Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Apr-27 07:38:57 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
C:\Users\Test\Documents\Visual Studio 2008\Projects\oosososo\x64\Debug\oosososo.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 38/71 (Scanned on 2024-05-04 02:58:30) |
ALYac:
Trojan.Generic.35791427
AVG: Win64:DropperX-gen [Drp] Antiy-AVL: Trojan/Win64.ShellCode Arcabit: Trojan.Generic.D2222243 Avast: Win64:DropperX-gen [Drp] Avira: TR/Redcap.isogt BitDefender: Trojan.Generic.35791427 Bkav: W64.AIDetectMalware Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Trojan.Generic.35791427 (B) F-Secure: Trojan.TR/Redcap.isogt FireEye: Trojan.Generic.35791427 Fortinet: W32/PossibleThreat GData: Win64.Trojan.Agent.PJHLI6 Google: Detected K7AntiVirus: Riskware ( 00584baa1 ) K7GW: Riskware ( 00584baa1 ) Kaspersky: Trojan.Win64.Shellcode.jr Kingsoft: Win32.Troj.Unknown.a Lionic: Trojan.Win32.Shellcode.4!c MAX: malware (ai score=88) Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.243303889.susgen McAfee: Artemis!33B6D21BF906 MicroWorld-eScan: Trojan.Generic.35791427 Microsoft: Trojan:Win32/Wacatac.A!ml Paloalto: generic.ml Rising: Trojan.Shellcode!8.2FDD (CLOUD) Sangfor: Trojan.Win32.Silverfox.ulgyzg Skyhigh: Artemis Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrendMicro-HouseCall: TROJ_GEN.R002H07E124 VIPRE: Trojan.Generic.35791427 Varist: W64/ABRisk.WRQQ-3055 ZoneAlarm: Trojan.Win64.Shellcode.jr |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2024-Apr-27 07:38:57 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x22e00 |
SizeOfInitializedData | 0xf400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000002A28 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x36000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LocalReAlloc
LocalSize LocalAlloc VirtualProtect GetTimeZoneInformation CompareStringW CompareStringA HeapReAlloc LCMapStringW LCMapStringA GetStringTypeW GetStringTypeA IsValidLocale EnumSystemLocalesA GetUserDefaultLCID GetTimeFormatA GetDateFormatA GetLocaleInfoA GetLocaleInfoW HeapSize IsValidCodePage GetOEMCP GetACP GetCPInfo VirtualQuery GetProcessHeap GetSystemTimeAsFileTime GetCurrentProcessId GetTickCount QueryPerformanceCounter HeapDestroy HeapCreate HeapSetInformation GetStartupInfoA GetFileType GetModuleHandleW Sleep GetProcAddress ExitProcess GetStartupInfoW RaiseException IsDebuggerPresent DebugBreak WideCharToMultiByte MultiByteToWideChar lstrlenA LoadLibraryA EncodePointer DecodePointer TlsAlloc FlsGetValue FlsSetValue FlsFree SetLastError GetCurrentThreadId GetLastError GetCurrentThread FlsAlloc WriteFile GetStdHandle GetModuleFileNameA DeleteCriticalSection LeaveCriticalSection FatalAppExitA EnterCriticalSection TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext RtlUnwindEx SetConsoleCtrlHandler FreeLibrary InitializeCriticalSectionAndSpinCount HeapAlloc RtlPcToFileHeader HeapFree GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW SetHandleCount SetEnvironmentVariableA |
---|---|
USER32.dll |
DispatchMessageW
TranslateMessage TranslateAcceleratorW GetMessageW LoadAcceleratorsW LoadStringW MessageBoxA RegisterClassExW EndDialog DialogBoxParamW DestroyWindow DefWindowProcW BeginPaint EndPaint PostQuitMessage CreateWindowExW ShowWindow UpdateWindow LoadIconW LoadCursorW |
WINHTTP.dll |
WinHttpOpen
WinHttpCloseHandle WinHttpSendRequest WinHttpOpenRequest WinHttpConnect WinHttpReadData WinHttpQueryDataAvailable WinHttpReceiveResponse |
oosososo |
OOSOSOSO |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Apr-27 07:38:56 |
Version | 0.0 |
SizeofData | 108 |
AddressOfRawData | 0x28e28 |
PointerToRawData | 0x28028 |
Referenced File | C:\Users\Test\Documents\Visual Studio 2008\Projects\oosososo\x64\Debug\oosososo.pdb |
XOR Key | 0x43c1531e |
---|---|
Unmarked objects | 0 |
C objects (VS2008 build 21022) | 74 |
ASM objects (VS2008 build 21022) | 9 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 7 |
Total imports | 113 |
C++ objects (VS2008 build 21022) | 39 |
Linker (VS2008 build 21022) | 1 |
151 | 1 |
Resource objects (VS2008 build 21022) | 1 |