Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-May-11 05:35:45 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 156 is possibly compressed or encrypted. |
Malicious | VirusTotal score: 55/69 (Scanned on 2018-10-02 18:11:24) |
Bkav:
W32.BochachaAG.Trojan
MicroWorld-eScan: Trojan.GenericKD.30770255 CAT-QuickHeal: Trojan.Mauvaise.SL1 ALYac: Trojan.Ransom.Rapid Cylance: Unsafe Zillya: Trojan.GenericKD.Win32.160890 K7AntiVirus: Adware ( 004e096c1 ) BitDefender: Trojan.GenericKD.30770255 K7GW: Adware ( 004e096c1 ) Arcabit: Trojan.Generic.D1D5844F TrendMicro: Ransom_RAPID.THEBAAH F-Prot: W32/S-e898dea3!Eldorado Symantec: Trojan.Gen.2 TrendMicro-HouseCall: Ransom_RAPID.THEBAAH Paloalto: generic.ml Kaspersky: HEUR:Trojan.Win32.Generic NANO-Antivirus: Trojan.Win32.Chapak.fcazgp ViRobot: Trojan.Win32.GandCrab.322569 AegisLab: Packer.Generic!c Rising: Trojan.Kryptik!1.B22E (CLOUD) Endgame: malicious (high confidence) Emsisoft: Trojan.GenericKD.30770255 (B) Comodo: UnclassifiedMalware F-Secure: Trojan.GenericKD.30770255 DrWeb: Trojan.Encoder.24384 VIPRE: Trojan.Win32.Generic!BT Invincea: heuristic McAfee-GW-Edition: BehavesLike.Win32.Generic.dh Fortinet: W32/Kryptik.GKJF!tr SentinelOne: static engine - malicious Cyren: W32/S-e898dea3!Eldorado Jiangmin: Trojan.GandCrypt.ci Webroot: W32.Adware.Gen Avira: HEUR/AGEN.1035231 MAX: malware (ai score=100) Microsoft: Ransom:Win32/Genasom SUPERAntiSpyware: Trojan.Agent/Gen-Kryptik AhnLab-V3: Win-Trojan/Gandcrab01.Exp ZoneAlarm: HEUR:Trojan.Win32.Generic Sophos: Mal/GandCrab-B ESET-NOD32: a variant of Win32/Kryptik.GGQN McAfee: RDN/Generic.hbg AVware: Trojan.Win32.Generic!BT VBA32: TrojanRansom.GandCrypt Malwarebytes: Trojan.MalPack Panda: Trj/CI.A Tencent: Win32.Trojan.Chapak.Htvk Yandex: Trojan.Chapak! Ikarus: Trojan.Win32.Crypt GData: Win32.Trojan-Ransom.GandCrab.N Ad-Aware: Trojan.GenericKD.30770255 AVG: Win32:Malware-gen Avast: Win32:Malware-gen CrowdStrike: malicious_confidence_60% (D) Qihoo-360: Win32/Trojan.c76 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-May-11 05:35:45 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x17600 |
SizeOfInitializedData | 0xa587400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005DF2 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x19000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xa5a3000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3e03e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTapePosition
lstrlenW GetProcAddress LoadLibraryA FindFirstVolumeMountPointA GetThreadPriority AddConsoleAliasA GlobalAlloc CreateFileW FlushFileBuffers WriteConsoleW SetStdHandle OutputDebugStringW LoadLibraryExW SetFilePointerEx GetConsoleMode lstrlenA WaitForSingleObject CloseHandle PulseEvent WideCharToMultiByte EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection MultiByteToWideChar GetStringTypeW GetLastError HeapFree GetCommandLineA GetCPInfo RaiseException RtlUnwind HeapAlloc IsProcessorFeaturePresent UnhandledExceptionFilter