PE Compile Time

2010-02-25 02:49:53

PE Imphash

4fd02c30131afec2ff69809c9a86e7dd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d92a 0x0001da00 6.63891617583
.rdata 0x0001f000 0x000054e4 0x00005600 5.11598900838
.data 0x00025000 0x00005a40 0x00001a00 3.76208286036
.rsrc 0x0002b000 0x000001b4 0x00000200 5.11262354953

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0002b058 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library WS2_32.dll:
0x41f1c4 inet_addr
0x41f1c8 htons
0x41f1cc WSAStartup
0x41f1d0 WSACreateEvent
0x41f1d4 WSASocketA
0x41f1d8 connect
0x41f1dc WSAEventSelect
0x41f1e0 WSAResetEvent
0x41f1ec ioctlsocket
0x41f1f0 closesocket
0x41f1f4 WSACloseEvent
0x41f1f8 gethostname
0x41f1fc gethostbyname
0x41f200 inet_ntoa
0x41f204 send
0x41f208 WSAGetLastError
0x41f20c recv
Library KERNEL32.dll:
0x41f034 WriteConsoleA
0x41f038 ReadFile
0x41f03c Sleep
0x41f040 CloseHandle
0x41f044 CreateProcessA
0x41f048 ResetEvent
0x41f04c WaitForSingleObject
0x41f050 GetStartupInfoA
0x41f054 GetConsoleOutputCP
0x41f05c SetEvent
0x41f060 GetTickCount
0x41f068 GetVersionExA
0x41f06c GetLastError
0x41f074 GetDiskFreeSpaceExA
0x41f078 GetDriveTypeA
0x41f080 HeapFree
0x41f084 GetProcessHeap
0x41f088 HeapAlloc
0x41f08c CreateEventA
0x41f090 WriteConsoleW
0x41f094 SetStdHandle
0x41f098 GetLocaleInfoW
0x41f09c CreateFileA
0x41f0a8 CreateFileW
0x41f0ac CreatePipe
0x41f0b4 FreeLibrary
0x41f0b8 MultiByteToWideChar
0x41f0bc lstrcpynA
0x41f0c0 lstrlenA
0x41f0c4 GetProcAddress
0x41f0c8 LoadLibraryA
0x41f0dc GetModuleHandleA
0x41f0e0 GetCurrentProcess
0x41f0e4 OpenProcess
0x41f0e8 TerminateProcess
0x41f0ec WideCharToMultiByte
0x41f0f4 RtlUnwind
0x41f0fc SetEndOfFile
0x41f100 IsDebuggerPresent
0x41f104 RaiseException
0x41f108 ExitThread
0x41f10c GetCurrentThreadId
0x41f110 CreateThread
0x41f114 GetCommandLineA
0x41f118 HeapReAlloc
0x41f11c GetModuleHandleW
0x41f120 TlsGetValue
0x41f124 TlsAlloc
0x41f128 TlsSetValue
0x41f12c TlsFree
0x41f134 SetLastError
0x41f13c GetCPInfo
0x41f140 GetACP
0x41f144 GetOEMCP
0x41f148 IsValidCodePage
0x41f14c LCMapStringA
0x41f150 LCMapStringW
0x41f154 HeapCreate
0x41f158 VirtualFree
0x41f15c VirtualAlloc
0x41f160 ExitProcess
0x41f164 SetHandleCount
0x41f168 GetStdHandle
0x41f16c GetFileType
0x41f170 WriteFile
0x41f174 GetConsoleCP
0x41f178 GetConsoleMode
0x41f17c FlushFileBuffers
0x41f180 SetFilePointer
0x41f184 HeapSize
0x41f188 GetModuleFileNameA
0x41f1a0 GetCurrentProcessId
0x41f1a4 GetStringTypeA
0x41f1a8 GetStringTypeW
0x41f1ac GetUserDefaultLCID
0x41f1b0 GetLocaleInfoA
0x41f1b4 EnumSystemLocalesA
0x41f1b8 IsValidLocale
Library ADVAPI32.dll:
0x41f008 GetTokenInformation
0x41f00c LookupAccountSidA
0x41f010 OpenProcessToken
0x41f018 LogonUserA
Library CRYPT32.dll:

!This program cannot be run in DOS mode.
`.rdata
@.data
E(PSSj
SVWjD^3
PSSSSSS
PSSSSSS
FYY;t$
FYY;t$
t}9>uyj
tz9uvj
F09^(u
HtkHtCH
@PVhPlB
ySSShE
t6Ht'Ht
j$hx0B
0WWWWW
0WWWWW
QQSVWd
^SSSSS
jXh 2B
0SSSSS
j,hh3B
HtHu4j
s[S;7|G;w
tR99u2
_VVVVV
^WWWWW
HHtXHHt
>If90t
0A@@Ju
t"SS9]
uBh#LA
j@j ^V
^F<-uB
<xtX<XtT
<+t(<-t$:
+t HHt
>=Yt1j
URPQQhpMA
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
^SSSSS
j"^SSSSS
HHtYHHt
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t+WWVPV
^SSSSS
^SSSSS
u,VVWV
t VV9u
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
!@#%$^#@!
bad allocation
cmd.exe /c
?%s failed, error code is %d
succeed.
Killing process %d
Killing process %s
bad cast
ios_base::eofbit set
ios_base::failbit set
ios_base::badbit set
InitializeSecurityContext Failed. Error:
Send to Server failed.
HandShake with the server failed. Error:
Out of memory
Microsoft Unified Security Protocol Provider
1.3.6.1.5.5.7.3.2
Getting Maximum SSL chunk size failed. Error:
EncryptMessage failed. Error:
Decryption Failed. Context Expired.
Decryption Failed. Error:
Out of memory!
Out of memory.
Failed to load security dll.
Failed to Acquire Credentials. Error:
InitSecurityInterfaceA
Secur32.dll
Security.dll
2.16.840.1.113730.4.1
1.3.6.1.4.1.311.10.3.3
1.3.6.1.5.5.7.3.1
Delete
NoRemove
ForceRemove
ntdll.dll
NtQuerySystemInformation
SeDebugPrivilege
Unknown exception
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GAIsProcessorFeaturePresent
KERNEL32
(null)
`h````
xpxxxx
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
string too long
invalid string position
WSACloseEvent
WSAEnumNetworkEvents
WSAWaitForMultipleEvents
WSAResetEvent
WSAEventSelect
WSASocketA
WSACreateEvent
WS2_32.dll
ReadFile
CloseHandle
CreateProcessA
ResetEvent
WaitForSingleObject
GetStartupInfoA
CreatePipe
GetCurrentDirectoryA
SetEvent
GetTickCount
GetSystemPowerStatus
GetVersionExA
GetLastError
GetVolumeInformationA
GetDiskFreeSpaceExA
GetDriveTypeA
GetLogicalDriveStringsA
HeapFree
GetProcessHeap
HeapAlloc
CreateEventA
KERNEL32.dll
CreateProcessAsUserA
LogonUserA
ADVAPI32.dll
CertFreeCertificateChain
CertFreeCertificateContext
CertVerifyCertificateChainPolicy
CertGetCertificateChain
CRYPT32.dll
FreeLibrary
MultiByteToWideChar
lstrcpynA
lstrlenA
GetProcAddress
LoadLibraryA
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleHandleA
GetCurrentProcess
OpenProcess
TerminateProcess
WideCharToMultiByte
GetSystemTimeAsFileTime
RtlUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RaiseException
ExitThread
GetCurrentThreadId
CreateThread
GetCommandLineA
HeapReAlloc
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
InterlockedDecrement
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LCMapStringA
LCMapStringW
HeapCreate
VirtualFree
VirtualAlloc
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
WriteFile
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
HeapSize
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetCurrentProcessId
GetStringTypeA
GetStringTypeW
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
InitializeCriticalSectionAndSpinCount
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
GetLocaleInfoW
CreateFileA
SetEnvironmentVariableA
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
LookupAccountSidA
GetTokenInformation
SetCurrentDirectoryA
CreateFileW
SetEndOfFile
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVfacet@locale@std@@
.?AVcodecvt_base@std@@
.?AUctype_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDH@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVruntime_error@std@@
.?AVfailure@ios_base@std@@
.?AVbad_cast@std@@
.?AV?$basic_fstream@DU?$char_traits@D@std@@@std@@
.?AVException@@
.?AVSSLException@@
.?AVSSLSendException@@
.PAVSSLException@@
.PAVException@@
.PAVSSLSendException@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
UTF-16LE
UNICODE
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Shady.m!c
tehtris Clean
ClamAV Win.Trojan.Agent-30686
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Fugrafa.98569
Cylance unsafe
Zillya Backdoor.Shady.Win32.1
Paloalto Clean
Sangfor Trojan.Win32.Agent.PMX
K7AntiVirus Trojan ( 0055e3dd1 )
Alibaba Malware:Win32/km_24a0e.None
K7GW Trojan ( 0055e3dd1 )
Cybereason malicious.c8b499
Baidu Clean
VirIT Backdoor.Win32.Generic.BMZF
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic Clean
ESET-NOD32 Win32/Agent.PMX
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 99)
Kaspersky Backdoor.Win32.Shady.d
BitDefender Gen:Variant.Fugrafa.98569
NANO-Antivirus Trojan.Win32.Shady.ucmgh
ViRobot Trojan.Win32.S.Agent.151552.AA
MicroWorld-eScan Gen:Variant.Fugrafa.98569
Tencent Malware.Win32.Gencirc.13af750e
TACHYON Backdoor/W32.Shady.151552
Sophos Mal/Generic-R
F-Secure Heuristic.HEUR/AGEN.1362094
DrWeb Win32.HLLW.Autoruner1.19011
VIPRE Gen:Variant.Fugrafa.98569
TrendMicro BKDR_SHADY.B
McAfee-GW-Edition BehavesLike.Win32.NetLoader.ch
Trapmine Clean
FireEye Gen:Variant.Fugrafa.98569
Emsisoft Gen:Variant.Fugrafa.98569 (B)
SentinelOne Clean
GData Gen:Variant.Fugrafa.98569
Jiangmin Backdoor/Shady.b
Webroot W32.Backdoor.Gen
Avira HEUR/AGEN.1362094
Antiy-AVL Trojan[Backdoor]/Win32.Shady
Gridinsoft Clean
Xcitium Malware@#2vy4mnhtegbq
Arcabit Trojan.Fugrafa.D18109
SUPERAntiSpyware Clean
ZoneAlarm Backdoor.Win32.Shady.d
Microsoft Trojan:Win32/Connapts
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!7712D05C8B49
MAX malware (ai score=100)
VBA32 Backdoor.Shady
Malwarebytes Malware.AI.334716129
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall BKDR_SHADY.B
Rising Backdoor.Shady!8.DB1D (TFE:5:hTMWxtKyOXN)
Yandex Trojan.GenAsa!dCKUazmmcaE
Ikarus Backdoor.Win32.Shady
MaxSecure Trojan.Malware.4141278.susgen
Fortinet W32/Shady.D!tr.bdr
BitDefenderTheta Gen:NN.ZexaF.36250.jqW@aeBysNbi
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
IRMA Signature
ESET Security (Windows) Win32/Agent.PMX trojan
Avast Core Security (Linux) Win32:Malware-gen
C4S ClamAV (Linux) Win.Trojan.Agent-30686
F-Secure Antivirus (Linux) Trojan.TR/Agent.151552.164 [Aquarius]
Windows Defender (Windows) Trojan:Win32/Connapts
McAfee CLI scanner (Linux) Clean
Microsoft Defender ATP (Linux) Backdoor:Win32/Tartober.A
Forticlient (Linux) Clean
Bitdefender Antivirus (Linux) Gen:Variant.Fugrafa.98569
G Data Antivirus (Windows) Virus: Gen:Variant.Fugrafa.98569 (Engine A)
Sophos Anti-Virus (Linux) Mal/Generic-R
DrWeb Antivirus (Linux) Win32.HLLW.Autoruner1.19011
Trend Micro SProtect (Linux) Clean
ClamAV (Linux) Win.Trojan.Agent-30686
eScan Antivirus (Linux) Gen:Variant.Fugrafa.98569(DB)
Kaspersky Standard (Windows) UDS:Backdoor.Win32.Shady.d
Cuckoo

We're processing your submission... This could take a few seconds.