| File Path | Type and Hashes |
|---|
| Match Rules |
|---|
| File Name: | 972631C1A59F7256B984C3878296797B7607D0B8.exe |
| File Type: | PE32 executable (GUI) Intel 80386, for MS Windows |
| SHA1: | 972631c1a59f7256b984c3878296797b7607d0b8 |
| MD5: | e26f7a876b6c2ae91a3165b4d82171c8 |
| First Seen Date: | 2017-11-06 01:49:37.786336 ( ) |
| Number of Clients Seen: | 0 |
| Last Analysis Date: | 2017-11-06 01:49:37.786336 ( ) |
| Human Expert Analysis Date: | 2017-11-06 13:49:53.514955 ( ) |
| Human Expert Analysis Result: | PUA |
| Property | Value |
|---|---|
| file type enum | 6 |
| number of sections | 8 |
| compilation time stamp | 0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC] [SUSPICIOUS] |
| entry point | 0x408cec (CODE) |
| machine type | Intel 386 or later - 32Bit |
| file size | 77312 |
| sha256 | a2af2a6a4729b7fd4b91418c33e35b0d66bc16ea76ec1771cbbf4d6e311743cf |
| mime type | application/x-dosexec |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
|---|---|---|---|---|---|
| CODE | 0x1000 | 0x7f28 | 0x8000 | 6.38129627033 | 885dd6af7664efc487c1e3ff036fb7ed |
| DATA | 0x9000 | 0x53c | 0x600 | 2.73838426797 | 997a08644bec37f07efa621ba12c8264 |
| BSS | 0xa000 | 0x691 | 0x0 | 0.0 | d41d8cd98f00b204e9800998ecf8427e |
| .idata | 0xb000 | 0xa14 | 0xc00 | 4.13684649355 | f8a2c2f2fe9d4b7c8c2821cfc75b1035 |
| .tls | 0xc000 | 0x8 | 0x0 | 0.0 | d41d8cd98f00b204e9800998ecf8427e |
| .rdata | 0xd000 | 0x18 | 0x200 | 0.20448815744 | d61303205e73ca096826f93772cb8a34 |
| .reloc | 0xe000 | 0x738 | 0x800 | 6.36757598905 | 5c9027af6b185664b106f3dc54b6c4f9 |
| .rsrc | 0xf000 | 0x8e00 | 0x8e00 | 7.41477311937 | 16e7109991581ae67c79edd8321e414e |
-
kernel32.dll
- DeleteCriticalSection
- LeaveCriticalSection
- EnterCriticalSection
- InitializeCriticalSection
- VirtualFree
- VirtualAlloc
- LocalFree
- LocalAlloc
- GetVersion
- GetCurrentThreadId
- WideCharToMultiByte
- MultiByteToWideChar
- GetThreadLocale
- GetStartupInfoA
- GetModuleFileNameA
- GetLocaleInfoA
- GetCommandLineA
- FreeLibrary
- ExitProcess
- CreateThread
- WriteFile
- UnhandledExceptionFilter
- RtlUnwind
- RaiseException
- GetStdHandle
-
user32.dll
- GetKeyboardType
- MessageBoxA
- CharNextA
-
advapi32.dll
- RegQueryValueExA
- RegOpenKeyExA
- RegCloseKey
-
oleaut32.dll
- SysFreeString
- SysReAllocStringLen
- SysAllocStringLen
-
kernel32.dll
- TlsSetValue
- TlsGetValue
- LocalAlloc
- GetModuleHandleA
-
advapi32.dll
- RegSetValueExW
- RegQueryValueExW
- RegQueryValueExA
- RegOpenKeyExW
- RegOpenKeyExA
- RegCloseKey
-
kernel32.dll
- WriteFile
- WinExec
- WaitForSingleObject
- UnmapViewOfFile
- Sleep
- SizeofResource
- SetLastError
- SetFilePointer
- OutputDebugStringA
- MapViewOfFile
- LockResource
- LoadResource
- GetTickCount
- GetTempPathW
- GetLastError
- GetFileSize
- GetFileAttributesW
- FreeResource
- FormatMessageA
- FindResourceA
- ExitProcess
- CreateProcessW
- CreateFileMappingW
- CreateFileW
- CreateFileA
- CloseHandle
-
gdi32.dll
- SetTextColor
- SetBkColor
-
user32.dll
- wvsprintfA
- WaitForInputIdle
- TrackPopupMenu
- ShowWindow
- SetWindowTextA
- SetForegroundWindow
- SetFocus
- SetDlgItemTextW
- SetDlgItemTextA
- SetCursor
- SendMessageA
- PostQuitMessage
- MessageBoxA
- LoadCursorA
- IsDlgButtonChecked
- GetDlgItem
- GetCursorPos
- FindWindowExA
- FindWindowA
- EndDialog
- EnableWindow
- DialogBoxParamA
- DestroyMenu
- CreatePopupMenu
- CheckDlgButton
- AppendMenuA
-
shell32.dll
- ShellExecuteExA
-
shell32.dll
- IsUserAnAdmin
- ShellExecuteW
- ShellExecuteA
- SHGetSpecialFolderPathW
RT_ICON
RT_DIALOG
RT_RCDATA
RT_GROUP_ICON
RT_MANIFEST