Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Sep-07 20:37:49 |
Debug artifacts |
C:\dacufofupip2\rimemofozetozi\file-gedigitasopuv\36 yo.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 58/67 (Scanned on 2021-10-19 08:10:45) |
Bkav:
W32.AIDetect.malware1
Lionic: Trojan.Win32.DelShad.4!c Elastic: malicious (high confidence) MicroWorld-eScan: Gen:Heur.Mint.Titirez.Iq0@a9d0C9aG ALYac: Trojan.Ransom.LockBit Malwarebytes: Trojan.MalPack Sangfor: Trojan.Win32.Save.a K7AntiVirus: Trojan ( 005690671 ) Alibaba: Trojan:Win32/Azorult.ad698775 K7GW: Trojan ( 005690671 ) CrowdStrike: win/malicious_confidence_90% (W) Cyren: W32/Kryptik.EWJ.gen!Eldorado Symantec: ML.Attribute.HighConfidence ESET-NOD32: a variant of Win32/Kryptik.HMID APEX: Malicious Paloalto: generic.ml ClamAV: Win.Malware.Generic-9890416-0 Kaspersky: HEUR:Trojan.Win32.DelShad.gen BitDefender: Gen:Heur.Mint.Titirez.Iq0@a9d0C9aG NANO-Antivirus: Trojan.Win32.DelShad.jahqkr SUPERAntiSpyware: Trojan.Agent/Gen-Kryptik Avast: Win32:DropperX-gen [Drp] Ad-Aware: Gen:Heur.Mint.Titirez.Iq0@a9d0C9aG TACHYON: Ransom/W32.LockBit.567296 Sophos: ML/PE-A Comodo: Malware@#98zlr5gd3klu DrWeb: Trojan.Encoder.34323 Zillya: Trojan.Kryptik.Win32.3496259 TrendMicro: Ransom.Win32.LOCKBIT.ENO McAfee-GW-Edition: BehavesLike.Win32.Lockbit.hc FireEye: Generic.mg.e01007b2ff8fcb64 Emsisoft: Gen:Heur.Mint.Titirez.Iq0@a9d0C9aG (B) Ikarus: Trojan.Win32.Azorult GData: Win32.Trojan.BSE.13K4JBF Jiangmin: Trojan.Stop.auq Webroot: W32.Malware.Gen Avira: TR/Crypt.Agent.whamq Antiy-AVL: Trojan/Generic.ASMalwS.349162D Kingsoft: Win32.Troj.Undef.(kcloud) Gridinsoft: Trojan.Win32.Kryptik.oa Arcabit: Trojan.Mint.Titirez.EEBF19 Microsoft: Trojan:Win32/Azorult.RF!MTB Cynet: Malicious (score: 100) AhnLab-V3: CoinMiner/Win.Glupteba.R440044 Acronis: suspicious McAfee: Packed-GDT!E01007B2FF8F MAX: malware (ai score=84) VBA32: BScope.Backdoor.Mokes Cylance: Unsafe TrendMicro-HouseCall: Ransom.Win32.LOCKBIT.ENO Rising: Trojan.Kryptik!1.D91D (CLASSIC) Yandex: Trojan.DelShad!mDHWPvPiqrc SentinelOne: Static AI - Malicious PE Fortinet: W32/GenKryptik.FKHU!tr BitDefenderTheta: Gen:NN.ZexaF.34218.Iq0@a8d0C9aG AVG: Win32:DropperX-gen [Drp] Panda: Trj/Genetic.gen MaxSecure: Trojan.Malware.74279478.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2020-Sep-07 20:37:49 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x70200 |
SizeOfInitializedData | 0x1d3ae00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001D6E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x72000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1da8000 |
SizeOfHeaders | 0x400 |
Checksum | 0x8c7f6 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
SetLocalTime
InterlockedIncrement ReadConsoleA InterlockedDecrement GetCurrentProcess GetSystemWindowsDirectoryW SetEnvironmentVariableW GetEnvironmentStringsW GetUserDefaultLCID AddConsoleAliasW SetVolumeMountPointW EnumCalendarInfoExW WriteFile GetUserDefaultLangID GetEnvironmentStrings WriteConsoleOutputA LeaveCriticalSection lstrcpynW FindNextVolumeW VerifyVersionInfoA HeapQueryInformation GetModuleFileNameW GetACP GetConsoleOutputCP GetProcAddress GetComputerNameExW VerLanguageNameA CreateTimerQueueTimer HeapUnlock LocalAlloc GetDefaultCommConfigA GetModuleHandleA QueueUserWorkItem GetConsoleTitleW PeekConsoleInputA GetCPInfoExA ReadConsoleInputW GlobalReAlloc LCMapStringW PulseEvent GetCommandLineW UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW Sleep ExitProcess GetLastError GetStdHandle GetModuleFileNameA TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError GetCurrentThreadId EnterCriticalSection TerminateProcess IsDebuggerPresent HeapSize SetHandleCount GetFileType GetStartupInfoA DeleteCriticalSection SetFilePointer FreeEnvironmentStringsW HeapCreate VirtualFree HeapFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime LoadLibraryA InitializeCriticalSectionAndSpinCount GetCPInfo GetOEMCP IsValidCodePage MultiByteToWideChar RtlUnwind HeapAlloc HeapReAlloc VirtualAlloc WideCharToMultiByte SetStdHandle GetLocaleInfoA GetStringTypeA GetStringTypeW LCMapStringA GetConsoleCP GetConsoleMode FlushFileBuffers CloseHandle WriteConsoleA WriteConsoleW CreateFileA |
---|---|
USER32.dll |
RealGetWindowClassW
|
GDI32.dll |
GetCharWidthFloatA
|
Teluyopabem wile cogeruroga gob weto bopado tuvoja |
Nizav wasebuweguxu kaxaka polaxamuwo taxoyud riximunu |
Duboyo lejo hujahig sohafote kudetuvog bajac |
Coyuvodi kevovipuyuviw |
Fef jupabilav hak zefobebiregova boci sopapikibiyefo xowehujutiye sipuyof vizelazafaxuvac |
Mawezusaxised sumazusi mihi pumezezeb pacubetuyonoyen |
Xub hukiyutawoxine copidudidos soyatilixolehuy doco cesetigijobuduk juxiwudukuzos fihutabucizuhed pozakoliyofe |
Widihaxotegafu hawu riwusizo tinisagayusag |
Sis gabajuwoho novoyukiwapepab |
Cawo kipifucezi gapu vihovixeyalesej hasamadajoko hudixogi badeyudevaseya keto xatufaxuwenih xokaham |
Pihopofuwezume tadamapicolid luzikufujeyi wubowe takiridutuza famecihoyol hatelifobuza |
Feti kuzemidejunari fovapexazij nibi moreb dixagaw zowu |
Xanuludi weki |
Lewehe makihexiyowud nulakuwet mitifudomuzuhan tafiju tohe rocufiduzuwovet |
Tiwucike jirecuvacirin kug hocafifohigesoz mihecuhumimuya |
Sudukahiv nixovihayekazup lim tosopupami lobap yoxiguwupumej cugakap mevivodugav nusanafixoy wikifahageva |
Hivudal lazawubitoluxed pinujerutu kuyig busuxojedul gunezejiwigajo cudilamokixilu |
Kejocus sijizojagejijun lezoxa |
Tah sewodanifovojiv nit kapahari wejanalaporafo rujawowucebaye yowuci govo wopovayuto |
Sohusidipo pepikakowiwa |
Doveror tebawiroli xofihocu falew kofohikewuweco fogeyewog wiyotesexih feyegike |
Sepefe mamebikalarifo cawejociyiyo xuxizugo kanevupul jadepado tavofic jecoyop vumidafo |
Vabayasised taserururodukef riresijeruzameh |
Cuhe sazo jabupafulaya bel yasolosolugize voyufiherovixeb |
Vuradeleye gij menuti yehari fecaxagefucarir vay decocix |
Dujulesiye dadaveyiyehit geciwigun biwudusowoku tosizadekuhar lovihic wijalu najexamamug siyarije kefevi |
Fuhizofo vukemasok |
Biladuy tahalalofogun gocuzidategeheg yacivit mafuyul bahotan witixi bodicovo ximuc |
Yijeveyeliju dubibozag saragekeconucin zuxosuwamar lusex mejexebiyuh gaco soyavedilapuk pebusuhovila bimewaduki |
Mecebagucu pamexilide pahosezogif |
Bavopifivid foxehi zunulejil |
Memikatelacaf wiyijuzovay zelanatojudub |
Netuposiwoveyaf navasigef porebowubuce |
Hiwal divimajehehoxot haxif |
Vivat |
Focutilur neyetoyamenapis raruv kigileba sahepegubux jifules wexidukige leju rih |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Aug-25 15:28:13 |
Version | 0.0 |
SizeofData | 84 |
AddressOfRawData | 0x73750 |
PointerToRawData | 0x71d50 |
Referenced File | C:\dacufofupip2\rimemofozetozi\file-gedigitasopuv\36 yo.pdb |
StartAddressOfRawData | 0x4737cc |
---|---|
EndAddressOfRawData | 0x4747bc |
AddressOfIndex | 0x2191a8c |
AddressOfCallbacks | 0x4721bc |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |