| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-20 11:28:11 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
E:\jenkins\.jenkins\workspace\install_project\install_setup\install_and_uninstall\Release\setup.pdb
|
| FileVersion | 1.1026.1070.520 |
| ProductVersion | 1.1026.1070.520 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to Blowfish Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 203 detected as a CAB Installer file. |
| Info | The PE is digitally signed. |
Signer: \xE6\x88\x90\xE9\x83\xBD\xE5\xA5\x87\xE9\xB2\x81\xE7\xA7\x91\xE6\x8A\x80\xE6\x9C\x89\xE9\x99\x90\xE5\x85\xAC\xE5\x8F\xB8
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x150 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-May-20 11:28:11 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x14c000 |
| SizeOfInitializedData | 0x473600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00099B74 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x5c5000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x5cb49a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateEventW
WaitForMultipleObjects GetTempFileNameW CreateProcessW GetStartupInfoW GetVersion OpenEventW GlobalAddAtomW GetFileSizeEx GetCommandLineW DecodePointer LoadLibraryExW lstrcmpiW LoadLibraryA GetLocalTime CopyFileW OutputDebugStringA ResetEvent GetPrivateProfileStringW CreateDirectoryW GetShortPathNameW FormatMessageW GetCurrentProcessId CreateMutexW WaitForSingleObject LeaveCriticalSection EnterCriticalSection InitializeCriticalSection GetTickCount64 IsDebuggerPresent EncodePointer InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList FlushInstructionCache GlobalLock GlobalAlloc GetSystemDirectoryW GetLogicalDriveStringsW GetDriveTypeW GetDiskFreeSpaceExW MoveFileExW MoveFileW lstrlenW GetWindowsDirectoryW SetLastError GetTempPathW SetFileAttributesW RemoveDirectoryW GetFullPathNameW GetFileAttributesW FindNextFileW FindFirstFileW FindClose DeleteFileW GetLongPathNameW WideCharToMultiByte GetTickCount Sleep GetLastError WritePrivateProfileStringW FindResourceW SizeofResource WriteConsoleW ReadConsoleW SetStdHandle WaitForSingleObjectEx SetEnvironmentVariableW SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExW FindFirstFileExA SetConsoleCtrlHandler EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetTimeFormatW GetDateFormatW GetCurrentThread GetConsoleMode GetConsoleCP GetCurrentDirectoryW SetCurrentDirectoryW GetExitCodeProcess TerminateProcess GetCurrentProcess VerifyVersionInfoW GetCurrentThreadId DeleteCriticalSection InitializeCriticalSectionEx RaiseException VerSetConditionMask MultiByteToWideChar UnlockFile LockFile GetFileSize MulDiv Process32NextW Process32FirstW CreateToolhelp32Snapshot GlobalFindAtomW GlobalDeleteAtom LockResource LoadResource GetModuleHandleW GetModuleFileNameW FreeLibrary FindResourceExW GetVersionExW DeviceIoControl UnmapViewOfFile MapViewOfFile CreateFileMappingW GetFileAttributesExW CreateFileW LoadLibraryW DosDateTimeToFileTime GetProcAddress GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc HeapDestroy OutputDebugStringW SetFilePointer ReadFile LocalFileTimeToFileTime GetTempFileNameA GetTempPathA CloseHandle SetEvent LocalAlloc IsProcessorFeaturePresent VirtualAlloc VirtualFree LoadLibraryExA OpenProcess GlobalFree LocalFree GlobalUnlock GetStringTypeW InitializeCriticalSectionAndSpinCount SwitchToThread TlsAlloc SetFilePointerEx GetFileType GetACP GetModuleFileNameA ExitProcess GetTimeZoneInformation GetModuleHandleExW FreeLibraryAndExitThread TlsGetValue ResumeThread ExitThread CreateThread TlsSetValue TlsFree GetSystemTimeAsFileTime CompareStringW LCMapStringW GetLocaleInfoW GetCPInfo OpenFileMappingW UnhandledExceptionFilter SetUnhandledExceptionFilter QueryPerformanceCounter FlushFileBuffers SearchPathW SetFileTime FindCloseChangeNotification FindFirstChangeNotificationW CompareFileTime GetFileInformationByHandle SetEndOfFile GetStdHandle InterlockedCompareExchange FreeResource GetSystemWindowsDirectoryW lstrcmpA InterlockedFlushSList WriteFile DeleteFileA CreateFileA RtlUnwind ReleaseMutex FileTimeToDosDateTime FileTimeToLocalFileTime SystemTimeToFileTime GetSystemTime GetFileTime FindNextFileA FindFirstFileA lstrcmpiA GetSystemInfo |
|---|---|
| USER32.dll |
DrawTextW
UnhookWinEvent wsprintfW SetTimer KillTimer GetWindowTextLengthW GetMessageW TranslateMessage DispatchMessageW PeekMessageW DestroyWindow GetDC ReleaseDC SendMessageW ShowWindow IsWindowVisible IsIconic SetForegroundWindow FindWindowExW GetWindowThreadProcessId PostMessageW IsWindow SetCursor SetRect OffsetRect LoadCursorW ScreenToClient PtInRect CopyRect DrawFocusRect BeginPaint EndPaint IsRectEmpty DefWindowProcW CallWindowProcW UnregisterClassW RegisterClassExW GetClassInfoExW CreateWindowExW InvalidateRect GetClientRect GetWindowRect GetWindowLongW SetWindowLongW GetParent UpdateLayeredWindow SetWindowPos SetWindowRgn SystemParametersInfoW WaitForInputIdle GetSystemMetrics MonitorFromWindow GetWindowTextW SetWinEventHook UnregisterClassA FindWindowW SendNotifyMessageW SendMessageTimeoutW RegisterWindowMessageW MessageBoxW IsDialogMessageW EndDialog BringWindowToTop RedrawWindow GetMonitorInfoW LoadImageW GetWindow MapWindowPoints SetWindowTextW CharNextW MoveWindow PostQuitMessage ExitWindowsEx SetProcessDPIAware DialogBoxParamW |
| GDI32.dll |
DeleteObject
SaveDC RestoreDC SetTextColor SetBkMode CreateRectRgn CombineRgn SetViewportOrgEx CreateCompatibleDC CreateCompatibleBitmap BitBlt ExtTextOutW SetBkColor DeleteDC SelectObject GetTextExtentPoint32W GetDeviceCaps CreateFontIndirectW EnumFontFamiliesW CreateFontW |
| ADVAPI32.dll |
CryptAcquireContextW
RegQueryValueExA RegOpenKeyExA RegEnumKeyExA RegSetValueExW RegQueryInfoKeyW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegQueryValueExW RegOpenKeyExW RegEnumKeyExW RegCloseKey LookupPrivilegeValueW AdjustTokenPrivileges OpenProcessToken UnlockServiceDatabase StartServiceW QueryServiceStatusEx QueryServiceStatus QueryServiceLockStatusW QueryServiceConfig2W QueryServiceConfigW OpenServiceW OpenSCManagerW LockServiceDatabase DeleteService CreateServiceW ControlService CloseServiceHandle ChangeServiceConfig2W ChangeServiceConfigW GetUserNameW AllocateAndInitializeSid CheckTokenMembership FreeSid DeleteAce EqualSid LookupAccountSidW LookupAccountNameW SetEntriesInAclW GetExplicitEntriesFromAclW GetNamedSecurityInfoW SetNamedSecurityInfoW BuildExplicitAccessWithNameW GetTrusteeNameW GetTokenInformation CryptReleaseContext CryptDestroyKey CryptSetKeyParam CryptGenRandom CryptImportKey CryptEncrypt CryptDecrypt CryptContextAddRef RegGetValueW |
| SHELL32.dll |
#165
CommandLineToArgvW SHGetSpecialFolderPathW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW ShellExecuteW SHLoadInProc ShellExecuteExW SHChangeNotify SHGetDesktopFolder SHGetSpecialFolderLocation SHCreateDirectoryExW |
| ole32.dll |
CoCreateGuid
CoInitializeSecurity CoSetProxyBlanket CoInitialize CoTaskMemRealloc CoUninitialize CLSIDFromProgID StringFromGUID2 CreateStreamOnHGlobal OleRun CoTaskMemFree CoCreateInstance CoInitializeEx CoTaskMemAlloc |
| OLEAUT32.dll |
VariantCopy
CreateErrorInfo SetErrorInfo VariantChangeType GetErrorInfo VariantInit SysStringLen VariantClear SysAllocStringByteLen SysStringByteLen SysAllocString SysFreeString VarUI4FromStr |
| SHLWAPI.dll |
PathIsRootW
PathFindFileNameA PathRenameExtensionA PathAppendW PathCombineW PathFileExistsW PathRemoveFileSpecW PathFindExtensionW wnsprintfW StrCmpW PathFindFileNameW PathUnquoteSpacesW SHGetValueW SHSetValueW PathIsPrefixW PathIsRelativeW StrStrIW SHDeleteValueW PathIsDirectoryW StrStrIA StrCmpNIW StrTrimA StrToIntExW SHGetValueA SHSetValueA PathAppendA SHDeleteKeyW StrCmpIW |
| COMCTL32.dll |
InitCommonControlsEx
_TrackMouseEvent |
| gdiplus.dll |
GdipDeleteBrush
GdipGraphicsClear GdipDrawImagePointRectI GdipSetStringFormatTrimming GdipSetStringFormatLineAlign GdipSetStringFormatAlign GdipSetStringFormatFlags GdipDeleteStringFormat GdipCreateStringFormat GdipMeasureString GdipDrawString GdiplusStartup GdiplusShutdown GdipAlloc GdipFree GdipCloneImage GdipDisposeImage GdipGetImageWidth GdipGetImageHeight GdipCreateBitmapFromStream GdipCreateBitmapFromFile GdipCreateBitmapFromStreamICM GdipCreateBitmapFromFileICM GdipCreateFromHDC GdipDeleteGraphics GdipDrawImageRectRect GdipDrawImageRectRectI GdipCloneBrush GdipDeleteFont GdipCreateSolidFill GdipCreateImageAttributes GdipDisposeImageAttributes GdipSetImageAttributesColorMatrix GdipSetTextRenderingHint GdipCreateFontFamilyFromName GdipDeleteFontFamily GdipCreateFont GdipFillRectangleI |
| Cabinet.dll |
#23
#20 #22 |
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| PSAPI.DLL |
EnumProcesses
GetModuleFileNameExW |
| SETUPAPI.dll |
SetupIterateCabinetW
|
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| WININET.dll |
InternetGetConnectedState
|
| urlmon.dll |
URLDownloadToCacheFileW
URLDownloadToFileW |
| Secur32.dll |
GetUserNameExW
|
| CRYPT32.dll |
CryptBinaryToStringW
CryptBinaryToStringA CertGetNameStringW CryptStringToBinaryW CryptStringToBinaryA |
| WINTRUST.dll |
WTHelperProvDataFromStateData
WinVerifyTrust |
| Ordinal | 1 |
|---|---|
| Address | 0x44ee0 |
| Ordinal | 2 |
|---|---|
| Address | 0x44fb0 |
| 鲁大师 |
| buychannel_02 |
| normal |
| no |
| 0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1026.1070.520 |
| ProductVersion | 1.1026.1070.520 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | Chinese - PRC |
| FileVersion (#2) | 1.1026.1070.520 |
| ProductVersion (#2) | 1.1026.1070.520 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-20 11:28:11 |
| Version | 0.0 |
| SizeofData | 124 |
| AddressOfRawData | 0x17b1c8 |
| PointerToRawData | 0x17a5c8 |
| Referenced File | E:\jenkins\.jenkins\workspace\install_project\install_setup\install_and_uninstall\Release\setup.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-20 11:28:11 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x17b244 |
| PointerToRawData | 0x17a644 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-20 11:28:11 |
| Version | 0.0 |
| SizeofData | 984 |
| AddressOfRawData | 0x17b258 |
| PointerToRawData | 0x17a658 |
| StartAddressOfRawData | 0x57b640 |
|---|---|
| EndAddressOfRawData | 0x57b648 |
| AddressOfIndex | 0x59dd94 |
| AddressOfCallbacks | 0x54d96c |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x595aec |
| SEHandlerTable | 0x579f20 |
| SEHandlerCount | 1194 |
| XOR Key | 0x39844a5e |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 18 |
| 243 (40116) | 173 |
| 242 (40116) | 31 |
| C++ objects (VS2017 v15.9.12-13 compiler 27031) | 5 |
| C objects (LTCG) (27051) | 2 |
| Unmarked objects (#2) | 1 |
| C++ objects (VS2017 v15.7.5 compiler 26433) | 10 |
| C++ objects (VS2017 v15.9.14-15 compiler 27032) | 6 |
| 199 (41118) | 3 |
| ASM objects (VS 2015/2017 runtime 26706) | 25 |
| C objects (VS 2015/2017 runtime 26706) | 35 |
| C++ objects (VS 2015/2017 runtime 26706) | 81 |
| C objects (65501) | 4 |
| 208 (65501) | 3 |
| Imports (65501) | 41 |
| Total imports | 480 |
| C objects (27051) | 1 |
| C++ objects (27051) | 106 |
| Exports (27051) | 1 |
| Resource objects (27051) | 1 |
| 151 | 2 |
| Linker (27051) | 1 |
No comments yet.