Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Malicious | VirusTotal score: 38/69 (Scanned on 2023-09-22 08:58:59) |
ALYac:
Gen:Variant.Zusy.489786
AVG: Win32:MalwareX-gen [Trj] AhnLab-V3: Trojan/Win.Generic.C5488559 Alibaba: Trojan:Win32/Redcap.69ddcf3c Antiy-AVL: Trojan/Win32.Delf Arcabit: Trojan.Zusy.D7793A Avast: Win32:MalwareX-gen [Trj] Avira: TR/Redcap.uuylg BitDefender: Gen:Variant.Zusy.489786 Bkav: W32.Common.9710E649 CrowdStrike: win/grayware_confidence_70% (D) Cynet: Malicious (score: 99) DrWeb: Trojan.Siggen21.30405 ESET-NOD32: a variant of Win32/Delf.UZB Emsisoft: Gen:Variant.Zusy.489786 (B) F-Secure: Trojan.TR/Redcap.uuylg FireEye: Gen:Variant.Zusy.489786 Fortinet: W32/Delf.UZB!tr GData: Gen:Variant.Zusy.489786 Google: Detected Ikarus: Trojan.DarkGate Jiangmin: Trojan.Agent.eruq K7AntiVirus: Trojan ( 005a5c941 ) K7GW: Trojan ( 005a5c941 ) Kaspersky: HEUR:Trojan.Win32.Agent.gen MAX: malware (ai score=81) Malwarebytes: Malware.AI.2643273264 MaxSecure: Trojan.Malware.300983.susgen McAfee: GenericRXAA-AA!85DD61EC4125 MicroWorld-eScan: Gen:Variant.Zusy.489786 Microsoft: Trojan:Win32/Sabsik.TE.B!ml NANO-Antivirus: Trojan.Win32.Delf.kavbgd Panda: Trj/GdSda.A Rising: Trojan.Delf!8.67 (TFE:5:6FY8tWTQ8aE) TrendMicro: TROJ_GEN.R002C0XIL23 TrendMicro-HouseCall: TROJ_GEN.R002C0XIL23 VIPRE: Gen:Variant.Zusy.489786 ZoneAlarm: HEUR:Trojan.Win32.Agent.gen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x75c00 |
SizeOfInitializedData | 0xfe00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00076A90 (Section: CODE) |
BaseOfCode | 0x1000 |
BaseOfData | 0x77000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x90000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_LIBRARY_PROCESS_INIT
|
SizeofStackReserve | 0 |
SizeofStackCommit | 0 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
---|---|
user32.dll |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
kernel32.dll (#3) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
version.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
gdi32.dll |
UnrealizeObject
StretchBlt SetWindowOrgEx SetViewportOrgEx SetTextColor SetStretchBltMode SetROP2 SetPixel SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SelectPalette SelectObject SaveDC RestoreDC RectVisible RealizePalette PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetTextMetricsA GetTextExtentPoint32A GetSystemPaletteEntries GetStockObject GetPixel GetPaletteEntries GetObjectA GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits ExcludeClipRect DeleteObject DeleteDC CreateSolidBrush CreatePenIndirect CreatePalette CreateHalftonePalette CreateFontIndirectA CreateDIBitmap CreateDIBSection CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap BitBlt |
user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
kernel32.dll (#4) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
kernel32.dll (#5) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
comctl32.dll |
ImageList_SetIconSize
ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_SetDragCursorImage ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Remove ImageList_DrawEx ImageList_Draw ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_SetImageCount ImageList_GetImageCount ImageList_Destroy ImageList_Create |
Ordinal | 1 |
---|---|
Address | 0x763dc |
Ordinal | 2 |
---|---|
Address | 0x763e0 |
Ordinal | 3 |
---|---|
Address | 0x763e8 |
Ordinal | 4 |
---|---|
Address | 0x76410 |
Ordinal | 5 |
---|---|
Address | 0x7640c |
Ordinal | 6 |
---|---|
Address | 0x76408 |
Ordinal | 7 |
---|---|
Address | 0x76404 |
Ordinal | 8 |
---|---|
Address | 0x76414 |
Ordinal | 9 |
---|---|
Address | 0x76400 |
Ordinal | 10 |
---|---|
Address | 0x763fc |
Ordinal | 11 |
---|---|
Address | 0x763f8 |
Ordinal | 12 |
---|---|
Address | 0x763f4 |
Ordinal | 13 |
---|---|
Address | 0x763f0 |
Ordinal | 14 |
---|---|
Address | 0x763ec |
Ordinal | 15 |
---|---|
Address | 0x763e4 |
Ordinal | 16 |
---|---|
Address | 0x76418 |
Ordinal | 17 |
---|---|
Address | 0x7641c |
Window Background |
Window Frame |
Window Text |
No help keyword specified. |
Caption Text |
Default |
Gray Text |
Highlight Background |
Highlight Text |
Inactive Border |
Inactive Caption |
Inactive Caption Text |
Info Background |
Info Text |
Menu Background |
Menu Text |
None |
Scroll Bar |
3D Dark Shadow |
3D Light |
Blue |
Fuchsia |
Aqua |
White |
Money Green |
Sky Blue |
Cream |
Medium Gray |
Active Border |
Active Caption |
Application Workspace |
Background |
Button Face |
Button Highlight |
Button Shadow |
Button Text |
Unable to find a Table of Contents |
No help found for %s |
No context-sensitive help installed |
No topic-based help system installed |
Black |
Maroon |
Green |
Olive |
Navy |
Purple |
Teal |
Gray |
Silver |
Red |
Lime |
Yellow |
Home |
Left |
Up |
Right |
Down |
Ins |
Del |
Shift+ |
Ctrl+ |
Alt+ |
Clipboard does not support Icons |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
Cancel |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
Yes to &All |
BkSp |
Tab |
Esc |
Enter |
Space |
PgUp |
PgDn |
End |
Cannot make a visible window modal |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
Cannot drag a form |
Warning |
Error |
Information |
Confirm |
&Yes |
&No |
OK |
Icon image is not valid |
Cannot change the size of an icon |
Unsupported clipboard format |
Out of system resources |
Canvas does not allow drawing |
Invalid image size |
Invalid ImageList |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Invalid property path |
Invalid property value |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
Error reading %s%s%s: %s |
Stream read error |
Property is read-only |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
%s not in a class registration group |
Property %s does not exist |
Stream write error |
Bitmap image is not valid |
Friday |
Saturday |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Can't write to a read-only resource stream |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file "%s". %s |
Cannot open file "%s". %s |
Invalid stream format |
''%s'' is not a valid component name |
September |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
May |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
Invalid variant type conversion |
Invalid variant operation |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Custom variant type (%s%.4x) is out of range |
Custom variant type (%s%.4x) already used by %s |
Custom variant type (%s%.4x) is not usable |
Too many custom variant types have been registered |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
'%s' is not a valid integer value |
Invalid argument to time encode |
Invalid argument to date encode |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |