Architecture |
Subsystem |
Compilation Date | 2023-Oct-07 13:30:55 |
Detected languages |
English - United States
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C# v7.0 / Basic .NET .NET executable -> Microsoft |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
Suspicious | The PE is possibly a dropper. |
Resource 53248 is possibly compressed or encrypted.
Resources amount for 92.2678% of the executable. |
Malicious | VirusTotal score: 39/71 (Scanned on 2024-02-12 06:57:27) |
APEX: Malicious AVG: FileRepMalware [Trj] Arcabit: Trojan.Fugrafa.D49D81 Avast: FileRepMalware [Trj] Avira: HEUR/AGEN.1317245 BitDefender: Gen:Variant.Fugrafa.302465 BitDefenderTheta: Gen:NN.ZexaF.36744.@xW@aeMgzTdi Bkav: W32.AIDetectMalware CrowdStrike: win/malicious_confidence_90% (W) Cybereason: malicious.3e33fd Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Fugrafa.302465 (B) F-Secure: Heuristic.HEUR/AGEN.1317245 FireEye: GData: Gen:Variant.Fugrafa.302465 Jiangmin: Trojan.Shelma.kbc Kaspersky: UDS:Trojan.Win32.GenericML.xnet Kingsoft: Win32.Trojan.GenericML.xnet Lionic: Trojan.Win32.GenericML.4!c MAX: malware (ai score=81) Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.300983.susgen McAfee: Artemis!F6631D229BE2 MicroWorld-eScan: Gen:Variant.Fugrafa.302465 Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Generic@AI.100 (RDML:mbqcEC7KjdpWxFaXWAnLhw) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: Sophos: Mal/Generic-S (PUA) Symantec: ML.Attribute.HighConfidence VBA32: Win32.Trojan.Cryptor.Heur VIPRE: Gen:Variant.Fugrafa.302465 ZoneAlarm: UDS:Trojan.Win32.GenericML.xnet tehtris: Generic.Malware |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
Machine |
NumberofSections | 5 |
TimeDateStamp | 2023-Oct-07 13:30:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 14.0 |
SizeOfCode | 0x10000 |
SizeOfInitializedData | 0x58c600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001A1C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x11000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59f000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CopyFileA GetLastError LockResource Process32Next CloseHandle FreeConsole CreateToolhelp32Snapshot LoadResource GetProcAddress CreateProcessA WriteConsoleW SetEndOfFile HeapReAlloc HeapSize FindResourceA GetCurrentProcess Process32First SizeofResource GetSystemInfo GetModuleFileNameA ReadConsoleW ReadFile FlushFileBuffers CreateFileW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW TerminateProcess RtlUnwind SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW EncodePointer RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapFree GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx HeapAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetFileType GetStringTypeW CompareStringW LCMapStringW GetProcessHeap DecodePointer |
USER32.dll |
SystemParametersInfoA |
ADVAPI32.dll |
RegOpenKeyExA RegEnumValueA GetTokenInformation RegCloseKey |
SHELL32.dll |
NETAPI32.dll |
NetApiBufferFree |
Characteristics |
TimeDateStamp | 2023-Oct-07 13:30:55 |
Version | 0.0 |
SizeofData | 752 |
AddressOfRawData | 0x1634c |
PointerToRawData | 0x1574c |
Characteristics |
TimeDateStamp | 2023-Oct-07 13:30:55 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xc0 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x418040 |
SEHandlerTable | 0x41615c |
SEHandlerCount | 10 |
XOR Key | 0x1ace4767 |
Unmarked objects | 0 |
ASM objects (30795) | 10 |
C++ objects (30795) | 148 |
C objects (30795) | 20 |
C++ objects (VS 2015-2022 runtime 33030) | 38 |
C objects (VS 2015-2022 runtime 33030) | 18 |
ASM objects (VS 2015-2022 runtime 33030) | 21 |
Imports (30795) | 11 |
Total imports | 105 |
C objects (LTCG) (33135) | 1 |
Resource objects (33135) | 1 |
151 | 1 |
Linker (33135) | 1 |