filename | Net.exe | |
---|---|---|
size | 785408 (0xbfc00) | |
md5 | c7fda7f76e70e4dc0afef2052e1e9cc7 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub This file is packed with UPX. Analysis will be incomplete without unpacking. |
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
UPX0 | 0x1000 | 0xaf000 | 0 | RWX UDATA | |
UPX1 | 0xb0000 | 0xbe000 | 0xbda00 | RWX IDATA | |
.rsrc | 0x16e000 | 0x2000 | 0x1e00 | RW- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x16fab8 | 0x27c | |
RESOURCE | 0x16e000 | 0x1ab8 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0x16d840 | 0x18 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x56d858 | 0x56d869 | 0x4d70c0 | 0 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.DLL | LoadLibraryA | ||
KERNEL32.DLL | GetProcAddress | ||
KERNEL32.DLL | ExitProcess | ||
advapi32.dll | RegFlushKey | ||
comctl32.dll | ImageList_Add | ||
gdi32.dll | SaveDC | ||
ole32.dll | OleDraw | ||
oleaut32.dll | VariantCopy | ||
shell32.dll | ShellExecuteA | ||
user32.dll | GetDC | ||
version.dll | VerQueryValueA | ||
winmm.dll | PlaySoundA | ||
wsock32.dll | inet_ntoa |
StringTable 041804E2
CompanyName | |
FileDescription | |
FileVersion | 1.0.0.4 |
InternalName | |
LegalCopyright | |
LegalTrademarks | |
OriginalFilename | |
ProductName | |
ProductVersion | 1.0.0.0 |
Comments |
VS_FIXEDFILEINFO
FileVersion | 1.0.0.4 |
ProductVersion | 1.0.0.4 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
![]() |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[!] string size(36140) > stringtable size(96). truncated to 94
[!] string size(123124) > stringtable size(1472). truncated to 1470
[!] cannot convert "h\n\x04\xF6N ,\x12\x97\x85\xA7\xB4CD\xEBu"... to UTF-16
[!] string size(19216) > stringtable size(948). truncated to 946
[!] cannot convert "\x11\x13+\x02\x82\n\x14a\x1Ax\xC1C\x10\xB7S\x05"... to UTF-16
[!] string size(66804) > stringtable size(1496). truncated to 1494
[!] cannot convert "\xFE4u\x83\xA5(5Aa\x8F\x04\x04\"\xE6\xE4."... to UTF-16
[!] string size(124376) > stringtable size(1068). truncated to 1066
[!] cannot convert "\xB9\x01'}\x04\xF7\\\xCE\xD3\x18BHG\x00\xC4\n"... to UTF-16
[!] string size(96140) > stringtable size(808). truncated to 806
[!] cannot convert "L\xBBLB\x96\xEF\x86zi\x93\\\x19\xE4{Pe"... to UTF-16
[!] string size(59602) > stringtable size(964). truncated to 962
[!] cannot convert "\x1E\x87\x1EAc\x8B\x86\xF1}$=>XlE$"... to UTF-16
[!] string size(8128) > stringtable size(836). truncated to 834
[!] cannot convert "@\x9EL\xA7AXk\a\xECn\xA8&\xE0\x06\xC1^"... to UTF-16
[!] string size(69064) > stringtable size(740). truncated to 738
[!] cannot convert "\x00\xF5\x8D\x9B\x98H\x10'A>\x94!&\xA4~X"... to UTF-16
[!] string size(81700) > stringtable size(492). truncated to 490
[!] cannot convert "\xF4\xE4\xB8\xC8\xE4\x04\x86\xE4\x92G\xE0\xB8\xE4\xE0\bC"... to UTF-16
[!] string size(98576) > stringtable size(316). truncated to 314
[!] cannot convert "\xD63_\xB0a#\xADI\xEB_\x11/\x93\x81\x1Di"... to UTF-16
[!] string size(13336) > stringtable size(712). truncated to 710
[!] cannot convert "$\xB6[\xE7W\xC6\xDB\xDA\xA5\xF6\xFA'\xAA\x7F'\e"... to UTF-16
[!] string size(27790) > stringtable size(284). truncated to 282
[!] cannot convert "\x130\a1\x87\x8C?\x97\xBCY\xC7p\n\xB8X\x99"... to UTF-16
[!] string size(35094) > stringtable size(236). truncated to 234
[!] cannot convert "$\x0FEs\e\x00\x04\xD9\x02\xA56\xC6\xD1\xB2U5"... to UTF-16
[!] string size(56852) > stringtable size(304). truncated to 302
[!] cannot convert "\a\x88T\xE1\xCE\x86\xCA(\x02\xD9u\x1641-w"... to UTF-16
[!] string size(25394) > stringtable size(1068). truncated to 1066
[!] cannot convert "{o\nFB8b\xB7\n\x13b\\\xE2+\xF8\xAE"... to UTF-16
[!] string size(70566) > stringtable size(940). truncated to 938
[!] cannot convert "G\x04F\xD1J\x1F8\xE08\x11\xED\xFC\xDCM\xF2\x9E"... to UTF-16
[!] string size(101762) > stringtable size(900). truncated to 898
[!] cannot convert "\xBA\xAF\xC3K\xF2\t\xD3E\xE0j\x02\x1Ei\xB0#B"... to UTF-16
[!] string size(18416) > stringtable size(972). truncated to 970
[!] cannot convert "t\xD9\x99\xC2\xDAg_\xB0\xABy\x13\x94\x93\x1E\x023"... to UTF-16
[!] string size(124674) > stringtable size(592). truncated to 590
[!] cannot convert " \x19\nlF^\xDAQ\xBD$\xD8\abtn("... to UTF-16
[!] string size(71182) > stringtable size(236). truncated to 234
[!] cannot convert "\xC6\xEDL\x90\b\v\ba$m1&\v2_\x85"... to UTF-16
[!] string size(28448) > stringtable size(476). truncated to 474
[!] cannot convert "\x1Ep\xFB\b\x13\xA9\x02\x85\x93\xC2B\x1E\xD8\xB2!\x1C"... to UTF-16
[!] string size(51916) > stringtable size(1004). truncated to 1002
[!] cannot convert "l0c\xB0\e \x12\xF5\xE3\x13MI@~\xD4\xCC"... to UTF-16
[!] string size(16872) > stringtable size(1012). truncated to 1010
[!] cannot convert "\xF0\xB5\xB7\xE0\xB5\x12\x1FX\xC8qs\xEC_\x815\x12"... to UTF-16
[!] string size(78432) > stringtable size(780). truncated to 778
[!] cannot convert "\x00\xE2Q7 *\x9D\x13@\x03\x81W\xCC_\xD6\x15"... to UTF-16
[!] string size(78516) > stringtable size(808). truncated to 806
[!] cannot convert "\t[F'`a\x93A\xADb\x7F\xB9:\xD7\x068"... to UTF-16
[!] refusing to read CURDIRENTRY beyond resource size