592781b763501610dd1ca845ab29352633136d880f5a7aa122eaab907f16cb08

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2010-Oct-11 06:23:32
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Can access the registry:
  • SHGetValueW
Malicious The file contains overlay data. 2131247 bytes of data starting at offset 0x2a800.
The file contains a CAB Installer file after the PE data.
Overlay data amounts for 92.4488% of the executable.
Safe VirusTotal score: 0/69 (Scanned on 2026-09-14 13:37:27) All the AVs think this file is safe.

Hashes

MD5 71c27dfd56fefa74951b588ee8ca3c46 🔍
SHA1 d466937b184f73319e7557ffa9f5fe6214ef0a73 🔍
SHA256 592781b763501610dd1ca845ab29352633136d880f5a7aa122eaab907f16cb08 🔍
SHA3 33705267973d2a4837d3608190f9767c84f9a641ac41f609c36dff05b68357bb 🔍
SSDeep 49152:YCpm1bZEpev0aF5GfB/aLe4qeuP/zt27af3ahJP+3+w5:Y31bKc0aOB/aLe4HuHzt27xhNj2 🔍
Imports Hash 260ce3925f0b8c904435875eff5fbe62 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2010-Oct-11 06:23:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x10800
SizeOfInitializedData 0x19c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00005F37 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x12000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x2e000
SizeOfHeaders 0x400
Checksum 0x33a2d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8229382f6f146bfbd83b3c12c8617e42 🔍
SHA1 77916be5bd998ab0e79a718f0daa3108c0538a31 🔍
SHA256 f601c853f74c54553533a2efc304a35a1e527425b09ea2fdd9e7e34a39ba40dd 🔍
SHA3 b907365a0133044ba9df241824bb3f7282b11d5c9176ea3923f6566b576a9ec5 🔍
VirtualSize 0x10614
VirtualAddress 0x1000
SizeOfRawData 0x10800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.63092

.rdata

MD5 c941e4acc5252c7247168fe382e57210 🔍
SHA1 f9dff5d1237f522fc84d551bef2b0571f4200584 🔍
SHA256 bbca99bb7acf7c01571ea982da8123c5146af15135b4b75dd4fe2336b2a628d9 🔍
SHA3 fbdb7ca236196f0a4add896244fb8ccedde9e63c450d88b02c9d607d43d4ef03 🔍
VirtualSize 0x2fb6
VirtualAddress 0x12000
SizeOfRawData 0x3000
PointerToRawData 0x10c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.39008

.data

MD5 5619c176e3ba1416303809f5c920461b 🔍
SHA1 f67bf90a4a41fd1314336e524baca1308a8bd356 🔍
SHA256 52e17980f7c16dc7b0350d054d709c76fa0092ef8549e575300b21f2a39861cb 🔍
SHA3 18c5788e16d07442c41f5a0c1be8765c5560500c4b36261208af7869a9876ea4 🔍
VirtualSize 0x2568
VirtualAddress 0x15000
SizeOfRawData 0x1200
PointerToRawData 0x13c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.62082

.rsrc

MD5 62fcb2eca4dc0cead28b8efc81bcca8e 🔍
SHA1 287f5e4e395547de080d77daa03927eac386bc5b 🔍
SHA256 dd03a486a1d3d54e06d8e94a05ac09b109d2365a3f2cb8f31843ef703ea8c06f 🔍
SHA3 0d577d062601e8c41ce4f70dba0334679bccf59fbd42ed5e81f8bee8044590fa 🔍
VirtualSize 0x158f0
VirtualAddress 0x18000
SizeOfRawData 0x15a00
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.61137

Imports

KERNEL32.dll lstrcpyW
lstrlenW
GetFileAttributesW
GetCurrentDirectoryW
GetModuleFileNameW
WideCharToMultiByte
MultiByteToWideChar
GetCurrentThreadId
TlsGetValue
TlsSetValue
GetTickCount
SetFileAttributesW
CloseHandle
SetFileTime
LocalFileTimeToFileTime
DosDateTimeToFileTime
CreateFileW
GetLastError
CreateDirectoryW
FreeLibrary
DeleteFileW
GetProcAddress
LoadLibraryW
TlsAlloc
LoadLibraryA
GetProcessHeap
SetEndOfFile
InitializeCriticalSectionAndSpinCount
HeapSize
HeapReAlloc
VirtualAlloc
GetLocaleInfoA
GetStringTypeW
RaiseException
RtlUnwind
ReadFile
SetFilePointer
WriteFile
GetConsoleCP
GetConsoleMode
GetCommandLineA
GetStartupInfoA
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
GetModuleHandleW
TlsFree
SetLastError
LCMapStringA
LCMapStringW
HeapFree
HeapAlloc
GetModuleHandleA
Sleep
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
SetStdHandle
EnterCriticalSection
LeaveCriticalSection
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
ExitProcess
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeA
USER32.dll UpdateWindow
DialogBoxParamW
KillTimer
EndDialog
wsprintfW
MessageBoxW
GetWindowTextW
LoadStringW
GetDlgItem
SetWindowTextW
SendDlgItemMessageW
SendMessageW
SetTimer
SHELL32.dll SHGetSpecialFolderLocation
SHBrowseForFolderW
SHGetPathFromIDListW
SHGetMalloc
SHLWAPI.dll SHGetValueW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.88368
MD5 4c7b4ebe204b069c423ed1ead53959dd 🔍
SHA1 449a3edb3c1416f4c9effa6873deeb4f2a9eb60d 🔍
SHA256 bdc78018d0c39d64e821616e3879b8dca0cfa2b8636e4ddaf6d5e9f8b7215fa0 🔍
SHA3 383a51e33ae71dc1885b4e136dda61889458ddb4eb125de71b58132194393bb4 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45419
MD5 06dd6e64035f92449d898748a17d3cd9 🔍
SHA1 5def612a093660700b020520c7bcb1379fc44a57 🔍
SHA256 c1a9becb19732bfa22551939d7c1da199d5dc0e2bbb4f227c12e315297536882 🔍
SHA3 83ce5483b3ae587c3b8bcb04cb40f446f6ff92eb39b3b0b1625987599c3970a4 🔍

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1088a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95823
Detected Filetype PNG graphic file
MD5 743a8cb937251aedd121225b4484271a 🔍
SHA1 47705918a48ed361a412925575cb11ba6ad9988a 🔍
SHA256 8273c16a960cab4bb5da41a64c5e679c9feee698504bcda75500058bdadfbb73 🔍
SHA3 86f6eae2481c702d7b645fe4a8dbc7daeb3b0036aecc3df8df93c9b70273c253 🔍

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15649
MD5 1a4c202b0a9191c1c43f15506dd59c42 🔍
SHA1 0d6a988bb990e77ee8ca93a1351450dccaaae924 🔍
SHA256 b7a2f11aedd1038155be5a51c0d4e119af1e54f10b70b379de9f185c8da21d8d 🔍
SHA3 09d7c1281cb25eb61cb0db100e3f6d9f9f99850484e2efafb7cb5dc3edfa571f 🔍

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.34076
MD5 88989b98428e551092a0c2b6b7f96599 🔍
SHA1 ee8e7516817d105a8bc649146574dd0fde16a659 🔍
SHA256 9584559529d56b37676f889a265414653b27597439f9233f2fe097183b1bd66b 🔍
SHA3 29200bbd148da9484ca4c2e0ea398793385aa4e0e582eec34a951628e9fda863 🔍

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92283
MD5 6a675d5e2a3ab6564f371b8cce0c17c9 🔍
SHA1 d20f26bd312602013cb7130ecaaa2d63934ff301 🔍
SHA256 de327dd091579eaae572924dca02cbb7b13357822dd6244cf3915b042ed67709 🔍
SHA3 c960d5916365a82979fe69298d492e18d1ebf70a232ef7647830ca2ce5bd5b29 🔍

101

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17433
MD5 2666f1e07d4e11a80a134011064f97f7 🔍
SHA1 ee1ceb1d332cb897ba49aecd4e40f4205b94624c 🔍
SHA256 ad6b4430271b885c20aec2bccac4b62a3d4e5fd12ac2c524a6fc9e16909c0b71 🔍
SHA3 ac3822c48ac4d1135ba1aae3fe58e20321b1e4ee15804f513c9c0dd8b0790850 🔍

102

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x9e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97599
MD5 7e90550a22f1bf52c39692fbb4c30008 🔍
SHA1 ea8fff471a9d7315300be5310a1e42a23943e4e0 🔍
SHA256 9218623c3788b841e18d8b4e16fe0ccf0584f5a6787b85ee6d1478b279acd494 🔍
SHA3 aa6c9d75bf55c70808fddf91967bb950a153c5f7a1e0acaec16338a60d4d8f53 🔍

1 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8785
MD5 a27a1ab977895f2a409063ea2be367fa 🔍
SHA1 261199ac6997a2a2dca64fc78e8bb2b8d973c190 🔍
SHA256 6e71828b8d4a506ee54e5b9b68c1ae6e9afb4c24a6636255c78c92bb9f9a5906 🔍
SHA3 0458d99ee0b2e9130e860e05be44947fd8a3d6208cc9689da0ec566d9014ced3 🔍

100

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62564
Detected Filetype Icon file
MD5 49a38b2609e0cdd045c656651a242ddf 🔍
SHA1 bdb831e6b245debb8c6c17c8f097041ebd19acf9 🔍
SHA256 b0e7d5c80d0c91dcb24323a0e13f4af7fa217f967c34c4810839490e5e680836 🔍
SHA3 85f10c0af20aff754c34a6ae7972cbc90a57b55bcfeb0ce276329f49e190b352 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x26e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02301
MD5 b8bf5471699c11a216ab9e6cc81184ec 🔍
SHA1 c83c5ccf4ea42b20af2a10d1f6ef7e1a733782a6 🔍
SHA256 cd5da690f175edb1a0c4c9e93f0f7e6ff74999be182f6680da05806dff33977b 🔍
SHA3 bb938e439477f7a36f7b6533b67218cc68b86cc18a40cb4d6a4aec768404c5c4 🔍

String Table contents

Extract Failed.
Choose Extract Folder:
Folder %s already exists.
Continue?

Version Info

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x415040
SEHandlerTable 0x413e40
SEHandlerCount 13

RICH Header

XOR Key 0xec8eca62
Unmarked objects 0
150 (20413) 1
ASM objects (VS2008 SP1 build 30729) 21
C objects (VS2008 SP1 build 30729) 113
Imports (VS2012 build 50727 / VS2005 build 50727) 9
Total imports 118
C++ objects (VS2008 SP1 build 30729) 48
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.