Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2013-Nov-07 11:09:18 |
Detected languages |
English - United States
|
FileVersion | 2, 0, 0, 44 |
ProductName | SERB-CRAFT AntiCheat Installer |
ProductVersion | 2, 0, 0, 44 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
1061090 bytes of data starting at offset 0x2f000.
The overlay data has an entropy of 7.99804 and is possibly compressed or encrypted. Overlay data amounts for 84.6433% of the executable. |
Suspicious | VirusTotal score: 2/69 (Scanned on 2022-03-01 20:45:33) |
Bkav:
W32.AIDetect.malware2
APEX: Malicious |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2013-Nov-07 11:09:18 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x22000 |
SizeOfInitializedData | 0xc000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001C312 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x23000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x30000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetModuleHandleA
MoveFileExA GetCurrentProcess GetDriveTypeA GetModuleFileNameA GetVersionExA GetVersion CompareStringA GetTimeZoneInformation IsBadCodePtr IsBadReadPtr SetUnhandledExceptionFilter GetStringTypeW GetStringTypeA GetFileType GetStdHandle SetHandleCount GetEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter GetOEMCP GetACP FormatMessageA LCMapStringW LCMapStringA IsBadWritePtr HeapReAlloc VirtualAlloc VirtualFree HeapCreate HeapDestroy GetEnvironmentVariableA GetCommandLineA GetStartupInfoA FileTimeToLocalFileTime FileTimeToSystemTime FindNextFileA RemoveDirectoryA MoveFileA RtlUnwind DeleteFileA SetEnvironmentVariableA CreateDirectoryA HeapFree HeapAlloc HeapCompact TerminateProcess ExitProcess CopyFileA SetFileTime OpenFile GetFileAttributesA SetFileAttributesA SetErrorMode GetPrivateProfileStringA WritePrivateProfileStringA LoadLibraryExA FindResourceA GetTickCount GetFullPathNameA MultiByteToWideChar WideCharToMultiByte GetLocalTime GetTempPathA GetShortPathNameA GetExitCodeProcess CompareStringW GetCurrentDirectoryA SetCurrentDirectoryA CreateProcessA Sleep lstrcatA lstrlenA WinExec LoadLibraryA GetProcAddress FreeLibrary GetDiskFreeSpaceA GlobalAlloc GlobalLock GlobalUnlock GlobalFree CloseHandle SetFilePointer WriteFile ReadFile CreateFileA GetLastError FindFirstFileA FindClose GetWindowsDirectoryA GetCPInfo GetSystemDirectoryA |
---|---|
USER32.dll |
ExitWindowsEx
IsIconic PostQuitMessage DefWindowProcA AdjustWindowRectEx DialogBoxParamA EndDialog CheckDlgButton SetTimer KillTimer SendDlgItemMessageA GetFocus BringWindowToTop GetLastActivePopup SendMessageA GetWindow FindWindowA LoadCursorA LoadIconA PostMessageA GetSysColor ScreenToClient GetWindowRect GetDlgItem EndPaint BeginPaint GetClientRect FillRect DrawTextA GetSystemMetrics GetDlgItemTextA IsClipboardFormatAvailable OpenClipboard GetClipboardData CloseClipboard IsDlgButtonChecked CheckRadioButton SetFocus GetParent UpdateWindow IsWindowVisible InvalidateRect CreateDialogParamA RedrawWindow PeekMessageA GetMessageA IsDialogMessageA TranslateMessage DispatchMessageA SetDlgItemTextA SetWindowTextA SetWindowPos ShowWindow DestroyWindow CreateWindowExA GetWindowLongA IsWindowEnabled CallWindowProcA ValidateRect SetWindowLongA GetClassNameA MessageBoxA EnableWindow SendMessageTimeoutA wsprintfA RegisterClassA |
GDI32.dll |
CreatePalette
SetBkColor ExtTextOutA GetSystemPaletteEntries AddFontResourceA RemoveFontResourceA GetStockObject GetDeviceCaps DeleteDC DeleteObject BitBlt SelectObject CreateCompatibleBitmap CreateCompatibleDC RealizePalette SelectPalette CreateHalftonePalette CreateDIBPatternBrush CreateSolidBrush SetBrushOrgEx SetStretchBltMode StretchDIBits CreateFontIndirectA SetBkMode SetTextColor |
comdlg32.dll |
GetOpenFileNameA
|
ADVAPI32.dll |
RegCreateKeyExA
OpenProcessToken LookupPrivilegeValueA AdjustTokenPrivileges RegCreateKeyA RegEnumKeyExA RegDeleteKeyA RegCloseKey RegDeleteValueA RegOpenKeyA RegSetValueExA RegQueryValueA RegOpenKeyExA RegQueryValueExA |
SHELL32.dll |
DragQueryFileA
DragFinish ShellExecuteA SHBrowseForFolderA SHGetSpecialFolderLocation SHGetPathFromIDListA SHGetMalloc DragAcceptFiles |
ole32.dll |
CoGetMalloc
CoCreateInstance OleInitialize OleUninitialize |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA VerFindFileA |
COMCTL32.dll |
#17
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 2.0.0.44 |
ProductVersion | 2.0.0.44 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileVersion (#2) | 2, 0, 0, 44 |
ProductName | SERB-CRAFT AntiCheat Installer |
ProductVersion (#2) | 2, 0, 0, 44 |
Resource LangID | English - United States |
---|
XOR Key | 0xc7f5d3f1 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
C++ objects (8047) | 8 |
14 (7299) | 20 |
C objects (8047) | 73 |
C objects (VC++ 6.0 SP5 build 8804) | 15 |
C objects (2190) | 2 |
Imports (2179) | 19 |
Total imports | 221 |
49 (9044) | 2 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |