| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2009-Dec-05 22:50:52 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is an NSIS installer | Unusual section name found: .ndata |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
12393 bytes of data starting at offset 0x8400.
The overlay data has an entropy of 7.98388 and is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 42/71 (Scanned on 2024-01-31 21:09:54) |
ALYac:
Trojan.Generic.31510985
APEX: Malicious AVG: NSIS:MalwareX-gen [Trj] Alibaba: TrojanDropper:Win32/MalwareX.77638d55 Antiy-AVL: Trojan/Win32.Wacatac.b Arcabit: Trojan.Generic.D1E0D1C9 Avast: NSIS:MalwareX-gen [Trj] Avira: HEUR/AGEN.1345540 BitDefender: Trojan.Generic.31510985 Bkav: W32.AIDetectMalware ClamAV: Win.Trojan.Generic-9855872-0 CrowdStrike: win/malicious_confidence_60% (W) Cybereason: malicious.ee138f Cylance: unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: NSIS/Agent.NCY Elastic: malicious (high confidence) Emsisoft: Trojan.Generic.31510985 (B) F-Secure: Heuristic.HEUR/AGEN.1345540 FireEye: Trojan.Generic.31510985 Fortinet: NSIS/Agent.NCY!tr GData: Trojan.Generic.31510985 Google: Detected Kaspersky: HEUR:Trojan.Win32.Generic Lionic: Trojan.Win32.Generic.4!c MAX: malware (ai score=87) McAfee: Artemis!93BBDED93E97 MicroWorld-eScan: Trojan.Generic.31510985 Microsoft: Trojan:Win32/Wacatac.B!ml Sangfor: Trojan.NSIS.Agent.Ve30 SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Dropper.ph Sophos: Mal/Generic-S Tencent: Win32.Trojan.Generic.Pgil Trapmine: malicious.high.ml.score TrendMicro: TROJ_GEN.R067C0PFU22 TrendMicro-HouseCall: TROJ_GEN.R067C0PFU22 VIPRE: Trojan.Generic.31510985 Varist: W32/NSIS_Agent.H.gen!Eldorado VirIT: Trojan.Win32.NSISDrp.BQJ ZoneAlarm: HEUR:Trojan.Win32.Generic |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2009-Dec-05 22:50:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x5e00 |
| SizeOfInitializedData | 0x28400 |
| SizeOfUninitializedData | 0x400 |
| AddressOfEntryPoint | 0x000030FA (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CompareFileTime
SearchPathA GetShortPathNameA GetFullPathNameA MoveFileA SetCurrentDirectoryA GetFileAttributesA GetLastError CreateDirectoryA SetFileAttributesA Sleep GetTickCount GetFileSize GetModuleFileNameA GetCurrentProcess CopyFileA ExitProcess GetWindowsDirectoryA SetFileTime GetCommandLineA SetErrorMode LoadLibraryA lstrcpynA GetDiskFreeSpaceA GlobalUnlock GlobalLock CreateThread CreateProcessA RemoveDirectoryA CreateFileA GetTempFileNameA lstrlenA lstrcatA GetSystemDirectoryA GetVersion CloseHandle lstrcmpiA lstrcmpA ExpandEnvironmentStringsA GlobalFree GlobalAlloc WaitForSingleObject GetExitCodeProcess GetModuleHandleA LoadLibraryExA GetProcAddress FreeLibrary MultiByteToWideChar WritePrivateProfileStringA GetPrivateProfileStringA WriteFile ReadFile MulDiv SetFilePointer FindClose FindNextFileA FindFirstFileA DeleteFileA GetTempPathA |
|---|---|
| USER32.dll |
EndDialog
ScreenToClient GetWindowRect EnableMenuItem GetSystemMenu SetClassLongA IsWindowEnabled SetWindowPos GetSysColor GetWindowLongA SetCursor LoadCursorA CheckDlgButton GetMessagePos LoadBitmapA CallWindowProcA IsWindowVisible CloseClipboard SetClipboardData EmptyClipboard RegisterClassA TrackPopupMenu AppendMenuA CreatePopupMenu GetSystemMetrics SetDlgItemTextA GetDlgItemTextA MessageBoxIndirectA CharPrevA DispatchMessageA PeekMessageA DestroyWindow CreateDialogParamA SetTimer SetWindowTextA PostQuitMessage SetForegroundWindow wsprintfA SendMessageTimeoutA FindWindowExA SystemParametersInfoA CreateWindowExA GetClassInfoA DialogBoxParamA CharNextA OpenClipboard ExitWindowsEx IsWindow GetDlgItem SetWindowLongA LoadImageA GetDC EnableWindow InvalidateRect SendMessageA DefWindowProcA BeginPaint GetClientRect FillRect DrawTextA EndPaint ShowWindow |
| GDI32.dll |
SetBkColor
GetDeviceCaps DeleteObject CreateBrushIndirect CreateFontIndirectA SetBkMode SetTextColor SelectObject |
| SHELL32.dll |
SHGetPathFromIDListA
SHBrowseForFolderA SHGetFileInfoA ShellExecuteA SHFileOperationA SHGetSpecialFolderLocation |
| ADVAPI32.dll |
RegQueryValueExA
RegSetValueExA RegEnumKeyA RegEnumValueA RegOpenKeyExA RegDeleteKeyA RegDeleteValueA RegCloseKey RegCreateKeyExA |
| COMCTL32.dll |
ImageList_AddMasked
ImageList_Destroy #17 ImageList_Create |
| ole32.dll |
CoTaskMemFree
OleInitialize OleUninitialize CoCreateInstance |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
| XOR Key | 0x69ead975 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2003 (.NET) build 4035) | 2 |
| Total imports | 155 |
| Imports (VS2003 (.NET) build 4035) | 17 |
| 48 (9044) | 10 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.