| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Oct-02 05:04:04 |
| Detected languages |
English - United States
|
| Comments | This installation was built with Inno Setup. |
| CompanyName | |
| FileDescription | Last Epoch Beneath Ancient Skies Update v1.3.6 Setup |
| FileVersion | |
| LegalCopyright | |
| ProductName | Last Epoch Beneath Ancient Skies Update v1.3.6 |
| ProductVersion |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .itext |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
8972847 bytes of data starting at offset 0x25600.
The overlay data has an entropy of 7.94611 and is possibly compressed or encrypted. Overlay data amounts for 98.3225% of the executable. |
| Malicious | VirusTotal score: 29/72 (Scanned on 2026-02-09 19:09:24) |
AVG:
FileRepMalware [Misc]
Avast: FileRepMalware [Misc] Avira: TR/AVI.Agent.lhnkx CTX: exe.trojan.crack CrowdStrike: win/grayware_confidence_100% (D) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win32/HackTool.Crack.ES potentially unsafe application Elastic: malicious (high confidence) F-Secure: Trojan.TR/AVI.Agent.lhnkx Fortinet: Riskware/Crack Google: Detected Ikarus: Trojan-Spy.Agent K7AntiVirus: Unwanted-Program ( 005ce22d1 ) K7GW: Unwanted-Program ( 005ce22d1 ) Lionic: Trojan.Win32.Crack.4!c MaxSecure: Trojan.Malware.510284395.susgen McAfeeD: ti!6B054F076116 Microsoft: Trojan:Win32/Kepavll!rfn Sangfor: Trojan.Win32.Agent.Vdf2 Sophos: Mal/Generic-S Symantec: Trojan.Gen.2 TrellixENS: Artemis!6D6804BFAE6D TrendMicro-HouseCall: TROJ_GEN.R002H01K125 Varist: W32/ABTrojan.VTRY-4475 VirIT: Trojan.Win32.DelphGen.JBW Webroot: Win.Hacktool.Gen alibabacloud: HackTool:Win/Crack.EB |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 8 |
| TimeDateStamp | 2012-Oct-02 05:04:04 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x15000 |
| SizeOfInitializedData | 0x10200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00016478 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x17000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x30000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
| kernel32.dll |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| kernel32.dll (#2) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| user32.dll (#2) |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
| kernel32.dll (#3) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| comctl32.dll |
InitCommonControls
|
| kernel32.dll (#4) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| advapi32.dll (#3) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Invalid file name - %s |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Monitor support function not initialized |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Out of memory |
| I/O error %d |
| File not found |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.0.0.0 |
| ProductVersion | 0.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Comments | This installation was built with Inno Setup. |
| CompanyName | |
| FileDescription | Last Epoch Beneath Ancient Skies Update v1.3.6 Setup |
| FileVersion (#2) | |
| LegalCopyright | |
| ProductName | Last Epoch Beneath Ancient Skies Update v1.3.6 |
| ProductVersion (#2) |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x41f000 |
|---|---|
| EndAddressOfRawData | 0x41f008 |
| AddressOfIndex | 0x4177b4 |
| AddressOfCallbacks | 0x420010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.