| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1992-Jun-19 22:22:17 |
| Detected languages |
English - United States
Spanish - Spain (International sort) |
| Suspicious | PEiD Signature: | Crunch 4 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
| Suspicious | VirusTotal score: 1/69 (Scanned on 2022-08-09 06:38:32) | MaxSecure: Trojan.Malware.300983.susgen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 1992-Jun-19 22:22:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x2c7600 |
| SizeOfInitializedData | 0xa0200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x002C83FC (Section: CODE) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2c9000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x370000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_LIBRARY_PROCESS_INIT
|
| SizeofStackReserve | 0 |
| SizeofStackCommit | 0 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte RemoveDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
|---|---|
| user32.dll |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
| advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte RemoveDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| kernel32.dll (#3) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte RemoveDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
| mpr.dll |
WNetOpenEnumA
WNetGetUniversalNameA WNetEnumResourceA WNetCloseEnum |
| version.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
| gdi32.dll |
UnrealizeObject
TextOutA StretchBlt StartPage StartDocA SetWindowOrgEx SetWindowExtEx SetWinMetaFileBits SetViewportOrgEx SetViewportExtEx SetTextCharacterExtra SetTextColor SetTextAlign SetStretchBltMode SetROP2 SetPixel SetMapMode SetEnhMetaFileBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SetAbortProc SelectPalette SelectObject SelectClipRgn SaveDC RoundRect RestoreDC Rectangle RectVisible RealizePalette PtInRegion Polyline Polygon PolyPolyline PlayEnhMetaFile PatBlt OffsetRgn MoveToEx MaskBlt LineTo LPtoDP IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsA GetTextExtentPointA GetTextExtentPoint32A GetTextColor GetSystemPaletteEntries GetStockObject GetRegionData GetPixel GetPaletteEntries GetObjectA GetNearestColor GetFontLanguageInfo GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetCharWidthA GetCharABCWidthsA GetBrushOrgEx GetBitmapBits GdiFlush FillRgn ExtTextOutA ExtCreateRegion ExtCreatePen ExcludeClipRect Escape EnumFontsA EnumFontFamiliesExA EnumFontFamiliesA EndPage EndDoc Ellipse DeleteObject DeleteMetaFile DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRoundRectRgn CreateRectRgn CreatePolygonRgn CreatePenIndirect CreatePen CreatePatternBrush CreatePalette CreateICA CreateHalftonePalette CreateFontIndirectA CreateDIBitmap CreateDIBSection CreateDCA CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileA CombineRgn BitBlt |
| user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA CharNextA |
| ole32.dll |
CoTaskMemFree
StringFromCLSID CoCreateGuid |
| kernel32.dll (#4) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte RemoveDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| ole32.dll (#2) |
CoTaskMemFree
StringFromCLSID CoCreateGuid |
| oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| comctl32.dll |
ImageList_SetIconSize
ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_SetDragCursorImage ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControls |
| imm32.dll |
ImmSetCompositionWindow
ImmSetCompositionFontA ImmGetCompositionStringA ImmReleaseContext ImmGetContext |
| winspool.drv |
OpenPrinterA
EnumPrintersA DocumentPropertiesA ClosePrinter |
| shell32.dll |
ShellExecuteA
DragQueryPoint DragQueryFileA DragFinish DragAcceptFiles |
| comdlg32.dll |
PageSetupDlgA
PrintDlgA ChooseFontA ReplaceTextA FindTextA GetSaveFileNameA GetOpenFileNameA |
| oledlg.dll |
OleUIObjectPropertiesA
OleUIInsertObjectA |
| winmm.dll |
sndPlaySoundA
|
| kernel32.dll (#5) |
DeleteCriticalSection
LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc GetVersion GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte RemoveDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CreateThread WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
| Ordinal | 1 |
|---|---|
| Address | 0x2c7340 |
| Ordinal | 2 |
|---|---|
| Address | 0x2c71f4 |
| Ordinal | 3 |
|---|---|
| Address | 0x2c71a8 |
| Ordinal | 4 |
|---|---|
| Address | 0x2c70f0 |
| Ordinal | 5 |
|---|---|
| Address | 0x2c7050 |
| Ordinal | 6 |
|---|---|
| Address | 0x2c6f94 |
| Ordinal | 7 |
|---|---|
| Address | 0x2c6ef0 |
| Ordinal | 8 |
|---|---|
| Address | 0x2c6e80 |
| Ordinal | 9 |
|---|---|
| Address | 0x2c6e14 |
| Ordinal | 10 |
|---|---|
| Address | 0x2c6da0 |
| Ordinal | 11 |
|---|---|
| Address | 0x2c6d40 |
| Ordinal | 12 |
|---|---|
| Address | 0x2c75cc |
| Ordinal | 13 |
|---|---|
| Address | 0x2c744c |
| Ordinal | 14 |
|---|---|
| Address | 0x2c739c |
| Ordinal | 15 |
|---|---|
| Address | 0x2c6cf0 |
| Ordinal | 16 |
|---|---|
| Address | 0x2c72a0 |
| Ordinal | 17 |
|---|---|
| Address | 0x2c7240 |
| Ordinal | 18 |
|---|---|
| Address | 0x2c72f4 |
| Ordinal | 19 |
|---|---|
| Address | 0x2c69a8 |
| Ordinal | 20 |
|---|---|
| Address | 0x2c6920 |
| Ordinal | 21 |
|---|---|
| Address | 0x2c6ba8 |
| Ordinal | 22 |
|---|---|
| Address | 0x2c6b48 |
| Ordinal | 23 |
|---|---|
| Address | 0x2c6aa8 |
| Ordinal | 24 |
|---|---|
| Address | 0x2c6898 |
| Ordinal | 25 |
|---|---|
| Address | 0x2c65bc |
| Ordinal | 26 |
|---|---|
| Address | 0x2c6674 |
| Ordinal | 27 |
|---|---|
| Address | 0x2c6504 |
| Ordinal | 28 |
|---|---|
| Address | 0x2c6560 |
| Ordinal | 29 |
|---|---|
| Address | 0x2c64a8 |
| Ordinal | 30 |
|---|---|
| Address | 0x2c63e0 |
| Ordinal | 31 |
|---|---|
| Address | 0x2c6388 |
| Ordinal | 32 |
|---|---|
| Address | 0x2c6324 |
| Ordinal | 33 |
|---|---|
| Address | 0x2c62dc |
| Ordinal | 34 |
|---|---|
| Address | 0x2c62d4 |
| Out of memory or executable file is corrupt |
| File was not found |
| Path was not found |
| Sharing violation or netword error |
| A library required separate data segments for each task |
| Insufficient memory to start application |
| Incorrect version of Windows |
| File is not a Windows application or there was an error in the .EXE image |
| Application was designed for a different operating system |
| Application was designed for MS-DOS 4.0 |
| Unknown executable file type |
| Cannot load a real-mode application |
| Cannot load a second instance of an executable file containing multiple, non-read-only data segments |
| Cannot load a compressed executable file |
| A dynamic-link library (DLL) file is invalid |
| Application requires Windows 32-bit extensions |
| No association for specified file type |
| Delete all selected records? |
| Type your password |
| Unlock application |
| Database name: %s |
| The data were changed. Save them? |
| Relational operators require a field and a constant |
| Expression expected but %s found |
| ')' expected but %s found |
| Invalid filter expression character: '%s' |
| Unterminated string constant |
| Unterminated field name |
| Filter expression incorrectly terminated |
| Incorrectly formed filter expression |
| &Prev |
| &Next |
| Error message |
| Server Error |
| BDE Error |
| Database Engine Error |
| The new and confirmed passwords do not match |
| Password has not been changed |
| Password has been changed |
| &Confirm password: |
| &New password: |
| &Old password: |
| Change password |
| Invalid user name or password |
| &Password: |
| &User name: |
| Type your user name and password |
| Application "%s" |
| Registration |
| Calculate |
| Search |
| Insert |
| Edit |
| Browse |
| Closed |
| Cannot perform this operation when controls are not captured |
| Cannot perform this operation when controls are captured |
| Field '%s' cannot be used in a filter expression |
| NULL only allowed with '=' and '<>' |
| Field '%s' is not of type Boolean |
| Do you wish to retry the connect to database? |
| Cannot perform this operation on a local database |
| Details |
| Could not load '%s' library |
| File specified is not an executable file, dynamic-link library, or icon file |
