Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Nov-15 22:29:32 |
Detected languages |
English - United States
|
Debug artifacts |
Q:\cmd\27\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb
|
FileDescription | Setup |
FileVersion | 16.0.28315.86 built by: D16.0 |
InternalName | setup.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | setup.exe |
ProductVersion | 16.0.28315.86 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: REVERSO S.A.S.
Issuer: GlobalSign Extended Validation CodeSigning CA - SHA256 - G3 |
Safe | VirusTotal score: 0/67 (Scanned on 2021-05-02 07:12:40) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Nov-15 22:29:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5b800 |
SizeOfInitializedData | 0x28e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000352A7 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x5d000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | A.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x89000 |
SizeOfHeaders | 0x400 |
Checksum | 0x879fb |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetNativeSystemInfo
EndUpdateResourceW CreateToolhelp32Snapshot Process32FirstW Process32NextW SetEvent CreateEventW LoadResource LockResource SizeofResource FindResourceW GetEnvironmentVariableW ExpandEnvironmentStringsW CreateDirectoryW DeleteFileW GetFileAttributesW GetTempFileNameW ReadFile OpenProcess GetCurrentProcess GetSystemInfo GetSystemDirectoryW GetWindowsDirectoryW GetVersionExW GetModuleFileNameW GlobalAlloc GlobalFree LocalFree FormatMessageW CopyFileW GetDateFormatW GetTimeFormatW CompareStringW WideCharToMultiByte RaiseException InitializeCriticalSectionAndSpinCount GetCurrentProcessId Sleep HeapSetInformation SetFilePointer GetDiskFreeSpaceExW CreateFileW DeleteCriticalSection CreateThread LeaveCriticalSection EnterCriticalSection InitializeCriticalSection lstrlenW MulDiv GetTickCount GetExitCodeProcess LoadLibraryW GetTempPathW SwitchToThread FindNextFileW UpdateResourceA BeginUpdateResourceA FindResourceA lstrlenA DeleteFileA CreateFileA UpdateResourceW BeginUpdateResourceW GetVersion GetEnvironmentVariableA HeapReAlloc HeapSize WriteConsoleW ReadConsoleW GetProcessHeap SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP IsValidCodePage FindFirstFileExW SetEndOfFile OutputDebugStringW SetFilePointerEx GetConsoleMode GetConsoleCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW GetFileType FindFirstFileW FindClose GetProcAddress FreeLibrary WaitForSingleObject GetLastError CloseHandle WriteFile GetStringTypeW HeapAlloc HeapFree GetACP GetModuleHandleExW ExitProcess MultiByteToWideChar VirtualProtect VirtualQuery GetModuleHandleW LoadLibraryExA QueryPerformanceCounter GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent TerminateProcess RtlUnwind SetLastError TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW GetStdHandle |
---|---|
GDI32.dll |
GetStockObject
EnumFontFamiliesExW DeleteObject CreateFontIndirectW GetObjectW GetTextMetricsW SelectObject GetTextExtentPoint32W GetDeviceCaps DeleteDC CreateCompatibleDC |
ole32.dll |
CoUninitialize
CoInitialize |
Secur32.dll |
GetComputerObjectNameW
|
SHELL32.dll |
ShellExecuteExW
SHGetMalloc SHGetPathFromIDListW SHGetSpecialFolderLocation ShellExecuteW ShellExecuteA |
USER32.dll |
SystemParametersInfoW
IsDialogMessageW LoadImageW LoadIconW LoadCursorW SetClassLongW ScreenToClient GetWindowRect GetClientRect SetWindowTextW ShowScrollBar SetForegroundWindow EnableWindow GetFocus SetFocus SendDlgItemMessageW SetDlgItemTextW GetDlgItem CreateDialogIndirectParamW CreateDialogParamW MoveWindow ShowWindow DestroyWindow SendMessageW SendMessageA PeekMessageW DispatchMessageW TranslateMessage ExitWindowsEx MessageBoxW ReleaseDC GetDC DrawTextW GetSystemMetrics GetDialogBaseUnits MessageBoxA SetCursor MsgWaitForMultipleObjects |
CRYPT32.dll |
CertGetCertificateChain
CertFreeCertificateChain CertVerifyCertificateChainPolicy |
WININET.dll |
InternetCrackUrlW
InternetCombineUrlW |
msi.dll |
#8
#78 #150 #92 |
ADVAPI32.dll (delay-loaded) |
RegCloseKey
RegOpenKeyExW RegQueryValueExW AllocateAndInitializeSid FreeSid CryptAcquireContextW CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash RegQueryValueExA RegQueryInfoKeyA RegOpenKeyExA RegEnumValueA RegCreateKeyExA RegSetValueExA RegSetValueExW RegQueryInfoKeyW RegCreateKeyExW RegEnumValueW |
Attributes | 0x1 |
---|---|
Name | ADVAPI32.dll |
ModuleHandle | 0x5e718 |
DelayImportAddressTable | 0x5e1fc |
DelayImportNameTable | 0x5c444 |
BoundDelayImportTable | 0x5c67c |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x225e6 |
Ordinal | 2 |
---|---|
Address | 0x22601 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 16.0.28315.86 |
ProductVersion | 16.0.28315.86 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | Setup |
FileVersion (#2) | 16.0.28315.86 built by: D16.0 |
InternalName | setup.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | setup.exe |
ProductVersion (#2) | 16.0.28315.86 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-15 22:29:32 |
Version | 0.0 |
SizeofData | 93 |
AddressOfRawData | 0x138b0 |
PointerToRawData | 0x12cb0 |
Referenced File | Q:\cmd\27\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-15 22:29:32 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x13910 |
PointerToRawData | 0x12d10 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Nov-15 22:29:32 |
Version | 0.0 |
SizeofData | 944 |
AddressOfRawData | 0x13924 |
PointerToRawData | 0x12d24 |
Size | 0x68 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x45d038 |
SEHandlerTable | 0x4135a0 |
SEHandlerCount | 196 |
XOR Key | 0xa9889d2 |
---|---|
Unmarked objects | 0 |
241 (40116) | 13 |
243 (40116) | 156 |
242 (40116) | 29 |
ASM objects (24723) | 21 |
C objects (24723) | 34 |
C++ objects (24723) | 64 |
Imports (65501) | 23 |
Total imports | 349 |
ASM objects (25025) | 1 |
C++ objects (25025) | 31 |
Exports (25025) | 1 |
Resource objects (25025) | 1 |
Linker (25025) | 1 |