2b37b276288b931cbffef4f247901b6ad5f05f628f6c31ab6f1f039a7ce66a1e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Jun-13 14:19:44
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName test
FileDescription test
FileVersion 1.0.0.0
InternalName test.dll
LegalCopyright
OriginalFilename test.dll
ProductName test
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 c42a31d203482fa02e3f9cf669a894a3 🔍
SHA1 53a986587a30faa79bb493dcf9b792170b0065f2 🔍
SHA256 2b37b276288b931cbffef4f247901b6ad5f05f628f6c31ab6f1f039a7ce66a1e 🔍
SHA3 225343fd695dfdcaafb2965e68616b60f1d94300e84f418710bac3317867a8a7 🔍
SSDeep 3072:TAi4pxpEHmAdx4/kyHRZa0YiRAl278IVn2JbS1cJw8lWL:TAi4pxpRkyHRZa0Gl278IVNc2cW 🔍
Imports Hash 6a91eb82bfd19d2706c7d43c46f7064e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Jun-13 14:19:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x16a00
SizeOfInitializedData 0xd000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000011360 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x29000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7686fed8e498738623d126176eb8df02 🔍
SHA1 b11d93db3c7ab73668c8afcf1e043b833857be8e 🔍
SHA256 822cbf045dae22059a0ea7e79d8c326557cdb921fb37a75648bd840a125476d2 🔍
SHA3 798a2cc2c335d8b18ab2aa5dd24d0116a85066b1178e850ca98c07e0782739b8 🔍
VirtualSize 0x1695c
VirtualAddress 0x1000
SizeOfRawData 0x16a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37174

.rdata

MD5 a3e820dad194427577f5c974d2c715c8 🔍
SHA1 98787c253ac586e823f72a87511283d8fffd1671 🔍
SHA256 90091fc009503596d1796cc23cd32e44924c64da0eda88797f5fea85a9507370 🔍
SHA3 df429d377eb2be87632c4ff205d3954c49e082837eb10e98184189c72658065c 🔍
VirtualSize 0x95de
VirtualAddress 0x18000
SizeOfRawData 0x9600
PointerToRawData 0x16e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.49056

.data

MD5 9d4485976b9ffc9a5e02cc516df7037d 🔍
SHA1 7eacb3453e5ec6cc45b60a2e031d1d98e7301fd1 🔍
SHA256 08e2b3284a1fcd62bb326279acacd0c33f4c140887e7b7a0ef7bbe4dc391bb0b 🔍
SHA3 f5c298e17770ac7044db17ca86c0ff2a8e3761a869db938b0017c54ecff6ac2f 🔍
VirtualSize 0x1858
VirtualAddress 0x22000
SizeOfRawData 0xa00
PointerToRawData 0x20400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.32303

.pdata

MD5 58b5c0ba22a038ca54d885829ab5f06d 🔍
SHA1 c51368b74ee6b258c16be30200d8f5df143f8e5f 🔍
SHA256 52361b3c46d4eb026eccfd768df081dd77cac91d74d5f84aa8dfaf1607b6d7e6 🔍
SHA3 d3504d45f9a1c42ea5e405c1a23d1ba65464842235b9c88e51b7d7d09b93b2d9 🔍
VirtualSize 0x13bc
VirtualAddress 0x24000
SizeOfRawData 0x1400
PointerToRawData 0x20e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.9833

_RDATA

MD5 f03e9bc08417a2c7013707183af3d6f7 🔍
SHA1 71bee5fe0c24b393899d13c3c2e3267b23f6de8e 🔍
SHA256 7a66534bd1ecead54ce21ecbe29ec7dcad84e0e4b7195df405c009d422d1c613 🔍
SHA3 5fa991e3dd29f0819c10d2611a7b35d1a029c3eb9281d70d662669ffc7ffb5ee 🔍
VirtualSize 0x1f4
VirtualAddress 0x26000
SizeOfRawData 0x200
PointerToRawData 0x22200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.20663

.reloc

MD5 373814e3aa75bacedd47b10d2b34ac1b 🔍
SHA1 83da5a329808a15709db4bf088ff9c1983bba1f4 🔍
SHA256 5a7d064a742430e08087004174a6ec386bbe555730ffa1bc8e2454e5561a7c13 🔍
SHA3 36c70ac2754c29e85c5d6a9d156393012196db1717c71cd0b1db6e551e5df104 🔍
VirtualSize 0x318
VirtualAddress 0x27000
SizeOfRawData 0x400
PointerToRawData 0x22400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.70614

.rsrc

MD5 1f9ca9756afb569154bf232a3c847775 🔍
SHA1 e213e6d0ab66d5880353c950d0b8e2aeb855577f 🔍
SHA256 5aab43a89e2581dad4e1c5b658ba43366d50e168f661923645f63dd4db927e39 🔍
SHA3 1edb7b21d7902003874f87669ee4d9c8a5f48c851a42e1753714a39d38fd6988 🔍
VirtualSize 0x524
VirtualAddress 0x28000
SizeOfRawData 0x600
PointerToRawData 0x22800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.88573

Imports

KERNEL32.dll FreeLibrary
LoadLibraryExW
OutputDebugStringW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
GetModuleHandleW
MultiByteToWideChar
GetFileAttributesExW
LoadLibraryA
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetProcAddress
GetWindowsDirectoryW
FindResourceW
GetLastError
ActivateActCtx
FindClose
CreateActCtxW
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll _invalid_parameter_noinfo_noreturn
_exit
exit
_initterm_e
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_errno
abort
__p___wargv
_c_exit
_register_thread_local_exe_atexit_callback
terminate
__p___argc
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
fputwc
__p__commode
_set_fmode
fputws
_wfsopen
fflush
__stdio_common_vfwprintf
__stdio_common_vsnwprintf_s
__stdio_common_vswprintf
setvbuf
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
free
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll toupper
_wcsdup
wcsncmp
wcsnlen
strcpy_s
api-ms-win-crt-convert-l1-1-0.dll wcstoul
_wtoi
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
_time64
wcsftime
api-ms-win-crt-locale-l1-1-0.dll setlocale
___mb_cur_max_func
_configthreadlocale
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_lock_locales
_unlock_locales
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x298
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16563
MD5 45496cd7cbc7e026dab281ea609b5759 🔍
SHA1 d5dca303f5d27f2c63274276b34d0273b7d41e7a 🔍
SHA256 afccc9755c7ac4f5bfe51c731631e199a6d37777f4a54f1766bf4505c01c3ac9 🔍
SHA3 1ba774eef7c322b220e5d41407fe474c4c0dc503bd3ff43bcab3699a70d43a4a 🔍

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9 🔍
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734 🔍
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a 🔍
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName test
FileDescription test
FileVersion (#2) 1.0.0.0
InternalName test.dll
LegalCopyright
OriginalFilename test.dll
ProductName test
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Jun-13 19:45:12
Version 0.0
SizeofData 109
AddressOfRawData 0x1e190
PointerToRawData 0x1cf90
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Jun-13 19:45:12
Version 0.0
SizeofData 20
AddressOfRawData 0x1e200
PointerToRawData 0x1d000

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Jun-13 19:45:12
Version 0.0
SizeofData 1004
AddressOfRawData 0x1e214
PointerToRawData 0x1d014

TLS Callbacks

StartAddressOfRawData 0x14001e648
EndAddressOfRawData 0x14001e658
AddressOfIndex 0x140023840
AddressOfCallbacks 0x1400184e0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140022040
GuardCFCheckFunctionPointer 5368808464
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xecfe021e
Unmarked objects 0
Unmarked objects (#2) 1
C objects (33218) 12
ASM objects (33218) 18
C++ objects (33218) 86
Imports (VS2008 SP1 build 30729) 16
Imports (30795) 9
Total imports 201
C++ objects (LTCG) (33523) 10
Linker (33523) 1

Errors

Leave a comment

No comments yet.