Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-May-14 11:05:36 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | PEiD Signature: | HQR data file |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Unusual section name found: .qtmetad |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: The Qt Company Oy
Issuer: thawte SHA256 Code Signing CA |
Safe | VirusTotal score: 0/71 (Scanned on 2020-01-04 22:14:16) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2019-May-14 11:05:36 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0xd68c00 |
SizeOfInitializedData | 0x5fba00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00CC9C50 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xd6a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1392000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1378845 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
IMM32.dll |
ImmAssociateContext
ImmGetCompositionStringW ImmNotifyIME ImmSetCompositionWindow ImmSetCandidateWindow ImmGetVirtualKey ImmReleaseContext ImmGetContext ImmGetDefaultIMEWnd |
---|---|
OLEAUT32.dll |
#184
#12 #8 #7 #6 #10 #9 #4 #2 |
UxTheme.dll |
OpenThemeData
DrawThemeBackground GetThemeColor GetThemeSysFont IsThemeActive GetThemeTransitionDuration GetCurrentThemeName IsAppThemed SetWindowTheme GetThemePropertyOrigin GetThemeMargins GetThemeEnumValue GetThemeInt GetThemeBool IsThemeBackgroundPartiallyTransparent GetThemePartSize GetThemeBackgroundRegion #47 CloseThemeData DrawThemeTextEx SetWindowThemeAttribute |
dwmapi.dll |
DwmEnableBlurBehindWindow
DwmIsCompositionEnabled DwmExtendFrameIntoClientArea DwmDefWindowProc |
IPHLPAPI.DLL |
GetAdaptersAddresses
GetAdaptersInfo |
CRYPT32.dll |
CertGetCertificateChain
CertGetCertificateContextProperty CertDuplicateCertificateContext CertFindCertificateInStore CertEnumCertificatesInStore CertCloseStore CertOpenStore CertCreateCertificateContext CertFreeCertificateContext CertFreeCertificateChain |
GDI32.dll |
GetRegionData
CreateBitmap GetDIBits SetWorldTransform ExtTextOutW BitBlt CombineRgn CreateRectRgn DeleteObject OffsetRgn SelectClipRgn GetDeviceCaps CreateCompatibleBitmap CreateCompatibleDC CreateDCW DeleteDC SelectObject ChoosePixelFormat SetPixelFormat GetBitmapBits GetObjectW CreateFontIndirectW EnumFontFamiliesExW GetFontData GetStockObject AddFontResourceExW RemoveFontResourceExW AddFontMemResourceEx RemoveFontMemResourceEx GetTextMetricsW GetTextFaceW CreateDIBSection GdiFlush GetCharABCWidthsW GetCharABCWidthsFloatW GetGlyphOutlineW GetOutlineTextMetricsW GetTextExtentPoint32W GetCharABCWidthsI SetBkMode SetGraphicsMode SetTextColor SetTextAlign |
MPR.dll |
WNetGetUniversalNameA
|
VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
WS2_32.dll |
WSARecvFrom
WSASend WSASendTo WSASocketW #16 #19 WSAConnect WSAAccept #21 WSARecv #13 WSANtohs #6 #5 #3 #2 #151 #7 #111 #52 #51 #22 #11 #8 WSANtohl #9 WSAHtonl #18 #112 #57 #115 #116 #101 WSAIoctl #14 |
KERNEL32.dll |
AreFileApisANSI
HeapReAlloc IsProcessorFeaturePresent IsDebuggerPresent ExitThread HeapAlloc GetCPInfo GetCommandLineA RtlUnwind SetConsoleCtrlHandler HeapFree GetStringTypeW DecodePointer EncodePointer CreateMutexW ReleaseMutex ReadConsoleInputA ReadConsoleW GetConsoleCP GetConsoleMode RaiseException SetStdHandle UnhandledExceptionFilter SetUnhandledExceptionFilter InitializeCriticalSectionAndSpinCount CreateTimerQueue SignalObjectAndWait GetLogicalProcessorInformation CreateTimerQueueTimer GetStdHandle GetFileType GetLargestConsoleWindowSize SetConsoleScreenBufferSize FreeConsole AttachConsole AllocConsole SetConsoleMode GetConsoleWindow GetCommandLineW CloseHandle CreateProcessW LocalFree FormatMessageW GetFileAttributesExW GetLongPathNameW GetShortPathNameW GetEnvironmentVariableW GetCurrentProcess IsWow64Process OpenProcess GetLogicalDriveStringsA CreateToolhelp32Snapshot Process32FirstW Process32NextW FindFirstVolumeW FindNextVolumeW FindVolumeClose GetDiskFreeSpaceExA ChangeTimerQueueTimer GetDriveTypeW GetVolumePathNamesForVolumeNameW SetErrorMode WaitForSingleObject TerminateProcess GetLastError FileTimeToSystemTime CreateFileW DeviceIoControl FlushFileBuffers LockFile UnlockFile WriteFile CompareFileTime GetProcAddress GetFileSize ReadFile SetEndOfFile SetFilePointer SetFileTime OpenEventW OpenFileMappingW MapViewOfFile UnmapViewOfFile SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW DeleteFileW RemoveDirectoryW SetFileAttributesW GetTempPathW SetLastError GetCurrentProcessId GetCurrentThreadId GetTickCount GetSystemDirectoryW GetModuleHandleW MoveFileW GetFileInformationByHandle FindClose FindCloseChangeNotification FindFirstChangeNotificationW FindFirstFileW FindNextFileW GetLogicalDriveStringsW GetModuleHandleA EnterCriticalSection LeaveCriticalSection DeleteCriticalSection MultiByteToWideChar WideCharToMultiByte FreeLibrary GetModuleFileNameW LoadLibraryExW LoadLibraryW GetSystemTimeAsFileTime FileTimeToDosDateTime GetVersionExW InitializeCriticalSection SetEvent ResetEvent ReleaseSemaphore CreateEventW CreateSemaphoreW VirtualAlloc VirtualFree GetSystemInfo GlobalMemoryStatus FileTimeToLocalFileTime WaitForMultipleObjects ExpandEnvironmentStringsW CheckRemoteDebuggerPresent GlobalAlloc GlobalLock GlobalUnlock GetLocaleInfoW LoadLibraryA GlobalSize GetUserDefaultLangID LocalAlloc lstrlenW GetVolumeInformationW lstrcmpW Sleep GetTempPathA GetTempFileNameA VerSetConditionMask VerifyVersionInfoW QueryPerformanceCounter QueryPerformanceFrequency ExitProcess GetSystemTime SystemTimeToFileTime GetTimeZoneInformation VirtualProtect CreateFileMappingW DisconnectNamedPipe WaitNamedPipeW GlobalFree ConnectNamedPipe CreateNamedPipeW GetOverlappedResult SetHandleInformation FlushConsoleInputBuffer GetNativeSystemInfo OutputDebugStringW CompareStringW GetUserDefaultLCID GetStartupInfoW GetLocalTime DuplicateHandle SwitchToThread CreateThread GetCurrentThread SetThreadPriority GetThreadPriority TerminateThread ResumeThread TlsAlloc TlsGetValue TlsSetValue TlsFree WaitForSingleObjectEx GetEnvironmentStringsW FreeEnvironmentStringsW GetExitCodeProcess GetProcessId GetTickCount64 GetDateFormatW GetTimeFormatW GetCurrencyFormatW GetUserPreferredUILanguages LCMapStringW ReadFileEx PeekNamedPipe CancelIoEx SleepEx WriteFileEx GetFileAttributesW GetFullPathNameW GetLogicalDrives CopyFileW GetFileInformationByHandleEx SetFilePointerEx MoveFileExW FindFirstFileExW GetModuleHandleExW FindNextChangeNotification GetGeoInfoW GetUserGeoID DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait IsValidLocale EnumSystemLocalesW HeapSize GetProcessHeap GetModuleFileNameA IsValidCodePage GetACP GetOEMCP SystemTimeToTzSpecificLocalTime SetEnvironmentVariableA SetEnvironmentVariableW WriteConsoleW GetThreadTimes FreeLibraryAndExitThread InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList UnregisterWaitEx CreateProcessA GetDriveTypeA |
USER32.dll |
GetClientRect
GetCursorPos ChildWindowFromPointEx GetSysColorBrush LoadImageW MonitorFromWindow GetMonitorInfoW EnumDisplayMonitors GetSysColor LoadIconW IsHungAppWindow SetClipboardViewer ChangeClipboardChain RegisterClipboardFormatW GetKeyboardLayout RegisterWindowMessageW CreateCaret DestroyCaret HideCaret SetCaretPos PeekMessageW IsZoomed GetKeyState GetKeyboardState ToAscii ToUnicode MapVirtualKeyW GetMenu TrackPopupMenuEx SetMenuItemInfoW NotifyWinEvent RegisterClassW SetCursorPos GetCursor GetFocus CreateCursor CreateIconIndirect GetIconInfo GetCursorInfo GetClipboardFormatNameW TrackMouseEvent GetMessageExtraInfo GetAsyncKeyState GetWindowTextW RealGetWindowClassW DrawIconEx MessageBoxW WindowFromDC CallWindowProcW SetPropW GetPropW RemovePropW GetProcessWindowStation GetUserObjectInformationW MessageBoxA PostThreadMessageW TranslateMessage DispatchMessageW GetQueueStatus MsgWaitForMultipleObjectsEx SetTimer KillTimer SetWindowsHookExW UnhookWindowsHookEx CallNextHookEx CharNextExA RegisterDeviceNotificationW UnregisterDeviceNotification RegisterClassExW GetClassInfoW UnregisterClassW GetKeyboardLayoutList GetAncestor DestroyIcon DestroyCursor SetParent GetParent SetWindowLongW GetWindowLongW ScreenToClient ClientToScreen SetCursor AdjustWindowRectEx GetWindowRect SetWindowTextW InvalidateRect GetUpdateRect SetWindowRgn EndPaint BeginPaint ReleaseDC GetDC SetForegroundWindow GetForegroundWindow EnableMenuItem GetSystemMetrics ReleaseCapture SetCapture GetCapture SetWindowPlacement SetFocus IsIconic IsWindowVisible LoadCursorW PostMessageW DrawMenuBar GetSystemMenu RemoveMenu EnumWindows GetWindowPlacement SetWindowPos MoveWindow FlashWindowEx SetLayeredWindowAttributes UpdateLayeredWindow ShowWindow DestroyWindow IsChild CreateWindowExW DefWindowProcW AttachThreadInput SendMessageW UpdateLayeredWindowIndirect SystemParametersInfoW GetDesktopWindow GetCaretBlinkTime MessageBeep IsWindow GetDoubleClickTime CharUpperW SendMessageTimeoutW GetWindowThreadProcessId |
SHELL32.dll |
CommandLineToArgvW
SHParseDisplayName #155 SHBrowseForFolderW SHGetKnownFolderIDList SHGetPathFromIDListW SHGetMalloc SHCreateItemFromParsingName SHCreateItemFromIDList ShellExecuteW #727 SHGetStockIconInfo SHGetFileInfoW SHGetSpecialFolderPathW SHChangeNotify SHGetFolderLocation ShellExecuteExW SHGetFolderPathW SHGetKnownFolderPath |
ole32.dll |
ReleaseStgMedium
OleIsCurrentClipboard OleFlushClipboard OleSetClipboard CoGetMalloc CoTaskMemAlloc CoCreateGuid StringFromGUID2 DoDragDrop CoInitializeEx OleUninitialize OleInitialize RevokeDragDrop RegisterDragDrop CoLockObjectExternal CoTaskMemFree CoCreateInstance CoInitialize CoUninitialize OleGetClipboard |
ADVAPI32.dll |
AllocateAndInitializeSid
RegQueryInfoKeyW RegFlushKey RegEnumValueW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW MapGenericMask CheckTokenMembership FreeSid RegCloseKey RegOpenKeyExW RegQueryValueExW RegSetValueExW GetFileSecurityW OpenProcessToken AdjustTokenPrivileges LookupPrivilegeValueW RegNotifyChangeKeyValue AddAccessAllowedAce GetLengthSid GetTokenInformation InitializeAcl InitializeSecurityDescriptor SetSecurityDescriptorDacl SetSecurityDescriptorGroup SetSecurityDescriptorOwner DeregisterEventSource RegisterEventSourceA ReportEventA CryptAcquireContextA CryptReleaseContext CryptDestroyKey CryptSetHashParam CryptGetProvParam CryptGetUserKey DuplicateToken CryptExportKey CryptDecrypt CryptCreateHash CryptDestroyHash CryptSignHashA CryptEnumProvidersA AccessCheck CopySid |
WINMM.dll |
timeSetEvent
PlaySoundW timeKillEvent |
d3d9.dll |
D3DPERF_GetStatus
D3DPERF_SetMarker D3DPERF_EndEvent D3DPERF_BeginEvent Direct3DCreate9 |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x16aae60 |
SEHandlerTable | 0x1638f50 |
SEHandlerCount | 4005 |
XOR Key | 0xd8c63f32 |
---|---|
Unmarked objects | 0 |
C++ objects (20806) | 4 |
199 (41118) | 3 |
ASM objects (VS2013 build 21005) | 83 |
C++ objects (VS2013 build 21005) | 141 |
C objects (VS2013 build 21005) | 301 |
C++ objects (65501) | 1 |
C objects (65501) | 7 |
208 (65501) | 1 |
Unmarked objects (#2) | 20 |
Imports (65501) | 35 |
Total imports | 628 |
C objects (VS2013 UPD5 build 40629) | 608 |
C++ objects (VS2013 UPD5 build 40629) | 1441 |
Resource objects (VS2013 build 21005) | 1 |
Linker (VS2013 UPD5 build 40629) | 1 |