| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-06 10:58:22 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\Users\U201123\Work\PrivateLibrary\Libraries\ElectronDRM\src\MediaHandle\Release\MediaHandle.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Sanus Med Co.
Issuer: GlobalSign GCC R45 CodeSigning CA 2020 |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 28c7bf9f17ef9e029df779c2adf8cf19 🔍 |
|---|---|
| SHA1 | d90829f9a980ce9cabb7c2b86237fa9a200d5b8d 🔍 |
| SHA256 | 1834039fa73f1cc6c5b40088950e6f169a4cfd6bf3f2f3de84bbc2f4c3f62892 🔍 |
| SHA3 | 77089ef3e03cf784f1efc96d832bec1fcaf4989a449eafad264bac974e0c08f4 🔍 |
| SSDeep | 24576:itJ3GtEvJhwWPbuWadF5c0HJFqITcj+6zZvZ:+hwddFi0HNRYZB 🔍 |
| Imports Hash | 65961eb4fafca8bd61dcb0cd9d905740 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Aug-06 10:58:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x9a800 |
| SizeOfInitializedData | 0x49600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0007B204 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x9c000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4eb000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xed1b0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 567052a08fd2160f78e00734023fb332 🔍 |
|---|---|
| SHA1 | a94df8063eaec3e440cb099fdd1e0e2e9b8ca836 🔍 |
| SHA256 | f570a65422690fd3cedd17b8e3f464e6a5821c91df2192fb557df7d1d5b03adf 🔍 |
| SHA3 | 02aca56ecfb1a92bdaa4b244155b03355e03b97259e55dff0e430569e2cdf570 🔍 |
| VirtualSize | 0x9a6dd |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x9a800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.66152 |
| MD5 | 6b3740cce13913a80969386e79a5e997 🔍 |
|---|---|
| SHA1 | 74203b0112b36d254bbde1c67e086aea5a69f7a1 🔍 |
| SHA256 | 415898847e4e840a3f99ec409b5c0ab8194909b1202b225b29b1d2b06da786fa 🔍 |
| SHA3 | e0ae75da2ecd07dca946f43e347e426caf252d23361ded9575967b902a43b229 🔍 |
| VirtualSize | 0x2923e |
| VirtualAddress | 0x9c000 |
| SizeOfRawData | 0x29400 |
| PointerToRawData | 0x9ac00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.56039 |
| MD5 | 1071a200166460976b839d28ce26028f 🔍 |
|---|---|
| SHA1 | e9712844bbc316e0febe0cacb83d5b094703aac8 🔍 |
| SHA256 | a0a38069a5e4b3d7bed37c5bca1374ec0858481e003bb012f6def35621511847 🔍 |
| SHA3 | a6d4e6f55a1f04ecb9aa36be3bc864b728955ce8fd4eee3d2cbfc8b3f81c3e0e 🔍 |
| VirtualSize | 0x40b484 |
| VirtualAddress | 0xc6000 |
| SizeOfRawData | 0x8400 |
| PointerToRawData | 0xc4000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.01886 |
| MD5 | 3021450cd2d0409ba6bcabeb7e7f2495 🔍 |
|---|---|
| SHA1 | 3ca0116ae89d9ae1e8dfb36b1b50887dfb4ecc21 🔍 |
| SHA256 | 6c607d1fe868dfaf3d9834c52b6e2378f0c8aec4c645f26ff5e42fec92fd83be 🔍 |
| SHA3 | 489e50c022cfc92800ca110acdf9d1a9c7247f653d57f85b419ab9a12cc4c43d 🔍 |
| VirtualSize | 0x1b4 |
| VirtualAddress | 0x4d2000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xcc400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.09959 |
| MD5 | f580891596e6ba368af2c3a74019312f 🔍 |
|---|---|
| SHA1 | 7c7da46d28565949d919afc35e6269191bee9003 🔍 |
| SHA256 | 8a91bbf63605e69df2a899f03de002976d142e5bbe59fdd16a3684f24b826c69 🔍 |
| SHA3 | 3bbef5f0f7d1736078f9a6ae388f33c929c739eddf34910283338bc3f7cb5a7a 🔍 |
| VirtualSize | 0x17abc |
| VirtualAddress | 0x4d3000 |
| SizeOfRawData | 0x17c00 |
| PointerToRawData | 0xcc600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.51492 |
| MMCodec.dll |
#1140
#593 #1134 #709 #1222 #1117 #572 #717 #186 #878 #132 #665 #894 #746 #1424 #1266 #1329 #564 #1082 #949 #1373 #901 #210 #945 #807 #472 #65 #20 #1052 #1368 #253 #566 #1021 #1092 #507 #1132 #1352 #911 #451 #611 #497 #1288 #375 #513 #670 #495 #434 #32 #546 #282 #133 #1155 #1355 #712 #833 #1232 #1017 #9 #424 #1245 #1253 #763 #1334 #1065 #189 #460 #362 #940 #548 #533 #511 #882 #14 #181 #1250 #1040 #1343 #295 #697 #998 #62 #109 #574 #1438 #919 #368 #100 #1427 #1043 #83 #291 #1366 #1148 #466 #1114 #399 #200 #553 #693 #308 #475 #1252 #60 #956 #232 #565 #214 #338 #1129 #646 #868 #731 #1087 #503 #477 #1167 #727 #196 #1209 #1346 #598 #839 #373 #850 #325 #948 #113 #819 #1434 #1080 #148 #471 #1133 #55 #791 #597 |
|---|---|
| KERNEL32.dll |
WriteConsoleW
GetConsoleOutputCP WriteConsoleA LoadLibraryA InitializeCriticalSectionAndSpinCount GetModuleHandleA GetStringTypeW GetStringTypeA SetStdHandle GetCurrentProcessId GetTickCount GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA FlushFileBuffers GetStartupInfoA GetFileType SetHandleCount HeapSize RaiseException GetConsoleMode GetConsoleCP RtlUnwind LCMapStringW LCMapStringA GetStdHandle ExitProcess CompareStringA VirtualFree HeapCreate TlsFree TlsSetValue TlsAlloc TlsGetValue GetProcAddress GetModuleHandleW IsValidCodePage GetOEMCP GetACP InterlockedDecrement InterlockedIncrement GetCPInfo InterlockedExchange GetCommandLineA GetFileAttributesW GetSystemTimeAsFileTime IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter TerminateProcess CreateThread GetCurrentThreadId ExitThread CreateDirectoryW HeapReAlloc HeapAlloc HeapFree SetEnvironmentVariableA CompareStringW CreateFileA GetProcessHeap VirtualAlloc SetLastError GetLocaleInfoA WriteFile SetEndOfFile SetFilePointer CreateFileMappingA UnmapViewOfFile MapViewOfFile QueryPerformanceFrequency GetSystemInfo QueryPerformanceCounter SetThreadPriority CreateSemaphoreW ReleaseSemaphore OutputDebugStringA DeleteFileW GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte CreateFileW ReadFile GetFileSize EnterCriticalSection LeaveCriticalSection DeleteTimerQueueTimer CloseHandle GetDiskFreeSpaceExA ReleaseMutex DeleteCriticalSection CreateToolhelp32Snapshot GetCurrentProcess WaitForSingleObject SetThreadExecutionState OutputDebugStringW InitializeCriticalSection Sleep GetLastError CreateTimerQueueTimer MoveFileW Process32FirstW Process32NextW CreateMutexA |
| ADVAPI32.dll |
OpenProcessToken
AdjustTokenPrivileges LookupPrivilegeValueW |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
CoInitialize
CoUninitialize |
| WINMM.dll |
timeGetDevCaps
timeBeginPeriod timeEndPeriod |
| WS2_32.dll |
WSAGetLastError
htons ioctlsocket recv select __WSAFDIsSet closesocket send getsockopt htonl connect inet_addr socket WSAStartup WSACleanup accept listen bind setsockopt shutdown |
| Ordinal | 1 |
|---|---|
| Address | 0x3420 |
| Ordinal | 2 |
|---|---|
| Address | 0x3100 |
| Ordinal | 3 |
|---|---|
| Address | 0x3050 |
| Ordinal | 4 |
|---|---|
| Address | 0x2e50 |
| Ordinal | 5 |
|---|---|
| Address | 0x2eb0 |
| Ordinal | 6 |
|---|---|
| Address | 0x2c90 |
| Ordinal | 7 |
|---|---|
| Address | 0x2d60 |
| Ordinal | 8 |
|---|---|
| Address | 0x2de0 |
| Ordinal | 9 |
|---|---|
| Address | 0x2ef0 |
| Ordinal | 10 |
|---|---|
| Address | 0x31b0 |
| Ordinal | 11 |
|---|---|
| Address | 0x3370 |
| Ordinal | 12 |
|---|---|
| Address | 0x32e0 |
| Ordinal | 13 |
|---|---|
| Address | 0x3250 |
| Ordinal | 14 |
|---|---|
| Address | 0x2fa0 |
| Ordinal | 15 |
|---|---|
| Address | 0x41e0 |
| Ordinal | 16 |
|---|---|
| Address | 0x3b60 |
| Ordinal | 17 |
|---|---|
| Address | 0x3ac0 |
| Ordinal | 18 |
|---|---|
| Address | 0x3920 |
| Ordinal | 19 |
|---|---|
| Address | 0x3d20 |
| Ordinal | 20 |
|---|---|
| Address | 0x38e0 |
| Ordinal | 21 |
|---|---|
| Address | 0x3c80 |
| Ordinal | 22 |
|---|---|
| Address | 0x3be0 |
| Ordinal | 23 |
|---|---|
| Address | 0x3860 |
| Ordinal | 24 |
|---|---|
| Address | 0x3960 |
| Ordinal | 25 |
|---|---|
| Address | 0x3ba0 |
| Ordinal | 26 |
|---|---|
| Address | 0x3a80 |
