Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Mar-10 21:13:32 |
FileDescription | |
FileVersion | 6.3 |
InternalName | Codom.exe |
LegalCopyright | Copyright © 2016 |
OriginalFilename | Codom.exe |
ProductName | Windows Os |
ProductVersion | 6.3 |
Assembly Version | 6.3 |
Info | Matching compiler(s): |
Microsoft Visual Basic v5.0/v6.0
Microsoft Visual Basic v5.0 - v6.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to TEA |
Malicious | VirusTotal score: 29/69 (Scanned on 2019-05-11 20:20:01) |
MicroWorld-eScan:
Gen:Variant.Johnnie.169933
CMC: Trojan.Win32.VBInject!O McAfee: GenericRXHI-SW!B6E621887C74 Cylance: Unsafe BitDefender: Gen:Variant.Johnnie.169933 Arcabit: Trojan.Johnnie.D297CD ESET-NOD32: a variant of Win32/Injector.EESJ Kaspersky: Backdoor.Win32.DarkKomet.ifdq Alibaba: Trojan:Win32/Injector.b3dd41d2 Endgame: malicious (high confidence) DrWeb: BackDoor.Tordev.976 McAfee-GW-Edition: GenericRXHI-SW!B6E621887C74 Trapmine: malicious.moderate.ml.score FireEye: Generic.mg.b6e621887c747e29 Emsisoft: Gen:Variant.Johnnie.169933 (B) SentinelOne: DFI - Suspicious PE MAX: malware (ai score=80) Antiy-AVL: Trojan/Win32.Fuerboos Microsoft: Trojan:Win32/Fuerboos.E!cl ZoneAlarm: Backdoor.Win32.DarkKomet.ifdq GData: Gen:Variant.Johnnie.169933 AhnLab-V3: Trojan/Win32.RL_Hpvb.R264220 ALYac: Gen:Variant.Johnnie.169933 Ad-Aware: Gen:Variant.Johnnie.169933 Fortinet: W32/Generic.AC.4380E0!tr AVG: FileRepMalware Cybereason: malicious.87c747 Avast: FileRepMalware CrowdStrike: win/malicious_confidence_100% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xb8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2017-Mar-10 21:13:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.534 |
SizeOfCode | 0xa7000 |
SizeOfInitializedData | 0x7000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000034FC (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xa8000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 36.216 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xaf000 |
SizeOfHeaders | 0x1000 |
Checksum | 0xb660e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
MSVBVM60.DLL |
__vbaVarTstGt
__vbaVarSub __vbaStrI2 #690 _CIcos _adj_fptan #585 __vbaHresultCheck __vbaStrI4 __vbaVarMove __vbaRedimPreserveVar __vbaVarVargNofree __vbaAryMove __vbaFreeVar #588 __vbaLenBstr __vbaLateIdCall __vbaStrVarMove __vbaVarIdiv __vbaPut3 __vbaEnd __vbaFreeVarList _adj_fdiv_m64 __vbaFpCDblR8 __vbaVarIndexStore #620 __vbaNextEachVar __vbaRaiseEvent #621 __vbaFreeObjList #516 __vbaStrErrVarCopy __vbaVarIndexLoadRef #517 _adj_fprem1 #518 __vbaRecAnsiToUni #519 __vbaResume __vbaForEachCollAd __vbaStrCat #660 __vbaLsetFixstr __vbaRecDestruct __vbaSetSystemError #662 __vbaHresultCheckObj #556 #558 __vbaLenVar _adj_fdiv_m32 __vbaVarTstLe #666 __vbaAryVar #667 __vbaVarXor __vbaVarCmpGe __vbaAryDestruct #669 __vbaLateMemSt #592 __vbaForEachCollObj __vbaBoolStr #593 __vbaExitProc __vbaVarForInit #594 __vbaFileCloseAll __vbaOnError __vbaObjSet #595 _adj_fdiv_m16i __vbaVarIndexStoreObj __vbaObjSetAddref _adj_fdivr_m16i __vbaVarIndexLoad #598 #599 __vbaFpR4 #520 __vbaStrFixstr __vbaRefVarAry __vbaFpR8 __vbaVarTstLt __vbaBoolVarNull _CIsin __vbaErase #631 __vbaLateMemStAd #525 __vbaNextEachCollObj __vbaVargVarMove __vbaVarZero #632 __vbaChkstk #526 __vbaFileClose EVENT_SINK_AddRef __vbaGenerateBoundsError __vbaExitEachColl __vbaGet3 #529 __vbaStrCmp __vbaGet4 __vbaPutOwner3 __vbaAryConstruct2 __vbaVarTstEq __vbaR4Str __vbaPrintObj #561 __vbaI2I4 __vbaVarLikeVar __vbaObjVar DllFunctionCall __vbaVarOr __vbaVarLateMemSt __vbaFpUI1 #564 __vbaCastObjVar __vbaLbound __vbaStrR4 __vbaRedimPreserve _adj_fpatan __vbaR4Var __vbaFixstrConstruct __vbaLateIdCallLd __vbaRedim __vbaUI1ErrVar __vbaRecUniToAnsi EVENT_SINK_Release __vbaNew #600 #601 __vbaUI1I2 _CIsqrt __vbaVarAnd __vbaObjIs EVENT_SINK_QueryInterface __vbaVarMul __vbaStrUI1 __vbaUI1I4 __vbaExceptHandler #711 __vbaStrToUnicode __vbaPrintFile #712 __vbaDateStr #606 #713 _adj_fprem _adj_fdivr_m64 #607 __vbaVarDiv #714 __vbaI2Str #608 __vbaVarCmpLe #716 __vbaFPException #717 __vbaInStrVar __vbaGetOwner3 __vbaUbound __vbaStrVarVal __vbaVarCat #534 __vbaCheckType __vbaDateVar #535 __vbaI2Var #536 __vbaLsetFixstrFree #537 #644 #645 _CIlog #539 __vbaErrorOverflow __vbaFileOpen __vbaR8Str __vbaVar2Vec __vbaNew2 #648 __vbaInStr #570 _adj_fdiv_m32i #572 _adj_fdivr_m32i #573 __vbaStrCopy #681 __vbaI4Str __vbaVarNot __vbaVarCmpLt __vbaFreeStrList #576 _adj_fdivr_m32 __vbaPowerR8 __vbaR8Var _adj_fdiv_r #578 #685 #100 __vbaVarTstNe __vbaVarSetVar __vbaI4Var __vbaVarCmpEq #689 __vbaLateMemCall __vbaAryLock __vbaVarAdd __vbaVarDup __vbaStrToAnsi #613 #614 __vbaFpI2 #616 __vbaVarTstGe __vbaUnkVar __vbaVarLateMemCallLd __vbaFpI4 __vbaVarCopy __vbaLateMemCallLd __vbaVarSetObjAddref __vbaRecDestructAnsi #617 _CIatan __vbaCastObj __vbaUI1Str __vbaAryCopy #618 __vbaStrMove __vbaForEachVar __vbaStrVarCopy __vbaR8IntI4 #619 #650 _allmul __vbaLenVarB __vbaLateIdSt _CItan #546 __vbaNextEachCollAd __vbaUI1Var __vbaFPInt __vbaAryUnlock __vbaVarForNext _CIexp __vbaMidStmtBstr __vbaRecAssign __vbaI4ErrVar #580 __vbaFreeStr __vbaFreeObj #581 |
---|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.17.1.2 |
ProductVersion | 6.17.1.2 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
FileDescription | |
FileVersion (#2) | 6.3 |
InternalName | Codom.exe |
LegalCopyright | Copyright © 2016 |
OriginalFilename | Codom.exe |
ProductName | Windows Os |
ProductVersion (#2) | 6.3 |
Assembly Version | 6.3 |
Resource LangID | UNKNOWN |
---|
XOR Key | 0x83cdad41 |
---|---|
Unmarked objects | 0 |
14 (7299) | 1 |
9 (8041) | 19 |
13 (8169) | 1 |