MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Loads dropped or rewritten executable
|
Executed via COM
|
Reads the hosts file
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0001744F | 0x00017600 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.66831 |
.rdata | 0x00019000 | 0x00007568 | 0x00007600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 5.24882 |
.data | 0x00021000 | 0x00001400 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 2.24743 |
.rsrc | 0x00023000 | 0x0018D108 | 0x0018D200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 7.9846 |
.reloc | 0x001B1000 | 0x00001270 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 6.34218 |
No exports.