Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1992-Jun-19 22:22:17 |
Detected languages |
English - United States
Russian - Russia |
CompanyName | |
FileDescription | |
FileVersion | 4.1.0.0 |
InternalName | |
LegalCopyright | paul_met & EdHell |
LegalTrademarks | |
OriginalFilename | MakaronEX |
ProductName | MakaronEX NewGen |
ProductVersion | 4.1.0.0 |
Comments | Enjoy! |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to AES |
Suspicious | The PE is possibly packed. | Unusual section name found: .itext |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
Resource TFORM7 is possibly compressed or encrypted.
Resource TFORM8 is possibly compressed or encrypted. The resource timestamps differ from the PE header:
|
Suspicious | VirusTotal score: 2/72 (Scanned on 2022-11-17 00:31:24) |
APEX:
Malicious
MaxSecure: Trojan.Malware.300983.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 9 |
TimeDateStamp | 1992-Jun-19 22:22:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0xdc400 |
SizeOfInitializedData | 0x54800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000DD5F0 (Section: .itext) |
BaseOfCode | 0x1000 |
BaseOfData | 0xde000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x13d000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
---|---|
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
user32.dll |
GetKeyboardType
DestroyWindow LoadStringA MessageBoxA CharNextA |
kernel32.dll |
GetACP
Sleep VirtualFree VirtualAlloc GetTickCount QueryPerformanceCounter GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CompareStringA WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
kernel32.dll (#2) |
GetACP
Sleep VirtualFree VirtualAlloc GetTickCount QueryPerformanceCounter GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CompareStringA WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
user32.dll (#2) |
GetKeyboardType
DestroyWindow LoadStringA MessageBoxA CharNextA |
opengl32.dll |
wglMakeCurrent
wglDeleteContext wglCreateContext |
msimg32.dll |
GradientFill
|
gdi32.dll |
UnrealizeObject
SwapBuffers StretchBlt SetWindowOrgEx SetWinMetaFileBits SetViewportOrgEx SetTextColor SetStretchBltMode SetROP2 SetPixelFormat SetPixel SetEnhMetaFileBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SelectPalette SelectObject SelectClipRgn SaveDC RestoreDC Rectangle RectVisible RealizePalette Polyline Polygon PlayEnhMetaFile PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsA GetTextExtentPointA GetTextExtentPoint32A GetSystemPaletteEntries GetStockObject GetRgnBox GetPixel GetPaletteEntries GetObjectA GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits GdiFlush ExtTextOutA ExcludeClipRect DeleteObject DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateHalftonePalette CreateFontIndirectA CreateDIBitmap CreateDIBSection CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileA CombineRgn ChoosePixelFormat BitBlt |
version.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
kernel32.dll (#3) |
GetACP
Sleep VirtualFree VirtualAlloc GetTickCount QueryPerformanceCounter GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CompareStringA WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
ole32.dll |
CoTaskMemAlloc
CoCreateInstance CoUninitialize CoInitializeEx CoInitialize |
kernel32.dll (#4) |
GetACP
Sleep VirtualFree VirtualAlloc GetTickCount QueryPerformanceCounter GetCurrentThreadId InterlockedDecrement InterlockedIncrement VirtualQuery WideCharToMultiByte SetCurrentDirectoryA MultiByteToWideChar lstrlenA lstrcpynA LoadLibraryExA GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleA GetModuleFileNameA GetLocaleInfoA GetLastError GetCurrentDirectoryA GetCommandLineA FreeLibrary FindFirstFileA FindClose ExitProcess ExitThread CompareStringA WriteFile UnhandledExceptionFilter SetFilePointer SetEndOfFile RtlUnwind ReadFile RaiseException GetStdHandle GetFileSize GetFileType CreateFileA CloseHandle |
oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
comctl32.dll |
_TrackMouseEvent
ImageList_SetIconSize ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_GetIcon ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControls |
shell32.dll |
Shell_NotifyIconA
ShellExecuteA |
shell32.dll (#2) |
Shell_NotifyIconA
ShellExecuteA |
comdlg32.dll |
GetOpenFileNameA
|
glu32.dll |
gluPerspective
|
opengl32.dll (#2) |
wglMakeCurrent
wglDeleteContext wglCreateContext |
Input is not an valid %s Format. |
Input can not be convert to %s Format. |
copy Input to Output |
Hexadecimal |
Hexadecimal lowercase |
MIME Base 64 |
UU Coding |
XX Coding |
