| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2001-Jan-17 14:08:04 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to DES |
| Suspicious | The PE is possibly packed. |
Unusual section name found: CODE32
Unusual section name found: CONST32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2023-07-17 06:35:40) |
BitDefenderTheta:
Gen:NN.ZexaE.36318.cuW@aK!x5ad
MaxSecure: Trojan.Malware.300983.susgen |
| e_magic | MZ |
|---|---|
| e_cblp | 0 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0xb |
| e_sp | 0x100 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2001-Jan-17 14:08:04 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x5224 |
| SizeOfInitializedData | 0xbbb4 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001A26 (Section: CODE32) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 1.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 3.A |
| Win32VersionValue | 0 |
| SizeOfImage | 0x15000 |
| SizeOfHeaders | 0x2b0 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x8000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
RegCloseKey
RegCreateKeyExA RegSetValueExA |
|---|---|
| kernel32.dll |
CreateMutexA
CreateFileMappingA CreateFileA CloseHandle GetCommandLineA GetCurrentProcessId GetEnvironmentStrings GetFileType GetLastError GetModuleFileNameA GetLocaleInfoA GetProcAddress GetModuleHandleA GetConsoleScreenBufferInfo GetThreadLocale GetStdHandle GetVersionExA LoadLibraryA MapViewOfFile OpenMutexA RaiseException ReadFile ReleaseMutex SetFilePointer ExitProcess TlsGetValue TlsSetValue TlsAlloc VirtualQuery WaitForSingleObject WriteFile VirtualAlloc VirtualFree SetEndOfFile lstrlenA RtlUnwind |
| MSVCRT.DLL |
_itoa
|
| user32.dll |
LoadStringA
OemToCharA MessageBoxA wvsprintfA |
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%s' is not a valid date |
| '%s' is not a valid time |
| '%s' is not a valid date and time |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Invalid filename |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Invalid variant type conversion |
| Invalid variant operation |
| Variant method calls not supported |
| Read |
| Write |
| Format result longer than 4096 characters |
| Format string too long |
| Error creating variant array |
| Variant is not an array |
| Variant array index out of bounds |
| External exception %x |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
No comments yet.