| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-10 11:13:41 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Volxp\source\repos\static-injector\x64\Release\static-injector.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 3/71 (Scanned on 2026-05-14 19:32:28) |
Bkav:
W32.Malware.8AD1988E
CrowdStrike: win/malicious_confidence_70% (D) Symantec: ML.Attribute.HighConfidence |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-10 11:13:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd400 |
| SizeOfInitializedData | 0x8000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000CE94 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x19000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
OpenProcess
CreateToolhelp32Snapshot Process32Next CloseHandle VirtualAllocEx CreateProcessA WideCharToMultiByte QueryFullProcessImageNameW ReadProcessMemory VirtualQueryEx MultiByteToWideChar LocalFree VirtualQuery WriteProcessMemory GetCurrentProcess WaitForSingleObject GetModuleHandleA GetLastError K32GetModuleInformation GetProcAddress K32EnumProcessModulesEx K32GetModuleBaseNameA K32EnumProcesses K32EnumProcessModules GetCurrentDirectoryW InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId TerminateProcess Process32First DuplicateHandle Sleep CreateDirectoryW CreateFileW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW GetFileInformationByHandle SetFileInformationByHandle AreFileApisANSI DeviceIoControl GetModuleHandleW CopyFileW GetFileInformationByHandleEx CreateSymbolicLinkW FormatMessageA GetLocaleInfoEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent QueryPerformanceCounter |
|---|---|
| USER32.dll |
MessageBoxA
GetWindowThreadProcessId FindWindowA |
| MSVCP140.dll |
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ?good@ios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Winerror_map@std@@YAHH@Z ?_Syserror_map@std@@YAPEBDH@Z ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Xlength_error@std@@YAXPEBD@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xout_of_range@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xbad_alloc@std@@YAXXZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exceptions@std@@YAHXZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_terminate
memcmp __current_exception __std_exception_destroy __C_specific_handler _CxxThrowException memset memmove __std_exception_copy __current_exception_context memcpy |
| api-ms-win-crt-stdio-l1-1-0.dll |
fputc
fclose fgetc fwrite fgetpos setvbuf ungetc fsetpos fread _get_stream_buffer_pointers __acrt_iob_func __stdio_common_vfprintf getchar fflush __p__commode _set_fmode _fseeki64 |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode malloc free |
| api-ms-win-crt-runtime-l1-1-0.dll |
_set_app_type
_seh_filter_exe _register_thread_local_exe_atexit_callback _c_exit abort __p___argv terminate exit __p___argc _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _exit _initterm_e _initterm _get_initial_narrow_environment _cexit _invoke_watson |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
|
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
_configthreadlocale |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-10 11:13:41 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0x112e4 |
| PointerToRawData | 0xfae4 |
| Referenced File | C:\Users\Volxp\source\repos\static-injector\x64\Release\static-injector.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-10 11:13:41 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x11348 |
| PointerToRawData | 0xfb48 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-10 11:13:41 |
| Version | 0.0 |
| SizeofData | 800 |
| AddressOfRawData | 0x1135c |
| PointerToRawData | 0xfb5c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-10 11:13:41 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140015040 |
| XOR Key | 0x70b5210b |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 33 |
| Imports (35207) | 6 |
| Imports (33145) | 7 |
| Total imports | 240 |
| ASM objects (35222) | 1 |
| C++ objects (LTCG) (35226) | 7 |
| Resource objects (35226) | 1 |
| Linker (35226) | 1 |
No comments yet.