cf739822d53749d1b08e4f499cc8d20151c057b71de2c8d2d255e49155a4bcb2

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2011-Dec-05 14:11:16

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h)
Suspicious PEiD Signature: Crunch 4
Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
  • b3 eb 36 e4 4f 52 ce 11 9f 53 00 20 af 0b a7 70
May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • http://www.indigorose.com
  • http://www.tsstodd.com
  • indigorose.com
  • tsstodd.com
  • www.indigorose.com
  • www.tsstodd.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to Blowfish
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongA
  • GetWindowLongW
Can access the registry:
  • RegEnumKeyA
  • RegEnumValueA
  • RegEnumKeyExA
  • RegQueryInfoKeyA
  • RegDeleteValueA
  • RegDeleteKeyA
  • RegCreateKeyExA
  • RegOpenKeyA
  • RegCloseKey
  • RegSetValueExA
  • RegQueryValueExA
  • RegCreateKeyA
  • RegQueryValueA
  • RegSetValueA
  • RegOpenKeyExA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • CallNextHookEx
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • URLDownloadToFileA
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerA
  • QueryServiceStatus
  • ControlService
  • DeleteService
  • CreateServiceA
  • OpenServiceA
  • EnumServicesStatusA
Enumerates local disk drives:
  • GetDriveTypeA
  • GetVolumeInformationA
  • GetLogicalDriveStringsA
Manipulates other processes:
  • OpenProcess
Changes object ACLs:
  • SetNamedSecurityInfoA
  • SetFileSecurityA
Can take screenshots:
  • GetDCEx
  • FindWindowA
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Can use the microphone to record audio:
  • waveInOpen
Can shut the system down or lock the screen:
  • ExitWindowsEx
Safe VirusTotal score: 0/62 (Scanned on 2021-01-09 02:07:30) All the AVs think this file is safe.

Hashes

MD5 4746c50e6c1679ba108c1584d93288c1 🔍
SHA1 29e67f4f548b0dcbbd1579abd33e2a219e2c9bae 🔍
SHA256 cf739822d53749d1b08e4f499cc8d20151c057b71de2c8d2d255e49155a4bcb2 🔍
SHA3 92952e50b2fe3fdea133ca005b704dda5ce9a60aa92fbe9bb24ebe39afac5b2b 🔍
SSDeep 98304:dW24tXvqWApwYU26Vg6HxeYEpO2GQCN7yNTns+1CPSD7bwVKYloj9ghi1RebM39d:QvqW4wpY6HyoyNSSD7bwDojD390brV2 🔍
Imports Hash c4b0b4e10969ef6c95d7c9506a45d7b9 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x128

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2011-Dec-05 14:11:16
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x3d7c00
SizeOfInitializedData 0x237600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0024493B (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x3d9000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x664000
SizeOfHeaders 0x400
Checksum 0x62c86f
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8dbaaf79acd74c6c4e4cf508f966d670 🔍
SHA1 15a365ad84dc1f25819a9e204f832db9d2d05e71 🔍
SHA256 989c01abaf011b52fd380310d571ef2efb2c3ef0b4ac446be1d4b43e0587a5e9 🔍
SHA3 f1b6ef4b0317b09d0fc25f6ad526fa28dfac956d3d4a56d683417a52ea9aa511 🔍
VirtualSize 0x3d7a34
VirtualAddress 0x1000
SizeOfRawData 0x3d7c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66395

.rdata

MD5 c552cf901c6618517021a44987d408f1 🔍
SHA1 27c6fc6f0f2afe799f273a87f2c7379414879b33 🔍
SHA256 f3e5e968bdd98a3c167c901715e6e114e77ed98e7585790238847605d343bc42 🔍
SHA3 59638a29dbb5bd0ae8e083a625d3ec7a74e9baf805e853e08b215971a064960c 🔍
VirtualSize 0xd5638
VirtualAddress 0x3d9000
SizeOfRawData 0xd5800
PointerToRawData 0x3d8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.2685

.data

MD5 598db74946da4cd53683fabf209ec11a 🔍
SHA1 7b7c4b35858bf849e5adad74f47b9c20b2556adb 🔍
SHA256 db0b4c453e0d4af0c67fa30d14d3bb6e024b687380da8fcece5c8baa22093e05 🔍
SHA3 cd9b279cf849568c11c077c1ab1abc1bae898f369bdf98a5aa9048b19da6edf9 🔍
VirtualSize 0x76b58
VirtualAddress 0x4af000
SizeOfRawData 0x24400
PointerToRawData 0x4ad800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.3525

.rsrc

MD5 de629285299df8a99d0f62aeea0a15af 🔍
SHA1 acee98c8ac25fce7efb63b7c45033ee5d02c7ec0 🔍
SHA256 54d62c5af9b5a05f4fb28aabd75c0dc88739457fadf1aeb778aeada30ab4b7f1 🔍
SHA3 99da5877a8806efa464a19d22620e14e885da2eea22c2dedaedf86f0131b36ac 🔍
VirtualSize 0x13d990
VirtualAddress 0x526000
SizeOfRawData 0x13da00
PointerToRawData 0x4d1c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.45298

Imports

lua5.1.dll lua_pushfstring
lua_getinfo
lua_getstack
lua_pushlstring
lua_gettop
lua_tointeger
lua_isnumber
lua_concat
lua_isstring
lua_tothread
lua_type
luaL_newstate
lua_close
lua_sethook
lua_settop
luaL_openlibs
luaL_loadbuffer
lua_pushcclosure
lua_insert
lua_pcall
lua_remove
lua_pushstring
lua_setfield
lua_pushnumber
lua_pushboolean
lua_pushnil
lua_getfield
lua_tonumber
lua_toboolean
lua_createtable
lua_settable
lua_gettable
lua_error
lua_next
luaL_openlib
lua_pushvalue
lua_tolstring
WINMM.dll mixerOpen
mixerSetControlDetails
mixerGetLineInfoA
mixerGetLineControlsA
mixerGetControlDetailsA
waveInReset
waveInClose
waveInOpen
waveInStart
waveInGetNumDevs
waveInGetDevCapsA
waveInUnprepareHeader
mixerGetNumDevs
waveInAddBuffer
waveOutGetPosition
waveOutReset
waveOutWrite
waveOutUnprepareHeader
waveOutPrepareHeader
waveOutClose
waveOutOpen
waveOutGetNumDevs
waveOutGetDevCapsA
mciGetErrorStringA
mciSendCommandA
timeGetTime
mixerClose
waveInPrepareHeader
PlaySoundA
timeGetDevCaps
sndPlaySoundA
timeBeginPeriod
timeSetEvent
timeKillEvent
timeEndPeriod
WSOCK32.dll socket
WSAAsyncGetHostByName
inet_addr
WSACancelAsyncRequest
connect
ioctlsocket
htons
WSACleanup
WSAStartup
select
WSAGetLastError
__WSAFDIsSet
inet_ntoa
send
closesocket
recv
VERSION.dll GetFileVersionInfoA
GetFileVersionInfoSizeA
VerQueryValueA
MSACM32.dll acmStreamOpen
acmStreamConvert
acmStreamUnprepareHeader
acmStreamClose
acmStreamSize
acmStreamPrepareHeader
acmFormatSuggest
KERNEL32.dll LocalFileTimeToFileTime
DosDateTimeToFileTime
SetVolumeLabelA
GetLocalTime
FlushFileBuffers
MoveFileA
VirtualUnlock
FreeResource
VirtualFree
VirtualAlloc
GetModuleFileNameW
lstrcmpW
GlobalDeleteAtom
GlobalFindAtomA
GlobalAddAtomA
GlobalGetAtomNameA
GetThreadLocale
ResumeThread
LocalReAlloc
EnumResourceLanguagesA
ConvertDefaultLocale
GetFileTime
GetStringTypeExA
LockFile
UnlockFile
DuplicateHandle
GetFileAttributesExA
GetFileSizeEx
GetProfileIntA
GlobalFlags
GetCPInfo
GetOEMCP
GetModuleHandleW
LoadLibraryW
GetSystemDirectoryW
SearchPathA
FindResourceExA
HeapAlloc
HeapFree
GetSystemTimeAsFileTime
ExitProcess
GetTimeFormatA
GetDateFormatA
VirtualQuery
HeapReAlloc
GetCommandLineA
GetStartupInfoA
RtlUnwind
RaiseException
ExitThread
SetStdHandle
GetFileType
HeapSize
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetACP
IsValidCodePage
LCMapStringA
LCMapStringW
HeapCreate
GetStdHandle
CompareStringW
SetEnvironmentVariableW
GetStringTypeA
GetStringTypeW
InitializeCriticalSectionAndSpinCount
GetTimeZoneInformation
SetHandleCount
GetConsoleCP
GetConsoleMode
FreeEnvironmentStringsW
GetEnvironmentStringsW
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
GetProcessHeap
LocalLock
LocalUnlock
IsDBCSLeadByte
lstrcmpA
TlsGetValue
IsBadReadPtr
TlsFree
TlsSetValue
GlobalHandle
TlsAlloc
GetProcessAffinityMask
VirtualProtect
VirtualLock
OpenFile
InterlockedDecrement
QueryPerformanceCounter
QueryPerformanceFrequency
ResetEvent
GetCurrentThreadId
GetSystemDefaultLangID
DeviceIoControl
SetErrorMode
IsBadStringPtrA
WriteFile
SetEndOfFile
GetFileSize
GetSystemInfo
GlobalMemoryStatus
GetDriveTypeA
GetComputerNameA
ExpandEnvironmentStringsA
FreeEnvironmentStringsA
GetEnvironmentStrings
GetCurrentProcessId
GetLocaleInfoA
GlobalSize
TerminateThread
CreateThread
WaitForSingleObject
CreateEventA
SetEvent
GetExitCodeThread
GetThreadPriority
SetThreadPriority
DeleteCriticalSection
InitializeCriticalSection
GetCurrentThread
GetCurrentProcess
GetTickCount
LoadLibraryExA
TerminateProcess
OpenProcess
GetTempPathA
LocalFree
FormatMessageA
GetWindowsDirectoryA
GetShortPathNameA
MoveFileExA
CopyFileA
GetPrivateProfileSectionA
GetPrivateProfileStringA
GetPrivateProfileSectionNamesA
WritePrivateProfileStringA
lstrcpyA
MulDiv
GetTempFileNameA
GetExitCodeProcess
CreateProcessA
GetDiskFreeSpaceA
CreateDirectoryA
RemoveDirectoryA
DeleteFileA
SetFileTime
SystemTimeToFileTime
SetCurrentDirectoryA
GetCurrentDirectoryA
FindNextFileA
CloseHandle
ReadFile
SetFilePointer
CreateFileA
GetVolumeInformationA
GetFullPathNameA
FindClose
FindFirstFileA
FileTimeToSystemTime
FileTimeToLocalFileTime
lstrlenA
GlobalFree
GlobalReAlloc
GlobalUnlock
GlobalLock
GlobalAlloc
SetFileAttributesA
lstrcpynA
Sleep
GetEnvironmentVariableA
SetEnvironmentVariableA
GetSystemDirectoryA
FreeLibrary
lstrlenW
InterlockedIncrement
GetFileAttributesA
GetModuleFileNameA
GetProcAddress
GetModuleHandleA
LoadLibraryA
GetLastError
SetLastError
CompareStringA
GetVersionExA
MultiByteToWideChar
FindResourceA
LoadResource
LockResource
SizeofResource
WideCharToMultiByte
InterlockedExchange
EnterCriticalSection
LeaveCriticalSection
FileTimeToDosDateTime
lstrcmpiA
GetLogicalDriveStringsA
LocalAlloc
EnumResourceNamesA
LoadLibraryExW
LocalSize
EnumResourceTypesA
IsBadWritePtr
lstrcatA
USER32.dll DefMDIChildProcA
TranslateMDISysAccel
PostThreadMessageA
SubtractRect
GetTabbedTextExtentA
DestroyCursor
DrawIcon
GetDCEx
IsCharLowerA
MapVirtualKeyExA
SetWindowContextHelpId
MapDialogRect
IsMenu
IsZoomed
GetSysColorBrush
UnpackDDElParam
ReuseDDElParam
LoadAcceleratorsA
InsertMenuItemA
BringWindowToTop
TranslateAcceleratorA
DestroyAcceleratorTable
NotifyWinEvent
GetMessageA
ValidateRect
DestroyMenu
MapVirtualKeyA
GetKeyNameTextA
EndPaint
BeginPaint
GetMenuStringA
SetMenuItemBitmaps
GetMenuCheckMarkDimensions
ModifyMenuA
CheckMenuItem
WinHelpA
SetWindowsHookExA
CallNextHookEx
GetClassLongA
SetPropA
GetPropA
RemovePropA
GetLastActivePopup
BeginDeferWindowPos
EndDeferWindowPos
GetTopWindow
GetMessageTime
ScrollWindow
TrackPopupMenuEx
SetMenu
