2bb05940b78c4b15473105f6ea1886ef95773fcbd59f1a17897edd1636a06a92

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2013-Mar-30 01:01:23
Detected languages English - United States
CompanyName IT Relation A/S
FileDescription
FileVersion 1. 2. 0. 0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName ITR Default Printer Fix
ProductVersion 1. 2. 0. 0
Comments

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Info Cryptographic algorithms detected in the binary: Uses constants related to RC5 or RC6
Suspicious The PE is possibly packed. Unusual section name found: .itext
Info The PE contains common functions which appear in legitimate applications. Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
Suspicious The PE is possibly a dropper. Resource SCRIPT is possibly compressed or encrypted.
Resources amount for 79.4013% of the executable.
Malicious VirusTotal score: 7/70 (Scanned on 2026-05-05 07:43:10) CrowdStrike: win/grayware_confidence_70% (D)
Cylance: Unsafe
Google: Detected
Ikarus: Trojan.Win32
MaxSecure: Trojan.Malware.300983.susgen
Trapmine: malicious.moderate.ml.score
tehtris: Generic.Malware

Hashes

MD5 5009198238541a21c14bccd80efa8dac
SHA1 9f74da5f4083ec40f7d963126219a12f49bcb952
SHA256 2bb05940b78c4b15473105f6ea1886ef95773fcbd59f1a17897edd1636a06a92
SHA3 351dc35808e20426fa461582aeacfe4d849decf2d103b39425ceb86aab6be8b7
SSDeep 3072:aVZSaZxDFIFFxUoFMfJDYEffOPdYBJAosVQgA:aVZNFIFF8J0CfOPdYX7r
Imports Hash 6ff9616547fc6d4a6bdafbae0ee60000

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 9
TimeDateStamp 2013-Mar-30 01:01:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x4000
SizeOfInitializedData 0x18800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000050B4 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x6000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x26000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d49d2fef757ff5d1d54bb833531e18bb
SHA1 23628be03efb4f6b5d31c420312cf7a4ce7c9f56
SHA256 68fedf923b1ef212723b321f9567bf148481de83406ea147b88121474c7d5fda
SHA3 20ff3347d83707122955abee277c06322b46864f5be8e2fbb4db9f304bc33de5
VirtualSize 0x3928
VirtualAddress 0x1000
SizeOfRawData 0x3a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.61166

.itext

MD5 9eb8cea4a700b4b77f95c598fdd864f4
SHA1 321c33b917da63fe415c461231ebdb77aba9afa3
SHA256 a7f77551666257c097f5f498f8dd38fc9f21ef956c5e79b9c97800e13a5e2be9
SHA3 90891df3a63b2cf3bef52ec7f3d49559321ea74edc3787c4a9e7468d17704c0f
VirtualSize 0x4b0
VirtualAddress 0x5000
SizeOfRawData 0x600
PointerToRawData 0x3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.89233

.data

MD5 001bac00e38cc36b68445eb5f915f25d
SHA1 8306bec01197ed53ccae63b54028977262aad6f7
SHA256 a431d853e6517efc123950e4fb5a8706542a04ad51686a9a831b1551f21033f2
SHA3 41d54c5f5e22f35a20fa6f822f84751b6a625250616c02ec807ca4077c1b9db4
VirtualSize 0x7b0
VirtualAddress 0x6000
SizeOfRawData 0x800
PointerToRawData 0x4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.26303

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x2978
VirtualAddress 0x7000
SizeOfRawData 0
PointerToRawData 0x4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 bd53e0c14560ba475ac962b18fae51a6
SHA1 5b89e602535c7aea5fba9341df33a3e17b9f521d
SHA256 a1fc1baed28a520d3340db9a828d2ff3949ea51a0b56b6f585f92d339304a3ff
SHA3 9582f9237b7575a85d05f085c5441ae1503a4d5469086148c32654683cbe080f
VirtualSize 0x5de
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.42144

