| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2014-Feb-26 02:05:15 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 5/70 (Scanned on 2026-08-15 17:25:10) |
DrWeb:
Trojan.Inject4.6518
MaxSecure: Trojan.Malware.300983.susgen Microsoft: Trojan:Win32/Wacatac.B!ml NANO-Antivirus: Trojan.Win32.Inject4.kkmxit VBA32: Trojan.Inject |
| MD5 | c0b18acc7560b274e312ca3e8bb79618 🔍 |
|---|---|
| SHA1 | 59f58a440d58a7eb9f114e7c9ca8e4756f8004ad 🔍 |
| SHA256 | c3df7f856dd2eae7ae0994716dc864eef8c316f74b667f2e23d48d485c946cf0 🔍 |
| SHA3 | 8f82245f4747d89f79b6176926608839b24f8d50027c5ba467c6c33b2ed2a181 🔍 |
| SSDeep | 24576:Ktl25/phgIFUJDND1nb8rGEQHtASNRMS0wgAjIpr/511x:KtA5/InN51P0TN/rX 🔍 |
| Imports Hash | c87f27c035ab10cf299284a3cadc2af0 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2014-Feb-26 02:05:15 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x104000 |
| SizeOfInitializedData | 0x81000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000014C7 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x105000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x18b000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 6a9be7bfea83a5efca087282da920be4 🔍 |
|---|---|
| SHA1 | 539e427ce7ab222ad79d7bca98b27997e6196e29 🔍 |
| SHA256 | 1a098254ab4a096539958addc891b9e994887d72740e4686dead56673f498eef 🔍 |
| SHA3 | d498d838fb97b9ecf7bd0f8fa88a5d2a542ad2ee09243dc2a1286511e5c1788d 🔍 |
| VirtualSize | 0x1033fc |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x104000 |
| PointerToRawData | 0x1000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.71072 |
| MD5 | 85a58572382e0d03e0f015fba111a043 🔍 |
|---|---|
| SHA1 | 7704d623d70e242508b5f46be6c43d4dd67c02a1 🔍 |
| SHA256 | 88500e9099e14b51885712b1fe14b4d7dcd8a4e83a8f406e67f8fbe0a2afaa10 🔍 |
| SHA3 | d37eb50be179ffd6ea8b95f8a333d9370093ae29974c8716bdf75d167a11f1e2 🔍 |
| VirtualSize | 0xc967 |
| VirtualAddress | 0x105000 |
| SizeOfRawData | 0xd000 |
| PointerToRawData | 0x105000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.6959 |
| MD5 | 018803bea0b9789618b094ba773397bf 🔍 |
|---|---|
| SHA1 | a1f067d68fd43d8d839d6c892471c3677338c75c 🔍 |
| SHA256 | c775a96964b21ff8764facf1fc584b9405549a7069205c182864641477344874 🔍 |
| SHA3 | e2fc8dc2075ad493815a67e80da2ecea7c9930d3084f57f59606e168f07f14be 🔍 |
| VirtualSize | 0x62334 |
| VirtualAddress | 0x112000 |
| SizeOfRawData | 0x20000 |
| PointerToRawData | 0x112000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.90229 |
| MD5 | aad16f37e7701f05736b8eab5bf0c179 🔍 |
|---|---|
| SHA1 | 5c0fda0e120c92a8f1ec46795d7935fb3853f570 🔍 |
| SHA256 | 38f94a9b9dc3517c2e3ac0e648a892b9c9cc19e41ed791adfc24c6da80f23fa9 🔍 |
| SHA3 | ac08632d858c40d34977f55e30db428a50b9b749d592145a03b37e48ec62b9a5 🔍 |
| VirtualSize | 0x5cc8 |
| VirtualAddress | 0x175000 |
| SizeOfRawData | 0x6000 |
| PointerToRawData | 0x132000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.39943 |
| MD5 | fab4dd736894dfd4c6a9e4b53981999b 🔍 |
|---|---|
| SHA1 | 8354770bd053fa25a389d44769ca0206e9046fc9 🔍 |
| SHA256 | f99950d55b5c291753a4e94ed0f8e77de29cb8e69faed03f43d038290b1ebc77 🔍 |
| SHA3 | c56560a944d5449ac949f46fdbb2b3be0ca45fcecf04ce1032641272e235c461 🔍 |
| VirtualSize | 0xf406 |
| VirtualAddress | 0x17b000 |
| SizeOfRawData | 0x10000 |
| PointerToRawData | 0x138000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.25746 |
| KERNEL32.dll |
FindResourceA
VirtualProtect GetSystemTimeAsFileTime FileTimeToLocalFileTime FileTimeToSystemTime SetThreadPriority CreateThread TerminateThread GetDriveTypeA DeviceIoControl ResetEvent QueryPerformanceFrequency QueryPerformanceCounter OpenFile VirtualLock LoadResource LockResource VirtualAlloc GetModuleHandleA GetCommandLineA ExitProcess LoadLibraryA GetProcAddress FreeLibrary GetVersionExA Sleep GetTempPathA GetSystemDirectoryA GetWindowsDirectoryA GetModuleFileNameA CreateEventA CloseHandle SetEvent WaitForSingleObject MultiByteToWideChar CreateDirectoryA RemoveDirectoryA DeleteFileA CopyFileA SetCurrentDirectoryA GetCurrentDirectoryA FindClose FindFirstFileA GetFileAttributesA FindNextFileA VirtualFree GetFullPathNameA EnterCriticalSection InitializeCriticalSection InterlockedExchange DeleteCriticalSection LeaveCriticalSection InterlockedDecrement InterlockedIncrement WideCharToMultiByte RtlUnwind GetVersion RaiseException HeapAlloc HeapFree GetTimeZoneInformation GetSystemTime GetLocalTime HeapReAlloc LCMapStringA LCMapStringW GetCPInfo CompareStringA CompareStringW TerminateProcess GetCurrentProcess HeapSize GetLastError GetCurrentThreadId TlsSetValue TlsAlloc TlsFree SetLastError TlsGetValue SetHandleCount GetStdHandle GetFileType GetStartupInfoA FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW GetEnvironmentVariableA HeapDestroy HeapCreate WriteFile SetUnhandledExceptionFilter IsBadWritePtr SetFilePointer FlushFileBuffers ReadFile IsValidLocale IsValidCodePage GetLocaleInfoA EnumSystemLocalesA GetUserDefaultLCID GetStringTypeA GetStringTypeW IsBadReadPtr IsBadCodePtr GetACP GetOEMCP SetEnvironmentVariableA SetStdHandle CreateFileA SetEndOfFile GetLocaleInfoW SetEnvironmentVariableW |
|---|---|
| USER32.dll |
UpdateWindow
CreateWindowExA RegisterClassA LoadCursorA UnregisterClassA DestroyWindow ShowCursor ShowWindow ClientToScreen GetClientRect SetCursorPos ReleaseCapture SetCapture ScreenToClient SetCursor PostMessageA EndPaint BeginPaint SetTimer DefWindowProcA DispatchMessageA PeekMessageA GetMessageA GetWindowLongA GetWindowRect SetWindowPos SetWindowLongA InvalidateRect MoveWindow GetSystemMetrics SystemParametersInfoA ToAscii MapVirtualKeyA MessageBoxA SetForegroundWindow CharLowerBuffA KillTimer SendDlgItemMessageA EndDialog GetDlgItem EnableWindow GetWindowTextA SetWindowTextA GetForegroundWindow DialogBoxParamA GetDesktopWindow GetCursorPos |
| WSOCK32.dll |
socket
bind gethostbyname WSACleanup WSAStartup setsockopt listen closesocket getsockname accept send ntohl ioctlsocket recv connect WSAGetLastError inet_addr __WSAFDIsSet getpeername ntohs htonl htons sendto select inet_ntoa recvfrom |
| WINMM.dll |
waveInReset
