Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Dec-06 07:04:21 |
Detected languages |
English - United States
|
Debug artifacts |
E:\scljenkins-slv\workspace\InstallFramework-VS2017@2\develop\global\release\bin\common\x86\Setup.pdb
|
CompanyName | Autodesk, Inc. |
FileDescription | Autodesk component |
FileVersion | 12.0.748.0.3 |
LegalCopyright | Copyright 2017 Autodesk, Inc. All rights reserved. |
ProductVersion | 12.0.748.0.3 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. | Resources amount for 88.0064% of the executable. |
Info | The PE is digitally signed. |
Signer: Autodesk
Issuer: Symantec Class 3 SHA256 Code Signing CA - G2 |
Safe | VirusTotal score: 0/71 (Scanned on 2024-04-25 08:57:40) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2019-Dec-06 07:04:21 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x11a00 |
SizeOfInitializedData | 0xe0200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00006EE6 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x13000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xf5000 |
SizeOfHeaders | 0x400 |
Checksum | 0xfe96f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
gdiplus.dll |
GdiplusStartup
GdiplusShutdown |
---|---|
KERNEL32.dll |
GetCurrentThreadId
FreeLibrary GetModuleFileNameW GetModuleHandleW GetProcAddress LoadLibraryExW LoadResource SizeofResource lstrcmpiW FindResourceW MultiByteToWideChar GetConsoleMode GetConsoleCP FlushFileBuffers GetStringTypeW DeleteCriticalSection InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection GetLastError RaiseException DecodePointer SetCurrentDirectoryW SetFilePointerEx WriteConsoleW CloseHandle GetFileType GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP IsValidCodePage SetStdHandle QueryPerformanceCounter IsDebuggerPresent OutputDebugStringW UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetStartupInfoW CreateFileW GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead RtlUnwind SetLastError EncodePointer TlsAlloc TlsGetValue TlsSetValue TlsFree ExitProcess GetModuleHandleExW WideCharToMultiByte GetStdHandle WriteFile GetACP HeapFree HeapAlloc HeapSize HeapReAlloc LCMapStringW FindClose FindFirstFileExW FindNextFileW |
USER32.dll |
DefWindowProcW
DestroyWindow CharNextW MessageBoxW |
ADVAPI32.dll |
RegEnumKeyExW
RegCreateKeyExW RegSetValueExW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegDeleteValueW RegDeleteKeyW |
ole32.dll |
CoTaskMemRealloc
CoTaskMemFree CoInitialize CoTaskMemAlloc CoCreateInstance CoUninitialize |
OLEAUT32.dll |
VarUI4FromStr
|
SHLWAPI.dll |
PathAppendW
PathFileExistsW PathRemoveFileSpecW |
COMCTL32.dll |
InitCommonControlsEx
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 12.0.748.3 |
ProductVersion | 12.0.748.3 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Autodesk, Inc. |
FileDescription | Autodesk component |
FileVersion (#2) | 12.0.748.0.3 |
LegalCopyright | Copyright 2017 Autodesk, Inc. All rights reserved. |
ProductVersion (#2) | 12.0.748.0.3 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Dec-06 07:04:21 |
Version | 0.0 |
SizeofData | 126 |
AddressOfRawData | 0x18744 |
PointerToRawData | 0x17544 |
Referenced File | E:\scljenkins-slv\workspace\InstallFramework-VS2017@2\develop\global\release\bin\common\x86\Setup.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Dec-06 07:04:21 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x187c4 |
PointerToRawData | 0x175c4 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Dec-06 07:04:21 |
Version | 0.0 |
SizeofData | 820 |
AddressOfRawData | 0x187d8 |
PointerToRawData | 0x175d8 |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x41a014 |
SEHandlerTable | 0x4186f0 |
SEHandlerCount | 21 |
XOR Key | 0x7a0a9242 |
---|---|
Unmarked objects | 0 |
241 (40116) | 10 |
243 (40116) | 122 |
242 (40116) | 24 |
ASM objects (VS 2015/2017 runtime 26706) | 18 |
C objects (VS 2015/2017 runtime 26706) | 18 |
C++ objects (VS 2015/2017 runtime 26706) | 46 |
C objects (65501) | 1 |
Imports (65501) | 17 |
Total imports | 116 |
C++ objects (VS2017 v15.8.5-8 compiler 26730) | 2 |
Resource objects (VS2017 v15.8.5-8 compiler 26730) | 1 |
151 | 1 |
Linker (VS2017 v15.8.5-8 compiler 26730) | 1 |