7edd4530e8936584892f4be18d3619c2b530a231297b2c78421bbd866e1ef858

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2007-Mar-11 06:13:54
Detected languages German - Germany
Comments only free for private use
CompanyName Hessing
FileDescription runasspc
FileVersion 2, 0, 7, 0
InternalName runasspc
LegalCopyright Copyright © 2005-2007
LegalTrademarks www.robotronic.de
OriginalFilename runasspc.exe
ProductName runasspc
ProductVersion 2, 0, 7, 0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++
Microsoft Visual C++ v6.0
Microsoft Visual C++ v5.0/v6.0 (MFC)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • domainname.com
  • robotronic.de
  • www.robotronic.de
Info Cryptographic algorithms detected in the binary: Uses constants related to AES
Malicious The PE contains functions mostly used by malware. Possibly launches other programs:
  • CreateProcessWithLogonW
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetLogicalDriveStringsA
Safe VirusTotal score: 0/70 (Scanned on 2023-07-01 06:07:29) All the AVs think this file is safe.

Hashes

MD5 610c66e253a481c5795ece5db6e6825f
SHA1 e613fec885e1623fc3733700a0f9562f07d9af93
SHA256 7edd4530e8936584892f4be18d3619c2b530a231297b2c78421bbd866e1ef858
SHA3 25c8ee8b007970583762e3c26a5cf2877b9c26693cedba5c29ad4e28c645da8e
SSDeep 768:tUv8K//32Ig5zfmgN9XL+RkHoynwqZEWUNRInYOGhBaho9S4AJKqBz8MZhUG1W2:2fHpCnL+eH5REWJGN9S4A3AyvCa
Imports Hash 622aaaca29c2586f069ebe31ed5426bf

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2007-Mar-11 06:13:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x9000
SizeOfInitializedData 0x8000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00007F42 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x12000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 07ec37afdecc38eb8b8910364a5d09f4
SHA1 a0b8582a26811ecb9be153eab8b445e4bc8a734d
SHA256 35f0de0d021f508032dfeab85987cc7fcea7ebe50162804a6bab2f47ac3af9cc
SHA3 55f740a01eb539b842d21a1bd35d22bf8f6d15e6a29db6bd666a6ff23560fd2d
VirtualSize 0x80c2
VirtualAddress 0x1000
SizeOfRawData 0x9000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.7253

.rdata

MD5 fafd29e38a3392074f0e1df327bdcd45
SHA1 f6f76613389702c5743826a85d23997a7655bc7b
SHA256 9a23c81144942ddfaa7118235c134896065f9e3f6cbec20bd62cea947f6454bd
SHA3 0058caff0b36ab9e1f8b5fad1a5553442918efdd9155f270c54c17d658e3ec67
VirtualSize 0x55f2
VirtualAddress 0xa000
SizeOfRawData 0x6000
PointerToRawData 0xa000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.42676

.data

MD5 4a52bc1fe1091c85fe22700174d10528
SHA1 8b40e2d2893425eda8c8c71793c70eba992f1863
SHA256 d02a47792a7ce8f44fb5745fb18d35656e79e807adce7a39d28895197b72102b
SHA3 2ee0ead3cb74645f49abe4e52ed10650db1fe46f001780debf168d8c010e4630
VirtualSize 0xd14
VirtualAddress 0x10000
SizeOfRawData 0x1000
PointerToRawData 0x10000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.2674

.rsrc

MD5 1129878dbe9e5e756c715ec6628dcf8b
SHA1 bed7627cba023b5bca00454f633c8d5e435827f6
SHA256 ee68fcacd94695e47402897783e9199417f934058a703424fa7c93df5f1681d5
SHA3 096eb54a0e490ec227c06cb2e0ac4907d3a4e43699c63b00409277c83a63545f
VirtualSize 0xc28
VirtualAddress 0x11000
SizeOfRawData 0x1000
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.50493

