Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
English - Australia
|
Info | Matching compiler(s): | Borland Delphi 3 -> Portions Copyright (c) 1983,97 Borland (h) |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Suspicious | VirusTotal score: 2/65 (Scanned on 2017-09-06 02:01:27) |
Rising:
Malware.Undefined!8.C (cloud:yCFTgSVGyHT)
Antiy-AVL: Trojan/Win32.TGeneric |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x2d000 |
SizeOfInitializedData | 0x9c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0002DDDC (Section: CODE) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 1.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3c000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess CreateThread WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
---|---|
user32.dll |
GetKeyboardType
LoadStringA MessageBoxA |
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
oleaut32.dll |
VariantChangeTypeEx
VariantCopyInd VariantClear SysStringLen SysFreeString SysReAllocStringLen SysAllocStringLen |
kernel32.dll (#2) |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess CreateThread WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
kernel32.dll (#3) |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess CreateThread WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
gdi32.dll |
TextOutA
SetTextColor SetTextAlign SetPixel SetBkMode SetBkColor SelectObject Rectangle Polyline Polygon MoveToEx LineTo GetTextMetricsA GetTextExtentPoint32A GetStockObject GetPixel GetObjectA GetDeviceCaps EnumFontFamiliesExA Ellipse DeleteObject DeleteDC CreateSolidBrush CreatePen CreateFontIndirectA CreateFontA CreateCompatibleDC CreateCompatibleBitmap CreateBitmap BitBlt |
user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA |
ole32.dll |
CoUninitialize
CoInitialize |
oleaut32.dll (#2) |
VariantChangeTypeEx
VariantCopyInd VariantClear SysStringLen SysFreeString SysReAllocStringLen SysAllocStringLen |
shell32.dll |
ShellExecuteA
DragQueryFileA DragFinish DragAcceptFiles |
comctl32.dll |
InitCommonControls
|
comdlg32.dll |
ChooseColorA
GetSaveFileNameA GetOpenFileNameA |
Saturday |
Cannot assign a %s to a %s |
Cannot create file %s |
Cannot open file %s |
Stream read error |
Stream write error |
List index out of bounds (%d) |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
Operation not allowed on sorted string list |
String list does not allow duplicates |
Invalid property value |
OLE error %.8x |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
Error creating variant array |
Variant is not an array |
Variant array index out of bounds |
External exception %x |
Assertion failed |
Interface not supported |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
Win32 Error. Code: %d. |
%s |
A Win32 API function failed |
Jan |
Feb |
Mar |
Apr |
May |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Invalid variant type conversion |
Invalid variant operation |
Variant method calls not supported |
Read |
Write |
'%s' is not a valid integer value |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
StartAddressOfRawData | 0x432000 |
---|---|
EndAddressOfRawData | 0x43200c |
AddressOfIndex | 0x42f4d4 |
AddressOfCallbacks | 0x433010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |