Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 08627e41d99990bedddab6ca99e6d4f6
SHA1SUM : 626ff8aa9cbdf1d01e104f20f32c94679722df53

architecture: i386, flags 0x0000010a:
EXEC_P, HAS_DEBUG, D_PAGED
start address 0x0093a0cc

Characteristics 0x10f
relocations stripped
executable
line numbers stripped
symbols stripped
32 bit words

Time/Date Wed May 2 22:55:42 2007
Magic 010b (PE32)
MajorLinkerVersion 6
MinorLinkerVersion 0
SizeOfCode 00016000
SizeOfInitializedData 00008200
SizeOfUninitializedData 00000000
AddressOfEntryPoint 000000000053a0cc
BaseOfCode 0000000000001000
BaseOfData 0000000000017000
ImageBase 0000000000400000
SectionAlignment 0000000000001000
FileAlignment 0000000000000200
MajorOSystemVersion 4
MinorOSystemVersion 0
MajorImageVersion 0
MinorImageVersion 0
MajorSubsystemVersion 4
MinorSubsystemVersion 0
Win32Version 00000000
SizeOfImage 0053b000
SizeOfHeaders 00000400
CheckSum 000180dc
Subsystem 00000002 (Windows GUI)
DllCharacteristics 00000000
SizeOfStackReserve 0000000000100000
SizeOfStackCommit 0000000000001000
SizeOfHeapReserve 0000000000100000
SizeOfHeapCommit 0000000000001000
LoaderFlags 00000000
NumberOfRvaAndSizes 799fff7f

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 000000000053a000 000000b0 Import Directory [parts of .idata]
Entry 2 0000000000000000 00000000 Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000000000 00000000 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 0000000000000000 00000000 Thread Storage Directory [.tls]
Entry a 0000000000000000 00000000 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000000000 00000000 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in .dotfix at 0x93a000

The Import Tables (interpreted .dotfix section contents)
vma: Hint Time Forward DLL First
Table Stamp Chain Name Thunk
0053a000 0053a044 00000000 00000000 0053a054 0053a044

DLL Name: KERNEL32.DLL
vma: Hint/Ord Member-Name Bound-To
53a06c 0 GetProcAddress
53a07d 0 GetModuleHandleA
53a090 0 LoadLibraryA

0053a014 0053a03c 00000000 00000000 0053a061 0053a03c

DLL Name: USER32.DLL
vma: Hint/Ord Member-Name Bound-To
53a09f 0 MessageBoxA

0053a028 00000000 00000000 00000000 00000000 00000000

Sections:
Idx Name Size VMA LMA File off Algn
0 .text 00009d79 00401000 00401000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE
1 .rsrc 00000e83 00420000 00420000 0000a200 2**2
CONTENTS, ALLOC, LOAD, CODE
2 00000065 00421000 00421000 0000b200 2**2
CONTENTS, ALLOC, LOAD, CODE
3 00005539 00922000 00922000 0000b400 2**2
CONTENTS, ALLOC, LOAD, CODE
4 .dotfix 000006e4 0093a000 0093a000 00010a00 2**2
CONTENTS, ALLOC, LOAD, CODE
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 4638FACE Wed May 2 22:55:42 2007
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 0053B000
Code Base: 00001000 Size: 00016000
Data Base: 00017000 Size: 00008200
Entry Point: 0053A0CC (file offset 00010ACC)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: .text RVA: 00001000 Offset: 00000400 Size: 00009D79 Flags: E0000020 (CERW)
2: .rsrc RVA: 00020000 Offset: 0000A200 Size: 00000E83 Flags: E0000020 (CERW)
3: RVA: 00021000 Offset: 0000B200 Size: 00000065 Flags: E0000020 (CERW)
4: RVA: 00522000 Offset: 0000B400 Size: 00005539 Flags: E0000020 (CERW)
5: .dotfix RVA: 0053A000 Offset: 00010A00 Size: 000006E4 Flags: E0000020 (CERW)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: KERNEL32.DLL
Addr: 0053A044 hint: 0(0000) Name: GetProcAddress
Addr: 0053A048 hint: 0(0000) Name: GetModuleHandleA
Addr: 0053A04C hint: 0(0000) Name: LoadLibraryA

