40c6f5e59ed8b3cec0b9dfdc22dd013d

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-25 22:04:50
Detected languages English - United States
Turkish - Turkey
Comments FC Portables
CompanyName fcportables.com
FileDescription Total Commander
FileVersion 0.0.0.0
InternalName Total Commander
LegalCopyright fcportables.com
LegalTrademarks FC Portables
OriginalFilename Total Commander.exe
ProductName Total Commander
ProductVersion 0.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • fcportables.com
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegEnumKeyW
  • RegQueryValueExW
  • RegSetValueExW
  • RegCloseKey
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 107917 bytes of data starting at offset 0xc400.
The overlay data has an entropy of 7.37163 and is possibly compressed or encrypted.
Malicious VirusTotal score: 3/72 (Scanned on 2025-01-16 02:12:30) Bkav: W32.AIDetectMalware
Cylance: Unsafe
Trapmine: suspicious.low.ml.score

Hashes

MD5 40c6f5e59ed8b3cec0b9dfdc22dd013d
SHA1 b5a9567619afb421013553883fe0116cb2ab2527
SHA256 f3402c93e32a91e1e058f9667896d5e2bd956ab5cc00f4934c0e8a2d705bfdb8
SHA3 e0dd8c3ddbcc67d96f83912d7ced2ffccd764c9cd64c3ee328c249dce72f139d
SSDeep 3072:DThRuiU7PEEuN2JNow4lfvzugJLCb+jItrCxiBTraQ+gY5vAh0wJxRD:DT5Uz/PodZvzugJOb+jIV9aQ+bExRD
Imports Hash 61259b55b8912888e90f516ca08dc514

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Sep-25 22:04:50
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6800
SizeOfInitializedData 0x68a00
SizeOfUninitializedData 0x4000
AddressOfEntryPoint 0x00003640 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x1b5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d01cd60c08ad4410541807ebc6d4a26f
SHA1 cca8db9f16fffff600a7360732050417b896642a
SHA256 e6a285ae8205f4d415744af7308e97f5c5aecc86a296b426f8822a3879a5e4a3
SHA3 def8900c99f3464a38ca46898bdff84d3770a0d4310d7deb0c412c2250792713
VirtualSize 0x6676
VirtualAddress 0x1000
SizeOfRawData 0x6800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41581

.rdata

MD5 8c5edfd8ff9cc0135e197611be38ca18
SHA1 dc4f14d019cad6646b38852dfb7370532acafebc
SHA256 95df72950424a97746c83c619f9aa736879b408a87751927b5d41994e8183a9c
SHA3 b74f8f6ea5fb7e429da44419f9d163743fd38ce97f3b9819fb2397744d42dad2
VirtualSize 0x139a
VirtualAddress 0x8000
SizeOfRawData 0x1400
PointerToRawData 0x6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14107

.data

MD5 c7e50177934aec2fcddfd0aceaf14b43
SHA1 5917c20d90f495fa85b3e706d39ce99f49a5786e
SHA256 12f60dacbf494944e7afc646d7dd92335464b2063e2892bd730fed6b1b3caba4
SHA3 b810d0a178bc4e13e1b39b2e7c763d77dc2e4064c22d260b393224d6078218db
VirtualSize 0x66378
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.10645

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x140000
VirtualAddress 0x71000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 c17300ab09083b5c6137a55213df8c0e
SHA1 8acd21b4adc6e5007097efbae3a34c84d1fd79db
SHA256 d15d1a5b133649f42f0a46053bdb6603171090d9eaea012866accdbd77c5520e
SHA3 fb3a2e325b230af253422218eac93aa9b911dd933791dd835e3c0c8e4bdcdd8d
VirtualSize 0x3c98
VirtualAddress 0x1b1000
SizeOfRawData 0x3e00
PointerToRawData 0x8600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.56727

