Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 1fa87bae316f2cbcc9e3c0116ac981f4
SHA1SUM : 5649bc676f6e5c0ba79f2c510b45ec11506e89bf

architecture: i386, flags 0x0000010a:
EXEC_P, HAS_DEBUG, D_PAGED
start address 0x0046df00

Characteristics 0x10f
relocations stripped
executable
line numbers stripped
symbols stripped
32 bit words

Time/Date Sat Nov 10 01:00:23 2007
Magic 010b (PE32)
MajorLinkerVersion 7
MinorLinkerVersion 10
SizeOfCode 00011000
SizeOfInitializedData 00001000
SizeOfUninitializedData 0005d000
AddressOfEntryPoint 000000000006df00
BaseOfCode 000000000005e000
BaseOfData 000000000006f000
ImageBase 0000000000400000
SectionAlignment 0000000000001000
FileAlignment 0000000000000200
MajorOSystemVersion 4
MinorOSystemVersion 0
MajorImageVersion 0
MinorImageVersion 0
MajorSubsystemVersion 4
MinorSubsystemVersion 0
Win32Version 00000000
SizeOfImage 00070000
SizeOfHeaders 00001000
CheckSum 00000000
Subsystem 00000002 (Windows GUI)
DllCharacteristics 00000000
SizeOfStackReserve 0000000000100000
SizeOfStackCommit 0000000000001000
SizeOfHeapReserve 0000000000100000
SizeOfHeapCommit 0000000000001000
LoaderFlags 00000000
NumberOfRvaAndSizes 00000010

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 000000000006f000 00000120 Import Directory [parts of .idata]
Entry 2 0000000000000000 00000000 Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000000000 00000000 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 0000000000000000 00000000 Thread Storage Directory [.tls]
Entry a 000000000006f120 00000048 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000000000 00000000 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in UPX2 at 0x46f000

The Import Tables (interpreted UPX2 section contents)
vma: Hint Time Forward DLL First
Table Stamp Chain Name Thunk
0006f000 00000000 00000000 00000000 0006f090 0006f064

DLL Name: KERNEL32.DLL

0006f014 00000000 00000000 00000000 0006f09d 0006f078

DLL Name: MPR.dll

0006f028 00000000 00000000 00000000 0006f0a5 0006f080

DLL Name: VERSION.dll

0006f03c 00000000 00000000 00000000 0006f0b1 0006f088

DLL Name: WS2_32.dll

0006f050 00000000 00000000 00000000 00000000 00000000

Sections:
Idx Name Size VMA LMA File off Algn
0 UPX0 0005d000 00401000 00401000 00000400 2**2
CONTENTS, ALLOC, CODE
1 UPX1 00010200 0045e000 0045e000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
2 UPX2 00000200 0046f000 0046f000 00010600 2**2
CONTENTS, ALLOC, LOAD, DATA
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 4734F497 Sat Nov 10 01:00:23 2007
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 00070000
Code Base: 0005E000 Size: 00011000
Data Base: 0006F000 Size: 00001000 (plus 0005D000 uninitialized)
Entry Point: 0006DF00 (file offset 00010300)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: UPX0 RVA: 00001000 Offset: 00000400 Size: 00000000 Flags: E0000080 (UERW)
2: UPX1 RVA: 0005E000 Offset: 00000400 Size: 00010200 Flags: E0000040 (DERW)
3: UPX2 RVA: 0006F000 Offset: 00010600 Size: 00000200 Flags: C0000040 (DRW)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: KERNEL32.DLL
Addr: 0006F064 hint: 0(0000) Name: LoadLibraryA
Addr: 0006F068 hint: 0(0000) Name: GetProcAddress
Addr: 0006F06C hint: 0(0000) Name: VirtualProtect
Addr: 0006F070 hint: 0(0000) Name: ExitProcess

DLL: MPR.dll
Addr: 0006F078 hint: 0(0000) Name: WNetAddConnection2A

DLL: VERSION.dll
Addr: 0006F080 hint: 0(0000) Name: VerQueryValueA

DLL: WS2_32.dll
Addr: 0006F088 Ord#: 4(0004) Name: connect

BtAV
]W#P
;H{6jE
<SVt9
n;AvS#
PSh'h
A,j2
A#hg=N
9]az
PVKlN^]y
SGWt}
|BjS"<
}d*t
}T6y
9E`u&
`)0l
MHbL*9
9]dYYu
du`;H8a8
W"8AX*
C{Zj
A,pt_1
Xq!f
Evx`
b\`@L
n/t $t
Vk~+?
'x0|PSu
?lE
:W::
'LVjH0
>94}\J
v8BN0
YSy,
3|.u
l)LSX WA
H>_p
CS!b
$PsP
{/}[
Qu:,
}l_A
j/h4
^;S 9I
jJ<f
;L"v
~Jr#
G88!
=t +D
;08Y
PSu
9{P.C
NTSQ
cwj+
C!CeV
R90]+
eD#nW
%9}(
O;NF\
j=aNu
WI,>
@h(t
g,t+V
PT5t
6^oXp
Wc"9
%,>*
*nzM
92u8.
MpAP
oY2Cat
W3*-^t
'j!x
`$l$
UPP:
hR@@
_ pe
W,Sj
EELk1
6v]Tpd0
El](^
HVs%
pF Wt^
2M<Q
Xk \
ZVk`
8^9]
]2 0
/$!<Y
|^_V
)6|P
bi`8u
ALA<"
jlzg\
_@^w
0aLPR
0(\)~pq'
<|u@PC>
AYxP
P/]pPC
gr9}p
;}hulL
q;Ep~
-S@I6
yhOp$
A7NY
j2 |?
E,h(
rj(wWd
ht|
d`_\^@
G+6h
Zdfl
MHQvS
}hk;
u\e-
#`t&
_^cSU
-T/Wh(
\} ;
p&Y<8
9M+h
#ONF
*mg;
3\F.
@]F.#
Yyi
xa Em
{w89
D{].|
54R]@[
|$|s09 A+
kC$$
@~"8
qGB;
<aY|
$WZV+;G}
1owE
40Q\@
@VhT*B
BBw&VC
;l^_[J
Uf!W
ho5pTP
y-K&
xGux#
MZp@+
ntPOp
|it
tmj A
}"RE
Qr0xx
{yI9
PWU
<;48!8$
36}dK
S/XE
}Z-8
7,|V
h#8V0
Gr!W<
19\^~
L2P3T}
^^N
9|tC{*
_]LQhh
Xw[r
jKX%wK
T72+&
<?Zu9d7
E`'#D
g$ZSS
"Cy,
!8 n
uDj3
0VGyT'f
IJpB:
^kD,J
~t/=
1,/N
B%\t
C=5|V
G9Ud
\Jhl
eptb
Lxh@
9u V
;POl
'&FLmgd
VVPGT
3ZN]
NdSq
Bu+h
13xG
\GB
pHo"
thSoh2
h<<[V
C'PZ
p4a3
NSy3U\@
QZ^&
/x$2
V/0/
<S:-
883#
32x
X,f
Ox8Ck?
gp50/+<
SXo:A
mX$"
@<x\
Y[e*
0M]r$
@u83
pNYr
1hkc
F]Tr
1HmP
g"4Z
YY|
8-u+
\hh%
>t>,
hHH(m2
3xY1PW
DByw
t%?!P
Q8JA
t20'
H]D.
@@4(
6Ht
9#tc
tSPQh
pPWw
Hh$!
{u@1
_):D
E8ZL
PmDY
)hu%j
R(XM
,00Z
"#d36
wT!0:
=%lG
U$?^
\&ZhWD
2\*_I;
eB.|(p
`zXe"0
|Wp*'
$uvh!
gDVK
u5_|
c%D*
ePg1
pC{P
/9\=
oBB4
(:SW
<pB.
D=8(,pB.,
=Tt~0
Ez l
u V.@
D0PZO(
(08AI
(w?C
&x;C
@zOG
,8Q0
P-=!
B8t/
8%Xh
h`'$3S
05F6
m=='
900_w
Y`/6
'(U<
#9Ifp
?(xdN)
C}!+
>RPZ.t1
3,Y@
RKK-
U<YY
r$o'
#}m'
X h|-hP
u%Ppa
D3B9$
a0RT
jJFT~k
}&H`~
tDd;
Ixp$;
V#~l
$2RQ
+gTf
Sj"h
t>=9$
m[$6
]l/M
t1V3
<o6
uaGA;
QHtN
WSSQm
ay(h
??9X
`Lh&
#]h4
`\uX
SH%/
@G22!|Xd
[[]L
.tCX
}l0k
utUp
SU ~ a3
dtA-uW
MHF;K|
8[u?
u^%U~
@H#G^Zu:
Gh '
o$%x
=Y>}3
J]rV
~;E8
TdD7
m\tX
>8_\w
YvXU
EV3j
;0YY
RH_"
u?*{
u-Vs
~s4ok
[YA<k
X1;4t
A(h@
048<-
%B'^
'HYX
M`QF
`@ ^4u
eQPU
h"@W
6kU8]
(9#u
T0.e&
RCtu
,KMB7
-+#C'
OHg:
DLT\o
A2$
$FFf
)t5r
XPH@80
]= u
HuL=
\Mkn
S<m&
7`5Qv
H n8=
9pnj
\{0
Qx$Hx
v 8
j6t JV
}H.|
PEP4
"<`}
0 Gx
PFCG
=%+:
66A)
(zHT2v
)QDN
DDY3
j@DB8
mPhN
<Xo[U
Cza|
Ygl;_
v%:1"
+0DqF
Vr9b
6&:a
s"95
Xl}8P
0Lh3
%gD1$
0t)F
B;xB
TG4"
^["Vc
;l !
.RXp
h8 x
VP+FY
!Mxt
>F95
:^@:
4=<M
L?S[
Yr!0
(@ht=`R
WSPa
rHKN
Jj`hH
8MZu
ZH|(
n2~H
O4.D
vrPQ
N.+W
Fag+}
WPg-
@Dy<
HWZ(
^LHHt
{It.
ht l
Wj*6u
9<352e
?pXb3
!>-u
3t$M
|3ZxC
RSYX
vls$qZ}l[)
t1_dd
cddj{sB
J S`
eH3u
T dtO
onxt@Xu
0x-`
koFf
u|ol
j{w\
>b WS
^IH,
; kVW
0o?^
j XZ
5$hfj2
hZa7
~ u9
pfZ=
8b1=
i!Vu
j0[;
pt{_Z
ou*Z`
#&!7*
l_s7
n@$vFa
Hsut
6 u#
u!)1
^IdN
q2"b
YZH^
;"u`
NCHx
_R_CQ
NBKl\3
=18;O<
SF2V
N;#JJb[
Uz-"
%CCA"
& 3s
N0v@>J
J0J\
7x,!
HbE;Z
<}#D
Ttsj
h2B+
7_ht
J 5-=L1
Hur6`(
&m,D
5ug[x
uU::
C@-|~
}ZSQ?j
"tC{
eTE3
p;Q(@'
P@<~
E8JO
l+)t
9tP|
:oQQH\\
8csm
P;.td
qgC.3
y|E
c`V2
2@h0
6JP]
)\ yu1
Et~=;F
UJh|[Ul
4P[t
w(Xh
cF n
.6 |
NTX}
i|zr$
;6sVS
S;7|B
=86Z
b/u
mB~jo
w]dX
CaXhP
hQC]Y
?TQE
FE c'5N
t95@
@I9M
(;tk
`@.
Tt.+
XrLd
DC6=
1HPp
!o:x!
C0L5
<{2D
G#4;
[4j8h
E SS/n]
hcz$
SS=;K
#Pqd
VSb8
!kc3
@#W3)
t#A@v
5js`N=
X9;u@
_QP>
\,l0
ck@^O
Wj@J
qKOO^
a=Vu
;E+
FFD#
d-0#
kV> g
YFB"
Oo>TV
t/GB45F
9Qz"
_=Y/
<Yv"
Zhx7
TYYO!
v^IS
$<"u
bp7V
UYZ3
N96W
@BD\t
j_k+o
>eaF
kyf9
D$4f
t#8U
QDC20XC00
CBs{S
2?xHw
AZ!CC
(bHI
QS 7
R9/u
*/^]
:w/3
8^ @
L,}H
zr@@
Q@PK
WDcT
zr X
x\%v
y|
t4=JN
1%ok?
Iu*
): +HIC|
Y,5]
iO@ Z
$ [ g
HJ!+$~
zX-7
LX_*j
zx@m^
UE!.$
W`tfv
Y(|1:
p1Q8
}sT#
P{kR
Y!^C;
3u&XO
~;x|
Y[uUn
M<]D)
aA,L
h`8
hx+g
PPP/
A0Z]
d-7z
X xR
pF9B
l7L
\b!Rw
>{d8
HXHPSj
t2?J
IIPB
v%Pq$
<{)L
u+^'
={`6
ocwu
u5M:
{Lu
4UD(Z
g^``8Z
+9~J
f2nw
WWSu
!I,'m3
%U@ z
Z a7"
3XP:-j
S#kJ
s;SM
9MZ&
stA'
0B;/$t
z,St|
w9op
~u+Vj
^)D/
DC! >
O33V
dE/`<
u/6RY3
\\uS
cX0tF
5a&t]
{\YB
Dezj
j XO
f 'g4
?RDbK
Cu.h
.]Fh
ru=F0`:
nZ3t
9\N4
#L)j
?@?
T,
5 tI
M]XG
(@}>j
9+}+
)KYu
N `f
Xilq
zQ`*u
!1Wp4
9wYg+
vlo
k@!-
{3hmE
#$TU
" Total: %d
,/[SCAN]
Exploit S
nJtis
cD7Scan n
~ ac0ve.oCurren4
s4[FTP,Failed to
mar<serpr,
ror<<
X>WS7Qfo
;;hFtC
quest
&Hm-_
thla
Sub-
.g-{
hHatw
Rng.
w6ker
ize cr
iT\epmap
?GET / Z
/1.0
$Nego
/cncV
i &-
1 1)gew+
%bye
!del1
dowxXP (SP0+
/NT4820
O2Kp
er'$cg
Bypass]>RFB,037l
22.GooT
y rnt
fi@QUIT
rVsf
9|15RO
BINARY
PORT
succ0
ul!<
'*6[^,],
LIS/P
PASVoT e4
`BIZI/A
ATYPEo57 "/"
/P$W
VStnyF
SY/3fUAlw
oggri
pp331
quR|qw
0wf j0
found
?NFG#@Z
fioGE
sock
()Hg,
4avi32.dllOSQ
FZeH0
ExTDir_S
vAttr
SHCh
Dify
/AAddY1
_D6Flu
acbf
{_A?.d
Del/
^eJobm'
jtn_Ica"40z_E*
C>sc
wMoz
&la/4.
ZOJJUrlA'
'wG}
66to
shnl
DLaB
FDIsS
ws2_3
zObj
BitBl*
IBl4r
YDC'
agdaGWNx
;[3r
Lo$up
FhHr
TextAGc
xias
.chPZh
9vAg
ngsO
c!Mo\
rsY))
n Nex
Sn~r
mIRw
Shut
AX"N1"
ops"6
?nfc_JsTCPIP.
:FzUAP
YMr+b
INFO
U*I64uMHz. OS
[_gX
)FSy<+)
TimUpt
H:mm:s't
BtrY
voXP
98^T
`9N/
hvot
[AlT
%.2d- 4
@re_O6"
6FadI
RL=Mor
DNS
vD+em1fKB:
Q.n.
..?*R
moTpE
q !=cG
X[Q :oQPRIVM
CE?%02X
0f69
d705
a9261e31
b6e88c
136?3ac340832f29(15}w{
38fbe\6f75LbccGfd456
d816acae554c7
N4Ol
b24p
+T1P1n50]ph
P://iQ.Jg/o*
MODE?
%.HOST
UJLR
nick
t._9
h2SP2fx.
istw
:r'
yVBD
KYIDQ
ldu2
mMW 1Y
oLabfullo
cJdn
kwm
VWwedw
ALL]ek
g%sA
wi| aHe83
<djfo
v\ed
aQP`0
?Joinedk*e
bae_P
s.wKil
gNoOp
SBpp=
e7 4\E?
}5pC
entWVi$
ztsM
fmsg:
ACTION
oCyclGPAR
7{FD
g{Ca
cle'
x'p ?u
^?id
illg
oin'X
%s%suD
{fdns
'`Po
n l%|+Q3Wen
E$ty>^O
.ZcB
fwn'
'oTg
logglg
oGal
eJk:
sOlg8RX
RSIY
0w7i
~bk4
6aTzt
(@rg
$AzA
>P$%d
`:!in.7$
PINGp
me.wVERS
3D'!
?T0"
QqY`'
0< :y,
GBKW
JOIN
PONG
(Z@gE
Bb,i
D.EM\
*PPt=5+
HewDP^Ny
tppB
^*:E}dA8&
=)G!
DebugA
l&DTx
NCt/
(8PX
7:WP
:i!flo?o3
>f'2
cAMD
n+000
GAIs0
vERN
EL32
!G( Hl%
PTLOSS#
vPgoS
DOM4n?
AIN#R6029
Kof+Mf
Z.P'XA
frmG@
"(TMA
O7oH
lowiq
6std5
NfJcG
mulX
~rU
ay.w09
F jT$
W8arguQs
|[oi+
Libra
-k!B
n>8O
frp+
b@ld?
9Wh@
(tEw
s@ely
Htte)N
be5d
_1]V5
lup'
oxb1#QN
eDS/
d"tz
hrpm
!siO
AG'T
.;1G
G>gp
:@4v?
/d~137
7ow44
1025
wasn1
wsmb
"gwnt
_2$X
EdIww
MARBg
MEOWV
0&(/
Po[A
G 0|
5Jkm
SMBrz'
WORK PK&
ROGRAM
3.1aNMbf
@Xne2,
NT 0 0
P CKFDETC
CAA
GHIJKJ
NOPQRST
XYZabcde
fghijklmnopq
uvwxyz0
789+/
mSffn
^1P%
S V"`
&~@>
;|$$u
Jw:$
ZNX`3)Adb`x
h<_1
Gt8%S
kPxXf
VzX*
dWN,
^WU#:
v02Z/
X sw)l>t
&`dos-kaVna
##srbija
nc##65
Vw\R
xOLE
\Lsa
@^Tter
Pzwg
-i
>!9Y
X[7[(
WRQQ
wbUWo
WgR/S
]p{
xx@o
kU'9
HMXB
?Zd;
?/L[
S;uD
U>c{
zc%C1
.:3q
-64OS
NKeb
?AV/@
engthA?`+
_of_r
JBUPU%
$TUUU
* JBU
P$TUIU
* UBU
PUTUI
$* UUU
PU%UI
$T UU
JBUPU%
$TUUU
* JBU
P$TUIU
* UBU
PUTUI
$* UUU
PU%UI
$T UU
JBUPU%
$TUUU
* JBU
P$TUIU
* UBU
PUTUI
$* UUU
PU%UI
$T UU
JBUPU%
$TUUU
* JBU
P$TUIU
* UBU
PUTUI
$* UUU
PU%UI
$T UU
JBUPU%
$TUUU
* JBU
P$TUIU
* UBU
PUTUI
$* UUU
Sleep
GetLastError
reateTh
d7SyemDi
ct@yA)ModuzFi
Name
&ExitiL
alSlionBn
T kCou<
In<:izko
}AndSpinMDe
ByzoWid0
l>ha
loseHa
Wxe/T
r&sa
dPipe
WaTF
cAddHss_v_{
m|M:ag
Un$6
pViewOf'M
t!zme
L@bStr
At"buhsA
pyWG
{Dat
OHnI~0
CuxenoId
M|xAE
foAC
ZL;08
}pSize
mbyP
Clth
Buff
#CP+
ACPmIAsl
UPoi
^nnu2
_.Jtl
`.rd
@.MG{
XPTPSW
KERNEL32.DLL
MPR.dll
VERSION.dll
WS2_32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
ExitProcess
WNetAddConnection2A
VerQueryValueA