88fda2ef328a6636b00500d87c97bb67

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Feb-02 13:14:20
Detected languages English - United States
FileDescription A helper tool for checking if your product feeds fulfill the standard requirements for the integration with the Digitec Galaxus online shops
FileVersion 1.0.1
InternalName Feedchecker
OriginalFilename Feedchecker
ProductName Feedchecker
ProductVersion 1.0.2
Language English / German
LegalTrademarks

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • formats.info
  • io.formats.info
  • pandas.io.formats.info
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Suspicious The file contains overlay data. 9562210 bytes of data starting at offset 0x4d200.
The overlay data has an entropy of 7.99077 and is possibly compressed or encrypted.
Overlay data amounts for 96.802% of the executable.
Malicious VirusTotal score: 10/73 (Scanned on 2024-06-07 03:06:19) APEX: Malicious
Bkav: W32.Common.292FDCB6
Cylance: Unsafe
Fortinet: W32/PossibleThreat
MaxSecure: Trojan.Malware.121218.susgen
McAfee: Artemis!88FDA2EF328A
McAfeeD: ti!B3A010A3D9E0
Paloalto: generic.ml
Panda: Trj/Chgt.AD
Skyhigh: BehavesLike.Win64.Generic.tc

Hashes

MD5 88fda2ef328a6636b00500d87c97bb67
SHA1 7dc82ce3d05415070585f57ed7d8f57f28a13a84
SHA256 b3a010a3d9e0655dfb3f5ccaac16efdfb6c2ba015327826125682ff8308fa0b8
SHA3 24beb39e0c6be804caa12df3e10bdaddc86b2917438d1c42023289f43b06266d
SSDeep 196608:Bc08nM2MhwQdik9fI/s0v/sSNgaomGFtXP42CYufRg0:HQkc/1gaOWv60
Imports Hash 1af6c885af093afc55142c2f1761dbe8

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Feb-02 13:14:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x29e00
SizeOfInitializedData 0x23000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000C1F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x54000
SizeOfHeaders 0x400
Checksum 0x97876d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x1e8480
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 62616acf257019688180f494b4eb78d4
SHA1 012f637ebf64da68093faf41b0f2c939dc5902af
SHA256 7568a0023ac06e947f3977db238017d17e80aa694b2fca2e2177a27a9d9b7c73
SHA3 136fb604286631346b13055e41f751ac4ced839cb08e916296bb3889740f75fb
VirtualSize 0x29c90
VirtualAddress 0x1000
SizeOfRawData 0x29e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4831

.rdata

MD5 1659d4d274904a15ba34fedf63b7a2a2
SHA1 e65addd67e50129dc4257139f38d21bd3cbe51b1
SHA256 035b63ff0355feee7b9262f85e44b2fc49ebb3dbc49f92885317884312da68e5
SHA3 876982670566cbc59df5decfddc95635c0afe9f0eb26eaeb58a50c23a53aefde
VirtualSize 0x12bf4
VirtualAddress 0x2b000
SizeOfRawData 0x12c00
PointerToRawData 0x2a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.83505

.data

MD5 99d84572872f2ce8d9bdbc2521e1966e
SHA1 1745c4ccf67c876d978058025646a6fc708919e0
SHA256 38832a73d4f0bee667066837ff09b7b2d61d6a52f95f8ff67f31699d6259cd20
SHA3 58fe1fb70b3e9e03cced62aeeb962d64068bf67d1a451d70017c8ebd326cad3a
VirtualSize 0x3338
VirtualAddress 0x3e000
SizeOfRawData 0xe00
PointerToRawData 0x3ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.82717

.pdata

MD5 39f0a7d8241a665fc55289b5f9977819
SHA1 9434c071dd5d0d893bb3b1ff7938635f2b8e7b78
SHA256 a4522af33f823a5501b7449a4955fb1300d48ad82dedff0be9bc5991bbef8c6a
SHA3 5b395d7accf8a4dbdd5dfeffeadb07309e3c735855df1796f0a093c772ff8118
VirtualSize 0x22a4
VirtualAddress 0x42000
SizeOfRawData 0x2400
PointerToRawData 0x3dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.31639

_RDATA

MD5 624222957a635749731104f8cdf6f9b7
SHA1 d41e40498bc70e400e76e7a3585431f4145e40b9
SHA256 4bb815b5aeb6d4a8c6d79f03aca77fd8e5932d67665a11e808b174b714eef724
SHA3 bdae1a4bc0c2bd0d06a72a76c9a599ea3afe7dfa004e0b46277675f1ec38068e
VirtualSize 0x15c
VirtualAddress 0x45000
SizeOfRawData 0x200
PointerToRawData 0x40000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.83327

.rsrc

MD5 f315371f0eee207a3cda66fbffbb675a
SHA1 499123aaae5879a9bf2fbb69f832d5516dd04567
SHA256 1c760c81753ec3a3fb40fd9649b9617b883ff816257c3be2770b35f717d8a65b
SHA3 1f2a34f0f0357b0db5b2925ff738cb810dcf0c6147ee1dc264f2bc2670de76fd
VirtualSize 0xc6b8
VirtualAddress 0x46000
SizeOfRawData 0xc800
PointerToRawData 0x40200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.05588

.reloc

MD5 4138d4447f190c2657ec208ef31be551
SHA1 41f776fbf46111f4aac8e7ff1e7fa89541eda087
SHA256 6d0446dfad2fe0f8b0220b0031af4c220fbb7e9002fdb1c76bd38c4d17b85aed
SHA3 b89616b1b553c7efb9a63061f47fa6c98e5e668e1965a28a42e3c0c42647ddc6
VirtualSize 0x75c
VirtualAddress 0x53000
SizeOfRawData 0x800
PointerToRawData 0x4ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.24013

Imports

USER32.dll CreateWindowExW
MessageBoxW
MessageBoxA
SystemParametersInfoW
DestroyIcon
SetWindowLongPtrW
GetWindowLongPtrW
GetClientRect
InvalidateRect
ReleaseDC
GetDC
DrawTextW
GetDialogBaseUnits
EndDialog
DialogBoxIndirectParamW
MoveWindow
SendMessageW
COMCTL32.dll #380
KERNEL32.dll IsValidCodePage
GetStringTypeW
GetFileAttributesExW
HeapReAlloc
FlushFileBuffers
GetCurrentDirectoryW
GetACP
GetOEMCP
GetModuleHandleW
MulDiv
GetLastError
SetDllDirectoryW
GetModuleFileNameW
CreateSymbolicLinkW
GetProcAddress
GetCommandLineW
GetEnvironmentVariableW
GetCPInfo
ExpandEnvironmentStringsW
CreateDirectoryW
GetTempPathW
WaitForSingleObject
Sleep
GetExitCodeProcess
CreateProcessW
GetStartupInfoW
FreeLibrary
LoadLibraryExW
SetConsoleCtrlHandler
FindClose
FindFirstFileExW
CloseHandle
GetCurrentProcess
LocalFree
FormatMessageW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
GetTimeZoneInformation
HeapSize
WriteConsoleW
SetEndOfFile
SetEnvironmentVariableW
RtlUnwindEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
RaiseException
RtlPcToFileHeader
GetCommandLineA
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetFullPathNameW
RemoveDirectoryW
FindNextFileW
SetStdHandle
DeleteFileW
ReadFile
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
HeapFree
GetConsoleMode
ReadConsoleW
SetFilePointerEx
GetConsoleOutputCP
GetFileSizeEx
HeapAlloc
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
CompareStringW
LCMapStringW
ADVAPI32.dll OpenProcessToken
GetTokenInformation
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidW
GDI32.dll SelectObject
DeleteObject
CreateFontIndirectW

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1392
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.73117
Detected Filetype PNG graphic file
MD5 40e4b5c77c30e3b3473fb9283cb3341b
SHA1 bc19ff42aaac9a0a5a0e5d957b995da734f8297c
SHA256 bd52676a679f0ea9b9025344edc9964146ba5dbce04c00527a7ae43bb4e495b5
SHA3 58b42d9ef819abb4b910171096c77797b91cada8084d1b9751f148962bd42d99

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.73688
MD5 dc4bc0c1063ec8a547742ef391c321f1
SHA1 5008843969d6f588187fd6a5e7a5cd6958489472
SHA256 d25b21205a36940c838759952c0b75353ff2ead61362d49c6cc5a7174e4a28d6
SHA3 68d938632288436e5103510e5dd9352ea0abc32c72d905b473edafe7348b3516

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.74581
MD5 72c76005bd79dbf3c6fc3b930062e3e3
SHA1 6a75dfce5213bd635acaf1bd43ed5faa730dc31d
SHA256 8289ff44721cf8d46ec8e4e02eda323cec22028c6d0bdd49de65900aa8f986cc
SHA3 9bc58009cfcc162b03c5df2426c4c39fef292f2e9be352311aeab11a6b2bdc00

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.88206
MD5 92edf4d3fa34693d255a8b37230412cb
SHA1 71e6c065f5596ec5fa86d628ff66bf49dbde0a9e
SHA256 b2819fd5e8b6ef39fd6069a399f901079dac1b1d8feb576480c000e4c796e81d
SHA3 22b5a43e837242cd7fb662cb52ef4595a7f5fb4f7c14a66b786b03f19e77ddaf

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.96072
MD5 5b2ffd3ad460c056b33e7d5fdd06db1b
SHA1 50667f9d6980a7282cc6c7b742436245c1c300d6
SHA256 d0d0983f4da3f448b0ad8525e24cb165d586049d9c253c631fe8c3fa03351643
SHA3 f8919496d7bab0ca752c6cf1a5a44824c76b2608e4f5a8860cd71d35174f3747

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.14593
MD5 688463498df5475aac8adb2d74c7aa17
SHA1 6175a760a45dabc2c129e24b72792c29614e081e
SHA256 43e31a12e8c783171e51af86b6740540d99f701253dfbcfe8c0271a7f68cfe40
SHA3 bda849478ea6a857b8586dd5c3682d02fd597d136321811546ec1b23777f6b9c

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.18636
MD5 64bd1a5310cc568c079e1162f19462c5
SHA1 20c6cc8749705788cc8349ae2d30e2ff39c3b04c
SHA256 84f7529950cc86cc5b2c116111cdcf2871bb9b20bcc4989396219a3081fe3ca7
SHA3 68c21d9ec83c5f7c1c51b04217295ab7c8d784efed2d2cc7d495bc9b7f2ba178

8

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.54716
MD5 42a6b1b56800938966f4eff1dd7bedee
SHA1 e9314478a883ee8f0d97dbeaaa6731bfe646d8d9
SHA256 cd2bcfbe15de26559ee42d9d997e0528c12a584e97bad77f974ee8379cdba181
SHA3 6e6cfdd478da0d829ed4f6a026cbdc5a3298a8f5b4a86230a8ae28813782bd5f

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95799
Detected Filetype Icon file
MD5 435f929cb973c6448d8787528e0c93b7
SHA1 6505a627e0fb93e4b287e9ea4d9561d59dc9da92
SHA256 79ccb1d0b9662cbd8335cc041d80ca5858fe7b468cf464c91720602b551946b9
SHA3 6596ab4795d2cb93b2bf635c01147764a985301befeda7953de6402a35f488c8

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x394
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35644
MD5 95283628c85a56b602b9c22ee0c512b7
SHA1 d153d736af0b8dfc43fda0604a391ec4eb581be4
SHA256 214ad631ae94f244498c596f35c58fddcfe569e17cf228e14d98acc9b2ed2172
SHA3 23efe8ced686a47ea127d828f7ccbe17fbac4dad6b83ee698c7077a9870c645e

1 (#4)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x50d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25791
MD5 84da8dee6b319ea0b10b6de5489c6aae
SHA1 5f8991f3e065fd95614859a293f88b9c70e4bb23
SHA256 abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11
SHA3 08f0562915b54bedce5a84e9d32cb2efcc538268785103b1852338e20a3b4606

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.6.0
ProductVersion 1.0.6.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileDescription A helper tool for checking if your product feeds fulfill the standard requirements for the integration with the Digitec Galaxus online shops
FileVersion (#2) 1.0.1
InternalName Feedchecker
OriginalFilename Feedchecker
ProductName Feedchecker
ProductVersion (#2) 1.0.2
Language (#2) English / German
LegalTrademarks
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Feb-02 13:14:20
Version 0.0
SizeofData 772
AddressOfRawData 0x3a860
PointerToRawData 0x39a60

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14003e018
GuardCFCheckFunctionPointer 5368886304
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x853fae11
Unmarked objects 0
ASM objects (30795) 8
C++ objects (30795) 188
C objects (30795) 10
253 (VS 2015-2022 runtime 32533) 4
C++ objects (VS 2015-2022 runtime 32533) 40
C objects (VS 2015-2022 runtime 32533) 17
ASM objects (VS 2015-2022 runtime 32533) 9
Imports (30795) 11
Total imports 139
C objects (32826) 21
Linker (32826) 1

Errors

<-- -->