d4dd9c9757aeebad582c6ed683df3af53d180e96b4841c80a657f6ab2be822a6

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1998-Nov-02 13:23:15
Debug artifacts resdll.dbg

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • attributes.cn
  • bigfoot.com
  • bitstream.com
  • cgi.netscape.com
  • company.com
  • directory3.attributes.cn
  • dls.netscape.com
  • domain.com
  • fedex.com
  • four11.com
  • ftp.verisign.com
  • ftp://ftp.verisign.com
  • ftp://ftp.verisign.com/repository/CPS
  • fullcirclesoftware.com
  • guide.netscape.com
  • home.netscape.com
  • http://cgi.netscape.com
  • http://cgi.netscape.com/cgi-bin/rlcgi.cgi?URL
  • http://cgi.netscape.com/eng/mozilla/2.0/extensions/info.cgi
  • http://guide.netscape.com
  • http://guide.netscape.com/?t
  • http://guide.netscape.com/guide/people.html
  • http://guide.netscape.com/guide/people.html?t
  • http://guide.netscape.com/guide/whats_cool.html
  • http://guide.netscape.com/guide/whats_cool.html?t
  • http://guide.netscape.com/guide/whats_new.html
  • http://guide.netscape.com/guide/whats_new.html?t
  • http://guide.netscape.com/guide/yellow_pages.html
  • http://guide.netscape.com/guide/yellow_pages.html?t
  • http://home.netscape.com
  • http://home.netscape.com/
  • http://home.netscape.com/bookmark/4_5/tstart.html
  • http://home.netscape.com/comprod/business_solutions/education/index.html
  • http://home.netscape.com/comprod/products/communicator/version_4.0/dynfonts
  • http://home.netscape.com/comprod/products/navigator/version_2.0/plugins/index.html
  • http://home.netscape.com/eng/mozilla/4.0/relnotes/windows-4.0.html
  • http://home.netscape.com/home/first.html
  • http://home.netscape.com/home/gold3.0_templates.html
  • http://home.netscape.com/home/gold4.0_wizard.html
  • http://home.netscape.com/home/internet-search.html
  • http://home.netscape.com/home/register.html
  • http://home.netscape.com/home/services.html
  • http://home.netscape.com/home/update.html
  • http://home.netscape.com/info/security-doc.html
  • http://home.netscape.com/menu/intl/
  • http://home.netscape.com/menu/prodsupp/client/
  • http://keyword.netscape.com
  • http://keyword.netscape.com/
  • http://mysystem.com
  • http://netcaster.netscape.com
  • http://netcaster.netscape.com/finder/container/index.html'
  • http://www-rl.netscape.com
  • http://www-rl.netscape.com/wtgn?
  • http://www.bitstream.com
  • http://www.fullcirclesoftware.com
  • http://www.fullcirclesoftware.com/
  • http://www.inso.com
  • http://www.inso.com/
  • http://www.javasoft.com
  • http://www.javasoft.com/
  • http://www.lucent.com
  • http://www.lucent.com/
  • http://www.marimba.com
  • http://www.neologic.com
  • http://www.netcast.com
  • http://www.odi.com
  • http://www.precept.com
  • http://www.radvision.com
  • http://www.s
  • http://www.sgi.com
  • http://www.visigenic.com
  • http://www.voxware.com
  • https://www.verisign.co.jp
  • https://www.verisign.com
  • https://www.verisign.com/repository/CPS
  • infospace.com
  • javasoft.com
  • keyword.netscape.com
  • ldap-trace.fedex.com
  • ldap.bigfoot.com
  • ldap.directory3.attributes.cn
  • ldap.four11.com
  • ldap.infospace.com
  • ldap.switchboard.com
  • ldap.whowhere.com
  • lucent.com
  • marimba.com
  • mysystem.com
  • name.domain.com
  • neologic.com
  • netcast.com
  • netcaster.netscape.com
  • netscape.com
  • precept.com
  • radvision.com
  • rl.netscape.com
  • servername.domain.com
  • switchboard.com
  • trace.fedex.com
  • verisign.co.jp
  • verisign.com
  • visigenic.com
  • voxware.com
  • whowhere.com
  • www-rl.netscape.com
  • www.bitstream.com
  • www.fullcirclesoftware.com
  • www.inso.com
  • www.javasoft.com
  • www.lucent.com
  • www.marimba.com
  • www.neologic.com
  • www.netcast.com
  • www.odi.com
  • www.precept.com
  • www.radvision.com
  • www.rsa.com
  • www.sgi.com
  • www.verisign.co.jp
  • www.verisign.com
  • www.visigenic.com
  • www.voxware.com
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Suspicious The file contains overlay data. 896 bytes of data starting at offset 0xd4400.
Safe VirusTotal score: 0/71 (Scanned on 2023-01-05 15:27:58) All the AVs think this file is safe.

Hashes

MD5 f9f30f47bd4452ee94734a70024793bd 🔍
SHA1 c61b9aa197e4d9343dff1666138a78fbd69dffe2 🔍
SHA256 d4dd9c9757aeebad582c6ed683df3af53d180e96b4841c80a657f6ab2be822a6 🔍
SHA3 297ba0a7f67669c549097c5636156ca77e44458cacafcf65f08787a64f826d7d 🔍
SSDeep 6144:C3QjCyB6BLbPmId2voFbZJrV42Epeszf3s8C3jSciV29K4Kb8h7vJgov5P:1jCy4pTDsc9yc 🔍
Imports Hash d61431e470317850458d9f9d8d855461 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 1998-Nov-02 13:23:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 4.0
SizeOfCode 0x1c00
SizeOfInitializedData 0xd2600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00001160 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x3000
ImageBase 0x60250000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xd8000
SizeOfHeaders 0x400
Checksum 0xde584
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 5ebbc43a382472d455391ade8f0b74fc 🔍
SHA1 b55badf3959a8391a7f51c9c183e31b13b8c3f49 🔍
SHA256 b62084f340721ef6fac4f52e1aa5542b83c8d8f210fd659612d32a7dd756a097 🔍
SHA3 171e712e82aeeb5dca6917b456a614917bc83572467be0159f92586e6a1013af 🔍
VirtualSize 0x1a91
VirtualAddress 0x1000
SizeOfRawData 0x1c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.30206

.rdata

MD5 7bb8e82a5c6ee1fe2439a0d2779b22d1 🔍
SHA1 56afca09977b907a6583335d9d666f7c5096ad62 🔍
SHA256 d038368955220c56ed73a269ed5b2b8d8da74ff48dff306ff984839894863b35 🔍
SHA3 3330958252c5d7e39c44967a03d0ec2f207593b5976400597eb7582ee5c25d36 🔍
VirtualSize 0x397
VirtualAddress 0x3000
SizeOfRawData 0x400
PointerToRawData 0x2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.68181

.data

MD5 e75619a112033e4b5544159d6ed68c09 🔍
SHA1 1e6614500b1e0683b96043a6a37d8cd072edd66e 🔍
SHA256 ce7eb5318a2b2197ea6113270a5bcbf52495e9bbff00744eee48e33ab5d9d51b 🔍
SHA3 723a7160500ecf7b7c3f8999ab04deee8096dd37b700d0d6c6c4077582c252f7 🔍
VirtualSize 0xdbc
VirtualAddress 0x4000
SizeOfRawData 0xc00
PointerToRawData 0x2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.710381

.idata

MD5 6de0c2e864463572142bae0af45c1d3d 🔍
SHA1 ad45e43b170eff942550b534853555273c170473 🔍
SHA256 8eeccc686f2cbeb244d5d700b8d79bf7daf69920ccbef5ee28231b9429ccab7d 🔍
SHA3 7865f9167d05182ae8220edd65dedbe56ef31e6291a2354187f85bc5753945ad 🔍
VirtualSize 0x322
VirtualAddress 0x5000
SizeOfRawData 0x400
PointerToRawData 0x3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.64592

.rsrc

MD5 36546c6bbdcd7031e6f1251d685bf6a8 🔍
SHA1 657bc758251a119bacea981ac4eb166845de71a9 🔍
SHA256 bb8ace52e6154971aa20f3da2ad5fbb84f28be402959794a6b1c95bdbb07d8c4 🔍
SHA3 f7afd5b3f6798f38c81de6e8ba29acc6c669c48ccec0b6ae7b52b6eac93bd7af 🔍
VirtualSize 0xd0304
VirtualAddress 0x6000
SizeOfRawData 0xd0400
PointerToRawData 0x3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.16776

.reloc

MD5 dbcf77c4d644f868d3b7c3666384b016 🔍
SHA1 a12d3a84f176eb3b6c87fc0b1962594916c4cfc7 🔍
SHA256 722d712323809a8abba949ec3554f64e698ca24adad16c453634d88abd59e0c9 🔍
SHA3 e6ed5321cd32d6479fe483d690571380d7f9aec46d3943133d61c250c8fed599 🔍
VirtualSize 0xad4
VirtualAddress 0xd7000
SizeOfRawData 0xc00
PointerToRawData 0xd3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.69893

Imports

KERNEL32.dll GetCPInfo
GetProcAddress
GetModuleHandleA
GetVersion
ExitProcess
TerminateProcess
GetCurrentProcess
HeapDestroy
HeapCreate
VirtualFree
SetHandleCount
GetFileType
GetStdHandle
GetStartupInfoA
GetModuleFileNameA
GetCommandLineA
GetACP
GetOEMCP
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
WideCharToMultiByte
DisableThreadLibraryCalls
WriteFile
HeapFree
HeapAlloc
VirtualAlloc
LoadLibraryA

Delayed Imports

Version Info

IMAGE_DEBUG_TYPE_MISC

Characteristics 0
TimeDateStamp 1998-Nov-02 13:00:40
Version 0.0
SizeofData 272
AddressOfRawData 0
PointerToRawData 0xd4400
Referenced File resdll.dbg

IMAGE_DEBUG_TYPE_FPO

Characteristics 0
TimeDateStamp 1998-Nov-02 13:00:40
Version 0.0
SizeofData 624
AddressOfRawData 0
PointerToRawData 0xd4510

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: The PE's resource section exceeds the parsing limits. Resources will not be parsed.
Leave a comment

No comments yet.