Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-Nov-06 08:09:12 |
Detected languages |
English - United States
German - Germany |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 44/68 (Scanned on 2017-11-14 21:03:30) |
MicroWorld-eScan:
Trojan.GenericKD.12541634
CAT-QuickHeal: Trojan.Agent McAfee: RDN/Generic Dropper Cylance: Unsafe Zillya: Dropper.Agent.Win32.280161 K7GW: Trojan ( 0051ae5a1 ) K7AntiVirus: Trojan ( 0051ae5a1 ) Arcabit: Trojan.Generic.DBF5EC2 Invincea: heuristic Symantec: Trojan.Gen.2 TrendMicro-HouseCall: TROJ_GEN.R011C0PK917 Avast: Win32:Malware-gen Kaspersky: Trojan.Win32.Agent.ikvy BitDefender: Trojan.GenericKD.12541634 Paloalto: generic.ml AegisLab: Troj.Generickd!c Tencent: Win32.Trojan.Agent.Ajvg Ad-Aware: Trojan.GenericKD.12541634 Emsisoft: Trojan.GenericKD.12541634 (B) Comodo: UnclassifiedMalware F-Secure: Trojan.GenericKD.12541634 DrWeb: Trojan.Siggen7.31529 VIPRE: Trojan.Win32.Generic!BT TrendMicro: TROJ_GEN.R011C0PK917 McAfee-GW-Edition: RDN/Generic Dropper Sophos: Mal/Generic-S Ikarus: Trojan-Dropper.Win32.Agent Webroot: W32.Trojan.Gen Avira: TR/Drop.Agent.ceuii Fortinet: W32/Agent.RUB!tr Antiy-AVL: Trojan/Win32.TSGeneric Endgame: malicious (high confidence) Microsoft: Trojan:Win32/Tiggre!rfn ViRobot: Trojan.Win32.S.Agent.183296.FT ZoneAlarm: Trojan.Win32.Agent.ikvy AhnLab-V3: Trojan/Win32.Injector.C2250605 ALYac: Trojan.GenericKD.12541634 AVware: Trojan.Win32.Generic!BT MAX: malware (ai score=100) ESET-NOD32: a variant of Win32/TrojanDropper.Agent.RUB GData: Trojan.GenericKD.12541634 AVG: Win32:Malware-gen Panda: Trj/GdSda.A CrowdStrike: malicious_confidence_100% (D) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2017-Nov-06 08:09:12 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xe200 |
SizeOfInitializedData | 0x1f200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000028D8 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x10000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x34000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
HeapFree
InitializeCriticalSectionEx HeapSize GetLastError HeapReAlloc RaiseException HeapAlloc DecodePointer HeapDestroy DeleteCriticalSection GetProcessHeap WideCharToMultiByte CreateMutexA GetConsoleWindow Sleep lstrcmpiW WriteConsoleW FlushFileBuffers SetFilePointerEx GetConsoleMode GetConsoleCP GetStringTypeW SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW CloseHandle EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW GetProcAddress UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead OutputDebugStringW EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW SetLastError RtlUnwind MultiByteToWideChar ExitProcess GetModuleHandleExW GetModuleFileNameA GetStdHandle WriteFile GetCommandLineA GetCommandLineW GetACP GetFileType CompareStringW LCMapStringW FindClose FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCPInfo CreateFileW |
---|---|
USER32.dll |
ShowWindow
MessageBoxW |
ole32.dll |
CoInitializeEx
CoUninitialize CoCreateInstance CLSIDFromProgID |
OLEAUT32.dll |
#8
#12 #9 #2 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Nov-06 08:09:12 |
Version | 0.0 |
SizeofData | 920 |
AddressOfRawData | 0x29ef8 |
PointerToRawData | 0x284f8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Nov-06 08:09:12 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x42e000 |
---|---|
EndAddressOfRawData | 0x42e008 |
AddressOfIndex | 0x42cd10 |
AddressOfCallbacks | 0x4101a4 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x42c00c |
SEHandlerTable | 0x429ed0 |
SEHandlerCount | 10 |
XOR Key | 0x5e21871f |
---|---|
Unmarked objects | 0 |
241 (40116) | 9 |
243 (40116) | 123 |
242 (40116) | 24 |
C++ objects (23013) | 2 |
ASM objects (VS2015 UPD3 build 24123) | 19 |
C++ objects (VS2015 UPD3 build 24123) | 39 |
C objects (VS2015 UPD3 build 24123) | 18 |
C objects (65501) | 3 |
Imports (65501) | 9 |
Total imports | 112 |
265 (VS2015 UPD3.1 build 24215) | 8 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
151 | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |