| Architecture |
UNKNOWN
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Jun-20 16:57:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\__w\1\s\exe\arm64\Release\Procmon64a.pdb
|
| CompanyName | Sysinternals - www.sysinternals.com |
| FileDescription | Process Monitor |
| FileVersion | 4.01 |
| InternalName | Process Monitor |
| LegalCopyright | Copyright © 1996-2024 Mark Russinovich |
| OriginalFilename | Process Monitor |
| ProductName | Sysinternals Procmon |
| ProductVersion | 4.01 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource RCDRIVERNT detected as a PE Executable. |
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2011 |
| Safe | VirusTotal score: 0/61 (Scanned on 2026-05-24 05:01:31) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
UNKNOWN
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-Jun-20 16:57:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xf7800 |
| SizeOfInitializedData | 0x135a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000C1130 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x231000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x21ec6f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WS2_32.dll |
getsockname
listen recv closesocket socket gethostbyname WSAGetLastError ntohs WSAStartup htonl inet_addr inet_ntoa bind connect htons accept send gethostbyaddr WSASetLastError getservbyname getservbyport |
|---|---|
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| COMCTL32.dll |
ImageList_ReplaceIcon
ImageList_SetBkColor ImageList_AddMasked ImageList_BeginDrag ImageList_EndDrag ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock ImageList_GetImageCount ImageList_DrawIndirect CreateStatusWindowW ImageList_SetOverlayImage InitCommonControlsEx ImageList_Add ImageList_Draw ImageList_GetIcon ImageList_DrawEx ImageList_GetIconSize ImageList_Destroy ImageList_Create |
| FLTLIB.DLL |
FilterSendMessage
FilterConnectCommunicationPort FilterGetMessage FilterReplyMessage |
| KERNEL32.dll |
AcquireSRWLockExclusive
AcquireSRWLockShared InitializeSRWLock GetSystemInfo VerSetConditionMask RaiseException GetCurrentThreadId VerifyVersionInfoW GlobalAddAtomW EnumResourceNamesW SetCurrentDirectoryW CreateProcessW OpenProcess CompareStringW GetLocaleInfoW VirtualQuery lstrcmpW lstrcmpiW MultiByteToWideChar GetFileSize SetEndOfFile SetFilePointer TryEnterCriticalSection VirtualAlloc CreateFileMappingW MapViewOfFile UnmapViewOfFile FileTimeToLocalFileTime LocalFileTimeToFileTime ReadFile FormatMessageW FileTimeToSystemTime SystemTimeToFileTime GetDateFormatW GetTimeFormatW ReleaseSRWLockExclusive QueryPerformanceCounter QueryPerformanceFrequency HeapCreate SetEvent ResetEvent ReleaseSemaphore CreateEventW WaitForMultipleObjects CreateSemaphoreW ExitProcess SetThreadPriority GetComputerNameA GetFileAttributesExW DecodePointer GetCurrentProcessId SetProcessShutdownParameters VirtualFree GetComputerNameW SetConsoleCtrlHandler OpenThread GetThreadContext GetSystemDirectoryA TrySubmitThreadpoolCallback LoadLibraryA FindClose FindFirstFileW FindNextFileW GetEnvironmentVariableW SetEnvironmentVariableW InterlockedPushEntrySList InterlockedPopEntrySList EncodePointer OutputDebugStringW IsDebuggerPresent InitializeSListHead GetStartupInfoW SetUnhandledExceptionFilter SleepConditionVariableSRW WakeAllConditionVariable GetStringTypeW LCMapStringEx GetCPInfo RtlPcToFileHeader RtlLookupFunctionEntry RtlUnwindEx FlsAlloc FlsGetValue FlsSetValue FlsFree TerminateProcess GetModuleHandleExW GetConsoleCP VirtualProtect ExitThread FreeLibraryAndExitThread InitializeCriticalSectionAndSpinCount LCMapStringW GetSystemDirectoryW GetCurrentProcess SetFileAttributesW GetCurrentDirectoryW ExpandEnvironmentStringsW InitializeCriticalSection DeleteCriticalSection InitializeCriticalSectionEx GetLastError GetTickCount64 GetTickCount GetSystemTimeAsFileTime GetCurrentThread CreateThread Sleep WaitForSingleObject FreeResource GlobalMemoryStatusEx GetFullPathNameW lstrlenW MulDiv LoadLibraryW FreeLibrary GetThreadId LeaveCriticalSection EnterCriticalSection CloseHandle GetTempPathW WriteFile GetTempFileNameW DeleteFileW CreateFileW GetModuleFileNameW ReleaseSRWLockShared GetPrivateProfileStringW GetPrivateProfileIntW FindResourceW SizeofResource LockResource LoadResource FindResourceExW GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc HeapDestroy GetFileAttributesW GlobalLock GlobalUnlock GlobalAlloc LocalFree LocalAlloc GetProcAddress GetModuleHandleW GetFileType GetCommandLineW GetStdHandle LoadLibraryExW GetVersionExW SetLastError GetUserDefaultLCID EnumSystemLocalesW GetConsoleMode SetConsoleMode ReadConsoleInputW ReadConsoleW GetConsoleOutputCP GetFileSizeEx SetFilePointerEx FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers WriteConsoleW FlushInstructionCache LoadLibraryExA WideCharToMultiByte GetNumberFormatW IsValidLocale |
| USER32.dll |
FlashWindowEx
LoadStringA DrawEdge GetMessageW TranslateMessage DispatchMessageW PeekMessageW GetMessagePos PostQuitMessage GetWindowPlacement SetWindowPlacement CheckRadioButton CharLowerW CreatePopupMenu RemoveMenu InsertMenuItemW SetRectEmpty ChildWindowFromPoint CheckMenuRadioItem SetRect WindowFromPoint ClientToScreen AdjustWindowRectEx SetMenuDefaultItem GetMenuItemInfoW DeleteMenu AppendMenuW GetMenuItemCount GetMenuItemID GetSubMenu EnableMenuItem LoadMenuW TranslateAcceleratorW LoadAcceleratorsW ReleaseCapture SetCapture GetCapture SetFocus GetDlgCtrlID SetDlgItemInt CreateDialogParamW EndDeferWindowPos DeferWindowPos BeginDeferWindowPos GetClassInfoExW RegisterClassExW TrackMouseEvent MonitorFromPoint MapWindowPoints GetCursor GetCursorPos GetFocus LoadStringW LoadIconW MessageBeep GetPropW SetPropW SetActiveWindow UnregisterClassW GetDesktopWindow DialogBoxParamW GetWindow MessageBoxW EnableWindow CheckDlgButton GetDlgItemTextW DestroyWindow IsWindow GetWindowRect EqualRect GetMenuStringW GetWindowModuleFileNameW GetMonitorInfoW MonitorFromWindow SystemParametersInfoW GetScrollInfo SetScrollInfo DestroyIcon CallNextHookEx UnhookWindowsHookEx SetWindowsHookExW GetClassNameW GetParent SetClassLongPtrW SetWindowLongPtrW GetWindowLongPtrW SetWindowLongW GetWindowLongW PtInRect OffsetRect CopyRect FrameRect FillRect DrawFocusRect ScreenToClient GetClientRect GetWindowTextLengthW GetWindowTextW ShowScrollBar SetScrollPos RedrawWindow InvalidateRect EndPaint BeginPaint ReleaseDC GetWindowDC GetDC UpdateWindow DrawTextW GetSystemMetrics IsWindowEnabled GetClassLongPtrW IntersectRect ScrollWindowEx ValidateRect GetUpdateRgn GetUpdateRect GetKeyState CreateIconIndirect GetForegroundWindow SetMenuInfo GetMenuInfo TrackPopupMenuEx KillTimer SetTimer IsZoomed IsWindowVisible SetWindowPos MoveWindow ShowWindow IsChild CreateWindowExW CallWindowProcW DefWindowProcW PostMessageW SetMenu GetMenu CharNextW IsMenu GetWindowThreadProcessId FindWindowExW FindWindowW SetForegroundWindow IsIconic WaitForInputIdle CreateIconFromResourceEx GetDlgItemInt GetActiveWindow RegisterWindowMessageW GetAsyncKeyState SetWindowTextA EnumChildWindows ModifyMenuW SetDlgItemTextW InsertMenuW GetIconInfo DrawIconEx LoadImageW GetSysColor SetMenuItemInfoW DestroyMenu EmptyClipboard SetClipboardData CloseClipboard OpenClipboard LoadCursorW InflateRect GetSysColorBrush SetCursor SetWindowTextW GetDlgItem EndDialog DialogBoxIndirectParamW SendMessageW UnionRect DrawFrameControl GetAncestor IsDialogMessageW IsDlgButtonChecked |
| GDI32.dll |
CreateBitmapIndirect
GetDIBits CreateRectRgn CreateRectRgnIndirect GetBkMode RectInRegion GdiFlush CreatePatternBrush ExcludeClipRect GetPixel PatBlt SetPixel SetBrushOrgEx RestoreDC SaveDC SetROP2 GetTextMetricsW CreateFontW GetObjectW GetBitmapBits GetBkColor CreateDIBSection Polyline CreateBitmap SelectClipRgn GetCurrentObject TextOutW MoveToEx SetTextAlign SetTextColor SetBkMode Rectangle LineTo GetTextExtentPoint32W GetStockObject CreatePen CreateFontIndirectW CreateSolidBrush SetViewportOrgEx ExtTextOutW SetBkColor SelectObject DeleteObject DeleteDC CreateCompatibleDC CreateCompatibleBitmap BitBlt EndPage StartPage EndDoc StartDocW Polygon GetDeviceCaps SetMapMode |
| COMDLG32.dll |
GetSaveFileNameW
ChooseColorW ChooseFontW FindTextW GetOpenFileNameW PrintDlgW |
| ADVAPI32.dll |
ConvertStringSidToSidW
ConvertSidToStringSidW RegSetValueW RegEnumKeyW LookupAccountSidW MapGenericMask GetTokenInformation GetLengthSid FreeSid EqualSid AllocateAndInitializeSid RegQueryInfoKeyW RegEnumValueW RegEnumKeyExW RegCreateKeyExW RegDeleteValueW RegDeleteKeyW LookupPrivilegeValueW AdjustTokenPrivileges OpenProcessToken RegGetValueW RegSetValueExW RegQueryValueExW RegOpenKeyExW RegOpenKeyW RegCreateKeyW RegCloseKey |
| SHELL32.dll |
SHGetSpecialFolderLocation
ExtractIconExW SHGetPathFromIDListW CommandLineToArgvW SHChangeNotify SHBrowseForFolderW SHGetMalloc DragQueryFileW ShellExecuteExW SHGetFileInfoW ShellExecuteW |
| ole32.dll |
CoTaskMemFree
RegisterDragDrop ReleaseStgMedium CoTaskMemRealloc OleUninitialize CreateBindCtx OleInitialize CoTaskMemAlloc CoCreateInstance CoSetProxyBlanket CoInitializeEx |
| OLEAUT32.dll |
SysAllocStringLen
VariantTimeToSystemTime VarUI4FromStr SysAllocStringByteLen VariantChangeType VariantClear VariantInit SafeArrayGetElement SafeArrayUnaccessData SafeArrayAccessData SafeArrayGetLBound SafeArrayGetUBound SafeArrayDestroy SysStringLen SysFreeString SysAllocString |
| SHLWAPI.dll |
SHAutoComplete
|
| UxTheme.dll |
IsThemeActive
SetWindowTheme IsAppThemed IsCompositionActive |
| dwmapi.dll |
DwmSetWindowAttribute
DwmDefWindowProc |
| ntdll.dll |
RtlGetVersion
|
| Process Monitor - Sysinternals: www.sysinternals.com |
| Save (Ctrl+S) |
| Save (Ctrl+S) |
| High Resolution Date & Time |
| Capture (Ctrl+E) |
| Capture (Ctrl+E) |
| Autoscroll (Ctrl+A) |
| Autoscroll (Ctrl+A) |
| Clear (Ctrl+X) |
| Clear (Ctrl+X) |
| Show Process Tree |
| Process Tree |
| Filter (Ctrl+L) |
| Filter (Ctrl+L) |
| Find (Ctrl+F) |
| Find (Ctrl+F) |
| Open |
| Open |
| Event Properties |
| Event Properties |
| Show File System Activity |
| Show File System Activity |
| Show Registry Activity |
| Show Registry Activity |
| Show Network Activity |
| Show Network Activity |
| Show Process and Thread Activity |
| Show Process and Thread Activity |
| Highlight (Ctrl+H) |
| Highlight (Ctrl+H) |
| Show Profiling Events |
| Show Profiling Events |
| Include Process From Window |
| Include Process From Window |
| Jump to Object (Ctrl+J) |
| Jump to Object (Ctrl+J) |
| Date & Time |
| Process Name |
| PID |
| Operation |
| Result |
| Detail |
| Sequence |
| Object Reference |
| Company |
| Description |
| Command Line |
| User |
| Image Path |
| Session |
| Event Complete |
| Path |
| TID |
| Image Load |
| Frame |
| Address |
| Relative Time |
| Duration |
| Time of Day |
| Module |
| Location |
| Version |
| Event Class |
| Authentication ID |
| Virtualized |
| Integrity |
| Category |
| Parent PID |
| Architecture |
| Completion Time |
| Process Start |
| High Resolution Process Start |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.1.0.0 |
| ProductVersion | 4.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Sysinternals - www.sysinternals.com |
| FileDescription | Process Monitor |
| FileVersion (#2) | 4.01 |
| InternalName | Process Monitor |
| LegalCopyright | Copyright © 1996-2024 Mark Russinovich |
| OriginalFilename | Process Monitor |
| ProductName | Sysinternals Procmon |
| ProductVersion (#2) | 4.01 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-20 16:57:31 |
| Version | 0.0 |
| SizeofData | 68 |
| AddressOfRawData | 0x13468c |
| PointerToRawData | 0x13328c |
| Referenced File | C:\__w\1\s\exe\arm64\Release\Procmon64a.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-20 16:57:31 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1346d0 |
| PointerToRawData | 0x1332d0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-20 16:57:31 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0x1346e4 |
| PointerToRawData | 0x1332e4 |
| StartAddressOfRawData | 0x140134b20 |
|---|---|
| EndAddressOfRawData | 0x140134b38 |
| AddressOfIndex | 0x14016f6e8 |
| AddressOfCallbacks | 0x1400fa3e8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140157080 |
| GuardCFCheckFunctionPointer | 5369733464 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xc3ba0bcb |
|---|---|
| Unmarked objects | 0 |
| C++ objects (30795) | 182 |
| Unmarked objects (#2) | 1 |
| C++ objects (33218) | 94 |
| C objects (33218) | 18 |
| ASM objects (33218) | 13 |
| ASM objects (30795) | 3 |
| C objects (30795) | 22 |
| Total imports | 562 |
| Imports (30795) | 33 |
| C objects (33523) | 2 |
| C++ objects (33523) | 73 |
| Resource objects (33523) | 1 |
| 151 | 1 |
| Linker (33523) | 1 |
No comments yet.