Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Jul-10 17:06:24 |
TLS Callbacks | 2 callback(s) detected. |
Suspicious | PEiD Signature: | HQR data file |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: LGN Software
Issuer: LGN Software |
Malicious | VirusTotal score: 6/68 (Scanned on 2021-09-16 04:05:20) |
ESET-NOD32:
a variant of Python/Agent.MU.gen
Sophos: Mal/Generic-R + Mal/BadCert-Gen McAfee-GW-Edition: Artemis McAfee: Artemis!CF48C63ABACD Ikarus: Trojan.Python.Agent Fortinet: W32/Agent.MU!tr |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 10 |
TimeDateStamp | 2021-Jul-10 17:06:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x1285c00 |
SizeOfInitializedData | 0x1c95400 |
SizeOfUninitializedData | 0x72a00 |
AddressOfEntryPoint | 0x00000000000014B0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x1d0d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1c9ab54 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x968000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
python38.dll |
PyObject_GC_Del
_PyObject_GC_Resize _PyObject_GC_New _PyObject_GC_Malloc PyObject_GC_UnTrack PyObject_GC_Track _PyTraceMalloc_NewReference PyIter_Next PyObject_GetIter PyObject_IsSubclass PyObject_IsInstance PyMapping_Check PySequence_Contains PySequence_List PySequence_Tuple PySequence_GetItem PySequence_InPlaceConcat PySequence_Check PyNumber_ToBase PyNumber_Float PyNumber_Long PyNumber_AsSsize_t PyNumber_Index PyNumber_Invert PyNumber_Positive PyNumber_Negative PyNumber_InPlaceMultiply PyNumber_InPlaceAdd PyNumber_InPlaceLshift PyNumber_FloorDivide PyNumber_Add PyNumber_Subtract PyBuffer_Release PyObject_GetBuffer PyObject_DelItem PyObject_SetItem PyObject_GetItem PyObject_LengthHint PyObject_Size PyBool_Type _Py_FalseStruct _Py_TrueStruct _PyByteArray_empty_string PyByteArray_Type PyByteArray_FromStringAndSize PyByteArray_FromObject PyBytes_Type _PyBytes_Resize PyBytes_FromString PyBytes_FromStringAndSize PyObject_CallFunctionObjArgs PyObject_CallMethodObjArgs PyObject_CallObject PyObject_Call PyCapsule_New PyMethod_Type PyCode_Type PyCode_NewWithPosOnlyArgs PyComplex_Type PyComplex_FromDoubles PyProperty_Type PyDict_Type PyDict_DelItemString PyDict_SetItemString PyDict_GetItemString PyDict_Copy PyDict_Merge PyDict_MergeFromSeq2 PyDict_Next PyDict_DelItem PyDict_SetItem PyDict_GetItem _PyDict_NewPresized PyDict_New PyEnum_Type PyReversed_Type PyExc_ImportWarning PyExc_Exception PyExc_KeyError PyExc_RuntimeError PyExc_IOError PyExc_UnboundLocalError PyExc_PermissionError PyExc_AttributeError PyExc_ZeroDivisionError PyExc_ValueError PyExc_BaseException PyExc_OverflowError PyExc_UnicodeError PyExc_UnicodeDecodeError PyExc_IsADirectoryError PyExc_SyntaxError PyExc_StopIteration PyExc_OSError PyExc_NotImplementedError PyExc_StopAsyncIteration PyExc_TypeError PyExc_NameError PyExc_LookupError PyExc_IndexError PyExc_UnicodeEncodeError PyExc_ImportError PyExc_SystemError PyExc_AssertionError PyExc_GeneratorExit PyExc_FileNotFoundError PyExc_ModuleNotFoundError PyException_SetContext PyException_GetContext PyException_SetCause PyException_GetTraceback PyFloat_Type PyFloat_FromString PyFloat_FromDouble PyFrame_Type PyFrame_New PyFrame_GetLineNumber PyFunction_Type _PyAsyncGenWrappedValue_Type PyCoro_Type PyGen_Type PyAsyncGen_Type _PyGen_FetchStopIterationValue _PyGen_SetStopIterationValue PySeqIter_Type PyCallIter_Type PyList_Type PyList_Insert PyList_SetItem PyList_New PyLong_Type PyLong_FromUnicodeObject PyLong_FromString PyLong_FromSsize_t PyLong_FromUnsignedLongLong PyLong_FromLongLong PyLong_FromVoidPtr PyLong_AsLong PyLong_AsLongAndOverflow PyLong_FromLong _PyLong_New PyMemoryView_Type PyCFunction_Type PyCFunction_NewEx PyModule_Type PyModuleDef_Type PyModule_GetDef PyModule_GetFilenameObject PyModule_GetName PyModule_GetDict PyModule_ExecDef PyModule_FromDefAndSpec2 PyModule_NewObject _Py_NoneStruct _Py_NotImplementedStruct _Py_Dealloc PyObject_Dir PyCallable_Check PyObject_IsTrue PyObject_GenericSetAttr PyObject_GenericGetAttr PyObject_SelfIter PyObject_SetAttr PyObject_GetAttr PyObject_SetAttrString PyObject_HasAttrString PyObject_GetAttrString PyObject_RichCompareBool PyObject_RichCompare PyObject_Str PyObject_Repr _PyObject_New _Py_tracemalloc_config PyObject_Free PyObject_Realloc PyObject_Malloc PyMem_Realloc PyMem_Malloc PyRange_Type PyFrozenSet_Type PySet_Type _PySet_NextEntry PySet_Add PyFrozenSet_New PySet_New PySlice_Type _Py_EllipsisObject PyEllipsis_Type PySlice_New PyStructSequence_InitType PyStructSequence_SetItem PyStructSequence_New PyTuple_Type PyTuple_Pack PyTuple_New PyBaseObject_Type PySuper_Type PyType_Type PyType_Ready _PyType_Lookup PyType_GetFlags PyType_IsSubtype PyUnicode_Type PyUnicode_InternInPlace PyUnicode_Format PyUnicode_Substring PyUnicode_Concat PyUnicode_Join PyUnicode_FindChar PyUnicode_Find PyUnicode_DecodeUTF8 PyUnicode_GetLength PyUnicode_AsUnicode PyUnicode_AsUTF8 PyUnicode_FromEncodedObject PyUnicode_FromOrdinal PyUnicode_FromFormat PyUnicode_FromString PyUnicode_FromStringAndSize PyUnicode_FromWideChar _PyUnicode_Ready PyUnicode_New PyObject_ClearWeakRefs _PyWarnings_Init PyErr_WarnEx PyMap_Type PyFilter_Type PyZip_Type PyEval_GetFuncName PyEval_GetFrame PyEval_EvalCodeEx PyEval_EvalFrameEx PyEval_EvalCode Py_MakePendingCalls PyEval_SaveThread PyEval_AcquireThread PyEval_ThreadsInitialized PyErr_WriteUnraisable PyErr_Format PyErr_SetFromErrno PyErr_NoMemory PyErr_BadArgument _PyErr_FormatFromCause PyErr_NormalizeException PyErr_ExceptionMatches PyErr_GivenExceptionMatches PyImport_FrozenModules _PyArg_NoKeywords PyArg_UnpackTuple PyArg_ParseTupleAndKeywords PyArg_ParseTuple PyImport_ImportModule PyImport_ImportFrozenModule PyImport_ExecCodeModuleEx PyImport_ExecCodeModule _PyImport_FixupExtensionObject PyImport_GetModule PyImport_GetModuleDict Py_NoSiteFlag Py_NoUserSiteDirectory Py_DontWriteBytecodeFlag Py_DebugFlag Py_BytesWarningFlag Py_VerboseFlag Py_OptimizeFlag Py_UTF8Mode Py_InteractiveFlag Py_InspectFlag Py_IgnoreEnvironmentFlag Py_FrozenFlag PyMarshal_ReadObjectFromString _Py_PackageContext PyModule_AddObject Py_BuildValue PyOS_snprintf Py_SetPythonHome Py_SetPath Py_Exit Py_Initialize PyThreadState_Get Py_CompileStringExFlags PyErr_Print PyErr_PrintEx PySys_WriteStderr PySys_SetArgv PySys_SetPath PySys_SetObject PySys_GetObject PyTraceBack_Type |
---|---|
KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection FindResourceA FormatMessageA GetCommandLineW GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetLastError GetModuleFileNameW GetProcAddress GetShortPathNameW GetStartupInfoA GetSystemTimeAsFileTime GetTempPathW GetTickCount InitializeCriticalSection LeaveCriticalSection LoadLibraryExW LoadResource LockResource QueryPerformanceCounter RtlAddFunctionTable RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetDllDirectoryW SetErrorMode SetUnhandledExceptionFilter Sleep TerminateProcess TlsGetValue UnhandledExceptionFilter VirtualProtect VirtualQuery |
msvcrt.dll |
__C_specific_handler
__argc __argv __getmainargs __initenv __iob_func __lconv_init __set_app_type __setusermatherr _acmdln _amsg_exit _cexit _errno _fmode _initterm _itoa_s _onexit _snprintf _wcsicmp abort atoi calloc exit fprintf free fwrite getenv malloc mbstowcs memcmp memcpy memset printf puts signal strchr strcmp strlen strncmp strncpy strrchr vfprintf vsprintf wcscmp wcslen |
SHELL32.dll |
CommandLineToArgvW
|
StartAddressOfRawData | 0x1766000 |
---|---|
EndAddressOfRawData | 0x1766008 |
AddressOfIndex | 0x175ec3c |
AddressOfCallbacks | 0x1765040 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x0000000001684AB0
0x0000000001684A80 |