Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jun-13 06:17:06 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: ORDARA LTD
Issuer: Symantec Class 3 Extended Validation Code Signing CA - G2 |
Malicious | VirusTotal score: 46/70 (Scanned on 2019-10-22 06:21:33) |
MicroWorld-eScan:
Trojan.GenericKD.41843578
CAT-QuickHeal: Trojan.Alreay McAfee: Trojan-Banking Cylance: Unsafe Zillya: Trojan.Alreay.Win32.96 K7AntiVirus: Riskware ( 0040eff71 ) BitDefender: Trojan.GenericKD.41843578 K7GW: Riskware ( 0040eff71 ) CrowdStrike: win/malicious_confidence_100% (W) TrendMicro: TROJ_NOROINHECTOR.ZKGJ Symantec: Trojan Horse ESET-NOD32: a variant of Generik.CWSORYC Paloalto: generic.ml ClamAV: Win.Trojan.Alreay-7189192-0 Kaspersky: Trojan-Banker.Win32.Alreay.gen Alibaba: TrojanBanker:Win32/Alreay.53f12375 Avast: Win32:Malware-gen Ad-Aware: Trojan.GenericKD.41843578 Sophos: Troj/Banker-GYS DrWeb: Trojan.Inject3.28611 VIPRE: Trojan.Win32.Generic!BT Invincea: heuristic McAfee-GW-Edition: Trojan-Banking Trapmine: malicious.high.ml.score FireEye: Trojan.GenericKD.41843578 Emsisoft: Trojan.GenericKD.41843578 (B) SentinelOne: DFI - Suspicious PE Cyren: W32/Trojan.QCFO-5814 Jiangmin: Trojan.Banker.Alreay.cg Antiy-AVL: Trojan[Banker]/Win32.Alreay Microsoft: Trojan:Win32/LazInjector.DD!MSR Arcabit: Trojan.Generic.D27E7B7A ZoneAlarm: Trojan-Banker.Win32.Alreay.gen GData: Trojan.GenericKD.41843578 AhnLab-V3: HackTool/Win32.Injector.C3480956 ALYac: Spyware.Banker.Alreay MAX: malware (ai score=89) VBA32: TrojanBanker.Alreay TrendMicro-HouseCall: TROJ_NOROINHECTOR.ZKGJ Yandex: Trojan.PWS.Alreay! Ikarus: Trojan.Inject MaxSecure: Trojan.Malware.9448723.susgen Fortinet: W32/Alreay.A!tr AVG: Win32:Malware-gen Panda: Trj/GdSda.A Qihoo-360: Win32/Trojan.9db |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Jun-13 06:17:06 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x9800 |
SizeOfInitializedData | 0x4a00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001FD7 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x13000 |
SizeOfHeaders | 0x400 |
Checksum | 0x14afd |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LoadLibraryA
GetLastError OpenProcess VirtualAllocEx WriteProcessMemory GetProcAddress WaitForSingleObject CreateToolhelp32Snapshot Module32First Module32Next CloseHandle GetCurrentProcess GetModuleHandleA GetLocalTime GetModuleHandleW ExitProcess DecodePointer GetCommandLineA HeapSetInformation GetStartupInfoW TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent EncodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount RtlUnwind SetHandleCount GetStdHandle GetFileType DeleteCriticalSection HeapFree LoadLibraryW TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement WriteFile GetModuleFileNameW GetModuleFileNameA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW HeapCreate QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime SetFilePointer GetConsoleCP GetConsoleMode GetCPInfo GetACP GetOEMCP IsValidCodePage Sleep CreateFileA SetStdHandle FlushFileBuffers HeapSize WriteConsoleW MultiByteToWideChar LCMapStringW GetStringTypeW HeapAlloc HeapReAlloc IsProcessorFeaturePresent SetEndOfFile GetProcessHeap ReadFile CreateFileW |
---|---|
ADVAPI32.dll |
LookupPrivilegeValueA
OpenProcessToken AdjustTokenPrivileges |
SHLWAPI.dll |
PathFileExistsA
|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40e004 |
SEHandlerTable | 0x40cdb0 |
SEHandlerCount | 3 |
XOR Key | 0x557b9d30 |
---|---|
Unmarked objects | 0 |
152 (20115) | 1 |
C++ objects (VS2010 build 30319) | 25 |
ASM objects (VS2010 build 30319) | 14 |
C objects (VS2010 build 30319) | 98 |
Imports (VS2008 SP1 build 30729) | 7 |
Total imports | 92 |
175 (VS2010 build 30319) | 2 |
Linker (VS2010 build 30319) | 1 |