Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Jul-03 19:37:15 |
Detected languages |
English - United States
|
Debug artifacts |
D:\dbs\el\ddvsm\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb
|
FileDescription | Setup |
FileVersion | 17.0.35103.136 built by: d17.11 |
InternalName | setup.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | setup.exe |
ProductVersion | 17.0.35103.136 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. | Resource FILEDATA0 detected as a PE Executable. |
Safe | VirusTotal score: 0/72 (Scanned on 2024-12-09 17:13:15) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2024-Jul-03 19:37:15 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5d600 |
SizeOfInitializedData | 0x4a800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00036FC0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x5f000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | A.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xad000 |
SizeOfHeaders | 0x400 |
Checksum | 0x86087 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
OpenProcess
GetNativeSystemInfo EndUpdateResourceW VerifyVersionInfoW CreateToolhelp32Snapshot Process32FirstW Process32NextW SetEvent CreateEventW LoadResource LockResource SizeofResource FindResourceW GetEnvironmentVariableW ExpandEnvironmentStringsW CreateDirectoryW DeleteFileW GetFileAttributesW GetTempFileNameW Sleep GetTempPathW GetCurrentProcess GetSystemInfo GetSystemDirectoryW GetWindowsDirectoryW GetVersionExW GetModuleFileNameW GetModuleHandleA GlobalAlloc GlobalFree LocalFree FormatMessageW CopyFileW GetDateFormatW GetTimeFormatW CompareStringW WideCharToMultiByte InitializeCriticalSectionAndSpinCount HeapSetInformation SetFilePointer GetDiskFreeSpaceExW CreateFileW VerSetConditionMask DeleteCriticalSection CreateThread LeaveCriticalSection EnterCriticalSection InitializeCriticalSection lstrlenW GetCurrentProcessId MulDiv GetTickCount GetExitCodeProcess LoadLibraryW ReadFile SwitchToThread FindNextFileW UpdateResourceA BeginUpdateResourceA FindResourceA lstrlenA DeleteFileA CreateFileA UpdateResourceW BeginUpdateResourceW GetVersion GetEnvironmentVariableA LCMapStringEx InitializeCriticalSectionEx WriteConsoleW HeapReAlloc HeapSize GetProcessHeap GetStringTypeW SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW MultiByteToWideChar GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP SetEndOfFile IsValidCodePage FindFirstFileExW OutputDebugStringW SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW FindFirstFileW FindClose GetProcAddress FreeLibrary WaitForSingleObject GetLastError CloseHandle WriteFile HeapFree HeapAlloc GetFileType GetModuleHandleExW ExitProcess GetStdHandle LoadLibraryExW TlsFree TlsSetValue RaiseException VirtualProtect VirtualQuery GetModuleHandleW LoadLibraryExA QueryPerformanceCounter GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent TerminateProcess RtlUnwind SetLastError TlsAlloc TlsGetValue |
---|---|
GDI32.dll |
GetStockObject
EnumFontFamiliesExW DeleteObject CreateFontIndirectW GetObjectW GetTextMetricsW SelectObject GetTextExtentPoint32W GetDeviceCaps DeleteDC CreateCompatibleDC |
ole32.dll |
CoUninitialize
CoInitialize |
Secur32.dll |
GetComputerObjectNameW
|
SHELL32.dll |
SHGetMalloc
ShellExecuteExW SHGetPathFromIDListW SHGetSpecialFolderLocation ShellExecuteW ShellExecuteA |
USER32.dll |
SystemParametersInfoW
IsDialogMessageW LoadImageW LoadIconW LoadCursorW SetClassLongW SetCursor GetWindowRect GetClientRect SetWindowTextW ShowScrollBar SetForegroundWindow EnableWindow MsgWaitForMultipleObjects GetFocus SetFocus SendDlgItemMessageW SetDlgItemTextW GetDlgItem CreateDialogIndirectParamW CreateDialogParamW MoveWindow ShowWindow DestroyWindow SendMessageW SendMessageA PeekMessageW DispatchMessageW TranslateMessage ExitWindowsEx MessageBoxW ReleaseDC GetDC DrawTextW GetSystemMetrics GetDialogBaseUnits MessageBoxA ScreenToClient |
CRYPT32.dll |
CertGetCertificateChain
CertFreeCertificateChain CertVerifyCertificateChainPolicy |
WININET.dll |
InternetCrackUrlW
InternetCombineUrlW |
msi.dll |
#92
#150 #78 #8 |
SHLWAPI.dll |
UrlUnescapeW
|
ADVAPI32.dll (delay-loaded) |
RegCloseKey
RegQueryValueExA RegOpenKeyExW RegQueryValueExW AllocateAndInitializeSid FreeSid CryptAcquireContextW CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash RegQueryInfoKeyA RegOpenKeyExA RegEnumValueA RegCreateKeyExA RegSetValueExA RegSetValueExW RegQueryInfoKeyW RegEnumValueW RegCreateKeyExW |
Attributes | 0x1 |
---|---|
Name | ADVAPI32.dll |
ModuleHandle | 0x6076c |
DelayImportAddressTable | 0x64000 |
DelayImportNameTable | 0x5e194 |
BoundDelayImportTable | 0x5e3cc |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x21360 |
Ordinal | 2 |
---|---|
Address | 0x21390 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 17.0.35103.136 |
ProductVersion | 17.0.35103.136 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | Setup |
FileVersion (#2) | 17.0.35103.136 built by: d17.11 |
InternalName | setup.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | setup.exe |
ProductVersion (#2) | 17.0.35103.136 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Jul-03 19:37:15 |
Version | 0.0 |
SizeofData | 99 |
AddressOfRawData | 0xffd8 |
PointerToRawData | 0xf3d8 |
Referenced File | D:\dbs\el\ddvsm\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Jul-03 19:37:15 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x1003c |
PointerToRawData | 0xf43c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Jul-03 19:37:15 |
Version | 0.0 |
SizeofData | 1020 |
AddressOfRawData | 0x10050 |
PointerToRawData | 0xf450 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Jul-03 19:37:15 |
Version | 0.0 |
SizeofData | 4 |
AddressOfRawData | 0x1044c |
PointerToRawData | 0xf84c |
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x45f080 |
SEHandlerTable | 0x40fba8 |
SEHandlerCount | 189 |
GuardCFCheckFunctionPointer | 4596556 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x59181ac0 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2015/2017 runtime 25711) | 11 |
C++ objects (VS2015/2017 runtime 25711) | 178 |
C objects (VS2015/2017 runtime 25711) | 22 |
C objects (VS 2015-2022 runtime 33030) | 18 |
ASM objects (VS 2015-2022 runtime 33030) | 21 |
C++ objects (VS 2015-2022 runtime 33030) | 85 |
Imports (65501) | 25 |
Total imports | 351 |
ASM objects (33136) | 1 |
C++ objects (33136) | 31 |
Exports (33136) | 1 |
Resource objects (33136) | 1 |
Linker (33136) | 1 |