| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1992-Jun-19 22:22:17 |
| Detected languages |
English - United States
|
| Suspicious | PEiD Signature: |
ASPack v2.12
ASProtect v?.? -> If you know this version, post on PEiD board (h2) |
| Suspicious | The PE is packed with Aspack or Armadillo |
Unusual section name found:
Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Section .rsrc is both writable and executable. Section .data is both writable and executable. Unusual section name found: .adata Section .adata is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE header may have been manually modified. |
Resource TLOGOFORM is possibly compressed or encrypted.
The resource timestamps differ from the PE header:
|
| Suspicious | The file contains overlay data. |
3856630 bytes of data starting at offset 0xa5200.
The overlay data has an entropy of 7.99804 and is possibly compressed or encrypted. Overlay data amounts for 85.0793% of the executable. |
| Malicious | VirusTotal score: 3/71 (Scanned on 2026-05-15 15:49:07) |
Skyhigh:
BehavesLike.Win32.Dropper.rc
ViRobot: Backdoor.Win32.RBot.2624126 Zillya: Backdoor.RBot.Win32.16951 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 1992-Jun-19 22:22:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x11e200 |
| SizeOfInitializedData | 0x39200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: ) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x120000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1e8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetProcAddress
GetModuleHandleA LoadLibraryA |
|---|---|
| user32.dll |
GetKeyboardType
|
| advapi32.dll |
RegQueryValueExA
|
| oleaut32.dll |
SysFreeString
|
| advapi32.dll (#2) |
RegQueryValueExA
|
| mpr.dll |
WNetGetConnectionA
|
| version.dll |
VerQueryValueA
|
| gdi32.dll |
UnrealizeObject
|
| user32.dll (#2) |
GetKeyboardType
|
| oleaut32.dll (#2) |
SysFreeString
|
| ole32.dll |
CoCreateInstance
|
| comctl32.dll |
ImageList_SetIconSize
|
| winspool.drv |
OpenPrinterA
|
| shell32.dll |
ShellExecuteA
|
| shell32.dll (#2) |
ShellExecuteA
|
| comdlg32.dll |
ChooseColorA
|
| winmm.dll |
timeGetTime
|
| d3d8.dll |
Direct3DCreate8
|
| ddraw.dll |
DirectDrawCreate
|
| wsock32.dll |
WSACleanup
|
| oleaut32.dll (#3) |
SysFreeString
|
| kernel32.dll (#2) |
GetProcAddress
GetModuleHandleA LoadLibraryA |
| Image is empty |
| Invalid reduction method |
| Loading... |
| Saving... |
| Converting... |
| Rendering... |
| Copying... |
| Optimizing... |
| Cannot change the size of a JPEG image |
| JPEG error #%d |
| JPEG Image File |
| Unsupported Application Extension block size |
| Unknown GIF block type |
| Object type not supported for operation |
| Invalid GIF data |
| Image height too small for contained frames |
| Image width too small for contained frames |
| Clipboard operations not supported for GIF objects |
| Image exceeds Logical Screen size |
| No global or local color table defined |
| Invalid pixel coordinates |
| Unsupported PixelFormat |
| Invalid image dimensions |
| Image has no DIB |
| Invalid stream operation |
| Color not in color table |
| Color table is empty |
| Failed to Save Stream |
| No help keyword specified. |
| Premature end of data |
| Color table overflow |
| Invalid color index |
| Unsupported GIF version |
| Invalid GIF signature |
| Invalid number of colors specified in Screen Descriptor |
| Invalid number of colors specified in Image Descriptor |
| Unknown extension type |
| Invalid extension introducer |
| Failed to allocate memory for GIF DIB |
| Decoder bit buffer under-run |
| Circular decoder table entry |
| Invalid Image trailer |
| Internal error: Extension Instance does not match Extension Label |
| Inactive Border |
| Inactive Caption |
| Inactive Caption Text |
| Info Background |
| Info Text |
| Menu Background |
| Menu Text |
| None |
| Scroll Bar |
| 3D Dark Shadow |
| 3D Light |
| Window Background |
| Window Frame |
| Window Text |
| RichEdit line insertion error |
| Failed to Load Stream |
| Sky Blue |
| Cream |
| Medium Gray |
| Active Border |
| Active Caption |
| Application Workspace |
| Background |
| Button Face |
| Button Highlight |
| Button Shadow |
| Button Text |
| Caption Text |
| Default |
| Gray Text |
| Highlight Background |
| Highlight Text |
| Maroon |
| Green |
| Olive |
| Navy |
| Purple |
| Teal |
| Gray |
| Silver |
| Red |
| Lime |
| Yellow |
| Blue |
| Fuchsia |
| Aqua |
| White |
| Money Green |
| There is no default printer currently selected |
| Menu '%s' is already being used by another form |
| No MCI device open |
| Unknown error code |
| Docked control must have a name |
| Error removing control from dock tree |
| - Dock zone not found |
| - Dock zone has no control |
| Separator |
| Error setting %s.Count |
| Listbox (%s) style must be virtual in order to set Count |
| Unable to find a Table of Contents |
| No help found for %s |
| No context-sensitive help installed |
| No topic-based help system installed |
| Black |
| Del |
| Shift+ |
| Ctrl+ |
| Alt+ |
| Unable to insert a line |
| The specified directory does not exist. Create it? |
| Select Directory |
| Directory &Name: |
| D&rives: |
| &Directories: |
| &Files: (*.*) |
| Ne&twork... |
| Invalid clipboard format |
| Clipboard does not support Icons |
| Cannot open clipboard |
| Text exceeds memo capacity |
| N&o to All |
| Yes to &All |
| BkSp |
| Tab |
| Esc |
| Enter |
| Space |
| PgUp |
| PgDn |
| End |
| Home |
| Left |
| Up |
| Right |
| Down |
| Ins |
| Bitmaps |
| Invalid input value |
| Invalid input value. Use escape key to abandon changes |
| Warning |
| Error |
| Information |
| Confirm |
| &Yes |
| &No |
| OK |
| Cancel |
| &Help |
| &Abort |
| &Retry |
| &Ignore |
| &All |
| Can only modify an image if it contains a bitmap |
| A control cannot have itself as its parent |
| OK |
| Cancel |
| &Yes |
| &No |
| &Help |
| &Close |
| &Ignore |
| &Retry |
| Abort |
| &All |
| Cannot drag a form |
| Metafiles |
| Enhanced Metafiles |
| Icons |
| Cannot focus a disabled or invisible window |
| Control '%s' has no parent window |
| Parent given is not a parent of '%s' |
| Cannot hide an MDI Child Form |
| Cannot change Visible in OnShow or OnHide |
| Cannot make a visible window modal |
| Menu index out of range |
| Menu inserted twice |
| Sub-menu is not in menu |
| Not enough timers available |
| Printer is not currently printing |
| Printing in progress |
| Printer selected is not valid |
| %s on %s |
| GroupIndex cannot be less than a previous menu item's GroupIndex |
| Cannot create form. No MDI forms are currently active |
| Icon image is not valid |
| Metafile is not valid |
| Invalid pixel format |
| Scan line index out of range |
| Cannot change the size of an icon |
| Unknown picture file extension (.%s) |
| Unsupported clipboard format |
| Out of system resources |
| Canvas does not allow drawing |
| Invalid image size |
| Invalid ImageList |
| Invalid ImageList Index |
| Failed to read ImageList data from stream |
| Failed to write ImageList data to stream |
| Error creating window device context |
| Error creating window class |
| Stream read error |
| Property is read-only |
| Failed to get data for '%s' |
| Failed to set data for '%s' |
| Resource %s not found |
| %s.Seek not implemented |
| Operation not allowed on sorted list |
| Too many rows or columns deleted |
| %s not in a class registration group |
| Property %s does not exist |
| Stream write error |
| Thread creation error: %s |
| Thread Error: %s (%d) |
| ? |
| ''%s'' is not a valid date and time |
| Bitmap image is not valid |
| Grid too large for operation |
| Grid index out of range |
| Unable to write to %s |
| Invalid file name - %s |
| Invalid stream format |
| ''%s'' is not a valid component name |
| Invalid property value |
| Invalid property path |
| Invalid property value |
| Invalid data type for '%s' |
| Cannot insert or delete rows from grid |
| List capacity out of bounds (%d) |
| List count out of bounds (%d) |
| List index out of bounds (%d) |
| Out of memory while expanding memory stream |
| Error reading %s%s%s: %s |
| Saturday |
| Unable to create directory |
| Ancestor for '%s' not found |
| Cannot assign a %s to a %s |
| Bits index out of range |
| Can't write to a read-only resource stream |
| CheckSynchronize called from thread $%x, which is NOT the main thread |
| Class %s not found |
| A class named %s already exists |
| List does not allow duplicates ($0%x) |
| A component named %s already exists |
| String list does not allow duplicates |
| Cannot create file "%s". %s |
| Fixed column count must be less than column count |
| Fixed row count must be less than row count |
| Cannot open file "%s". %s |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%s' is not a valid date |
| '%s' is not a valid time |
| '%s' is not a valid date and time |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Invalid filename |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| StartAddressOfRawData | 0x597000 |
|---|---|
| EndAddressOfRawData | 0x597010 |
| AddressOfIndex | 0x5200d4 |
| AddressOfCallbacks | 0x598010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.