| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-26 10:32:09 |
| Detected languages |
Chinese - PRC
|
| FileVersion | 6.1.7601.17514 |
| FileDescription | Microsoft@ Windows@ Operating System |
| ProductName | Microsoft@ Windows@ Operating System |
| ProductVersion | 6.1.7601.17514 |
| CompanyName | Windows |
| LegalCopyright | @ Microsoft Corportion ALL rights reserved |
| Comments | Windows |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h) UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Suspicious | The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable. Unusual section name found: UPX1 Section UPX1 is both writable and executable. Unusual section name found: .SCY Section .SCY is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 2d4e939c1d57a72b5503970cbd459216 🔍 |
|---|---|
| SHA1 | d727b9525a1e0622c376701ac6a27552c9e37b6e 🔍 |
| SHA256 | cd55f7976ff35228c4fc53c06f4c42f5489d896702e1edb73f45f90888d62de3 🔍 |
| SHA3 | 4c80e2db97fcdf916ae415ca9d6772c453918d49090d8b686bea28a69304f996 🔍 |
| SSDeep | 24576:NvdhRF5kX7TwzT+Xp9RPhnk3X6XJf9SZqDvPGW3IRCJzwcyahGYvzn4pGWv3vUv:NPU2RRCBwPanvL9e398SmsD5 🔍 |
| Imports Hash | 19a2f91f3993246ffe8b89b84a6d0d38 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2026-Sep-26 10:32:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x14f000 |
| SizeOfInitializedData | 0x1000 |
| SizeOfUninitializedData | 0x50000 |
| AddressOfEntryPoint | 0x00024C39 (Section: UPX0) |
| BaseOfCode | 0x51000 |
| BaseOfData | 0x1a0000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a3000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1546ab |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | bc3d8de179847ac3dc443bc2c54d1fda 🔍 |
|---|---|
| SHA1 | 7def2ce9a10bf7030644f499a118dbeb920507c2 🔍 |
| SHA256 | 668bb162b7943b549f9a679bbc1e06e998d6686028a45cd1e3dba966d97a6bbd 🔍 |
| SHA3 | aeb75f91507eb64927e1d6c06e07817fc321748988ab108dd90c9cf8871e8841 🔍 |
| VirtualSize | 0x50000 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x50000 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.82346 |
| MD5 | dc55ae4993f50e1f90477134f1972e17 🔍 |
|---|---|
| SHA1 | 87685f270058e1ed0fe4e86b07b823aba0b48809 🔍 |
| SHA256 | 6c885605c5907c04f2e2b2f5a8feee1dab876535c6c6895b315e8b4e79335dcd 🔍 |
| SHA3 | 3ee51f022b8effb0649272ec2da295862d8ab85561e3e0800e40df6deeb34947 🔍 |
| VirtualSize | 0x14f000 |
| VirtualAddress | 0x51000 |
| SizeOfRawData | 0x14f000 |
| PointerToRawData | 0x50400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 7.80504 |
| MD5 | 4b177a29399053e17078264097eb28cf 🔍 |
|---|---|
| SHA1 | 605cae5c6ee440210fa9597a3e5a7bf8c044cc62 🔍 |
| SHA256 | 6900181e1d49da3a03bed5759cf54b4b8c477512923a29a7a8d55743d7d7bd22 🔍 |
| SHA3 | 43f5489c8f2a2b196bf1059bd2a438c795a1d877601d8a6cbfc123785e879805 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x1a0000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x19f400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.24704 |
| MD5 | ca26a4b189fb8a41e48ee9404c818e0d 🔍 |
|---|---|
| SHA1 | 48bcd48bbe9d75500a0633c68360a5fe9d49b7b1 🔍 |
| SHA256 | b1f8cdb7b5ea3079551c03177ebe93eaa898ad67818c3db1aa80c0ac80c40fe7 🔍 |
| SHA3 | 958c06c7e383cee42c247a654bc70f5bf2885f44e12c5ea0642e351f629e81fe 🔍 |
| VirtualSize | 0x2000 |
| VirtualAddress | 0x1a1000 |
| SizeOfRawData | 0x1e00 |
| PointerToRawData | 0x19fc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.44983 |
| advapi32.dll |
CryptHashData
RegCreateKeyExA RegOpenKeyExA RegOpenKeyA RegQueryValueExA RegCloseKey CryptGetHashParam CryptDestroyHash CryptReleaseContext CryptCreateHash CryptAcquireContextA RegSetValueExA |
|---|---|
| comctl32.dll |
InitCommonControls
|
| gdi32.dll |
GetObjectA
Escape ExtTextOutA TextOutA RectVisible PtVisible |
| gdi32.dll (#2) |
GetObjectA
Escape ExtTextOutA TextOutA RectVisible PtVisible |
| kernel32.dll |
SetStdHandle
IsBadCodePtr GetStringTypeW GetStringTypeA LCMapStringW SetUnhandledExceptionFilter IsBadWritePtr VirtualAlloc VirtualFree HeapCreate HeapDestroy GetVersionExA GetFileType GetStdHandle SetHandleCount MultiByteToWideChar GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter GetACP HeapSize RaiseException RtlUnwind GetCommandLineA GetOEMCP GetCPInfo FlushFileBuffers OpenEventA CreateEventA lstrcpynA RtlMoveMemory CreateThread CreateProcessA WaitForSingleObject CloseHandle GetShortPathNameA GetWindowsDirectoryA GetSystemDirectoryA CreateFileW GetFileTime GetFileAttributesW FileTimeToLocalFileTime FileTimeToSystemTime GetLocaleInfoA GetDateFormatA GetTimeFormatA LeaveCriticalSection InitializeCriticalSection EnterCriticalSection LCMapStringA LoadLibraryA GetProcAddress FreeLibrary GetTickCount SetFilePointer GetStartupInfoA FindFirstFileA RemoveDirectoryA FindNextFileA FindClose GetLocalTime GetEnvironmentVariableA GetPrivateProfileStringA GetFileAttributesA WriteFile Sleep GlobalAlloc GlobalLock GlobalUnlock GlobalFree GetUserDefaultLCID WideCharToMultiByte CreateFileA GetFileSize ReadFile GetModuleFileNameA CreateDirectoryA DeleteFileA IsBadReadPtr HeapFree HeapReAlloc HeapAlloc ExitProcess GetModuleHandleA GetProcessHeap TerminateProcess OpenProcess GetCurrentProcess Process32Next Process32First CreateToolhelp32Snapshot SetWaitableTimer CreateWaitableTimerA SetErrorMode GetProcessVersion FindResourceA LoadResource LockResource GetVersion GlobalGetAtomNameA GlobalAddAtomA GetEnvironmentStringsW GetTempPathA GlobalFindAtomA GetLastError GetCurrentThreadId GetCurrentThread lstrcmpiA lstrcmpA GlobalDeleteAtom lstrlenA LocalAlloc LocalFree TlsAlloc DeleteCriticalSection GlobalHandle TlsFree GlobalReAlloc TlsSetValue LocalReAlloc TlsGetValue lstrcpynA MulDiv GlobalFlags InterlockedDecrement WritePrivateProfileStringA lstrcatA lstrcpyA InterlockedIncrement SetLastError |
| oleaut32.dll |
VariantInit
SafeArrayAllocDescriptor SafeArrayAllocData SafeArrayGetDim SafeArrayGetLBound SafeArrayGetUBound SafeArrayAccessData SafeArrayUnaccessData SafeArrayGetElemsize SysFreeString VarR8FromCy VarDateFromBool VariantChangeType LoadTypeLib LHashValOfNameSys RegisterTypeLib VariantCopy SafeArrayCreate SysAllocString VariantClear SafeArrayDestroy VariantTimeToSystemTime SystemTimeToVariantTime |
| shell32.dll |
SHGetSpecialFolderLocation
SHGetPathFromIDListA |
| shlwapi.dll |
PathIsDirectoryW
PathFileExistsA PathFindExtensionA |
| user32.dll |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#2) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#3) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#4) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#5) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#6) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#7) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| user32.dll (#8) |
FindWindowA
MsgWaitForMultipleObjects DispatchMessageA TranslateMessage PeekMessageA WaitForInputIdle ClientToScreen PostMessageW FindWindowExA |
| winspool.drv |
DocumentPropertiesA
ClosePrinter OpenPrinterA |
| ole32.dll |
OleIsCurrentClipboard
OleFlushClipboard CoRevokeClassObject CoRegisterMessageFilter CoFreeUnusedLibraries OleUninitialize OleInitialize CoInitialize CoUninitialize OleRun CoCreateInstance CLSIDFromString CLSIDFromProgID |
| oledlg.dll |
OleUIBusyA
|
| Type |
RT_VERSION
|
|---|---|
| Language | Chinese - PRC |
| Codepage | Latin 1 / Western European |
| Size | 0x314 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.44231 |
| MD5 | 792882fa87c7a75b66440a4762b52f10 🔍 |
| SHA1 | 998a7481367a39d3486dfce7e20eda4307655d46 🔍 |
| SHA256 | 38587b1d9025cc0c31bb5e325f492f80de5233d55a0e04becb6c5dc3c12dc09d 🔍 |
| SHA3 | f5aa126000166bf2385b52c319e93f93f41a79d38e6d7f7147fd52c5dae64fb1 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0 |
| FileVersion | 6.1.7601.17514 |
| ProductVersion | 6.1.7601.17514 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Chinese - PRC |
| FileVersion (#2) | 6.1.7601.17514 |
| FileDescription | Microsoft@ Windows@ Operating System |
| ProductName | Microsoft@ Windows@ Operating System |
| ProductVersion (#2) | 6.1.7601.17514 |
| CompanyName | Windows |
| LegalCopyright | @ Microsoft Corportion ALL rights reserved |
| Comments | Windows |
| Resource LangID | Chinese - PRC |
|---|
| XOR Key | 0x3b5e7537 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 1 |
| C objects (VS2003 (.NET) build 4035) | 6 |
| 14 (7299) | 31 |
| C objects (VS98 SP6 build 8804) | 137 |
| Imports (VS2003 (.NET) build 4035) | 25 |
| Total imports | 495 |
| C++ objects (VS98 SP6 build 8804) | 164 |
| Unmarked objects (#2) | 1 |
| C++ objects (VS98 build 8168) | 2 |
No comments yet.