| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Suspicious | PEiD Signature: |
Crunch/PE v5.0
PeStubOEP v1.x HQR data file |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to base58 Uses known Diffie-Helman primes |
| Suspicious | The PE is possibly packed. | Unusual section name found: .symtab |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Lambdatest
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0x8b |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0x11a1a00 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 3.0 |
| SizeOfCode | 0x7e9000 |
| SizeOfInitializedData | 0x1c4400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00077370 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xf77000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 1.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x11d8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x11af48b |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
WriteFile
WriteConsoleW WerSetFlags WerGetFlags WaitForMultipleObjects WaitForSingleObject VirtualQuery VirtualFree VirtualAlloc TlsAlloc SwitchToThread SuspendThread SetWaitableTimer SetUnhandledExceptionFilter SetProcessPriorityBoost SetEvent SetErrorMode SetConsoleCtrlHandler ResumeThread RaiseFailFastException PostQueuedCompletionStatus LoadLibraryW LoadLibraryExW SetThreadContext GetThreadContext GetSystemInfo GetSystemDirectoryA GetStdHandle GetQueuedCompletionStatusEx GetProcessAffinityMask GetProcAddress GetErrorMode GetEnvironmentStringsW GetCurrentThreadId GetConsoleMode FreeEnvironmentStringsW ExitProcess DuplicateHandle CreateWaitableTimerExW CreateThread CreateIoCompletionPort CreateEventA CloseHandle AddVectoredExceptionHandler |
|---|
No comments yet.