| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Feb-25 16:11:55 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x40 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2024-Feb-25 16:11:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x92c00 |
| SizeOfInitializedData | 0x82c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000060C48 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x11d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1199d0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
TerminateProcess
VerSetConditionMask VerifyVersionInfoW GetStdHandle IsDebuggerPresent DebugBreak OutputDebugStringW WriteConsoleW GetCurrentThreadId CreateThread Sleep GetLocalTime SetEvent CreateEventW FormatMessageW GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP IsValidCodePage FindFirstFileExW GetSystemTimeAsFileTime SetFilePointerEx GetConsoleMode GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW FlsFree FlsSetValue FlsGetValue FlsAlloc HeapQueryInformation HeapSize HeapReAlloc HeapAlloc HeapFree SetStdHandle GetModuleHandleExW LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError InterlockedPushEntrySList RtlUnwindEx RaiseException RtlPcToFileHeader FileTimeToSystemTime GetModuleFileNameW WriteFile SetFilePointer ReadFile GetFileType GetFileSizeEx GetFileAttributesExW FindNextFileW FindClose GetExitCodeThread FileTimeToLocalFileTime CreateFileW CreateDirectoryW CreateMutexW WaitForSingleObject ReleaseMutex CloseHandle GetLastError LoadLibraryW GetProcAddress GetModuleHandleW FreeLibrary LocalFree ExitProcess GetCommandLineW |
|---|---|
| USER32.dll |
ScrollWindowEx
GetIconInfo CreateIconIndirect DestroyIcon SetParent EnableWindow DestroyWindow CreateWindowExW DrawFrameControl DrawFocusRect DrawTextW GetScrollPos SetWindowTextW wsprintfW SetMenuItemInfoW InsertMenuItemW RemoveMenu EndMenu TrackPopupMenu GetMenuItemCount DestroyMenu CreatePopupMenu CreateMenu DrawMenuBar ShowScrollBar SetScrollPos SystemParametersInfoW MapVirtualKeyW GetDoubleClickTime GetScrollInfo DestroyCursor GetClassLongPtrW EqualRect IntersectRect FrameRect PostQuitMessage SetTimer KillTimer DefWindowProcW UnregisterClassW RegisterClassExW GetFocus GetAsyncKeyState GetCapture IsWindowEnabled CreateAcceleratorTableW DestroyAcceleratorTable GetDC GetWindowDC ReleaseDC GetWindowRect GetCursorPos ScreenToClient WindowFromPoint ChildWindowFromPointEx FillRect InflateRect PtInRect GetDesktopWindow LoadCursorW LoadIconW TranslateMessage DispatchMessageW PeekMessageW SendMessageW WaitMessage CallWindowProcW ShowWindow SetWindowPos IsWindowVisible SetFocus GetActiveWindow TranslateAcceleratorW GetMenu SetMenu GetMenuItemInfoW SetActiveWindow GetSysColorBrush GetClientRect AdjustWindowRectEx SetCursor ClientToScreen SetRectEmpty GetWindowLongPtrW SetWindowLongPtrW GetParent EnumChildWindows GetAncestor TrackMouseEvent InvalidateRect GetKeyState GetSystemMetrics BeginPaint EndPaint MapWindowPoints ReleaseCapture SetCapture GetSysColor RedrawWindow GetDialogBaseUnits SetWindowLongW GetWindowLongW SetScrollInfo |
| GDI32.dll |
CreateFontW
GetTextMetricsW GetObjectW SetBkMode SetTextAlign MoveToEx SetWindowOrgEx LineTo Rectangle SetBkColor GetStockObject CreateSolidBrush SelectObject DeleteDC CreateCompatibleDC CreateCompatibleBitmap CreatePen CreateBitmap SetTextColor BitBlt GetTextExtentPoint32W GetDeviceCaps ExcludeClipRect DeleteObject CreatePatternBrush |
| SHELL32.dll |
SHGetFolderPathW
SHBrowseForFolderW SHGetPathFromIDListW CommandLineToArgvW |
| COMDLG32.dll |
ChooseColorW
GetOpenFileNameW GetSaveFileNameW |
| gdiplus.dll |
GdipGetWorldTransform
GdipGetImagePalette GdipGetImagePaletteSize GdipGetImagePixelFormat GdipTranslateWorldTransform GdipMultiplyWorldTransform GdipGetPropertyItemSize GdipCreateMatrix GdipCreateMatrix2 GdipDeleteMatrix GdipInvertMatrix GdipGetMatrixElements GdipImageGetFrameDimensionsList GdipGetImageEncoders GdipDeleteBrush GdipCreateSolidFill GdipGetPropertyItem GdipCreateBitmapFromStreamICM GdipCreateLineBrushFromRectWithAngle GdipSetLineTransform GdipBitmapLockBits GdipSaveImageToStream GdipMultiplyLineTransform GdipBitmapUnlockBits GdipTranslateLineTransform GdipScaleLineTransform GdipRotateLineTransform GdipDeletePen GdipGetImageGraphicsContext GdipScaleWorldTransform GdipSetSmoothingMode GdipDrawImageRectI GdipCloneBrush GdipGetImageEncodersSize GdiplusStartup GdipSetTextRenderingHint GdipImageGetFrameCount GdipResetWorldTransform GdipDeleteFont GdipCreateFont GdipDeleteFontFamily GdipCreateFontFamilyFromName GdipGetImageHeight GdipSetPenDashArray GdipSetPenDashStyle GdipSetPenBrushFill GdipSetPenColor GdipSetPenLineJoin GdipSetPenLineCap197819 GdipSetPenWidth GdipCreatePen1 GdipSetLineWrapMode GdipSetLinePresetBlend GdipSetSolidFillColor GdipSetMatrixElements GdipDrawImageRectRect GdipDrawImageRect GdipSetImageAttributesColorMatrix GdipDisposeImageAttributes GdipCreateImageAttributes GdipCreateHICONFromBitmap GdipCreateHBITMAPFromBitmap GdipCreateBitmapFromScan0 GdipImageSelectActiveFrame GdipDisposeImage GdipCloneImage GdipGraphicsClear GdipDeleteGraphics GdiplusShutdown GdipAlloc GdipFree GdipCreateFromHDC GdipGetImageWidth |
| SHLWAPI.dll |
#12
|
| COMCTL32.dll |
ImageList_Replace
ImageList_Add ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControlsEx |
| UxTheme.dll |
GetThemePartSize
GetThemeFont |
| WS2_32.dll |
recv
send shutdown WSAStartup WSACleanup WSAGetLastError closesocket |
| api-ms-win-core-winrt-l1-1-0.dll |
RoUninitialize
RoInitialize |
| api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlLookupFunctionEntry
RtlCaptureContext RtlVirtualUnwind |
| api-ms-win-core-errorhandling-l1-1-0.dll |
SetUnhandledExceptionFilter
UnhandledExceptionFilter |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetStartupInfoW
GetCurrentProcess GetCurrentProcessId |
| api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
|
| api-ms-win-core-synch-l1-1-0.dll |
AcquireSRWLockExclusive
EnterCriticalSection TryAcquireSRWLockExclusive DeleteCriticalSection ReleaseSRWLockExclusive LeaveCriticalSection InitializeCriticalSectionEx |
| api-ms-win-core-synch-l1-2-0.dll |
WakeAllConditionVariable
SleepConditionVariableSRW |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceFrequency
QueryPerformanceCounter |
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
|
| api-ms-win-core-string-l1-1-0.dll |
MultiByteToWideChar
WideCharToMultiByte GetStringTypeW |
| api-ms-win-core-localization-l1-2-0.dll |
GetCPInfo
LCMapStringEx |
| api-ms-win-core-util-l1-1-0.dll |
DecodePointer
EncodePointer |
| ole32.dll |
CoCreateFreeThreadedMarshaler
CoGetApartmentType |
| OLEAUT32.dll |
SysAllocString
SysFreeString SysStringLen GetErrorInfo SetErrorInfo |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Feb-25 16:11:55 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0xf3894 |
| PointerToRawData | 0xf2894 |
| StartAddressOfRawData | 0x1400f3d08 |
|---|---|
| EndAddressOfRawData | 0x1400f3d10 |
| AddressOfIndex | 0x14010b898 |
| AddressOfCallbacks | 0x140094c50 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140102980 |
No comments yet.