swf.exe
First submission 2024-10-14 22:10:02
File details
File type: | PE32 executable (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 4322.13 KB (4425861 bytes) |
Compile time: | 1992-06-20 00:22:17 |
MD5: | 243bc25631e2f0dcfc8dbcdcdd0d886e |
SHA1: | ef0da7b9bd0331f958773f8963679500c0c0db01 |
SHA256: | 0c41eb21ae94b114e165b3196accbb6e1457e7a0f579e18a001a26b50656ba4f |
Import Hash : | 884310b1928934402ea6fec1dbd3cf5e |
Sections 8 | CODE DATA BSS .idata .tls .rdata .reloc .rsrc |
Directories 3 | import resource tls |
URLs, FQDN and IP indicators 1
PE Sections 4 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
CODE | 0x1000 | 0x8fe0 | 36864 | 6eddef5fd230aab076a2fe4f265e8a9f7facccd8 | 61e836cac9c673512632038dd84ce39d | |
DATA | 0xa000 | 0x248 | 1024 | a8d55b6b7fbd0c51600e9a9cfba4ce6e0936132a | 1605dbc615f9347957e3d584e5f6343d | |
BSS | 0xb000 | 0xe34 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.idata | 0xc000 | 0x950 | 2560 | e49e2b7cb13448780832c319b573685a5082edd7 | bd5bdc394dd9459844ea032b48349bc1 | |
.tls | 0xd000 | 0x8 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.rdata | 0xe000 | 0x18 | 512 | 217e47adc0fbd0a02677f10d9af22bb5dc7739cf | d293bf8d4ebe9826d58e1d27c25fe4b6 | |
.reloc | 0xf000 | 0x8a8 | 0 | da39a3ee5e6b4b0d3255bfef95601890afd80709 | d41d8cd98f00b204e9800998ecf8427e | |
.rsrc | 0x10000 | 0x3000 | 10240 | 89268eb03f05e2b040eb2f2f060b940a16fbe881 | dc17271102df91847964239fcb21e164 |
PE Resources 6
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_ICON | LANG_DUTCH | SUBLANG_DUTCH | 0x10ccc | 2216 | |
RT_STRING | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x11f60 | 174 | |
RT_RCDATA | LANG_NEUTRAL | SUBLANG_NEUTRAL | 0x12010 | 44 | |
RT_GROUP_ICON | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x1203c | 62 | |
RT_VERSION | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x1207c | 1020 | |
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x12478 | 887 |
Meta infos 6
LegalCopyright: | |
FileVersion: | |
CompanyName: | |
Translation: | 0x0409 0x04e4 |
FileDescription: | Glass Video Converter Setup |
Comments: | This installation was built with Inno Setup: http://www.innosetup.com |
Packers detected 4
Borland Delphi 3.0 (???) |
Borland Delphi 4.0 |
Inno Installer v5.1.2] ;collides with: Borland Delphi 2.0 [Overlay |
Inno Setup Module v5 |
Anti debug functions 2
GetLastError |
RaiseException |
Strings analysis - File found
Library |
OLEAUT32.dll |
USER32.dll |
COMCTL32.dll |
ADVAPI32.dll |
KERNEL32.dll |
SHELL32.dll |
Strings analysis - Possible URLs found 1
http://www.innosetup.com |