附加信息 |
File size: 326423 bytes |
MD5 : 4154a1d4dcf030d5c77167abe7b46748 |
SHA1 : eed73de8e4f28d16623703b132c2eb91cf3e799e |
SHA256: e4d3f75b5bc8f6b0b749f5b1c5096d4d0e2425e850004aae38283f58129c6448 |
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1000
timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)
machinetype.......: 0x14C (Intel I386)
( 2 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0xD2000 0x4C000 8.00 0d6577517ee773c247539706434ea0b3
.rsrc 0xD3000 0x3000 0x3000 5.07 121989a0943df444b7a2eed3b3ef5b8e
( 13 imports )
> advapi32.dll: RegQueryValueExA
> comctl32.dll: ImageList_SetIconSize
> gdi32.dll: UnrealizeObject
> kernel32.dll: LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree
> lz32.dll: LZClose
> ole32.dll: CreateStreamOnHGlobal
> oleaut32.dll: SysFreeString
> shell32.dll: Shell_NotifyIconA
> urlmon.dll: URLDownloadToFileA
> user32.dll: GetKeyboardType
> version.dll: VerQueryValueA
> winmm.dll: sndPlaySoundA
> wtsapi32.dll: WTSTerminateProcess
( 0 exports )
|
TrID : File type identification
Win32 EXE PECompact compressed (v2.x) (48.0%)
Win32 EXE PECompact compressed (generic) (33.8%)
Win32 Executable Generic (6.9%)
Win32 Dynamic Link Library (generic) (6.1%)
Win16/32 Executable Delphi generic (1.6%) |
ssdeep: 6144:cNnDmgrpVh+pgMJyCcQP0YMhZjHPxcwNTsDZr0ewIq7HvCTvFptLK:cxTVSvPcQP0dr7sNJq7ivHo |
PEiD : PECompact 2.xx --> BitSum Technologies |
packers (Kaspersky): PE_Patch.PECompact, PecBundle, PECompact |
packers (F-Prot): PecBundle, PECompact |
RDS : NSRL Reference Data Set
|