Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2025-Jan-16 18:58:29 |
TLS Callbacks | 2 callback(s) detected. |
Debug artifacts |
D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
|
CompanyName | NavaioSecurityTest |
FileDescription | NavaioSecurityTest |
FileVersion | 1.0.0.0 |
InternalName | NavaioSecurityTest.dll |
LegalCopyright | |
OriginalFilename | NavaioSecurityTest.dll |
ProductName | NavaioSecurityTest |
ProductVersion | 1.0.0+f06abc8f247547acebe552b1b7a02393211c0aff |
Assembly Version | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to RC5 or RC6 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .CLR_UEF
Unusual section name found: Section |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. | Resource MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER detected as a PE Executable. |
Suspicious | The file contains overlay data. | 5161793 bytes of data starting at offset 0x933a00. |
Malicious | VirusTotal score: 3/73 (Scanned on 2025-03-12 20:56:00) |
APEX:
Malicious
Zillya: Trojan.Rozena.Win32.240132 huorong: HEUR:Worm/Autorun.d |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 10 |
TimeDateStamp | 2025-Jan-16 18:58:29 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x613600 |
SizeOfInitializedData | 0x320000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000005C92C0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x950000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x180000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
RaiseException
FreeLibrary SetErrorMode RaiseFailFastException GetExitCodeProcess TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter AddVectoredExceptionHandler MultiByteToWideChar GetTickCount FlushInstructionCache QueryPerformanceFrequency QueryPerformanceCounter RtlLookupFunctionEntry LocateXStateFeature RtlDeleteFunctionTable InterlockedPushEntrySList InterlockedFlushSList InitializeSListHead GetTickCount64 DuplicateHandle QueueUserAPC WaitForSingleObjectEx SetThreadPriority GetThreadPriority GetCurrentThreadId TlsAlloc GetCurrentThread GetCurrentProcessId CreateThread GetModuleHandleW WaitForMultipleObjectsEx SignalObjectAndWait RtlCaptureContext SetThreadStackGuarantee VirtualQuery WriteFile GetStdHandle GetConsoleOutputCP MapViewOfFileEx UnmapViewOfFile GetStringTypeExW InterlockedPopEntrySList ExitProcess Sleep CreateMemoryResourceNotification VirtualAlloc VirtualFree VirtualProtect SleepEx SwitchToThread SuspendThread ResumeThread InitializeContext SetXStateFeaturesMask RtlRestoreContext CloseThreadpoolTimer CreateThreadpoolTimer SetThreadpoolTimer ReadFile GetFileSize GetEnvironmentVariableW SetEnvironmentVariableW CreateEventW SetEvent ResetEvent GetThreadContext SetThreadContext GetEnabledXStateFeatures CopyContext WerRegisterRuntimeExceptionModule RtlInstallFunctionTableCallback GetSystemDefaultLCID GetUserDefaultLCID RtlUnwind HeapAlloc HeapFree GetProcessHeap HeapCreate HeapDestroy GetEnvironmentStringsW FreeEnvironmentStringsW FormatMessageW CreateSemaphoreExW ReleaseSemaphore GetACP LCMapStringEx LocalFree VerSetConditionMask VerifyVersionInfoW QueryThreadCycleTime GetLogicalProcessorInformationEx SetThreadGroupAffinity GetThreadGroupAffinity GetProcessGroupAffinity GetCurrentProcessorNumberEx GetProcessAffinityMask QueryInformationJobObject CloseHandle GetSystemTimeAsFileTime GetModuleFileNameW CreateProcessW GetCPInfo LoadLibraryExW CreateFileW GetFileAttributesExW GetFullPathNameW LoadLibraryExA OutputDebugStringA OpenEventW ReleaseMutex ExitThread CreateMutexW HeapReAlloc CreateNamedPipeA WaitForMultipleObjects DisconnectNamedPipe CreateFileA CancelIoEx GetOverlappedResult ConnectNamedPipe FlushFileBuffers SetFilePointer MapViewOfFile GetActiveProcessorGroupCount GetSystemTime SetConsoleCtrlHandler GetLocaleInfoEx GetUserDefaultLocaleName RtlAddFunctionTable LoadLibraryW CreateDirectoryW RemoveDirectoryW CreateActCtxW ActivateActCtx FindResourceW GetWindowsDirectoryW GetFileSizeEx FindFirstFileExW FindNextFileW GetTempPathW FindClose LoadLibraryA GetCurrentDirectoryW IsWow64Process EncodePointer DecodePointer CreateFileMappingA TlsSetValue TlsGetValue GetSystemInfo GetCurrentProcess OutputDebugStringW IsDebuggerPresent LeaveCriticalSection EnterCriticalSection DeleteCriticalSection InitializeCriticalSection WideCharToMultiByte GetCommandLineW GetProcAddress GetModuleHandleExW SetThreadErrorMode FlushProcessWriteBuffers SetLastError DebugBreak WaitForSingleObject GetNumaHighestNodeNumber SetThreadAffinityMask SetThreadIdealProcessorEx GetThreadIdealProcessorEx VirtualAllocExNuma GetNumaProcessorNodeEx VirtualUnlock GetLargePageMinimum IsProcessInJob K32GetProcessMemoryInfo GetLogicalProcessorInformation GlobalMemoryStatusEx ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW RtlVirtualUnwind IsProcessorFeaturePresent RtlUnwindEx InitializeCriticalSectionAndSpinCount TlsFree RtlPcToFileHeader TryAcquireSRWLockExclusive GetExitCodeThread GetStringTypeW InitializeCriticalSectionEx GetLastError CreateFileMappingW |
---|---|
ADVAPI32.dll |
ReportEventW
AdjustTokenPrivileges RegGetValueW SetKernelObjectSecurity GetSidSubAuthorityCount GetSidSubAuthority GetTokenInformation OpenProcessToken DeregisterEventSource RegisterEventSourceW RegQueryValueExW RegOpenKeyExW RegCloseKey EventRegister SetThreadToken RevertToSelf OpenThreadToken EventWriteTransfer EventWrite LookupPrivilegeValueW |
ole32.dll |
CreateStreamOnHGlobal
CoRevokeInitializeSpy CoGetClassObject CoGetContextToken CoGetObjectContext CoUnmarshalInterface CoMarshalInterface CoGetMarshalSizeMax CLSIDFromProgID CoReleaseMarshalData CoTaskMemFree CoTaskMemAlloc CoCreateGuid CoInitializeEx CoRegisterInitializeSpy CoWaitForMultipleHandles CoUninitialize CoCreateFreeThreadedMarshaler |
OLEAUT32.dll |
CreateErrorInfo
SysFreeString GetErrorInfo SetErrorInfo SysStringLen SysAllocString SysAllocStringLen SafeArrayGetDim SafeArrayGetLBound SafeArrayDestroy QueryPathOfRegTypeLib LoadTypeLibEx SafeArrayGetVartype VariantChangeType VariantChangeTypeEx VariantClear VariantInit VarCyFromDec SafeArrayAllocDescriptorEx GetRecordInfoFromTypeInfo SafeArraySetRecordInfo SafeArrayAllocData SafeArrayGetElemsize SysStringByteLen SysAllocStringByteLen SafeArrayCreateVector SafeArrayPutElement LoadRegTypeLib |
USER32.dll |
LoadStringW
MessageBoxW |
SHELL32.dll |
ShellExecuteW
|
api-ms-win-crt-string-l1-1-0.dll |
strncat_s
wcsncat_s strcmp wcsnlen wcscat_s towupper iswascii _strdup strncpy strnlen wcstok_s isdigit isupper isalpha towlower _wcsdup iswspace isspace islower strtok_s _wcsnicmp strcspn __strncnt strlen wcscpy_s toupper wcsncpy_s strcpy_s strcat_s strncpy_s _strnicmp tolower wcsncmp iswupper strncmp _stricmp _wcsicmp |
api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsscanf
fflush __acrt_iob_func __stdio_common_vfprintf __stdio_common_vswprintf __stdio_common_vfwprintf fputws fputwc _get_stream_buffer_pointers _fseeki64 fread fsetpos ungetc fgetpos fgets fgetc fputc _wfsopen _wfopen __p__commode _set_fmode __stdio_common_vsnprintf_s setvbuf _setmode _dup _fileno ftell fseek fputs __stdio_common_vsnwprintf_s __stdio_common_vsprintf_s fwrite _flushall fopen fclose |
api-ms-win-crt-runtime-l1-1-0.dll |
_crt_atexit
_cexit _seh_filter_exe _set_app_type _register_onexit_function _configure_wide_argv _initialize_wide_environment _get_initial_wide_environment _initterm _initterm_e _exit _invalid_parameter_noinfo_noreturn __p___argc __p___wargv _c_exit _register_thread_local_exe_atexit_callback _initialize_onexit_table _beginthreadex terminate _controlfp_s _wcserror_s _invalid_parameter_noinfo _errno exit abort |
api-ms-win-crt-convert-l1-1-0.dll |
_atoi64
_ltow_s _wtoi strtoul _wcstoui64 atol _itow_s strtoull wcstoul |
api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode calloc malloc realloc |
api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
api-ms-win-crt-math-l1-1-0.dll |
asinhf
atanhf cbrtf acoshf cosh cbrt coshf exp expf acosh atanh floor floorf fma fmaf cosf _fdopen cos ceilf _copysignf _isnanf trunc truncf ilogb ilogbf tanhf ceil fmod fmodf atanf frexp atan2f atan2 log log10 log10f atan asinf log2 log2f logf pow powf sin sinf asin sinh sinhf sqrt sqrtf tan tanf tanh acosf _copysign asinh _isnan _finite modf modff acos __setusermatherr |
api-ms-win-crt-time-l1-1-0.dll |
_time64
_gmtime64_s wcsftime |
api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
api-ms-win-crt-locale-l1-1-0.dll |
_unlock_locales
setlocale __pctype_func ___lc_locale_name_func _lock_locales ___lc_codepage_func ___mb_cur_max_func _configthreadlocale localeconv |
api-ms-win-crt-filesystem-l1-1-0.dll |
_wrename
_unlock_file _wremove _lock_file |
VERSION.dll (delay-loaded) |
VerQueryValueW
GetFileVersionInfoExW GetFileVersionInfoSizeExW |
Attributes | 0x1 |
---|---|
Name | VERSION.dll |
ModuleHandle | 0x79c800 |
DelayImportAddressTable | 0x7e9000 |
DelayImportNameTable | 0x78f5c0 |
BoundDelayImportTable | 0x78f660 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 2 |
---|---|
Address | 0x794de8 |
Ordinal | 3 |
---|---|
Address | 0x7a8238 |
Ordinal | 4 |
---|---|
Address | 0x7955e0 |
Ordinal | 5 |
---|---|
Address | 0x56a350 |
Ordinal | 6 |
---|---|
Address | 0x63d680 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | NavaioSecurityTest |
FileDescription | NavaioSecurityTest |
FileVersion (#2) | 1.0.0.0 |
InternalName | NavaioSecurityTest.dll |
LegalCopyright | |
OriginalFilename | NavaioSecurityTest.dll |
ProductName | NavaioSecurityTest |
ProductVersion (#2) | 1.0.0+f06abc8f247547acebe552b1b7a02393211c0aff |
Assembly Version | 1.0.0.0 |
Resource LangID | UNKNOWN |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Jan-16 18:58:29 |
Version | 0.0 |
SizeofData | 116 |
AddressOfRawData | 0x715d7c |
PointerToRawData | 0x71377c |
Referenced File | D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Jan-16 18:58:29 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x715df0 |
PointerToRawData | 0x7137f0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Jan-16 18:58:29 |
Version | 0.0 |
SizeofData | 1332 |
AddressOfRawData | 0x715e04 |
PointerToRawData | 0x713804 |
StartAddressOfRawData | 0x140716380 |
---|---|
EndAddressOfRawData | 0x14071656d |
AddressOfIndex | 0x14079c850 |
AddressOfCallbacks | 0x140617028 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
Callbacks |
0x00000001405C8740
0x00000001405C8F00 |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140793040 |
GuardCFCheckFunctionPointer | 5375094472 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x41ce4d1e |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 22 |
ASM objects (34321) | 20 |
C objects (34321) | 18 |
C++ objects (34321) | 96 |
C objects (33138) | 8 |
Imports (33138) | 13 |
Total imports | 520 |
ASM objects (34435) | 21 |
C++ objects (LTCG) (34435) | 653 |
Exports (34435) | 1 |
Resource objects (34435) | 1 |
Linker (34435) | 1 |