| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Jan-16 07:18:14 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\paulb\code\Squirrel\squirrel.windows\src\Setup\bin\Release\Setup.pdb
|
| FileDescription | SourceTree |
| FileVersion | 3.4.26 |
| InternalName | Setup.exe |
| LegalCopyright | Copyright © Atlassian |
| OriginalFilename | Setup.exe |
| ProductName | SourceTree |
| ProductVersion | 3.4.26 |
| SquirrelAwareVersion | 1 |
| CompanyName | Atlassian |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 99.325% of the executable. |
| Info | The PE is digitally signed. |
Signer: Atlassian Pty Ltd
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-02-25 15:55:29) | Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2018-Jan-16 07:18:14 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1bc00 |
| SizeOfInitializedData | 0x185e200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00009E92 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x187e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x187c6a9 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetCurrentProcess
LoadLibraryW FreeLibrary InitializeCriticalSectionEx GetFileAttributesW CreateFileW SetFilePointer ReadFile SystemTimeToFileTime GetCurrentDirectoryW MultiByteToWideChar LocalFileTimeToFileTime WideCharToMultiByte CreateDirectoryW WriteFile SetFileTime FreeResource SizeofResource LockResource CreateProcessW GetCurrentThreadId DecodePointer RaiseException LeaveCriticalSection EnterCriticalSection lstrcmpiW LoadLibraryExW SetFilePointerEx GetModuleFileNameW GetConsoleCP FlushFileBuffers GetStringTypeW SetStdHandle DeleteFileW CloseHandle GetExitCodeProcess WaitForSingleObject MoveFileW GetTempFileNameW GetLastError GetTempPathW DeleteCriticalSection GetModuleHandleW GetProcAddress lstrlenW FindResourceW LoadResource VerSetConditionMask GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP WriteConsoleW IsValidCodePage FindNextFileW FindFirstFileExW FindClose HeapReAlloc HeapSize GetConsoleMode VerifyVersionInfoW IsDebuggerPresent OutputDebugStringW UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime InitializeSListHead RtlUnwind SetLastError EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree ExitProcess GetModuleHandleExW GetStdHandle GetACP HeapFree HeapAlloc GetFileType CompareStringW LCMapStringW |
|---|---|
| USER32.dll |
CharNextW
ExitWindowsEx wsprintfW MessageBoxW DestroyWindow LoadStringW GetActiveWindow |
| ADVAPI32.dll |
GetUserNameW
RegOpenKeyExW RegDeleteValueW RegCreateKeyExW RegEnumKeyExW RegQueryInfoKeyW RegDeleteKeyW GetTokenInformation RegCloseKey AdjustTokenPrivileges OpenProcessToken LookupPrivilegeValueW RegSetValueExW RegQueryValueExW |
| SHELL32.dll |
SHGetFolderPathW
ShellExecuteExW ShellExecuteW |
| ole32.dll |
CoTaskMemRealloc
CoTaskMemFree CoCreateInstance CoTaskMemAlloc CoInitialize |
| OLEAUT32.dll |
VariantInit
SysFreeString SysAllocString VarUI4FromStr VariantClear |
| urlmon.dll |
URLDownloadToFileW
|
| SHLWAPI.dll |
PathIsUNCW
|
| COMCTL32.dll |
InitCommonControlsEx
|
| Setup |
| http://go.microsoft.com/fwlink/?LinkId=397707 |
| http://go.microsoft.com/fwlink/?LinkId=780596 |
| Install .NET 4.5 |
| Install .NET 4.6 |
| This application requires the .NET Framework 4.5. Click the Install button to get started. |
| SETUP |
| This application requires the .NET Framework 4.6. Click the Install button to get started. |
| This application requires the .NET Framework 4.5 or above. Clicking the Install button will download the latest version of this operating system component from Microsoft and install it on your PC. |
| This application requires the .NET Framework 4.6 or above. Clicking the Install button will download the latest version of this operating system component from Microsoft and install it on your PC. |
| net46 |
| net47 |
| This application requires the .NET Framework 4.7 or above. Clicking the Install button will download the latest version of this operating system component from Microsoft and install it on your PC. |
| This application requires the .NET Framework 4.7. Click the Install button to get started. |
| Install .NET 4.7 |
| http://go.microsoft.com/fwlink/?LinkId=825298 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.4.26.0 |
| ProductVersion | 3.4.26.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | SourceTree |
| FileVersion (#2) | 3.4.26 |
| InternalName | Setup.exe |
| LegalCopyright | Copyright © Atlassian |
| OriginalFilename | Setup.exe |
| ProductName | SourceTree |
| ProductVersion (#2) | 3.4.26 |
| SquirrelAwareVersion | 1 |
| CompanyName | Atlassian |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-16 07:18:14 |
| Version | 0.0 |
| SizeofData | 102 |
| AddressOfRawData | 0x25bf4 |
| PointerToRawData | 0x24bf4 |
| Referenced File | C:\Users\paulb\code\Squirrel\squirrel.windows\src\Setup\bin\Release\Setup.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-16 07:18:14 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x25c5c |
| PointerToRawData | 0x24c5c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-16 07:18:14 |
| Version | 0.0 |
| SizeofData | 820 |
| AddressOfRawData | 0x25c70 |
| PointerToRawData | 0x24c70 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-16 07:18:14 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x98 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x428004 |
| SEHandlerTable | 0x425b80 |
| SEHandlerCount | 29 |
| XOR Key | 0x26aebe28 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 9 |
| 243 (40116) | 123 |
| 242 (40116) | 24 |
| ASM objects (VS2015 v14.0.? compiler 25305) | 18 |
| C objects (VS2015 v14.0.? compiler 25305) | 20 |
| C++ objects (VS2015 v14.0.? compiler 25305) | 48 |
| C objects (65501) | 2 |
| 208 (65501) | 1 |
| Imports (65501) | 19 |
| Total imports | 148 |
| C++ objects (LTCG) (VS2017 v15.3.* compiler 25508) | 6 |
| Resource objects (VS2017 v15.3.* compiler 25508) | 1 |
| 151 | 1 |
| Linker (VS2017 v15.3.* compiler 25508) | 1 |
No comments yet.