Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-May-16 05:59:04 |
Detected languages |
English - United States
|
Debug artifacts |
D:\_work\4\s\Endpoint\Setup required\MSI Enterprise\Win32\Release\STInstallAgent.pdb
|
CompanyName | Safetica Technologies |
FileDescription | Safetica MSI Install |
FileVersion | 11,4,6,0 |
InternalName | Safetica MSI Install |
LegalCopyright | Copyright (C) 2024, Safetica |
LegalTrademarks | Safetica Technologies |
OriginalFilename | STInstallAgent.dll |
ProductName | Safetica MSI Install |
ProductVersion | 11.4.6 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Suspicious | The PE is possibly packed. | Unusual section name found: .orpc |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/69 (Scanned on 2024-06-07 07:46:24) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2024-May-16 05:59:04 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1f7000 |
SizeOfInitializedData | 0xd4000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x001A0E99 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1f9000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2cf000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
RPCRT4.dll |
CStdStubBuffer_QueryInterface
NdrOleAllocate CStdStubBuffer_DebugServerRelease CStdStubBuffer_Disconnect IUnknown_QueryInterface_Proxy CStdStubBuffer_IsIIDSupported CStdStubBuffer_Connect UuidToStringW CStdStubBuffer_AddRef NdrOleFree CStdStubBuffer_CountRefs IUnknown_AddRef_Proxy CStdStubBuffer_Invoke NdrCStdStubBuffer_Release NdrClientCall2 NdrDllGetClassObject RpcBindingFree RpcStringFreeW RpcStringBindingComposeW RpcBindingFromStringBindingW CStdStubBuffer_DebugServerQueryInterface IUnknown_Release_Proxy RpcBindingSetOption |
---|---|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoExW GetFileVersionInfoSizeExW |
MPR.dll |
WNetGetUniversalNameW
|
NETAPI32.dll |
NetShareGetInfo
Netbios NetApiBufferFree |
KERNEL32.dll |
GetSystemInfo
CreateProcessW IsWow64Process GetExitCodeProcess GetNativeSystemInfo QueueUserWorkItem GetVolumePathNameW WriteConsoleW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage ReadConsoleW EnumSystemLocalesW IsValidLocale LCMapStringW GetConsoleMode GetConsoleOutputCP SetFilePointerEx GetStdHandle ExitProcess GetFileType SetStdHandle VirtualQuery VirtualAlloc HeapQueryInformation GetCommandLineW GetCommandLineA ExitThread InterlockedFlushSList RtlUnwind GetCPInfo CompareStringEx LCMapStringEx GetLocaleInfoEx FindFirstFileExW QueryPerformanceFrequency AcquireSRWLockShared ReleaseSRWLockShared TryAcquireSRWLockExclusive AcquireSRWLockExclusive ReleaseSRWLockExclusive GetStringTypeW FormatMessageA RaiseException OutputDebugStringW HeapFree InitializeCriticalSectionEx HeapSize GetLastError HeapReAlloc HeapAlloc DecodePointer DeleteCriticalSection GetProcessHeap MultiByteToWideChar MoveFileExW WideCharToMultiByte LocalAlloc Sleep LocalFree GetTickCount SizeofResource LockResource LoadResource FindResourceW GetTimeFormatW SystemTimeToFileTime GetDateFormatW WaitForMultipleObjects WaitForSingleObject CreateEventW SetEvent CloseHandle GetUserDefaultUILanguage CreateMutexW ReleaseMutex DeleteFileW CopyFileW ReadFile WriteFile SetFilePointer CreateFileW FileTimeToSystemTime GetLocalTime GetFileSize FormatMessageW GetModuleHandleExW GetModuleFileNameW VerSetConditionMask VerifyVersionInfoW GetCurrentThreadId GetCurrentProcessId SetLastError EnterCriticalSection LeaveCriticalSection InitializeCriticalSection FreeLibraryAndExitThread CreateThread ResetEvent FileTimeToLocalFileTime GetProcAddress GetModuleHandleW SetEndOfFile GetTempPathW FindFirstFileW FindNextFileW FindClose GlobalAlloc GlobalSize GlobalUnlock GlobalLock GlobalFree MulDiv SetThreadPriority ResumeThread OutputDebugStringA GetCurrentThread GetVersionExW FreeLibrary GetModuleHandleA LoadLibraryExW LoadLibraryW GlobalDeleteAtom lstrcmpA lstrcmpW GetPrivateProfileIntW GetPrivateProfileStringW WritePrivateProfileStringW GlobalAddAtomW InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GlobalReAlloc GlobalHandle LocalReAlloc SetErrorMode CompareStringW GlobalGetAtomNameW EncodePointer GetSystemDirectoryW LoadLibraryA GlobalFindAtomW GetCurrentDirectoryW GetLocaleInfoW GetSystemDefaultUILanguage GlobalFlags FlushFileBuffers GetFullPathNameW GetVolumeInformationW LockFile UnlockFile DuplicateHandle GetCurrentProcess lstrcmpiW VirtualProtect GetFileAttributesW GetFileAttributesExW GetFileSizeEx GetFileTime SystemTimeToTzSpecificLocalTime lstrcpyW FindResourceExW GetWindowsDirectoryW GetTickCount64 GetProfileIntW SearchPathW GetTempFileNameW GetUserDefaultLCID UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime GetTimeZoneInformation GetDriveTypeW GetVolumePathNamesForVolumeNameW QueryDosDeviceW InitializeSListHead |
USER32.dll |
MoveWindow
MapDialogRect IntersectRect TrackMouseEvent LoadImageW GetNextDlgGroupItem SetCapture ReleaseCapture ShowWindow GetMonitorInfoW MonitorFromWindow WinHelpW GetScrollInfo SetScrollInfo LoadIconW GetWindow GetTopWindow GetClassLongW SetWindowLongW PtInRect EqualRect CopyRect MapWindowPoints ScreenToClient AdjustWindowRectEx GetWindowRect GetClientRect RemovePropW GetPropW SetPropW ShowScrollBar GetScrollRange SetScrollRange GetScrollPos SetScrollPos ScrollWindow RedrawWindow EndPaint BeginPaint WindowFromPoint DrawFocusRect IsRectEmpty DrawIconEx GetIconInfo UnregisterClassW GetDesktopWindow EnumThreadWindows MessageBeep EnableScrollBar GetClassNameW EndDialog HideCaret MessageBoxW GetMenuStringW GetMenuState InvertRect NotifyWinEvent CreatePopupMenu GetMenuDefaultItem MapVirtualKeyW GetKeyNameTextW LoadMenuW SetLayeredWindowAttributes EnumDisplayMonitors OpenClipboard CloseClipboard SetClipboardData EmptyClipboard DrawStateW SetClassLongW SetWindowRgn CheckDlgButton SetWindowTextW IsDialogMessageW CopyImage SystemParametersInfoW DeleteMenu ClientToScreen RealChildWindowFromPoint SetTimer KillTimer InvalidateRect DrawTextW DrawTextExW GrayStringW TabbedTextOutW GetWindowDC FillRect DestroyIcon CharUpperW DestroyMenu GetMenuItemInfoW InflateRect SendDlgItemMessageA SetRectEmpty OffsetRect CreateDialogIndirectParamW GetNextDlgTabItem GetSubMenu GetMenuItemID GetMenuItemCount InsertMenuW AppendMenuW RemoveMenu GetMessageW TranslateMessage DispatchMessageW PeekMessageW SendMessageW IsWindowVisible GetActiveWindow GetKeyState ValidateRect GetCursorPos SetWindowsHookExW CallNextHookEx PostMessageW PostQuitMessage ShowOwnedPopups SetCursor EnableWindow IsWindowEnabled GetWindowLongW GetParent GetWindowThreadProcessId GetLastActivePopup GetFocus CheckMenuItem EnableMenuItem SetMenuItemBitmaps GetMenuCheckMarkDimensions SetMenuItemInfoW LoadBitmapW UnhookWindowsHookEx GetSystemMetrics GetDC ReleaseDC GetSysColor GetSysColorBrush LoadCursorW GetWindowTextW GetWindowTextLengthW RegisterWindowMessageW GetMessagePos GetMessageTime DefWindowProcW CallWindowProcW RegisterClassW GetClassInfoW GetClassInfoExW CreateWindowExW IsWindow IsMenu IsChild DestroyWindow SetWindowPos GetWindowPlacement SetWindowPlacement BeginDeferWindowPos DeferWindowPos EndDeferWindowPos IsIconic GetDlgItem GetDlgCtrlID SetFocus GetCapture GetMenu SetMenu TrackPopupMenu UpdateWindow SetActiveWindow GetForegroundWindow SetForegroundWindow SetParent DrawEdge DrawFrameControl IsZoomed GetSystemMenu BringWindowToTop SetCursorPos CopyIcon FrameRect DrawIcon UnionRect UpdateLayeredWindow MonitorFromPoint LoadAcceleratorsW TranslateAcceleratorW InsertMenuItemW UnpackDDElParam ReuseDDElParam GetComboBoxInfo PostThreadMessageW WaitMessage GetKeyboardLayout IsCharLowerW MapVirtualKeyExW ToUnicodeEx GetKeyboardState CreateAcceleratorTableW DestroyAcceleratorTable CopyAcceleratorTableW SetRect LockWindowUpdate SetMenuDefaultItem GetDoubleClickTime ModifyMenuW RegisterClipboardFormatW CharUpperBuffW IsClipboardFormatAvailable GetUpdateRect DrawMenuBar DefFrameProcW DefMDIChildProcW TranslateMDISysAccel SubtractRect CreateMenu GetWindowRgn DestroyCursor GetAsyncKeyState |
GDI32.dll |
DeleteObject
GetObjectW SetTextColor SetBkColor DeleteDC CreateBitmap GetDeviceCaps CreateDCW PtVisible BitBlt GetTextFaceW GetViewportOrgEx GetWindowOrgEx SetPixelV SetPaletteEntries ExtFloodFill PtInRegion GetBoundsRect FrameRgn FillRgn RoundRect OffsetRgn GetRgnBox Rectangle LPtoDP CreateRoundRectRgn Polyline Polygon CreatePolygonRgn GetTextColor Ellipse CreateEllipticRgn SetDIBColorTable CreateDIBSection StretchBlt SetPixel GetTextCharsetInfo EnumFontFamiliesW CreateDIBitmap CreateCompatibleBitmap GetBkColor RealizePalette GetSystemPaletteEntries GetPaletteEntries GetNearestPaletteIndex CreatePalette EnumFontFamiliesExW GetTextMetricsW DPtoLP SetRectRgn PatBlt CreateRectRgnIndirect CombineRgn GetTextExtentPoint32W CreateFontIndirectW ScaleWindowExtEx ScaleViewportExtEx OffsetWindowOrgEx OffsetViewportOrgEx SetWindowOrgEx SetWindowExtEx SetViewportOrgEx SetViewportExtEx ExtTextOutW TextOutW MoveToEx SetTextAlign SetROP2 SetPolyFillMode GetLayout SetLayout SetMapMode SetBkMode SelectPalette SelectObject ExtSelectClipRgn SelectClipRgn SaveDC RestoreDC RectVisible CreateCompatibleDC LineTo IntersectClipRect GetWindowExtEx GetViewportExtEx GetStockObject GetPixel GetObjectType GetClipBox ExcludeClipRect Escape CreateSolidBrush CreateRectRgn CreatePatternBrush CreatePen CreateHatchBrush CopyMetaFileW |
MSIMG32.dll |
TransparentBlt
AlphaBlend |
WINSPOOL.DRV |
OpenPrinterW
ClosePrinter DocumentPropertiesW |
ADVAPI32.dll |
GetLengthSid
OpenServiceW OpenSCManagerW CloseServiceHandle SetSecurityDescriptorDacl AllocateAndInitializeSid FreeSid InitializeSecurityDescriptor InitializeAcl AddAccessAllowedAce RegDeleteKeyExW RegEnumKeyExW RegEnumValueW RegQueryValueW RegEnumKeyW RegSetValueExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegQueryValueExW RegCloseKey RegOpenKeyExW |
SHELL32.dll |
SHGetFolderPathW
SHGetFileInfoW ShellExecuteW SHGetPathFromIDListW SHGetSpecialFolderLocation SHGetDesktopFolder DragQueryFileW DragFinish SHBrowseForFolderW SHAppBarMessage |
SHLWAPI.dll |
PathFileExistsW
PathFindExtensionW PathFindFileNameW PathIsUNCW PathStripToRootW PathRemoveFileSpecW StrFormatKBSizeW |
UxTheme.dll |
GetWindowTheme
GetThemeSysColor IsAppThemed IsThemeBackgroundPartiallyTransparent DrawThemeParentBackground GetCurrentThemeName GetThemeColor GetThemePartSize DrawThemeText DrawThemeBackground OpenThemeData CloseThemeData |
ole32.dll |
OleLockRunning
RevokeDragDrop RegisterDragDrop CoLockObjectExternal OleGetClipboard DoDragDrop CreateStreamOnHGlobal CoDisconnectObject CoInitialize ReleaseStgMedium OleDuplicateData CoTaskMemFree CoTaskMemAlloc CoCreateGuid CoRegisterPSClsid OleRun CoRegisterClassObject CoInitializeEx CoSetProxyBlanket CoCreateInstance CoUninitialize OleCreateMenuDescriptor OleDestroyMenuDescriptor OleTranslateAccelerator IsAccelerator |
OLEAUT32.dll |
SysStringLen
SysAllocStringLen LoadTypeLib BSTR_UserMarshal BSTR_UserUnmarshal BSTR_UserFree BSTR_UserSize SysFreeString SysAllocString VariantClear SystemTimeToVariantTime VariantTimeToSystemTime VarBstrFromDate VariantCopy VariantChangeType VariantInit |
msi.dll |
#74
|
gdiplus.dll |
GdipDrawImageI
GdipCreateFromHDC GdipSetInterpolationMode GdipCreateBitmapFromHBITMAP GdipDeleteGraphics GdipBitmapUnlockBits GdipBitmapLockBits GdipDrawImageRectI GdiplusShutdown GdipAlloc GdipFree GdiplusStartup GdipCloneImage GdipDisposeImage GdipGetImageGraphicsContext GdipGetImageWidth GdipGetImageHeight GdipGetImagePixelFormat GdipGetImagePalette GdipGetImagePaletteSize GdipCreateBitmapFromScan0 GdipCreateBitmapFromStream |
OLEACC.dll |
AccessibleObjectFromWindow
LresultFromObject CreateStdAccessibleObject |
IMM32.dll |
ImmReleaseContext
ImmGetOpenStatus ImmGetContext |
WINMM.dll |
PlaySoundW
|
WS2_32.dll |
htonl
GetAddrInfoW InetNtopW WSAStartup WSACleanup FreeAddrInfoW GetNameInfoW ntohl |
IPHLPAPI.DLL |
GetAdaptersInfo
|
Ordinal | 1 |
---|---|
Address | 0x2aba0 |
Ordinal | 2 |
---|---|
Address | 0x2a610 |
Ordinal | 3 |
---|---|
Address | 0x2ade0 |
Ordinal | 4 |
---|---|
Address | 0x2a600 |
DCInstall |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 11.4.6.0 |
ProductVersion | 11.4.6.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Safetica Technologies |
FileDescription | Safetica MSI Install |
FileVersion (#2) | 11,4,6,0 |
InternalName | Safetica MSI Install |
LegalCopyright | Copyright (C) 2024, Safetica |
LegalTrademarks | Safetica Technologies |
OriginalFilename | STInstallAgent.dll |
ProductName | Safetica MSI Install |
ProductVersion (#2) | 11.4.6 |
Resource LangID | UNKNOWN |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-16 05:59:04 |
Version | 0.0 |
SizeofData | 109 |
AddressOfRawData | 0x27c1a4 |
PointerToRawData | 0x27a5a4 |
Referenced File | D:\_work\4\s\Endpoint\Setup required\MSI Enterprise\Win32\Release\STInstallAgent.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-16 05:59:04 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x27c214 |
PointerToRawData | 0x27a614 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-16 05:59:04 |
Version | 0.0 |
SizeofData | 956 |
AddressOfRawData | 0x27c228 |
PointerToRawData | 0x27a628 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-16 05:59:04 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x1027c5f4 |
---|---|
EndAddressOfRawData | 0x1027c5fc |
AddressOfIndex | 0x102a67a0 |
AddressOfCallbacks | 0x101f9e28 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x10294fe4 |
SEHandlerTable | 0x1027ad68 |
SEHandlerCount | 1168 |
XOR Key | 0x4714e55b |
---|---|
Unmarked objects | 0 |
ASM objects (29395) | 28 |
C objects (29395) | 38 |
C++ objects (29395) | 213 |
C objects (CVTCIL) (29395) | 1 |
C objects (VS 2015-2022 runtime 32533) | 18 |
ASM objects (VS 2015-2022 runtime 32533) | 27 |
C++ objects (VS 2015-2022 runtime 32533) | 408 |
Imports (29395) | 51 |
Total imports | 1001 |
C++ objects (LTCG) (VS2022 Update 7 (17.7.4) compiler 32825) | 44 |
Exports (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
Resource objects (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
151 | 1 |
Linker (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |