Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2011-Aug-26 21:05:55 |
Detected languages |
English - United States
|
Debug artifacts |
t:\ses\x86\ship\0\opatchinst.pdb
|
CompanyName | Microsoft Corporation |
FileVersion | 12.0.6650.5000 |
LegalCopyright | © 2006 Microsoft Corporation. All rights reserved. |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
ProductVersion | 12.0.6650.5000 |
Info | Matching compiler(s): |
Microsoft Visual C++ 8.0
MSVC++ v.8 (procedure 1 recognized - h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Malicious | The file headers were tampered with. | The RICH header checksum is invalid. |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA |
Safe | VirusTotal score: 0/73 (Scanned on 2020-06-15 06:22:04) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2011-Aug-26 21:05:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0x49600 |
SizeOfInitializedData | 0xe4600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000305EE (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x4c000 |
ImageBase | 0x30000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x132000 |
SizeOfHeaders | 0x400 |
Checksum | 0xc62ad4 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
lstrlenW
FreeLibrary GetProcAddress LoadLibraryA GetVersionExA CloseHandle GetExitCodeProcess WaitForSingleObject MultiByteToWideChar lstrlenA GetFileSize CreateFileA CreateDirectoryA DeleteFileA GetTempFileNameA GetTempPathA GetFullPathNameA UnmapViewOfFile MapViewOfFile CreateFileMappingA CopyFileA MoveFileA Sleep CreateThread ReadFile ExpandEnvironmentStringsA SetEvent CreateEventA SetFilePointer WriteFile CreateFileW GetTempFileNameW GetTempPathW DeleteFileW CreateProcessW LockResource WideCharToMultiByte FindResourceA GetSystemDirectoryA GetUserDefaultLangID GetSystemDefaultLangID GlobalFree GlobalAlloc CompareStringA GetCurrentProcess WritePrivateProfileStringA GetWindowsDirectoryA SetCurrentDirectoryA CreateProcessA GetDiskFreeSpaceExA GetModuleFileNameA SetLastError GetCurrentDirectoryA SetFileTime DosDateTimeToFileTime LocalAlloc FlushFileBuffers WriteConsoleW GetConsoleOutputCP WriteConsoleA SetStdHandle GetStringTypeW GetStringTypeA LCMapStringW LoadResource GetLastError GetFileAttributesW LocalFree InterlockedExchange GetACP GetLocaleInfoA GetThreadLocale GetCommandLineA HeapFree HeapAlloc GetProcessHeap GetStartupInfoA TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RaiseException HeapReAlloc RtlUnwind GetFileAttributesA ExitThread GetCurrentThreadId GetModuleHandleA ExitProcess GetStdHandle FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType DeleteCriticalSection TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement InterlockedDecrement HeapDestroy HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime LeaveCriticalSection EnterCriticalSection VirtualAlloc HeapSize GetCPInfo GetOEMCP InitializeCriticalSection GetConsoleCP GetConsoleMode LCMapStringA |
---|---|
OLEAUT32.dll |
#12
#2 #6 #8 #9 |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
ole32.dll |
CoTaskMemFree
CoCreateInstance CLSIDFromProgID CoInitialize |
SHLWAPI.dll |
#176
|
GDI32.dll |
CreateFontIndirectA
|
ADVAPI32.dll (delay-loaded) |
CryptGetHashParam
CryptDestroyHash CryptHashData CryptReleaseContext CryptCreateHash CryptAcquireContextA RegCloseKey RegSetValueExA RegOpenKeyExA RegCreateKeyExA RegQueryValueExA RegQueryValueExW RegOpenKeyExW AdjustTokenPrivileges LookupPrivilegeValueA OpenProcessToken FreeSid EqualSid AllocateAndInitializeSid GetTokenInformation |
Attributes | 0x1 |
---|---|
Name | ADVAPI32.dll |
ModuleHandle | 0x4daa4 |
DelayImportAddressTable | 0x4b000 |
DelayImportNameTable | 0x49350 |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2011-Aug-26 21:05:55 |
Version | 0.0 |
SizeofData | 101 |
AddressOfRawData | 0x4a550 |
PointerToRawData | 0x49950 |
Referenced File | t:\ses\x86\ship\0\opatchinst.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2011-Aug-26 21:05:55 |
Version | 555.4346 |
SizeofData | 4 |
AddressOfRawData | 0x4a54c |
PointerToRawData | 0x4994c |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x3004c908 |
SEHandlerTable | 0x3000cb34 |
SEHandlerCount | 251 |
XOR Key | 0x250aaf0b |
---|---|
Unmarked objects | 0 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 22 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
Imports (2035) | 2 |
Imports (9210) | 2 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 129 |
37 (8755) | 2 |
Imports (2067) | 5 |
Total imports | 239 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 95 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |