Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2014-Aug-02 22:19:45 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
30788784 bytes of data starting at offset 0x13000.
Overlay data amounts for 99.7479% of the executable. |
Malicious | VirusTotal score: 6/72 (Scanned on 2020-11-21 12:40:50) |
APEX:
Malicious
F-Secure: Worm.WORM/Lodbak.Gen Avira: WORM/Lodbak.Gen Cynet: Malicious (score: 100) Cylance: Unsafe Rising: Trojan.Hatecrypt!1.A528 (CLASSIC) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2014-Aug-02 22:19:45 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xc000 |
SizeOfInitializedData | 0x6000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00006444 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xd000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb12000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTempPathA
GetModuleFileNameA GetStdHandle Sleep SetConsoleCursorInfo SetConsoleCursorPosition SetConsoleTextAttribute GetTickCount GetConsoleMode ExitProcess TerminateProcess GetCurrentProcess GetCommandLineA GetVersion GetLastError GetFileAttributesA HeapFree CloseHandle SetFilePointer SetHandleCount GetFileType GetStartupInfoA WriteFile ReadFile GetProcAddress GetModuleHandleA UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree RtlUnwind HeapAlloc GetExitCodeProcess WaitForSingleObject CreateProcessA VirtualAlloc HeapReAlloc SetStdHandle FlushFileBuffers MultiByteToWideChar GetStringTypeA GetStringTypeW CreateFileA GetCPInfo GetACP GetOEMCP LoadLibraryA CompareStringA CompareStringW SetEnvironmentVariableA SetEndOfFile LCMapStringA LCMapStringW WriteConsoleA ReadConsoleInputA SetConsoleMode |
---|---|
WINMM.dll |
timeGetTime
|
XOR Key | 0x994e6f88 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
C++ objects (VS98 build 8168) | 1 |
14 (7299) | 15 |
19 (8034) | 5 |
Total imports | 65 |
C objects (VS98 build 8168) | 95 |
Resource objects (VS98 cvtres build 1720) | 1 |