| Function not yet implemented |
| Previous Month| |
| Previous Year| |
| Next Month| |
| Next Year| |
| Select a Date |
| All files (*.*)|*.* |
| Browse |
| 獵慣r : [Commit (Hard commit)]": [Commit retaining (Soft commit)]: [Rollback]&: [Rollback retaining (Soft rollback)]: [Start transaction][Application: Error de registro de cambios:0No es posible activar registro de cambios en %s:#El registro de cambios está abierto#El registro de cambios está cerrado/El registro de cambios no tiene nombre asignado+Se ha efectuado un borrado en cascada en %s"WriteLogRecord: Error de escrituraError en GetLogField [%s is an InterBase 2007 function. Please upgrade to InterBase 2007 to use this functonality: [Connect]: [Disconnect][Misc] [Error] |
| : [Attach] |
| : [Detach] : [Query] : [Start]: [Execute] <NULL><BLOB> |
| : [Fetch] : [Prepare] Plan: ' Plan: Can't retrieve plan - too large 1%s component requires Client to function properly1%s component requires Server to function properlyInvalid option specifiedUnexpected onError return value Unexpected onStatus return valueDPB Constant (%s) is unknownTPB Constant (%s) is unknown#Unknown Error - Can't retrieve plan3Size Mismatch - Field %s size is too small for dataEvents already registeredKTrying to store a string of length %d into a field that can only contain %dNot enough timers availableY%s is an InterBase 6.5 function. Please upgrade to InterBase 6.5 to use this functonalityeCan not find default login prompt dialog. Please add DBLogDlg to the uses section of your main file.Y%s is an InterBase 7.0 function. Please upgrade to InterBase 7.0 to use this functonalityY%s is an InterBase 7.1 function. Please upgrade to InterBase 7.1 to use this functonality %Query Parameters missing or incorrect%start Parameters missing or incorrectUnexpected Output buffer valueXGeneric ServiceStart not applicable: Use Specific Procedures to set configuration params'SQL Monitor Instance is already presentCannot print valueSEOFReachedEOF in comment detectedEOF in string detectedParameter name expectedSuccessful executionDelphiException %sNo Install Options selectedDestinationDirectory is not setSourceDirectory is not setUninstall File Name is not set Cannot Drop System IndexTable Name MismatchIndex Field Missing%Cannot Cancel events while processing |
| Invalid EventExceded Maximum Event limitsNo Events RegisteredInvalid QueueingInvalid RegistrationInvalid Batch MoveSQL Dialect InvalidSPB Constant Not supportedSPB Constant Unknown3Cannot perform operation -- service is not attached/Cannot perform operation -- service is attachedServer Name Missing 8Column types don't match. (From index: %d; To index: %d)_Can't end a shared transaction unless it is forced and equal to the transaction's TimeoutActionUnsupported Field TypeCircular DataLink ReferenceEmpty SQL Statementuse Open for a Select StatementRequired Param value not set!No Stored Procedure Name assigned<use ExecProc for Procedure; use TQuery for Select procedures |
| Update FailedCachedUpdates not enabled#Request is not live - cannot modifyNo ProviderNo Records AffectedNo Table Name assigned6Cannot Create Primary Index; are created automatically Field "%s" is read-onlyField "%s" not foundNot in edit mode-Cannot insert into dataset. (No insert query)%Cannot post. (No update/insert query) Cannot update. (No update query)-Cannot delete from dataset. (No delete query)&Cannot refresh row. (No refresh query)Buffer not set!Circular references not permittedSQL Parse Error: |
| %s |
| User abortData set is uni-directional1Cannot create shared resource. (Windows error %d)-Windows API error. (Windows error %d [$%.8x])Column lists do not match Beginning of fileInvalid statement handle |
| IBSQL OpenIBSQL ClosedDataset openDataset closedUnknown SQL Data type (%d)4Invalid column index (index exceeds permitted range)7Invalid parameter index (index exceeds permitted range)Invalid data conversion!Column cannot be set to null (%s)Blob stream cannot be readBlob stream cannot be writtenEmpty query3Cannot "open" a non-select statement. Use ExecQueryNo access to field "%s" |