e510287ff91bed1835b8136f75ad1953db420e00f8af4376cb21e7766e83c6f7

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2009-Jul-17 10:55:13
Detected languages English - United States
Comments Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName Apache Software Foundation
FileDescription ApacheBench command line utility
FileVersion 2.2.14
InternalName ab.exe
LegalCopyright Copyright 2009 The Apache Software Foundation.
OriginalFilename ab.exe
ProductName Apache HTTP Server
ProductVersion 2.2.14

Plugin Output

Suspicious PEiD Signature: UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h)
UPX -> www.upx.sourceforge.net
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
Info Interesting strings found in the binary: Contains domain names:
  • apache.org
  • http://www.apache.org
  • http://www.apache.org/
  • http://www.apache.org/licenses/LICENSE-2.0
  • http://www.zeustech.net
  • http://www.zeustech.net/
  • www.apache.org
  • www.zeustech.net
  • zeustech.net
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
Unusual section name found: .idata2
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 b22c9ad879a592684b4b7ee6a4fdbfc3 🔍
SHA1 85fae32c807deba9bbbff391559b4d4198a19cea 🔍
SHA256 e510287ff91bed1835b8136f75ad1953db420e00f8af4376cb21e7766e83c6f7 🔍
SHA3 ba8161222f3aa36a13c1510ca98ab6690599efd07ab51ad43765fa9f1b78569e 🔍
SSDeep 1536:Iol1NeFhyxZh1GWAMZJln9AiMb+KR0Nc8Qswdq3v:ll1kuh19A+f5e0Nc8Qs9 🔍
Imports Hash 5edff169c272af95979688ef432d2738 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2009-Jul-17 10:55:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0xb000
SizeOfInitializedData 0x1000
SizeOfUninitializedData 0xc000
AddressOfEntryPoint 0x000043A6 (Section: UPX0)
BaseOfCode 0xd000
BaseOfData 0x18000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x19a00
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 30c11146842a2afc46129808d12c9423 🔍
SHA1 c037cf7eedc1667a17ae0799dd7c4b10bbcce791 🔍
SHA256 ec1bff36e983c10d40a47c79cf13f8f3cbe0d3edfbe845386d91182d4cf3cee7 🔍
SHA3 d71cccd5db9fcc27264988d1b6e89719ff8d43e5520034b8eedfb741bd66f66f 🔍
VirtualSize 0xc000
VirtualAddress 0x1000
SizeOfRawData 0xc000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.792

UPX1

MD5 339f5faa532a5a636ccde27798f51b24 🔍
SHA1 dd6c6da6c59532dfe487c47d7344aeb3a8b97003 🔍
SHA256 65443c3129ed67fb831141acba601c92a70de436af3e40696357d4d8eb4f648e 🔍
SHA3 fa75c2849357dad1cba579def2bbd9b551209a2516edd0cbc1d614cc584fe90f 🔍
VirtualSize 0xb000
VirtualAddress 0xd000
SizeOfRawData 0xb000
PointerToRawData 0xd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.36389

.rsrc

MD5 0a3b4dd8e14e1e5a68b4d426e3fe3966 🔍
SHA1 7a32d1598f6c0c835ae486b5b75e4a07912d9fa6 🔍
SHA256 2c367f95fccadc872975b710ea64e70670ce9a5edb4e75f47f58cc6a87cb6cb0 🔍
SHA3 452c9c060cfb238fa8f8ec1c3a86eb569e9def3e7c7cd8b37674e055bff0d7b0 🔍
VirtualSize 0x1000
VirtualAddress 0x18000
SizeOfRawData 0x1000
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.33923

.idata2

MD5 0b17b30e3f925971dfa7f86f356bb7c7 🔍
SHA1 5f779dfcd7d41cd09daf76bd05335e487e54293c 🔍
SHA256 fe4b7ac578b9b2c9ca565f60480ed5eb3358fa86ca2b060877bd359112747f0f 🔍
SHA3 4034112ae0197199392c26d8a32bf7f1f85f57f456632da812e72ca7074049b8 🔍
VirtualSize 0x1000
VirtualAddress 0x19000
SizeOfRawData 0xa00
PointerToRawData 0x19000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.13584

Imports

ADVAPI32.dll FreeSid
AllocateAndInitializeSid
KERNEL32.DLL PeekNamedPipe
ReadFile
WriteFile
LoadLibraryA
GetProcAddress
GetVersionExA
GetExitCodeProcess
TerminateProcess
LeaveCriticalSection
SetEvent
ReleaseMutex
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSection
CreateMutexA
GetFileType
SetLastError
FreeEnvironmentStringsW
GetEnvironmentStringsW
GlobalFree
GetCommandLineW
TlsAlloc
TlsFree
DuplicateHandle
GetCurrentProcess
SetHandleInformation
CloseHandle
GetSystemTimeAsFileTime
FileTimeToSystemTime
GetTimeZoneInformation
FileTimeToLocalFileTime
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
Sleep
FormatMessageA
msvcrt.dll _iob
_except_handler3
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
__setusermatherr
_initterm
__getmainargs
__p___initenv
_XcptFilter
_exit
_onexit
__dllonexit
strrchr
wcsncmp
_close
wcslen
wcscpy
strerror
modf
strspn
realloc
__p__environ
__p__wenviron
_errno
free
strncmp
strstr
strncpy
_ftol
qsort
fopen
perror
fclose
fflush
calloc
malloc
signal
printf
_isctype
atoi
exit
__mb_cur_max
_pctype
strchr
fprintf
_controlfp
_mbsdup
_strnicmp
WS2_32.dll getsockopt
connect
htons
gethostbyname
htonl
ioctlsocket
setsockopt
socket
closesocket
select
inet_addr
__WSAFDIsSet
WSAStartup
WSACleanup
WSAGetLastError

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x768
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49991
MD5 ddfda397f78597f8a3a40b972300dc26 🔍
SHA1 1e92b61cf6c7f7d73422bb7a2c0c335a7e459a7d 🔍
SHA256 465417d96548ce85076f6509efac41e5ad02fee2b8f712416e8b6aa08d93c494 🔍
SHA3 d057bd49bc4c303fa2411089f9681ec0f7baa4225cc802200eb9508872771603 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.2.14.0
ProductVersion 2.2.14.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName Apache Software Foundation
FileDescription ApacheBench command line utility
FileVersion (#2) 2.2.14
InternalName ab.exe
LegalCopyright Copyright 2009 The Apache Software Foundation.
OriginalFilename ab.exe
ProductName Apache HTTP Server
ProductVersion (#2) 2.2.14
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x859e59d7
Unmarked objects 0
12 (7291) 4
14 (7299) 9
C objects (8047) 11
Linker (8047) 3
Total imports 201
Imports (2179) 8
48 (9044) 40
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

Leave a comment

No comments yet.