693ec9d1bd533ace442ee47f42f518e4

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-May-03 03:14:06
Detected languages English - United States
Korean - Korea
Debug artifacts c:\devel\Ark6\bin\bdzsfx.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious PEiD Signature: ACE Archive
HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
Can access the registry:
  • RegDeleteValueW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegOpenKeyExW
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegCloseKey
  • RegDeleteKeyW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Enumerates local disk drives:
  • GetDriveTypeW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Suspicious The file contains overlay data. 1156300 bytes of data starting at offset 0x4d200.
Overlay data amounts for 78.5421% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 693ec9d1bd533ace442ee47f42f518e4
SHA1 b3cf8731b21fd08f392bc83bb3e456b3d640dae0
SHA256 65c80fc6694dc7d5b9b4faaf5e9ab2ad6bd7b488a64488efc239df1753903e9f
SHA3 3248cb1e2c22eb22f23996d96281c01f1f807d32bfa270e806f59f38111d4737
SSDeep 24576:Gr4wp01Q/Y6qz28ffvmpDpMBzReNVJvq9ejFn4B6N7SdYirVcdtuVmBrtezhEPH7:0Lp0sqz28/mpDpMBzReNVJvq9ejFn4BU
Imports Hash 58e9f13d94e5f71643321bca35d7df53

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2019-May-03 03:14:06
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x32400
SizeOfInitializedData 0x1aa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00022463 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x34000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x60000
SizeOfHeaders 0x400
Checksum 0x4db4c
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 54aaeefedb3c972b4117852370297466
SHA1 3c3d6a2cd69411214660e6e6b9ca52fee37ac7d9
SHA256 adb34e777f4246a717b19676b15428a140e9abe09756d2a57fb635327ed09a6c
SHA3 ebe04fd0261635a761a190869d2b1fb94463e7a461ee0b67885ccc45df82bc73
VirtualSize 0x32327
VirtualAddress 0x1000
SizeOfRawData 0x32400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.72214

.rdata

MD5 b0f6fc1b3fbf73b6e736065fc317f1f8
SHA1 ee8100d99a8db24924b1192abcb2021fd263d872
SHA256 9de9e0b0c6ef7677c7ce0f6a7b1c6c4ea0e5c8dc9f6579afa091d016f6158e10
SHA3 46c59cd5a56e1275995137e23db31a46a4e8acbbcc9ab92bb3619ef6d651c7d0
VirtualSize 0xa4aa
VirtualAddress 0x34000
SizeOfRawData 0xa600
PointerToRawData 0x32800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.11216

.data

MD5 bee6e905c71f4f0669d94f986bb17949
SHA1 6dd503fd5d5d7187f2df3e6229ec7cb3544f1730
SHA256 978b63c13bfd3bd289b0888e708d7c0f93da4a0c5f0df326bb96b69ee14dafc1
SHA3 6af9e2d3bbde53d123d5a527532bb2d21e4ec95405ae79a1a4844a01309089bb
VirtualSize 0x11dfc
VirtualAddress 0x3f000
SizeOfRawData 0x2000
PointerToRawData 0x3ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.04212

.rsrc

MD5 82e029da83fe7cf6fe9161ff9979c97e
SHA1 72b41c710c87ca7e6ed919412b54d30478d9efa8
SHA256 9504b456a38f0635251721f012463f3becfe91dec8f2729d5d0178fdd3c1e8dd
SHA3 78f39cef4d61895ec97913d48bfc233d0470636ae873d86f0692273deefaddfe
VirtualSize 0x9464
VirtualAddress 0x51000
SizeOfRawData 0x9600
PointerToRawData 0x3ee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.65972

.reloc

MD5 53baf97dcdc3fca411c9846e47575de7
SHA1 8442ef6adb2182feb60c81e15e5299321229a418
SHA256 69396326a83bbd8e6e0f266702255d89280364ddf1573026c517a534c6e499eb
SHA3 465bdf9813378d6b197a49f826d38eaf2b0ba46ff338dbd90f9756188ff509f3
VirtualSize 0x4c06
VirtualAddress 0x5b000
SizeOfRawData 0x4e00
PointerToRawData 0x48400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.74376

