| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Mar-10 01:37:02 |
| Detected languages |
English - United States
|
| TLS Callbacks | 3 callback(s) detected. |
| Suspicious | PEiD Signature: | HQR data file |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to Blowfish Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .qtmetad
Unusual section name found: .qtmimed |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/65 (Scanned on 2026-07-07 03:41:21) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 11 |
| TimeDateStamp | 2021-Mar-10 01:37:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xf89c00 |
| SizeOfInitializedData | 0x1742e00 |
| SizeOfUninitializedData | 0x1e00 |
| AddressOfEntryPoint | 0x00001480 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xf8b000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x174b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1746344 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
AccessCheck
AllocateAndInitializeSid BuildTrusteeWithSidW CopySid DuplicateToken FreeSid GetEffectiveRightsFromAclW GetLengthSid GetNamedSecurityInfoW GetTokenInformation LookupAccountSidW MapGenericMask OpenProcessToken RegCloseKey RegCreateKeyExW RegCreateKeyW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegFlushKey RegNotifyChangeKeyValue RegOpenKeyExW RegQueryInfoKeyW RegQueryValueExW RegSetValueExW SystemFunction036 |
|---|---|
| d3d9.dll |
Direct3DCreate9Ex
|
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmGetWindowAttribute DwmIsCompositionEnabled DwmSetWindowAttribute |
| dxva2.dll |
DXVA2CreateDirect3DDeviceManager9
|
| EVR.dll |
MFCreateVideoSampleFromSurface
|
| GDI32.dll |
AddFontMemResourceEx
AddFontResourceExW BitBlt ChoosePixelFormat CombineRgn CreateBitmap CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateFontIndirectW CreatePen CreateRectRgn CreateSolidBrush DeleteDC DeleteObject DescribePixelFormat EnumFontFamiliesExW ExtTextOutW GdiFlush GetBitmapBits GetCharABCWidthsFloatW GetCharABCWidthsW GetDIBits GetDeviceCaps GetFontData GetGlyphOutlineW GetObjectW GetOutlineTextMetricsW GetPixelFormat GetRegionData GetStockObject GetTextExtentPoint32W GetTextFaceW GetTextMetricsW OffsetRgn Rectangle RemoveFontMemResourceEx RemoveFontResourceExW SelectClipRgn SelectObject SetBkMode SetGraphicsMode SetLayout SetPixelFormat SetTextAlign SetTextColor SetWorldTransform SwapBuffers |
| IMM32.DLL |
ImmAssociateContext
ImmAssociateContextEx ImmGetCompositionStringW ImmGetContext ImmGetDefaultIMEWnd ImmGetOpenStatus ImmGetVirtualKey ImmNotifyIME ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionWindow |
| IPHLPAPI.DLL |
ConvertInterfaceIndexToLuid
ConvertInterfaceLuidToIndex ConvertInterfaceLuidToNameW ConvertInterfaceNameToLuidW GetAdaptersAddresses GetNetworkParams |
| KERNEL32.dll |
AddVectoredExceptionHandler
AreFileApisANSI CheckRemoteDebuggerPresent CloseHandle CompareStringEx CompareStringW CopyFileW CreateDirectoryW CreateEventA CreateEventW CreateFileA CreateFileMappingA CreateFileMappingW CreateFileW CreateMutexW CreateProcessW CreateSemaphoreA CreateThread DeleteCriticalSection DeleteFileA DeleteFileW DeviceIoControl DuplicateHandle EnterCriticalSection ExitProcess ExpandEnvironmentStringsW FileTimeToSystemTime FindClose FindCloseChangeNotification FindFirstChangeNotificationW FindFirstFileExW FindFirstFileW FindNextChangeNotification FindNextFileW FlushFileBuffers FlushViewOfFile FormatMessageA FormatMessageW FreeLibrary GetCommandLineW GetConsoleWindow GetCurrencyFormatW GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDiskFreeSpaceA GetDiskFreeSpaceW GetDriveTypeW GetExitCodeProcess GetExitCodeThread GetFileAttributesA GetFileAttributesExW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSize GetFileType GetFullPathNameA GetFullPathNameW GetGeoInfoW GetHandleInformation GetLastError GetLocalTime GetLocaleInfoW GetLogicalDrives GetLongPathNameW GetModuleFileNameW GetModuleHandleA GetModuleHandleExW GetModuleHandleW GetNativeSystemInfo