| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Mar-22 22:14:43 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\agent\_work\36\s\wix\build\ship\x86\burn.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 |
| FileVersion | 14.50.35719.0 |
| InternalName | setup |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | VC_redist.x64.exe |
| ProductName | Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 |
| ProductVersion | 14.50.35719.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .wixburn |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2011 |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-03-02 18:41:25) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-Mar-22 22:14:43 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x4cc00 |
| SizeOfInitializedData | 0x28200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000302E5 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x4e000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x79000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x11bdcb8 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExW RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegQueryValueExW RegSetValueExW OpenProcessToken AdjustTokenPrivileges LookupPrivilegeValueW InitiateSystemShutdownExW GetUserNameW CloseEventLog OpenEventLogW ReportEventW ConvertStringSecurityDescriptorToSecurityDescriptorW CreateWellKnownSid InitializeAcl DecryptFileW SetEntriesInAclW ChangeServiceConfigW CloseServiceHandle ControlService OpenSCManagerW OpenServiceW QueryServiceStatus SetNamedSecurityInfoW CheckTokenMembership AllocateAndInitializeSid SetEntriesInAclA SetSecurityDescriptorOwner SetSecurityDescriptorGroup SetSecurityDescriptorDacl InitializeSecurityDescriptor GetTokenInformation CryptDestroyHash CryptHashData CryptCreateHash CryptGetHashParam CryptReleaseContext CryptAcquireContextW QueryServiceConfigW |
|---|---|
| USER32.dll |
PeekMessageW
PostMessageW IsWindow WaitForInputIdle PostQuitMessage GetMessageW TranslateMessage MsgWaitForMultipleObjects PostThreadMessageW GetMonitorInfoW MonitorFromPoint IsDialogMessageW LoadCursorW LoadBitmapW SetWindowLongW GetWindowLongW GetCursorPos MessageBoxW CreateWindowExW UnregisterClassW RegisterClassW DefWindowProcW DispatchMessageW |
| OLEAUT32.dll |
VariantInit
SysAllocString VariantClear SysFreeString |
| GDI32.dll |
DeleteDC
DeleteObject SelectObject StretchBlt GetObjectW CreateCompatibleDC |
| SHELL32.dll |
CommandLineToArgvW
SHGetFolderPathW ShellExecuteExW |
| ole32.dll |
CoUninitialize
CoInitializeEx CoInitialize StringFromGUID2 CoCreateInstance CoTaskMemFree CoInitializeSecurity CLSIDFromProgID |
| KERNEL32.dll |
GetFileType
GetStdHandle EncodePointer InitializeCriticalSectionAndSpinCount SetLastError RtlUnwind CreateFileW CloseHandle ExitProcess CreateFileA SetFilePointer WriteFile GetLastError GetCurrentProcessId GetSystemDirectoryW LoadLibraryW lstrlenA HeapSetInformation GetModuleHandleW GetProcAddress LocalFree SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW DeleteFileW FindClose FindFirstFileW FindNextFileW GetFileAttributesW GetTempFileNameW RemoveDirectoryW SetFileAttributesW GetTempPathW MoveFileExW FormatMessageW lstrlenW MultiByteToWideChar IsValidCodePage LCMapStringW ExpandEnvironmentStringsW GetFileSizeEx GetFullPathNameW ReadFile SetFilePointerEx SetFileTime Sleep GlobalAlloc GlobalFree CopyFileW GetLocalTime GetModuleFileNameW CompareStringW HeapAlloc HeapReAlloc HeapFree HeapSize GetProcessHeap FreeLibrary InitializeCriticalSection DeleteCriticalSection ReleaseMutex GetCurrentProcess FindFirstFileExW TlsAlloc TlsGetValue TlsSetValue TlsFree CreateProcessW GetVersionExW VerSetConditionMask GetVolumePathNameW EnterCriticalSection LeaveCriticalSection GetSystemTime GetWindowsDirectoryW GetNativeSystemInfo GetSystemWow64DirectoryW GetModuleHandleExW GetComputerNameW VerifyVersionInfoW GetDateFormatW GetUserDefaultUILanguage GetUserDefaultLangID GetSystemDefaultLangID GetStringTypeW DuplicateHandle LoadLibraryExW CreateEventW ProcessIdToSessionId ConnectNamedPipe SetNamedPipeHandleState CreateNamedPipeW WaitForSingleObject GetProcessId OpenProcess CreateThread GetExitCodeThread SetEvent WaitForMultipleObjects LocalFileTimeToFileTime SetEndOfFile ResetEvent DosDateTimeToFileTime CompareStringA GetExitCodeProcess SetThreadExecutionState CopyFileExW CreateMutexW CreateFileMappingW MapViewOfFile UnmapViewOfFile GetThreadLocale GetStartupInfoW IsDebuggerPresent GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers GetConsoleOutputCP GetConsoleMode DecodePointer WriteConsoleW GetModuleHandleA VirtualAlloc VirtualFree SystemTimeToTzSpecificLocalTime SystemTimeToFileTime GetCurrentThreadId WideCharToMultiByte InitializeSListHead GetSystemTimeAsFileTime QueryPerformanceCounter IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter LoadLibraryExA VirtualQuery VirtualProtect GetSystemInfo RaiseException GetTimeZoneInformation |
| RPCRT4.dll |
UuidCreate
|
| VERSION.dll (delay-loaded) |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
| Attributes | 0x1 |
|---|---|
| Name | VERSION.dll |
| ModuleHandle | 0x6ebec |
| DelayImportAddressTable | 0x6ea7c |
| DelayImportNameTable | 0x6bc78 |
| BoundDelayImportTable | 0x6bf0c |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 14.50.35719.0 |
| ProductVersion | 14.50.35719.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 |
| FileVersion (#2) | 14.50.35719.0 |
| InternalName | setup |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | VC_redist.x64.exe |
| ProductName | Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 |
| ProductVersion (#2) | 14.50.35719.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Mar-22 22:14:43 |
| Version | 0.0 |
| SizeofData | 72 |
| AddressOfRawData | 0x6b0dc |
| PointerToRawData | 0x6a0dc |
| Referenced File | C:\agent\_work\36\s\wix\build\ship\x86\burn.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Mar-22 22:14:43 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x6b124 |
| PointerToRawData | 0x6a124 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Mar-22 22:14:43 |
| Version | 0.0 |
| SizeofData | 1000 |
| AddressOfRawData | 0x6b138 |
| PointerToRawData | 0x6a138 |
| StartAddressOfRawData | 0x46b530 |
|---|---|
| EndAddressOfRawData | 0x46b538 |
| AddressOfIndex | 0x46ec0c |
| AddressOfCallbacks | 0x44e434 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0x800 |
| EditList | 0 |
| SecurityCookie | 0x46e008 |
| SEHandlerTable | 0x46b0b0 |
| SEHandlerCount | 11 |
| XOR Key | 0x1d0f3cfb |
|---|---|
| Unmarked objects | 0 |
| ASM objects (28900) | 10 |
| C++ objects (28900) | 145 |
| C objects (VS 2015/2017 runtime 26706) | 19 |
| ASM objects (VS 2015/2017 runtime 26706) | 19 |
| C++ objects (VS 2015/2017 runtime 26706) | 44 |
| C objects (28900) | 23 |
| C objects (CVTCIL) (28900) | 2 |
| Imports (28900) | 17 |
| Total imports | 334 |
| C++ objects (27051) | 75 |
| Resource objects (27051) | 1 |
| 151 | 2 |
| Linker (27051) | 1 |
No comments yet.