b0eea66f156eec3be63fea4011f72515651ff6007b32f741008f22b0c01d892e

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2015-Jul-10 03:29:04
Detected languages English - United States
Debug artifacts nslookup.pdb
CompanyName Microsoft Corporation
FileDescription nslookup
FileVersion 10.0.10240.16384 (th1.150709-1700)
InternalName nslookup.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename nslookup.exe
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.10240.16384

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Suspicious The PE contains functions most legitimate programs don't use. Can access the registry:
  • RegCloseKey
Possibly launches other programs:
  • system
Uses Windows's Native API:
  • ntohs
  • NtQueryValueKey
  • NtOpenKey
Leverages the raw socket API to access the Internet:
  • htons
  • inet_ntoa
  • send
  • closesocket
  • socket
  • recv
  • WSAGetLastError
  • ntohs
  • freeaddrinfo
  • getprotobynumber
  • getservbyport
  • select
  • htonl
  • gethostname
  • getaddrinfo
  • WSAStartup
  • connect
Safe VirusTotal score: 0/65 (Scanned on 2026-06-29 04:32:25) All the AVs think this file is safe.

Hashes

MD5 1a386554e016e71c35e1775ca8ffd862
SHA1 e2bd8887a5beab830814ea3be99fd8928bac1593
SHA256 b0eea66f156eec3be63fea4011f72515651ff6007b32f741008f22b0c01d892e
SHA3 1cf4909d5dd6b41cf050179f30056636e2b0873b2e1db5f9b8a1efaf25b325ce
SSDeep 1536:KA/cbbvMqvps/aPwFmqKMzoZIvDmQBf8Kf8SRfeZZiT6jC9:KZvMqvpsa4FxKMzoZIvrR8W8koZiM
Imports Hash 2db43adb351dcd8bbf1321617f88956b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2015-Jul-10 03:29:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0xc600
SizeOfInitializedData 0x7800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000CD00 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xe000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x17000
SizeOfHeaders 0x400
Checksum 0x18cc4
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x40000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b994da39056e0246a5cfa08e95990f37
SHA1 b90ec2f6e12a060306a949b1e5a12b18798a1d91
SHA256 5d2912f1103451102df00693b24347899718d56377da86acafbe1df85098ae3d
SHA3 200ffe2cfb6bd0444da2a950b3890212c832338e2c97703861e1d77edde46e1c
VirtualSize 0xc570
VirtualAddress 0x1000
SizeOfRawData 0xc600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45252

.data

MD5 d35f4a7db9c7a5fa2ad169a4d08bcba1
SHA1 85b77432411c608ec25a5c699b6cf424a6e50523
SHA256 5779d7a03150ea97bf974493369a20071882e6faf99949668a86a96080739fca
SHA3 337dfc97c975c39611cfdaecf95d142694fa7628a3533c8ce5b74e320e2b2b90
VirtualSize 0x4900
VirtualAddress 0xe000
SizeOfRawData 0x3a00
PointerToRawData 0xca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.672129

.idata

MD5 5dda26c0ed1c3fa8f92796be4c845633
SHA1 805b984f220a3dbf7892189f8324798a183c2b16
SHA256 12f141e92b43a93431f1349ec0db27da7725c56c48436f0eef9bac48a8472761
SHA3 a06f51a040bfff45361f12f93e8ebaa59fee25e565ff4856f6788c032314fec4
VirtualSize 0xd46
VirtualAddress 0x13000
SizeOfRawData 0xe00
PointerToRawData 0x10400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.09368

.didat

MD5 1769b8ddef4f69121654fa02e2146513
SHA1 62c159dd8a3b0b79c369990eb36bdcd35e7ec91e
SHA256 d4a5c2df542def96af13023d7d6860cdc0717350bc75ca9fd3ea773464a12764
SHA3 4a67b06bd4910405ec9253d2da52d4de9c72b69db7b1f301ef00d56fa0848ca8
VirtualSize 0x8
VirtualAddress 0x14000
SizeOfRawData 0x200
PointerToRawData 0x11200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0407808

.rsrc

MD5 096b059334d2640bf0a80ccb4be98e73
SHA1 300ad0b6d5b72636ee79fcc9060c45b43e66dca4
SHA256 a1b75ba2bfd45a3218d7c5d1b18f9ad7c5ead20a47526f4da012d7757de388f5
SHA3 0f44d149f43e030e0246e90738c5378c147770f25ebe8592656b7515e761bd2b
VirtualSize 0xd00
VirtualAddress 0x15000
SizeOfRawData 0xe00
PointerToRawData 0x11400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.9287

.reloc

MD5 7f26844e83554f6eac00bb886af883e3
SHA1 7216c071f2fb0f1f8a83fbf066bceac7455cbc7b
SHA256 e53f07c9d36b3604035ca636fce0055b6ee57b9e2cc2ccd3a4034ff27a4a6bea
SHA3 6829b3ee5cd01e85f34bb52d18003e7d0c8acef9b9d370357f94553abb369501
VirtualSize 0xe8c
VirtualAddress 0x16000
SizeOfRawData 0x1000
PointerToRawData 0x12200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.51853