SetUnhandledExceptionFilter SetLastError InitializeCriticalSectionAndSpinCount Sleep GetCurrentProcess TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetStartupInfoW GetModuleHandleW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW IsDebuggerPresent GetProcessHeap GetCurrentThreadId ExitProcess GetModuleHandleExW HeapSize GetStdHandle GetFileType GetModuleFileNameA WriteFile GetModuleFileNameW QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime GetEnvironmentStringsW FreeEnvironmentStringsW IsValidCodePage GetACP GetOEMCP HeapReAlloc GetConsoleCP |
---|---|
USER32.dll |
DrawCaption
IsChild DeleteMenu GetWindowTextLengthA MapVirtualKeyA LoadCursorFromFileW PostMessageA GetMenuInfo GetWindow |
GDI32.dll |
SetMapMode
|
ADVAPI32.dll |
ReportEventA
|
Gumegeda gupegaleheruwa gobukire de |
Voco xuvazege sucidu lasabahohome gevula heloyeho zojikilovaxa ru |
Jedamacavi yeyojele fuwahokeno nohuwumipu tedi mabozodese yi lemejevuxotipu |
Xabone ramuyokeza |
Yoxitijigu desu hanudi |
Teramexizosima keluxepuve mira zelerinekabati gisojerojezo tolupa sisulimuri |
Rivu |
Jufuro dehuhamoveto ketumo difejigefaso zamoluyu |
Xuvuwa jeyowu jovutuzudiposu xezoyirudipu fopicivehopowe |
Ru kukiyipucaje |
Bonaxi wiyo vizicesehizu jiza yonizinuki sihi nitufatotovo hewimipuzigovu jozilu wibadu |
Vazefabofavise funotudovoza wesoji metasujinefe geci pa no luyifozobe |
Catu |
Bageguzovewa naveto gisadaya rojo hefajagomate |
Lisozaze lopuguye wotunedobedu hixoti wiroza coyemibatiyupi |
Fisenogifakeku honi vasowoma zajitezapuvayi tolohureje vutusibebicixi dusawericeci |
Doraju xejilizu yowi jufebo doyilubuli coki |
Cakuja kacoza zususezebonu lise tusidafohixeka hotiyiwifuvuda moni xuxahotogu |
Lagobaji rasularule ga fefojixe jalugivocifawi zaletexirubodo xuye budamozigohaxa |
Degumofi pasi cajocowe |
Cucipiwe te wavasa loge juxosidijoharu xayo |
Zopizusu moko |
Jukeyu pocunucipojafi yayama pinonebaza hinoja goho xogameki xi |
Gihepipigudi si |
Lowo xuwuyelepena darajuho jojinupucayiru redo |
Nucosego gilibobixayo |
Gelavomejuca |
Fiteyiya pelitayazu kesijavobohi sabi yoho xucojanu |
Hikeba zukilajatovi tacofu gorakojatobu |
Medapiposijepa |
Wucatojosutuya |
Gacikuyi letozoyihebe zobuwuciwudoca duferojudewo |
Pofo xobanijodirivu |
Wutogogi difegoribiwi |
Wuze juvinehi siviho hicefogavohazo |
Ri fezidawa zugeniyokulu yesepu hezimo sa fodidusepeja cudage muvafalomiseyi cuwatitakoneye |
Mejozuzuyuwa kocapa vayifire biguheyihe mesu |
Poridukaferaho domafemiro cidareja xulada wimiduvitana |
Hi furajodacira ricivu posamizezahoma sowakuzu kaku pikikumujagubo lagijonava jigoyu |
Gulucu rukeyuroyupo hevelivudubiyu yina xodeyadosawe wecarixage virehu husezoyi fuwupivizimaja kacanaluhi |
Hofe |
Xoyefepuwahu jecugetutunivi leralu wafujojoxaruku lurazapunekuce dolapedu bo |
Cawijataze pureduneyijo mocugagahu |
Tutolorubewo mapebokazumi gesakuki |
Tunodolekoxo sizeveke cecudixetixake herese yetasoho rabenusereva takeneva |
Pacelu nuyifu nogaceboraco yenusa luwahozepumoju hogorunufigu |
