73e82428f1687e1af62fea1ab16bd5255b5300c336510d3168f06f28fb04f49a

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2007-Feb-05 06:24:52
Detected languages Korean - Korea

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
InstallShield 2000
MASM/TASM - sig2(h)
Microsoft Visual C++
Microsoft Visual C++ v6.0
Microsoft Visual C++ v5.0/v6.0 (MFC)
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 3454e617fd9c92f937a97c7c78fb445a 🔍
SHA1 16967e600b2a57308d72913b445c315f0e5a229d 🔍
SHA256 73e82428f1687e1af62fea1ab16bd5255b5300c336510d3168f06f28fb04f49a 🔍
SHA3 415a7142b27f39f360a95a54cd3d0b70090114403bb907684c4a2d2e64c0888e 🔍
SSDeep 24576:LUZFfa/nnliNAXaJufRfT0FY7K6a6Tc14s:8Fi/n4NJul0FY46T 🔍
Imports Hash 546ef461999cc6d9847c453e18683c11 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2007-Feb-05 06:24:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0xd3000
SizeOfInitializedData 0x65000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000BF860 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xd4000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x139000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x3e8000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 87b882af9fdaacee5c6c55816736f5ad 🔍
SHA1 fc8181f94f1218311d3b74147536431f3dee67ac 🔍
SHA256 f4144abefc4adaafb15637350f0bc72ce1fb4cf19d5fd052d45ab9288943d004 🔍
SHA3 ec5d433bd8405dd847925b0a45e7d8ff5e7e5af11f21c5aa8e434e72d422263b 🔍
VirtualSize 0xd2475
VirtualAddress 0x1000
SizeOfRawData 0xd3000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.28971

.rdata

MD5 7d43f0d6e41ad83baf76c55c003cafbf 🔍
SHA1 e3214728dd607c13bc7656ece9f6692ffe8526ba 🔍
SHA256 ef0a9fc6377ffd01a5b941e33f6eec6363896cb3d9501ea93f9a146f2f701a1e 🔍
SHA3 8ab961182d50bd4782ff06ea9213097afb78086e4efddd83e470e462272df8f4 🔍
VirtualSize 0x3440
VirtualAddress 0xd4000
SizeOfRawData 0x4000
PointerToRawData 0xd4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.39728

.data

MD5 61dcf26da6e72c04076adb0efd0122dd 🔍
SHA1 3bcd4b4cc55ec66d6ac28e9ced52da5c10388099 🔍
SHA256 c8f29345fdccce85b9f1e94587f92ff61c5d66e593d465ebdc17744506941622 🔍
SHA3 1ebe50b04ad5c8b5ca3eaf8d17f1f9246fad7c1a7934dcbf062bec9826bb93ac 🔍
VirtualSize 0x5e6f8
VirtualAddress 0xd8000
SizeOfRawData 0x5b000
PointerToRawData 0xd8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.58182

.rsrc

MD5 94cd5cdba321099b0c241b9f94ab4b2b 🔍
SHA1 829b3ee2367984668b7a3f139117218b0e51eaad 🔍
SHA256 531e95fcce26368571716b495e6cafb261215e3a15f5cc76e476832cef28ef03 🔍
SHA3 3b48085dd57505738d32c1919fa89d8d0dd4d09e368bd5dd6cb337f634592731 🔍
VirtualSize 0x10e0
VirtualAddress 0x137000
SizeOfRawData 0x2000
PointerToRawData 0x133000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.88342

Imports

KERNEL32.dll SetFilePointer
WriteConsoleA
lstrlenA
GetTickCount
CreateThread
CreateEventA
InitializeCriticalSection
DeleteCriticalSection
CloseHandle
WaitForSingleObject
SetEvent
LeaveCriticalSection
EnterCriticalSection
ExitThread
ResetEvent
WaitForMultipleObjects
FileTimeToSystemTime
FreeConsole
ReadConsoleInputA
AllocConsole
GetStdHandle
GetCurrentProcessId
GetCurrentDirectoryA
FreeLibrary
GetProcAddress
GetLastError
LoadLibraryA
SetLastError
GetEnvironmentVariableA
GetModuleFileNameA
GetCurrentThread
GetCurrentProcess
Sleep
GetModuleHandleA
InterlockedExchange
SetEnvironmentVariableA
CompareStringW
CompareStringA
RaiseException
SetEndOfFile
LCMapStringW
LCMapStringA
GetOEMCP
GetACP
GetCPInfo
CreateFileA
FlushFileBuffers
SetStdHandle
GetStringTypeW
GetStringTypeA
MultiByteToWideChar
InterlockedDecrement
HeapValidate
GetFileType
SetHandleCount
GetEnvironmentStringsW
GetStartupInfoA
InterlockedIncrement
FreeEnvironmentStringsA
UnhandledExceptionFilter
FreeEnvironmentStringsW
HeapCreate
HeapDestroy
VirtualAlloc
VirtualFree
GetVersionExA
HeapReAlloc
HeapAlloc
GetLocalTime
HeapFree
CreateDirectoryA
WideCharToMultiByte
ReadFile
TlsAlloc
IsBadCodePtr
SetUnhandledExceptionFilter
GetTimeZoneInformation
GetSystemTime
RtlUnwind
IsBadWritePtr
IsBadReadPtr
GetEnvironmentStrings
DebugBreak
ExitProcess
TlsGetValue
GetCommandLineA
GetVersion
GetCurrentThreadId
TlsSetValue
WriteFile
OutputDebugStringA
TerminateProcess
USER32.dll EndDialog
SetWindowLongA
CreateDialogParamA
ShowWindow
SendMessageA
GetWindowTextA
GetWindow
SetFocus
CallWindowProcA
SystemParametersInfoA
GetActiveWindow
MessageBoxA
GetDlgItem
SetWindowTextA
GetMessageA
TranslateMessage
DispatchMessageA
PostMessageA
wsprintfA
ole32.dll CoCreateInstance
CoInitialize
ODBC32.dll #68
#12
#19
#72
#41
#48
#49
#18
#76
#30
#43
#4
#13
#45
#16
#11
#9
#10
#26
#24
#75
#39
#7
#31
#21
ODBCCP32.dll #6

Delayed Imports

101

Type RT_DIALOG
Language Korean - Korea
Codepage UNKNOWN
Size 0x212
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29019
MD5 430911dda02508c21ab8a7ea405460bf 🔍
SHA1 c07f6da7581338bd431fe85692046c2b2d4ec9ed 🔍
SHA256 4d60e8e247bab479637e916a6c7caf8e4354e2c65f0aff099f4f24492f3cdfa9 🔍
SHA3 6434472d99d735b87d1d7bb97fa22ade966ca483f86ab024af5fbd1b1c499273 🔍

102

Type RT_DIALOG
Language Korean - Korea
Codepage UNKNOWN
Size 0xe36
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09124
MD5 186641d21aa3aebd41f33ffbd8304a5b 🔍
SHA1 bb2fdd50522e790676f006486173bc957ee0fe08 🔍
SHA256 06954de295fc34c7c977d220c6df9e7202bd7e3fa53ed91b422ac5378cd6c4a1 🔍
SHA3 2de3979ee0bb20497ed1fc3e50c623bcab9b157fad1b92de2303a8c2b5fbf746 🔍

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xba612929
Unmarked objects 0
C++ objects (8047) 1
12 (7291) 1
C++ objects (VS98 SP6 build 8804) 10
14 (7299) 32
C objects (VS98 SP6 build 8804) 139
19 (8152) 11
Total imports 148
C++ objects (VS98 SP6 build 8804) (#2) 55
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

Leave a comment

No comments yet.