| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2020-Dec-04 14:32:13 |
| Detected languages |
English - United States
|
| Debug artifacts |
sscqry.exe
|
| CompanyName | Shared Services Canada |
| FileDescription | Software Asset Management and Query Tool |
| FileVersion | 3.11.11160.c8502464e4 |
| InternalName | sscqry.exe |
| LegalCopyright | Shared Services Canada |
| OriginalFilename | sscqry.exe |
| ProductName | Software Asset Manager |
| ProductVersion | 3.11.11160.c8502464e4 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Shared Services Canada
Issuer: Entrust Code Signing CA - OVCS1 |
| Safe | VirusTotal score: 0/69 (Scanned on 2021-03-31 21:29:12) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2020-Dec-04 14:32:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x172a00 |
| SizeOfInitializedData | 0xfae00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000158000 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x273000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1dfd95 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| pdh.dll |
PdhMakeCounterPathW
PdhCloseQuery PdhAddCounterW PdhOpenQueryA PdhGetFormattedCounterValue PdhCollectQueryData |
|---|---|
| WINHTTP.dll |
WinHttpCloseHandle
WinHttpOpen WinHttpGetProxyForUrl WinHttpGetIEProxyConfigForCurrentUser |
| PSAPI.DLL |
GetProcessImageFileNameW
GetProcessMemoryInfo GetModuleFileNameExW GetModuleFileNameExA |
| WSOCK32.dll |
WSAStartup
WSACleanup WSAGetLastError recv connect socket closesocket __WSAFDIsSet gethostbyname getsockname WSASetLastError shutdown send inet_ntoa getsockopt select |
| WS2_32.dll |
freeaddrinfo
getaddrinfo |
| KERNEL32.dll |
GetStdHandle
WriteFile GetModuleFileNameW GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte GetCurrentProcess ExitProcess TerminateProcess GetModuleHandleExW GetCommandLineA GetCommandLineW GetACP GetCurrentThread OutputDebugStringA OutputDebugStringW CloseHandle WaitForSingleObjectEx CreateThread HeapAlloc HeapFree FindClose FindFirstFileExA FindNextFileA FindNextFileW IsValidCodePage GetOEMCP GetCPInfo GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableA CompareStringW LCMapStringW SetStdHandle GetFileType GetStringTypeW GetProcessHeap HeapSize HeapReAlloc FlushFileBuffers GetConsoleCP GetConsoleMode SetFilePointerEx WriteConsoleW CreateFileW MoveFileExW AreFileApisANSI ReadFile TryEnterCriticalSection HeapCreate GetFullPathNameW GetDiskFreeSpaceW LockFile InitializeCriticalSection SetFilePointer GetFullPathNameA SetEndOfFile UnlockFileEx GetTempPathW TlsGetValue WaitForSingleObject GetFileAttributesW GetVersionExW UnmapViewOfFile HeapValidate Sleep GetTempPathA FormatMessageW GetDiskFreeSpaceA GetFileAttributesA GetFileAttributesExW FlushViewOfFile CreateFileA LoadLibraryA GetVersionExA DeleteFileA DeleteFileW GetSystemInfo LoadLibraryW HeapCompact HeapDestroy UnlockFile CreateFileMappingA LocalFree LockFileEx GetFileSize SystemTimeToFileTime GetSystemTime FormatMessageA CreateFileMappingW RaiseException GetTickCount OpenProcess GlobalFree CreatePipe GetTimeZoneInformation CreateProcessA GetExitCodeProcess VirtualQuery VirtualProtect VirtualFree VirtualAlloc GetNativeSystemInfo IsBadReadPtr Thread32Next Thread32First SuspendThread ResumeThread GetModuleHandleA CreateToolhelp32Snapshot GetExitCodeThread Process32NextW SetEvent TerminateThread Process32FirstW ResetEvent Module32FirstW GetThreadTimes Module32NextW CreateEventA ConvertThreadToFiber IsWow64Process GetProcessTimes OpenThread QueryPerformanceFrequency GetSystemPowerStatus SetErrorMode GetVolumeInformationA GetComputerNameExW FileTimeToSystemTime GetSystemDirectoryA VirtualUnlock VirtualLock ExpandEnvironmentStringsW ExpandEnvironmentStringsA GetEnvironmentVariableW GetEnvironmentVariableA SetThreadPriority HeapLock HeapWalk GetProcessHeaps HeapUnlock CreateDirectoryW RemoveDirectoryW SetFileTime GetFileInformationByHandle MoveFileW ReleaseSemaphore CreateSemaphoreA FindFirstFileW TlsAlloc InitializeCriticalSectionAndSpinCount DeleteCriticalSection LeaveCriticalSection EnterCriticalSection SetLastError GetLastError RtlUnwindEx GetModuleHandleW IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter LoadLibraryExW GetProcAddress FreeLibrary TlsFree MapViewOfFile TlsSetValue RtlUnwind ExitThread FreeLibraryAndExitThread CreateMutexW DuplicateHandle |
| SHELL32.dll |
SHGetFolderPathW
|
| ADVAPI32.dll |
RegQueryValueExW
LookupAccountNameW CryptAcquireContextA CryptGenRandom CryptReleaseContext OpenSCManagerW EnumServicesStatusExW QueryServiceConfigW QueryServiceConfig2W OpenServiceW QueryServiceStatusEx GetSecurityInfo SetSecurityDescriptorDacl SetFileSecurityW RegOpenKeyA SetEntriesInAclW ConvertStringSidToSidW InitializeSecurityDescriptor CreateServiceA AdjustTokenPrivileges RevertToSelf QueryServiceConfigA LookupPrivilegeValueA ChangeServiceConfigA ControlService StartServiceA ImpersonateSelf ChangeServiceConfig2A OpenThreadToken RegDeleteKeyA OpenProcessToken LsaOpenPolicy LsaClose LookupAccountSidW GetTokenInformation RegCloseKey StartServiceCtrlDispatcherA CloseServiceHandle RegQueryValueExA SetServiceStatus OpenSCManagerA RegCreateKeyExA RegisterServiceCtrlHandlerExA RegFlushKey DeleteService RegSetValueExA RegOpenKeyExA OpenServiceA |
| WININET.dll |
InternetGetConnectedState
|
| Ordinal | 1 |
|---|---|
| Address | 0x1b10 |
| Ordinal | 2 |
|---|---|
| Address | 0x1010 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.11.11160.0 |
| ProductVersion | 3.11.11160.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Shared Services Canada |
| FileDescription | Software Asset Management and Query Tool |
| FileVersion (#2) | 3.11.11160.c8502464e4 |
| InternalName | sscqry.exe |
| LegalCopyright | Shared Services Canada |
| OriginalFilename | sscqry.exe |
| ProductName | Software Asset Manager |
| ProductVersion (#2) | 3.11.11160.c8502464e4 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Dec-04 14:32:13 |
| Version | 0.0 |
| SizeofData | 35 |
| AddressOfRawData | 0x1a4ef8 |
| PointerToRawData | 0x1a3cf8 |
| Referenced File | sscqry.exe |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Dec-04 14:32:13 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1a4f1c |
| PointerToRawData | 0x1a3d1c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Dec-04 14:32:13 |
| Version | 0.0 |
| SizeofData | 712 |
| AddressOfRawData | 0x1a4f30 |
| PointerToRawData | 0x1a3d30 |
| Size | 0x108 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401bf028 |
| XOR Key | 0xc4c2a410 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 11 |
| 243 (40116) | 160 |
| 242 (40116) | 16 |
| 199 (41118) | 5 |
| C++ objects (VS2019 Update 2 (16.2) compiler 27905) | 37 |
| C objects (VS2019 Update 2 (16.2) compiler 27905) | 19 |
| ASM objects (VS2019 Update 2 (16.2) compiler 27905) | 9 |
| Imports (VS2008 SP1 build 30729) | 29 |
| Total imports | 353 |
| 264 (28106) | 198 |
| Exports (28106) | 1 |
| Resource objects (28106) | 1 |
| 151 | 1 |
| Linker (28106) | 1 |
No comments yet.