Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1996-Nov-26 04:52:33 |
Detected languages |
English - United States
|
Debug artifacts |
notepad.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Notepad |
FileVersion | 10.0.17763.475 (WinBuild.160101.0800) |
InternalName | Notepad |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | NOTEPAD.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.17763.475 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/68 (Scanned on 2019-11-26 04:59:36) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 1996-Nov-26 04:52:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1ac00 |
SizeOfInitializedData | 0x25400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000001AC50 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x43000 |
SizeOfHeaders | 0x400 |
Checksum | 0x4d615 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x11000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
OpenProcessToken
GetTokenInformation DuplicateEncryptionInfoFile RegSetValueExW RegQueryValueExW RegCreateKeyW RegCloseKey RegOpenKeyExW EventSetInformation EventRegister EventUnregister EventWriteTransfer IsTextUnicode DecryptFileW |
---|---|
KERNEL32.dll |
GetACP
LocalUnlock DeleteFileW SetEndOfFile GetFullPathNameW GetFileAttributesExW GetFileInformationByHandle CreateFileMappingW MapViewOfFile MultiByteToWideChar LocalReAlloc UnmapViewOfFile LocalSize GetStartupInfoW FindNLSString LocalLock GlobalUnlock GlobalAlloc GetModuleFileNameA CreateSemaphoreExW ReleaseSemaphore GetModuleHandleExW WaitForSingleObject GetCurrentThreadId ReleaseMutex OutputDebugStringW WaitForSingleObjectEx OpenSemaphoreW CreateMutexExW DebugBreak IsDebuggerPresent GetLastError GetFileAttributesW WriteFile SetLastError WideCharToMultiByte GetTimeFormatW GetDateFormatW GetLocalTime GetUserDefaultUILanguage FoldStringW FormatMessageW FindClose FindFirstFileW lstrcmpW FreeLibrary GetCurrentProcessId HeapSetInformation GetCommandLineW GetCurrentProcess MulDiv GetLocaleInfoW GlobalFree HeapAlloc GetProcessHeap HeapFree GetProcAddress GetModuleHandleW LocalAlloc LocalFree CloseHandle ReadFile CreateFileW SetErrorMode lstrcmpiW GlobalLock |
GDI32.dll |
StartPage
StartDocW SetAbortProc DeleteDC CreateDCW AbortDoc EndPage GetTextMetricsW SetBkMode LPtoDP SetWindowExtEx SetViewportExtEx SetMapMode GetTextExtentPoint32W TextOutW EnumFontsW GetTextFaceW SelectObject DeleteObject CreateFontIndirectW GetDeviceCaps EndDoc |
USER32.dll |
SetWinEventHook
GetMessageW TranslateAcceleratorW IsDialogMessageW TranslateMessage DispatchMessageW UnhookWinEvent SetWindowTextW OpenClipboard IsClipboardFormatAvailable CloseClipboard SetDlgItemTextW GetDlgItemTextW EndDialog SendDlgItemMessageW WinHelpW GetCursorPos ScreenToClient GetKeyboardLayout GetParent SetScrollPos InvalidateRect UpdateWindow GetWindowPlacement SetWindowPlacement CharUpperW GetSystemMenu LoadAcceleratorsW SetWindowLongW CreateWindowExW RegisterWindowMessageW LoadCursorW RegisterClassExW GetWindowTextLengthW GetWindowLongW PeekMessageW GetWindowTextW EnableWindow CreateDialogParamW DrawTextExW CharNextW RedrawWindow SetWindowPos GetDlgCtrlID GetForegroundWindow DestroyWindow MessageBeep PostQuitMessage SetFocus IsIconic DefWindowProcW LoadStringW SetActiveWindow SetCursor GetDpiForWindow ReleaseDC ChildWindowFromPoint ShowWindow EnableMenuItem GetSubMenu CheckMenuItem GetMenu MessageBoxW DialogBoxParamW PostMessageW SetThreadDpiAwarenessContext MoveWindow GetClientRect SendMessageW GetDC GetFocus LoadIconW LoadImageW |
msvcrt.dll |
_lock
_commode _fmode _acmdln __dllonexit __setusermatherr _onexit memcpy _cexit _exit exit __set_app_type __getmainargs _amsg_exit _XcptFilter free memcpy_s iswctype wcsnlen _wcsicmp __C_specific_handler _wtol swprintf_s _vsnwprintf ?terminate@@YAXXZ memset _unlock _ismbblead _initterm _callnewh malloc _purecall __CxxFrameHandler3 wcscmp |
api-ms-win-core-com-l1-1-0.dll |
CoCreateGuid
CoTaskMemFree CoTaskMemAlloc CoCreateInstance CoInitializeEx CoUninitialize CoCreateFreeThreadedMarshaler CoWaitForMultipleHandles PropVariantClear |
api-ms-win-core-synch-l1-2-0.dll |
WakeAllConditionVariable
SleepConditionVariableSRW Sleep |
api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlLookupFunctionEntry
RtlVirtualUnwind RtlCaptureContext |
api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
RaiseException SetUnhandledExceptionFilter |
api-ms-win-core-processthreads-l1-1-0.dll |
TerminateProcess
|
api-ms-win-core-synch-l1-1-0.dll |
AcquireSRWLockExclusive
CreateEventExW ReleaseSRWLockExclusive SetEvent |
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTimeAsFileTime
GetTickCount |
api-ms-win-core-libraryloader-l1-2-0.dll |
GetModuleFileNameW
LoadLibraryExW |
api-ms-win-core-processthreads-l1-1-1.dll |
GetProcessMitigationPolicy
|
api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsCreateString
WindowsGetStringRawBuffer WindowsDeleteString WindowsCreateStringReference |
api-ms-win-core-winrt-error-l1-1-0.dll |
SetRestrictedErrorInfo
|
api-ms-win-core-string-l1-1-0.dll |
CompareStringOrdinal
|
api-ms-win-core-winrt-l1-1-0.dll |
RoInitialize
RoGetActivationFactory RoUninitialize |
api-ms-win-core-winrt-error-l1-1-1.dll |
RoGetMatchingRestrictedErrorInfo
|
COMCTL32.dll |
CreateStatusWindowW
#345 |
COMDLG32.dll |
FindTextW
PageSetupDlgW GetSaveFileNameW GetOpenFileNameW CommDlgExtendedError GetFileTitleW ChooseFontW PrintDlgExW ReplaceTextW |
ntdll.dll |
WinSqmAddToStream
|
PROPSYS.dll |
PropVariantToStringVectorAlloc
PSGetPropertyDescriptionListFromString |
SHELL32.dll |
ShellAboutW
DragQueryFileW SHAddToRecentDocs DragFinish DragAcceptFiles ShellExecuteW SHCreateItemFromParsingName |
SHLWAPI.dll |
SHStrDupW
PathFileExistsW PathIsNetworkPathW PathFindExtensionW PathIsFileSpecW |
WINSPOOL.DRV |
ClosePrinter
GetPrinterDriverW OpenPrinterW |
urlmon.dll |
FindMimeFromData
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.17763.475 |
ProductVersion | 10.0.17763.475 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Notepad |
FileVersion (#2) | 10.0.17763.475 (WinBuild.160101.0800) |
InternalName | Notepad |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | NOTEPAD.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.17763.475 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 1996-Nov-26 04:52:33 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0x209fc |
PointerToRawData | 0x1f9fc |
Referenced File | notepad.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 1996-Nov-26 04:52:33 |
Version | 0.0 |
SizeofData | 820 |
AddressOfRawData | 0x20a20 |
PointerToRawData | 0x1fa20 |
Characteristics |
0
|
---|---|
TimeDateStamp | 1996-Nov-26 04:52:33 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x140020d54 |
---|---|
EndAddressOfRawData | 0x140020d5c |
AddressOfIndex | 0x140025060 |
AddressOfCallbacks | 0x14001d0b0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x108 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140024318 |
GuardCFCheckFunctionPointer | 5368827968 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x36fa2951 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 30 |
ASM objects (26213) | 3 |
C objects (26213) | 24 |
C++ objects (26213) | 6 |
Imports (26213) | 27 |
Total imports | 287 |
264 (26213) | 26 |
Resource objects (26213) | 1 |
Linker (26213) | 1 |