Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Jan-08 09:39:28 |
Detected languages |
English - United States
|
Debug artifacts |
D:\ActivationTool\x64\Release\ActivationTool.pdb
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/70 (Scanned on 2021-02-27 09:20:03) | AhnLab-V3: HackTool/Win64.Activator.C4319446 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2021-Jan-08 09:39:28 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x324c00 |
SizeOfInitializedData | 0x203800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000002A1EC0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x52c000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetEnvironmentVariableW
GetCurrentProcessId TerminateProcess GetVersionExW GetModuleFileNameW LoadResource LockResource SizeofResource FindResourceW IsValidCodePage RtlCaptureContext GetCurrentThread SetCurrentDirectoryW GetFileType CopyFileW FindNextFileW FreeLibrary LoadLibraryW GetCommandLineW WriteFile SetEvent WaitForMultipleObjects IsBadReadPtr IsBadStringPtrA ExpandEnvironmentStringsW MulDiv GetStdHandle FreeConsole AttachConsole WriteConsoleA WriteConsoleW FillConsoleOutputCharacterW GetConsoleScreenBufferInfo SetConsoleCursorPosition ReadConsoleOutputCharacterA GlobalAlloc GlobalUnlock GlobalLock GlobalSize ResetEvent WaitForSingleObjectEx RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent GetStartupInfoW QueryPerformanceCounter InitializeSListHead RtlUnwindEx RtlPcToFileHeader RtlUnwind LoadLibraryExW GetModuleHandleExW SetStdHandle DeleteFileW FlushFileBuffers GetConsoleMode ReadConsoleW GetConsoleCP SetFilePointerEx GetDriveTypeW GetFullPathNameW MoveFileExW GetTimeZoneInformation GetFileSizeEx GetDateFormatW GetTimeFormatW EnumSystemLocalesW SetEndOfFile GetOEMCP SetEnvironmentVariableW GetCurrentDirectoryW GetEnvironmentStringsW FreeEnvironmentStringsW FindFirstFileExW GetCommandLineA GetCurrentThreadId ExitProcess GetCurrentProcess InitializeCriticalSection GetUserDefaultLCID IsValidLocale GetACP GetTempPathW GetTempFileNameW GetLongPathNameW GetFileTime GetFileAttributesW FindFirstFileW FindClose CreateFileW FormatMessageW SetErrorMode OutputDebugStringW IsDebuggerPresent GetCPInfo GetStringTypeW GetLocaleInfoW LCMapStringW CompareStringW EncodePointer LocalFree GetProcAddress GetModuleHandleW GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc SwitchToThread CreateEventW InitializeCriticalSectionAndSpinCount SetLastError LeaveCriticalSection EnterCriticalSection WideCharToMultiByte QueryPerformanceFrequency GetLogicalDriveStringsW CreateProcessW GetProcessHeap DeleteCriticalSection HeapDestroy DecodePointer HeapAlloc RaiseException CloseHandle HeapReAlloc GlobalFree GetLastError MultiByteToWideChar HeapSize WaitForSingleObject InitializeCriticalSectionEx PeekNamedPipe CreatePipe HeapFree ReadFile |
---|---|
USER32.dll |
PtInRect
GetParent SetParent GetWindow SetWindowsHookExW UnhookWindowsHookEx CallNextHookEx IsDialogMessageW SetScrollInfo GetScrollInfo SystemParametersInfoW CreateDialogParamW GetDlgItem DestroyCursor CreateIconIndirect IsMenu keybd_event GetWindowTextLengthW HideCaret DrawTextW DrawFocusRect DrawStateW SetRectEmpty CopyRect OffsetRect SetWindowRgn GetProcessDefaultLayout DestroyIcon GetComboBoxInfo FindWindowExW GetClassInfoW IsRectEmpty DrawIconEx GetWindowTextW MessageBeep SetRect GetClassNameW CreateAcceleratorTableW DestroyAcceleratorTable TranslateAcceleratorW GetDoubleClickTime GetCaretBlinkTime