| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2022-Aug-30 01:35:57 |
| Detected languages |
English - United States
Korean - Korea |
| Debug artifacts |
C:\works\starplayeragent\axisProxy\x64\Release\StarPlayerAgent64.pdb
|
| CompanyName | Axissoft |
| FileDescription | StarPlayer Agent |
| FileVersion | 1.3.15.2 |
| InternalName | starplayer.exe |
| LegalCopyright | Copyright (C) 2010. Axissoft.corp. all rights reserved. |
| OriginalFilename | starplayer.exe |
| ProductName | StarPlayer Agent |
| ProductVersion | 1.1.0.1 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Axissoft Corp.
Issuer: Symantec Class 3 SHA256 Code Signing CA |
| Safe | VirusTotal score: 0/70 (Scanned on 2022-09-09 09:16:05) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x138 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2022-Aug-30 01:35:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x25b600 |
| SizeOfInitializedData | 0x13da00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000020E2CC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x39e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x397e3d |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreateFileW
DeviceIoControl lstrcpyW DeleteFileW GetTempFileNameW GetFileSizeEx SetFilePointer SetEndOfFile GetTempPathW FindFirstFileW FindNextFileW FindClose GetDiskFreeSpaceExW WriteFile ReadFile UnmapViewOfFile FlushViewOfFile GetFileSize CreateFileMappingW MapViewOfFile GetProcessTimes GetTickCount HeapAlloc GetProcessHeap HeapFree K32GetModuleFileNameExW GetExitCodeProcess ResetEvent GetExitCodeThread ResumeThread CreateThread SetThreadPriority IsDebuggerPresent InitializeCriticalSectionEx RaiseException DecodePointer GetEnvironmentVariableW GetLogicalDriveStringsW QueryDosDeviceW VirtualQueryEx K32GetMappedFileNameW K32EnumProcesses GetStdHandle GetFileType RtlVirtualUnwind LoadLibraryA LoadLibraryW QueryPerformanceCounter GlobalMemoryStatus FlushConsoleInputBuffer SystemTimeToFileTime SystemTimeToTzSpecificLocalTime PeekNamedPipe GetDriveTypeW RtlUnwind WriteConsoleW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage FindFirstFileExW HeapSize ReadConsoleInputW SetConsoleMode SetStdHandle GetTimeZoneInformation ReadConsoleW GetConsoleMode GetConsoleOutputCP FlushFileBuffers HeapReAlloc EnumSystemLocalesW GetCurrentProcess lstrcatW lstrlenW GetModuleFileNameA lstrcpyA GetSystemTime GetModuleHandleW GetProcAddress GetSystemInfo OpenProcess GetVersionExW GlobalFree LoadLibraryExW FreeLibrary FindResourceW LoadResource LockResource FreeResource SizeofResource TlsFree TlsSetValue TlsGetValue ExitProcess GetConsoleWindow OutputDebugStringW GetModuleFileNameW OutputDebugStringA ReleaseMutex CreateMutexW GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime MultiByteToWideChar WideCharToMultiByte Sleep CreateWaitableTimerW VerifyVersionInfoW VerSetConditionMask SetLastError GetQueuedCompletionStatus SetWaitableTimer CreateIoCompletionPort PostQueuedCompletionStatus SleepEx SetEvent CreateEventW WaitForSingleObject QueueUserAPC TerminateThread WaitForMultipleObjects CloseHandle InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection DeleteCriticalSection IsValidLocale GetLocaleInfoW CompareStringW GetTimeFormatW GetDateFormatW GetCommandLineW GetCommandLineA GetConsoleCP SetConsoleCtrlHandler GetModuleHandleExW FreeLibraryAndExitThread ExitThread RtlPcToFileHeader RtlUnwindEx AreFileApisANSI GetModuleHandleA FileTimeToSystemTime SetFilePointerEx GetFullPathNameW GetFileInformationByHandle GetFileAttributesW GetCurrentDirectoryW SetCurrentDirectoryW VirtualQuery InitializeSListHead GetStartupInfoW IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlLookupFunctionEntry RtlCaptureContext GetStringTypeExA GetUserDefaultLCID LCMapStringA LCMapStringW GetStringTypeExW GetLocaleInfoEx LCMapStringEx GetCPInfo CompareStringEx EncodePointer GetStringTypeW TryEnterCriticalSection AcquireSRWLockExclusive GetLastError TlsAlloc ReleaseSRWLockExclusive InitializeSRWLock WaitForSingleObjectEx QueryPerformanceFrequency FormatMessageA LocalFree |
|---|---|
| USER32.dll |
MessageBoxW
LoadStringW LoadStringA CloseClipboard IsWindow GetWindowLongW wsprintfW IsClipboardFormatAvailable GetWindowThreadProcessId GetWindowTextLengthW GetClassNameW GetDesktopWindow PostMessageW OpenClipboard EmptyClipboard MsgWaitForMultipleObjects PeekMessageW TranslateMessage DispatchMessageW GetProcessWindowStation GetUserObjectInformationW GetSystemMetrics |
| GDI32.dll |
CreateCompatibleDC
DeleteObject CreateCompatibleBitmap DeleteDC SelectObject BitBlt CreateDCW |
| ADVAPI32.dll |
CryptAcquireContextW
SetServiceStatus RegisterServiceCtrlHandlerExW ReportEventW RegisterEventSourceW DeregisterEventSource EnumServicesStatusW RegEnumValueA EnumDependentServicesW QueryServiceStatusEx SetSecurityDescriptorDacl InitializeSecurityDescriptor RegOpenKeyExW RegQueryValueExW RegCreateKeyExW LookupPrivilegeValueW AdjustTokenPrivileges RegCloseKey RegSetValueExW OpenProcessToken CreateProcessAsUserW LsaOpenPolicy LsaAddAccountRights DuplicateTokenEx LsaClose RegOpenKeyW LookupAccountNameW OpenSCManagerW CryptCreateHash CryptHashData CryptDestroyHash CryptGetHashParam CryptReleaseContext StartServiceW DeleteService ControlService QueryServiceStatus OpenServiceW ChangeServiceConfig2W CloseServiceHandle CreateServiceW StartServiceCtrlDispatcherW |
| SHELL32.dll |
#165
|
| ole32.dll |
StringFromGUID2
CoInitialize CoUninitialize CoCreateInstance CreateStreamOnHGlobal CoCreateGuid |
| OLEAUT32.dll |
VariantClear
SysAllocStringLen SysAllocString SysStringByteLen VariantChangeType SysFreeString SysAllocStringByteLen VariantInit SysStringLen |
| SHLWAPI.dll |
PathRemoveFileSpecA
PathAppendA PathRemoveExtensionW PathFindFileNameW PathAppendW StrFormatByteSize64A PathFileExistsW |
| WS2_32.dll |
WSAIoctl
getsockopt setsockopt WSAStartup WSACleanup __WSAFDIsSet closesocket shutdown select listen WSARecv WSASend WSASocketW WSAStringToAddressW WSASetLastError send recv getsockname getpeername connect bind WSAGetLastError getaddrinfo freeaddrinfo ntohl htonl ntohs htons accept ioctlsocket |
| MSWSOCK.dll |
GetAcceptExSockaddrs
AcceptEx |
| WTSAPI32.dll |
WTSFreeMemory
WTSQuerySessionInformationW WTSQueryUserToken |
| gdiplus.dll |
GdipGetImageEncoders
GdipCreateBitmapFromHBITMAP GdipGetImageEncodersSize GdiplusStartup GdiplusShutdown GdipFree GdipAlloc GdipDisposeImage GdipCloneImage GdipSaveImageToStream |
| WININET.dll |
InternetGetConnectedState
|
| VERSION.dll |
VerQueryValueW
|
| WINHTTP.dll |
WinHttpCloseHandle
WinHttpGetProxyForUrl WinHttpOpen WinHttpGetIEProxyConfigForCurrentUser |
| USERENV.dll |
RefreshPolicyEx
CreateEnvironmentBlock DestroyEnvironmentBlock |
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| SETUPAPI.dll |
SetupDiOpenDevRegKey
SetupDiGetDeviceRegistryPropertyA SetupDiGetClassDevsA SetupDiEnumDeviceInfo |
| urlmon.dll |
URLDownloadToCacheFileW
URLDownloadToCacheFileA |
| WINMM.dll |
mixerGetLineInfoW
mixerOpen mixerGetNumDevs mixerSetControlDetails mixerGetControlDetailsW mixerClose mixerGetID mixerGetLineControlsW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.3.15.2 |
| ProductVersion | 1.1.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Korean - Korea |
| CompanyName | Axissoft |
| FileDescription | StarPlayer Agent |
| FileVersion (#2) | 1.3.15.2 |
| InternalName | starplayer.exe |
| LegalCopyright | Copyright (C) 2010. Axissoft.corp. all rights reserved. |
| OriginalFilename | starplayer.exe |
| ProductName | StarPlayer Agent |
| ProductVersion (#2) | 1.1.0.1 |
| Resource LangID | Korean - Korea |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Aug-30 01:35:57 |
| Version | 0.0 |
| SizeofData | 93 |
| AddressOfRawData | 0x2d6c4c |
| PointerToRawData | 0x2d564c |
| Referenced File | C:\works\starplayeragent\axisProxy\x64\Release\StarPlayerAgent64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Aug-30 01:35:57 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x2d6cac |
| PointerToRawData | 0x2d56ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Aug-30 01:35:57 |
| Version | 0.0 |
| SizeofData | 1024 |
| AddressOfRawData | 0x2d6cc0 |
| PointerToRawData | 0x2d56c0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Aug-30 01:35:57 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1402d70e0 |
|---|---|
| EndAddressOfRawData | 0x1402d70e8 |
| AddressOfIndex | 0x14035c0e4 |
| AddressOfCallbacks | 0x14025de68 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140338ff8 |
| XOR Key | 0x2fb8167c |
|---|---|
| Unmarked objects | 0 |
| ASM objects (27412) | 13 |
| C++ objects (27412) | 203 |
| C objects (30034) | 19 |
| ASM objects (30034) | 10 |
| C++ objects (CVTCIL) (27412) | 1 |
| C++ objects (24245) | 13 |
| C++ objects (30034) | 109 |
| C++ objects (VS2019 Update 4 (16.4.6) compiler 28319) | 3 |
| C objects (27412) | 31 |
| Imports (27412) | 41 |
| Total imports | 401 |
| Unmarked objects (#2) | 26 |
| C objects (VS2015 UPD3.1 build 24215) | 473 |
| C++ objects (LTCG) (VS2019 Update 11 (16.11.9) compiler 30139) | 24 |
| Resource objects (VS2019 Update 11 (16.11.9) compiler 30139) | 1 |
| 151 | 1 |
| Linker (VS2019 Update 11 (16.11.9) compiler 30139) | 1 |
No comments yet.