| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Jan-04 17:47:34 |
| Detected languages |
Process Default Language
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
2933966 bytes of data starting at offset 0xef400.
The overlay data has an entropy of 7.9983 and is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 12/69 (Scanned on 2026-05-08 22:23:51) |
AVG:
FileRepMalware [Misc]
Avast: FileRepMalware [Misc] CrowdStrike: win/malicious_confidence_60% (D) Cylance: Unsafe Elastic: malicious (high confidence) Fortinet: W32/SchoolGirl.OY!tr Gridinsoft: Trojan.Win32.Downloader.oa!s1 Jiangmin: Trojan.Sdum.anm McAfeeD: ti!C127DA8D06FF NANO-Antivirus: Trojan.Win32.Dwn.jvlqmk VBA32: Trojan.Diztakun Zillya: Trojan.Sdum.Win32.10190 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2023-Jan-04 17:47:34 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x84200 |
| SizeOfInitializedData | 0x6ae00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00063713 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x86000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf4000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
#17
|
|---|---|
| WINMM.dll |
timeBeginPeriod
joyGetDevCapsW joyGetPosEx timeEndPeriod |
| KERNEL32.dll |
MultiByteToWideChar
WideCharToMultiByte GlobalAddAtomW GlobalDeleteAtom lstrlenW GetCommandLineW GetExitCodeProcess GlobalAlloc GlobalLock GlobalUnlock SetErrorMode GetCurrentDirectoryW GlobalFree LoadLibraryW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA FindNextFileA FindFirstFileExA DecodePointer GetFileType GetProcessHeap LCMapStringW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetOEMCP IsValidCodePage GetStringTypeW GetCPInfo HeapFree HeapReAlloc HeapAlloc GetStdHandle FindNextFileW GetModuleHandleExW ExitProcess SetEnvironmentVariableW DeleteFileW HeapSize GetACP DeleteCriticalSection LeaveCriticalSection EnterCriticalSection EncodePointer RtlUnwind InitializeSListHead GetCurrentThreadId GetCurrentProcessId GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError QueryPerformanceFrequency QueryPerformanceCounter LoadLibraryExA GetModuleHandleW VirtualQuery VirtualProtect GetSystemInfo RaiseException CreateMutexW GetModuleFileNameW Sleep SetCurrentDirectoryW ReleaseMutex WaitForSingleObject FindClose FindFirstFileW CloseHandle SetFilePointerEx SetFilePointer WriteFile GetLastError ReadFile CreateFileW CreateDirectoryW GetTempFileNameW GetTempPathW WriteConsoleW RemoveDirectoryW GetVersionExW GetLocaleInfoW FreeLibrary GetProcAddress LoadLibraryExW SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers GetModuleFileNameA |
| USER32.dll |
DrawTextW
OffsetRect DestroyWindow PostQuitMessage DrawEdge GetUpdateRect DefMDIChildProcW EndPaint BeginPaint InflateRect GetClassNameW GetDlgItemTextW SendDlgItemMessageW EndDialog GetDlgItem SetDlgItemTextW GetTabbedTextExtentW MapVirtualKeyW GetInputState DrawMenuBar SetMenuInfo DestroyMenu LoadMenuIndirectW GetMenuItemCount SetWindowPlacement GetWindowPlacement EndDeferWindowPos DeferWindowPos BeginDeferWindowPos GetDesktopWindow GetSystemMenu UpdateWindow GetWindow RegisterClassW RegisterClassExW ModifyMenuW GetMenuStringW GetMenuItemID DialogBoxParamW FillRect LoadImageW LoadIconW GetMonitorInfoW MonitorFromWindow GetSystemMetrics RedrawWindow IsIconic IsDialogMessageW SetTimer GetClipboardData CloseClipboard SetClipboardData EmptyClipboard OpenClipboard IsClipboardFormatAvailable CheckMenuItem EnableMenuItem GetMenu PtInRect PostMessageW InvalidateRect SetFocus GetFocus CallWindowProcW RemovePropW SetPropW SetWindowLongW GetPropW MessageBoxW GetParent GetActiveWindow ShowCursor SetCapture ReleaseCapture GetKeyState GetWindowRect GetWindowDC SetCursorPos ClientToScreen ScreenToClient GetCursorPos LoadStringW MapWindowPoints SetWindowPos IsZoomed GetWindowLongW AdjustWindowRectEx SendMessageW LockWindowUpdate ShowWindow IsWindowVisible GetClientRect SetWindowTextW wsprintfW IntersectRect KillTimer DestroyIcon GetSubMenu DeleteMenu GetMenuState LoadCursorW SetCursor SystemParametersInfoW GetSysColor ReleaseDC CreateIconIndirect GetDC MsgWaitForMultipleObjects DispatchMessageW TranslateMessage TranslateMDISysAccel GetMessageW PeekMessageW DialogBoxIndirectParamW |
| GDI32.dll |
CreatePalette
SelectPalette RealizePalette EnumFontFamiliesExW GetStockObject SelectObject GetTextExtentPointW GetDeviceCaps GetObjectW CreateFontIndirectW DeleteObject CreatePen Rectangle LineTo SetBkColor ExtTextOutW SetTextColor SetBkMode CreateRectRgn GetClipRgn ExcludeClipRect SelectClipRgn SetDIBits CreateCompatibleBitmap CreateSolidBrush CreateBitmap |
| COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
| SHELL32.dll |
DragFinish
DragQueryFileW ShellExecuteExW DragAcceptFiles |
| MMFS2.dll (delay-loaded) |
#3
#172 #831 #19 #1033 #1145 #425 #1144 #423 #430 #1146 #121 #31 #1105 #255 #281 #174 #419 #688 #192 #120 #333 #80 #468 #280 #67 #125 #249 #276 #366 #959 #945 #123 #124 #11 #1049 #1036 #173 #493 #487 #372 #520 #585 #341 #342 #417 #355 #610 #445 #344 #50 #62 #34 #982 #1106 #1017 #876 #361 #32 #63 #832 #742 #102 #101 #17 #16 #103 #753 #536 #756 #343 #686 #443 #1000 #265 #1068 #162 #765 #1069 #379 #661 #1031 #433 #184 #191 #825 #201 #158 #177 #186 #163 #176 #189 #1073 #183 #153 #1072 #10 #9 #6 #8 #7 #766 #64 #43 #65 #66 #264 #587 #448 #286 #568 #169 #849 #571 #701 #703 #170 #51 #74 #83 #97 #81 #979 #79 #187 #82 #76 #78 #106 #107 #105 #168 #691 #75 #241 #272 #245 #274 #363 #645 #584 #519 #356 #739 #713 #137 #554 #155 #786 #619 #462 #761 #411 #1120 #469 #1134 #95 #1123 #1126 #94 #1124 #1125 #98 #91 #47 #24 #59 #61 #60 #70 #69 #68 #819 #820 #77 #72 #389 #755 #795 #1054 #1077 #204 #205 #1071 #203 #195 #198 #196 #199 #808 #813 #809 #807 #811 #810 #814 #812 #826 #827 #828 #422 #803 #806 #800 #802 #804 #798 #805 #799 #801 #797 #830 #829 #607 #1074 #494 #1130 #1029 #611 #1081 #27 #39 #29 #834 #1101 #1007 #837 #896 #975 #953 #893 #986 #954 #895 #1048 #929 #677 #412 #234 #612 #678 #413 #679 #1118 #680 #573 #414 #415 #416 #232 #972 #681 #476 #620 #762 #236 #114 #104 #171 #789 #790 #46 #111 #42 #113 #115 #254 #785 #722 #328 #116 #90 #84 #1010 #92 #1008 #1011 #117 #997 #996 #998 #108 #109 #73 #110 #71 #913 #859 #878 #994 #894 #974 #882 #948 #991 #269 #267 #268 #976 #1006 #985 #1037 #794 #1053 #1128 #35 #1080 #18 #340 #14 #984 #5 #418 #750 #695 #23 #1070 #373 #740 #546 #4 #1055 #2 #1104 |
| Attributes | 0x1 |
|---|---|
| Name | MMFS2.dll |
| ModuleHandle | 0xa28e8 |
| DelayImportAddressTable | 0xa23d0 |
| DelayImportNameTable | 0x9e724 |
| BoundDelayImportTable | 0x9ec3c |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0xa2260 |
| Ordinal | 2 |
|---|---|
| Address | 0xa2264 |
| ee67d99d-0785-45a2-8089-04dceeafb554 |
| Impossible d'initialiser l'application. |
| Erreur lors de l'ouverture du fichier. |
| Pas assez de mémoire! |
| Erreur de fichier! |
| Impossible de trouver %s! |
| Impossible de charger %s. Cet objet a peut-être besoin d'un programme externe ou d'une librairie non installée. |
| Il n'y a pas assez d'espace disponible sur le drive temporaire. Libérez de l'espace disque et ré-essayez. |
| Cette application a été construite avec une version incompatible de Clickteam Fusion. |
| Format inconnu! |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.0.294.14 |
| ProductVersion | 3.0.294.14 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Process Default Language |
| Resource LangID | Process Default Language |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Jan-04 17:47:34 |
| Version | 0.0 |
| SizeofData | 884 |
| AddressOfRawData | 0x9d4c4 |
| PointerToRawData | 0x9bac4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Jan-04 17:47:34 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4a1014 |
| SEHandlerTable | 0x49d420 |
| SEHandlerCount | 41 |
| XOR Key | 0xd8cfa4c9 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 46 |
| 243 (40116) | 139 |
| 242 (40116) | 35 |
| ASM objects (VS 2015/2017 runtime 26706) | 20 |
| C objects (VS 2015/2017 runtime 26706) | 20 |
| C++ objects (VS 2015/2017 runtime 26706) | 43 |
| Imports (VS2008 SP1 build 30729) | 15 |
| Total imports | 617 |
| C++ objects (LTCG) (27048) | 43 |
| Exports (27048) | 1 |
| Resource objects (27048) | 1 |
| Linker (27048) | 1 |
No comments yet.