bb7425b82141a1c0f7d60e5106676bb1

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2010-Dec-19 16:16:19

Plugin Output

Info Matching compiler(s): Microsoft Visual C++
Microsoft Visual C++ v6.0
Microsoft Visual C++ v5.0/v6.0 (MFC)
Suspicious PEiD Signature: Armadillo v1.71
Info The following exploit mitigation techniques have been detected Stack Canary: disabled
SafeSEH: disabled
ASLR: disabled
DEP: disabled
Malicious VirusTotal score: 30/55 (Scanned on 2016-12-14 14:39:35) Bkav: W32.Clod835.Trojan.0b8a
nProtect: Trojan/W32.Agent.16384.BFW
McAfee: RDN/Generic.grp
Malwarebytes: Trojan.SystemKiller
Zillya: Downloader.Amonetize.Win32.3112
TheHacker: Trojan/Agent.wom
TrendMicro: TROJ_GEN.R00JC0EGI16
Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9857
Symantec: Trojan.Gen.2
ESET-NOD32: a variant of Win32/Agent.WOM
TrendMicro-HouseCall: TROJ_GEN.R00JC0EGI16
Avast: Win32:Malware-gen
GData: Win32.Trojan.Agent.RE19WZ
NANO-Antivirus: Trojan.Win32.Rogue.davsrf
AegisLab: Troj.Rogue.Gen!c
Comodo: UnclassifiedMalware
VIPRE: Trojan.Win32.Generic!BT
McAfee-GW-Edition: RDN/Generic.grp
Cyren: W32/Trojan.CZAN-7287
Avira: TR/Rogue.11196274
Antiy-AVL: Trojan/Win32.TSGeneric
ViRobot: Trojan.Win32.Z.Agent.16384.ADZ[h]
AhnLab-V3: Trojan/Win32.Agent.C957604
ALYac: Trojan.Agent.16384SS
AVware: Trojan.Win32.Generic!BT
Yandex: Trojan.Agent!ibNK9H/HlPg
Ikarus: Trojan.Rogue
Fortinet: W32/Agent.WOM!tr
AVG: Agent5.CDE
Qihoo-360: Win32/Trojan.8b5

Hashes

MD5 bb7425b82141a1c0f7d60e5106676bb1
SHA1 9dce39ac1bd36d877fdb0025ee88fdaff0627cdb
SHA256 58898bd42c5bd3bf9b1389f0eee5b39cd59180e8370eb9ea838a0b327bd6fe47
SHA3 b281616b26a6bd84f92beb625733c49563fb8576306d8fe4af3e1902a5348411
SSDeep 96:1t6Y5CuDzp17S5eVIV2cFL+31znx9+NNoyn:v6Y7117S5ercZ+FznxcNNoyn
Imports Hash 2b5f75aa75c57ed7c68f7be490d63605

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2010-Dec-19 16:16:19
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x1000
SizeOfInitializedData 0x2000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x1820 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x4000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics (EMPTY)
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7e39ebe7cdeda4c636d513a0fe140ff4
SHA1 150d709dcae7e0ae30ac6e5c76fda74ce168a62b
SHA256 44ab4d055abe09f315f217245f131fa4b9c162ffc992034b28ada7d2e8e8c87f
SHA3 399c0978695ae5a37bdf94da1a0c638172dfcb6a392e261c53a6e5539c4f4ede
VirtualSize 0x970
VirtualAddress 0x1000
SizeOfRawData 0x1000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.45086

.rdata

MD5 2de0f3a50219cb3d0dc891c4fbf6f02a
SHA1 9a80eabe5c64342b6bc9f4f31212ceb37b014055
SHA256 c6c6d685937af139911a720a86a1d901e30d015c8bc4a0d27756141e231df5eb
SHA3 e35dffc944aec5ddc8e4ba9002ecdabe91b8ab7483e604d1faa0e64da4193ff8
VirtualSize 0x2b2
VirtualAddress 0x2000
SizeOfRawData 0x1000
PointerToRawData 0x2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.13245

.data

MD5 f5e2ba1465f131f57b0629e96bbe107e
SHA1 129de8d9c6bbe1ba01c6b0d5ce5781c61eb042dc
SHA256 86aa10f4f5e696b8953e0a639a9725869803d85c1642d3e86e9fc7574d2eedb3
SHA3 0e79042b34d5db779eb7077692c08de882b688ab24867e174f41588412b9bf81
VirtualSize 0xfc
VirtualAddress 0x3000
SizeOfRawData 0x1000
PointerToRawData 0x3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.438854

Imports

KERNEL32.dll CloseHandle
UnmapViewOfFile
IsBadReadPtr
MapViewOfFile
CreateFileMappingA
CreateFileA
FindClose
FindNextFileA
FindFirstFileA
CopyFileA
MSVCRT.dll malloc
exit
_exit
_XcptFilter
__p___initenv
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
_stricmp

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

Errors