Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Jul-26 18:08:08 |
Suspicious | PEiD Signature: | PeStubOEP v1.x |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2024-Jul-26 18:08:08 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x536600 |
SizeOfInitializedData | 0x1b9200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000004D9070 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x6f4000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VMProtectSDK64.dll |
VMProtectDecryptStringW
VMProtectDecryptStringA |
---|---|
SHLWAPI.dll |
PathFileExistsA
|
ADVAPI32.dll |
RegCreateKeyA
RegOpenKeyExA RegCloseKey RegSetValueExA RegQueryValueExA |
ole32.dll |
StringFromGUID2
|
ntdll.dll |
RtlPcToFileHeader
RtlUnwindEx NtClose NtQuerySystemInformation RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext VerSetConditionMask ZwMapViewOfSection RtlInitUnicodeString RtlUnwind |
dbghelp.dll |
SymLoadModuleEx
SymCleanup SymUnloadModule64 SymGetTypeFromName SymSetOptions SymInitialize SymGetTypeInfo SymFromName |
urlmon.dll |
URLDownloadToFileA
|
USER32.dll |
ReleaseDC
GetDC SetProcessDPIAware GetKeyboardLayout GetKeyState GetMessageExtraInfo MonitorFromWindow ReleaseCapture SetCapture GetCapture TrackMouseEvent LoadCursorA SetCursor IsWindowUnicode ScreenToClient SetCursorPos ClientToScreen GetForegroundWindow GetClientRect SetClipboardData EmptyClipboard CloseClipboard GetClipboardData OpenClipboard GetWindowThreadProcessId FindWindowA GetCursorPos |
KERNEL32.dll |
GetDateFormatW
SetEndOfFile WriteConsoleW HeapSize GetTimeZoneInformation HeapReAlloc GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage FlushFileBuffers ReadConsoleW SetFilePointerEx GetFileSizeEx GetConsoleMode GetConsoleOutputCP WriteFile VirtualProtect FlsFree FlsSetValue FlsGetValue FlsAlloc HeapAlloc HeapFree GetModuleFileNameW ExitProcess ReadFile GetModuleHandleExW FreeLibraryAndExitThread ExitThread CreateThread TerminateProcess LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount RaiseException InterlockedFlushSList GetLocaleInfoW Sleep VirtualFree GetFileAttributesExA CreateFileA GetCurrentProcessId OpenProcess CloseHandle LoadLibraryA GetProcAddress GetTempPathW CreateDirectoryA GetLastError SetLastError DeleteFileA VirtualAlloc LocalFree GetCurrentProcess CreateFileW DeviceIoControl LoadLibraryExA MultiByteToWideChar GlobalLock GetTimeFormatW GlobalUnlock GlobalAlloc GlobalFree QueryPerformanceFrequency QueryPerformanceCounter FreeLibrary GetLocaleInfoA GetModuleHandleA AllocConsole SetStdHandle ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead FormatMessageA TryAcquireSRWLockExclusive FindClose FindFirstFileExW FindNextFileW IsValidLocale GetFullPathNameW AreFileApisANSI GetLocaleInfoEx WaitForSingleObjectEx GetExitCodeThread EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection LCMapStringEx GetStringTypeW CompareStringEx GetCPInfo GetUserDefaultLCID CompareStringW WideCharToMultiByte GetFileType GetStdHandle EnumSystemLocalesW LCMapStringW |
GDI32.dll |
GetDeviceCaps
CreateRectRgn DeleteObject |
dwmapi.dll |
DwmGetColorizationColor
DwmEnableBlurBehindWindow DwmIsCompositionEnabled |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Jul-26 18:08:08 |
Version | 0.0 |
SizeofData | 968 |
AddressOfRawData | 0x58f024 |
PointerToRawData | 0x58da24 |
StartAddressOfRawData | 0x18058f438 |
---|---|
EndAddressOfRawData | 0x18058f440 |
AddressOfIndex | 0x1806aa510 |
AddressOfCallbacks | 0x1805387d8 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1806880c0 |
XOR Key | 0x9a629076 |
---|---|
Unmarked objects | 0 |
C++ objects (33136) | 180 |
C objects (33136) | 33 |
ASM objects (33136) | 24 |
ASM objects (33731) | 10 |
C objects (33731) | 15 |
C++ objects (33731) | 91 |
Imports (33136) | 20 |
Imports (VS2015 UPD3.1 build 24215) | 3 |
Total imports | 223 |
Unmarked objects (#2) | 16 |
Linker (33812) | 1 |