Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Mar-08 01:19:43 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\kyle\Desktop\trash\corruption.vip-master\2.pdb
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
Uses functions commonly found in keyloggers:
|
Malicious | VirusTotal score: 22/64 (Scanned on 2018-03-29 01:10:13) |
CAT-QuickHeal:
Trojan.IGENERIC
McAfee: Artemis!9A325943F058 K7AntiVirus: Unwanted-Program ( 005261191 ) K7GW: Unwanted-Program ( 005261191 ) TrendMicro: TROJ_GEN.R03FC0OCC18 Cyren: W32/Trojan.HADM-1030 Symantec: Trojan.Gen.2 TrendMicro-HouseCall: TROJ_GEN.R03FC0OCC18 Paloalto: generic.ml AegisLab: Gen.Variant.Razy!c VIPRE: Trojan.Win32.Generic!BT McAfee-GW-Edition: BehavesLike.Win32.Trojan.dh Sophos: Harmony Loader (PUA) Ikarus: Trojan.Graftor Fortinet: Riskware/GameHack AVware: Trojan.Win32.Generic!BT MAX: malware (ai score=94) ESET-NOD32: a variant of Win32/GameHack.BZX potentially unsafe SentinelOne: static engine - malicious eGambit: Trojan.Generic Panda: Trj/GdSda.A Qihoo-360: Win32/Trojan.395 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Mar-08 01:19:43 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5ca00 |
SizeOfInitializedData | 0xa4400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00057BE0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x5e000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x105000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
Sleep
CreateThread FreeLibraryAndExitThread Beep GetTickCount GetModuleHandleW GetProcAddress GetModuleHandleA VirtualProtect GetCurrentProcess K32GetModuleInformation GetStdHandle IsBadCodePtr SetConsoleTextAttribute GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter CreateEventW WaitForSingleObjectEx ResetEvent SetEvent DeleteCriticalSection LeaveCriticalSection EnterCriticalSection CloseHandle InitializeSListHead |
---|---|
USER32.dll |
MessageBoxA
GetForegroundWindow GetKeyNameTextA GetCursorPos GetAsyncKeyState ScreenToClient |
MSVCP140.dll |
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PAD1AAPAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SAIPAPBVfacet@locale@2@PBV42@@Z ?good@ios_base@std@@QBE_NXZ ?flags@ios_base@std@@QBEHXZ ?width@ios_base@std@@QBE_JXZ ?width@ios_base@std@@QAE_J_J@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAPAD0PAH001@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z ?_BADOFF@std@@3_JB ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@M@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xbad_alloc@std@@YAXXZ ?always_noconv@codecvt_base@std@@QBE_NXZ ?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ ?_Xlength_error@std@@YAXPBD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z ?_Xout_of_range@std@@YAXPBD@Z ??0_Lockit@std@@QAE@H@Z ??1_Lockit@std@@QAE@XZ ?uncaught_exception@std@@YA_NXZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z ??Bid@locale@std@@QAEIXZ |
WINMM.dll |
PlaySoundA
|
VCRUNTIME140.dll |
_CxxThrowException
_purecall __std_exception_destroy memcmp __CxxFrameHandler3 memmove __std_type_info_destroy_list _except_handler4_common __std_exception_copy __vcrt_InitializeCriticalSectionEx strchr strstr memchr memcpy memset |
api-ms-win-crt-runtime-l1-1-0.dll |
_errno
_invalid_parameter_noinfo _invalid_parameter_noinfo_noreturn _configure_narrow_argv _initterm_e _initterm terminate _cexit _crt_atexit _execute_onexit_table _register_onexit_function _initialize_onexit_table _seh_filter_dll _initialize_narrow_environment |
api-ms-win-crt-math-l1-1-0.dll |
floor
_CIatan2 _libm_sse2_cos_precise _except1 _libm_sse2_sin_precise ceil fmaxf _libm_sse2_pow_precise _libm_sse2_sqrt_precise _CIfmod _libm_sse2_acos_precise _libm_sse2_atan_precise copysignf |
api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free malloc |
api-ms-win-crt-stdio-l1-1-0.dll |
setvbuf
ungetc __stdio_common_vsprintf_s ftell fseek fwrite fread ferror fopen_s puts _fseeki64 __acrt_iob_func fsetpos __stdio_common_vfprintf __stdio_common_vsprintf _get_stream_buffer_pointers fputc fgetpos fgetc fflush fclose __stdio_common_vsnprintf_s |
api-ms-win-crt-convert-l1-1-0.dll |
atoi
strtoul atof mbstowcs_s |
api-ms-win-crt-utility-l1-1-0.dll |
rand
|
api-ms-win-crt-string-l1-1-0.dll |
isdigit
isalpha strncmp strcpy_s isspace |
api-ms-win-crt-time-l1-1-0.dll |
clock
_time64 strftime _localtime64 |
api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
Ordinal | 1 |
---|---|
Address | 0x26030 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Mar-08 01:19:43 |
Version | 0.0 |
SizeofData | 80 |
AddressOfRawData | 0xb97a0 |
PointerToRawData | 0xb85a0 |
Referenced File | C:\Users\kyle\Desktop\trash\corruption.vip-master\2.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Mar-08 01:19:43 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xb97f0 |
PointerToRawData | 0xb85f0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Mar-08 01:19:43 |
Version | 0.0 |
SizeofData | 816 |
AddressOfRawData | 0xb9804 |
PointerToRawData | 0xb8604 |
StartAddressOfRawData | 0x100b9b44 |
---|---|
EndAddressOfRawData | 0x100b9b4c |
AddressOfIndex | 0x100fd428 |
AddressOfCallbacks | 0x1005e48c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x98 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x100eabe8 |
SEHandlerTable | 0x100b93e0 |
SEHandlerCount | 240 |
XOR Key | 0xfa0696fa |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 18 |
ASM objects (25305) | 5 |
C objects (25305) | 11 |
Imports (25305) | 4 |
C++ objects (25305) | 22 |
Imports (24610) | 7 |
Total imports | 186 |
C++ objects (25508) | 32 |
Exports (25508) | 1 |
Resource objects (25508) | 1 |
Linker (25508) | 1 |