\output\LcScience64.pdb |
Size | 0x94 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14000b1c8 |
XOR Key | 0xc40369bb |
---|---|
Unmarked objects | 0 |
Total imports | 84 |
Imports (VS2008 SP1 build 30729) | 3 |
C objects (VS2008 SP1 build 30729) | 2 |
ASM objects (VS2008 SP1 build 30729) | 3 |
C objects (65501) | 4 |
ASM objects (65501) | 1 |
C objects (VS2013 UPD4 build 31101) | 14 |
Resource objects (VS2013 build 21005) | 1 |
Linker (VS2013 UPD4 build 31101) | 1 |