96a10fc5ead4403fafd235a9ce4fe44a

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2012-Dec-21 20:59:46

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
MASM/TASM - sig1(h)
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Suspicious The PE is possibly a dropper. Resource DLL is possibly compressed or encrypted.
Resources amount for 99.3979% of the executable.
Malicious VirusTotal score: 48/68 (Scanned on 2019-11-24 20:56:15) MicroWorld-eScan: Dropped:Trojan.Generic.23064886
CAT-QuickHeal: Riskware.Dupatcher.A4
McAfee: FilePatcher
Malwarebytes: HackTool.FilePatch
Zillya: Tool.Patcher.Win32.23296
K7AntiVirus: Trojan ( 0040f3a51 )
Alibaba: HackTool:Win32/Patcher.d3b1b7cb
K7GW: Trojan ( 0040f3a51 )
CrowdStrike: win/malicious_confidence_80% (D)
Arcabit: Trojan.Generic.D15FF136
Baidu: Win32.Trojan.Generic.f
Cyren: W32/Agent.EWQQ-1275
Symantec: PUA.Keygen
ESET-NOD32: a variant of Win32/HackTool.Patcher.AD potentially unsafe
APEX: Malicious
Paloalto: generic.ml
BitDefender: Dropped:Trojan.Generic.23064886
SUPERAntiSpyware: Hack.Tool/Gen-Patcher
Ad-Aware: Dropped:Trojan.Generic.23064886
Sophos: Generic Patcher (PUA)
Comodo: TrojWare.Win32.Agent.WFN@4t5srs
VIPRE: Trojan.Win32.Agent.wfn (v)
TrendMicro: TROJ_GEN.R014C0OE919
McAfee-GW-Edition: BehavesLike.Win32.PUPXFQ.bz
Fortinet: Riskware/GamePatcher
Trapmine: malicious.moderate.ml.score
FireEye: Generic.mg.96a10fc5ead4403f
Emsisoft: Dropped:Trojan.Generic.23064886 (B)
SentinelOne: DFI - Malicious PE
F-Prot: W32/Agent.KFY
Webroot: W32.Hacktool.Gen
MAX: malware (ai score=100)
Antiy-AVL: RiskWare[RiskTool]/Win32.Patcher
Endgame: malicious (high confidence)
Microsoft: PUA:Win32/Keygen
AhnLab-V3: HackTool/Win32.Patcher.C2563559
Acronis: suspicious
ALYac: Dropped:Trojan.Generic.23064886
Cylance: Unsafe
TrendMicro-HouseCall: TROJ_GEN.R014C0OE919
Rising: PUF.Patcher!1.B3BB (CLASSIC)
Yandex: Riskware.HackTool!LT2poWNG63M
Ikarus: PUA.HackTool.Patcher
GData: Win32.Riskware.Patcher.E
BitDefenderTheta: Gen:Trojan.Heur2.FU.WuW@aqPiTKg
AVG: FileRepMalware
Cybereason: malicious.5ead44
Panda: Trj/CI.A

Hashes

MD5 96a10fc5ead4403fafd235a9ce4fe44a
SHA1 cf7c7a7214b00b3631c1a98a02624d427150059c
SHA256 d684d4c53a92951654dee974484433b211375ee600f364abcd42b5d692c1cafa
SHA3 0cebb679d30f19dded18b720527034d28f69071ae1d900bd5f4be5bc108650c8
SSDeep 1536:kvYNK7IhH5QkbinWnmoJRwzX6EfG8ti6CwbwLFvDWt3RTbmT5O6H3LOXPLDRztr:kk6SLxDWpChKzRtYC6L3
Imports Hash dc73a9bd8de0fd640549c85ac4089b87

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2012-Dec-21 20:59:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0x200
SizeOfInitializedData 0xc2000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000102B (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0xc7000
SizeOfHeaders 0x400
Checksum 0xecdd
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4c584307e5aa70f515ee8c3d942e5f6c
SHA1 05668764efd56b4a53d8574ff9dec26b851ca07b
SHA256 9c0c821fe1c66ad45a044fec0be845fa08b96ea7b7c24e852b132a92fe08a90c
SHA3 a56964eb90adb7bd0f5c92dbd62425658cbd2b396621386f34ca3397e2a0465f
VirtualSize 0x1f6
VirtualAddress 0x1000
SizeOfRawData 0x200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.06408

.rdata

MD5 e5aa65265e17d8a1b524adbc10c0a1ad
SHA1 0e0eb11d610df253f860f9b46790f28f7477d12a
SHA256 b8af2ef3ea5c0fb35d0c846a94425f028f8cdba30eefbb401377749e0266640b
SHA3 7c0d77a4d031c3944bb719376c53cf53fc047471e027fa4f69aacd44c986f6a8
VirtualSize 0x1d8
VirtualAddress 0x2000
SizeOfRawData 0x200
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.27064

.data

MD5 f8fedf1be1122ff5cd0e5b4716311cc5
SHA1 c41831c104ced77633be9d2b09364c22a9392a73
SHA256 b23a9af37c2bfeb0bcb17555a8038d0403b12616851e58513e9135a77c84363b
SHA3 eed0f7054aa182d7497331ee77969143efb3a63e8fee1ed02e44e82494404132
VirtualSize 0x34
VirtualAddress 0x3000
SizeOfRawData 0x200
PointerToRawData 0x800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.568988

.rsrc

MD5 4c04e134beef359509dd3c9fc3e29c59
SHA1 caecfa7c7aa8f1d40d3d5482681dfc50f6156cbf
SHA256 afe73202b00927d2a13ada116eeb98deb95393beeb6279e6681b48188c4038c3
SHA3 1a3f3f41bcf23ec04a610d9a60e3a018ad60ec1093d240a56162c1a1edcd79e2
VirtualSize 0xc1840
VirtualAddress 0x4000
SizeOfRawData 0xc1a00
PointerToRawData 0xa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.62485

.reloc

MD5 2e6554ffc943448b686d85ad68f9ec9a
SHA1 2983937fa0491ffb874e3d5084ddc909f7b417ba
SHA256 4bb6e032bb8a0cc87b345564204b1e74d8eb2ed7665c2a1d82dcd3b3096bf885
SHA3 1037aac5df319410ca7ed864e945ccb384d66f6e8ac2a1f9c2cfcdc03c63f497
VirtualSize 0x52
VirtualAddress 0xc6000
SizeOfRawData 0x200
PointerToRawData 0xc2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.736046

Imports

kernel32.dll DeleteFileA
ExitProcess
FindResourceA
FreeLibrary
GetModuleHandleA
GetProcAddress
GetTempPathA
LoadLibraryA
LoadResource
RtlMoveMemory
SizeofResource
VirtualAlloc
lstrcatA
CloseHandle
CreateFileA
FlushFileBuffers
WriteFile

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x12428
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98469
MD5 01b7a55c0206b7ae044f95eb88908404
SHA1 fac988ea792c1b72df36ba80f0f4b930d65d2b69
SHA256 ab67a0dd7d956a5922657e648267b468c3c9db7968ba523d6df62da3ece5de42
SHA3 7690bb3df5312c62b44f02f27c97c641fc019440e3d1b368dac58ef50899a619

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4c28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.23077
MD5 04f828c13b1a63f3f066a63ed4d2fd97
SHA1 83325121d848e937f89cb6c0fe72923903067d07
SHA256 0cd5bdb5d6d6b79b6ea8c9980f2695ab9ed41609d4f6a5a52fc0fbf4c6d37d06
SHA3 ed0ff7c896427169831363638a21a6441b06ebd33b49a68e3bf1abfb3fe8498b

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78327
MD5 70d391279a89c6fcf9203ca37f7cde86
SHA1 dd15b1dd602d6e12cb9255507a873415f1ba6583
SHA256 11f1acb46c4b5a3a4c6c616f87bf4c42861a1ff2133903ae9281a429b832abc8
SHA3 4a87a1264fe05015ef6cb5772aee0dd6e4a976f5a4b255e6ebf73396adb0542a

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31188
MD5 90894a11b7798da40b24fa1912602371
SHA1 f4f557abd3f72937d8711b8a9cba72b513745e31
SHA256 23f9fa3595e18dc3bfd88ed063a887fb79cfb710f4b1991fa1482e6f41f519b6
SHA3 8fe2b8825af26d395cd4a5a332f739a126a67ca9f2cce159f27e9f8bfff2d966

