| File name: | WinCE CAB Manager 3.0.0.22 PORTABLE.exe |
| Full analysis: | https://app.any.run/tasks/a6fb2951-ba3c-49ec-ab61-7c00b4e11d30 |
| Verdict: | No threats detected |
| Analysis date: | October 21, 2019, 14:53:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BDC65F4594B6D733B48B63C3AA77946D |
| SHA1: | FF60489D05F5AFAFC861801344AB00DC2E005F3A |
| SHA256: | 65F2F905CB7226A55226B7A607E97D6B147CBF9797F68639E5061951A7DBB1CE |
| SSDEEP: | 196608:cwhjwRvGF8RH3J8ObYslQBHhyZh3EicBsGMO+6djV5AZpmLmsQlDlGhD:yvGyHZ8Ob8hyvSBsGPYZbH54 |
| .exe | | | Thinapp Packaged Portable Application Launcher executable (99.1) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (0.4) |
| .exe | | | DOS Executable Generic (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:04:03 07:56:28+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 83.82 |
| CodeSize: | 24576 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1361 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 03-Apr-2008 05:56:28 |
| Detected languages: |
|
| Comments: | http://www.ocpsoftware.com |
| CompanyName: | OCP Software, Inc. |
| FileDescription: | WinCE CAB Manager 3.0 |
| FileVersion: | 3, 0, 0, 22 |
| InternalName: | CeCabManager |
| LegalCopyright: | Copyright (c) 2001-2008 OCP Software, Inc. |
| LegalTrademarks: | - |
| OriginalFilename: | CeCabManager.EXE |
| PrivateBuild: | - |
| ProductName: | WinCE CAB Manager 3.0 |
| ProductVersion: | 3, 0, 0, 22 |
| SpecialBuild: | - |
| ThinAppBuildDateTime: | 20090111 125957 |
| ThinAppLicense: | ThinApp |
| ThinAppVersion: | 4.0.1-2866 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000180 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 2 |
| Time date stamp: | 03-Apr-2008 05:56:28 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006000 | 0x00006000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.52638 |
.res | 0x00007000 | 0x00231000 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.34854 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 3.52307 | 1204 | UNKNOWN | English - United States | RT_VERSION |
2 | 2.59536 | 744 | UNKNOWN | English - United States | RT_ICON |
3 | 2.27335 | 296 | UNKNOWN | English - United States | RT_ICON |
4 | 2.47702 | 34 | UNKNOWN | English - United States | RT_GROUP_ICON |
KERNEL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 944 | "C:\Program Files\WinCE CAB Manager\CeCabManager.exe" | C:\Users\admin\AppData\Local\Temp\Stubs\1D0FC5~1\CeCabManager.exe | — | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 | |||||||||||||||
| 2924 | "C:\Users\admin\AppData\Local\Temp\WinCE CAB Manager 3.0.0.22 PORTABLE.exe" | C:\Users\admin\AppData\Local\Temp\WinCE CAB Manager 3.0.0.22 PORTABLE.exe | explorer.exe | ||||||||||||
User: admin Company: OCP Software, Inc. Integrity Level: MEDIUM Description: WinCE CAB Manager 3.0 Exit code: 3221225725 Version: 3, 0, 0, 22 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Registry.rw.tvr.lck.USER-PC.ffffffffb04 | — | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\TEMP\2820-1.manifest | — | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\TEMP\2820-2.manifest | — | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Stubs\1d0fc5890b54cc6d449ec5a61be10a8917ca0\CeCabManager.exe.b6cb04.tmp | — | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Registry.rw.tvr.lck | binary | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Registry.tvr.backup | binary | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Stubs\1D0FC5~1\CeCabManager.exe | executable | |
MD5:— | SHA256:— | |||
| 2924 | WinCE CAB Manager 3.0.0.22 PORTABLE.exe | C:\Users\admin\AppData\Local\Temp\Registry.rw.tvr | binary | |
MD5:— | SHA256:— | |||