| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Jul-13 22:47:16 |
| TLS Callbacks | 1 callback(s) detected. |
| Comments | |
| CompanyName | |
| FileDescription | RIOT Brute / Checker |
| FileVersion | 9.3.1.2 |
| InternalName | Riot BC.exe |
| LegalCopyright | Copyright Bestea© 2025 |
| LegalTrademarks | |
| OriginalFilename | Riot BC.exe |
| ProductName | |
| ProductVersion | 9.3.1.2 |
| Assembly Version | 9.3.1.2 |
| Suspicious | PEiD Signature: | ASPack v2.12 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is packed with Enigma Protector |
Section .text is both writable and executable.
Unusual section name found: .aspack Section .aspack is both writable and executable. Unusual section name found: .adata Section .adata is both writable and executable. Unusual section name found: .enigma1 Section .enigma1 is both writable and executable. Unusual section name found: .enigma2 Section .enigma2 is both writable and executable. The number of imports reported in the RICH header is inconsistent. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. |
Resource __ is possibly compressed or encrypted.
Resources amount for 83.9635% of the executable. |
| Malicious | VirusTotal score: 42/72 (Scanned on 2025-10-10 17:23:23) |
ALYac:
Gen:Variant.Tedy.609590
APEX: Malicious AVG: Win32:Evo-gen [Trj] AhnLab-V3: Malware/Win32.RL_Generic.R331513 Antiy-AVL: GrayWare/Win32.Wacapew Arcabit: Trojan.Application.Lazy.343 Avast: Win32:Evo-gen [Trj] BitDefender: Gen:Variant.Application.Lazy.343 Bkav: W32.AIDetectMalware CTX: exe.unknown.lazy ClamAV: Win.Trojan.Trojanx-10003922-0 CrowdStrike: win/malicious_confidence_70% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: a variant of Win32/Packed.Enigma.DU Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Application.Lazy.343 (B) Fortinet: W32/Enigma.DU!tr GData: Gen:Variant.Application.Lazy.343 Google: Detected Gridinsoft: Trojan.Heur!.03212021 Ikarus: Trojan.MSIL.EzirizNetReactor Jiangmin: Trojan.Fsysna.pma Kingsoft: malware.kb.a.1000 Malwarebytes: Generic.Trojan.Malpack.DDS McAfeeD: ti!62D969571557 MicroWorld-eScan: Gen:Variant.Application.Lazy.343 Microsoft: Trojan:Win32/Wacatac.B!ml Panda: Trj/Genetic.gen Sangfor: Suspicious.Win32.Save.ins SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Generic.rc Sophos: Generic ML PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score TrellixENS: GenericRXOF-UC!0BE7E68C9CA1 VBA32: TScope.Malware-Cryptor.SB VIPRE: Gen:Variant.Application.Lazy.343 Varist: W32/Trojan.PTXQ-0455 Zillya: Trojan.EzirizNetReactor.Win32.559 tehtris: Generic.Malware |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 8 |
| TimeDateStamp | 2012-Jul-13 22:47:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x19800 |
| SizeOfInitializedData | 0x3c2200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x003E0001 (Section: .aspack) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1b000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x45a000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x3dd67d |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x200000 |
| SizeofHeapCommit | 0x2000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle |
|---|---|
| user32.dll |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
| advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle |
| advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| kernel32.dll (#3) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle |
| user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
| kernel32.dll (#4) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle |
| kernel32.dll (#5) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle |
| ole32.dll |
CreateStreamOnHGlobal
CoUninitialize CoInitialize |
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| ntdll.dll |
RtlInitUnicodeString
RtlFreeUnicodeString RtlFormatCurrentUserKeyPath RtlDosPathNameToNtPathName_U NtQuerySystemInformation |
| SHFolder.dll |
SHGetFolderPathW
SHGetFolderPathA |
| ntdll.dll (#2) |
RtlInitUnicodeString
RtlFreeUnicodeString RtlFormatCurrentUserKeyPath RtlDosPathNameToNtPathName_U NtQuerySystemInformation |
| shlwapi.dll |
PathMatchSpecW
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 9.3.1.2 |
| ProductVersion | 9.3.1.2 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Comments | |
| CompanyName | |
| FileDescription | RIOT Brute / Checker |
| FileVersion (#2) | 9.3.1.2 |
| InternalName | Riot BC.exe |
| LegalCopyright | Copyright Bestea© 2025 |
| LegalTrademarks | |
| OriginalFilename | Riot BC.exe |
| ProductName | |
| ProductVersion (#2) | 9.3.1.2 |
| Assembly Version | 9.3.1.2 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
1808214613
|
|---|---|
| TimeDateStamp | 2094-Oct-26 01:42:40 |
| Version | 10077.16092 |
| SizeofData | 1034936791 |
| AddressOfRawData | 0x83d899cc |
| PointerToRawData | 0x45fe3028 |
| StartAddressOfRawData | 0x810018 |
|---|---|
| EndAddressOfRawData | 0x810040 |
| AddressOfIndex | 0x810040 |
| AddressOfCallbacks | 0x810044 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0084CB70
|
| XOR Key | 0x7eea712c |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 build 21022) | 19 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 7 |
| Total imports | 112 |
| C++ objects (VS2008 build 21022) | 48 |
| C objects (VS2008 build 21022) | 142 |
| Resource objects (VS2008 build 21022) | 1 |
No comments yet.