GetProcAddress GetProcessAffinityMask GetProcessHeap GetStartupInfoA GetStartupInfoW GetSystemDirectoryW GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetTempPathA GetTempPathW GetThreadContext GetThreadPriority GetTickCount64 GetTickCount GetTimeFormatW GetTimeZoneInformation GetUserDefaultLCID GetUserDefaultLangID GetUserGeoID GetUserPreferredUILanguages GetVersionExA GetVersionExW GetVolumeInformationW GetVolumePathNamesForVolumeNameW GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock HeapAlloc HeapCompact HeapCreate HeapDestroy HeapFree HeapReAlloc HeapSize HeapValidate InitializeCriticalSection IsDBCSLeadByteEx IsDebuggerPresent LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryW LocalFree LockFile LockFileEx MapViewOfFile MoveFileExW MoveFileW MulDiv MultiByteToWideChar OpenProcess OutputDebugStringA OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException RaiseFailFastException ReadFile RegisterWaitForSingleObject ReleaseMutex ReleaseSemaphore RemoveDirectoryW RemoveVectoredExceptionHandler ResetEvent ResumeThread SetCurrentDirectoryW SetEndOfFile SetErrorMode SetEvent SetFileAttributesW SetFilePointer SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetProcessAffinityMask SetThreadContext SetThreadPriority SetUnhandledExceptionFilter Sleep SuspendThread SwitchToThread SystemTimeToFileTime TerminateProcess TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection TzSpecificLocalTimeToSystemTime UnhandledExceptionFilter UnlockFile UnlockFileEx UnmapViewOfFile UnregisterWaitEx VirtualAlloc VirtualFree VirtualProtect VirtualQuery WTSGetActiveConsoleSessionId WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteFile lstrcmpW |
| MF.dll |
MFGetService
|
| MFPlat.DLL |
MFCreateMediaType
MFFrameRateToAverageTimePerFrame |
| msvcrt.dll |
___mb_cur_max_func
__argc __doserrno __getmainargs __initenv __lconv_init __p___argv __p__acmdln __p__fmode __pioinfo __set_app_type __setusermatherr _amsg_exit _beginthreadex _cexit _close _endthreadex _errno _exit _filelengthi64 _fileno _get_osfhandle _getdrive _hypot _initterm _iob _lock _lseeki64 _onexit _open_osfhandle _putenv _read _setjmp3 _snwprintf _strdup _strnicmp _timezone _tzname _tzset _ultoa _unlock _vsnprintf _waccess _wchmod _wgetdcwd _wgetenv_s _write _write abort acos asin atan atof atoi bsearch calloc exit fclose feof ferror fflush fgetpos fgets fopen fprintf fputc fputs fread free gmtime frexp fseek fsetpos ftell fwprintf fwrite getc getenv islower ispunct isspace isupper iswctype isxdigit localeconv localtime log10 longjmp malloc memchr mktime memcmp memcpy memmove memset printf putc puts qsort raise rand realloc remove setlocale signal sprintf srand sscanf strcat strchr strcmp strcoll strcpy strcspn strerror strftime strlen strncmp strncpy strrchr strstr strtol strtoul strxfrm tan tolower toupper towlower towupper ungetc vfprintf wcscmp wcscoll wcscpy wcsftime wcslen wcsncmp wcsrchr wcsxfrm |
| NETAPI32.dll |
NetApiBufferFree
NetShareEnum |
| ODBC32.dll |
SQLAllocHandle
SQLBindParameter SQLCloseCursor SQLColAttributeW SQLColumnsW SQLDescribeColW SQLDisconnect SQLDriverConnectW SQLEndTran SQLExecDirectW SQLExecute SQLFetch SQLFetchScroll SQLFreeHandle SQLGetData SQLGetDiagRecW SQLGetFunctions SQLGetInfoW SQLGetStmtAttrW SQLGetTypeInfoW SQLMoreResults SQLNumResultCols SQLPrepareW SQLPrimaryKeysW SQLRowCount SQLSetConnectAttrW SQLSetEnvAttr SQLSetStmtAttrW SQLSpecialColumnsW SQLTablesW |
| ole32.dll |
CoCreateGuid
CoCreateInstance CoGetMalloc CoInitialize CoInitializeEx CoLockObjectExternal CoTaskMemAlloc CoTaskMemFree CoUninitialize CreateBindCtx DoDragDrop OleFlushClipboard OleGetClipboard OleInitialize OleIsCurrentClipboard OleSetClipboard OleUninitialize PropVariantClear RegisterDragDrop ReleaseStgMedium RevokeDragDrop StringFromCLSID StringFromGUID2 |
| OLEAUT32.dll |
SafeArrayCreateVector
SafeArrayPutElement SysAllocString SysFreeString SysStringLen VariantClear VariantInit |
| SHELL32.dll |
CommandLineToArgvW
