Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2016-Aug-22 18:55:10 |
Detected languages |
English - United States
|
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
C:\Jenkins\workspace\Release6.0_Build\Platform\vs2008\out\release-6.0\Tanium_x86\RelWithDebInfo\TaniumSender.pdb
|
FileDescription | Tanium |
InternalName | Tanium |
FileVersion | 6.0.314.1540 |
LegalCopyright | Copyright (C) Tanium Inc. 2009-2016 |
ProductName | Tanium |
ProductVersion | 6.0.314.1540 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Tanium Inc.
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Safe | VirusTotal score: 0/68 (Scanned on 2017-11-10 02:53:03) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2016-Aug-22 18:55:10 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x3d5c00 |
SizeOfInitializedData | 0xd8400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00367A66 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x3d7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x4ce000 |
SizeOfHeaders | 0x400 |
Checksum | 0x4be2db |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0xf4240 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CreateIoCompletionPort
GetQueuedCompletionStatus PostQueuedCompletionStatus GetCurrentThreadId LocalAlloc lstrlenA FormatMessageA WideCharToMultiByte GetModuleFileNameA TerminateThread GetSystemDirectoryA GetACP GetModuleHandleW ReleaseMutex UnmapViewOfFile ResetEvent SetEvent MapViewOfFile CreateFileMappingA MultiByteToWideChar CreateFileW SetFileTime LocalFileTimeToFileTime DosDateTimeToFileTime GetFileTime GetVersion SystemTimeToFileTime GetComputerNameExW SetUnhandledExceptionFilter GetVersionExA LocalFree GlobalFree GlobalAlloc GetStdHandle AllocConsole InterlockedPopEntrySList SetConsoleCtrlHandler IsDebuggerPresent UnhandledExceptionFilter RtlUnwind CreateWaitableTimerA SetWaitableTimer GetSystemInfo CompareStringW CompareStringA WriteConsoleW GetConsoleOutputCP WriteConsoleA GetLocaleInfoW IsValidLocale EnumSystemLocalesA HeapAlloc LCMapStringW LCMapStringA GetStringTypeExW GetStringTypeExA GetUserDefaultLCID FindNextFileA FindFirstFileA FindNextFileW FindFirstFileW GetShortPathNameW GetFileInformationByHandle CopyFileA MoveFileA CopyFileW MoveFileW CreateHardLinkA CreateDirectoryA DeleteFileA InterlockedPushEntrySList InterlockedFlushSList InitializeSListHead GetSystemTimeAsFileTime SetLastError WriteFile SetFilePointer ReadFile CreateFileA SetFilePointerEx SetEndOfFile InterlockedDecrement InterlockedIncrement GetLocalTime Sleep GetTickCount GetCurrentProcess SetProcessWorkingSetSize GetCurrentProcessId CreateEventA CreateProcessA InterlockedExchange TerminateProcess WaitForSingleObject LoadLibraryA GetProcAddress FreeLibrary OpenMutexA CreateMutexA GetLastError CloseHandle GetModuleHandleA GetStringTypeW GetStringTypeA GetLocaleInfoA QueryPerformanceCounter GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA InitializeCriticalSectionAndSpinCount IsValidCodePage GetOEMCP HeapSize FlushFileBuffers RemoveDirectoryA GetConsoleMode GetConsoleCP GetStartupInfoA SetHandleCount VirtualAlloc FatalAppExitA VirtualFree HeapDestroy HeapCreate GetCPInfo HeapReAlloc GetTimeZoneInformation GetCommandLineA GetFileType SetStdHandle GetDriveTypeA FileTimeToLocalFileTime FileTimeToSystemTime SetFileAttributesA SetEnvironmentVariableA ExitProcess CreateThread GetFullPathNameA GetDiskFreeSpaceExA CreateHardLinkW CreateDirectoryW ExitThread GetDateFormatA GetTimeFormatA InterlockedExchangeAdd GetProcessAffinityMask LeaveCriticalSection EnterCriticalSection OpenProcess TlsAlloc TlsGetValue GetThreadPriority DuplicateHandle GetCurrentThread SetThreadPriority ReleaseSemaphore TlsSetValue CreateSemaphoreA TlsFree DeleteCriticalSection InitializeCriticalSection SetThreadContext GetThreadContext ResumeThread SuspendThread WaitForMultipleObjects InterlockedCompareExchange HeapFree GetProcessHeap lstrlenW GetFileAttributesA GetFileAttributesW GetFileAttributesExW GetCurrentDirectoryW SetCurrentDirectoryW GetFileAttributesExA GetCurrentDirectoryA SetCurrentDirectoryA FindClose GetDiskFreeSpaceExW GetFullPathNameW RemoveDirectoryW DeleteFileW RaiseException |
---|---|
USER32.dll |
LoadStringA
RegisterClassA CreateWindowExA DefWindowProcA DestroyWindow LoadStringW |
ole32.dll |
CoSetProxyBlanket
CoGetInstanceFromFile CLSIDFromProgID CoCreateInstance CoInitialize CoInitializeEx CoInitializeSecurity CoUninitialize |
OLEAUT32.dll |
#2
#7 #6 #150 #35 #17 #77 #20 #19 #25 #161 #9 #12 #8 #202 #201 #200 #149 |
ADVAPI32.dll |
QueryServiceStatus
CreateServiceA ChangeServiceConfig2A StartServiceCtrlDispatcherA RegisterServiceCtrlHandlerA StartServiceA RegDeleteValueA OpenSCManagerA OpenServiceA ControlService DeleteService CloseServiceHandle RegDeleteKeyA RegCreateKeyA RegisterEventSourceA ReportEventA DeregisterEventSource SetServiceStatus GetUserNameA LookupAccountNameA IsValidSid GetLengthSid CopySid RegEnumValueA RegQueryInfoKeyA RegEnumKeyExA RegOpenKeyExA RegQueryValueExA RegCreateKeyExA RegSetValueExA RegCloseKey |
WS2_32.dll |
WSASend
WSARecv #5 WSAIoctl #3 #14 #8 #115 #10 #4 #7 #18 #151 #17 #16 #20 #19 #1 #13 #6 #2 #23 #21 #15 #112 #57 #11 #52 #111 #9 #22 |
VERSION.dll |
GetFileVersionInfoA
GetFileVersionInfoSizeA VerQueryValueA |
TaniumCryptoLibrary.dll |
?TaniumCryptosystem@@YAABVCryptosystem@@XZ
?SetConvertSigsToCryptoPPFlag@@YAX_N@Z ?InitializeTaniumCryptosystem@@YAABVCryptosystem@@PAV?$basic_istream@DU?$char_traits@D@std@@@std@@W4FIPSMode@CryptosystemPreferences@@W4PreferredCryptosystem@5@@Z |
WINMM.dll |
timeEndPeriod
timeBeginPeriod |
python27.dll (delay-loaded) |
PyThreadState_Delete
PyEval_ReleaseThread PyRun_StringFlags PyEval_AcquireThread PyThreadState_New PyUnicodeUCS2_AsUnicode PyUnicodeUCS2_AsUTF8String PyType_IsSubtype PyObject_GetAttrString PyDict_GetItemString PyString_AsString PyObject_Str PyErr_Fetch PyDict_Clear PyDict_SetItemString PyLong_FromVoidPtr PyDict_Copy PyModule_GetDict PyImport_AddModule Py_IsInitialized PyThreadState_Get PyEval_InitThreads Py_Initialize Py_SetPythonHome Py_InitModule4 PyErr_SetString PyString_FromStringAndSize PyEval_RestoreThread PyEval_SaveThread PyNumber_AsSsize_t PyLong_AsVoidPtr PyNumber_Check PyInt_FromSsize_t PyString_Size PyInt_AsLong PyString_FromString PyDict_Next |
Attributes | 0x1 |
---|---|
Name | python27.dll |
ModuleHandle | 0x4a41dc |
DelayImportAddressTable | 0x489520 |
DelayImportNameTable | 0x46aeb4 |
BoundDelayImportTable | 0x46b248 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.0.314.1540 |
ProductVersion | 6.0.314.1540 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
FileDescription | Tanium |
InternalName | Tanium |
FileVersion (#2) | 6.0.314.1540 |
LegalCopyright | Copyright (C) Tanium Inc. 2009-2016 |
ProductName | Tanium |
ProductVersion (#2) | 6.0.314.1540 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Aug-22 18:55:10 |
Version | 0.0 |
SizeofData | 137 |
AddressOfRawData | 0x40e750 |
PointerToRawData | 0x40d750 |
Referenced File | C:\Jenkins\workspace\Release6.0_Build\Platform\vs2008\out\release-6.0\Tanium_x86\RelWithDebInfo\TaniumSender.pdb |
StartAddressOfRawData | 0x8a7000 |
---|---|
EndAddressOfRawData | 0x8a7001 |
AddressOfIndex | 0x8a47b8 |
AddressOfCallbacks | 0x7d847c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x0075D9D0
|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x887d90 |
SEHandlerTable | 0x81a2c0 |
SEHandlerCount | 3980 |
XOR Key | 0x3af6c99a |
---|---|
Unmarked objects | 0 |
150 (20413) | 6 |
ASM objects (VS2008 SP1 build 30729) | 57 |
C++ objects (VS2008 build 21022) | 19 |
Imports (VS2008 SP1 build 30729) | 2 |
C objects (VS2008 SP1 build 30729) | 219 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 5 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 17 |
Total imports | 324 |
C++ objects (VS2008 SP1 build 30729) | 566 |
Linker (VS2008 build 21022) | 1 |
151 | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |