| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2016-May-09 14:01:29 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\wahiko\Desktop\GHost94_Plus\Release\hacker9.pdb
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/67 (Scanned on 2025-04-14 10:03:51) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2016-May-09 14:01:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x3b1a00 |
| SizeOfInitializedData | 0x2e0000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x002D46A4 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3b3000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb7f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6a0214 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GlobalUnlock
GlobalLock GlobalSize GlobalFree GlobalAlloc FileTimeToSystemTime FileTimeToLocalFileTime GetVersionExW GetSystemInfo OutputDebugStringW GlobalMemoryStatus HeapFree GetProcessHeap HeapAlloc GetVersionExA GetOEMCP GetCurrentDirectoryW SetCurrentDirectoryW CreateFileA ExitThread ResumeThread CreateThread SetThreadPriority SuspendThread GetCurrentThread InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection SetFilePointer LoadLibraryA VirtualFree VirtualQuery VirtualAlloc GetLastError GetTempFileNameW ReadFile GetExitCodeThread GetFileSize FindFirstFileW FindNextFileW FindClose lstrlenW WaitForMultipleObjects GetThreadPriority lstrcmpW lstrcpyW MulDiv lstrcpynW InterlockedIncrement InterlockedDecrement CreateSemaphoreA ReleaseSemaphore GetTempPathW WideCharToMultiByte GetTempFileNameA GetTempPathA GetSystemTimeAsFileTime DecodePointer EncodePointer GetCommandLineA HeapSetInformation GetStartupInfoW HeapReAlloc RtlUnwind GetModuleHandleW RaiseException TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent TlsAlloc TlsGetValue TlsSetValue TlsFree SetLastError IsProcessorFeaturePresent HeapCreate GetStdHandle GetModuleFileNameW SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType GetTimeZoneInformation MultiByteToWideChar GetConsoleCP GetConsoleMode GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW GetCurrentProcessId HeapSize GetCPInfo GetACP IsValidCodePage FlushFileBuffers LCMapStringW SetStdHandle WriteConsoleW GetStringTypeW CompareStringW SetEnvironmentVariableA SetEndOfFile DeleteFileW CreateFileW WriteFile LoadLibraryW GetProcAddress FreeLibrary SetEvent CreateEventA WaitForSingleObject ResetEvent CloseHandle ExitProcess GetCurrentThreadId Sleep GetLocalTime QueryPerformanceFrequency QueryPerformanceCounter GetTickCount |
|---|---|
| USER32.dll |
GetMenuItemInfoW
GetMenuItemCount PostMessageW ShowCursor MessageBoxW GetClientRect FillRect ChangeDisplaySettingsA SetWindowPos SetForegroundWindow AttachThreadInput GetWindowThreadProcessId GetForegroundWindow SetActiveWindow AdjustWindowRectEx SetWindowLongW ClientToScreen DrawMenuBar MoveWindow DefWindowProcW SetCursor PostQuitMessage EndPaint BeginPaint DestroyMenu BringWindowToTop RegisterClassExW LoadCursorW UnhookWindowsHookEx SetTimer KillTimer GetMonitorInfoW EnumDisplaySettingsW EnumDisplayMonitors GetKeyboardState GetDesktopWindow GetMonitorInfoA PostThreadMessageA GetQueueStatus RegisterWindowMessageA MsgWaitForMultipleObjects OpenClipboard IsClipboardFormatAvailable CloseClipboard GetClipboardData ShowWindow UpdateWindow SystemParametersInfoW LoadIconW SetClassLongW SetWindowTextW SetMenu GetWindowRect GetDC ReleaseDC UnregisterClassW FindWindowW DestroyWindow GetCursorPos ClipCursor PeekMessageW IsDialogMessageW TranslateAcceleratorW TranslateMessage DispatchMessageW MessageBoxA SendMessageW SetWindowRgn EmptyClipboard GetWindowLongW SetClipboardData |
| GDI32.dll |
GetObjectA
StretchDIBits SelectObject CreateDIBSection EnumFontFamiliesExW DeleteDC CreateCompatibleDC DeleteObject GetDeviceCaps CombineRgn CreateRectRgn GetStockObject CreateSolidBrush CreateDCW Rectangle GetGlyphOutlineW GetTextMetricsA CreateFontW SetBkMode SetBkColor SetTextColor GetCharacterPlacementW TextOutW GetTextExtentPoint32W SetDIBitsToDevice |
| SHELL32.dll |
DragQueryFileW
DragFinish DragAcceptFiles DragQueryFileA |
| Ordinal | 1 |
|---|---|
| Address | 0x3a1740 |
| Ordinal | 2 |
|---|---|
| Address | 0x3a1870 |
| Ordinal | 3 |
|---|---|
| Address | 0x3a0910 |
| Ordinal | 4 |
|---|---|
| Address | 0x3a18b0 |
| Ordinal | 5 |
|---|---|
| Address | 0x3a1a70 |
| Ordinal | 6 |
|---|---|
| Address | 0x3a1b70 |
| Ordinal | 7 |
|---|---|
| Address | 0x3a07a0 |
| Ordinal | 8 |
|---|---|
| Address | 0x3a07f0 |
| Ordinal | 9 |
|---|---|
| Address | 0x3aaba0 |
| Ordinal | 10 |
|---|---|
| Address | 0x39f8a0 |
| Ordinal | 11 |
|---|---|
| Address | 0x39fcd0 |
| Ordinal | 12 |
|---|---|
| Address | 0x39f7e0 |
| Ordinal | 13 |
|---|---|
| Address | 0x39fd70 |
| Ordinal | 14 |
|---|---|
| Address | 0x3a1a70 |
| Ordinal | 15 |
|---|---|
| Address | 0x39f670 |
| Ordinal | 16 |
|---|---|
| Address | 0x39f6d0 |
| Ordinal | 17 |
|---|---|
| Address | 0x3a1a80 |
| Ordinal | 18 |
|---|---|
| Address | 0x3a1ad0 |
| Ordinal | 19 |
|---|---|
| Address | 0x3a1ae0 |
| Ordinal | 20 |
|---|---|
| Address | 0x3a1b20 |
| Ordinal | 21 |
|---|---|
| Address | 0x3a0320 |
| Ordinal | 22 |
|---|---|
| Address | 0x3a0770 |
| Ordinal | 23 |
|---|---|
| Address | 0x39ffd0 |
| Ordinal | 24 |
|---|---|
| Address | 0x3aab80 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2016-May-09 14:01:29 |
| Version | 0.0 |
| SizeofData | 81 |
| AddressOfRawData | 0x44d96c |
| PointerToRawData | 0x44c76c |
| Referenced File | C:\Users\wahiko\Desktop\GHost94_Plus\Release\hacker9.pdb |
| XOR Key | 0xc665f9ab |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 2 |
| ASM objects (VS2010 SP1 build 40219) | 58 |
| C objects (VS2010 SP1 build 40219) | 169 |
| C++ objects (VS2010 SP1 build 40219) | 50 |
| C objects (VS98 SP6 build 8804) | 196 |
| C++ objects (VS98 SP6 build 8804) | 64 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 75 |
| Imports (VS2008 SP1 build 30729) | 9 |
| Total imports | 253 |
| C++ objects (VS2008 SP1 build 30729) | 87 |
| 175 (VS2010 SP1 build 40219) | 93 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.