filename | dump.bin | |
---|---|---|
size | 66048 (0x10200) | |
md5 | e7c61a1bef8532784a2dd3e74c5178e6 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | Win.Trojan.CryptoTorLocker2015 FOUND | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x1688 | 0x1800 | R-X CODE | |
.rdata | 0x3000 | 0x820 | 0xa00 | R-- IDATA | |
.data | 0x4000 | 0x38bb | 0x600 | RW- IDATA | |
.rsrc | 0x8000 | 0xf98a4 | 0xf9a00 | RW- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x3138 | 0xa0 | |
RESOURCE | 0x8000 | 0xf98a4 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0x3000 | 0x138 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] non-empty last IMAGE_IMPORT_DESCRIPTOR: #<struct PEdump::IMAGE_IMPORT_DESCRIPTOR OriginalFirstThunk=4206636, TimeDateStamp=0, ForwarderChain=0, Name=0, FirstThunk=0, module_name=nil, original_first_thunk=nil, first_thunk=nil>
[?] can't find file_offset of VA 0x777a35ff
[?] can't find file_offset of VA 0x306a0040
[?] can't find file_offset of VA 0x176a0875
[?] can't find file_offset of VA 0x7d4e850
[?] import ofs 0x2ac00 VA=0x30000 beyond EOF
[?] import ofs 0x3b300 VA=0x40700 beyond EOF
[?] import ofs 0x2ac01 VA=0x30001 beyond EOF
[?] import ofs 0x1b200 VA=0x20600 beyond EOF
[?] import ofs 0x1af00 VA=0x20300 beyond EOF
[?] can't find file_offset of VA 0xa3000001
[?] can't find file_offset of VA 0x6a146a00
[?] can't find file_offset of VA 0x40776a
[?] can't find file_offset of VA 0x7a2
[?] can't find file_offset of VA 0x35ff016a
[?] can't find file_offset of VA 0x40752da0
[?] can't find file_offset of VA 0x326a326a
[?] can't find file_offset of VA 0x75013c00
[?] import ofs 0x5b200 VA=0x60600 beyond EOF
[?] import ofs 0x4ac02 VA=0x50002 beyond EOF
[?] import ofs 0x1b600 VA=0x20a00 beyond EOF
[?] can't find file_offset of VA 0x1deb0000
[?] can't find file_offset of VA 0x875ff00
[?] can't find file_offset of VA 0x680875ff
[?] can't find file_offset of VA 0x6a196a00
[?] can't find file_offset of VA 0x404433
[?] can't find file_offset of VA 0x777a35ff
[?] invalid VA 0x4f8ab7aa in OriginalFirstThunk[75] for
[?] invalid VA 0x2e50024d in OriginalFirstThunk[77] for
[?] invalid VA 0x224206 in OriginalFirstThunk[78] for
[?] invalid VA 0x1700112b in OriginalFirstThunk[79] for
[?] invalid VA 0x40c0005 in OriginalFirstThunk[80] for
[?] import ofs 0x1ad00 VA=0x20100 beyond EOF
[?] invalid VA 0x3070702 in OriginalFirstThunk[83] for
[?] import ofs 0x1b200 VA=0x20600 beyond EOF
[?] invalid VA 0x4000104 in OriginalFirstThunk[85] for
[?] invalid VA 0x1020001 in OriginalFirstThunk[86] for
[?] can't find file_offset of VA 0x306a0040
[?] import table: empty FirstThunk for
[?] can't find file_offset of VA 0x6a617501
[?] can't find file_offset of VA 0x748e850
[?] can't find file_offset of VA 0xff006a10
[?] can't find file_offset of VA 0x7d834eeb
[?] can't find file_offset of VA 0x40751d35
[?] can't find file_offset of VA 0x20750f0c
[?] can't find file_offset of VA 0x50bc458d
[?] can't find file_offset of VA 0xe80875ff
[?] can't find file_offset of VA 0x100c7d83
[?] can't find file_offset of VA 0x6de
[?] can't find file_offset of VA 0x6a0f75
[?] can't find file_offset of VA 0xc7d8313
[?] can't find file_offset of VA 0x6a0d7502
[?] can't find file_offset of VA 0xff1475ff
[?] can't find file_offset of VA 0x70ee800
[?] can't find file_offset of VA 0x75ff1075
[?] can't find file_offset of VA 0xec8b5500
[?] can't find file_offset of VA 0x875ff0c
[?] can't find file_offset of VA 0xd10c6dd1
[?] can't find file_offset of VA 0x550008c2
[?] can't find file_offset of VA 0x458b086d
[?] can't find file_offset of VA 0x6aec8b
[?] can't find file_offset of VA 0xff1875ff
[?] can't find file_offset of VA 0x776635ff
[?] can't find file_offset of VA 0x75ff1475
[?] can't find file_offset of VA 0x40443868
[?] can't find file_offset of VA 0xc75ff10
[?] can't find file_offset of VA 0x2006800
[?] can't find file_offset of VA 0x6aec8b
[?] can't find file_offset of VA 0x3de80000
[?] can't find file_offset of VA 0x776635ff