| Ordinal | 27 |
|---|---|
| Address | 0x3b00 |
| Ordinal | 28 |
|---|---|
| Address | 0x39e0 |
| Ordinal | 29 |
|---|---|
| Address | 0x3dc0 |
| Ordinal | 30 |
|---|---|
| Address | 0x3a40 |
| Ordinal | 31 |
|---|---|
| Address | 0x38a0 |
| Ordinal | 32 |
|---|---|
| Address | 0x1260 |
| Ordinal | 33 |
|---|---|
| Address | 0x3590 |
| Ordinal | 34 |
|---|---|
| Address | 0x3610 |
| Ordinal | 35 |
|---|---|
| Address | 0x3640 |
| Ordinal | 36 |
|---|---|
| Address | 0x3540 |
| Ordinal | 37 |
|---|---|
| Address | 0x35b0 |
| Ordinal | 38 |
|---|---|
| Address | 0x35e0 |
| Ordinal | 39 |
|---|---|
| Address | 0x34d0 |
| Ordinal | 40 |
|---|---|
| Address | 0x3e40 |
| Ordinal | 41 |
|---|---|
| Address | 0x2ac0 |
| Ordinal | 42 |
|---|---|
| Address | 0x2aa0 |
| Ordinal | 43 |
|---|---|
| Address | 0x1000 |
| Ordinal | 44 |
|---|---|
| Address | 0x1030 |
| Ordinal | 45 |
|---|---|
| Address | 0x2b80 |
| Ordinal | 46 |
|---|---|
| Address | 0x2ba0 |
| Ordinal | 47 |
|---|---|
| Address | 0x1010 |
| Ordinal | 48 |
|---|---|
| Address | 0x2bc0 |
| Ordinal | 49 |
|---|---|
| Address | 0x11a0 |
| Ordinal | 50 |
|---|---|
| Address | 0x3670 |
| Ordinal | 51 |
|---|---|
| Address | 0x4180 |
| Ordinal | 52 |
|---|---|
| Address | 0x4100 |
| Ordinal | 53 |
|---|---|
| Address | 0x40c0 |
| Ordinal | 54 |
|---|---|
| Address | 0x40a0 |
| Ordinal | 55 |
|---|---|
| Address | 0x4120 |
| Ordinal | 56 |
|---|---|
| Address | 0x4140 |
| Ordinal | 57 |
|---|---|
| Address | 0x41a0 |
| Ordinal | 58 |
|---|---|
| Address | 0x41c0 |
| Ordinal | 59 |
|---|---|
| Address | 0x4160 |
| Ordinal | 60 |
|---|---|
| Address | 0x40e0 |
| Ordinal | 61 |
|---|---|
| Address | 0x3f90 |
| Ordinal | 62 |
|---|---|
| Address | 0x1f50 |
| Ordinal | 63 |
|---|---|
| Address | 0x1f80 |
| Ordinal | 64 |
|---|---|
| Address | 0x1e10 |
| Ordinal | 65 |
|---|---|
| Address | 0x1dd0 |
| Ordinal | 66 |
|---|---|
| Address | 0x20e0 |
| Ordinal | 67 |
|---|---|
| Address | 0x2120 |
| Ordinal | 68 |
|---|---|
| Address | 0x21d0 |
| Ordinal | 69 |
|---|---|
| Address | 0x2100 |
| Ordinal | 70 |
|---|---|
| Address | 0x3770 |
| Ordinal | 71 |
|---|---|
| Address | 0x3820 |
| Ordinal | 72 |
|---|---|
| Address | 0x3840 |
| Ordinal | 73 |
|---|---|
| Address | 0x36f0 |
| Ordinal | 74 |
|---|---|
| Address | 0x1430 |
| Ordinal | 75 |
|---|---|
| Address | 0x1490 |
| Ordinal | 76 |
|---|---|
| Address | 0x1070 |
| Ordinal | 77 |
|---|---|
| Address | 0x44c0 |
| Ordinal | 78 |
|---|---|
| Address | 0x44a0 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x15a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.79597 |
| MD5 | 24d3b502e1846356b0263f945ddd5529 🔍 |
| SHA1 | bac45b86a9c48fc3756a46809c101570d349737d 🔍 |
| SHA256 | 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e 🔍 |
| SHA3 | 1244ed60820da52dc4b53880ec48e3b587dbdbd9545f01fa2b1c0fcfea1d5e9e 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-06 10:58:22 |
| Version | 0.0 |
| SizeofData | 123 |
| AddressOfRawData | 0xb5798 |
| PointerToRawData | 0xb4398 |
| Referenced File | c:\Users\U201123\Work\PrivateLibrary\Libraries\ElectronDRM\src\MediaHandle\Release\MediaHandle.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4c64b4 |
| SEHandlerTable | 0x4bd160 |
| SEHandlerCount | 387 |
| XOR Key | 0xa14b648d |
|---|---|
| Unmarked objects | 0 |
| 150 (20413) | 5 |
| C++ objects (VS2008 SP1 build 30729) | 75 |
| ASM objects (VS2008 SP1 build 30729) | 42 |
| C objects (VS2008 SP1 build 30729) | 198 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 20 |
| Imports (VS2008 SP1 build 30729) | 3 |
| Total imports | 325 |
| 137 (VS2008 SP1 build 30729) | 214 |
| Exports (VS2008 SP1 build 30729) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.