Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2011-Oct-18 18:46:44 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 37/67 (Scanned on 2017-12-08 11:38:51) |
CAT-QuickHeal:
Trojan.IGENERIC
McAfee: RDN/Generic Downloader.x Cylance: Unsafe Zillya: Trojan.Agent.Win32.658205 TheHacker: Trojan/Agent.qsx TrendMicro: TROJ_GEN.R0C1C0OFL17 Symantec: Trojan.Gen.2 ESET-NOD32: a variant of Win32/Agent.QSX TrendMicro-HouseCall: TROJ_GEN.R0C1C0OFL17 Paloalto: generic.ml NANO-Antivirus: Trojan.Win32.MLW.cwjidf SUPERAntiSpyware: Trojan.Agent/Gen-DeepScan Avast: Win32:Malware-gen Tencent: Win32.Trojan.Downloader.Pfje Comodo: UnclassifiedMalware DrWeb: Trojan.Siggen7.6837 VIPRE: Trojan.Win32.Generic!BT Invincea: heuristic McAfee-GW-Edition: RDN/Generic Downloader.x Cyren: W32/Trojan.OCXB-3800 Webroot: W32.Malware.Heur Avira: TR/Downloader.Gen Antiy-AVL: Trojan/Win32.BTSGeneric Kingsoft: Win32.Troj.DeepScan.a.(kcloud) Endgame: malicious (high confidence) AegisLab: Troj.Downloader.Gen!c GData: Win32.Trojan.Agent.4GWFKL AhnLab-V3: Trojan/Win32.Downloader.C1963708 AVware: Trojan.Win32.Generic!BT MAX: malware (ai score=100) Malwarebytes: Trojan.Agent Yandex: Trojan.Agent!UPg2K7fn8bU Ikarus: Trojan.Win32.Agent Fortinet: W32/Generic.AC.1B45AB!tr AVG: Win32:Malware-gen Cybereason: malicious.c6f8d2 CrowdStrike: malicious_confidence_70% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2011-Oct-18 18:46:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xa000 |
SizeOfInitializedData | 0x6000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00003896 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x11000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ExpandEnvironmentStringsA
CopyFileA GetModuleFileNameA GetShortPathNameA Sleep WriteFile ReadFile GetLastError GetSystemDirectoryA CreateFileA GetFileTime SetFileTime DeleteFileA CloseHandle CompareStringW CompareStringA CreateProcessA GetFileAttributesA FlushFileBuffers LoadLibraryA GetProcAddress LCMapStringW LCMapStringA VirtualAlloc SetFilePointer GetStringTypeW ExitProcess TerminateProcess GetCurrentProcess GetTimeZoneInformation GetSystemTime GetLocalTime DuplicateHandle GetCommandLineA GetVersion SetStdHandle GetFileType SetHandleCount GetStdHandle GetStartupInfoA CreatePipe GetExitCodeProcess WaitForSingleObject HeapReAlloc HeapAlloc GetCPInfo GetACP GetOEMCP UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW GetModuleHandleA GetEnvironmentVariableA GetVersionExA HeapDestroy HeapCreate VirtualFree HeapFree RtlUnwind MultiByteToWideChar GetStringTypeA SetEnvironmentVariableA |
---|---|
ADVAPI32.dll |
OpenSCManagerA
OpenServiceA ChangeServiceConfigA CloseServiceHandle CreateServiceA RegDeleteValueA RegCreateKeyExA RegSetValueExA RegOpenKeyExA RegQueryValueExA DeleteService |
SHELL32.dll |
ShellExecuteA
|
WS2_32.dll |
#22
#115 #52 #19 #23 #9 #4 #3 #16 #116 |
XOR Key | 0x4b3692b7 |
---|---|
Unmarked objects | 0 |
C++ objects (VS98 SP6 build 8804) | 1 |
14 (7299) | 17 |
C objects (VS98 SP6 build 8804) | 84 |
19 (8034) | 9 |
Total imports | 88 |
C++ objects (VS98 SP6 build 8804) (#2) | 1 |