| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2011-Apr-19 06:26:53 |
| Detected languages |
English - United Kingdom
English - United States |
| CompanyName | Simon Tatham |
| ProductName | PuTTY suite |
| FileDescription | SSH, Telnet and Rlogin client |
| InternalName | PuTTY |
| OriginalFilename | PuTTY |
| FileVersion | Release 0.61 |
| ProductVersion | Release 0.61 |
| LegalCopyright | Copyright © 1997-2011 Simon Tatham. |
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes |
| Suspicious | The PE is possibly packed. | Unusual section name found: lmtC |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 50/62 (Scanned on 2026-03-27 06:14:21) |
APEX:
Malicious
AhnLab-V3: Trojan/Win32.Patched.R275304 Alibaba: Trojan:Win32/Leivion.c8762659 Arcabit: Win32.Swrot.A Avira: TR/Crypt.XPACK.Gen BitDefender: Win32.Swrot.A Bkav: W32.AIDetectMalware CTX: exe.trojan.swrort ClamAV: Win.Trojan.MSF_Shellcode-1 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.Swrort.1 ESET-NOD32: Generik.ICWDZIK trojan Elastic: malicious (high confidence) Emsisoft: Win32.Swrot.A (B) F-Secure: Trojan.TR/Crypt.XPACK.Gen Fortinet: W32/Rozena.D!tr GData: Win32.Swrot.A Google: Detected Ikarus: Trojan.Win32.Swrort Jiangmin: Win32/PatchFile.ip K7AntiVirus: Trojan ( 004786151 ) K7GW: Trojan ( 004786151 ) Kaspersky: Trojan.Win32.Patched.qa Kingsoft: Win32.Infected.AutoInfector.a Lionic: Trojan.Win32.Swrort.4!c Malwarebytes: Malware.Heuristic.2108 MicroWorld-eScan: Win32.Swrot.A Microsoft: VirTool:Win32/CobaltStrike.A NANO-Antivirus: Virus.Win32.Gen-Crypt.ccnc Paloalto: generic.ml Panda: Generic Suspicious Rising: HackTool.Swrort!1.6477 (CLASSIC) Sangfor: Hacktool.Win32.Patched.Vzus SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Infected.gh Sophos: Mal/Swrort-D Symantec: ML.Attribute.HighConfidence Tencent: Win32.Trojan.Patched.Lcnw VIPRE: Win32.Swrot.A Varist: W32/Swrort.C VirIT: Win32.Swrot.A Xcitium: TrojWare.Win32.Rozena.A@4jwdqr Yandex: Win32.Swrort.Gen.2 ZoneAlarm: Mal/Swrort-D Zoner: Probably Heur.ExeHeaderL alibabacloud: Backdoor:Win/metasploit.shellcode huorong: HVM:Trojan/Swrort.gen!A |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2011-Apr-19 06:26:53 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x55000 |
| SizeOfInitializedData | 0x28000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0007D000 (Section: lmtC) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x55000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7e000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyA GetUserNameA CopySid GetLengthSid RegCreateKeyA RegSetValueExA RegDeleteKeyA RegEnumKeyA RegDeleteValueA RegCreateKeyExA |
|---|---|
| COMCTL32.dll |
#14
#15 #17 #13 |
| comdlg32.dll |
ChooseColorA
ChooseFontA GetOpenFileNameA GetSaveFileNameA |
| GDI32.dll |
CreateBitmap
IntersectClipRect ExcludeClipRect UpdateColors DeleteDC GetTextExtentPoint32A CreateCompatibleDC DeleteObject TextOutA SetBkColor SetTextColor Rectangle CreateSolidBrush GetStockObject SelectObject CreateFontIndirectA GetTextExtentExPointA SetMapMode GetDeviceCaps GetTextMetricsA CreateFontA RealizePalette SelectPalette CreatePalette ExtTextOutA GetCharacterPlacementW SetBkMode GetBkMode ExtTextOutW GetCharABCWidthsFloatA GetPixel SetTextAlign CreateCompatibleBitmap TranslateCharsetInfo GetObjectA LineTo MoveToEx CreatePen SetPixel Polyline GetCharWidthW GetCharWidth32W GetCharWidthA GetCharWidth32A SetPaletteEntries UnrealizeObject |
| IMM32.dll |
ImmReleaseContext
ImmGetCompositionStringW ImmSetCompositionFontA ImmGetContext ImmSetCompositionWindow |
| ole32.dll |
CoUninitialize
CoInitialize CoCreateInstance |
| SHELL32.dll |
ShellExecuteA
|
| USER32.dll |
SetForegroundWindow
CreateMenu GetSystemMenu GetDoubleClickTime GetForegroundWindow GetQueueStatus GetClipboardOwner FindWindowA MessageBoxIndirectA WinHelpA UpdateWindow DefWindowProcA InvalidateRect SetWindowPos EndPaint GetWindowTextA GetWindowTextLengthA GetClientRect BeginPaint SetWindowTextA PeekMessageA MsgWaitForMultipleObjects IsWindow CreateCaret ShowCaret HideCaret DestroyCaret TranslateMessage EnableMenuItem GetCursorPos TrackPopupMenu ScreenToClient GetKeyboardLayout SetKeyboardState ToAsciiEx SetScrollInfo GetMessageTime PostMessageA CheckMenuItem IsZoomed FlashWindow GetClipboardData RegisterClipboardFormatA OpenClipboard SetClipboardData CloseClipboard SetCaretPos KillTimer SetTimer GetKeyboardState SetClassLongA SetCursor ShowCursor CreatePopupMenu InsertMenuA DeleteMenu AppendMenuA IsIconic GetSystemMetrics GetCapture ReleaseCapture LoadIconA GetDesktopWindow MoveWindow DefDlgProcA LoadCursorA CreateDialogParamA GetMessageA GetWindowLongA IsDialogMessageA DispatchMessageA PostQuitMessage EnableWindow DialogBoxParamA EndDialog GetParent SetActiveWindow GetWindowPlacement SetWindowPlacement RegisterWindowMessageA DrawEdge SetCapture MessageBoxA SetFocus GetDlgItem GetDlgItemTextA SetDlgItemTextA CheckDlgButton IsDlgButtonChecked CheckRadioButton SetWindowLongA MessageBeep SendDlgItemMessageA GetDC ReleaseDC SendMessageA MapDialogRect GetCaretBlinkTime DestroyWindow RegisterClassA GetSysColor SystemParametersInfoA GetWindowRect CreateWindowExA ShowWindow EmptyClipboard |
| WINMM.dll |
PlaySoundA
|
| WINSPOOL.DRV |
OpenPrinterA
StartDocPrinterA StartPagePrinter EndDocPrinter ClosePrinter EnumPrintersA WritePrinter EndPagePrinter |
| KERNEL32.dll |
SetEnvironmentVariableA
CompareStringW CompareStringA HeapSize SetEndOfFile InterlockedExchange RtlUnwind SetFilePointer SetStdHandle GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter VirtualFree HeapCreate HeapDestroy GetFileType GetStdHandle SetHandleCount LCMapStringW LCMapStringA VirtualQuery GetSystemInfo VirtualAlloc VirtualProtect GetTimeZoneInformation FlushFileBuffers GetStringTypeW GetStringTypeA GetCommandLineA GetStartupInfoA GetSystemTimeAsFileTime DeleteFileA TerminateProcess ExitProcess HeapFree HeapReAlloc HeapAlloc GetDateFormatA GetTimeFormatA GetCurrentDirectoryA SetCurrentDirectoryA GetACP GetLocalTime GetEnvironmentVariableA SetCommBreak CreateFileA GetCommState SetCommState SetCommTimeouts ClearCommBreak CreatePipe SetHandleInformation GetCurrentThreadId OpenProcess LocalAlloc LocalFree GetWindowsDirectoryA FindFirstFileA FindNextFileA FindClose GetCurrentProcessId QueryPerformanceCounter GlobalMemoryStatus GetCurrentThread GetThreadTimes GetCurrentProcess GetProcessTimes GetSystemTime GetSystemTimeAdjustment GetSystemDirectoryA WriteFile CreateEventA ReadFile GetLastError WaitForSingleObject GetOverlappedResult SetEvent LoadLibraryA FreeLibrary CreateFileMappingA MapViewOfFile UnmapViewOfFile GetModuleFileNameA CreateProcessA CloseHandle Beep CreateThread WideCharToMultiByte GlobalAlloc GlobalLock GlobalUnlock GlobalFree IsDBCSLeadByteEx MultiByteToWideChar GetLocaleInfoA GetOEMCP GetCPInfo lstrcpynA GetModuleHandleA GetProcAddress GetVersionExA MulDiv GetTickCount |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.61.0.0 |
| ProductVersion | 0.61.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United Kingdom |
| CompanyName | Simon Tatham |
| ProductName | PuTTY suite |
| FileDescription | SSH, Telnet and Rlogin client |
| InternalName | PuTTY |
| OriginalFilename | PuTTY |
| FileVersion (#2) | Release 0.61 |
| ProductVersion (#2) | Release 0.61 |
| LegalCopyright | Copyright © 1997-2011 Simon Tatham. |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x471680 |
| SEHandlerTable | 0x46e710 |
| SEHandlerCount | 2 |
| XOR Key | 0x38f67e29 |
|---|---|
| Unmarked objects | 0 |
| 105 (2067) | 2 |
| C++ objects (VS2003 (.NET) build 3077) | 2 |
| ASM objects (VS2003 (.NET) build 3077) | 27 |
| Imports (2067) | 2 |
| Imports (9210) | 4 |
| Imports (2179) | 17 |
| Total imports | 301 |
| C objects (VS2003 (.NET) build 3077) | 188 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.