| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2018-Mar-24 23:52:36 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\users\franci~1\docume~1\projects\interc~1\instal~1\exe\objfre_wxp_x86\i386\install-interception.pdb
|
| CompanyName | Francisco Lopes |
| FileDescription | Interception command line installation tool |
| FileVersion | 1.00 built by: WinDDK |
| InternalName | install-interception.exe |
| LegalCopyright | Copyright (C) 2008-2018 Francisco Lopes da Silva |
| OriginalFilename | install-interception.exe |
| ProductName | Interception |
| ProductVersion | 1.00 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Info | The PE contains common functions which appear in legitimate applications. |
Can access the registry:
|
| Malicious | The PE is possibly a dropper. |
Resource KBDNT51X86 detected as a PE Executable.
Resource KBDNT52A64 detected as a PE Executable. Resource KBDNT52I64 detected as a PE Executable. Resource KBDNT52X86 detected as a PE Executable. Resource KBDNT60A64 detected as a PE Executable. Resource KBDNT60I64 detected as a PE Executable. Resource KBDNT60X86 detected as a PE Executable. Resource KBDNT61A64 detected as a PE Executable. Resource KBDNT61I64 detected as a PE Executable. Resource KBDNT61X86 detected as a PE Executable. Resource MOUNT51X86 detected as a PE Executable. Resource MOUNT52A64 detected as a PE Executable. Resource MOUNT52I64 detected as a PE Executable. Resource MOUNT52X86 detected as a PE Executable. Resource MOUNT60A64 detected as a PE Executable. Resource MOUNT60I64 detected as a PE Executable. Resource MOUNT60X86 detected as a PE Executable. Resource MOUNT61A64 detected as a PE Executable. Resource MOUNT61I64 detected as a PE Executable. Resource MOUNT61X86 detected as a PE Executable. Resources amount for 91.9299% of the executable. |
| Safe | VirusTotal score: 0/70 (Scanned on 2026-09-30 15:32:24) | All the AVs think this file is safe. |
| MD5 | 0f0b50d92e030b8965ce669c8058fa6e 🔍 |
|---|---|
| SHA1 | 257b3f0402285a29f4618b32958c208b3e9d4c4d 🔍 |
| SHA256 | e137863a79da797f08e7a137280ff2a123809044a888fd75ce9c973198915abe 🔍 |
| SHA3 | a10edc30288782aa7cb98787b2dc07da9e3270daf33decfc0338381cb0cbc024 🔍 |
| SSDeep | 6144:+sglhAWORQG8O1dMDmJPjQy4xZWLUKc2:+s4LjGvMk74+B 🔍 |
| Imports Hash | 51850908103fac568ec032763c0d304c 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2018-Mar-24 23:52:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.1 |
| SizeOfCode | 0x7400 |
| SizeOfInitializedData | 0x6bc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000614C (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x9000 |
| ImageBase | 0x1000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 6.1 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x75000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x73ee6 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | f816ef1172d630becd862509fa267f20 🔍 |
|---|---|
| SHA1 | beab3b691ffe49ac115d005ad6e3f00853d33ba1 🔍 |
| SHA256 | ca333f2424ed5c838e5ef77fe5fdc06ae28ddf50ef59670eaab1ac09417158b3 🔍 |
| SHA3 | fffb4c42e2b3f5c172fcd447d765469b3ef9389cc35652f6fd458d67b02d3332 🔍 |
| VirtualSize | 0x7348 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x7400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.29395 |
| MD5 | 5cdbc8d836e28a8ef555e1cd75b7de67 🔍 |
|---|---|
| SHA1 | 1043d6711cc1ed40961443bb4c547a3fde61f200 🔍 |
| SHA256 | adf7245f88b615fdcde42325d31ca035bfc57381b4da0672aaab232793fa6936 🔍 |
| SHA3 | 4492ce65c406a45d33e0b7abc4897ff6126045c8262be179403ab1bf9758637a 🔍 |
| VirtualSize | 0xa64 |
| VirtualAddress | 0x9000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x7800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.61902 |
| MD5 | bdc6a91804b4ea1535b825315a3552d8 🔍 |
|---|---|
| SHA1 | 7d247391965b3d0021abb8bdded4993ab712b315 🔍 |
| SHA256 | 41341a154295ad8cdcc9dccbc657e3dcf05f9ec54fd00941932eddf2300728ff 🔍 |
| SHA3 | 970c648d2f624e65269bba8b4018ebaa86ff5c2947415f6829435f0b91a36d2f 🔍 |
| VirtualSize | 0x69fb0 |
| VirtualAddress | 0xa000 |
| SizeOfRawData | 0x6a000 |
| PointerToRawData | 0x7e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.10871 |
| MD5 | fe9ba407b019cb79b979ed1cf0521b7a 🔍 |
|---|---|
| SHA1 | 5604ea3a6c4c7634fb42988c7a2b0d0c2c56e86f 🔍 |
| SHA256 | 2cee02e2043519b5df3481a62bea41bc0253b42d8a1938fc681e16b80a57f7cf 🔍 |
| SHA3 | bbd1b7f2f4927cf7099c58a142f975fb8d2e84fcce635d3248d5b3ce581e3099 🔍 |
| VirtualSize | 0xee2 |
| VirtualAddress | 0x74000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x71e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.71506 |
| ADVAPI32.dll |
RegSetValueExA
RegCloseKey RegQueryValueExA RegOpenKeyA RegCreateKeyA RegDeleteKeyA |
|---|---|
| KERNEL32.dll |
GetCurrentProcess
GetProcAddress GetModuleHandleA GetLastError MoveFileExA GetSystemDirectoryA GetSystemInfo CloseHandle FreeResource WriteFile CreateFileA LockResource LoadResource SizeofResource FindResourceA GetVersionExA UnhandledExceptionFilter TerminateProcess GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter SetUnhandledExceptionFilter RtlUnwind OutputDebugStringA InterlockedCompareExchange InterlockedDecrement InterlockedIncrement LeaveCriticalSection EnterCriticalSection DeleteCriticalSection InitializeCriticalSection InterlockedExchange Sleep |
| msvcrt.dll |
free
_callnewh malloc ??0bad_cast@@QAE@ABV0@@Z ??1bad_cast@@UAE@XZ fgetc fputc ungetc fflush setvbuf fwrite fgetpos fseek fsetpos fclose __iob_func __crtLCMapStringA __pctype_func isupper ___lc_codepage_func ___lc_handle_func abort islower __getmainargs _cexit _exit _XcptFilter _initterm _amsg_exit __setusermatherr __p__commode __p__fmode __set_app_type ??1type_info@@UAE@XZ __uncaught_exception memmove _unlock __dllonexit _lock _onexit ?terminate@@YAXXZ _controlfp _errno __CxxFrameHandler exit ??0exception@@QAE@XZ _CxxThrowException ??0exception@@QAE@ABV0@@Z ??1exception@@UAE@XZ ?what@exception@@UBEPBDXZ ??0exception@@QAE@ABQBD@Z memset memcpy _stricmp setlocale |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x37e8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.60873 |
| Detected Filetype | PE Executable |
| MD5 | 11e2ddee4e43ed149811b18a165f5eb8 🔍 |
| SHA1 | 06d9e144cf5d3f3f96ce02c8983b869d293cb399 🔍 |
| SHA256 | 2d5e418aac76968d8aa792b847bf72b8ab3b5b0beebf8d9fd169328f95decbe1 🔍 |
| SHA3 | 5b7c1219f45995c56e0a93884c5de9cac40f9d8d73c604d1f796ecf9d702647a 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.25252 |
| Detected Filetype | PE Executable |
| MD5 | 2ae720c59177a29b5b26d66bbafad219 🔍 |
| SHA1 | 151f6b1b3b67a59cc924537a14ff6bfe27ed0ec0 🔍 |
| SHA256 | ba219ef5c872b99f95467396722ffc8e5236dfb1230f68e93917cb0e24b09441 🔍 |
| SHA3 | 126ee29ac392be27ab3c1e11019b1f579aacb714f3240b86ba73c82d35218c3d 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x7c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.63714 |
| Detected Filetype | PE Executable |
| MD5 | b6850e9b97a567e94a53197194763301 🔍 |
| SHA1 | 06fa985337564d97fba91061c0b32c06321265f4 🔍 |
| SHA256 | fa211e28021adf0a501e134d7b5a659b1560179a1e9e4763f70e42fabd254cc8 🔍 |
| SHA3 | 7520fa7bf3c9a24f2711b693395bee3a6ee94123135f7408916bc7cdb4900159 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24282 |
| Detected Filetype | PE Executable |
| MD5 | f40a1521f31dcf87a9be983541578a4d 🔍 |
| SHA1 | 29b904791cd46bab20cb585644b98765c3429705 🔍 |
| SHA256 | f7963cc31148783e359ec45f064e77c6cbfacd4fc3baeaac471d87c0ca5a44b7 🔍 |
| SHA3 | a6636e9e8db007f54cc2982146b61aed309addbeaae2b55fc9fe2a53a5b5a8e5 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.25685 |
| Detected Filetype | PE Executable |
| MD5 | 96f483def02b1aee69eab323766138d1 🔍 |
| SHA1 | 2874d6c3f7b06406cfff0cadd2c1ed655c8fec20 🔍 |
| SHA256 | 39ec0dad42164332e506af730f5a0d8309d6648ad6c70d65df83b80c984115af 🔍 |
| SHA3 | 0255f8be70577cceb152c62d9460582f68af8e20faff109b21d6c781e397fc6b 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x7c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.6876 |
| Detected Filetype | PE Executable |
| MD5 | d75fd83a1b226340b33bcc3e2b418cf3 🔍 |
| SHA1 | 14cfb3359b1ec656b3289024cc8a57c81a40ea87 🔍 |
| SHA256 | 0261e28100f2a910cf9b32514f8dda84d1a6475135d1aa383b9cf2d17e0f5156 🔍 |
| SHA3 | 6d7d3a739009819c91a304130bada71ef06c7822c1c20a8b065abe559f315e86 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24624 |
| Detected Filetype | PE Executable |
| MD5 | 74704263322c66e5843b26f5611780db 🔍 |
| SHA1 | 6b82bc3148b7f4c7987a559b20443d3f33476b69 🔍 |
| SHA256 | 403c6c71662772cf0c5ae527aa4af8bbfc35b35aa68e6ac12204fdf4f6ab3d63 🔍 |
| SHA3 | 71e23b9fb544705aa75ec6459b4319f1253db8ee8688e326e585a7a021c1965b 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.23554 |
| Detected Filetype | PE Executable |
| MD5 | 9d39232310190dc8c0cb7472db523a1e 🔍 |
| SHA1 | e32cb026441aa952d70fac7f9f6495d850ebd82e 🔍 |
| SHA256 | 2cb5ec142cfac879bce4a2f9549258db972aebbd24f4551b6b748b464eb7dba9 🔍 |
| SHA3 | d53ca92fb5c76d3bf2c1b79bc8895ad114ad1fb375d7ffbb1fc8b01f6ac075e0 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x8a68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.67247 |
| Detected Filetype | PE Executable |
| MD5 | a4063901d8fda19755f5cc0a42d01256 🔍 |
| SHA1 | 1e571d110204c0ad63f1acbb1bf83c6b346e007f 🔍 |
| SHA256 | bc9b8019e74a59316db7b5bcbb1cb26dffcd5127f776b3c330b16db031e03727 🔍 |
| SHA3 | cb16ddf29aa058d70fa3a1da7b806cfe0d0941eea2cd8217fac906266f0db9a2 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24849 |
| Detected Filetype | PE Executable |
| MD5 | 08d1211820889f97d8a8796584d38eb9 🔍 |
| SHA1 | 1107d0d47b91dead969d3ca6aaf9a4e5182b8508 🔍 |
| SHA256 | 979f790b75860fc713c159740f00ed4a11e7bc785e417b3442f765ffec4ddc36 🔍 |
| SHA3 | 9ed1b91596dcf478c4e1b840c9d71458efbbb33be1e4ac7156da6e718e381127 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x36e8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.67913 |
| Detected Filetype | PE Executable |
| MD5 | b415aa8139b67abfc88bd6d013650580 🔍 |
| SHA1 | b9762b339897f9a10ab4252259a920b12b4bcdf8 🔍 |
| SHA256 | 02b89143119f935315072b83a187666e7979d43f4df6c356ae1164137cd8e144 🔍 |
| SHA3 | ecbb473bd222743ca20a6aeb8d39f807c6a02d89e43694073c13986ef5bfb74a 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24896 |
| Detected Filetype | PE Executable |
| MD5 | 3b395be58d1566aef2771be99d5622e2 🔍 |
| SHA1 | bfcaa0d44899bc8fb4f42b2fd85a7ce7ff74514e 🔍 |
| SHA256 | b5289df2042c5f5c3fe47a18a4ec268d9f019ffb4df1dfa2c3e41b4c214a79cf 🔍 |
| SHA3 | 73a83ebca486daf2d8a3af52cf7f1b82e808fd4c99d74bb9032ed98a4183f9aa 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x7c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.67401 |
| Detected Filetype | PE Executable |
| MD5 | e8283ade2e51815db0c0e5a1f9198666 🔍 |
| SHA1 | 5b06205c97adb712fb418ed7554eb173b335d373 🔍 |
| SHA256 | e8826bf187d52fa0e35e427c7ae9ce9b998a3d2eaf71e368236ec920109f0e98 🔍 |
| SHA3 | ef6e0d0a9471c31f04830a5e162a8e4281b32c630b9880d7cc38338bd7121b30 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24111 |
| Detected Filetype | PE Executable |
| MD5 | 265de84ffb10efe79f8624f17dfeadcd 🔍 |
| SHA1 | 6301564171cdf65fe611a584e3fda2a75ae2c5d8 🔍 |
| SHA256 | 51a1f7dd44e0a806bcb0cae219518ec4ff20b7d0a8d494a14c962fef68984bec 🔍 |
| SHA3 | 098f8d219582884a6b61a9ece5f9717ba0c4e83b3fa2d8b0afc181c5a51b0ee3 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.25131 |
| Detected Filetype | PE Executable |
| MD5 | ab3829d150b7c1db6aa1288a351df002 🔍 |
| SHA1 | cee34902f5a3b3262990d4d7d8f04ac1f446dcc8 🔍 |
| SHA256 | 6883febd0d83f6ff9170199a6ca5ed9ed9bbe052084048da59d6c537e48f8e64 🔍 |
| SHA3 | a5e0193622be8b6c8603d28601684237e1b75cf14d95d3bbf4ce782b68680346 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x7e68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.65557 |
| Detected Filetype | PE Executable |
| MD5 | 3c64faf45d1105b5940e939ef965726d 🔍 |
| SHA1 | 5cdfe6269d9ceb243f8c4b7c508c9c4cc87311ce 🔍 |
| SHA256 | bfeac8a0ca961d047a710e34bd380c99666d3d32007ba2af26cd9a49fa22d264 🔍 |
| SHA3 | 4ef58646e47f709e854b9a16ff4ffe04c7fbd9b169f29822a9eac3e582dd3911 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.2387 |
| Detected Filetype | PE Executable |
| MD5 | f2812024f37245222339e67211d8bbfc 🔍 |
| SHA1 | 303cbf2e551d96cb5f24f10fdc6175b956dac0f2 🔍 |
| SHA256 | 1db4a8168c074f14a541bc1e8811073c848e3a9baf48e00094c725186ef7569e 🔍 |
| SHA3 | 3bc9690c00d69f2a39080d456ef57052e3050c0ec4936b04a1a3286b8ea219a3 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x4868 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.23246 |
| Detected Filetype | PE Executable |
| MD5 | ccf564011eefa7b44d74915d231b8fd7 🔍 |
| SHA1 | f7a1fabf2042c74697937049efa693ede71b804e 🔍 |
| SHA256 | 0f12d47d01864ca5e1eb663a52b3d2c060521e57b68ff99d70e7f01506e400f9 🔍 |
| SHA3 | afe560c36428138d039190b1fae29f5e74a699fc6a6ad4663349fef4ecfa93b7 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x8c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.64751 |
| Detected Filetype | PE Executable |
| MD5 | 7884a44055bdefc7dab6ac5f8a67a6c3 🔍 |
| SHA1 | e0afc5cdeffe254ae91c1e8e68888145fc56fc72 🔍 |
| SHA256 | 2f1a83091302437d5bff08ff2dd316cc3760be9342546d73c027b76313a74fd3 🔍 |
| SHA3 | 8f594e91dab8564e3191b50a47b091f5c849dcd42ba3903e584f64cab764b21a 🔍 |
| Type |
DRIVER
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x3c68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.24252 |
| Detected Filetype | PE Executable |
| MD5 | 63cd86f720b000cf7cc75bb78cecbdc3 🔍 |
| SHA1 | 2ffb0a465cae88360a9ec03880ecce77f0bc7948 🔍 |
| SHA256 | 548c86a06fdacc093e7a3b9a5484ffae6f66d9676a05b7b7e8d666da52defdc6 🔍 |
| SHA3 | 2be8f18d081a646b0a2ddc9f28af969dd2ce3c826981fe9cf888afefd67d43cd 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x38c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.35269 |
| MD5 | 7407c8227604d202e15872be69eaae24 🔍 |
| SHA1 | 94a8795308d5613312364d18c05e018293cbf402 🔍 |
| SHA256 | 88a915e3d60925e4df05aaf488f0fb0ecab4ea481acf310032b61fc46009ea1d 🔍 |
| SHA3 | 2575a087f40f1d3c69793440c7b71a89e672e3ac5551827f394489b5cc958816 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Francisco Lopes |
| FileDescription | Interception command line installation tool |
| FileVersion (#2) | 1.00 built by: WinDDK |
| InternalName | install-interception.exe |
| LegalCopyright | Copyright (C) 2008-2018 Francisco Lopes da Silva |
| OriginalFilename | install-interception.exe |
| ProductName | Interception |
| ProductVersion (#2) | 1.00 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Mar-24 23:52:36 |
| Version | 0.0 |
| SizeofData | 127 |
| AddressOfRawData | 0x1de0 |
| PointerToRawData | 0x11e0 |
| Referenced File | c:\users\franci~1\docume~1\projects\interc~1\instal~1\exe\objfre_wxp_x86\i386\install-interception.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1009184 |
| SEHandlerTable | 0x1001f80 |
| SEHandlerCount | 24 |
| XOR Key | 0x4fa7b87b |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 SP1 build 30729) | 6 |
| Imports (VS2008 SP1 build 30729) | 2 |
| C objects (VS2008 SP1 build 30729) | 69 |
| Imports (VS2003 (.NET) build 4035) | 5 |
| Total imports | 132 |
| C++ objects (VS2008 SP1 build 30729) | 31 |
| 126 (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2008 SP1 build 30729) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.