| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-30 12:51:32 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Session Manager |
| FileVersion | 10.0.19041.1 |
| InternalName | smss |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | smss.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.19041.1 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2026-Jul-30 12:51:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe0600 |
| SizeOfInitializedData | 0x5b200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000ABCB0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x141000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x13b322 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FlushInstructionCache
CreateFileW Module32Next GetProcessId Module32First OpenProcess CreateToolhelp32Snapshot QueryFullProcessImageNameA QueryFullProcessImageNameW GetExitCodeProcess LoadLibraryW GetModuleHandleW WaitForSingleObject GetCurrentProcess SetErrorMode GetCurrentThread IsDebuggerPresent GetCurrentProcessId OutputDebugStringA WideCharToMultiByte GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency IsDBCSLeadByte VerSetConditionMask FreeLibrary QueryPerformanceCounter LoadLibraryExA VirtualQuery GetSystemInfo SetEndOfFile WriteConsoleW HeapSize GetProcessHeap SetStdHandle SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage HeapReAlloc ReadConsoleW GetConsoleMode GetConsoleOutputCP GetLastError SetFilePointerEx GetComputerNameA GetTimeZoneInformation GetFileType EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW VirtualProtect FlsFree FlsSetValue FlsGetValue FlsAlloc HeapFree HeapAlloc GetCommandLineW GetCommandLineA ExitProcess GetModuleFileNameW WriteFile GetStdHandle ReadFile GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError RaiseException RtlPcToFileHeader RtlUnwindEx TerminateProcess IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter SetFileAttributesW GetEnvironmentVariableW GlobalUnlock LocalFree GlobalLock MultiByteToWideChar GetModuleHandleA ReleaseMutex GetCurrentThreadId RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext InitializeSListHead GlobalFree GlobalAlloc GetProcAddress GetFileSizeEx CloseHandle FlushFileBuffers CreateMutexA ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW TryAcquireSRWLockExclusive Sleep WaitForSingleObjectEx GetExitCodeThread FormatMessageA GetLocaleInfoEx CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW SetFileInformationByHandle AreFileApisANSI GetFileInformationByHandleEx InitializeCriticalSectionEx GetSystemTimeAsFileTime EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer LCMapStringEx GetStringTypeW GetCPInfo RtlUnwind |
|---|---|
| USER32.dll |
SetForegroundWindow
GetWindowLongW AdjustWindowRectEx GetKeyState GetMessageExtraInfo SetPropA GetDC SetWindowPos MonitorFromWindow EnumDisplayMonitors ScreenToClient WindowFromPoint GetCapture SetWindowLongA ClientToScreen IsChild TrackMouseEvent GetKeyboardLayout GetMonitorInfoA GetPropA SetCapture SetCursor GetClientRect IsWindowUnicode SetWindowLongPtrA ReleaseCapture IsIconic SetCursorPos ReleaseDC GetCursorPos MoveWindow SetWindowDisplayAffinity GetForegroundWindow SetLayeredWindowAttributes SetFocus BringWindowToTop SetWindowLongW PostQuitMessage DefWindowProcW GetWindowRect LoadCursorA DestroyWindow SetWindowRgn CreateWindowExW GetSystemMetrics UnregisterClassW RegisterClassExW ShowWindow IsWindow DispatchMessageW PeekMessageW TranslateMessage GetWindowLongPtrA FindWindowA UpdateWindow SendInput GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetWindowThreadProcessId GetKeyNameTextA AttachThreadInput MapVirtualKeyA MessageBoxA |
| GDI32.dll |
GetDeviceCaps
CreateRoundRectRgn |
| ADVAPI32.dll |
RegQueryValueExA
RegCloseKey RegOpenKeyExA |
| SHELL32.dll |
ShellExecuteW
|
| ole32.dll |
CoInitializeEx
|
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| d3d11.dll (delay-loaded) |
D3D11CreateDeviceAndSwapChain
|
| Attributes | 0x1 |
|---|---|
| Name | d3d11.dll |
| ModuleHandle | 0x131510 |
| DelayImportAddressTable | 0x13d0e8 |
| DelayImportNameTable | 0x1164d0 |
| BoundDelayImportTable | 0x1166d0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.19041.1 |
| ProductVersion | 10.0.19041.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Session Manager |
| FileVersion (#2) | 10.0.19041.1 |
| InternalName | smss |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | smss.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.19041.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 12:51:32 |
| Version | 0.0 |
| SizeofData | 1268 |
| AddressOfRawData | 0x106828 |
| PointerToRawData | 0x105228 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 12:51:32 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x106d44 |
| PointerToRawData | 0x105744 |
| StartAddressOfRawData | 0x140106d70 |
|---|---|
| EndAddressOfRawData | 0x140108170 |
| AddressOfIndex | 0x1401315a4 |
| AddressOfCallbacks | 0x1400e2870 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001400AC170
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401190c0 |
| GuardCFCheckFunctionPointer | 5369636640 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x3c008954 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 183 |
| C objects (33145) | 35 |
| ASM objects (33145) | 23 |
| ASM objects (35207) | 10 |
| C objects (35207) | 16 |
| Imports (33145) | 17 |
| Total imports | 302 |
| C++ objects (35207) | 100 |
| C++ objects (LTCG) (35228) | 38 |
| Resource objects (35228) | 1 |
| 151 | 1 |
| Linker (35228) | 1 |
No comments yet.