DLL: USER32.DLL
Addr: 0053A03C hint: 0(0000) Name: MessageBoxA

M:F<^y
>#tq
_ l}1
lc)?
lXLQ-
Z7YH)
kz9_
hX%{
TA@*
bA[J
)az&
ZVBg
BLX&
sj3d
\ue.
!_s"
3K:
.\>4:
Or2.R
v.MQ
/4\"
t{jH
!A=UH`o
v]s3
F3</kk
jGIY
c[)=
:T/K_
}frX
:tdN
#^R>j;
#nT0Y
P\7{
*s;g
WI7A
td`Y
XRBr
$&@4:
[PMY
{<zzE
VM))k
4'0<
;+ce
"5 x
[k-I6 X
aViy
+{l8
i@k~
qWTT.
i);G
`#x2
UTbR
n]H;
6XGEb
3k9}
K ]*
N0`@
H#sE
;$el%
U]IVk
.n#)
s+?/
r'zg
LC/|
1xtwr
UY,K
\zon
L]D)
^0v+
9=$M
DLK'
A(xSk
yFhc
h 4'
"nw:
0B`n;
`V'5
k-6%
RZ}]%
hhYYv
k53&
;8@c
Bv'K
BK'#aa
Q\-X
MHW;
c|ST-
p\aaO
c(;fk
kOC~
eg=w
DohK
aBeg
ZzCw
zc)^
o-K"
\rA=w@m
f1)z
vf5E
q^d
M-x1
3d?PW
7W:*
( J>
g(%\
L(Vp
H"G9n
?@]k9
X%)(
:M)s
8#c>
qM6jO
7D$A?7mX
3~v.r
79.Yyq`
#,h8
HQx_
{`*4
R"xJ
U5R+
9:?|n
rMf?
D-4N
)1PbA
Kks@9
=o^n
N#"b
;)Xo
f7R[jI
$l_I
n?0{
lO2Z|
Scp
?#oE
$mE5Q
Z:rn
b 6u
tn A_
!XSo
Xseu
)yFa
Wm$
`o~BkIO
zDT+z
{zCq
km:c
%6'T
(Uy&
K^m)
=X_d
XKRR^
DL<!
L-5IM
4"]w
&k?b5^
J[H#
!Z(aZ
BO@Q
PwY^
U%sX
vFNd
<5Yw
:^OF
8@qJI
PnJN
9 8L
H]~#
DUN4
X5V*MV
&RF{
^QnF"`
_5?!
$UW[
A)fS
Kn=_
|^LS
=#_w0)
}\/`#sb3)
OaG
$>od!
3BS E
]`<X*
xo(3
/e]P<
H K;
Q^M^
{$DR_
~hJU
nCX!
u<Qe
+}D6
}pAh
9fV/M#
I6be
`(v"
r8al
qVdL
IO=*~
xB%n
XJNex
IA]Y
V*'<7Z
i9)f
[jJU
h#PR
V87G
}d0!L
u>yA
R;0+Q
?\!k
!|8F*
X x+T
pir@
r?UYI
$9>$%
9RKa&
'[y~%?+
@)4K
Krze
V`el
{'7U
C7h@
WSA/
O\;d
Z"+_
zP.:
\oWE
t<:2I
@f$^
#Eo_7
)|q(
p'q=7
R91K
6~Q*
g=c\T
Jk{8!
24|m
06SF
UQ$F
(X,(<c
@@HH
@@HH
@H@H
@H@H
J&d1
c<D]
@H@H
@H@H
&6a);/FTC%W
yIN4j
#*M-
ePAP
z2#bV
R/?9
G)tQ
AM|N
Z@7P3
='6Ox
oIfeh
hw(gm
K Ns@
>\<:
t|hr_
8&9hCn
(cAsVKy
S,`r
eU0dZ
$ic+2
HovQ
vQ|B
w*%Yb
{s }
ccIG
j\Mh
T]>T
Ucs[
c\r];
we) w
gBgF&q
+ELW
oo.{T
U.XVzj
!i)u
;` @
XK586jN
f`jV
O'19
%Dv;L
X'YO
v"E%
lVm.
>O!1
6U}Ut
\c!$/R
|;bi
Iy7 5
9`E1!
HS*e
NPc$
+u!)
EuR
BD#
mGzp
6sek
Fk6W^)(P
gs]N
it<e-6<W]2\+S7
,qX9
{Y*|z
QU|4
&'//
yd?J
5kpP
UJ&Z
=19s
e|\n
|B>H}e
I;1N
H<Hc;
C@1ld#
"@fNB
7@UM
Au*l
A:GNT
`A5a&8}
n$oe
"H#D
r'NB
qQ@-
KLv|t
:b-o
jBoQS
_d?1
fdNX
d}hE
57hf
/#Z\
>.Rm
"LAC*
?G:&
Nx){
KpDS
Jwt
mP&~
o1XS
S\=,{K39
B#D1
Zl_'
fmLJ
\$1~n`
}Y\T
-ftf
e<0i
L:Yv
x?cz
o-NH
Xe\/
kAh!
(rpZ
cpSh
ylSr
:UDf`
hEF#
*S)b
dx*o
!p{Q/
GY$b2p
d;^.
Z/Cw
QeAI
S-ZE8
H6!3
>Lf'
wo:j
h?Et
}gO#
E_-{8
mU?L
EcUC
KLe2
AZ(-Jr
~<0@
pD1=
WP$2
i24?
AE}Z
Va@QB:
:$x}
Z Uz
[>~E
`<XN
%@Q(
-j@M
9;,Ca
el
+ F
J3K:
-C+`
bO,Gq&#
vB-c8
W_UH
hptY
%d~:
22(h
.56+R
?43J\
pwmd
=dx{G>\y6~
Fg\id$
](3_
&F,Q
-U*::}T
F:|=
<L5"~
^b21O4
NX4PL
4#"9Q
!><o
\U|6
;j3z
psQN
7x)T
pE[QP
<'P5
6I*?
ibvZ
M%GC
HU@U
S4O:
S_-rb
;$3v)c
!R%I
!gcV
mzp_
{e}B
MM)=4
HlO\#S
ODC+[
iKVS
[,M.1
Z{Sm
/#J*
A2y/&
TC$Ev
KiT,
D;!8
lkW@
G-=-
#vBz@Mr &
nSsr
, yQs
)I4`
cuo9.
J!d_
\Qr@?
f'F'
?*/Q
FzgBq
/~p<-U@
\VR|x
SAxG
JATY
cx#6
wbS"
YBCtM
3|8q
kDf|$
$&+c S
jL3L&~2
9a8_j.2
kern0l32.ud
Lo|a
i;brr8yADG
etPOoc
tualAhh2
MSVC+RTR
ER)v
Fozg
undWi
Xw-ADsV+PI
EnumV
SHEqL
cuSt
u4<E
AoJd
: xs
a)H+
$ub6
0_'V?
=D^*
:~g}]?
/17_
a@@p
_|phK
`nt{
}4p@
t5;*
I ?W
m;2=
QRV>
YRK>
C0QNz
PpEQ
tDR/
Zh0lo
6Lk$
v[Pd
M.J9R
-\os
on er
Th}e
y5|l
id|SDqL
H$an>>`\p
0MzI?1
([F#6
d.BA
j7@h
83aC
kern
l32:.d
Load
GetP
oNs4
`cMGag
5!L]
S-O
_@*.
*dQ&?:-
C)$+S
cW/+_
X AU
M@KG
W7A?
$}Us
XJ?H;
/T0-
$% *
=:J
K&*]
Z9S
G<W Y
8<$\
'DEI
Xi$Q]
O:#U!`h+
&N4
O0E@J5
X DF^
V8\'
1G6O6;
-,K_
QCR>81
JSBMN
!:M5$CIf
bTS'6
`]\+@
7$^Z
RVJKH
@JQ1\;
+%#(]
+.\Q
G=&X)u(
> ZO"*?
aJ1/9q#7
I8^+
\?N4
*SDX
RJG9S<]D
A`lT
R@c[-
,=7 O
U.VX%$
,$<{
X<(2$
60,>7
5G*3LWDQ{[
'@`#)IFD
Vl~F
M!Rp
Vb`@F%
3G.W
6+K,
/H$4
C\VQ>
;? }
QWHq
SZ=Y
-N5_
-#ux
:LU#*E\I
J<Q1
$V[N
P"b?
1UJ"
1BP=[3
" IrM
:'d9
M]>EaX!
5b^N{
U&9&
<9&b
[MO9?+
34EP
=8UF -
<X\:
]89O5
7OQ1
MtK9
@2K-
R=4Y
+A(#;6V
:;W4U`
?I-N
#S'D
2^K'
!=7d
$C "
C1Z7>B
1J4dU)8
?P *;>
M^LE_E
6q%N
:Z3+
c/7]
W3)^
4R!J
G;2/`ad@^";
$D@c
,`0~
%cA3
\*aY
a#TC
a"zY
`A)f
T%=;
@FVP?;%[
+7I`
5c!SF
Z\$H
*&/@b
4JQVTh
~JXa7
&2KU=A
;[I _
->D\
>ByKu
)KBW:\
Kq_S
cH;/
Ny-mMe[[
L)V0J
)CE-
93B
kq[v
-NcZ
(0&YBFZ
WFa=
6Br,x2qQ
)?<(-'[
R0CMXd
U)('H
G;bZ%
M,U7
c:P%
!" SC]
?[x8v$
.GSL
M?6bx
#@RUc
2^"[
]7H<
%'82
S4#"%
-`(O
ZJ"Cdb
"NVT]92/
@\2SC
kUO[E
#KN*`XBZ
a52T'0
HFE%Q
&)XC]J
_d$-%a
2]b8
%>dQnVH
K:.T
.<5C
p*I\/!
c^9@
_ S7
R!OAS
L_y-
*]IL
WNJK
.OM"PT
cH$2Y
V6SA s
V8W!+
dR=(
E<Ze@
OS;|U
c`*&
Q$L;+
+EbV
:S_r
'Q"&n(
%]9WM
Pb-JG.F
\6#(1,h
>LK0
RAO^
*2K.q
}G->4
E:6F#
`]Q1-KHXX
ST,\
AA_ Q
").A2-
c!K8BG
(,2MP
H!Sq
>ofJp
b'=:_+V\s[
*W;C
$\&3[
6Q_[
Jjy|
6d@Z
4C1R
*?Hz
E/5UE\
#-"!
PJL%
]4BEH`
9#"T?q
:-AZ
$](#V
?bC3
IgCX
?#^=
EimC\
sEW,
ON_?E
/^#Pr
H0-.;
#@96OM
U%\
]Wb9
<a>S
/DU=
0 N:
0=[,
L>AZ5
1`M'I
T"HB2
_-b
8 3XU
c.aJ
123LU
`OG$
2a3J(
.0Z',(
eH)U/
D5/[Q;
CEIH
PM#$
:E`1
]&["8c)
W$vE
^F-L
bX@`>%-
C7P<
WRV3b
1I\Q
5=.W
:ZPD
"[3B:
K1 )"s
,^%J
]J5a`
85V=.
%(6$"5
)I^3
5&L43Z
8^Q=E
*7 :UB
ZA/M
.\bF"R
@_Ys^
*SV.
J)="$
E'D<C&C
IZN`
W S=J;}{
XK%5`
c^ L
uE [
XavH
a5M/
/`XD=1
2>[
>(xR
0`[Q
; *b=
0:3I
C\<BV [
,/b%*Q-Lz
[C_*
a$LZ
47\>8%`
]SU@b
H7BILCW
X A,F
JGAZXb
2J ';\u
N:)+
"^?];
/d #
_Q][D
`@N+
Q<1.$
62>'
]DJR
P$";G.L&
=S:W
R3ZK
V$]>
+IN3q=
1N+:
,1NJQ
&:y%
2FE#
2 SA
a0%*
-|}_
sP/'
QN^Z
,/<0V
U6: Z[
@]0G:rK<a%
W0JV
<cQO&
<8KWC
Ja] xI
>U&=
R_9[H/B
dMf09&
G=~A
p9=@
:6B@J$3G
3E J
_ZU5
+HtJ8D
',C0]QG
01AN
Z;+ I$1cx
.#(0
F/?Z
]+L,
9H=<OQ`DN
V>;M
50D>
\7CE
C@:17]
qK<X/
1-XSD
;. XJ
4COG
^,X]
'?*F
^;%43,$
e{Nq
LH>0&G
P(XN
/=XF
%`Da_S.%M)]?3
$iwG
7E 9FU
RSP
QXW*C^x
&G^N
Q1
RM2zI
95J1
:^ER
&"V7/G
0WA0#
DU V;
610C9
V1X]`
]F-a
5:>~=
Q @<?NK
!b4Z.9
L9&ZU
`ECr@ F'(
]$Rc
Zb<m
/M+C1P
3_LEI
_yf~
:>_ 1!
QbT
9>`]PSd
& V0T
40 b<
>d3J
6J^{Z
a9?U
P`]2Z
N! '.
%`_\
=!6H
\0T:
`Z="
N>!3
+`:N`5
U^P.I'
.y@}]O
&VcP
8Q(!
dg~R`7
-QOP&1::
1RVqWs.
!UA -M
?wRt)
|Ru'
h@?I
c[$!F
6 :E>
Qq#
L74N
V(J3/
D9<>
E1zj
MZH#i
*=P^
[ <-
y"Q](
G"S]Z%
P@O`3X
0:1N
_,?Pc/
b<TH3
26[5
I&8R
X`/ 4
%-LU2
+c[1
T!:#
Oa-%
W?1v
c M6
c#:%
$ NaIE
]',(U-
$<J ,_KL
k`Za
<$._
P2=!
^1(?
Sc8V$
)($SN8Z
)?0c
_<[X
6^H)-
Q#XS5
^EG326N[
30>D`
B]\L
UbX3
#(!HG
0,.tZ
I`48]
_ DN
H:=*
,GW]UN
!PA
1J2?
^QP/
=8*B
KM:_
\`5?*[<+
8;4
FbE9CQ
IF46d
Kcx.N3
Vz b.
'*R:<
7KQ5YG
=_!@
k'a_
7@LZ`PV'%['!
E%q6^
:h:N
*#2,%Z
yv~N
[#%"
/158
'.I*dK:MT
=%:,n
@03H'
(0&_%X/
+@-F5qbK#
cBT]
:HI!SY
N6IB 9
@2*;[
>\,47
Sz]MP
RF`'?ID
D)*<
D0"A
;O$:
N4/<_ M
yMGP
"8MJ/b
8$GA
>Q]
P0BC(9\
1!XY
<0OJ
urqc
yT/
't]L0
!-H'
Tqys
zcKU
P)2E
`m%Q
[>/Y[
G0;/Z$
>5sQ
$S'PG
UTB0
9<3E=\4
Q@G4LJF
L_EJ
p91Q
aC+H?
<+bXR
4>`I
?)@_b
]4Rq=
E&T3#
?&BG; RCZ
A8UT/
69"K
95A0Sa\
B[ !JDR
+L.a5D
47H
<-]$
Q&2#
b*2I6S
M"X,
,\^H
A ZR4
"_/RF
g|>u
#`U_5:
&^c:K
F1_?0Q
W>XQ
<B.8
;'+@
D;*R0T
@Wqn
R`CQv4x"
<J/7,:
%,ObV#
BM3x
%!ZO3<
+:?"
C/*.RJGK1
1?,d
-OL>?
)U$J
_?i_
S/bT
6% -:
&:F>
_I;#
%3 *
`1'+5
$`aDwK
+, LX
UQ=@*
q-T[
O 2L
<HKG
dI63
:L%"
l":9
A X,
52=GO
!8H&Y
>?W%
T)Pc R
)ZMPE c
Q48YJ
A?>QaK
XQc/
b+1
`|:u(:
_ BG
q,r_
75C\
<$FIKH
7:P&
.F-H2S7
4E(M?T'P
_z$
JI\U
1a-A5N2
$6 Zb(>
; ~#]
@]XG
D."Fz!
[4A#
QBRc
bJ?\S_
.\\Ek
E_ ]&\7
Q2/=
-S_T
yVx|
8?GT[
A;X>>N<
E4K"+b
4a)_
,/$_TZr+
@: D
;RP6
Z %r[
,J;_?
a17.=c
9 6[(
)34/Y%
1=$a
8[J!2
rQ9ObJ
.'V
oh\=
)*_V
!GS]J
~]%+]
$(6:=
_\>_
?y:1
+$D:CG;
E<;S
V76 W]!
;=sL
@=/L
J2?_
-Y0)
&) 4%a'
"K+RJ(
Ab\H
9<C^
K06V
^E:!
>%3RV
|X<6
G K&F
'm]?J'U
Ar0
P4J@
9]2{R
3"DT
TLu"
KERNEL32.DLL
USER32.DLL
GetProcAddress
GetModuleHandleA
LoadLibraryA
MessageBoxA
GlobalAlloc
GlobalFree
+|$(
t$,j
VirtualAlloc
VirtualFree
KERsN
L32.D^
GetPro
cAd{zqs
Han|
ibrnJy
RhH:Y
AZ6G*lf?
j@h'-
D H<VB
Hy:9
QSVW
Y_^[
er c,a
PExit