附加訊息 |
File size: 3546408 bytes |
MD5...: 170e6abffd368ab1ce37735937a9fb44 |
SHA1..: f087fa296b1c077917fdd842404d1c638605398f |
SHA256: f2e68da0065e61da64e8ef76e5cfbb5b592e244a49215ff3eabe03fab3367f5a |
ssdeep: 98304:EORHye909rkWrYQwRhbv4+RoXOrNRiiOKV6:EOR3909rC4+SXuoT
|
PEiD..: - |
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x185b0
timedatestamp.....: 0x4b14be65 (Tue Dec 01 06:57:41 2009)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x10000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x11000 0x8000 0x7800 7.88 ed99dbb99263b5cbc94ba60d9234aeb4
.rsrc 0x19000 0x4000 0x4000 5.18 aa6576cfc67228595c30f742ebb68fb4
( 6 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> GDI32.dll: BitBlt
> MSVCRT.dll: exit
> ole32.dll: CoTaskMemFree
> OLEAUT32.dll: -
> USER32.dll: SetTimer
( 0 exports )
|
RDS...: NSRL Reference Data Set
- |
pdfid.: - |
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%) |
packers (Kaspersky): UPX |
sigcheck:
publisher....: Alen Soft
copyright....: Copyright(C) 2003-2006
product......: ____
description..: ____ ____
original name: setup.exe
internal name: ttpsetup.exe
file version.: 5, 6, 2, 0
comments.....: _______________________________
signers......: -
signing date.: -
verified.....: Unsigned
|
packers (F-Prot): UPX, 7Z, Unicode, NSIS, UTF-8 |