| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2013-Oct-18 09:26:29 |
| Detected languages |
English - United States
|
| FileVersion | 2, 0, 0, 0 |
| ProductVersion | 2, 0, 0, 0 |
| LegalCopyright | Copyright (C) 2021 |
| FileDescription | FSScanConfig v2.0 |
| ProductName | FSScanConfig |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource 129 is possibly compressed or encrypted. |
| Info | The PE is digitally signed. |
Signer: Freshworks Inc
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Malicious | VirusTotal score: 3/74 (Scanned on 2024-07-16 03:23:40) |
Jiangmin:
Worm.VBS.adn
VirIT: Trojan.Win32.DownLoader17.DNGL Xcitium: TrojWare.Win32.TrojanDropper.Dexel.A@6k1yft |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2013-Oct-18 09:26:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x2b200 |
| SizeOfInitializedData | 0x30400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0001A388 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x63000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6609e |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FileTimeToLocalFileTime
GetFileAttributesW GetFileSizeEx GetFileTime HeapAlloc HeapFree RtlUnwind HeapReAlloc RaiseException VirtualProtect VirtualAlloc GetSystemInfo VirtualQuery HeapSize TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetCPInfo GetACP GetOEMCP IsValidCodePage GetModuleFileNameA FreeEnvironmentStringsW CreateFileW SetHandleCount GetStartupInfoA HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetSystemTimeAsFileTime InitializeCriticalSectionAndSpinCount GetTimeZoneInformation GetConsoleCP GetConsoleMode LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA SetStdHandle WriteConsoleA WriteConsoleW CreateFileA SetEnvironmentVariableA GetFullPathNameW GetVolumeInformationW FindFirstFileW FindClose GetCurrentProcess DuplicateHandle GetFileSize SetEndOfFile UnlockFile LockFile WritePrivateProfileStringW GetModuleHandleA GlobalFlags TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection GlobalHandle GlobalReAlloc EnterCriticalSection TlsGetValue LeaveCriticalSection LocalAlloc FileTimeToSystemTime GetCurrentProcessId SetErrorMode GetCurrentThread ConvertDefaultLocale EnumResourceLanguagesW GetLocaleInfoW LoadLibraryExW CompareStringA InterlockedExchange InterlockedDecrement InterlockedIncrement lstrlenA lstrcmpA GetCurrentThreadId GlobalAddAtomW GlobalFindAtomW GlobalDeleteAtom LoadLibraryW CompareStringW LoadLibraryA FreeLibrary lstrcmpW GetProcAddress GetVersionExA SetLastError GlobalFree GlobalAlloc GlobalLock GlobalUnlock lstrlenW SetFilePointer ReadFile WriteFile SetConsoleOutputCP GetConsoleOutputCP WideCharToMultiByte GetFileType FlushFileBuffers ExpandEnvironmentStringsW CloseHandle GetExitCodeProcess WaitForSingleObject GetModuleFileNameW ExitProcess LocalFree GetLastError FormatMessageW GetStdHandle CreateThread Sleep GetModuleHandleW GetCommandLineW MultiByteToWideChar FindResourceW LoadResource LockResource GetEnvironmentStringsW SizeofResource |
|---|---|
| USER32.dll |
CharUpperW
SetCursor GrayStringW DrawTextExW DrawTextW TabbedTextOutW ClientToScreen DestroyMenu ShowWindow SetWindowTextW LoadCursorW GetDC ReleaseDC GetSysColorBrush GetWindowThreadProcessId IsWindowEnabled PostQuitMessage SetMenuItemBitmaps GetMenuCheckMarkDimensions ModifyMenuW EnableMenuItem GetMessageW GetCursorPos ValidateRect RegisterWindowMessageW LoadIconW WinHelpW GetCapture SetWindowsHookExW CallNextHookEx GetClassLongW GetClassNameW SetPropW GetPropW RemovePropW GetFocus IsWindow GetWindowTextW GetForegroundWindow GetLastActivePopup GetDlgItem GetTopWindow DestroyWindow UnhookWindowsHookEx GetMessageTime GetMessagePos MapWindowPoints GetKeyState SetMenu GetActiveWindow MsgWaitForMultipleObjects PeekMessageW TranslateMessage EnableWindow SetForegroundWindow IsWindowVisible GetClientRect PostMessageW MessageBoxW CreateWindowExW GetClassInfoExW GetClassInfoW LoadBitmapW DispatchMessageW CharToOemBuffW GetSubMenu GetMenuItemCount GetMenuItemID GetMenuState GetWindow GetSystemMetrics GetWindowRect GetWindowPlacement IsIconic SystemParametersInfoA SetWindowPos SetWindowLongW GetWindowLongW GetMenu PtInRect CopyRect RegisterClassW GetSysColor AdjustWindowRectEx GetParent GetDlgCtrlID SendMessageW DefWindowProcW CallWindowProcW CheckMenuItem |
| GDI32.dll |
DeleteDC
GetStockObject ScaleWindowExtEx SetWindowExtEx ScaleViewportExtEx SetViewportExtEx OffsetViewportOrgEx SetViewportOrgEx SelectObject Escape TextOutW RectVisible GetDeviceCaps SetMapMode RestoreDC SaveDC DeleteObject ExtTextOutW CreateBitmap SetBkColor SetTextColor GetClipBox PtVisible |
| COMDLG32.dll |
GetFileTitleW
|
| WINSPOOL.DRV |
DocumentPropertiesW
OpenPrinterW ClosePrinter |
| ADVAPI32.dll |
RegSetValueExW
RegEnumKeyW RegDeleteKeyW RegQueryValueW RegOpenKeyW RegCreateKeyExW RegCloseKey RegQueryValueExW RegEnumKeyExW RegOpenKeyExW CreateProcessWithLogonW |
| SHLWAPI.dll |
PathStripToRootW
PathIsUNCW PathFindFileNameW PathFindExtensionW |
| ole32.dll |
CoDisconnectObject
StringFromGUID2 CoGetObject CoCreateInstance CLSIDFromProgID CoInitialize |
| OLEAUT32.dll |
SysFreeString
VariantInit VariantCopy VariantClear SysAllocStringLen VariantChangeType LoadTypeLibEx LoadRegTypeLib SysAllocString SysStringLen LoadTypeLib |
| OLEACC.dll (delay-loaded) |
LresultFromObject
CreateStdAccessibleObject |
| Attributes | 0x1 |
|---|---|
| Name | OLEACC.dll |
| ModuleHandle | 0x3ced0 |
| DelayImportAddressTable | 0x3a3ec |
| DelayImportNameTable | 0x36454 |
| BoundDelayImportTable | 0x36490 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| mycscript |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.0.0 |
| ProductVersion | 2.0.0.0 |
| FileFlags |
VS_FF_DEBUG
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 2, 0, 0, 0 |
| ProductVersion (#2) | 2, 0, 0, 0 |
| LegalCopyright | Copyright (C) 2021 |
| FileDescription | FSScanConfig v2.0 |
| ProductName | FSScanConfig |
| Resource LangID | UNKNOWN |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x438dd4 |
| SEHandlerTable | 0x433e70 |
| SEHandlerCount | 115 |
| XOR Key | 0x632ec4c9 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 8 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 21 |
| Total imports | 520 |
| ASM objects (VS2008 SP1 build 30729) | 25 |
| C objects (VS2008 SP1 build 30729) | 150 |
| C++ objects (VS2008 SP1 build 30729) | 130 |
| C++ objects (VS2008 build 21022) | 3 |
| 138 (VS2008 SP1 build 30729) | 8 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |