| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-17 12:28:33 |
| Detected languages |
English - United States
|
| CompanyName | Adobe Inc |
| FileDescription | Adobe Download Manager |
| FileVersion | 2.0.0.861s |
| InternalName | Adobe Download Manager |
| LegalCopyright | Copyright 2019 Adobe Inc. All rights reserved. |
| OriginalFilename | Adobe Download Manager |
| ProductName | Adobe Download Manager |
| ProductVersion | 2.0.0.861s |
| Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. |
Resource 145 is possibly compressed or encrypted.
Resource 146 is possibly compressed or encrypted. Resource 147 is possibly compressed or encrypted. Resource 148 is possibly compressed or encrypted. Resource 149 is possibly compressed or encrypted. Resource 150 is possibly compressed or encrypted. Resource 151 is possibly compressed or encrypted. Resource 152 is possibly compressed or encrypted. Resource 153 is possibly compressed or encrypted. Resource 154 is possibly compressed or encrypted. Resource 155 is possibly compressed or encrypted. Resource 172 is possibly compressed or encrypted. Resource 173 is possibly compressed or encrypted. Resource 179 is possibly compressed or encrypted. Resource 184 is possibly compressed or encrypted. Resource 185 is possibly compressed or encrypted. Resource 187 is possibly compressed or encrypted. Resource 189 is possibly compressed or encrypted. Resource 190 is possibly compressed or encrypted. Resource 191 is possibly compressed or encrypted. Resource 192 is possibly compressed or encrypted. Resource 193 is possibly compressed or encrypted. Resource 194 is possibly compressed or encrypted. Resource 200 is possibly compressed or encrypted. Resource 201 is possibly compressed or encrypted. Resource 202 is possibly compressed or encrypted. Resource 206 is possibly compressed or encrypted. Resource 207 is possibly compressed or encrypted. Resource 208 is possibly compressed or encrypted. Resource 209 is possibly compressed or encrypted. Resource 210 is possibly compressed or encrypted. Resource 211 is possibly compressed or encrypted. Resource 213 is possibly compressed or encrypted. Resource 215 is possibly compressed or encrypted. Resource 216 is possibly compressed or encrypted. Resource 217 is possibly compressed or encrypted. Resource 218 is possibly compressed or encrypted. Resource 219 is possibly compressed or encrypted. Resource 220 is possibly compressed or encrypted. Resource 221 is possibly compressed or encrypted. Resource 222 is possibly compressed or encrypted. Resource 223 is possibly compressed or encrypted. Resource 224 is possibly compressed or encrypted. Resource 225 is possibly compressed or encrypted. Resource 226 is possibly compressed or encrypted. Resource 227 is possibly compressed or encrypted. Resource 228 is possibly compressed or encrypted. Resource 229 is possibly compressed or encrypted. Resource 230 is possibly compressed or encrypted. Resource 168 is possibly compressed or encrypted. Resource 231 is possibly compressed or encrypted. Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource 3843 is possibly compressed or encrypted. Resource 3857 is possibly compressed or encrypted. Resource 3858 is possibly compressed or encrypted. Resource 3859 is possibly compressed or encrypted. Resource 3866 is possibly compressed or encrypted. Resource 3867 is possibly compressed or encrypted. Resource 3868 is possibly compressed or encrypted. Resource 3887 is possibly compressed or encrypted. Resource 160 is possibly compressed or encrypted. Resources amount for 97.7191% of the executable. |
| Info | The PE is digitally signed. |
Signer: Adobe Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-04-27 12:16:16) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2026-Apr-17 12:28:33 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x189000 |
| SizeOfInitializedData | 0x5000 |
| SizeOfUninitializedData | 0x2f6000 |
| AddressOfEntryPoint | 0x0047F6B0 (Section: UPX1) |
| BaseOfCode | 0x2f7000 |
| BaseOfData | 0x480000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x485000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1947dd |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
FreeSid
|
|---|---|
| COMCTL32.dll |
InitCommonControlsEx
|
| GDI32.dll |
LPtoDP
|
| gdiplus.dll |
GdipFree
|
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
| ole32.dll |
OleRun
|
| OLEAUT32.dll |
SysFreeString
|
| SHELL32.dll |
DragFinish
|
| SHLWAPI.dll |
UrlIsW
|
| 礁 ᘠ耀礖 ᙈ耀礗 ᙰ耀礘 ᚘ |