ffebc28e042e12cebde68ad02462046c9d63c897f4330c5df6599832021cba19

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2017-Apr-18 12:20:48
Detected languages English - United States
English - Zimbabwe
CompanyName UG North
FileDescription Windows DSE overrider
FileVersion 1.2.0.1704
InternalName dsefix.exe
LegalCopyright Copyright (C) 2014 - 2017 EP_X0FF, MP_ART and N.Rin, based on WinNT/Turla exploit
OriginalFilename dsefix.exe
ProductName DSEFix
ProductVersion 1.2.0.1704

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • exploit
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Suspicious The PE is possibly packed. Unusual section name found: shrd
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • NtQuerySystemInformation
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
Uses Windows's Native API:
  • NtQueryDirectoryObject
  • NtOpenDirectoryObject
  • NtQuerySystemInformation
  • NtAllocateVirtualMemory
  • NtDeleteFile
  • NtFreeVirtualMemory
  • NtClose
Interacts with services:
  • CreateServiceW
  • OpenSCManagerW
  • DeleteService
  • ControlService
  • OpenServiceW
Suspicious VirusTotal score: 1/60 (Scanned on 2017-05-26 13:04:17) Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9820

Hashes

MD5 ca127ebd958b98c55ee4ef277a1d3547 🔍
SHA1 7d5567d519f69165647871fde9e4d13bb0cb9234 🔍
SHA256 ffebc28e042e12cebde68ad02462046c9d63c897f4330c5df6599832021cba19 🔍
SHA3 e537265fd9ecc1c109ffc2fd3bcd1913ad0670a21338c9a6597677d88b71994f 🔍
SSDeep 1536:Ke8ul2U/41jC3d38uezp0Dw+49tKMgVxAlIi9:5/41jC3d38uezp0U9vgLA/ 🔍
Imports Hash b9c03d01e3110584eae1adb0a0a2095e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2017-Apr-18 12:20:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x3600
SizeOfInitializedData 0x14600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000002C30 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1e000
SizeOfHeaders 0x400
Checksum 0x22d69
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7be7927c9096fce419154ef1891fe0b3 🔍
SHA1 6e3cf548783a0c7c3c2f59ae7738efbaf0b639e8 🔍
SHA256 b923167a9f06a826f4afbcddc3fe9cdd0f0679d5f88e35ab307da396ab627ae6 🔍
SHA3 1ce49f05842d00e9b35b7e2d5cf80c184a46f68991e05e41aaf4967acf964ddd 🔍
VirtualSize 0x3530
VirtualAddress 0x1000
SizeOfRawData 0x3600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.26383

.rdata

MD5 98a252d1b35fc29dfb106943fbdcce5b 🔍
SHA1 281e18c7a1f334954783505f0aa749c91cd983ba 🔍
SHA256 0a292ccbfbcb22bfe8de89b608ded692c0e8916be7b53427fc8637b5313c066c 🔍
SHA3 82b084be8b4ca8b92bbff60ab37a62c56476cc35915f483851b58bace7150364 🔍
VirtualSize 0x2248
VirtualAddress 0x5000
SizeOfRawData 0x2400
PointerToRawData 0x3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.845

.data

MD5 6dfa911b7bb494a78c97c992f03fd3cd 🔍
SHA1 48afafbb4fdb46d20bcff849f2cb816bbb8a6038 🔍
SHA256 4ae6d635a75d062f1c68f9e13e9162b67ab2379bf2953b1647a7fd4a12c2a249 🔍
SHA3 f50650b07d2fe0a9dc9f93790a035a45f8022daa13e65f5411eb6ca27cf641fd 🔍
VirtualSize 0x113d4
VirtualAddress 0x8000
SizeOfRawData 0x10e00
PointerToRawData 0x5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.21144

.pdata

MD5 96b7dc96bb52c23a4a207240437173c5 🔍
SHA1 c82837e1e05dee2adfce5947c0d35a34ea64d353 🔍
SHA256 8c866036996427b86d087aa4ddfc950fd226fedd0376705d7585e01c25dbcd48 🔍
SHA3 dca48de68480f29add276cddc8ab06e3ec79b8849e36bf3ad0f40228980c4461 🔍
VirtualSize 0x2a0
VirtualAddress 0x1a000
SizeOfRawData 0x400
PointerToRawData 0x16c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.97307

shrd

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x4
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 23e2881e604f4fb8965937a1436654ad 🔍
SHA1 d897c78ef1ea3599ded3714b71ce841b1b5dc767 🔍
SHA256 9463715f00c0994abbc4de0c5767c2e08d343460be047bb02fba9883a475ac1f 🔍
SHA3 1e601d689c73839a530bf58952be565b8f7b20c0f8ea762930a50fa6eeac19f0 🔍
VirtualSize 0x570
VirtualAddress 0x1c000
SizeOfRawData 0x600
PointerToRawData 0x17200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.95001

.reloc

MD5 06ca74c20a48f848770aa5a4bbcea22c 🔍
SHA1 75c27e8a14cc90b9058c69ed1d26957053275506 🔍
SHA256 cb41fdfa3b8958d6710f7b9461569a9abbd181a6f7b62130558993c164e2ecee 🔍
SHA3 b3c2f2f1935b8cf26ab3e43c1106e2d574d05817afb09acfb930f36e5f5f81e4 🔍
VirtualSize 0x20
VirtualAddress 0x1d000
SizeOfRawData 0x200
PointerToRawData 0x17800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.357698

Imports

KERNEL32.dll CloseHandle
GetCommandLineW
GetStdHandle
SetConsoleMode
DeviceIoControl
LoadLibraryExA
GetSystemDirectoryW
GetConsoleMode
GetSystemDirectoryA
GetLastError
ExitProcess
GetModuleHandleW
FreeLibrary
SetConsoleTitleW
GetFileAttributesW
MoveFileExW
IsProcessorFeaturePresent
TerminateProcess
Sleep
CreateFileW
SetLastError
GetProcessHeap
WriteConsoleW
HeapAlloc
HeapFree
WriteFile
GetProcAddress
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
USER32.dll wsprintfW
ADVAPI32.dll CreateServiceW
RegCloseKey
RegOpenKeyExW
CloseServiceHandle
OpenSCManagerW
DeleteService
ControlService
StartServiceW
OpenServiceW
ntdll.dll NtQueryDirectoryObject
RtlFreeHeap
NtOpenDirectoryObject
NtQuerySystemInformation
RtlAllocateHeap
RtlGetVersion
NtAllocateVirtualMemory
NtDeleteFile
RtlInitUnicodeString
NtFreeVirtualMemory
NtClose
RtlUnwindEx

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x348
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51268
MD5 3c4f537726654fd5dd451e0999e58827 🔍
SHA1 5d18aa359d1c6e6b0a7a55f351beb92db880c6f1 🔍
SHA256 67aab5ffc63b34cbd917e8dd848dfb5d2cfc934013b9d31d77b61ea2ec85d987 🔍
SHA3 9fbb518433beaf05de0a4bb2aebe916add7b98f2555e33c1546c6a6468001afa 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.2.0.1704
ProductVersion 1.2.0.1704
FileFlags (EMPTY)
FileOs VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
FileType VFT_APP
Language English - Zimbabwe
CompanyName UG North
FileDescription Windows DSE overrider
FileVersion (#2) 1.2.0.1704
InternalName dsefix.exe
LegalCopyright Copyright (C) 2014 - 2017 EP_X0FF, MP_ART and N.Rin, based on WinNT/Turla exploit
OriginalFilename dsefix.exe
ProductName DSEFix
ProductVersion (#2) 1.2.0.1704
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

Size 0x94
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140008000
GuardCFCheckFunctionPointer 5368730104
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x2b904537
Unmarked objects 0
C objects (VS2015 UPD3 build 24123) 11
ASM objects (VS2015 UPD3 build 24123) 4
Imports (65501) 9
Total imports 67
264 (VS2015 UPD3.1 build 24215) 21
Resource objects (VS2015 UPD3 build 24210) 1
151 1
Linker (VS2015 UPD3.1 build 24215) 1

Errors

Leave a comment

No comments yet.