Natoduho kejekayilaka |
Fafa |
Delo cifucavoxilitu vabu jupe xoyixuhapi kosi hemukuxabikugi kijabeso gutuyo zukonipi |
Dolipowelileba xupewu rixazona |
Yaneyevetuwipu febedopi yocomujiyezejo susutimevu mavi zasehapezofo gijuxo |
Cuza locitotebosi nimusebu yubepijepa puhaso |
Yukoxuhiru renagepuxakeni hi fezace silotamomoxi hu lone xesodamerure ladupado |
Yiwa yaye hacubenegijugu |
Xelo zopo vuzevokubo munavepoxarozu |
Buzolufafora |
Haloxudelihe bomiwaroti jaxosuhevoyeca mi bezivehu duninexa wuvofapexawi xusukazerera cosugo balixiwe |
Femaxusunutave cehenu bepuhugu wuje jixa fu |
Notalefebuha fucayepe caxubofo serogatidi fevi cezakowukewo fejavehebaji givihazifuya cizogizanu gipaya |
Fodujugifoyuni cekinobemitoku wacitixahaluxu |
Pinecesaxi kula tebutohutejijo bodugorekoso recusotu |
Zaxafixo ba moyevetizababa gewoxodo |
Finaradolonumu wiwitowepore jezalefewuxamu xetajovowo taxayula |
Gorayocicene hozogolehejo sazobilonoziwo |
Tikefevasukena hewehove mari wikujinucewuza zaludavako |
Niborukikekimu xurupo vojurotavugoyi yiyugosekadoha jedumiyabedase |
Fazenevidizaho kaledeticegoda cegudohako mojewehogidipo kafusucoja xifogujeyi tabemojeyu zebazobupuyobu metelawefi |
Xohilu jusucufususabo heni hideyadizerule viyahu dejitafepi jiwagekuwizume |
Danepi kotigodi muwusocu diwuze mikevasohi rovacopisagibe pisa toxi |
Dolezosiwayu humuni ciduladipibawe sacavawi cewecotu wijaharorajuco zibubajoce |
Rarupixoyo wahulepoki kuwu cetuma gikezaca cudicuzo danecololaru malivuzawuju kigisunudoxefe sepexuje |
Boxisitofijiva hima daxucohecavu liladoxu napibifu zidagoso sepudaheme |
Gigore ri vekeka risaru ginile vusu |
Yihuruya deyafi pihajabonorexo keneve kivubaki veke |
Tuca wozibiyuhu renosu xipame nuponaga rozukafotovibi bozuvemayuzu te |
Libuze vahilipezipaxu rotocomupekofe ridimarijo |
Racurema xojose wumaja mepozo |
Mirogifunohabu zo novi tekicole senimupe zumotibo |
Nodi pececidujuciye xawekozari |
Lugezelokaxefa molaliyevexe faki wo be koyetepeze soka xovovahoteri bewivo johikinoniwohe |
Gecavapubaxaxi hibofexe |
Kazahaviwexe peniwanegi kicudoso |
Rabuzo gasojisorizose |
Budiwuzahi beliga |
Cesapajaye yazedexi sudoyomuhosa |
Bata rikiyahavi xurifizaki xuhikatipucaxe |
Jirehebe taje daraguluyoda wohu |
Cekodi kicisupizipika rebegivine |
Howusoceguto sixuxacojo fodagolu hito kihonize zigesoje vilohamocu gorozotahuja miju |
Pi josudota kupove temulavifiposo |
Yeruxiyehoxi decekajegexo zayagopegi yutusu wofobolikuhu bujojukalolijo ga |
Xecufa zukofatepaxudo cagigiyove kesodoxo fezavu yubokejuni kudihube kopukafolozepi |
Saxulu civavu hufirazepi bomigi fuzihu |
Nasabuga kuku ceha |
Bugukuwu |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x16bf054c |
---|---|
Unmarked objects | 0 |
ASM objects (VS2013 build 21005) | 28 |
C++ objects (VS2013 build 21005) | 65 |
C objects (VS2013 build 21005) | 179 |
Imports (VS2008 SP1 build 30729) | 9 |
Total imports | 99 |
229 (VS2013 UPD5 build 40629) | 1 |
Resource objects (VS2013 build 21005) | 1 |
Linker (VS2013 UPD5 build 40629) | 1 |