15f476137041e479083d23b293216e9383680ea3111f1ac640343797d16ee984

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2023-May-12 15:46:02
Detected languages English - United States
Debug artifacts C:\Users\Authority\Desktop\C++ projects\DwmLutSetup\x64\Release\dwm_lut.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • https://doi.org
Suspicious The PE contains functions most legitimate programs don't use. Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegGetValueA
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Suspicious VirusTotal score: 2/70 (Scanned on 2023-06-25 06:11:17) CrowdStrike: win/malicious_confidence_70% (W)
Cynet: Malicious (score: 100)

Hashes

MD5 0f05482477a55eb2f095ce969e15ebbf 🔍
SHA1 b447e63e5cf911eff7501048b17835f7e9b7e944 🔍
SHA256 15f476137041e479083d23b293216e9383680ea3111f1ac640343797d16ee984 🔍
SHA3 c86eb579e2758fc147b04d577b012ed185f86d2f5f51d38227c426b56846bdf0 🔍
SSDeep 1536:9+6au8ODt0bW/JKcEu5dhgXovSqXwDEOFKi1xmhy:gunt0iBEqhgXBewDAi1x 🔍
Imports Hash 9dcb56b4e918d22b1e0bf5dfb4b64369 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2023-May-12 15:46:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9c00
SizeOfInitializedData 0x7200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000009088 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x15000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bad53f340f67ffb1f6228674043bcd91 🔍
SHA1 86f9a358493d5e873fcf5689e4cd4647246ed25c 🔍
SHA256 92e86087aba08c4d7c56c0204acc666eb11cdb06836a279df63f85652fb5315e 🔍
SHA3 1412d0d5531c686308dc1ca08ed964689e79a9909834a2cf2a45cf0ba258f907 🔍
VirtualSize 0x9ac5
VirtualAddress 0x1000
SizeOfRawData 0x9c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.11023

.rdata

MD5 025b241e469be4bfab600143eb7eeac7 🔍
SHA1 524344cdf753bb45d8190c98685b184d8a44ddae 🔍
SHA256 afd8bb9d6c07f3d244a8aa624af1c57a95492b89d7d397412fdb907907bc6327 🔍
SHA3 7d4e5014ebf223d0295a46ab8ad1eb0fd7ca69c7b93991bc105a0362d48ff7a2 🔍
VirtualSize 0x48dc
VirtualAddress 0xb000
SizeOfRawData 0x4a00
PointerToRawData 0xa000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.89644

.data

MD5 87d07efa6f6ed0ab28191416cb0ea9ff 🔍
SHA1 331dfe4ab3beb577c5f399c593905e56f39b92ed 🔍
SHA256 7419437e435e89379d7570ada31dc232efc749d43a3a16f8a9f8ac643fa0a4c1 🔍
SHA3 f23b7e2207a1d53a00f956cf385be20d7c3ae174e8700a79333a2adf9d9c6439 🔍
VirtualSize 0x1b58
VirtualAddress 0x10000
SizeOfRawData 0x1400
PointerToRawData 0xea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.82133

.pdata

MD5 49c068800fd2f43f4e10900dc89bfc85 🔍
SHA1 6fb825190c09e619092af951dbaa7d04833a5e76 🔍
SHA256 9bdec797578bcfab7c0f9a8b3cea9232d32e4cc209a4fe16e120dfe1f552abec 🔍
SHA3 bff5b1d077332616d12435b1986e8c8c69cb60a7c939a6746c5110dc8a5f651f 🔍
VirtualSize 0x6cc
VirtualAddress 0x12000
SizeOfRawData 0x800
PointerToRawData 0xfe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.89149

.rsrc

MD5 2de7a7e5655807213f61edcfc2c273bc 🔍
SHA1 844ed93a8c6d54d6878aeff4f97edb8b600a10bd 🔍
SHA256 e8e25f1fae523e81f32919c22cc2d61b0fff23d8ac64f10c517ba3001094ca90 🔍
SHA3 b8460f781b64156fbe56b624975ce41ef6ab9c0b9defcbc7edac62df3e3e4320 🔍
VirtualSize 0xf8
VirtualAddress 0x13000
SizeOfRawData 0x200
PointerToRawData 0x10600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.51862

.reloc

MD5 161370bbc039d9e305a73ddbd7ef8f74 🔍
SHA1 8665b1c764ce26f6814ebf2c63fea6d38c42ec79 🔍
SHA256 80dd03ced1c442e2a88629bc051be256fd8f4ff4d5e3c735895d73e25d8fe4c6 🔍
SHA3 5c1b0199cfa81ea956a51b492bb7f83592662d525682e1ee2341087180b2c183 🔍
VirtualSize 0x94
VirtualAddress 0x14000
SizeOfRawData 0x200
PointerToRawData 0x10800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.91998

Imports

KERNEL32.dll FindClose
FindNextFileA
GetModuleHandleW
K32GetModuleInformation
GetCurrentProcess
VerSetConditionMask
VerifyVersionInfoW
ExpandEnvironmentStringsA
Sleep
HeapDestroy
HeapCreate
CloseHandle
FindFirstFileA
LocalFree
HeapReAlloc
HeapFree
GetCurrentProcessId
GetCurrentThreadId
OpenThread
SuspendThread
ResumeThread
FormatMessageA
SetThreadContext
FlushInstructionCache
VirtualProtect
CreateToolhelp32Snapshot
Thread32First
Thread32Next
GetSystemInfo
VirtualAlloc
VirtualFree
VirtualQuery
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetThreadContext
HeapAlloc
USER32.dll MessageBoxA
ADVAPI32.dll RegGetValueA
MSVCP140.dll ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_N@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@J@Z
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEBX@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Xlength_error@std@@YAXPEBD@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?uncaught_exceptions@std@@YAHXZ
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_type_info_destroy_list
_CxxThrowException
__C_specific_handler
memcpy
__std_exception_destroy
__std_exception_copy
__std_terminate
memmove
memset
strstr
memcmp
api-ms-win-crt-stdio-l1-1-0.dll _fileno
_chsize
ftell
fseek
fopen
fclose
fgets
__stdio_common_vsprintf
__stdio_common_vsscanf
__stdio_common_vfprintf
api-ms-win-crt-heap-l1-1-0.dll free
malloc
realloc
_callnewh
api-ms-win-crt-runtime-l1-1-0.dll _initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_seh_filter_dll
_initterm_e
_initterm
_execute_onexit_table
_invalid_parameter_noinfo_noreturn
_cexit

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x91
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8858
MD5 f7ad1eab748bc07570a57ec87787cf90 🔍
SHA1 0b1608da9fef218386e825db575c65616826d9f4 🔍
SHA256 d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04 🔍
SHA3 6c9541b36948c19ae507d74223621875b3af4064f7cd8200bdb97e15a047e96a 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2023-May-12 15:46:02
Version 0.0
SizeofData 100
AddressOfRawData 0xd658
PointerToRawData 0xc658
Referenced File C:\Users\Authority\Desktop\C++ projects\DwmLutSetup\x64\Release\dwm_lut.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2023-May-12 15:46:02
Version 0.0
SizeofData 20
AddressOfRawData 0xd6bc
PointerToRawData 0xc6bc

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2023-May-12 15:46:02
Version 0.0
SizeofData 660
AddressOfRawData 0xd6d0
PointerToRawData 0xc6d0

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2023-May-12 15:46:02
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x180010228

RICH Header

XOR Key 0x12aa3ae7
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 6
C++ objects (VS2022 Update 4 (17.4.2) compiler 31935) 18
C objects (VS2022 Update 4 (17.4.2) compiler 31935) 8
ASM objects (VS2022 Update 4 (17.4.2) compiler 31935) 4
C++ objects (30795) 1
Imports (VS2022 Update 4 (17.4.2) compiler 31935) 6
C objects (VS2022 Update 4 (17.4.5) compiler 31942) 4
Imports (30795) 9
Total imports 154
C++ objects (LTCG) (VS2022 Update 5 (17.5.4) compiler 32217) 2
Resource objects (VS2022 Update 5 (17.5.4) compiler 32217) 1
Linker (VS2022 Update 5 (17.5.4) compiler 32217) 1

Errors

Leave a comment

No comments yet.