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0xb000
SizeOfRawData 0
PointerToRawData 0x5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 cddb6f8db920f9b052ea99b6dfe54f39
SHA1 4c4d333c0ab5d8d70acf45c0273f6ba986c5cf6d
SHA256 f07f4963d28a179cf15ed57697f641b9384389e6a69d005dc0dbd717ac9f9044
SHA3 739e47548fedbbc4183968d5b998fe9db2ddee6588786f3d162a23d88fe7395c
VirtualSize 0x18
VirtualAddress 0xc000
SizeOfRawData 0x200
PointerToRawData 0x5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.reloc

MD5 848178dd37a39c782d21507d9d53dc24
SHA1 40d3b54cb0cf3ec167790b72052d419339f2ce4f
SHA256 6bc667e24b829c177cc0eeb3a692b595f601b921eff9c24b6930d5fe015d1184
SHA3 2f9167e6d6ddbeb1b1b8282cee1ecf4b3d929a46868e59820fec7c110a30e9db
VirtualSize 0x450
VirtualAddress 0xd000
SizeOfRawData 0x600
PointerToRawData 0x5400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42664

.rsrc

MD5 31ed9461be348b34569ab9ddbe7847ad
SHA1 2ae7116d7d38731dc08232faa8c6d9e455d46119
SHA256 0477835b80d61c6ce2dd55ffb76e52006e64bd150913d66c49e6bb2da3f760ee
SHA3 ef0d2a391cde3be3d4c859654f7892476c3eb5370814e5c946d4c3e0809f0fbb
VirtualSize 0x170b8
VirtualAddress 0xe000
SizeOfRawData 0x17200
PointerToRawData 0x5a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.70301

Imports

advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
user32.dll GetKeyboardType
DestroyWindow
MessageBoxA
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetTickCount
QueryPerformanceCounter
GetCurrentThreadId
VirtualQuery
GetStartupInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetTickCount
QueryPerformanceCounter
GetCurrentThreadId
VirtualQuery
GetStartupInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
user32.dll (#2) GetKeyboardType
DestroyWindow
MessageBoxA
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetTickCount
QueryPerformanceCounter
GetCurrentThreadId
VirtualQuery
GetStartupInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.89548
MD5 48c458f8a72c7d3b70ccdf429c1bf12e
SHA1 8f9fa7783b8a262d7f609e306544221128b6d8a7
SHA256 b9743ddc1d6d186713cc340c84a23df87a5280eee71183ac1781a88b830354d9
SHA3 6d11f0eb6579ef3542c7c399e03dc452aebd79c60ca1ef46e1e34644780e4a98

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.22331
MD5 8c8d20d9ef181c6c4af03b65c74d441e
SHA1 69e4434625b26fe20866885463d99e613751b05f
SHA256 f73a5475b715bcfa22ff6e4359cca580177ba1fe542c6f9cf469b15d61f6b047
SHA3 24c1904a68d4fe0a3255e35b5729a16fc978a36c9d289f94a87d7ad4b22321ac

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.63245
MD5 8193924d4b06f27453cb8d23f3f38d89
SHA1 b778d9b26566a42979efa14ea7797b507570d0d8
SHA256 46bff73a542ca7863158a2d197572a21e860aa1c9f62909b7316ec9aba3fca53
SHA3 6be4fda6511f4102f4a737fd121fbabd39030847ca3998a054d31a983a438f1b

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33412
MD5 cf03c301525aef3275fb73cbd8793c58
SHA1 8812e13854a55bd0d194621940203f4a676cabc5
SHA256 4203037c7f38ba475b751616366fe27adb512a0b37a281b5c262a7fede74fd1e
SHA3 2c2bd20e7ad581b8c9bf07c6b9bfed31414aeaea1f2bf559f0dda29a46a9a38b

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.93355
MD5 d46617641e3fb30f54341ed7fe22da50
SHA1 2423fdcba4e0018f31560ed1d73fa9fd04687b9f
SHA256 afdf167fce0d5140b9819ee3c3fd7680aaaeef06421f4674f38b4f77b944ec28
SHA3 979c34389c0397d7c544e128d67c64c16bbaa714393b6887853fe3ea5825327f

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.97688
MD5 24038eae52ad8a25fc9722f0049fb03e
SHA1 0afc31b280394c8b2c077c30cda2843020e60506
SHA256 7dec330baff3d0d6935282b47996775050a18ebe8c97b4346992d130b3a6cf5f
SHA3 cc53df16dfb3f89d6f1acd0d0e962d3912441f8091df7fd08bbc3e06b8672419

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.02283
MD5 cc85868d882a212daf0de1108d2c5d55
SHA1 528ae9a87990107e2aa0ecb00d2949db06c5c520
SHA256 5b67de9730c3c3e13377c6c501f6408e1fd3db1584f9f155e0bd36b10e385f8c
SHA3 468272c9ac071fa5e3a66562099b260b12a426751c6abe13c15e865cf0d45e5d

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.31546
MD5 d7536fcb5f3323e1d4f7291c37216c27
SHA1 f89058d352918092723eea994da7c2727e1c1889
SHA256 6da9934eeb46a3690fe89207fbba1da3a4bef55eda11006d9aec552f5cb71fb1
SHA3 a5be57f1ff4b30a501fce4c237fc63dcd443bcefae3ba6b76de8be5942ec5bc9

SCRIPT

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x7e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.69065
MD5 072dfd3282a87f889375a823d6af6ef8
SHA1 2e440b1a90bc6a26f082cba9079777892983d33d
SHA256 aeaea00a88b187b0eef7c35bb9c6727a7fe91ac251baebca99dfd098e72aa5d4
SHA3 48000a9924b44eace33aaa43322dec8025f390690cd1061477411bdaaccafce4

SETT

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45996
MD5 836c2e375866aea6836b920ee1a90b46
SHA1 096a204799d474b52fa4e7911620ccc7487cf853
SHA256 bc0cf8dcadbc5be2256d936f3da56c05ed2935a17e631a72b2671489ce894904
SHA3 daa0f3c7eb5fef0bb9d8c1a6231a3876147b863dd5dbc940998a27fe7be5a916

MAINICON

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82677
Detected Filetype Icon file
MD5 d433d98e2de9040241b1fffac5927461
SHA1 aa0f4e60550d74264f4ee2f31e6be128f27ecffc
SHA256 ded270f81e6c2bcf7df1649911ee05fc16526177970a94b9dcce07195f6a0ffa
SHA3 c3ff97525b44d56534b610a2a968d5e7ca38953696d5feeb01547e957b535215

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x2cc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23592
MD5 73ff40807748b2d401f326cc51319f62
SHA1 a6acee7335fae7fa9a58dd6c670fd4f30a6061c5
SHA256 6bd90aa7ab8faecc93e7e1efe741b11571dde52c310bd198f4341767c87accd1
SHA3 d597df6e4bdbd945cd42245b462a8daa54e9da772b5200de30b26b38613d41b5

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x207
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.09391
MD5 a368c49d1140f6964a25db0d94976db0
SHA1 b9a420567e23a8aec933ab5313055f7d07837910
SHA256 e50a58e314eb50a33317e3126f0060c5256d16dca9d86942caec239b682bb326
SHA3 91f68b383a8ba1f16d6ee0fec06050842ec69d3bd090bdf869ff401812cb7f71

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.2.0.0
ProductVersion 1.2.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
CompanyName IT Relation A/S
FileDescription
FileVersion (#2) 1. 2. 0. 0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName ITR Default Printer Fix
ProductVersion (#2) 1. 2. 0. 0
Comments
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x40b000
EndAddressOfRawData 0x40b008
AddressOfIndex 0x406778
AddressOfCallbacks 0x40c010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.