| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-May-28 08:26:25 |
| Detected languages |
English - United States
|
| CompanyName | Human Plus One Corp. |
| FileDescription | DTG, DTF & UV Printer Printing Software |
| FileVersion | 10.5.0.0 |
| LegalCopyright | Copyright 2005 Human Plus One Corp. All rights reserved. |
| ProductVersion | 10.5.0.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Suspicious | The PE is possibly packed. |
Unusual section name found:
Unusual section name found: Unusual section name found: Unusual section name found: Unusual section name found: Section is both writable and executable. Unusual section name found: .winlice Section .winlice is both writable and executable. Unusual section name found: .boot |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Can access the registry:
|
| Info | The PE is digitally signed. |
Signer: Tin Hoc Nam Anh
Issuer: Tin Hoc Nam Anh |
| Malicious | VirusTotal score: 7/70 (Scanned on 2024-03-04 23:06:54) |
Bkav:
W32.AIDetectMalware
Google: Detected Ikarus: Trojan.Crypt McAfee: Artemis!D0CB6D177599 Skyhigh: Artemis Trapmine: suspicious.low.ml.score VBA32: BScope.Trojan.Wacatac |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 11 |
| TimeDateStamp | 2022-May-28 08:26:25 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xbd600 |
| SizeOfInitializedData | 0x122200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x01A621B8 (Section: .boot) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xbf000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x26dc000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x10c9a2a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetModuleHandleA
|
|---|---|
| Imagelib17u.dll |
?AlphaCreate@CxImage@@QAE_NXZ
|
| SETUPAPI.dll |
SetupDiGetClassDevsA
|
| mfc140u.dll |
#11024
|
| USER32.dll |
DrawEdge
|
| GDI32.dll |
CreateCompatibleBitmap
|
| WINSPOOL.DRV |
OpenPrinterW
|
| ADVAPI32.dll |
RegOpenKeyW
|
| SHELL32.dll |
DragFinish
|
| COMCTL32.dll |
ImageList_GetImageInfo
|
| ScreenLib17u.dll |
??1CXTPPropertyGridItem@@UAE@XZ
|
| gdiplus.dll |
GdiplusShutdown
|
| VCOMP140.DLL |
_vcomp_fork
|
| WS2_32.dll |
WSAGetLastError
|
| WINTRUST.dll |
WTHelperProvDataFromStateData
|
| CRYPT32.dll |
CertGetNameStringW
|
| VERSION.dll |
GetFileVersionInfoW
|
| VCRUNTIME140.dll |
__std_terminate
|
| api-ms-win-crt-heap-l1-1-0.dll |
realloc
|
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_invalid_parameter_noinfo
|
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
|
| api-ms-win-crt-stdio-l1-1-0.dll |
rewind
|
| api-ms-win-crt-math-l1-1-0.dll |
ceil
|
| api-ms-win-crt-filesystem-l1-1-0.dll |
_fstat64i32
|
| api-ms-win-crt-time-l1-1-0.dll |
_ctime64
|
| api-ms-win-crt-locale-l1-1-0.dll |
localeconv
|
| api-ms-win-crt-utility-l1-1-0.dll |
ldiv
|
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| Textile |
| Textile |
| Textile.Document |
| Textile.Document |
| All Files(*.eps,*.ps,*.pdf;*.bmp,*.tif,*.jpg;*.png,*.psd)|*.eps;*.ps;*.bmp;*.tif;*.jpg;*.png;*.psd;*.pdf|Encapsulated PostScript(*.eps)|*.eps|PostScript(*.ps)|*.pdf|Portable document format(*.pdf)|*.pdf|Windows Bitmap(*.bmp)|*.bmp|tagged Image File Format(*.tif)|*.tif|JPEG File(*.jpg)|*.jpg|Portable Network Graphics(*.png)|*.png|Photoshop Data File(*.psd)|*.psd|| |
| Objects |
| Selected |
| Info |
| Line Color |
| Output Size |
| Width |
| Height |
| X |
| Position X |
| Y |
| Position Y |
| Original Size |
| Width |
| Height |
| Equal Proportion |
| Ratio X |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.5.0.0 |
| ProductVersion | 10.5.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Human Plus One Corp. |
| FileDescription | DTG, DTF & UV Printer Printing Software |
| FileVersion (#2) | 10.5.0.0 |
| LegalCopyright | Copyright 2005 Human Plus One Corp. All rights reserved. |
| ProductVersion (#2) | 10.5.0.0 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x9009e9a0 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| 199 (41118) | 10 |
| Imports (27045) | 2 |
| C objects (VS 2015/2017 runtime 26706) | 13 |
| ASM objects (VS 2015/2017 runtime 26706) | 8 |
| C++ objects (VS 2015/2017 runtime 26706) | 31 |
| Imports (VS 2015/2017 runtime 26706) | 8 |
| C objects (VS2017 v15.9.2-3 compiler 27024) | 21 |
| Imports (27412) | 28 |
| Imports (VS2017 v15.9.2-3 compiler 27024) | 3 |
| Total imports | 1346 |
| C objects (VS98 SP6 build 8804) | 10 |
| C objects (27048) | 50 |
| C++ objects (27048) | 65 |
| Resource objects (27048) | 1 |
| 151 | 1 |
| Linker (27048) | 1 |
No comments yet.