02624b60feea1951a751d83d4a9c43c122a34d28af3555c58baa021d3d4542b8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2009-Jul-14 00:04:59
Detected languages English - United States
Debug artifacts WdfCoInstaller01009.pdb
CompanyName Microsoft Corporation
FileDescription WDF Coinstaller
FileVersion 1.9.7600.16385 (win7_rtm.090713-1255)
InternalName WdfCoInstaller.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WdfCoInstaller.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 1.9.7600.16385

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • crl.microsoft.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0H
  • http://crl.microsoft.com/pki/crl/products/tspca.crl0H
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/CSPCA.crt0
  • http://www.microsoft.com/pki/certs/tspca.crt0
  • http://www.microsoft.com0
  • microsoft.com
  • www.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryW
  • GetProcAddress
Can access the registry:
  • RegFlushKey
  • RegSetValueExW
  • RegCreateKeyExW
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
Interacts with services:
  • DeleteService
  • OpenSCManagerW
  • QueryServiceConfigW
  • ChangeServiceConfigW
  • QueryServiceStatusEx
  • OpenServiceW
Malicious The PE is possibly a dropper. Resource WDFCAB_RESOURCE detected as a CAB Installer file.
Resources amount for 93.2804% of the executable.
Info The PE is digitally signed. Signer: Microsoft Windows Component Publisher
Issuer: Microsoft Windows Verification Intermediate PCA
Safe VirusTotal score: 0/63 (Scanned on 2022-02-04 19:28:41) All the AVs think this file is safe.

Hashes

MD5 3162264290fc86416cf5d78d3fa3b662 🔍
SHA1 f3c94eb38c348d946579ff5524c59ee9f0a66036 🔍
SHA256 02624b60feea1951a751d83d4a9c43c122a34d28af3555c58baa021d3d4542b8 🔍
SHA3 ee736c5ff2edddc3d8daf906008e5af8d52e474db8c277e385d3c548261393b6 🔍
SSDeep 24576:8U4MsColC6Je/ZgY7OOfcEpiRLH87SyVXGe38uKUj+NFVov1PJLfVKZ8F5mEeZW:9FCsfZRZA6Xn388avVovfLd+Mo4iE 🔍
Imports Hash 70497fec79daa5f71de3b34faee686a5 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 5
TimeDateStamp 2009-Jul-14 00:04:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 9.1
SizeOfCode 0xf800
SizeOfInitializedData 0x193000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000EAB4 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x2000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 6.1
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x1ab000
SizeOfHeaders 0x400
Checksum 0x1b9237
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f0a019b68606971888ae475c950c0de9 🔍
SHA1 6ea395bed04f338e661397c1968ed39821c7db2c 🔍
SHA256 c80431511a45d7e08db9ad3b97a88924cd1dff53896f951c4407af40cbd159eb 🔍
SHA3 c487c7a6a35ea198db41dd14b124d23ca8fcdecc186b5a9b11d722a0e138063d 🔍
VirtualSize 0xf74c
VirtualAddress 0x1000
SizeOfRawData 0xf800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.43985

.data

MD5 c3e535d9cabfd994ab3b311578a19d26 🔍
SHA1 279b556f060c0addb80ef38a333820153e205f56 🔍
SHA256 ef41c04adc81d0afa99b1974e78df098db1a842ecabf40d2461898e39950215e 🔍
SHA3 99230517a49e6976ae6bb609827c7d050c77a73a5330ece259d291e278302b64 🔍
VirtualSize 0x4ae8
VirtualAddress 0x11000
SizeOfRawData 0x600
PointerToRawData 0xfc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.2858

.pdata

MD5 67b09b70d83d398379cc05d229087114 🔍
SHA1 0791dc477fc0cb22852f83dcc26d185522c83bf4 🔍
SHA256 a66889af890be04cc3ff7741b01c2c8f8b5ed03529d18b6cfa6cf34d96bea402 🔍
SHA3 30518fbf6f6fdb37ceead5f227a8384be72872b71e767044f58ae11b9ea23831 🔍
VirtualSize 0x42c
VirtualAddress 0x16000
SizeOfRawData 0x600
PointerToRawData 0x10200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.28248

.rsrc

MD5 40cb7e099cbc8c79f90545343f9d1b54 🔍
SHA1 2bc3d462baeb7eeb8017a24fb1a48d3a7ce38553 🔍
SHA256 f46bd720fdbf28a30b719ea8a5adef8e7414db754bea60fd83605066a3d9187b 🔍
SHA3 42b93882a432a5915c1e74b2eed10712d0423592e1822a421d3a4c34df25dc93 🔍
VirtualSize 0x19216c
VirtualAddress 0x17000
SizeOfRawData 0x192200
PointerToRawData 0x10800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99971

.reloc

MD5 6b3ab2211d8e36e9addbbcbed4395638 🔍
SHA1 8ea718a1c21f8a54f803b7cf7b9942c5ea988499 🔍
SHA256 c01350fdcda90ee151e1e27144070cba1455fff6ef725de88e39d21902d6453c 🔍
SHA3 79cd7eb59321013a12db56d708a4d95cf56633f20bb40f16c45f366f1482b807 🔍
VirtualSize 0x118
VirtualAddress 0x1aa000
SizeOfRawData 0x200
PointerToRawData 0x1a2a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.149797

Imports

msvcrt.dll memset
memcpy
__C_specific_handler
_amsg_exit
_initterm
_XcptFilter
_ultow
malloc
_wcsnicmp
free
_wtoi
_wcsicmp
_stricmp
_vsnwprintf
SETUPAPI.dll SetupDiSetDeviceInstallParamsW
SetupCloseLog
SetupOpenInfFileW
SetupCloseInfFile
CM_Set_DevNode_Problem_Ex
SetupDiGetDeviceInstallParamsW
SetupLogErrorW
SetupOpenLog
SetupDiGetActualSectionToInstallW
SetupFindNextMatchLineW
SetupDiGetSelectedDriverW
SetupGetStringFieldW
SetupPromptReboot
SetupFindFirstLineW
SetupGetLineCountW
SetupDiGetDriverInfoDetailW
KERNEL32.dll GetModuleFileNameW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
Sleep
LoadLibraryExW
ExpandEnvironmentStringsW
GetFileInformationByHandle
DeleteFileW
CloseHandle
FindNextFileW
RemoveDirectoryW
LockResource
GetLocalTime
FindClose
SetLastError
CreateFileW
FileTimeToSystemTime
TerminateProcess
GetExitCodeProcess
FormatMessageW
SizeofResource
WriteFile
OutputDebugStringW
WaitForSingleObject
CreateDirectoryW
CreateProcessW
LoadResource
FindResourceW
FindFirstFileW
LoadLibraryW
WideCharToMultiByte
FreeLibrary
lstrlenA
LocalFree
GetWindowsDirectoryW
LocalAlloc
GlobalFree
GetProcAddress
GetLastError
VerifyVersionInfoW
GetModuleHandleW
VerSetConditionMask
ADVAPI32.dll DeleteService
OpenSCManagerW
QueryServiceConfigW
ChangeServiceConfigW
RegFlushKey
RegSetValueExW
RegCreateKeyExW
RegCloseKey
RegOpenKeyExW
CloseServiceHandle
QueryServiceStatusEx
RegQueryValueExW
OpenServiceW
CRYPT32.dll CertGetCertificateContextProperty
WINTRUST.dll WTHelperGetProvCertFromChain
WTHelperGetProvSignerFromChain
WinVerifyTrust
WTHelperProvDataFromStateData
SHELL32.dll CommandLineToArgvW
USER32.dll LoadStringW
IsCharAlphaNumericW
IsCharAlphaW
ole32.dll CoTaskMemFree

Delayed Imports

WdfCoInstaller

Ordinal 1
Address 0x9c78

WdfPostDeviceInstall

Ordinal 2
Address 0xa110

WdfPostDeviceRemove

Ordinal 3
Address 0xa1d8

WdfPreDeviceInstall

Ordinal 4
Address 0xa0b4

WdfPreDeviceInstallEx

Ordinal 5
Address 0x9f08

WdfPreDeviceRemove

Ordinal 6
Address 0xa17c

KMDF_VERSION_RC

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.58496
MD5 9e6638248f3763da532e5076758c48e2 🔍
SHA1 12add60c14dd2ac0746ab82e8b16849dc7840994 🔍
SHA256 0cbaa8140a942b0f8e032b3ad1583b2ce7e9cf4d42f45d932037758190c2eb25 🔍
SHA3 c46b323e6e3f95c7c030093b07fc45bf07edf8d720d120ae9c1bd7fb3e1d2639 🔍

WDFCAB_RESOURCE

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x191cab
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99977
Detected Filetype CAB Installer file
MD5 c0380a4c95256398c1ca790d4f935342 🔍
SHA1 c25db3304ac5dad6a67cc4ee4ef11616d518f41d 🔍
SHA256 7d8fe3abc9c019a71eff0496b8ba6b2f73849d9c6d95f23e610cdba0843469b7 🔍
SHA3 2eff89c994c5382270fd550aed7a223705d80af5e10c7bad15f08360637ce02d 🔍

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52203
MD5 b8926025701c49a46734d63213bf5582 🔍
SHA1 64f4f448857b651e77ccd0f0c5a1d5edff63f302 🔍
SHA256 88f9b8c1e5d868fe5793814624c9dab08ca1ae4a5349b17cf3dd57fff549bd8d 🔍
SHA3 1638fea884e96233e9a480b76616b73f1f8ebfbc2de1a5de8ccf82153acc2d7c 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.9.7600.16385
ProductVersion 1.9.7600.16385
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language UNKNOWN
CompanyName Microsoft Corporation
FileDescription WDF Coinstaller
FileVersion (#2) 1.9.7600.16385 (win7_rtm.090713-1255)
InternalName WdfCoInstaller.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WdfCoInstaller.dll
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 1.9.7600.16385
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2009-Jul-14 00:04:59
Version 0.0
SizeofData 48
AddressOfRawData 0x8304
PointerToRawData 0x7704
Referenced File WdfCoInstaller01009.pdb

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x25be1584
Unmarked objects 0
ASM objects (VS2008 SP1 build 30729) 1
C++ objects (VS2008 SP1 build 30729) 15
Total imports 164
Imports (VS2008 SP1 build 30729) 19
C objects (VS2008 SP1 build 30729) 57
Exports (VS2008 SP1 build 30729) 1
137 (VS2008 SP1 build 30729) 8
126 (VS2012 build 50727 / VS2005 build 50727) 1
Linker (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.