| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Oct-25 08:16:55 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\kjk\src\sumatrapdf\out\rel64\SumatraPDF.pdb
|
| FileDescription | SumatraPDF |
| FileVersion | 3.5.2 |
| LegalCopyright | Copyright 2006-2022 all authors (GPLv3) |
| ProductName | SumatraPDF |
| ProductVersion | 3.5.2 |
| CompanyName | Krzysztof Kowalczyk |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Krzysztof Kowalczyk
Issuer: Sectigo RSA Code Signing CA |
| Suspicious | VirusTotal score: 1/66 (Scanned on 2026-03-10 15:27:48) | VirIT: Deceptor.FlexDocu.EOA |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2023-Oct-25 08:16:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x59b200 |
| SizeOfInitializedData | 0xa1c000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000005548C4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xfbd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xf61aef |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
ImageList_EndDrag
ImageList_Add ImageList_DragEnter ImageList_DragMove ImageList_BeginDrag ImageList_Create ImageList_AddMasked #345 #410 #413 InitCommonControlsEx #412 ImageList_Destroy CreatePropertySheetPageW ImageList_GetIconSize ImageList_Draw |
|---|---|
| KERNEL32.dll |
SystemTimeToFileTime
GetSystemTimeAsFileTime QueryPerformanceCounter GetLogicalDrives CloseHandle FindResourceW GetModuleHandleW MulDiv VerSetConditionMask VerifyVersionInfoW EnterCriticalSection LeaveCriticalSection InitializeCriticalSection DeleteCriticalSection HeapCreate HeapFree GetCurrentProcess TerminateProcess GetEnvironmentVariableA WaitForSingleObject GetCurrentThreadId GetLocaleInfoA CreateToolhelp32Snapshot QueryPerformanceFrequency Sleep IsDebuggerPresent DebugBreak CreateMutexW ReleaseMutex DecodePointer LoadLibraryExA WriteConsoleW GetStringTypeW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExW GetTimeZoneInformation HeapSize GetProcessHeap SetStdHandle EnumSystemLocalesW GetUserDefaultLCID IsValidLocale LCMapStringW FlsFree FlsSetValue FlsGetValue FlsAlloc GetConsoleOutputCP ReadConsoleW SetEnvironmentVariableW GetModuleHandleExW FreeLibraryAndExitThread SetFilePointerEx LCMapStringEx TlsFree InitializeCriticalSectionAndSpinCount EncodePointer RtlUnwind RtlPcToFileHeader RtlUnwindEx InitializeCriticalSectionEx GetStartupInfoW InitializeSListHead SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive IsProcessorFeaturePresent UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext CreateSemaphoreW GetProcessAffinityMask ReleaseSemaphore GetConsoleMode MoveFileW FlushFileBuffers GetFileType SetEndOfFile CreateHardLinkW RemoveDirectoryW DeviceIoControl SetThreadPriority SetLastError SetConsoleCtrlHandler GetCurrentDirectoryW FoldStringW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime TzSpecificLocalTimeToSystemTime IsDBCSLeadByte GetCPInfo CompareStringW AreFileApisANSI LocalFileTimeToFileTime RaiseException FileTimeToDosDateTime FileTimeToLocalFileTime SetThreadContext FlushInstructionCache VirtualAlloc VirtualFree VirtualProtect GetSystemDirectoryW OpenThread VirtualQuery GetThreadContext GetModuleHandleA ResumeThread SuspendThread Thread32First Thread32Next AllocConsole FormatMessageA CreateProcessW InitializeSRWLock InitializeConditionVariable GetThreadGroupAffinity InitOnceBeginInitialize InitOnceComplete WakeConditionVariable GetEnvironmentVariableW FreeLibrary LoadLibraryW OutputDebugStringW LoadLibraryExW