| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Aug-15 07:24:28 |
| Detected languages |
English - United States
|
| CompanyName | BlackBOX Sistemi |
| FileDescription | BlackBOX Sistemi HUTOOL PRO |
| FileVersion | 3.5.0.1 |
| InternalName | HUTOOL |
| LegalCopyright | BlackBOX Sistemi |
| LegalTrademarks | BlackBOX Sistemi |
| OriginalFilename | HUTOOL3.exe |
| ProductName | BlackBOX Sistemi HUTOOL PRO |
| ProductVersion | 3.5.0.1 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VirtualPC presence:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to AES |
| Suspicious | The PE is possibly packed. |
Section .text is both writable and executable.
Unusual section name found: .hut3 Section .hut3 is both writable and executable. Unusual section name found: .hut3 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC+2 timezone. |
| Malicious | VirusTotal score: 42/69 (Scanned on 2022-07-08 06:49:35) |
Bkav:
W32.AIDetect.malware1
MicroWorld-eScan: Gen:Variant.Ursu.389733 FireEye: Generic.mg.d12c6fda7ce2f385 ALYac: Gen:Variant.Ursu.389733 Cylance: Unsafe VIPRE: Gen:Variant.Ursu.389733 K7AntiVirus: Trojan ( 005239691 ) Alibaba: Packed:Win32/NoobyProtect.d86da6df K7GW: Trojan ( 005239691 ) Cybereason: malicious.a7ce2f Cyren: W32/Troj_Obfusc.P.gen!Eldorado Symantec: ML.Attribute.HighConfidence Elastic: malicious (high confidence) ESET-NOD32: a variant of Win32/Packed.NoobyProtect.Q suspicious APEX: Malicious Paloalto: generic.ml BitDefender: Gen:Variant.Ursu.389733 Avast: Win32:Malware-gen Ad-Aware: Gen:Variant.Ursu.389733 Sophos: Mal/Generic-S Comodo: MalCrypt.Indus!@1qrzi1 McAfee-GW-Edition: BehavesLike.Win32.Injector.vh Trapmine: malicious.moderate.ml.score Emsisoft: Gen:Variant.Ursu.389733 (B) SentinelOne: Static AI - Malicious PE GData: Gen:Variant.Ursu.389733 MAX: malware (ai score=87) Antiy-AVL: Trojan/Generic.ASBOL.C6B4 Kingsoft: Win32.Heur.KVMH008.a.(kcloud) Gridinsoft: Trojan.Heur!.03050021 Microsoft: Trojan:Win32/Emotet!ml Cynet: Malicious (score: 100) AhnLab-V3: Malware/Gen.Generic.C3053169 McAfee: Artemis!D12C6FDA7CE2 Malwarebytes: Malware.Heuristic.1003 TrendMicro-HouseCall: TROJ_GEN.R002H0CAD22 Rising: Trojan.Generic@AI.89 (RDMK:6UwuczX6KoxySptK9a+HAQ) MaxSecure: Trojan.Malware.73877075.susgen Fortinet: Riskware/Application BitDefenderTheta: Gen:NN.ZexaF.34786.@x0@aehFuIki AVG: Win32:Malware-gen CrowdStrike: win/malicious_confidence_70% (W) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2018-Aug-15 07:24:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0 |
| SizeOfInitializedData | 0 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0067F942 (Section: .hut3) |
| BaseOfCode | 0 |
| BaseOfData | 0 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x69e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6a84cc |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
CharNextW
LoadStringW |
| kernel32.dll |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| kernel32.dll (#2) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| user32.dll (#2) |
CharNextW
LoadStringW |
| gdi32.dll |
UnrealizeObject
StretchDIBits StretchBlt StartPage StartDocW SetWindowOrgEx SetWinMetaFileBits SetViewportOrgEx SetTextColor SetStretchBltMode SetRectRgn SetROP2 SetPixel SetEnhMetaFileBits SetDIBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SetAbortProc SelectPalette SelectObject SelectClipRgn SaveDC RoundRect RestoreDC ResizePalette Rectangle RectVisible RealizePalette Polyline Polygon PolyBezierTo PolyBezier PlayEnhMetaFile Pie PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsW GetTextExtentPointW GetTextExtentPoint32W GetSystemPaletteEntries GetStockObject GetRgnBox GetPixel GetPaletteEntries GetObjectW GetNearestPaletteIndex GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileDescriptionW GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits GdiFlush FrameRgn ExtTextOutW ExtFloodFill ExcludeClipRect EnumFontsW EnumFontFamiliesExW EndPage EndDoc Ellipse DeleteObject DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateICW CreateHalftonePalette CreateFontIndirectW CreateDIBitmap CreateDIBSection CreateDCW CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileW Chord BitBlt ArcTo Arc AngleArc AbortDoc |
| version.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
| kernel32.dll (#3) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| kernel32.dll (#4) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| netapi32.dll |
NetWkstaGetInfo
|
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| ole32.dll |
OleUninitialize
OleInitialize CoTaskMemFree CoTaskMemAlloc CoCreateInstance CoUninitialize CoInitialize IsEqualGUID |
| comctl32.dll |
InitializeFlatSB
FlatSB_SetScrollProp FlatSB_SetScrollPos FlatSB_SetScrollInfo FlatSB_GetScrollPos FlatSB_GetScrollInfo _TrackMouseEvent ImageList_GetImageInfo ImageList_SetIconSize ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Copy ImageList_LoadImageW ImageList_GetIcon ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_SetOverlayImage ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_SetImageCount ImageList_GetImageCount ImageList_Destroy ImageList_Create |
| user32.dll (#3) |
CharNextW
LoadStringW |
| msvcrt.dll |
memset
memcpy |
| shell32.dll |
Shell_NotifyIconW
|
| wininet.dll |
InternetReadFile
InternetQueryDataAvailable InternetOpenUrlA InternetOpenA InternetOpenW InternetConnectA InternetConnectW InternetCloseHandle HttpSendRequestW HttpQueryInfoW HttpOpenRequestW |
| winspool.drv |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| winspool.drv (#2) |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| IPHLPAPI.DLL |
GetInterfaceInfo
|
| PSAPI.DLL |
GetMappedFileNameW
|
| Ordinal | 1 |
|---|---|
| Address | 0x207c5c |
| Ordinal | 2 |
|---|---|
| Address | 0x60128 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.5.0.1 |
| ProductVersion | 3.5.0.1 |
| FileFlags |
VS_FF_PRIVATEBUILD
VS_FF_SPECIALBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | BlackBOX Sistemi |
| FileDescription | BlackBOX Sistemi HUTOOL PRO |
| FileVersion (#2) | 3.5.0.1 |
| InternalName | HUTOOL |
| LegalCopyright | BlackBOX Sistemi |
| LegalTrademarks | BlackBOX Sistemi |
| OriginalFilename | HUTOOL3.exe |
| ProductName | BlackBOX Sistemi HUTOOL PRO |
| ProductVersion (#2) | 3.5.0.1 |
| Resource LangID | English - United States |
|---|