[?] can't find file_offset of VA 0x75ff1875
[?] can't find file_offset of VA 0x75ff0040
[?] can't find file_offset of VA 0x1075ff14
[?] can't find file_offset of VA 0xe8006a00
[?] can't find file_offset of VA 0x68
[?] can't find file_offset of VA 0x608
[?] can't find file_offset of VA 0xff004077
[?] can't find file_offset of VA 0x1cc2c9
[?] can't find file_offset of VA 0x75ff2075
[?] can't find file_offset of VA 0x6810
[?] can't find file_offset of VA 0x1c75ff0c
[?] can't find file_offset of VA 0x75ff5000
[?] can't find file_offset of VA 0x1cc2c900
[?] can't find file_offset of VA 0x44446808
[?] can't find file_offset of VA 0xec8b5500
[?] can't find file_offset of VA 0x458d006a
[?] can't find file_offset of VA 0x68f8c483
[?] can't find file_offset of VA 0xf9e850fc
[?] can't find file_offset of VA 0x6a006a
[?] can't find file_offset of VA 0x83000006
[?] can't find file_offset of VA 0x800368
[?] can't find file_offset of VA 0x6a357e
[?] can't find file_offset of VA 0xfc75ff00
[?] can't find file_offset of VA 0xff0c75ff
[?] can't find file_offset of VA 0x5014458d
[?] can't find file_offset of VA 0x75ff0875
[?] can't find file_offset of VA 0x6a1075ff
[?] can't find file_offset of VA 0xf875ff02
[?] can't find file_offset of VA 0xff006a00
[?] can't find file_offset of VA 0xc483ec8b
[?] can't find file_offset of VA 0xc3e8fc75
[?] can't find file_offset of VA 0x26a53f0
[?] can't find file_offset of VA 0x38ee905
[?] can't find file_offset of VA 0x6a0e6a
[?] can't find file_offset of VA 0x45890000
[?] can't find file_offset of VA 0x37ae905
[?] can't find file_offset of VA 0x6a50f0
[?] can't find file_offset of VA 0x45890000
[?] can't find file_offset of VA 0xe90575c0
[?] can't find file_offset of VA 0xf075fff4
[?] can't find file_offset of VA 0x364
[?] can't find file_offset of VA 0x352e905
[?] can't find file_offset of VA 0x50f84589
[?] can't find file_offset of VA 0x45890000
[?] can't find file_offset of VA 0x5ea
[?] can't find file_offset of VA 0x6af88bfc
[?] can't find file_offset of VA 0x8b10c783
[?] can't find file_offset of VA 0xc7831f8b
[?] can't find file_offset of VA 0xe883f445
[?] can't find file_offset of VA 0x86a5304
[?] can't find file_offset of VA 0xe90575c0
[?] can't find file_offset of VA 0x65b535ff
[?] can't find file_offset of VA 0x314
[?] can't find file_offset of VA 0x5ace800
[?] can't find file_offset of VA 0x407519a3
[?] can't find file_offset of VA 0xfb030000
[?] can't find file_offset of VA 0x79e80040
[?] can't find file_offset of VA 0xc7831f8b
[?] can't find file_offset of VA 0xb000005
[?] can't find file_offset of VA 0xff575300
[?] can't find file_offset of VA 0xe90575c0
[?] can't find file_offset of VA 0x40751d35
[?] can't find file_offset of VA 0x86a5304
[?] can't find file_offset of VA 0x57ce800
[?] can't find file_offset of VA 0x65b535ff
[?] can't find file_offset of VA 0x2b4
[?] can't find file_offset of VA 0x49e80040
[?] can't find file_offset of VA 0x407521a3
[?] can't find file_offset of VA 0xfb030000
[?] can't find file_offset of VA 0xff575300
[?] can't find file_offset of VA 0x6857106a
[?] can't find file_offset of VA 0x6857056a
[?] can't find file_offset of VA 0x406dc9
[?] can't find file_offset of VA 0x407529
[?] can't find file_offset of VA 0x406dd9
[?] can't find file_offset of VA 0x10c78300
[?] can't find file_offset of VA 0x4c78300
[?] can't find file_offset of VA 0x6857046a
[?] can't find file_offset of VA 0x4065a5
[?] can't find file_offset of VA 0x4065a9
[?] can't find file_offset of VA 0x4065ad
[?] can't find file_offset of VA 0x55c3c95b
[?] can't find file_offset of VA 0x4c78300
[?] can't find file_offset of VA 0xbb60ec8b
[?] can't find file_offset of VA 0xc9850c4d
[?] can't find file_offset of VA 0x406db9
[?] can't find file_offset of VA 0xc2c90475
[?] can't find file_offset of VA 0x4942aa1a
[?] can't find file_offset of VA 0xfa830008
[?] can't find file_offset of VA 0xc961f075
[?] can't find file_offset of VA 0x20632f00
[?] can't find file_offset of VA 0xeb0008c2
[?] can't find file_offset of VA 0x206c6564
[?] can't find file_offset of VA 0x200
[?] can't find file_offset of VA 0x20220022
[?] can't find file_offset of VA 0x4066b968
[?] can't find file_offset of VA 0x402155
[?] can't find file_offset of VA 0x214d6800
[?] can't find file_offset of VA 0x4068b968
[?] can't find file_offset of VA 0x4068b9
[?] can't find file_offset of VA 0x486e800
[?] can't find file_offset of VA 0x456
[?] can't find file_offset of VA 0x215e6800
[?] can't find file_offset of VA 0x6a006a
[?] can't find file_offset of VA 0x63e8006a
[?] can't find file_offset of VA 0x4068b968
[?] can't find file_offset of VA 0xc3000004
[?] can't find file_offset of VA 0x488
[?] can't find file_offset of VA 0x752135ff
[?] can't find file_offset of VA 0x3cee8c3
[?] can't find file_offset of VA 0x404e5068
[?] can't find file_offset of VA 0xb5a30000
[?] can't find file_offset of VA 0x2006800
[?] can't find file_offset of VA 0x40595068
[?] can't find file_offset of VA 0xbbe80000
[?] can't find file_offset of VA 0x412e800
[?] can't find file_offset of VA 0x89e8006a
[?] can't find file_offset of VA 0x680000
[?] can't find file_offset of VA 0xff000003
[?] can't find file_offset of VA 0x39ae800
[?] can't find file_offset of VA 0x4065ad35
[?] can't find file_offset of VA 0x59a30000
[?] can't find file_offset of VA 0x23ce8ff
[?] can't find file_offset of VA 0x68004065
[?] can't find file_offset of VA 0xd9680000
[?] can't find file_offset of VA 0x403c6800
[?] can't find file_offset of VA 0x6800406d
[?] can't find file_offset of VA 0x50680040
[?] can't find file_offset of VA 0x68004059
[?] can't find file_offset of VA 0xe8004059
[?] can't find file_offset of VA 0x405450
[?] can't find file_offset of VA 0x6affff
[?] can't find file_offset of VA 0x36a006a
[?] can't find file_offset of VA 0xc3e80040
[?] can't find file_offset of VA 0x26a006a
[?] can't find file_offset of VA 0xa3000002
[?] can't find file_offset of VA 0x46680040
[?] can't find file_offset of VA 0x406551
[?] can't find file_offset of VA 0xff004075
[?] can't find file_offset of VA 0x406551
[?] can't find file_offset of VA 0x40655135
[?] can't find file_offset of VA 0x68004059
[?] can't find file_offset of VA 0x293d8000
[?] can't find file_offset of VA 0x4043d4
[?] can't find file_offset of VA 0xe8000001
[?] can't find file_offset of VA 0x4043a668
[?] can't find file_offset of VA 0x6a
[?] can't find file_offset of VA 0xa7e80000
[?] can't find file_offset of VA 0x655005c6
[?] can't find file_offset of VA 0xb9000002
[?] can't find file_offset of VA 0x802d74d8
[?] can't find file_offset of VA 0x19
[?] can't find file_offset of VA 0xd8841c1
[?] can't find file_offset of VA 0x2a5c3a00
[?] can't find file_offset of VA 0x404450
[?] can't find file_offset of VA 0x5505c62e
[?] can't find file_offset of VA 0xf082e851
[?] can't find file_offset of VA 0x2a004044
[?] can't find file_offset of VA 0x5859ffff
[?] can't find file_offset of VA 0x7be80040
[?] can't find file_offset of VA 0xe8c57d49
[?] can't find file_offset of VA 0x6a000002
[?] can't find file_offset of VA 0x4065b9
[?] can't find file_offset of VA 0x20ee800
[?] can't find file_offset of VA 0x2135ff00
[?] can't find file_offset of VA 0x6de96800
[?] can't find file_offset of VA 0x68
[?] can't find file_offset of VA 0x4b680040
[?] can't find file_offset of VA 0xa8e880
[?] can't find file_offset of VA 0x406de968
[?] can't find file_offset of VA 0xea680000
[?] can't find file_offset of VA 0x6800
[?] can't find file_offset of VA 0x4065b968
[?] can't find file_offset of VA 0x8fe88000
[?] can't find file_offset of VA 0x26ee800
[?] can't find file_offset of VA 0x80680000
[?] can't find file_offset of VA 0x43a36800
[?] can't find file_offset of VA 0x40595068
[?] can't find file_offset of VA 0x50680040
[?] can't find file_offset of VA 0x444b6800
[?] can't find file_offset of VA 0x49e8
[?] can't find file_offset of VA 0xb9680040
[?] can't find file_offset of VA 0x6de96800
[?] can't find file_offset of VA 0x40438d68
[?] can't find file_offset of VA 0xb9680040
[?] can't find file_offset of VA 0x65b96800
[?] can't find file_offset of VA 0x7e80040
[?] can't find file_offset of VA 0x4e80c600
[?] can't find file_offset of VA 0xb9680040
[?] invalid VA 0x40301425 in OriginalFirstThunk[0] for
[?] invalid VA 0x1025ff00 in OriginalFirstThunk[1] for
[?] invalid VA 0x4030e825 in OriginalFirstThunk[3] for
[?] invalid VA 0x4030e025 in OriginalFirstThunk[6] for
[?] invalid VA 0x40303425 in OriginalFirstThunk[9] for
[?] invalid VA 0x2c25ff00 in OriginalFirstThunk[10] for
[?] can't find file_offset of VA 0x68004065
[?] import table: empty FirstThunk for
[?] can't find file_offset of VA 0xf8c483ec
[?] can't find file_offset of VA 0x80000000
[?] can't find file_offset of VA 0x50fc458d
[?] can't find file_offset of VA 0x43796800
[?] can't find file_offset of VA 0x50f8458d
[?] can't find file_offset of VA 0x6a0040
[?] can't find file_offset of VA 0xc3e81475
[?] can't find file_offset of VA 0xff0c75ff
[?] can't find file_offset of VA 0x50000001
[?] can't find file_offset of VA 0x1f8e8f8
[?] can't find file_offset of VA 0x6a1475ff
[?] can't find file_offset of VA 0x75ff0000
[?] can't find file_offset of VA 0xfcc483ec
[?] can't find file_offset of VA 0x1dee8f8
[?] can't find file_offset of VA 0x40755e
[?] can't find file_offset of VA 0x755e6800
[?] can't find file_offset of VA 0x15e
[?] can't find file_offset of VA 0x43dd6800
[?] can't find file_offset of VA 0x6a006a
[?] can't find file_offset of VA 0x40755e
[?] can't find file_offset of VA 0x6a036a
[?] can't find file_offset of VA 0x46680040
[?] can't find file_offset of VA 0xfc458900
[?] can't find file_offset of VA 0xff004075
[?] can't find file_offset of VA 0xc9000000
[?] can't find file_offset of VA 0xb9e8fc75
[?] can't find file_offset of VA 0x25ffccc3
[?] can't find file_offset of VA 0x403128
[?] can't find file_offset of VA 0x403130
[?] can't find file_offset of VA 0x312425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403108
[?] can't find file_offset of VA 0x312025ff
[?] can't find file_offset of VA 0x310425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x4030fc
[?] can't find file_offset of VA 0x4030f8
[?] can't find file_offset of VA 0x311425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403040
[?] can't find file_offset of VA 0x304c25ff
[?] can't find file_offset of VA 0x304425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403058
[?] can't find file_offset of VA 0x403050
[?] can't find file_offset of VA 0x305c25ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403068
[?] can't find file_offset of VA 0x307425ff
[?] can't find file_offset of VA 0x306c25ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403080
[?] can't find file_offset of VA 0x403078
[?] can't find file_offset of VA 0x308425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403090
[?] can't find file_offset of VA 0x309c25ff
[?] can't find file_offset of VA 0x309425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x4030a8
[?] can't find file_offset of VA 0x4030a0
[?] can't find file_offset of VA 0x30ac25ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x4030b8
[?] can't find file_offset of VA 0x30c425ff
[?] can't find file_offset of VA 0x30bc25ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x40303c
[?] can't find file_offset of VA 0x4030c8
[?] can't find file_offset of VA 0x30d825ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403004
[?] can't find file_offset of VA 0x302425ff
[?] can't find file_offset of VA 0x300825ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x403000
[?] can't find file_offset of VA 0x403020
[?] can't find file_offset of VA 0x301425ff
[?] can't find file_offset of VA 0x25ff0040
[?] can't find file_offset of VA 0x4030e4
[?] can't find file_offset of VA 0x303425ff
[?] can't find file_offset of VA 0x30e025ff
[?] can't find file_offset of VA 0x25ff0040