Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Feb-03 09:44:32 |
Detected languages |
English - United States
|
FileVersion | 1.1.24.05 |
ProductVersion | 1.1.24.05 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/67 (Scanned on 2021-03-10 23:46:53) | Zillya: Trojan.Starter.Win32.21811 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2017-Feb-03 09:44:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xc1000 |
SizeOfInitializedData | 0x88000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000A3798 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x155000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WSOCK32.dll |
WSACleanup
inet_addr gethostbyname gethostname WSAStartup |
---|---|
WINMM.dll |
mixerSetControlDetails
waveOutGetVolume joyGetPosEx mixerGetControlDetailsW mixerOpen mixerGetDevCapsW mixerGetLineControlsW waveOutSetVolume mixerClose mciSendStringW joyGetDevCapsW mixerGetLineInfoW |
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
COMCTL32.dll |
ImageList_Create
CreateStatusWindowW ImageList_ReplaceIcon ImageList_GetIconSize ImageList_Destroy ImageList_AddMasked |
PSAPI.DLL |
GetModuleFileNameExW
GetProcessImageFileNameW GetModuleBaseNameW |
KERNEL32.dll |
FindClose
FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW WideCharToMultiByte MultiByteToWideChar GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess TerminateProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW GetDiskFreeSpaceW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW CreateDirectoryW ReadFile WriteFile DeleteFileW SetFileAttributesW LocalFileTimeToFileTime SetFileTime GetFileSizeEx GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetWindowsDirectoryW GetTempPathW GetFullPathNameW GetShortPathNameW LoadLibraryW FreeLibrary EnterCriticalSection LeaveCriticalSection VirtualProtect FindNextFileW CompareStringW RemoveDirectoryW CopyFileW GetCurrentProcess FormatMessageW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize IsWow64Process VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount RtlUnwindEx RaiseException EncodePointer RtlPcToFileHeader InitializeSListHead QueryPerformanceCounter IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext CreateEventW WaitForSingleObjectEx ResetEvent SetEvent GetCommandLineW ExitProcess GetModuleHandleExW HeapSize HeapReAlloc HeapQueryInformation HeapFree HeapAlloc FindFirstFileW LockResource LoadResource SizeofResource FindResourceW GetSystemTimeAsFileTime GetModuleFileNameW DeleteCriticalSection GetCPInfo GetVersionExW GetModuleHandleW GetProcAddress GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock GetCurrentDirectoryW SetErrorMode InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount MulDiv TlsSetValue TlsFree LCMapStringW GetStringTypeW GetConsoleCP GetConsoleMode GetProcessHeap FindFirstFileExW GetCommandLineA IsValidCodePage GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers WriteConsoleW QueryDosDeviceW ReadConsoleW |
USER32.dll |
SetParent
GetClassInfoExW GetAncestor UpdateWindow GetMessagePos GetClassLongPtrW DefDlgProcW CallWindowProcW CheckRadioButton IntersectRect PtInRect CreateDialogIndirectParamW GetWindowLongPtrW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu GetMenuItemInfoW CreateMenu CreatePopupMenu SetMenuInfo AppendMenuW DestroyMenu TrackPopupMenuEx CreateIconIndirect GetDesktopWindow CopyImage CreateIconFromResourceEx EnumClipboardFormats GetWindow BringWindowToTop GetTopWindow SetActiveWindow EnumChildWindows MoveWindow GetQueueStatus GetWindowRect GetClientRect SystemParametersInfoW AdjustWindowRectEx DrawTextW SetRect GetIconInfo SetWindowLongPtrW IsWindowVisible MessageBoxW LoadImageW ChangeClipboardChain SetClipboardViewer LoadAcceleratorsW EnableMenuItem GetMenu CreateWindowExW RegisterClassExW LoadCursorW DestroyIcon DestroyWindow IsCharAlphaW GetCursor MapVirtualKeyExW VkKeyScanExW GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharUpperW IsCharLowerW IsCharAlphaNumericW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW ReleaseDC GetDC OpenClipboard GetClipboardData GetClipboardFormatNameW RedrawWindow MapWindowPoints RemovePropW SetPropW GetPropW FlashWindow SetMenu ExitWindowsEx GetMenuStringW GetSubMenu GetMenuItemID GetMenuItemCount SetWindowTextW GetLastInputInfo CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow ClientToScreen MessageBeep SetDlgItemTextW GetDlgItem SendDlgItemMessageW DialogBoxParamW SetForegroundWindow DefWindowProcW FillRect DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW IsIconic IsZoomed EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetLayeredWindowAttributes SetWindowPos CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable SetWindowRgn SetFocus MapVirtualKeyW GetGUIThreadInfo CheckMenuItem |
GDI32.dll |
GetPixel
GetClipRgn GetCharABCWidthsW SetBkMode CreatePatternBrush SetBrushOrgEx EnumFontFamiliesExW CreateDIBSection GdiFlush SetBkColor ExcludeClipRect SetTextColor GetClipBox BitBlt CreateCompatibleBitmap GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush CreateFontW FillRgn GetDeviceCaps DeleteObject |
COMDLG32.dll |
CommDlgExtendedError
GetSaveFileNameW GetOpenFileNameW |
ADVAPI32.dll |
RegDeleteKeyW
RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW RegDeleteValueW |
SHELL32.dll |
DragQueryPoint
SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW ExtractIconW |
ole32.dll |
OleInitialize
OleUninitialize CoCreateInstance CoInitialize CoUninitialize CLSIDFromString CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
OLEAUT32.dll |
SafeArrayGetLBound
GetActiveObject SysStringLen OleLoadPicture SafeArrayUnaccessData SafeArrayGetElemsize SafeArrayAccessData SafeArrayUnlock SafeArrayPtrOfIndex SafeArrayLock SafeArrayGetDim SafeArrayDestroy SafeArrayGetUBound VariantCopyInd SafeArrayCopy SysAllocString VariantChangeType VariantClear SafeArrayCreate SysFreeString |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.1.24.5 |
ProductVersion | 1.1.24.5 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileVersion (#2) | 1.1.24.05 |
ProductVersion (#2) | 1.1.24.05 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-03 09:44:32 |
Version | 0.0 |
SizeofData | 948 |
AddressOfRawData | 0xee2cc |
PointerToRawData | 0xed6cc |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-03 09:44:32 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x14010e000 |
---|---|
EndAddressOfRawData | 0x14010e008 |
AddressOfIndex | 0x1400fd838 |
AddressOfCallbacks | 0x1400c2f08 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x94 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1400fa018 |
XOR Key | 0x87a45a01 |
---|---|
Unmarked objects | 0 |
241 (40116) | 19 |
243 (40116) | 140 |
242 (40116) | 23 |
ASM objects (VS2015 UPD3 build 24123) | 8 |
C++ objects (VS2015 UPD3 build 24123) | 40 |
C objects (VS2015 UPD3 build 24123) | 20 |
C objects (VS2008 SP1 build 30729) | 6 |
135 (VS2008 SP1 build 30729) | 1 |
Imports (VS2008 SP1 build 30729) | 27 |
Total imports | 457 |
ASM objects (VS2015 UPD3 build 24210) | 2 |
265 (VS2015 UPD3.1 build 24215) | 42 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |