Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-May-25 08:59:35 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
D:\Jenkins\.jenkins\workspace\master_lu\diagnosetools\tcp_connecter\Release\Diagnose.pdb
|
FileDescription | 问题验证 |
FileVersion | 5.1022.1005.520 |
InternalName | Diagnose.tpi |
LegalCopyright | 版权所有(C)2008-2022 |
OriginalFilename | Diagnose.tpi |
ProductName | 问题验证 |
ProductVersion | 5.1022.1005.520 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to Blowfish |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Chengdu Qilu Technology Co. Ltd.
Issuer: DigiCert SHA2 Assured ID Code Signing CA |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2022-May-25 08:59:35 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5f000 |
SizeOfInitializedData | 0x2b400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000148AD (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x60000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x8d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x92d13 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
lstrcmpiW
CreateEventW LoadLibraryExW GetModuleFileNameW GetModuleHandleW DeleteFileW CreateMutexW GetPrivateProfileIntW SetEvent LeaveCriticalSection EnterCriticalSection InitializeCriticalSection SetLastError GetCurrentThreadId GetProcAddress FreeLibrary InterlockedDecrement InterlockedIncrement MultiByteToWideChar FindResourceExW FindResourceW CreateFileA GetSystemDirectoryW lstrcmpiA lstrcmpA DeviceIoControl CloseHandle SizeofResource LoadResource WaitForSingleObject GetExitCodeProcess LockResource DeleteCriticalSection InitializeCriticalSectionAndSpinCount GetLastError GetSystemWindowsDirectoryW FreeResource Sleep InterlockedCompareExchange WriteConsoleW ReadConsoleW SetEndOfFile SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP IsValidCodePage FindFirstFileExA EnumSystemLocalesW RaiseException GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc GetUserDefaultLCID IsValidLocale GetStdHandle HeapDestroy DecodePointer IsDebuggerPresent OutputDebugStringW EncodePointer InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList GetCurrentProcess FlushInstructionCache IsProcessorFeaturePresent VirtualAlloc VirtualFree LoadLibraryExA WideCharToMultiByte GetStringTypeW FormatMessageW SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount CompareStringW LCMapStringW GetLocaleInfoW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId LoadLibraryW GetVersionExW MapViewOfFile UnmapViewOfFile CreateFileMappingW OpenFileMappingW GetFileSizeEx ReadFile CreateFileW LocalFree ReleaseMutex WriteFile FlushFileBuffers WaitForMultipleObjects FindClose FindNextFileA RtlUnwind InterlockedFlushSList CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetModuleFileNameA GetFileType SetFilePointerEx GetConsoleCP GetConsoleMode GetTimeZoneInformation GetACP |
---|---|
USER32.dll |
CallWindowProcW
wsprintfW DefWindowProcW LoadCursorW SetWindowLongW CharNextW DestroyWindow IsWindow CreateWindowExW GetClassInfoExW RegisterClassExW PostMessageW PeekMessageW DispatchMessageW TranslateMessage GetMessageW UnregisterClassW SetTimer GetWindowLongW PostQuitMessage |
ADVAPI32.dll |
RegOpenKeyExA
RegEnumKeyExA GetTokenInformation OpenProcessToken RegSetValueExW RegQueryInfoKeyW RegOpenKeyExW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegCloseKey RegQueryValueExW RegQueryValueExA |
SHELL32.dll |
ShellExecuteExW
SHCreateDirectoryExW |
ole32.dll |
CoTaskMemFree
CoCreateGuid CoInitialize CoTaskMemRealloc CoTaskMemAlloc CoCreateInstance |
OLEAUT32.dll |
VarUI4FromStr
|
SHLWAPI.dll |
PathAppendW
PathFileExistsW PathIsDirectoryW PathCombineW PathRemoveFileSpecW StrStrIW StrStrIA StrCmpIW StrCmpNIW StrTrimA SHSetValueA SHGetValueA |
urlmon.dll |
URLDownloadToFileW
URLDownloadToCacheFileW |
VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
CRYPT32.dll |
CertGetNameStringW
|
WINTRUST.dll |
WinVerifyTrust
WTHelperProvDataFromStateData |
WININET.dll |
InternetGetConnectedState
|
IPHLPAPI.DLL |
GetAdaptersInfo
|
Ordinal | 1 |
---|---|
Address | 0x2920 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.1022.1005.520 |
ProductVersion | 5.1022.1005.520 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | Chinese - PRC |
FileDescription | 问题验证 |
FileVersion (#2) | 5.1022.1005.520 |
InternalName | Diagnose.tpi |
LegalCopyright | 版权所有(C)2008-2022 |
OriginalFilename | Diagnose.tpi |
ProductName | 问题验证 |
ProductVersion (#2) | 5.1022.1005.520 |
Resource LangID | Chinese - PRC |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-May-25 08:59:35 |
Version | 0.0 |
SizeofData | 113 |
AddressOfRawData | 0x7ba3c |
PointerToRawData | 0x7ae3c |
Referenced File | D:\Jenkins\.jenkins\workspace\master_lu\diagnosetools\tcp_connecter\Release\Diagnose.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-May-25 08:59:35 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x7bab0 |
PointerToRawData | 0x7aeb0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-May-25 08:59:35 |
Version | 0.0 |
SizeofData | 924 |
AddressOfRawData | 0x7bac4 |
PointerToRawData | 0x7aec4 |
StartAddressOfRawData | 0x1007be70 |
---|---|
EndAddressOfRawData | 0x1007be78 |
AddressOfIndex | 0x10086934 |
AddressOfCallbacks | 0x100603ac |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x10082188 |
SEHandlerTable | 0x1007b6c0 |
SEHandlerCount | 223 |
XOR Key | 0x75fc9e51 |
---|---|
Unmarked objects | 0 |
C objects (LTCG) (VS2017 v15.9.12-13 compiler 27031) | 2 |
Unmarked objects (#2) | 1 |
C++ objects (VS2017 v15.7.5 compiler 26433) | 10 |
241 (40116) | 17 |
243 (40116) | 159 |
242 (40116) | 30 |
C++ objects (VS2017 v15.9.14-15 compiler 27032) | 6 |
ASM objects (VS 2015/2017 runtime 26706) | 25 |
C objects (VS 2015/2017 runtime 26706) | 33 |
C++ objects (VS 2015/2017 runtime 26706) | 64 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 SP1 build 30729) | 27 |
Total imports | 239 |
C++ objects (VS2017 v15.9.12-13 compiler 27031) | 29 |
Exports (VS2017 v15.9.12-13 compiler 27031) | 1 |
Resource objects (VS2017 v15.9.12-13 compiler 27031) | 1 |
151 | 1 |
Linker (VS2017 v15.9.12-13 compiler 27031) | 1 |