Architecture |
Subsystem |
Compilation Date | 2012-Nov-15 12:20:03 |
Detected languages |
English - United Kingdom
English - United States |
Debug artifacts |
CompanyName | Istanbul NLP |
FileDescription | Istanbul NLP |
FileVersion | |
InternalName | Istanbul NLP |
LegalCopyright | Istanbul NLP |
LegalTrademarks | Istanbul NLP |
OriginalFilename | Senior Okuma |
ProductName | Istanbul NLP |
ProductVersion | |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) |
Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser Crunch 4 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses constants related to TEA Uses known Diffie-Helman primes Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
Malicious | The PE is possibly a dropper. |
Resource 101 detected as a PE Executable.
Resource 102 detected as a PE Executable. Resource 107 is possibly compressed or encrypted. |
Suspicious | The file contains overlay data. | 5012124 bytes of data starting at offset 0x189b000. |
Suspicious | VirusTotal score: 1/70 (Scanned on 2023-12-17 05:09:05) | CrowdStrike: win/grayware_confidence_60% (D) |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x128 |
Signature | PE |
Machine |
NumberofSections | 6 |
TimeDateStamp | 2012-Nov-15 12:20:03 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 9.0 |
SizeOfCode | 0x569e00 |
SizeOfInitializedData | 0x1330e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x004F81AD (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x56b000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x18d5000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1a16a68 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WS2_32.dll |
gethostbyaddr inet_addr inet_ntoa gethostname setsockopt shutdown send sendto getsockopt __WSAFDIsSet select getsockname listen bind socket connect recvfrom accept recv WSAGetLastError getservbyname ntohl ioctlsocket getaddrinfo freeaddrinfo WSASetLastError getpeername WSAStartup htonl WSACleanup htons ntohs gethostbyname |
urlmon.dll |
DDRAW.dll |
d3d9.dll |
WinHttpOpen WinHttpGetProxyForUrl WinHttpCloseHandle |
KERNEL32.dll |
SetCommState PurgeComm FileTimeToSystemTime FileTimeToLocalFileTime GetFileTime GetTempFileNameW DebugBreak GetEnvironmentVariableW GetCPInfo IsValidCodePage GlobalMemoryStatus GetComputerNameW TerminateProcess OpenProcess GetFileType SetCurrentDirectoryW CopyFileW CreateMutexW ReleaseMutex TlsSetValue ExitProcess SetThreadPriority SuspendThread ResumeThread TlsGetValue TlsFree TlsAlloc GetModuleHandleA ExpandEnvironmentStringsW WaitForMultipleObjects CreatePipe PeekNamedPipe SetNamedPipeHandleState DuplicateHandle GetACP GetUserDefaultLCID IsValidLocale GetLocaleInfoW GetCurrentThread IsBadReadPtr IsBadStringPtrA EscapeCommFunction ReadConsoleOutputCharacterA GetConsoleScreenBufferInfo GetStdHandle WriteConsoleA WriteConsoleW FillConsoleOutputCharacterW SetConsoleCursorPosition SetErrorMode GetCommandLineW HeapSize GlobalSize SleepEx ExpandEnvironmentStringsA GetVersion GetVersionExA FlushConsoleInputBuffer WaitNamedPipeA OpenFileMappingA OpenEventA GetSystemDirectoryA GetModuleFileNameA GetWindowsDirectoryA GetLocaleInfoA CreateEventA ResetEvent GetFileAttributesExA SetCurrentDirectoryA GetCurrentDirectoryA QueryPerformanceFrequency FindNextFileA FindFirstFileA GetTimeZoneInformation HeapReAlloc IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter SetCommBreak GetCommState ClearCommError GetProcessHeap HeapFree HeapAlloc CreateThread CreateEventW GetExitCodeThread TerminateThread SetEvent FindNextFileW FindClose FindFirstFileW GetVolumeInformationW lstrlenA IsProcessorFeaturePresent CompareStringW CompareStringA GetStringTypeA EnumSystemLocalesA GetDateFormatA GetTimeFormatA SetEnvironmentVariableA GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA GetConsoleOutputCP InitializeCriticalSectionAndSpinCount GetOEMCP SetHandleCount HeapCreate GetStringTypeW LCMapStringW FreeConsole LCMapStringA SetConsoleMode ReadConsoleInputA DeviceIoControl GlobalMemoryStatusEx VerLanguageNameW GetStartupInfoW GetExitCodeProcess GetLogicalDriveStringsW CreateProcessW GetDriveTypeW GetSystemDefaultLangID OutputDebugStringA SetFileAttributesW GetShortPathNameW GetLongPathNameW WaitForSingleObject DeleteFileA AreFileApisANSI GetSystemTime LocalFree GetTempPathA GetCurrentProcessId DeleteFileW CloseHandle GetFileAttributesExW GetDiskFreeSpaceA CreateFileMappingW GetDiskFreeSpaceW LockFileEx GetTempPathW FlushFileBuffers CreateFileW ReadFile GetFileAttributesW GetFileAttributesA GetVersionExW FormatMessageW Sleep LoadLibraryW WideCharToMultiByte WriteFile FormatMessageA GetSystemTimeAsFileTime UnlockFileEx GetTickCount LockFile UnlockFile InterlockedCompareExchange QueryPerformanceCounter SetEndOfFile UnmapViewOfFile MapViewOfFile SetFilePointer GetFileSize CreateFileA GetFullPathNameA GetFullPathNameW LockResource InterlockedExchange LoadLibraryA VirtualAlloc VirtualFree lstrcmpA lstrcpynW GetCurrentThreadId DeleteCriticalSection lstrcmpiW EnterCriticalSection GetProcAddress SetLastError GetLastError RaiseException FlushInstructionCache GlobalUnlock lstrlenW MultiByteToWideChar lstrcmpW MulDiv LeaveCriticalSection SizeofResource GlobalAlloc InitializeCriticalSection GlobalLock GetCurrentProcess InterlockedDecrement InterlockedIncrement LoadLibraryExW LoadResource FreeLibrary FindResourceW OutputDebugStringW GetModuleFileNameW GetModuleHandleW GlobalFree GetConsoleCP SetConsoleCtrlHandler GetConsoleMode CreateDirectoryW SetEnvironmentVariableW GetCommandLineA GetStartupInfoA RtlUnwind SetStdHandle MoveFileW ExitThread GetFileInformationByHandle GetDriveTypeA |
USER32.dll |
GetDoubleClickTime DestroyCursor GetDialogBaseUnits DrawEdge DrawStateW SetRect CheckMenuRadioItem GetSysColorBrush DrawIconEx DrawFrameControl CreateMenu AppendMenuW ModifyMenuW RemoveMenu InsertMenuItemW InsertMenuW CreatePopupMenu SetMenuItemInfoW GetSubMenu DestroyMenu GetMenuState SetMenu FindWindowExW LoadBitmapW InflateRect PtInRect UnregisterHotKey RegisterHotKey GetMenuItemCount GetMenuItemInfoW BeginDeferWindowPos EndDeferWindowPos MapWindowPoints GetUpdateRgn DeferWindowPos IsDialogMessageW TrackPopupMenu GetCapture GetActiveWindow GetMessageTime IsWindowEnabled SetParent GetCursorPos WindowFromPoint ScrollWindow EnableScrollBar SetScrollInfo GetScrollInfo EnableWindow GetKeyState GetAsyncKeyState PostQuitMessage SetWindowRgn GetMenu GetSystemMenu EnableMenuItem DrawMenuBar GetWindowPlacement ValidateRect IsIconic BringWindowToTop CreateIconIndirect GetIconInfo DestroyIcon SetCursor MsgWaitForMultipleObjects SetTimer KillTimer DdePostAdvise DdeConnect DdeNameService DdeCreateStringHandleW DdeClientTransaction DdeDisconnect DdeInitializeW DdeGetLastError DdeCreateDataHandle DdeGetData DdeFreeDataHandle DdeQueryStringW DdeUninitialize DdeFreeStringHandle WaitForInputIdle SetActiveWindow UnregisterClassA MoveWindow GetWindow PostThreadMessageW RegisterClassW MessageBeep GetWindowThreadProcessId CallNextHookEx SetWindowsHookExW UnhookWindowsHookEx ShowCursor SetCursorPos mouse_event CheckMenuItem PostMessageW SetForegroundWindow FindWindowW ExitWindowsEx EnumWindows SystemParametersInfoW FlashWindow IsWindowVisible GetWindowDC IsClipboardFormatAvailable ShowWindow MessageBoxW GetSystemMetrics keybd_event CloseClipboard VkKeyScanW MapVirtualKeyW EmptyClipboard OpenClipboard SetClipboardData UnionRect DrawTextW OffsetRect DrawFocusRect GetMessagePos HideCaret ChildWindowFromPoint ValidateRgn wsprintfW ChangeDisplaySettingsW EnumDisplaySettingsW GetClipboardFormatNameW CreateDialogIndirectParamW DefWindowProcW CallWindowProcW SetWindowTextW SendMessageW GetUserObjectInformationW GetProcessWindowStation IsZoomed MessageBoxA ReleaseCapture CreateWindowExW IsWindow SetWindowPos GetSysColor GetDesktopWindow RedrawWindow SetWindowLongW GetDlgItem ReleaseDC GetClassNameW GetWindowTextW CreateDialogParamW GetWindowLongW InvalidateRect GetMessageW TranslateMessage PeekMessageW CopyRect DispatchMessageW UpdateLayeredWindow AdjustWindowRectEx GetWindowRect LoadImageW LoadIconW EnumDisplayMonitors UpdateWindow GetLayeredWindowAttributes EndPaint ClientToScreen DestroyWindow GetWindowTextLengthW DestroyAcceleratorTable ScreenToClient CharNextW RegisterWindowMessageW FillRect IsChild SetCapture UnregisterClassW GetFocus GetParent InvalidateRgn LoadCursorW RegisterClassExW GetDC GetClassInfoExW BeginPaint SetFocus CreateAcceleratorTableW GetClientRect |
GDI32.dll |
ExtSelectClipRgn ExtFloodFill GetCharABCWidthsW GetTextExtentExPointW Arc Pie Polygon SetPolyFillMode PolyPolygon Rectangle RoundRect Ellipse MaskBlt ExtTextOutW StretchBlt CreateDIBitmap CreatePalette GetDIBColorTable LineTo MoveToEx GetPaletteEntries GetNearestPaletteIndex ExtCreatePen CombineRgn CreateHatchBrush CreatePatternBrush SelectClipRgn RestoreDC CreateRectRgnIndirect CreateICW SetTextAlign GetSystemPaletteEntries SetAbortProc StartPage CreateDCW EnumFontFamiliesExW GetEnhMetaFileW DeleteEnhMetaFile GetEnhMetaFileHeader CreateEnhMetaFileW PlayEnhMetaFile CloseEnhMetaFile SetViewportExtEx SetWindowExtEx SetWindowOrgEx PolyBezier SetPixel GetPixel SetROP2 Polyline RectInRegion SaveDC GetClipBox PtInRegion EqualRgn GetRgnBox SetTextColor SetBkMode CreateFontIndirectW GetOutlineTextMetricsW ExcludeClipRect SetBrushOrgEx CreateRectRgn GdiFlush GetTextExtentPoint32W SelectPalette RealizePalette GetRegionData ExtCreateRegion OffsetRgn SetBkColor CreateBitmap GetDIBits StretchDIBits SetStretchBltMode EndPage GetTextMetricsW SetViewportOrgEx SetMapMode StartDocW TextOutW EndDoc CreateDIBSection BitBlt DeleteDC GetDeviceCaps DeleteObject SelectObject CreateCompatibleDC CreateCompatibleBitmap GetObjectW GetStockObject CreatePen CreateSolidBrush |
