Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Peframe v. 5.0
- Short information
- ------------------------------------------------------------
- File type PE32 executable (GUI) Intel 80386, for MS Windows
- File name jucheck.exe
- File size 80896
- Hash MD5 070e9a317ee53ac3814eb86bc7d5bf49
- Compile time 2014-10-19 09:14:39
- Sections 5 (0 suspicious)
- Directories import, resource, debug, relocation
- Detected packer, mutex, antidbg
- Import Hash 3e68822a115a7a54dd73bca4eb619c7d
- Paker info
- ------------------------------------------------------------
- Microsoft Visual C++ 8
- Resources info
- ------------------------------------------------------------
- RT_MANIFEST 381 <?xml version='1.0' encoding='UTF-8
- Import function
- ------------------------------------------------------------
- ADVAPI32.dll 7
- SHELL32.dll 1
- KERNEL32.dll 80
- USER32.dll 2
- WINHTTP.dll 9
- Antidbg info
- ------------------------------------------------------------
- GetLastError
- IsDebuggerPresent
- IsProcessorFeaturePresent
- OutputDebugStringW
- Process32FirstW
- Process32NextW
- TerminateProcess
- UnhandledExceptionFilter
- Mutex info
- ------------------------------------------------------------
- CreateMutexA
- ReleaseMutex
- WaitForSingleObject
- Apialert info
- ------------------------------------------------------------
- CloseHandle
- CopyFileA
- CreateDirectoryA
- CreateFileW
- CreateMutexA
- CreateProcessA
- CreateThread
- CreateToolhelp32Snapshot
- DeleteCriticalSection
- DeleteFileA
- DeviceIoControl
- ExitProcess
- GetCommandLineA
- GetCurrentProcess
- GetCurrentProcessId
- GetModuleFileNameA
- GetModuleFileNameW
- GetModuleHandleExW
- GetModuleHandleW
- GetProcAddress
- GetStartupInfoW
- HeapAlloc
- InitializeCriticalSectionAndSpinCount
- IsDebuggerPresent
- LoadLibraryExW
- LoadLibraryW
- MessageBoxA
- MessageBoxW
- OpenProcess
- OpenProcessToken
- OutputDebugStringW
- Process32FirstW
- Process32NextW
- ReadProcessMemory
- RegCloseKey
- RegOpenKeyExW
- ReleaseMutex
- SetFilePointerEx
- Sleep
- TerminateProcess
- UnhandledExceptionFilter
- WaitForSingleObject
- WriteFile
- Filename found
- ------------------------------------------------------------
- Web Page 179.43.160.34/wp-content/temp/gate.php
- Library mscoree.dll
- Library USER32.DLL
- Library kernel32.dll
- Library ADVAPI32.dll
- Library SHELL32.dll
- Library WINHTTP.dll
- IP found
- ------------------------------------------------------------
- 179.43.160.34
- Fuzzing match
- ------------------------------------------------------------
- 1 String too long
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement