| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Sep-01 13:43:08 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
installer.pdb
|
| FileVersion | 2.7.0.3 |
| InternalName | installer |
| LegalCopyright | Copyright (C) 2025 Kristjan Skutta |
| OriginalFilename | installer.exe |
| ProductName | Wallpaper Engine Installer |
| ProductVersion | 2.7.0.3 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Skutta Software GmbH
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/70 (Scanned on 2026-03-02 10:06:00) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x40 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Sep-01 13:43:08 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x29c00 |
| SizeOfInitializedData | 0x38c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00009BBB (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2b000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x66000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x727e4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
MultiByteToWideChar
IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetCurrentProcess TerminateProcess WriteConsoleW HeapSize GetTimeZoneInformation FormatMessageA LocalFree GetLocaleInfoEx GetCurrentDirectoryW CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW CloseHandle GetLastError GetProcAddress GetFileInformationByHandleEx WideCharToMultiByte GetStringTypeW ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx GetCPInfo RaiseException RtlUnwind SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW GetStdHandle WriteFile HeapFree HeapAlloc IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW FlsAlloc FlsGetValue FlsSetValue FlsFree VirtualProtect GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetProcessHeap GetFileType SetStdHandle GetFileSizeEx SetFilePointerEx FlushFileBuffers GetConsoleOutputCP GetConsoleMode ReadFile ReadConsoleW HeapReAlloc SetEndOfFile |
|---|---|
| SHELL32.dll |
ShellExecuteW
|
| Ordinal | 1 |
|---|---|
| Address | 0x38b78 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.7.0.3 |
| ProductVersion | 2.7.0.3 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | UNKNOWN |
| FileVersion (#2) | 2.7.0.3 |
| InternalName | installer |
| LegalCopyright | Copyright (C) 2025 Kristjan Skutta |
| OriginalFilename | installer.exe |
| ProductName | Wallpaper Engine Installer |
| ProductVersion (#2) | 2.7.0.3 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Sep-01 13:43:08 |
| Version | 0.0 |
| SizeofData | 38 |
| AddressOfRawData | 0x360b0 |
| PointerToRawData | 0x350b0 |
| Referenced File | installer.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Sep-01 13:43:08 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x360d8 |
| PointerToRawData | 0x350d8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Sep-01 13:43:08 |
| Version | 0.0 |
| SizeofData | 1060 |
| AddressOfRawData | 0x360ec |
| PointerToRawData | 0x350ec |
| StartAddressOfRawData | 0x436520 |
|---|---|
| EndAddressOfRawData | 0x436522 |
| AddressOfIndex | 0x439d08 |
| AddressOfCallbacks | 0x42b1ec |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
| Callbacks |
0x00429E61
|
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x438040 |
| SEHandlerTable | 0x435f8c |
| SEHandlerCount | 17 |
No comments yet.