864e2065596979b4c92db640fd0b9a9bbd124bca5ca932adb35958b0eaa2250a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-30 12:51:32
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
CompanyName Microsoft Corporation
FileDescription Windows Session Manager
FileVersion 10.0.19041.1
InternalName smss
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename smss.exe
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.1

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • https://github.com
  • https://openfontlicense.orgThis
  • https://openfontlicense.orghttps
  • https://typedesigner.deSergej
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExA
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegCloseKey
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
  • AttachThreadInput
  • MapVirtualKeyA
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 a147b7df5807fe12bb82367b83f3b051
SHA1 2999c6088bf2e60d2db1e8233b0bd42f63a7a6f5
SHA256 864e2065596979b4c92db640fd0b9a9bbd124bca5ca932adb35958b0eaa2250a
SHA3 66c1a94796518f083860a57699fe31e19e3dad58883c8922ed636649d6327874
SSDeep 24576:hrL3JzTvM6DF6IldjA+k2kHLMjTtJusEiKi0rl2BO7s:VLCrIlxlZfOiT0r
Imports Hash 93e90a0eb83a50e61538e23b81f47228

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2026-Jul-30 12:51:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xe0600
SizeOfInitializedData 0x5b200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000ABCB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x141000
SizeOfHeaders 0x400
Checksum 0x13b322
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6a7172c6b07da04c8029f5e0d059455f
SHA1 4fef88283c31b43cafeb05fbd19604f52dc88d56
SHA256 121ba7dccc68038a899a9751dc2e750f5b51faa17ca9f71262e19e6fce34efdc
SHA3 821bd1742b2ddadf464a4f83cd6b7a6d95fbfd983f4bb009ff691951e9716a18
VirtualSize 0xe05fc
VirtualAddress 0x1000
SizeOfRawData 0xe0600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55667

.rdata

MD5 f87b3d607bed2013f835631d53672b23
SHA1 38caf31fc37ae1af6aa27002dd81a89148934d91
SHA256 1134f4c9b9335ec8180e5d40d3bdfa6d8338df613d279d2fcfd0428a63f31bc9
SHA3 53cc8455c1840bba09ae9c43975ab7aeb29b767a3efb727f97de1be3dda90b20
VirtualSize 0x36128
VirtualAddress 0xe2000
SizeOfRawData 0x36200
PointerToRawData 0xe0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.96806

.data

MD5 65998035ef476ee1f9d1c113d756d0e2
SHA1 acba92d8af7c3274f3dd85964becf38384d3fd9d
SHA256 1eeb8b22d674dfc83b1866913395ee0ffcc48e5e42e060d9320b90c630fb1ffd
SHA3 0739e82ae0fb0dd626e4b0f38c7b74fb4def083f08fb71e6656624bef197a95d
VirtualSize 0x19e58
VirtualAddress 0x119000
SizeOfRawData 0x13e00
PointerToRawData 0x116c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.2506

.pdata

MD5 01a9ab89733e4f18b850f872283c9dfe
SHA1 cd09ddb9d2ae1548b0585c8f8c8e6a832ff36aca
SHA256 71c549734706edaf1fce98b16cefd5b9ab71c3088379264597c52eabc713c217
SHA3 e300f7efc23674021b54f4c5d42d00e6759fc250037c965902dd47e942964497
VirtualSize 0x97ec
VirtualAddress 0x133000
SizeOfRawData 0x9800
PointerToRawData 0x12aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.08604

.didat

MD5 b73286b218d45eab29474b5ace133ef5
SHA1 45f97b6003d135645478878ec4ef828ec00d7af3
SHA256 331a214ab974acf3ad6e11402aca68c9ac39b2899135c3ec8a9e75915ae73396
SHA3 c80bd29dbaec97fea2b679732a5aa293aca0c398b5ec84174f2e371a06d8f52c
VirtualSize 0x108
VirtualAddress 0x13d000
SizeOfRawData 0x200
PointerToRawData 0x134200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.80981

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x13e000
SizeOfRawData 0x200
PointerToRawData 0x134400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 127f82ca742798dc60b04903df59989a
SHA1 5386dbb427e44b9f17b3cf149e21334a3247c81d
SHA256 815d57c3a92f2ef395da137b6ece7b1debc0e6d0e7379652a80c4ffeaaf96d4f
SHA3 717accab0cb313b178db21d27fe2380293b492ebdec18198d8c97d4996045ab8
VirtualSize 0x570
VirtualAddress 0x13f000
SizeOfRawData 0x600
PointerToRawData 0x134600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.86313

.reloc

MD5 4d2d9c60dc3f736fe007893a429fd798
SHA1 44a61f7a745469f86dd7fdb0a71a65bc544eca87
SHA256 a2a8eca7a6503bb3207866942c4ad190e99a83560d8e80be88d96b15fddbbaa1
SHA3 c7a30c3fb3bd2a8a14e9af9d9d44c709c7640adfbc895b8218772e56dcbe03bd
VirtualSize 0xd2c
VirtualAddress 0x140000
SizeOfRawData 0xe00
PointerToRawData 0x134c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.31797