timeKillEvent timeSetEvent timeGetTime timeEndPeriod timeGetDevCaps mciSendCommandA mciGetErrorStringA waveOutGetDevCapsA waveOutGetNumDevs waveOutOpen waveOutClose waveOutPrepareHeader waveOutUnprepareHeader waveOutWrite waveOutReset waveOutGetPosition waveInAddBuffer waveInPrepareHeader waveInUnprepareHeader waveInGetDevCapsA waveInGetNumDevs waveInStart waveInOpen waveInClose timeBeginPeriod mixerGetControlDetailsA mixerGetLineControlsA mixerGetLineInfoA mixerSetControlDetails mixerOpen mixerGetNumDevs mixerClose |
| d3dxof.dll |
DirectXFileCreate
|
| DPLAYX.dll |
#4
|
| DDRAW.dll |
DirectDrawCreateEx
DirectDrawEnumerateExA |
| DINPUT.dll |
DirectInputCreateEx
|
| GDI32.dll |
GetStockObject
RemoveFontResourceA ExtTextOutA SetTextColor SetBkColor GetCharABCWidthsA GetTextExtentPoint32A DeleteObject DeleteDC GetTextMetricsA SelectObject CreateCompatibleDC AddFontResourceA CreateFontA |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize CLSIDFromString |
| ADVAPI32.dll |
RegOpenKeyExA
RegOpenKeyA RegEnumKeyA RegQueryValueExA RegCloseKey |
| MSACM32.dll |
acmStreamPrepareHeader
acmStreamSize acmStreamOpen acmFormatSuggest acmStreamClose acmStreamUnprepareHeader acmStreamConvert |
| Ordinal | 1 |
|---|---|
| Address | 0x14c7 |
| Ordinal | 2 |
|---|---|
| Address | 0x1421 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x8a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.4623 |
| MD5 | 68ce246e55d32876439a255c84f936b3 🔍 |
| SHA1 | d190dbb310b7c7ae3ae99a05a5b7bee279d85257 🔍 |
| SHA256 | bd1b0f635e840236f04fde022f5fff56cc25b66951b4bbc4f2a53326fae53a27 🔍 |
| SHA3 | 1abcac9a03ffb1ed8266936afc03d096cf8fec7d0e605a535d91ce9fb3c203b4 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1c0 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.37163 |
| MD5 | 46f7261d8a947bba1031252be1ddc986 🔍 |
| SHA1 | 0ca15518dc056ef6dca1081391073cf7588acd1e 🔍 |
| SHA256 | de2b6bfe8f76ae94f4a952e231ed9c62359705efeb36f2004d1f3951b931674e 🔍 |
| SHA3 | b9086150ef7a8d882130a78f25497f13c3251798af959b8531551ad6cb4ea03c 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x5111 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.49416 |
| MD5 | a2360f9e718c1f1914c1a40e10b63b72 🔍 |
| SHA1 | 1d56b29923394da9d50c5ece47e61aba4e9d432d 🔍 |
| SHA256 | 26a594e971a223a384787c27882202f41563a3a961d252ef7c2a62c22e40600b 🔍 |
| SHA3 | c69ae491bee5bf20b8832fe37fa93d37c013ae566ee9c150f5ea02e7114edff6 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.81924 |
| Detected Filetype | Icon file |
| MD5 | cbee427fa121aba9b9b265ff05de5383 🔍 |
| SHA1 | 24fcae33001c8e0f5ec795c6edf076a69d59589f 🔍 |
| SHA256 | 494e4fd717fa1ee0c5c7bb3b4e28fdab4b7f6e95b4f9865f5ab86f03f62ae62c 🔍 |
| SHA3 | a3fa35d56632275ba55716a4964f02031270f61f06a903fc460ac2dd6bebde85 🔍 |
| XOR Key | 0x71d53605 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 3 |
| 14 (7299) | 50 |
| C++ objects (8047) | 13 |
| C objects (8047) | 6 |
| C++ objects (VC++ 6.0 SP5 build 8804) | 5 |
| C objects (VC++ 6.0 SP5 build 8804) | 75 |
| C objects (VS98 SP6 build 8804) | 210 |
| 19 (9049) | 10 |
| Unmarked objects (#2) | 15 |
| 19 (8034) | 22 |
| Total imports | 255 |
| C++ objects (VS98 SP6 build 8804) | 98 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
| Linker (VC++ 6.0 SP5 imp/exp build 8447) | 1 |
No comments yet.