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.72472
MD5 58450f10cf62fe4927322a76cb460e4b
SHA1 2f29f260d2cd2eece619957ab48e6017a8b24d56
SHA256 8ad476de74ebbd942206aa798cbea081aff4cee720382a4c8e20518433666e78
SHA3 e74ca7d08b3458a8694ff73a71f1b12b19c1bacc73e11b84e4d68df86144a169

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x608
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.66556
MD5 b0febddb54cee30c6a4e58f7bf3c882f
SHA1 1bcbfc3400534e0c7aeb39f00e81d43ffffda6ba
SHA256 79252db7604bbf6b600a7ca8e52511dc8cb41c6bb2186a6e0904ff8d505b566a
SHA3 dfa48fb823755d0d7d7332d494805631d54ef7fe713fbdf0100888b41c8727f5

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.07754
MD5 8775e7f4d7f09c27b69838ab0197e0dc
SHA1 d2750c4d97cb1c1cd52309890c6e865451be2186
SHA256 65f1bfeaf1bc94e3f6d235dbeed62be7fa657d79437e6dbb1c1fa196de41f919
SHA3 762b4fb5382f28f93281bab26b7acbed071ab52972ca19bf93f0fd3153f343ea

8

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x32028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.55249
MD5 d8b07ecb0742ecda8b0c2c271cc4f919
SHA1 3e2c441e5bd46d933cc52620848bc6d5df0162c1
SHA256 15dfc17f0610b510d8b24561e681e855fdb9616d7f1729450918f5f3b6a33867
SHA3 b76480d5b4ae99d3bc4c8d5c8b708da97bbca9f36170fb9f9239dc22812d4dd6

9

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75743
MD5 53e1c013414c184f3c6a3984c621d022
SHA1 c1578b0e3c296dee7337198e1ccbef9c5652a977
SHA256 f48e98617050ada73555fe73859b19fbbe82df1a929dbe4eb655c82d58dad53e
SHA3 df5507f1fa9e3aedbebfa29348bc68b3d16dd4e5acc3a7c8d786518908e620e7

10

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35918
MD5 a240766099f770d33bf8f6bc9ee81492
SHA1 2328a094335f9c0ad2d3f4f304b69cf070450850
SHA256 6fc3d487cf279088f51427fae74e61291df72469094a424c062dd30b57df072d
SHA3 95f92b28bd90aa8b10a041fd5ea53dad7ad515ffaad4c6881eef93841e2122b8

11

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.39524
MD5 a6445b94e144a4dfecf586745db16710
SHA1 d2489f20707e075799023a1a953b4861889a33cc
SHA256 85d653974ca54a85acc4586dfdae8bae1ae26b535e6515deb02cb9195934cc16
SHA3 d7335974adc97e38c34fa80b37283eb257fa622d52932aa9fd9b90c541c0d07c

12

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x748
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.5353
MD5 c9e9a056bf051e0d6fc4516960bbe0d5
SHA1 c735323ca9e22b55e86f23bfa24a7bbd3c55536e
SHA256 c6888df118f3e8376cc6aae732391b14925372754c71e4100ccecf291a699873
SHA3 1cb07d3705f480133c20c2a0e8bb55a80399c815ac9ff78c98efdecf57598120

13

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x528
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86849
MD5 f48e8717355133bdcdc314d59499ebd3
SHA1 74e1a3c08f079f021e40b4595a723d379a4d13d1
SHA256 35b059859940700733c028957fe8de4ebcbeb49dfa44b065d1a4300a0addc85a
SHA3 e835297ccccc71a123ed90e5551dc4d8a5338f66beb60c118fc2096ae62bff90

14

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.13336
MD5 f370fe1aabd3d89024517a32fc22a776
SHA1 a54c1f9e223ad480b975b45cd66ccb98e27e505d
SHA256 4bc1b61040a04c66a69530d1da24bb710d546fdf55722bc36209c98735dc6478
SHA3 a8e241974f1b3720bca60f3a943511e4370e0dcbf09436248e1726a2bad14ef3

