| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-Jun-05 14:15:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Francja\source\repos\sv_pureLevelBypass\x64\Release\sv_pureLevelBypass.pdb
|
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Malicious | VirusTotal score: 6/69 (Scanned on 2026-07-17 10:34:48) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_70% (W) Gridinsoft: Trojan.Win64.Agent.cl MaxSecure: Trojan.Malware.317832575.susgen McAfeeD: ti!389F4D5E8DB8 TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101GF26ZU |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-Jun-05 14:15:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xda00 |
| SizeOfInitializedData | 0x26200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000DB68 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x38000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteProcessMemory
GetConsoleScreenBufferInfo SetConsoleTitleA SetConsoleScreenBufferSize GetStdHandle SetConsoleMode Module32Next Module32First OpenProcess CreateToolhelp32Snapshot GetConsoleMode SetConsoleCursorInfo CloseHandle ReadProcessMemory GetConsoleWindow AllocConsole VirtualQueryEx GetModuleHandleW GetLastError MultiByteToWideChar Sleep RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent |
|---|---|
| USER32.dll |
GetWindowLongA
FindWindowA SetLayeredWindowAttributes GetWindowThreadProcessId SetWindowPos SetWindowLongA |
| MSVCP140.dll |
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ ??_7_Facet_base@std@@6B@ _Query_perf_frequency ??1_Lockit@std@@QEAA@XZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ ??0_Lockit@std@@QEAA@H@Z ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Xbad_alloc@std@@YAXXZ ?_Xout_of_range@std@@YAXPEBD@Z ?id@?$numpunct@D@std@@2V0locale@2@A ?_Xlength_error@std@@YAXPEBD@Z ??_7facet@locale@std@@6B@ _Query_perf_counter ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?_Getlconv@_Locinfo@std@@QEBAPEBUlconv@@XZ ?_Getfalse@_Locinfo@std@@QEBAPEBDXZ ?_Gettrue@_Locinfo@std@@QEBAPEBDXZ ??Bid@locale@std@@QEAA_KXZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z |
| VCRUNTIME140.dll |
memmove
memset __std_exception_destroy __std_exception_copy __C_specific_handler _CxxThrowException __current_exception __current_exception_context memcpy |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode _callnewh calloc free |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
freopen_s __acrt_iob_func _set_fmode |
| api-ms-win-crt-math-l1-1-0.dll |
_dsign
__setusermatherr _fdsign _ldsign |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
terminate _crt_atexit _register_onexit_function _initialize_onexit_table _seh_filter_exe _register_thread_local_exe_atexit_callback _c_exit _cexit __p___argv _invalid_parameter_noinfo_noreturn _set_app_type _exit exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-05 14:15:28 |
| Version | 0.0 |
| SizeofData | 108 |
| AddressOfRawData | 0x31cf0 |
| PointerToRawData | 0x30af0 |
| Referenced File | C:\Users\Francja\source\repos\sv_pureLevelBypass\x64\Release\sv_pureLevelBypass.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-05 14:15:28 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x31d5c |
| PointerToRawData | 0x30b5c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-05 14:15:28 |
| Version | 0.0 |
| SizeofData | 800 |
| AddressOfRawData | 0x31d70 |
| PointerToRawData | 0x30b70 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-05 14:15:28 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140034000 |
| XOR Key | 0x58071884 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 10 |
| ASM objects (33731) | 3 |
| C objects (33731) | 10 |
| C++ objects (33731) | 32 |
| Imports (33731) | 6 |
| Imports (30795) | 5 |
| Total imports | 177 |
| C++ objects (LTCG) (33808) | 1 |
| Resource objects (33808) | 1 |
| Linker (33808) | 1 |
No comments yet.