Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Apr-21 07:42:17 |
Detected languages |
English - United States
|
Debug artifacts |
W:\Work2\Projects_VideoSoftDev\common\ExecuteHelper\x64\Release\ExecuteHelper.pdb
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: FLASH-INTEGRO LLC
Issuer: Sectigo Public Code Signing CA R36 |
Safe | VirusTotal score: 0/72 (Scanned on 2022-11-26 20:23:07) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2022-Apr-21 07:42:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x20c00 |
SizeOfInitializedData | 0x10000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000008BE8 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x35000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3e797 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LoadResource
LockResource SizeofResource FindResourceW MultiByteToWideChar lstrlenW FindResourceExW GetLastError InitializeCriticalSectionEx DeleteCriticalSection WriteConsoleW CreateFileW GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc RaiseException HeapDestroy GetConsoleMode GetConsoleCP FlushFileBuffers SetFilePointerEx GetStringTypeW SetStdHandle LCMapStringW FreeEnvironmentStringsW GetEnvironmentStringsW WideCharToMultiByte GetCommandLineW GetCommandLineA IsDebuggerPresent OutputDebugStringW EnterCriticalSection LeaveCriticalSection LocalFree CloseHandle InitializeCriticalSectionAndSpinCount SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW GetProcAddress RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlPcToFileHeader RtlUnwindEx SetLastError EncodePointer TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW GetStdHandle WriteFile GetFileType FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo |
---|---|
USER32.dll |
GetDesktopWindow
|
ADVAPI32.dll |
RegQueryValueExW
RegOpenKeyExW RegDeleteKeyW RegCreateKeyExW RegCloseKey RegSetValueExW |
SHELL32.dll |
SHGetFolderPathW
|
ole32.dll |
CoUninitialize
OleRun CoCreateInstance CoInitialize |
OLEAUT32.dll |
VariantClear
SysFreeString SysAllocString GetErrorInfo |
SHLWAPI.dll |
PathFileExistsW
|
MSVFW32.dll |
ICClose
ICOpen ICSendMessage |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Apr-21 07:42:17 |
Version | 0.0 |
SizeofData | 106 |
AddressOfRawData | 0x2b528 |
PointerToRawData | 0x2a528 |
Referenced File | W:\Work2\Projects_VideoSoftDev\common\ExecuteHelper\x64\Release\ExecuteHelper.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Apr-21 07:42:17 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x2b594 |
PointerToRawData | 0x2a594 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Apr-21 07:42:17 |
Version | 0.0 |
SizeofData | 988 |
AddressOfRawData | 0x2b5a8 |
PointerToRawData | 0x2a5a8 |
StartAddressOfRawData | 0x14002b9a8 |
---|---|
EndAddressOfRawData | 0x14002b9b0 |
AddressOfIndex | 0x14002fd48 |
AddressOfCallbacks | 0x140022408 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14002f028 |
XOR Key | 0x26844a84 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v14.15 compiler 26715) | 5 |
C++ objects (VS2017 v14.15 compiler 26715) | 146 |
C objects (30034) | 17 |
ASM objects (30034) | 9 |
C++ objects (30034) | 49 |
C objects (VS2017 v14.15 compiler 26715) | 11 |
Imports (VS2017 v14.15 compiler 26715) | 17 |
Total imports | 128 |
C++ objects (VS2019 Update 11 (16.11.10) compiler 30140) | 3 |
Resource objects (VS2019 Update 11 (16.11.10) compiler 30140) | 1 |
Linker (VS2019 Update 11 (16.11.10) compiler 30140) | 1 |