Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2018-Nov-20 01:28:30 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\degrigis\documents\visual studio 2010\Projects\DolphinDropperAES\Release\DolphinDropperAES.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to AES |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
1233257 bytes of data starting at offset 0xa600.
Overlay data amounts for 96.6689% of the executable. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Nov-20 01:28:30 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x5400 |
SizeOfInitializedData | 0x4e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001D75 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xf000 |
SizeOfHeaders | 0x400 |
Checksum | 0x17f52 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetModuleFileNameA
OpenFile GetFileSize CreateFileMappingW MapViewOfFile VirtualAlloc CreateFileW WriteFile CloseHandle GetCommandLineW HeapSetInformation TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent EncodePointer DecodePointer HeapAlloc RaiseException GetProcAddress GetModuleHandleW ExitProcess GetStdHandle GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW DeleteCriticalSection TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId GetLastError InterlockedDecrement HeapCreate QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime HeapFree Sleep HeapSize LeaveCriticalSection EnterCriticalSection LoadLibraryW GetCPInfo GetACP GetOEMCP IsValidCodePage RtlUnwind HeapReAlloc WideCharToMultiByte IsProcessorFeaturePresent LCMapStringW MultiByteToWideChar GetStringTypeW |
---|---|
SHELL32.dll |
ShellExecuteW
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-20 01:28:30 |
Version | 0.0 |
SizeofData | 128 |
AddressOfRawData | 0x92b8 |
PointerToRawData | 0x7ab8 |
Referenced File | C:\Users\degrigis\documents\visual studio 2010\Projects\DolphinDropperAES\Release\DolphinDropperAES.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40a03c |
SEHandlerTable | 0x409420 |
SEHandlerCount | 3 |
XOR Key | 0x6ba9c413 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2010 SP1 build 40219) | 24 |
ASM objects (VS2010 SP1 build 40219) | 14 |
C objects (VS2010 SP1 build 40219) | 66 |
Imports (VS2008 SP1 build 30729) | 5 |
Total imports | 75 |
175 (VS2010 SP1 build 40219) | 2 |
Linker (VS2010 SP1 build 40219) | 1 |