Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1970-Jan-01 00:00:00 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 48/68 (Scanned on 2019-03-01 03:39:50) |
MicroWorld-eScan:
Trojan.GenericKD.5333249
CAT-QuickHeal: Trojan.Endowerpo McAfee: Trojan-FNDH!A193184E61E3 K7GW: Trojan ( 00510ef01 ) K7AntiVirus: Trojan ( 00510ef01 ) TrendMicro: TROJ_INDUSTROYER.C F-Prot: W32/Industroyer.B.gen!Eldorado Symantec: Backdoor.Industroyer TrendMicro-HouseCall: TROJ_INDUSTROYER.C Paloalto: generic.ml Kaspersky: Trojan.Win32.Industroyer.c BitDefender: Trojan.GenericKD.5333249 NANO-Antivirus: Trojan.Win32.Industroyer.errctz Avast: Win32:Malware-gen Rising: Trojan.Industroyer!8.E852 (CLOUD) Endgame: malicious (high confidence) Emsisoft: Trojan.GenericKD.5333249 (B) Comodo: Malware@#3e6e8fsjode2u F-Secure: Trojan.TR/Agent.ntnvk DrWeb: Trojan.Industroyer.5 Zillya: Trojan.Industroyer.Win32.3 McAfee-GW-Edition: Trojan-FNDH!A193184E61E3 Fortinet: W32/Industroyer.A!tr Cyren: W32/Industroyer.B.gen!Eldorado Webroot: W32.Trojan.Gen Avira: TR/Agent.ntnvk MAX: malware (ai score=100) Antiy-AVL: Trojan/Win32.Industroyer Arcabit: Trojan.Generic.D516101 ViRobot: Trojan.Win32.Industroyer.136704.A ZoneAlarm: Trojan.Win32.Industroyer.c Microsoft: Trojan:Win32/CrashOverride.A Sophos: Troj/Idtroyer-H AhnLab-V3: Trojan/Win32.Industroyer.R202380 VBA32: Trojan.Industroyer ALYac: Trojan.Agent.Endowerpo TACHYON: Trojan/W32.Industroyer.136704 Ad-Aware: Trojan.GenericKD.5333249 ESET-NOD32: a variant of Win32/Industroyer.A Tencent: Win32.Trojan.Industroyer.Klbs Yandex: Trojan.Industroyer! Ikarus: Trojan.Industroyer eGambit: Trojan.Generic GData: Win32.Backdoor.Industroyer.F AVG: Win32:Malware-gen Panda: Trj/GdSda.A CrowdStrike: win/malicious_confidence_100% (W) Qihoo-360: Trojan.Generic |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x17400 |
SizeOfInitializedData | 0xa800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005658 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x19000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x27000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
Process32First
SetConsoleTextAttribute GetStdHandle TerminateProcess WaitForMultipleObjects SetThreadPriority OpenProcess CreateToolhelp32Snapshot Sleep Process32Next CloseHandle CreateThread ReadConsoleW ReadFile SetEndOfFile HeapReAlloc HeapSize WriteConsoleW SetFilePointerEx SetStdHandle FlushFileBuffers UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead EncodePointer RaiseException InterlockedFlushSList GetLastError SetLastError RtlUnwind EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte HeapFree HeapAlloc LCMapStringW GetFileType GetACP WriteFile GetConsoleCP GetConsoleMode GetStringTypeW FindClose FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW GetProcessHeap CreateFileW DecodePointer |
---|---|
WS2_32.dll |
#3
getaddrinfo #115 #19 #23 #4 #16 freeaddrinfo #21 #111 |
Ordinal | 1 |
---|---|
Address | 0x14e0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Dec-18 02:48:22 |
Version | 0.0 |
SizeofData | 764 |
AddressOfRawData | 0x1f5f4 |
PointerToRawData | 0x1ddf4 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Dec-18 02:48:22 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x10021008 |
SEHandlerTable | 0x1001f5c0 |
SEHandlerCount | 13 |
XOR Key | 0x4a345c9e |
---|---|
Unmarked objects | 0 |
241 (40116) | 10 |
243 (40116) | 137 |
242 (40116) | 24 |
199 (41118) | 2 |
ASM objects (VS2015 UPD3 build 24123) | 18 |
C++ objects (VS2015 UPD3 build 24123) | 29 |
C objects (VS2015 UPD3 build 24123) | 16 |
Imports (VS2008 SP1 build 30729) | 5 |
Total imports | 106 |
265 (VS2015 UPD3 build 24210) | 8 |
Exports (VS2015 UPD3 build 24210) | 1 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3 build 24210) | 1 |