Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-May-06 18:42:41 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to Blowfish |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 32/71 (Scanned on 2019-05-09 05:44:19) |
MicroWorld-eScan:
Gen:Heur.Ransom.REntS.Gen.1
FireEye: Gen:Heur.Ransom.REntS.Gen.1 Qihoo-360: Win32/Trojan.Ransom.ec8 McAfee: Artemis!A20156344FC4 Malwarebytes: Ransom.JSWorm K7AntiVirus: Riskware ( 0040eff71 ) K7GW: Riskware ( 0040eff71 ) Arcabit: Trojan.Ransom.REntS.Gen.1 TrendMicro: Trojan.Win32.SONBOKLI.USXVPE819 TrendMicro-HouseCall: Trojan.Win32.SONBOKLI.USXVPE819 Avast: FileRepMalware Kaspersky: Trojan.Win32.DelShad.ec BitDefender: Gen:Heur.Ransom.REntS.Gen.1 Paloalto: generic.ml AegisLab: Trojan.Win32.Rents.4!c Tencent: Win32.Trojan.Delshad.Lifx Ad-Aware: Gen:Heur.Ransom.REntS.Gen.1 Sophos: Mal/Generic-S DrWeb: Trojan.Encoder.28062 McAfee-GW-Edition: BehavesLike.Win32.Dropper.fh Fortinet: W32/DelShad.EC!tr Trapmine: malicious.moderate.ml.score Emsisoft: Gen:Heur.Ransom.REntS.Gen.1 (B) Cyren: W32/Trojan.MBYK-3909 Microsoft: Trojan:Win32/Tiggre!plock ZoneAlarm: Trojan.Win32.DelShad.ec ALYac: Trojan.Ransom.JSWorm Rising: Trojan.Fuerboos!8.EFC8 (CLOUD) GData: Gen:Heur.Ransom.REntS.Gen.1 AVG: FileRepMalware Cybereason: malicious.44fc48 Panda: Trj/GdSda.A |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2019-May-06 18:42:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x3f400 |
SizeOfInitializedData | 0x4ee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000BA20 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x41000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x91000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
WriteFile
SetFilePointer FindClose CreateFileW GetFileAttributesW SetFileAttributesW CloseHandle lstrcmpiW CreateMutexA FindNextFileW Sleep GetLastError GetModuleFileNameA GetVolumeInformationA MultiByteToWideChar WideCharToMultiByte MoveFileW SetEndOfFile GetFileSizeEx FindFirstFileW WriteConsoleW HeapSize WaitForSingleObject ReadFile EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection DeleteCriticalSection GetCurrentThreadId DuplicateHandle WaitForSingleObjectEx GetCurrentProcess SwitchToThread GetCurrentThread GetExitCodeThread QueryPerformanceCounter SetLastError InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount GetModuleHandleW GetProcAddress EncodePointer DecodePointer CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId InitializeSListHead CreateTimerQueue SetEvent SignalObjectAndWait CreateThread SetThreadPriority GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait GetThreadTimes FreeLibrary FreeLibraryAndExitThread GetModuleFileNameW GetModuleHandleA LoadLibraryExW GetVersionExW VirtualAlloc VirtualProtect VirtualFree ReleaseSemaphore InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList UnregisterWaitEx LoadLibraryW RaiseException RtlUnwind ExitProcess GetModuleHandleExW ExitThread GetStdHandle GetCommandLineA GetCommandLineW SetFilePointerEx GetFileType FlushFileBuffers GetConsoleCP GetConsoleMode HeapFree HeapAlloc IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ReadConsoleW HeapReAlloc FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap SetStdHandle |
---|---|
ADVAPI32.dll |
GetUserNameA
|
SHELL32.dll |
ShellExecuteA
|
IPHLPAPI.DLL |
GetAdaptersInfo
|
Ordinal | 1 |
---|---|
Address | 0x6287 |
Ordinal | 2 |
---|---|
Address | 0x6291 |
Ordinal | 3 |
---|---|
Address | 0x3043 |
Ordinal | 4 |
---|---|
Address | 0x648e |
Ordinal | 5 |
---|---|
Address | 0x6407 |
Ordinal | 6 |
---|---|
Address | 0x6595 |
Ordinal | 7 |
---|---|
Address | 0x6515 |
Ordinal | 8 |
---|---|
Address | 0x6300 |
Ordinal | 9 |
---|---|
Address | 0x6317 |
Ordinal | 10 |
---|---|
Address | 0x303d |
Ordinal | 11 |
---|---|
Address | 0x2b00 |
Ordinal | 12 |
---|---|
Address | 0x50a38 |
Ordinal | 13 |
---|---|
Address | 0x50a80 |
Ordinal | 14 |
---|---|
Address | 0x62aa |
Ordinal | 15 |
---|---|
Address | 0x3061 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-May-06 18:42:41 |
Version | 0.0 |
SizeofData | 804 |
AddressOfRawData | 0x5458c |
PointerToRawData | 0x52d8c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-May-06 18:42:41 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x458068 |
SEHandlerTable | 0x4543f0 |
SEHandlerCount | 103 |
XOR Key | 0x929a0ca0 |
---|---|
Unmarked objects | 0 |
ASM objects (26213) | 18 |
C++ objects (26213) | 175 |
C objects (26213) | 23 |
ASM objects (VS 2015/2017 runtime 26706) | 22 |
C++ objects (VS 2015/2017 runtime 26706) | 120 |
C objects (VS 2015/2017 runtime 26706) | 36 |
Imports (26213) | 9 |
Total imports | 138 |
265 (VS2017 v15.9.11 compiler 27030) | 8 |
Exports (VS2017 v15.9.11 compiler 27030) | 1 |
Linker (VS2017 v15.9.11 compiler 27030) | 1 |