| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2019-Jul-07 21:21:44 |
| Detected languages |
English - United States
Japanese - Japan |
| Debug artifacts |
D:\Development\MyCode\VStudio\2005\WeKnows\Release\Installer.pdb
|
| CompanyName | Moo0 |
| FileDescription | Moo0 Installer |
| FileVersion | 1.0.0.0 |
| InternalName | Installer.exe |
| LegalCopyright | (c) Moo0. All rights reserved. |
| OriginalFilename | Installer.exe |
| ProductName | Moo0 Installer |
| ProductVersion | 1.0.0.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .giats |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 92.6597% of the executable. |
| Malicious | VirusTotal score: 4/72 (Scanned on 2024-07-30 05:18:34) |
Antiy-AVL:
Trojan/Win32.Kryptik
ClamAV: Win.Packed.Zusy-9798820-0 Jiangmin: Downloader.Agent.lje MaxSecure: Trojan.Malware.300983.susgen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x150 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 9 |
| TimeDateStamp | 2019-Jul-07 21:21:44 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x12f000 |
| SizeOfInitializedData | 0x154d800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000D53A9 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x130000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16a5000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ole32.dll |
OleFlushClipboard
CoRevokeClassObject OleIsCurrentClipboard CoRegisterMessageFilter CoGetClassObject OleGetClipboard RevokeDragDrop RegisterDragDrop CoLockObjectExternal CoTaskMemAlloc CLSIDFromProgID CLSIDFromString OleUninitialize OleInitialize CoFreeUnusedLibraries CoCreateGuid StgCreateDocfileOnILockBytes StgOpenStorageOnILockBytes CreateILockBytesOnHGlobal CoTaskMemFree CoCreateInstance CoUninitialize CoInitialize CoInitializeSecurity |
|---|---|
| USER32.dll |
IsDialogMessageW
SetWindowTextW MoveWindow WinHelpW LoadIconW UnhookWindowsHookEx GetTopWindow GetClassNameW GetClassLongW EqualRect MapWindowPoints ScreenToClient AdjustWindowRectEx GetWindowTextLengthW GetWindowTextW RemovePropW GetPropW SetPropW GetScrollRange GetScrollPos SetScrollPos EndPaint BeginPaint SetActiveWindow GetMenuItemCount GetMenuItemID GetSubMenu SetMenu GetMenu GetDlgCtrlID GetDlgItem EndDeferWindowPos DeferWindowPos BeginDeferWindowPos DestroyWindow IsChild IsMenu GetClassInfoExW GetClassInfoW RegisterClassW CallWindowProcW GetMessageTime GetMessagePos RegisterWindowMessageW GetLastActivePopup IsWindowEnabled CallNextHookEx SetWindowsHookExW ValidateRect GetKeyState GetActiveWindow IsWindowVisible PeekMessageW DispatchMessageW TranslateMessage LoadBitmapW SetMenuItemInfoW GetMenuCheckMarkDimensions SetMenuItemBitmaps EnableMenuItem GetFocus MapDialogRect GetWindow SetWindowContextHelpId SetWindowPos PostQuitMessage SetRectEmpty SendDlgItemMessageA CharUpperW DestroyMenu IsRectEmpty GetWindowThreadProcessId CopyRect GetParent GetMenuInfo RegisterClassExW IntersectRect GetMonitorInfoW GetSysColorBrush CreateCursor TabbedTextOutW DrawTextW DrawTextExW GrayStringW PostThreadMessageW UpdateWindow UnregisterHotKey MessageBeep GetNextDlgGroupItem RegisterHotKey SetWindowLongW CreateWindowExW PostMessageW InvalidateRgn IsZoomed IsIconic SetWindowRgn WindowFromPoint GetForegroundWindow MonitorFromWindow MonitorFromRect GetSystemMetrics SetRect EnumDisplayMonitors PtInRect GetWindowLongW LoadCursorW SetCursor GetCursorPos GetAsyncKeyState OffsetRect SetTimer KillTimer ReleaseDC GetDC CopyAcceleratorTableW CharNextW ReleaseCapture GetCapture SystemParametersInfoW DefWindowProcW RedrawWindow ClientToScreen RegisterClipboardFormatW GetWindowRect RealChildWindowFromPoint DrawIconEx GetIconInfo GetDesktopWindow wsprintfW MessageBoxW DrawMenuBar GetClientRect SetCapture DestroyIcon SetClipboardViewer ChangeClipboardChain InvalidateRect GetNextDlgTabItem CreateIconFromResource CreateIconFromResourceEx EndDialog CreateDialogIndirectParamW InflateRect GetWindowDC SendMessageW SetFocus SetForegroundWindow ShowWindow IsWindow CheckMenuItem GetSysColor EnableWindow UnregisterClassW GetMessageW |
| OLEAUT32.dll |
SystemTimeToVariantTime
VariantTimeToSystemTime VariantCopy SysAllocStringLen VariantChangeType SysStringLen OleCreateFontIndirect SafeArrayDestroy VariantClear VariantInit SysFreeString SysAllocString |
| SHELL32.dll |
#162
SHGetDesktopFolder #155 #716 #190 SHChangeNotify DragAcceptFiles SHFileOperationW SHGetFileInfoW SHGetSpecialFolderLocation ShellExecuteW SHGetPathFromIDListW SHGetMalloc DragQueryFileW DragFinish Shell_NotifyIconW SHBrowseForFolderW ShellExecuteExW |
| ADVAPI32.dll |
RegDeleteKeyW
RegDeleteValueW RegSetValueExW RegEnumKeyW RegQueryValueW GetUserNameW AdjustTokenPrivileges LookupPrivilegeValueW RegEnumValueW RegQueryValueExW RegOpenKeyExW RegCloseKey RegCreateKeyExW GetTokenInformation OpenProcessToken GetSidSubAuthority GetSidSubAuthorityCount GetSidIdentifierAuthority IsValidSid |
| KERNEL32.dll |
GetLastError
HeapReAlloc RaiseException HeapAlloc DecodePointer DeleteCriticalSection GetProcessHeap EnterCriticalSection LeaveCriticalSection WideCharToMultiByte MultiByteToWideChar GetOEMCP CloseHandle InterlockedDecrement GetModuleFileNameW GetCurrentProcessId SetProcessWorkingSetSize GetCurrentProcess SetPriorityClass CreateFileW WriteFile WaitForSingleObject EnumResourceTypesW EnumResourceNamesW FindResourceExW SizeofResource EnumResourceLanguagesW FreeLibrary BeginUpdateResourceW UpdateResourceW EndUpdateResourceW LoadLibraryW LoadResource LockResource FreeResource GetSystemTimeAsFileTime FindResourceW GetProcAddress FormatMessageW GetEnvironmentStringsW SetLastError lstrlenW ExpandEnvironmentStringsW SuspendThread CreateThread TerminateThread ResumeThread GetThreadPriority SetThreadPriority GetVolumeInformationW GetFileAttributesExW GetFileInformationByHandle GetFileAttributesW SetFileAttributesW FindFirstFileW FindNextFileW FindClose GetDiskFreeSpaceW SetFileTime MoveFileExW VirtualAlloc VirtualFree DeleteFileW RemoveDirectoryW CopyFileW GetTempPathW GetTempFileNameW EnumSystemCodePagesW GetCPInfoExW GetModuleHandleW GetVersionExW GetUserDefaultUILanguage GetSystemDefaultLangID GetTimeZoneInformation FileTimeToLocalFileTime FileTimeToSystemTime SystemTimeToTzSpecificLocalTime LocalFileTimeToFileTime lstrcpyW GlobalAddAtomW ReadFile CreateToolhelp32Snapshot Process32FirstW OpenProcess Process32NextW SetFilePointerEx FlushFileBuffers SetEndOfFile GlobalLock GlobalUnlock GetCurrentThreadId TerminateProcess GetFileSize SetFilePointer GetStdHandle CreateDirectoryW GetSystemDirectoryW HeapSize GetFullPathNameW GetCurrentDirectoryW GetSystemInfo CreateEventW SetEvent ResetEvent WaitForMultipleObjects GetACP OutputDebugStringA GetModuleHandleA GetCurrentThread LoadLibraryExW GlobalAlloc GlobalDeleteAtom lstrcmpA lstrcmpW CompareStringA GetTickCount GlobalFree GetPrivateProfileIntW GetPrivateProfileStringW WritePrivateProfileStringW EncodePointer LoadLibraryA GlobalFindAtomW MulDiv GetProfileIntW TlsAlloc TlsGetValue TlsSetValue TlsFree GlobalReAlloc GlobalHandle LocalAlloc LocalReAlloc CompareStringW GetLocaleInfoW GetSystemDefaultUILanguage GlobalFlags GetThreadLocale LockFile UnlockFile DuplicateHandle VirtualProtect SetErrorMode GetFileSizeEx GetFileTime WaitForSingleObjectEx UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent QueryPerformanceCounter InitializeSListHead IsDebuggerPresent GetStartupInfoW GetCPInfo IsValidCodePage FindFirstFileExW FreeEnvironmentStringsW ReadConsoleW GetConsoleMode GetConsoleCP SetStdHandle GetStringTypeW LCMapStringW ExitProcess HeapQueryInformation GetCommandLineW GetCommandLineA GetModuleHandleExW FreeLibraryAndExitThread ExitThread PeekNamedPipe GetFileType GetDriveTypeW QueryPerformanceFrequency VirtualQuery RtlUnwind OutputDebugStringW InitializeCriticalSectionAndSpinCount HeapFree Sleep InitializeCriticalSection SetEnvironmentVariableA LocalFree WriteConsoleW |
| GDI32.dll |
EndDoc
Escape ExtTextOutW TextOutW RectVisible PtVisible CreateDCW SetViewportOrgEx SetViewportExtEx GetBkColor GetWindowExtEx StartDocW GetDeviceCaps SetBkMode GetStockObject RestoreDC SaveDC SetBkColor EndPage SetMapMode CreateSolidBrush StretchBlt GetStretchBltMode GetTextExtentPoint32W SetStretchBltMode SetWindowExtEx ExtSelectClipRgn StartPage SetTextColor CreateFontIndirectW BitBlt GetPaletteEntries GetCurrentObject DeleteDC SetDIBColorTable GetDIBColorTable SelectObject CreateCompatibleDC CreateDIBSection GetObjectW OffsetViewportOrgEx CreateBitmap ScaleViewportExtEx ScaleWindowExtEx CreateRectRgnIndirect GetRgnBox ExcludeClipRect GetClipBox GetTextColor GetViewportExtEx DeleteObject DPtoLP GetMapMode |
| WINSPOOL.DRV |
ClosePrinter
DocumentPropertiesW OpenPrinterW |
| COMCTL32.dll |
InitCommonControlsEx
|
| SHLWAPI.dll |
PathStripToRootW
PathIsUNCW PathFindFileNameW PathFindExtensionW StrFormatByteSizeW |
| oledlg.dll |
OleUIBusyW
|
| urlmon.dll |
URLDownloadToFileW
URLDownloadToCacheFileW |
| WININET.dll |
InternetGetConnectedState
InternetOpenW InternetConnectW HttpOpenRequestW HttpSendRequestW HttpQueryInfoW InternetReadFile InternetCloseHandle |
| OLEACC.dll |
CreateStdAccessibleObject
LresultFromObject |
| Open |
| Save As |
| All Files (*.*) |
| Untitled |
| an unnamed file |
| &Hide |
| No error message is available. |
| Attempted an unsupported operation. |
| A required resource was unavailable. |
| Out of memory. |
| An unknown error has occurred. |
| Encountered an improper argument. |
| Incorrect filename. |
| Failed to open document. |
| Failed to save document. |
| Save changes to %1? |
| Failed to create empty document. |
| The file is too large to open. |
| Could not start print job. |
| Failed to launch help. |
| Internal application error. |
| Command failed. |
| Insufficient memory to perform operation. |
| System registry entries have been removed and the INI file (if any) was deleted. |
| Not all of the system registry entries (or INI file) were removed. |
| This program requires the file %Ts, which was not found on this system. |
| This program is linked to the missing export %Ts in the file %Ts. This machine may have an incompatible version of %Ts. |
| Enter an integer. |
| Enter a number. |
| Enter an integer between %1 and %2. |
| Enter a number between %1 and %2. |
| Enter no more than %1 characters. |
| Select a button. |
| Enter an integer between 0 and 255. |
| Enter a positive integer. |
| Enter a date and/or time. |
| Enter a currency. |
| Enter a GUID. |
| Enter a time. |
| Enter a date. |
| Unexpected file format. |
| %1 |
| Cannot find this file. |
| Verify that the correct path and file name are given. |
| Destination disk drive is full. |
| Unable to read from %1, it is opened by someone else. |
| Unable to write to %1, it is read-only or opened by someone else. |
| Encountered an unexpected error while reading %1. |
| Encountered an unexpected error while writing %1. |
| %1: %2 |
| Continue running script? |
| Dispatch exception: %1 |
| Unable to read write-only property. |
| Unable to write read-only property. |
| Unable to load mail system support. |
| Mail system DLL is invalid. |
| Send Mail failed to send message. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| %1 was not found. |
| %1 contains an incorrect path. |
| Could not open %1 because there are too many open files. |
| Access to %1 was denied. |
| An incorrect file handle was associated with %1. |
| Could not remove %1 because it is the current directory. |
| Could not create %1 because the directory is full. |
| Seek failed on %1 |
| Encountered a hardware I/O error while accessing %1. |
| Encountered a sharing violation while accessing %1. |
| Encountered a locking violation while accessing %1. |
| Disk full while accessing %1. |
| Attempted to access %1 past its end. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| Attempted to write to the reading %1. |
| Attempted to access %1 past its end. |
| Attempted to read from the writing %1. |
| %1 has a bad format. |
| %1 contained an unexpected object. |
| %1 contains an incorrect schema. |
| pixels |
| Uncheck |
| Check |
| Mixed |
| One or more auto-saved documents were found. |
| These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
| Do you want to recover these auto-saved documents? |
| Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
| Recover the auto-saved documents |
| Open the auto-saved versions instead of the explicitly saved versions |
| Don't recover the auto-saved documents |
| Use the last explicitly saved versions of the documents |
| %Ts [Recovered] |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Moo0 |
| FileDescription | Moo0 Installer |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | Installer.exe |
| LegalCopyright | (c) Moo0. All rights reserved. |
| OriginalFilename | Installer.exe |
| ProductName | Moo0 Installer |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | Japanese - Japan |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Jul-07 21:21:44 |
| Version | 0.0 |
| SizeofData | 89 |
| AddressOfRawData | 0x17986c |
| PointerToRawData | 0x178c6c |
| Referenced File | D:\Development\MyCode\VStudio\2005\WeKnows\Release\Installer.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Jul-07 21:21:44 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1798c8 |
| PointerToRawData | 0x178cc8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Jul-07 21:21:44 |
| Version | 0.0 |
| SizeofData | 1028 |
| AddressOfRawData | 0x1798dc |
| PointerToRawData | 0x178cdc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Jul-07 21:21:44 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x5b6000 |
|---|---|
| EndAddressOfRawData | 0x5b6008 |
| AddressOfIndex | 0x5914d4 |
| AddressOfCallbacks | 0x53090c |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x5c |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x5889e4 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0x50769d59 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 38 |
| 243 (40116) | 177 |
| 242 (40116) | 33 |
| C++ objects (VS2008 SP1 build 30729) | 1 |
| Imports (VS2008 SP1 build 30729) | 28 |
| ASM objects (VS2015 UPD3 build 24123) | 36 |
| C objects (VS2015 UPD3 build 24123) | 24 |
| C++ objects (VS2015 UPD3 build 24123) | 162 |
| C objects (VS2003 (.NET) build 4035) | 1 |
| Imports (VS2003 (.NET) build 4035) | 11 |
| Total imports | 727 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 10 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 56 |
| C objects (VS2008 SP1 build 30729) | 15 |
| C objects (24234) | 14 |
| C objects (VS2017 v15.4.* compiler 25547) | 74 |
| C++ objects (LTCG) (24234) | 273 |
| Resource objects (24234) | 1 |
| 151 | 1 |
| Linker (24234) | 1 |
No comments yet.