Architecture |
Subsystem |
Compilation Date | 2022-Mar-18 03:04:42 |
Detected languages |
Chinese - PRC
English - United States |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
Suspicious | VirusTotal score: 2/72 (Scanned on 2025-01-24 16:03:28) |
CrowdStrike: win/malicious_confidence_70% (W) |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
Machine |
NumberofSections | 7 |
TimeDateStamp | 2022-Mar-18 03:04:42 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
Magic | PE32+ |
LinkerVersion | 14.0 |
SizeOfCode | 0x11400 |
SizeOfInitializedData | 0x2f800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000002940 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x45000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FormatMessageW GetLastError CloseHandle CreateProcessW GetModuleHandleW WriteConsoleW CreateFileW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW GetStdHandle WriteFile ExitProcess GetModuleHandleExW HeapAlloc HeapFree FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle GetFileType GetStringTypeW FlsAlloc FlsGetValue FlsSetValue FlsFree LCMapStringW GetProcessHeap HeapSize HeapReAlloc FlushFileBuffers GetConsoleOutputCP GetConsoleMode SetFilePointerEx |
USER32.dll |
Characteristics |
TimeDateStamp | 2022-Mar-18 03:04:42 |
Version | 0.0 |
SizeofData | 796 |
AddressOfRawData | 0x1b01c |
PointerToRawData | 0x1981c |
Characteristics |
TimeDateStamp | 2022-Mar-18 03:04:42 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x138 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14001d008 |
XOR Key | 0x229e3ca5 |
Unmarked objects | 0 |
ASM objects (28900) | 5 |
C++ objects (28900) | 138 |
C objects (28900) | 10 |
C objects (30034) | 16 |
ASM objects (30034) | 9 |
C++ objects (30034) | 45 |
Imports (28900) | 5 |
Total imports | 91 |
C++ objects (LTCG) (VS2019 Update 11 (16.11.6-7) compiler 30137) | 1 |
Resource objects (VS2019 Update 11 (16.11.6-7) compiler 30137) | 1 |
151 | 1 |
Linker (VS2019 Update 11 (16.11.6-7) compiler 30137) | 1 |