SHBrowseForFolderW SHCreateItemFromIDList SHCreateItemFromParsingName SHFileOperationW SHGetFileInfoW SHGetKnownFolderIDList SHGetKnownFolderPath SHGetMalloc SHGetPathFromIDListW SHGetStockIconInfo ShellExecuteW Shell_NotifyIconGetRect Shell_NotifyIconW |
| USER32.dll |
AdjustWindowRectEx
AppendMenuW AttachThreadInput BeginPaint CallNextHookEx ChangeClipboardChain ChangeWindowMessageFilterEx CharNextExA ChildWindowFromPointEx ClientToScreen CloseTouchInputHandle CreateCaret CreateCursor CreateIconIndirect CreateMenu CreatePopupMenu CreateWindowExW DefWindowProcW DestroyCaret DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageW DrawIconEx DrawMenuBar EnableMenuItem EndPaint EnumDisplayDevicesW EnumDisplayMonitors EnumWindows FindWindowA FlashWindowEx GetAncestor GetAsyncKeyState GetCapture GetCaretBlinkTime GetClassInfoW GetClientRect GetClipboardFormatNameW GetCursor GetCursorInfo GetCursorPos GetDC GetDesktopWindow GetDoubleClickTime GetFocus GetForegroundWindow GetIconInfo GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardState GetMenu GetMenuItemInfoW GetMessageExtraInfo GetMonitorInfoW GetParent GetQueueStatus GetShellWindow GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTouchInputInfo GetUpdateRect GetWindow GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId HideCaret InsertMenuW InvalidateRect IsChild IsHungAppWindow IsIconic IsTouchWindow IsWindow IsWindowEnabled IsWindowVisible IsZoomed KillTimer LoadCursorW LoadIconW LoadImageW MapVirtualKeyW MessageBeep MessageBoxW ModifyMenuW MonitorFromPoint MonitorFromWindow MoveWindow MsgWaitForMultipleObjects MsgWaitForMultipleObjectsEx PeekMessageW PostMessageW PostThreadMessageW RealGetWindowClassW RegisterClassExW RegisterClassW RegisterClipboardFormatW RegisterDeviceNotificationW RegisterPowerSettingNotification RegisterTouchWindow RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu ScreenToClient SendMessageW SetCapture SetCaretPos SetClipboardViewer SetCursor SetCursorPos SetFocus SetForegroundWindow SetLayeredWindowAttributes SetMenu SetMenuItemInfoW SetParent SetTimer SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowCaret ShowWindow SystemParametersInfoW ToAscii ToUnicode TrackMouseEvent TrackPopupMenu TrackPopupMenuEx TranslateMessage UnhookWindowsHookEx UnregisterClassW UnregisterDeviceNotification UnregisterPowerSettingNotification UnregisterTouchWindow UpdateLayeredWindow UpdateLayeredWindowIndirect WindowFromPoint |
| USERENV.dll |
GetUserProfileDirectoryW
|
| UxTheme.dll |
CloseThemeData
DrawThemeBackgroundEx GetCurrentThemeName GetThemeBackgroundRegion GetThemeBool GetThemeColor GetThemeEnumValue GetThemeInt GetThemeMargins GetThemePartSize GetThemePropertyOrigin GetThemeTransitionDuration IsAppThemed IsThemeActive IsThemeBackgroundPartiallyTransparent OpenThemeData SetWindowTheme |
| VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
| WINMM.DLL |
PlaySoundW
mixerGetControlDetailsW mixerGetID mixerGetLineControlsW mixerGetLineInfoW mixerSetControlDetails timeBeginPeriod timeEndPeriod timeKillEvent timeSetEvent waveInAddBuffer waveInClose waveInGetDevCapsW waveInGetNumDevs waveInOpen waveInPrepareHeader waveInReset waveInStart waveInUnprepareHeader waveOutClose waveOutGetDevCapsW waveOutGetNumDevs waveOutOpen waveOutPause waveOutPrepareHeader waveOutReset waveOutRestart waveOutUnprepareHeader waveOutWrite |
| WS2_32.dll |
WSAAccept
WSAAsyncSelect WSACleanup WSAConnect WSAGetLastError WSAHtonl WSAIoctl WSANtohl WSANtohs WSARecv WSARecvFrom WSASend WSASendTo WSASocketW WSAStartup __WSAFDIsSet bind closesocket freeaddrinfo getaddrinfo gethostname getnameinfo getpeername getsockname getsockopt htonl htons listen ntohl select setsockopt |
| WTSAPI32.dll |
WTSFreeMemory
WTSQuerySessionInformationW |
| StartAddressOfRawData | 0x1afd000 |
|---|---|
| EndAddressOfRawData | 0x1afd004 |
| AddressOfIndex | 0x1af4c70 |
| AddressOfCallbacks | 0x1afc020 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00479DB0
0x00479D60 0x0049AE90 |
No comments yet.