Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2014-Feb-15 06:32:39 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
Malicious | The file headers were tampered with. | The RICH header checksum is invalid. |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
3212 bytes of data starting at offset 0xd0600.
The overlay data has an entropy of 7.94659 and is possibly compressed or encrypted. |
Malicious | VirusTotal score: 24/49 (Scanned on 2014-03-15 09:07:11) |
MicroWorld-eScan:
Gen:Variant.Symmi.37420
CMC: Packed.Win32.Hrup.2!O McAfee: Artemis!87E221027DC4 NANO-Antivirus: Trojan.Win32.Ponmocup.cumdag Norman: Troj_Generic.SZULO TrendMicro-HouseCall: TROJ_GEN.F47V0314 Avast: Win32:Malware-gen Kaspersky: HEUR:Trojan.Win32.Generic BitDefender: Gen:Variant.Symmi.37420 SUPERAntiSpyware: Trojan.Agent/Gen-Ponmocup Ad-Aware: Gen:Variant.Symmi.37420 Sophos: Mal/Generic-S Comodo: UnclassifiedMalware F-Secure: Gen:Variant.Symmi.37420 DrWeb: Trojan.DownLoader7.14920 VIPRE: Trojan.Win32.Vundo.aba (v) AntiVir: TR/Crypt.ZPACK.55740 McAfee-GW-Edition: Artemis!87E221027DC4 Emsisoft: Gen:Variant.Symmi.37420 (B) Antiy-AVL: Trojan/Win32.SGeneric GData: Gen:Variant.Symmi.37420 ESET-NOD32: a variant of Win32/Ponmocup.IP.gen AVG: Crypt3.CJJ Panda: Suspicious file |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2014-Feb-15 06:32:39 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x13600 |
SizeOfInitializedData | 0xc0200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000EA99 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x15000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xd6000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
VirtualAlloc
GetProcAddress GetModuleHandleW ExitProcess DecodePointer GetCommandLineA HeapSetInformation GetStartupInfoW IsProcessorFeaturePresent InitializeCriticalSectionAndSpinCount DeleteCriticalSection LeaveCriticalSection FatalAppExitA EnterCriticalSection EncodePointer GetLastError SetConsoleCtrlHandler FreeLibrary InterlockedExchange LoadLibraryW GetLocaleInfoW UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent TerminateProcess GetCurrentProcess TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement GetCurrentThread WriteFile GetStdHandle GetModuleFileNameW GetModuleFileNameA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType HeapCreate HeapDestroy QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime HeapFree Sleep GetCPInfo GetACP GetOEMCP IsValidCodePage HeapSize RtlUnwind HeapAlloc HeapReAlloc LCMapStringW MultiByteToWideChar GetStringTypeW |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4d2184 |
SEHandlerTable | 0x498910 |
SEHandlerCount | 3 |
XOR Key | 0x579f7768 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2008 SP1 build 30729) | 1 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 build 21022) | 2 |
C objects (30311) | 1 |
Imports (VS2008 SP1 build 30729) | 3 |
Imports (VS2010 build 30319) | 2 |
Total imports | 64 |
152 (20115) | 1 |
ASM objects (VS2010 build 30319) | 1 |
C objects (VS2010 build 30319) | 20 |
C++ objects (VS2010 build 30319) | 6 |
C++ objects (30311) | 6 |
Resource objects (30311) | 1 |
Linker (30311) | 1 |