| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2010-Feb-04 16:51:42 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\2010r1\REALbasic\REALbasic Visual Studio\release\X86RunHoudini.pdb
|
| CompanyName | |
| FileVersion | 1.0.0.0 |
| Country | |
| Release | Development |
| FileDescription | |
| LegalCopyright | |
| ProductVersion | |
| ProductName | |
| OriginalFilename | NavaDebugger |
| InternalName |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to Blowfish |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
8173479 bytes of data starting at offset 0x22d000.
Overlay data amounts for 78.1781% of the executable. |
| Malicious | VirusTotal score: 24/59 (Scanned on 2025-07-29 05:20:47) |
AVG:
Win32:Adware-gen [Adw]
Alibaba: Trojan:Win32/FakeAV.01406cc8 Avast: Win32:Adware-gen [Adw] Cylance: Unsafe Fortinet: Riskware/NavaShield GData: Gen:Variant.Trojan.FakeAV.Nava.1 Google: Detected Jiangmin: Trojan.CryFile.jf Kaspersky: Trojan-FakeAV.Win32.Nava.b Kingsoft: Win32.Trojan-FakeAV.Nava.gen Lionic: Trojan.Win32.Generic.luRG McAfeeD: ti!7D899D2D33BD MicroWorld-eScan: Gen:Variant.Trojan.FakeAV.Nava.1 Microsoft: Trojan:Win32/Occamy.C7D NANO-Antivirus: Trojan.Win32.FakeAv.bgsrq Sophos: Generic Reputation PUA (PUA) Symantec: PUA.Gen.2 Tencent: Malware.Win32.Gencirc.13fed1c7 TrendMicro-HouseCall: TROJ_GEN.R002H0CC825 VBA32: TrojanFakeAV.Nava VIPRE: Gen:Variant.Trojan.FakeAV.Nava.1 Varist: W32/ABApplication.NMHD-5823 Xcitium: Malware@#3jt9vgx2bdozg alibabacloud: Trojan:Win/Nava.b |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2010-Feb-04 16:51:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x168000 |
| SizeOfInitializedData | 0xe9000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x001469FF (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x169000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x252000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
|---|---|
| COMCTL32.dll |
#17
ImageList_Destroy ImageList_Add InitCommonControlsEx ImageList_Create |
| WINMM.dll |
midiOutOpen
midiOutShortMsg midiOutClose mciSendStringA mciSendStringW |
| iphlpapi.dll |
GetAdaptersInfo
|
| KERNEL32.dll |
ExitProcess
OutputDebugStringA GetUserDefaultLangID CreateEventW SwitchToFiber CreateFiber ConvertThreadToFiber DeleteFiber GetACP IsValidCodePage TlsAlloc TlsFree TlsSetValue TlsGetValue MulDiv GetVersion GetLogicalDrives InterlockedIncrement InterlockedDecrement ClearCommError ResetEvent GetCommState WaitForSingleObject SetCommBreak GetCommProperties EscapeCommFunction ClearCommBreak SetCommState SetCommTimeouts CreateEventA GetCurrentProcess GetOverlappedResult GetCommandLineA VirtualFree GetProcessHeap IsBadReadPtr HeapAlloc VirtualProtect HeapFree GetSystemDirectoryA GetModuleHandleA TerminateProcess GetSystemTimeAsFileTime HeapReAlloc GetFileType SetStdHandle SetUnhandledExceptionFilter IsDebuggerPresent GetStartupInfoA SetLastError GetCurrentThreadId HeapSize RaiseException GetStdHandle HeapDestroy HeapCreate GetConsoleCP GetConsoleMode SetHandleCount RtlUnwind SetEnvironmentVariableW OutputDebugStringW GetEnvironmentVariableW GetCommandLineW ExpandEnvironmentStringsW WideCharToMultiByte GetModuleFileNameA LoadLibraryW VirtualAlloc _lopen _llseek _lread _lclose LoadResource FindResourceA LockResource lstrcpyA GetFileTime CopyFileW FindNextFileW GetSystemDirectoryW FindClose