ClosePrinter DocumentPropertiesW |
COMDLG32.dll |
ChooseColorW ChooseFontW PageSetupDlgW GetOpenFileNameW CommDlgExtendedError PrintDlgW |
ADVAPI32.dll |
RegQueryInfoKeyW RegDeleteKeyW RegDeleteValueW RegOpenKeyExW RegEnumKeyExW RegCloseKey RegSetValueExW RegQueryValueExW RegOpenKeyW GetUserNameW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken RegEnumValueW RegEnumKeyW DeregisterEventSource ReportEventA RegisterEventSourceA RegEnumValueA CryptGenRandom RegCreateKeyExW CryptAcquireContextA RegOpenKeyExA |
SHELL32.dll |
ExtractIconW DragQueryFileW DragQueryPoint DragFinish DragAcceptFiles SHBrowseForFolderW SHGetPathFromIDListW SHGetMalloc SHGetSpecialFolderLocation #680 ShellExecuteExW SHFileOperationW Shell_NotifyIconW SHGetFileInfoW |
ole32.dll |
OleIsCurrentClipboard ReleaseStgMedium RevokeDragDrop CoLockObjectExternal RegisterDragDrop OleRun CoTaskMemAlloc CoGetClassObject CoCreateInstance OleLockRunning CoUninitialize CoTaskMemRealloc CLSIDFromProgID CLSIDFromString CreateStreamOnHGlobal StringFromGUID2 OleInitialize OleUninitialize CoInitialize CoTaskMemFree OleGetClipboard OleSetContainedObject OleFlushClipboard |
OLEAUT32.dll |
SysStringLen VariantClear LoadTypeLib VariantInit SysAllocStringLen VarUI4FromStr SysFreeString LoadRegTypeLib SysAllocStringByteLen VariantChangeType SysStringByteLen DispCallFunc SafeArrayAccessData SafeArrayDestroy SafeArrayCreate SafeArrayCreateVector SafeArrayUnaccessData SafeArrayPutElement VariantCopy SystemTimeToVariantTime VariantTimeToSystemTime GetErrorInfo OleCreateFontIndirect |
WINMM.dll |
waveInUnprepareHeader mmioCreateChunk mmioClose waveInReset waveInAddBuffer mmioAscend waveInOpen waveInPrepareHeader waveInStart waveInGetDevCapsW waveInClose joyGetPos joyGetNumDevs joyGetDevCapsW joySetCapture mixerSetControlDetails mixerGetLineInfoW waveOutGetVolume waveOutSetVolume mixerGetControlDetailsW mixerOpen mixerGetLineControlsW mmioWrite timeGetTime waveOutGetDevCapsW |
COMCTL32.dll |
#16 ImageList_Destroy ImageList_Draw ImageList_Add ImageList_Create ImageList_GetImageCount ImageList_GetIconSize ImageList_ReplaceIcon ImageList_Replace ImageList_Remove ImageList_SetBkColor ImageList_SetDragCursorImage ImageList_BeginDrag ImageList_DragMove ImageList_DragEnter ImageList_EndDrag ImageList_DragLeave |
RPCRT4.dll |
RpcStringFreeW |
Signature | 0xfeef04bd |
StructVersion | 0x10000 |
FileVersion | |
ProductVersion | |
FileFlags | (EMPTY) |
FileOs |
FileType |
Resource LangID | English - United Kingdom |
Characteristics |
TimeDateStamp | 2012-Nov-15 12:20:03 |
Version | 0.0 |
SizeofData | 69 |
AddressOfRawData | 0x7e7560 |
PointerToRawData | 0x7e6760 |
Referenced File | C:\MDM\Zinc4\projector\Release\projector.pdb |
StartAddressOfRawData | 0xe02000 |
EndAddressOfRawData | 0xe0200c |
AddressOfIndex | 0xdfd784 |
AddressOfCallbacks | 0x96cc14 |
SizeOfZeroFill | 0 |
Characteristics |
Callbacks | (EMPTY) |
Size | 0x48 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0xd85fc4 |
SEHandlerTable | 0xbff9d0 |
SEHandlerCount | 2562 |
XOR Key | 0x95e13ba7 |
