Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jul-14 00:24:50 |
Detected languages |
English - United States
|
CompanyName | Sun Microsystems, Inc. |
FileDescription | vc_runtime |
FileVersion | 5.5.75.32 |
InternalName | vc_runtime |
LegalCopyright | Copyright © 2004 |
OriginalFilename | VC_RUNTIME.DLL |
ProductName | Java(TM) Platform SE 6 |
ProductVersion | 5.5.75.32 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | The program tries to mislead users about its origins. | The PE pretends to be from Sun Microsystems but is not signed! |
Malicious | VirusTotal score: 10/67 (Scanned on 2019-09-15 09:08:08) |
MicroWorld-eScan:
Trojan.GenericKD.32454726
FireEye: Generic.mg.f010b0b7681ede24 Kaspersky: UDS:DangerousObject.Multi.Generic BitDefender: Trojan.GenericKD.32454726 AegisLab: Trojan.Multi.Generic.4!c Ad-Aware: Trojan.GenericKD.32454726 Emsisoft: Trojan.GenericKD.32454726 (B) Microsoft: Trojan:Win32/Casdet!rfn ZoneAlarm: UDS:DangerousObject.Multi.Generic GData: Trojan.GenericKD.32454726 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Jul-14 00:24:50 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x25800 |
SizeOfInitializedData | 0x13e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001E08C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x27000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x3d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3ebb8 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LoadLibraryA
GetProcAddress SetErrorMode GetCurrentProcess GetTickCount WriteFile Sleep WideCharToMultiByte HeapReAlloc DecodePointer GetCommandLineA UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent EncodePointer TerminateProcess GetSystemTimeAsFileTime HeapCreate HeapDestroy TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement GetModuleHandleW SetLastError InterlockedDecrement LoadLibraryW GetCPInfo GetACP GetOEMCP IsValidCodePage RaiseException ExitProcess SetHandleCount GetStdHandle InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW DeleteCriticalSection GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter LeaveCriticalSection EnterCriticalSection SetFilePointer GetConsoleCP GetConsoleMode MultiByteToWideChar LCMapStringW GetStringTypeW HeapSize RtlUnwind IsProcessorFeaturePresent SetStdHandle WriteConsoleW FlushFileBuffers IsBadReadPtr VirtualFree HeapFree HeapAlloc FreeLibrary GetNativeSystemInfo ExpandEnvironmentStringsW CloseHandle CreateFileW GetModuleFileNameW ReadFile GetFileSize GetCurrentProcessId GetVersion GetCurrentThreadId GetLastError |
---|---|
SHLWAPI.dll |
PathRemoveFileSpecW
PathFindFileNameW |
SHELL32.dll |
#680
|
Ordinal | 1 |
---|---|
Address | 0xd690 |
Ordinal | 2 |
---|---|
Address | 0xd4c0 |
Ordinal | 3 |
---|---|
Address | 0xd060 |
Ordinal | 4 |
---|---|
Address | 0xd290 |
Ordinal | 5 |
---|---|
Address | 0xd7d0 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.5.75.32 |
ProductVersion | 5.5.75.32 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | UNKNOWN |
CompanyName | Sun Microsystems, Inc. |
FileDescription | vc_runtime |
FileVersion (#2) | 5.5.75.32 |
InternalName | vc_runtime |
LegalCopyright | Copyright © 2004 |
OriginalFilename | VC_RUNTIME.DLL |
ProductName | Java(TM) Platform SE 6 |
ProductVersion (#2) | 5.5.75.32 |
Resource LangID | UNKNOWN |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1002b038 |
SEHandlerTable | 0x10029690 |
SEHandlerCount | 13 |
XOR Key | 0x708668c9 |
---|---|
Unmarked objects | 0 |
Exports (VS2012 UPD3 build 60610) | 97 |
Resource objects (VS2012 UPD2 build 60315) | 110 |
ASM objects (VS2012 UPD2 build 60315) | 24 |
Resource objects (VS2010 SP1 build 40219) | 88 |
ASM objects (VS2010 SP1 build 40219) | 77 |
Total imports | 297 |
Exports (VS2008 build 21022) | 53 |
Imports (VS2008 SP1 build 30729) | 107 |
ASM objects (VS2008 SP1 build 30729) | 64 |