| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2021-Aug-23 03:55:16 |
| Detected languages |
English - United States
|
| CompanyName | Studio 3T |
| FileDescription | Studio 3T is the professional IDE, client, and GUI for MongoDB |
| FileVersion | 0. 0. 0. 0 |
| InternalName | |
| LegalCopyright | B4A |
| LegalTrademarks | |
| OriginalFilename | |
| ProductName | Studio 3T for MongoDB |
| ProductVersion | 0.0.0.0 |
| Comments | board4all.biz |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource SRC is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 47/72 (Scanned on 2025-03-08 15:31:12) |
APEX:
Malicious
AVG: Win32:Malware-gen AhnLab-V3: Malware/Win.CQ.R475397 Alibaba: Trojan:Win32/Convagent.ca3e6ec9 Antiy-AVL: Trojan/Win32.Poweliks Avast: Win32:Malware-gen Avira: TR/Redcap.zdcwr Bkav: W32.Common.AF6D6A6D CAT-QuickHeal: Trojan.Ghanarava.1679620450cff8ee CTX: exe.trojan.convagent ClamAV: Win.Malware.Midie-9973163-0 CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.KillProc2.16825 Elastic: malicious (high confidence) F-Secure: Trojan.TR/Redcap.zdcwr Fortinet: W32/PossibleThreat Google: Detected Gridinsoft: Ransom.Win32.Wacatac.oa!s1 Ikarus: Trojan.Agent Jiangmin: Trojan.Runner.iy Kaspersky: HEUR:Trojan.Win32.Convagent.gen Lionic: Trojan.Win32.Convagent.4!c Malwarebytes: Generic.Malware.Agent.DDS MaxSecure: Trojan.Malware.140075420.susgen McAfee: GenericRXPZ-CQ!500FE6511290 McAfeeD: ti!8B9C489961BB Microsoft: Trojan:Win32/Convagent!MSR NANO-Antivirus: Trojan.Win32.KillProc2.jpnjbx Paloalto: generic.ml Panda: Trj/Genetic.gen Rising: Trojan.Convagent!8.12323 (CLOUD) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Generic.fh Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.10bdec39 Trapmine: suspicious.low.ml.score VBA32: BScope.Trojan.MulDrop Varist: W32/ABRisk.UOJO-5487 ViRobot: Trojan.Win.Z.Ulise.308224 Webroot: W32.Trojan.Gen Zillya: Trojan.Inject.Win32.320601 alibabacloud: Trojan:Win/Fragtor.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 2021-Aug-23 03:55:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x2f400 |
| SizeOfInitializedData | 0x1bc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00030410 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x31000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x6a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
MessageBoxA
CharNextW LoadStringW |
| kernel32.dll |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess SwitchToThread GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| kernel32.dll (#2) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess SwitchToThread GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| user32.dll (#2) |
MessageBoxA
CharNextW LoadStringW |
| mpr.dll |
WNetGetConnectionW
WNetCancelConnection2W WNetAddConnection2W |
| kernel32.dll (#3) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess SwitchToThread GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| kernel32.dll (#4) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess SwitchToThread GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| MSVCRT.DLL |
_getch
|
| msvcrt.dll |
_ltow
_ultow _wtol wcstoul wcstol _pipe feof ferror fgets _pclose _wpopen fflush _dup2 _dup _close _get_osfhandle _open_osfhandle |
| shell32.dll |
ShellExecuteExW
|
| kernel32.dll (delay-loaded) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess SwitchToThread GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| Attributes | 0x1 |
|---|---|
| Name | kernel32.dll |
| ModuleHandle | 0x4e060 |
| DelayImportAddressTable | 0x4e06c |
| DelayImportNameTable | 0x4e084 |
| BoundDelayImportTable | 0x4e09c |
| UnloadDelayImportTable | 0x4e0ac |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Insert the diskette that contains the batch file |
| and press any key when ready. |
| No batch label specified to GOTO command. |
| The system cannot find the batch label specified - %s |
| Invalid attempt to call batch label outside of batch script. |
| The system cannot open the device or file specified. |
| The handle could not be duplicated |
| during redirection of handle %s. |
| The handle could not be opened |
| during redirection of handle %s. |
| Out of memory. |
| The input line is too long. |
| The following character string is too long: |
| %s |
| The following usage of the path operator in batch-parameter |
| substitution is invalid: %s |
| "%s" is an invalid current directory path. UNC paths are not supported. |
| Defaulting to Windows directory. |
| The unicode output option to CMD.EXE is not supported by this |
| version of the operating system. |
| The Process Identification Number is %s. |
| File association not found for extension %s |
| File type "%s" not found or no open command associated with it. |
| The system is out of environment space. |
| Environment variable %s not defined |
| Invalid parameter to SETLOCAL command |
| Maximum setlocal recursion level reached. |
| The batch file cannot be found. |
| Not enough quota is available to process this command. |
| The system cannot complete the process. |
| The system cannot execute the specified program. |
| An incorrect parameter was |
| entered for the command. |
| The system cannot find the drive specified. |
| The syntax of the command is incorrect. |
| Error occurred while processing: %s. |
| The system cannot accept the path |
| or file name requested. |
| The system cannot find the file specified. |
| "%s" is not a recognized device. |
| A subdirectory or file %s already exists. |
| The directory or file cannot be created. |
| The handle could not be duplicated during |
| a pipe operation. |
| %s was unexpected at this time. |
| The device is not ready. |
| Invalid parameter to SHIFT command |
| There is not enough space on the disk. |
| The system cannot write to the specified device. |
| Not enough storage is available to process this command. |
| The name specified is not recognized as an internal or external command, |
| operable program or batch file. |
| The process cannot access the file because it is being used by another process. |
| The system cannot start another process at this time. |
| The specified disk or diskette cannot be accessed. |
| The system cannot find the file %s. |
| Access is denied. |
| This version of %s is not compatible with the version of Windows you're running. Check your computer's system information to see whether you need a x86 (32-bit) or x64 (64-bit) version of the program, and then contact the software publisher. |
| The disk is in use or locked by another process. |
| The operating system cannot run %s. |
| Cannot run %s in Win32 mode. |
| %s is not a valid Win32 application. |
| The %s application cannot be run in Win32 mode. |
| The current directory is invalid. |
| The current date is: |
| The current time is: |
| KEYS is on. |
| KEYS is off. |
| ^C |
| Volume in drive %s is %s |
| Volume in drive %s has no label. |
| Volume Serial Number is %s |
| Press any key to continue . . . |
| Enter the new date: (mm-dd-yy) |
| Enter the new date: (yy-mm-dd) |
| Enter the new date: (dd-mm-yy) |
| Enter the new time: |
| The system cannot accept the date entered. |
| The system cannot accept the time entered. |
| The process tried to write to a nonexistent pipe. |
| Windows 7 |
| Windows Server 2008 R2 |
| Windows 2000 |
| Windows XP |
| Windows Server 2003 |
| Windows Server 2003 R2 |
| Windows Server 2012 |
| Windows 8 |
| Abyssmedia(R) QBFC(TM) (x86) version 1.0 |
| (C) Copyright 2001-2017 Abyss Media Company. |
| %s |
| Terminate batch job (Y/N)? |
| Microsoft Windows [Version %s] |
| Command Processor Extensions enabled by default. |
| Command Processor Extensions Enabled |
| ECHO is on. |
| ECHO is off. |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Invalid file name - %s |
| The specified file was not found |
| %s (Version %d.%d, Build %d, %5:s) |
| %s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
| 32-bit Edition |
| 64-bit Edition |
| Windows |
| Windows Vista |
| Windows Server 2008 |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| Variant or safe array index out of bounds |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid argument |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Monitor support function not initialized |
| Feature not implemented |
| Method called on disposed object |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s%s |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| Error creating variant or safe array |
| '%d.%d' is not a valid timestamp |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.0.0.0 |
| ProductVersion | 0.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| CompanyName | Studio 3T |
| FileDescription | Studio 3T is the professional IDE, client, and GUI for MongoDB |
| FileVersion (#2) | 0. 0. 0. 0 |
| InternalName | |
| LegalCopyright | B4A |
| LegalTrademarks | |
| OriginalFilename | |
| ProductName | Studio 3T for MongoDB |
| ProductVersion (#2) | 0.0.0.0 |
| Comments | board4all.biz |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x44f000 |
|---|---|
| EndAddressOfRawData | 0x44f008 |
| AddressOfIndex | 0x431bfc |
| AddressOfCallbacks | 0x450010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.