Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Jun-27 13:05:49 |
Detected languages |
English - United States
|
Comments | Zeje veximosakixuzi rojegoko mahedogujekole zi jufizorozaro rozofoba vufepamacora |
FileVersion | 26, 10, 3, 37 |
LegalCopyright | Wejigabohari |
LegalTrademarks | Gulaxafadi lakihoke rujiwisi pu vejato rihelixeja fobasigowofe |
ProductVersion | 26, 10, 3, 37 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 143 is possibly compressed or encrypted. |
Malicious | VirusTotal score: 50/64 (Scanned on 2017-07-17 20:49:15) |
MicroWorld-eScan:
Trojan.GenericKD.5520679
CMC: Trojan-Downloader.Win32.Gamarue.2!O CAT-QuickHeal: TrojanBanker.Emotet ALYac: Trojan.GenericKD.5520679 Malwarebytes: Trojan.Injector VIPRE: Trojan.Win32.Generic!BT K7GW: Trojan ( 005110a31 ) K7AntiVirus: Trojan ( 005110a31 ) Invincea: heuristic Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9997 Symantec: Ransom.Kovter TrendMicro-HouseCall: TROJ_EMOTET.XXTY Avast: Win32:Malware-gen Kaspersky: Trojan-Banker.Win32.Emotet.vpi BitDefender: Trojan.GenericKD.5520679 NANO-Antivirus: Trojan.Win32.Emotet.eqnkml ViRobot: Trojan.Win32.Agent.208384.K AegisLab: Ml.Attribute.Gen!c Rising: Trojan.Emotet!8.B95 (cloud:sPyaITM3AjE) Ad-Aware: Trojan.GenericKD.5520679 Sophos: Mal/Generic-S F-Secure: Trojan.GenericKD.5520679 DrWeb: Trojan.Siggen7.21438 Zillya: Trojan.Emotet.Win32.751 TrendMicro: TROJ_EMOTET.XXTY McAfee-GW-Edition: BehavesLike.Win32.FakeAlertSecurityTool.dc Emsisoft: Trojan.GenericKD.5520679 (B) SentinelOne: static engine - malicious Cyren: W32/Trojan.PCTX-2702 Jiangmin: Trojan.Banker.Emotet.av Webroot: W32.Trojan.Gen Avira: TR/Crypt.Xpack.nhrvm Antiy-AVL: Trojan[Banker]/Win32.Emotet Microsoft: Trojan:Win32/Emotet.K Endgame: malicious (high confidence) Arcabit: Trojan.Generic.D543D27 ZoneAlarm: Trojan-Banker.Win32.Emotet.vpi GData: Win32.Trojan-Spy.Emotet.AC AhnLab-V3: Trojan/Win32.Inject.C2021913 McAfee: Packed-NA!7DD17081FB73 AVware: Trojan.Win32.Generic!BT Panda: Trj/GdSda.A ESET-NOD32: a variant of Win32/Kryptik.FTYF Tencent: Win32.Trojan.Inject.Auto Yandex: Trojan.PWS.Emotet! Ikarus: Trojan.Win32.Krypt Fortinet: W32/GenKryptik.ALTJ!tr AVG: Win32:Malware-gen Paloalto: generic.ml CrowdStrike: malicious_confidence_90% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2017-Jun-27 13:05:49 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0xb200 |
SizeOfInitializedData | 0x28400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001431 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xd000 |
ImageBase | 0x1100000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x36000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3e939 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetSystemTimes
GetThreadSelectorEntry GetSystemTimeAdjustment GetACP GetProcAddress LoadLibraryA GetCommandLineA GetStartupInfoA TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetModuleHandleW Sleep ExitProcess WriteFile GetStdHandle GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetLastError GetEnvironmentStringsW SetHandleCount GetFileType DeleteCriticalSection TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapCreate VirtualFree HeapFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime RaiseException GetModuleHandleA LeaveCriticalSection EnterCriticalSection InitializeCriticalSectionAndSpinCount GetCPInfo GetOEMCP IsValidCodePage HeapAlloc VirtualAlloc HeapReAlloc RtlUnwind HeapSize GetLocaleInfoA LCMapStringA MultiByteToWideChar LCMapStringW GetStringTypeA GetStringTypeW |
---|---|
USER32.dll |
GetNextDlgTabItem
RealGetWindowClassW GetAltTabInfoW GetDlgCtrlID |
WINHTTP.dll |
WinHttpCloseHandle
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 26.10.3.37 |
ProductVersion | 26.10.3.37 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
Comments | Zeje veximosakixuzi rojegoko mahedogujekole zi jufizorozaro rozofoba vufepamacora |
FileVersion (#2) | 26, 10, 3, 37 |
LegalCopyright | Wejigabohari |
LegalTrademarks | Gulaxafadi lakihoke rujiwisi pu vejato rihelixeja fobasigowofe |
ProductVersion (#2) | 26, 10, 3, 37 |
Resource LangID | UNKNOWN |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x111100c |
SEHandlerTable | 0x110ff90 |
SEHandlerCount | 3 |
XOR Key | 0xe61ef640 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2008 build 21022) | 28 |
ASM objects (VS2008 build 21022) | 25 |
C objects (VS2008 build 21022) | 96 |
Total imports | 83 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 7 |
138 (VS2008 build 21022) | 1 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 build 21022) | 1 |