SetScrollRange
GetScrollRange
SetScrollPos
GetScrollPos
ShowScrollBar
GetClassInfoExA
AdjustWindowRectEx
DeferWindowPos
GetScrollInfo
SetScrollInfo
SetWindowPlacement
GetMenu
IsIconic
GetWindowPlacement
GetWindowTextLengthA
GetDlgCtrlID
IsDialogMessageA
SendDlgItemMessageA
CheckRadioButton
CheckDlgButton
UnhookWindowsHookEx
CreateDialogIndirectParamA
GetDlgItem
IsWindowEnabled
CharToOemA
OemToCharBuffA
CharLowerA
WaitForInputIdle
SetDlgItemTextA
SetWindowTextA
EndDialog
DialogBoxParamA
GetActiveWindow
OemToCharA
CharNextA
CharPrevA
CharUpperBuffA
CharLowerBuffA
UnregisterClassA
ExitWindowsEx
RemoveMenu
DrawMenuBar
CreateWindowExA
RegisterClassA
DestroyWindow
GetAsyncKeyState
GetNextDlgTabItem
WindowFromPoint
GetDoubleClickTime
ClipCursor
InvertRect
IsClipboardFormatAvailable
GetClassInfoA
DrawEdge
FrameRect
FillRect
TrackMouseEvent
InsertMenuA
EnableScrollBar
MapWindowPoints
DrawFrameControl
CreatePopupMenu
GetMenuItemCount
DefFrameProcA
GetWindowRgn
EqualRect
GetForegroundWindow
GetWindowThreadProcessId
GetWindowTextA
GetWindow
EnumWindows
SetActiveWindow
DrawAnimatedRects
SetParent
EnumChildWindows
FindWindowA
GetClassNameA
GetMenuItemID
TrackPopupMenu
SetMenuDefaultItem
GetSubMenu
SendMessageTimeoutA
MsgWaitForMultipleObjects
wsprintfA
DrawIconEx
LoadBitmapA
CharUpperA
GrayStringA
DrawTextExA
DrawTextA
TabbedTextOutA
MessageBeep
IsChild
RegisterWindowMessageA
ShowWindow
MoveWindow
UnionRect
SetWindowRgn
TranslateMessage
LoadCursorA
SetCursor
SetRectEmpty
DefWindowProcA
UpdateWindow
InvalidateRgn
IntersectRect
SetCapture
GetCapture
SetFocus
GetFocus
SetWindowPos
CallWindowProcA
GetWindowDC
EnableMenuItem
DeleteMenu
GetSystemMenu
PostQuitMessage
RegisterClassExA
GetMenuState
MessageBoxA
GetMessagePos
DestroyIcon
DrawFocusRect
SetRect
DrawStateA
InflateRect
GetIconInfo
GetMenuItemInfoA
CopyRect
GetSystemMetrics
AppendMenuA
SystemParametersInfoA
DispatchMessageA
PeekMessageA
CloseWindow
GetParent
PostMessageA
ReleaseCapture
GetKeyState
PtInRect
ScreenToClient
GetCursorPos
RedrawWindow
GetSysColor
InvalidateRect
IsWindowVisible
IsWindow
OffsetRect
LoadIconA
SendMessageA
SetTimer
KillTimer
EnableWindow
ReleaseDC
UpdateLayeredWindow
ClientToScreen
GetDesktopWindow
IsRectEmpty
GetClientRect
GetDC
GetWindowRect
LoadImageA
SetForegroundWindow
SetWindowLongA
GetWindowLongA
SetWindowLongW
GetWindowLongW
IsWindowUnicode
CreateIconIndirect
CreateIconFromResourceEx
CallWindowProcW
DefWindowProcW
DefFrameProcW
DefDlgProcA
CreateAcceleratorTableA
GetKeyboardState
GetKeyboardLayout
ToAsciiEx
CopyIcon
SetCursorPos
GetMenuDefaultItem
EmptyClipboard
CloseClipboard
SetClipboardData
CopyImage
OpenClipboard
WaitMessage
DefDlgProcW
DefMDIChildProcW
RegisterClassW
LookupIconIdFromDirectoryEx
GetMenuStringW
HideCaret
ShowCaret
GetCursor
ShowOwnedPopups
SetClassLongA
LockWindowUpdate
GetUpdateRect
GetNextDlgGroupItem
RegisterClipboardFormatA
CreateMenu
CopyAcceleratorTableA
GetKeyboardLayoutList
LoadMenuA
GDI32.dll AddFontResourceA
RemoveFontResourceA
CreateHalftonePalette
CreateFontIndirectA
GetTextColor
Polygon
SelectPalette
RealizePalette
GetWindowOrgEx
GetWindowExtEx
IntersectClipRect
CreateRectRgnIndirect
CombineRgn
LPtoDP
GetMapMode
GetViewportExtEx
DPtoLP
GetDeviceCaps
CreateRectRgn
BitBlt
ExtCreateRegion
CreateRoundRectRgn
GetBkColor
GetPaletteEntries
GdiFlush
PtVisible
RectVisible
TextOutA
ExtTextOutA
Escape
CreateFontA
EnumFontFamiliesExA
CreateScalableFontResourceA
CreatePalette
CreateBitmap
PatBlt
CreatePatternBrush
SetMapMode
ExcludeClipRect
LineTo
MoveToEx
SetTextAlign
AbortDoc
GetPixel
SetViewportExtEx
ScaleViewportExtEx
Rectangle
OffsetWindowOrgEx
SetWindowExtEx
ScaleWindowExtEx
GetCurrentPositionEx
PolyBezierTo
ExtSelectClipRgn
GetObjectType
CreateHatchBrush
GetStockObject
CreateEllipticRgn
CreatePolygonRgn
Polyline
Ellipse
GetRgnBox
CreateDIBitmap
EnumFontFamiliesA
GetTextCharsetInfo
GetCharWidthA
StretchDIBits
OffsetRgn
SetDIBColorTable
GetDIBits
StartPage
SetPixel
RoundRect
FillRgn
FrameRgn
GetBoundsRect
GetViewportOrgEx
ExtFloodFill
SetPaletteEntries
GetTextAlign
GetTextFaceA
GetNearestPaletteIndex
GetSystemPaletteEntries
DeleteMetaFile
SetPixelV
StartDocA
GetCurrentObject
SetViewportOrgEx
CreatePen
SetWindowOrgEx
GetTextExtentPoint32A
OffsetViewportOrgEx
SelectClipRgn
GetClipRgn
GetBkMode
GetTextMetricsA
CreateCompatibleBitmap
PtInRegion
EndDoc
SetStretchBltMode
SetROP2
SetPolyFillMode
RestoreDC
SaveDC
CreateDCA
CopyMetaFileA
SetTextColor
CreateSolidBrush
StretchBlt
SetBrushOrgEx
GetBitmapBits
GetTextExtentPoint32W
ExtTextOutW
StrokePath
FillPath
StrokeAndFillPath
EndPath
CloseFigure
BeginPath
SetWinMetaFileBits
DeleteEnhMetaFile
GetEnhMetaFileHeader
GetMetaFileBitsEx
GetMetaFileA
GetEnhMetaFileA
PlayEnhMetaFile
GetClipBox
GetDCOrgEx
SetBkColor
SetBkMode
GetStretchBltMode
SetRectRgn
DeleteDC
SelectObject
CreateDIBSection
EndPage
CreateCompatibleDC
GetObjectA
DeleteObject
MSIMG32.dll TransparentBlt
AlphaBlend
COMDLG32.dll GetSaveFileNameA
GetFileTitleA
WINSPOOL.DRV ClosePrinter
OpenPrinterA
DocumentPropertiesA
ADVAPI32.dll AdjustTokenPrivileges
RegEnumKeyA
GetUserNameA
UnlockServiceDatabase
OpenSCManagerA
GetServiceDisplayNameA
QueryServiceStatus
ControlService
StartServiceA
DeleteService
CloseServiceHandle
CreateServiceA
OpenServiceA
RegConnectRegistryA
RegEnumValueA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteValueA
RegDeleteKeyA
RegCreateKeyExA
EnumServicesStatusA
EqualSid
GetTokenInformation
OpenProcessToken
OpenThreadToken
RegOpenKeyA
LookupAccountSidA
SetNamedSecurityInfoA
SetEntriesInAclA
FreeSid
GetNamedSecurityInfoA
ConvertStringSidToSidA
AllocateAndInitializeSid
RegCloseKey
RegSetValueExA
RegQueryValueExA
RegCreateKeyA
GetFileSecurityA
SetFileSecurityA
RegQueryValueA
RegSetValueA
IsValidSid
LookupAccountNameA
ConvertSidToStringSidA
RegOpenKeyExA
LookupPrivilegeValueA
SHELL32.dll ShellExecuteExA
ExtractIconA
ShellExecuteA
SHBrowseForFolderA
SHGetPathFromIDListA
SHGetMalloc
DragQueryFileA
DragFinish
ExtractIconExA
SHGetFileInfoA
SHAppBarMessage
Shell_NotifyIconA
SHGetSpecialFolderLocation
COMCTL32.dll ImageList_GetImageInfo
ImageList_GetBkColor
FlatSB_GetScrollProp
_TrackMouseEvent
ImageList_DrawEx
ImageList_Destroy
ImageList_GetImageCount
ImageList_GetIconSize
ImageList_DrawIndirect
SHLWAPI.dll PathFindFileNameA
PathFindExtensionA
PathStripToRootA
PathIsUNCA
UrlUnescapeA
PathRemoveFileSpecW
oledlg.dll #1
#8
ole32.dll CreateStreamOnHGlobal
CLSIDFromString
CoCreateInstance
CoInitialize
OleDestroyMenuDescriptor
OleCreateMenuDescriptor
IsAccelerator
OleTranslateAccelerator
CoRegisterMessageFilter
CoRevokeClassObject
OleLockRunning
CoUninitialize
RevokeDragDrop
CoLockObjectExternal
RegisterDragDrop
DoDragDrop
OleGetClipboard
OleFlushClipboard
OleIsCurrentClipboard
OleSetClipboard
CoInitializeEx
OleInitialize
CoFreeUnusedLibraries
OleUninitialize
CreateILockBytesOnHGlobal
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
CoGetClassObject
CoDisconnectObject
CLSIDFromProgID
OleDuplicateData
CoTaskMemAlloc
ReleaseStgMedium
CoTaskMemFree
OLEAUT32.dll VariantTimeToSystemTime
SystemTimeToVariantTime
VarUdateFromDate
LoadTypeLib
RegisterTypeLib
VariantClear
SysStringLen
SysAllocStringByteLen
SysStringByteLen
OleCreateFontIndirect
SafeArrayDestroy
VariantChangeType
VariantCopy
SysAllocStringLen
VariantInit
SysAllocString
SysFreeString
OleLoadPicturePath
urlmon.dll URLDownloadToFileA
gdiplus.dll GdipCloneImage
GdiplusShutdown
GdipDrawImageI
GdipGetImageGraphicsContext
GdiplusStartup
GdipBitmapUnlockBits
GdipBitmapLockBits
GdipCreateBitmapFromScan0
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipGetImagePalette
GdipGetImagePaletteSize
GdipGetImagePixelFormat
GdipGetImageHeight
GdipGetImageWidth
GdipDisposeImage
GdipDeleteGraphics
GdipAlloc
GdipFree
NETAPI32.dll Netbios
IMM32.dll ImmGetOpenStatus
ImmReleaseContext
ImmGetContext
imagehlp.dll ImageDirectoryEntryToData
OLEACC.dll (delay-loaded) AccessibleObjectFromWindow
LresultFromObject
CreateStdAccessibleObject

Delayed Imports

Attributes 0x1
Name OLEACC.dll
ModuleHandle 0x512ca0
DelayImportAddressTable 0x4d31c0
DelayImportNameTable 0x4a98ec
BoundDelayImportTable 0x4a9bd4
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x1eaee223
Unmarked objects 0
C objects (VS2008 build 21022) 93
150 (20413) 11
ASM objects (VS2008 SP1 build 30729) 67
C objects (VS2008 SP1 build 30729) 250
C++ objects (VS2008 SP1 build 30729) 523
C objects (VC++ 6.0 SP5 imp/exp build 8447) 31
C++ objects (VS2008 build 21022) 127
C objects (VS2012 build 50727 / VS2005 build 50727) 17
Imports (VS2012 build 50727 / VS2005 build 50727) 44
Unmarked objects (#2) 7
49 (9044) 5
48 (9044) 75
Imports (VS2008 SP1 build 30729) 3
Total imports 1106
138 (VS2008 SP1 build 30729) 287
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

[!] Error: The PE's resource section exceeds the parsing limits. Resources will not be parsed.
Leave a comment

No comments yet.