| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2012-Dec-20 19:14:11 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | PolyEnE 0.01+ by Lennart Hedlund |
| Suspicious | The PE is possibly packed. |
Section .text is both writable and executable.
Section .rdata is both writable and executable. Section .data is both writable and executable. Section .reloc is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | c0eda8cecc986c673c8fddbc09e97e63 🔍 |
|---|---|
| SHA1 | 98586d6590d45ca3e918848edbdd8ac58b90b338 🔍 |
| SHA256 | d5b099723bcffe9277e74a3db811aa6a50311e3fa738c910c03e34fd93837dfe 🔍 |
| SHA3 | d3c906be543362e537bb687c270904b83e665e1720fa32e00ce04c17609194d3 🔍 |
| SSDeep | 768:0/EAAqxG0QqLccK+xL7scaOZ/IcGs8WbwnWh+6AXT2qEDnXbiPGEDUXnpT0rJmn:tAc0QqgHW7/ZwcF8c6jELX+PupTNj 🔍 |
| Imports Hash | 318cc6baf22de5640b5a89a3bd3b774c 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2012-Dec-20 19:14:11 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.46509 |
| SizeOfCode | 0x9000 |
| SizeOfInitializedData | 0x6200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000014AC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xa000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 64EE.B5AD |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x11000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 6e899933b524feb2c4f200fc156dc368 🔍 |
|---|---|
| SHA1 | 5e3f98f83e1bfece30ae1d5aafb0941a281b45da 🔍 |
| SHA256 | 7d95d5f59e0725bc553b442b1efed38ed1be6bd43a6a8f10df28facf0930dd97 🔍 |
| SHA3 | c80768654578125d599081af84fa736409f9676ae3e15e8e4d5b29c42376c7f2 🔍 |
| VirtualSize | 0x8e1a |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x9000 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.47831 |
| MD5 | 4d5b9657a77a74d46378bd96ecc71026 🔍 |
|---|---|
| SHA1 | 4193829645ffa0e1fffb6f41a233646dfa7c7bbc 🔍 |
| SHA256 | 979f37cd25703242b7a89215d09417557154f6528654fe08336092ef4fa726f7 🔍 |
| SHA3 | 435cd5f27cdf4ce739384a88fe55355ece7c1baf50e39681d6e4f3bccd222b12 🔍 |
| VirtualSize | 0x24aa |
| VirtualAddress | 0xa000 |
| SizeOfRawData | 0x2600 |
| PointerToRawData | 0x9400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.71712 |
| MD5 | dc0360ce4763cef036d2419b768b494c 🔍 |
|---|---|
| SHA1 | 9886268567327d42a78f4b8c0365a72cff954427 🔍 |
| SHA256 | dc2fe74be2e5b4b862239a8b7f23c528b4576362cc564c42d46603fc01b0624e 🔍 |
| SHA3 | ecef40d22f9657d4caff89a52095b6c853516aa003bff4b6d5c90f3f66a4357e 🔍 |
| VirtualSize | 0x2c90 |
| VirtualAddress | 0xd000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0xba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.10314 |
| MD5 | a7a65e6422ef38588fbe19b91f01517e 🔍 |
|---|---|
| SHA1 | cb80aeeb07f766ce7d243df0fbc3fef84cdd8b37 🔍 |
| SHA256 | 27f548a3f446d16e8e8b772513dedb43124681ad7833a6afed963dd4a76adf2e 🔍 |
| SHA3 | f98c69dcf5bd91e4604228fd30342c352773d3cff163d9081d09e61100a1806a 🔍 |
| VirtualSize | 0xd10 |
| VirtualAddress | 0x10000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0xca00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.48703 |
| ADVAPI32.dll |
RegSetValueExW
RegCloseKey RegCreateKeyExW |
|---|---|
| KERNEL32.dll |
GetCommandLineA
HeapSetInformation TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetLastError HeapFree CloseHandle EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount RtlUnwind GetProcAddress GetModuleHandleW ExitProcess WriteFile GetStdHandle GetModuleFileNameW GetModuleFileNameA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoW DeleteCriticalSection TlsAlloc TlsGetValue TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapCreate QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers Sleep CreateFileA GetCPInfo GetACP GetOEMCP IsValidCodePage MultiByteToWideChar LoadLibraryW WriteConsoleW SetFilePointer IsProcessorFeaturePresent HeapAlloc HeapReAlloc SetEndOfFile GetProcessHeap ReadFile LCMapStringW GetStringTypeW HeapSize CreateFileW |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x40d004 |
| SEHandlerTable | 0x40bae0 |
| SEHandlerCount | 3 |
| XOR Key | 0x21b7de49 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 build 30319) | 29 |
| ASM objects (VS2010 build 30319) | 14 |
| C objects (VS2010 build 30319) | 99 |
| Imports (VS2008 SP1 build 30729) | 5 |
| Total imports | 81 |
| 174 (VS2010 build 30319) | 2 |
| Linker (VS2010 build 30319) | 1 |
No comments yet.