15

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.40701
MD5 0f1f2c6c71d7467ff63dbebf7daa65b1
SHA1 9dbefd4a36416adf5913d1eb7c603c163ac27fad
SHA256 27cfbd658926454be36df3dcc21a344eb0ec616b18bd3882a74fa2e2cf265b9d
SHA3 54dd5f72d31a53bf545fb3a4618382c168edddad25475b74cf515f1da8627c2f

16

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56384
MD5 0d783c75d7aa76a4bdaa9b69ff6ab537
SHA1 d7a2160bd0ad24d26cb5b03cf977ba2cb4872246
SHA256 b0df35e11cf1d2ea8a9e55c6627c49754ed9efa98534f68d036cae3710c9047a
SHA3 50bee90c03881d3f3e1718b0fe1859e487e0f0f2e6384379bb3da732a914e9a8

17

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04549
MD5 f7633bc61455729e9386d16ec9a70b1d
SHA1 b641f0a690a13d07069360c1a05a89f327827dbe
SHA256 34c94dce1472f1cb9c7b4aedc39a762f6b33373c4e7217b74b37fa4f68761feb
SHA3 c4789b9f0ddb4f5da50f909aae7239dc33ed74453593d0290ba17113783799f6

18

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.84829
MD5 c4c55464f91773aa8697cedce7c6071c
SHA1 8dcc1a135133cb7a967254deedefa102dcf56962
SHA256 bb8fee069d7ced40158d8aa641874bc82152da87d205d30dde0c33affb9b987b
SHA3 140ebdb489fef6e98e340348e639b71f1d4c291ac4c930898fb723d6a0e02bca

19

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.47784
MD5 30df4f2a5abe98355dbf1442ae9b33b3
SHA1 ffb06fe25d542399cf2a6c7bdf45b973f74a50c8
SHA256 fa221cd752a8166f26e301a5fc9a20836421f412e2869e01f5fc512b0dee8431
SHA3 a8e0ee5fc700a0d8dab48e49fca194cef1af4c226d5801e09fbe6c1128a20c3a

20

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.69034
MD5 4d79336818279ed8f5ca96c9723ef9f5
SHA1 ef4cb09f8cdd58a27afa17cb68d9288d5076dafd
SHA256 c82457764048517e91c5506bb47223f3e68c5728847be1c419dc32e4d6ebf340
SHA3 241572010b914e4d77d0747324a39544a92d6b721fb4026fbb39313ee194e213

21

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75999
MD5 6fe7dc731401e7c0e45414a71545f869
SHA1 81551acc2683a23d3b5b122db412fba274ea277c
SHA256 bcc9bc4b6dc87ab0ed13a27bee7fe88849d60cfb2bbaf202308c650c4594c444
SHA3 109492b4c9077d13ffb5b8eeebb2cceaa82e4e9be4ed9dd39a34f4a2211853fe

DLL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe000
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99708
MD5 076e36e9b3d5b84c29612a9fad090794
SHA1 b5a1a20e18cb963757e553b394f794f8bfab355e
SHA256 0fadd0d039813753980ad917a57bc400e42487e4eb3b911fbfca59c504f97efb
SHA3 d4a36f9b3944971deb2d90cf96c95d9dc06c1259022306baa300e81ae40522a1

500

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x12c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.60285
Detected Filetype Icon file
MD5 c18157ad01eadeb6ba96f1238ce7ed53
SHA1 d3f1f92990ba67f32ea96d65716dd2d61c608e3d
SHA256 bdc64e1d129972b36d0e5415cb5aa5effdd4195e9e2c5e58db6a5a9a4df4054e
SHA3 1ba6f5e4d1091246c844bd19531330ef1746d9c151650072cb53013e2bc437a0

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x382
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.85663
MD5 3d015c7d35d5e650f594c23c7368cd6f
SHA1 b5fdca6e0c5847a306b43553ce96c7c37a40c680
SHA256 3e11f55df49746534018ddcb81f928559124029992dfaa0adb67318b2d41df15
SHA3 94d9e3898971601d603eb374856eca2677a11d61314d956b1f82e18cd60c9b4c

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x9103f02d
Unmarked objects 0
18 (8444) 1
Imports (VS2010 build 30319) 3
Total imports 17
ASM objects (VS2010 build 30319) 1
Resource objects (VS2010 build 30319) 1
Linker (VS2010 build 30319) 1

Errors

<-- -->