| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Mar-21 08:53:38 |
| Detected languages |
English - United States
Korean - Korea |
| Debug artifacts |
d:\ClientTeam\20. Release\2. ê¸ë¡ë²\[12.03.22] MU_ENG_1.04.05\tmp\Global Release\main.pdb
|
| CompanyName | WebZen |
| FileDescription | main |
| FileVersion | 1, 4, 5, 0 |
| InternalName | main |
| LegalCopyright | Copyright â 2002 |
| OriginalFilename | main.exe |
| ProductName | WebZen mu main |
| ProductVersion | 1, 0, 0, 1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES Uses constants related to Blowfish Uses constants related to Twofish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .dlib
Section .dlib is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 11/71 (Scanned on 2026-04-17 05:13:15) |
APEX:
Malicious
CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe DeepInstinct: MALICIOUS Fortinet: Riskware/Artmoney Google: Detected Gridinsoft: Trojan.Win32.Gen.vb!n Ikarus: Trojan.Win32 McAfeeD: ti!51C311C50B8C Paloalto: generic.ml TrellixENS: Artemis!1C15A39B3877 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2012-Mar-21 08:53:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x920800 |
| SizeOfInitializedData | 0x15ce00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x009217F7 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x922000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9480000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa850a4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| IMM32.dll |
ImmGetContext
ImmSetCompositionWindow ImmGetCompositionWindow ImmGetOpenStatus ImmGetDefaultIMEWnd ImmGetIMEFileNameA ImmGetDescriptionA ImmSetOpenStatus ImmGetCompositionStringA ImmSetConversionStatus ImmGetConversionStatus ImmReleaseContext |
|---|---|
| DSOUND.dll |
#1
#2 |
| OPENGL32.dll |
glColor4f
glDisable glEnd glVertex2f glTexCoord2f glBegin glColor3f glTexImage2D glBindTexture glFlush glClear glPopMatrix glAlphaFunc glDepthFunc glTranslatef glRotatef glLoadIdentity glPushMatrix glMatrixMode wglDeleteContext wglMakeCurrent glGetString wglCreateContext glClearColor glVertex3f glNormal3f glVertex3fv glColor3fv glDeleteTextures glTexParameteri glGenTextures glTexEnvf glDepthMask glPolygonMode glFrontFace glStencilFunc glColorMask glStencilOp glScalef glColor4ub glEnable glGetFloatv glReadPixels glBlendFunc glViewport glFogfv glFogf glFogi glTexEnvi glGetIntegerv glColor3ub |
| GLU32.dll |
gluPerspective
gluOrtho2D |
| WINMM.dll |
timeKillEvent
timeSetEvent timeGetDevCaps timeBeginPeriod mmioWrite mmioOpenA mmioDescend mmioRead mmioAscend mmioClose timeGetTime timeEndPeriod |
| WS2_32.dll |
getservbyport
gethostbyaddr getservbyname htonl listen WSASetLastError connect gethostname setsockopt socket shutdown recv closesocket WSAStartup bind htons inet_addr __WSAFDIsSet select getpeername getsockname inet_ntoa ntohs ioctlsocket accept WSASend WSAAsyncSelect sendto WSAGetLastError send WSACleanup gethostbyname |
| VERSION.dll |
GetFileVersionInfoA
VerQueryValueA GetFileVersionInfoSizeA |
| wzAudio.dll |
wzAudioCreate
wzAudioOption wzAudioDestroy wzAudioGetStreamOffsetRange wzAudioPlay wzAudioStop |
| KERNEL32.dll |
InterlockedCompareExchange
RtlUnwind UnhandledExceptionFilter IsDebuggerPresent RaiseException GetTickCount IsBadReadPtr lstrlenA GlobalUnlock GlobalLock CreateFileA GetCommandLineA CloseHandle ExitProcess ReadFile GetFileSize GetLastError GetPrivateProfileStringA GetCurrentDirectoryA DeleteFileA CopyFileA SetFileAttributesA Process32Next TerminateProcess OpenProcess Process32First CreateToolhelp32Snapshot WinExec Sleep FindClose FindFirstFileA GetLocalTime GetCurrentThreadId SetFilePointer SystemTimeToFileTime LocalFileTimeToFileTime CreateDirectoryA GetFileAttributesA SetFileTime WriteFile MultiByteToWideChar WideCharToMultiByte QueryPerformanceCounter QueryPerformanceFrequency WritePrivateProfileStringA GetSystemDirectoryA lstrcmpiA GetVersionExA SetProcessAffinityMask SetThreadPriority SetPriorityClass GetProcessAffinityMask GetThreadPriority GetPriorityClass GetCurrentThread GetCurrentProcess FreeLibrary GetProcAddress LoadLibraryA GlobalMemoryStatus SetConsoleMode GetStdHandle AllocConsole FreeConsole SetConsoleTitleA GetConsoleTitleA SetLastError SetConsoleCursorPosition FillConsoleOutputAttribute FillConsoleOutputCharacterA GetConsoleScreenBufferInfo SetConsoleTextAttribute ReadConsoleOutputA GetCurrentProcessId SetUnhandledExceptionFilter GetExitCodeThread WaitForSingleObject CreateThread InitializeCriticalSection DeleteCriticalSection LeaveCriticalSection InterlockedExchange CompareStringA CompareStringW GetThreadContext MapViewOfFile UnmapViewOfFile CreateFileMappingA lstrcpynA Module32Next Module32First GetModuleFileNameA RemoveDirectoryA FindNextFileA GetFullPathNameA FileTimeToSystemTime FileTimeToLocalFileTime IsBadStringPtrA OpenFileMappingA IsBadWritePtr SetEvent SetEndOfFile GetModuleHandleA CreateMutexA ResumeThread ResetEvent GetExitCodeProcess WaitForMultipleObjects CreateProcessA CreateEventA OpenEventA OpenMutexA MoveFileExA lstrcatA TerminateThread ReleaseMutex GetComputerNameA lstrcmpA GetModuleFileNameW VirtualProtect VirtualQuery VirtualAlloc VirtualFree LoadLibraryExA GetTempFileNameA GetTempPathA HeapFree GetProcessHeap HeapAlloc GetFileInformationByHandle DuplicateHandle SetStdHandle CreatePipe PeekNamedPipe lstrcpyA GetFileAttributesW CreateDirectoryW DeleteFileW lstrlenW CreateFileW SetFileAttributesW GetFileSizeEx GetSystemTimeAsFileTime GetModuleHandleW GetTimeZoneInformation GetStartupInfoA MoveFileA ExitThread GetCPInfo LCMapStringA LCMapStringW TlsGetValue TlsAlloc TlsSetValue TlsFree HeapSize HeapCreate HeapDestroy FatalAppExitA HeapReAlloc GetACP GetOEMCP EnterCriticalSection InterlockedIncrement IsValidCodePage GetTimeFormatA GetDateFormatA GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA InterlockedDecrement IsValidLocale GetStringTypeA GetStringTypeW GetConsoleCP GetConsoleMode SetHandleCount GetFileType SetConsoleCtrlHandler InitializeCriticalSectionAndSpinCount FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW FlushFileBuffers GetLocaleInfoW WriteConsoleA GetConsoleOutputCP WriteConsoleW SetEnvironmentVariableA LocalFree CompareFileTime FileTimeToDosDateTime GetSystemTime FormatMessageA GetFullPathNameW GetCurrentDirectoryW GetTempPathW MoveFileW CopyFileW SetCurrentDirectoryW SetCurrentDirectoryA RemoveDirectoryW GetFileTime FindFirstFileW FindNextFileW |
| USER32.dll |
ChangeDisplaySettingsA
FindWindowA SystemParametersInfoA DefWindowProcA ReleaseCapture ReleaseDC ShowCursor KillTimer IntersectRect wsprintfA SetTimer SetScrollPos GetScrollPos SetCapture SetFocus PostMessageW CreateWindowExW ShowWindow GetDC PostQuitMessage SendMessageW SetWindowTextW GetWindowTextW GetWindowTextA GetCaretPos GetWindowLongW SendMessageA CallWindowProcW OpenClipboard GetClipboardData CloseClipboard SetWindowLongW DestroyWindow SetRect GetActiveWindow GetCursorPos ScreenToClient GetDoubleClickTime EndPaint BeginPaint CreateWindowExA RegisterClassA LoadCursorA LoadIconA SetForegroundWindow GetSystemMetrics AdjustWindowRect IsIconic DispatchMessageA TranslateMessage GetMessageA PeekMessageA UpdateWindow EnumDisplaySettingsA GetDesktopWindow SetWindowsHookExA UnhookWindowsHookEx CharUpperW CharUpperA CharLowerW CharLowerA GetWindowThreadProcessId GetClassNameA GetSystemMenu DrawMenuBar RemoveMenu EnumChildWindows SetWindowPos GetKeyboardLayoutNameA wvsprintfA GetAsyncKeyState PtInRect OffsetRect MessageBoxA PostMessageA SetCursorPos UnregisterHotKey RegisterHotKey GetWindowRect IsWindowVisible CallNextHookEx GetFocus GetKeyboardLayout |
| GDI32.dll |
CreateCompatibleDC
SelectObject DeleteObject CreateDIBSection DeleteDC SetTextColor SetBkColor SwapBuffers GetStockObject SetPixelFormat ChoosePixelFormat GetTextExtentPoint32W TextOutW CreateFontA |
| ADVAPI32.dll |
CryptGetUserKey
RegCloseKey RegSetValueExA RegCreateKeyExA RegQueryValueExA RegDeleteKeyA RegOpenKeyExA SetSecurityDescriptorDacl InitializeSecurityDescriptor RegDeleteValueA RegCreateKeyA CryptReleaseContext CryptDestroyKey CryptEncrypt CryptImportKey CryptAcquireContextA CryptGenKey CryptExportKey CryptGetProvParam CryptEnumProvidersA CryptAcquireContextW RegSetValueExW CryptGenRandom RegEnumValueA CryptDestroyHash CryptVerifySignatureA CryptHashData CryptCreateHash CryptDecrypt CryptDeriveKey CryptGetHashParam GetUserNameA |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
| dbghelp.dll |
SymCleanup
SymGetLineFromAddr64 SymFromAddr StackWalk64 SymInitialize SymSetOptions MiniDumpWriteDump |
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| WININET.dll |
InternetCloseHandle
FtpPutFileA FtpCreateDirectoryA InternetOpenUrlA InternetConnectA InternetOpenA InternetReadFile InternetOpenW InternetConnectW HttpQueryInfoW HttpSendRequestA HttpOpenRequestW InternetQueryDataAvailable FtpOpenFileW FtpFindFirstFileW |
| CRYPT32.dll |
CertNameToStrA
PFXExportCertStoreEx CertDeleteCertificateFromStore CertSaveStore CertAddCertificateContextToStore CertSetCertificateContextProperty CertAddEncodedCertificateToStore CertFindCertificateInStore CertEnumCertificatesInStore CertDuplicateCertificateContext CertDuplicateStore CryptEncodeObject CryptSignMessage CertOpenStore CryptDecryptMessage CertCloseStore CryptMsgOpenToDecode CryptMsgUpdate CryptMsgClose CryptMsgGetParam CertGetSubjectCertificateFromStore CertGetCertificateContextProperty CertFreeCertificateContext CryptMsgControl CryptDecodeObject CertGetIntendedKeyUsage CertFreeCertificateChain CertFreeCertificateChainEngine CertGetCertificateChain CertCreateCertificateChainEngine CertCreateCertificateContext CryptAcquireCertificatePrivateKey CertVerifyRevocation |
| urlmon.dll |
URLDownloadToFileW
URLDownloadToFileA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.4.5.0 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | WebZen |
| FileDescription | main |
| FileVersion (#2) | 1, 4, 5, 0 |
| InternalName | main |
| LegalCopyright | Copyright â 2002 |
| OriginalFilename | main.exe |
| ProductName | WebZen mu main |
| ProductVersion (#2) | 1, 0, 0, 1 |
| Resource LangID | Korean - Korea |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2012-Mar-21 08:53:38 |
| Version | 0.0 |
| SizeofData | 117 |
| AddressOfRawData | 0x9ebc58 |
| PointerToRawData | 0x9ea858 |
| Referenced File | d:\ClientTeam\20. Release\2. ê¸ë¡ë²\[12.03.22] MU_ENG_1.04.05\tmp\Global Release\main.pdb |
| XOR Key | 0x14d2fc8d |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2008 build 21022) | 280 |
| 150 (20413) | 5 |
| ASM objects (VS2008 SP1 build 30729) | 60 |
| C objects (VS2008 SP1 build 30729) | 211 |
| Linker (VC++ 6.0 SP5 imp/exp build 8447) | 2 |
| C++ objects (VC++ 6.0 SP5 build 8804) | 1 |
| C++ objects (VS98 SP6 build 8804) | 11 |
| C objects (VS98 build 8168) | 44 |
| C objects (9178) | 1 |
| C++ objects (9178) | 1 |
| Imports (9210) | 2 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 35 |
| Total imports | 517 |
| C++ objects (VS2008 SP1 build 30729) | 585 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.