Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
Chinese - PRC
English - United States |
CompanyName | Adasky.com |
FileDescription | eBook Workshop |
FileVersion | 1.5.0.0 |
InternalName | book.exe |
LegalCopyright | Copyright (C) 2002-2004 Adasky.com |
LegalTrademarks | $$ |
OriginalFilename | book.exe |
ProductName | eBook Workshop |
ProductVersion | 1.5.0.0 |
Comments | Create Professional eBooks |
Suspicious | PEiD Signature: | ASPack v2.12 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Suspicious | The PE is packed with Aspack or Armadillo |
Unusual section name found: .aspack
Unusual section name found: .adata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource BBABORT is possibly compressed or encrypted. Resource BBALL is possibly compressed or encrypted. Resource BBCANCEL is possibly compressed or encrypted. Resource BBCLOSE is possibly compressed or encrypted. Resource BBHELP is possibly compressed or encrypted. Resource BBIGNORE is possibly compressed or encrypted. Resource BBNO is possibly compressed or encrypted. Resource BBOK is possibly compressed or encrypted. Resource BBRETRY is possibly compressed or encrypted. Resource BBYES is possibly compressed or encrypted. Resource BOOKBMP1 is possibly compressed or encrypted. Resource BOOKBMP2 is possibly compressed or encrypted. Resource BOOKBMP3 is possibly compressed or encrypted. Resource BOOKBMP4 is possibly compressed or encrypted. Resource CLOSEDFOLDER is possibly compressed or encrypted. Resource CURRENTFOLDER is possibly compressed or encrypted. Resource 4090 is possibly compressed or encrypted. Resource 4091 is possibly compressed or encrypted. Resource 4092 is possibly compressed or encrypted. Resource 4094 is possibly compressed or encrypted. Resource 4095 is possibly compressed or encrypted. Resource 4096 is possibly compressed or encrypted. Resource PACKAGEINFO is possibly compressed or encrypted. Resource TADAXPFORM is possibly compressed or encrypted. Resource TFRMABOUT is possibly compressed or encrypted. Resource TFRMIMGABOUT is possibly compressed or encrypted. Resource TFRMPASSW is possibly compressed or encrypted. Resource TFRMSPLASH is possibly compressed or encrypted. Resource TMAINFORM is possibly compressed or encrypted. The resource timestamps differ from the PE header:
|
Suspicious | The file contains overlay data. |
6800931 bytes of data starting at offset 0x4a200.
The overlay data has an entropy of 7.99884 and is possibly compressed or encrypted. Overlay data amounts for 95.7265% of the executable. |
Suspicious | VirusTotal score: 2/71 (Scanned on 2024-04-16 18:14:08) |
Trapmine:
suspicious.low.ml.score
VirIT: Trojan.Win32.Generic.ACH |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0xa3800 |
SizeOfInitializedData | 0x1c600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000C7001 (Section: .aspack) |
BaseOfCode | 0x1000 |
BaseOfData | 0xa5000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 1.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xca000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetProcAddress
GetModuleHandleA LoadLibraryA |
---|---|
user32.dll |
GetKeyboardType
|
advapi32.dll |
RegQueryValueExA
|
oleaut32.dll |
VariantChangeTypeEx
|
advapi32.dll (#2) |
RegQueryValueExA
|
version.dll |
VerQueryValueA
|
gdi32.dll |
UnrealizeObject
|
user32.dll (#2) |
GetKeyboardType
|
ole32.dll |
CreateStreamOnHGlobal
|
oleaut32.dll (#2) |
VariantChangeTypeEx
|
comctl32.dll |
ImageList_SetIconSize
|
shell32.dll |
ShellExecuteA
|
urlmon.dll |
CoInternetCreateZoneManager
|
winmm.dll |
timeGetTime
|
Books D VarFileInfo $ Translation ЉӤ † ࢨ ( @ ᤜýᰝÿᰤþḥÿ⨫ü⬬ýⴳþ⼴ÿㄵÿ㠴ý㠺ý㨻þ㬼ÿ䍃ü䑄þ |
컆फ़ћ߾橪⾢嶞厯팳韩ख䊟冃5勏˼ꔡ䞷菉գ脛7 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.5.0.0 |
ProductVersion | 1.5.0.0 |
FileFlags |
VS_FF_PRERELEASE
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Adasky.com |
FileDescription | eBook Workshop |
FileVersion (#2) | 1.5.0.0 |
InternalName | book.exe |
LegalCopyright | Copyright (C) 2002-2004 Adasky.com |
LegalTrademarks | $$ |
OriginalFilename | book.exe |
ProductName | eBook Workshop |
ProductVersion (#2) | 1.5.0.0 |
Comments | Create Professional eBooks |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0x4ad000 |
---|---|
EndAddressOfRawData | 0x4ad010 |
AddressOfIndex | 0x4a84d4 |
AddressOfCallbacks | 0x4ae010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |