1834039fa73f1cc6c5b40088950e6f169a4cfd6bf3f2f3de84bbc2f4c3f62892

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-06 10:58:22
Detected languages English - United States
Debug artifacts c:\Users\U201123\Work\PrivateLibrary\Libraries\ElectronDRM\src\MediaHandle\Release\MediaHandle.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h)
MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to Blowfish
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
Info The PE is digitally signed. Signer: Sanus Med Co.
Issuer: GlobalSign GCC R45 CodeSigning CA 2020
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 28c7bf9f17ef9e029df779c2adf8cf19 🔍
SHA1 d90829f9a980ce9cabb7c2b86237fa9a200d5b8d 🔍
SHA256 1834039fa73f1cc6c5b40088950e6f169a4cfd6bf3f2f3de84bbc2f4c3f62892 🔍
SHA3 77089ef3e03cf784f1efc96d832bec1fcaf4989a449eafad264bac974e0c08f4 🔍
SSDeep 24576:itJ3GtEvJhwWPbuWadF5c0HJFqITcj+6zZvZ:+hwddFi0HNRYZB 🔍
Imports Hash 65961eb4fafca8bd61dcb0cd9d905740 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2026-Aug-06 10:58:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x9a800
SizeOfInitializedData 0x49600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0007B204 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x9c000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x4eb000
SizeOfHeaders 0x400
Checksum 0xed1b0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 567052a08fd2160f78e00734023fb332 🔍
SHA1 a94df8063eaec3e440cb099fdd1e0e2e9b8ca836 🔍
SHA256 f570a65422690fd3cedd17b8e3f464e6a5821c91df2192fb557df7d1d5b03adf 🔍
SHA3 02aca56ecfb1a92bdaa4b244155b03355e03b97259e55dff0e430569e2cdf570 🔍
VirtualSize 0x9a6dd
VirtualAddress 0x1000
SizeOfRawData 0x9a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66152

.rdata

MD5 6b3740cce13913a80969386e79a5e997 🔍
SHA1 74203b0112b36d254bbde1c67e086aea5a69f7a1 🔍
SHA256 415898847e4e840a3f99ec409b5c0ab8194909b1202b225b29b1d2b06da786fa 🔍
SHA3 e0ae75da2ecd07dca946f43e347e426caf252d23361ded9575967b902a43b229 🔍
VirtualSize 0x2923e
VirtualAddress 0x9c000
SizeOfRawData 0x29400
PointerToRawData 0x9ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.56039

.data

MD5 1071a200166460976b839d28ce26028f 🔍
SHA1 e9712844bbc316e0febe0cacb83d5b094703aac8 🔍
SHA256 a0a38069a5e4b3d7bed37c5bca1374ec0858481e003bb012f6def35621511847 🔍
SHA3 a6d4e6f55a1f04ecb9aa36be3bc864b728955ce8fd4eee3d2cbfc8b3f81c3e0e 🔍
VirtualSize 0x40b484
VirtualAddress 0xc6000
SizeOfRawData 0x8400
PointerToRawData 0xc4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.01886

.rsrc

MD5 3021450cd2d0409ba6bcabeb7e7f2495 🔍
SHA1 3ca0116ae89d9ae1e8dfb36b1b50887dfb4ecc21 🔍
SHA256 6c607d1fe868dfaf3d9834c52b6e2378f0c8aec4c645f26ff5e42fec92fd83be 🔍
SHA3 489e50c022cfc92800ca110acdf9d1a9c7247f653d57f85b419ab9a12cc4c43d 🔍
VirtualSize 0x1b4
VirtualAddress 0x4d2000
SizeOfRawData 0x200
PointerToRawData 0xcc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.09959

.reloc

MD5 f580891596e6ba368af2c3a74019312f 🔍
SHA1 7c7da46d28565949d919afc35e6269191bee9003 🔍
SHA256 8a91bbf63605e69df2a899f03de002976d142e5bbe59fdd16a3684f24b826c69 🔍
SHA3 3bbef5f0f7d1736078f9a6ae388f33c929c739eddf34910283338bc3f7cb5a7a 🔍
VirtualSize 0x17abc
VirtualAddress 0x4d3000
SizeOfRawData 0x17c00
PointerToRawData 0xcc600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.51492

Imports

MMCodec.dll #1140
#593
#1134
#709
#1222
#1117
#572
#717
#186
#878
#132
#665
#894
#746
#1424
#1266
#1329
#564
#1082
#949
#1373
#901
#210
#945
#807
#472
#65
#20
#1052
#1368
#253
#566
#1021
#1092
#507
#1132
#1352
#911
#451
#611
#497
#1288
#375
#513
#670
#495
#434
#32
#546
#282
#133
#1155
#1355
#712
#833
#1232
#1017
#9
#424
#1245
#1253
#763
#1334
#1065
#189
#460
#362
#940
#548
#533
#511
#882
#14
#181
#1250
#1040
#1343
#295
#697
#998
#62
#109
#574
#1438
#919
#368
#100
#1427
#1043
#83
#291
#1366
#1148
#466
#1114
#399
#200
#553
#693
#308
#475
#1252
#60
#956
#232
#565
#214
#338
#1129
#646
#868
#731
#1087
#503
#477
#1167
#727
#196
#1209
#1346
#598
#839
#373
#850
#325
#948
#113
#819
#1434
#1080
#148
#471
#1133
#55
#791
#597
KERNEL32.dll WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetModuleHandleA
GetStringTypeW
GetStringTypeA
SetStdHandle
GetCurrentProcessId
GetTickCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
FlushFileBuffers
GetStartupInfoA
GetFileType
SetHandleCount
HeapSize
RaiseException
GetConsoleMode
GetConsoleCP
RtlUnwind
LCMapStringW
LCMapStringA
GetStdHandle
ExitProcess
CompareStringA
VirtualFree
HeapCreate
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
GetProcAddress
GetModuleHandleW
IsValidCodePage
GetOEMCP
GetACP
InterlockedDecrement
InterlockedIncrement
GetCPInfo
InterlockedExchange
GetCommandLineA
GetFileAttributesW
GetSystemTimeAsFileTime
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
CreateThread
GetCurrentThreadId
ExitThread
CreateDirectoryW
HeapReAlloc
HeapAlloc
HeapFree
SetEnvironmentVariableA
CompareStringW
CreateFileA
GetProcessHeap
VirtualAlloc
SetLastError
GetLocaleInfoA
WriteFile
SetEndOfFile
SetFilePointer
CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
QueryPerformanceFrequency
GetSystemInfo
QueryPerformanceCounter
SetThreadPriority
CreateSemaphoreW
ReleaseSemaphore
OutputDebugStringA
DeleteFileW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
CreateFileW
ReadFile
GetFileSize
EnterCriticalSection
LeaveCriticalSection
DeleteTimerQueueTimer
CloseHandle
GetDiskFreeSpaceExA
ReleaseMutex
DeleteCriticalSection
CreateToolhelp32Snapshot
GetCurrentProcess
WaitForSingleObject
SetThreadExecutionState
OutputDebugStringW
InitializeCriticalSection
Sleep
GetLastError
CreateTimerQueueTimer
MoveFileW
Process32FirstW
Process32NextW
CreateMutexA
ADVAPI32.dll OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueW
SHELL32.dll ShellExecuteA
ole32.dll CoInitialize
CoUninitialize
WINMM.dll timeGetDevCaps
timeBeginPeriod
timeEndPeriod
WS2_32.dll WSAGetLastError
htons
ioctlsocket
recv
select
__WSAFDIsSet
closesocket
send
getsockopt
htonl
connect
inet_addr
socket
WSAStartup
WSACleanup
accept
listen
bind
setsockopt
shutdown

Delayed Imports

_cJSON_AddArrayToObject@8

Ordinal 1
Address 0x3420

_cJSON_AddBoolToObject@12

Ordinal 2
Address 0x3100

_cJSON_AddFalseToObject@8

Ordinal 3
Address 0x3050

_cJSON_AddItemReferenceToArray@8

Ordinal 4
Address 0x2e50

_cJSON_AddItemReferenceToObject@12

Ordinal 5
Address 0x2eb0

_cJSON_AddItemToArray@8

Ordinal 6
Address 0x2c90

_cJSON_AddItemToObject@12

Ordinal 7
Address 0x2d60

_cJSON_AddItemToObjectCS@12

Ordinal 8
Address 0x2de0

_cJSON_AddNullToObject@8

Ordinal 9
Address 0x2ef0

_cJSON_AddNumberToObject@16

Ordinal 10
Address 0x31b0

_cJSON_AddObjectToObject@8

Ordinal 11
Address 0x3370

_cJSON_AddRawToObject@12

Ordinal 12
Address 0x32e0

_cJSON_AddStringToObject@12

Ordinal 13
Address 0x3250

_cJSON_AddTrueToObject@8

Ordinal 14
Address 0x2fa0

_cJSON_Compare@12

Ordinal 15
Address 0x41e0

_cJSON_CreateArray@0

Ordinal 16
Address 0x3b60

_cJSON_CreateArrayReference@4

Ordinal 17
Address 0x3ac0

_cJSON_CreateBool@4

Ordinal 18
Address 0x3920

_cJSON_CreateDoubleArray@8

Ordinal 19
Address 0x3d20

_cJSON_CreateFalse@0

Ordinal 20
Address 0x38e0

_cJSON_CreateFloatArray@8

Ordinal 21
Address 0x3c80

_cJSON_CreateIntArray@8

Ordinal 22
Address 0x3be0

_cJSON_CreateNull@0

Ordinal 23
Address 0x3860

_cJSON_CreateNumber@8

Ordinal 24
Address 0x3960

_cJSON_CreateObject@0

Ordinal 25
Address 0x3ba0

_cJSON_CreateObjectReference@4

Ordinal 26
Address 0x3a80

_cJSON_CreateRaw@4

Ordinal 27
Address 0x3b00

_cJSON_CreateString@4

Ordinal 28
Address 0x39e0

_cJSON_CreateStringArray@8

Ordinal 29
Address 0x3dc0

_cJSON_CreateStringReference@4

Ordinal 30
Address 0x3a40

_cJSON_CreateTrue@0

Ordinal 31
Address 0x38a0

_cJSON_Delete@4

Ordinal 32
Address 0x1260

_cJSON_DeleteItemFromArray@8

Ordinal 33
Address 0x3590

_cJSON_DeleteItemFromObject@8

Ordinal 34
Address 0x3610

_cJSON_DeleteItemFromObjectCaseSensitive@8

Ordinal 35
Address 0x3640

_cJSON_DetachItemFromArray@8

Ordinal 36
Address 0x3540

_cJSON_DetachItemFromObject@8

Ordinal 37
Address 0x35b0

_cJSON_DetachItemFromObjectCaseSensitive@8

Ordinal 38
Address 0x35e0

_cJSON_DetachItemViaPointer@8

Ordinal 39
Address 0x34d0

_cJSON_Duplicate@8

Ordinal 40
Address 0x3e40

_cJSON_GetArrayItem@8

Ordinal 41
Address 0x2ac0

_cJSON_GetArraySize@4

Ordinal 42
Address 0x2aa0

_cJSON_GetErrorPtr@0

Ordinal 43
Address 0x1000

_cJSON_GetNumberValue@4

Ordinal 44
Address 0x1030

_cJSON_GetObjectItem@8

Ordinal 45
Address 0x2b80

_cJSON_GetObjectItemCaseSensitive@8

Ordinal 46
Address 0x2ba0

_cJSON_GetStringValue@4

Ordinal 47
Address 0x1010

_cJSON_HasObjectItem@8

Ordinal 48
Address 0x2bc0

_cJSON_InitHooks@4

Ordinal 49
Address 0x11a0

_cJSON_InsertItemInArray@12

Ordinal 50
Address 0x3670

_cJSON_IsArray@4

Ordinal 51
Address 0x4180

_cJSON_IsBool@4

Ordinal 52
Address 0x4100

_cJSON_IsFalse@4

Ordinal 53
Address 0x40c0

_cJSON_IsInvalid@4

Ordinal 54
Address 0x40a0

_cJSON_IsNull@4

Ordinal 55
Address 0x4120

_cJSON_IsNumber@4

Ordinal 56
Address 0x4140

_cJSON_IsObject@4

Ordinal 57
Address 0x41a0

_cJSON_IsRaw@4

Ordinal 58
Address 0x41c0

_cJSON_IsString@4

Ordinal 59
Address 0x4160

_cJSON_IsTrue@4

Ordinal 60
Address 0x40e0

_cJSON_Minify@4

Ordinal 61
Address 0x3f90

_cJSON_Parse@4

Ordinal 62
Address 0x1f50

_cJSON_ParseWithLength@8

Ordinal 63
Address 0x1f80

_cJSON_ParseWithLengthOpts@16

Ordinal 64
Address 0x1e10

_cJSON_ParseWithOpts@12

Ordinal 65
Address 0x1dd0

_cJSON_Print@4

Ordinal 66
Address 0x20e0

_cJSON_PrintBuffered@12

Ordinal 67
Address 0x2120

_cJSON_PrintPreallocated@16

Ordinal 68
Address 0x21d0

_cJSON_PrintUnformatted@4

Ordinal 69
Address 0x2100

_cJSON_ReplaceItemInArray@12

Ordinal 70
Address 0x3770

_cJSON_ReplaceItemInObject@12

Ordinal 71
Address 0x3820

_cJSON_ReplaceItemInObjectCaseSensitive@12

Ordinal 72
Address 0x3840

_cJSON_ReplaceItemViaPointer@12

Ordinal 73
Address 0x36f0

_cJSON_SetNumberHelper@12

Ordinal 74
Address 0x1430

_cJSON_SetValuestring@8

Ordinal 75
Address 0x1490

_cJSON_Version@0

Ordinal 76
Address 0x1070

_cJSON_free@4

Ordinal 77
Address 0x44c0

_cJSON_malloc@4

Ordinal 78
Address 0x44a0

1

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x15a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79597
MD5 24d3b502e1846356b0263f945ddd5529 🔍
SHA1 bac45b86a9c48fc3756a46809c101570d349737d 🔍
SHA256 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e 🔍
SHA3 1244ed60820da52dc4b53880ec48e3b587dbdbd9545f01fa2b1c0fcfea1d5e9e 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-06 10:58:22
Version 0.0
SizeofData 123
AddressOfRawData 0xb5798
PointerToRawData 0xb4398
Referenced File c:\Users\U201123\Work\PrivateLibrary\Libraries\ElectronDRM\src\MediaHandle\Release\MediaHandle.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4c64b4
SEHandlerTable 0x4bd160
SEHandlerCount 387

RICH Header

XOR Key 0xa14b648d
Unmarked objects 0
150 (20413) 5
C++ objects (VS2008 SP1 build 30729) 75
ASM objects (VS2008 SP1 build 30729) 42
C objects (VS2008 SP1 build 30729) 198
Imports (VS2012 build 50727 / VS2005 build 50727) 20
Imports (VS2008 SP1 build 30729) 3
Total imports 325
137 (VS2008 SP1 build 30729) 214
Exports (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.