81ffa3c945593517d644675d267077798564182fcd2a11e6bcbab138774017e3

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Oct-14 11:26:56
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName SecHex
FileDescription SecHex-GUI
FileVersion 1.0.0.0
InternalName SecHex-GUI.dll
LegalCopyright
OriginalFilename SecHex-GUI.dll
ProductName Spoofy
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Suspicious VirusTotal score: 2/72 (Scanned on 2025-07-17 00:22:10) Malwarebytes: RiskWare.Agent
Webroot: W32.Hack.Tool

Hashes

MD5 40a383e1bc8789442b784d3d85554a12
SHA1 840b8a3048c39714430cd8d14b3330cd32588195
SHA256 81ffa3c945593517d644675d267077798564182fcd2a11e6bcbab138774017e3
SHA3 cc1c1a92b57bc193e30f64bb2f589232131042266659a6ffaf7f1e8dc8371a67
SSDeep 3072:h5vnr5Tbx829UOeKnn2LFzZBp13u36wKp4zULC7oflf:hBKjK2LFzZNfIULy4
Imports Hash a8308de57fce070f4cb88c7f43bf4b27

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Oct-14 11:26:56
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18600
SizeOfInitializedData 0xf200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000014050 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8ba40b8040bd058914989c2acf2b0d09
SHA1 852478d9c389d77f5a6642d63f1ecbcaf3bfaefe
SHA256 334a1e4af4cf8c73fd0b14a6a8d1586fcb26ec6d839a63bbb1b8ff7ede6c5b5a
SHA3 cf32528ffa67521fd364c68e5668c7a6040107071c54cc6bf33df996aea4e6e9
VirtualSize 0x185fc
VirtualAddress 0x1000
SizeOfRawData 0x18600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.33502

.rdata

MD5 e005670478d4c826513df696f62e58dc
SHA1 3d8681478f95f2f585f161210dd5ae74ea848817
SHA256 df2877eb7c4beef8f6cb27148820de1e3765022640e2e0905c1b0be3d9b093fb
SHA3 41be8e1657481e217ae40b469d8ac2252c6953530ebaec135a65e6851374b7d3
VirtualSize 0x9700
VirtualAddress 0x1a000
SizeOfRawData 0x9800
PointerToRawData 0x18a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.55599

.data

MD5 4f28795e0c1b2ae3bc24f88524be1617
SHA1 e876be6fc1793a7e6321722953e7ed1eaa30400e
SHA256 6e4a708459c37a7309e3dbc363137f43f8e4a6a0bf7df8bd40f6cf716355785a
SHA3 a0564a94504ead980a98038e1b41abc657d7ebb4b379513595088e745d3f9605
VirtualSize 0x1958
VirtualAddress 0x24000
SizeOfRawData 0xa00
PointerToRawData 0x22200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.47383

.pdata

MD5 299fd63f421a366c6705b013f85f6947
SHA1 7c39ae61df0499cc4344a8ed1cb01c2ec603a990
SHA256 81bb6182b016a9241a6ea1c657cf4ef418fd239fb94f4c0ca5d38fbd4e686ff0
SHA3 0df180cfea37055b9945ccdd0a6f004729ef3560d0818c8d97c71518f2a6810e
VirtualSize 0x144c
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x22c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.90097

_RDATA

MD5 41ea609ed0ec71f23235d9e9b18cc429
SHA1 03240ae8bb1c12991e04fcbe7b76a977afb2f971
SHA256 35d18ff27b98e33e48179da2ddc32a049ef929849d56206accc174d8742a98ab
SHA3 24afc7045d58391176b7ce1b5412861f0537f9682cb458bc10c610a3aa44dc0f
VirtualSize 0xf4
VirtualAddress 0x28000
SizeOfRawData 0x200
PointerToRawData 0x24200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.44277

.reloc

MD5 3e4cd569c82075913d2243fb9e045f32
SHA1 b1461a5a441e1cccdc67c8cf02b28898c68373d9
SHA256 b2ca338412fb88ed9470a29bbbb30f214bc857ea5acf030b6de65d75e144c5eb
SHA3 40db256150f5391679bf72b9a7e999ca88af95b9da1f090d8de3d39bdd7152c3
VirtualSize 0x318
VirtualAddress 0x29000
SizeOfRawData 0x400
PointerToRawData 0x24400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.70426

