a712b3a431a5b05afb257d39683be1b2

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Tola
FileDescription Cadirocol Setup
FileVersion 3.2.3.6
LegalCopyright
ProductName Cadirocol
ProductVersion 2.3

Plugin Output

Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 1620939 bytes of data starting at offset 0x22c00.
The overlay data has an entropy of 7.9998 and is possibly compressed or encrypted.
Overlay data amounts for 91.9277% of the executable.
Malicious VirusTotal score: 40/67 (Scanned on 2018-09-18 06:45:31) MicroWorld-eScan: Trojan.GenericKD.31204560
CAT-QuickHeal: Trojan.IGENERIC
McAfee: Artemis!A712B3A431A5
Cylance: Unsafe
K7GW: Adware ( 005104571 )
K7AntiVirus: Adware ( 005104571 )
Symantec: PUA.Gen.2
ESET-NOD32: Win32/InstallCore.Gen.A potentially unwanted
TrendMicro-HouseCall: TROJ_GEN.R03BC0OI818
Paloalto: generic.ml
Kaspersky: not-a-virus:AdWare.Win32.DealPly.drjxm
BitDefender: Trojan.GenericKD.31204560
NANO-Antivirus: Virus.Win32.Gen-Crypt.ccnc
ViRobot: Adware.Installcore.1763275
Avast: FileRepMetagen [PUP]
Rising: Adware.InstallCore!1.A30C (CLASSIC)
Ad-Aware: Trojan.GenericKD.31204560
Sophos: Generic PUA PE (PUA)
F-Secure: Trojan.GenericKD.31204560
VIPRE: Trojan.Win32.Generic!BT
TrendMicro: TROJ_GEN.R03BC0OI818
McAfee-GW-Edition: BehavesLike.Win32.AdwareFileTour.tc
Emsisoft: Trojan.GenericKD.31204560 (B)
SentinelOne: static engine - malicious
Cyren: W32/Trojan.LOLB-5501
Webroot: W32.Adware.Gen
Microsoft: PUA:Win32/Presenoker
Endgame: malicious (high confidence)
Arcabit: Trojan.Generic.D1DC24D0
ZoneAlarm: not-a-virus:AdWare.Win32.DealPly.drjxm
GData: Win32.Application.InstallCore.LR@gen
AhnLab-V3: PUP/Win32.DealPly.C2296925
ALYac: Trojan.GenericKD.31204560
AVware: Trojan.Win32.Generic!BT
VBA32: Adware.DealPly
Malwarebytes: PUP.Optional.InstallCore
Fortinet: Adware/DealPly
AVG: FileRepMetagen [PUP]
Panda: PUP/RnkBend
Qihoo-360: HEUR/QVM42.2.9DFF.Malware.Gen

Hashes

MD5 a712b3a431a5b05afb257d39683be1b2
SHA1 f4705f4414c5a24da2f93e407f8fd9a49dd3803e
SHA256 44c76d573055e764d9669b7473a719d07ca36b1fca18b0bc4b5c6fc8fb083482
SHA3 b7362ba8c4009188703132438e69026949d15f8168cd9ce898b0750ac984bce3
SSDeep 49152:mrIkLC7gGdoEgeX4YV9RyQOvu68N1ggbSoqWGpf8:GIk6gDuZV+QOvuzugb88
Imports Hash 4fb639b17a439bf0efa713bd4c6e715b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x9e00
SizeOfInitializedData 0x18a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000A5F8 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0xb000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 1.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x29000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 6a5771cb12ca8aee04cce488771fe5a7
SHA1 d9a34841bf4babe3a9a229368aeaa12515ddd913
SHA256 6a5d9cbf3195fb99d8dac910c32d1aeb68396a8bf6646f82ea92ecf21d7af93c
SHA3 5b95922591b732b86c77434f5a2a0578519c90b2a501399d2ac43d7272e3cad3
VirtualSize 0x9d30
VirtualAddress 0x1000
SizeOfRawData 0x9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.67591

DATA

MD5 1ee71d84f1c77af85f1f5c278f880572
SHA1 7de911e50da81747314fc3485c1084d4ee50e6e7
SHA256 cf4e6480022c8eb98f3e55bd2500d15af438fc8030ff45378d06f85667b21701
SHA3 3b99c7e61fc4cbf760235841c472b86851e95cb909b0c9c25773658daace7f58
VirtualSize 0x250
VirtualAddress 0xb000
SizeOfRawData 0x400
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.75182

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xe8c
VirtualAddress 0xc000
SizeOfRawData 0
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 bb5485bf968b970e5ea81292af2acdba
SHA1 40a39d9e8c8cecd5356ab96745d82d2ebfe17cfb
SHA256 d9ea6e80cc1edfdffa8d534a8c61448b19b74d683845b94ad6d9a543e5ceb8cf
SHA3 09274dc071547ce3dc33528de99c9ad5a9eb119600e5a61b3127f74cde6dcfbf
VirtualSize 0x950
VirtualAddress 0xd000
SizeOfRawData 0xa00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.43073

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0xe000
SizeOfRawData 0
PointerToRawData 0xb000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 9ba824905bf9c7922b6fc87a38b74366
SHA1 f43ee83e6afa1c343ff6db68e13efde43471cbb6
SHA256 ad44157821ba24c07dd44f66940dd75adee9d6919a0577c5a75aa502637dddaa
SHA3 370eba5499bce03a18d462f5b9e6ee4598126f2a2243cc5fa1590c7c7245c5d7
VirtualSize 0x18
VirtualAddress 0xf000
SizeOfRawData 0x200
PointerToRawData 0xb000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.204488

.reloc

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8c4
VirtualAddress 0x10000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED

.rsrc

MD5 1f574a01e53bdf1ba14919061e2a4c2e
SHA1 7486c888a7aaa62fca5fd31184231754ebaf76a5
SHA256 04af515d2eaa2415fa1314e4346cd5bd9abbd4b74e293878e4ba6dcb6ad2689a
SHA3 b8bb1da4b4f7d055acc72acb7fc5a8d6becf541fec86ed879075434f921ce47c
VirtualSize 0x179b0
VirtualAddress 0x11000
SizeOfRawData 0x17a00
PointerToRawData 0xb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 5.92429

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll MessageBoxA
oleaut32.dll VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll (#2) MessageBoxA
comctl32.dll InitCommonControls
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.88025
MD5 dad4c87b0cab9bd0de20e5e071ab4e79
SHA1 08f08ce50ab025bef625fd8adbf745f43c0e4bba
SHA256 7065bf8bb4d61fd6575011603cee80fe9dc1cd9a653059fda0861af208d911fc
SHA3 ab6d632a73b3170389b7f763e226494ce55502e24174057526fad678beb15f07

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x32e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.86354
MD5 03d88d9a74fe2d3104c8084539f7e718
SHA1 1f79601fb5290ff16b49aba320890c545a1119e6
SHA256 5c303d2052ccbe61ea84daed0d196528fe45276d7455ee1fc4b1bfbafb045f83
SHA3 dec89b9c3df9d9702378c4acec04ad851cfd1146022bf419856b8680d92b3e29

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.85367
MD5 d9abaa16e8772b6b36333e854725d183
SHA1 8853ea3e04903258e3b8d0e988f1b78befe7cc3c
SHA256 90712dc4cce49923d6b87024964d0dcdcee070a95351f495839a829bd7e3641b
SHA3 520fdfb09041fb8023c5597c7aef53d38ce5831f4d5df3ec72a2c08f2da23344

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21823
MD5 bbf4b644f9dd284b35eb31573d0df2f7
SHA1 4f9885ae629e83464e313af5254ef86f01accd0b
SHA256 2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
SHA3 ebed2e4a929600c1460761d462143feb092840986b31c9748d3aeb8174d4205e

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31515
MD5 ac2a0551cb90f91d779ee8622682dfb1
SHA1 ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
SHA256 840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
SHA3 58a85f5c53df73aa79e5f5a36aa151ca0d9da4d450ebc2975a3ee827b46342a5

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25024
MD5 c99b474c52df3049dfb38b5308f2827d
SHA1 7375e693629ce6bbd1a0419621d094bcd2c67bb7
SHA256 26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
SHA3 c6013febd14dd876e3b81111ec17dd2724dbf4147b0ad7be9d03259bcb59fef3

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86149
MD5 aec4e28ea9db1361160cde225d158108
SHA1 249013a10cde021c713ba2dc8912f9e05be35735
SHA256 d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
SHA3 a067c4d88d719ed8d568951acb776bd798b691a8b153f8d94ba0574ede1fbf4c

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20731
MD5 c76a8843204c0572bca24ada35abe8c7
SHA1 066052030d0a32310da8cb5a51d0590960a65f32
SHA256 00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
SHA3 07523cf88b3803ea41acfeb3c9c0c4b5b4b9fb6f9a3232802491d8de1b6c9166

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04592
MD5 4bd4f3f6d918ba49d8800ad83d277a86
SHA1 1f5e4c73965fea1d1f729efbe7568dcd081a2168
SHA256 34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
SHA3 2d01c56a5bf0b390addf4fb5b6ae02f9a64bd03ffd300d3763615bbb8ec911fe

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.3673
MD5 5abbddeb07ce29b530331122798224e6
SHA1 d4168f8b727a14bc3de344f488a81e09b949c4ba
SHA256 326f3bce8a303859b33d897e215eefe06f85d8258c31377feb25238fe86dad48
SHA3 36e19d4cc52869c4e3089e2b8140a1bda8b527aa39105d37a19fede90c2ab343

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70363
Detected Filetype Icon file
MD5 8036f7ab798b66add782ad4a60adb703
SHA1 7e07390593fed011bdf4f7137e23849a81a09cbc
SHA256 4e13cabcc73d0cfe57482b6b24879f84bb0623cb7d0f839e24c278e85457343a
SHA3 83c66087565dc30c0b313c2553441f67b1677ffeb8969883c732a6385008837c

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x4f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56829
MD5 b1f991c75326d0f16efc8c531ef86dd6
SHA1 353faaf84fb6a193346fd0c29c84dad6eb22f218
SHA256 6d4ed61f85d7823e5b7ed9a2a4f3c0896092026d480f9e66c2580ee0d800e031
SHA3 1a37ba40e1e4eebd93f2a599d2c6604e75c14e5a3fb935a6064a18d429515720

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11919
MD5 a561f3d4bfa3931040422a49ec17c06e
SHA1 9a27136c8b8073f832d2f3a9239a49f0c14cfaf6
SHA256 8d51d4405593fb12ba0d4a2708507e2300b363f7ce3cf538cb65c25cc1d3044f
SHA3 5ef4d8131a8cc50f1295dc3ebde9c211384f3ca41c657f5c8b18fd6b3a5c7c75

String Table contents

'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Invalid variant type conversion
Invalid variant operation
Variant method calls not supported
Read
Write
Format result longer than 4096 characters
Format string too long
Error creating variant array
Variant is not an array
Variant array index out of bounds
External exception %x
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.2.3.6
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Tola
FileDescription Cadirocol Setup
FileVersion (#2) 3.2.3.6
LegalCopyright
ProductName Cadirocol
ProductVersion (#2) 2.3
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x40e000
EndAddressOfRawData 0x40e008
AddressOfIndex 0x40c3d0
AddressOfCallbacks 0x40f010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted! [!] Error: Could not reach the requested directory (offset=0x0). [*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .reloc has a size of 0!
<-- -->