Additional information
Show all
|
MD5 : 10fd85e1e8b4f949dcf9ef304f661b2c |
SHA1 : 9355661736c4640eb6d34f759e29686f40da5298 |
SHA256: 26d6e70a9f63dcd14bdb9bc2085a9f0678642175dfd06c29b6b206d21619468a |
ssdeep: 1536:siziIgm0+clnimEGoXBxSrsoKiLb6JNw6wkHtkE/B:TYB+ihEN787KiX6M6hHtkE/B |
File size : 71278 bytes |
First seen: 2010-08-27 15:17:23 |
Last seen : 2010-10-30 00:02:21 |
TrID:
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%) |
sigcheck:
publisher....:
copyright....:
product......:
description..: yexingyu
original name:
internal name:
file version.: 3. 0. 0. 0
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned
|
PEiD: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
packers (F-Prot): UPX |
packers (Kaspersky): UPX |
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x2A7E0
timedatestamp....: 0x2A425E19 (Fri Jun 19 22:22:17 1992)
machinetype......: 0x14c (I386)
[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
UPX0, 0x1000, 0x1C000, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e
UPX1, 0x1D000, 0xE000, 0xDA00, 7.91, d01300ec3c7e6799a29e74f008baf367
.rsrc, 0x2B000, 0x4000, 0x3400, 3.47, e1466d941e3581f3cf89313c6f961093
[[ 4 import(s) ]]
KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, ExitProcess
advapi32.dll: RegCloseKey
oleaut32.dll: VariantCopy
user32.dll: CharNextA
|
ExifTool:
file metadata
CharacterSet: Windows, Latin1
CodeSize: 57344
Comments:
CompanyName:
EntryPoint: 0x2a7e0
FileDescription: yexingyu
FileFlagsMask: 0x003f
FileOS: Win32
FileSize: 70 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 3. 0. 0. 0
FileVersionNumber: 3.0.0.0
ImageVersion: 0.0
InitializedDataSize: 16384
InternalName:
LanguageCode: English (U.S.)
LegalCopyright:
LegalTrademarks:
LinkerVersion: 2.25
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Executable application
OriginalFilename:
PEType: PE32
ProductName:
ProductVersion: 0.0.0.0
ProductVersionNumber: 0.0.0.0
Subsystem: Windows command line
SubsystemVersion: 4.0
TimeStamp: 1992:06:20 00:22:17+02:00
UninitializedDataSize: 114688
[/td][/td] |
Symantec reputation:Suspicious.Insight |