Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2007-Mar-17 10:50:38 |
Detected languages |
Korean - Korea
|
Comments | |
CompanyName | WebZen |
FileDescription | main |
FileVersion | 1, 2, 20, 0 |
InternalName | main |
LegalCopyright | Copyright ? 2002 |
LegalTrademarks | |
OriginalFilename | main.exe |
PrivateBuild | |
ProductName | WebZen mu main |
ProductVersion | 1, 0, 0, 1 |
SpecialBuild |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 3/73 (Scanned on 2024-07-04 00:28:02) |
Rising:
Trojan.Fuery!8.EAFB (RDMK:cmRtazqp/Txbx7H9SBvgd8+40csg)
VBA32: BScope.Trojan.KillFiles tehtris: Generic.Malware |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2007-Mar-17 10:50:38 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x302000 |
SizeOfInitializedData | 0x771b000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x002EBE15 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x303000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 6.1 |
ImageVersion | 0.0 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x7a1e000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
IMM32.dll |
ImmGetCompositionStringA
ImmGetCompositionWindow ImmSetCompositionWindow ImmGetOpenStatus ImmGetDefaultIMEWnd ImmGetConversionStatus ImmSetConversionStatus ImmGetContext ImmGetDescriptionA ImmGetIMEFileNameA ImmReleaseContext ImmSetOpenStatus |
---|---|
DSOUND.dll |
#1
#2 |
OPENGL32.dll |
glColor3f
glEnd glVertex3fv glTexCoord2f glBegin glColor3fv glGetIntegerv glGetString glAlphaFunc glFogf glFogfv glEnable glDisable glClearColor glTexImage2D glBindTexture glVertex3f glDepthMask glPolygonMode glFrontFace glStencilFunc glColorMask glVertex2f glDepthFunc glStencilOp glTexParameteri glTexEnvf glPixelStorei glDeleteTextures glIsTexture glColor4ub glLoadIdentity glMatrixMode glPopMatrix glClear glTranslatef glRotatef glPushMatrix wglDeleteContext wglMakeCurrent wglCreateContext glScalef glGenTextures glTexEnvi glReadPixels glGetFloatv glBlendFunc glViewport glFogi glFlush glColor4f |
GLU32.dll |
gluOrtho2D
gluPerspective |
WINMM.dll |
mmioAscend
mmioOpenA mmioClose timeGetTime mmioDescend mmioRead timeGetDevCaps timeBeginPeriod mmioWrite timeEndPeriod |
KERNEL32.dll |
CreateMutexA
TerminateThread CreateThread OpenMutexA EnterCriticalSection LeaveCriticalSection lstrcatA OpenEventA ReleaseMutex GetComputerNameA lstrcmpA ExitProcess VirtualAlloc VirtualFree VirtualProtect LoadLibraryExA GetTempFileNameA GetTempPathA HeapFree GetProcessHeap HeapAlloc GetFileInformationByHandle GetCurrentThreadId GetTickCount Sleep lstrlenA CloseHandle WriteFile SetFilePointer CreateFileA DeleteFileA ReadFile GetLocalTime GetSystemDirectoryA lstrcmpiA GetVersionExA QueryPerformanceCounter SetProcessAffinityMask SetThreadPriority SetPriorityClass GetProcessAffinityMask GetThreadPriority GetPriorityClass GetCurrentThread GetCurrentProcess QueryPerformanceFrequency DuplicateHandle FreeLibrary GetProcAddress LoadLibraryA GlobalMemoryStatus GlobalUnlock GlobalLock GetCommandLineA GetFileSize GetLastError GetPrivateProfileStringA GetCurrentDirectoryA CopyFileA SetFileAttributesA Process32Next TerminateProcess OpenProcess Process32First CreateToolhelp32Snapshot WinExec FindClose FindFirstFileA GetModuleFileNameA IsBadReadPtr WaitForSingleObject CreateEventA CreateProcessA WaitForMultipleObjects GetExitCodeProcess GetModuleHandleA ResetEvent ResumeThread SetEndOfFile DeleteCriticalSection InitializeCriticalSection SetEvent WideCharToMultiByte CreateFileMappingA UnmapViewOfFile MapViewOfFile FindNextFileA RemoveDirectoryA GetFileAttributesA CreateDirectoryA GetThreadContext lstrcpynA GetCurrentProcessId Module32First Module32Next SetUnhandledExceptionFilter IsValidLocale IsValidCodePage GetLocaleInfoA EnumSystemLocalesA GetUserDefaultLCID SetHandleCount GetFileType UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings LCMapStringW GetEnvironmentStringsW GetEnvironmentVariableA HeapDestroy HeapCreate IsBadWritePtr IsBadCodePtr GetStringTypeA GetStringTypeW CompareStringA CompareStringW SetEnvironmentVariableA SetConsoleCtrlHandler GetLocaleInfoW SetStdHandle CreatePipe GetStdHandle PeekNamedPipe FlushFileBuffers lstrcpyA InterlockedExchange RtlUnwind InterlockedDecrement InterlockedIncrement GetTimeZoneInformation GetSystemTime GetStartupInfoA GetVersion GetSystemTimeAsFileTime RaiseException TlsSetValue TlsAlloc TlsFree SetLastError TlsGetValue HeapReAlloc HeapSize GetCPInfo GetACP GetOEMCP FatalAppExitA MultiByteToWideChar LCMapStringA OutputDebugStringA |
USER32.dll |
SetWindowLongA
GetFocus UnregisterHotKey RegisterHotKey GetAsyncKeyState GetKeyboardLayout GetKeyboardLayoutNameA OpenClipboard SendMessageA wsprintfA GetWindowRect SetWindowPos CallNextHookEx UnhookWindowsHookEx SetWindowsHookExA GetDesktopWindow MessageBoxA CallWindowProcA GetWindowLongA GetCaretPos GetWindowTextA SetWindowTextA ShowWindow ReleaseDC GetDC CreateWindowExA CloseClipboard SetFocus IsWindowVisible GetScrollPos SetScrollPos SetTimer FindWindowA ShowCursor SystemParametersInfoA ReleaseCapture SetCapture DefWindowProcA PostQuitMessage EndPaint BeginPaint DestroyWindow RegisterClassA LoadCursorA LoadIconA SetForegroundWindow GetSystemMetrics AdjustWindowRect IsIconic DispatchMessageA TranslateMessage GetMessageA PeekMessageA PostMessageA GetClipboardData UpdateWindow EnumDisplaySettingsA SetCursorPos KillTimer SetRect OffsetRect PtInRect GetDoubleClickTime ScreenToClient GetCursorPos GetActiveWindow IntersectRect wvsprintfA ChangeDisplaySettingsA |
GDI32.dll |
SetBkColor
SetPixelFormat ChoosePixelFormat CreateFontA SetBkMode SwapBuffers SelectObject TextOutA DeleteObject DeleteDC CreateDIBSection CreateCompatibleDC BitBlt GetTextExtentPointA GetTextExtentPoint32A SetTextColor GetStockObject |
ADVAPI32.dll |
InitializeSecurityDescriptor
RegDeleteKeyA CryptGetHashParam CryptDeriveKey CryptDecrypt CryptImportKey CryptCreateHash CryptHashData CryptVerifySignatureA CryptDestroyHash CryptDestroyKey CryptReleaseContext SetSecurityDescriptorDacl RegDeleteValueA RegEnumValueA CryptAcquireContextA RegSetValueExA RegCreateKeyExA RegOpenKeyExA RegQueryValueExA GetUserNameA RegCloseKey |
SHELL32.dll |
ShellExecuteA
|
ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
WS2_32.dll |
gethostbyname
WSAAsyncSelect setsockopt socket shutdown recv WSASend WSAStartup WSACleanup send WSAGetLastError inet_addr htons connect closesocket |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
wzAudio.dll |
wzAudioStop
wzAudioPlay wzAudioGetStreamOffsetRange wzAudioDestroy wzAudioOption wzAudioCreate |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.2.20.0 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Korean - Korea |
Comments | |
CompanyName | WebZen |
FileDescription | main |
FileVersion (#2) | 1, 2, 20, 0 |
InternalName | main |
LegalCopyright | Copyright ? 2002 |
LegalTrademarks | |
OriginalFilename | main.exe |
PrivateBuild | |
ProductName | WebZen mu main |
ProductVersion (#2) | 1, 0, 0, 1 |
SpecialBuild |
Resource LangID | Korean - Korea |
---|
XOR Key | 0x6578ef78 |
---|---|
Unmarked objects | 0 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 2 |
12 (7291) | 4 |
14 (7299) | 42 |
C objects (VS98 SP6 build 8804) | 163 |
C++ objects (8047) | 3 |
C++ objects (VC++ 6.0 SP5 build 8804) | 10 |
C objects (VS98 build 8168) | 44 |
C++ objects (9178) | 1 |
Imports (9210) | 2 |
Total imports | 364 |
19 (8034) | 25 |
C++ objects (VS98 SP6 build 8804) | 191 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |