PE Compile Time

2014-07-01 21:02:13

PE Imphash

ebc6265200d8989371b723b2f52c43df

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00013000 0x00013000 6.22778615921
UPX1 0x00014000 0x00015000 0x00015000 5.21169789851
UPX2 0x00029000 0x00012000 0x00012000 0.255915063506

Imports

Library KERNEL32.DLL:
0x42526c ExitProcess
0x425274 FormatMessageA
0x425278 GetLastError
0x42527c GetModuleFileNameA
0x425280 GetModuleHandleA
0x425284 GetProcAddress
0x425288 GetTickCount
0x42528c GetVersionExA
0x425290 SetLastError
0x425298 Sleep
0x42529c SleepEx
Library ADVAPI32.DLL:
0x425250 CryptCreateHash
0x425254 CryptDestroyHash
0x425258 CryptGetHashParam
0x42525c CryptHashData
0x425260 CryptReleaseContext
Library msvcrt.dll:
0x4252c0 __getmainargs
0x4252c4 __mb_cur_max
0x4252c8 __p__environ
0x4252cc __p__fmode
0x4252d0 __set_app_type
0x4252d4 _cexit
0x4252d8 _errno
0x4252dc _iob
0x4252e0 _isctype
0x4252e4 _onexit
0x4252e8 _pctype
0x4252ec _setmode
0x4252f0 _stati64
0x4252f4 _stricmp
0x4252f8 _strnicmp
0x4252fc _sys_nerr
0x425300 atexit
0x425304 calloc
0x425308 fclose
0x42530c fflush
0x425310 fgets
0x425314 fopen
0x425318 fprintf
0x42531c fputc
0x425320 fputs
0x425324 fread
0x425328 free
0x42532c fseek
0x425330 ftell
0x425334 fwrite
0x425338 getenv
0x42533c gmtime
0x425340 malloc
0x425344 mbstowcs
0x425348 memchr
0x42534c memcmp
0x425350 memcpy
0x425354 memmove
0x425358 memset
0x42535c printf
0x425360 puts
0x425364 qsort
0x425368 rand
0x42536c realloc
0x425370 setlocale
0x425374 signal
0x425378 sprintf
0x42537c srand
0x425380 sscanf
0x425384 strchr
0x425388 strcmp
0x42538c strcpy
0x425390 strerror
0x425394 strncmp
0x425398 strncpy
0x42539c strrchr
0x4253a0 strstr
0x4253a4 strtol
0x4253a8 strtoul
0x4253ac time
0x4253b0 tolower
0x4253b4 wcstombs
Library msvcrt.dll:
0x4252a8 _read
0x4252ac _strdup
0x4252b0 _unlink
0x4252b4 _write
Library WS2_32.DLL:
0x4253c0 WSACleanup
0x4253c4 WSAGetLastError
0x4253c8 WSAIoctl
0x4253cc WSASetLastError
0x4253d0 WSAStartup
0x4253d4 __WSAFDIsSet
0x4253d8 bind
0x4253dc closesocket
0x4253e0 connect
0x4253e4 gethostbyname
0x4253e8 getpeername
0x4253ec getsockname
0x4253f0 getsockopt
0x4253f4 htons
0x4253f8 ioctlsocket
0x4253fc ntohs
0x425400 recv
0x425404 select
0x425408 send
0x42540c setsockopt
0x425410 socket

