Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2021-Apr-19 00:16:33 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 9/68 (Scanned on 2022-05-07 19:55:52) |
Elastic:
malicious (moderate confidence)
Cynet: Malicious (score: 100) APEX: Malicious FireEye: Generic.mg.dca162879895c95f Avira: HEUR/AGEN.1213203 VBA32: suspected of Trojan.Downloader.gen MaxSecure: Trojan.Malware.300983.susgen BitDefenderTheta: Gen:NN.ZexaF.34638.huW@aiOUqPgi CrowdStrike: win/malicious_confidence_100% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2021-Apr-19 00:16:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x16200 |
SizeOfInitializedData | 0x9800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001FD2 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x18000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x24000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
Sleep
GetLastError GetTempPathW CloseHandle GetSystemTime WriteConsoleW DeleteFileW CreateMutexA GetVolumeInformationW SetEndOfFile ReadConsoleW ReadFile HeapReAlloc HeapSize CreateFileW SetFilePointerEx UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW RaiseException GetTimeZoneInformation GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapFree HeapAlloc WideCharToMultiByte GetCPInfo MultiByteToWideChar CompareStringW LCMapStringW GetFileType FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetStringTypeW GetProcessHeap FlushFileBuffers GetConsoleCP GetConsoleMode GetFileSizeEx DecodePointer |
---|---|
DNSAPI.dll |
DnsQuery_W
|
WININET.dll |
HttpSendRequestW
HttpQueryInfoW InternetOpenW HttpOpenRequestW InternetCloseHandle InternetConnectW |
Ordinal | 1 |
---|---|
Address | 0x1c50 |
Ordinal | 2 |
---|---|
Address | 0x1c40 |
Ordinal | 3 |
---|---|
Address | 0x1c40 |
Ordinal | 4 |
---|---|
Address | 0x1c40 |
Ordinal | 5 |
---|---|
Address | 0x1c40 |
Ordinal | 6 |
---|---|
Address | 0x1c40 |
Ordinal | 7 |
---|---|
Address | 0x1c40 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Apr-19 00:16:33 |
Version | 0.0 |
SizeofData | 672 |
AddressOfRawData | 0x1dbcc |
PointerToRawData | 0x1c1cc |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Apr-19 00:16:33 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xbc |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x41f004 |
SEHandlerTable | 0x41dbc0 |
SEHandlerCount | 3 |
XOR Key | 0x690369a3 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v14.15 compiler 26715) | 10 |
C++ objects (VS2017 v14.15 compiler 26715) | 150 |
C objects (VS2017 v14.15 compiler 26715) | 18 |
C++ objects (VS 2015/2017/2019 runtime 29118) | 37 |
C objects (VS 2015/2017/2019 runtime 29118) | 17 |
ASM objects (VS 2015/2017/2019 runtime 29118) | 19 |
Imports (VS2017 v14.15 compiler 26715) | 7 |
Total imports | 95 |
C++ objects (LTCG) (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
Exports (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
Resource objects (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
Linker (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |