| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2096-Mar-14 04:00:21 |
| Detected languages |
English - United States
|
| Debug artifacts |
powershell.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Windows PowerShell |
| FileVersion | 10.0.19041.3996 (WinBuild.160101.0800) |
| InternalName | POWERSHELL |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | PowerShell.EXE |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.19041.3996 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 78.6427% of the executable. |
| Safe | VirusTotal score: 0/73 (Scanned on 2025-03-31 14:45:47) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2096-Mar-14 04:00:21 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x9600 |
| SizeOfInitializedData | 0x66200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000042A0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x72000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x798b4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| msvcrt.dll |
_unlock
_lock _commode _fmode _initterm __setusermatherr _cexit __dllonexit exit __set_app_type __wgetmainargs _amsg_exit _XcptFilter ?terminate@@YAXXZ ??1type_info@@UEAA@XZ memmove _exit _onexit _vsnwprintf _wcsicmp _wcsnicmp bsearch fclose _wfopen _itow_s wcstoul wcschr __uncaught_exception memcpy _CxxThrowException ?what@exception@@UEBAPEBDXZ ??1exception@@UEAA@XZ ??0exception@@QEAA@AEBV0@@Z ??0exception@@QEAA@AEBQEBDH@Z ??0exception@@QEAA@AEBQEBD@Z _callnewh malloc wcsncmp wcsrchr free _purecall ??3@YAXPEAX@Z memcpy_s ??_V@YAXPEAX@Z __C_specific_handler __CxxFrameHandler3 memset |
|---|---|
| ATL.DLL |
#30
|
| KERNEL32.dll |
UnmapViewOfFile
GetVersionExW GetLocaleInfoW GetUserDefaultUILanguage GetSystemDefaultUILanguage SearchPathW FindResourceExW GetTickCount GetSystemTimeAsFileTime GetCurrentThreadId QueryPerformanceCounter LoadResource SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive CreateFileMappingW IsWow64Process SetConsoleTitleW GetFileType FreeLibrary TerminateProcess GetStartupInfoW VerifyVersionInfoW FindFirstFileW MapViewOfFile LoadLibraryExW CompareStringW GetModuleHandleW SetLastError GetModuleHandleExW GetCurrentProcess GetStdHandle WriteFile GetCurrentProcessId ExpandEnvironmentStringsW VerSetConditionMask LocalFree WriteConsoleW GetModuleFileNameW SetThreadUILanguage K32GetModuleFileNameExW GetProcAddress SetErrorMode FindClose CreateFileW GetFileAttributesW OpenProcess CreateToolhelp32Snapshot Sleep FormatMessageW Process32FirstW CloseHandle GetLastError Process32NextW |
| OLEAUT32.dll |
SysFreeString
SafeArrayPutElement SysAllocString VariantClear SafeArrayCreate SysStringLen |
| ADVAPI32.dll |
EventRegister
RegEnumKeyExW RegOpenKeyExW RegGetValueW EventUnregister EventWriteTransfer RegCloseKey RegQueryValueExW EventSetInformation |
| OLE32.dll |
CoInitialize
PropVariantClear CoTaskMemAlloc CoUninitialize CoCreateInstance CoInitializeEx |
| USER32.dll |
LoadStringW
|
| mscoree.dll |
CorBindToRuntimeEx
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.19041.3996 |
| ProductVersion | 10.0.19041.3996 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows PowerShell |
| FileVersion (#2) | 10.0.19041.3996 (WinBuild.160101.0800) |
| InternalName | POWERSHELL |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | PowerShell.EXE |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.19041.3996 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2096-Mar-14 04:00:21 |
| Version | 0.0 |
| SizeofData | 39 |
| AddressOfRawData | 0x14934 |
| PointerToRawData | 0x13334 |
| Referenced File | powershell.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2096-Mar-14 04:00:21 |
| Version | 0.0 |
| SizeofData | 1120 |
| AddressOfRawData | 0x1495c |
| PointerToRawData | 0x1335c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2096-Mar-14 04:00:21 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x14dbc |
| PointerToRawData | 0x137bc |
| StartAddressOfRawData | 0x140014de0 |
|---|---|
| EndAddressOfRawData | 0x140014de8 |
| AddressOfIndex | 0x140017c40 |
| AddressOfCallbacks | 0x14000ee30 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x118 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140017648 |
| GuardCFCheckFunctionPointer | 5368769976 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xce6fcf17 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 build 21022) | 2 |
| Imports (VS2008 SP1 build 30729) | 10 |
| ASM objects (27412) | 2 |
| C objects (27412) | 27 |
| Total imports | 139 |
| Imports (27412) | 5 |
| C++ objects (27412) | 9 |
| C objects (POGO O) (27412) | 9 |
| Resource objects (27412) | 1 |
| Linker (27412) | 1 |