Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Feb-17 10:52:31 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
D:\Jenkins\.jenkins\workspace\master_lu\diagnosetools\tcp_connecter\Release\Diagnose.pdb
|
FileDescription | 问题验证 |
FileVersion | 5.1022.1000.217 |
InternalName | Diagnose.tpi |
LegalCopyright | 版权所有(C)2008-2022 |
OriginalFilename | Diagnose.tpi |
ProductName | 问题验证 |
ProductVersion | 5.1022.1000.217 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to Blowfish |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Chengdu Qilu Technology Co. Ltd.
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Suspicious | VirusTotal score: 1/68 (Scanned on 2022-03-28 14:24:28) | ESET-NOD32: a variant of Win32/Qihoo360.O potentially unwanted |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2022-Feb-17 10:52:31 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5b200 |
SizeOfInitializedData | 0x2fa00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000154CD (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x5d000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x8e000 |
SizeOfHeaders | 0x400 |
Checksum | 0x9a474 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
lstrcmpiW
CreateEventW LoadLibraryExW GetModuleFileNameW GetModuleHandleW DeleteFileW CreateMutexW GetPrivateProfileIntW SetEvent LeaveCriticalSection EnterCriticalSection InitializeCriticalSection SetLastError GetCurrentThreadId GetProcAddress FreeLibrary InterlockedDecrement InterlockedIncrement MultiByteToWideChar FindResourceExW FindResourceW CreateFileA GetSystemDirectoryW lstrcmpiA lstrcmpA DeviceIoControl CloseHandle SizeofResource LoadResource WaitForSingleObject GetExitCodeProcess LockResource DeleteCriticalSection InitializeCriticalSectionAndSpinCount GetLastError GetSystemWindowsDirectoryW FreeResource Sleep InterlockedCompareExchange WriteConsoleW ReadConsoleW SetEndOfFile SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA RaiseException GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc GetOEMCP IsValidCodePage FindNextFileA FindFirstFileExA FindClose EnumSystemLocalesW HeapDestroy DecodePointer IsDebuggerPresent OutputDebugStringW EncodePointer InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList GetCurrentProcess FlushInstructionCache IsProcessorFeaturePresent VirtualAlloc VirtualFree LoadLibraryExA WideCharToMultiByte GetStringTypeW FormatMessageW SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount CompareStringW LCMapStringW GetLocaleInfoW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId LoadLibraryW GetVersionExW ReadFile CreateFileW LocalFree ReleaseMutex WritePrivateProfileStringW WriteFile FlushFileBuffers WaitForMultipleObjects RtlUnwind InterlockedFlushSList CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetModuleFileNameA GetFileType SetFilePointerEx GetConsoleCP GetConsoleMode GetTimeZoneInformation GetACP GetStdHandle IsValidLocale GetUserDefaultLCID |
---|---|
USER32.dll |
PostQuitMessage
LoadCursorW SetWindowLongW CharNextW DestroyWindow IsWindow CreateWindowExW GetClassInfoExW RegisterClassExW PostMessageW PeekMessageW DispatchMessageW TranslateMessage GetMessageW UnregisterClassW CallWindowProcW SetTimer wsprintfW DefWindowProcW GetWindowLongW |
ADVAPI32.dll |
RegOpenKeyExA
RegEnumKeyExA GetTokenInformation OpenProcessToken RegQueryValueExW RegSetValueExW RegQueryInfoKeyW RegOpenKeyExW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegCloseKey RegQueryValueExA |
SHELL32.dll |
#165
SHGetSpecialFolderPathW SHCreateDirectoryExW ShellExecuteExW |
ole32.dll |
CoTaskMemAlloc
CoCreateInstance CoTaskMemFree CoTaskMemRealloc CoInitialize CoCreateGuid |
OLEAUT32.dll |
VarUI4FromStr
|
SHLWAPI.dll |
PathAppendW
PathRemoveFileSpecW SHGetValueW PathCombineW StrStrIW StrStrIA SHGetValueA PathFileExistsW StrCmpIW StrCmpNIW StrTrimA SHSetValueA |
CRYPT32.dll |
CertGetNameStringW
|
WINTRUST.dll |
WTHelperProvDataFromStateData
WinVerifyTrust |
VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
WININET.dll |
InternetGetConnectedState
|
IPHLPAPI.DLL |
GetAdaptersInfo
|
urlmon.dll |
URLDownloadToCacheFileW
URLDownloadToFileW |
Ordinal | 1 |
---|---|
Address | 0x3650 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.1022.1000.217 |
ProductVersion | 5.1022.1000.217 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | Chinese - PRC |
FileDescription | 问题验证 |
FileVersion (#2) | 5.1022.1000.217 |
InternalName | Diagnose.tpi |
LegalCopyright | 版权所有(C)2008-2022 |
OriginalFilename | Diagnose.tpi |
ProductName | 问题验证 |
ProductVersion (#2) | 5.1022.1000.217 |
Resource LangID | Chinese - PRC |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Feb-17 10:52:31 |
Version | 0.0 |
SizeofData | 113 |
AddressOfRawData | 0x7d654 |
PointerToRawData | 0x7bc54 |
Referenced File | D:\Jenkins\.jenkins\workspace\master_lu\diagnosetools\tcp_connecter\Release\Diagnose.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Feb-17 10:52:31 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x7d6c8 |
PointerToRawData | 0x7bcc8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Feb-17 10:52:31 |
Version | 0.0 |
SizeofData | 924 |
AddressOfRawData | 0x7d6dc |
PointerToRawData | 0x7bcdc |
StartAddressOfRawData | 0x1007da88 |
---|---|
EndAddressOfRawData | 0x1007da90 |
AddressOfIndex | 0x100879ac |
AddressOfCallbacks | 0x1005d3cc |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x10083190 |
SEHandlerTable | 0x1007d310 |
SEHandlerCount | 209 |
XOR Key | 0x34819bc4 |
---|---|
Unmarked objects | 0 |
C objects (LTCG) (VS2017 v15.9.12-13 compiler 27031) | 2 |
Unmarked objects (#2) | 1 |
C++ objects (VS2017 v15.7.5 compiler 26433) | 10 |
241 (40116) | 17 |
243 (40116) | 157 |
242 (40116) | 30 |
C++ objects (VS2017 v15.9.14-15 compiler 27032) | 6 |
ASM objects (VS 2015/2017 runtime 26706) | 25 |
C objects (VS 2015/2017 runtime 26706) | 33 |
C++ objects (VS 2015/2017 runtime 26706) | 64 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 SP1 build 30729) | 27 |
Total imports | 235 |
C++ objects (VS2017 v15.9.12-13 compiler 27031) | 24 |
Exports (VS2017 v15.9.12-13 compiler 27031) | 1 |
Resource objects (VS2017 v15.9.12-13 compiler 27031) | 1 |
151 | 1 |
Linker (VS2017 v15.9.12-13 compiler 27031) | 1 |