GetCPInfo GetOEMCP LCMapStringA LCMapStringW SetFileAttributesW SetFileTime MoveFileW DeleteFileW GetCurrentThread CreateDirectoryW GetWindowsDirectoryW GetLongPathNameW GetFileAttributesW GetLogicalDriveStringsW RemoveDirectoryW SetCurrentDirectoryW GetShortPathNameW FindFirstFileW GetCurrentDirectoryW GlobalSize GlobalFree GlobalAlloc GlobalReAlloc CreateFileA GetCurrentProcessId CompareFileTime GetLocalTime LocalFileTimeToFileTime GetSystemTime GetDateFormatA FileTimeToLocalFileTime GetTimeFormatA SystemTimeToFileTime GetTimeZoneInformation UnhandledExceptionFilter FileTimeToSystemTime GetFileSize GetTempFileNameW CloseHandle GetLastError WriteFile GetTempPathW FlushFileBuffers CreateFileW ReadFile SetEndOfFile SetFilePointer DeleteCriticalSection LeaveCriticalSection InitializeCriticalSection EnterCriticalSection GlobalUnlock GlobalLock FreeLibrary LoadLibraryA GetVersionExA Sleep GetProcAddress GetLocaleInfoW MultiByteToWideChar GetUserDefaultLCID QueryPerformanceCounter QueryPerformanceFrequency GetTickCount GetStringTypeExA CompareStringW CompareStringA IsDBCSLeadByteEx GetLocaleInfoA GetModuleHandleW GetModuleFileNameW FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW WriteConsoleA GetConsoleOutputCP WriteConsoleW GetStringTypeA GetStringTypeW GetCommModemStatus |
| USER32.dll |
IsIconic
CreateMDIWindowW RegisterClassW PostMessageA RegisterWindowMessageA TrackMouseEvent GetFocus GetMenuState EnumChildWindows GetWindow IsZoomed GetTopWindow BringWindowToTop AdjustWindowRect GetSystemMenu GetClassInfoW DestroyCursor VkKeyScanA DeleteMenu DestroyMenu GetMenuItemID SetMenuItemInfoW CheckMenuItem GetWindowTextLengthW EnableWindow RemovePropA SetWindowTextW GetMessagePos GetKeyState GetSubMenu GetMenuStringW GetMenuItemInfoW IsClipboardFormatAvailable RegisterClipboardFormatA OpenClipboard wsprintfA GetPropA FrameRect SetPropA InvalidateRgn SetParent CreateWindowExW BeginPaint EndPaint UpdateWindow DragDetect GetClassNameA ValidateRect ShowCursor GetMonitorInfoA EnumDisplayMonitors RegisterClassA SetTimer KillTimer MsgWaitForMultipleObjectsEx WindowFromPoint ReleaseCapture GetMessageW DispatchMessageW TranslateMDISysAccel PeekMessageW SystemParametersInfoA DrawFrameControl DrawIconEx FindWindowW GetMenu ShowWindow GetMenuItemCount CreateWindowExA ChildWindowFromPointEx CreateIconIndirect RedrawWindow DefWindowProcA CreateCursor LoadImageA MessageBoxW GetWindowTextW GetWindowTextLengthA ScreenToClient MoveWindow GetKeyNameTextW MapVirtualKeyA SetClipboardData GetClipboardData EmptyClipboard CreateIconFromResource CreateIconFromResourceEx DrawTextW LoadIconA InvertRect DrawIcon GetSysColorBrush DrawFocusRect GetIconInfo LoadCursorFromFileW DestroyIcon SendMessageW GetParent SetWindowPos FillRect SetForegroundWindow DispatchMessageA IsWindowVisible MessageBoxA EnumWindows PeekMessageA TranslateMessage ClientToScreen GetClientRect GetWindowRect GetForegroundWindow TrackPopupMenu GetCursorPos CreatePopupMenu CallWindowProcW DefWindowProcW GetWindowLongW DefFrameProcW ReleaseDC SetWindowLongW GetDC SetScrollRange GetScrollRange SetScrollInfo GetScrollPos GetScrollInfo SetScrollPos SetWindowLongA GetWindowLongA DrawMenuBar CopyRect SetCapture CreateMenu DefMDIChildProcW SendMessageA MessageBeep GetDoubleClickTime OffsetRect SetRect ScrollWindow CloseClipboard SetFocus GetSystemMetrics InvalidateRect WindowFromDC CharLowerBuffA CharUpperBuffA GetAsyncKeyState DrawEdge InsertMenuW DestroyWindow EnableMenuItem LoadCursorA SetMenu SetCursor GetMessageTime GetSysColor GetActiveWindow |
| GDI32.dll |
GetSystemPaletteEntries
Polygon SetBrushOrgEx SetTextAlign CreateMetaFileW CloseMetaFile CreateEnhMetaFileW CloseEnhMetaFile EnumFontsW EnumFontFamiliesExW CreateRectRgn CombineRgn CreatePen LineTo SelectClipRgn CreatePatternBrush SetBkMode SetPixelV GetTextExtentPoint32W CreateBitmap CreateSolidBrush GetFontLanguageInfo Ellipse GetClipRgn GetPixel Rectangle SetTextColor RoundRect GetTextMetricsA GetTextMetricsW DeleteEnhMetaFile DeleteMetaFile CreateDIBitmap GetMetaFileA GetEnhMetaFileW EnumEnhMetaFile CreateFontIndirectA SetViewportOrgEx SetBkColor GetEnhMetaFileA SetMapMode CreateFontW CreateBrushIndirect SetPixel StartDocA SetAbortProc EndDoc CreateICA SetViewportExtEx StartPage SetWindowExtEx EndPage GetStockObject CreateDIBSection DeleteDC StretchBlt CreateCompatibleBitmap RealizePalette BitBlt CreateDCA StretchDIBits SetDIBitsToDevice SelectPalette DeleteObject GetObjectA GetDIBits CreatePalette GetEnhMetaFileHeader SelectObject SetStretchBltMode CreateCompatibleDC MoveToEx TranslateCharsetInfo GetDeviceCaps |
| comdlg32.dll |
GetOpenFileNameW
GetSaveFileNameW ChooseColorA PageSetupDlgA PrintDlgA |
| ADVAPI32.dll |
DeregisterEventSource
ReportEventW RegisterEventSourceW RegEnumValueW RegQueryValueExW RegCreateKeyExW RegDeleteValueW RegSetValueExW RegCloseKey RegEnumKeyExW RegDeleteKeyW RegOpenKeyExW RegQueryInfoKeyW ImpersonateSelf AccessCheck MapGenericMask GetFileSecurityW OpenThreadToken RevertToSelf RegisterServiceCtrlHandlerA SetServiceStatus StartServiceCtrlDispatcherA |
| SHELL32.dll |
DragAcceptFiles
DragQueryFileW Shell_NotifyIconW SHGetDesktopFolder SHGetSpecialFolderLocation SHFileOperationW SHGetPathFromIDListW SHGetMalloc SHBrowseForFolderW ShellExecuteW DragFinish |
| ole32.dll |
CLSIDFromProgID
CLSIDFromString CoInitialize CoCreateInstance CoUninitialize CoTaskMemFree IIDFromString CoGetClassObject OleInitialize OleUninitialize CoTaskMemAlloc RegisterDragDrop RevokeDragDrop DoDragDrop |
| OLEAUT32.dll |
OleCreatePictureIndirect
SysAllocString SysFreeString OleLoadPicturePath |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags |
VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | |
| FileVersion (#2) | 1.0.0.0 |
| Country | |
| Release | Development |
| FileDescription | |
| LegalCopyright | |
| ProductVersion (#2) | |
| ProductName | |
| OriginalFilename | NavaDebugger |
| InternalName |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2010-Feb-04 16:51:42 |
| Version | 0.0 |
| SizeofData | 94 |
| AddressOfRawData | 0x19d4a0 |
| PointerToRawData | 0x19d4a0 |
| Referenced File | c:\2010r1\REALbasic\REALbasic Visual Studio\release\X86RunHoudini.pdb |
| XOR Key | 0x407d3198 |
|---|---|
| Unmarked objects | 0 |
| 126 (50327) | 3 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 57 |
| C objects (VS2003 (.NET) build 4035) | 10 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 151 |
| C objects (VS98 build 8168) | 6 |
| Imports (VS2003 (.NET) build 4035) | 25 |
| Total imports | 487 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 55 |
| 114 (VS2012 build 50727 / VS2005 build 50727) | 251 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |
No comments yet.