02586d66a474e000030d283bfa460764ef88f7c7dbbf604af6731f80298b980d

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Mar-07 06:15:49
Detected languages English - United States
Comments Please visit http://www.internetdownloadmanager.com
CompanyName Tonec Inc.
FileDescription Internet Download Manager installer
FileVersion 6, 42, 63, 1
InternalName installer
LegalCopyright © 1999-2026. Tonec FZE. All rights reserved.
LegalTrademarks Internet Download Manager (IDM)
OriginalFilename installer.exe
ProductName Internet Download Manager installer
ProductVersion 6, 42, 63, 1

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Interesting strings found in the binary: Contains domain names:
  • http://www.internetdownloadmanager.com
  • internetdownloadmanager.com
  • www.internetdownloadmanager.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Can access the registry:
  • RegDeleteValueW
  • RegQueryValueExW
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Info The PE is digitally signed. Signer: Tonec Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/71 (Scanned on 2026-08-02 06:13:16) All the AVs think this file is safe.

Hashes

MD5 ce8c13894ae8aa5cfcfd181f448ecfd6
SHA1 62e185fbb660d22cc4d236627d25d72e23dd3f82
SHA256 02586d66a474e000030d283bfa460764ef88f7c7dbbf604af6731f80298b980d
SHA3 53b4bb4e42537da967b8304b02b5d59fc5f4c79cdd5d8011e65efb9f95c106c1
SSDeep 196608:Cb5pth4wgoPmko6H8BPhQWJNY+SUtUzJB8rpmrCcfU9OZqLvZ0FkD2pegNB4nGpX:Yz/Qkoq8B+SrYJB8SCh4ZOukKpv9pdIe
Imports Hash 7cd322a21a166e5f354457c41d1d9fb7

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2026-Mar-07 06:15:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0xb800
SizeOfInitializedData 0xc800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00005B7A (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xd000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x1b000
SizeOfHeaders 0x400
Checksum 0xbe4b9f
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x400000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4f437ba7c64bec6b45132cbcc73291a3
SHA1 fa79a28b352248952be0e16b8347ba9458f8bb43
SHA256 97bba7f7e204dea1cf1c728dce6cff9eeb18b099533b14a097e1f0fc39d014ac
SHA3 1be5cafd672ca0877851dcc9ee6fc46ae2bfc61238f6057517c545e3121b939e
VirtualSize 0xb6a7
VirtualAddress 0x1000
SizeOfRawData 0xb800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.62296

.rdata

MD5 a55f23ab5ee38f12c831880c0da5f58c
SHA1 aa31d4173dc8f14e2e6432bce1398dca45dfe8ff
SHA256 3b508ba4406eee97483f701520ba03f942024c6e8d721dc3d1152ce4fa4b11a1
SHA3 b84ce88d8e21d1a454267d35fe771e6c946a5ab832bee2bb4c51ba03aae1bac4
VirtualSize 0x36ca
VirtualAddress 0xd000
SizeOfRawData 0x3800
PointerToRawData 0xbc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.28151

.data

MD5 a17e312e84c792a9f31a8be52bc778a8
SHA1 a22f73552fb1084f56d20e5996e0b30a345eb6d9
SHA256 c2587ae2429848e900d223d7890009b2f0d8baa15f64199be6178ff98840eb3d
SHA3 4e35a59c2f4eac023a6dd2b52e3fc640c88e2f74dc29f6bf4498fc11b81bc9bf
VirtualSize 0x2ebc
VirtualAddress 0x11000
SizeOfRawData 0x2000
PointerToRawData 0xf400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.6504

.rsrc

MD5 03c969c0edeb6917badbf0a5b9a75df2
SHA1 e2ca9bafc270c8b3ce0ae771fec524b07c97e484
SHA256 238cc9b5690f1e9a106fbf370a01d0a128182c0a5365630dba1916c2ea401144
SHA3 611bfa8136f98294cf5c60c6d95c007a63d074cafedccf342a0da786386ca012
VirtualSize 0x4758
VirtualAddress 0x14000
SizeOfRawData 0x4800
PointerToRawData 0x11400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.5043

.reloc

MD5 25c72562c847efdbcdb69999c30c97cd
SHA1 7f5ed53c6578f6a148b9fbf87b3113ecd473199d
SHA256 6498dbed86423bcdddb1355ff4797b727684f5a676bae42bcbbe62d9222a840e
SHA3 c843e44eda1ed616a68f221bb096ae018751bd3936fa8f453bd899c545db63ae
VirtualSize 0x1652
VirtualAddress 0x19000
SizeOfRawData 0x1800
PointerToRawData 0x15c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.03596

Imports

ADVAPI32.dll RegDeleteValueW
RegQueryValueExW
RegOpenKeyExA
RegCloseKey
USER32.dll FindWindowA
ShowWindow
SetForegroundWindow
CreateDialogParamA
SetWindowTextA
GetMessageA
TranslateMessage
DispatchMessageA
wsprintfW
DestroyWindow
PostQuitMessage
wsprintfA
MessageBoxA
SendMessageA
SHELL32.dll SHBrowseForFolderW
SHGetPathFromIDListW
KERNEL32.dll LCMapStringW
LCMapStringA
GetStringTypeW
MultiByteToWideChar
GetStringTypeA
GetLocaleInfoA
GetDiskFreeSpaceW
GetProcAddress
GetModuleHandleA
FreeLibrary
LoadLibraryA
GetCurrentProcess
LocalFree
lstrlenA
CloseHandle
WriteFile
SetFilePointer
CreateFileW
FormatMessageA
GetLastError
CreateThread
CreateProcessW
GetModuleFileNameW
GetExitCodeThread
WaitForSingleObject
CreateDirectoryW
GetFileAttributesW
GetTempPathW
GetVersionExA
ExitProcess
CreateMutexA
ExitThread
MapViewOfFile
SetFileTime
GetFileTime
CreateFileMappingA
GetFileSize
UnmapViewOfFile
RtlUnwind
HeapFree
GetCommandLineA
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapAlloc
RaiseException
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
Sleep
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
InitializeCriticalSectionAndSpinCount

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16329
MD5 22b5208fd33f39a96113c64c24afa79c
SHA1 7a70793e4dc3cb7388c49546a28dfb7c100034f7
SHA256 de3d46f63bbf78a5938201e061449420519986a2584e13a4798934b6d3a2c103
SHA3 77da5491d253c72caeb9f06f5e16ee7684a6a8bd7a7cee7316caa04f21e16655

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43807
MD5 9f19adff526a8a458885da518c7080b9
SHA1 126cc8b1938d16a5d79377dc74955a0b0482b10f
SHA256 63981971f0288b4d232f5c8cef1b9c474ae0093bd17226b332ef471bc3c74351
SHA3 c6b4f3f6c95c0d3de2f6cace27b51ece62eeef0cc6264645f85451e90428b3cf

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.32162
MD5 059f3ab932a58897ce5e72af6116b4fd
SHA1 bdb0eaa963f642e73ce0612dd59925a6d7d73845
SHA256 3203ade86fd3a5e5feef75c8ee56ea07fa702e2fe0b4d1abce092ce8b9b3e43b
SHA3 e5038565954558940ff93765c2693a39798e44f0a0231609ebd8e6f83ec6d44d

101

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02492
MD5 7abf55cba514525357a2dc8f010863a9
SHA1 366f83a1b79778b2e5f22f67bd0231d60413e4b0
SHA256 edb179b560d1fa0104a238642f85c5643f5f2749bb62b4d8b16dfc42251dd55c
SHA3 15ed9935ececa11c2dfebc2bece2efda50fdc3963254c87618b2686efdd77823

102

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 409e1724611e0bc39356e2f58888db55
SHA1 c06c0e66cc2f7956256e2f018aa0294bfa914960
SHA256 6ab18c3b81a5d30c5a190a4504cae807d73b1a4d02d56ffddf641abbb62b7210
SHA3 315b2ad40793f4ef885ff4c878169b02c62f619b57780a98a76c8538cd0ee5c9

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x448
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4447
MD5 e5bf00c389c028774095d1372747455a
SHA1 9b5b49069b59edec8e47203d5b5bcf0fc30190f7
SHA256 40974f3426032a1b83016101771a879b64134e4be318ac53734d7ba0d3ad6bb3
SHA3 c3a78fe677b040cbb01ecf70f75f4d243a5937e9df543d43492001b089ba50be

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x58a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29449
MD5 04d1bd55cfb16a43c60f392bcc4d1698
SHA1 57c334943e327c604f951102afd722911bbd15af
SHA256 502d0f2bea320b9e31362a8a26561ec6b51a55a940789562c9484670591e0fe0
SHA3 01b2366e070859e8402b1dbcc361e6144eb498f371bc23f7ad8d98bf7ac08606

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6.42.63.1
ProductVersion 6.42.63.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Please visit http://www.internetdownloadmanager.com
CompanyName Tonec Inc.
FileDescription Internet Download Manager installer
FileVersion (#2) 6, 42, 63, 1
InternalName installer
LegalCopyright © 1999-2026. Tonec FZE. All rights reserved.
LegalTrademarks Internet Download Manager (IDM)
OriginalFilename installer.exe
ProductName Internet Download Manager installer
ProductVersion (#2) 6, 42, 63, 1
Resource LangID English - United States

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x412190
SEHandlerTable 0x40f800
SEHandlerCount 7

RICH Header

XOR Key 0x878f2bba
Unmarked objects 0
ASM objects (VS2008 SP1 build 30729) 19
Imports (VS2012 build 50727 / VS2005 build 50727) 9
Total imports 119
C++ objects (VS2008 SP1 build 30729) 38
C objects (VS2008 SP1 build 30729) 90
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.