| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2017-Apr-18 12:20:48 |
| Detected languages |
English - United States
English - Zimbabwe |
| CompanyName | UG North |
| FileDescription | Windows DSE overrider |
| FileVersion | 1.2.0.1704 |
| InternalName | dsefix.exe |
| LegalCopyright | Copyright (C) 2014 - 2017 EP_X0FF, MP_ART and N.Rin, based on WinNT/Turla exploit |
| OriginalFilename | dsefix.exe |
| ProductName | DSEFix |
| ProductVersion | 1.2.0.1704 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Suspicious | The PE is possibly packed. | Unusual section name found: shrd |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/60 (Scanned on 2017-05-26 13:04:17) | Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9820 |
| MD5 | ca127ebd958b98c55ee4ef277a1d3547 🔍 |
|---|---|
| SHA1 | 7d5567d519f69165647871fde9e4d13bb0cb9234 🔍 |
| SHA256 | ffebc28e042e12cebde68ad02462046c9d63c897f4330c5df6599832021cba19 🔍 |
| SHA3 | e537265fd9ecc1c109ffc2fd3bcd1913ad0670a21338c9a6597677d88b71994f 🔍 |
| SSDeep | 1536:Ke8ul2U/41jC3d38uezp0Dw+49tKMgVxAlIi9:5/41jC3d38uezp0U9vgLA/ 🔍 |
| Imports Hash | b9c03d01e3110584eae1adb0a0a2095e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2017-Apr-18 12:20:48 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3600 |
| SizeOfInitializedData | 0x14600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000002C30 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x22d69 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 7be7927c9096fce419154ef1891fe0b3 🔍 |
|---|---|
| SHA1 | 6e3cf548783a0c7c3c2f59ae7738efbaf0b639e8 🔍 |
| SHA256 | b923167a9f06a826f4afbcddc3fe9cdd0f0679d5f88e35ab307da396ab627ae6 🔍 |
| SHA3 | 1ce49f05842d00e9b35b7e2d5cf80c184a46f68991e05e41aaf4967acf964ddd 🔍 |
| VirtualSize | 0x3530 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x3600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.26383 |
| MD5 | 98a252d1b35fc29dfb106943fbdcce5b 🔍 |
|---|---|
| SHA1 | 281e18c7a1f334954783505f0aa749c91cd983ba 🔍 |
| SHA256 | 0a292ccbfbcb22bfe8de89b608ded692c0e8916be7b53427fc8637b5313c066c 🔍 |
| SHA3 | 82b084be8b4ca8b92bbff60ab37a62c56476cc35915f483851b58bace7150364 🔍 |
| VirtualSize | 0x2248 |
| VirtualAddress | 0x5000 |
| SizeOfRawData | 0x2400 |
| PointerToRawData | 0x3a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.845 |
| MD5 | 6dfa911b7bb494a78c97c992f03fd3cd 🔍 |
|---|---|
| SHA1 | 48afafbb4fdb46d20bcff849f2cb816bbb8a6038 🔍 |
| SHA256 | 4ae6d635a75d062f1c68f9e13e9162b67ab2379bf2953b1647a7fd4a12c2a249 🔍 |
| SHA3 | f50650b07d2fe0a9dc9f93790a035a45f8022daa13e65f5411eb6ca27cf641fd 🔍 |
| VirtualSize | 0x113d4 |
| VirtualAddress | 0x8000 |
| SizeOfRawData | 0x10e00 |
| PointerToRawData | 0x5e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.21144 |
| MD5 | 96b7dc96bb52c23a4a207240437173c5 🔍 |
|---|---|
| SHA1 | c82837e1e05dee2adfce5947c0d35a34ea64d353 🔍 |
| SHA256 | 8c866036996427b86d087aa4ddfc950fd226fedd0376705d7585e01c25dbcd48 🔍 |
| SHA3 | dca48de68480f29add276cddc8ab06e3ec79b8849e36bf3ad0f40228980c4461 🔍 |
| VirtualSize | 0x2a0 |
| VirtualAddress | 0x1a000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x16c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.97307 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x4 |
| VirtualAddress | 0x1b000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x17000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 23e2881e604f4fb8965937a1436654ad 🔍 |
|---|---|
| SHA1 | d897c78ef1ea3599ded3714b71ce841b1b5dc767 🔍 |
| SHA256 | 9463715f00c0994abbc4de0c5767c2e08d343460be047bb02fba9883a475ac1f 🔍 |
| SHA3 | 1e601d689c73839a530bf58952be565b8f7b20c0f8ea762930a50fa6eeac19f0 🔍 |
| VirtualSize | 0x570 |
| VirtualAddress | 0x1c000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x17200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.95001 |
| MD5 | 06ca74c20a48f848770aa5a4bbcea22c 🔍 |
|---|---|
| SHA1 | 75c27e8a14cc90b9058c69ed1d26957053275506 🔍 |
| SHA256 | cb41fdfa3b8958d6710f7b9461569a9abbd181a6f7b62130558993c164e2ecee 🔍 |
| SHA3 | b3c2f2f1935b8cf26ab3e43c1106e2d574d05817afb09acfb930f36e5f5f81e4 🔍 |
| VirtualSize | 0x20 |
| VirtualAddress | 0x1d000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x17800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 0.357698 |
| KERNEL32.dll |
CloseHandle
GetCommandLineW GetStdHandle SetConsoleMode DeviceIoControl LoadLibraryExA GetSystemDirectoryW GetConsoleMode GetSystemDirectoryA GetLastError ExitProcess GetModuleHandleW FreeLibrary SetConsoleTitleW GetFileAttributesW MoveFileExW IsProcessorFeaturePresent TerminateProcess Sleep CreateFileW SetLastError GetProcessHeap WriteConsoleW HeapAlloc HeapFree WriteFile GetProcAddress GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter |
|---|---|
| USER32.dll |
wsprintfW
|
| ADVAPI32.dll |
CreateServiceW
RegCloseKey RegOpenKeyExW CloseServiceHandle OpenSCManagerW DeleteService ControlService StartServiceW OpenServiceW |
| ntdll.dll |
NtQueryDirectoryObject
RtlFreeHeap NtOpenDirectoryObject NtQuerySystemInformation RtlAllocateHeap RtlGetVersion NtAllocateVirtualMemory NtDeleteFile RtlInitUnicodeString NtFreeVirtualMemory NtClose RtlUnwindEx |
| Type |
RT_VERSION
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x348 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.51268 |
| MD5 | 3c4f537726654fd5dd451e0999e58827 🔍 |
| SHA1 | 5d18aa359d1c6e6b0a7a55f351beb92db880c6f1 🔍 |
| SHA256 | 67aab5ffc63b34cbd917e8dd848dfb5d2cfc934013b9d31d77b61ea2ec85d987 🔍 |
| SHA3 | 9fbb518433beaf05de0a4bb2aebe916add7b98f2555e33c1546c6a6468001afa 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.2.0.1704 |
| ProductVersion | 1.2.0.1704 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
|
| FileType |
VFT_APP
|
| Language | English - Zimbabwe |
| CompanyName | UG North |
| FileDescription | Windows DSE overrider |
| FileVersion (#2) | 1.2.0.1704 |
| InternalName | dsefix.exe |
| LegalCopyright | Copyright (C) 2014 - 2017 EP_X0FF, MP_ART and N.Rin, based on WinNT/Turla exploit |
| OriginalFilename | dsefix.exe |
| ProductName | DSEFix |
| ProductVersion (#2) | 1.2.0.1704 |
| Resource LangID | UNKNOWN |
|---|
| Size | 0x94 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140008000 |
| GuardCFCheckFunctionPointer | 5368730104 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x2b904537 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2015 UPD3 build 24123) | 11 |
| ASM objects (VS2015 UPD3 build 24123) | 4 |
| Imports (65501) | 9 |
| Total imports | 67 |
| 264 (VS2015 UPD3.1 build 24215) | 21 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| 151 | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |
No comments yet.