Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Apr-02 13:18:55 |
Detected languages |
English - United States
German - Germany |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 31/70 (Scanned on 2021-04-14 07:58:14) |
MicroWorld-eScan:
Trojan.GenericKD.46061122
McAfee: Artemis!DA1035191F6F Malwarebytes: Malware.AI.1564591014 Zillya: Trojan.Agent.Win32.1946984 Alibaba: Trojan:Win32/Generic.a9855a04 Symantec: Trojan.Gen.MBT Paloalto: generic.ml Kaspersky: Trojan.Win32.Agent.xahjwf BitDefender: Trojan.GenericKD.46061122 Avast: Win64:Malware-gen Ad-Aware: Trojan.GenericKD.46061122 Emsisoft: Trojan.GenericKD.46061122 (B) DrWeb: Trojan.MulDrop16.43165 McAfee-GW-Edition: BehavesLike.Win64.Dropper.th FireEye: Trojan.GenericKD.46061122 Sophos: Mal/Generic-S APEX: Malicious GData: Trojan.GenericKD.46061122 Jiangmin: Trojan.Agent.dfwk Avira: TR/Agent.yftdf Arcabit: Trojan.Generic.D2BED642 AegisLab: Trojan.Win32.Agent.4!c Microsoft: Trojan:Win32/Wacatac.B!ml Cynet: Malicious (score: 100) ALYac: Trojan.GenericKD.46061122 MAX: malware (ai score=88) Rising: Trojan.Agent!8.B1E (CLOUD) Ikarus: Trojan.Agent AVG: Win64:Malware-gen Panda: Trj/CI.A Qihoo-360: Win32/Trojan.Generic.HgEASSYA |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2021-Apr-02 13:18:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xd6600 |
SizeOfInitializedData | 0xcf200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000009ADEC (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1aa000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CreateDirectoryW
GetModuleFileNameA FindFirstFileW GetFullPathNameW FindNextFileW RemoveDirectoryW FindClose GetFileAttributesW GetFileInformationByHandle DeleteFileW GetCurrentDirectoryW MoveFileExW GlobalMemoryStatusEx GetModuleHandleW CopyFileW CreateDirectoryExW ReadFile WriteFile PeekNamedPipe GetCurrentProcessId WaitNamedPipeW lstrlenW GetModuleFileNameW GetCommandLineW Sleep SetUnhandledExceptionFilter Process32First CreateToolhelp32Snapshot Process32Next GetNativeSystemInfo CreateProcessA SleepConditionVariableCS EnterCriticalSection WakeConditionVariable LeaveCriticalSection InitializeCriticalSection InitializeConditionVariable CreateThread DeleteCriticalSection lstrcmpiA FormatMessageA WriteConsoleW HeapSize GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP LocalFree FindFirstFileExW SetStdHandle GetTimeZoneInformation HeapReAlloc GetFileSizeEx GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW WideCharToMultiByte CompareStringW GetTimeFormatW GetDateFormatW HeapFree HeapAlloc ReadConsoleW GetConsoleMode SetFilePointerEx GetStdHandle SystemTimeToFileTime TzSpecificLocalTimeToSystemTime SetFileTime GetFileType SetEndOfFile CloseHandle GetFileAttributesExW GetLastError FormatMessageW GlobalLock GlobalFree GlobalAlloc MultiByteToWideChar QueryPerformanceCounter VerifyVersionInfoW FreeLibraryAndExitThread ExitThread GetModuleHandleExW ExitProcess LoadLibraryExW FreeLibrary TlsFree TlsSetValue TlsGetValue TlsAlloc SetLastError CreateFileW DeviceIoControl IsValidCodePage GlobalUnlock RtlUnwindEx GetCPInfo GetStringTypeW LCMapStringEx RtlUnwind DecodePointer EncodePointer GetExitCodeThread VerSetConditionMask GetProcAddress QueryPerformanceFrequency LCMapStringW InitOnceExecuteOnce InitializeCriticalSectionAndSpinCount SetEvent ResetEvent WaitForSingleObjectEx CreateEventW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive InitializeCriticalSectionEx TryEnterCriticalSection WakeAllConditionVariable SleepConditionVariableSRW RtlPcToFileHeader RaiseException |
---|---|
USER32.dll |
ReleaseCapture
GetClientRect SetCursor SetCapture GetForegroundWindow IsChild ClientToScreen GetCapture ScreenToClient LoadCursorA UnregisterClassA PeekMessageA TranslateMessage SetLayeredWindowAttributes DefWindowProcA ShowWindow GetSystemMetrics DestroyWindow DispatchMessageA SetForegroundWindow GetWindowTextA FindWindowExA PostQuitMessage GetClassNameA GetKeyState SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard SetWindowPos GetWindowRect RegisterClassExA SetCursorPos GetCursorPos CreateWindowExA GetWindowThreadProcessId |
ADVAPI32.dll |
RegCloseKey
RegSetValueExW RegCreateKeyExW |
SHELL32.dll |
SHGetSpecialFolderPathA
ShellExecuteA CommandLineToArgvW |
ole32.dll |
CoCreateInstance
CoUninitialize PropVariantClear CoInitialize |
dwmapi.dll |
DwmExtendFrameIntoClientArea
|
IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext |
WINHTTP.dll |
WinHttpOpen
WinHttpQueryDataAvailable WinHttpConnect WinHttpSetTimeouts WinHttpSendRequest WinHttpWriteData WinHttpGetProxyForUrl WinHttpGetIEProxyConfigForCurrentUser WinHttpCloseHandle WinHttpSetOption WinHttpOpenRequest WinHttpReadData WinHttpQueryHeaders WinHttpAddRequestHeaders WinHttpReceiveResponse WinHttpCrackUrl |
d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
WS2_32.dll |
accept
bind closesocket listen WSAStartup send socket ntohs getnameinfo recv htonl WSAGetLastError setsockopt htons |
CRYPT32.dll |
CertFreeCertificateContext
CertCloseStore CertFindCertificateInStore CertOpenSystemStoreA |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Apr-02 13:18:55 |
Version | 0.0 |
SizeofData | 984 |
AddressOfRawData | 0xf7c3c |
PointerToRawData | 0xf663c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Apr-02 13:18:55 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x1400f8038 |
---|---|
EndAddressOfRawData | 0x1400f8040 |
AddressOfIndex | 0x140162000 |
AddressOfCallbacks | 0x1400d88e8 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14010a010 |
XOR Key | 0xdefe77f1 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 23 |
C++ objects (27412) | 202 |
C++ objects (VS 2015/2017/2019 runtime 29804) | 98 |
C objects (VS 2015/2017/2019 runtime 29804) | 18 |
ASM objects (VS 2015/2017/2019 runtime 29804) | 10 |
C++ objects (29912) | 2 |
C objects (27412) | 28 |
262 (27412) | 1 |
Imports (27412) | 25 |
Total imports | 276 |
265 (29912) | 26 |
Resource objects (29912) | 1 |
151 | 1 |
Linker (29912) | 1 |