| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2000-Nov-07 22:39:22 |
| Info | Matching compiler(s): |
Installer VISE Custom
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-04-01 03:09:08) | NANO-Antivirus: Trojan.Win32.Symmi.eixmlw |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2000-Nov-07 22:39:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x5000 |
| SizeOfInitializedData | 0x2000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001AB5 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x6000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x8000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetFilePointer
CloseHandle CreateProcessA CreateFileMappingA MapViewOfFile UnmapViewOfFile GetFileSize CreateFileA GetModuleFileNameA GetFileType GetStdHandle GetLastError DeleteFileA FindFirstFileA FileTimeToSystemTime FileTimeToLocalFileTime ExitProcess TerminateProcess GetCurrentProcess GetModuleHandleA GetStartupInfoA GetCommandLineA GetVersion UnhandledExceptionFilter SetEndOfFile FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW SetHandleCount CompareStringW SetEnvironmentVariableA HeapDestroy HeapCreate VirtualFree HeapFree RtlUnwind WriteFile GetTimeZoneInformation GetCPInfo GetACP GetOEMCP HeapAlloc VirtualAlloc HeapReAlloc GetProcAddress LoadLibraryA MultiByteToWideChar LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW CompareStringA |
|---|---|
| USER32.dll |
MessageBoxA
|
| ADVAPI32.dll |
RegSetValueExA
RegCloseKey RegCreateKeyExA RegOpenKeyExA |
| XOR Key | 0x4208f650 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 2 |
| 14 (7299) | 14 |
| C objects (VS98 build 8168) | 42 |
| 19 (8034) | 7 |
| Total imports | 62 |
| C++ objects (VS98 build 8168) | 3 |
No comments yet.