Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-May-20 05:49:44 |
Detected languages |
Chinese - PRC
English - United States |
FileDescription | 应用帮助和支持 |
FileVersion | 5.5022.1105.520 |
InternalName | support.exe |
LegalCopyright | 版权所有 (C) 2008-2022 |
OriginalFilename | support.exe |
ProductName | support.exe |
ProductVersion | 5.5022.1105.520 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to Blowfish |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Chengdu Qilu Technology Co. Ltd.
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x140 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2022-May-20 05:49:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x8fe00 |
SizeOfInitializedData | 0x71800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00052262 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x91000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x104000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1033c6 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
MapViewOfFile
UnmapViewOfFile CreateFileMappingW GetCurrentProcessId CreateMutexW GetVersionExW lstrcmpiW LoadLibraryExW CopyFileW TerminateProcess CreatePipe CreateProcessW GetStartupInfoW GetFileAttributesW GetModuleHandleW GetModuleFileNameW LoadLibraryW CloseHandle SizeofResource InterlockedDecrement InterlockedIncrement WritePrivateProfileStringW SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExW WriteConsoleW ReadConsoleW SetEndOfFile SetStdHandle EnumSystemLocalesW GetUserDefaultLCID IsValidLocale LoadResource GetACP GetStdHandle ExitProcess GetTimeZoneInformation GetConsoleMode GetConsoleCP SetFilePointerEx GetFileType FindNextFileW FreeLibraryAndExitThread ExitThread RtlUnwind GlobalFree GlobalUnlock GlobalLock GlobalAlloc OpenFileMappingW CreateFileA GetSystemDirectoryW lstrcmpiA lstrcmpA DeviceIoControl GetSystemWindowsDirectoryW FreeResource Sleep InterlockedCompareExchange QueryPerformanceCounter CreateFileW FindClose ReadFile WriteFile GetFileSizeEx SetLastError GetTickCount MoveFileW RemoveDirectoryW GetTempPathW CreateEventW WaitForMultipleObjects WaitForSingleObject DeleteCriticalSection InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection InitializeCriticalSection GetLastError GetCurrentThreadId RaiseException GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter ReleaseMutex LocalFree FlushFileBuffers DecodePointer LoadLibraryExA VirtualFree VirtualAlloc IsProcessorFeaturePresent FlushInstructionCache InterlockedPushEntrySList InterlockedPopEntrySList InitializeSListHead OutputDebugStringW IsDebuggerPresent GetCPInfo GetLocaleInfoW LCMapStringW CompareStringW GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc SwitchToThread EncodePointer FormatMessageW GetStringTypeW GetProcessHeap HeapSize HeapFree SetEvent CreateThread WideCharToMultiByte MultiByteToWideChar DeleteFileW FindResourceExW HeapReAlloc HeapAlloc GetModuleHandleExW FindResourceW HeapDestroy GetProcAddress FreeLibrary LockResource |
---|---|
USER32.dll |
DrawFocusRect
DestroyWindow IsWindow CreateWindowExW SendMessageW GetWindowThreadProcessId UnregisterClassW PostMessageW UpdateLayeredWindow PtInRect WaitForInputIdle LoadImageW DestroyIcon LoadIconW SetForegroundWindow GetForegroundWindow GetSystemMetrics IsIconic IsWindowVisible AttachThreadInput RegisterWindowMessageW CharNextW GetClassInfoExW RegisterClassExW PeekMessageW DispatchMessageW TranslateMessage GetMessageW ShowWindow CallWindowProcW PostQuitMessage DefWindowProcW GetMonitorInfoW MonitorFromWindow LoadCursorW GetWindow GetParent GetDesktopWindow SetWindowLongW GetWindowLongW OffsetRect MapWindowPoints ScreenToClient SetCursor GetWindowRect GetClientRect InvalidateRect EndPaint BeginPaint ReleaseDC GetDC EnableWindow KillTimer SetTimer ReleaseCapture SetCapture GetAsyncKeyState EndDialog DialogBoxParamW BringWindowToTop SetWindowPos wsprintfW CopyRect UnionRect EqualRect |
GDI32.dll |
SaveDC
RectVisible ExtTextOutW GetObjectW CreateDIBSection SetBkColor SelectObject SelectClipRgn OffsetViewportOrgEx RestoreDC DeleteObject DeleteDC CreateRectRgnIndirect CreateCompatibleDC CreateCompatibleBitmap BitBlt EnumFontFamiliesW SetViewportOrgEx CreateFontW |
ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyExA RegEnumKeyExA GetTokenInformation OpenProcessToken RegQueryInfoKeyW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegSetValueExW RegQueryValueExW RegOpenKeyExW RegCreateKeyExW RegCloseKey |
SHELL32.dll |
SHGetPathFromIDListW
ShellExecuteExW Shell_NotifyIconW ShellExecuteW SHGetSpecialFolderPathW SHGetSpecialFolderLocation |
ole32.dll |
CoUninitialize
CoCreateInstance CLSIDFromProgID CoTaskMemAlloc CoTaskMemRealloc CoTaskMemFree CoCreateGuid CoInitialize CreateStreamOnHGlobal |
OLEAUT32.dll |
SysAllocString
VarUI4FromStr SysFreeString |
SHLWAPI.dll |
SHSetValueW
PathRemoveBackslashW PathUnquoteSpacesW PathRemoveFileSpecW PathIsRelativeW PathCombineW PathIsDirectoryW SHSetValueA SHGetValueW PathRemoveExtensionW PathFindFileNameW PathFindExtensionW PathFileExistsW PathAppendW SHGetValueA StrCmpIW StrStrIA StrStrIW StrCmpNIW StrTrimA |
WININET.dll |
HttpOpenRequestW
InternetCloseHandle HttpSendRequestW HttpQueryInfoA InternetReadFile InternetConnectW InternetOpenW InternetGetConnectedState HttpAddRequestHeadersA |
COMCTL32.dll |
_TrackMouseEvent
|
VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
urlmon.dll |
URLDownloadToCacheFileW
URLDownloadToFileW |
IPHLPAPI.DLL |
GetAdaptersInfo
|
dbghelp.dll |
MakeSureDirectoryPathExists
|
NETAPI32.dll |
Netbios
|
CRYPT32.dll |
CertGetNameStringW
|
WINTRUST.dll |
WinVerifyTrust
WTHelperProvDataFromStateData |
gdiplus.dll |
GdipCreateBitmapFromFile
GdipCreateBitmapFromStream GdipDisposeImage GdipCloneImage GdiplusShutdown GdiplusStartup GdipSetStringFormatTrimming GdipSetStringFormatLineAlign GdipSetStringFormatAlign GdipSetStringFormatFlags GdipDeleteStringFormat GdipCreateStringFormat GdipMeasureString GdipDrawString GdipAlloc GdipFree GdipCreateFontFamilyFromName GdipDeleteFontFamily GdipCreateFont GdipDeleteBrush GdipCreateSolidFill GdipGetImageWidth GdipGetImageHeight GdipCreateFromHDC GdipDeleteGraphics GdipSetTextRenderingHint GdipFillRectangleI GdipDrawImageRectRect GdipDrawImageRectRectI |
Ordinal | 1 |
---|---|
Address | 0x35b10 |
downloader |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.5022.1105.520 |
ProductVersion | 5.5022.1105.520 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | Chinese - PRC |
FileDescription | 应用帮助和支持 |
FileVersion (#2) | 5.5022.1105.520 |
InternalName | support.exe |
LegalCopyright | 版权所有 (C) 2008-2022 |
OriginalFilename | support.exe |
ProductName | support.exe |
ProductVersion (#2) | 5.5022.1105.520 |
Resource LangID | Chinese - PRC |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-May-20 05:49:44 |
Version | 0.0 |
SizeofData | 984 |
AddressOfRawData | 0xd9028 |
PointerToRawData | 0xd8228 |
StartAddressOfRawData | 0x4d9410 |
---|---|
EndAddressOfRawData | 0x4d9418 |
AddressOfIndex | 0x4e8934 |
AddressOfCallbacks | 0x4915f0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4e55d4 |
SEHandlerTable | 0x4d8a70 |
SEHandlerCount | 366 |
XOR Key | 0xa131a741 |
---|---|
Unmarked objects | 0 |
241 (40116) | 18 |
243 (40116) | 163 |
242 (40116) | 31 |
C++ objects (VS2017 v15.8.1 compiler 26726) | 15 |
C objects (LTCG) (VS2017 v15.9.12-13 compiler 27031) | 2 |
Unmarked objects (#2) | 1 |
C++ objects (VS2017 v15.7.5 compiler 26433) | 10 |
ASM objects (VS 2015/2017 runtime 26706) | 25 |
C++ objects (VS2017 v15.9.14-15 compiler 27032) | 7 |
C++ objects (VS 2015/2017 runtime 26706) | 73 |
C objects (VS 2015/2017 runtime 26706) | 35 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 SP1 build 30729) | 39 |
Total imports | 382 |
C objects (VS2017 v15.9.12-13 compiler 27031) | 1 |
C++ objects (VS2017 v15.9.12-13 compiler 27031) | 38 |
Exports (VS2017 v15.9.12-13 compiler 27031) | 1 |
Resource objects (VS2017 v15.9.12-13 compiler 27031) | 1 |
151 | 1 |
Linker (VS2017 v15.9.12-13 compiler 27031) | 1 |