| filename | downloadq.dll | |
|---|---|---|
| size | 151552 (0x25000) | |
| md5 | ab930bef054816bf2986e4145d471992 | |
| type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | Win.Malware.Razy-6703914-0 FOUND | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Sections
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0x2c000 | 0x3b | |
| IMPORT | 0x2d000 | 0x13e8 | |
| RESOURCE | 0 | 0 | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0x2f000 | 0xcd8 | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0 | 0 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0x2d39c | 0x2d4 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| module_name | hint | ord | function_name |
|---|---|---|---|
| ADVAPI32.DLL | 93 | CryptAcquireContextA | |
| ADVAPI32.DLL | 96 | CryptCreateHash | |
| ADVAPI32.DLL | 99 | CryptDestroyHash | |
| ADVAPI32.DLL | 113 | CryptGetHashParam | |
| ADVAPI32.DLL | 117 | CryptHashData | |
| ADVAPI32.DLL | 120 | CryptReleaseContext | |
| ADVAPI32.DLL | 246 | GetUserNameW | |
| ADVAPI32.DLL | 386 | RegCloseKey | |
| ADVAPI32.DLL | 390 | RegCreateKeyExA | |
| ADVAPI32.DLL | 393 | RegDeleteKeyA | |
| ADVAPI32.DLL | 397 | RegDeleteValueA | |
| ADVAPI32.DLL | 401 | RegEnumKeyExA | |
| ADVAPI32.DLL | 404 | RegEnumValueA | |
| ADVAPI32.DLL | 413 | RegOpenKeyExA | |
| ADVAPI32.DLL | 423 | RegQueryValueExA | |
| ADVAPI32.DLL | 434 | RegSetValueExA | |
| CRYPT32.DLL | 40 | CryptUnprotectData | |
| GDI32.dll | 12 | BitBlt | |
| GDI32.dll | 33 | CreateCompatibleBitmap | |
| GDI32.dll | 34 | CreateCompatibleDC | |
| GDI32.dll | 70 | DeleteDC | |
| GDI32.dll | 73 | DeleteObject | |
| GDI32.dll | 147 | GetDIBits | |
| GDI32.dll | 281 | SelectObject | |
| KERNEL32.dll | 82 | CloseHandle | |
| KERNEL32.dll | 128 | CreateDirectoryW | |
| KERNEL32.dll | 142 | CreateFileW | |
| KERNEL32.dll | 154 | CreateMutexA | |
| KERNEL32.dll | 160 | CreatePipe | |
| KERNEL32.dll | 163 | CreateProcessA | |
| KERNEL32.dll | 188 | CreateToolhelp32Snapshot | |
| KERNEL32.dll | 212 | DeleteFileW | |
| KERNEL32.dll | 236 | EnterCriticalSection | |
| KERNEL32.dll | 279 | ExitProcess | |
| KERNEL32.dll | 291 | FileTimeToSystemTime | |
| KERNEL32.dll | 300 | FindClose | |
| KERNEL32.dll | 304 | FindFirstFileA | |
| KERNEL32.dll | 311 | FindFirstFileW | |
| KERNEL32.dll | 321 | FindNextFileA | |
| KERNEL32.dll | 323 | FindNextFileW | |
| KERNEL32.dll | 352 | FreeLibrary | |
| KERNEL32.dll | 388 | GetCommandLineA | |
| KERNEL32.dll | 397 | GetComputerNameW | |
| KERNEL32.dll | 447 | GetCurrentProcessId | |
| KERNEL32.dll | 451 | GetCurrentThreadId | |
| KERNEL32.dll | 459 | GetDiskFreeSpaceExA | |
| KERNEL32.dll | 464 | GetDriveTypeA | |
| KERNEL32.dll | 483 | GetFileAttributesExW | |
| KERNEL32.dll | 486 | GetFileAttributesW | |
| KERNEL32.dll | 510 | GetLastError | |
| KERNEL32.dll | 511 | GetLocalTime | |
| KERNEL32.dll | 515 | GetLogicalDriveStringsA | |
| KERNEL32.dll | 528 | GetModuleFileNameW | |
| KERNEL32.dll | 577 | GetProcAddress | |
| KERNEL32.dll | 590 | GetProcessTimes | |
| KERNEL32.dll | 606 | GetStartupInfoA | |
| KERNEL32.dll | 623 | GetSystemInfo | |
| KERNEL32.dll | 627 | GetSystemTime | |
| KERNEL32.dll | 656 | GetTickCount | |
| KERNEL32.dll | 671 | GetVersionExA | |
| KERNEL32.dll | 673 | GetVolumeInformationA | |
| KERNEL32.dll | 734 | InitializeCriticalSection | |
| KERNEL32.dll | 814 | LeaveCriticalSection | |
| KERNEL32.dll | 817 | LoadLibraryA | |
| KERNEL32.dll | 829 | LocalFree | |
| KERNEL32.dll | 856 | MoveFileW | |
| KERNEL32.dll | 860 | MultiByteToWideChar | |
| KERNEL32.dll | 885 | OpenProcess | |
| KERNEL32.dll | 896 | PeekNamedPipe | |
| KERNEL32.dll | 904 | Process32First | |
| KERNEL32.dll | 906 | Process32Next | |
| KERNEL32.dll | 947 | ReadFile | |
| KERNEL32.dll | 974 | ReleaseMutex | |
| KERNEL32.dll | 999 | ResumeThread | |
| KERNEL32.dll | 1064 | SetErrorMode | |
| KERNEL32.dll | 1073 | SetFileAttributesW | |
| KERNEL32.dll | 1078 | SetFilePointer | |
| KERNEL32.dll | 1152 | Sleep | |
| KERNEL32.dll | 1166 | TerminateProcess | |
| KERNEL32.dll | 1247 | WideCharToMultiByte | |
| KERNEL32.dll | 1267 | WriteFile | |
| msvcrt.dll | 201 | _assert | |
| msvcrt.dll | 214 | _beginthreadex | |
| msvcrt.dll | 285 | _errno | |
| msvcrt.dll | 309 | _filelengthi64 | |
| msvcrt.dll | 678 | _mkdir | |
| msvcrt.dll | 766 | _snwprintf | |
| msvcrt.dll | 791 | _stat | |
| msvcrt.dll | 903 | _vscprintf | |
| msvcrt.dll | 909 | _vsnprintf | |
| msvcrt.dll | 1004 | _wfopen | |
| msvcrt.dll | 1098 | calloc | |
| msvcrt.dll | 1111 | fclose | |
| msvcrt.dll | 1114 | fflush | |
| msvcrt.dll | 1116 | fgetpos | |
| msvcrt.dll | 1117 | fgets | |
| msvcrt.dll | 1122 | fopen | |
| msvcrt.dll | 1130 | fread | |
| msvcrt.dll | 1131 | free | |
| msvcrt.dll | 1132 | freopen | |
| msvcrt.dll | 1137 | fseek | |
| msvcrt.dll | 1138 | fsetpos | |
| msvcrt.dll | 1139 | ftell | |
| msvcrt.dll | 1140 | fwprintf | |
| msvcrt.dll | 1142 | fwrite | |
| msvcrt.dll | 1147 | getenv | |
| msvcrt.dll | 1183 | localtime | |
| msvcrt.dll | 1187 | malloc | |
| msvcrt.dll | 1198 | memcmp | |
| msvcrt.dll | 1204 | mktime | |
| msvcrt.dll | 1220 | realloc | |
| msvcrt.dll | 1221 | remove | |
| msvcrt.dll | 1232 | sprintf | |
| msvcrt.dll | 1238 | strcat | |
| msvcrt.dll | 1240 | strchr | |
| msvcrt.dll | 1241 | strcmp | |
| msvcrt.dll | 1243 | strcpy | |
| msvcrt.dll | 1253 | strncpy | |
| msvcrt.dll | 1272 | time | |
| msvcrt.dll | 1283 | utime | |
| msvcrt.dll | 1299 | wcscat | |
| NETAPI32.DLL | 39 | NetApiBufferFree | |
| NETAPI32.DLL | 173 | NetWkstaGetInfo | |
| SHELL32.DLL | 75 | SHFileOperationW | |
| SHELL32.DLL | 144 | ShellExecuteA | |
| SHELL32.DLL | 148 | ShellExecuteW | |
| USER32.dll | 91 | CreateWindowExW | |
| USER32.dll | 135 | DefWindowProcW | |
| USER32.dll | 149 | DispatchMessageA | |
| USER32.dll | 205 | EnumWindows | |
| USER32.dll | 248 | GetDC | |
| USER32.dll | 250 | GetDesktopWindow | |
| USER32.dll | 259 | GetForegroundWindow | |
| USER32.dll | 267 | GetKeyNameTextW | |
| USER32.dll | 268 | GetKeyState | |
| USER32.dll | 273 | GetKeyboardState | |
| USER32.dll | 276 | GetLastInputInfo | |
| USER32.dll | 297 | GetMessageW | |
| USER32.dll | 326 | GetSystemMetrics | |
| USER32.dll | 353 | GetWindowTextW | |
| USER32.dll | 397 | IsWindowVisible | |
| USER32.dll | 430 | MapVirtualKeyW | |
| USER32.dll | 468 | PostQuitMessage | |
| USER32.dll | 481 | RegisterClassExW | |
| USER32.dll | 494 | ReleaseDC | |
| USER32.dll | 508 | SendMessageA | |
| USER32.dll | 513 | SendMessageW | |
| USER32.dll | 526 | SetCursorPos | |
| USER32.dll | 575 | SetWindowTextW | |
| USER32.dll | 585 | ShowWindow | |
| USER32.dll | 599 | ToUnicode | |
| USER32.dll | 608 | TranslateMessage | |
| USER32.dll | 636 | keybd_event | |
| USER32.dll | 637 | mouse_event | |
| WS2_32.dll | 26 | WSACleanup | |
| WS2_32.dll | 43 | WSAGetLastError | |
| WS2_32.dll | 54 | WSAIoctl | |
| WS2_32.dll | 84 | WSAStartup | |
| WS2_32.dll | 131 | __WSAFDIsSet | |
| WS2_32.dll | 134 | closesocket | |
| WS2_32.dll | 135 | connect | |
| WS2_32.dll | 139 | gethostbyname | |
| WS2_32.dll | 150 | htons | |
| WS2_32.dll | 152 | inet_ntoa | |
| WS2_32.dll | 155 | ioctlsocket | |
| WS2_32.dll | 158 | ntohs | |
| WS2_32.dll | 159 | recv | |
| WS2_32.dll | 161 | select | |
| WS2_32.dll | 162 | send | |
| WS2_32.dll | 164 | setsockopt | |
| WS2_32.dll | 165 | shutdown | |
| WS2_32.dll | 166 | socket |
| ord | entry_va | function_name |
|---|
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )