| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Nov-02 06:08:41 |
| Detected languages |
English - United States
German - Germany |
| CompanyName | MiTeC |
| FileDescription | Structured Storage Viewer |
| FileVersion | 4.1.2.0 |
| LegalCopyright | Copyright (c) 2005-2022, Michal Mutl |
| LegalTrademarks | All rights reserved |
| ProductName | SS Viewer |
| ProductVersion | 4.0.0.0 |
| OriginalFilename | SSView.exe |
| BuildTimestamp | 2022-11-02 08:08:41 |
| Suspicious | The PE is possibly packed. |
Unusual section name found:
Unusual section name found: Unusual section name found: Unusual section name found: Unusual section name found: Unusual section name found: Section is both writable and executable. The PE only has 4 import(s). |
| Info | The PE contains common functions which appear in legitimate applications. |
Can access the registry:
|
| Info | The PE's resources present abnormal characteristics. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource 8 is possibly compressed or encrypted. Resource 9 is possibly compressed or encrypted. Resource 10 is possibly compressed or encrypted. Resource 11 is possibly compressed or encrypted. Resource 12 is possibly compressed or encrypted. Resource 13 is possibly compressed or encrypted. Resource 14 is possibly compressed or encrypted. Resource 15 is possibly compressed or encrypted. Resource 16 is possibly compressed or encrypted. Resource 17 is possibly compressed or encrypted. Resource 18 is possibly compressed or encrypted. Resource 19 is possibly compressed or encrypted. Resource 20 is possibly compressed or encrypted. Resource 21 is possibly compressed or encrypted. Resource ABCOMCTRLS_LOCK is possibly compressed or encrypted. Resource ABCOMCTRLS_SORTDOWN is possibly compressed or encrypted. Resource ABCOMCTRLS_SORTUP is possibly compressed or encrypted. Resource ABCOMCTRLS_ZIP is possibly compressed or encrypted. Resource BOOKMARKICONS is possibly compressed or encrypted. Resource CLOSEDFOLDER is possibly compressed or encrypted. Resource CURRENTFOLDER is possibly compressed or encrypted. Resource EXECUTABLE is possibly compressed or encrypted. Resource KNOWNFILE is possibly compressed or encrypted. Resource NETWORK is possibly compressed or encrypted. Resource OPENFOLDER is possibly compressed or encrypted. Resource SYNEDITINTERNALIMAGES is possibly compressed or encrypted. Resource SYNEDITWRAPPED is possibly compressed or encrypted. Resource UNKNOWNFILE is possibly compressed or encrypted. Resource VT_MOVEALL is possibly compressed or encrypted. Resource VT_MOVEEW is possibly compressed or encrypted. Resource VT_MOVENS is possibly compressed or encrypted. Resource VT_XPBUTTONMINUS is possibly compressed or encrypted. Resource VT_XPBUTTONPLUS is possibly compressed or encrypted. Resource 4048 is possibly compressed or encrypted. Resource 4049 is possibly compressed or encrypted. Resource 4050 is possibly compressed or encrypted. Resource 4051 is possibly compressed or encrypted. Resource 4052 is possibly compressed or encrypted. Resource 4053 is possibly compressed or encrypted. Resource 4054 is possibly compressed or encrypted. Resource 4055 is possibly compressed or encrypted. Resource 4056 is possibly compressed or encrypted. Resource 4057 is possibly compressed or encrypted. Resource 4058 is possibly compressed or encrypted. Resource 4059 is possibly compressed or encrypted. Resource 4060 is possibly compressed or encrypted. Resource 4061 is possibly compressed or encrypted. Resource 4062 is possibly compressed or encrypted. Resource 4063 is possibly compressed or encrypted. Resource 4064 is possibly compressed or encrypted. Resource 4065 is possibly compressed or encrypted. Resource 4066 is possibly compressed or encrypted. Resource 4067 is possibly compressed or encrypted. Resource 4068 is possibly compressed or encrypted. Resource 4069 is possibly compressed or encrypted. Resource 4070 is possibly compressed or encrypted. Resource 4071 is possibly compressed or encrypted. Resource 4072 is possibly compressed or encrypted. Resource 4073 is possibly compressed or encrypted. Resource 4075 is possibly compressed or encrypted. Resource 4076 is possibly compressed or encrypted. Resource 4077 is possibly compressed or encrypted. Resource 4078 is possibly compressed or encrypted. Resource 4079 is possibly compressed or encrypted. Resource 4080 is possibly compressed or encrypted. Resource 4081 is possibly compressed or encrypted. Resource 4082 is possibly compressed or encrypted. Resource 4083 is possibly compressed or encrypted. Resource 4084 is possibly compressed or encrypted. Resource 4085 is possibly compressed or encrypted. Resource 4086 is possibly compressed or encrypted. Resource 4087 is possibly compressed or encrypted. Resource 4088 is possibly compressed or encrypted. Resource 4089 is possibly compressed or encrypted. Resource 4090 is possibly compressed or encrypted. Resource 4092 is possibly compressed or encrypted. Resource 4093 is possibly compressed or encrypted. Resource 4094 is possibly compressed or encrypted. Resource 4095 is possibly compressed or encrypted. Resource 4096 is possibly compressed or encrypted. Resource BBABORT is possibly compressed or encrypted. Resource BBABORT_DISABLED is possibly compressed or encrypted. Resource BBALL is possibly compressed or encrypted. Resource BBALL_DISABLED is possibly compressed or encrypted. Resource BBCANCEL is possibly compressed or encrypted. Resource BBCANCEL_DISABLED is possibly compressed or encrypted. Resource BBCLOSE is possibly compressed or encrypted. Resource BBCLOSE_DISABLED is possibly compressed or encrypted. Resource BBHELP is possibly compressed or encrypted. Resource BBHELP_DISABLED is possibly compressed or encrypted. Resource BBIGNORE is possibly compressed or encrypted. Resource BBIGNORE_DISABLED is possibly compressed or encrypted. Resource BBNO is possibly compressed or encrypted. Resource BBNO_DISABLED is possibly compressed or encrypted. Resource BBOK is possibly compressed or encrypted. Resource BBOK_DISABLED is possibly compressed or encrypted. Resource BBRETRY is possibly compressed or encrypted. Resource BBRETRY_DISABLED is possibly compressed or encrypted. Resource BBYES is possibly compressed or encrypted. Resource BBYES_DISABLED is possibly compressed or encrypted. Resource EULA is possibly compressed or encrypted. Resource MSG_ERROR is possibly compressed or encrypted. Resource MSG_INFO is possibly compressed or encrypted. Resource MSG_WARNING is possibly compressed or encrypted. Resource TDLGABOUT is possibly compressed or encrypted. Resource TDLGMRUMGMT is possibly compressed or encrypted. Resource TDLGREGWIZ is possibly compressed or encrypted. Resource TDLG_OPENXML_BROWSER is possibly compressed or encrypted. Resource TDLG_SSV_ES is possibly compressed or encrypted. Resource TDLG_SSV_NEWPS is possibly compressed or encrypted. Resource TDLG_SSV_PREFS is possibly compressed or encrypted. Resource TDLG_SSV_PROP is possibly compressed or encrypted. Resource TDLG_SSV_SAVESTREAMS is possibly compressed or encrypted. Resource TDLG_SS_HEXFIND is possibly compressed or encrypted. Resource TWND_SSV_MAIN is possibly compressed or encrypted. Resource TWND_SSV_VIEWER is possibly compressed or encrypted. Resource 19614 is possibly compressed or encrypted. |
| Info | The PE is digitally signed. |
Signer: ing. Michal Mutl
Issuer: Sectigo Public Code Signing CA R36 |
| Suspicious | VirusTotal score: 1/70 (Scanned on 2026-05-11 09:05:14) | VBA32: BScope.Trojan.Tiggre |
| e_magic | MZ |
|---|---|
| e_cblp | 0x5f29 |
| e_cp | 0x4ff |
| e_crlc | 0x31f7 |
| e_cparhdr | 0x32a0 |
| e_minalloc | 0x9f41 |
| e_maxalloc | 0xb088 |
| e_ss | 0x95e1 |
| e_sp | 0xe5f5 |
| e_csum | 0x2fc3 |
| e_ip | 0xac5f |
| e_cs | 0xa9f6 |
| e_ovno | 0xcd9f |
| e_oemid | 0x9eb |
| e_oeminfo | 0xb40d |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2022-Nov-02 06:08:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x537400 |
| SizeOfInitializedData | 0xb7600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00616000 (Section: ) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x539000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x62e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2a2fae |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetModuleHandleW
|
|---|---|
| user32.dll |
GetMenuState
|
| advapi32.dll |
RegOpenKeyExW
|
| comctl32.dll |
ImageList_SetImageCount
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.1.2.0 |
| ProductVersion | 4.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MiTeC |
| FileDescription | Structured Storage Viewer |
| FileVersion (#2) | 4.1.2.0 |
| LegalCopyright | Copyright (c) 2005-2022, Michal Mutl |
| LegalTrademarks | All rights reserved |
| ProductName | SS Viewer |
| ProductVersion (#2) | 4.0.0.0 |
| OriginalFilename | SSView.exe |
| BuildTimestamp | 2022-11-02 08:08:41 |
| Resource LangID | English - United States |
|---|
No comments yet.