Exports

Ordinal Address Name
1 0x401bf8 curl_easy_cleanup
2 0x4019e7 curl_easy_duphandle
3 0x418ac2 curl_easy_escape
4 0x401bdc curl_easy_getinfo
5 0x401eb4 curl_easy_init
6 0x4017f0 curl_easy_pause
7 0x401c0a curl_easy_perform
8 0x40179f curl_easy_recv
9 0x40194a curl_easy_reset
10 0x401739 curl_easy_send
11 0x401da2 curl_easy_setopt
12 0x4032b8 curl_easy_strerror
13 0x418a5b curl_easy_unescape
14 0x418bc4 curl_escape
15 0x402b39 curl_formadd
16 0x40200e curl_formfree
17 0x402a56 curl_formget
18 0x4188c8 curl_free
19 0x41b9b0 curl_getdate
20 0x418870 curl_getenv
21 0x401dca curl_global_cleanup
22 0x401e02 curl_global_init
23 0x401ef0 curl_global_init_mem
24 0x4108f8 curl_maprintf
25 0x41080f curl_mfprintf
26 0x41082e curl_mprintf
27 0x40f786 curl_msnprintf
28 0x410852 curl_msprintf
29 0x40c0ab curl_multi_add_handle
30 0x40a0b1 curl_multi_assign
31 0x40b81d curl_multi_cleanup
32 0x40a618 curl_multi_fdset
33 0x40b7b5 curl_multi_info_read
34 0x40c2f2 curl_multi_init
35 0x40b94e curl_multi_perform
36 0x40bef3 curl_multi_remove_handle
37 0x40b618 curl_multi_setopt
38 0x40bc8c curl_multi_socket
39 0x40bc5a curl_multi_socket_action
40 0x40bc26 curl_multi_socket_all
41 0x4032cd curl_multi_strerror
42 0x40a506 curl_multi_timeout
43 0x40bcbd curl_multi_wait
44 0x410877 curl_mvaprintf
45 0x4107b5 curl_mvfprintf
46 0x4107cf curl_mvprintf
47 0x41097d curl_mvsnprintf
48 0x4107ee curl_mvsprintf
49 0x4115c4 curl_share_cleanup
50 0x411528 curl_share_init
51 0x411669 curl_share_setopt
52 0x4032e2 curl_share_strerror
53 0x40dd74 curl_slist_append
54 0x40ddba curl_slist_free_all
55 0x4109e9 curl_strequal
56 0x4109c8 curl_strnequal
57 0x418aab curl_unescape
!This program cannot be run in DOS mode.
Sj&,Ph$
t[QQVP
PPXDR
t[QQVP
3QQj4j
VSQRPh
t'QQhh0B
u0PPShz
:/tbPPj/R
uMPPRj
@RRj?P
8[uqQQj%P
u!PPh?
w&RPh|
4$SPhO
B8QQPR
VSPPjhj
t/Pj8VS
t?PPVh
FXRj.SP
<Ste<E
<itk<ntA<g
7<utK<x
3PPj`j
\PPj;S
u7PPhb
u6PPhb
Bu'@u$
u6PPhb
u_PPj S
^dPSQV
t*QPRh
t"RRPS
|QQj:V
<\tI<]
u;PPhB
t)PPhE
;/tD;]
RPVSh7
RPVShN
wPPj/S
@PPj/S
G|u'VVj
WtSRPW
4$SPhd
(90u!Qj
SShD!B
libgcj_s.dll
_Jv_RegisterClasses
ma num wa rifaien yanje v1.0
rifaien2-%s.exe
ma num wa gyen orn hyzik %s en exec ween NODE%i
NODE%i
file[]
submit
http://wecan.hasthe.technology/upload
curl_easy_perform() failed: %s
ma au ga rre gyaje weel
[[UNIQUE]]9
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
CONNECT_ONLY is required!
Failed to get recent socket
easy handle already used in multi handle
------------------------%08x%08x
; filename="%s"
Content-Type: multipart/form-data
%s; boundary=%s
Content-Disposition: form-data; name="
Content-Type: multipart/mixed; boundary=%s
Content-Disposition: attachment
Content-Type: %s
couldn't open file "%s"
--%s--
--%s--
application/octet-stream
image/gif
image/jpeg
text/plain
text/html
application/xml
No error
Unknown error %d (%#x)
%255[^:]:%d:%255s
/etc/ssl/certs/ca-certificates.crt
no_proxy
NO_PROXY
_proxy
http_proxy
all_proxy
ALL_PROXY
socks5h
socks5
socks4a
socks4
[%*45[0123456789abcdefABCDEF:.]%c
;type=%c
%s://%s%s%s:%hu%s%s%s
Port number out of range
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
User-Agent: %s
%15[^:]:%[^
:]://%[^
/?]%[^
/?]%[^
<url> malformed
Protocol %s not supported or disabled in libcurl
%s://%s
memory shortage
anonymous
ftp@example.com
%I64u-
identity
Set-Cookie:
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
<no protocol>
In state %d with no easy_conn, bail out!
Resolving timed out after %ld milliseconds
Connection timed out after %ld milliseconds
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
Operation timed out after %ld milliseconds with %I64d bytes received
unknown
#HttpOnly_
%s%s%s
%1023[^;
=]=%4999[^;
secure
httponly
domain
version
max-age
expires
Set-Cookie:
# Netscape HTTP Cookie File
# http://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# Fatal libcurl error
Header
[%s %s %s]
Write callback asked for PAUSE when not supported!
Failed writing body (%zu != %zu)
Failed writing header
Recv failure: %s
Send failure: %s
sa_addr inet_ntop() failed with errno %d: %s
Couldn't bind to interface '%s'
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
bind failed with errno %d: %s
Connection time-out
getpeername() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
Failed to connect to %s port %ld: %s
0123456789abcdefghijklmnopqrstuvwxyz
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
%d.%d.%d.%d
Avoided giant realloc for header (max is %d)!
Failed to alloc memory for big header!
The requested URL returned error: %d
Empty reply from server
Invalid TIMEVALUE
%s, %02d %s %4d %02d:%02d:%02d GMT
If-Modified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Content-Type:
Content-Length
Connection
Expect:
100-continue
Expect: 100-continue
Digest
Proxy-authorization:
Authorization:
Proxy-
%sAuthorization: Basic %s
User-Agent:
Referer:
Referer: %s
Cookie:
Accept-Encoding:
Accept-Encoding: %s
Transfer-Encoding:
chunked
Chunky upload is not supported by HTTP 1.0
Transfer-Encoding: chunked
Host: %s%s%s
Host: %s%s%s:%hu
ftp://
;type=
;type=%c
Accept:
Accept: */*
Could not seek stream
Could only read %I64d bytes from the input
File already completely uploaded
Range:
Range: bytes=%s
Content-Range:
Content-Range: bytes 0-%I64d/%I64d
Content-Range: bytes %s%I64d/%I64d
Content-Range: bytes %s/%I64d
ftp://%s:%s@%s
Proxy-Connection:
Proxy-Connection: Keep-Alive
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
Cookie:
%s%s=%s
Content-Length: 0
Failed sending POST request
Internal HTTP POST error!
Content-Length:
Content-Length: %I64d
Could not get Content-Type header line!
Failed sending PUT request
Content-Type: application/x-www-form-urlencoded
Failed sending HTTP POST request
Failed sending HTTP request
HTTP/%d.%d %3d
HTTP %3d
RTSP/%d.%d %3d
The requested URL returned error: %s
Maximum file size exceeded
Server:
keep-alive
Connection:
identity
deflate
x-gzip
compress
x-compress
Content-Encoding:
Set-Cookie:
Last-Modified:
WWW-Authenticate:
Proxy-authenticate:
Location:
%08x%08x%08x%08x
%s:%s:%s
%s:%.*s
auth-int
d41d8cd98f00b204e9800998ecf8427e
%s:%s:%08x:%s:%s:%s
Proxy-
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", cnonce="%s", nc=%08x, qop=%s, response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", response="%s"
%s, opaque="%s"
%s, algorithm="%s"
Digest
opaque
algorithm
MD5-sess
Connection time-out
SOCKS5: no connection here
SOCKS5: connection timeout
SOCKS5: error occurred during connection
Unable to send initial SOCKS5 request.
SOCKS5 nothing to read
SOCKS5 read timeout
SOCKS5 read error occurred
Unable to receive initial SOCKS5 response.
Received invalid version in initial SOCKS5 response.
Failed to send SOCKS5 sub-negotiation request.
Unable to receive SOCKS5 sub-negotiation response.
User was rejected by the SOCKS5 server (%d %d).
SOCKS5 GSSAPI per-message authentication is not supported.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
No authentication method was acceptable.
Undocumented SOCKS5 mode attempted to be used by server.
Failed to resolve "%s" for SOCKS5 connect.
Failed to send SOCKS5 connect request.
Failed to receive SOCKS5 connect request ack.
SOCKS5 reply has wrong version, version should be 5.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%d. (%d)
%hu.%hu.%hu.%hu
Failed to resolve "%s" for SOCKS4 connect.
Too long SOCKS proxy name, can't use!
Failed to send SOCKS4 connect request.
Failed to receive SOCKS4 connect request ack.
SOCKS4 reply has wrong version, version should be 4.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
%s:%hu
CONNECT
%s%s%s:%hu
Host: %s
Proxy-Connection:
Proxy-Connection: Keep-Alive
User-Agent:
CONNECT %s HTTP/%s
%s%s%s%s
Failed sending CONNECT to proxy
Proxy CONNECT aborted due to timeout
Proxy CONNECT aborted due to select/poll error
Proxy CONNECT aborted
Proxy CONNECT followed by %zd bytes of opaque data. Data ignored (known bug #39)
WWW-Authenticate:
Proxy-authenticate:
Content-Length:
Connection:
chunked
Transfer-Encoding:
HTTP/1.%d %d
Received HTTP code %d from proxy after CONNECT
%%%02X
machine
password
_netrc
%s%s%s
%5I64d
%4I64dk
%2I64d.%0I64dM
%4I64dM
%2I64d.%0I64dG
%4I64dG
%4I64dT
%4I64dP
--:--:--
%2I64d:%02I64d:%02I64d
%3I64dd %02I64dh
%7I64dd
Callback aborted
** Resuming transfer from byte position %I64d
%% Total %% Received %% Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
%3I64d %s %3I64d %s %3I64d %s %s %s %s %s %s %s
zDOperation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Maximum (%ld) redirects followed
%15[^?&/:]://%c
No URL set!
seek callback returned error %d
ioctl callback returned error %d
necessary data rewind wasn't possible
operation aborted by callback
Read callback asked for PAUSE when not supported!
read function returned funny value
select/poll returned error
HTTP server doesn't seem to support byte ranges. Cannot resume.
Failed writing data
%s in chunked-encoding
Failed to alloc scratch buffer!
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
Operation timed out after %ld milliseconds with %I64d bytes received
transfer closed with %I64d bytes remaining to read
transfer closed with outstanding read data remaining
%31[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz]
%02d:%02d:%02d
%02d:%02d
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday
0123456789
%c%c==
%c%c%c=
%c%c%c%c
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Bad content-encoding found
Out of memory
Too long hexadecimal number
Illegal or missing hexadecimal sequence
Malformed encoding found
Write error
survivalist.exe
curl_easy_cleanup
curl_easy_duphandle
curl_easy_escape
curl_easy_getinfo
curl_easy_init
curl_easy_pause
curl_easy_perform
curl_easy_recv
curl_easy_reset
curl_easy_send
curl_easy_setopt
curl_easy_strerror
curl_easy_unescape
curl_escape
curl_formadd
curl_formfree
curl_formget
curl_free
curl_getdate
curl_getenv
curl_global_cleanup
curl_global_init
curl_global_init_mem
curl_maprintf
curl_mfprintf
curl_mprintf
curl_msnprintf
curl_msprintf
curl_multi_add_handle
curl_multi_assign
curl_multi_cleanup
curl_multi_fdset
curl_multi_info_read
curl_multi_init
curl_multi_perform
curl_multi_remove_handle
curl_multi_setopt
curl_multi_socket
curl_multi_socket_action
curl_multi_socket_all
curl_multi_strerror
curl_multi_timeout
curl_multi_wait
curl_mvaprintf
curl_mvfprintf
curl_mvprintf
curl_mvsnprintf
curl_mvsprintf
curl_share_cleanup
curl_share_init
curl_share_setopt
curl_share_strerror
curl_slist_append
curl_slist_free_all
curl_strequal
curl_strnequal
curl_unescape
ExitProcess
ExpandEnvironmentStringsA
FormatMessageA
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetTickCount
GetVersionExA
SetLastError
SetUnhandledExceptionFilter
SleepEx
CryptAcquireContextA
CryptCreateHash
CryptDestroyHash
CryptGetHashParam
CryptHashData
CryptReleaseContext
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_isctype
_onexit
_pctype
_setmode
_stati64
_stricmp
_strnicmp
_sys_nerr
atexit
calloc
fclose
fflush
fprintf
fwrite
getenv
gmtime
malloc
mbstowcs
memchr
memcmp
memcpy
memmove
memset
printf
realloc
setlocale
signal
sprintf
sscanf
strchr
strcmp
strcpy
strerror
strncmp
strncpy
strrchr
strstr
strtol
strtoul
tolower
wcstombs
_strdup
_unlink
_write
WSACleanup
WSAGetLastError
WSAIoctl
WSASetLastError
WSAStartup
__WSAFDIsSet
closesocket
connect
gethostbyname
getpeername
getsockname
getsockopt
ioctlsocket
select
setsockopt
socket
P`.data
.rdata
0@.bss
.edata
0@.idata
4(/6=D
KRY`gM
3:AHOM
4MV]dkryt]
5<CJQM
4MX_fmt
#*18?5M
_netrc
%% Tota]
Spe9 Time,
ss thanw
sec X
[eset!
ioctl b
U|adcas
scratch bu
#0QkFp
~outst
%c%c==
OK#hexadecim
number
or mis
%sequ^e
4,?O^m
getinfo
global_7
_mem\maprintf
_assign_'
$fdK#a
remove
x*_all
0!\vRvp
slist_ap
4MDTt|;
LXdp|M
44@LXd
,8DP;
$4DL\df
ExitProcess
pandEnvir
StringsA
FormaG
tM&age
Module
jAddrG
5TickCount
wionlter
CryptAcqO@&
CreateHash
Destroy
ReleaseZ
x__getZargWM
__mb_cur_max
__p__ed
errnoiob
scon p
s@Kstati64/
ys_nWCE
ombstowcDmemch
{qsfnG
+sscanf
Dtodtr{
unlin9m
WSACk6
Start]_(FDIs"
w@.i'Ca]
XPTPSW
ADVAPI32.DLL
KERNEL32.DLL
msvcrt.dll
WS2_32.DLL
CryptHashData
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
KERNEL32.DLL
ADVAPI32.DLL
msvcrt.dll
msvcrt.dll
WS2_32.DLL
ExitProcess
ExpandEnvironmentStringsA
FormatMessageA
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetTickCount
GetVersionExA
SetLastError
SetUnhandledExceptionFilter
SleepEx
CryptAcquireContextA
CryptCreateHash
CryptDestroyHash
CryptGetHashParam
CryptHashData
CryptReleaseContext
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_isctype
_onexit
_pctype
_setmode
_stati64
_stricmp
_strnicmp
_sys_nerr
atexit
calloc
fclose
fflush
fprintf
fwrite
getenv
gmtime
malloc
mbstowcs
memchr
memcmp
memcpy
memmove
memset
printf
realloc
setlocale
signal
sprintf
sscanf
strchr
strcmp
strcpy
strerror
strncmp
strncpy
strrchr
strstr
strtol
strtoul
tolower
wcstombs
_strdup
_unlink
_write
WSACleanup
WSAGetLastError
WSAIoctl
WSASetLastError
WSAStartup
__WSAFDIsSet
closesocket
connect
gethostbyname
getpeername
getsockname
getsockopt
ioctlsocket
select
setsockopt
socket
 !"#$%&'()*+,-./012345678
 !"#$%&
'()*+,-./0123456
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Banker-LAA [Trj]
C4S ClamAV (Linux) Win.Malware.Cymt-10023133-0
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Troj/Bdoor-BHD
Bitdefender Antivirus (Linux) Trojan.Agent.CYZT
G Data Antivirus (Windows) Virus: Trojan.Agent.CYZT (Engine A)
WithSecure (Linux) Trojan.TR/Agent.qasng
ESET Security (Windows) a variant of Win32/Agent.AAEF trojan
DrWeb Antivirus (Linux) Clean
ClamAV (Linux) Win.Malware.Cymt-10023133-0
eScan Antivirus (Linux) Trojan.Agent.CYZT(DB)
Kaspersky Standard (Windows) HEUR:Flooder.Win32.CoreWarrior.a
Emsisoft Commandline Scanner (Windows) Trojan.Agent.CYZT (B)
Cuckoo

We're processing your submission... This could take a few seconds.