Malaysia Honeynet Project // Malware Database (Beta)

my-honeynet.org / list stats search
Hash 8d14872e0007b514d8e5e348311ada12
First seen 2007-07-17T08:30:27
Last seen 2007-07-18T17:17:40
Filetype MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit
Mimetype application/x-dosexec
Size 130560
Hits 8
Clamav
F-Prot
Antivir TR/Click.MMZ.89 No Virus Found
AVG
Objdump
binaries/8d14872e0007b514d8e5e348311ada12:     file format efi-app-ia32
binaries/8d14872e0007b514d8e5e348311ada12
architecture: i386, flags 0x0000010b:
HAS_RELOC, EXEC_P, HAS_DEBUG, D_PAGED
start address 0x000000000042500d

Characteristics 0x818e
	executable
	line numbers stripped
	symbols stripped
	little endian
	32 bit words
	big endian

Time/Date		Sat Jun 20 06:22:17 1992

ImageBase		0000000000400000
SectionAlignment	0000000000001000
FileAlignment		0000000000000200
MajorOSystemVersion	4
MinorOSystemVersion	0
MajorImageVersion	0
MinorImageVersion	0
MajorSubsystemVersion	4
MinorSubsystemVersion	0
Win32Version		00000000
SizeOfImage		00026000
SizeOfHeaders		00000400
CheckSum		00023e0a
Subsystem		00000002	(Windows GUI)
DllCharacteristics	00000000
SizeOfStackReserve	0000000000100000
SizeOfStackCommit	0000000000004000
SizeOfHeapReserve	0000000000100000
SizeOfHeapCommit	0000000000001000
LoaderFlags		00000000
NumberOfRvaAndSizes	00000010

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 0000000000025c7c 00000052 Import Directory [parts of .idata]
Entry 2 0000000000009000 0001bd9c Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000008000 00000248 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 0000000000007000 00000018 Thread Storage Directory [.tls]
Entry a 0000000000000000 00000000 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000000000 00000000 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in  at 0x425c7c

The Import Tables (interpreted  section contents)
 vma:            Hint    Time      Forward  DLL       First
                 Table   Stamp     Chain    Name      Thunk
 00025c7c	00025cad 00000000 00000000 00025ca4 00025cc6

	DLL Name: KERNEL32
	vma:  Hint/Ord Member-Name Bound-To
	25cb5	    0  GetProcAddress

 00025c90	00000000 00000000 00000000 00000000 00000000


PE File Base Relocations (interpreted .reloc section contents)

Virtual Address: 00001000 Chunk size 204 (0xcc) Number of fixups 98
	reloc    0 offset    2 [1002] HIGHLOW
	reloc    1 offset    a [100a] HIGHLOW
	reloc    2 offset   12 [1012] HIGHLOW
	reloc    3 offset   1a [101a] HIGHLOW
	reloc    4 offset   22 [1022] HIGHLOW
	reloc    5 offset   2a [102a] HIGHLOW
	reloc    6 offset   32 [1032] HIGHLOW
	reloc    7 offset   3a [103a] HIGHLOW
	reloc    8 offset   42 [1042] HIGHLOW
	reloc    9 offset   4a [104a] HIGHLOW
	reloc   10 offset   52 [1052] HIGHLOW
	reloc   11 offset   5a [105a] HIGHLOW
	reloc   12 offset   62 [1062] HIGHLOW
	reloc   13 offset   6a [106a] HIGHLOW
	reloc   14 offset   72 [1072] HIGHLOW
	reloc   15 offset   7a [107a] HIGHLOW
	reloc   16 offset   82 [1082] HIGHLOW
	reloc   17 offset   8a [108a] HIGHLOW
	reloc   18 offset   92 [1092] HIGHLOW
	reloc   19 offset   9a [109a] HIGHLOW
	reloc   20 offset   a2 [10a2] HIGHLOW
	reloc   21 offset   aa [10aa] HIGHLOW
	reloc   22 offset   b2 [10b2] HIGHLOW
	reloc   23 offset   ba [10ba] HIGHLOW
	reloc   24 offset   c2 [10c2] HIGHLOW
	reloc   25 offset   ca [10ca] HIGHLOW
	reloc   26 offset   d2 [10d2] HIGHLOW
	reloc   27 offset   da [10da] HIGHLOW
	reloc   28 offset   e0 [10e0] HIGHLOW
	reloc   29 offset   f1 [10f1] HIGHLOW
	reloc   30 offset   fa [10fa] HIGHLOW
	reloc   31 offset  113 [1113] HIGHLOW
	reloc   32 offset  11c [111c] HIGHLOW
	reloc   33 offset  12e [112e] HIGHLOW
	reloc   34 offset  146 [1146] HIGHLOW
	reloc   35 offset  167 [1167] HIGHLOW
	reloc   36 offset  180 [1180] HIGHLOW
	reloc   37 offset  199 [1199] HIGHLOW
	reloc   38 offset  1aa [11aa] HIGHLOW
	reloc   39 offset  1bf [11bf] HIGHLOW
	reloc   40 offset  1cc [11cc] HIGHLOW
	reloc   41 offset  1ec [11ec] HIGHLOW
	reloc   42 offset  446 [1446] HIGHLOW
	reloc   43 offset  52f [152f] HIGHLOW
	reloc   44 offset  558 [1558] HIGHLOW
	reloc   45 offset  55f [155f] HIGHLOW
	reloc   46 offset  566 [1566] HIGHLOW
	reloc   47 offset  636 [1636] HIGHLOW
	reloc   48 offset  64b [164b] HIGHLOW
	reloc   49 offset  67e [167e] HIGHLOW
	reloc   50 offset  6ce [16ce] HIGHLOW
	reloc   51 offset  6e0 [16e0] HIGHLOW
	reloc   52 offset  712 [1712] HIGHLOW
	reloc   53 offset  7b2 [17b2] HIGHLOW
	reloc   54 offset  805 [1805] HIGHLOW
	reloc   55 offset  85d [185d] HIGHLOW
	reloc   56 offset  868 [1868] HIGHLOW
	reloc   57 offset  8d4 [18d4] HIGHLOW
	reloc   58 offset  8db [18db] HIGHLOW
	reloc   59 offset  8ec [18ec] HIGHLOW
	reloc   60 offset  8f8 [18f8] HIGHLOW
	reloc   61 offset  948 [1948] HIGHLOW
	reloc   62 offset  a16 [1a16] HIGHLOW
	reloc   63 offset  a32 [1a32] HIGHLOW
	reloc   64 offset  a53 [1a53] HIGHLOW
	reloc   65 offset  a79 [1a79] HIGHLOW
	reloc   66 offset  ab3 [1ab3] HIGHLOW
	reloc   67 offset  ab9 [1ab9] HIGHLOW
	reloc   68 offset  aca [1aca] HIGHLOW
	reloc   69 offset  ad9 [1ad9] HIGHLOW
	reloc   70 offset  adf [1adf] HIGHLOW
	reloc   71 offset  aed [1aed] HIGHLOW
	reloc   72 offset  afd [1afd] HIGHLOW
	reloc   73 offset  b10 [1b10] HIGHLOW
	reloc   74 offset  b1a [1b1a] HIGHLOW
	reloc   75 offset  b1e [1b1e] HIGHLOW
	reloc   76 offset  b24 [1b24] HIGHLOW
	reloc   77 offset  b28 [1b28] HIGHLOW
	reloc   78 offset  b2d [1b2d] HIGHLOW
	reloc   79 offset  b34 [1b34] HIGHLOW
	reloc   80 offset  b3a [1b3a] HIGHLOW
	reloc   81 offset  b42 [1b42] HIGHLOW
	reloc   82 offset  b48 [1b48] HIGHLOW
	reloc   83 offset  b58 [1b58] HIGHLOW
	reloc   84 offset  b62 [1b62] HIGHLOW
	reloc   85 offset  b89 [1b89] HIGHLOW
	reloc   86 offset  b8e [1b8e] HIGHLOW
	reloc   87 offset  b93 [1b93] HIGHLOW
	reloc   88 offset  bb5 [1bb5] HIGHLOW
	reloc   89 offset  bbe [1bbe] HIGHLOW
	reloc   90 offset  bd4 [1bd4] HIGHLOW
	reloc   91 offset  bec [1bec] HIGHLOW
	reloc   92 offset  c07 [1c07] HIGHLOW
	reloc   93 offset  c26 [1c26] HIGHLOW
	reloc   94 offset  c2f [1c2f] HIGHLOW
	reloc   95 offset  c55 [1c55] HIGHLOW
	reloc   96 offset  c62 [1c62] HIGHLOW
	reloc   97 offset  f0f [1f0f] HIGHLOW

Virtual Address: 00002000 Chunk size 328 (0x148) Number of fixups 160
	reloc    0 offset   d9 [20d9] HIGHLOW
	reloc    1 offset   e2 [20e2] HIGHLOW
	reloc    2 offset   ed [20ed] HIGHLOW
	reloc    3 offset   f2 [20f2] HIGHLOW
	reloc    4 offset  102 [2102] HIGHLOW
	reloc    5 offset  109 [2109] HIGHLOW
	reloc    6 offset  116 [2116] HIGHLOW
	reloc    7 offset  137 [2137] HIGHLOW
	reloc    8 offset  143 [2143] HIGHLOW
	reloc    9 offset  14b [214b] HIGHLOW
	reloc   10 offset  151 [2151] HIGHLOW
	reloc   11 offset  15e [215e] HIGHLOW
	reloc   12 offset  16e [216e] HIGHLOW
	reloc   13 offset  17b [217b] HIGHLOW
	reloc   14 offset  181 [2181] HIGHLOW
	reloc   15 offset  185 [2185] HIGHLOW
	reloc   16 offset  18c [218c] HIGHLOW
	reloc   17 offset  195 [2195] HIGHLOW
	reloc   18 offset  19e [219e] HIGHLOW
	reloc   19 offset  1af [21af] HIGHLOW
	reloc   20 offset  20e [220e] HIGHLOW
	reloc   21 offset  238 [2238] HIGHLOW
	reloc   22 offset  246 [2246] HIGHLOW
	reloc   23 offset  24b [224b] HIGHLOW
	reloc   24 offset  264 [2264] HIGHLOW
	reloc   25 offset  274 [2274] HIGHLOW
	reloc   26 offset  285 [2285] HIGHLOW
	reloc   27 offset  296 [2296] HIGHLOW
	reloc   28 offset  2a2 [22a2] HIGHLOW
	reloc   29 offset  2a7 [22a7] HIGHLOW
	reloc   30 offset  2ac [22ac] HIGHLOW
	reloc   31 offset  2b3 [22b3] HIGHLOW
	reloc   32 offset  2ba [22ba] HIGHLOW
	reloc   33 offset  2c4 [22c4] HIGHLOW
	reloc   34 offset  2db [22db] HIGHLOW
	reloc   35 offset  2e7 [22e7] HIGHLOW
	reloc   36 offset  2ee [22ee] HIGHLOW
	reloc   37 offset  300 [2300] HIGHLOW
	reloc   38 offset  312 [2312] HIGHLOW
	reloc   39 offset  31f [231f] HIGHLOW
	reloc   40 offset  32b [232b] HIGHLOW
	reloc   41 offset  338 [2338] HIGHLOW
	reloc   42 offset  34a [234a] HIGHLOW
	reloc   43 offset  352 [2352] HIGHLOW
	reloc   44 offset  35a [235a] HIGHLOW
	reloc   45 offset  362 [2362] HIGHLOW
	reloc   46 offset  36a [236a] HIGHLOW
	reloc   47 offset  372 [2372] HIGHLOW
	reloc   48 offset  37a [237a] HIGHLOW
	reloc   49 offset  382 [2382] HIGHLOW
	reloc   50 offset  38a [238a] HIGHLOW
	reloc   51 offset  392 [2392] HIGHLOW
	reloc   52 offset  39a [239a] HIGHLOW
	reloc   53 offset  3a2 [23a2] HIGHLOW
	reloc   54 offset  3aa [23aa] HIGHLOW
	reloc   55 offset  3b2 [23b2] HIGHLOW
	reloc   56 offset  3ba [23ba] HIGHLOW
	reloc   57 offset  3c2 [23c2] HIGHLOW
	reloc   58 offset  3ca [23ca] HIGHLOW
	reloc   59 offset  3d2 [23d2] HIGHLOW
	reloc   60 offset  3df [23df] HIGHLOW
	reloc   61 offset  3eb [23eb] HIGHLOW
	reloc   62 offset  3f8 [23f8] HIGHLOW
	reloc   63 offset  40a [240a] HIGHLOW
	reloc   64 offset  412 [2412] HIGHLOW
	reloc   65 offset  41f [241f] HIGHLOW
	reloc   66 offset  42b [242b] HIGHLOW
	reloc   67 offset  438 [2438] HIGHLOW
	reloc   68 offset  44a [244a] HIGHLOW
	reloc   69 offset  452 [2452] HIGHLOW
	reloc   70 offset  45a [245a] HIGHLOW
	reloc   71 offset  462 [2462] HIGHLOW
	reloc   72 offset  47a [247a] HIGHLOW
	reloc   73 offset  4a9 [24a9] HIGHLOW
	reloc   74 offset  51e [251e] HIGHLOW
	reloc   75 offset  6aa [26aa] HIGHLOW
	reloc   76 offset  6de [26de] HIGHLOW
	reloc   77 offset  70b [270b] HIGHLOW
	reloc   78 offset  717 [2717] HIGHLOW
	reloc   79 offset  724 [2724] HIGHLOW
	reloc   80 offset  736 [2736] HIGHLOW
	reloc   81 offset  7a0 [27a0] HIGHLOW
	reloc   82 offset  7ae [27ae] HIGHLOW
	reloc   83 offset  7bc [27bc] HIGHLOW
	reloc   84 offset  7fc [27fc] HIGHLOW
	reloc   85 offset  85b [285b] HIGHLOW
	reloc   86 offset  893 [2893] HIGHLOW
	reloc   87 offset  8f1 [28f1] HIGHLOW
	reloc   88 offset  938 [2938] HIGHLOW
	reloc   89 offset  995 [2995] HIGHLOW
	reloc   90 offset  9f7 [29f7] HIGHLOW
	reloc   91 offset  a0a [2a0a] HIGHLOW
	reloc   92 offset  a1c [2a1c] HIGHLOW
	reloc   93 offset  a20 [2a20] HIGHLOW
	reloc   94 offset  a24 [2a24] HIGHLOW
	reloc   95 offset  a28 [2a28] HIGHLOW
	reloc   96 offset  a2c [2a2c] HIGHLOW
	reloc   97 offset  a30 [2a30] HIGHLOW
	reloc   98 offset  a34 [2a34] HIGHLOW
	reloc   99 offset  a38 [2a38] HIGHLOW
	reloc  100 offset  a3c [2a3c] HIGHLOW
	reloc  101 offset  a40 [2a40] HIGHLOW
	reloc  102 offset  a44 [2a44] HIGHLOW
	reloc  103 offset  a48 [2a48] HIGHLOW
	reloc  104 offset  a4c [2a4c] HIGHLOW
	reloc  105 offset  a54 [2a54] HIGHLOW
	reloc  106 offset  a6b [2a6b] HIGHLOW
	reloc  107 offset  a78 [2a78] HIGHLOW
	reloc  108 offset  a83 [2a83] HIGHLOW
	reloc  109 offset  a88 [2a88] HIGHLOW
	reloc  110 offset  a9f [2a9f] HIGHLOW
	reloc  111 offset  aa7 [2aa7] HIGHLOW
	reloc  112 offset  ab6 [2ab6] HIGHLOW
	reloc  113 offset  ad2 [2ad2] HIGHLOW
	reloc  114 offset  ad7 [2ad7] HIGHLOW
	reloc  115 offset  ae1 [2ae1] HIGHLOW
	reloc  116 offset  aed [2aed] HIGHLOW
	reloc  117 offset  b01 [2b01] HIGHLOW
	reloc  118 offset  b07 [2b07] HIGHLOW
	reloc  119 offset  b11 [2b11] HIGHLOW
	reloc  120 offset  b20 [2b20] HIGHLOW
	reloc  121 offset  b2d [2b2d] HIGHLOW
	reloc  122 offset  b3a [2b3a] HIGHLOW
	reloc  123 offset  b44 [2b44] HIGHLOW
	reloc  124 offset  b49 [2b49] HIGHLOW
	reloc  125 offset  b5f [2b5f] HIGHLOW
	reloc  126 offset  b6c [2b6c] HIGHLOW
	reloc  127 offset  b71 [2b71] HIGHLOW
	reloc  128 offset  b7e [2b7e] HIGHLOW
	reloc  129 offset  b8f [2b8f] HIGHLOW
	reloc  130 offset  b9c [2b9c] HIGHLOW
	reloc  131 offset  ba9 [2ba9] HIGHLOW
	reloc  132 offset  bae [2bae] HIGHLOW
	reloc  133 offset  bbb [2bbb] HIGHLOW
	reloc  134 offset  bcc [2bcc] HIGHLOW
	reloc  135 offset  bd9 [2bd9] HIGHLOW
	reloc  136 offset  bde [2bde] HIGHLOW
	reloc  137 offset  beb [2beb] HIGHLOW
	reloc  138 offset  c04 [2c04] HIGHLOW
	reloc  139 offset  c09 [2c09] HIGHLOW
	reloc  140 offset  c16 [2c16] HIGHLOW
	reloc  141 offset  c21 [2c21] HIGHLOW
	reloc  142 offset  c2d [2c2d] HIGHLOW
	reloc  143 offset  c5e [2c5e] HIGHLOW
	reloc  144 offset  c6b [2c6b] HIGHLOW
	reloc  145 offset  c7b [2c7b] HIGHLOW
	reloc  146 offset  c80 [2c80] HIGHLOW
	reloc  147 offset  c9b [2c9b] HIGHLOW
	reloc  148 offset  ca0 [2ca0] HIGHLOW
	reloc  149 offset  cb0 [2cb0] HIGHLOW
	reloc  150 offset  cb5 [2cb5] HIGHLOW
	reloc  151 offset  cc4 [2cc4] HIGHLOW
	reloc  152 offset  cde [2cde] HIGHLOW
	reloc  153 offset  ceb [2ceb] HIGHLOW
	reloc  154 offset  cf0 [2cf0] HIGHLOW
	reloc  155 offset  cff [2cff] HIGHLOW
	reloc  156 offset  d14 [2d14] HIGHLOW
	reloc  157 offset  d1f [2d1f] HIGHLOW
	reloc  158 offset  d3d [2d3d] HIGHLOW
	reloc  159 offset  d71 [2d71] HIGHLOW

Virtual Address: 00003000 Chunk size 32 (0x20) Number of fixups 12
	reloc    0 offset   20 [3020] HIGHLOW
	reloc    1 offset   24 [3024] HIGHLOW
	reloc    2 offset   28 [3028] HIGHLOW
	reloc    3 offset   2c [302c] HIGHLOW
	reloc    4 offset   30 [3030] HIGHLOW
	reloc    5 offset   38 [3038] HIGHLOW
	reloc    6 offset   3c [303c] HIGHLOW
	reloc    7 offset   40 [3040] HIGHLOW
	reloc    8 offset   80 [3080] HIGHLOW
	reloc    9 offset   84 [3084] HIGHLOW
	reloc   10 offset   88 [3088] HIGHLOW
	reloc   11 offset    0 [3000] ABSOLUTE

Virtual Address: 00007000 Chunk size 20 (0x14) Number of fixups 6
	reloc    0 offset    0 [7000] HIGHLOW
	reloc    1 offset    4 [7004] HIGHLOW
	reloc    2 offset    8 [7008] HIGHLOW
	reloc    3 offset    c [700c] HIGHLOW
	reloc    4 offset    0 [7000] ABSOLUTE
	reloc    5 offset    0 [7000] ABSOLUTE

Sections:
Idx Name          Size      VMA               LMA               File off  Algn
  0 CODE          00001e4c  0000000000401000  0000000000401000  00000400  2**2
                  CONTENTS, ALLOC, LOAD, READONLY, CODE
  1 DATA          000000c8  0000000000403000  0000000000403000  00002400  2**2
                  CONTENTS, ALLOC, LOAD, DATA
  2 BSS           00000000  0000000000404000  0000000000404000  00002600  2**2
                  CONTENTS
  3 .idata        000004de  0000000000405000  0000000000405000  00002600  2**2
                  CONTENTS, ALLOC, LOAD, DATA
  4 .tls          00000000  0000000000406000  0000000000406000  00002c00  2**2
                  CONTENTS
  5 .rdata        00000018  0000000000407000  0000000000407000  00002c00  2**2
                  CONTENTS, ALLOC, LOAD, READONLY, DATA, SHARED
  6 .reloc        00000248  0000000000408000  0000000000408000  00002e00  2**2
                  CONTENTS, ALLOC, LOAD, READONLY, DATA, SHARED
  7 .rsrc         0001bd9c  0000000000409000  0000000000409000  00003200  2**2
                  CONTENTS, ALLOC, LOAD, READONLY, DATA, SHARED
  8               00000e00  0000000000425000  0000000000425000  0001f000  2**2
                  CONTENTS, ALLOC, LOAD, CODE
SYMBOL TABLE:
no symbols
© 2007 Malaysia Honeynet Project. Data captured using nepenthes. Frontend coded by spoonfork.