Imports

ADVAPI32.dll RegCreateKeyExW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegOpenKeyExW
RegEnumValueW
SHELL32.dll SHGetSpecialFolderLocation
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
IIDFromString
CoTaskMemFree
COMCTL32.dll #17
ImageList_Create
ImageList_Destroy
ImageList_AddMasked
USER32.dll GetClientRect
EndPaint
DrawTextW
IsWindowEnabled
DispatchMessageW
wsprintfA
CharNextA
CharPrevW
MessageBoxIndirectW
GetDlgItemTextW
SetDlgItemTextW
GetSystemMetrics
FillRect
AppendMenuW
TrackPopupMenu
OpenClipboard
SetClipboardData
CloseClipboard
IsWindowVisible
CallWindowProcW
GetMessagePos
CheckDlgButton
LoadCursorW
SetCursor
GetSysColor
SetWindowPos
GetWindowLongW
PeekMessageW
SetClassLongW
GetSystemMenu
EnableMenuItem
GetWindowRect
ScreenToClient
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
FindWindowExW
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
EmptyClipboard
CreatePopupMenu
GDI32.dll SetBkMode
SetBkColor
GetDeviceCaps
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
SetTextColor
SelectObject
KERNEL32.dll GetExitCodeProcess
WaitForSingleObject
GetModuleHandleA
GetProcAddress
GetSystemDirectoryW
lstrcatW
Sleep
lstrcpyA
WriteFile
GetTempFileNameW
lstrcmpiA
RemoveDirectoryW
CreateProcessW
CreateDirectoryW
GetLastError
CreateThread
GlobalLock
GlobalUnlock
GetDiskFreeSpaceW
WideCharToMultiByte
lstrcpynW
lstrlenW
SetErrorMode
GetVersionExW
GetCommandLineW
GetTempPathW
GetWindowsDirectoryW
SetEnvironmentVariableW
CopyFileW
ExitProcess
GetCurrentProcess
GetModuleFileNameW
GetFileSize
CreateFileW
GetTickCount
MulDiv
SetFileAttributesW
GetFileAttributesW
SetCurrentDirectoryW
MoveFileW
GetFullPathNameW
GetShortPathNameW
SearchPathW
CompareFileTime
SetFileTime
CloseHandle
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalFree
GlobalAlloc
GetModuleHandleW
LoadLibraryExW
MoveFileExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
lstrlenA
MultiByteToWideChar
ReadFile
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.22979
MD5 4abf461f82e48a1d062a245b7165af2e
SHA1 a92f18e0f19580d35c9ed0454c1a51d8e7b7807c
SHA256 641b4c03aef49d728ddf18bec3c5438850db6c24314b5ce8f10000b257a77b00
SHA3 6a6df405925ef52b113166ef8de2608f9fc8e205bb1a3938eda4838315884f2d

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66174
MD5 3409f314895161597f3c395cc5f65525
SHA1 1a99d016d65e567f24449d9362afb6ac44006d0b
SHA256 fecdb955f8d7f1c219ff8167f90b64f3cb52e53337494577ff73c0ac1dafcd96
SHA3 b3b19241cc6454389e45833e50b742ae1927a5f161017350a99f2cbc66914f26

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87228
MD5 342ad3fc8890c3e322fa5c9cea16b6fc
SHA1 b9f3b3e8f818601b3887ce5d611d511f4663613a
SHA256 a8d9dbff8670eb6b79b028eb3242433e9e9da289d816f86e7d2d5b661e74cc5e
SHA3 c783f4139d925ff3c102b8a8292dcd6af12cc809d76b1d7f3f1e354c39901220

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48825
MD5 6be4e1387d369cf86e68eacbdd0e81dd
SHA1 351970fe2681b9b35b5d59ad052011ed96a96e17
SHA256 85025c8556952f6a651c2468c8a0d58853b0ba482be9ad5cd3060f216540dfc0
SHA3 45e552e173141e06d113209b6cc915042ad0b4d5531464b8dbe5637029f489cb

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87985
MD5 8121841afe19a32ba08aa6ee8ae633f1
SHA1 f50d72b3863f3d65849bc7b8a85c1038dfcce859
SHA256 089e6abe6b7e194f43f8d36a068b4ba5e3112217043088592b371c5d89708d6c
SHA3 69fa08c1c1cad64652364536fdbc64dd87bfc44dee8d14df3e39dcf32162bdac

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12941
MD5 c16b08dfa3a7525464d2e2952bd37806
SHA1 4734dce252cba65b8f56fa1e8d3a5203ed81a79e
SHA256 499e4b981149851d28dd2dd0c9f5106deb13939568caeae625558721a61c1642
SHA3 e7d3991084295de0615cf1a31b4cfbbc63d87966cdd5038a668e01133bf19a13

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64136
MD5 86969b39fd9c7b78bccf1518d791a0df
SHA1 f54f0afdbf4d29666da3fb80b2e2d2ccdbbb82f5
SHA256 5c61adc8f8344dbaa38031f74c99816c9c833b7d4d036d00aa3ac17d1f46eccf
SHA3 1708eb8a8bdddefe0080b6541df4c2391550177ef97ad5fee5f567a5da5d53c6

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73942
MD5 abae527be44293e0a188879151cc5a20
SHA1 3b770af49624138072781fc9c0303c166d04eae9
SHA256 499bf86593c386a11511de4d919f58a343ea26d4897fc31fe3efe7e19ead81ae
SHA3 b70b8c2ca48176b558cfe97dd802817e925bddc1f956b35c07f450b8e0537820

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01048
MD5 e27ebf6762e99552aea6f1a7877cc738
SHA1 0b550db1e9416e8440ca080fe950f7421196e77c
SHA256 7ab3236260ca1c38a3d94a4dc6b90db51690c8c72baa908d5a7ddd834d435db3
SHA3 b8ddfe3fdb6dd592229a0c725c25d5e41ae53496f8068c8d68697191f246f7b7

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x58
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76109
MD5 076eaa29cb0fd488dbf28132ba9053ce
SHA1 4ed7d9235080ca286344b50642c16cfe8bf1adda
SHA256 fb1541fab691418f4ba1d7881ee001103522cc5bc7e351b993c04cf0b4bc1385
SHA3 bfb755e23413508cb86824e402871098d7f3f998e137ff56be87aa36e045a57c

405

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.55952
MD5 42ffea438086bc96d67864e42e213d98
SHA1 5e388ef762ebb9fa076c6f46d718966eb6670f99
SHA256 dc6a29809f8a42a0c1dcb4fd797e8a467c980de166cc66a83a32192b2f53a1da
SHA3 a244963fa8137eb43b42900bd1d9a79a717373ad6adb98790040a9682ed77460

406

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82795
MD5 916138140d4f7a4c7eb9154fd19cf69b
SHA1 a1438202241ca82b79cf26a3290f0504e4776487
SHA256 957bfd5d7e56d54206473412dec1388fcc63d069b5bf1591329c5b7a14c37c1a
SHA3 143554d0fab54938c7d840ea33a1c782434b18fcba1a057cc67358e5ce787120

411

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.36476
MD5 a6e82d7b05a5b3f5961b64f1642a06ee
SHA1 12b290ffc5492d4ee7fcb2398411f5cd8e2f63fd
SHA256 e9c101b10de7cb49faad8c6cbc66a8c98b63d107c92fbd6160bf711149450786
SHA3 aa6c8ba15c0f1fd950ab322991aff62e650279e97a3f3c6b885148ed427c7059

505

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65896
MD5 98d883153a1e14132992b81a092bf62b
SHA1 376d6a0a41e9be87867c385cd863356e67d971de
SHA256 e3aa57e918a071442241e7c37c02556d35d02656b68150f906dcc836bd324217
SHA3 b810f2d3359a586b971fb26bb4f74d455495d4afc86d31563f34848030cd8d65

506

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92746
MD5 c59875269fdeef231fa68e660d25cd24
SHA1 284f7b3262e1e5d020261903d3e726ba4f8f62e8
SHA256 5ef03c55601452fd55173e5c809fc3b59181da0433e414a3cba02191f03d7d4c
SHA3 6417beeef3db1414f3022eed328210bda7c0d47de77240acedc317f561a2a816

511

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x50
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63292
MD5 9fd86d0859f2cb45a303f2eccbb728ef
SHA1 e5ee9f452cb943e5c3b21783da7abf4a748d9ca2
SHA256 66c5a54fc613b3a72b0ce1651649944bfbef2d0c2068f2ecba821ed82188496c
SHA3 7fe952e87ecbbdf41b8934c0cd40f81161a5b312c4640e037bd47dca5b16717d

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Icon file
MD5 f70771cfd93218e0da5b0b45af15d4cd
SHA1 778a9a90cc44e3833f9b5b45929465567e44cb69
SHA256 8ba3a2e4e72ee5f60718eb9ad3f29fa859b38e7b5e52a9b03ebd6547d54019d3
SHA3 44c4488b210d6bed764e8f94561afa6bc2cfaee0ca7fc61079b4b217eaabbd02

1 (#2)

Type RT_VERSION
Language Turkish - Turkey
Codepage UNKNOWN
Size 0x354
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22917
MD5 e8cf4c6eac1ddbb6b472dcea3f79aa92
SHA1 32bc417fbffc852a057dc539d95dc21a169fa92c
SHA256 25c25504bf07ec5ea36a87876415c325262719444d60483e2bfc674cb37e45e0
SHA3 ec18ea8ea72619b7bf23fefdee7d27c0feb4a3f89334fa9d19f7077170a7883f

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x423
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29652
MD5 b8a892a48614f0785e13d89f73286598
SHA1 652b3ceae6ee7b9bd71ab809e86d9123253bb7a1
SHA256 ad54570966156168778cfe52795fc43998a47766ee7079ac1a1e5c39e4cb8a22
SHA3 a26365869c4765315b04c3884d1005612305c774e32aa65318d42b82cbd4decf

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Turkish - Turkey
Comments FC Portables
CompanyName fcportables.com
FileDescription Total Commander
FileVersion (#2) 0.0.0.0
InternalName Total Commander
LegalCopyright fcportables.com
LegalTrademarks FC Portables
OriginalFilename Total Commander.exe
ProductName Total Commander
ProductVersion (#2) 0.0.0.0
Resource LangID Turkish - Turkey

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
<-- -->