Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jan-11 18:59:07 |
Detected languages |
English - United States
|
Debug artifacts |
Y:\work\80d8bf0ac6046a03\shell\build\desktop\Installer\_win32\installer2\Release\installer_stub.pdb
|
CompanyName | Spotify Ltd |
FileDescription | SpotifyInstaller |
FileVersion | 0,0,0,0 |
InternalName | SpotifyInstaller |
LegalCopyright | Copyright (c) 2018, Spotify Ltd |
OriginalFilename | SpotifyInstaller.exe |
ProductName | Spotify |
ProductVersion | 1.0.72.117.g6bd7cc73 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Spotify AB
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Safe | VirusTotal score: 0/68 (Scanned on 2019-11-27 16:28:06) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Jan-11 18:59:07 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x67400 |
SizeOfInitializedData | 0x48800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0003FF71 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x69000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb3000 |
SizeOfHeaders | 0x400 |
Checksum | 0xbb97d |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
COMCTL32.dll |
InitCommonControlsEx
|
---|---|
SHELL32.dll |
ShellExecuteExW
SHGetFolderPathW SHChangeNotify ShellExecuteW |
KERNEL32.dll |
WriteFile
CloseHandle GetLastError InitializeCriticalSection EnterCriticalSection LeaveCriticalSection WaitForSingleObject CreateMutexW OpenMutexW Sleep GetCurrentProcess TerminateProcess GetExitCodeProcess CreateProcessW OpenProcess GetLocalTime GetTickCount GetModuleFileNameW LoadLibraryExA VerifyVersionInfoW CompareStringW MultiByteToWideChar WideCharToMultiByte SetEvent CreateEventW CreateThread GetModuleHandleW CreateDirectoryW DeleteFileW FindClose FindFirstFileW FindNextFileW GetFileAttributesW RemoveDirectoryW GetCurrentProcessId MoveFileExW GetFileSize SetEndOfFile SetFilePointer GetTempPathW CreateFileMappingW MapViewOfFile UnmapViewOfFile GetLocaleInfoA GetUserDefaultUILanguage GetProcAddress CreateFileW VerSetConditionMask SetFilePointerEx DeviceIoControl LCMapStringW AreFileApisANSI LocalFree FormatMessageA SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExW GetTimeZoneInformation GetProcessHeap ReadFile VirtualQuery GetConsoleMode GetConsoleCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetTimeFormatW GetDateFormatW LoadLibraryW GetCommandLineW GetFileType GetACP GetStdHandle GetModuleHandleExW ExitProcess ReadConsoleW HeapSize WriteConsoleW GetSystemInfo VirtualProtect DeleteCriticalSection EncodePointer DecodePointer SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetLocaleInfoW GetStringTypeW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent ResetEvent WaitForSingleObjectEx IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentThreadId InitializeSListHead RaiseException RtlUnwind FreeLibrary LoadLibraryExW HeapAlloc HeapReAlloc HeapFree |
USER32.dll |
wsprintfW
LoadIconW LoadCursorW SetWindowLongW GetWindowLongW MessageBoxW AdjustWindowRect SetTimer SetDlgItemTextW GetDlgItem ShowWindow CreateWindowExW RegisterClassExW DefWindowProcW PostMessageW SendMessageW DispatchMessageW TranslateMessage GetMessageW GetWindowThreadProcessId FindWindowA SendMessageTimeoutA wsprintfA GetActiveWindow GetSystemMetrics |
GDI32.dll |
GetStockObject
|
ole32.dll |
CoCreateGuid
CoCreateInstance CoInitializeEx |
OLEAUT32.dll |
#6
#2 |
ADVAPI32.dll |
OpenProcessToken
RegSetValueExW RegOpenKeyExW RegCreateKeyExW GetTokenInformation |
VERSION.dll (delay-loaded) |
GetFileVersionInfoW
VerQueryValueA GetFileVersionInfoSizeW |
Attributes | 0x1 |
---|---|
Name | VERSION.dll |
ModuleHandle | 0xa3c5c |
DelayImportAddressTable | 0xa37f4 |
DelayImportNameTable | 0x9ac44 |
BoundDelayImportTable | 0x9ad10 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.72.117 |
ProductVersion | 0.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Spotify Ltd |
FileDescription | SpotifyInstaller |
FileVersion (#2) | 0,0,0,0 |
InternalName | SpotifyInstaller |
LegalCopyright | Copyright (c) 2018, Spotify Ltd |
OriginalFilename | SpotifyInstaller.exe |
ProductName | Spotify |
ProductVersion (#2) | 1.0.72.117.g6bd7cc73 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jan-11 18:59:07 |
Version | 0.0 |
SizeofData | 124 |
AddressOfRawData | 0x95430 |
PointerToRawData | 0x93c30 |
Referenced File | Y:\work\80d8bf0ac6046a03\shell\build\desktop\Installer\_win32\installer2\Release\installer_stub.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jan-11 18:59:07 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x954ac |
PointerToRawData | 0x93cac |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jan-11 18:59:07 |
Version | 0.0 |
SizeofData | 1040 |
AddressOfRawData | 0x954c0 |
PointerToRawData | 0x93cc0 |
StartAddressOfRawData | 0x4a5000 |
---|---|
EndAddressOfRawData | 0x4a5008 |
AddressOfIndex | 0x4a434c |
AddressOfCallbacks | 0x46949c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x68 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x49c0e4 |
SEHandlerTable | 0x494fa0 |
SEHandlerCount | 292 |
XOR Key | 0x979165bb |
---|---|
Unmarked objects | 0 |
ASM objects (24610) | 13 |
C++ objects (24610) | 161 |
C objects (24610) | 22 |
199 (41118) | 1 |
ASM objects (24723) | 22 |
C objects (24723) | 34 |
262 (24610) | 3 |
Imports (24610) | 17 |
Total imports | 194 |
C++ objects (24723) | 62 |
C objects (VS2017 v15.2 compiler 25019) | 2 |
C++ objects (VS2017 v15.2 compiler 25019) | 23 |
Resource objects (VS2017 v15.2 compiler 25019) | 1 |
Linker (VS2017 v15.2 compiler 25019) | 1 |