Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Apr-11 08:35:20 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 3/65 (Scanned on 2018-06-05 00:18:07) |
Bkav:
W32.eHeur.Malware14
Cylance: Unsafe Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9994 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2017-Apr-11 08:35:20 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x6e00 |
SizeOfInitializedData | 0x4200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001242 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x8000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x10000 |
SizeOfHeaders | 0x400 |
Checksum | 0xf385 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
WaitForSingleObject
VirtualAlloc CreateThread GetCommandLineA HeapSetInformation GetProcAddress GetModuleHandleW ExitProcess DecodePointer SetUnhandledExceptionFilter WriteFile GetStdHandle GetModuleFileNameW GetModuleFileNameA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW DeleteCriticalSection EncodePointer TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId GetLastError InterlockedDecrement HeapCreate QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime TerminateProcess GetCurrentProcess UnhandledExceptionFilter IsDebuggerPresent EnterCriticalSection LeaveCriticalSection LoadLibraryW HeapFree Sleep GetCPInfo GetACP GetOEMCP IsValidCodePage RtlUnwind HeapSize HeapAlloc HeapReAlloc LCMapStringW MultiByteToWideChar GetStringTypeW GetConsoleCP GetConsoleMode FlushFileBuffers SetFilePointer IsProcessorFeaturePresent CloseHandle WriteConsoleW SetStdHandle CreateFileW |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40b060 |
SEHandlerTable | 0x409a10 |
SEHandlerCount | 3 |
XOR Key | 0x892aaed6 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 3 |
Total imports | 77 |
C++ objects (VS2010 build 30319) | 23 |
ASM objects (VS2010 build 30319) | 15 |
C objects (VS2010 build 30319) | 84 |
174 (VS2010 build 30319) | 1 |
Linker (VS2010 build 30319) | 1 |