| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2014-Aug-31 15:34:44 |
| Detected languages |
English - United States
French - France Italian - Italy |
| Comments | http://nssm.cc/ |
| FileDescription | The non-sucking service manager |
| FileVersion | 2.24 |
| LegalCopyright | Public Domain; Author Iain Patterson 2003-2014 |
| ProductName | NSSM 32-bit |
| ProductVersion | 2.24 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/72 (Scanned on 2026-04-15 07:36:29) |
DrWeb:
Tool.Nssm.5
Rising: HackTool.NSSM!1.CABB (CLASSIC) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2014-Aug-31 15:34:44 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x1be00 |
| SizeOfInitializedData | 0x2be00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00013E53 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x55306 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| SHLWAPI.dll |
PathUnquoteSpacesW
PathFindExtensionW |
|---|---|
| KERNEL32.dll |
CreateThread
SetHandleInformation CreatePipe DuplicateHandle GetCommandLineW TlsAlloc GetProcessTimes OpenProcess Thread32Next Thread32First CreateToolhelp32Snapshot GenerateConsoleCtrlEvent SetConsoleCtrlHandler GetExitCodeProcess Process32NextW Process32FirstW SetCurrentDirectoryW GetCurrentDirectoryW GetWindowsDirectoryW DeleteCriticalSection UnregisterWait WaitForSingleObject LeaveCriticalSection SetWaitableTimer EnterCriticalSection ResumeThread SetProcessAffinityMask RegisterWaitForSingleObject GetSystemTimeAsFileTime CreateWaitableTimerW InitializeCriticalSection ReadFile CreateFileA WriteConsoleW GetConsoleOutputCP WriteConsoleA HeapSize RtlUnwind GetLocaleInfoA GetStringTypeW GetStringTypeA LCMapStringW LCMapStringA FlushFileBuffers GetConsoleMode GetConsoleCP WideCharToMultiByte VirtualAlloc HeapReAlloc GetTickCount QueryPerformanceCounter VirtualFree SetLastError HeapCreate SetStdHandle InitializeCriticalSectionAndSpinCount LoadLibraryA GetFileInformationByHandle Sleep SystemTimeToFileTime CloseHandle CompareFileTime FileTimeToSystemTime MoveFileW GetSystemTime CreateFileW SetFilePointer SetEndOfFile WriteFile FreeLibrary GetProcAddress LoadLibraryW GetCurrentProcess GetProcessAffinityMask FindResourceExW LoadResource GetModuleHandleW LocalFree TlsGetValue LocalAlloc TlsSetValue GetUserDefaultLangID FormatMessageW GetModuleFileNameW CreateProcessW TerminateProcess GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW ExpandEnvironmentStringsW AllocConsole SetConsoleTitleW GetStdHandle FillConsoleOutputAttribute FillConsoleOutputCharacterW GetConsoleWindow GetCurrentProcessId FreeConsole GetProcessHeap HeapAlloc GetComputerNameW HeapFree GetLastError GetCurrentThreadId TlsFree IsValidCodePage MultiByteToWideChar ExitProcess SetHandleCount GetFileType GetStartupInfoA UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetCPInfo InterlockedIncrement InterlockedDecrement GetACP GetOEMCP GetModuleFileNameA |
| USER32.dll |
EnumWindows
PostThreadMessageW PostMessageW LoadImageW SetWindowLongW GetMessageW IsDialogMessageW TranslateMessage DispatchMessageW DestroyWindow PostQuitMessage ShowWindow SetFocus GetWindowLongW CheckRadioButton SetWindowPos SetDlgItemInt SetDlgItemTextW SendMessageW GetDlgItemTextW GetDlgItem EnableWindow GetDlgItemInt SendDlgItemMessageW GetWindowRect GetDesktopWindow MoveWindow CreateDialogIndirectParamW MessageBoxW MessageBoxIndirectW GetSystemMenu EnableMenuItem GetWindowThreadProcessId GetSystemMetrics |
| COMDLG32.dll |
GetOpenFileNameW
|
| ADVAPI32.dll |
CreateServiceW
StartServiceW ControlService SetServiceStatus DeleteService QueryServiceConfig2W ChangeServiceConfig2W ChangeServiceConfigW QueryServiceConfigW OpenServiceW GetServiceKeyNameW EnumServicesStatusW OpenSCManagerW QueryServiceStatus RegDeleteKeyW RegOpenKeyExW RegQueryValueExW RegCloseKey RegCreateKeyExW RegSetValueExW StartServiceCtrlDispatcherW AllocateAndInitializeSid CheckTokenMembership RegDeleteValueW IsTextUnicode RegisterEventSourceW ReportEventW DeregisterEventSource GetServiceDisplayNameW CloseServiceHandle LsaEnumerateAccountRights LsaAddAccountRights FreeSid LsaLookupSids LsaClose LsaLookupNames LsaFreeMemory IsValidSid GetSidSubAuthorityCount GetSidLengthRequired GetSidIdentifierAuthority InitializeSid GetSidSubAuthority LsaOpenPolicy LsaNtStatusToWinError RegisterServiceCtrlHandlerExW |
| SHELL32.dll |
ShellExecuteExW
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.24.0.74 |
| ProductVersion | 2.24.0.74 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | http://nssm.cc/ |
| FileDescription | The non-sucking service manager |
| FileVersion (#2) | 2.24 |
| LegalCopyright | Public Domain; Author Iain Patterson 2003-2014 |
| ProductName | NSSM 32-bit |
| ProductVersion (#2) | 2.24 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x422760 |
| SEHandlerTable | 0x420230 |
| SEHandlerCount | 3 |
| XOR Key | 0xaa457e7 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 build 21022) | 17 |
| C objects (VS2008 build 21022) | 107 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 13 |
| Total imports | 219 |
| C++ objects (VS2008 build 21022) | 50 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 build 21022) | 1 |
No comments yet.