| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2016-Oct-19 07:15:05 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| FileDescription | |
| OriginalFilename | setup.exe |
| CompanyName | BSS LLC |
| LegalCopyright | Copyright BSS LLC |
| FileVersion | 4.0.3.16 |
| ProductName | BSS CryptoPlugin |
| ProductVersion | 4.0.3.16 |
| Suspicious | PEiD Signature: | Encapsulated Postscript graphics file v3.0 EPSF-3.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: /4 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
| Info | The PE is digitally signed. |
Signer: Limited liability company Banks Soft Systems
Issuer: GlobalSign GCC R45 EV CodeSigning CA 2020 |
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-05-28 09:36:56) | Kaspersky: UDS:DangerousObject.Multi.Generic |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 11 |
| TimeDateStamp | 2016-Oct-19 07:15:05 |
| PointerToSymbolTable | 0x2b5c00 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x1d2c00 |
| SizeOfInitializedData | 0x2b5800 |
| SizeOfUninitializedData | 0x1c00 |
| AddressOfEntryPoint | 0x000012A0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1d4000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2be000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xc129ad |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.DLL |
GetSecurityDescriptorOwner
GetSidIdentifierAuthority GetUserNameA GetUserNameW RegCloseKey RegOpenKeyExA RegQueryValueExA |
|---|---|
| COMCTL32.DLL |
InitCommonControlsEx
|
| COMDLG32.DLL |
ChooseColorA
CommDlgExtendedError GetOpenFileNameA GetOpenFileNameW GetSaveFileNameA GetSaveFileNameW |
| GDI32.dll |
Arc
BitBlt Chord CombineRgn CreateBitmap CreateCompatibleBitmap CreateCompatibleDC CreateDCA CreateDIBSection CreateDIBitmap CreateFontIndirectA CreateFontIndirectW CreatePalette CreatePatternBrush CreatePen CreateRectRgn CreateRectRgnIndirect CreateSolidBrush DPtoLP DeleteDC DeleteObject EnumFontFamiliesA EnumFontFamiliesW ExtCreatePen ExtTextOutA GetBkMode GetCharWidthA GetCharWidthW GetDIBits GetDeviceCaps GetFontData GetMapMode GetNearestColor GetNearestPaletteIndex GetObjectA GetPaletteEntries GetPixel GetRgnBox GetStockObject GetTextCharset GetTextExtentPoint32A GetTextExtentPoint32W GetTextExtentPointA GetTextFaceA GetTextFaceW GetTextMetricsA OffsetClipRgn PatBlt Pie Polygon Polyline RealizePalette RectInRegion Rectangle ResizePalette SelectClipRgn SelectObject SelectPalette SetBkColor SetBkMode SetBrushOrgEx SetMapMode SetPaletteEntries SetPolyFillMode SetROP2 SetRectRgn SetTextAlign SetTextColor StretchDIBits TextOutA TextOutW TranslateCharsetInfo UpdateColors |
| IMM32.DLL |
ImmGetCompositionStringA
ImmGetCompositionStringW ImmGetContext ImmReleaseContext ImmSetCompositionWindow |
| KERNEL32.dll |
BuildCommDCBA
BuildCommDCBW ClearCommError CloseHandle CopyFileA CopyFileW CreateDirectoryA CreateDirectoryW CreateEventA CreateFileA CreateFileMappingA CreateFileW CreatePipe CreateProcessA CreateProcessW CreateSemaphoreA CreateThread DeleteCriticalSection DeleteFileA DeleteFileW DeviceIoControl DuplicateHandle EnterCriticalSection EscapeCommFunction ExitProcess FindClose FindFirstFileA FindFirstFileW FindNextFileA FindNextFileW FindResourceA FlushFileBuffers FormatMessageA FreeLibrary GetACP GetCommModemStatus GetCommState GetCommandLineA GetComputerNameA GetComputerNameW GetConsoleCP GetConsoleMode GetCurrentDirectoryA GetCurrentDirectoryW GetCurrentProcess GetCurrentThread GetCurrentThreadId GetEnvironmentVariableA GetEnvironmentVariableW GetExitCodeProcess GetExitCodeThread GetFileAttributesA GetFileAttributesW GetFileInformationByHandle GetFileType GetFullPathNameA GetFullPathNameW GetLastError GetLocaleInfoA GetLogicalDriveStringsA GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetOverlappedResult GetPrivateProfileStringA GetProcAddress GetProcessHeap GetShortPathNameA GetShortPathNameW GetStartupInfoA GetStdHandle GetSystemInfo GetSystemTimeAsFileTime GetTempFileNameA GetTempFileNameW GetTempPathA GetTempPathW GetTickCount GetTimeZoneInformation GetVersion GetVersionExA GetVolumeInformationA GetVolumeInformationW GetWindowsDirectoryA GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalUnlock HeapAlloc HeapFree InitializeCriticalSection InterlockedDecrement InterlockedIncrement IsDBCSLeadByte LeaveCriticalSection LoadLibraryA LoadLibraryExA LoadLibraryExW LoadResource LocalFree LockResource MapViewOfFile MoveFileA MoveFileW MulDiv MultiByteToWideChar OutputDebugStringA PeekConsoleInputA PeekNamedPipe PurgeComm QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleA ReadConsoleW ReadFile ReleaseSemaphore RemoveDirectoryA RemoveDirectoryW ResetEvent SearchPathA SearchPathW SetCommState SetCommTimeouts SetConsoleMode SetCurrentDirectoryA SetCurrentDirectoryW SetEndOfFile SetEnvironmentVariableW SetErrorMode SetEvent SetFileAttributesA SetFileAttributesW SetFilePointer SetFileTime SetHandleInformation SetLastError SetThreadPriority SetUnhandledExceptionFilter SetupComm Sleep TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue UnmapViewOfFile VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteConsoleA WriteConsoleW WriteFile lstrcmpiA lstrcpyA lstrcpyW lstrcpynA lstrlenA lstrlenW |
| msvcrt.dll |
_ftime
_getpid _hypot _isatty _putenv _strdup _stricmp _strnicmp _timezone _tzset _write |
| msvcrt.dll (#2) |
_ftime
_getpid _hypot _isatty _putenv _strdup _stricmp _strnicmp _timezone _tzset _write |
| OLE32.dll |
CreateBindCtx
CreateFileMoniker GetRunningObjectTable |
| OLEAUT32.DLL |
CreateErrorInfo
SetErrorInfo SysAllocString SysFreeString VariantChangeType VariantClear VariantInit |
| SHELL32.DLL |
SHBrowseForFolderA
SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetPathFromIDListA SHGetPathFromIDListW |
| USER32.dll |
AdjustWindowRectEx
BeginPaint CallNextHookEx CallWindowProcA CallWindowProcW CharLowerA CharLowerW ClientToScreen CloseClipboard CreateCaret CreateIconFromResource CreateIconIndirect CreateMenu CreatePopupMenu CreateWindowExA CreateWindowExW DefWindowProcA DefWindowProcW DestroyCaret DestroyIcon DestroyMenu DestroyWindow DispatchMessageA DrawEdge DrawFocusRect DrawFrameControl DrawMenuBar EmptyClipboard EnableWindow EndPaint EnumWindows FillRect GetAsyncKeyState GetCapture GetClassLongA GetClientRect GetClipboardData GetClipboardOwner GetCursorPos GetDC GetDesktopWindow GetFocus GetForegroundWindow GetKeyState GetKeyboardLayout GetMenuCheckMarkDimensions GetMenuItemCount GetMessageA GetMessagePos GetParent GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetWindow GetWindowLongA GetWindowPlacement GetWindowRect GetWindowTextA GetWindowTextW InsertMenuA InsertMenuW InvalidateRect IsClipboardFormatAvailable IsIconic IsWindow IsWindowVisible IsZoomed KillTimer LoadBitmapA LoadCursorA LoadCursorFromFileA LoadIconA MapVirtualKeyA MessageBeep MessageBoxA MessageBoxW MoveWindow MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageA PostMessageA PostQuitMessage RegisterClassA RegisterClassExA RegisterClassW ReleaseCapture ReleaseDC RemoveMenu ScreenToClient ScrollWindowEx SendInput SendMessageA SendMessageW SetActiveWindow SetCapture SetCaretPos SetClassLongA SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetMenu SetParent SetScrollInfo SetTimer SetWindowLongA SetWindowLongW SetWindowPos SetWindowTextA SetWindowTextW SetWindowsHookExA ShowWindow SystemParametersInfoA ToAscii TrackPopupMenu TranslateMessage UnhookWindowsHookEx UnregisterClassA UpdateWindow VkKeyScanA WaitForInputIdle WindowFromPoint wsprintfA |
| WS2_32.dll |
WSAAsyncSelect
WSACleanup WSAGetLastError WSAStartup accept bind closesocket connect gethostbyaddr gethostbyname gethostname getpeername getservbyname getsockname getsockopt htons inet_addr inet_ntoa ioctlsocket listen ntohs recv select send setsockopt socket |
| Ordinal | 1 |
|---|---|
| Address | 0x24dc |
| Ordinal | 2 |
|---|---|
| Address | 0x28b8 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.0.3.16 |
| ProductVersion | 4.0.3.16 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| FileDescription | |
| OriginalFilename | setup.exe |
| CompanyName | BSS LLC |
| LegalCopyright | Copyright BSS LLC |
| FileVersion (#2) | 4.0.3.16 |
| ProductName | BSS CryptoPlugin |
| ProductVersion (#2) | 4.0.3.16 |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x686019 |
|---|---|
| EndAddressOfRawData | 0x68601c |
| AddressOfIndex | 0x67fb28 |
| AddressOfCallbacks | 0x685004 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x005C7D50
0x005C7D00 |
No comments yet.