Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Sep-01 13:41:29 |
Detected languages |
English - United States
|
CompanyName | VORACIOUS help Utility GmbH |
FileDescription | VORACIOUS help Utility |
FileVersion | 1.3.0.000 |
InternalName | VORACIOUShelpUtility.exe |
LegalCopyright | VORACIOUS help Utility GmbH |
OriginalFilename | VORACIOUShelpUtility.exe |
ProductName | VORACIOUS help Utility |
ProductVersion | 1.3.0.000 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Unusual section name found: .qtmetad |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: 10sIT Oy
Issuer: Sectigo Public Code Signing CA R36 |
Malicious | VirusTotal score: 3/71 (Scanned on 2022-09-23 03:01:55) |
DrWeb:
Adware.Downware.20090
Malwarebytes: Adware.SpecialSearchOffer Emsisoft: Application.Updater (A) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2022-Sep-01 13:41:29 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x654000 |
SizeOfInitializedData | 0x2e0800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x005D1BF4 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x655000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x93d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x93ec96 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
RemoveFontMemResourceEx
AddFontResourceExW GetTextFaceW ExtTextOutW BitBlt GetDIBits CreateRectRgn CreateDCW SelectObject SetTextAlign GdiFlush SetWorldTransform EnumFontFamiliesExW RemoveFontResourceExW OffsetRgn CreateFontIndirectW GetStockObject GetCharABCWidthsI DeleteDC AddFontMemResourceEx GetObjectW CombineRgn GetDeviceCaps CreateDIBSection GetTextMetricsW CreateCompatibleBitmap CreateBitmap SetTextColor GetRegionData GetTextExtentPoint32W GetOutlineTextMetricsW SelectClipRgn CreateCompatibleDC DeleteObject SetBkMode GetGlyphOutlineW GetCharABCWidthsW GetCharABCWidthsFloatW GetFontData SetGraphicsMode |
---|---|
OLEAUT32.dll |
SystemTimeToVariantTime
VariantChangeType VariantInit SysAllocStringLen SysFreeString SysStringLen SysAllocString |
IMM32.dll |
ImmReleaseContext
ImmGetContext ImmNotifyIME ImmSetCompositionWindow ImmGetCompositionStringW ImmGetDefaultIMEWnd ImmSetCandidateWindow |
WINMM.dll |
PlaySoundW
|
KERNEL32.dll |
GetThreadPriority
ReleaseSemaphore MoveFileW Sleep LoadLibraryA LeaveCriticalSection SetHandleCount InterlockedIncrement VirtualQuery GetSystemInfo GetVolumeInformationW GetTempPathW GlobalSize MultiByteToWideChar CloseHandle GetSystemDirectoryW FindFirstFileExW TlsGetValue SetStdHandle GetOEMCP PeekNamedPipe GetFileAttributesExW GetFileAttributesW InterlockedExchange GetModuleFileNameW ReleaseMutex QueryPerformanceCounter EnterCriticalSection MapViewOfFile GetLogicalDrives CreateSemaphoreW GetDriveTypeW CreateDirectoryW FreeEnvironmentStringsW GetFileSizeEx GetCurrentProcessId GetFileInformationByHandle FlushFileBuffers SetUnhandledExceptionFilter SetLastError GetConsoleMode GetTimeFormatA DecodePointer SetFilePointer TerminateProcess GetCPInfo GetFullPathNameW GetLocaleInfoA GetGeoInfoW UnhandledExceptionFilter GetTimeZoneInformation ResumeThread DeviceIoControl CreateFileW InterlockedDecrement TlsFree LocalFree CreateProcessW GlobalAlloc GetConsoleWindow GetCommandLineA SetEndOfFile GetModuleHandleA TlsSetValue CreateEventW GetFileSize FindFirstFileW GetSystemTimeAsFileTime HeapAlloc GetLocaleInfoW TerminateThread DuplicateHandle HeapSize GetLastError HeapCreate GetUserDefaultLangID RtlUnwind GlobalLock DeleteFileA SetThreadPriority OutputDebugStringA FindNextFileW SetFilePointerEx HeapSetInformation SetEvent CreateThread EnumSystemLocalesA GetProcAddress HeapFree LoadLibraryW FindClose GetConsoleCP GetDateFormatA GetUserDefaultLCID DeleteFileW InitializeCriticalSection GetLongPathNameW OutputDebugStringW IsProcessorFeaturePresent GetCurrentThread WriteConsoleW GetCurrentProcess GetUserGeoID GetEnvironmentStringsW GetProcessHeap GetCurrencyFormatW GetStdHandle ResetEvent IsValidCodePage SetEnvironmentVariableA EncodePointer ExpandEnvironmentStringsW CheckRemoteDebuggerPresent GetUserDefaultUILanguage SystemTimeToTzSpecificLocalTime GetCurrentDirectoryW GetVersionExW GetCommandLineW GlobalUnlock SleepEx GetModuleFileNameA CopyFileW VerSetConditionMask OpenProcess FreeLibrary RemoveDirectoryW GetACP lstrlenA ReadFile GetModuleHandleW WideCharToMultiByte VerifyVersionInfoW GetTickCount64 FileTimeToSystemTime IsValidLanguageGroup OpenFileMappingW HeapReAlloc FormatMessageW IsValidLocale ExitThread InitializeCriticalSectionAndSpinCount SetFileAttributesW FileTimeToLocalFileTime GetFileType SetErrorMode WaitForSingleObject GetTickCount VirtualFree GetStringTypeW CreateMutexW RaiseException GetDateFormatW DeleteCriticalSection ExitProcess GetCurrentThreadId UnmapViewOfFile CompareStringW GetTimeFormatW IsDebuggerPresent MoveFileExW GetLocalTime GetStartupInfoW CreateFileMappingW CreateFileA GetSystemTime LCMapStringW GetEnvironmentVariableA lstrcmpW TlsAlloc WaitForMultipleObjects QueryPerformanceFrequency WriteFile |
USER32.dll |
ChildWindowFromPointEx
GetParent TrackPopupMenuEx GetDoubleClickTime SetCursorPos DrawIconEx IsChild MessageBeep GetWindowThreadProcessId EndPaint GetClassInfoW CreateCaret ChangeClipboardChain BeginPaint TranslateMessage SetClipboardViewer SetMenuItemInfoW UnregisterClassW GetMonitorInfoW GetDC SetCaretPos MapVirtualKeyW GetKeyboardLayoutList PostMessageW GetDesktopWindow ScreenToClient SetParent GetClipboardFormatNameW SetFocus FlashWindowEx GetQueueStatus SetTimer GetForegroundWindow GetSysColor IsWindowVisible GetWindowLongW MessageBoxW GetWindowPlacement SetForegroundWindow GetWindowRect MsgWaitForMultipleObjectsEx ReleaseCapture UnhookWindowsHookEx CreateCursor GetSysColorBrush SystemParametersInfoW ReleaseDC SetWindowsHookExW GetMenu DispatchMessageW GetCursorInfo HideCaret ShowWindow SetCapture SetWindowLongW DestroyCaret EnableMenuItem CreateWindowExW EnumWindows RegisterClassExW SetWindowRgn GetAncestor SetWindowPos AdjustWindowRectEx GetCursorPos RealGetWindowClassW CallNextHookEx GetKeyboardState EnumDisplayMonitors DestroyWindow CharNextExA SendMessageW LoadIconW ToAscii GetAsyncKeyState GetFocus TrackMouseEvent MoveWindow SetWindowTextW RegisterClassW KillTimer GetSystemMetrics GetSystemMenu IsZoomed GetCapture GetUpdateRect GetWindowTextW CreateIconIndirect DestroyCursor RegisterClipboardFormatW DefWindowProcW GetMessageExtraInfo NotifyWinEvent RegisterWindowMessageW GetCaretBlinkTime ToUnicode IsIconic GetClientRect SetCursor InvalidateRect PeekMessageW GetIconInfo ClientToScreen DestroyIcon GetKeyState LoadImageW |
SHELL32.dll |
SHGetSpecialFolderPathW
SHBrowseForFolderW SHGetPathFromIDListW ShellExecuteW SHGetMalloc SHGetFileInfoW |
ole32.dll |
OleInitialize
CoUninitialize CoInitialize RevokeDragDrop OleIsCurrentClipboard DoDragDrop OleFlushClipboard ReleaseStgMedium CoTaskMemAlloc OleGetClipboard RegisterDragDrop CoLockObjectExternal OleSetClipboard CoGetMalloc CoCreateInstance CoCreateGuid CoTaskMemFree OleUninitialize |
ADVAPI32.dll |
RegSetValueExW
RegEnumValueW RegQueryInfoKeyW RegDeleteKeyW RegOpenKeyExW RegCloseKey CryptDestroyHash OpenProcessToken GetTokenInformation GetLengthSid RegEnumKeyExW CryptGenRandom RegQueryValueExW RegFlushKey CryptCreateHash CryptEncrypt CryptDestroyKey CryptHashData CryptGetHashParam RegDeleteValueW FreeSid CopySid CryptAcquireContextW RegCreateKeyExW CryptImportKey CryptReleaseContext |
WS2_32.dll |
htons
getsockopt getpeername socket connect WSASetLastError WSAIoctl bind accept listen htonl sendto recvfrom select __WSAFDIsSet ioctlsocket gethostname ntohs getsockname setsockopt WSAEventSelect recv WSACloseEvent getaddrinfo WSAEnumNetworkEvents WSAWaitForMultipleEvents freeaddrinfo WSAResetEvent WSAStartup WSACleanup WSAGetLastError send closesocket WSAAsyncSelect WSACreateEvent |
CRYPT32.dll |
CertOpenStore
CryptDecodeObjectEx CertGetCertificateChain PFXImportCertStore CertFindExtension CertFreeCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CertEnumCertificatesInStore CertFreeCertificateContext CertCloseStore CertFindCertificateInStore CryptStringToBinaryW CertAddCertificateContextToStore CryptQueryObject |
WLDAP32.dll |
#117
#216 #73 #301 #167 #79 #142 #46 #27 #127 #147 #133 #26 #208 #145 #219 #14 #41 |
Ordinal | 1 |
---|---|
Address | 0x511b60 |
Ordinal | 2 |
---|---|
Address | 0x511e60 |
Ordinal | 3 |
---|---|
Address | 0x511e60 |
Ordinal | 4 |
---|---|
Address | 0x4dea40 |
Ordinal | 5 |
---|---|
Address | 0x4de990 |
Ordinal | 6 |
---|---|
Address | 0x4dea60 |
Ordinal | 7 |
---|---|
Address | 0x4c2ad0 |
Ordinal | 8 |
---|---|
Address | 0x4c2ac0 |
Ordinal | 9 |
---|---|
Address | 0x4c2ac0 |
Ordinal | 10 |
---|---|
Address | 0x4c1ae0 |
Ordinal | 11 |
---|---|
Address | 0x4c0580 |
Ordinal | 12 |
---|---|
Address | 0x4c07a0 |
Ordinal | 13 |
---|---|
Address | 0x4c06d0 |
Ordinal | 14 |
---|---|
Address | 0x4c2310 |
Ordinal | 15 |
---|---|
Address | 0x4c2620 |
Ordinal | 16 |
---|---|
Address | 0x4c2540 |
Ordinal | 17 |
---|---|
Address | 0x4c0500 |
Ordinal | 18 |
---|---|
Address | 0x4c1a50 |
Ordinal | 19 |
---|---|
Address | 0x4c03d0 |
Ordinal | 20 |
---|---|
Address | 0x4c04d0 |
Ordinal | 21 |
---|---|
Address | 0x4c0540 |
Ordinal | 22 |
---|---|
Address | 0x4c2650 |
Ordinal | 23 |
---|---|
Address | 0x4be950 |
Ordinal | 24 |
---|---|
Address | 0x4c01f0 |
Ordinal | 25 |
---|---|
Address | 0x4bff30 |
Ordinal | 26 |
---|---|
Address | 0x4c0060 |
Ordinal | 27 |
---|---|
Address | 0x4be730 |
Ordinal | 28 |
---|---|
Address | 0x4be7e0 |
Ordinal | 29 |
---|---|
Address | 0x4c0370 |
Ordinal | 30 |
---|---|
Address | 0x4be800 |
Ordinal | 31 |
---|---|
Address | 0x4be620 |
Ordinal | 32 |
---|---|
Address | 0x4be6a0 |
Ordinal | 33 |
---|---|
Address | 0x4bff80 |
Ordinal | 34 |
---|---|
Address | 0x4c00e0 |
Ordinal | 35 |
---|---|
Address | 0x4c01c0 |
Ordinal | 36 |
---|---|
Address | 0x4c0340 |
Ordinal | 37 |
---|---|
Address | 0x4de8e0 |
Ordinal | 38 |
---|---|
Address | 0x511210 |
Ordinal | 39 |
---|---|
Address | 0x511200 |
Ordinal | 40 |
---|---|
Address | 0x5111f0 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.3.0.0 |
ProductVersion | 1.3.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | VORACIOUS help Utility GmbH |
FileDescription | VORACIOUS help Utility |
FileVersion (#2) | 1.3.0.000 |
InternalName | VORACIOUShelpUtility.exe |
LegalCopyright | VORACIOUS help Utility GmbH |
OriginalFilename | VORACIOUShelpUtility.exe |
ProductName | VORACIOUS help Utility |
ProductVersion (#2) | 1.3.0.000 |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0xce7000 |
---|---|
EndAddressOfRawData | 0xce7002 |
AddressOfIndex | 0xce45b0 |
AddressOfCallbacks | 0xa55834 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0xce03c8 |
SEHandlerTable | 0xcbba20 |
SEHandlerCount | 1202 |
XOR Key | 0xb2712396 |
---|---|
Unmarked objects | 0 |
C objects (VS 2015/2017/2019 runtime 29118) | 8 |
ASM objects (VS 2015/2017/2019 runtime 29118) | 3 |
C++ objects (VS 2015/2017/2019 runtime 29118) | 19 |
Imports (VS 2015/2017/2019 runtime 29118) | 7 |
Imports (VS2008 SP1 build 30729) | 32 |
Total imports | 451 |
C++ objects (LTCG) (VS2019 Update 8 (16.8.4) compiler 29336) | 3 |
Exports (VS2019 Update 8 (16.8.4) compiler 29336) | 1 |
Resource objects (VS2019 Update 8 (16.8.4) compiler 29336) | 1 |
Linker (VS2019 Update 8 (16.8.4) compiler 29336) | 1 |