| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2013-Jan-02 09:46:37 |
| Debug artifacts |
X:\dev\_exploits\_Local\WindowsRegistryRootkit\bin\rootkit_installer.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) Microsoft Visual C++ |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 50/73 (Scanned on 2020-03-02 17:41:26) |
MicroWorld-eScan:
Trojan.Generic.8814730
FireEye: Trojan.Generic.8814730 McAfee: Artemis!DBF64C0BCB9A Cylance: Unsafe VIPRE: Rootkit.Win32.Agent.Gen (fs) Sangfor: Malware K7AntiVirus: Riskware ( 0040eff71 ) Alibaba: Trojan:Win32/Diple.228f9700 K7GW: Riskware ( 0040eff71 ) Cybereason: malicious.bcb9a5 Arcabit: Trojan.Generic.D86808A TrendMicro: TROJ_GEN.R002C0DBT20 Symantec: Trojan.Gen.2 Kaspersky: Trojan.Win32.Diple.fzxp BitDefender: Trojan.Generic.8814730 NANO-Antivirus: Trojan.Win32.Swrort.cylunw Rising: Trojan.Win32.Generic.148A80CB (C64:YzY0Ol75g2fxYVfK) Ad-Aware: Trojan.Generic.8814730 Emsisoft: Trojan.Generic.8814730 (B) Comodo: Malware@#2eohwuae0cmy9 F-Secure: Trojan.TR/Swrort.A.8471 Zillya: Trojan.Diple.Win32.78248 McAfee-GW-Edition: Artemis!Trojan Sophos: Mal/Generic-S SentinelOne: DFI - Suspicious PE Jiangmin: Trojan/Generic.autgc Avira: TR/Swrort.A.8471 Fortinet: W32/Diple.FZXP!tr Antiy-AVL: Trojan/Win32.AGeneric Endgame: malicious (high confidence) Microsoft: Trojan:Win32/Leivion.I AegisLab: Trojan.Win32.Diple.4!c ZoneAlarm: Trojan.Win32.Diple.fzxp TACHYON: Trojan/W32.Diple.155136 ALYac: Trojan.Generic.8814730 MAX: malware (ai score=100) VBA32: Backdoor.Swrort Panda: Generic Malware ESET-NOD32: a variant of Generik.CNEOVNE TrendMicro-HouseCall: TROJ_GEN.R002C0DBT20 Tencent: Win32.Trojan.Diple.Wweg Yandex: Trojan.Diple!fmId3uybRkY Ikarus: Trojan.Veil MaxSecure: Trojan.Malware.10368649.susgen GData: Trojan.Generic.8814730 Webroot: W32.Trojan.Gen AVG: Multi:Swrort-A [Trj] Avast: Multi:Swrort-A [Trj] CrowdStrike: win/malicious_confidence_100% (W) Qihoo-360: Win32/Trojan.fb5 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2013-Jan-02 09:46:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x19000 |
| SizeOfInitializedData | 0xe600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00006D2A (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FreeLibrary
LoadLibraryExA IsBadStringPtrW GetSystemDirectoryA lstrlenA GetVersionExA WriteFile lstrcpynA OutputDebugStringA GetCurrentProcessId LoadLibraryA SetStdHandle SetEnvironmentVariableA CompareStringW GetModuleHandleA GetProcAddress LocalAlloc LocalFree GetCurrentProcess GetLastError GetStdHandle CloseHandle ReadConsoleInputA SetConsoleMode GetConsoleMode PeekConsoleInputA GetNumberOfConsoleInputEvents HeapFree HeapAlloc GetCommandLineA TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent CreateFileA DeleteCriticalSection LeaveCriticalSection FatalAppExitA EnterCriticalSection HeapCreate HeapDestroy VirtualFree VirtualAlloc HeapReAlloc GetModuleHandleW Sleep ExitProcess GetModuleFileNameA GetFileAttributesA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement GetCurrentThread QueryPerformanceCounter GetTickCount GetSystemTimeAsFileTime WriteConsoleA GetConsoleOutputCP WriteConsoleW MultiByteToWideChar InitializeCriticalSectionAndSpinCount RtlUnwind GetCPInfo GetACP GetOEMCP IsValidCodePage SetConsoleCtrlHandler InterlockedExchange GetExitCodeProcess WaitForSingleObject CreateProcessA GetConsoleCP FlushFileBuffers LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetTimeFormatA GetDateFormatA GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale SetFilePointer HeapSize GetLocaleInfoW CompareStringA GetTimeZoneInformation |
|---|---|
| USER32.dll |
ExitWindowsEx
MessageBoxA |
| ADVAPI32.dll |
RegDeleteValueA
RegCloseKey RegSetValueExA OpenProcessToken LookupPrivilegeValueA AdjustTokenPrivileges RegOpenKeyA |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2013-Jan-02 09:46:37 |
| Version | 0.0 |
| SizeofData | 97 |
| AddressOfRawData | 0x1d7f0 |
| PointerToRawData | 0x1cbf0 |
| Referenced File | X:\dev\_exploits\_Local\WindowsRegistryRootkit\bin\rootkit_installer.pdb |
| XOR Key | 0x1041fc85 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 SP1 build 30729) | 17 |
| C objects (VS2008 SP1 build 30729) | 101 |
| 18 (8444) | 1 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 7 |
| Total imports | 110 |
| C++ objects (VS2008 SP1 build 30729) | 36 |
| Resource objects (VS2008 SP1 build 30729) | 1 |