Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 0a0261b96a5602e80df5390f5701d3e4
SHA1SUM : 57374ceae40e363e5f133938ed4808bac5b6f783

architecture: i386, flags 0x0000010a:
EXEC_P, HAS_DEBUG, D_PAGED
start address 0x00432bfb

Characteristics 0x10f
relocations stripped
executable
line numbers stripped
symbols stripped
32 bit words

Time/Date Wed May 2 23:26:08 2007
Magic 010b (PE32)
MajorLinkerVersion 6
MinorLinkerVersion 0
SizeOfCode 0000b000
SizeOfInitializedData 00001000
SizeOfUninitializedData 00016000
AddressOfEntryPoint 0000000000032bfb
BaseOfCode 000000000002a000
BaseOfData 0000000000022000
ImageBase 0000000000400000
SectionAlignment 0000000000001000
FileAlignment 0000000000000200
MajorOSystemVersion 4
MinorOSystemVersion 0
MajorImageVersion 0
MinorImageVersion 0
MajorSubsystemVersion 4
MinorSubsystemVersion 0
Win32Version 00000000
SizeOfImage 00034000
SizeOfHeaders 00001000
CheckSum 0001b348
Subsystem 00000002 (Windows GUI)
DllCharacteristics 00000000
SizeOfStackReserve 0000000000100000
SizeOfStackCommit 0000000000001000
SizeOfHeapReserve 0000000000100000
SizeOfHeapCommit 0000000000001000
LoaderFlags 00000000
NumberOfRvaAndSizes 00000010

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 000000000002a000 00000110 Import Directory [parts of .idata]
Entry 2 0000000000000000 00000000 Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000000000 00000000 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 000000000002a110 00000018 Thread Storage Directory [.tls]
Entry a 0000000000000000 00000000 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000000000 00000000 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in fzj3qwht at 0x42a000

The Import Tables (interpreted fzj3qwht section contents)
vma: Hint Time Forward DLL First
Table Stamp Chain Name Thunk
0002a000 0002a0cc 00000000 ffffffff 0002a03c 0002a0b4

DLL Name: kernel32.dll
vma: Hint/Ord Member-Name Bound-To
2a04c 0 GetModuleHandleA
2a060 0 LoadLibraryA
2a070 0 GetProcAddress
2a084 0 ExitProcess
2a094 0 VirtualAlloc
2a0a4 0 VirtualFree

0002a014 0002a108 00000000 ffffffff 0002a0e8 0002a104

DLL Name: user32.dll
vma: Hint/Ord Member-Name Bound-To
2a0f4 0 MessageBoxA

0002a028 00000000 00000000 00000000 00000000 00000000

Sections:
Idx Name Size VMA LMA File off Algn
0 UPX0 00016000 00401000 00401000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE
1 UPX1 0000ac00 00417000 00417000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
2 UPX2 00000000 00422000 00422000 0000b000 2**2
CONTENTS, ALLOC, LOAD, DATA
3 hjohnhn9 00000000 00423000 00423000 0000b000 2**2
CONTENTS, ALLOC, LOAD, CODE
4 fzj3qwht 00008c1f 0042a000 0042a000 0000b000 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
5 0niaacah 00000200 00433000 00433000 00013e00 2**2
CONTENTS, ALLOC, READONLY
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 463901F0 Wed May 2 23:26:08 2007
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 00034000
Code Base: 0002A000 Size: 0000B000
Data Base: 00022000 Size: 00001000 (plus 00016000 uninitialized)
Entry Point: 00032BFB (file offset 00013BFB)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: UPX0 RVA: 00001000 Offset: 00000400 Size: 00000000 Flags: E00000A0 (CUERW)
2: UPX1 RVA: 00017000 Offset: 00000400 Size: 0000AC00 Flags: E0000060 (CDERW)
3: UPX2 RVA: 00022000 Offset: 0000B000 Size: 00000000 Flags: C0000040 (DRW)
4: hjohnhn9 RVA: 00023000 Offset: 0000B000 Size: 00000000 Flags: E0000020 (CERW)
5: fzj3qwht RVA: 0002A000 Offset: 0000B000 Size: 00008C1F Flags: E0000060 (CDERW)
6: 0niaacah RVA: 00033000 Offset: 00013E00 Size: 00000200 Flags: 40000080 (UR)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: kernel32.dll
Addr: 0002A0B4 hint: 0(0000) Name: GetModuleHandleA
Addr: 0002A0B8 hint: 0(0000) Name: LoadLibraryA
Addr: 0002A0BC hint: 0(0000) Name: GetProcAddress
Addr: 0002A0C0 hint: 0(0000) Name: ExitProcess
Addr: 0002A0C4 hint: 0(0000) Name: VirtualAlloc
Addr: 0002A0C8 hint: 0(0000) Name: VirtualFree

DLL: user32.dll
Addr: 0002A104 hint: 0(0000) Name: MessageBoxA

[6YY
B2sR
=v{8
9wNM
t#"]
P=+|F
~_BY,H
7uEnDX
0v8O
NKpr
?ng_
K$?:
@0~S
UX^LSjY
Pwt18
8pg0]j
>tNj2
&&[xl(
,fjD
V !F
XAR1
2[4h,
FN+h
6l-d
~YJz$
+vX|l
h4{
,.@DPI
g0sW
6exa
RO,3
;-vQ>
P%3O
$r,!
a2&(
[`@j
mf d
u%"
/uW=
2&Y73
Mo0|;
hP ,
@P$I
FR+a2f
uSaI}
Xmy!
:"TWn<Y
fO3IZ
i9],
T(y
1\'|8
h?mz
fX4r
Bm`E
6PB8fT
]B-k
4&&+
Cned*
hh&X
X<\$#[
5m X
r /h0
LD@>Z
X2W(
tdl$
X7`!%
tM4R
x]/">:
*u]h
P1@I
C0u!h
vtA\
QL6c
~j2#D
8LN.
&P&&
tX^,G
Iddd
)H9(s/0b
pje7@
]r`#
B0Tr
Ch;,
:Fa3Yd
\F,rx
!#XXXG
rXXX
+\\;
sc}`
/DF;
*9rH
d.XJx
u?yY
t=3<
3MD6
!6@@
]2rr
&g'lX
,80r
$;'r>%
C:`gX
s{1Er
Q[6tyn
`@k/
(9J}kl
"E:d
@08{YA
{mVv3s
&Gg;,
96}m@/
4UOjB
p|.h
p y&
n'4Y
\qa%bF
!S~sKC
g8~U
~k.]
6,|<
Ijqj
8BET$
x%(f
SVh,
-|rb
;AsQ
C"x
]v/
'h"6
jV3(
;T/ H
;l2Y\7
1uU1y+
AvT\F
reM$LR
"D4xh?
Wa=^
0<nz
l?a`'
Z0On
#:\M
IzTn
TrG9a,
vI{QA
ktfE
)n
4qdB j+B
1(9K
4wXX
5 a$g
gU!#
@Gr,
YT8
hMv"
0OwJ
%#:3
q8;M
;[p7V
PIsH
97*6
`,tn
<d_,
CO:
;m7Tl
3"[2H
m>;i
DnIn
&hT}
;X'
"}Tc
T636
e{`K%0
r\Iw
u462[
r2V$
+L8+=P
NtdT
y+"s
z6#
lBbe
qNO-
hxD|
CGt2
*t-i
=j7U#
C;5Bv d-
sIA;
hp+h
O`eE
hl"*
]HH#
SIPv
K>;#
hhs?#'hh
-a*e
PUM6
"Q8G
8 U=
jE/W
}zfYWX
$0''''84(,
IZ0<
NWOhr
sD^u(
gVM!N[
v8kZ
lO0=
m %7(
l\? #u8QyXS1
v(f.
5|"Xu
02Cl
97u
$d:E
t'0%
&rd{`
%+$=
0#-
%ly!
Dl)%
7NAp
sSF
raGr"\
VX0H
I+.y
SBN C<
7 odc
V/t Kb
8d@&|u>
d@;<
%O>'
_#R(
`(a2
;=0r
"em2
NDH
h\C^2
= Cc
,(N;'U
X@lv!c{@4
[Ye'
E<;@.
#8t9(
+(=v+
7PmN
Gw/`
sht#x
<Ohh2u+h
\;+d*
dtXu
(rg*
d&6h
#[HF
Jy6;
F,Kr
la.9
5ZjA
; xm*!-H
!@z_P
J&dB
5!Pd
0h,vY
M QUQ%O
#&j9j0r
?"?u1+
d+rv
8iI,
yr"yp
h[a
HiS2`
L009Vv 0
t30y
!{-u9>z
ruZt4@
r>u)R
#Kg'F
2 >(
;MiU
@!@uU
6<!G
[H S
\#_i}
?"<i`sx
%#\*
]VlN
(K65e
{#Eg
F0fQ
@r5`
PP?;Q
QZ^&
og$?
35rX
G ?9
nD")
<_J8
*J~r
i7$=
2$C
c 0.,G
="J!
H5Pf
>\q2G4Y
lFui
2$cO
!cC2
9D j
Tf*y
`/r`
Pr;Q3
d*y2h`2
&u\:
h8s
+,FL$*
&C.Lf2
lA;-
2@[I
u5:=
bQWp
r`sxAhp
2!C<4
0+1r
a$,J
Bt+Y
t<r{lE6P
P:vkH
ZHQ/
PQHo
I1k}
<8mG)
)tP<
0*6'P
jEa
*8T{`
E/Y+
P_6Up
0z8a
$lFQ.
P)$
Pm@
V/l[U
9l"lVMV
;#tX
|dz h$
fx[w]
p>[`l
p.+T
*%s;(
"0y?
iBUJ
%+b'QS
lu%Y
E$*V`
0X@"h3}
KhT3Y
+&e9
EY^2`
lB#3
X,Y@
pfa!
v0pA
*?,,
JdGL
,$a
ut{a.4
Z'pn
+yYV
l6m-
)] !'
^sia
D)za
<Yo#;
lr$;
@{"N f
?{ 5
g*o+
49zK6
JO(7
R[$E+?
^Q<E
1( #
/QSM j65
#[#H0
4q,d
,I(Y
<3d(L
A:b1
<F&dd
KF&d
&8I,;4
k@t(
e~>E
XB09
0*mX
E%E0
ghp!
l /$
R*[g
8'4-{
<W1'
F0Da
tB,!C
u3y%
2!>q
;cl@
F*uX/
+i_$
|tV5
B(ld
QW.M
f@3u
dkx;
htph
EFFxt
Q}/u
=OL$]
pMlh
VC2`W(3
TFFFFPLHDFFFF@<84
FF0( $p
Y.8s
GdWr
#p;{`![
bot(s) found with
string !s.;l
)x-- Li.-
Kill
Cmd.exe procesl
;has terma
lnV rea
+m0!Cc
r}hfO
c,ma
RemK
2fhRvk
?open
Qivu%
0.2f
3KB/
wb/S
sf< ofJX
CC!END "
"!d$b
<7Ke
GET /
HTTP/1.0
Hoi`$
u;s!
downlo $sn
{art'Suc
lyXQ|-
l46h
9$ftp:/=!X
]Z`y"usC21
803t
(#04Q
Modu
K[AW
c|sh
IFLAGS
EXCEPTI
ON_FT
STACK_OVER
NUABLE_
_DIVIDBY_ZFOC
IL9GAL'iRUC
BR*KPOF7
SS_XO
sOTHg
netG
ws2_322
WN|^
AAHm+KX,
Sche
Job&
/piBuf
NhiI
3c c
I 11r
10.yv
168.
27]`
A08^
%'p-
02XG
HKUS
LMCUR
dT4
+s\C
V+nu
sp\R/@
8aga0
kgO 8%
]cbat
b623#=
6MT<
\?pvl
diPU:
ySh=.Z
ARDW
2003
]98#T
X+wQkY
K'p+
qWRC
Q\GTo
T Fqs
cd-V
btg'
ICMP
U6KVL
cmpCloH
DGOE
> [< pc
43sQu
q&_h
\*r925{
Nh,X
ipv4 g
TheJ
_Fc db#
8Cv$8(
`"#&|
V7CY8
sPART
Vc7_
G<B`
OvB~
@w;b:e6_
mN;en
KWdX
@~ a
W"Jcf2
<rly.7
)6#BROKEN
'yZ&
f128
en=c ##3A
PRIVMSG5T
!=$/X
$unW
lps
cSSNOT
0451
g +xXx
ig01
?1`R
kltP
eggd
)4:$
BC0FGHIJ
$$PQ`TUVWXYZ
:gcjkl
vwxyz
HV}89+/C
MEOW
sC2dC
$C2$
s`[X
o`5U4
}uu@
sA#7
SMBre
PC NETWSK
OGRAM -P+
M#fQ
3Ra'M#2XJ@0
NT LM 0
i^KR
F.w0
&,@(m4
TZ&cY"\ k
@O|p@
'$Y[
`ck+\
I#$9W
hW S
O2Kp
\P]E\
xr!W
VHOD
/7?@A
"IJKM
`XPM
4MD@<80(4M
d`\TP
8;0(
0?( g
|ph`i
0VKx
80(]
blaw
p/kia
Lh3a
=o+sqlo
love
moneyslutitch
z?_uc
e3gN
pqazA
xp2k98%
emP=
pI%`
41-re~
z'pwO
ms\A,k+[
s \0
m7A$j
\rdAh
D] ocie
#cij<7
ibmco
t6oig&
.3up
53ky
kerR
x 3
fh 1024 J
[g0:
drwxr
m$r'(-
k150{
/425K
57 "/"
#_331
FTP #*
(HTi
^$(f
c0`Z
i* 3
Eamd
AtWS
[&{Hg
`j+$
)OAp/7
IIS/
(X*x
n*0E
);s""
NPo]
,Vb l+,
Z'yl0a
6 s(
0YHc
rumh
{a[<yA36zA4
8dEhf
ghGRg
h5UlDv
FXP\si
SOlA
?bpX
%[!E
P<=%G3D;
[%[^]
KC;3
m+Se2lZ
IE:A
.xoC
ewMSN E
819c
5e7ee00cO
'd530.E
d%x[
s{vC
kI06
r'nr9H
ZqS<
A|thrr
E03C
IC aQ
u-cl{@
_ Hn
:MD
ifyP
M3A0
Sp/L
IdMH
>Hu2we
MS"{3(
x%x3
.?AV_
W`jG@
Loca{
SNDi
f["n/
Libra
pydLaJ
Wri~pp
Pip|
-[0
PeekG
j2DR
9CaM
mapViewOf
mzbM
uBu<DAbj
k1:qu
I/EU*Du
o]Y3L
MmpVa
9Keyh
PrbEmn
nRam
'j??1
UAE@X
lvsn
t2@YAPAXI@Z
3{X{
G%_b
k1\ Y
vv_h
izfh
6ucsn
.[a8ifsT
wAlp
G@cN
`XkI;^
MNh)
eYp 4
WSAI%
@.&'
0hFv
kernel32.dll
GetModuleHandleA
LoadLibraryA
GetProcAddress
ExitProcess
VirtualAlloc
VirtualFree
user32.dll
MessageBoxA
$]0~
\$d7
JC2a
0yBD
7lu1
mgm
)-#k
S%kyFh
w=~=
xj$9
=459
CuHF];
>q(EA(
,`%I
^9g,
;x"=
n81-
`_0v<t[
Y$',U
f/Q^
*/|o
]AOk
"E+U
6+Zh8
-(|m
p)! j2
yyb<w&
mP>A
UsfS
?d_$
7 P]
%w=:D=
%@ W
9,y2
v.E;
33>f
$4,v
QZ5&
_bYS_
$C.`L
\ei}
x aJ
% RW
8dZZJ=6
9@ wt
LUb?
*&PD
MG[[
?F>u
6k 5Y
tI13
#QgOa
{A%-
c'qXt
*F-:
T!(|
X1~s
;B0l
~6aW
bf6{
J"ex
>ppl
#+!C
ji9h
P&TW
_a%Y
%'$S
ykm%
?09K
P-6D
0h~_s
faqo
&.q/F
^!YK
jzVpZ
Easb
8o~>%
x>,3
c\dw
R^R=
(FgA
8YVO
*.0A\H
/-?]
z^J@
Z /ub
NF*b|K
C,tz
S;U)7
}P`x
GO+5
DAtO
SwO;
u1EMB
i,CS
lRvu
QEL*
wIJ@^I
%*3y
}U/^-
mYL<F.;u
T%;d
SFZ
+,2G
R;.A
FCe%
>4]Xt,
N;ZK
*)b7"
RkUJ
`txj[
=u0@QD
KX >)-g
V/u
Xs9
g "$
Dr$<
kg}g
J%LdI
%v}\`
qQqp
e<VZ
UmK|
bo#Y
+ t%
Tg(!
D{^;
+!^'Z"o
0LJ7z;j
?0uP
r%Qm
W<9r
]u%_
{%l#w
eU@KgRn
1<CS
`m"3m
;8>x"
#r1$
^wQ
Zm)"d
9A;`m
UE&rZ
QU~!
3t=p
Z`+S
r:_Z
;"Zdks
_\qf
\z b
D/;_
v>m^
u/\_
[BmN
A!xI2G
jlB
^/l
O)zv
evzZ0
LWtn
sR6C
=% p
>8TQ
qmNE
N+D;
8#o.
Y!oG
3Wq25
nk\X
9xo<$}
$;Z+
v?j\9
~zBl4E
ijn-@H
k76q
s$%ow
| +y2
e0.
\ <:t
We4@
aEp7
NRUP58
ixor
Zb z#
gHcQ
:$Aj=
a(ik7
n5e9
;-r
I61c
]}`_
J9'EV
dGUom
(hrp
uh ?sQ
PCB,
S.U$
U)Q5
9_}{B_
NU5W
-b^VSO{
&o>H
6 $S%
h[Kn
43ZW
yZGL
Z16'lU
Gp$V
o/<^
p@?8
sPj'
N wE
AAX
AAAAV
JC{C
?kq9}
{E<v
Ap;K
EIpe
u(l=
)P>L
=p/-k6
b%1(zh
a:_H
PdCU}`
svBKiB
:xW9
by%m
e Gd
LJGk
AFa=
#q!C
v_7N
U25z
*Er(
1[RD
|_aA
zLl>
[M$^T cRf
-XX-
yx ?
t:Z6
=k+#
t\Z<
`a[Mi
Op5s
:A35DI
eS[(X
+G0}
9Bmf
7^Q2
0G5nh\=
D+@O
J1b4
&KZ;\
KDkuW
.c`l
G/!&NM
j Lo
Us >q
Wt,l
u'\4
uc t
'T@;
}u`@*
>0.G
az!]
kTf7
XgOB
^v$H
~*ezI@t
41^#
}Vbu6P
5dc%#
S[zqt
O"E9}V
dBWz
ufR}
I!w3
_:Ek+
~x`F
ay%V
mT{
> V'
(2YZ
G>pV
btSWl
HJ F
sfj}
b)`~
e:`8
1D_|
Y.fY
?RxR84{Ml
#6?H
?}4Z
E:|ZR
SpN[
4W&
Yp+`
Eh?~QK
%*|z
Vgb5
_2F0P
'eu2
5De11
{E,5
?C!Z
>v UO=q
IJ#D
s.fJsz
_{w&
*ffj
K\=E{
2vz`
O5kbH
F29dV
\{UM
P+]M`
LuX;
Pv:-
Zz`@
LcM7
HXC:
P;c6
Zp_XoTH]
Lytx
X.Zs*YQ
8Ah$
>?O-~
-C)$j
;C%\l
=.5Y
5>!<
mR|VX
~-KP
eUG[U
2z]8
HQP
?^J=
;=+|
Ms)u
25.Z^
7f<5
*~H{
=ab<K
SGKa8
3=?F
k}II
=E]Lo
p9Lv
]wmF
oo@>e
BCSf
ALIV
E7hd
S2Je_
dq}S
ctPhE
X2|H
]qs7
&jwcv(
qaE_
J(;k
ozuC
1K^Tj
g='x
J= p
pmw4
DA}PI
h9m
}nk$8
u eR(B/
:<1^
.TC'
@}(H
-$W`
$2<"
kf@]
)jIe
{5A0`
Vs:S
TgR3PJm+
A#g!Z[
ea8e
W|Fm].iS
q6?v
Hx1s
1\`\
bzqR
H<`_?
4|&A
i/ h
jZ.u`0
*q{<"
iNeZr6C
`$@:
ktf|-b
r!4bM
nyh@
F 3#u
Y>,n
'*al
l2Q3
gLG]
qr;V6n
UIt
k~\4)*
huv`
ApfV
RU$X
C6s17_
fCdk
jx+@?
"f5C0
Vqk%:C
81r>
dj:W
lhX(
flE$c
o,2JWK
b^JC
XVWQSP
X[Y_^
_[Z|