Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Oct-07 13:30:55 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C# v7.0 / Basic .NET .NET executable -> Microsoft |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. |
Resource 53248 is possibly compressed or encrypted.
Resources amount for 92.2678% of the executable. |
Malicious | VirusTotal score: 39/71 (Scanned on 2024-02-12 06:57:27) |
ALYac:
Gen:Variant.Fugrafa.302465
APEX: Malicious AVG: FileRepMalware [Trj] Arcabit: Trojan.Fugrafa.D49D81 Avast: FileRepMalware [Trj] Avira: HEUR/AGEN.1317245 BitDefender: Gen:Variant.Fugrafa.302465 BitDefenderTheta: Gen:NN.ZexaF.36744.@xW@aeMgzTdi Bkav: W32.AIDetectMalware CrowdStrike: win/malicious_confidence_90% (W) Cybereason: malicious.3e33fd Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Fugrafa.302465 (B) F-Secure: Heuristic.HEUR/AGEN.1317245 FireEye: Generic.mg.f6631d229be28f67 GData: Gen:Variant.Fugrafa.302465 Jiangmin: Trojan.Shelma.kbc Kaspersky: UDS:Trojan.Win32.GenericML.xnet Kingsoft: Win32.Trojan.GenericML.xnet Lionic: Trojan.Win32.GenericML.4!c MAX: malware (ai score=81) Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.300983.susgen McAfee: Artemis!F6631D229BE2 MicroWorld-eScan: Gen:Variant.Fugrafa.302465 Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Generic@AI.100 (RDML:mbqcEC7KjdpWxFaXWAnLhw) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Generic.tc Sophos: Mal/Generic-S (PUA) Symantec: ML.Attribute.HighConfidence VBA32: Win32.Trojan.Cryptor.Heur VIPRE: Gen:Variant.Fugrafa.302465 ZoneAlarm: UDS:Trojan.Win32.GenericML.xnet tehtris: Generic.Malware |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2023-Oct-07 13:30:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x10000 |
SizeOfInitializedData | 0x58c600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001A1C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x11000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59f000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
Sleep
CopyFileA GetLastError LockResource Process32Next CloseHandle FreeConsole CreateToolhelp32Snapshot LoadResource GetProcAddress CreateProcessA WriteConsoleW SetEndOfFile HeapReAlloc HeapSize FindResourceA GetCurrentProcess Process32First SizeofResource GetSystemInfo GetModuleFileNameA ReadConsoleW ReadFile FlushFileBuffers CreateFileW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW TerminateProcess RtlUnwind SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW EncodePointer RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapFree GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx HeapAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetFileType GetStringTypeW CompareStringW LCMapStringW GetProcessHeap DecodePointer |
---|---|
USER32.dll |
SendInput
SystemParametersInfoA |
ADVAPI32.dll |
OpenProcessToken
RegOpenKeyExA RegEnumValueA GetTokenInformation RegCloseKey |
SHELL32.dll |
ShellExecuteA
|
NETAPI32.dll |
NetGetDCName
NetApiBufferFree |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-07 13:30:55 |
Version | 0.0 |
SizeofData | 752 |
AddressOfRawData | 0x1634c |
PointerToRawData | 0x1574c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-07 13:30:55 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x418040 |
SEHandlerTable | 0x41615c |
SEHandlerCount | 10 |
XOR Key | 0x1ace4767 |
---|---|
Unmarked objects | 0 |
ASM objects (30795) | 10 |
C++ objects (30795) | 148 |
C objects (30795) | 20 |
C++ objects (VS 2015-2022 runtime 33030) | 38 |
C objects (VS 2015-2022 runtime 33030) | 18 |
ASM objects (VS 2015-2022 runtime 33030) | 21 |
Imports (30795) | 11 |
Total imports | 105 |
C objects (LTCG) (33135) | 1 |
Resource objects (33135) | 1 |
151 | 1 |
Linker (33135) | 1 |