Imports

KERNEL32.dll FlushInstructionCache
CreateFileW
Module32Next
GetProcessId
Module32First
OpenProcess
CreateToolhelp32Snapshot
QueryFullProcessImageNameA
QueryFullProcessImageNameW
GetExitCodeProcess
LoadLibraryW
GetModuleHandleW
WaitForSingleObject
GetCurrentProcess
SetErrorMode
GetCurrentThread
IsDebuggerPresent
GetCurrentProcessId
OutputDebugStringA
WideCharToMultiByte
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
IsDBCSLeadByte
VerSetConditionMask
FreeLibrary
QueryPerformanceCounter
LoadLibraryExA
VirtualQuery
GetSystemInfo
SetEndOfFile
WriteConsoleW
HeapSize
GetProcessHeap
SetStdHandle
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetOEMCP
GetACP
IsValidCodePage
HeapReAlloc
ReadConsoleW
GetConsoleMode
GetConsoleOutputCP
GetLastError
SetFilePointerEx
GetComputerNameA
GetTimeZoneInformation
GetFileType
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
VirtualProtect
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HeapFree
HeapAlloc
GetCommandLineW
GetCommandLineA
ExitProcess
GetModuleFileNameW
WriteFile
GetStdHandle
ReadFile
GetModuleHandleExW
FreeLibraryAndExitThread
ExitThread
CreateThread
LoadLibraryExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
TerminateProcess
IsProcessorFeaturePresent
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SetFileAttributesW
GetEnvironmentVariableW
GlobalUnlock
LocalFree
GlobalLock
MultiByteToWideChar
GetModuleHandleA
ReleaseMutex
GetCurrentThreadId
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
InitializeSListHead
GlobalFree
GlobalAlloc
GetProcAddress
GetFileSizeEx
CloseHandle
FlushFileBuffers
CreateMutexA
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
TryAcquireSRWLockExclusive
Sleep
WaitForSingleObjectEx
GetExitCodeThread
FormatMessageA
GetLocaleInfoEx
CreateDirectoryW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
SetFileInformationByHandle
AreFileApisANSI
GetFileInformationByHandleEx
InitializeCriticalSectionEx
GetSystemTimeAsFileTime
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
GetStringTypeW
GetCPInfo
RtlUnwind
USER32.dll SetForegroundWindow
GetWindowLongW
AdjustWindowRectEx
GetKeyState
GetMessageExtraInfo
SetPropA
GetDC
SetWindowPos
MonitorFromWindow
EnumDisplayMonitors
ScreenToClient
WindowFromPoint
GetCapture
SetWindowLongA
ClientToScreen
IsChild
TrackMouseEvent
GetKeyboardLayout
GetMonitorInfoA
GetPropA
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
SetWindowLongPtrA
ReleaseCapture
IsIconic
SetCursorPos
ReleaseDC
GetCursorPos
MoveWindow
SetWindowDisplayAffinity
GetForegroundWindow
SetLayeredWindowAttributes
SetFocus
BringWindowToTop
SetWindowLongW
PostQuitMessage
DefWindowProcW
GetWindowRect
LoadCursorA
DestroyWindow
SetWindowRgn
CreateWindowExW
GetSystemMetrics
UnregisterClassW
RegisterClassExW
ShowWindow
IsWindow
DispatchMessageW
PeekMessageW
TranslateMessage
GetWindowLongPtrA
FindWindowA
UpdateWindow
SendInput
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetWindowThreadProcessId
GetKeyNameTextA
AttachThreadInput
MapVirtualKeyA
MessageBoxA
GDI32.dll GetDeviceCaps
CreateRoundRectRgn
ADVAPI32.dll RegQueryValueExA
RegCloseKey
RegOpenKeyExA
SHELL32.dll ShellExecuteW
ole32.dll CoInitializeEx
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
d3d11.dll (delay-loaded) D3D11CreateDeviceAndSwapChain

Delayed Imports

Attributes 0x1
Name d3d11.dll
ModuleHandle 0x131510
DelayImportAddressTable 0x13d0e8
DelayImportNameTable 0x1164d0
BoundDelayImportTable 0x1166d0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x350
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4159
MD5 0f3c2fe13d3af1058f71adbb7768d114
SHA1 476e454c4ec7d8764b9e0be316b949b560217296
SHA256 47a1672a97f84811525ad53466222a91a828c52263d1234467ff82cb8651fde6
SHA3 67fe5bca6f784d2772de473db147e3b2c93fa938e0b166d2ff4354015cd28c4e

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.19041.1
ProductVersion 10.0.19041.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Windows Session Manager
FileVersion (#2) 10.0.19041.1
InternalName smss
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename smss.exe
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.19041.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-30 12:51:32
Version 0.0
SizeofData 1268
AddressOfRawData 0x106828
PointerToRawData 0x105228

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Jul-30 12:51:32
Version 0.0
SizeofData 4
AddressOfRawData 0x106d44
PointerToRawData 0x105744

TLS Callbacks

StartAddressOfRawData 0x140106d70
EndAddressOfRawData 0x140108170
AddressOfIndex 0x1401315a4
AddressOfCallbacks 0x1400e2870
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001400AC170

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401190c0
GuardCFCheckFunctionPointer 5369636640
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x3c008954
Unmarked objects 0
C++ objects (33145) 183
C objects (33145) 35
ASM objects (33145) 23
ASM objects (35207) 10
C objects (35207) 16
Imports (33145) 17
Total imports 302
C++ objects (35207) 100
C++ objects (LTCG) (35228) 38
Resource objects (35228) 1
151 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.