Imports

msvcrt.dll strncmp
strchr
isspace
perror
fgets
free
fopen
getenv
strncpy_s
_write
fflush
_XcptFilter
_strnicmp
memcpy
memcmp
sprintf_s
strcat_s
strcpy_s
fputc
__p__commode
fputs
_amsg_exit
__getmainargs
__set_app_type
putc
gmtime
exit
fclose
getc
_exit
_cexit
putchar
system
__p__fmode
__setusermatherr
_initterm
?terminate@@YAXXZ
_controlfp
realloc
fwrite
ferror
fprintf
fread
printf
__iob_func
_vsnprintf_s
malloc
sscanf_s
_except_handler4_common
memset
WS2_32.dll htons
inet_ntoa
send
closesocket
socket
recv
WSAGetLastError
ntohs
freeaddrinfo
getprotobynumber
getservbyport
select
htonl
gethostname
getaddrinfo
WSAStartup
connect
api-ms-win-core-localization-l1-2-1.dll FormatMessageA
SetThreadUILanguage
DNSAPI.dll DnsQueryConfigAllocEx
DnsFreeConfigStructure
api-ms-win-core-heap-l1-2-0.dll HeapSetInformation
api-ms-win-core-errorhandling-l1-1-1.dll SetUnhandledExceptionFilter
SetLastError
GetLastError
UnhandledExceptionFilter
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
MSWSOCK.dll s_perror
api-ms-win-core-heap-l2-1-0.dll LocalFree
LocalAlloc
api-ms-win-core-synch-l1-2-0.dll Sleep
api-ms-win-core-processthreads-l1-1-2.dll GetCurrentThreadId
GetCurrentProcessId
GetCurrentProcess
TerminateProcess
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
api-ms-win-core-sysinfo-l1-2-1.dll GetTickCount
GetSystemTimeAsFileTime
ntdll.dll RtlIpv6StringToAddressExA
RtlIpv6AddressToStringExA
RtlIpv4AddressToStringExA
RtlIpv6AddressToStringA
RtlIpv4StringToAddressA
EtwTraceMessage
NtQueryValueKey
RtlAllocateHeap
RtlFreeUnicodeString
RtlInitString
RtlUnicodeStringToAnsiString
RtlFreeHeap
NtOpenKey
RtlAnsiStringToUnicodeString
api-ms-win-core-processenvironment-l1-2-0.dll ExpandEnvironmentStringsA
api-ms-win-core-delayload-l1-1-1.dll DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-apiquery-l1-1-0.dll ApiSetQueryApiSetPresence
ext-ms-win-ntuser-chartranslation-l1-1-0.dll (delay-loaded) CharToOemBuffA

Delayed Imports

Attributes 0x1
Name ext-ms-win-ntuser-chartranslation-l1-1-0.dll
ModuleHandle 0x11bd0
DelayImportAddressTable 0x14000
DelayImportNameTable 0xd54c
BoundDelayImportTable 0xd568
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75361
MD5 3e31b859eb1be6f3e89da865e2b3eee8
SHA1 1aa1640b05a92326987180cf02815f922de59c4e
SHA256 fb6c63fe0305b579b84f6c848bf5723e6b897c5f80f1977a8e4bd92e51f8d2c8
SHA3 9f7fe1294bcd4b5196e83feded27daa35e00b635eb6503efbd6049fa84d14fac

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8078
MD5 ea3482a8ccfce700bd9dc9266d31a28a
SHA1 be0dd477db3280c48cc26549efe6f06a2a335bb9
SHA256 bc538ad570ed08bcfa1d6de5e15f6a4b1022c9ed90c615f7fbd8426249cefbe3
SHA3 8f9a402af9d8f72101f64efa660d115bac270ecf9506499121c9a4c43ea8fbc4

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.60083
MD5 a67ffe835f7cf0d6d30f530557580990
SHA1 0f7f9f06e8b302040dfb845fbff61cf37f45b2ed
SHA256 0c5c1de00970054ad75f90842e3685bacdac888432f7e653c56c4a312aa13ea5
SHA3 12c7ac641f362de5d7c391f161d7085c93bc4419e3718644bd51ed3ab126fc65

ID_ICON_MAIN

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.37086
Detected Filetype Icon file
MD5 d59e0d372ea5fd8c1f4de744376a6af4
SHA1 6883ce60e71a83424db0b41d0ab6bf61080e3de2
SHA256 b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b
SHA3 5e39df982879204dd9f129a37d1e1c2ff906e88de9ae01b4418db5e8455e7ae1

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x380
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48363
MD5 002dc5ed86ea62d152c87c20a1fb59d5
SHA1 8c125a6f72cba82a45ea8621f77441e2594037f4
SHA256 6d27db4a6957596d32f55ef24dd85af681c540628879778c7d98dc2bb4eaee08
SHA3 dfa8b79cd9ca32565fa6faae003a12b574d32dc1eeedf96bd37ce9c3a2fa607b

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x2a7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92809
MD5 a5529a6216c87e0bbf40eecc0a365ab8
SHA1 db3a5a5c3fb82be63ff3c805175e7a6b132a6eb2
SHA256 115cd5569ca734957856177b322d52e9019d26b0e4dfc5ff5bec7035a418fdd6
SHA3 d8f3ce5c90f268f504bff8cc447598d3764f9403a4a86e9e95dc15382e3c9e25

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.10240.16384
ProductVersion 10.0.10240.16384
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription nslookup
FileVersion (#2) 10.0.10240.16384 (th1.150709-1700)
InternalName nslookup.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename nslookup.exe
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.10240.16384
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2015-Jul-10 03:29:04
Version 0.0
SizeofData 37
AddressOfRawData 0x3f84
PointerToRawData 0x3384
Referenced File nslookup.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2015-Jul-10 03:29:04
Version 0.0
SizeofData 576
AddressOfRawData 0x3fc0
PointerToRawData 0x33c0

TLS Callbacks

Load Configuration

Size 0x68
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x40e004
SEHandlerTable 0x403f80
SEHandlerCount 1
GuardCFCheckFunctionPointer 4272628
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xf682d51e
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 42
243 (40116) 2
241 (40116) 3
242 (40116) 21
Total imports 168
239 (40116) 7
246 (40116) 33
Imports (40116) 1
240 (40116) 1

Errors

Leave a comment

No comments yet.