Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2012-Jan-12 00:05:48 |
Detected languages |
English - United States
|
CompanyName | The MASM32 SDK |
FileDescription | MASM32 Installation |
FileVersion | 11.0 |
InternalName | Install |
OriginalFilename | install.exe |
LegalCopyright | © 2011 The MASM32 SDK |
ProductName | MASM32 SDK |
ProductVersion | 11.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C# v7.0 / Basic .NET MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
Info | The PE contains common functions which appear in legitimate applications. |
Possibly launches other programs:
|
Malicious | VirusTotal score: 5/71 (Scanned on 2020-02-09 23:03:59) |
Bkav:
HW32.Packed.
APEX: Malicious Trapmine: malicious.high.ml.score eGambit: Unsafe.AI_Score_99% Cybereason: malicious.c9dbf3 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2012-Jan-12 00:05:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x1800 |
SizeOfInitializedData | 0x4f1600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001000 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x3000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x4f6000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
gdi32.dll |
CreateFontA
GetStockObject |
---|---|
user32.dll |
SetCapture
ReleaseCapture LoadBitmapA GetWindowRect GetWindowLongA GetDlgCtrlID UpdateWindow TranslateMessage ShowWindow SetWindowTextA SetWindowPos SetWindowLongA SetMenu SetForegroundWindow SetFocus SendMessageA RegisterClassExA PostQuitMessage MessageBoxIndirectA LoadMenuA LoadIconA LoadCursorA GetSystemMetrics GetParent GetMessageA GetDlgItem EndDialog DispatchMessageA DialogBoxParamA DialogBoxIndirectParamA DefWindowProcA CreateWindowExA CallWindowProcA AnimateWindow |
kernel32.dll |
DeleteFileA
WriteFile FlushFileBuffers ReadFile GetFileSize CreateFileA FindFirstFileA FindClose Sleep SetThreadPriority SetPriorityClass GetThreadPriority GetExitCodeProcess GetCurrentThread CreateProcessA CloseHandle WinExec SleepEx SetCurrentDirectoryA RemoveDirectoryA MultiByteToWideChar GlobalFree GlobalAlloc GetVolumeInformationA GetModuleHandleA GetLogicalDriveStringsA GetDriveTypeA GetCurrentDirectoryA GetCommandLineA ExitProcess CreateDirectoryA |
comctl32.dll |
InitCommonControlsEx
|
shell32.dll |
ShellExecuteA
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 11.0.0.0 |
ProductVersion | 11.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | The MASM32 SDK |
FileDescription | MASM32 Installation |
FileVersion (#2) | 11.0 |
InternalName | Install |
OriginalFilename | install.exe |
LegalCopyright | © 2011 The MASM32 SDK |
ProductName | MASM32 SDK |
ProductVersion (#2) | 11.0 |
Resource LangID | English - United States |
---|
XOR Key | 0xf0c17688 |
---|---|
Unmarked objects | 0 |
19 (8078) | 80 |
18 (8444) | 10 |
42 (8803) | 1 |
Unmarked objects (#2) | 2 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |