| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Apr-17 21:29:18 |
| Detected languages |
English - United States
|
| CompanyName | e-ImageData |
| FileDescription | PowerScan |
| FileVersion | 7.5.25040.17644 |
| InternalName | ScanPro.exe |
| LegalCopyright | (c) e-ImageData. All rights reserved. |
| OriginalFilename | ScanPro.exe |
| ProductName | PowerScan |
| ProductVersion | 7.5.25040.17644 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA256 Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | The PE's resources are bigger than it is. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. |
Resource IDB_BITMAP_CLOUD_SCAN_OFF is possibly compressed or encrypted.
Resource 133 is possibly compressed or encrypted. Resource 135 is possibly compressed or encrypted. Resource 136 is possibly compressed or encrypted. Resource 140 is possibly compressed or encrypted. Resource 141 is possibly compressed or encrypted. Resource 142 is possibly compressed or encrypted. Resource 143 is possibly compressed or encrypted. Resource 145 is possibly compressed or encrypted. Resource 146 is possibly compressed or encrypted. Resource 147 is possibly compressed or encrypted. Resource 148 is possibly compressed or encrypted. Resource 149 is possibly compressed or encrypted. Resource 150 is possibly compressed or encrypted. Resource 151 is possibly compressed or encrypted. Resource 152 is possibly compressed or encrypted. Resource 153 is possibly compressed or encrypted. Resource 154 is possibly compressed or encrypted. Resource 155 is possibly compressed or encrypted. Resource 156 is possibly compressed or encrypted. Resource 157 is possibly compressed or encrypted. Resource 158 is possibly compressed or encrypted. Resource 159 is possibly compressed or encrypted. Resource 160 is possibly compressed or encrypted. Resource 161 is possibly compressed or encrypted. Resource 162 is possibly compressed or encrypted. Resource 163 is possibly compressed or encrypted. Resource 164 is possibly compressed or encrypted. Resource 165 is possibly compressed or encrypted. Resource 166 is possibly compressed or encrypted. Resource 167 is possibly compressed or encrypted. Resource 168 is possibly compressed or encrypted. Resource 176 is possibly compressed or encrypted. Resource 177 is possibly compressed or encrypted. Resource 178 is possibly compressed or encrypted. Resource 183 is possibly compressed or encrypted. Resource 184 is possibly compressed or encrypted. Resource 186 is possibly compressed or encrypted. Resource 187 is possibly compressed or encrypted. Resource 188 is possibly compressed or encrypted. Resource 190 is possibly compressed or encrypted. Resource 191 is possibly compressed or encrypted. Resource 192 is possibly compressed or encrypted. Resource 197 is possibly compressed or encrypted. Resource 204 is possibly compressed or encrypted. Resource 205 is possibly compressed or encrypted. Resource 206 is possibly compressed or encrypted. Resource 207 is possibly compressed or encrypted. Resource 208 is possibly compressed or encrypted. Resource 209 is possibly compressed or encrypted. Resource 210 is possibly compressed or encrypted. Resource 211 is possibly compressed or encrypted. Resource 212 is possibly compressed or encrypted. Resource 213 is possibly compressed or encrypted. Resource 214 is possibly compressed or encrypted. Resource 215 is possibly compressed or encrypted. Resource 216 is possibly compressed or encrypted. Resource 217 is possibly compressed or encrypted. Resource 218 is possibly compressed or encrypted. Resource 219 is possibly compressed or encrypted. Resource 220 is possibly compressed or encrypted. Resource 221 is possibly compressed or encrypted. Resource 222 is possibly compressed or encrypted. Resource 223 is possibly compressed or encrypted. Resource 224 is possibly compressed or encrypted. Resource 225 is possibly compressed or encrypted. Resource 226 is possibly compressed or encrypted. Resource 227 is possibly compressed or encrypted. Resource 228 is possibly compressed or encrypted. Resource 229 is possibly compressed or encrypted. Resource 230 is possibly compressed or encrypted. Resource 231 is possibly compressed or encrypted. Resource 233 is possibly compressed or encrypted. Resource 234 is possibly compressed or encrypted. Resource 235 is possibly compressed or encrypted. Resource 236 is possibly compressed or encrypted. Resource 237 is possibly compressed or encrypted. Resource 238 is possibly compressed or encrypted. Resource 239 is possibly compressed or encrypted. Resource 240 is possibly compressed or encrypted. Resource 241 is possibly compressed or encrypted. Resource 242 is possibly compressed or encrypted. Resource 243 is possibly compressed or encrypted. Resource 244 is possibly compressed or encrypted. Resource 245 is possibly compressed or encrypted. Resource 246 is possibly compressed or encrypted. Resource 247 is possibly compressed or encrypted. Resource 248 is possibly compressed or encrypted. Resource 249 is possibly compressed or encrypted. Resource 251 is possibly compressed or encrypted. Resource 252 is possibly compressed or encrypted. Resource 253 is possibly compressed or encrypted. Resource 254 is possibly compressed or encrypted. Resource 255 is possibly compressed or encrypted. Resource 256 is possibly compressed or encrypted. Resource 257 is possibly compressed or encrypted. Resource 258 is possibly compressed or encrypted. Resource 259 is possibly compressed or encrypted. Resource 262 is possibly compressed or encrypted. Resource 263 is possibly compressed or encrypted. Resource 264 is possibly compressed or encrypted. Resource 265 is possibly compressed or encrypted. Resource 266 is possibly compressed or encrypted. Resource 267 is possibly compressed or encrypted. Resource 268 is possibly compressed or encrypted. Resource 269 is possibly compressed or encrypted. Resource 271 is possibly compressed or encrypted. Resource 272 is possibly compressed or encrypted. Resource 273 is possibly compressed or encrypted. Resource 274 is possibly compressed or encrypted. Resource 277 is possibly compressed or encrypted. Resource 278 is possibly compressed or encrypted. Resource 279 is possibly compressed or encrypted. Resource 280 is possibly compressed or encrypted. Resource 281 is possibly compressed or encrypted. Resource 282 is possibly compressed or encrypted. Resource 283 is possibly compressed or encrypted. Resource 288 is possibly compressed or encrypted. Resource 290 is possibly compressed or encrypted. Resource 291 is possibly compressed or encrypted. Resource 292 is possibly compressed or encrypted. Resource 293 is possibly compressed or encrypted. Resource 294 is possibly compressed or encrypted. Resource 295 is possibly compressed or encrypted. Resource 296 is possibly compressed or encrypted. Resource 297 is possibly compressed or encrypted. Resource 298 is possibly compressed or encrypted. Resource 299 is possibly compressed or encrypted. Resource 300 is possibly compressed or encrypted. Resource 301 is possibly compressed or encrypted. Resource 302 is possibly compressed or encrypted. Resource 303 is possibly compressed or encrypted. Resource 304 is possibly compressed or encrypted. Resource 310 is possibly compressed or encrypted. Resource 311 is possibly compressed or encrypted. Resource 312 is possibly compressed or encrypted. Resource 313 is possibly compressed or encrypted. Resource 314 is possibly compressed or encrypted. Resource 315 is possibly compressed or encrypted. Resource 316 is possibly compressed or encrypted. Resource 317 is possibly compressed or encrypted. Resource 328 is possibly compressed or encrypted. Resource 329 is possibly compressed or encrypted. Resource 330 is possibly compressed or encrypted. Resource 331 is possibly compressed or encrypted. Resource 332 is possibly compressed or encrypted. Resource 333 is possibly compressed or encrypted. Resource 334 is possibly compressed or encrypted. Resource 335 is possibly compressed or encrypted. Resource 336 is possibly compressed or encrypted. Resource 337 is possibly compressed or encrypted. Resource 338 is possibly compressed or encrypted. Resource 339 is possibly compressed or encrypted. Resource 340 is possibly compressed or encrypted. Resource 341 is possibly compressed or encrypted. Resource 352 is possibly compressed or encrypted. Resource 353 is possibly compressed or encrypted. Resource 354 is possibly compressed or encrypted. Resource 355 is possibly compressed or encrypted. Resource 356 is possibly compressed or encrypted. Resource 357 is possibly compressed or encrypted. Resource 358 is possibly compressed or encrypted. Resource 360 is possibly compressed or encrypted. Resource 362 is possibly compressed or encrypted. Resource 363 is possibly compressed or encrypted. Resource 364 is possibly compressed or encrypted. Resource 365 is possibly compressed or encrypted. Resource 366 is possibly compressed or encrypted. Resource 367 is possibly compressed or encrypted. Resource 368 is possibly compressed or encrypted. Resource 369 is possibly compressed or encrypted. Resource 370 is possibly compressed or encrypted. Resource 371 is possibly compressed or encrypted. Resource 372 is possibly compressed or encrypted. Resource 373 is possibly compressed or encrypted. Resource 374 is possibly compressed or encrypted. Resource 375 is possibly compressed or encrypted. Resource 379 is possibly compressed or encrypted. Resource 380 is possibly compressed or encrypted. Resource 381 is possibly compressed or encrypted. Resource 382 is possibly compressed or encrypted. Resource 383 is possibly compressed or encrypted. Resource 384 is possibly compressed or encrypted. Resource 385 is possibly compressed or encrypted. Resource 386 is possibly compressed or encrypted. Resource 387 is possibly compressed or encrypted. Resource 388 is possibly compressed or encrypted. Resource 389 is possibly compressed or encrypted. Resource 390 is possibly compressed or encrypted. Resource 391 is possibly compressed or encrypted. Resource 392 is possibly compressed or encrypted. Resource 393 is possibly compressed or encrypted. Resource 394 is possibly compressed or encrypted. Resource 395 is possibly compressed or encrypted. Resource 396 is possibly compressed or encrypted. Resource 397 is possibly compressed or encrypted. Resource 398 is possibly compressed or encrypted. Resource 446 is possibly compressed or encrypted. Resource 447 is possibly compressed or encrypted. Resource 448 is possibly compressed or encrypted. Resource 449 is possibly compressed or encrypted. Resource 450 is possibly compressed or encrypted. Resource 454 is possibly compressed or encrypted. Resource 455 is possibly compressed or encrypted. Resource 460 is possibly compressed or encrypted. Resources amount for 232.41% of the executable. |
| Info | The PE is digitally signed. |
Signer: E-Imagedata Corp.
Issuer: GlobalSign GCC R45 EV CodeSigning CA 2020 |
| Malicious | VirusTotal score: 3/61 (Scanned on 2025-07-28 16:29:03) |
GData:
Win32.Trojan.Agent.6OG1UJ
Google: Detected Ikarus: Trojan.Crypt |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x160 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Apr-17 21:29:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 1644793110 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0x2fc400 |
| SizeOfInitializedData | 0x1c72c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2fe000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x27ab000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x89fb43 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetProcAddress
LoadLibraryA VirtualAlloc VirtualFree VirtualProtect GetVersionExA GetModuleHandleA GetCommandLineA GetStartupInfoA |
|---|---|
| CPPREST120_2_1.dll |
?GET@methods@http@web@@2V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@B
|
| POWRPROF.dll |
PowerReadFriendlyName
|
| VERSION.dll |
GetFileVersionInfoSizeW
|
| DBGHELP.dll |
MiniDumpWriteDump
|
| SSL-48.dll |
SSL_get_ex_data_X509_STORE_CTX_idx
|
| CRYPTO-46.dll |
X509_free
|
| PXLAPI40.dll |
_PxLUninitialize@4
|
| LIBTIFF3.dll |
#15
|
| HID.dll |
HidP_GetCaps
|
| SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
|
| DNSAPI.dll |
DnsQuery_W
|
| XMPCORE.dll |
#6
|
| MFC120U.dll |
#8367
|
| MSVCR120.dll |
getenv
|
| USER32.dll |
SetTimer
|
| GDI32.dll |
SetDIBits
|
| MSIMG32.dll |
AlphaBlend
|
| COMDLG32.dll |
GetOpenFileNameW
|
| WINSPOOL.drv |
EnumPrintersW
|
| ADVAPI32.dll |
CryptAcquireContextW
|
| SHELL32.dll |
SHGetFileInfoW
|
| COMCTL32.dll |
_TrackMouseEvent
|
| SHLWAPI.dll |
PathIsDirectoryW
|
| OLE32.dll |
CoInitialize
|
| OLEAUT32.dll |
VariantClear
|
| GDIPLUS.dll |
GdipCreateBitmapFromStream
|
| MSVCP120.dll |
?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEXXZ
|
| WS2_32.dll |
gethostname
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 7.5.25040.17644 |
| ProductVersion | 7.5.25040.17644 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | e-ImageData |
| FileDescription | PowerScan |
| FileVersion (#2) | 7.5.25040.17644 |
| InternalName | ScanPro.exe |
| LegalCopyright | (c) e-ImageData. All rights reserved. |
| OriginalFilename | ScanPro.exe |
| ProductName | PowerScan |
| ProductVersion (#2) | 7.5.25040.17644 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x2baac60 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0x54c5fc17 |
|---|---|
| Unmarked objects | 0 |
| 209 (65501) | 2 |
| C objects (65501) | 2 |
| C++ objects (65501) | 1 |
| 208 (65501) | 2 |
| 199 (41118) | 3 |
| ASM objects (VS2013 build 21005) | 10 |
| C objects (VS2013 build 21005) | 21 |
| C++ objects (VS2013 build 21005) | 6 |
| C++ objects (20806) | 10 |
| 221 (20806) | 2 |
| Imports (VS2003 (.NET) build 4035) | 2 |
| 221 (VS2013 build 21005) | 6 |
| Linker (VC++ 6.0 SP5 imp/exp build 8447) | 2 |
| Imports (VS2015 UPD3.1 build 24215) | 2 |
| 221 (VS2013 UPD4 build 31101) | 6 |
| Imports (65501) | 38 |
| 221 (30324) | 3 |
| Total imports | 1513 |
| C objects (VS2013 UPD4 build 31101) | 50 |
| C++ objects (VS2013 UPD4 build 31101) | 125 |
| Resource objects (VS2013 build 21005) | 1 |
| 151 | 1 |
| Linker (VS2013 UPD4 build 31101) | 1 |
No comments yet.