Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Borland Delphi 3 -> Portions Copyright (c) 1983,97 Borland (h) |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Suspicious | VirusTotal score: 2/72 (Scanned on 2020-06-30 17:31:41) |
Zillya:
Downloader.Agent.Win32.291467
MaxSecure: Trojan.Malware.300983.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x47800 |
SizeOfInitializedData | 0xe000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00048454 (Section: CODE) |
BaseOfCode | 0x1000 |
BaseOfData | 0x49000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 1.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x5c000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
---|---|
user32.dll |
GetKeyboardType
LoadStringA MessageBoxA |
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
oleaut32.dll |
VariantChangeTypeEx
VariantCopyInd VariantClear SysStringLen SysFreeString SysReAllocStringLen SysAllocStringLen |
kernel32.dll (#2) |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
kernel32.dll (#3) |
GetCurrentThreadId
DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection VirtualFree VirtualAlloc LocalFree LocalAlloc InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenA lstrcpyA LoadLibraryExA GetThreadLocale GetStartupInfoA GetModuleFileNameA GetLocaleInfoA GetLastError GetCommandLineA FreeLibrary ExitProcess WriteFile SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
gdi32.dll |
UnrealizeObject
StretchBlt SetWindowOrgEx SetWinMetaFileBits SetViewportOrgEx SetTextColor SetStretchBltMode SetROP2 SetPixel SetEnhMetaFileBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SelectPalette SelectObject SaveDC RestoreDC Rectangle RectVisible RealizePalette PlayEnhMetaFile PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsA GetTextExtentPointA GetSystemPaletteEntries GetStockObject GetPixel GetPaletteEntries GetObjectA GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits ExtTextOutA ExcludeClipRect EnumFontsA EnumFontFamiliesExA DeleteObject DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateHalftonePalette CreateFontIndirectA CreateDIBitmap CreateDIBSection CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileA BitBlt |
user32.dll (#2) |
GetKeyboardType
LoadStringA MessageBoxA |
ole32.dll |
IsEqualGUID
|
comctl32.dll |
ImageList_SetIconSize
ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_SetDragCursorImage ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Remove ImageList_DrawEx ImageList_Draw ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControls |
Shift+ |
Ctrl+ |
Alt+ |
Value must be between %d and %d |
Unable to insert a line |
Clipboard does not support Icons |
Bits index out of range |
Invalid data type for '%s' |
Failed to set data for '%s' |
Failed to get data for '%s' |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
Yes to &All |
BkSp |
Tab |
Esc |
Enter |
Space |
PgUp |
PgDn |
End |
Home |
Left |
Up |
Right |
Down |
Ins |
Del |
Icons |
Bitmaps |
Warning |
Error |
Information |
Confirm |
&Yes |
&No |
OK |
Cancel |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
OK |
Cancel |
&Yes |
&No |
&Help |
&Close |
&Ignore |
&Retry |
Abort |
&All |
Cannot drag a form |
Metafiles |
Enhanced Metafiles |
Invalid image size |
Invalid ImageList |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Cannot make a visible window modal |
%s property out of range |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
A component named %s already exists |
''%s'' is not a valid component name |
A class named %s already exists |
Invalid property value |
Invalid property path |
Property does not exist |
Property is read-only |
Error reading %s%s%s: %s |
Ancestor for '%s' not found |
Bitmap image is not valid |
Icon image is not valid |
Metafile is not valid |
Cannot change the size of an icon |
Unsupported clipboard format |
Out of system resources |
Canvas does not allow drawing |
Saturday |
Cannot assign a %s to a %s |
Cannot create file %s |
Cannot open file %s |
Stream read error |
Stream write error |
Out of memory while expanding memory stream |
Can't write to a read-only resource stream |
Class %s not found |
Invalid stream format |
Resource %s not found |
List index out of bounds (%d) |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
Operation not allowed on sorted string list |
String list does not allow duplicates |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
Error creating variant array |
Variant is not an array |
Variant array index out of bounds |
External exception %x |
Assertion failed |
Interface not supported |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
Win32 Error. Code: %d. |
%s |
A Win32 API function failed |
Jan |
Feb |
Mar |
Apr |
May |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Invalid variant type conversion |
Invalid variant operation |
Variant method calls not supported |
Read |
Write |
'%s' is not a valid integer value |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
StartAddressOfRawData | 0x44e000 |
---|---|
EndAddressOfRawData | 0x44e010 |
AddressOfIndex | 0x44a4d0 |
AddressOfCallbacks | 0x44f010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |