23a186492e5eb4e59019070c48f11489

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-25 21:57:46
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegEnumKeyW
  • RegQueryValueExW
  • RegSetValueExW
  • RegCloseKey
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: VISUALWARE
Issuer: GlobalSign GCC R45 EV CodeSigning CA 2020
Safe VirusTotal score: 0/71 (Scanned on 2026-02-04 08:00:32) All the AVs think this file is safe.

Hashes

MD5 23a186492e5eb4e59019070c48f11489
SHA1 568884e162e044fad12c75759470023cfa476c10
SHA256 a32b43eaf5d54154322aee37e42f7237a4660cba5c4e5ff3f9211c2e71f6bcab
SHA3 8ee3ea6c5441aa9db97a2d8afaf734eae4c93262ef7e895e4395f52142931f92
SSDeep 49152:9mE88HAWMQIPiuZ/3i3txxHUrTCeQ++holG5YL6L:9mHW7Cpy3txoCeQ+myL6
Imports Hash 56a78d55f3f7af51443e58e0ce2fb5f6

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Sep-25 21:57:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6a00
SizeOfInitializedData 0x2da00
SizeOfUninitializedData 0x800
AddressOfEntryPoint 0x0000352D (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x9e000
SizeOfHeaders 0x400
Checksum 0x1eb65b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ce9df19df15aa7bfbc0a8d0af0b841d0
SHA1 6cba022a30ad3c84a5343e05a15e49562c18aba0
SHA256 c902047f3976f37a722b89e3e2401d690d77b3e70ebaf7a32e9ac5ce6ff34a5e
SHA3 a80cef7bf78b6d8cf31176f4f7b837d46a7ec1b2d2dd9ab44d791ec0b29f199c
VirtualSize 0x6897
VirtualAddress 0x1000
SizeOfRawData 0x6a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4584

.rdata

MD5 a118375c929d970903c1204233b7583d
SHA1 73c2bec231377068f99d5c55ff5c975960280e6c
SHA256 322668435dbcf8d7246f9f554db08e811dd251f45ad883764e7af6b723e51e0a
SHA3 712081c7df3abf95c9a3dacb7e21700d783b1ca8d1105fe9df0f6df834b73c24
VirtualSize 0x14a6
VirtualAddress 0x8000
SizeOfRawData 0x1600
PointerToRawData 0x6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.02411

.data

MD5 82a10c59a8679bb952fc8316070b8a6c
SHA1 7e347dcff055b97091b833896e1097b7ed374fdd
SHA256 05429ca22a1221b4c12a26881799b71b769633a366bccd17b0114acd29ac162f
SHA3 e2e59928a622a7543320d477ef40fed9784205f20846697c8936055ee1f94925
VirtualSize 0x2b018
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.15458

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1c000
VirtualAddress 0x36000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 a74be61da4cd863a4276c2b55c19cee4
SHA1 94ed13c3ac4c88425eaf046a55204a8b17a4e4ed
SHA256 ba965bb9679e3794e303a221677ce825918cca907417a22a2266c26a439870b2
SHA3 b1e72a5227edbd1cfe67a40628ece220415fe00575913b1d11e2d4376781fde1
VirtualSize 0x4b908
VirtualAddress 0x52000
SizeOfRawData 0x4ba00
PointerToRawData 0x8a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.72529

Imports

ADVAPI32.dll RegCreateKeyExW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegOpenKeyExW
RegEnumValueW
SHELL32.dll SHGetSpecialFolderLocation
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
IIDFromString
CoTaskMemFree
COMCTL32.dll #17
ImageList_Create
ImageList_Destroy
ImageList_AddMasked
USER32.dll GetClientRect
EndPaint
DrawTextW
IsWindowEnabled
DispatchMessageW
wsprintfA
CharNextA
CharPrevW
MessageBoxIndirectW
GetDlgItemTextW
SetDlgItemTextW
GetSystemMetrics
FillRect
AppendMenuW
TrackPopupMenu
OpenClipboard
SetClipboardData
CloseClipboard
IsWindowVisible
CallWindowProcW
GetMessagePos
CheckDlgButton
LoadCursorW
SetCursor
GetSysColor
SetWindowPos
GetWindowLongW
PeekMessageW
SetClassLongW
GetSystemMenu
EnableMenuItem
GetWindowRect
ScreenToClient
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
FindWindowExW
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
EmptyClipboard
CreatePopupMenu
GDI32.dll SetBkMode
SetBkColor
GetDeviceCaps
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
SetTextColor
SelectObject
KERNEL32.dll GetExitCodeProcess
WaitForSingleObject
GetModuleHandleA
GetProcAddress
GetSystemDirectoryW
lstrcatW
Sleep
lstrcpyA
WriteFile
GetTempFileNameW
CreateFileW
lstrcmpiA
RemoveDirectoryW
CreateProcessW
CreateDirectoryW
GetLastError
CreateThread
GlobalLock
GlobalUnlock
GetDiskFreeSpaceW
WideCharToMultiByte
lstrcpynW
lstrlenW
SetErrorMode
GetVersionExW
GetCommandLineW
GetTempPathW
GetWindowsDirectoryW
SetEnvironmentVariableW
CopyFileW
ExitProcess
GetCurrentProcess
GetModuleFileNameW
GetFileSize
GetTickCount
MulDiv
SetFileAttributesW
GetFileAttributesW
SetCurrentDirectoryW
MoveFileW
GetFullPathNameW
GetShortPathNameW
SearchPathW
CompareFileTime
SetFileTime
CloseHandle
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalFree
GlobalAlloc
GetModuleHandleW
LoadLibraryExW
MoveFileExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
lstrlenA
MultiByteToWideChar
ReadFile
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.03105
MD5 4030d73671e3a64331f2b23518b1975f
SHA1 3778bf42d2fb9654fe96e6dc87220ac4ef23537d
SHA256 8f44da2c0bf320c2b958ddd3bde45f4ac99cfbefe1f11fe0295a285bf5be0bbc
SHA3 777ff24377351e6a7abe5ea17eb93f674af737edea64b6297fca20cd142b0b75

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.19191
MD5 0b4a1b72d3dbc3016cf26a00650acba5
SHA1 d1aad55d265193904b6a3521793975a034ce48ae
SHA256 52cfcdc65a724f7e26df06e78b5d275ec454935cb219178e565f32bff59e41c7
SHA3 562a07458fe99fd57dfd111d379cddab0eb275b38b72fb08e34fcca999a2c7d4

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.35632
MD5 591e62344f5b7aff9121ccde3bc06aea
SHA1 307a6f17b2b8ad59130e1cb195b8af315e50ad2d
SHA256 a0928ff52817ed3ab44b7063c2dc138d79d565be5aaf357fc75ed8bceaf530bf
SHA3 cad18af67b3122c99c3552b5f27ee9efb65006529dcb702e878aad5d87c76b53

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66859
MD5 4e0a9c5457794eb64376e345a2a3da09
SHA1 b56a17cafbe698564c5c7d48b84e57591f836d63
SHA256 483c1e10a4e1466a077c4b0772ac1e718adb7e7864fa8fbcbf1e49c8853ff084
SHA3 83a427030d9fe33629e9e67a4d6ddf92ea040bf9a0c5eef879b5945235088fab

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x37f7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94915
Detected Filetype PNG graphic file
MD5 2b800fbee8b374fac827604639c0bf9b
SHA1 5aed3ff587cf46ba18e4065504c054030e6d4517
SHA256 9352838b288d364563117807d75349210e7e6fc04ebedd34d04e7ff7dbc5bf68
SHA3 babcee4d7456a56f897763c56ad6c80eb83f5c81f883cc62a3022325e123de2a

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.93843
MD5 bc4c939a1e4574f293a4d38a6dfd7b94
SHA1 7282444d2bcf1707ced33658d8bf841f696e0dbf
SHA256 25b14b92c3ad4a5e5e4898b849e29d51818ec296cae7def1b31da460948d6435
SHA3 ca082af4046a377bd1c181e89826fd9666f99fd37359bad66f790bd265332e15

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43723
MD5 7fce87ca1b8e03f3f7f26cf48ff0fd1a
SHA1 dea23b40c1ab0e874bc239df0cff039fd54b0864
SHA256 87985ffcdb6e0ae7100c91c331f3664280cc94962a3389b300abd30354c6627a
SHA3 cae8246b25af07f71eed513cc243934604d2ec19f908046fd2b40a764bf7ea6e

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.79825
MD5 dbc06c7bb6c50b6790b6ccf501da7fa7
SHA1 ce7a00a8c5e6975398e0a9fa3dc1e9f48da187d8
SHA256 42b80c41f481add925a7c018bd5fb382b36e81fd53d83cee7a8253a6f15ffb0e
SHA3 6e7b4c5cba867f70313fa9313ba94b06520896ac375a3f428d2ffac49ef6ad26

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.27938
MD5 4db71b4a4e4166b42b95ebdd5f3285b4
SHA1 6245f969ecbf2d364f1fe789b58afc34689c9c50
SHA256 a1db71fa288c28d350f59b0d7ecb94042864a996ebee844bea9b1667ee578895
SHA3 f901a1040f6af38166585952929ec76cac369da8c25f3074a2c683c6d6d75bca

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68372
MD5 583fb02149a19ffff54516cfd5edebd4
SHA1 9de29568e142e36811e4fc5130e60fdb78f3db06
SHA256 9dfacbe444e14cd17c5956afa713f043c2b1150d37868af1661b5bb848fee3f5
SHA3 6c2967d2415996675fe0ca406c7a3ab94fe6cfd18bf7b98cf11f20c314b3fc81

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 5b3e1cb25be7a2dbae4f08f0d4794ed23dbd6ea37a3f9702be12dba588f42a7b

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92767
MD5 1db3e4c32b9560257ddf3506fef9dd3f
SHA1 6666e0c8336456cfacec71d84415c6516e9e2673
SHA256 587a03198c39f990e77691056bb5705e21374281862ce06de94c68172f50f763
SHA3 30ca0affc3f1d2ef8b37f2103db7581caaf88548823fb3ae1d308fae9738dab4

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07075
Detected Filetype Icon file
MD5 d8df1cc55778627a9db56329b771a0ba
SHA1 7c733f114a50ce2aa3cc56d7efefca2447d54abf
SHA256 66039c5638800b99145f5efea38639463cf5a50e7d1a1a3a0c08cd50cd3288d6
SHA3 15c07509b8abf1f29d5f6ee5dd55e884ae6015e461fe33afc720972a3c526068

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x42a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29667
MD5 ce1a1b88b240dc5b256df883d2e5f7a6
SHA1 91da55100458d138965d2696a5e03b7016c59ef9
SHA256 e96e376abf99a4a8bf75e01410303516655ed98a36b8f61f1db71161992fe979
SHA3 c329b586cf35a84677191b3cde3a1d9164cdc6f38d6021aa8d356e7305b704dc

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!