Imports

KERNEL32.dll lstrlenA
FormatMessageA
GetLastError
GetModuleHandleA
GetCommandLineA
GetLogicalDriveStringsA
GetCurrentDirectoryA
LocalAlloc
GetCurrentProcess
GetComputerNameA
MultiByteToWideChar
GetEnvironmentVariableA
ReadFile
GetFileSize
CreateFileA
LocalFree
CloseHandle
ExitProcess
USER32.dll wsprintfA
MessageBoxA
EnableWindow
ADVAPI32.dll OpenProcessToken
CreateProcessWithLogonW
USERENV.dll CreateEnvironmentBlock
DestroyEnvironmentBlock
MFC42.DLL #536
#6662
#4278
#4277
#5683
#5265
#4376
#4998
#2514
#6052
#4078
#1775
#4407
#5241
#2385
#5163
#6374
#4353
#5280
#3798
#4837
#4441
#2648
#2055
#6376
#3749
#5065
#1727
#5261
#2446
#2124
#5277
#2982
#3147
#3259
#4465
#3136
#3262
#2985
#3081
#2976
#3830
#3831
#3825
#3079
#4080
#4627
#4425
#3597
#800
#641
#540
#324
#825
#4234
#926
#535
#860
#6199
#3092
#4710
#2379
#4853
#561
#815
#941
#924
#939
#922
#2818
#858
#6877
#537
#1575
#5651
#3127
#3616
#3663
#6153
#6392
#6648
#940
#1997
#5448
#823
#3318
#3337
#3789
#798
#5194
#350
#533
#6663
#6778
#4129
#3790
#2915
#5572
MSVCRT.dll ??1exception@@UAE@XZ
??0exception@@QAE@ABQBD@Z
_CxxThrowException
rand
_ftol
time
??1type_info@@UAE@XZ
__dllonexit
??0exception@@QAE@ABV0@@Z
_exit
_XcptFilter
exit
_itoa
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
_mbscmp
__CxxFrameHandler
_onexit
__p___initenv
MSVCP60.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
??1_Winit@std@@QAE@XZ
??0_Winit@std@@QAE@XZ
??1Init@ios_base@std@@QAE@XZ
??0Init@ios_base@std@@QAE@XZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
??6std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@0@AAV10@PBD@Z

Delayed Imports

1

Type RT_ICON
Language German - Germany
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.94792
MD5 56e66b55de59af042b6bda0910ce4faf
SHA1 570e96d95da46e2921b9829f9a841823062086f6
SHA256 cb136ec90a2cb47fdd23b2d95a29589d48e20afc47751b8bbf668e793b398918
SHA3 73a272c2ccc45d9472441405d4ecde225fcbc0573bf7131f80fbab03fdaf9f4d

105

Type RT_DIALOG
Language German - Germany
Codepage UNKNOWN
Size 0x114
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05863
MD5 55363afed919d54640f6db10bad09e4d
SHA1 ca51ea06edce918e3c136760e26085e9edcc2762
SHA256 151c53c545d47e34f227e53ddc1f956e5beccdc33b982d2229ad8d207b3f0f47
SHA3 149316f3c38676a15819d366a6a25e60e340ff42a49ed985ce8c41a7bbc14f04

1 (#2)

Type RT_STRING
Language German - Germany
Codepage UNKNOWN
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.24891
MD5 2bc78a94b7a75a14fbdc93721f7da7a4
SHA1 a650aa0315fa1176a8337cf1fc9dc61130d25f46
SHA256 5f78071f3e8186d3f7009e5ab0e7a30726bea652b4f0e0331182549e8ee3c175
SHA3 37b2eb7016c681fbff3b7001ac2ac49fe5eb40e76c007a4f99daec9f994b81ab

103

Type RT_GROUP_ICON
Language German - Germany
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

1 (#3)

Type RT_VERSION
Language German - Germany
Codepage UNKNOWN
Size 0x65c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36112
MD5 40dcef5f2d81b2720336f4a767e97d26
SHA1 a444a0b30792dc7b60b020e6daa2dfceafc942e1
SHA256 31009a813c179a037ed1c0608a54c4c4ba33626d0049d915350bd58e735c58d1
SHA3 8e31dbf0f18f4825404e7d6aed38e5dec6a27856eda5f3e57c57044eed986ee6

String Table contents

RUNASSPC

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.0.7.0
ProductVersion 2.0.7.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments only free for private use
CompanyName Hessing
FileDescription runasspc
FileVersion (#2) 2, 0, 7, 0
InternalName runasspc
LegalCopyright Copyright © 2005-2007
LegalTrademarks www.robotronic.de
OriginalFilename runasspc.exe
ProductName runasspc
ProductVersion (#2) 2, 0, 7, 0
Resource LangID German - Germany

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x95ac5401
Unmarked objects 0
12 (7291) 1
14 (7299) 1
C++ objects (8047) 1
C objects (8047) 11
Linker (8047) 4
C++ objects (8569) 2
Linker (8569) 2
Total imports 163
Imports (VS2003 (.NET) build 4035) 9
C++ objects (VC++ 6.0 SP5 build 8804) 5
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

Leave a comment

No comments yet.