199e438137f460d4a93498e96b850341

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jan-30 03:57:45
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
Can access the registry:
  • RegCreateKeyExA
  • RegOpenKeyExA
  • RegEnumValueA
  • RegDeleteKeyA
  • RegDeleteValueA
  • RegCloseKey
  • RegSetValueExA
  • RegQueryValueExA
  • RegEnumKeyA
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Stephen Duda
Issuer: DigiCert SHA2 Assured ID Code Signing CA
Safe VirusTotal score: 0/70 (Scanned on 2023-08-08 11:59:50) All the AVs think this file is safe.

Hashes

MD5 199e438137f460d4a93498e96b850341
SHA1 b765f82ab169bd6c69006371222590237775b40f
SHA256 efcf273c4b6ecc24de20d8ba2787d0701bd6c7c49f05130102962f30e419b37d
SHA3 5e7b6db0a619d355a65fbc6fa1f62e9c2d1315b1dd1d9dcb32b9a54ea377cfe5
SSDeep 786432:jTfS7mrkw4zOr+jVHbzIZ3p81hAiG7qu1iAAVMJf2lhiObIn:/qhwr+zIZ3p8MixAT4riOEn
Imports Hash 3abe302b6d9a1256e6a915429af4ffd2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2018-Jan-30 03:57:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6400
SizeOfInitializedData 0x27c00
SizeOfUninitializedData 0x400
AddressOfEntryPoint 0x0000320C (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x4c000
SizeOfHeaders 0x400
Checksum 0x1ddb385
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 94777a1c66c6303b9367f07906450c26
SHA1 1a7254fbe4aeb19ae7c784f07e26420a0b9898b2
SHA256 6bd0bbf591f7829db092d41f8221134c3e482b635f9e7232b2105e3862d9c9ec
SHA3 53c644fe2d502e06215ac4b2a2fa34dffa9fcb81cd4e37c6a4ecb620489bbbdc
VirtualSize 0x628f
VirtualAddress 0x1000
SizeOfRawData 0x6400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4422

.rdata

MD5 5143a41b917c20afc11d259fd85b6ffc
SHA1 2ff2d5d12e967a8260b40ce62d90a10448bc2b58
SHA256 53c575236f5ae06a36a706acdeeef288df39bfcce09174fac87638a450902f32
SHA3 e51e68e831ec34f74657c720e22343dea80a0815b54ae11221ffc39f6fd8e785
VirtualSize 0x1354
VirtualAddress 0x8000
SizeOfRawData 0x1400
PointerToRawData 0x6800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.23627

.data

MD5 12c02de2bdc517e2722ceeb84aff8b34
SHA1 6df8d71b035ce54d05049078453b024b03cfa2ea
SHA256 45e114e64928b1029315b54c2189efa4ec320f9e466761b62edb983beaca8eb3
SHA3 1f9d0689ab8b4d6f3d4257704dc837dc2e9f8a5552abd594d53720951bd7c44a
VirtualSize 0x25518
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.04938

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x17000
VirtualAddress 0x30000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 e8f08ea9f8c123fa1f0bf742470e5e96
SHA1 8cc2ea77eea47af8359febab5c7cbec5f6c1d559
SHA256 2f364d0a80e222911bb4d75956f66299b4185663278b64fc7313b893b769b895
SHA3 ef28907b513f1097a85202c6ec7be7ed0711f0243eca57d112c1ebaf5771836b
VirtualSize 0x4b78
VirtualAddress 0x47000
SizeOfRawData 0x4c00
PointerToRawData 0x8200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.81798

Imports

KERNEL32.dll GetTempPathA
GetFileSize
GetModuleFileNameA
GetCurrentProcess
CopyFileA
ExitProcess
SetEnvironmentVariableA
Sleep
GetTickCount
GetCommandLineA
lstrlenA
GetVersion
SetErrorMode
lstrcpynA
GetDiskFreeSpaceA
GlobalUnlock
GetWindowsDirectoryA
SetCurrentDirectoryA
GetLastError
CreateDirectoryA
CreateProcessA
RemoveDirectoryA
CreateFileA
GetTempFileNameA
ReadFile
WriteFile
lstrcpyA
MoveFileExA
lstrcatA
GetSystemDirectoryA
GetProcAddress
GetExitCodeProcess
WaitForSingleObject
CompareFileTime
SetFileAttributesA
GetFileAttributesA
GetShortPathNameA
MoveFileA
GetFullPathNameA
SetFileTime
SearchPathA
CloseHandle
lstrcmpiA
CreateThread
GlobalLock
lstrcmpA
FindFirstFileA
FindNextFileA
DeleteFileA
SetFilePointer
GetPrivateProfileStringA
FindClose
MultiByteToWideChar
FreeLibrary
MulDiv
WritePrivateProfileStringA
LoadLibraryExA
GetModuleHandleA
GlobalAlloc
GlobalFree
ExpandEnvironmentStringsA
USER32.dll ScreenToClient
GetSystemMenu
SetClassLongA
IsWindowEnabled
SetWindowPos
GetSysColor
GetWindowLongA
SetCursor
LoadCursorA
CheckDlgButton
GetMessagePos
LoadBitmapA
CallWindowProcA
IsWindowVisible
CloseClipboard
SetClipboardData
EmptyClipboard
PostQuitMessage
GetWindowRect
EnableMenuItem
CreatePopupMenu
GetSystemMetrics
SetDlgItemTextA
GetDlgItemTextA
MessageBoxIndirectA
CharPrevA
DispatchMessageA
PeekMessageA
ReleaseDC
EnableWindow
InvalidateRect
SendMessageA
DefWindowProcA
BeginPaint
GetClientRect
FillRect
DrawTextA
EndDialog
RegisterClassA
SystemParametersInfoA
CreateWindowExA
GetClassInfoA
DialogBoxParamA
CharNextA
ExitWindowsEx
GetDC
CreateDialogParamA
SetTimer
GetDlgItem
SetWindowLongA
SetForegroundWindow
LoadImageA
IsWindow
SendMessageTimeoutA
FindWindowExA
OpenClipboard
TrackPopupMenu
AppendMenuA
EndPaint
DestroyWindow
wsprintfA
ShowWindow
SetWindowTextA
GDI32.dll SelectObject
SetBkMode
CreateFontIndirectA
SetTextColor
DeleteObject
GetDeviceCaps
CreateBrushIndirect
SetBkColor
SHELL32.dll SHGetSpecialFolderLocation
ShellExecuteExA
SHGetPathFromIDListA
SHBrowseForFolderA
SHGetFileInfoA
SHFileOperationA
ADVAPI32.dll AdjustTokenPrivileges
RegCreateKeyExA
RegOpenKeyExA
SetFileSecurityA
OpenProcessToken
LookupPrivilegeValueA
RegEnumValueA
RegDeleteKeyA
RegDeleteValueA
RegCloseKey
RegSetValueExA
RegQueryValueExA
RegEnumKeyA
COMCTL32.dll ImageList_Create
ImageList_AddMasked
ImageList_Destroy
#17
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoCreateInstance

Delayed Imports

110

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x666
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82633
MD5 b6bf70baab40fe438feff063bfb9ff6f
SHA1 7d4659d43e08d368ddacd31945872461c0b06253
SHA256 0e90a9e4b8f3a5bf990e8aadfd8096ad7aeaf1a4e032ac7b6395ce191d61c142
SHA3 cab98fabaf20118d9a8a4d2bcff4383a7291a0e04ff11a8690e71eed619c75e7
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.26612
MD5 0ec0a0948a526b9c7eebe39bb02b6b0b
SHA1 867b304f20fd74abeb5c30515837f1c41cd3bf8f
SHA256 d442adb90ba296c7e617d2f58d6fa6f308bcd8ef65e5e9c66db4dd27f93fcfbe
SHA3 5bc458755a2ca5c7475620389d9b6b67952973c4366c6777d45c969b8bc67cd4

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9993
MD5 6b224e01af48ec8e4c17a59d9534e885
SHA1 de787d2a1e840618ba2c7eb69d28f6966c404d1d
SHA256 50279c9885b490e74b49ac0273940b6e0891b62fc9ffb5c52e35422a694f248b
SHA3 71b543301bccda64ba61a27873c952890233e0cbec10e0b59245fc303bcfadbc

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.24459
MD5 ca82d899b1d402941b5c92ed9028cd95
SHA1 fb329ec4455d5caf1753305debcc14ab6ebb9015
SHA256 9da1013c864092e49c2676b3ba68a0d4513457d77d251730ed73cc5f4a4813b1
SHA3 768277223731ffdcb799e50961d0afccf23bbae54118d53b834617ccbd0c5cd9

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01502
MD5 05e60fd47096a729dda2aaa4ab05ebc7
SHA1 de8ec9b484fa4f565b14f55503c9cd95231b633b
SHA256 61f762babde9942f43ee97154b8734efeed0632a6ea778dc395793ae3e3e7507
SHA3 f8ba0d4a91389414904cc66226099f27f482055e90ba449e2396193f139713d8

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.16057
MD5 d9ee3a2962251a241bce41b0524cfc0e
SHA1 2ba919aaa7237367a158e4b95385ab1ee07643d8
SHA256 69e6579a37fcaec037634e7fecbfc6a26093ea81dc4bd555d8a12187d2cd0866
SHA3 a1699668464f7edf9a748dfc264f9d30e3c69a228be0a18cade30c14aa6c77ba

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34146
MD5 53482d364aa2d4ae7ca05199dad7651a
SHA1 ccb213408acc7f5ddb94753e6410be23aab5cedd
SHA256 ff06189b43a5c1d6cc5d1b7cbf6ab56b1157ec52807945d652274a211462cba5
SHA3 60659e39ef3f267c267093f8bc4c87ed61eea4ef96ac0f583184f580844573e5

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04232
MD5 636ad42555a835e3a94209043df4a45a
SHA1 c878613bda5cba6cb5769846e60229890c5df248
SHA256 491e52ded039ec6684277e6f1f820e288763ae6d20e682bcfffb6cee4518ac23
SHA3 4b79e60727e0f7be7495c59fb949e22bd753cff6e145e4694257a21a7b5dba8c

102

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71813
MD5 7add80697358fcc3e63354d269ea5ac9
SHA1 72c0a1363b9b4fee0a4acb42b31cd9b5e0664c4c
SHA256 b29c7a1301ddb0e896faf944d8ea8f4e57ff4f3d5fc3e5dc5bf3e64ed6be2fdd
SHA3 40a0e6b6b579b110550a4c3304eb33293a293d9aa288b02b11750143b52423fe

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56193
MD5 db6dd0434da4d7cac564518725167e09
SHA1 a65a1367d7cd96450f089a8f8108239bbcea9f5b
SHA256 c50631fc1f8425a95fd1edcc8e730d339e193a38f18d42372c32847a5ad2c016
SHA3 4e3be5455c51e1cb04836e318cb69ecdffd2deadd0f338d4bc985d8f5ca653ff

104

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70411
MD5 9bf5ce4f6c93b09e4f5659e204c7ef69
SHA1 70260f4f07476e289d4f0da08f6ea81edf377c05
SHA256 4978808cfa3a9f541262585edca9b87268d2025e637f7254b269cef216b39a79
SHA3 006381732c2dfc87ce25f0b93f7446bbeb1549e901e375f8a720af89e0ef211a

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67385
MD5 d1a92272fbd597e1aa19021483110d5a
SHA1 9f75072682b37c6c52361d8c988ebd06dd003f63
SHA256 15663576584c947d634dab9848defcc7d8f05eb0b7e7c6d52d81eca695fc7a6e
SHA3 704756797695ae34f6fae500852bca70e5066a1d1993348fe40ccf626235d0d6

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89384
MD5 3f145145da21614de72c0da073529fb6
SHA1 824b69a49adb1c6105446ed2d4fdf482d6a497ca
SHA256 2291b810e47f055ab2ff100618a8a9966f1fbf5fc0cb58e9f8fbb36ac7c983fa
SHA3 999c540cbf8b2538317695989c1e3c2913db9113267473fc49c24cac4119d558

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89887
MD5 663040d6315b1d6ce8c0334d182ed8fc
SHA1 ebcfff801a12fb8ad1200a4526fca8bd2c3e96cf
SHA256 cb3c86cbcb579244a6f819f9c1807a7e89b6e600982ec6ea0841fcdcb16a9efd
SHA3 6a25a2cb16aeb17693f10e8aaa0245c701701db571b458fde7830291a4a01cfc

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6691
Detected Filetype Icon file
MD5 e624f041c921d299a6da3a8c5f48f989
SHA1 ffa07c86ac3dac45398ee07b26610dfb5c99d8ea
SHA256 fed46e06346fb8f64b14c18408a82caf955929ac0e65151630539dc5bd194584
SHA3 b51d47dbe9cbe18b1f520275504256022a827f919672b081943ae45cd4ff44c9

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x42a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29645
MD5 6c58e1192918c8491e3384f8bf87c358
SHA1 df33c3ba83a16cd4e85e3fb0085e16ca7e318745
SHA256 b251b264714bacfeb161373c09090f4d94fb9dd50a1007caff6f5664f767e75f
SHA3 40ec52e5f40167463f08f754ab4183ba4cf40f1e3e4b930d9c771f83c0c9adca

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd246d0e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 159
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
<-- -->