| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Aug-18 13:13:52 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\Work\Workspace\Win32\build\x64-Release\HopmonClient.pdb
|
| FileVersion | 24.07.07 |
| LegalCopyright | Copyright (C) 2021 - 2022 |
| ProductVersion | 24.07.07 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-Aug-18 13:13:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x391800 |
| SizeOfInitializedData | 0x400600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000352068 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x796000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
ConnectNamedPipe
CreateNamedPipeW WaitNamedPipeW GetConsoleWindow CreateMutexW OpenMutexW SetEvent ResetEvent WaitForSingleObjectEx CreateEventW WaitForMultipleObjects GlobalSize GlobalLock GlobalUnlock GetSystemTimeAsFileTime SystemTimeToTzSpecificLocalTime GetTimeZoneInformation SystemTimeToFileTime FileTimeToSystemTime LoadLibraryW FreeLibrary GetProcAddress GlobalAlloc TzSpecificLocalTimeToSystemTime GetStdHandle OutputDebugStringW LocalAlloc CreateThread SetThreadPriority GetExitCodeThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetOverlappedResult CreateIoCompletionPort GetQueuedCompletionStatus PostQueuedCompletionStatus CancelIo MultiByteToWideChar WideCharToMultiByte ExitProcess VirtualAllocEx VirtualFreeEx CreateRemoteThread WriteProcessMemory WriteConsoleW GetProcessHeap SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetCPInfo GetOEMCP IsValidCodePage FindNextFileA FindFirstFileExA SetStdHandle GetStringTypeW LCMapStringW CompareStringW HeapReAlloc HeapAlloc GetFileAttributesExW CreateProcessA HeapFree GetConsoleCP ReadConsoleW GetACP GetModuleFileNameA GetFileType SetConsoleMode ReadConsoleInputA PeekConsoleInputA GetNumberOfConsoleInputEvents GetConsoleMode GetModuleHandleExW SetConsoleCtrlHandler LoadLibraryExW EncodePointer RaiseException RtlPcToFileHeader RtlUnwindEx InitializeSListHead GetStartupInfoW IsDebuggerPresent InitializeCriticalSectionAndSpinCount IsProcessorFeaturePresent UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext FindFirstFileW DeleteFileW SetFileAttributesW RemoveDirectoryW CreateDirectoryW SetFileTime GetFileTime FindClose SetFilePointerEx FlushFileBuffers ReadFile WriteFile GetFileSizeEx Thread32Next Thread32First Process32NextW Process32FirstW CreateToolhelp32Snapshot CreateProcessW CreatePipe SetHandleInformation WaitForSingleObject GetExitCodeProcess TerminateProcess GetCurrentProcessId OpenProcess GetUserDefaultLCID GetLocaleInfoA LocalFree CreateFileW CloseHandle DeviceIoControl GetProcessAffinityMask GlobalMemoryStatusEx DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection GetFileAttributesW EnumResourceNamesW GetCommandLineW GetCurrentThreadId QueryPerformanceFrequency QueryPerformanceCounter FindNextFileW GetSystemWow64DirectoryW GetTempPathW GetSystemDirectoryW GetModuleHandleW GetModuleFileNameW GetTickCount WinExec Sleep SetLastError GetLastError SwitchToThread SetUnhandledExceptionFilter GetCurrentProcess HeapSize |
|---|---|
| USER32.dll |
TrackPopupMenuEx
RemoveMenu DestroyMenu CreatePopupMenu CreateMenu DestroyCursor SetCursor SetMenuInfo SetParent GetSysColor ScreenToClient ClientToScreen GetWindowRect GetClientRect RedrawWindow InvalidateRect InsertMenuItemW SetMenuItemInfoW OpenClipboard CloseClipboard SetClipboardData EmptyClipboard OpenInputDesktop SetThreadDesktop PtInRect SetWindowLongPtrW LoadIconA MonitorFromWindow CreateIconIndirect EnumWindows FindWindowExW PostMessageW GetWindowThreadProcessId RegisterWindowMessageW CloseDesktop TranslateMessage DispatchMessageW GetMessageExtraInfo SendMessageW SendMessageTimeoutW GetParent EnumChildWindows GetClassNameW GetThreadDesktop DefWindowProcW PostQuitMessage RegisterClassW RegisterClassExW EndPaint BeginPaint IsWindowEnabled EnableWindow CreateWindowExW IsWindow DestroyWindow SetLayeredWindowAttributes SetWindowPos IsIconic SetFocus ReleaseCapture GetSystemMetrics GetForegroundWindow GetDC ReleaseDC SetWindowTextW GetWindowLongW SetWindowLongW FindWindowW GetWindow LoadCursorW LoadIconW DestroyIcon SetScrollInfo GetScrollInfo SystemParametersInfoW GetMonitorInfoW EnumDisplayMonitors GetAncestor SetDlgItemTextW GetActiveWindow MessageBoxW PostThreadMessageW GetMessageTime GetUserObjectInformationW IsZoomed GetMenu SetMenu SetWindowRgn GetMessageW AdjustWindowRectEx SetCapture GetCapture GetFocus BringWindowToTop ShowWindowAsync UpdateLayeredWindow GetMessagePos GetKeyState SetForegroundWindow GetDesktopWindow GetCursorPos EnumDisplaySettingsW MapVirtualKeyW TrackMouseEvent |
| GDI32.dll |
DeleteDC
DeleteObject GetDeviceCaps SelectObject CreateDCW SetStretchBltMode SetBrushOrgEx CreateDIBSection CreateSolidBrush SetBkColor SetBkMode SetTextColor CreateCompatibleDC CreateCompatibleBitmap BitBlt CreateRoundRectRgn CreateBitmap CreateFontW EnumFontFamiliesExW StretchBlt CreateEllipticRgn |
| COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW |
| ADVAPI32.dll |
InitializeSecurityDescriptor
StartServiceCtrlDispatcherW SetServiceStatus RegisterServiceCtrlHandlerW RegQueryValueExW RegEnumKeyW RegCreateKeyExW RegSetValueExW RegOpenKeyExW RegEnumValueW RegDeleteValueW RegCloseKey StartServiceW QueryServiceStatusEx QueryServiceConfigW OpenServiceW OpenSCManagerW DeleteService CreateServiceW ControlService CloseServiceHandle ChangeServiceConfig2W ChangeServiceConfigW SetSecurityDescriptorDacl ImpersonateNamedPipeClient GetUserNameW CryptAcquireContextW CryptReleaseContext CryptGenRandom OpenProcessToken AllocateAndInitializeSid FreeSid CreateProcessAsUserW CheckTokenMembership |
| SHELL32.dll |
SHOpenFolderAndSelectItems
#190 #155 ShellExecuteExW DragQueryFileW Shell_NotifyIconW SHBrowseForFolderW SHGetPathFromIDListW SHGetMalloc SHGetFolderPathW |
| ole32.dll |
CoUninitialize
OleDuplicateData CoSetProxyBlanket CoInitializeSecurity StringFromGUID2 ReleaseStgMedium CoCreateInstance RevokeDragDrop RegisterDragDrop CoInitializeEx OleInitialize DoDragDrop |
| OLEAUT32.dll |
VariantClear
SysAllocString VarBstrFromDec SysFreeString |
| VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW VerQueryValueW |
| COMCTL32.dll |
#413
InitCommonControlsEx #410 |
| WS2_32.dll |
ntohs
WSAStartup |
| DSOUND.dll |
#8
#12 |
| IMM32.dll |
ImmAssociateContext
|
| gdiplus.dll |
GdipSetTextRenderingHint
GdipSetInterpolationMode GdipSetWorldTransform GdipTranslateWorldTransform GdipGetWorldTransform GdipDrawLine GdipDrawLines GdipDrawArc GdipDrawRectangle GdipDrawEllipse GdipDrawPie GdipDrawPolygon GdipDrawPath GdipFillRectangle GdipFillPolygon GdipFillEllipse GdipFillPie GdipFillPath GdipDrawImageRectRect GdipSetClipRect GdipSetClipPath GdipGetClipBounds GdipSaveGraphics GdipRestoreGraphics GdipDeleteFontFamily GdipGetFamily GdipGetFontStyle GdipGetFontSize GdipDrawString GdipStringFormatGetGenericTypographic GdipCreateFontFamilyFromName GdipGetGenericFontFamilySansSerif GdipGetEmHeight GdipGetCellAscent GdipGetCellDescent GdipCreateBitmapFromScan0 GdipSetSmoothingMode GdipDeleteFont GdipMeasureString GdipAddPathEllipse GdipCreateTexture GdipCreateLineBrush GdipSetLinePresetBlend GdipSetLineWrapMode GdipCreatePathGradientFromPath GdipSetPathGradientCenterColor GdipSetPathGradientSurroundColorsWithCount GdipSetPathGradientCenterPoint GdipGetPathGradientPointCount GdipSetPathGradientPresetBlend GdipSetPenMiterLimit GdipSetPenDashStyle GdipSetPathFillMode GdipStartPathFigure GdipClosePathFigure GdipAddPathLine GdipAddPathBezier GdipGetImageWidth GdipGetImageGraphicsContext GdipDisposeImage GdipCloneImage GdipGraphicsClear GdipDeleteGraphics GdipCreateFromHDC GdipFree GdipAlloc GdipGetSmoothingMode GdipSetImageAttributesColorMatrix GdipDisposeImageAttributes GdipCreateImageAttributes GdipGetPenFillType GdipGetPenColor GdipSetPenColor GdipSetPenLineJoin GdipSetPenLineCap197819 GdipDeletePen GdipClonePen GdipCreatePen1 GdipGetSolidFillColor GdipSetSolidFillColor GdipCreateSolidFill GdipGetBrushType GdipDeleteBrush GdipCloneBrush GdipGetMatrixElements GdipDeleteMatrix GdipCreateMatrix2 GdipCreateMatrix GdipWidenPath GdipAddPathString GdipDeletePath GdipGetImageHeight GdipCreatePath GdiplusStartup GdipBitmapUnlockBits GdipBitmapLockBits GdipCreateFont GdipCreateBitmapFromHBITMAP GdipGetLineSpacing GdipClonePath |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 24.7.7.0 |
| ProductVersion | 24.7.7.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 24.07.07 |
| LegalCopyright | Copyright (C) 2021 - 2022 |
| ProductVersion (#2) | 24.07.07 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Aug-18 13:13:52 |
| Version | 0.0 |
| SizeofData | 83 |
| AddressOfRawData | 0x42203c |
| PointerToRawData | 0x420c3c |
| Referenced File | D:\Work\Workspace\Win32\build\x64-Release\HopmonClient.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Aug-18 13:13:52 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x422090 |
| PointerToRawData | 0x420c90 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Aug-18 13:13:52 |
| Version | 0.0 |
| SizeofData | 908 |
| AddressOfRawData | 0x4220a4 |
| PointerToRawData | 0x420ca4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Aug-18 13:13:52 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140422450 |
|---|---|
| EndAddressOfRawData | 0x140422458 |
| AddressOfIndex | 0x14057ff10 |
| AddressOfCallbacks | 0x140394540 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x100 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140511830 |
| XOR Key | 0x30d8ef20 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 33 |
| 243 (40116) | 168 |
| 242 (40116) | 59 |
| 199 (41118) | 5 |
| ASM objects (VS2017 v15.6.6 compiler 26131) | 11 |
| C objects (VS2017 v15.6.6 compiler 26131) | 21 |
| C++ objects (VS2017 v15.6.6 compiler 26131) | 48 |
| C objects (VS2008 SP1 build 30729) | 2 |
| Imports (VS2008 SP1 build 30729) | 31 |
| Total imports | 566 |
| C++ objects (VS2017 v15.7.5 compiler 26433) | 245 |
| C objects (VS2017 v15.7.5 compiler 26433) | 136 |
| C++ objects (LTCG) (VS2017 v15.7.5 compiler 26433) | 38 |
| Resource objects (VS2017 v15.7.5 compiler 26433) | 1 |
| 151 | 1 |
| Linker (VS2017 v15.7.5 compiler 26433) | 1 |
No comments yet.