Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2020-Oct-28 03:33:44 |
Detected languages |
English - United States
|
TLS Callbacks | 2 callback(s) detected. |
Debug artifacts |
C:\Repos\Launcher\x64\Release\Launcher.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
Info | The PE's resources present abnormal characteristics. | Resource 101 is possibly compressed or encrypted. |
Suspicious | VirusTotal score: 1/72 (Scanned on 2020-11-21 07:10:11) | Cynet: Malicious (score: 100) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2020-Oct-28 03:33:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x2600 |
SizeOfInitializedData | 0x3600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000002374 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xa000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
SizeofResource
VirtualAlloc LockResource LoadResource FindResourceW GetModuleHandleW GetModuleFileNameW OpenProcess CreateToolhelp32Snapshot Process32NextW K32GetModuleBaseNameW Process32FirstW CloseHandle GetCurrentProcessId CreateProcessW GetComputerNameExA RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetLastError RtlCaptureContext MultiByteToWideChar LocalFree |
---|---|
OLEAUT32.dll |
#16
#8 #22 #9 #411 #15 #21 #26 #2 #6 |
WS2_32.dll |
#23
#16 #115 getaddrinfo #3 freeaddrinfo #19 #4 #116 |
mscoree.dll |
CLRCreateInstance
|
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
__current_exception_context
_CxxThrowException __std_exception_destroy __std_exception_copy memcpy __C_specific_handler __std_terminate memset __current_exception |
api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_narrow_environment
_get_initial_narrow_environment terminate _crt_atexit _configure_narrow_argv _set_app_type _seh_filter_exe _register_onexit_function _initterm exit _initialize_onexit_table __p___argv _initterm_e _exit _register_thread_local_exe_atexit_callback _c_exit _cexit __p___argc |
api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vswprintf
__p__commode _set_fmode |
api-ms-win-crt-heap-l1-1-0.dll |
free
malloc _set_new_mode _callnewh |
api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Oct-28 03:33:44 |
Version | 0.0 |
SizeofData | 67 |
AddressOfRawData | 0x49ac |
PointerToRawData | 0x33ac |
Referenced File | C:\Repos\Launcher\x64\Release\Launcher.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Oct-28 03:33:44 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x49f0 |
PointerToRawData | 0x33f0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Oct-28 03:33:44 |
Version | 0.0 |
SizeofData | 872 |
AddressOfRawData | 0x4a04 |
PointerToRawData | 0x3404 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Oct-28 03:33:44 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x140004d90 |
---|---|
EndAddressOfRawData | 0x140004d91 |
AddressOfIndex | 0x140006120 |
AddressOfCallbacks | 0x140004390 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
Callbacks |
0x0000000140001270
0x0000000140001440 |
Size | 0x130 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140006008 |
XOR Key | 0x9cda5573 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 10 |
Imports (28619) | 4 |
Imports (VS2008 build 21022) | 2 |
C++ objects (28619) | 34 |
C objects (28619) | 10 |
ASM objects (28619) | 4 |
Imports (27412) | 7 |
Total imports | 99 |
265 (28806) | 3 |
Resource objects (28806) | 1 |
151 | 1 |
Linker (28806) | 1 |