e8a40a74fa8782514698eddd819631a0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2009-Dec-05 22:50:52
Detected languages Chinese - PRC
English - United States
Comments
CompanyName Aisino Corporation
FileDescription 金报税盘税务数字证书驱动安装程序
FileVersion 1.1.1.12
LegalCopyright Copyright 2012-2016 Aisino.
LegalTrademarks AISINO
ProductName 金报税盘税务数字证书驱动

Plugin Output

Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExA
  • GetProcAddress
Can access the registry:
  • RegQueryValueExA
  • RegSetValueExA
  • RegEnumKeyA
  • RegEnumValueA
  • RegOpenKeyExA
  • RegDeleteKeyA
  • RegDeleteValueA
  • RegCloseKey
  • RegCreateKeyExA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 1963373 bytes of data starting at offset 0x14000.
The overlay data has an entropy of 7.998 and is possibly compressed or encrypted.
Overlay data amounts for 95.9947% of the executable.
Suspicious VirusTotal score: 2/71 (Scanned on 2020-02-13 16:01:36) APEX: Malicious
Cybereason: malicious.fe8b3c

Hashes

MD5 e8a40a74fa8782514698eddd819631a0
SHA1 bdbefd1fe8b3c8f881ee7f02f4ff210d853ecc9a
SHA256 a8b1a8f901162f7986475be018a533b7f1efe2f3f967f85ce0cb0f4fbc544f6c
SHA3 32f9f882050cab43fceded6f7da478f971081c770d2912b41fd8929372b0008f
SSDeep 49152:qW4Fcvnqz9P+EeqNB8mm0r0AdJNvWVd8hqFp:qW4FcvogIB8d0rf9AFp
Imports Hash f2eb8d789695eff25c68c44db80d0898

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2009-Dec-05 22:50:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x5e00
SizeOfInitializedData 0x28400
SizeOfUninitializedData 0x400
AddressOfEntryPoint 0x000030FA (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x7000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x45000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 856b32eb77dfd6fb67f21d6543272da5
SHA1 6597c511c2ee72f68f5246460f0683dae16dcade
SHA256 c6c2b4f41d6598b94106de36b422dd84534fd9a11d84b2b6a47b3be49524c750
SHA3 649e621f7eb7edb175d8285b7c35de1209efc88af5abb31f95bab19076fff3b4
VirtualSize 0x5c4c
VirtualAddress 0x1000
SizeOfRawData 0x5e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.44011

.rdata

MD5 dc77f8a1e6985a4361c55642680ddb4f
SHA1 3d397ee25b2dd83ab741c67375880151cae94ed8
SHA256 576cdd5bc72421d008c86f056d0727c54cc8b3ec0961e5d0462af48278543d51
SHA3 d419a2c597e2f7a8a19b7c5c2090a93c78625e69629ff7d66a5359bfd614a8f4
VirtualSize 0x129c
VirtualAddress 0x7000
SizeOfRawData 0x1400
PointerToRawData 0x6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.04684

.data

MD5 7922d4ce117d7d5b3ac2cffe4b0b5e4f
SHA1 4e56bb1994226ae0285c7adee470777262de2c99
SHA256 97773fd68ac3aebb9795c59dc00c5dbc0c992ce0c3c2ef90bfff27eb1cd72b3d
SHA3 2a1aceed5a92a7ab4f568335758aa6da79df1e2fe50997652ea0f52f0813bead
VirtualSize 0x25c58
VirtualAddress 0x9000
SizeOfRawData 0x400
PointerToRawData 0x7600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.801

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x9000
VirtualAddress 0x2f000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 634777fe24e150aecdddccdcf6cf5567
SHA1 9b7994fe5a51a7f03b8e2c5873de23bc49019ced
SHA256 0a3a035b9736fd9c463478057b146c8c8dbb4213fc9199d48990d250b244b397
SHA3 74154891d90d68495e9361186a598e41663e05f8774fe2399343571deef3e0cc
VirtualSize 0xc4c0
VirtualAddress 0x38000
SizeOfRawData 0xc600
PointerToRawData 0x7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.74477

Imports

KERNEL32.dll CompareFileTime
SearchPathA
GetShortPathNameA
GetFullPathNameA
MoveFileA
SetCurrentDirectoryA
GetFileAttributesA
GetLastError
CreateDirectoryA
SetFileAttributesA
Sleep
GetTickCount
GetFileSize
GetModuleFileNameA
GetCurrentProcess
CopyFileA
ExitProcess
GetWindowsDirectoryA
SetFileTime
GetCommandLineA
SetErrorMode
LoadLibraryA
lstrcpynA
GetDiskFreeSpaceA
GlobalUnlock
GlobalLock
CreateThread
CreateProcessA
RemoveDirectoryA
CreateFileA
GetTempFileNameA
lstrlenA
lstrcatA
GetSystemDirectoryA
GetVersion
CloseHandle
lstrcmpiA
lstrcmpA
ExpandEnvironmentStringsA
GlobalFree
GlobalAlloc
WaitForSingleObject
GetExitCodeProcess
GetModuleHandleA
LoadLibraryExA
GetProcAddress
FreeLibrary
MultiByteToWideChar
WritePrivateProfileStringA
GetPrivateProfileStringA
WriteFile
ReadFile
MulDiv
SetFilePointer
FindClose
FindNextFileA
FindFirstFileA
DeleteFileA
GetTempPathA
USER32.dll EndDialog
ScreenToClient
GetWindowRect
EnableMenuItem
GetSystemMenu
SetClassLongA
IsWindowEnabled
SetWindowPos
GetSysColor
GetWindowLongA
SetCursor
LoadCursorA
CheckDlgButton
GetMessagePos
LoadBitmapA
CallWindowProcA
IsWindowVisible
CloseClipboard
SetClipboardData
EmptyClipboard
RegisterClassA
TrackPopupMenu
AppendMenuA
CreatePopupMenu
GetSystemMetrics
SetDlgItemTextA
GetDlgItemTextA
MessageBoxIndirectA
CharPrevA
DispatchMessageA
PeekMessageA
DestroyWindow
CreateDialogParamA
SetTimer
SetWindowTextA
PostQuitMessage
SetForegroundWindow
wsprintfA
SendMessageTimeoutA
FindWindowExA
SystemParametersInfoA
CreateWindowExA
GetClassInfoA
DialogBoxParamA
CharNextA
OpenClipboard
ExitWindowsEx
IsWindow
GetDlgItem
SetWindowLongA
LoadImageA
GetDC
EnableWindow
InvalidateRect
SendMessageA
DefWindowProcA
BeginPaint
GetClientRect
FillRect
DrawTextA
EndPaint
ShowWindow
GDI32.dll SetBkColor
GetDeviceCaps
DeleteObject
CreateBrushIndirect
CreateFontIndirectA
SetBkMode
SetTextColor
SelectObject
SHELL32.dll SHGetPathFromIDListA
SHBrowseForFolderA
SHGetFileInfoA
ShellExecuteA
SHFileOperationA
SHGetSpecialFolderLocation
ADVAPI32.dll RegQueryValueExA
RegSetValueExA
RegEnumKeyA
RegEnumValueA
RegOpenKeyExA
RegDeleteKeyA
RegDeleteValueA
RegCloseKey
RegCreateKeyExA
COMCTL32.dll ImageList_AddMasked
ImageList_Destroy
#17
ImageList_Create
ole32.dll CoTaskMemFree
OleInitialize
OleUninitialize
CoCreateInstance
VERSION.dll GetFileVersionInfoSizeA
GetFileVersionInfoA
VerQueryValueA

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43037
MD5 eca82ffeaa68e312f050735f39a11250
SHA1 6334e8f2a817d0249cc0cef7cd7be984ec223d1f
SHA256 08d9589e24ddca48ff45d8414a9ed7cc0f5951e67db773e11ef0687cc2d53050
SHA3 153798bf3c71b571df1480f98de0d1e71de4777dfbeffa80dd0906f28e022fc3

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.25694
MD5 7944c363a11b841c7ff01b943ebeab7d
SHA1 52b5512fe690f5bfc160bde5bbd5b2eab182c5c2
SHA256 792eb553184727c24e049d55fb4cf87a1e1876f7198a93bc99b14010c7d0055d
SHA3 5b49f25934ccc35c0280fdcc0c648e9b77041dbc7459c2f67b0121a2ced6a9d5

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.85947
MD5 e0ef2c66fdd621bf9648f5eb11891c86
SHA1 dacabbb865bc9110ce4d7de680d731d7a2fec7f7
SHA256 aee6acd9e4f0c9561a4dcdaa0dde6b4473482612e6e3657f272017a306da0dc5
SHA3 1aa10c537a7a3339db750604510466375920aec3bfa7e025f9025dca01102b38

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.96217
MD5 892c3c757a8e277d46681d24cad4852c
SHA1 47c084446c2efa6408cbb009b930bb41e97ccbc6
SHA256 7ad9503db5d65057245c39699614a6274dbdc26071b9a58bbf9b951883eb59e4
SHA3 b9d47f9dc6e95bf87e40f1a606b64e154431f808b88965c1ad4519ac01d16546

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.54094
MD5 ecc80d3054247df6db906ed44f7eb6ae
SHA1 1f38daf4601d0447f878e082ed89adcbd09c2529
SHA256 1abf3970683072332cf27258ec439bb0cdff80c2d2903778651bb02543be1009
SHA3 f2b35f643cd979a77aa454a829a7f7f10cd67724983945759d239a4167c6a6eb

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.67441
MD5 28da38e0b27daaf787c7cab26b3e8788
SHA1 aea927fc6ad5cbc49bf15146e0db240dfc377b58
SHA256 4bfded65cc680b62ff335852df84676c2e4c94ac24f44befbbbadab88c8ecc03
SHA3 15e78f889f7fd7a0e93f27033d5940403bcb67b8c4fc2e99ade45af878734b9f

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39407
MD5 afe64ee175337f333b0d1f1981990c4a
SHA1 280e5869befd605bb8a978c8bdb551cc626e8547
SHA256 c5985471a44994e82a09a6e88dc6019cfcabb9015d6849944b641043f837ab56
SHA3 3e70a45b261fdef3026784fd5fb48898eae956a7a5ce120ffb899a71b5d3deb0

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32067
MD5 77424e6c217416fc53fb296a2082ca6f
SHA1 9db15693bbfff9f9f73c282a46856cd2eb989dfe
SHA256 f92a39ce726694b7d33d3aaef77836f13ef620856e53da2a7eadde26a93eed0c
SHA3 9d1ca9c20f68f7fb8291dbf87dfb7aeb8d8a668ed07d6c6dafffbb82213f8325

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7369
MD5 22129c59f66196ca02161ac1297a1317
SHA1 6b7cb611fb358a8d739b06a1e6804378116c010b
SHA256 10ff7b6f8647bfff9cf29b49484baaa77d6491760673224746adac0e5d3534d1
SHA3 1c99700451a4cfe2ddce61f7c006ea29ea816d4b9a389641eb24be76e712942d

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.3109
MD5 e9d4e5f6006c2247bf2dd5230d8ef291
SHA1 e3777df3e71136ccbb81f34f5ed7047ed9550786
SHA256 6d35b8ad6ff69ba576d0eb36f23286d57f2f3256c226a3c6e00ed21e8a88954a
SHA3 829faa2ce22c6b47efe494886b550290bfb668785029573a56c0d49dfb9b84c0

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.6942
MD5 adc2b3c77ca0e60b0bd15464699a3667
SHA1 3b753a3e78d1441f727b7f382badf1e54f4a4cab
SHA256 a6222b32b90bf137fe14463efddcbd9463c4fdc31694a411df468734ffd13213
SHA3 9d7856fe1fd174c458bd86aa474dc22cad5f7f7ffd5124ea7b3c9843a9dfc821

12

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.58727
MD5 727d879389b0af1f158f7cfdfccf9f4e
SHA1 dcfefb63777e7de4a71f318260a35ad8bb06c60d
SHA256 5bf933d245a2fb7e96d755df4875bdec0c5fb92c6dc9839f1bfd78f2f5a0dfa0
SHA3 c45772d410da44e0a60ff6f67275549266983de59d21c5f46971d669919bcc85

13

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08649
MD5 c1f4f0d8cfd3278b08f87f258ea4f55d
SHA1 4636e404430b61645da0accfade6eed4ad6ae5ae
SHA256 72d3861a5b68ba6b2069a90e1aa40b8050135549b0ca8e3f2618e0f1f6991e0c
SHA3 931f84767d60d8e51f31e3873f052525a78851b8e9701f188df7c354b77ccf37

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x10c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.47654
MD5 888fbcc92ebd6174786b32d45350005a
SHA1 ba4959d06247a07012fbca926691e2e709c7aa8f
SHA256 b98ac97ffc283bc465d34958c79f8a31480c0f98eb44c5e23977bee9ba52b703
SHA3 1ec3fb0c9114bc10f7c71e9bf1d15c48a5e39fd99193dfce3db02c097cbb626c

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62576
MD5 4429bc1da2cf5ffffaca57dfbeff9eaa
SHA1 65063c7c88ddfd422886554570c73793ea1bf2f9
SHA256 3f0bc1e0fc8d86dee74d2ed2e601ad0dfbd163bd38daeecdb3be5d4dfb00e54b
SHA3 1c3d43e398f8fab0c6bb889fd5ec88a911f9eafc4d9882ca7596a55556b8fc95

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86626
MD5 8c69d2c81dd2d9050d0fa94df90ff16b
SHA1 cd71d904da747d7141e5abdde9363f7e240b26bd
SHA256 1a39a3aabdee2aa68c507c55ff37c38722b05b7f8bde66185a2462792381d8cd
SHA3 b80b33ab6bf40b07bc32c7a6a11831084f7c97a27dff86d576769d0aab14b979

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9304
MD5 2497a44fff8b76b5129662b60a617c85
SHA1 f73bd7c9caa4c1f7a0e4840d69b0accdc6d167a0
SHA256 a10617b39293152a65ad5c91ca4f35135845c7b785e3a582e58f6c8229045b85
SHA3 aaf1dc708c305944a11a7180ef5ee2c8f722c3dd6d4bf91e0ae0f6c2b1a331ca

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1325
Detected Filetype Icon file
MD5 27045ef417487b08aed66336e2b7dc58
SHA1 1dcfe5751d3eef32c273e98fcdb6efb19db26ade
SHA256 fbffca788522daa7bb5b51399f425ef78c2220edbabbea9f937a89559607916a
SHA3 c7ba7c0216cd640641a4a1f5fd39ce1606e16aae88a933df5cebc475afe97bb5

1 (#2)

Type RT_VERSION
Language Chinese - PRC
Codepage UNKNOWN
Size 0x290
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76391
MD5 ec4de10eb8caea3491c5fef978b51cd4
SHA1 4bd05d3f41b90139058c8815ea8d7d91fe2c7a0d
SHA256 698d59cead52fb4197314ae0fa45890fcde679c918cfc574331030c5252167cf
SHA3 863abd5ea21ad537e539751d99cc68f3e31468bab946e10c40d3e10958d715da

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x215
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.10394
MD5 6f1fa2dee815707f6c8db07afb4b18c1
SHA1 c96d1933d55c50e9d6ef96edd688ceedd40bb203
SHA256 88c91f1165efa7a0b506ba4eba225b865b4f41798c813648a1677f6bf3e1efcd
SHA3 ec52942465ed8024f844234fed6211fe66082c8fe074eed5103b3e825c09b617

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 1.1.1.12
ProductVersion 1.1.1.12
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Chinese - PRC
Comments
CompanyName Aisino Corporation
FileDescription 金报税盘税务数字证书驱动安装程序
FileVersion (#2) 1.1.1.12
LegalCopyright Copyright 2012-2016 Aisino.
LegalTrademarks AISINO
ProductName 金报税盘税务数字证书驱动
Resource LangID Chinese - PRC

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x69ead975
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 155
Imports (VS2003 (.NET) build 4035) 17
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!