| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2007-Nov-07 07:42:58 |
| Detected languages |
English - United States
|
| Debug artifacts |
setup.pdb
|
| FileDescription | Setup |
| FileVersion | 9.0.21022.8 built by: RTM |
| InternalName | setup.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | setup.exe |
| ProductVersion | 9.0.21022.8 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource FILEDATA0 detected as a PE Executable. |
| Info | The PE is digitally signed. |
Signer: \x00{\x002\x007\x005\x000\x006\x004\x00A\x009\x00-\x00F\x007\x009\x00A\x00-\x004\x00C\x002\x000\x00-\x00B\x008\x00A\x008\x00-\x001\x008\x003\x008\x001\x009\x004\x004\x00A\x007\x001\x00B\x00}
Issuer: \x00{\x002\x007\x005\x000\x006\x004\x00A\x009\x00-\x00F\x007\x009\x00A\x00-\x004\x00C\x002\x000\x00-\x00B\x008\x00A\x008\x00-\x001\x008\x003\x008\x001\x009\x004\x004\x00A\x007\x001\x00B\x00} |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2007-Nov-07 07:42:58 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x48c00 |
| SizeOfInitializedData | 0x49400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00028DA6 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x4a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 9.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x97000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x935b7 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateFileW
OpenProcess Process32NextW Process32FirstW CreateToolhelp32Snapshot GetCurrentProcessId SetFilePointer HeapSetInformation CreateEventA SetEvent SizeofResource LockResource LoadResource FindResourceA GetVersionExA CompareStringA GetFileAttributesA GetModuleFileNameA DeleteFileA MultiByteToWideChar GetTempPathA LocalFree FormatMessageA GetTimeFormatA GetDateFormatA CreateDirectoryA CopyFileA GetWindowsDirectoryA GetSystemDirectoryA GetSystemInfo GetCurrentProcess ExpandEnvironmentStringsA GlobalFree GlobalAlloc WideCharToMultiByte GetEnvironmentVariableA ReadFile Sleep GetDiskFreeSpaceExA IsValidCodePage EndUpdateResourceA DeleteCriticalSection CreateThread InitializeCriticalSection EnterCriticalSection LeaveCriticalSection MulDiv lstrlenW WaitForSingleObject GetExitCodeProcess CloseHandle GetTickCount FindFirstFileA FindNextFileA GetTempFileNameA FindClose GetProcessHeap UpdateResourceA BeginUpdateResourceA LoadLibraryA lstrlenA UpdateResourceW GetTempPathW GetTempFileNameW GetSystemDirectoryW GetModuleFileNameW GetFileAttributesW FormatMessageW FindResourceW DeleteFileW CreateDirectoryW CopyFileW BeginUpdateResourceW GetVersion CreateFileA SetStdHandle WriteConsoleW GetConsoleOutputCP WriteConsoleA GetLocaleInfoW IsValidLocale EnumSystemLocalesA GetLocaleInfoA GetUserDefaultLCID SetEndOfFile GetStringTypeW GetStringTypeA InitializeCriticalSectionAndSpinCount HeapSize FlushFileBuffers GetConsoleMode GetConsoleCP HeapReAlloc VirtualAlloc HeapAlloc LCMapStringW LCMapStringA GetOEMCP GetACP GetCPInfo GetSystemTimeAsFileTime GetLastError GetProcAddress FreeLibrary WriteFile LocalAlloc InterlockedExchange RaiseException GetCommandLineA GetStartupInfoA RtlUnwind HeapFree TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetModuleHandleW ExitProcess GetStdHandle FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapCreate VirtualFree QueryPerformanceCounter |
|---|---|
| GDI32.dll |
GetStockObject
GetObjectA EnumFontFamiliesExA CreateFontIndirectA DeleteObject CreateCompatibleDC GetDeviceCaps GetObjectW DeleteDC SelectObject GetTextMetricsA GetTextExtentPoint32A |
| ole32.dll |
CoInitialize
CoUninitialize |
| SHELL32.dll |
ShellExecuteExW
SHGetMalloc SHGetPathFromIDListW SHGetSpecialFolderLocation ShellExecuteW ShellExecuteA ShellExecuteExA |
| USER32.dll |
ShowScrollBar
GetClientRect SetClassLongA LoadCursorA SetCursor SetWindowTextA CreateDialogIndirectParamA CreateDialogParamA SetForegroundWindow EnableWindow GetFocus SetFocus ScreenToClient MoveWindow LoadImageA SetDlgItemTextA SendMessageA GetDlgItem MsgWaitForMultipleObjects PeekMessageA IsDialogMessageA TranslateMessage DispatchMessageA DestroyWindow ShowWindow SendDlgItemMessageA GetWindowRect SystemParametersInfoA ExitWindowsEx CharNextA MessageBoxA DrawTextW GetSystemMetrics GetDC GetDialogBaseUnits ReleaseDC MessageBoxW LoadIconA |
| ADVAPI32.dll (delay-loaded) |
RegCloseKey
FreeSid AllocateAndInitializeSid RegQueryValueExA RegOpenKeyExA CryptDestroyHash CryptReleaseContext CryptGetHashParam CryptHashData CryptCreateHash CryptAcquireContextA RegCreateKeyExA RegEnumValueA RegQueryInfoKeyA RegSetValueExW RegSetValueExA RegQueryInfoKeyW RegOpenKeyExW RegCreateKeyExW RegEnumValueW |
| Attributes | 0x1 |
|---|---|
| Name | ADVAPI32.dll |
| ModuleHandle | 0x4b804 |
| DelayImportAddressTable | 0x4b74c |
| DelayImportNameTable | 0x48644 |
| BoundDelayImportTable | 0x48864 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 9.0.21022.8 |
| ProductVersion | 9.0.21022.8 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | Setup |
| FileVersion (#2) | 9.0.21022.8 built by: RTM |
| InternalName | setup.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | setup.exe |
| ProductVersion (#2) | 9.0.21022.8 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2007-Nov-07 07:42:58 |
| Version | 0.0 |
| SizeofData | 34 |
| AddressOfRawData | 0x7200 |
| PointerToRawData | 0x6600 |
| Referenced File | setup.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x44a170 |
| SEHandlerTable | 0x407520 |
| SEHandlerCount | 204 |
| XOR Key | 0x2bc206cb |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 build 21022) | 18 |
| C objects (VS2008 build 21022) | 142 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 15 |
| Total imports | 335 |
| C++ objects (VS2008 build 21022) | 102 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 build 21022) | 1 |
No comments yet.