Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2024-Feb-11 16:18:24 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 29/71 (Scanned on 2024-02-11 16:24:19) |
ALYac:
Gen:Trojan.FileInfector.huW@aGlbG@oi
APEX: Malicious AVG: FileRepMalware [Inf] Arcabit: Trojan.FileInfector.EAD1218 Avast: FileRepMalware [Inf] BitDefender: Gen:Trojan.FileInfector.huW@aGlbG@oi Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (moderate confidence) Emsisoft: Gen:Trojan.FileInfector.huW@aGlbG@oi (B) FireEye: Gen:Trojan.FileInfector.huW@aGlbG@oi GData: Gen:Trojan.FileInfector.huW@aGlbG@oi Kaspersky: VHO:Trojan-PSW.Win32.Stealer.camw Lionic: Trojan.Win32.Generic.4!c MAX: malware (ai score=85) Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.300983.susgen McAfee: Artemis!A8B54533C6A8 MicroWorld-eScan: Gen:Trojan.FileInfector.huW@aGlbG@oi Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Generic@AI.100 (RDML:aX2dyUFA4+riZrOlxz/JWQ) Sangfor: Trojan.Win32.FileInfector.Vbqs Skyhigh: BehavesLike.Win32.Worm.ch Symantec: ML.Attribute.HighConfidence VBA32: Win32.Trojan.Cryptor.Heur VIPRE: Gen:Trojan.FileInfector.huW@aGlbG@oi ZoneAlarm: VHO:Trojan-PSW.Win32.Stealer.camw tehtris: Generic.Malware |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2024-Feb-11 16:18:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x14e00 |
SizeOfInitializedData | 0x9a00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000017B0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x16000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x22000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetLogicalDrives
FindFirstFileA FindNextFileA FindClose WaitForSingleObject GetCurrentThreadId ExitThread GetFileAttributesA FreeConsole CreateThread WriteConsoleW SetEndOfFile HeapSize ReadConsoleW QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW GetCurrentProcess TerminateProcess RtlUnwind GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW EncodePointer RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapFree CloseHandle HeapReAlloc GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx HeapAlloc GetFileType FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetStringTypeW CompareStringW LCMapStringW GetProcessHeap CreateFileW FlushFileBuffers ReadFile DecodePointer |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Feb-11 16:18:24 |
Version | 0.0 |
SizeofData | 752 |
AddressOfRawData | 0x1bdcc |
PointerToRawData | 0x1afcc |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Feb-11 16:18:24 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x41d040 |
SEHandlerTable | 0x41bbdc |
SEHandlerCount | 10 |
XOR Key | 0xabb83b9a |
---|---|
Unmarked objects | 0 |
ASM objects (30795) | 10 |
C++ objects (30795) | 150 |
C objects (30795) | 20 |
253 (VS 2015-2022 runtime 33030) | 1 |
C++ objects (VS 2015-2022 runtime 33030) | 38 |
C objects (VS 2015-2022 runtime 33030) | 18 |
ASM objects (VS 2015-2022 runtime 33030) | 20 |
Imports (30795) | 5 |
Total imports | 93 |
C objects (LTCG) (33135) | 1 |
Resource objects (33135) | 1 |
Linker (33135) | 1 |