| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found:
Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. Unusual section name found: Section is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource 101 detected as a PE Executable.
Resource 102 detected as a PE Executable. |
| Suspicious | The file contains overlay data. | 1 bytes of data starting at offset 0xd56000. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0 |
| e_cp | 0 |
| e_crlc | 0 |
| e_cparhdr | 0 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 0.0 |
| SizeOfCode | 0 |
| SizeOfInitializedData | 0x373400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000009E20D6 (Section: ) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 0.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd7a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x2000000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x4000000 |
| SizeofHeapCommit | 0x2800001000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ./.\kErnel32 |
AcquireSRWLockExclusive
AllocConsole CloseHandle CopyFileW CreateDirectoryA CreateDirectoryW CreateEventA CreateFileA CreateFileMappingA CreateFileW CreateHardLinkW CreateMutexA CreateProcessA CreateSymbolicLinkW CreateThread DeleteCriticalSection DeleteFileW DeviceIoControl EnterCriticalSection ExitProcess FillConsoleOutputAttribute FillConsoleOutputCharacterA FindClose FindFirstFileExW FindFirstFileW FindNextFileW FindResourceW FlushConsoleInputBuffer FormatMessageA FormatMessageW FreeLibrary GetConsoleMode GetConsoleScreenBufferInfo GetConsoleWindow GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetEnvironmentVariableA GetExitCodeProcess GetFileAttributesExW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFullPathNameW GetLastError GetLocaleInfoA GetLocaleInfoEx GetModuleHandleA GetModuleHandleW GetProcAddress GetStartupInfoW GetStdHandle GetSystemDirectoryA GetSystemDirectoryW GetSystemTimeAsFileTime GetTickCount GetTickCount64 GlobalAlloc GlobalFree GlobalLock GlobalUnlock InitializeCriticalSectionEx InitializeSListHead IsDebuggerPresent IsProcessorFeaturePresent K32GetModuleInformation LeaveCriticalSection LoadLibraryA LoadLibraryExA LoadResource LocalFree LockResource MapViewOfFile MoveFileExW MultiByteToWideChar OpenProcess OutputDebugStringA PeekNamedPipe QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleInputW ReadFile ReleaseMutex ReleaseSRWLockExclusive RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetConsoleCtrlHandler SetConsoleCursorPosition SetConsoleMode SetConsoleScreenBufferSize SetConsoleTextAttribute SetConsoleTitleA SetConsoleWindowInfo SetEvent SetFileInformationByHandle SetLastError SetUnhandledExceptionFilter SizeofResource Sleep SleepConditionVariableSRW SleepEx TerminateProcess UnhandledExceptionFilter VerSetConditionMask VerifyVersionInfoW VirtualAlloc VirtualFree VirtualProtect WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WakeAllConditionVariable WideCharToMultiByte WinExec WriteConsoleW WriteFile |
|---|---|
| .\USeR32 |
ClientToScreen
CloseClipboard DestroyWindow DispatchMessageA DrawMenuBar EmptyClipboard EnumChildWindows EnumWindows FindWindowA FindWindowExA FindWindowW GetAsyncKeyState GetCapture GetClassNameA GetClientRect GetClipboardData GetCursorPos GetDC GetDesktopWindow GetForegroundWindow GetKeyState GetKeyboardLayout GetMessageExtraInfo GetSystemMenu GetWindowLongA GetWindowRect GetWindowTextA GetWindowThreadProcessId IsWindow IsWindowUnicode LoadCursorA MessageBoxA MonitorFromWindow OpenClipboard PeekMessageA PostMessageA PostQuitMessage ReleaseCapture ReleaseDC ScreenToClient SetCapture SetClipboardData SetCursor SetCursorPos SetLayeredWindowAttributes SetProcessDPIAware SetWindowLongA SetWindowPos SetWindowTextA SetWindowTextW ShowWindow TrackMouseEvent TranslateMessage UpdateWindow |
| ./.\ShEll32 |
SHGetFolderPathA
ShellExecuteA ShellExecuteW |
| .\oleauT32 |
#2
#6 |
| .\.\GdI32 |
CreateRectRgn
DeleteObject GetDeviceCaps |
| .\.\d3D11 |
D3D11CreateDeviceAndSwapChain
|
| ./.\ntDll |
NtClose
NtCreateFile NtCreateSection NtDeviceIoControlFile NtLoadDriver NtMapViewOfSection NtQuerySystemInformation NtReadFile NtUnloadDriver RtlAdjustPrivilege RtlAllocateHeap RtlCreateRegistryKey RtlDosPathNameToRelativeNtPathName_U_WithStatus RtlFreeHeap RtlGetFullPathName_UEx RtlImageNtHeaderEx RtlInitUnicodeString RtlReleaseRelativeName RtlWriteRegistryValue __C_specific_handler __chkstk _setjmp _stricmp _vsnwprintf _wcsicmp cos log longjmp memchr memcmp memcpy memmove memset pow qsort sin strcat_s strchr strcmp strcspn strlen strncmp strncpy strpbrk strrchr strspn strstr strtol tan toupper wcscat_s wcschr wcscpy_s wcslen wcsncmp wcsncpy_s |
| ./MSVCP140 |
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0_Lockit@std@@QEAA@H@Z ??0ios_base@std@@IEAA@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1_Lockit@std@@QEAA@XZ ??1ios_base@std@@UEAA@XZ ??4?$_Yarn@_W@std@@QEAAAEAV01@PEB_W@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Id_cnt@id@locale@std@@0HA ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?_Syserror_map@std@@YAPEBDH@Z ?_Throw_Cpp_error@std@@YAXH@Z ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Winerror_map@std@@YAHH@Z ?_Xbad_alloc@std@@YAXXZ ?_Xbad_function_call@std@@YAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?clear@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?eof@ios_base@std@@QEBA_NXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?good@ios_base@std@@QEBA_NXZ ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?id@?$ctype@D@std@@2V0locale@2@A ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?init@?$basic_ios@DU?$char_traits@D@std@@@std@@IEAAXPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@_N@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?uncaught_exceptions@std@@YAHXZ ?wcerr@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z _Cnd_do_broadcast_at_thread_exit _Mtx_lock _Mtx_unlock _Query_perf_counter _Query_perf_frequency _Thrd_detach _Thrd_id _Thrd_join _Xtime_get_ticks |
| .\iMM32 |
ImmGetContext
ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionWindow |
| .\D3dcOMpiler_43 |
D3DCompile
|
| .\.\dwMapi |
DwmEnableBlurBehindWindow
DwmExtendFrameIntoClientArea DwmGetColorizationColor DwmIsCompositionEnabled |
| ././Ws2_32 |
#116
WSACloseEvent WSACreateEvent WSAEnumNetworkEvents WSAEventSelect #111 WSAIoctl WSAResetEvent #112 #115 WSAWaitForMultipleEvents #151 #1 #2 #3 #4 freeaddrinfo getaddrinfo #57 #5 #6 #7 #8 #9 #10 #13 #15 #16 #17 #18 #19 #20 #21 #23 |
| .\.\IPhLpAPI |
if_nametoindex
|
| .\./AdVapI32 |
CryptAcquireContextW
CryptCreateHash CryptDestroyHash CryptDestroyKey CryptEncrypt CryptGetHashParam CryptHashData CryptImportKey CryptReleaseContext |
| .\CRypt32 |
CertAddCertificateContextToStore
CertCloseStore CertCreateCertificateChainEngine CertEnumCertificatesInStore CertFindCertificateInStore CertFindExtension CertFreeCRLContext CertFreeCTLContext CertFreeCertificateChain CertFreeCertificateChainEngine CertFreeCertificateContext CertGetCertificateChain CertGetNameStringW CertOpenStore CryptDecodeObjectEx CryptQueryObject CryptStringToBinaryW PFXImportCertStore |
| ./.\secur32 |
InitSecurityInterfaceW
|
| .\.\bCRyPt |
BCryptGenRandom
|
| ./VCRUNtimE140 |
_CxxThrowException
__CxxFrameHandler3 __current_exception __current_exception_context __std_exception_copy __std_exception_destroy __std_terminate |
| ./vcruNTime140_1 |
__CxxFrameHandler4
|
| aPI-mS-win-crT-TiME-l1-1-0 |
_W_Getdays
_W_Getmonths _gmtime64_s _localtime64 _time64 strftime |
| API-ms-win-crT-sTDiO-L1-1-0 |
__acrt_iob_func
__p__commode __stdio_common_vfprintf __stdio_common_vsprintf __stdio_common_vsprintf_s __stdio_common_vsscanf _close _fseeki64 _get_stream_buffer_pointers _lseeki64 _read _set_fmode _wfopen _wfsopen _write _wsopen_s fclose feof fflush fgetc fgetpos fgets fopen fputc fputs fread freopen freopen_s fseek fsetpos ftell fwrite getchar setvbuf ungetc |
| api-Ms-win-CRt-ruNtiME-L1-1-0 |
_beginthreadex
_c_exit _cexit _configure_narrow_argv _crt_atexit _errno _exit _get_narrow_winmain_command_line _initialize_narrow_environment _initialize_onexit_table _initterm _initterm_e _invoke_watson _register_onexit_function _register_thread_local_exe_atexit_callback _seh_filter_exe _set_app_type abort exit strerror_s system terminate |
| aPI-Ms-WIN-CRt-MATh-l1-1-0 |
__setusermatherr
_fdopen acosf atan2f cosf expf fmodf logf powf sinf sqrtf |
| aPI-mS-win-CRt-ConVeRT-l1-1-0 |
atof
strtod strtoll strtoull wcstombs_s |
| aPI-MS-WIn-CRt-Heap-l1-1-0 |
_callnewh
_set_new_mode calloc free malloc realloc |
| aPi-Ms-WIn-Crt-lOCALe-L1-1-0 |
_configthreadlocale
localeconv |
| api-mS-win-cRt-FIlESYStEM-l1-1-0 |
_fstat64
_fullpath _lock_file _unlink _unlock_file _wstat64 |
| APi-MS-win-Crt-string-L1-1-0 |
_strdup
|
| ApI-Ms-Win-crT-UtiLITY-L1-1-0 |
rand
|
| StartAddressOfRawData | 0x140d62000 |
|---|---|
| EndAddressOfRawData | 0x140d62008 |
| AddressOfIndex | 0x140d43d90 |
| AddressOfCallbacks | 0x140a4cb18 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0 |
No comments yet.