Imports

KERNEL32.dll GetTickCount
FileTimeToSystemTime
GetCurrentProcessId
LoadLibraryW
QueryPerformanceCounter
WideCharToMultiByte
VirtualAlloc
VirtualFree
DeleteFileW
WaitForSingleObject
CreateEventW
SetEvent
ResetEvent
lstrcatW
GetFileAttributesA
GetFileAttributesW
lstrlenA
lstrcpyW
SetFileAttributesW
GetFileSize
CreateFileW
GetCurrentThread
SetFileTime
GetTimeZoneInformation
SystemTimeToTzSpecificLocalTime
Sleep
GlobalMemoryStatusEx
GetDriveTypeW
WriteFile
SetFilePointer
CreateFileA
ReadFile
FlushFileBuffers
GlobalAlloc
GlobalLock
GlobalUnlock
MulDiv
GetVersion
GetSystemDirectoryW
CompareStringA
WriteConsoleW
CloseHandle
WriteConsoleA
SetStdHandle
GetStringTypeW
GetStringTypeA
LCMapStringA
GetConsoleMode
GetConsoleCP
GetLocaleInfoA
SetEnvironmentVariableW
SetEnvironmentVariableA
CompareStringW
GetSystemTimeAsFileTime
GetCommandLineW
GetStartupInfoA
GetFileType
SetHandleCount
RtlUnwind
LCMapStringW
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
InitializeCriticalSectionAndSpinCount
GetModuleFileNameA
GetStdHandle
HeapCreate
GetEnvironmentStringsW
FreeEnvironmentStringsW
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
IsDebuggerPresent
SetUnhandledExceptionFilter
GetModuleHandleA
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoW
CreateThread
ExitThread
ExitProcess
IsProcessorFeaturePresent
LoadLibraryA
InterlockedCompareExchange
GetProcessHeap
HeapSize
HeapReAlloc
CreateProcessW
SetCurrentDirectoryW
GetUserDefaultLangID
GetCurrentThreadId
SetLastError
FlushInstructionCache
GetCurrentProcess
DeleteCriticalSection
InitializeCriticalSection
LoadLibraryExW
MultiByteToWideChar
EnterCriticalSection
RaiseException
LeaveCriticalSection
lstrcmpiW
GetProcAddress
GetModuleHandleW
FreeLibrary
GetLastError
InterlockedDecrement
InterlockedIncrement
GlobalFree
lstrcpynW
CreateDirectoryW
GetModuleFileNameW
lstrlenW
FindResourceExW
FindResourceW
LoadResource
LockResource
GetConsoleOutputCP
SizeofResource
HeapFree
HeapAlloc
HeapDestroy
USER32.dll TranslateMessage
SendMessageW
PeekMessageW
UnregisterClassA
CharNextW
DispatchMessageW
RegisterWindowMessageW
EndPaint
BeginPaint
ShowWindow
GetForegroundWindow
DrawIcon
DrawTextW
GetSysColor
CreateWindowExW
DestroyWindow
IsDialogMessageW
GetCapture
CreateDialogIndirectParamW
ReleaseDC
GetDC
OffsetRect
CopyRect
SystemParametersInfoW
MonitorFromRect
GetFocus
GetSystemMetrics
SetFocus
InvalidateRect
EndDialog
KillTimer
ScreenToClient
MessageBoxW
EnableWindow
SetTimer
GetDlgItem
SetDlgItemTextW
SetWindowTextW
GetWindow
MonitorFromWindow
GetMonitorInfoW
LoadIconW
GetClientRect
PostMessageW
MapWindowPoints
GetParent
MoveWindow
GetWindowRect
SetWindowPos
GetWindowLongW
GetWindowTextW
GetWindowTextLengthW
SetWindowLongW
DialogBoxParamW
GetActiveWindow
GetMessageW
GDI32.dll GetObjectW
GetStockObject
SetBkMode
SetTextColor
GetDeviceCaps
ExtTextOutW
SetBkColor
GetTextExtentPoint32W
GetTextMetricsW
BitBlt
DeleteDC
SelectObject
CreateCompatibleDC
CreateDIBSection
DeleteObject
CreateFontIndirectW
ADVAPI32.dll AccessCheck
OpenThreadToken
RevertToSelf
ImpersonateSelf
GetFileSecurityW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
AreAllAccessesGranted
SHELL32.dll SHBrowseForFolderW
ShellExecuteW
SHGetPathFromIDListW
ole32.dll CoInitialize
CoCreateInstance
CoTaskMemAlloc
CoTaskMemRealloc
CoTaskMemFree
CoUninitialize
OLEAUT32.dll #277
SHLWAPI.dll PathIsDirectoryW

