Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Mar-24 08:31:19 |
Detected languages |
English - United States
|
Comments | Please visit http://www.internetdownloadmanager.com |
CompanyName | Tonec Inc. |
FileDescription | Internet Download Manager installer |
FileVersion | 6, 42, 7, 1 |
InternalName | installer |
LegalCopyright | © 1999-2024. Tonec FZE. All rights reserved. |
LegalTrademarks | Internet Download Manager (IDM) |
OriginalFilename | installer.exe |
ProductName | Internet Download Manager installer |
ProductVersion | 6, 42, 7, 1 |
Info | Matching compiler(s): |
MASM/TASM - sig1(h)
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE is possibly packed. | Section .text is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Tonec Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
Safe | VirusTotal score: 0/72 (Scanned on 2024-03-29 05:20:46) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2024-Mar-24 08:31:19 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x3e00 |
SizeOfInitializedData | 0x6800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00004336 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x5000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xc000 |
SizeOfHeaders | 0x400 |
Checksum | 0xb90f11 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
MSVCRT.dll |
_controlfp
__set_app_type __p__fmode __p__commode _adjust_fdiv _wsplitpath __setusermatherr _initterm __getmainargs _acmdln exit _XcptFilter _exit free calloc memcpy _except_handler3 memchr memcmp _itoa strlen ??2@YAPAXI@Z ??3@YAXPAX@Z wcsstr strstr wcschr wcslen wcscat memset wcsncpy __CxxFrameHandler wcscpy |
---|---|
KERNEL32.dll |
GetStartupInfoA
GetFileSize CreateFileMappingA GetFileTime SetFileTime MapViewOfFile ExitThread UnmapViewOfFile FormatMessageA CreateFileW SetFilePointer WriteFile lstrlenA LocalFree GetCurrentProcess WaitForSingleObject GetExitCodeThread GetModuleFileNameW CreateProcessW CloseHandle CreateMutexA ExitProcess GetVersionExA GetTempPathW GetFileAttributesW CreateDirectoryW CreateThread LoadLibraryA FreeLibrary GetDiskFreeSpaceW GetProcAddress GetModuleHandleA GetLastError |
USER32.dll |
SetForegroundWindow
ShowWindow FindWindowA wsprintfA DestroyWindow MessageBoxA SetWindowTextA SendMessageA GetMessageA TranslateMessage DispatchMessageA wsprintfW PostQuitMessage CreateDialogParamA |
ADVAPI32.dll |
RegDeleteValueW
RegQueryValueExW RegOpenKeyExA RegCloseKey |
SHELL32.dll |
SHGetPathFromIDListW
SHBrowseForFolderW |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.42.7.1 |
ProductVersion | 6.42.7.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
Comments | Please visit http://www.internetdownloadmanager.com |
CompanyName | Tonec Inc. |
FileDescription | Internet Download Manager installer |
FileVersion (#2) | 6, 42, 7, 1 |
InternalName | installer |
LegalCopyright | © 1999-2024. Tonec FZE. All rights reserved. |
LegalTrademarks | Internet Download Manager (IDM) |
OriginalFilename | installer.exe |
ProductName | Internet Download Manager installer |
ProductVersion (#2) | 6, 42, 7, 1 |
Resource LangID | English - United States |
---|
XOR Key | 0x14221cb |
---|---|
Unmarked objects | 0 |
19 (8034) | 8 |
14 (7299) | 2 |
C objects (8047) | 11 |
Linker (8047) | 3 |
Total imports | 87 |
C++ objects (VC++ 6.0 SP5 build 8804) | 2 |
C objects (VC++ 6.0 SP5 build 8804) | 9 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |