PE Compile Time

2015-11-24 06:03:06

PE Imphash

b41ed63b0e726445ee0a7b0a5dc7f96b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00014000 0x00010000 5.92477638934
UPX1 0x00015000 0x0000a000 0x00009800 1.5078652562
.rsrc 0x0001f000 0x00007000 0x00006a00 5.30653661944
.imports 0x00026000 0x00001000 0x00000800 4.42570527102
.reloc 0x00027000 0x00001000 0x00000c00 6.32288380929

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0002500c 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_GROUP_ICON 0x00025478 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00025500 0x0000025f LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with very long lines (607), with no line terminators

Imports

Library KERNEL32.DLL:
0x40c01c HeapSize
0x40c024 RtlUnwind
0x40c028 SetStdHandle
0x40c02c WriteConsoleW
0x40c030 CreateFileW
0x40c034 FlushFileBuffers
0x40c038 CompareStringW
0x40c044 GetStringTypeW
0x40c048 LoadLibraryW
0x40c04c ExitProcess
0x40c050 CreateFileA
0x40c054 GetFileSize
0x40c058 PeekNamedPipe
0x40c05c HeapAlloc
0x40c060 HeapFree
0x40c064 WaitForSingleObject
0x40c068 GetTickCount
0x40c06c GetProcessHeap
0x40c070 WriteFile
0x40c074 GetCommandLineA
0x40c078 GlobalAlloc
0x40c07c Sleep
0x40c080 GetExitCodeProcess
0x40c084 CreateProcessA
0x40c088 ReadFile
0x40c08c lstrcatA
0x40c090 CreateDirectoryA
0x40c098 GetLastError
0x40c09c OpenMutexA
0x40c0a0 CreatePipe
0x40c0a4 GetModuleFileNameA
0x40c0a8 CreateMutexA
0x40c0ac GetVersionExA
0x40c0b0 WinExec
0x40c0b4 CloseHandle
0x40c0b8 GetTempPathA
0x40c0bc lstrcpyA
0x40c0c0 HeapReAlloc
0x40c0c8 HeapSetInformation
0x40c0cc GetStartupInfoW
0x40c0d0 TerminateProcess
0x40c0d4 GetCurrentProcess
0x40c0dc IsDebuggerPresent
0x40c0e0 DecodePointer
0x40c0e4 EncodePointer
0x40c0e8 GetProcAddress
0x40c0ec GetModuleHandleW
0x40c0f0 GetStdHandle
0x40c0f4 GetModuleFileNameW
0x40c0f8 HeapCreate
0x40c0fc GetCPInfo
0x40c108 GetACP
0x40c10c GetOEMCP
0x40c110 IsValidCodePage
0x40c114 TlsAlloc
0x40c118 TlsGetValue
0x40c11c TlsSetValue
0x40c120 TlsFree
0x40c124 SetLastError
0x40c128 GetCurrentThreadId
0x40c12c WideCharToMultiByte
0x40c130 LCMapStringW
0x40c134 MultiByteToWideChar
0x40c13c RaiseException
0x40c148 SetHandleCount
0x40c150 GetFileType
0x40c15c GetCurrentProcessId
0x40c160 SetFilePointer
0x40c164 GetConsoleCP
0x40c168 GetConsoleMode
Library ADVAPI32.dll:
0x40c000 RegOpenKeyA
0x40c004 GetUserNameA
0x40c008 RegOpenKeyExA
0x40c00c RegQueryValueExA
0x40c010 RegSetValueExA
0x40c014 RegCloseKey
Library SHELL32.dll:
0x40c178 ShellExecuteA
Library urlmon.dll:
Library USER32.dll:
0x40c180 wsprintfA
Library WININET.dll:
0x40c188 DeleteUrlCacheEntry
Library WS2_32.dll:
0x40c190 closesocket
0x40c194 gethostbyname
0x40c198 gethostname
0x40c19c connect
0x40c1a0 WSAStartup
0x40c1a4 WSAGetLastError
0x40c1a8 htons
0x40c1ac WSACleanup
0x40c1b0 recv
0x40c1b4 socket
0x40c1b8 send

!This program cannot be run in DOS mode.
.imports
.reloc
RSSSWSS
HHtXHHt
?If90t
^SSSSS
t"SS9] u
>:u8FV
VVVVVQRSSj
j@j ^V
t hH1A
PPPPPPPP
PPPPPPPP
URPQQh
;t$,v-
UQPXY]Y[
bad allocation
(null)
`h````
xpxxxx
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
Unknown exception
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SOFTWARE\Microsoft\Windows NT\CurrentVersion\
ProductName
CSDVersion
sec.exe
C:\windows\system32\cmd.exe
%s /c %s
CMD:%s PROCESSED AT %d/%d/%d %d:%d:%d
$interval
Interval is set to %d min
$downloadexec
Download failure
Download success
Execution failure
Execution success
$download
Software\Microsoft\Windows\CurrentVersion\Run
C:\ProgramData\Update
C:\ProgramData\Update\wuauclt.exe
"C:\ProgramData\Update\wuauclt.exe" /run
C:\Program Files\Common Files\Update
C:\Program Files\Common Files\Update\wuauclt.exe
"C:\Program Files\Common Files\Update\wuauclt.exe" /run
Window Update
/c del /q "%s" >> NUL
c:\windows\system32\cmd.exe
MUTEX394039_4930023
i96;nE
E:\Data\My Projects\Troy Source Code\tcp1st\rifle\Release\rifle.pdb
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
158.69.115.115
HeapSize
IsProcessorFeaturePresent
RtlUnwind
SetStdHandle
WriteConsoleW
CreateFileW
FlushFileBuffers
CompareStringW
SetEnvironmentVariableA
UnhandledExceptionFilter
GetStringTypeW
LoadLibraryW
ExitProcess
CreateFileA
GetFileSize
PeekNamedPipe
HeapAlloc
HeapFree
WaitForSingleObject
GetTickCount
GetProcessHeap
WriteFile
GetCommandLineA
GlobalAlloc
GetExitCodeProcess
CreateProcessA
ReadFile
lstrcatA
CreateDirectoryA
SetCurrentDirectoryA
GetLastError
OpenMutexA
CreatePipe
GetModuleFileNameA
CreateMutexA
GetVersionExA
WinExec
CloseHandle
GetTempPathA
lstrcpyA
HeapReAlloc
GetSystemTimeAsFileTime
HeapSetInformation
GetStartupInfoW
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
IsDebuggerPresent
DecodePointer
EncodePointer
GetProcAddress
GetModuleHandleW
GetStdHandle
GetModuleFileNameW
HeapCreate
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetTimeZoneInformation
RaiseException
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
QueryPerformanceCounter
GetCurrentProcessId
SetFilePointer
GetConsoleCP
GetConsoleMode
EnterCriticalSection
LeaveCriticalSection
RegOpenKeyA
GetUserNameA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RegCloseKey
ShellExecuteA
URLOpenBlockingStreamA
wsprintfA
DeleteUrlCacheEntry
)u,$21
'AN'1K
]<%Xo=
`.rdata
@.data
@.reloc
IsValid;ag
ideCharToM
ultiBytLLCMap
`OToW-
ionAndSpin&
QueryPerfL
QP1a,;
wsp}tf
UrlCache
)u,$21
'AN'1K
]<%Xo=
XPTPSW
vvfvfw
~gnvggfvh
~wgv~vvgfvh
{wwwwvv~g
<9&!!!!!
!!&&!!!
H9&&9999&&!!!
E:8G:979&&&&!&
^`yy`_]DB879&&&&!&!
uppsuuutt
87&!&2&!!&<
vspijjr
VUUUUO
konnnnz
ooonng
P**+N.-
xwXXmmm
ZYYXmX
WWYYYX
ZWWWYW~
OOIOOU
OK;;;;;;=O
IHHA646A;;IO
;444&4;HHO
OA6A6H
,**+"((
43**((
wxvvvpqmY
AF++%%%#.
%+##.@
""""""""""
n68npppppp"
QOWVH=
J?&wwpdGTl IU
^RB`wfLO
eRS_w2XM
zsn644o
{kYg^PZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><ms_windowsSettings:dpiAware xmlns:ms_windowsSettings="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</ms_windowsSettings:dpiAware></windowsSettings></application></assembly>P
ADVAPI32.dll
KERNEL32.DLL
SHELL32.dll
urlmon.dll
USER32.dll
WININET.dll
WS2_32.dll
RegOpenKeyA
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellExecuteA
URLOpenBlockingStreamA
wsprintfA
DeleteUrlCacheEntry
r5x7|7
KERNEL32.DLL
HeapSize
IsProcessorFeaturePresent
RtlUnwind
SetStdHandle
WriteConsoleW
CreateFileW
FlushFileBuffers
CompareStringW
SetEnvironmentVariableA
UnhandledExceptionFilter
GetStringTypeW
LoadLibraryW
ExitProcess
CreateFileA
GetFileSize
PeekNamedPipe
HeapAlloc
HeapFree
WaitForSingleObject
GetTickCount
GetProcessHeap
WriteFile
GetCommandLineA
GlobalAlloc
GetExitCodeProcess
CreateProcessA
ReadFile
lstrcatA
CreateDirectoryA
SetCurrentDirectoryA
GetLastError
OpenMutexA
CreatePipe
GetModuleFileNameA
CreateMutexA
GetVersionExA
WinExec
CloseHandle
GetTempPathA
lstrcpyA
HeapReAlloc
GetSystemTimeAsFileTime
HeapSetInformation
GetStartupInfoW
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
IsDebuggerPresent
DecodePointer
EncodePointer
GetProcAddress
GetModuleHandleW
GetStdHandle
GetModuleFileNameW
HeapCreate
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetTimeZoneInformation
RaiseException
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
QueryPerformanceCounter
GetCurrentProcessId
SetFilePointer
GetConsoleCP
GetConsoleMode
EnterCriticalSection
LeaveCriticalSection
ADVAPI32.dll
RegOpenKeyA
GetUserNameA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RegCloseKey
SHELL32.dll
ShellExecuteA
urlmon.dll
URLOpenBlockingStreamA
USER32.dll
wsprintfA
WININET.dll
DeleteUrlCacheEntry
WS2_32.dll
3G4S4Z4`4l4
5%5.5B5b5g5n5
6P6f6s6z6
8(8;8H8
9'9G9`9~9
:5:<:H:
:X;\;`;
?B?Y?u?
030G0s0
3"3/3:3n3t3|3
30464<4G4T4`4g4m4s4~4
4'5.565<5C5i5x5
6+6I6T6Z6a6
67&7,72787t7
9-9D9i9
:&:J:^:|:
2.3A3p3
4'464>4K4W4c4i4{4
6#6(6.686A6L6X6]6m6r6x6~6
284<4@4D4H4L4P4T4a4s4S5]5j5
60787K7V7[7m7w7|7
:&:,:::n:{:
1,161I1m1
4!484Q4m4v4|4
8B8I8U8[8g8m8v8|8
:;;A;W;\;d;j;q;w;~;
<<$<,<1<8<G<L<R<[<{<
1,1K1\1a1g1x1}1
55'5-535x5
6#616?6
7 7-7@7M7o7U9\9
:6:c:n:t:z:
>1>g>n>v>
?&?+?0?G?
1%2/2p2{2
2a4r4z4
6N6U6j6
:8:[:h:t:|:
;#;<;Z;
<S=s=c>
5 5,595]5o5}5
7*7c7l7x7
;-;A;G;P;c;
<;<E<|<
<8===w=|=
>H?M?_?}?
0(03090I0N0_0g0m0w0}0
1#1=1?3F3L3
3h4S8e8w8
9-9?9Q9c9u9
9*<\<t<{<
= =j=p=t=x=|=
1%212<3u3
4;4T4p4
55,5K5
8-888[8
82989B9
6:6F6U6a6
7#8-8E8n8
=e=i=n=
1,20242H2L2t;|;
@1D1H1`1d1
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2T5X5
6 60646H6L6\6`6p6t6|6
7,707P7p7
8 8@8`8
9 9<9@9`9
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8
9 9$9(9,909<9
<(>,>0>4>8><>@>D>H>L>X>\>`>d>h>l>p>t>x>|>
A(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
WUSER32.DLL
((((( H
h(((( H
H
@CONOUT$
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Backdoor.Win32.RIFDOOR.SMTPTVLNT
Avast Core Security (Linux) Win32:Evo-gen [Trj]
C4S ClamAV (Linux) Win.Malware.Agentb-9639796-0
Trellix (Linux) GenericRXMV-ST
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Dropped:Generic.Dacic.06B5CF0E.A.3A6AA980
G Data Antivirus (Windows) Virus: Dropped:Generic.Dacic.06B5CF0E.A.3A6AA980 (Engine A), Win32.Trojan.PSE.1R5N4UM (Engine B)
WithSecure (Linux) Heuristic.HEUR/AGEN.1371816
ESET Security (Windows) a variant of Win32/Andariel.I trojan
DrWeb Antivirus (Linux) Trojan.DownLoader25.54608
ClamAV (Linux) Win.Malware.Agentb-9639796-0
eScan Antivirus (Linux) Dropped:Generic.Dacic.06B5CF0E.A.3A6AA980(DB)
Kaspersky Standard (Windows) Trojan.Win32.Agentb.bviq
Emsisoft Commandline Scanner (Windows) Dropped:Generic.Dacic.06B5CF0E.A.3A6AA980 (B)
Cuckoo

We're processing your submission... This could take a few seconds.