Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Apr-30 12:00:00 |
Detected languages |
English - United States
|
CompanyName | Igor Pavlov |
FileDescription | 7z SFX |
FileVersion | 18.05 |
InternalName | 7z.sfx |
LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
OriginalFilename | 7z.sfx.exe |
ProductName | 7-Zip |
ProductVersion | 18.05 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to AES |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | The file contains overlay data. |
10454556 bytes of data starting at offset 0x32400.
The file contains a 7-Zip compressed file after the PE data. Overlay data amounts for 98.0693% of the executable. |
Malicious | VirusTotal score: 3/70 (Scanned on 2023-06-30 09:41:07) |
Bkav:
W32.AIDetectMalware
CrowdStrike: win/grayware_confidence_60% (D) Trapmine: malicious.moderate.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Apr-30 12:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x29400 |
SizeOfInitializedData | 0xd000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0002769C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2b000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
OLEAUT32.dll |
SysFreeString
SysAllocStringLen SysAllocString VariantClear SysStringLen |
---|---|
ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize OleInitialize |
USER32.dll |
CheckDlgButton
IsDlgButtonChecked EndDialog SetDlgItemTextW GetFocus SetFocus GetKeyState InvalidateRect SetWindowTextW EnableWindow PostMessageW MessageBoxW SetTimer DialogBoxParamW SetWindowLongW GetWindowLongW ShowWindow MoveWindow ScreenToClient GetDlgItem GetWindowRect MapDialogRect SystemParametersInfoW GetWindowTextLengthW GetWindowTextW SendMessageW LoadStringW CharUpperW LoadIconW GetParent SetCursor LoadCursorW KillTimer |
SHELL32.dll |
SHGetPathFromIDListW
SHBrowseForFolderW SHGetFileInfoW SHGetMalloc |
MSVCRT.dll |
wcsstr
wcscmp _beginthreadex _except_handler3 ??1type_info@@UAE@XZ ?terminate@@YAXXZ __dllonexit _onexit _exit _XcptFilter exit _acmdln __getmainargs _initterm __setusermatherr _adjust_fdiv __p__commode __p__fmode __set_app_type _controlfp _CxxThrowException malloc memcpy memmove memset _purecall memcmp __CxxFrameHandler free |
KERNEL32.dll |
GetStartupInfoA
InitializeCriticalSection ResetEvent SetEvent CreateEventW WaitForSingleObject lstrlenW lstrcatW VirtualFree VirtualAlloc SetPriorityClass DeleteCriticalSection Sleep EnterCriticalSection LeaveCriticalSection WaitForMultipleObjects GetFileInformationByHandle GetStdHandle GlobalMemoryStatus GetSystemInfo GetCurrentProcess GetProcessAffinityMask FileTimeToLocalFileTime FileTimeToSystemTime CompareFileTime SetEndOfFile WriteFile ReadFile SetFilePointer GetFileSize GetLogicalDriveStringsW GetFileAttributesW GetModuleHandleA FindNextFileW FindFirstFileW FindClose GetTickCount GetCurrentDirectoryW SetLastError DeleteFileW CreateDirectoryW GetModuleHandleW MoveFileW RemoveDirectoryW SetFileAttributesW CreateFileW SetFileTime CloseHandle GetSystemDirectoryW FormatMessageW LocalFree GetModuleFileNameW MultiByteToWideChar GetLastError GetVersionExW LoadLibraryW GetProcAddress FreeLibrary GetCommandLineW LoadLibraryExW |
&Close |
&Continue |
&Foreground |
Paused |
Are you sure you want to cancel? |
Modified |
The system cannot allocate the required amount of memory |
Cannot create folder '{0}' |
Update operations are not supported for this archive. |
Can not open file '{0}' as archive |
Can not open encrypted archive '{0}'. Wrong password? |
Unsupported archive type |
Can not open the file as {0} archive |
The file is open as {0} archive |
The archive is open with offset |
Extracting |
Skipping |
Specify a location for extracted files. |
Full pathnames |
No pathnames |
Absolute pathnames |
Relative pathnames |
Ask before overwrite |
Overwrite without prompt |
Skip existing files |
Auto rename |
Auto rename existing files |
{0} bytes |
Unsupported compression method for '{0}'. |
Data error in '{0}'. File is broken |
CRC failed in '{0}'. File is broken. |
Data error in encrypted file '{0}'. Wrong password? |
CRC failed in encrypted file '{0}'. Wrong password? |
Wrong password? |
Unsupported compression method |
Data error |
CRC failed |
Unavailable data |
Unexpected end of data |
There are some data after the end of the payload data |
Is not archive |
Headers Error |
Wrong password |
Unavailable start of archive |
Unconfirmed start of archive |
Unsupported feature |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 18.5.0.0 |
ProductVersion | 18.5.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Igor Pavlov |
FileDescription | 7z SFX |
FileVersion (#2) | 18.05 |
InternalName | 7z.sfx |
LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
OriginalFilename | 7z.sfx.exe |
ProductName | 7-Zip |
ProductVersion (#2) | 18.05 |
Resource LangID | English - United States |
---|
XOR Key | 0x11c369bd |
---|---|
Unmarked objects | 0 |
C++ objects (8047) | 3 |
14 (7299) | 8 |
C objects (8047) | 11 |
Linker (8047) | 2 |
C objects (2190) | 2 |
Total imports | 160 |
Imports (2179) | 13 |
C++ objects (VS98 SP6 build 8804) | 88 |
C objects (VS98 SP6 build 8804) | 3 |
C objects (VS2010 SP1 build 40219) | 15 |
ASM objects (VS2010 SP1 build 40219) | 2 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |