| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Mar-25 13:29:55 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\program1\repos\projects\TestGenCode\x64\Debug\TestGenCode.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .nv_fatb
Unusual section name found: .nvFatBi |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/65 (Scanned on 2025-06-09 05:01:34) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2025-Mar-25 13:29:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x158c00 |
| SizeOfInitializedData | 0xa0a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000003512 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x200000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
UnlockFileEx
CloseHandle GetLastError QueryPerformanceCounter QueryPerformanceFrequency HeapCreate HeapDestroy HeapAlloc HeapReAlloc HeapFree InitializeSRWLock ReleaseSRWLockExclusive ReleaseSRWLockShared AcquireSRWLockExclusive AcquireSRWLockShared TryAcquireSRWLockExclusive TryAcquireSRWLockShared InitializeCriticalSection EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection DeleteCriticalSection InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableCS SetEvent ResetEvent ReleaseSemaphore WaitForSingleObject CreateEventA Sleep WaitForMultipleObjects GetCurrentProcess GetCurrentProcessId SwitchToThread GetCurrentThread GetCurrentThreadId TlsAlloc TlsGetValue LockFileEx TlsFree GlobalMemoryStatusEx GetSystemInfo GetLocalTime GetNativeSystemInfo VirtualAlloc VirtualProtect VirtualFree VirtualQuery GetLargePageMinimum FreeLibraryAndExitThread GetModuleFileNameA GetModuleHandleA GetModuleHandleExA LoadLibraryA GetProcessAffinityMask SetThreadAffinityMask CreateSemaphoreA CreateFileMappingA CreateFileMappingNumaA GetComputerNameA GetNumaNodeProcessorMask VerSetConditionMask CreateFileW GetFileAttributesW GetFullPathNameW SetLastError CreateProcessA CreateProcessW GetSystemDirectoryW GetModuleFileNameW GetModuleHandleW LoadLibraryExW LocalAlloc LocalFree VerifyVersionInfoW GlobalSize GlobalLock GlobalUnlock GetStartupInfoW GetModuleHandleExW RemoveDirectoryA GetFileAttributesExA FindNextFileA FindFirstFileA FindClose DeleteFileA CreateDirectoryA GetCurrentDirectoryA SetEnvironmentVariableA GetEnvironmentVariableA LoadLibraryExA GetProcAddress TlsSetValue FreeLibrary GetProcessHeap InitializeSListHead GetSystemTimeAsFileTime RaiseException IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext MultiByteToWideChar FormatMessageW SetThreadExecutionState GlobalFree GlobalAlloc WideCharToMultiByte |
|---|---|
| WINMM.dll |
timeEndPeriod
timeBeginPeriod |
| VCRUNTIME140D.dll |
strstr
__vcrt_GetModuleFileNameW __std_type_info_destroy_list __C_specific_handler_noexcept __current_exception_context __current_exception __C_specific_handler memmove __vcrt_LoadLibraryExW strrchr strchr wcsstr wcsrchr memset memcmp memcpy __vcrt_GetModuleHandleW |
| ucrtbased.dll |
acos
ceil fmod exit strcspn strspn strtok strtol strtoul _seh_filter_dll _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _crt_at_quick_exit _cexit _CrtDbgReport _CrtDbgReportW _seh_filter_exe _set_app_type __setusermatherr _get_initial_narrow_environment _initterm _initterm_e _exit _set_fmode __p___argc __p___argv qsort _register_thread_local_exe_atexit_callback _configthreadlocale _set_new_mode __p__commode terminate strcpy_s strcat_s __stdio_common_vsprintf_s _wmakepath_s _wsplitpath_s wcscpy_s pow log2f expm1f exp2f sqrt cos sin fmaxf fmin fminf fabs _time64 strlen atoi rand srand llabs labs abs free calloc __stdio_common_vfprintf ungetc fopen_s __acrt_iob_func hypot fmax tan strcmp log floor _mkdir _chdir _getcwd _findnext64i32 _findfirst64i32 _findclose _access _stat64i32 round strpbrk __stdio_common_vsscanf fgets system _errno _strnicmp _wcsnicmp _wcsicmp wcstok isdigit isalpha _beginthreadex realloc log1pf strncat ftell _fileno fgetc fflush ferror feof _get_osfhandle strncpy strncmp __stdio_common_vsprintf fwrite fseek fread fopen fclose _hypotf _fdsign _ldsign _dsign fmodf floorf ceilf sqrtf powf modff log10f logf expf tanhf sinhf coshf tanf sinf cosf atan2f atanf asinf acosf fmaf nextafterf copysignf tgammaf lgammaf erfcf erff remquof remainderf cbrtf cbrt fdimf truncf nearbyintf llrintf lrintf rintf llroundf lroundf roundf frexp scalblnf ilogbf logbf ldexp atanhf asinhf _c_exit acoshf malloc |
| USER32.dll |
RemovePropW
OpenClipboard CloseClipboard GetClipboardData TrackMouseEvent TranslateMessage DispatchMessageW PeekMessageW GetMessageTime SendMessageW RegisterDeviceNotificationW UnregisterDeviceNotification PostMessageW WaitMessage DefWindowProcW UnregisterClassW RegisterClassExW GetRawInputDeviceList RegisterRawInputDevices GetRawInputDeviceInfoA GetRawInputData EnumDisplayMonitors GetMonitorInfoW MonitorFromWindow SystemParametersInfoW EnumDisplayDevicesW EnumDisplaySettingsExW EnumDisplaySettingsW ChangeDisplaySettingsExW CreateIconIndirect LoadImageW DestroyIcon LoadCursorW GetClassLongPtrW SetWindowLongW GetWindowLongW PtInRect OffsetRect SetRect ClipCursor WindowFromPoint ScreenToClient ClientToScreen GetCursorPos SetCursor SetCursorPos AdjustWindowRectEx GetWindowRect GetClientRect SetWindowTextW CreateWindowExW GetPropW SetPropW ReleaseDC GetDC SetForegroundWindow GetSystemMetrics MsgWaitForMultipleObjects ReleaseCapture SetCapture MapVirtualKeyW ToUnicode GetKeyState GetActiveWindow SetFocus EmptyClipboard SetClipboardData IsZoomed BringWindowToTop IsIconic IsWindowVisible SetWindowPlacement GetWindowPlacement SetWindowPos MoveWindow FlashWindow SetLayeredWindowAttributes GetLayeredWindowAttributes ShowWindow DestroyWindow |
| GDI32.dll |
ChoosePixelFormat
CreateDCW CreateRectRgn DeleteDC DeleteObject DescribePixelFormat GetDeviceCaps SetPixelFormat CreateDIBSection GetDeviceGammaRamp SetDeviceGammaRamp SwapBuffers CreateBitmap |
| SHELL32.dll |
DragAcceptFiles
DragFinish DragQueryPoint DragQueryFileW |
| Ordinal | 1 |
|---|---|
| Address | 0x1bb02c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-24 12:55:53 |
| Version | 0.0 |
| SizeofData | 89 |
| AddressOfRawData | 0x1a35d0 |
| PointerToRawData | 0x1a25d0 |
| Referenced File | C:\program1\repos\projects\TestGenCode\x64\Debug\TestGenCode.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-24 12:55:53 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1a362c |
| PointerToRawData | 0x1a262c |
| StartAddressOfRawData | 0x1401f8000 |
|---|---|
| EndAddressOfRawData | 0x1401fa433 |
| AddressOfIndex | 0x1401d31e8 |
| AddressOfCallbacks | 0x14015ac90 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4096BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401beac0 |
| XOR Key | 0x29f71d9f |
|---|---|
| Unmarked objects | 0 |
| Imports (34321) | 2 |
| ASM objects (34321) | 4 |
| C objects (34321) | 10 |
| C++ objects (34321) | 26 |
| C objects (34433) | 6 |
| Imports (33140) | 13 |
| Total imports | 395 |
| C objects (VS2015 build 23026) | 1 |
| C++ objects (VS2015 build 23026) | 17 |
| C++ objects (34808) | 1 |
| Exports (34808) | 1 |
| Resource objects (34808) | 1 |
| Linker (34808) | 1 |
No comments yet.