| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Dec-29 20:40:55 |
| Detected languages |
English - United States
|
| CompanyName | MrAntiFun.net |
| FileDescription | MrAntiFun Trainer Engine |
| FileVersion | 1.03 |
| InternalName | MrAntiFun |
| LegalCopyright | Copyrights MrAntiFun.net © 2013-2019 |
| LegalTrademarks1 | MrAntiFun |
| LegalTrademarks2 | MrAntiFun.net |
| OriginalFilename | Trainer.exe |
| ProductName | MrAntiFun Trainer Engine |
| ProductVersion | 1.03 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | The PE is possibly a dropper. | Resource 2005 detected as a PE Executable. |
| Malicious | VirusTotal score: 35/72 (Scanned on 2025-01-28 11:23:45) |
ALYac:
Gen:Variant.Application.Ursu.378848
Antiy-AVL: RiskWare/MSIL.Gamehack Arcabit: Trojan.Application.Ursu.D5C7E0 BitDefender: Gen:Variant.Application.Ursu.378848 Bkav: W32.AIDetectMalware.CS CAT-QuickHeal: Trojan.ZpevdoFC.S7082265 CTX: exe.trojan.msil CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: a variant of MSIL/GameHack.AIM potentially unsafe Elastic: malicious (moderate confidence) Emsisoft: Gen:Variant.Application.Ursu.378848 (B) FireEye: Generic.mg.39ea51f9fe6f04ad GData: Gen:Variant.Application.Ursu.378848 Google: Detected Kingsoft: malware.kb.c.996 Lionic: Trojan.Win32.GameHack.4!c Malwarebytes: GameHack.HackTool.RiskWare.DDS MaxSecure: Trojan.Malware.74035103.susgen McAfee: Artemis!39EA51F9FE6F McAfeeD: ti!ED3916F3FF25 MicroWorld-eScan: Gen:Variant.Application.Ursu.378848 Paloalto: generic.ml Rising: Trojan.Cloxer!8.F54F (CLOUD) Sangfor: Trojan.Win32.Ursu.Vmjd SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Generic.bc Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence VIPRE: Gen:Variant.Application.Ursu.378848 Varist: W32/Trojan.GHM.gen!Eldorado Webroot: W32.Trojan.Gen Yandex: Trojan.GenAsa!YIUBK4KjtVQ alibabacloud: Trojan:MSIL/Gamehack.AIM |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2018-Dec-29 20:40:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x7600 |
| SizeOfInitializedData | 0x1f4bc000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000084BE (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x9000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1f4c7000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateToolhelp32Snapshot
Process32First Process32Next CloseHandle Module32First Module32Next OpenProcess VirtualQueryEx ReadProcessMemory GetSystemInfo VirtualAllocEx GetLastError VirtualFreeEx VirtualProtectEx WriteProcessMemory VirtualProtect GetCurrentProcess Beep GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetStartupInfoW GetModuleHandleW GetCurrentProcessId QueryPerformanceCounter IsProcessorFeaturePresent Sleep TerminateProcess |
|---|---|
| USER32.dll |
SetWindowsHookExA
CallNextHookEx |
| WINMM.dll |
PlaySoundA
|
| VCRUNTIME140.dll |
memmove
__CxxQueryExceptionSize __CxxExceptionFilter __CxxRegisterExceptionObject _except_handler4_common memset _CxxThrowException __std_exception_destroy __std_exception_copy __CxxDetectRethrow __CxxUnregisterExceptionObject __FrameUnwindFilter |
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
|
| api-ms-win-crt-runtime-l1-1-0.dll |
terminate
_controlfp_s _crt_atexit _register_onexit_function _initialize_onexit_table _invalid_parameter_noinfo_noreturn _register_thread_local_exe_atexit_callback _c_exit abort _seh_filter_exe _exit exit _initterm_e _initterm _get_narrow_winmain_command_line _initialize_narrow_environment _configure_narrow_argv _cexit _set_app_type |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z ?_Xbad_alloc@std@@YAXXZ |
| mscoree.dll |
_CorExeMain
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags |
VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
|
| FileOs | (EMPTY) |
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MrAntiFun.net |
| FileDescription | MrAntiFun Trainer Engine |
| FileVersion (#2) | 1.03 |
| InternalName | MrAntiFun |
| LegalCopyright | Copyrights MrAntiFun.net © 2013-2019 |
| LegalTrademarks1 | MrAntiFun |
| LegalTrademarks2 | MrAntiFun.net |
| OriginalFilename | Trainer.exe |
| ProductName | MrAntiFun Trainer Engine |
| ProductVersion (#2) | 1.03 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Dec-29 20:40:55 |
| Version | 0.0 |
| SizeofData | 876 |
| AddressOfRawData | 0x6d1c4 |
| PointerToRawData | 0x6bbc4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Dec-29 20:40:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x5c |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x46e36c |
| SEHandlerTable | 0x46d1c0 |
| SEHandlerCount | 1 |
| XOR Key | 0x4fd29f43 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| Imports (VS2008 build 21022) | 2 |
| Imports (VS2015 UPD3 build 24123) | 4 |
| ASM objects (VS2015 UPD3 build 24123) | 1 |
| C++ objects (VS2015 UPD3 build 24123) | 31 |
| C objects (VS2015 UPD3 build 24123) | 13 |
| Imports (65501) | 7 |
| Total imports | 84 |
| C++ objects (LTCG) (VS2015 UPD3.1 build 24215) | 1 |
| C++ objects (VS2015 UPD3.1 build 24215) | 1 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| 151 | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |
No comments yet.