GetProcAddress GetModuleFileNameW GetFileAttributesW OutputDebugStringA GetTempPathW GetUserDefaultUILanguage MapViewOfFile CreateFileMappingW UnmapViewOfFile SetErrorMode GetDateFormatW GetTimeFormatW MoveFileExW LoadResource LockResource SizeofResource SetThreadExecutionState GlobalAddAtomW GlobalDeleteAtom GetTickCount GetSystemTime GlobalUnlock GlobalLock GlobalFree GlobalAlloc GetCurrentThread Process32FirstW Process32NextW OpenProcess ExitProcess GetCommandLineW GetLastError SetUnhandledExceptionFilter Module32NextW PeekNamedPipe LocalFree SetCurrentDirectoryW LoadLibraryA AttachConsole GetVersionExW GetStdHandle SetConsoleScreenBufferSize GetCurrentProcessId HeapDestroy AddVectoredExceptionHandler GlobalMemoryStatusEx Module32FirstW HeapAlloc CreateThread GetSystemInfo HeapReAlloc SetEvent GetConsoleScreenBufferInfo ReadDirectoryChangesW QueueUserAPC ResetEvent ExitThread WaitForMultipleObjectsEx CompareFileTime CancelIo GetFileTime GetDriveTypeW GetTempFileNameW CopyFileW DeleteFileW GetFileAttributesExW GetFileInformationByHandle SetFileAttributesW GetVolumePathNameW SetFileTime GetDriveTypeA GetPrivateProfileIntW CreateEventW GetShortPathNameW GetLongPathNameW WritePrivateProfileStringW GetFileSizeEx GetACP MultiByteToWideChar GetExitCodeProcess ReadFile SetFilePointer TlsSetValue TlsAlloc TlsGetValue CreateEventA GetModuleFileNameA GetFullPathNameA FindClose FindFirstFileW GetFullPathNameW FindNextFileW lstrcpynW GetWindowsDirectoryW WideCharToMultiByte GetLocaleInfoW SetNamedPipeHandleState WriteFile CreateFileW CreateDirectoryW |
| USER32.dll |
SystemParametersInfoW
GetMessagePos WindowFromDC IsWindowEnabled GetUpdateRect SetRectEmpty GetClassInfoExW RegisterWindowMessageW GetCursorPos ClientToScreen SetLayeredWindowAttributes DeferWindowPos GetPropW RemovePropW BeginDeferWindowPos SetPropW EndDeferWindowPos HideCaret SetClassLongPtrW ShowCaret IsCharAlphaNumericW WindowFromPoint GetWindowThreadProcessId GetMessageW AllowSetForegroundWindow LoadBitmapW TranslateAcceleratorW LoadCursorW GetClassNameW SetParent MapVirtualKeyW ScreenToClient IsWindow CharLowerBuffW GetAncestor IsCharUpperW CheckRadioButton EndDialog SetDlgItemTextW SendDlgItemMessageW DialogBoxIndirectParamW IsDlgButtonChecked BringWindowToTop SetWindowLongW CheckDlgButton DialogBoxParamW MoveWindow OpenClipboard CloseClipboard EmptyClipboard ReuseDDElParam ShowWindowAsync IsWindowUnicode UnpackDDElParam ModifyMenuW CheckMenuRadioItem GetMenuItemID GetMenu SetMenuItemInfoW SetMenu DrawTextExW InsertMenuW GetWindowLongW GetWindow FindWindowExW GetFocus IsChild MessageBeep GetDesktopWindow UpdateWindow MessageBoxW MsgWaitForMultipleObjects DispatchMessageW SendMessageW PeekMessageW TranslateMessage GetDlgItem PostQuitMessage PostMessageW EnableWindow MessageBoxA CreateMenu LoadIconW SetActiveWindow DestroyWindow GetMenuItemInfoW GetSystemMenu CallWindowProcW GetWindowRect IsWindowVisible SetWindowPos GetMenuItemCount SetWindowLongPtrW CreateWindowExW CreatePopupMenu GetWindowLongPtrW RegisterClassExW GetClassLongPtrW SendInput DdeFreeStringHandle DdeDisconnect DrawTextW CheckMenuItem SetClipboardData DdeFreeDataHandle DdeClientTransaction DdeUninitialize DdeInitializeW TrackMouseEvent GetMonitorInfoW GetWindowInfo DdeConnect DdeCreateStringHandleW DestroyCursor EnumDisplayMonitors MonitorFromWindow MonitorFromRect CopyImage GetKeyState AdjustWindowRectEx OemToCharA CharToOemA OemToCharBuffA CharLowerW CharUpperW CharToOemBuffW TrackPopupMenu ShowWindow InvalidateRgn OffsetRect RedrawWindow MapWindowPoints SetMenuDefaultItem GetSysColor GetForegroundWindow DestroyAcceleratorTable DestroyMenu FindWindowW GetWindowDC TrackPopupMenuEx RemoveMenu GetClientRect IsZoomed AppendMenuW DrawIconEx EnableMenuItem DrawEdge GetParent DrawFrameControl InvalidateRect SetScrollInfo DefWindowProcW ShowScrollBar GetDC FillRect GetCursor GetScrollInfo GetScrollPos GetCapture SetTimer SetFocus SetCapture SetCursor KillTimer ReleaseCapture IsIconic ReleaseDC GetSystemMetrics BeginPaint SetForegroundWindow EndPaint CreateAcceleratorTableW IsDialogMessageW |
| GDI32.dll |
SetROP2
GetObjectA GetTextExtentPoint32W ExtTextOutW GetObjectW CreateDIBSection GetTextExtentPoint32A SetLayout CreateRoundRectRgn SelectClipRgn RoundRect BitBlt StartPage AbortDoc EndDoc CreateDCW GetDeviceCaps SetMapMode StartDocW EndPage Polyline LineTo MoveToEx SetBkColor Ellipse CreateFontIndirectW CreatePatternBrush CreateBitmap SetBkMode GetClipBox CreateRectRgn SetViewportOrgEx ExcludeClipRect ExtSelectClipRgn SetBrushOrgEx SelectObject CreateCompatibleDC PatBlt StretchBlt GetStockObject DeleteDC SetTextColor CreatePen Rectangle DeleteObject CreateSolidBrush GetDIBColorTable SetWorldTransform SetStretchBltMode SetDIBits TextOutW GetDIBits SetGraphicsMode SetDIBColorTable CreateCompatibleBitmap |
| WINSPOOL.DRV |
DocumentPropertiesW
#203 OpenPrinterW GetPrinterW EnumPrintersW DeviceCapabilitiesW ClosePrinter |
| COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW PrintDlgExW |
| ADVAPI32.dll |
CryptDestroyHash
RegQueryInfoKeyW RegCloseKey RegQueryValueExW RegGetValueW RegEnumKeyW InitializeSecurityDescriptor CheckTokenMembership FreeSid OpenProcessToken RegSetKeySecurity SetFileSecurityW LookupPrivilegeValueW AdjustTokenPrivileges CryptAcquireContextW CryptCreateHash CryptHashData RegOpenKeyExW CryptGetHashParam CryptReleaseContext SetSecurityDescriptorDacl AllocateAndInitializeSid |
| SHELL32.dll |
SHGetDesktopFolder
ShellExecuteExW DragAcceptFiles SHChangeNotify SHGetPathFromIDListW SHBrowseForFolderW SHGetFileInfoW SHGetMalloc DragFinish DragQueryFileW SHBindToParent SHAddToRecentDocs SHGetFolderPathW SHFileOperationW CommandLineToArgvW |
| ole32.dll |
CoSetProxyBlanket
CreateStreamOnHGlobal CoInitialize CoCreateInstance OleUninitialize OleInitialize CoTaskMemAlloc CoTaskMemFree CoGetMalloc ReleaseStgMedium CoUninitialize |
| OLEAUT32.dll |
VariantInit
VariantClear SysFreeString SysAllocString SafeArrayPutElement SafeArrayCreateVector |
| gdiplus.dll (delay-loaded) |
GdipMeasureString
GdipRotateWorldTransform GdipCreateBitmapFromGraphics GdipResetWorldTransform GdipDrawString GdipGetGenericFontFamilySansSerif GdipSetPageUnit GdipCreateFont GdipSetSmoothingMode GdipCreateFontFamilyFromName GdipSetCompositingQuality GdipDeleteFontFamily GdipCreateStringFormat GdipSetSolidFillColor GdipSetPenWidth GdipWindingModeOutline GdipDrawPath GdipFillPath GdipCreatePath GdipDeletePath GdipAddPathRectangleI GdiplusShutdown GdiplusStartup GdipSetTextRenderingHint GdipGetLogFontW GdipGetFontHeight GdipDeleteRegion GdipGetClip GdipCreateBitmapFromGdiDib GdipCreateRegion GdipGetDC GdipReleaseDC GdipGetRegionHRgn GdipSetCompositingMode GdipStringFormatGetGenericDefault GdipCloneStringFormat GdipFillEllipseI GdipDeleteStringFormat GdipScaleWorldTransform GdipSetStringFormatTrimming GdipSetStringFormatLineAlign GdipCreateFontFromLogfontA GdipDeleteFont GdipTranslateWorldTransform GdipDrawImageI GdipSetStringFormatAlign GdipSetStringFormatFlags GdipGetImageHeight GdipBitmapUnlockBits GdipCloneBitmapAreaI GdipCreateHBITMAPFromBitmap GdipBitmapSetResolution GdipBitmapLockBits GdipGetImageWidth GdipCreateBitmapFromScan0 GdipCloneImage GdipCreateBitmapFromHBITMAP GdipGetFamilyName GdipDeleteMatrix GdipTranslateMatrix GdipInvertMatrix GdipSetWorldTransform GdipCreateMatrix GdipTransformMatrixPoints GdipGetFamily GdipGetPropertyItemSize GdipDrawImageRectRectI GdipImageGetFrameCount GdipSetImageAttributesWrapMode GdipImageSelectActiveFrame GdipCreateImageAttributes GdipGetImagePixelFormat GdipSetInterpolationMode GdipGetImageHorizontalResolution GdipDisposeImageAttributes GdipGetPropertyItem GdipDrawLine GdipDrawImageRectRect GdipSetStringFormatMeasurableCharacterRanges GdipGetImageEncodersSize GdipStringFormatGetGenericTypographic GdipGetStringFormatFlags GdipMeasureCharacterRanges GdipGetRegionBounds GdipCreateBitmapFromStream GdipScaleMatrix GdipRotateMatrix GdipImageRotateFlip GdipGetImageEncoders GdipSetPropertyItem GdipDisposeImage GdipSaveImageToFile GdipCreateSolidFill GdipFillRectangleI GdipCreatePen1 GdipDrawLineI GdipDrawRectangleI GdipDeleteBrush GdipAlloc GdipCreateHatchBrush GdipFree GdipGetImageGraphicsContext GdipCreateFromHDC GdipCloneBrush GdipCreatePen2 GdipDeleteGraphics GdipCreateFontFromDC GdipDeletePen |
| Attributes | 0x1 |
|---|---|
| Name | gdiplus.dll |
| ModuleHandle | 0xe44480 |
| DelayImportAddressTable | 0xe440c8 |
| DelayImportNameTable | 0x811668 |
| BoundDelayImportTable | 0x812618 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.5.2.0 |
| ProductVersion | 3.5.2.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | SumatraPDF |
| FileVersion (#2) | 3.5.2 |
| LegalCopyright | Copyright 2006-2022 all authors (GPLv3) |
| ProductName | SumatraPDF |
| ProductVersion (#2) | 3.5.2 |
| CompanyName | Krzysztof Kowalczyk |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-25 08:16:55 |
| Version | 0.0 |
| SizeofData | 77 |
| AddressOfRawData | 0x7f7540 |
| PointerToRawData | 0x7f5b40 |
| Referenced File | C:\Users\kjk\src\sumatrapdf\out\rel64\SumatraPDF.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-25 08:16:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x7f7590 |
| PointerToRawData | 0x7f5b90 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-25 08:16:55 |
| Version | 0.0 |
| SizeofData | 1144 |
| AddressOfRawData | 0x7f75a4 |
| PointerToRawData | 0x7f5ba4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-25 08:16:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1407f7a50 |
|---|---|
| EndAddressOfRawData | 0x1407f7a70 |
| AddressOfIndex | 0x140e44a70 |
| AddressOfCallbacks | 0x14059e370 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140e20a10 |
| XOR Key | 0x93f8d3b1 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 35 |
| 253 (VS 2015-2022 runtime 32533) | 9 |
| C objects (VS 2015-2022 runtime 32533) | 20 |
| ASM objects (VS 2015-2022 runtime 32533) | 12 |
| C objects (30795) | 47 |
| C objects (CVTCIL) (30795) | 1 |
| C++ objects (30795) | 231 |
| C++ objects (CVTCIL) (30795) | 1 |
| C++ objects (VS 2015-2022 runtime 32533) | 95 |
| Imports (30795) | 25 |
| Total imports | 724 |
| Unmarked objects (#2) | 85 |
| C objects (LTCG) (VS2022 Update 7 (17.7.4) compiler 32825) | 723 |
| Resource objects (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
| Linker (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
No comments yet.