| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Jul-10 09:53:41 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\a\rufus\rufus\res\setup\x64\Release\setup.pdb
|
| CompanyName | Akeo Consulting |
| FileDescription | Windows Setup Wrapper |
| FileVersion | 1.0 |
| InternalName | Setup |
| LegalCopyright | © 2024 Pete Batard (GPL v3) |
| LegalTrademarks | https://rufus.ie/setup |
| OriginalFilename | setup.exe |
| ProductName | Setup |
| ProductVersion | 1.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Akeo Consulting
Issuer: Sectigo Public Code Signing CA EV R36 |
| Safe | VirusTotal score: 0/70 (Scanned on 2026-05-03 19:22:43) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Jul-10 09:53:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd600 |
| SizeOfInitializedData | 0x15600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000016E8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x27000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2ee6f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateProcessA
SetCurrentDirectoryW CloseHandle GetFileAttributesA GetLastError CreateFileW WriteConsoleW GetModuleFileNameW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwindEx SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW EncodePointer RaiseException RtlPcToFileHeader GetStdHandle WriteFile ExitProcess GetModuleHandleExW HeapAlloc HeapFree FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle GetFileType GetStringTypeW FlsAlloc FlsGetValue FlsSetValue FlsFree InitializeCriticalSectionEx VirtualProtect LCMapStringW GetProcessHeap HeapSize HeapReAlloc FlushFileBuffers GetConsoleOutputCP GetConsoleMode SetFilePointerEx |
|---|---|
| USER32.dll |
MessageBoxA
|
| ADVAPI32.dll |
RegDeleteKeyA
RegCreateKeyExA RegSetValueExA RegOpenKeyExA RegEnumKeyExA RegCloseKey |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | Akeo Consulting |
| FileDescription | Windows Setup Wrapper |
| FileVersion (#2) | 1.0 |
| InternalName | Setup |
| LegalCopyright | © 2024 Pete Batard (GPL v3) |
| LegalTrademarks | https://rufus.ie/setup |
| OriginalFilename | setup.exe |
| ProductName | Setup |
| ProductVersion (#2) | 1.0 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jul-10 09:53:41 |
| Version | 0.0 |
| SizeofData | 73 |
| AddressOfRawData | 0x17160 |
| PointerToRawData | 0x15b60 |
| Referenced File | D:\a\rufus\rufus\res\setup\x64\Release\setup.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jul-10 09:53:41 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x171ac |
| PointerToRawData | 0x15bac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jul-10 09:53:41 |
| Version | 0.0 |
| SizeofData | 840 |
| AddressOfRawData | 0x171c0 |
| PointerToRawData | 0x15bc0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jul-10 09:53:41 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140019000 |
| XOR Key | 0x3c9072f6 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33140) | 143 |
| C objects (33140) | 12 |
| ASM objects (33140) | 8 |
| ASM objects (35207) | 9 |
| C objects (35207) | 17 |
| C++ objects (35207) | 40 |
| Imports (33140) | 7 |
| Total imports | 102 |
| C objects (LTCG) (35209) | 1 |
| Resource objects (35209) | 1 |
| 151 | 1 |
| Linker (35209) | 1 |
No comments yet.