Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Apr-06 14:39:04 |
Detected languages |
Dutch - Netherlands
English - United States |
Comments | This installation was built with Inno Setup. |
CompanyName | Dmitry Bruhov |
FileDescription | WinThumbsPreloader Setup |
FileVersion | 1.0.1 |
LegalCopyright | Copyright (c) 2018 Dmitry Bruhov |
ProductName | WinThumbsPreloader |
ProductVersion | 1.0.1 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE is possibly packed. | Unusual section name found: .itext |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC+2 timezone. |
Suspicious | The file contains overlay data. |
513163 bytes of data starting at offset 0x1da00.
The overlay data has an entropy of 7.99965 and is possibly compressed or encrypted. Overlay data amounts for 80.8759% of the executable. |
Suspicious | VirusTotal score: 2/74 (Scanned on 2024-09-05 11:24:52) |
APEX:
Malicious
Bkav: W32.AIDetectMalware |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2016-Apr-06 14:39:04 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x10400 |
SizeOfInitializedData | 0xd200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000117DC (Section: .itext) |
BaseOfCode | 0x1000 |
BaseOfData | 0x12000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 6.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x28000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
---|---|
advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
user32.dll |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
kernel32.dll |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
kernel32.dll (#2) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
user32.dll (#2) |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
kernel32.dll (#3) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
comctl32.dll |
InitCommonControls
|
kernel32.dll (#4) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
advapi32.dll (#3) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
Friday |
Saturday |
Invalid file name - %s |
September |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
May |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
Invalid variant type conversion |
Invalid variant operation |
Invalid argument |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
Object lock not owned |
Monitor support function not initialized |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
Jan |
Feb |
Mar |
Apr |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Operation aborted |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Out of memory |
I/O error %d |
File not found |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.1.0 |
ProductVersion | 1.0.1.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
Comments | This installation was built with Inno Setup. |
CompanyName | Dmitry Bruhov |
FileDescription | WinThumbsPreloader Setup |
FileVersion (#2) | 1.0.1 |
LegalCopyright | Copyright (c) 2018 Dmitry Bruhov |
ProductName | WinThumbsPreloader |
ProductVersion (#2) | 1.0.1 |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0x41a000 |
---|---|
EndAddressOfRawData | 0x41a008 |
AddressOfIndex | 0x4127ac |
AddressOfCallbacks | 0x41b010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |