Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Sep-27 11:37:59 |
Detected languages |
English - United States
|
Debug artifacts |
Set-up.pdb
|
CompanyName | Adobe Inc. |
FileDescription | Adobe Installer |
FileVersion | 5.0.0.354 |
InternalName | Adobe Installer |
LegalCopyright | © 2015-2019 Adobe. All rights reserved. |
OriginalFilename | Adobe Installer |
ProductName | Adobe Installer |
ProductVersion | 5.0.0.354 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE's digital signature is invalid. |
Signer: Adobe Inc.
Issuer: DigiCert EV Code Signing CA (SHA2) The file was modified after it was signed. |
Suspicious | VirusTotal score: 1/69 (Scanned on 2021-04-12 17:08:08) | eGambit: PE.Heur.InvalidSig |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x138 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2019-Sep-27 11:37:59 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1fba00 |
SizeOfInitializedData | 0x316e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00197979 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1fd000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x517000 |
SizeOfHeaders | 0x400 |
Checksum | 0x513934 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SETUPAPI.dll |
CM_Get_DevNode_Status
SetupDiEnumDeviceInfo SetupDiDestroyDeviceInfoList SetupDiGetClassDevsW SetupDiGetDeviceRegistryPropertyW SetupDiGetDeviceInstanceIdW |
---|---|
COMCTL32.dll |
InitCommonControlsEx
|
SHELL32.dll |
SHGetKnownFolderPath
ShellExecuteW SHGetSpecialFolderPathW #51 CommandLineToArgvW ShellExecuteExW SHCreateDirectoryExW SHGetFolderPathW SHGetPathFromIDListW SHGetFolderLocation SHGetSpecialFolderLocation SHBrowseForFolderW SHGetMalloc #680 |
SHLWAPI.dll |
PathIsFileSpecW
PathAddExtensionW PathRenameExtensionW PathRemoveBackslashW PathRemoveExtensionW UrlIsW SHGetValueW PathIsSystemFolderW PathAppendW PathFileExistsW PathFileExistsA PathIsDirectoryW PathRemoveFileSpecW PathStripToRootW PathIsNetworkPathW PathFindFileNameW PathIsRootW PathIsRelativeW PathStripPathW PathIsUNCW |
KERNEL32.dll |
WideCharToMultiByte
GetCurrentProcess GetTempPathW CreateFileW GetVersionExW GetComputerNameExW FileTimeToSystemTime CloseHandle RaiseException LoadLibraryW GetProcAddress LocalFree CreateProcessW GetModuleHandleW FreeLibrary FindFirstFileW FindNextFileW TerminateProcess RemoveDirectoryW GetModuleFileNameW FindClose WaitForSingleObject OpenProcess SetFileAttributesW CreateToolhelp32Snapshot Sleep GetLastError Process32NextW DeleteFileW Process32FirstW CopyFileW GetExitCodeProcess ReadFile SetLastError lstrlenW LocalAlloc GetFileAttributesW FormatMessageW GetDiskFreeSpaceExW GetCurrentDirectoryW SetCurrentDirectoryW MoveFileExW GetFileSize lstrcpyW lstrcmpiW lstrcmpW GetDriveTypeW InitializeCriticalSectionEx DecodePointer DeleteCriticalSection GetFullPathNameW HeapSize HeapReAlloc HeapDestroy EnterCriticalSection LeaveCriticalSection GetCurrentThreadId GlobalAlloc GlobalLock GlobalUnlock MulDiv GetSystemDirectoryW SetDllDirectoryW GetStdHandle AttachConsole FreeConsole GetConsoleWindow CreateMutexW ReleaseMutex InitializeCriticalSectionAndSpinCount AreFileApisANSI TryEnterCriticalSection HeapCreate WriteFile InterlockedCompareExchange GetDiskFreeSpaceW OutputDebugStringA LockFile InitializeCriticalSection SetFilePointer GetFullPathNameA SetEndOfFile UnlockFileEx UnmapViewOfFile HeapValidate GetTempPathA HeapAlloc GetFileAttributesA GetFileAttributesExW OutputDebugStringW FlushViewOfFile CreateFileA LoadLibraryA WaitForSingleObjectEx GetVersionExA DeleteFileA GetSystemInfo HeapCompact UnlockFile CreateFileMappingA LockFileEx GetCurrentProcessId SystemTimeToFileTime GetSystemTimeAsFileTime GetSystemTime FormatMessageA CreateFileMappingW MapViewOfFile QueryPerformanceCounter GetTickCount FlushFileBuffers SizeofResource LockResource LoadResource FindResourceW MultiByteToWideChar VerSetConditionMask VerifyVersionInfoW GetUserDefaultLCID LCMapStringW DuplicateHandle ProcessIdToSessionId SetEvent TerminateThread GlobalFree CreateThread FindResourceExW ResetEvent GetThreadTimes QueryFullProcessImageNameW WaitForMultipleObjects GetFileSizeEx GetUserDefaultLangID GetUserDefaultUILanguage SetNamedPipeHandleState CreateNamedPipeW ConnectNamedPipe CreateDirectoryW SetFileTime LocalFileTimeToFileTime DosDateTimeToFileTime GetFileTime ReleaseSemaphore OpenSemaphoreW CreateSemaphoreW GetLocalTime GetTimeFormatW GetDateFormatW OpenMutexW GetTimeZoneInformation CreateSymbolicLinkW QueryPerformanceFrequency GetCurrentThread SetFilePointerEx ResumeThread SwitchToThread SignalObjectAndWait CreateTimerQueue VirtualFree VirtualAlloc FlushInstructionCache InterlockedPushEntrySList InterlockedPopEntrySList GetStartupInfoW IsDebuggerPresent InitializeSListHead IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetLocaleInfoW CompareStringW GetCPInfo HeapFree TlsFree TlsSetValue TlsGetValue TlsAlloc GetStringTypeW EncodePointer LoadLibraryExA VirtualQuery VirtualProtect SetThreadPriority GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait FreeLibraryAndExitThread GetModuleHandleA LoadLibraryExW InterlockedFlushSList QueryDepthSList UnregisterWaitEx RtlUnwind GetFileType SetStdHandle ExitThread GetModuleHandleExW ExitProcess GetACP IsValidLocale EnumSystemLocalesW GetConsoleMode ReadConsoleW GetConsoleCP FindFirstFileExW IsValidCodePage GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW CreateEventW SetEnvironmentVariableA WriteConsoleW GetProcessHeap GetDiskFreeSpaceA |
USER32.dll |
IsWindow
InvalidateRgn DispatchMessageW RedrawWindow ClientToScreen DestroyAcceleratorTable IsChild AttachThreadInput ShowWindow RegisterClassExW SetWindowTextW ScreenToClient CreateWindowExW FillRect DestroyWindow GetFocus GetWindow GetSysColor GetActiveWindow PostMessageW CallWindowProcW GetForegroundWindow MoveWindow CreateAcceleratorTableW SetFocus CharNextW DefWindowProcW GetMessageW GetClassInfoExW GetWindowTextLengthW GetWindowThreadProcessId BringWindowToTop TranslateAcceleratorW TranslateMessage LoadCursorW GetClassNameW SetCapture SetWindowLongW GetClientRect GetDlgItem PostQuitMessage GetParent RegisterWindowMessageW ReleaseCapture SetForegroundWindow InvalidateRect IsIconic BeginPaint EndPaint GetWindowTextW GetWindowRect GetDC SetWindowPos MessageBoxW SendMessageW GetDesktopWindow ReleaseDC UnregisterClassW GetWindowLongW wsprintfW PostThreadMessageW EnumWindows GetShellWindow AllowSetForegroundWindow LoadImageW SystemParametersInfoW EnableMenuItem LoadIconW GetSystemMetrics GetSystemMenu GetClassLongW AppendMenuW GetAsyncKeyState SetClassLongW |
GDI32.dll |
BitBlt
CreateSolidBrush DeleteObject DeleteDC GetStockObject CreateCompatibleDC GetDeviceCaps CreateCompatibleBitmap SelectObject GetObjectW |
ADVAPI32.dll |
SetEntriesInAclW
SetNamedSecurityInfoW GetNamedSecurityInfoW GetTokenInformation CreateWellKnownSid LookupPrivilegeValueW RegCloseKey AdjustTokenPrivileges SystemFunction036 RegCreateKeyExW RegFlushKey LookupAccountSidW RegSetValueExW RegOpenKeyExW EqualSid InitializeSecurityDescriptor FreeSid AllocateAndInitializeSid SetSecurityDescriptorDacl DuplicateTokenEx ConvertSidToStringSidW ImpersonateLoggedOnUser ConvertStringSidToSidW RevertToSelf CryptReleaseContext CryptGetHashParam CryptDestroyHash CryptHashData CryptCreateHash CryptAcquireContextW RegQueryValueExW GetUserNameW OpenProcessToken |
ole32.dll |
CoAddRefServerProcess
OleRun CoReleaseServerProcess CoInitializeSecurity CoSetProxyBlanket CoUninitialize CoInitialize OleLockRunning CLSIDFromString OleInitialize CreateStreamOnHGlobal CLSIDFromProgID CoTaskMemAlloc OleUninitialize CoGetClassObject CoCreateInstance StringFromGUID2 CoTaskMemFree CoCreateGuid CoInitializeEx |
OLEAUT32.dll |
VariantClear
SysAllocStringLen SysStringLen SysAllocString OleCreateFontIndirect LoadTypeLib VariantInit LoadRegTypeLib VariantChangeType SysAllocStringByteLen VariantCopy SysStringByteLen DispCallFunc GetErrorInfo SysFreeString |
CRYPT32.dll |
CertGetIssuerCertificateFromStore
CertGetNameStringW |
WINTRUST.dll |
WTHelperGetProvSignerFromChain
WTHelperGetProvCertFromChain WinVerifyTrust WTHelperProvDataFromStateData |
WININET.dll (delay-loaded) |
InternetCanonicalizeUrlW
|
Attributes | 0x1 |
---|---|
Name | WININET.dll |
ModuleHandle | 0x2763b0 |
DelayImportAddressTable | 0x276384 |
DelayImportNameTable | 0x26b368 |
BoundDelayImportTable | 0x26b614 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.0.0.354 |
ProductVersion | 5.0.0.354 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Adobe Inc. |
FileDescription | Adobe Installer |
FileVersion (#2) | 5.0.0.354 |
InternalName | Adobe Installer |
LegalCopyright | © 2015-2019 Adobe. All rights reserved. |
OriginalFilename | Adobe Installer |
ProductName | Adobe Installer |
ProductVersion (#2) | 5.0.0.354 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Sep-27 11:37:59 |
Version | 0.0 |
SizeofData | 35 |
AddressOfRawData | 0x2529b4 |
PointerToRawData | 0x2517b4 |
Referenced File | Set-up.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Sep-27 11:37:59 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x2529d8 |
PointerToRawData | 0x2517d8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Sep-27 11:37:59 |
Version | 0.0 |
SizeofData | 1244 |
AddressOfRawData | 0x2529ec |
PointerToRawData | 0x2517ec |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Sep-27 11:37:59 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x680000 |
---|---|
EndAddressOfRawData | 0x680008 |
AddressOfIndex | 0x679ca8 |
AddressOfCallbacks | 0x5fdc50 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x66e070 |
SEHandlerTable | 0x6517f0 |
SEHandlerCount | 1092 |
XOR Key | 0x9e69c8eb |
---|---|
Unmarked objects | 0 |
241 (40116) | 21 |
243 (40116) | 200 |
242 (40116) | 32 |
C++ objects (23013) | 4 |
199 (41118) | 1 |
ASM objects (23907) | 25 |
C objects (23907) | 39 |
C++ objects (23907) | 136 |
C objects (65501) | 9 |
C++ objects (VS2015 UPD2 build 23918) | 24 |
C objects (VS2015 UPD1 build 23506) | 1 |
C++ objects (VS2015 UPD1 build 23506) | 8 |
208 (65501) | 2 |
Imports (65501) | 35 |
Total imports | 530 |
265 (VS2015 UPD2 build 23918) | 200 |
Resource objects (VS2015 UPD2 build 23918) | 1 |
151 | 1 |
Linker (VS2015 UPD2 build 23918) | 1 |