| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Jan-25 08:00:36 |
| Detected languages |
English - United States
|
| FileVersion | 2.0.19 |
| ProductVersion | 2.0.19 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Jan-25 08:00:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe3000 |
| SizeOfInitializedData | 0x55400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000BEC3C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x141000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WSOCK32.dll |
WSAGetLastError
getservbyname htonl send recv inet_addr WSAAsyncSelect inet_ntoa gethostbyname WSASetLastError ioctlsocket htons gethostbyaddr getservbyport ntohs WSAStartup gethostname shutdown WSACleanup closesocket connect socket |
|---|---|
| WINMM.dll |
joyGetPosEx
mciSendStringW joyGetDevCapsW |
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| COMCTL32.dll |
ImageList_GetIconSize
ImageList_Create ImageList_Destroy ImageList_AddMasked ImageList_ReplaceIcon CreateStatusWindowW |
| PSAPI.DLL |
GetProcessImageFileNameW
|
| WININET.dll |
InternetCloseHandle
InternetReadFileExA InternetReadFile InternetOpenW InternetOpenUrlW |
| SHLWAPI.dll |
StrCmpLogicalW
|
| UxTheme.dll |
EnableThemeDialogTexture
SetWindowTheme IsAppThemed |
| dwmapi.dll |
DwmGetWindowAttribute
|
| KERNEL32.dll |
GlobalFree
GlobalUnlock WideCharToMultiByte GetCPInfo GetSystemDirectoryA LoadLibraryA GetProcAddress FreeLibrary GetCurrentThreadId GetEnvironmentVariableW IsValidCodePage LoadLibraryW GetLastError OutputDebugStringW lstrcmpiW GetStringTypeExW CreateThread SetThreadPriority GetExitCodeThread CloseHandle CreateMutexW VirtualProtect SetLastError GetModuleHandleW GetDiskFreeSpaceExW GetDriveTypeW CreateFileW DeviceIoControl SetVolumeLabelW GetVolumeInformationW GetDiskFreeSpaceW SetEnvironmentVariableW MultiByteToWideChar GetFullPathNameW GetFileAttributesW CreateDirectoryW ReadFile DeleteFileW LoadResource LockResource WriteFile SizeofResource SetCurrentDirectoryW CompareStringOrdinal CopyFileW SetFileAttributesW FindFirstFileW FindNextFileW FindClose FileTimeToLocalFileTime LocalFileTimeToFileTime GetSystemTimeAsFileTime SetFileTime GetFileSizeEx MoveFileW GlobalLock OpenProcess TerminateProcess SetPriorityClass GetProcessId QueryDosDeviceW EnterCriticalSection LeaveCriticalSection Beep GetLocalTime GetDateFormatW GetTimeFormatW GetDateFormatEx GetTickCount64 GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetCurrentDirectoryW GetSystemWindowsDirectoryW GetTempPathW WaitForSingleObject GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetVersionExW InitializeCriticalSection DeleteCriticalSection GetModuleFileNameW SetDllDirectoryW GetModuleHandleExW GetShortPathNameW CreateProcessW FormatMessageW CompareStringW RemoveDirectoryW GetCurrentProcess CreateToolhelp32Snapshot Process32FirstW Process32NextW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize IsWow64Process VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize FindResourceW SetErrorMode Sleep GetTickCount MulDiv RtlUnwindEx RtlPcToFileHeader RaiseException EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetCommandLineA RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent QueryPerformanceCounter GetCommandLineW ExitProcess HeapSize HeapReAlloc HeapQueryInformation HeapFree HeapAlloc GetProcessHeap FindFirstFileExW GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW FlsAlloc FlsGetValue FlsSetValue FlsFree LCMapStringW GlobalAlloc SetStdHandle GetStringTypeW FlushFileBuffers GetConsoleOutputCP GetConsoleMode WriteConsoleW GetCurrentProcessId InitializeSListHead |
| USER32.dll |
SetWindowPos
EnumWindows IsZoomed IsIconic GetLayeredWindowAttributes SetLayeredWindowAttributes DestroyWindow RegisterClassExW SystemParametersInfoW CreateWindowExW GetMenu EnableMenuItem LoadAcceleratorsW AddClipboardFormatListener RemoveClipboardFormatListener LoadImageW PostQuitMessage CheckMenuItem RegisterWindowMessageW DefWindowProcW SetForegroundWindow MonitorFromPoint GetSystemMenu GetMenuItemCount GetMenuItemID GetSubMenu GetMenuStringW ExitWindowsEx GetPropW GetClassLongW SetMenu SetPropW RemovePropW GetSysColor RedrawWindow DrawTextW SetParent GetClassInfoExW AdjustWindowRectEx GetAncestor UpdateWindow FlashWindow GetMessagePos GetSysColorBrush FillRect GetClassLongPtrW CallWindowProcW CheckRadioButton IntersectRect GetUpdateRect PtInRect CreateDialogIndirectParamW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW RemoveMenu SetMenuItemInfoW GetMenuItemInfoW SetMenuDefaultItem CreateMenu CreatePopupMenu SetMenuInfo DestroyMenu TrackPopupMenuEx CopyImage CreateIconIndirect CreateIconFromResourceEx DrawIconEx EnumClipboardFormats GetWindow BringWindowToTop GetQueueStatus GetLastActivePopup GetShellWindow MapVirtualKeyW VkKeyScanExW SetWindowRgn GetKeyboardLayoutNameW ActivateKeyboardLayout GetGUIThreadInfo GetWindowTextW mouse_event WindowFromPoint keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey SendMessageTimeoutW CharUpperW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx GetKeyboardLayout CharLowerW ReleaseDC GetDC DialogBoxParamW ScrollWindow GetSystemMetrics GetWindowRect GetWindowLongPtrW SetFocus DefDlgProcW MoveWindow MapWindowPoints GetClientRect EnableWindow MapDialogRect GetDlgItem SetWindowLongPtrW SetWindowTextW MessageBoxW OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW IsChild IsWindowVisible SetActiveWindow EnumChildWindows GetLastInputInfo LoadCursorW GetCursorInfo ClientToScreen MessageBeep GetIconInfo GetWindowTextLengthW InvalidateRect AdjustWindowRect SetDlgItemTextW SendDlgItemMessageW IsCharAlphaW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow IsClipboardFormatAvailable CountClipboardFormats SetWindowLongW ScreenToClient GetMonitorInfoW IsDialogMessageW SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID EnumDisplayMonitors DestroyIcon MapVirtualKeyExW BlockInput CallNextHookEx |
| GDI32.dll |
GdiFlush
CreateDIBSection EnumFontFamiliesExW SetBrushOrgEx GetObjectW CreatePatternBrush GetClipBox SetBkMode SetBkColor GetDeviceCaps CreateCompatibleDC CreateFontIndirectW GetStockObject CreateSolidBrush GetCharABCWidthsW GetTextMetricsW GetPixel GetDIBits SelectObject CreateDCW CreateFontW CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteObject BitBlt CreateCompatibleBitmap DeleteDC GetSystemPaletteEntries SetTextColor |
| ADVAPI32.dll |
UnlockServiceDatabase
RegDeleteKeyW RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken RegDeleteValueW GetUserNameW RegConnectRegistryW RegCloseKey RegOpenKeyExW RegQueryInfoKeyW RegEnumValueW RegEnumKeyExW CreateProcessWithLogonW OpenSCManagerW LockServiceDatabase CloseServiceHandle RegDeleteKeyExW |
| SHELL32.dll |
SHBrowseForFolderW
DragFinish SHGetKnownFolderPath ExtractIconW DragQueryPoint SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW DragQueryFileW SHGetDesktopFolder SHGetMalloc SHCreateItemFromParsingName ShellExecuteExW SHGetFolderPathW Shell_NotifyIconW |
| ole32.dll |
CoCreateInstance
CoTaskMemFree CLSIDFromString OleInitialize OleFlushClipboard OleUninitialize CoInitialize CoUninitialize CLSIDFromProgID CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
| OLEAUT32.dll |
SafeArrayUnaccessData
SafeArrayGetElemsize SafeArrayDestroy SysFreeString GetActiveObject SysStringLen SafeArrayCreate OleLoadPicture VariantChangeType SysAllocString SafeArrayCopy SysAllocStringLen VariantCopyInd SafeArrayGetUBound SafeArrayGetLBound VariantClear SafeArrayGetDim SafeArrayLock SafeArrayPtrOfIndex SafeArrayUnlock SafeArrayAccessData |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.19.0 |
| ProductVersion | 2.0.19.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 2.0.19 |
| ProductVersion (#2) | 2.0.19 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jan-25 08:00:36 |
| Version | 0.0 |
| SizeofData | 896 |
| AddressOfRawData | 0x11333c |
| PointerToRawData | 0x11273c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jan-25 08:00:36 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140121040 |
| XOR Key | 0xf62ea54d |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 23 |
| Unmarked objects (#2) | 1 |
| C++ objects (33218) | 46 |
| C objects (33218) | 19 |
| ASM objects (33218) | 17 |
| C objects (30795) | 25 |
| C++ objects (30795) | 156 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 33 |
| Total imports | 495 |
| ASM objects (33523) | 2 |
| C++ objects (LTCG) (33523) | 66 |
| Resource objects (33523) | 1 |
| Linker (33523) | 1 |
No comments yet.