Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Oct-10 23:00:09 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/73 (Scanned on 2024-03-14 18:43:10) |
APEX:
Malicious
MaxSecure: Trojan.Malware.300983.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2023-Oct-10 23:00:09 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x26800 |
SizeOfInitializedData | 0x1ee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000004EB0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x4a000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW SetEndOfFile RtlUnwindEx GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW EncodePointer RaiseException RtlPcToFileHeader FindClose FindFirstFileExW FindNextFileW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW HeapAlloc HeapFree FlsAlloc FlsGetValue FlsSetValue FlsFree CompareStringW LCMapStringW GetFileType CloseHandle FlushFileBuffers GetConsoleOutputCP GetConsoleMode ReadFile ReadConsoleW SetFilePointerEx GetFileSizeEx MultiByteToWideChar DeleteFileW MoveFileExW SetStdHandle HeapReAlloc WideCharToMultiByte IsValidCodePage GetACP GetOEMCP GetCPInfo GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetStringTypeW GetProcessHeap CreateFileW WaitForSingleObject GetExitCodeProcess CreateProcessW GetTimeZoneInformation HeapSize WriteConsoleW GetFileAttributesExW |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-10 23:00:09 |
Version | 0.0 |
SizeofData | 756 |
AddressOfRawData | 0x31a68 |
PointerToRawData | 0x30668 |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1400352c8 |
XOR Key | 0x3d88ca |
---|---|
Unmarked objects | 0 |
ASM objects (30795) | 8 |
C++ objects (30795) | 184 |
C objects (30795) | 10 |
Imports (30795) | 3 |
Total imports | 99 |
253 (VS2022 Update 4 (17.4.2) compiler 31935) | 3 |
C++ objects (VS2022 Update 4 (17.4.2) compiler 31935) | 40 |
C objects (VS2022 Update 4 (17.4.2) compiler 31935) | 18 |
ASM objects (VS2022 Update 4 (17.4.2) compiler 31935) | 9 |
C++ objects (VS2022 Update 5 (17.5.4) compiler 32217) | 1 |
C objects (VS2022 Update 5 (17.5.4) compiler 32217) | 2 |
Linker (VS2022 Update 5 (17.5.4) compiler 32217) | 1 |