d335904e0fc1209cced63553bebb5203

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2017-Jun-29 17:22:27

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual C++ 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • %temp%
  • Programs\Startup
Miscellaneous malware strings:
  • exploit
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious VirusTotal score: 52/65 (Scanned on 2017-09-03 19:30:36) MicroWorld-eScan: Trojan.Generic.22130915
CAT-QuickHeal: Trojan.Generic.FC.4551
McAfee: RDN/Generic.grp
Cylance: Unsafe
Zillya: Trojan.Injector.Win32.543999
K7GW: Trojan ( 0051200a1 )
K7AntiVirus: Trojan ( 0051200a1 )
Arcabit: Trojan.Generic.D151B0E3
Invincea: heuristic
Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9999
Symantec: W32.Spybot.Worm
TrendMicro-HouseCall: TROJ_GEN.R00UC0DGQ17
Avast: Win32:Malware-gen
Kaspersky: Trojan.MSIL.Agent.adcqq
BitDefender: Trojan.Generic.22130915
NANO-Antivirus: Trojan.Win32.Agent.erinqu
Paloalto: generic.ml
AegisLab: DangerousObject.Multi.Gen.lx9E
Tencent: Msil.Trojan.Agent.Woph
Ad-Aware: Trojan.Generic.22130915
Emsisoft: Trojan.Generic.22130915 (B)
F-Secure: Trojan.Generic.22130915
DrWeb: Trojan.DownLoader25.14792
VIPRE: Trojan.Win32.Generic!BT
TrendMicro: TROJ_GEN.R00UC0DGQ17
McAfee-GW-Edition: RDN/Generic.grp
Sophos: Mal/Generic-S
SentinelOne: static engine - malicious
Cyren: W32/Trojan.XMKM-2246
Webroot: W32.Trojan.Gen
Avira: TR/Dropper.Gen
Antiy-AVL: Trojan/Win32.TSGeneric
Endgame: malicious (high confidence)
Microsoft: VirTool:Win32/VBInject
ViRobot: Trojan.Win32.Z.Injector.536064.AQ
ZoneAlarm: Trojan.MSIL.Agent.adcqq
GData: Trojan.Generic.22130915
AhnLab-V3: Win-Trojan/FCN.140610
ALYac: Trojan.VBInject.RC
AVware: Trojan.Win32.Generic!BT
MAX: malware (ai score=100)
VBA32: Trojan.MSIL.Agent
Malwarebytes: Trojan.FakeMS
Zoner: Trojan.Msil
ESET-NOD32: a variant of MSIL/Injector.SNB
Rising: Dropper.Generic!8.35E (cloud:FwxACYginkV)
Yandex: Trojan.Agent!Ft1Ft3Av57k
Ikarus: Trojan.MSIL.RPX
Fortinet: MSIL/Injector.SNB!tr
AVG: Win32:Malware-gen
Panda: Trj/GdSda.A
CrowdStrike: malicious_confidence_100% (W)

Hashes

MD5 d335904e0fc1209cced63553bebb5203
SHA1 118580c111cd1d5da92c281647cb773d060dfb4b
SHA256 55b8c931d255cef1b2541db94a1eea700b9849c253ca5b24f31aeaf272a276c9
SHA3 5e1bf824bfc2afd8dd0e5a19e7c560a6b258b52298da62061259349583496a19
SSDeep 12288:kD3LAmOkOB8kL/utGjV6tJapnbFmy3PZUoyIGNOJiR:knGZGitGR
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2017-Jun-29 17:22:27
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 8.0
SizeOfCode 0x80e00
SizeOfInitializedData 0x1e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x82d3e (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x84000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x88000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bc71e78730de17ce2ac62f6ca0207241
SHA1 5248ac02f5332525d733dec7d8b550c6babcc13a
SHA256 50f5c30373694f1a9660ad768c64095fc18739426dcae344a7983c19c04c6462
SHA3 4584e81053a89265dde306b3d700f8cb692327c12dbcc157cee8dbc04f0fb2f6
VirtualSize 0x80d44
VirtualAddress 0x2000
SizeOfRawData 0x80e00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.16519

.rsrc

MD5 6387a995d8c8d62cc8c894ae554461aa
SHA1 38f0a0b3b799875d4ddb626eb3e14d455c7c9446
SHA256 d1c437b005f8bc03359e48288a06db45f970583b64c6f50138f435ef3278c4e3
SHA3 25a9e7776973d8677a2fab69f8fabc8eef90a2c7cb8cd6850a943a34ba00bb0a
VirtualSize 0x1a0a
VirtualAddress 0x84000
SizeOfRawData 0x1c00
PointerToRawData 0x81000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.1739

.reloc

MD5 549feb14bb8111f1377c3a6bfc2a6e88
SHA1 eeeb69a4e101c95bb23c97b05c6669dee6f3b74c
SHA256 10a54700ba52c048313dfd5ead9382ddbb60fe6478fbfc26ca44115ac6670628
SHA3 f5a64fc621a923bab7dd0c32867d111e45f854d06eb7cc402ddd5a84f266eb0d
VirtualSize 0xc
VirtualAddress 0x86000
SizeOfRawData 0x200
PointerToRawData 0x82c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.10191

Imports

mscoree.dll _CorExeMain

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
Entropy 4.85213
MD5 f526bc6086c01520d3a04cbbf2ae19e0
SHA1 e54e917c4762d0fbdf29e50906e35e798b99df82
SHA256 ac08deae876666e0e26c8a22e1794718a1b5bd0b73d5dd8a71d7542f5008f709
SHA3 b087ef43346db9a258ea2979a5b4e9b2ab37a6e492fe761d9b378e4b7d6f7e81

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
Entropy 5.19496
MD5 9a5bc96dfcfaada8ae03e5514594a51d
SHA1 edad97d86b0cc93de1d38e5aae2e2b5ebb9fd4e5
SHA256 9b9ee37f142f641a322bac0b06975f3ed9b32d89bb4ef975a7a34aac0c62712e
SHA3 db8806965db3cea2f59cd9a4ec924b5225b97cad857ea7c83414be8034303006

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x22
Entropy 1.88563
Detected Filetype Icon file
MD5 f59830b327862e43fd8156795de8ce86
SHA1 0a16c0e990148e24d084c07939b9c4195486a83b
SHA256 a952d351b0e7c4b08b3a84dfead42807e85b8ef0e01d1f67bf815972782ef6df
SHA3 531d7e9aae4e07b454f6bf7dbc956e46813abcd36dc7a510f7a49956cc0c6e2e

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3d0
Entropy 3.41942
MD5 85c37132c0e1b8582ceef0601eaf91f3
SHA1 1cd27cb3263e9de929fe607044d010e1ffd5c6bd
SHA256 a02b7bbc898706bd402faf2532694571db530319d6dc189ae5e87dafbb6b3a5d
SHA3 f0fbf198fbd21a1cdbb0b4139f3091ee9639d36fb7c621c8ff7df4f53d3e0ffc

Version Info

TLS Callbacks

Load Configuration

Errors

[!] Error: Could not read a VS_FIXED_FILE_INFO! [!] Error: Could not read a VS_FIXED_FILE_INFO! [*] Warning: Could not parse a VERSION_INFO resource!