.rsrc

MD5 de2918edb96ef2e89b31f93cd7d9896f
SHA1 dda77e3f9af6945cc3b0014002a3eb36b5763962
SHA256 fc2e46556226f055fbbe5ec88643424b3feba5b203d52dd12c6e489829d8ccf8
SHA3 8c16d8274ef52186e8085dfa80d7355a1b20795ec17139144fbd4a1f1b39101e
VirtualSize 0x22c4
VirtualAddress 0x2a000
SizeOfRawData 0x2400
PointerToRawData 0x24800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.89017

Imports

KERNEL32.dll FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
FindClose
MultiByteToWideChar
GetLastError
GetFileAttributesExW
GetFullPathNameW
GetProcAddress
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
LoadLibraryExW
FreeLibrary
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
EnterCriticalSection
FindFirstFileExW
OutputDebugStringW
LoadLibraryA
GetModuleHandleW
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___wargv
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_errno
_configure_wide_argv
_invalid_parameter_noinfo_noreturn
_set_app_type
_seh_filter_exe
_c_exit
exit
_cexit
_register_thread_local_exe_atexit_callback
_crt_atexit
_exit
_initterm_e
abort
_register_onexit_function
_initialize_onexit_table
terminate
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
__stdio_common_vsprintf_s
setvbuf
_wfopen
_set_fmode
__stdio_common_vswprintf
__acrt_iob_func
fputwc
fputws
__stdio_common_vfwprintf
fflush
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
free
malloc
calloc
api-ms-win-crt-string-l1-1-0.dll wcsnlen
strcpy_s
_wcsdup
strcspn
wcsncmp
toupper
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-locale-l1-1-0.dll __pctype_func
_unlock_locales
localeconv
_lock_locales
___lc_codepage_func
___mb_cur_max_func
_configthreadlocale
setlocale
___lc_locale_name_func
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
frexp
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
wcsftime
_time64

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.54241
MD5 38195e00ae938e323ef4f54ff6ccb1f1
SHA1 4d5f1fd78b4122f51abafa15d413ad4fd23b839e
SHA256 1605b757227ad18ec55a39c8cc1b022da8c574f76d6c9a90cbfe0b38fbe8a045
SHA3 3d86e0334d9c5a18b61e695640c9012549714586ca8e24fa359d759ada0171d3

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7815
Detected Filetype Icon file
MD5 3c68f77c35c26ff079a1c410ee44fa62
SHA1 0b40150c95fc2c6414c90d44ee78b8d8814b3393
SHA256 a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0
SHA3 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25071
MD5 0d338d394a157fdbc47e6d1c8f2c814f
SHA1 667f2b3633b0fc6e506f5bd2554b1ec9e1c06b08
SHA256 ae9c8cbcf9264342cad9b8e80873e7500a3de167801c56b02da93efc1a5c8450
SHA3 b29795d6a06c2452f3eefe20b027acd778633f22228f27135be5f3c6c75c381e

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.04025
MD5 5469ad846b700732c723495c4cf5946b
SHA1 0d121e749348cb5708ab9e8e8be6ca6745b335b4
SHA256 2933dc25e620e972f80a47e019680b4428f04260ad3b1e46c4d7e6eb5512fe33
SHA3 343eeea573cc6aee9eb1468eacc677bafd8b9eec0be5436f62efc98ad7a7069b

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName SecHex
FileDescription SecHex-GUI
FileVersion (#2) 1.0.0.0
InternalName SecHex-GUI.dll
LegalCopyright
OriginalFilename SecHex-GUI.dll
ProductName Spoofy
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 109
AddressOfRawData 0x1ff78
PointerToRawData 0x1e978
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 20
AddressOfRawData 0x1ffe8
PointerToRawData 0x1e9e8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 964
AddressOfRawData 0x1fffc
PointerToRawData 0x1e9fc

TLS Callbacks

StartAddressOfRawData 0x1400203e0
EndAddressOfRawData 0x1400203f0
AddressOfIndex 0x140025940
AddressOfCallbacks 0x14001a4c8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024020
GuardCFCheckFunctionPointer 5368816648
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x4ad45e8d
Unmarked objects 0
C objects (30034) 12
ASM objects (30034) 10
C++ objects (30034) 83
Imports (VS2008 SP1 build 30729) 16
Imports (29395) 9
Total imports 205
C++ objects (LTCG) (30154) 10
Linker (30154) 1

Errors

Leave a comment

No comments yet.