| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Mar-14 13:22:16 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\SurfRight\Producten\HitmanPro35\bin\x64\Release MT\HitmanPro_x64.pdb
|
| CompanyName | Sophos B.V. |
| FileDescription | HitmanPro 3.8 |
| FileVersion | 3, 8, 44, 340 |
| InternalName | HitmanPro38 |
| LegalCopyright | © 2006-2025 Sophos B.V. |
| OriginalFilename | HitmanPro.exe |
| ProductName | HitmanPro |
| ProductVersion | 3.8.44.340 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to Whirlpool Uses constants related to AES Uses constants related to Blowfish Uses constants related to DES Uses constants related to RC5 or RC6 Uses constants related to Twofish Uses constants related to TEA |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource 301 detected as a PE Executable.
Resource 302 detected as a PE Executable. Resource 303 detected as a PE Executable. Resource 305 detected as a PE Executable. Resource 307 detected as a PE Executable. Resource 308 detected as a PE Executable. Resource 310 is possibly compressed or encrypted. |
| Info | The PE is digitally signed. |
Signer: Sophos Ltd
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Suspicious | VirusTotal score: 1/72 (Scanned on 2026-02-03 22:57:13) | Jiangmin: Trojan.PSW.Pycoon.g |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Mar-14 13:22:16 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0x305200 |
| SizeOfInitializedData | 0xa9ee00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000002C3A08 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xda7000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xda4cac |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetModuleHandleW
GetLastError WaitForMultipleObjects CreateEventW CloseHandle SetEvent ResetEvent WaitForSingleObject InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection CreateThread SignalObjectAndWait TerminateThread Sleep VirtualAlloc VirtualFree OpenProcess VirtualQueryEx WaitForSingleObjectEx CreateWaitableTimerW SetWaitableTimer GetVersion LocalAlloc LocalFree GetProcAddress GlobalMemoryStatus FreeLibrary Heap32ListNext Heap32Next QueryPerformanceCounter Heap32First Heap32ListFirst GetTickCount GetSystemTimeAsFileTime Thread32First Thread32Next VirtualUnlock LoadLibraryA Process32FirstW VirtualLock Module32FirstW GetSystemInfo Process32NextW CreateToolhelp32Snapshot GetCurrentThreadId Module32NextW GetCurrentProcessId QueryPerformanceFrequency SetThreadPriority GetCurrentThread SystemTimeToFileTime LocalFileTimeToFileTime CompareFileTime GetLocalTime FileTimeToSystemTime SetLastError GetSystemDirectoryW VerifyVersionInfoW VerSetConditionMask GetWindowsDirectoryW CreateFileW DeviceIoControl GetFileInformationByHandle GetModuleHandleA GetProcessHeap HeapFree HeapAlloc HeapReAlloc FindResourceW SizeofResource LoadResource LockResource FreeResource OutputDebugStringW WriteFile ReadFile PeekNamedPipe WaitNamedPipeW GetCalendarInfoW GetFileSizeEx GetNativeSystemInfo FormatMessageW FileTimeToLocalFileTime GetLocaleInfoW TryEnterCriticalSection GetTempPathW RemoveDirectoryW FindFirstFileW FindClose FindNextFileW GetFileAttributesW GetCurrentProcess RegisterWaitForSingleObject UnregisterWaitEx FlushFileBuffers DisconnectNamedPipe GetOverlappedResult GetComputerNameW GetFileAttributesExW GetFileTime SetFileTime ResumeThread GetCommandLineW CreateProcessW ConvertDefaultLocale GetLogicalDriveStringsW QueryDosDeviceW SetThreadAffinityMask DeleteFileW GetModuleFileNameW SetErrorMode GetStdHandle GetDriveTypeW GetVolumeInformationW GetFileSize GetModuleHandleExA SetFileAttributesW CopyFileW TerminateProcess GetNumberFormatW GetVersionExW WTSGetActiveConsoleSessionId ProcessIdToSessionId GetProcessTimes LoadLibraryW GlobalAlloc OpenEventW AllocConsole LoadLibraryExW MultiByteToWideChar SetUnhandledExceptionFilter VirtualProtect VirtualQuery OpenThread SuspendThread GetThreadContext SetThreadContext SearchPathW GetSystemDirectoryA LoadLibraryExA DuplicateHandle CreateSemaphoreW ReleaseSemaphore GetEnvironmentVariableW WideCharToMultiByte GetSystemWow64DirectoryW GetSystemTime GetExitCodeProcess CreateHardLinkW InitializeCriticalSectionAndSpinCount RaiseException DecodePointer GetVolumeInformationA ExpandEnvironmentStringsW SetHandleInformation CreateNamedPipeW ConnectNamedPipe GetThreadPriority GetLongPathNameW VirtualAllocEx ReadProcessMemory VirtualFreeEx MoveFileW GetCurrentDirectoryW GetCurrentDirectoryA GlobalFree SetEndOfFile SetFilePointerEx FormatMessageA GetFullPathNameW GetFullPathNameA CreateFileA CreateMutexW HeapCompact SetFilePointer MapViewOfFile UnmapViewOfFile UnlockFile LockFile UnlockFileEx HeapDestroy GetFileAttributesA HeapCreate HeapValidate HeapSize LockFileEx GetDiskFreeSpaceW CreateFileMappingA CreateFileMappingW GetDiskFreeSpaceA OutputDebugStringA GetVersionExA GetTempPathA AreFileApisANSI DeleteFileA SetNamedPipeHandleState ExitProcess GetStringTypeW EncodePointer IsDebuggerPresent IsProcessorFeaturePresent GetModuleHandleExW GetConsoleMode ReadConsoleInputA SetConsoleMode GetACP RtlUnwindEx RtlPcToFileHeader RtlLookupFunctionEntry GetCPInfo RtlCaptureContext RtlVirtualUnwind UnhandledExceptionFilter TlsAlloc TlsGetValue TlsSetValue TlsFree GetStartupInfoW CompareStringW LCMapStringW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW IsValidCodePage GetOEMCP GetFileType GetConsoleCP GetEnvironmentStringsW FreeEnvironmentStringsW ReadConsoleW GetTimeZoneInformation SetStdHandle WriteConsoleW SetEnvironmentVariableW SetEnvironmentVariableA lstrlenA |
|---|---|
| USER32.dll (delay-loaded) |
RegisterClassExW
GetClassInfoW CloseDesktop SwitchDesktop CreateDesktopW OpenInputDesktop GetAsyncKeyState SystemParametersInfoW KillTimer EndPaint BeginPaint SetTimer SetWindowPos DrawTextA GetDesktopWindow GetSystemMetrics GetProcessWindowStation GetClassNameW GetUserObjectInformationW GetThreadDesktop MsgWaitForMultipleObjectsEx PeekMessageW RegisterHotKey ChangeDisplaySettingsW EnumDisplaySettingsW AllowSetForegroundWindow IsIconic ShowWindow AttachThreadInput GetForegroundWindow EnumWindows GetWindowThreadProcessId GetWindowLongW SetThreadDesktop MessageBoxW SetForegroundWindow GetWindowRect DispatchMessageW TranslateMessage IsDialogMessageW GetMessageW DrawTextW OffsetRect DrawEdge IsRectEmpty DestroyMenu CreatePopupMenu InsertMenuW ClientToScreen TrackPopupMenu RegisterDeviceNotificationW UnregisterDeviceNotification PostQuitMessage CopyRect PtInRect DestroyIcon GetIconInfo CopyIcon CallWindowProcW GetNextDlgTabItem InflateRect GetSysColorBrush FillRect SetRect GetInputState GetCursorPos GetCaretPos GetMessageTime GetMessagePos PostMessageW SetMenuDefaultItem EqualRect MoveWindow InvalidateRect FindWindowExW GetMenuItemCount DeleteMenu RegisterWindowMessageA DestroyWindow GetWindowTextLengthW GetFocus ChildWindowFromPointEx RegisterWindowMessageW ReleaseDC GetDC DrawFocusRect DrawIconEx SendMessageW MapWindowPoints GetParent LoadCursorW SetCursor RedrawWindow IsWindowEnabled WindowFromPoint SetFocus SetPropW GetAncestor GetDlgItem SetWindowLongW AdjustWindowRectEx RegisterClassW EnableWindow TrackMouseEvent ScreenToClient GetClientRect SetWindowTextW GetPropW EnumDesktopsW OpenDesktopW EnumDesktopWindows IsWindowVisible GetWindowTextW FindWindowW DefWindowProcW LoadImageW GetSysColor CloseWindow CreateWindowExW SetRectEmpty |
| Attributes | 0x1 |
|---|---|
| Name | USER32.dll |
| ModuleHandle | 0x430260 |
| DelayImportAddressTable | 0x42fce8 |
| DelayImportNameTable | 0x4180c0 |
| BoundDelayImportTable | 0x419c10 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.8.44.340 |
| ProductVersion | 3.8.44.340 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | Sophos B.V. |
| FileDescription | HitmanPro 3.8 |
| FileVersion (#2) | 3, 8, 44, 340 |
| InternalName | HitmanPro38 |
| LegalCopyright | © 2006-2025 Sophos B.V. |
| OriginalFilename | HitmanPro.exe |
| ProductName | HitmanPro |
| ProductVersion (#2) | 3.8.44.340 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-14 13:22:16 |
| Version | 0.0 |
| SizeofData | 96 |
| AddressOfRawData | 0x393330 |
| PointerToRawData | 0x391930 |
| Referenced File | C:\SurfRight\Producten\HitmanPro35\bin\x64\Release MT\HitmanPro_x64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-14 13:22:16 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x393390 |
| PointerToRawData | 0x391990 |
| Size | 0x70 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14041ea10 |
| XOR Key | 0x2b3a357b |
|---|---|
| Unmarked objects | 0 |
| ASM objects (20806) | 24 |
| C objects (20806) | 264 |
| 136 (VS2008 SP1 build 30729) | 1 |
| Unmarked objects (#2) | 1 |
| C++ objects (20806) | 94 |
| C objects (VS2008 SP1 build 30729) | 4 |
| 135 (VS2008 SP1 build 30729) | 3 |
| Imports (VS2008 SP1 build 30729) | 3 |
| Total imports | 561 |
| 229 (VS2013 UPD5 build 40629) | 264 |
| Resource objects (VS2013 build 21005) | 1 |
| 151 | 1 |
| Linker (VS2013 UPD5 build 40629) | 1 |