Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Feb-12 10:21:09 |
Detected languages |
English - United States
Process Default Language |
Comments | Eraser Setup Bootstrapper |
CompanyName | The Eraser Project |
FileDescription | Eraser Setup Bootstrapper |
FileVersion | 6.2.0.2992 |
InternalName | Eraser Setup Bootstrapper |
LegalCopyright | Copyright © 2008-2021 The Eraser Project |
OriginalFilename | Eraser Setup Bootstrapper |
ProductVersion | 6.2.0.2992 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. | Resources amount for 98.049% of the executable. |
Info | The PE is digitally signed. |
Signer: Heidi Computers Ltd
Issuer: GlobalSign CodeSigning CA - SHA256 - G3 |
Safe | VirusTotal score: 0/70 (Scanned on 2022-12-27 11:37:50) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2021-Feb-12 10:21:09 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x19000 |
SizeOfInitializedData | 0x840a00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000D4EF (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x861000 |
SizeOfHeaders | 0x400 |
Checksum | 0x85e541 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
COMCTL32.dll |
#17
|
---|---|
KERNEL32.dll |
GetFileSize
UpdateResourceW EndUpdateResourceW FindResourceW LoadResource SizeofResource LockResource CreateProcessW WaitForSingleObject GetExitCodeProcess GetNativeSystemInfo CreateDirectoryW RemoveDirectoryW FindFirstFileW DeleteFileW FindNextFileW FindClose GetTempPathW GetModuleFileNameW FormatMessageW ReadFile BeginUpdateResourceW SetFilePointerEx GetConsoleMode GetConsoleCP HeapSize SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExW GetFileType GetProcessHeap FlushFileBuffers WriteFile GetLastError CreateFileW CloseHandle WideCharToMultiByte MultiByteToWideChar EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetLastError InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetModuleHandleW GetProcAddress GetStringTypeW LCMapStringW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent SetEvent ResetEvent WaitForSingleObjectEx IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead RaiseException RtlUnwind FreeLibrary LoadLibraryExW HeapAlloc HeapReAlloc HeapFree ExitProcess GetModuleHandleExW GetStdHandle GetACP WriteConsoleW |
USER32.dll |
DefWindowProcW
CallWindowProcW PostQuitMessage SetWindowTextW SetWindowLongW GetWindowLongW EnableWindow UpdateWindow InvalidateRect ShowWindow RegisterClassExW LoadCursorW LoadIconW SendMessageW CreateWindowExW DestroyWindow DispatchMessageW TranslateMessage GetMessageW PeekMessageW MessageBoxW SystemParametersInfoW |
GDI32.dll |
CreateFontIndirectW
|
SHELL32.dll |
CommandLineToArgvW
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.2.0.2992 |
ProductVersion | 6.2.0.2992 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
Comments | Eraser Setup Bootstrapper |
CompanyName | The Eraser Project |
FileDescription | Eraser Setup Bootstrapper |
FileVersion (#2) | 6.2.0.2992 |
InternalName | Eraser Setup Bootstrapper |
LegalCopyright | Copyright © 2008-2021 The Eraser Project |
OriginalFilename | Eraser Setup Bootstrapper |
ProductVersion (#2) | 6.2.0.2992 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Feb-12 10:21:09 |
Version | 0.0 |
SizeofData | 960 |
AddressOfRawData | 0x240e8 |
PointerToRawData | 0x234e8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Feb-12 10:21:09 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x42b000 |
---|---|
EndAddressOfRawData | 0x42b008 |
AddressOfIndex | 0x427030 |
AddressOfCallbacks | 0x41a22c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x426070 |
SEHandlerTable | 0x424090 |
SEHandlerCount | 22 |
XOR Key | 0x74b61f7f |
---|---|
Unmarked objects | 0 |
241 (40116) | 12 |
243 (40116) | 135 |
242 (40116) | 29 |
ASM objects (VS2015 UPD3 build 24123) | 21 |
C++ objects (VS2015 UPD3 build 24123) | 54 |
C objects (VS2015 UPD3 build 24123) | 34 |
Imports (65501) | 13 |
Total imports | 138 |
C++ objects (LTCG) (24234) | 19 |
Resource objects (24234) | 1 |
151 | 1 |
Linker (24234) | 1 |