Delayed Imports

1

Type RT_ICON
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.37439
MD5 c55fefcc685e22f92d4c7743723b4eec
SHA1 e8106941c42be0e56275514f555a989b02019280
SHA256 5c5143ec89c27dd7b9f716dc9396733040e104b2c9e650fed013d08598c5526e
SHA3 93d8b023626e5fa730f11ed06e880918408a0e71d829e59ceca059890f4c230a

2

Type RT_ICON
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29784
MD5 468c9b774610f916ba0994b74f452a4f
SHA1 d3cec550e8dd1d75c5953350d697982c3e88b018
SHA256 1cfd8fde82c138866ff83f5b58e58ac2a7474c9e7fcd7ee22031876667dc5963
SHA3 b7c934efa7e494b0a2d45b9aacc964f2804ccd3d1c75cc9d10ca9040b69fbbbd

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.74585
MD5 9069bab7a66353882a163b2d699aa128
SHA1 dc575e7dcc1f96bbcdcebde6bdc7dccc68a3ca83
SHA256 cb0821d269e24158be25954742d2aa0bcc60336d496e3e724df4b7959abfd06c
SHA3 2d92f8cb1b8df8c383148d0275479e8eac70d782bc8c1842d93d2b51ff08aa66

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.34586
MD5 108058a75c56a741177fcb59d1418a1d
SHA1 399c512ab818fc14a4007415aef42e598011d590
SHA256 2bcf170c94688e43c54a66e51593d4ebc235f236eb740f828132e44c8fac9fc4
SHA3 36dc398ccbcddbee968216920ecb9d429ac1540238a623c7c3689453d4a53ea8

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.37439
MD5 c55fefcc685e22f92d4c7743723b4eec
SHA1 e8106941c42be0e56275514f555a989b02019280
SHA256 5c5143ec89c27dd7b9f716dc9396733040e104b2c9e650fed013d08598c5526e
SHA3 93d8b023626e5fa730f11ed06e880918408a0e71d829e59ceca059890f4c230a

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25cb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89047
Detected Filetype PNG graphic file
MD5 504da9fe0a85dcfbb042b2d25c802a5b
SHA1 4c83f29ff85236b0f84c0a42abd65ad00e55e40b
SHA256 3d93e979eb6d2f7e3d7791e7b682b00825c2c343d57a494ca6807a2917dbf771
SHA3 61e137c4d1d5b6c252fd24941eaf1ab94272fbbeb35ef24502d364b1d8d4e6f8

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98936
MD5 29faf16a5adb2e2e85b7953d514c03d9
SHA1 774937fa656a8e08d0afc6ef23f6738215f0520b
SHA256 cd43dc38d125aaad91d6bb0079d86a7fecb0ba5abfb684d2b5e9223074fd06da
SHA3 c2bc436db3b59d43a7578dd7623b0a6aa3f8c73dd59c10bb75dbfe930739785c

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31752
MD5 b40552748d79fe50f4630d994df1287e
SHA1 23a55c0c1f24125a49153c09909b0ec50169281f
SHA256 3a16cf8e404cfc0284898a7acbb8373f938b96e4dcc0bc409e67d3e08aabdebe
SHA3 b3851522199d2d7742daa07ebbc5b076b7011c725fc73f888cf61ad6d7daa910

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29784
MD5 468c9b774610f916ba0994b74f452a4f
SHA1 d3cec550e8dd1d75c5953350d697982c3e88b018
SHA256 1cfd8fde82c138866ff83f5b58e58ac2a7474c9e7fcd7ee22031876667dc5963
SHA3 b7c934efa7e494b0a2d45b9aacc964f2804ccd3d1c75cc9d10ca9040b69fbbbd

129

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23743
MD5 bdfa3096331d0d4398827a2d1ac17180
SHA1 776bbf76d012cddff0ab2a65a138d8f68ff8f089
SHA256 13cb336a3d826cdcf1a413ac14d035566f9ec6279de1ac6b75735ffea2d371d7
SHA3 9850cdca9f98010a0cd6905b07739cd6bd50a9dd1e6bdda02ad96f45bb8eb542

131

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x190
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14837
MD5 01cb2575002ca38f3625984afebf0a6b
SHA1 e8294d79a437399366693041f2b7fff22562e075
SHA256 98880014d04a1f06a9bcbf776e465d06efe3151ee6ef1457f5e1ebc52a3f4699
SHA3 913000ae5376437da85081078eff0f4f91fd5b6cc4b1094656afb9fdd8918609

7 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x38
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7274
MD5 c6601ea304531c2f2874f5a55f2a6994
SHA1 bd9e0afe6900092e40790a3dd0870204ce57d2ce
SHA256 9ecf21f432dacc4b52e53ada639c657d37c1d0e4bf044a311322f23d6d14b034
SHA3 d077767e0ce8d22ef17f4e599efc02cbafe821e369afd19f8d4dc9c6898b8c66

107

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70819
Detected Filetype Icon file
MD5 ca465607d0c7c78d7761e09bd400467c
SHA1 65d9a2c894ad33b7a9762d2b5502a16785b6fb30
SHA256 65f885559968204078212b32d8260a00b602009709fa80f0bf1decafbcc24058
SHA3 cdd4a79def8701beb0228639581eb55b634f26e44970036c8369685ad8306c34

130

Type RT_GROUP_ICON
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.29162
Detected Filetype Icon file
MD5 a3ad4ff749ca380a62615d20ef5e6bac
SHA1 9984c58ed6d862e6ffc7bcd431171979aef8986e
SHA256 28ee2d813e2ece242814279b5c41d9c48336e290cd2663781aaf2e63f5413adc
SHA3 3db28396a740c36f795710cf61d5fa2f8d25258031841685ccbf19c3e7e06add

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x54e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37872
MD5 dc5767d5848e9163377bbd789d48591e
SHA1 cc48d48b92dbb42da0e010bcc7b764ceaef7851e
SHA256 4de3e4323505b874e0b0d3cf9fa2d65a58455956a50dc22ffba6a7622591d0fe
SHA3 fcf8d34f2283c2cef065148b1ed12c005953a479b63e51e1ce1fa4084b77eec1

String Table contents

bdzsfx
BDZSFX

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-May-03 03:14:06
Version 0.0
SizeofData 53
AddressOfRawData 0x39568
PointerToRawData 0x37d68
Referenced File c:\devel\Ark6\bin\bdzsfx.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x43f050
SEHandlerTable 0x43b4c0
SEHandlerCount 88

RICH Header

XOR Key 0x7cc67314
Unmarked objects 0
ASM objects (VS2008 SP1 build 30729) 28
C objects (VS2008 SP1 build 30729) 153
C++ objects (VS2008 SP1 build 30729) 63
C objects (VS2012 build 50727 / VS2005 build 50727) 3
Imports (VS2012 build 50727 / VS2005 build 50727) 17
Total imports 254
138 (VS2008 SP1 build 30729) 126
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

<-- -->