60e0d5c8d0213d882cb8419281d180f0a80a334815a8e06f580e88ab8c78038c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2019-Dec-18 14:10:46
Detected languages English - United States
Debug artifacts G:\ade\build\sb_0-37309218-1576677305.38\release\client\RelWithDebInfo\mysql.pdb
FileVersion 5.7.29.0
ProductVersion 5.7.29.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
  • CurrentControlSet\services
Contains domain names:
  • dev.mysql.com
  • http://dev.mysql.com
  • http://dev.mysql.com/
  • http://www.mysql.com
  • http://www.mysql.com/
  • http://www.w3.org
  • http://www.w3.org/2001/XMLSchema-instance
  • https://shop.mysql.com
  • https://shop.mysql.com/
  • mysql.com
  • shop.mysql.com
  • www.mysql.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to Blowfish
Uses known Diffie-Helman primes
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExA
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegOpenKeyExA
  • RegEnumValueA
  • RegSetValueExA
  • RegCreateKeyA
  • RegCloseKey
Uses Microsoft's cryptographic API:
  • CryptGetUserKey
  • CryptDecrypt
  • CryptCreateHash
  • CryptSetHashParam
  • CryptSignHashW
  • CryptDestroyHash
  • CryptExportKey
  • CryptAcquireContextW
  • CryptGetProvParam
  • CryptDestroyKey
  • CryptReleaseContext
  • CryptEnumProvidersW
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Interacts with the certificate store:
  • CertOpenStore
Safe VirusTotal score: 0/72 (Scanned on 2023-12-23 17:30:36) All the AVs think this file is safe.

Hashes

MD5 fb4102f858e3d6e182b0cca9af57e937 🔍
SHA1 953c0db7c88f9fcde33d83f114c289ca2e3b1c80 🔍
SHA256 60e0d5c8d0213d882cb8419281d180f0a80a334815a8e06f580e88ab8c78038c 🔍
SHA3 8d26e13b22492ba526453d903825e973162eb27e6554ceef8287df0520df95fc 🔍
SSDeep 49152:LtGVMwVBPy/pblDzglwfvdL+6Clr6ZxBz0H3v19b1BH+cf184rpK67M8pdNgTWB:ZGewI4Svg6ClrIBzkv1PTt8FmNJ7Q 🔍
Imports Hash b93c4e33f67fb47be2b3f1c0276453e6 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2019-Dec-18 14:10:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 12.0
SizeOfCode 0x1cec00
SizeOfInitializedData 0x4dc600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000001CEEC0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x6ae000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bb32a47148c40d479dfd611a846e31e4 🔍
SHA1 a42985dc99242f9761a2204b6a7df0a8361c63ed 🔍
SHA256 876c05f404827d4fddefdc28f21dd07f309a7e823c3171bdcd4282b2ef08aa33 🔍
SHA3 16d668e6230f8801ed44f3c7612e77c4c976b3602a79cc8472b9b99d577be19a 🔍
VirtualSize 0x1cebff
VirtualAddress 0x1000
SizeOfRawData 0x1cec00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36392

.rdata

MD5 cd746c675f550c4f19629a1ad46c0829 🔍
SHA1 c1d8792d84ccb55e16d2f767f5091cf4abc45ddf 🔍
SHA256 99f8bdb6281724bc72cd1a6f4f3f4d693f0084b4a35f096b24075455818204f8 🔍
SHA3 7e15b05c9cd8c0540cf8ed78c27a9a836398b7b1c308b0bb24e8ea31f867f754 🔍
VirtualSize 0x369e90
VirtualAddress 0x1d0000
SizeOfRawData 0x36a000
PointerToRawData 0x1cf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.16417

.data

MD5 1b304e392d5bedca325b90d1fdd74e07 🔍
SHA1 a424bffef25920a2a05b7bf868900211d2d00ef2 🔍
SHA256 a39bbedd7c299c8c0549745fac4096784127572007c31b571d9a0baa89d44ddf 🔍
SHA3 c6c4d6ed1c89db96e690cfc59d89154bb8b4b311a651b11de0ba2cb10387fee9 🔍
VirtualSize 0x147e80
VirtualAddress 0x53a000
SizeOfRawData 0x81800
PointerToRawData 0x539000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.11107

.pdata

MD5 7da1a780d3b0339a15aa83a249147695 🔍
SHA1 6786e9d466eb362010338d016fc18c47840fbfec 🔍
SHA256 dfa453d8a24dff8f2e7513edbcdd74d4573737d5f2195277d8a2547298a72100 🔍
SHA3 a0bf5529aaa7a2d239b5e13581fe263e0f2edb854f073e1323aaabb196c1a94d 🔍
VirtualSize 0x211bc
VirtualAddress 0x682000
SizeOfRawData 0x21200
PointerToRawData 0x5ba800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28401

.rsrc

MD5 e125fb7ca8976dbbd366fe77d700e938 🔍
SHA1 add43cca841094075aa8284a6e7897e462472eb2 🔍
SHA256 7a36f2f4440a1740874b3b2eb812f6f4b6ff23f097363aa8920e4db09e08c75d 🔍
SHA3 39812b16814616d9236bd40272d35f7a71ab47498de7b7d1528944f7b7db9690 🔍
VirtualSize 0x368
VirtualAddress 0x6a4000
SizeOfRawData 0x400
PointerToRawData 0x5dba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.98613

.reloc

MD5 7aff9dcc73406d4f1c674327998d2f0e 🔍
SHA1 7633f86a40c1259d0b7cc594c735099571016c03 🔍
SHA256 93559178d2d1a2cc0423893e0eb202a74eda3296095034ce4a383b892fbf5565 🔍
SHA3 53fc09d8d73d2e53f9e4adab73580a1339d7459b1e5102064123fb269349f4fa 🔍
VirtualSize 0x8ef4
VirtualAddress 0x6a5000
SizeOfRawData 0x9000
PointerToRawData 0x5dbe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45684

Imports

KERNEL32.dll IsProcessorFeaturePresent
IsDebuggerPresent
DecodePointer
EncodePointer
GetEnvironmentVariableW
ReadConsoleA
LoadLibraryW
ConvertThreadToFiber
ConvertFiberToThread
FindClose
FindFirstFileW
FindNextFileW
FormatMessageW
GetSystemTime
SystemTimeToFileTime
GetFileType
GetVersion
GetModuleHandleW
MultiByteToWideChar
WideCharToMultiByte
CreateFiber
SwitchToFiber
DeleteFiber
InitializeCriticalSectionAndSpinCount
WaitForMultipleObjects
CancelIo
GetOverlappedResult
PeekNamedPipe
GetModuleHandleExW
GetLogicalDrives
SetLastError
GetFullPathNameA
GetFileAttributesA
FormatMessageA
LoadLibraryExA
FreeLibrary
CreateEventA
LoadLibraryA
GetCurrentProcess
DuplicateHandle
WriteFile
SetFilePointerEx
SetEndOfFile
ReadFile
GetFileSizeEx
GetFileAttributesExA
FlushFileBuffers
TerminateThread
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
DeleteCriticalSection
InitializeCriticalSection
GetProcAddress
GetModuleHandleA
GetWindowsDirectoryA
GetSystemDirectoryA
GetConsoleCP
WaitNamedPipeA
OpenFileMappingA
UnmapViewOfFile
MapViewOfFile
GetCurrentThreadId
GetCurrentProcessId
OpenEventA
CreateMutexA
WaitForSingleObject
ReleaseMutex
SetEvent
SetNamedPipeHandleState
WriteConsoleW
SetConsoleMode
ReadConsoleW
GetConsoleMode
LocalFree
GetCommandLineW
GetStdHandle
GetSystemTimeAsFileTime
QueryPerformanceFrequency
QueryPerformanceCounter
CloseHandle
CreateFileA
GetModuleFileNameA
GetLastError
GetLocaleInfoA
LeaveCriticalSection
EnterCriticalSection
SetConsoleCtrlHandler
DisconnectNamedPipe
Sleep
ADVAPI32.dll CryptGetUserKey
RegisterEventSourceW
EqualSid
GetUserNameW
CryptDecrypt
CryptCreateHash
CryptSetHashParam
CryptSignHashW
CryptDestroyHash
CryptExportKey
DeregisterEventSource
RegisterEventSourceA
CryptAcquireContextW
CryptGetProvParam
CryptDestroyKey
CryptReleaseContext
CryptEnumProvidersW
LookupAccountNameW
IsValidSid
GetTokenInformation
RegOpenKeyExA
RegEnumValueA
RegSetValueExA
RegCreateKeyA
RegCloseKey
ReportEventW
CRYPT32.dll CertDuplicateCertificateContext
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertOpenStore
CertGetCertificateContextProperty
CertFreeCertificateContext
Secur32.dll AcquireCredentialsHandleA
FreeCredentialsHandle
DeleteSecurityContext
InitializeSecurityContextW
GetUserNameExW
FreeContextBuffer
CompleteAuthToken
MSVCP120.dll ?_Xbad_alloc@std@@YAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAPEBDH@Z
?_Xlength_error@std@@YAXPEBD@Z
MSVCR120.dll _unlock
_calloc_crt
_setmode
__C_specific_handler
_onexit
__crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
__crtCaptureCurrentContext
__crtCapturePreviousContext
_XcptFilter
_amsg_exit
__getmainargs
__set_app_type
_cexit
_configthreadlocale
__setusermatherr
_initterm_e
_initterm
__initenv
_fmode
_commode
?terminate@@YAXXZ
__crtSetUnhandledExceptionFilter
?_type_info_dtor_internal_method@type_info@@QEAAXXZ
raise
_exit
_vsnprintf
_vsnwprintf
wcsstr
_strdup
_stat64i32
strspn
strcspn
toupper
realloc
sscanf
memchr
_CxxThrowException
??2@YAPEAX_K@Z
_purecall
strtok_s
strncpy
strncat
_localtime64_s
_stat64
_fstat64
fopen
_umask
qsort
_findnext64i32
_findfirst64i32
_findclose
_endthreadex
_beginthreadex
strerror_s
strcat_s
ftell
fseek
fread
ferror
_lock
_set_abort_behavior
fputc
fgets
_strtoui64
_strtoi64
strcmp
_getch
_cputs
iscntrl
isspace
ldiv
strnlen
_get_osfhandle
_tzset
_set_invalid_parameter_handler
freopen
_open_osfhandle
_dup2
_close
atoi
strtol
strncmp
malloc
free
calloc
memmove
memcpy
floor
__CxxFrameHandler3
_time64
_localtime64
_ctime64
clock
_hypot
strtoul
getenv
exit
_errno
sprintf
vfprintf
puts
putchar
putc
printf
perror
fwrite
fputs
fprintf
_fileno
fflush
fclose
__iob_func
strtok
strstr
strrchr
strpbrk
_strnicmp
strerror
strchr
??3@YAXPEAX@Z
memset
memcmp
_gmtime64_s
_wfopen
??_V@YAXPEAX@Z
_stricmp
signal
feof
_dup
_isatty
_putenv
_getcwd
_chdir
__dllonexit
_fdopen
bcrypt.dll BCryptGenRandom
USER32.dll GetProcessWindowStation
GetUserObjectInformationW
MessageBoxW
SHELL32.dll CommandLineToArgvW
WS2_32.dll bind
closesocket
getsockname
socket
WSAGetLastError
getaddrinfo
freeaddrinfo
__WSAFDIsSet
ntohs
ioctlsocket
getpeername
getsockopt
htonl
recv
select
send
setsockopt
shutdown
WSASetLastError
WSAIoctl
getnameinfo
gethostbyname
listen
accept
WSACleanup
WSAStartup
getservbyname
connect

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x148
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15359
MD5 0647928d45c832f979e2061ce7cce312 🔍
SHA1 f2e3b7d36f8f184fff3e9fac1939ea1fc29fce3a 🔍
SHA256 7b92ee264ecec94b5ba3ee604127ee80e479397ddaa9eb5956acb2848c674960 🔍
SHA3 bb6de2f3753c6a30ea8acf58dab11551a0f7009f71d4bf7cf5149c3fd5a172f9 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 5.7.29.0
ProductVersion 5.7.29.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 5.7.29.0
ProductVersion (#2) 5.7.29.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-Dec-18 14:10:46
Version 0.0
SizeofData 105
AddressOfRawData 0x50d4c0
PointerToRawData 0x50c4c0
Referenced File G:\ade\build\sb_0-37309218-1576677305.38\release\client\RelWithDebInfo\mysql.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2019-Dec-18 14:10:46
Version 0.0
SizeofData 20
AddressOfRawData 0x50d52c
PointerToRawData 0x50c52c

TLS Callbacks

Load Configuration

Size 0x70
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1405bb610

RICH Header

XOR Key 0x3aff63ad
Unmarked objects 0
199 (41118) 12
ASM objects (20806) 2
C objects (20806) 19
221 (20806) 4
C++ objects (20806) 7
C objects (VS2013 UPD5 build 40629) 108
C objects (VS2010 SP1 build 40219) 565
Imports (65501) 17
Total imports 306
C++ objects (VS2013 UPD5 build 40629) 18
Resource objects (VS2013 build 21005) 1
151 1
Linker (VS2013 UPD5 build 40629) 1

Errors

[*] Warning: Yara callback received an unhandled message (6).
Leave a comment

No comments yet.