ValidateRgn GetMenuState CreateMenu CreatePopupMenu DestroyMenu GetSubMenu InsertMenuW AppendMenuW ModifyMenuW RemoveMenu SetMenuInfo InsertMenuItemW SetMenuItemInfoW GetMessageW ValidateRect GetWindowDC BeginPaint EndPaint UnionRect GetDesktopWindow ChildWindowFromPoint DrawEdge DrawFrameControl CheckMenuItem GetMenuItemID GetSysColorBrush CheckMenuRadioItem RegisterClipboardFormatW GetClipboardFormatNameW wsprintfW ChangeDisplaySettingsExW EnumDisplaySettingsW MonitorFromPoint MonitorFromWindow GetMonitorInfoW EnumDisplayMonitors IsClipboardFormatAvailable FillRect GetSysColor ChildWindowFromPointEx WindowFromPoint MapWindowPoints ScreenToClient ClientToScreen GetCursorPos SetCursorPos GetClientRect EnableScrollBar ScrollWindow RedrawWindow InvalidateRect GetUpdateRgn ReleaseDC GetDC UpdateWindow GetMenuItemInfoW TrackPopupMenu GetMenuItemCount GetSystemMetrics IsWindowEnabled EnableWindow ReleaseCapture SetCapture GetCapture MapVirtualKeyW VkKeyScanW GetAsyncKeyState GetFocus GetActiveWindow SetFocus IsWindowVisible EndDeferWindowPos DeferWindowPos BeginDeferWindowPos AnimateWindow IsWindow CallWindowProcW PostQuitMessage GetMessageTime GetMessagePos UnregisterHotKey RegisterHotKey TranslateMessage GetWindowRect SetMenu SetWindowLongW SetWindowTextW SetForegroundWindow EnableMenuItem GetSystemMenu DrawMenuBar GetDialogBaseUnits CreateDialogIndirectParamW IsZoomed IsIconic GetWindowPlacement SetWindowPos MoveWindow FlashWindowEx SetLayeredWindowAttributes ShowWindow GetIconInfo LoadImageW LoadIconW LoadBitmapW SetWindowLongPtrW GetWindowLongPtrW GetWindowLongW GetKeyState DdeFreeStringHandle DdeQueryStringW DdeCreateStringHandleW DdeGetLastError DdeFreeDataHandle DdeGetData DdeCreateDataHandle DdeClientTransaction DdeNameService DdePostAdvise DdeDisconnect DdeConnect DdeUninitialize DdeInitializeW LoadCursorW SetCursor KillTimer SetTimer MsgWaitForMultipleObjects DispatchMessageW DestroyWindow DefWindowProcW SendMessageW PeekMessageW BringWindowToTop CreateWindowExW RegisterClassW PostMessageW PostThreadMessageW MessageBoxW UnregisterClassW InflateRect RegisterWindowMessageW |
COMCTL32.dll |
ImageList_GetIconSize
ImageList_GetImageInfo ImageList_Replace ImageList_Draw #17 #16 ImageList_Create ImageList_Destroy ImageList_GetImageCount ImageList_Add ImageList_SetBkColor |
RPCRT4.dll |
UuidToStringW
RpcStringFreeW |
UxTheme.dll |
OpenThemeData
CloseThemeData DrawThemeBackground GetThemeBackgroundContentRect IsThemeBackgroundPartiallyTransparent GetThemeColor DrawThemeParentBackground GetThemeFont GetThemeMargins GetThemeBackgroundExtent SetWindowTheme GetCurrentThemeName IsThemeActive IsAppThemed GetThemePartSize GetThemeInt GetThemeSysColor GetThemeSysFont IsThemePartDefined |
WINHTTP.dll |
WinHttpSendRequest
WinHttpWriteData WinHttpGetProxyForUrl WinHttpGetIEProxyConfigForCurrentUser WinHttpCloseHandle WinHttpConnect WinHttpOpenRequest WinHttpReadData WinHttpQueryHeaders WinHttpAddRequestHeaders WinHttpOpen WinHttpReceiveResponse WinHttpSetTimeouts WinHttpQueryDataAvailable WinHttpSetOption WinHttpCrackUrl |
MSIMG32.dll |
AlphaBlend
GradientFill |
GDI32.dll |
ExcludeClipRect
CreateRectRgn RealizePalette SelectObject SelectPalette Rectangle GetTextMetricsW SetBrushOrgEx GdiFlush CreateCompatibleDC DeleteDC StretchBlt CombineRgn CreateFontIndirectW CreateRectRgnIndirect OffsetRgn RectInRegion SelectClipRgn SetTextColor SetBkColor GetObjectW Pie MaskBlt GetStockObject GetPixel GetObjectType GetClipBox Ellipse Arc ExtFloodFill CreatePatternBrush GetRegionData ExtCreateRegion GetWindowExtEx GetViewportExtEx PolyPolygon GetGraphicsMode CreateSolidBrush GetOutlineTextMetricsW GetDeviceCaps DeleteObject RoundRect GetSystemPaletteEntries EndPage StartPage SetBkMode BitBlt CreateBitmap CreateBitmapIndirect ExtSelectClipRgn SetGraphicsMode SetMapMode SetLayout GetLayout SetPixel SetPolyFillMode StretchDIBits SetROP2 SetStretchBltMode GetWorldTransform SetWorldTransform ModifyWorldTransform ExtTextOutW Polygon Polyline PolyBezier SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx GetBkColor LineTo MoveToEx EqualRgn GetRgnBox PtInRegion CreatePalette GetNearestPaletteIndex GetPaletteEntries GetTextExtentPoint32W CreateHatchBrush CreateDIBitmap GetDIBits CreateDIBSection GetDIBColorTable CreatePen ExtCreatePen GetCharABCWidthsW GetTextExtentExPointW CreateICW CreateDCW EnumFontFamiliesExW CloseEnhMetaFile CreateEnhMetaFileW DeleteEnhMetaFile GetEnhMetaFileW GetEnhMetaFileHeader PlayEnhMetaFile SetAbortProc StartDocW EndDoc CreateCompatibleBitmap |
WINSPOOL.DRV |
DocumentPropertiesW
ClosePrinter OpenPrinterW |
COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW PageSetupDlgW PrintDlgW ChooseFontW CommDlgExtendedError |
ADVAPI32.dll |
RegSetValueExW
RegQueryValueExW RegOpenKeyExW RegEnumValueW GetUserNameW RegCloseKey RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyW |
SHELL32.dll |
DragQueryPoint
ExtractIconExW DragAcceptFiles ShellExecuteExW SHGetFileInfoW #6 ExtractIconW DragQueryFileW SHGetFolderPathW CommandLineToArgvW DragFinish |
ole32.dll |
CoLockObjectExternal
RegisterDragDrop RevokeDragDrop OleSetClipboard OleGetClipboard OleFlushClipboard OleIsCurrentClipboard CoTaskMemAlloc CoTaskMemFree OleUninitialize ReleaseStgMedium OleInitialize CoCreateInstance |
SHLWAPI.dll |
SHAutoComplete
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jan-08 09:39:28 |
Version | 0.0 |
SizeofData | 73 |
AddressOfRawData | 0x402ee4 |
PointerToRawData | 0x401ee4 |
Referenced File | D:\ActivationTool\x64\Release\ActivationTool.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jan-08 09:39:28 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x402f30 |
PointerToRawData | 0x401f30 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jan-08 09:39:28 |
Version | 0.0 |
SizeofData | 964 |
AddressOfRawData | 0x402f44 |
PointerToRawData | 0x401f44 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jan-08 09:39:28 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x140403338 |
---|---|
EndAddressOfRawData | 0x14040334c |
AddressOfIndex | 0x140492198 |
AddressOfCallbacks | 0x1403288e8 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks | (EMPTY) |
Size | 0x130 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1404568d0 |
XOR Key | 0x61b219b6 |
---|---|
Unmarked objects | 0 |
ASM objects (26715) | 19 |
C++ objects (26715) | 212 |
199 (41118) | 1 |
C objects (VS 2015/2017/2019 runtime 28619) | 19 |
ASM objects (VS 2015/2017/2019 runtime 28619) | 12 |
C objects (VS2019 Update 6 (16.6.1-5) compiler 28806) | 23 |
C++ objects (VS2019 Update 6 (16.6.1-5) compiler 28806) | 295 |
C++ objects (VS 2015/2017/2019 runtime 28619) | 96 |
C objects (26715) | 33 |
262 (26715) | 1 |
Imports (26715) | 31 |
Total imports | 600 |
265 (VS2019 Update 6 (16.6.1-5) compiler 28806) | 8 |
Resource objects (VS2019 Update 6 (16.6.1-5) compiler 28806) | 1 |
151 | 1 |
Linker (VS2019 Update 6 (16.6.1-5) compiler 28806) | 1 |