Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
English - United Kingdom
German - Germany |
CompanyName | Razor 1911 |
FileDescription | Razor 1911 Installer 2024 |
FileVersion | 1.0.0.0 |
InternalName | Razor 1911 Installer |
LegalCopyright | bp^Razor 1911 |
LegalTrademarks | Razor 1911 |
OriginalFilename | Setup.exe |
ProductName | |
ProductVersion | 1.0.0.0 |
Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h) UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 |
Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource 8 is possibly compressed or encrypted. Resource 9 is possibly compressed or encrypted. Resource 10 is possibly compressed or encrypted. Resource 11 is possibly compressed or encrypted. Resource 12 is possibly compressed or encrypted. Resource 15 is possibly compressed or encrypted. Resource 16 is possibly compressed or encrypted. Resource 17 is possibly compressed or encrypted. Resource 18 is possibly compressed or encrypted. Resource 19 is possibly compressed or encrypted. Resource 20 is possibly compressed or encrypted. Resource BBABORT is possibly compressed or encrypted. Resource BBALL is possibly compressed or encrypted. Resource BBCANCEL is possibly compressed or encrypted. Resource BBCLOSE is possibly compressed or encrypted. Resource BBHELP is possibly compressed or encrypted. Resource BBIGNORE is possibly compressed or encrypted. Resource BBNO is possibly compressed or encrypted. Resource BBOK is possibly compressed or encrypted. Resource BBRETRY is possibly compressed or encrypted. Resource BBYES is possibly compressed or encrypted. Resource PREVIEWGLYPH is possibly compressed or encrypted. Resource VT_CHECK_DARK is possibly compressed or encrypted. Resource VT_CHECK_LIGHT is possibly compressed or encrypted. Resource VT_FLAT is possibly compressed or encrypted. Resource VT_MOVEALL is possibly compressed or encrypted. Resource VT_MOVEEW is possibly compressed or encrypted. Resource VT_MOVENS is possibly compressed or encrypted. Resource VT_TICK_DARK is possibly compressed or encrypted. Resource VT_TICK_LIGHT is possibly compressed or encrypted. Resource VT_UTILITIES is possibly compressed or encrypted. Resource VT_XP is possibly compressed or encrypted. Resource VT_XPBUTTONMINUS is possibly compressed or encrypted. Resource VT_XPBUTTONPLUS is possibly compressed or encrypted. Resource 4078 is possibly compressed or encrypted. Resource 4079 is possibly compressed or encrypted. Resource 4080 is possibly compressed or encrypted. Resource 4081 is possibly compressed or encrypted. Resource 4082 is possibly compressed or encrypted. Resource 4083 is possibly compressed or encrypted. Resource 4086 is possibly compressed or encrypted. Resource 4087 is possibly compressed or encrypted. Resource 4088 is possibly compressed or encrypted. Resource 4089 is possibly compressed or encrypted. Resource 4090 is possibly compressed or encrypted. Resource 4091 is possibly compressed or encrypted. Resource 4093 is possibly compressed or encrypted. Resource 4094 is possibly compressed or encrypted. Resource 4095 is possibly compressed or encrypted. Resource 4096 is possibly compressed or encrypted. Resource BASS is possibly compressed or encrypted. Resource EXT is possibly compressed or encrypted. Resource PACKAGEINFO is possibly compressed or encrypted. Resource TFORM1 is possibly compressed or encrypted. Resource TFORM2 is possibly compressed or encrypted. Resource TQUERYFORM is possibly compressed or encrypted. Resource UNIN is possibly compressed or encrypted. The resource timestamps differ from the PE header:
|
Suspicious | The file contains overlay data. |
64324 bytes of data starting at offset 0xe4000.
The overlay data has an entropy of 7.90938 and is possibly compressed or encrypted. |
Malicious | VirusTotal score: 6/71 (Scanned on 2024-10-30 19:56:39) |
Antiy-AVL:
Trojan/Win32.Agent
Bkav: W32.AIDetectMalware Cylance: Unsafe Ikarus: Virus.Win32.Hupigon.AMD McAfeeD: ti!4470EE3EB5FC VBA32: BScope.Adware.Presenoker |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0xe2000 |
SizeOfInitializedData | 0x3000 |
SizeOfUninitializedData | 0xf0000 |
AddressOfEntryPoint | 0x001D2180 (Section: UPX1) |
BaseOfCode | 0xf1000 |
BaseOfData | 0x1d3000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1d6000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
advapi32.dll |
RegCloseKey
|
---|---|
comctl32.dll |
ImageList_Add
|
gdi32.dll |
Pie
|
KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
ole32.dll |
CoInitialize
|
oleaut32.dll |
VariantCopy
|
shell32.dll |
SHGetMalloc
|
user32.dll |
GetDC
|
version.dll |
VerQueryValueA
|
winmm.dll |
timeGetTime
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United Kingdom |
CompanyName | Razor 1911 |
FileDescription | Razor 1911 Installer 2024 |
FileVersion (#2) | 1.0.0.0 |
InternalName | Razor 1911 Installer |
LegalCopyright | bp^Razor 1911 |
LegalTrademarks | Razor 1911 |
OriginalFilename | Setup.exe |
ProductName | |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | German - Germany |
---|