Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Aug-20 09:03:09 |
Detected languages |
English - United States
|
Debug artifacts |
c:\tone\ask\note\dependPress.pdb
|
CompanyName | Allwind Four Winds Interactive |
FileDescription | Likefine |
FileVersion | 15.2.31.75 |
InternalName | Likefine |
LegalCopyright | Copyright © 2008-2019 Experiencechance |
LegalTrademarks | Likefine Allwind Four Winds Interactive |
OriginalFilename | Likefine |
ProductVersion | 15.2.31.75 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 43/60 (Scanned on 2019-09-02 18:17:50) |
MicroWorld-eScan:
Trojan.Agent.ECJZ
CMC: Trojan.Win32.Swizzor.3!O CAT-QuickHeal: Trojan.Gozi McAfee: GenericRXIK-LC!AF442FCDCF8D AegisLab: Trojan.Win32.Gozi.7!c K7AntiVirus: Trojan ( 0055664b1 ) Alibaba: TrojanBanker:Win32/Gozi.8267f6c1 K7GW: Trojan ( 0055664b1 ) Invincea: heuristic Symantec: Trojan.Gen.MBT ESET-NOD32: a variant of Win32/Kryptik.GVSG APEX: Malicious Paloalto: generic.ml Kaspersky: Trojan-Banker.Win32.Gozi.eku BitDefender: Trojan.Agent.ECJZ Avast: Win32:Trojan-gen Rising: Trojan.Kryptik!8.8 (TFE:5:3Vv2qPqE3JH) Ad-Aware: Trojan.Agent.ECJZ Comodo: Malware@#18ysfpbdkolwl TrendMicro: TROJ_GEN.R002C0WHN19 FireEye: Generic.mg.af442fcdcf8d2967 Sophos: Mal/Generic-S SentinelOne: DFI - Malicious PE Jiangmin: Trojan.Banker.Gozi.up Webroot: W32.Trojan.Gen Avira: TR/Crypt.Agent.ppuea Microsoft: Trojan:Win32/Occamy.C Arcabit: Trojan.Agent.ECJZ ZoneAlarm: Trojan-Banker.Win32.Gozi.eku GData: Trojan.Agent.ECJZ AhnLab-V3: Trojan/Win32.Ursnif.C3445746 Acronis: suspicious VBA32: TrojanBanker.Gozi ALYac: Trojan.Agent.ECJZ MAX: malware (ai score=83) TrendMicro-HouseCall: TROJ_GEN.R002C0WHN19 Tencent: Win32.Trojan-banker.Gozi.Lork TACHYON: Banker/W32.Gozi.551936 Fortinet: W32/Kryptik.DQJS!tr AVG: Win32:Trojan-gen Cybereason: malicious.dcf8d2 Panda: Trj/GdSda.A Qihoo-360: Win32/Trojan.c8f |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2010-Aug-20 09:03:09 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x26a00 |
SizeOfInitializedData | 0x72e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001B99 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x28000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x9d000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTempPathA
HeapSize WriteConsoleW GetConsoleOutputCP WriteConsoleA GetProcessHeap SetEndOfFile SetFilePointer GetCurrentProcessId GetFileTime FindFirstChangeNotificationA GetModuleFileNameA VirtualProtectEx LoadLibraryA Sleep WideCharToMultiByte MoveFileExA ExitProcess GetStartupInfoW TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent EnterCriticalSection LeaveCriticalSection SetHandleCount GetStdHandle GetFileType GetStartupInfoA DeleteCriticalSection RtlUnwind GetLastError HeapFree CloseHandle GetModuleHandleW GetProcAddress WriteFile GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetSystemTimeAsFileTime InitializeCriticalSectionAndSpinCount GetCPInfo GetACP GetOEMCP IsValidCodePage MultiByteToWideChar ReadFile CreateFileA HeapAlloc VirtualAlloc HeapReAlloc SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA |
---|---|
GDI32.dll |
CreateCompatibleBitmap
SetPixel StretchBlt GetTextExtentPoint32A PatBlt |
USER32.dll |
SetCursor
GetClassNameA GetDlgItemInt InsertMenuItemA IsWindowEnabled DrawIcon SetDlgItemInt CheckMenuRadioItem ShowScrollBar DispatchMessageA LoadImageA |
COMCTL32.dll |
ImageList_GetIcon
ImageList_Create ImageList_EndDrag ImageList_GetDragImage ImageList_GetImageCount |
ADVAPI32.dll |
RegOpenKeyExA
RegCreateKeyA RegQueryValueExA RegCloseKey |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 15.2.31.75 |
ProductVersion | 15.2.31.75 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Allwind Four Winds Interactive |
FileDescription | Likefine |
FileVersion (#2) | 15.2.31.75 |
InternalName | Likefine |
LegalCopyright | Copyright © 2008-2019 Experiencechance |
LegalTrademarks | Likefine Allwind Four Winds Interactive |
OriginalFilename | Likefine |
ProductVersion (#2) | 15.2.31.75 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Aug-20 09:03:09 |
Version | 0.0 |
SizeofData | 57 |
AddressOfRawData | 0x2b610 |
PointerToRawData | 0x2a410 |
Referenced File | c:\tone\ask\note\dependPress.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x42d004 |
SEHandlerTable | 0x42b650 |
SEHandlerCount | 3 |
XOR Key | 0xe5e35588 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2008 build 21022) | 34 |
ASM objects (VS2008 build 21022) | 16 |
C objects (VS2008 build 21022) | 109 |
Imports (VS2008 SP1 build 30729) | 11 |
Total imports | 116 |
138 (VS2008 SP1 build 30729) | 1 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |