Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Oct-17 12:50:23 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
15490048 bytes of data starting at offset 0x3a400.
Overlay data amounts for 98.4831% of the executable. |
Malicious | VirusTotal score: 27/72 (Scanned on 2023-10-17 13:59:16) |
APEX:
Malicious
AVG: PWSX-gen [Trj] AhnLab-V3: Malware/Win.Generic.C5513027 Avast: PWSX-gen [Trj] BitDefenderTheta: Gen:NN.ZexaE.36738.@tZ@aiNN@Hci Bkav: W32.AIDetectMalware CrowdStrike: win/malicious_confidence_90% (D) Cybereason: malicious.15b6ff Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: a variant of Win32/Kryptik.HTUK Elastic: malicious (high confidence) FireEye: Generic.mg.dd193b5a1353c931 GData: Win32.Trojan.PSE.11AU12L Google: Detected Ikarus: Trojan-Spy.Cinoshi Jiangmin: TrojanDownloader.Deyma.arb K7AntiVirus: Trojan ( 005a9f911 ) K7GW: Trojan ( 005a9f911 ) Microsoft: Trojan:Win32/Sabsik.FL.B!ml Rising: Backdoor.Agent!8.C5D (TFE:5:2amkDsTMsKK) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Sophos: ML/PE-A Symantec: ML.Attribute.HighConfidence Trapmine: malicious.high.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2023-Oct-17 12:50:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x12000 |
SizeOfInitializedData | 0x28c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00008F80 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x13000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3d000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
WaitForSingleObject
Sleep CreateThread lstrlenW VirtualProtect GetProcAddress LoadLibraryA VirtualAlloc LockResource LoadResource SizeofResource FindResourceW GetModuleHandleW GetModuleHandleA EnumSystemCodePagesW FreeConsole GetLastError HeapFree HeapAlloc RtlUnwind RaiseException GetCommandLineA HeapCreate VirtualFree DeleteCriticalSection LeaveCriticalSection EnterCriticalSection HeapReAlloc ExitProcess WriteFile GetStdHandle GetModuleFileNameA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoA QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetCPInfo GetACP GetOEMCP IsValidCodePage InitializeCriticalSectionAndSpinCount HeapSize LCMapStringA MultiByteToWideChar LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA |
---|---|
USER32.dll |
GetWindowTextLengthW
|
XOR Key | 0x30856e6e |
---|---|
Unmarked objects | 0 |
ASM objects (VS2008 build 21022) | 20 |
C objects (VS2008 build 21022) | 89 |
C++ objects (VS2008 build 21022) | 39 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
Imports (VS2003 (.NET) build 4035) | 3 |
Total imports | 86 |
C++ objects (VS2008 SP1 build 30729) | 1 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |