Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 1970-Jan-01 00:00:00 |
TLS Callbacks | 2 callback(s) detected. |
Suspicious | PEiD Signature: | HQR data file |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to RC5 or RC6 |
Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 11 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x1e1600 |
SizeOfInitializedData | 0x318a00 |
SizeOfUninitializedData | 0x5a200 |
AddressOfEntryPoint | 0x00000000000014F0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 0.0 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x37b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x32308d |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x200000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
ChoosePixelFormat
CreateBitmap CreateDCW CreateDIBSection CreateRectRgn DeleteDC DeleteObject DescribePixelFormat GetDeviceCaps GetDeviceGammaRamp SetDeviceGammaRamp SetPixelFormat SwapBuffers |
---|---|
KERNEL32.dll |
AddVectoredContinueHandler
AddVectoredExceptionHandler CloseHandle CreateEventA CreateFileA CreateFileW CreateIoCompletionPort CreateSemaphoreW CreateThread CreateWaitableTimerExW DeleteCriticalSection DuplicateHandle EnterCriticalSection ExitProcess FormatMessageW FreeEnvironmentStringsW FreeLibrary GetConsoleMode GetCurrentThreadId GetEnvironmentStringsW GetErrorMode GetFileInformationByHandle GetLastError GetModuleFileNameA GetModuleHandleExW GetModuleHandleW GetProcAddress GetProcessAffinityMask GetQueuedCompletionStatusEx GetStartupInfoA GetStartupInfoW GetStdHandle GetSystemDirectoryA GetSystemInfo GetThreadContext GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock InitializeCriticalSection IsDBCSLeadByteEx LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadLibraryW MultiByteToWideChar PostQueuedCompletionStatus QueryPerformanceCounter QueryPerformanceFrequency RaiseFailFastException ReadFile ReleaseSemaphore ResetEvent ResumeThread RtlLookupFunctionEntry RtlVirtualUnwind SetConsoleCtrlHandler SetErrorMode SetEvent SetProcessPriorityBoost SetThreadContext SetThreadExecutionState SetThreadPriority SetUnhandledExceptionFilter SetWaitableTimer Sleep SuspendThread SwitchToThread TlsAlloc TlsFree TlsGetValue TlsSetValue VerSetConditionMask VirtualAlloc VirtualFree VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WerGetFlags WerSetFlags WideCharToMultiByte WriteConsoleW WriteFile __C_specific_handler |
msvcrt.dll |
___lc_codepage_func
___mb_cur_max_func __getmainargs __initenv __iob_func __lconv_init __set_app_type __setusermatherr _access _acmdln _amsg_exit _assert _atoi64 _beginthread _cexit _chdir _commode _errno _findclose _findfirst64 _findnext64 _fmode _getcwd _hypot _initterm _lock _mkdir _onexit _stat64 _time64 _unlock _wassert _wfopen abort acos atof atoi calloc div exit fclose feof ferror fflush fgetc fgets fopen fopen_s fprintf fputc fread free frexp fseek ftell fwrite getc islower isspace isupper isxdigit localeconv malloc memchr memcmp memcpy memmove memset puts qsort rand realloc rewind signal strchr strcmp strcpy strcspn strerror strlen strncmp strncpy strpbrk strrchr strspn strstr strtok strtol strtoul system tan tolower ungetc vfprintf wcscmp wcscpy wcslen |
SHELL32.dll |
DragAcceptFiles
DragFinish DragQueryFileW DragQueryPoint |
USER32.dll |
AdjustWindowRectEx
BringWindowToTop ChangeDisplaySettingsExW ClientToScreen ClipCursor CloseClipboard CreateIconIndirect CreateWindowExW DefWindowProcW DestroyIcon DestroyWindow DispatchMessageW EmptyClipboard EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExW EnumDisplaySettingsW FlashWindow GetActiveWindow GetClassLongPtrW GetClientRect GetClipboardData GetCursorPos GetDC GetKeyState GetLayeredWindowAttributes GetMessageTime GetMonitorInfoW GetPropW GetRawInputData GetRawInputDeviceInfoA GetRawInputDeviceList GetSystemMetrics GetWindowLongW GetWindowPlacement GetWindowRect IsIconic IsWindowVisible IsZoomed LoadCursorW LoadImageW MapVirtualKeyW MonitorFromWindow MoveWindow MsgWaitForMultipleObjects OffsetRect OpenClipboard PeekMessageW PostMessageW PtInRect RegisterClassExW RegisterDeviceNotificationW RegisterRawInputDevices ReleaseCapture ReleaseDC RemovePropW ScreenToClient SendMessageW SetCapture SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetLayeredWindowAttributes SetPropW SetRect SetWindowLongW SetWindowPlacement SetWindowPos SetWindowTextW ShowWindow SystemParametersInfoW ToUnicode TrackMouseEvent TranslateMessage UnregisterClassW UnregisterDeviceNotification WaitMessage WindowFromPoint |
WINMM.dll |
timeBeginPeriod
timeEndPeriod |
Ordinal | 1 |
---|---|
Address | 0x36f3f0 |
Ordinal | 2 |
---|---|
Address | 0x9f8d0 |
Ordinal | 3 |
---|---|
Address | 0x9f880 |
Ordinal | 4 |
---|---|
Address | 0x9f920 |
StartAddressOfRawData | 0x140376000 |
---|---|
EndAddressOfRawData | 0x140376008 |
AddressOfIndex | 0x14036feac |
AddressOfCallbacks | 0x140375040 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x00000001401E0520
0x00000001401E04F0 |