Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Jun-19 09:55:38 |
Detected languages |
Japanese - Japan
|
Comments | |
CompanyName | |
FileDescription | AGE_System |
FileVersion | 1, 0, 0, 1 |
InternalName | AGE_System |
LegalCopyright | Copyright (C) 2012 |
LegalTrademarks | |
OriginalFilename | AGE_System.exe |
PrivateBuild | |
ProductName | AGE_System |
ProductVersion | 1, 0, 0, 1 |
SpecialBuild |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .2DJ
Section .2DJ is both writable and executable. |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 3584 bytes of data starting at offset 0xfd200. |
Malicious | VirusTotal score: 38/67 (Scanned on 2018-01-14 19:27:39) |
Bkav:
W32.HfsAutoB.248E
MicroWorld-eScan: Trojan.GenericKD.5858814 CAT-QuickHeal: Trojan.IGENERIC McAfee: Artemis!D644B6138B10 Cylance: Unsafe VIPRE: Trojan.Win32.Generic!BT K7GW: Riskware ( 0040eff71 ) K7AntiVirus: Riskware ( 0040eff71 ) TrendMicro: TROJ_GEN.R08JC0OH117 Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9991 Cyren: W32/Trojan.WGPR-3013 Symantec: Trojan.Gen.2 TrendMicro-HouseCall: TROJ_GEN.R08JC0OH117 Paloalto: generic.ml BitDefender: Trojan.GenericKD.5858814 NANO-Antivirus: Virus.Win32.Gen.ccmw Tencent: Win32.Trojan.Crypt.Wqcq Ad-Aware: Trojan.GenericKD.5858814 Sophos: Mal/Generic-S F-Secure: Trojan.GenericKD.5858814 Invincea: heuristic McAfee-GW-Edition: BehavesLike.Win32.Ramnit.fh Emsisoft: Trojan.GenericKD.5858814 (B) Webroot: W32.Trojan.Gen Antiy-AVL: Trojan/Win32.SGeneric Microsoft: Trojan:Win32/Skeeyah.A!bit Endgame: malicious (high confidence) Arcabit: Trojan.Generic.D5965FE AegisLab: Ml.Attribute.Gen!c GData: Trojan.GenericKD.5858814 ALYac: Trojan.GenericKD.5858814 AVware: Trojan.Win32.Generic!BT MAX: malware (ai score=100) WhiteArmor: Malware.HighConfidence Ikarus: Trojan.Win32.Skeeyah Fortinet: PossibleThreat Cybereason: malicious.1b8fb7 Panda: Generic Suspicious |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2017-Jun-19 09:55:38 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xbd000 |
SizeOfInitializedData | 0xb22000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00BE0004 (Section: .2DJ) |
BaseOfCode | 0x1000 |
BaseOfData | 0xbe000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xbe1000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GlobalFree
GlobalAlloc MultiByteToWideChar CreateEventA WaitForMultipleObjects DeleteFileA GlobalMemoryStatusEx WideCharToMultiByte SetEndOfFile IsBadCodePtr IsBadReadPtr SetUnhandledExceptionFilter GetStringTypeW GetStringTypeA FlushFileBuffers SetStdHandle GetCurrentProcessId LCMapStringW LCMapStringA RaiseException GetEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter GetDriveTypeA GetStdHandle WaitForSingleObject GetOEMCP GetCPInfo IsBadWritePtr HeapCreate HeapDestroy GetEnvironmentVariableA TlsGetValue SetLastError TlsAlloc TlsSetValue HeapSize TerminateProcess ExitProcess GetVersion GetCommandLineA GetStartupInfoA CreateDirectoryA RtlUnwind HeapReAlloc GetTickCount GetCurrentThread GetThreadPriority SetThreadPriority GetACP CreateThread GetLocalTime SetFilePointer CreateFileA SetFilePointerEx CloseHandle GetVersionExA GetModuleHandleA GetProcAddress GetSystemInfo FindFirstFileA GetModuleFileNameA QueryPerformanceCounter QueryPerformanceFrequency LeaveCriticalSection EnterCriticalSection DeleteCriticalSection GetVolumeInformationA InterlockedIncrement MulDiv GetCurrentThreadId GetFullPathNameA lstrcpyA OutputDebugStringA InitializeCriticalSection FreeLibrary ResetEvent SetEvent HeapFree GetCurrentProcess SetHandleCount ReadFile GetFileType Sleep VirtualFree VirtualAlloc IsProcessorFeaturePresent LoadLibraryA WriteFile GetLastError MapViewOfFile GetFileSize CreateFileMappingA CreateFileW UnmapViewOfFile HeapAlloc GetProcessHeap InterlockedDecrement |
---|---|
USER32.dll |
MsgWaitForMultipleObjects
GetQueueStatus PostThreadMessageA MoveWindow EnableWindow ClientToScreen SetCursorPos GetWindow GetClientRect InvalidateRect UpdateWindow CreateDialogParamA SetRect GetDlgItem SendMessageA GetDlgItemTextA EndDialog SetDlgItemTextA SystemParametersInfoA GetDC ReleaseDC GetAsyncKeyState GetKeyboardState ReleaseCapture SetCapture wsprintfA RegisterWindowMessageA GetWindowTextA IsWindowVisible GetWindowLongA ShowCursor ChangeDisplaySettingsA SetWindowTextA SetWindowLongA GetWindowRect SetWindowPos ShowWindow FindWindowA LoadIconA LoadCursorA RegisterClassExA CreateWindowExA AdjustWindowRect DestroyWindow EnumDisplaySettingsA DefWindowProcA PeekMessageA TranslateMessage DispatchMessageA PostQuitMessage BeginPaint EndPaint DialogBoxParamA MessageBoxA |
GDI32.dll |
GetGlyphOutlineA
EnumFontFamiliesExA CreateFontA SetTextColor CreateCompatibleDC CreateDIBSection SelectObject DeleteDC DeleteObject GetStockObject |
comdlg32.dll |
GetSaveFileNameA
|
SHELL32.dll |
SHGetSpecialFolderPathA
ShellExecuteA |
ole32.dll |
CoCreateInstance
CoUninitialize CoTaskMemAlloc CoFreeUnusedLibraries CoTaskMemFree CoSetProxyBlanket CoInitialize |
OLEAUT32.dll |
#6
#2 |
WINMM.dll |
timeSetEvent
timeGetTime timeBeginPeriod timeEndPeriod timeKillEvent |
d3d9.dll |
Direct3DCreate9
|
DSOUND.dll |
#11
|
ADVAPI32.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyA |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.1 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Japanese - Japan |
Comments | |
CompanyName | |
FileDescription | AGE_System |
FileVersion (#2) | 1, 0, 0, 1 |
InternalName | AGE_System |
LegalCopyright | Copyright (C) 2012 |
LegalTrademarks | |
OriginalFilename | AGE_System.exe |
PrivateBuild | |
ProductName | AGE_System |
ProductVersion (#2) | 1, 0, 0, 1 |
SpecialBuild |
Resource LangID | Japanese - Japan |
---|
XOR Key | 0x3c0dcbc9 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
C objects (VS98 SP6 build 8804) | 148 |
14 (7299) | 45 |
C objects (VS98 build 8168) | 22 |
C objects (9178) | 2 |
18 (8444) | 6 |
C++ objects (9178) | 117 |
C objects (2067) | 9 |
Imports (9210) | 4 |
C objects (2190) | 3 |
Imports (2179) | 19 |
Total imports | 231 |
C++ objects (VS98 SP6 build 8804) | 136 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |