| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Jul-21 03:07:05 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\LU\PRJ\smr.softpaqwrapper\Release\hpsoftpaqwrapper.pdb
|
| CompanyName | HP Inc. |
| FileDescription | Intel Management Engine Firmware |
| FileVersion | 0.2.75.23816 |
| InternalName | hpsoftpaqwrapper |
| OriginalFilename | hpsoftpaqwrapper.exe |
| ProductName | Intel Management Engine Firmware |
| ProductVersion | 11.8.94.4494 |
| LegalCopyright | Copyright (c) 2022 HP Development Company, LP. |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: HP Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/72 (Scanned on 2025-08-17 20:57:19) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2022-Jul-21 03:07:05 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x5f400 |
| SizeOfInitializedData | 0x37e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000487F4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x68b0b4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WideCharToMultiByte
SizeofResource LockResource LoadResource FindResourceW FindResourceExW CreateFileW SetFilePointer OutputDebugStringW GetEnvironmentVariableW GetFileSizeEx CreateFileMappingW MapViewOfFile UnmapViewOfFile LocalFree ExpandEnvironmentStringsW DosDateTimeToFileTime LocalFileTimeToFileTime SetFileTime SetFileAttributesW CreateDirectoryW GetFileAttributesW FreeLibrary LoadLibraryW TlsSetValue TlsGetValue GetTickCount GetCurrentProcess GetExitCodeThread ResumeThread TlsAlloc GlobalAlloc GlobalFree SetLastError RemoveDirectoryW GetTempPathW GetSystemDirectoryW DeleteFileW GetCurrentDirectoryW GetCurrentProcessId FindFirstFileW FindNextFileW FindClose GetModuleHandleA SetEndOfFile GetFileSize GetDiskFreeSpaceW GetDriveTypeW GetProcessAffinityMask MultiByteToWideChar GlobalMemoryStatusEx MulDiv FreeResource GlobalLock GlobalUnlock lstrcmpiW LoadLibraryExW GetModuleFileNameW EncodePointer CreateProcessW GetExitCodeProcess VirtualAlloc SetSearchPathMode GetShortPathNameW GetCommandLineW AttachConsole AllocConsole FreeConsole lstrlenW FlushFileBuffers FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP IsValidCodePage WriteConsoleW SetStdHandle GetStringTypeW LCMapStringW GetACP ExitProcess GetCPInfo GetFileType SetFilePointerEx GetConsoleCP ReadConsoleW GetConsoleMode FreeLibraryAndExitThread ExitThread CreateThread RtlPcToFileHeader RtlUnwindEx QueryPerformanceCounter GetStartupInfoW ResetEvent CloseHandle SetEvent CreateEventW WaitForSingleObject InitializeCriticalSection WaitForMultipleObjects GetFileInformationByHandle WriteFile GetStdHandle GetSystemInfo ReadFile VirtualFree LeaveCriticalSection EnterCriticalSection GetModuleHandleW GetProcessHeap DeleteCriticalSection GetProcAddress HeapDestroy DecodePointer HeapAlloc RaiseException HeapReAlloc GetLastError FormatMessageW HeapSize GetCurrentThreadId IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext WaitForSingleObjectEx GetSystemTimeAsFileTime TlsFree SwitchToThread InitializeCriticalSectionAndSpinCount GetFullPathNameW GetFileAttributesExW FindFirstFileExW FlushInstructionCache InterlockedPushEntrySList InitializeCriticalSectionEx GetModuleHandleExW HeapFree SearchPathW InterlockedPopEntrySList InitializeSListHead IsDebuggerPresent LoadLibraryExA VirtualQuery VirtualProtect |
|---|---|
| USER32.dll |
SetWindowLongW
GetWindowLongW SetDlgItemTextW SetWindowPos MapWindowPoints LoadCursorW SetCursor SendMessageW EnableWindow PostMessageW GetParent GetWindowRect GetDlgItem CharUpperW GetWindowTextLengthW GetWindowTextW GetActiveWindow SetFocus IsWindowVisible SetRectEmpty RegisterWindowMessageW GetDC ReleaseDC SetWindowTextW UnregisterClassW MessageBoxW GetWindowLongPtrW BeginPaint CharNextW SetWindowLongPtrW GetWindow MonitorFromWindow GetMonitorInfoW DefWindowProcW DestroyWindow CallWindowProcW GetSysColor GetClientRect EndPaint |
| GDI32.dll |
CreateFontIndirectW
SetStretchBltMode ExtTextOutW SetBkColor SetDIBColorTable SelectObject StretchBlt CreateDIBSection CreateCompatibleDC DeleteDC GetDeviceCaps GetObjectW DeleteObject |
| ADVAPI32.dll |
RegQueryInfoKeyW
OpenProcessToken SetNamedSecurityInfoW LookupPrivilegeValueW AdjustTokenPrivileges RegDeleteValueW RegCreateKeyExW RegSetValueExW RegOpenKeyExW RegEnumKeyExW AllocateAndInitializeSid RegCloseKey RegDeleteKeyW FreeSid GetSecurityDescriptorDacl ConvertStringSecurityDescriptorToSecurityDescriptorW |
| SHELL32.dll |
CommandLineToArgvW
SHBrowseForFolderW SHGetPathFromIDListW |
| ole32.dll |
OleUninitialize
OleInitialize CoCreateInstance CoInitialize CoTaskMemRealloc CreateStreamOnHGlobal CoTaskMemFree CoTaskMemAlloc |
| OLEAUT32.dll |
VariantClear
VarUI4FromStr SysFreeString SysAllocString SysAllocStringLen VariantCopy |
| SHLWAPI.dll |
StrStrIW
|
| COMCTL32.dll |
DestroyPropertySheetPage
InitCommonControlsEx PropertySheetW CreatePropertySheetPageW |
| gdiplus.dll |
GdipGetImageWidth
GdipGetImageHeight GdipGetImagePixelFormat GdipGetImagePaletteSize GdipGetImagePalette GdipCreateBitmapFromStream GdipCreateBitmapFromScan0 GdipBitmapLockBits GdipFree GdipAlloc GdipDisposeImage GdipGetImageGraphicsContext GdipDeleteGraphics GdipDrawImageI GdipBitmapUnlockBits GdiplusShutdown GdiplusStartup GdipCloneImage |
| MPR.dll (delay-loaded) |
WNetAddConnection2W
WNetEnumResourceW WNetCloseEnum WNetCancelConnection2W WNetOpenEnumW |
| Attributes | 0x1 |
|---|---|
| Name | MPR.dll |
| ModuleHandle | 0x85a80 |
| DelayImportAddressTable | 0x85a50 |
| DelayImportNameTable | 0x80b88 |
| BoundDelayImportTable | 0x80c20 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Usage: /s /e /f <target-path> |
| /s - Un-package the package in silent mode (not showing user interaction UI) |
| /f - Runtime switch that overrides the default target path specified in build time |
| /e - Prevent execution of default executable file specified in build time. |
| Only extracting the content files to target folder(Use this with /s /f) |
| License Agreement |
| Please read the following license agreement carefully. |
| Location to Save Files |
| Where would you like to save your files? |
| Extracting Files |
| The contents of this package are being extracted. |
| I &accept the terms in the license agreement |
| I &do not accept the terms in the license agreement |
| Please enter the folder where you want these files saved. If the folder does not exist, it will be created for you. To continue, click Next. |
| &Save files in folder: |
| &Change... |
| Please wait while the HP Softpaq Wrapper extracts the files needed to install %s on your computer. This may take a few moments. |
| Extracting %s... |
| Welcome to the HP Softpaq Wrapper for %s |
| The HP Softpaq Wrapper will help install %s on your computer. To continue, click Next. |
| The HP Softpaq Wrapper has finished %s on your computer. To exit the wrapper, click Finish. |
| HP Softpaq Wrapper Completed |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.2.75.23816 |
| ProductVersion | 0.2.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | HP Inc. |
| FileDescription | Intel Management Engine Firmware |
| FileVersion (#2) | 0.2.75.23816 |
| InternalName | hpsoftpaqwrapper |
| OriginalFilename | hpsoftpaqwrapper.exe |
| ProductName | Intel Management Engine Firmware |
| ProductVersion (#2) | 11.8.94.4494 |
| LegalCopyright | Copyright (c) 2022 HP Development Company, LP. |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Jul-21 03:07:05 |
| Version | 0.0 |
| SizeofData | 82 |
| AddressOfRawData | 0x76144 |
| PointerToRawData | 0x74944 |
| Referenced File | C:\LU\PRJ\smr.softpaqwrapper\Release\hpsoftpaqwrapper.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Jul-21 03:07:05 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x76198 |
| PointerToRawData | 0x74998 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Jul-21 03:07:05 |
| Version | 0.0 |
| SizeofData | 1080 |
| AddressOfRawData | 0x761ac |
| PointerToRawData | 0x749ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Jul-21 03:07:05 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140076608 |
|---|---|
| EndAddressOfRawData | 0x140076610 |
| AddressOfIndex | 0x1400862cc |
| AddressOfCallbacks | 0x140061930 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x100 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140083010 |
| XOR Key | 0x7be92cc6 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 5 |
| 243 (40116) | 138 |
| 242 (40116) | 13 |
| C objects (VS 2015/2017 runtime 26706) | 19 |
| ASM objects (VS 2015/2017 runtime 26706) | 8 |
| C++ objects (VS 2015/2017 runtime 26706) | 61 |
| C objects (65501) | 2 |
| Imports (65501) | 21 |
| Total imports | 305 |
| C++ objects (LTCG) (27045) | 91 |
| Resource objects (27045) | 1 |
| 151 | 2 |
| Linker (27045) | 1 |
No comments yet.