Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1970-Mar-07 10:30:28 |
Detected languages |
English - United Kingdom
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to DES |
Suspicious | The PE is possibly packed. |
Unusual section name found: _rwcseg
Unusual section name found: _TEXT_HA Unusual section name found: _rwdseg Section .text is both writable and executable. Section .data is both writable and executable. Unusual section name found: .dev1 Section .dev1 is both writable and executable. Unusual section name found: .dev2 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 3/66 (Scanned on 2020-08-20 14:35:54) |
Bkav:
W32.AIDetectVM.malware2
FireEye: Generic.mg.a2929a61e4d63dd3 APEX: Malicious |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x138 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 11 |
TimeDateStamp | 1970-Mar-07 10:30:28 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x458000 |
SizeOfInitializedData | 0x45a000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00425330 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x459000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x20e0000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WINMM.dll |
timeEndPeriod
timeGetTime timeBeginPeriod timeGetDevCaps |
---|---|
vorbisfile.dll |
ov_open_callbacks
ov_clear ov_time_total ov_time_tell ov_read ov_info ov_time_seek |
WS2_32.dll |
#16
#19 #3 #9 #11 #4 #111 #115 #116 #23 |
EAX.DLL |
#6
|
KERNEL32.dll |
VirtualProtect
GetOEMCP GetACP IsBadCodePtr IsBadReadPtr GetStringTypeW GetStringTypeA IsValidCodePage IsValidLocale EnumSystemLocalesA GetLocaleInfoA GetCPInfo GetDateFormatA VirtualQuery GetTickCount GetModuleHandleA GetProcAddress LoadLibraryA GetFileSize CloseHandle LocalFree WaitForSingleObjectEx GetOverlappedResult WaitForSingleObject ReleaseSemaphore SetFilePointer GetLastError ReadFile SetLastError CreateFileA ResumeThread SetThreadPriority GetThreadPriority GetCurrentThread CreateThread LocalAlloc CreateSemaphoreA GetDiskFreeSpaceA Sleep QueryPerformanceCounter InterlockedIncrement InterlockedDecrement lstrcatA lstrcpyA lstrlenA DeleteCriticalSection SuspendThread LeaveCriticalSection EnterCriticalSection InitializeCriticalSection MultiByteToWideChar DeleteFileA TerminateThread FindClose FindNextFileA GetFileAttributesA FindFirstFileA FreeLibrary QueryPerformanceFrequency OutputDebugStringA GetLocalTime CreateDirectoryA GetUserDefaultLCID SetStdHandle CreateEventA GetVolumeInformationA GetDriveTypeA GetLogicalDriveStringsA SetErrorMode GlobalMemoryStatus GetVersionExA GetCommandLineA GetFullPathNameA WideCharToMultiByte lstrcmpiA GetSystemInfo IsProcessorFeaturePresent LockResource LoadResource SizeofResource FindResourceA FindResourceW MapViewOfFile CreateFileMappingA CreateFileW UnmapViewOfFile ReleaseMutex CreateMutexA GetCurrentProcessId GetSystemDirectoryA GetModuleFileNameA FreeEnvironmentStringsA UnhandledExceptionFilter IsBadWritePtr VirtualAlloc VirtualFree HeapCreate HeapDestroy GetFileType GetStdHandle SetHandleCount FlushFileBuffers LCMapStringW LCMapStringA WriteFile FatalAppExitA SetUnhandledExceptionFilter HeapSize TlsAlloc TlsGetValue TlsSetValue GetCurrentThreadId TlsFree GetStartupInfoA HeapReAlloc HeapAlloc HeapFree GetSystemTimeAsFileTime GetCurrentProcess TerminateProcess ExitProcess RtlUnwind RaiseException InterlockedExchange FreeEnvironmentStringsW GetEnvironmentStringsW SetConsoleCtrlHandler GetTimeFormatA CompareStringA CompareStringW SetEnvironmentVariableA GetTimeZoneInformation SetEndOfFile GetLocaleInfoW GetCurrentDirectoryA GetSystemDefaultLCID SetCurrentDirectoryA GetEnvironmentStrings |
USER32.dll |
wsprintfA
IsIconic GetWindowLongA GetMenu AdjustWindowRectEx SystemParametersInfoA DestroyWindow SetWindowLongA ShowWindow LoadIconA LoadCursorA RegisterClassA ReleaseCapture GetWindowPlacement SetTimer ClipCursor PostQuitMessage SetCursor SetCapture DefWindowProcA MapVirtualKeyA UpdateWindow GetKeyState FindWindowA SetForegroundWindow PeekMessageA DispatchMessageA TranslateMessage GetKeyboardLayout DialogBoxParamA EndDialog GetDlgItem SetFocus SendMessageA SetWindowPos AdjustWindowRect CreateWindowExA ShowCursor GetWindowRect MessageBoxA SetWindowTextA ClientToScreen SetCursorPos GetClientRect |
GDI32.dll |
DeleteObject
|
ADVAPI32.dll |
RegCloseKey
RegCreateKeyExA RegOpenKeyExA RegQueryValueExA RegOpenKeyA RegSetValueExA |
ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize |
d3d9.dll (delay-loaded) |
Direct3DCreate9
|
Attributes | 0x1 |
---|---|
Name | d3d9.dll |
ModuleHandle | 0x89ce7c |
DelayImportAddressTable | 0x4e6554 |
DelayImportNameTable | 0x4a2fb0 |
BoundDelayImportTable | 0x4a2ff8 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Characteristics |
0
|
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
XOR Key | 0x5ca67d0 |
---|---|
Unmarked objects | 0 |
39 (9162) | 8 |
ASM objects (VS2002 (.NET) build 9466) | 49 |
C objects (VS2002 (.NET) build 9466) | 165 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 2 |
C objects (VS98 build 8168) | 5 |
Linker (VS98 build 8168) | 2 |
C objects (9178) | 5 |
Imports (9210) | 15 |
Total imports | 218 |
42 (8803) | 3 |
18 (8444) | 6 |
C++ objects (9178) | 48 |
48 (9044) | 121 |
Unmarked objects (#2) | 2 |
C++ objects (VS2002 (.NET) build 9466) | 469 |
Resource objects (VS2002 (.NET) build 9466) | 1 |
Linker (VS2002 (.NET) build 9466) | 1 |