Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Mar-18 02:34:22 |
Detected languages |
English - United States
|
Debug artifacts |
d:\dbs\el\jan\Target\x64\ship\postc2r\x-none\winword.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Word |
FileVersion | 16.0.13801.20360 |
InternalName | WinWord |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | WinWord.exe |
ProductName | Microsoft Office |
ProductVersion | 16.0.13801.20360 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .didat
Unusual section name found: .c2r |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. | Resources amount for 96.8216% of the executable. |
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010 |
Safe | VirusTotal score: 0/68 (Scanned on 2021-03-24 08:06:01) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2021-Mar-18 02:34:22 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x3c00 |
SizeOfInitializedData | 0x1d7c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000001680 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | A.0 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x1e2000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1ea38c |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
AppVIsvSubsystems64.dll |
#1
|
---|---|
ADVAPI32.dll |
RegQueryValueExW
RegOpenKeyExW RegSetValueExW RegCloseKey RegGetValueW |
KERNEL32.dll |
RtlLookupFunctionEntry
CreateMutexW WaitForSingleObject GetCurrentThreadId ReleaseMutex SuspendThread ResumeThread CreateEventW CloseHandle CreateThread GetThreadContext OpenThread GetSystemDirectoryW GetLastError GetProcAddress GetModuleHandleW FreeLibrary LoadLibraryExW GetCurrentProcessId GetFileAttributesW GetModuleHandleExW RtlCaptureContext UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess RtlVirtualUnwind LoadLibraryExA VirtualQuery GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RaiseException GetSystemInfo VirtualProtect IsProcessorFeaturePresent QueryPerformanceCounter |
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
__current_exception_context
memmove __current_exception __C_specific_handler wcsrchr __std_exception_copy __std_exception_destroy _CxxThrowException memset |
MSVCP140.dll |
_Query_perf_counter
_Query_perf_frequency ?_Xlength_error@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ |
api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsnwprintf_s
_set_fmode __stdio_common_vswprintf_s __p__commode |
api-ms-win-crt-time-l1-1-0.dll |
_time64
|
api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _set_new_mode |
api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
_initialize_onexit_table terminate _register_thread_local_exe_atexit_callback _invalid_parameter_noinfo_noreturn _c_exit _cexit _exit exit _initterm_e _initterm _get_narrow_winmain_command_line _initialize_narrow_environment _configure_narrow_argv _register_onexit_function _set_app_type _seh_filter_exe |
api-ms-win-crt-string-l1-1-0.dll |
_stricmp
wcsncpy_s wcsncat_s |
api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
api-ms-win-crt-locale-l1-1-0.dll |
__initialize_lconv_for_unsigned_char
_configthreadlocale |
Mso20Win32Client.dll (delay-loaded) |
#1110
|
Attributes | 0x1 |
---|---|
Name | Mso20Win32Client.dll |
ModuleHandle | 0x8328 |
DelayImportAddressTable | 0xa000 |
DelayImportNameTable | 0x6218 |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x6191 |
ForwardName | MSO.DllGetLCID |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 16.0.13801.20360 |
ProductVersion | 16.0.13801.20360 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Word |
FileVersion (#2) | 16.0.13801.20360 |
InternalName | WinWord |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | WinWord.exe |
ProductName | Microsoft Office |
ProductVersion (#2) | 16.0.13801.20360 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Mar-18 02:34:22 |
Version | 0.0 |
SizeofData | 280 |
AddressOfRawData | 0x6f00 |
PointerToRawData | 0x5f00 |
Referenced File | d:\dbs\el\jan\Target\x64\ship\postc2r\x-none\winword.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Mar-18 02:34:22 |
Version | 576.29714 |
SizeofData | 4 |
AddressOfRawData | 0x7018 |
PointerToRawData | 0x6018 |
Size | 0x130 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140008010 |
GuardCFCheckFunctionPointer | 5368731152 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x9f065f4d |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 16 |
Imports (VS2019 Update 7 (16.7.1) compiler 29111) | 6 |
C++ objects (VS2019 Update 7 (16.7.1) compiler 29111) | 27 |
C objects (VS2019 Update 7 (16.7.1) compiler 29111) | 10 |
ASM objects (VS2019 Update 7 (16.7.1) compiler 29111) | 3 |
Imports (27412) | 5 |
Total imports | 110 |
C++ objects (29114) | 1 |
270 (29114) | 5 |
Exports (29114) | 1 |
Resource objects (29114) | 1 |
151 | 2 |
Linker (29114) | 1 |