filename | 2182604_KAROSMULTI.exe | |
---|---|---|
size | 5962752 (0x5afc00) | |
md5 | 9e0482245d3b7592ccee8484889a51cd | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | Win.Trojan.Agent-1376694 FOUND | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
Sections
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x5000 | 0x302 | |
RESOURCE | 0x9000 | 0x5ad8e8 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0x8000 | 0x1c8 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0x7000 | 0x18 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x406000 | 0x406004 | 0x403060 | 0x407010 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetCurrentThreadId | ||
kernel32.dll | SetCurrentDirectoryA | ||
kernel32.dll | GetCurrentDirectoryA | ||
kernel32.dll | ExitProcess | ||
kernel32.dll | RtlUnwind | ||
kernel32.dll | RaiseException | ||
kernel32.dll | TlsSetValue | ||
kernel32.dll | TlsGetValue | ||
kernel32.dll | LocalAlloc | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | FreeLibrary | ||
kernel32.dll | HeapFree | ||
kernel32.dll | HeapReAlloc | ||
kernel32.dll | HeapAlloc | ||
kernel32.dll | GetProcessHeap | ||
kernel32.dll | WriteFile | ||
kernel32.dll | SizeofResource | ||
kernel32.dll | SetFilePointer | ||
kernel32.dll | LockResource | ||
kernel32.dll | LoadResource | ||
kernel32.dll | GetWindowsDirectoryA | ||
kernel32.dll | GetTempPathA | ||
kernel32.dll | GetSystemDirectoryA | ||
kernel32.dll | FreeResource | ||
kernel32.dll | FindResourceA | ||
kernel32.dll | CreateFileA | ||
kernel32.dll | CloseHandle | ||
shfolder.dll | SHGetFolderPathA | ||
shell32.dll | ShellExecuteA |
offset | size | type | comment | |
---|---|---|---|---|
15c1 | 15 | HTM | # | |
256c | 247296 | EXE | 02/15/2015 08:00:31 | # |
345b8 | 18444 | PNG | (256 x 256) | # |
3eb6c | 1122 | RAR | # | |
49cfe0 | 573952 | EXE | 07/22/2012 21:16:20 | # |
529268 | 550912 | EXE | 06/19/1992 22:22:17 | # |
5a18a7 | 56211 | JPG | # | |
5afa68 | 408 | BIN | overlay data past EOF | # |
Scanning the drive for archives: 1 file, 5962752 bytes (5823 KiB) -- Type = PE Physical Size = 5962752 CPU = x86 Characteristics = Executable 32-bit NoLineNums NoLocalSyms Little-Endian Big-Endian Created = 1992-06-19 22:22:17 Headers Size = 1024 Checksum = 0 Image Size = 5992448 Section Alignment = 4096 File Alignment = 512 Code Size = 5120 Initialized Data Size = 5956608 Uninitialized Data Size = 0 Linker Version = 2.25 OS Version = 4.0 Image Version = 0.0 Subsystem Version = 4.0 Subsystem = Windows GUI Stack Reserve = 1048576 Stack Commit = 16384 Heap Reserve = 1048576 Heap Commit = 4096 Image Base = 4194304 ---- Path = .rsrc/RCDATA/A1 Size = 4827764 Packed Size = 4827764 -- Path = .rsrc/RCDATA/A1 Type = Rar Offset = 247296 Physical Size = 4580468 Solid = - Blocks = 4 Multivolume = - Volumes = 1 Date Time Attr Size Compressed Name ------------------- ----- ------------ ------------ ------------------------ 2016-03-20 18:20:36 ....A 4510228 4395095 WinMediaInstall.exe 2016-03-20 18:25:51 ....A 102 102 WinInstall.bat 2016-03-20 18:33:53 ....A 416768 182112 WinInstall.exe 2016-05-13 16:42:59 ....A 12420 2663 drv_set.reg ------------------- ----- ------------ ------------ ------------------------ 2016-05-13 16:42:59 4939518 4579972 4 files
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK