| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-May-12 15:46:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Authority\Desktop\C++ projects\DwmLutSetup\x64\Release\dwm_lut.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Suspicious | VirusTotal score: 2/70 (Scanned on 2023-06-25 06:11:17) |
CrowdStrike:
win/malicious_confidence_70% (W)
Cynet: Malicious (score: 100) |
| MD5 | 0f05482477a55eb2f095ce969e15ebbf 🔍 |
|---|---|
| SHA1 | b447e63e5cf911eff7501048b17835f7e9b7e944 🔍 |
| SHA256 | 15f476137041e479083d23b293216e9383680ea3111f1ac640343797d16ee984 🔍 |
| SHA3 | c86eb579e2758fc147b04d577b012ed185f86d2f5f51d38227c426b56846bdf0 🔍 |
| SSDeep | 1536:9+6au8ODt0bW/JKcEu5dhgXovSqXwDEOFKi1xmhy:gunt0iBEqhgXBewDAi1x 🔍 |
| Imports Hash | 9dcb56b4e918d22b1e0bf5dfb4b64369 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2023-May-12 15:46:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x9c00 |
| SizeOfInitializedData | 0x7200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000009088 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x15000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | bad53f340f67ffb1f6228674043bcd91 🔍 |
|---|---|
| SHA1 | 86f9a358493d5e873fcf5689e4cd4647246ed25c 🔍 |
| SHA256 | 92e86087aba08c4d7c56c0204acc666eb11cdb06836a279df63f85652fb5315e 🔍 |
| SHA3 | 1412d0d5531c686308dc1ca08ed964689e79a9909834a2cf2a45cf0ba258f907 🔍 |
| VirtualSize | 0x9ac5 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x9c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.11023 |
| MD5 | 025b241e469be4bfab600143eb7eeac7 🔍 |
|---|---|
| SHA1 | 524344cdf753bb45d8190c98685b184d8a44ddae 🔍 |
| SHA256 | afd8bb9d6c07f3d244a8aa624af1c57a95492b89d7d397412fdb907907bc6327 🔍 |
| SHA3 | 7d4e5014ebf223d0295a46ab8ad1eb0fd7ca69c7b93991bc105a0362d48ff7a2 🔍 |
| VirtualSize | 0x48dc |
| VirtualAddress | 0xb000 |
| SizeOfRawData | 0x4a00 |
| PointerToRawData | 0xa000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.89644 |
| MD5 | 87d07efa6f6ed0ab28191416cb0ea9ff 🔍 |
|---|---|
| SHA1 | 331dfe4ab3beb577c5f399c593905e56f39b92ed 🔍 |
| SHA256 | 7419437e435e89379d7570ada31dc232efc749d43a3a16f8a9f8ac643fa0a4c1 🔍 |
| SHA3 | f23b7e2207a1d53a00f956cf385be20d7c3ae174e8700a79333a2adf9d9c6439 🔍 |
| VirtualSize | 0x1b58 |
| VirtualAddress | 0x10000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0xea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.82133 |
| MD5 | 49c068800fd2f43f4e10900dc89bfc85 🔍 |
|---|---|
| SHA1 | 6fb825190c09e619092af951dbaa7d04833a5e76 🔍 |
| SHA256 | 9bdec797578bcfab7c0f9a8b3cea9232d32e4cc209a4fe16e120dfe1f552abec 🔍 |
| SHA3 | bff5b1d077332616d12435b1986e8c8c69cb60a7c939a6746c5110dc8a5f651f 🔍 |
| VirtualSize | 0x6cc |
| VirtualAddress | 0x12000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0xfe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.89149 |
| MD5 | 2de7a7e5655807213f61edcfc2c273bc 🔍 |
|---|---|
| SHA1 | 844ed93a8c6d54d6878aeff4f97edb8b600a10bd 🔍 |
| SHA256 | e8e25f1fae523e81f32919c22cc2d61b0fff23d8ac64f10c517ba3001094ca90 🔍 |
| SHA3 | b8460f781b64156fbe56b624975ce41ef6ab9c0b9defcbc7edac62df3e3e4320 🔍 |
| VirtualSize | 0xf8 |
| VirtualAddress | 0x13000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x10600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.51862 |
| MD5 | 161370bbc039d9e305a73ddbd7ef8f74 🔍 |
|---|---|
| SHA1 | 8665b1c764ce26f6814ebf2c63fea6d38c42ec79 🔍 |
| SHA256 | 80dd03ced1c442e2a88629bc051be256fd8f4ff4d5e3c735895d73e25d8fe4c6 🔍 |
| SHA3 | 5c1b0199cfa81ea956a51b492bb7f83592662d525682e1ee2341087180b2c183 🔍 |
| VirtualSize | 0x94 |
| VirtualAddress | 0x14000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x10800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.91998 |
| KERNEL32.dll |
FindClose
FindNextFileA GetModuleHandleW K32GetModuleInformation GetCurrentProcess VerSetConditionMask VerifyVersionInfoW ExpandEnvironmentStringsA Sleep HeapDestroy HeapCreate CloseHandle FindFirstFileA LocalFree HeapReAlloc HeapFree GetCurrentProcessId GetCurrentThreadId OpenThread SuspendThread ResumeThread FormatMessageA SetThreadContext FlushInstructionCache VirtualProtect CreateToolhelp32Snapshot Thread32First Thread32Next GetSystemInfo VirtualAlloc VirtualFree VirtualQuery RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetThreadContext HeapAlloc |
|---|---|
| USER32.dll |
MessageBoxA
|
| ADVAPI32.dll |
RegGetValueA
|
| MSVCP140.dll |
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_N@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@J@Z ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEBX@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Xlength_error@std@@YAXPEBD@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?uncaught_exceptions@std@@YAHXZ ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ |
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_type_info_destroy_list
_CxxThrowException __C_specific_handler memcpy __std_exception_destroy __std_exception_copy __std_terminate memmove memset strstr memcmp |
| api-ms-win-crt-stdio-l1-1-0.dll |
_fileno
_chsize ftell fseek fopen fclose fgets __stdio_common_vsprintf __stdio_common_vsscanf __stdio_common_vfprintf |
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc realloc _callnewh |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_onexit_table
_initialize_narrow_environment _configure_narrow_argv _seh_filter_dll _initterm_e _initterm _execute_onexit_table _invalid_parameter_noinfo_noreturn _cexit |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x91 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.8858 |
| MD5 | f7ad1eab748bc07570a57ec87787cf90 🔍 |
| SHA1 | 0b1608da9fef218386e825db575c65616826d9f4 🔍 |
| SHA256 | d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04 🔍 |
| SHA3 | 6c9541b36948c19ae507d74223621875b3af4064f7cd8200bdb97e15a047e96a 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-12 15:46:02 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0xd658 |
| PointerToRawData | 0xc658 |
| Referenced File | C:\Users\Authority\Desktop\C++ projects\DwmLutSetup\x64\Release\dwm_lut.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-12 15:46:02 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xd6bc |
| PointerToRawData | 0xc6bc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-12 15:46:02 |
| Version | 0.0 |
| SizeofData | 660 |
| AddressOfRawData | 0xd6d0 |
| PointerToRawData | 0xc6d0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-May-12 15:46:02 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180010228 |
| XOR Key | 0x12aa3ae7 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 6 |
| C++ objects (VS2022 Update 4 (17.4.2) compiler 31935) | 18 |
| C objects (VS2022 Update 4 (17.4.2) compiler 31935) | 8 |
| ASM objects (VS2022 Update 4 (17.4.2) compiler 31935) | 4 |
| C++ objects (30795) | 1 |
| Imports (VS2022 Update 4 (17.4.2) compiler 31935) | 6 |
| C objects (VS2022 Update 4 (17.4.5) compiler 31942) | 4 |
| Imports (30795) | 9 |
| Total imports | 154 |
| C++ objects (LTCG) (VS2022 Update 5 (17.5.4) compiler 32217) | 2 |
| Resource objects (VS2022 Update 5 (17.5.4) compiler 32217) | 1 |
| Linker (VS2022 Update 5 (17.5.4) compiler 32217) | 1 |
No comments yet.