| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2011-Apr-18 04:42:45 |
| Detected languages |
Japanese - Japan
|
| Info | Matching compiler(s): |
MASM/TASM - sig1(h)
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses known Mersenne Twister constants |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
4879872 bytes of data starting at offset 0xc000.
Overlay data amounts for 99.0028% of the executable. |
| Malicious | VirusTotal score: 14/70 (Scanned on 2026-04-01 03:26:38) |
APEX:
Malicious
Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Fortinet: W32/PossibleThreat Google: Detected Gridinsoft: Trojan.Win32.Wacatac.cl Ikarus: Trojan.Crypt Jiangmin: Trojan.Inject.bugj Microsoft: Trojan:Win32/Wacatac.B!ml Paloalto: generic.ml Trapmine: malicious.high.ml.score TrellixENS: Artemis!224872DEBA4A VBA32: Trojan.Wacatac Zillya: Trojan.Sdum.Win32.10542 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2011-Apr-18 04:42:45 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x6000 |
| SizeOfInitializedData | 0x5000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00006550 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x48000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0xe1185250 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
Sleep
lstrcpyA OpenProcess WaitForSingleObject TerminateProcess CloseHandle GetCurrentDirectoryA SetCurrentDirectoryA LoadLibraryA GetProcAddress FreeLibrary ReadFile SetFilePointer GetStartupInfoA ConnectNamedPipe DisconnectNamedPipe TerminateThread CreateNamedPipeA CreateThread GetTempPathA GetCurrentProcessId ReadProcessMemory VirtualQueryEx VirtualProtectEx WriteProcessMemory GetFileTime SetFileTime DeleteFileA RemoveDirectoryA LockFile SetFileAttributesA GetFileSize CreateFileA WriteFile lstrcatA GetShortPathNameA CreateProcessA GetLastError ResumeThread GetModuleHandleA GetModuleFileNameA lstrlenA lstrcpynA UnmapViewOfFile MapViewOfFile CreateFileMappingA WideCharToMultiByte lstrlenW MultiByteToWideChar CreateDirectoryA GetTempFileNameA |
|---|---|
| USER32.dll |
EnumWindows
EnableWindow GetWindowThreadProcessId ShowWindow EndDialog DestroyWindow BeginPaint EndPaint KillTimer PostQuitMessage DialogBoxParamA DefWindowProcA SetTimer CreateWindowExA UpdateWindow PostMessageA LoadIconA RegisterWindowMessageA LoadCursorA RegisterClassExA LoadStringA FindWindowA LoadAcceleratorsA GetMessageA TranslateAcceleratorA TranslateMessage DispatchMessageA ChangeDisplaySettingsA EnumDisplaySettingsA GetForegroundWindow SetForegroundWindow MessageBoxA wsprintfA IsWindowVisible IsWindowEnabled |
| SHELL32.dll |
ShellExecuteA
|
| MSVCRT.dll |
exit
_acmdln __getmainargs _initterm __setusermatherr _XcptFilter __p__commode __p__fmode __set_app_type _except_handler3 _controlfp _adjust_fdiv _exit _onexit __dllonexit vsprintf _mbsnbcpy _mbsinc _strdup strstr strchr _splitpath _makepath _beginthread memmove ??2@YAPAXI@Z ??3@YAXPAX@Z time strtoul strncmp __CxxFrameHandler malloc free realloc |
| MFC42.DLL |
#1200
|
| VERSION.dll |
GetFileVersionInfoA
GetFileVersionInfoSizeA VerQueryValueA |
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyExA RegSetValueExA RegCreateKeyExA RegCloseKey GetUserNameA |
| ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize CoTaskMemFree StringFromCLSID |
| OLEAUT32.dll |
SysAllocStringLen
SysFreeString |
| SdWrap |
| SDWRAP |
| XOR Key | 0x42b009c3 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 2 |
| Imports (VS2003 (.NET) build 4035) | 2 |
| Linker (VS98 SP6 build 8804) | 2 |
| 14 (7299) | 2 |
| C objects (8047) | 11 |
| Linker (8047) | 2 |
| C objects (VS98 SP6 build 8804) | 1 |
| 19 (8022) | 4 |
| 19 (8034) | 13 |
| Total imports | 182 |
| C++ objects (VS98 SP6 build 8804) | 32 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.