| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jan-20 13:12:03 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
Monochrome.pdb
|
| CompanyName | samidy |
| FileDescription | Monochrome |
| FileVersion | 0.1.0 |
| ProductName | Monochrome |
| ProductVersion | 0.1.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-06 09:12:04) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jan-20 13:12:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8bc400 |
| SizeOfInitializedData | 0x400000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000894DD0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xcc2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| advapi32.dll |
RegQueryValueExW
EventSetInformation RegCloseKey EventUnregister EventWriteTransfer RegOpenKeyExW EventRegister RegGetValueW |
| ntdll.dll |
RtlNtStatusToDosError
NtOpenFile NtWriteFile NtReadFile NtCreateNamedPipeFile RtlGetVersion |
| kernel32.dll |
RaiseException
RtlPcToFileHeader FlsAlloc GetUserDefaultUILanguage FlsGetValue FlsSetValue FindNextFileW RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext TerminateProcess GetProcessId GetExitCodeProcess GetSystemInfo QueryPerformanceCounter GetSystemTimePreciseAsFileTime WriteFileEx CreateProcessW GetWindowsDirectoryW GetSystemTimeAsFileTime SleepConditionVariableSRW WakeAllConditionVariable GetSystemDirectoryW CompareStringOrdinal FreeEnvironmentStringsW CreateThread SetWaitableTimer CreateWaitableTimerExW GetConsoleOutputCP GetStdHandle LoadLibraryW MultiByteToWideChar CancelIo QueryPerformanceFrequency ReadFile SleepEx ReadFileEx WaitForMultipleObjects ExitProcess GetTempPathW GetFullPathNameW LoadLibraryA FindClose FindFirstFileExW GetFinalPathNameByHandleW GetOverlappedResult CreateEventW SwitchToThread GetFileInformationByHandleEx CreateDirectoryW GetCommandLineW GetEnvironmentStringsW GetCurrentDirectoryW SetLastError GetCurrentThread SetThreadStackGuarantee AddVectoredExceptionHandler lstrlenW AcquireSRWLockExclusive OutputDebugStringA OutputDebugStringW GetModuleFileNameW GetProcessHeap HeapFree LoadLibraryExW FreeLibrary DuplicateHandle FlsFree ReleaseSRWLockExclusive LCIDToLocaleName SetFileInformationByHandle CreateMutexA GetCurrentProcessId WaitForSingleObjectEx WideCharToMultiByte GetCurrentProcess HeapReAlloc GetEnvironmentVariableW EncodePointer GetModuleHandleW InitializeSListHead SetUnhandledExceptionFilter ReleaseMutex RtlUnwindEx CreateMutexW GetModuleHandleA Sleep WaitForSingleObject GetProcAddress GetLastError SetEnvironmentVariableW CloseHandle InitializeCriticalSectionEx LoadLibraryExA HeapAlloc GetConsoleMode GetFileInformationByHandle FormatMessageW WriteConsoleW GetCurrentThreadId CreatePipe GetFileAttributesW CreateFileW DeleteCriticalSection |
| user32.dll |
PostMessageW
CreateMenu SetMenu DrawMenuBar SetMenuItemInfoW AppendMenuW InsertMenuW PostQuitMessage CreateAcceleratorTableW SendMessageW DestroyAcceleratorTable GetMenuItemInfoW SetTimer TrackPopupMenu KillTimer ChangeWindowMessageFilterEx DestroyWindow CreateIcon ToUnicodeEx GetKeyState FindWindowW RegisterClassExW CreateWindowExW DefWindowProcW ScreenToClient GetWindowLongW GetClientRect ClientToScreen MonitorFromRect GetKeyboardState MapVirtualKeyExW SetWindowLongW EnableMenuItem GetSystemMenu SystemParametersInfoA SetPropW GetKeyboardLayout GetMenu FillRect ShowCursor SystemParametersInfoW TrackMouseEvent ClipCursor GetClipCursor IsWindowVisible DestroyIcon RedrawWindow EnumDisplayMonitors MonitorFromPoint SetWindowTextW GetWindowTextW GetWindowTextLengthW SetWindowDisplayAffinity SendInput SetForegroundWindow GetTouchInputInfo RegisterRawInputDevices ReleaseCapture SetCapture MsgWaitForMultipleObjectsEx CloseTouchInputHandle GetSystemMetrics RegisterWindowMessageA SetParent MapWindowPoints SetCursor GetCursorPos MonitorFromWindow GetWindow SetFocus ShowWindow ReleaseDC EnableWindow IsWindowEnabled GetWindowRect GetRawInputData FindWindowExW SetWindowRgn CreatePopupMenu IsProcessDPIAware GetDC RemoveMenu CheckMenuItem RegisterHotKey RegisterClassW GetAsyncKeyState UnregisterHotKey DrawIconEx DestroyMenu GetMenuBarInfo OffsetRect SetWindowLongPtrW GetWindowLongPtrW GetParent GetForegroundWindow GetWindowDC DrawTextW RegisterTouchWindow IsWindow AdjustWindowRectEx FlashWindowEx GetActiveWindow UpdateWindow InvalidateRect SetCursorPos GetMonitorInfoW InvalidateRgn GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW GetMessageW MapVirtualKeyW IsIconic EnumChildWindows DispatchMessageA GetMessageA ValidateRect AdjustWindowRect TranslateAcceleratorW SetWindowPos LoadCursorW DispatchMessageW TranslateMessage GetUpdateRect PeekMessageW PostThreadMessageW |
| shell32.dll |
DragQueryFileW
DragFinish SHAppBarMessage Shell_NotifyIconW SHCreateItemFromParsingName ShellExecuteW Shell_NotifyIconGetRect SHGetKnownFolderPath |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WakeByAddressAll WaitOnAddress |
| ole32.dll |
RevokeDragDrop
CoCreateFreeThreadedMarshaler CoCreateInstance OleInitialize RegisterDragDrop CoInitialize CoTaskMemFree CoUninitialize CoTaskMemAlloc CoIncrementMTAUsage CoInitializeEx |
| comctl32.dll |
TaskDialogIndirect
SetWindowSubclass DefSubclassProc RemoveWindowSubclass |
| gdi32.dll |
SetBkMode
SetTextColor BitBlt SelectObject DeleteObject GetDeviceCaps DeleteDC CombineRgn CreateSolidBrush CreateCompatibleDC CreateRectRgn CreateDIBSection |
| dwmapi.dll |
DwmGetWindowAttribute
DwmEnableBlurBehindWindow DwmSetWindowAttribute |
| shlwapi.dll |
SHCreateMemStream
|
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| oleaut32.dll |
SysFreeString
GetErrorInfo SysStringLen SetErrorInfo |
| SHELL32.dll |
#155
SHOpenFolderAndSelectItems #190 ShellExecuteExW |
| api-ms-win-crt-math-l1-1-0.dll |
pow
__setusermatherr trunc floor fmod round roundf |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
strlen _wcsicmp wcscmp strcpy_s |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
_ultow_s wcstol |
| api-ms-win-crt-runtime-l1-1-0.dll |
_seh_filter_exe
abort terminate _crt_atexit _set_app_type _configure_narrow_argv _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _get_initial_narrow_environment _initterm _register_thread_local_exe_atexit_callback _c_exit _cexit __p___argv _initterm_e exit _exit __p___argc |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
calloc
_set_new_mode malloc _callnewh free |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | samidy |
| FileDescription | Monochrome |
| FileVersion (#2) | 0.1.0 |
| ProductName | Monochrome |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-20 13:12:03 |
| Version | 0.0 |
| SizeofData | 39 |
| AddressOfRawData | 0xa4654c |
| PointerToRawData | 0xa44d4c |
| Referenced File | Monochrome.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-20 13:12:03 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xa46574 |
| PointerToRawData | 0xa44d74 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-20 13:12:03 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0xa46588 |
| PointerToRawData | 0xa44d88 |
| StartAddressOfRawData | 0x140a46a00 |
|---|---|
| EndAddressOfRawData | 0x140a46bbc |
| AddressOfIndex | 0x140c39f80 |
| AddressOfCallbacks | 0x1408bebc8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001408605A0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140c37940 |
| XOR Key | 0x6d528498 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35403) | 9 |
| C objects (35403) | 13 |
| C++ objects (35403) | 46 |
| Imports (33145) | 3 |
| Total imports | 445 |
| Unmarked objects (#2) | 621 |
| Resource objects (35722) | 1 |
| Linker (35722) | 1 |