| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-22 16:34:47 |
| Detected languages |
English - United States
|
| Debug artifacts |
E:\build\workdir\LinkTarget\Executable\updater.pdb
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: The Document Foundation
Issuer: Certum Code Signing 2021 CA |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-05-12 13:13:46) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-22 16:34:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1ea00 |
| SizeOfInitializedData | 0x27e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000001D4C4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x57c40 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
InitCommonControlsEx
|
|---|---|
| CRYPT32.dll |
CryptQueryObject
CryptImportPublicKeyInfo CryptMsgClose CertCloseStore CryptMsgGetParam CertFindCertificateInStore CertGetNameStringW CertGetNameStringA CertFreeCertificateContext |
| GDI32.dll |
SelectObject
|
| ole32.dll |
CoTaskMemFree
|
| RPCRT4.dll |
UuidCreate
RpcStringFreeW UuidToStringW |
| SHELL32.dll |
ShellExecuteExW
SHGetKnownFolderPath |
| SHLWAPI.dll |
PathUnquoteSpacesW
PathStripPathW PathCanonicalizeW PathIsUNCServerShareW PathRemoveFileSpecW PathStripToRootW PathCommonPrefixW PathAppendW |
| WS2_32.dll |
ntohl
|
| ADVAPI32.dll |
QueryServiceConfigW
CryptDestroyHash CryptGetHashParam CryptReleaseContext RegGetValueW AdjustTokenPrivileges LookupPrivilegeValueA OpenProcessToken GetTokenInformation RegQueryInfoKeyW RegEnumKeyExW CloseServiceHandle OpenSCManagerA StartServiceW CreateProcessAsUserW OpenServiceW QueryServiceStatusEx RegQueryValueExW CryptVerifySignatureA CryptAcquireContextA CryptCreateHash CryptHashData CryptDestroyKey RegCloseKey RegCreateKeyExW RegSetValueExW RegOpenKeyExW |
| WINTRUST.dll |
WinVerifyTrust
|
| USER32.dll |
LoadIconW
GetClientRect GetDlgItem GetDC GetDesktopWindow SetTimer DialogBoxParamW ReleaseDC WaitForInputIdle GetWindowRect wsprintfW OffsetRect GetWindowLongPtrW CopyRect SetWindowTextW EndDialog SendMessageW ScreenToClient SetWindowLongPtrW GetParent SetWindowPos DrawTextW |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| USERENV.dll |
CreateEnvironmentBlock
DestroyEnvironmentBlock |
| KERNEL32.dll |
GetCurrentThreadId
UnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId QueryPerformanceCounter SetUnhandledExceptionFilter InitializeSListHead RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext SleepConditionVariableSRW GetFullPathNameW DeviceIoControl WakeAllConditionVariable ReleaseSRWLockExclusive GetSystemTimeAsFileTime AcquireSRWLockExclusive LocalAlloc FreeLibrary LoadLibraryW GetDriveTypeW Process32FirstW DeleteFileW Process32NextW CreateToolhelp32Snapshot WriteFile CreateDirectoryW DeactivateActCtx GetModuleFileNameW ActivateActCtx CreateActCtxW LoadLibraryExW SetDllDirectoryW GetModuleHandleW GetProcAddress GetTickCount WideCharToMultiByte CopyFileW CreateProcessW MoveFileExW LocalFree UnlockFile CloseHandle GetLastError FormatMessageW Sleep GetPrivateProfileStringW MultiByteToWideChar QueryInformationJobObject FindFirstFileW SetLastError FindNextFileW GetLongPathNameW GetCurrentProcess TerminateProcess LockFile SetFilePointer SetEndOfFile FindClose WaitForSingleObject CreateFileW GetFileAttributesW GetSystemDirectoryW IsProcessInJob OpenProcess |
| VCRUNTIME140.dll |
_CxxThrowException
memset __std_type_info_destroy_list memmove memcpy __current_exception_context wcschr strchr __current_exception _purecall wcsstr __std_terminate wcsrchr __std_exception_destroy __std_exception_copy __C_specific_handler |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-string-l1-1-0.dll |
strtok
strpbrk wcstok_s strncpy wcspbrk wcsnlen wcsncat _strdup _wcsdup _wcsnicmp _wcsicmp strcmp strncmp _wcslwr wcsncpy wcsncmp |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
_wtoi64 wcstol |
| api-ms-win-crt-stdio-l1-1-0.dll |
ftell
_fseeki64 _ftelli64 rewind fgetc _wfopen_s fopen _fileno __stdio_common_vsprintf fclose __stdio_common_vswprintf fwrite _setmaxstdio _wfopen _set_fmode fflush __stdio_common_vfprintf fseek __stdio_common_vfwprintf fread __acrt_iob_func ferror __p__commode _get_osfhandle |
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
__p___wargv __p___argc _beginthreadex exit _errno _initterm_e _initterm _get_initial_wide_environment _initialize_wide_environment _configure_wide_argv _cexit _register_thread_local_exe_atexit_callback _wperror _exit _set_app_type perror terminate _seh_filter_exe _seh_filter_dll _configure_narrow_argv _initialize_narrow_environment _crt_at_quick_exit _initialize_onexit_table _invoke_watson _crt_atexit _register_onexit_function _execute_onexit_table |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
malloc free _callnewh |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_wchdir
_waccess _wstat64i32 _wrename _wchmod _wrmdir _wremove _fstat64i32 _wmkdir |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
_putenv |
| api-ms-win-crt-time-l1-1-0.dll |
strftime
_time64 _localtime64 _mktime64 |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| moz-updater.exe-4cdccec4-5ee0-4a06-9817-4cd899a9db49 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-22 16:34:47 |
| Version | 0.0 |
| SizeofData | 75 |
| AddressOfRawData | 0x284fc |
| PointerToRawData | 0x272fc |
| Referenced File | E:\build\workdir\LinkTarget\Executable\updater.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-22 16:34:47 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x28548 |
| PointerToRawData | 0x27348 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-22 16:34:47 |
| Version | 0.0 |
| SizeofData | 964 |
| AddressOfRawData | 0x2855c |
| PointerToRawData | 0x2735c |
| StartAddressOfRawData | 0x140028940 |
|---|---|
| EndAddressOfRawData | 0x140028948 |
| AddressOfIndex | 0x14002e9b8 |
| AddressOfCallbacks | 0x140020958 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14002e040 |
| XOR Key | 0x51767c94 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| Imports (35207) | 6 |
| 253 (35207) | 5 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 33 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 27 |
| Total imports | 255 |
| C++ objects (LTCG) (35224) | 22 |
| Resource objects (35224) | 1 |
| Linker (35224) | 1 |
No comments yet.