| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Nov-05 12:09:55 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
D:\sources\java\HMCL\HMCLauncher\Release\HMCLauncher.pdb
|
| CompanyName | huanghongxun |
| FileDescription | Hello Minecraft! Launcher For Windows |
| FileVersion | 3.5.0.0 |
| InternalName | HMCL.exe |
| LegalCopyright | Copyright (C) 2021 huangyuhui |
| OriginalFilename | HMCL.exe |
| ProductName | Hello Minecraft! Launcher |
| ProductVersion | 3.5.0.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
4811750 bytes of data starting at offset 0x18600.
The overlay data has an entropy of 7.96472 and is possibly compressed or encrypted. Overlay data amounts for 97.9673% of the executable. |
| Malicious | VirusTotal score: 26/71 (Scanned on 2024-06-19 11:05:43) |
ALYac:
Trojan.GenericKD.72786229
Antiy-AVL: Trojan/Win32.SGeneric Arcabit: Trojan.Generic.D456A135 BitDefender: Trojan.GenericKD.72786229 Cybereason: malicious.10ef68 Cylance: Unsafe DeepInstinct: MALICIOUS Elastic: malicious (moderate confidence) Emsisoft: Trojan.GenericKD.72786229 (B) FireEye: Trojan.GenericKD.72786229 Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.72786229 Jiangmin: Trojan.Starter.fi Lionic: Trojan.Win32.Generic.4!c MAX: malware (ai score=84) Malwarebytes: Malware.AI.3982725161 MaxSecure: Win.MxResIcn.Heur.Gen McAfee: Artemis!B03269510EF6 McAfeeD: ti!2FD35ED72F3E MicroWorld-eScan: Trojan.GenericKD.72786229 Sangfor: Trojan.Win32.Agent.V98u TrendMicro-HouseCall: TROJ_GEN.R002H09EM24 VIPRE: Trojan.GenericKD.72786229 Webroot: W32.Malware.Gen Zillya: Trojan.Agent.Win32.3270555 alibabacloud: Suspicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2022-Nov-05 12:09:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe400 |
| SizeOfInitializedData | 0xa800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000037ED (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x10000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
|---|---|
| KERNEL32.dll |
FindClose
GetUserDefaultUILanguage VerSetConditionMask VerifyVersionInfoW GetNativeSystemInfo GetModuleFileNameW FindNextFileW GetEnvironmentVariableW CreateProcessW GetConsoleMode GetConsoleCP FlushFileBuffers FindFirstFileW SetFilePointerEx WriteConsoleW DecodePointer GetLastError TlsGetValue HeapReAlloc HeapSize GetProcessHeap GetStringTypeW GetFileType UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind RaiseException SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc CreateFileW TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW ExitProcess GetModuleHandleExW GetStdHandle WriteFile MultiByteToWideChar WideCharToMultiByte GetACP LCMapStringW HeapAlloc CloseHandle HeapFree FindFirstFileExW IsValidCodePage GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle |
| USER32.dll |
MessageBoxW
|
| ADVAPI32.dll |
RegCloseKey
RegEnumKeyExW RegQueryInfoKeyW RegOpenKeyExW RegQueryValueExW |
| SHELL32.dll |
ShellExecuteW
SHGetFolderPathW |
| Ordinal | 1 |
|---|---|
| Address | 0x1779c |
| Ordinal | 2 |
|---|---|
| Address | 0x177a0 |
| HMCL |
| HMCL |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.4.0.0 |
| ProductVersion | 3.4.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Chinese - PRC |
| CompanyName | huanghongxun |
| FileDescription | Hello Minecraft! Launcher For Windows |
| FileVersion (#2) | 3.5.0.0 |
| InternalName | HMCL.exe |
| LegalCopyright | Copyright (C) 2021 huangyuhui |
| OriginalFilename | HMCL.exe |
| ProductName | Hello Minecraft! Launcher |
| ProductVersion (#2) | 3.5.0.0 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-05 12:09:55 |
| Version | 0.0 |
| SizeofData | 81 |
| AddressOfRawData | 0x15734 |
| PointerToRawData | 0x13f34 |
| Referenced File | D:\sources\java\HMCL\HMCLauncher\Release\HMCLauncher.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-05 12:09:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x15788 |
| PointerToRawData | 0x13f88 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-05 12:09:55 |
| Version | 0.0 |
| SizeofData | 764 |
| AddressOfRawData | 0x1579c |
| PointerToRawData | 0x13f9c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Nov-05 12:09:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x417004 |
| SEHandlerTable | 0x415710 |
| SEHandlerCount | 9 |
| XOR Key | 0xb8e80c4c |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 10 |
| 243 (40116) | 123 |
| 242 (40116) | 24 |
| C objects (VS 2015/2017 runtime 26706) | 17 |
| ASM objects (VS 2015/2017 runtime 26706) | 18 |
| C++ objects (VS 2015/2017 runtime 26706) | 41 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 105 |
| C++ objects (LTCG) (27045) | 5 |
| Exports (27045) | 1 |
| Resource objects (27045) | 1 |
| 151 | 1 |
| Linker (27045) | 1 |
No comments yet.