Length from Encryptionkey is invalid. |
Keysize for %s must be to %d-%d bytes |
%s is not initialized call Init() or InitKey() before. |
Enter password: |
Please insert a blank disk #%d |
Please insert the first disk |
Please insert the last disk |
Please insert disk #%d |
Disk is full. Required free space: %d bytes, but available only: %d bytes. Clean the disk or find another blank disk |
%s. File processing error, possibly disk is full |
File '%s' not found on inserted disk. Please insert last disk with required file |
Buffer overflow |
Invalid UTF7 |
OLE error %.8x |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
Dispatch methods do not support more than 64 parameters |
Circular Protection detected, Protection Object is invalid. |
String Format "%d" not exists. |
ASCII |
Unicode |
Big Endian Unicode |
UTF-8 |
UTF-7 |
Cannot remove shell notification icon |
Cannot create shell notification icon |
Invalid index |
Unable to insert an item |
Invalid owner |
This control requires version 4.70 or greater of COMCTL32.DLL |
Cannot change the size of a JPEG image |
JPEG error #%d |
JPEG Image File |
Overwrite file "%s" with "%s" |
Password for "%s" |
Ctrl+ |
Alt+ |
Unable to insert a line |
Clipboard does not support Icons |
Cannot open clipboard |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
Error loading dock zone from the stream. Expecting version %d, but found %d. |
Multiselect mode must be on for this feature |
Separator |
No OnGetItem event handler assigned |
"%s" is an invalid path |
ANSI |
BkSp |
Tab |
Esc |
Enter |
Space |
PgUp |
PgDn |
End |
Home |
Left |
Up |
Right |
Down |
Ins |
Del |
Shift+ |
Bitmaps |
Warning |
Error |
Information |
Confirm |
&Yes |
&No |
OK |
Cancel |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
Yes to &All |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
OK |
Cancel |
&Yes |
&No |
&Help |
&Close |
&Ignore |
&Retry |
Abort |
&All |
Cannot drag a form |
Metafiles |
Enhanced Metafiles |
Icons |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Parent given is not a parent of '%s' |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Cannot make a visible window modal |
%s property out of range |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
GroupIndex cannot be less than a previous menu item's GroupIndex |
No help found for context |
No topic-based help system installed |
Bitmap image is not valid |
Icon image is not valid |
Metafile is not valid |
Invalid pixel format |
Scan line index out of range |
Cannot change the size of an icon |
Unknown picture file extension (.%s) |
Unsupported clipboard format |
Out of system resources |
Canvas does not allow drawing |
Invalid image size |
Invalid ImageList |
Unable to Replace Image |
Invalid ImageList Index |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
Error reading %s%s%s: %s |
Stream read error |
Property is read-only |
Failed to get data for '%s' |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
%s not in a class registration group |
Property %s does not exist |
Stream write error |
Unable to find a Table of Contents |
No help found for %s |
No context-sensitive help installed |
Can't write to a read-only resource stream |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file "%s". %s |
Cannot open file "%s". %s |
Invalid stream format |
''%s'' is not a valid component name |
Invalid property value |
Invalid property path |
Invalid property value |
Invalid data type for '%s' |
List capacity out of bounds (%d) |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
December |
Sun |
Interface not supported |
Exception in safecall method |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Aug |
Sep |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
Invalid variant type conversion |
Invalid variant operation |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Format string too long |
'%s' is not a valid integer value |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 4.1.0.0 |
ProductVersion | 4.1.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Russian - Russia |
CompanyName | |
FileDescription | |
FileVersion (#2) | 4.1.0.0 |
InternalName | |
LegalCopyright | paul_met & EdHell |
LegalTrademarks | |
OriginalFilename | MakaronEX |
ProductName | MakaronEX NewGen |
ProductVersion (#2) | 4.1.0.0 |
Comments | Enjoy! |
Resource LangID | Russian - Russia |
---|
StartAddressOfRawData | 0x4f2000 |
---|---|
EndAddressOfRawData | 0x4f2054 |
AddressOfIndex | 0x4de7b4 |
AddressOfCallbacks | 0x4f3010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |