Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Oct-01 07:55:19 |
Detected languages |
English - United States
|
FileDescription | bvnvnbfg |
FileVersion | 3.3.3.3 |
InternalName | sfsdffdswef |
LegalCopyright | Copyright (C) 2003-2017 |
OriginalFilename | cbcbvdfg.exe |
ProductName | cvbsdsd |
ProductVersion | 3.3.3.3 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 40/72 (Scanned on 2020-07-11 08:50:53) |
MicroWorld-eScan:
Gen:Variant.Ulise.101067
FireEye: Generic.mg.c4e2317beabc6a84 ALYac: Gen:Variant.Ulise.101067 Cylance: Unsafe K7AntiVirus: Riskware ( 0040eff71 ) K7GW: Riskware ( 0040eff71 ) Cybereason: malicious.beabc6 Arcabit: Trojan.Ulise.D18ACB F-Prot: W32/Ursu.T.gen!Eldorado Symantec: ML.Attribute.HighConfidence APEX: Malicious Paloalto: generic.ml BitDefender: Gen:Variant.Ulise.101067 NANO-Antivirus: Riskware.Win32.Relevant.ffkiaf Avast: Win32:Adware-gen [Adw] Tencent: Malware.Win32.Gencirc.10b81bef Ad-Aware: Gen:Variant.Ulise.101067 Sophos: Mal/Generic-S F-Secure: Heuristic.HEUR/AGEN.1131041 DrWeb: Adware.Relevant.167 TrendMicro: TROJ_GEN.R002C0PG920 Emsisoft: Gen:Variant.Ulise.101067 (B) Cyren: W32/Ursu.T.gen!Eldorado Jiangmin: Trojan.MSIL.jnxo Avira: HEUR/AGEN.1131041 Fortinet: Riskware/PUP_XLG Antiy-AVL: Trojan/Win32.AGeneric Microsoft: PUA:Win32/Vigua.A Cynet: Malicious (score: 90) McAfee: PUP-XLG-IA MAX: malware (ai score=87) VBA32: BScope.Adware.Relevant TrendMicro-HouseCall: TROJ_GEN.R002C0PG920 Rising: Malware.Undefined!8.C (CLOUD) GData: Gen:Variant.Ulise.101067 BitDefenderTheta: Gen:NN.ZexaF.34132.fr0@aaXOs1ai AVG: Win32:Adware-gen [Adw] Panda: Trj/Genetic.gen CrowdStrike: win/malicious_confidence_70% (W) Qihoo-360: HEUR/QVM20.1.7D17.Malware.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2017-Oct-01 07:55:19 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xa1a00 |
SizeOfInitializedData | 0x75600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00088A72 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xa3000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x120000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WSOCK32.dll |
#11
#52 #57 #116 #115 |
---|---|
WINMM.dll |
joyGetPosEx
mciSendStringW waveOutGetVolume mixerGetDevCapsW mixerGetLineInfoW mixerSetControlDetails waveOutSetVolume mixerGetControlDetailsW mixerGetLineControlsW mixerOpen joyGetDevCapsW mixerClose |
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
COMCTL32.dll |
CreateStatusWindowW
ImageList_ReplaceIcon ImageList_GetIconSize ImageList_AddMasked ImageList_Destroy ImageList_Create |
PSAPI.DLL |
GetProcessImageFileNameW
GetModuleFileNameExW GetModuleBaseNameW |
KERNEL32.dll |
FindNextFileW
FindClose FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW WideCharToMultiByte MultiByteToWideChar GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess TerminateProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW GetDiskFreeSpaceW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW CreateDirectoryW ReadFile WriteFile DeleteFileW SetFileAttributesW LocalFileTimeToFileTime SetFileTime GetFileSizeEx GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetWindowsDirectoryW GetTempPathW GetFullPathNameW GetShortPathNameW LoadLibraryW FreeLibrary LockResource LeaveCriticalSection VirtualProtect QueryDosDeviceW CompareStringW RemoveDirectoryW CopyFileW GetCurrentProcess FormatMessageW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize RaiseException TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount RtlUnwind InitializeSListHead QueryPerformanceCounter GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent IsProcessorFeaturePresent CreateEventW WaitForSingleObjectEx ResetEvent SetEvent ExitProcess GetModuleHandleExW HeapSize HeapReAlloc HeapQueryInformation HeapFree HeapAlloc LCMapStringW LoadResource SizeofResource FindResourceW GetSystemTimeAsFileTime GetModuleFileNameW DeleteCriticalSection GetCPInfo GetVersionExW GetModuleHandleW GetProcAddress GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread GetStringTypeExW lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock GetCurrentDirectoryW FindFirstFileW SetErrorMode InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount MulDiv EncodePointer GetCommandLineA GetStringTypeW GetConsoleCP GetConsoleMode GetProcessHeap FindFirstFileExW IsValidCodePage GetOEMCP GetEnvironmentStringsW GetCommandLineW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers ReadConsoleW WriteConsoleW DecodePointer EnterCriticalSection VirtualQuery |
USER32.dll |
RedrawWindow
SetParent GetClassInfoExW GetAncestor UpdateWindow GetMessagePos GetClassLongW DefDlgProcW CallWindowProcW CheckRadioButton IntersectRect PtInRect CreateDialogIndirectParamW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu GetMenuItemInfoW CreateMenu CreatePopupMenu SetMenuInfo AppendMenuW DestroyMenu TrackPopupMenuEx CreateIconIndirect GetDesktopWindow CopyImage CreateIconFromResourceEx EnumClipboardFormats GetWindow BringWindowToTop GetTopWindow GetQueueStatus GetWindowRect GetClientRect SystemParametersInfoW AdjustWindowRectEx DrawTextW SetRect GetIconInfo SetWindowTextW IsWindowVisible CheckMenuItem MessageBoxW MapWindowPoints SetClipboardViewer LoadAcceleratorsW EnableMenuItem GetMenu CreateWindowExW RegisterClassExW LoadCursorW DestroyIcon DestroyWindow IsCharAlphaW MapVirtualKeyW MapVirtualKeyExW SetDlgItemTextW GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW ReleaseDC GetDC OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard PostMessageW RemovePropW SetPropW GetPropW FlashWindow SetMenu ExitWindowsEx GetMenuStringW GetSubMenu GetMenuItemID GetMenuItemCount GetLastInputInfo GetCursor ClientToScreen ChangeClipboardChain FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW GetDlgItem SendDlgItemMessageW DialogBoxParamW SetForegroundWindow DefWindowProcW FillRect DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW IsIconic IsZoomed EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetLayeredWindowAttributes SetWindowPos SetWindowRgn SetFocus GetGUIThreadInfo SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable SetActiveWindow MessageBeep EnumChildWindows VkKeyScanExW MoveWindow LoadImageW |
GDI32.dll |
GetClipRgn
GetClipBox GetCharABCWidthsW SetBkMode CreatePatternBrush SetBrushOrgEx EnumFontFamiliesExW CreateDIBSection GdiFlush ExcludeClipRect SetBkColor SetTextColor GetPixel BitBlt CreateCompatibleBitmap GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush CreateFontW FillRgn GetDeviceCaps DeleteObject |
COMDLG32.dll |
CommDlgExtendedError
GetOpenFileNameW GetSaveFileNameW |
ADVAPI32.dll |
RegDeleteValueW
RegDeleteKeyW RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW |
SHELL32.dll |
ExtractIconW
DragQueryPoint SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW |
ole32.dll |
OleUninitialize
CoCreateInstance CoInitialize CoUninitialize OleInitialize CLSIDFromString CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
OLEAUT32.dll |
#35
#20 #7 #418 #24 #18 #23 #22 #148 #21 #17 #16 #19 #11 #27 #2 #12 #9 #15 #6 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.3.3.3 |
ProductVersion | 3.3.3.3 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | bvnvnbfg |
FileVersion (#2) | 3.3.3.3 |
InternalName | sfsdffdswef |
LegalCopyright | Copyright (C) 2003-2017 |
OriginalFilename | cbcbvdfg.exe |
ProductName | cvbsdsd |
ProductVersion (#2) | 3.3.3.3 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Oct-01 07:55:19 |
Version | 0.0 |
SizeofData | 856 |
AddressOfRawData | 0xc6e64 |
PointerToRawData | 0xc5c64 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Oct-01 07:55:19 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x4c71cc |
---|---|
EndAddressOfRawData | 0x4c71d4 |
AddressOfIndex | 0x4cd6f0 |
AddressOfCallbacks | 0x4a3774 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x98 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4cb010 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x60b03f06 |
---|---|
Unmarked objects | 0 |
ASM objects (24610) | 11 |
C++ objects (24610) | 148 |
C objects (24610) | 18 |
ASM objects (25305) | 25 |
C++ objects (25305) | 42 |
C objects (25305) | 22 |
262 (24610) | 7 |
Imports (24610) | 27 |
Total imports | 453 |
265 (25508) | 42 |
Resource objects (25508) | 1 |
Linker (25508) | 1 |