65a7cb8fd1c7c529c40345b4746818f8947be736aa105007dfcc57b05897ed62

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2017-Jul-16 21:09:16
Detected languages English - United States
Debug artifacts C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb
CompanyName Microsoft Corporation
FileDescription Box Stub
FileVersion 14.7.2224.0 built by: NETFXDEV1(RAKSINGH-SECURE-RAKSINGH)
InternalName BoxStub.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename BoxStub.exe
ProductName Microsoft® .NET Framework
ProductVersion 14.7.2224.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Microsoft's Cryptography API
Suspicious The PE is possibly packed. Unusual section name found: .boxld01
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Possibly launches other programs:
  • CreateProcessW
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptGenRandom
  • CryptReleaseContext
Enumerates local disk drives:
  • GetLogicalDriveStringsW
  • GetDriveTypeW
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA
Safe VirusTotal score: 0/69 (Scanned on 2026-07-14 13:36:52) All the AVs think this file is safe.

Hashes

MD5 4fb795478a8f346c337a1f84baccc85b 🔍
SHA1 c0919415622d86c3d6ab19f0f92ea938788db847 🔍
SHA256 65a7cb8fd1c7c529c40345b4746818f8947be736aa105007dfcc57b05897ed62 🔍
SHA3 f217de1775c76fb093d279ad4691074258d6fae14d9428af80c98c755c3d64e4 🔍
SSDeep 24576:QGHL3siy9GlFSmtLvUDSRbm4Jah1rVxbMA4/syY9bkfHV8fasGJu/vqIluFhr6gP:FL3s76UeTUDBzrVxbMyh9bkfHV7JVIGb 🔍
Imports Hash f686eb34528e6097943b1f1e7edb826b 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2017-Jul-16 21:09:16
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0x27200
SizeOfInitializedData 0x7200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00018EE7 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x29000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion A.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x35000
SizeOfHeaders 0x400
Checksum 0x15ee4c
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7b3b1ee9ae8ad7764ec9d706f5340480 🔍
SHA1 4444f74aa968d8f96dff8d2753fe90f2392bed28 🔍
SHA256 02eaf0fb7b349f7e3cd5f15bdd1245ccadba3a12695889238b37cea210c2418d 🔍
SHA3 73f7ee42677d4fa277b6bba72a0a3d5246cc39350911ec6ebf2a03392af0ffe4 🔍
VirtualSize 0x2717a
VirtualAddress 0x1000
SizeOfRawData 0x27200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57385

.data

MD5 a149d291b9bcd11002c627167764f938 🔍
SHA1 0646d1cdf50348a4233c93ef696c03d3eb957603 🔍
SHA256 2460ee2ce3e77a53c07b236e68553b009d9309e50097008779cc46d2530c3b03 🔍
SHA3 f94a6518f3f01ed483a3d8b0e58db5d707a53a5dcacdb391caf8d647dcea0610 🔍
VirtualSize 0x3760
VirtualAddress 0x29000
SizeOfRawData 0x1400
PointerToRawData 0x27600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.4578

.idata

MD5 21f29dcea9763e518871fb03f70a5066 🔍
SHA1 ceaac9ea79baf85c5bcfef18eab49eb959833bd7 🔍
SHA256 13af283a4a704805cb07b2185fd04f9769aa385c027ab72be943ab5fee9a842b 🔍
SHA3 2da7e9af41b101b32fdb769d3b8ea8fd16466df515c05e2ba4fb626c095c99a9 🔍
VirtualSize 0x11e8
VirtualAddress 0x2d000
SizeOfRawData 0x1200
PointerToRawData 0x28a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.49693

.boxld01

MD5 a45102199314f711a564649aa722b8d6 🔍
SHA1 9f11197217cc69608807ac9e73836b5a99fcc301 🔍
SHA256 e3a10f1ba41b09efe366cb604701189a260f1fc2977878cb0abe7d0f94d95e7c 🔍
SHA3 a7ba64c196c46d877c372898c4e4c56e24719430a7ddfe8e39ce71e251ceac45 🔍
VirtualSize 0xb6
VirtualAddress 0x2f000
SizeOfRawData 0x200
PointerToRawData 0x29c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.67157

.rsrc

MD5 7ffaf02673b8edb0c1707a5ab1e24de5 🔍
SHA1 5faa686d2139b2d1215bb8bbe39450a7969ecf75 🔍
SHA256 abe26d19e3f15a8df829f40d2bd07a961f5cfb0acc95292b9c2c15d9a76df5d1 🔍
SHA3 9b52f2a3c8b0f6b0270d556f1d5da95ba90baaa8a4213314ad7ddfebfdbbd066 🔍
VirtualSize 0x1f18
VirtualAddress 0x30000
SizeOfRawData 0x2000
PointerToRawData 0x29e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.27609

.reloc

MD5 0e90504f35d64a06ae725d5c4572a9e4 🔍
SHA1 19d208084cd4eecaefe4b788a84bcd5768a8d11a 🔍
SHA256 375e49e0b044153a357456bb038775469cd0585c6aafb4496725ff56b0b1b60a 🔍
SHA3 a7d3ab8aa3c130e22826f73ca9bcaff8557a25c947b2d4edc8772014ed9d9e31 🔍
VirtualSize 0x2944
VirtualAddress 0x32000
SizeOfRawData 0x2a00
PointerToRawData 0x2be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.98867

Imports

ADVAPI32.dll CreateWellKnownSid
InitializeSecurityDescriptor
SetEntriesInAclW
SetSecurityDescriptorDacl
SetSecurityDescriptorOwner
CryptAcquireContextW
CryptGenRandom
CryptReleaseContext
DecryptFileW
KERNEL32.dll GetTickCount
SetEnvironmentVariableW
GetLastError
ExpandEnvironmentStringsW
CreateProcessW
Sleep
WaitForSingleObject
GetExitCodeProcess
CloseHandle
SetFileAttributesW
InitializeCriticalSection
CreateEventW
GetEnvironmentVariableW
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
SetEvent
GetCommandLineW
lstrlenW
CompareStringW
LocalFree
CreateDirectoryW
QueryDosDeviceW
GetLogicalDriveStringsW
GetDiskFreeSpaceExW
GetDriveTypeW
CreateFileW
DeviceIoControl
SetErrorMode
RemoveDirectoryW
MoveFileExW
GetProcAddress
GetSystemDirectoryW
LoadLibraryW
GetModuleHandleW
CreateThread
LocalAlloc
RaiseException
ExitThread
WaitForMultipleObjects
ResetEvent
CreateEventA
GetSystemInfo
FileTimeToSystemTime
FileTimeToLocalFileTime
FileTimeToDosDateTime
GetModuleHandleA
GetVersionExA
SetFileTime
LocalFileTimeToFileTime
DosDateTimeToFileTime
SetEndOfFile
DuplicateHandle
ReadFile
SetFilePointerEx
GlobalFree
GetCommandLineA
HeapSetInformation
GetStartupInfoW
SetUnhandledExceptionFilter
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameW
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
HeapFree
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapAlloc
LCMapStringW
FreeLibrary
InterlockedExchange
RtlUnwind
SetFilePointer
GetConsoleCP
GetConsoleMode
MultiByteToWideChar
GetStringTypeW
HeapSize
HeapReAlloc
IsProcessorFeaturePresent
SetStdHandle
WriteConsoleW
FlushFileBuffers
CreateFileA
GetLocalTime
GetComputerNameW
lstrlenA
FormatMessageW
GetSystemTime
GetTimeZoneInformation
SystemTimeToTzSpecificLocalTime
DeleteFileW
GetFileAttributesW
FindFirstFileW
FindNextFileW
FindClose
GetCurrentDirectoryW
SetCurrentDirectoryW
GetProcessHeap
GlobalAlloc
LoadLibraryA
COMCTL32.dll #17
RPCRT4.dll UuidToStringW
UuidCreate
RpcStringFreeW
SHELL32.dll CommandLineToArgvW
SHBrowseForFolderW
SHGetPathFromIDListW
SHLWAPI.dll PathRemoveExtensionW
USER32.dll MessageBoxW
GetTopWindow
GetWindowThreadProcessId
GetWindow
SendMessageW
PostMessageW
DialogBoxParamW
GetDlgItem
SetWindowTextW
EndDialog
PostQuitMessage
LoadStringW
SetWindowLongW
GetWindowLongW
CharUpperW
OLEAUT32.dll SysAllocString
VariantClear
Cabinet.dll (delay-loaded) #23
#22
#20

Delayed Imports

Attributes 0x1
Name Cabinet.dll
ModuleHandle 0x2af2c
DelayImportAddressTable 0x2a230
DelayImportNameTable 0x28054
BoundDelayImportTable 0x280b8
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

?dwPlaceholder@@3PAEA

Ordinal 1
Address 0x2f000

_DecodePointerInternal@4

Ordinal 2
Address 0xb99c

_EncodePointerInternal@4

Ordinal 3
Address 0xb981

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.98575
MD5 8100b2b22fba8347d8b166c11b075610 🔍
SHA1 f0ca10f3fd0cb66f76fd68d13d2a6eccb9197e1a 🔍
SHA256 1d0befd3d3b9277cd664e4fc1af9a8a4a524be3b1ca47e45c2b8a2dd00b97320 🔍
SHA3 05974ed337505800d68903a7b6b3b8a94546023ffc4af2e81504323ee2511adc 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3126
MD5 f37f643aac31d000c75788e118b7709a 🔍
SHA1 879f00328a99c1f35a30ef03dcf3a4b448592308 🔍
SHA256 82b5677fe0b8a309b111ad83a26f7ed2dcfcd58bb04407b4be8cbedadfbf7536 🔍
SHA3 a70456f1ae3d829748601975c86672a3287aaa3ae0a1e98afbc7551633905c8d 🔍

129

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x10c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13202
MD5 c76b372cb6902f47b9c94f1277e46cad 🔍
SHA1 cea5c48c80ee0313071c3e4610b896fafaff6dec 🔍
SHA256 c1ab53d2c56133b7887cb6c0595e339dab433e9a549f2111ec8d166de1322012 🔍
SHA3 bb783ca01943e1bed96b1bfc02fbd7fc06287dc0fc26b532d5af5cc7f60604c7 🔍

130

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x170
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 223bf019ef684ea9fcabeb35f22e78fd 🔍
SHA1 8377fcf928a05da22b3e5aec03ca2705dabb0bb3 🔍
SHA256 09badb19582df8788a5228c5c359c0976aee4b103b7139631c39fb6264daf823 🔍
SHA3 b020d24a3b316c2d90ccdd708f587b78d2048f497505ac408a951cd53f039919 🔍

1 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x582
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12155
MD5 76eed4c078a520c54b0a656f4576aa02 🔍
SHA1 5910e8e14575eb2d504f48ce926f82a885f02e26 🔍
SHA256 7a68bc5a303efd22a041441faceab409f47cfa727024a826fc4d0645d97491c9 🔍
SHA3 0a5dbe23aef8bb78bdd6a6293fa45b9582c66546cceca78980e1dbfef96ab43a 🔍

2 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65184
MD5 62609fee688f97cf3346a45e261ccc55 🔍
SHA1 826545b7fe7b8861bc6d308bc6687c9c8d078c2c 🔍
SHA256 2c3a0f4ce43f35752c87dadc5909801e492e0153e207f752ccdfac66581d54f2 🔍
SHA3 285a869a439f47d6f6a518917a56fca328e17a24adedcf6a25d15b72e7407972 🔍

32

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x40
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.85835
MD5 262dba98793a9b36d0daa0bff917561a 🔍
SHA1 a5d2b8b36c2f9001c7c49b400d8c016974034c95 🔍
SHA256 515634f628249ed0d61c55af378ae06240ab3059d1e584c2d226dd9c36e801bd 🔍
SHA3 a3bace9322dc16390d1dde3d6c96ca6bf909569b893ba0bb53b07f037e7ca316 🔍

107

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.37086
Detected Filetype Icon file
MD5 d59e0d372ea5fd8c1f4de744376a6af4 🔍
SHA1 6883ce60e71a83424db0b41d0ab6bf61080e3de2 🔍
SHA256 b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b 🔍
SHA3 5e39df982879204dd9f129a37d1e1c2ff906e88de9ae01b4418db5e8455e7ae1 🔍

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x640
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.3197
MD5 4730b52157c873020c6ce43eeb9962f9 🔍
SHA1 8a3cd28b70251d4a65aeb100be7575afad580969 🔍
SHA256 7d01b3d006ed07fc00aac60f8b49989e2ff26e0cf018b67170d8db3072fe01ae 🔍
SHA3 538d2a59bb171d4ff6ac6d6a9621aa14208d904d13a2948e9c0183ad52a30148 🔍

1 (#4)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x380
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59763
MD5 ad4c845b055fe3f86c195fb42aea089e 🔍
SHA1 9460ec1d6076257edd78ef85e0980bb4008fd716 🔍
SHA256 55516801b8169bcefc54b89f3b9e1720a5f28ac38eae9cdeda273669f3c4aa9c 🔍
SHA3 e4f2630607522c03aeb2ae09e23632345aaf8941ef91b8bcf36cfc2408da078a 🔍

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x598
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19477
MD5 9d103f7e1321b5c15a26c934136514da 🔍
SHA1 d7a4a21fe9d32d0eb15a1a45cd674344df559053 🔍
SHA256 71e998265c748e082db2794fafd6279bf2abfbf72f8a612cdf6c4c6c585bab4f 🔍
SHA3 0d53aca89b371647739cdd7ee77d891b42a5999af7ee6932237e2388dc00d355 🔍

String Table contents

Preparing:
Are you sure you want to cancel?
An error was encountered.
There is not enough disk space on your drive for the new files
to be uncompressed and installed. Please run this application
again after you have freed some space on your drive.
Unable to create or save new files in the folder into which
the files are being extracted. Please check the folder properties
to ensure you have permission on the folder to
write files and that the folder is not read-only.
The application cannot find one of its required files, possibly
because it was unable to create it in the folder. Please make
sure that the folder in which this application was downloaded is
accessible and not read-only.
Unable to execute the embedded application to complete the installation.
Extracting files

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2017-Jul-16 21:09:16
Version 0.0
SizeofData 88
AddressOfRawData 0x5848
PointerToRawData 0x4c48
Referenced File C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x429050
SEHandlerTable 0x4059d0
SEHandlerCount 59

RICH Header

XOR Key 0x57da3e54
Unmarked objects 0
ASM objects (VS2010 SP1 build 40219) 1
C objects (VS2012 build 50727 / VS2005 build 50727) 3
C objects (65501) 1
C++ objects (VS2010 build 30319) 46
ASM objects (VS2010 build 30319) 20
C objects (VS2010 build 30319) 105
Imports (65501) 17
Total imports 199
175 (VS2010 SP1 build 40219) 70
Exports (VS2010 SP1 build 40219) 1
Resource objects (VS2010 SP1 build 40219) 1
Linker (VS2010 SP1 build 40219) 1

Errors

[*] Warning: Multiple nodes using the name Version Info in a dictionary.
Leave a comment

No comments yet.