| File name: | ALICE.exe |
| Full analysis: | https://app.any.run/tasks/cfe84136-ba99-44ee-9e40-e9e77f3cd6f2 |
| Verdict: | No threats detected |
| Analysis date: | June 28, 2018, 19:04:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5: | 3ED14DD6DEC1D56DC514974449229398 |
| SHA1: | 187465383031C02AA3C079DC06E14688D344850B |
| SHA256: | DB1169DF116FDA46319C4B87607DF7B6A5E80B48DE5411D47684974CA22DD35A |
| SSDEEP: | 49152:vPihFYeIFGWErHfU60ej9/T5vAMoY0AIRfdMvDvAI0ZphYb:yFYeIFGWELMCj9/FWNWD/OG |
| .exe | | | Win32 Executable Delphi generic (25.5) |
|---|---|---|
| .scr | | | Windows screen saver (23.6) |
| .exe | | | DOS Executable Borland C++ (23.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (11.8) |
| .exe | | | Win32 Executable (generic) (8.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:05:26 13:33:58+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 5 |
| CodeSize: | 405504 |
| InitializedDataSize: | 40960 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x130c |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 26-May-2018 11:33:58 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0050 |
| Pages in file: | 0x0002 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x000F |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x001A |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000200 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 8 |
| Time date stamp: | 26-May-2018 11:33:58 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00063000 | 0x00062A00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.55487 |
.data | 0x00064000 | 0x0000A000 | 0x00005000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.86198 |
.tls | 0x0006E000 | 0x00001000 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0006F000 | 0x00001000 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.199108 |
.idata | 0x00070000 | 0x00003000 | 0x00002200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21701 |
.edata | 0x00073000 | 0x00001000 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.16399 |
.rsrc | 0x00074000 | 0x001F3000 | 0x001F2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.9241 |
.reloc | 0x00267000 | 0x00007000 | 0x00006E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 6.662 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.27742 | 3752 | UNKNOWN | Russian - Russia | RT_ICON |
2 | 2.80231 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
3 | 3.00046 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
4 | 2.56318 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
5 | 2.6949 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
6 | 2.62527 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
7 | 2.91604 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
4085 | 3.24022 | 536 | UNKNOWN | UNKNOWN | RT_STRING |
4086 | 3.1103 | 236 | UNKNOWN | UNKNOWN | RT_STRING |
4087 | 3.24235 | 748 | UNKNOWN | UNKNOWN | RT_STRING |
ADVAPI32.DLL |
COMCTL32.DLL |
GDI32.DLL |
KERNEL32.DLL |
OLEAUT32.DLL |
SHELL32.DLL |
USER32.DLL |
Title | Ordinal | Address |
|---|---|---|
__GetExceptDLLinfo | 1 | 0x00001365 |
@@Unit1@Initialize | 2 | 0x00002678 |
@@Unit1@Finalize | 3 | 0x00002688 |
___CPPdebugHook | 4 | 0x00064098 |
_Form1 | 5 | 0x00068ED4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1804 | "C:\Users\admin\AppData\Local\Temp\ALICE.exe" | C:\Users\admin\AppData\Local\Temp\ALICE.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1804 | ALICE.exe | C:\Users\admin\AppData\Local\Temp\taskmgr.exe | executable | |
MD5:3A989D5DE21268D200FD1CA7476FE918 | SHA256:23C50F1C37B7C55554C282BA1781E9D6279CBBD7BFC5F64772D2E7A8962EBE70 | |||