Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Apr-11 23:00:43 |
Detected languages |
Dutch - Belgium
English - United States French - Canada German - Germany Russian - Russia |
Suspicious | PEiD Signature: | PeStubOEP v1.x |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC+2 timezone. |
Info | The PE is digitally signed. |
Signer: Ashampoo GmbH & Co. KG
Issuer: Symantec Class 3 SHA256 Code Signing CA |
Suspicious | VirusTotal score: 1/64 (Scanned on 2022-11-13 01:34:59) | Jiangmin: Packed.Dico.pb |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2022-Apr-11 23:00:43 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x45de00 |
SizeOfInitializedData | 0x1b0e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0045ED7C (Section: .itext) |
BaseOfCode | 0x1000 |
BaseOfData | 0x460000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x63f000 |
SizeOfHeaders | 0x400 |
Checksum | 0x620033 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
winmm.dll |
sndPlaySoundW
timeGetTime |
---|---|
oleacc.dll |
LresultFromObject
|
winspool.drv |
DocumentPropertiesW
ClosePrinter OpenPrinterW GetDefaultPrinterW EnumPrintersW |
comdlg32.dll |
GetOpenFileNameW
|
comctl32.dll |
FlatSB_SetScrollInfo
InitCommonControls ImageList_DragMove ImageList_Destroy _TrackMouseEvent ImageList_DragShowNolock ImageList_Add ImageList_GetDragImage FlatSB_SetScrollProp ImageList_Create ImageList_EndDrag ImageList_DrawEx ImageList_SetImageCount FlatSB_GetScrollPos FlatSB_SetScrollPos InitializeFlatSB ImageList_Copy FlatSB_GetScrollInfo ImageList_Write ImageList_DrawIndirect ImageList_SetBkColor ImageList_GetBkColor ImageList_BeginDrag ImageList_GetIcon ImageList_Replace ImageList_GetImageCount ImageList_DragEnter ImageList_GetIconSize ImageList_SetIconSize ImageList_Read ImageList_DragLeave ImageList_Draw ImageList_Remove ImageList_ReplaceIcon ImageList_SetOverlayImage |
shell32.dll |
SHGetSpecialFolderLocation
Shell_NotifyIconW ShellExecuteExW SHGetPathFromIDListA SHGetPathFromIDListW SHGetFileInfoA SHGetFileInfoW SHGetMalloc SHGetDesktopFolder SHQueryRecycleBinW SHFileOperationA ShellExecuteW ExtractIconExA |
user32.dll |
CopyImage
MoveWindow SetMenuItemInfoW GetMenuItemInfoW DefFrameProcW GetDlgCtrlID RemovePropA FrameRect RegisterWindowMessageW GetMenuStringW FillRect UnregisterClassA SendMessageA IsClipboardFormatAvailable EnumWindows ShowOwnedPopups GetClassInfoExW GetClassInfoW GetScrollRange SetActiveWindow GetActiveWindow DrawEdge GetKeyboardLayoutList LoadBitmapW EnumChildWindows SendMessageTimeoutA GetScrollBarInfo UnhookWindowsHookEx SetCapture GetCapture ChildWindowFromPointEx CreatePopupMenu ShowCaret GetMenuItemID CharLowerBuffW PostMessageW SetWindowLongW IsZoomed SetParent DrawMenuBar GetClientRect IsChild IsIconic CallNextHookEx FindWindowExA ShowWindow SetForegroundWindow GetWindowTextW GetAsyncKeyState PostThreadMessageA DestroyWindow IsDialogMessageW RegisterClassW EndMenu CharNextW GetFocus GetDC SetFocus ReleaseDC CreateWindowExA GetClassLongW SetScrollRange DrawTextW PeekMessageA MessageBeep SetClassLongW LockWindowUpdate RemovePropW AttachThreadInput GetSubMenu DestroyIcon IsWindowVisible DispatchMessageA UnregisterClassW GetTopWindow SendMessageW GetMessageTime NotifyWinEvent SendMessageTimeoutW CreateMenu LoadStringW CharLowerW SetWindowRgn SetWindowPos GetMenuItemCount GetSysColorBrush GetWindowDC DrawTextExW EnumClipboardFormats ScrollDC GetScrollInfo SetWindowTextW GetMessageExtraInfo GetSysColor EnableScrollBar TrackPopupMenu DrawIconEx GetClassNameW GetMessagePos GetIconInfo SetScrollInfo GetKeyNameTextW GetDesktopWindow SetCursorPos GetCursorPos SetMenu GetMenuState GetMenu SetRect GetKeyState ValidateRect IsCharAlphaW GetCursor KillTimer BeginDeferWindowPos WaitMessage RegisterClassA TranslateMDISysAccel GetWindowPlacement GetClipboardFormatNameW CreateIconIndirect CreateWindowExW ChildWindowFromPoint GetMessageW GetDCEx PeekMessageW MonitorFromWindow GetUpdateRect GetPropA SetTimer SetPropA WindowFromPoint BeginPaint DrawStateW RegisterClipboardFormatW MapVirtualKeyW OffsetRect IsWindowUnicode DispatchMessageW TrackPopupMenuEx DefMDIChildProcW WaitForInputIdle GetSystemMenu SetScrollPos GetScrollPos InflateRect DrawFocusRect ReleaseCapture LoadCursorW ScrollWindow GetLastActivePopup GetSystemMetrics CharUpperBuffW GetClassNameA ClientToScreen SetClipboardData GetClipboardData SetWindowPlacement GetMonitorInfoW CheckMenuItem CharUpperW DefWindowProcW GetForegroundWindow ToAscii EnableWindow GetWindowThreadProcessId RedrawWindow SendMessageCallbackA EndPaint MsgWaitForMultipleObjectsEx LoadKeyboardLayoutW GetMenuItemInfoA ActivateKeyboardLayout GetParent MonitorFromRect InsertMenuItemW GetPropW MessageBoxW SetPropW UpdateWindow MsgWaitForMultipleObjects DestroyMenu SetWindowsHookExW EmptyClipboard GetDlgItem AdjustWindowRectEx IsWindow DrawIcon EnumThreadWindows InvalidateRect SetKeyboardState GetKeyboardState ScreenToClient DrawFrameControl IsCharAlphaNumericW SetCursor GetNextDlgTabItem CreateIcon RemoveMenu SubtractRect GetKeyboardLayoutNameW OpenClipboard TranslateMessage MapWindowPoints EnumDisplayMonitors CallWindowProcW CountClipboardFormats CloseClipboard DestroyCursor PostMessageA MessageBoxExW PostQuitMessage ShowScrollBar EnableMenuItem DeferWindowPos HideCaret EndDeferWindowPos FindWindowExW MonitorFromPoint LoadIconW SystemParametersInfoW GetWindow DefWindowProcA GetWindowLongW GetWindowRect InsertMenuW IsWindowEnabled IsDialogMessageA GetMenuDefaultItem FindWindowW DeleteMenu GetKeyboardLayout |
version.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoSizeA VerQueryValueW VerQueryValueA GetFileVersionInfoW GetFileVersionInfoA |
oleaut32.dll |
SafeArrayPutElement
SetErrorInfo GetErrorInfo VariantInit VariantClear SysFreeString SafeArrayAccessData SysReAllocStringLen SafeArrayCreate CreateErrorInfo SafeArrayGetElement GetActiveObject SysAllocStringLen SafeArrayUnaccessData SafeArrayPtrOfIndex VariantCopy SafeArrayGetUBound SafeArrayGetLBound VariantCopyInd VariantChangeType |
advapi32.dll |
CloseServiceHandle
RegSetValueExW LookupAccountNameW GetUserNameW RegQueryInfoKeyW IsValidSid GetSidSubAuthority GetTokenInformation LookupAccountSidA LookupAccountSidW RegCreateKeyExW SetSecurityDescriptorDacl OpenServiceW GetSidSubAuthorityCount RegEnumKeyExW QueryServiceStatus AdjustTokenPrivileges GetSidIdentifierAuthority LookupPrivilegeValueA OpenSCManagerW OpenProcessToken RegOpenKeyExW AllocateAndInitializeSid FreeSid RegDeleteValueW RegNotifyChangeKeyValue RegFlushKey RegEnumValueW RegQueryValueExW GetKernelObjectSecurity RegCloseKey InitializeSecurityDescriptor |
netapi32.dll |
NetWkstaGetInfo
NetApiBufferFree |
msvcrt.dll |
memcpy
memset |
kernel32.dll |
GetFileType
GetACP GetExitCodeProcess LocalFree CloseHandle SizeofResource VirtualProtectEx GetSystemDefaultLangID GetCurrentProcessId TerminateThread IsDebuggerPresent GetFullPathNameW FindNextFileW GlobalSize GetCPInfoExW WriteProcessMemory EnumSystemLocalesW GetTimeZoneInformation FileTimeToLocalFileTime GetVersionExA FreeLibrary HeapDestroy GetUserDefaultLCID FindFirstFileA SetLastError GetModuleFileNameW GetLastError GlobalAlloc GlobalUnlock CompareStringW CreateThread LoadLibraryA CreateMutexW ResetEvent GetVolumeInformationW OpenEventW RaiseException FormatMessageW GetCurrentThread CreateFileMappingA IsBadReadPtr ExpandEnvironmentStringsW LoadLibraryExW FileTimeToSystemTime VirtualQuery GlobalFindAtomW VirtualQueryEx Sleep SetFilePointer LoadResource SuspendThread GetTickCount WritePrivateProfileStringW WaitForMultipleObjects OpenFileMappingA GetFileSize GetStartupInfoW GetFileAttributesW GetThreadPriority SetThreadPriority VirtualAlloc GetSystemInfo GetTempPathW LeaveCriticalSection GetVolumePathNamesForVolumeNameW GetLogicalDriveStringsW GetModuleHandleA HeapCreate VerSetConditionMask GetDiskFreeSpaceW GetUserDefaultUILanguage GetConsoleOutputCP GetModuleFileNameA OpenMutexA HeapFree WideCharToMultiByte MultiByteToWideChar FindClose LoadLibraryW SetEvent FreeEnvironmentStringsW OpenEventA GetLocaleInfoW FormatMessageA GetLocalTime WaitForSingleObject DeleteCriticalSection SetErrorMode GetComputerNameW SleepEx IsValidLocale LoadLibraryExA GetTickCount64 FindNextVolumeW LocalAlloc GetPrivateProfileStringW WaitForMultipleObjectsEx SetFileAttributesW QueryDosDeviceW VirtualProtect CreateSemaphoreW ReadProcessMemory OpenFileMappingW QueryPerformanceFrequency SetProcessWorkingSetSize SetThreadContext VirtualFree GetThreadContext ExitProcess HeapAlloc GetFileAttributesA RtlUnwind GetCPInfo GetCommandLineA GetStdHandle GetModuleHandleW ReadFile FileTimeToDosDateTime CreateProcessW FindResourceW lstrcmpA MapViewOfFile MulDiv CreateFileA GetSystemDirectoryA GetVersion GetDriveTypeW FreeResource GlobalAddAtomW OpenProcess SwitchToThread FindVolumeClose GetExitCodeThread OutputDebugStringW GetFileAttributesExW SetPriorityClass TerminateProcess LockResource FindFirstVolumeW GetPriorityClass GetCurrentThreadId UnhandledExceptionFilter GlobalFree CreateEventA EnterCriticalSection ReleaseMutex GlobalDeleteAtom InitializeCriticalSection GlobalLock GetCurrentProcess GetCommandLineW ResumeThread GetProcAddress DuplicateHandle GetVersionExW VerifyVersionInfoW GetWindowsDirectoryW GetProcessVersion GetEnvironmentStringsW GetProcessAffinityMask LCMapStringW FindFirstFileW UnmapViewOfFile GetConsoleCP GlobalHandle lstrlenW QueryPerformanceCounter SetEndOfFile lstrcmpW CreateMutexA ReleaseSemaphore CreateFileW GetSystemDirectoryW SetThreadAffinityMask DeleteFileW GetEnvironmentVariableW WriteFile FindFirstFileExW ExitThread CreateFileMappingW CreatePipe TlsGetValue GetDateFormatW PulseEvent TlsSetValue GetSystemDefaultUILanguage EnumCalendarInfoW RemoveDirectoryW GlobalMemoryStatus CreateEventW SetThreadLocale GetThreadLocale |
gdiplus.dll |
GdipCreateRegionRect
GdipFillEllipseI GdipCreateMatrix GdipGetImageRawFormat GdipSetStringFormatTrimming GdiplusShutdown GdipCreateBitmapFromStream GdipLoadImageFromStream GdipCreateFont GdipLoadImageFromStreamICM GdipCreateStringFormat GdipSetPathGradientCenterPointI GdipSetSmoothingMode GdipGetSmoothingMode GdipResetClip GdipFillRectangle GdipFillPath GdipCreateLineBrushFromRect GdipDrawString GdipResetWorldTransform GdipAlloc GdipDeleteMatrix GdipSetClipRegion GdipClosePathFigure GdipDrawImageI GdipDeleteFontFamily GdipSetStringFormatLineAlign GdipResetPath GdipAddPathEllipse GdipAddPathArc GdipSetWorldTransform GdipAddPathCurve2I GdipCreateLineBrushFromRectWithAngle GdipDeleteRegion GdipCreatePath GdipCreatePen1 GdipSetPathGradientWrapMode GdipSetStringFormatHotkeyPrefix GdipBitmapGetPixel GdipCreateTexture GdipDrawLine GdipCreatePathGradientFromPath GdipGetPathGradientPointCount GdipSetPathGradientCenterPoint GdipCreateHatchBrush GdipSetLineGammaCorrection GdipSetPenDashStyle GdipDeletePen GdipRotateMatrix GdipDeleteGraphics GdipDrawPath GdipCreateBitmapFromStreamICM GdipSetPathGradientCenterColor GdipDeleteFont GdipDrawRectangle GdipFree GdipTranslateMatrix GdipSetTextRenderingHint GdipAddPathLine GdipDeleteStringFormat GdipGetImagePixelFormat GdipGetImageWidth GdipGetImageHeight GdipCreateFromHDC GdipSetPathGradientSurroundColorsWithCount GdipSetImageAttributesColorKeys GdipCreateSolidFill GdipCreateRegionPath GdipCreateImageAttributes GdiplusStartup GdipDeleteBrush GdipSetStringFormatAlign GdipCreateLineBrush GdipSetPathGradientPresetBlend GdipDeletePath GdipDrawImageRectRect GdipDrawImageRect GdipAddPathBezier GdipCreateFontFamilyFromName GdipDisposeImageAttributes GdipMeasureString GdipDisposeImage |
ole32.dll |
CreateDataAdviseHolder
CoCreateInstance OleGetClipboard CLSIDFromString OleSetClipboard IsEqualGUID CreateStreamOnHGlobal GetHGlobalFromStream CoGetClassObject CoInitialize OleDraw CoTaskMemAlloc DoDragDrop StringFromCLSID RevokeDragDrop IsAccelerator CoUninitialize ReleaseStgMedium RegisterDragDrop OleInitialize ProgIDFromCLSID OleUninitialize CoDisconnectObject CoTaskMemFree OleSetMenuDescriptor |
gdi32.dll |
Pie
SetPaletteEntries SetBkMode GetRandomRgn CreateCompatibleBitmap CreatePolygonRgn GetEnhMetaFileHeader CloseEnhMetaFile RectVisible AngleArc ResizePalette SetTextColor GetTextColor StretchBlt RoundRect SelectClipRgn RestoreDC SetRectRgn GetTextMetricsW GetWindowOrgEx SetPixelV CreatePalette CreateDCW CreateICW PolyBezierTo CreatePen GetStockObject CreateSolidBrush Polygon MoveToEx PlayEnhMetaFile Ellipse GetBitmapBits GetSystemPaletteEntries GetEnhMetaFileBits GetEnhMetaFilePaletteEntries CreatePenIndirect SetMapMode GetMapMode CreateFontIndirectW PolyBezier LPtoDP EndDoc GetObjectW GetCurrentObject GetWinMetaFileBits SetROP2 GetTextExtentExPointW GetEnhMetaFileDescriptionW ArcTo CreateEnhMetaFileW Arc CreateRectRgnIndirect TextOutW SelectPalette ExcludeClipRect MaskBlt SetWindowOrgEx CreatePatternBrush EndPage DeleteEnhMetaFile Chord SetDIBits SetViewportOrgEx CreateRectRgn RealizePalette SetDIBColorTable GetDIBColorTable GetGlyphOutlineW CreateBrushIndirect PatBlt SetEnhMetaFileBits Rectangle SaveDC DeleteDC BitBlt FrameRgn GetDeviceCaps GetTextExtentPoint32W GetClipBox IntersectClipRect Polyline CreateBitmap CombineRgn SetWinMetaFileBits CreateDIBitmap GetStretchBltMode CreateDIBSection SetStretchBltMode GetDIBits LineTo GetRgnBox EnumFontsW CreateHalftonePalette SelectObject DeleteObject ExtFloodFill UnrealizeObject CopyEnhMetaFileW OffsetRgn SetBkColor GetBkColor CreateCompatibleDC GetBrushOrgEx GetCurrentPositionEx SetDCPenColor GetNearestPaletteIndex GetTextExtentPointW ExtTextOutW SetBrushOrgEx GetPixel GdiFlush SetPixel EnumFontFamiliesExW StretchDIBits GetPaletteEntries |
ntdll.dll |
RtlGetVersion
|
kernel32.dll (delay-loaded) |
GetFileType
GetACP GetExitCodeProcess LocalFree CloseHandle SizeofResource VirtualProtectEx GetSystemDefaultLangID GetCurrentProcessId TerminateThread IsDebuggerPresent GetFullPathNameW FindNextFileW GlobalSize GetCPInfoExW WriteProcessMemory EnumSystemLocalesW GetTimeZoneInformation FileTimeToLocalFileTime GetVersionExA FreeLibrary HeapDestroy GetUserDefaultLCID FindFirstFileA SetLastError GetModuleFileNameW GetLastError GlobalAlloc GlobalUnlock CompareStringW CreateThread LoadLibraryA CreateMutexW ResetEvent GetVolumeInformationW OpenEventW RaiseException FormatMessageW GetCurrentThread CreateFileMappingA IsBadReadPtr ExpandEnvironmentStringsW LoadLibraryExW FileTimeToSystemTime VirtualQuery GlobalFindAtomW VirtualQueryEx Sleep SetFilePointer LoadResource SuspendThread GetTickCount WritePrivateProfileStringW WaitForMultipleObjects OpenFileMappingA GetFileSize GetStartupInfoW GetFileAttributesW GetThreadPriority SetThreadPriority VirtualAlloc GetSystemInfo GetTempPathW LeaveCriticalSection GetVolumePathNamesForVolumeNameW GetLogicalDriveStringsW GetModuleHandleA HeapCreate VerSetConditionMask GetDiskFreeSpaceW GetUserDefaultUILanguage GetConsoleOutputCP GetModuleFileNameA OpenMutexA HeapFree WideCharToMultiByte MultiByteToWideChar FindClose LoadLibraryW SetEvent FreeEnvironmentStringsW OpenEventA GetLocaleInfoW FormatMessageA GetLocalTime WaitForSingleObject DeleteCriticalSection SetErrorMode GetComputerNameW SleepEx IsValidLocale LoadLibraryExA GetTickCount64 FindNextVolumeW LocalAlloc GetPrivateProfileStringW WaitForMultipleObjectsEx SetFileAttributesW QueryDosDeviceW VirtualProtect CreateSemaphoreW ReadProcessMemory OpenFileMappingW QueryPerformanceFrequency SetProcessWorkingSetSize SetThreadContext VirtualFree GetThreadContext ExitProcess HeapAlloc GetFileAttributesA RtlUnwind GetCPInfo GetCommandLineA GetStdHandle GetModuleHandleW ReadFile FileTimeToDosDateTime CreateProcessW FindResourceW lstrcmpA MapViewOfFile MulDiv CreateFileA GetSystemDirectoryA GetVersion GetDriveTypeW FreeResource GlobalAddAtomW OpenProcess SwitchToThread FindVolumeClose GetExitCodeThread OutputDebugStringW GetFileAttributesExW SetPriorityClass TerminateProcess LockResource FindFirstVolumeW GetPriorityClass GetCurrentThreadId UnhandledExceptionFilter GlobalFree CreateEventA EnterCriticalSection ReleaseMutex GlobalDeleteAtom InitializeCriticalSection GlobalLock GetCurrentProcess GetCommandLineW ResumeThread GetProcAddress DuplicateHandle GetVersionExW VerifyVersionInfoW GetWindowsDirectoryW GetProcessVersion GetEnvironmentStringsW GetProcessAffinityMask LCMapStringW FindFirstFileW UnmapViewOfFile GetConsoleCP GlobalHandle lstrlenW QueryPerformanceCounter SetEndOfFile lstrcmpW CreateMutexA ReleaseSemaphore CreateFileW GetSystemDirectoryW SetThreadAffinityMask DeleteFileW GetEnvironmentVariableW WriteFile FindFirstFileExW ExitThread CreateFileMappingW CreatePipe TlsGetValue GetDateFormatW PulseEvent TlsSetValue GetSystemDefaultUILanguage EnumCalendarInfoW RemoveDirectoryW GlobalMemoryStatus CreateEventW SetThreadLocale GetThreadLocale |
Attributes | 0x1 |
---|---|
Name | kernel32.dll |
ModuleHandle | 0x49d1c0 |
DelayImportAddressTable | 0x49d1f8 |
DelayImportNameTable | 0x49d35c |
BoundDelayImportTable | 0x49d4c0 |
UnloadDelayImportTable | 0x49d5f0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x470630 |
Ordinal | 2 |
---|---|
Address | 0x103ec |
Ordinal | 3 |
---|---|
Address | 0x60308 |
Type |
RT_RCDATA
|
---|