| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Jan-18 10:10:35 |
| Detected languages |
English - United States
|
| CompanyName | MICROSOFT |
| FileVersion | 2,1,3,0 |
| ProductName | DLLHOST |
| InternalName | DLL |
| ProductVersion | 5.3.2.0 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. |
Resource E2B430437C1E8650D5C6499E6FF4073D is possibly compressed or encrypted.
Resource F12123178B2C18D38244FADB201A4C56 is possibly compressed or encrypted. Resources amount for 98.0705% of the executable. |
| Malicious | VirusTotal score: 27/68 (Scanned on 2026-03-30 11:24:46) |
APEX:
Malicious
Antiy-AVL: Trojan[Downloader]/Win32.Betload Bkav: W32.AIDetectMalware CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_90% (W) Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Fortinet: W32/PossibleThreat Gridinsoft: Crack.Win32.AutoKMS.cc!s2 Kingsoft: malware.kb.a.998 Lionic: Trojan.BAT.Agent.tnKf Malwarebytes: Malware.AI.1173398321 MaxSecure: Trojan.Malware.8328611.susgen McAfeeD: Real Protect-LS!74EDA110E0E3 Paloalto: generic.ml Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Dropper.wc Sophos: Generic ML PUA (PUA) Trapmine: malicious.high.ml.score TrellixENS: Artemis!74EDA110E0E3 VBA32: BScope.Trojan.MulDrop Varist: W32/Trojan.ICI.gen!Eldorado Webroot: W32.Trojan.Gen Xcitium: Malware@#193s1civ49b7z Zoner: Trojan.Win32.61412 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2017-Jan-18 10:10:35 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xea00 |
| SizeOfInitializedData | 0x36da00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: .code) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x11000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x380000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MSVCRT.dll |
memset
strncmp memmove strncpy strstr _strnicmp _stricmp strlen strcmp memcpy sprintf fabs ceil malloc floor free fclose strcpy tolower |
|---|---|
| KERNEL32.dll |
GetModuleHandleA
HeapCreate HeapDestroy ExitProcess RemoveDirectoryA GetExitCodeProcess GetTempFileNameA GetCommandLineA GetNativeSystemInfo FindResourceA LoadResource SizeofResource GetShortPathNameA GetWindowsDirectoryA GetSystemDirectoryA HeapAlloc HeapFree Sleep LoadLibraryA GetProcAddress FreeLibrary GetCurrentThreadId GetCurrentProcessId CloseHandle InitializeCriticalSection GetModuleFileNameA GetEnvironmentVariableA SetEnvironmentVariableA CreateFileA ReadFile WriteFile SetFilePointer DeleteFileA GetFileSize HeapReAlloc GetCurrentProcess TerminateProcess SetUnhandledExceptionFilter EnterCriticalSection LeaveCriticalSection GetVersionExA SetLastError HeapSize TlsAlloc CreateDirectoryA GetTempPathA SetFileAttributesA GetCurrentDirectoryA SetCurrentDirectoryA DeleteCriticalSection MultiByteToWideChar WideCharToMultiByte |
| USER32.DLL |
CharUpperA
CharLowerA MessageBoxA SendMessageA PostMessageA GetWindowThreadProcessId IsWindowVisible GetWindowLongA GetForegroundWindow IsWindowEnabled EnableWindow EnumWindows SetWindowPos DestroyWindow GetDC GetWindowTextLengthA GetWindowTextA SetRect DrawTextA GetSystemMetrics ReleaseDC GetSysColor GetSysColorBrush CreateWindowExA CallWindowProcA SetWindowLongA SetFocus RedrawWindow RemovePropA DefWindowProcA SetPropA GetParent GetPropA GetWindow SetActiveWindow UnregisterClassA DestroyAcceleratorTable LoadIconA LoadCursorA RegisterClassA AdjustWindowRectEx ShowWindow CreateAcceleratorTableA PeekMessageA MsgWaitForMultipleObjects GetMessageA GetActiveWindow TranslateAcceleratorA TranslateMessage DispatchMessageA GetFocus GetClientRect FillRect EnumChildWindows DefFrameProcA GetWindowRect IsChild GetClassNameA GetKeyState DestroyIcon RegisterWindowMessageA |
| GDI32.DLL |
GetStockObject
SelectObject SetBkColor SetTextColor GetTextExtentPoint32A CreateSolidBrush DeleteObject GetObjectA CreateCompatibleDC GetDIBits DeleteDC GetObjectType CreateDIBSection BitBlt CreateBitmap SetPixel |
| COMCTL32.DLL |
InitCommonControlsEx
|
| OLE32.DLL |
CoInitialize
CoTaskMemFree RevokeDragDrop |
| SHELL32.DLL |
ShellExecuteExA
|
| WINMM.DLL |
timeBeginPeriod
|
| SHLWAPI.DLL |
PathQuoteSpacesA
PathAddBackslashA PathRemoveArgsA PathGetArgsA PathRenameExtensionA PathUnquoteSpacesA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.1.3.0 |
| ProductVersion | 5.3.2.0 |
| FileFlags |
VS_FF_DEBUG
VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
|
| FileOs |
VOS_DOS
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_OS232
VOS_OS232_PM32
VOS_WINCE
VOS__PM32
VOS__WINDOWS16
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MICROSOFT |
| FileVersion (#2) | 2,1,3,0 |
| ProductName | DLLHOST |
| InternalName | DLL |
| ProductVersion (#2) | 5.3.2.0 |
| Resource LangID | UNKNOWN |
|---|
No comments yet.