| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2019-Apr-04 21:13:43 |
| Detected languages |
English - United States
|
| FileVersion | 1.1.30.03 |
| ProductVersion | 1.1.30.03 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource AUTOHOTKEY.EXE detected as a PE Executable. |
| Malicious | VirusTotal score: 5/69 (Scanned on 2024-03-18 09:07:59) |
Bkav:
W64.AIDetectMalware
CrowdStrike: win/malicious_confidence_70% (D) Jiangmin: Trojan.PSW.Predator.fk SentinelOne: Static AI - Suspicious PE VirIT: Trojan.Win64.Genus.DGW |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2019-Apr-04 21:13:43 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xc2c00 |
| SizeOfInitializedData | 0x17a000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000A5468 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x247000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WSOCK32.dll |
WSACleanup
inet_addr gethostbyname gethostname WSAStartup |
|---|---|
| WINMM.dll |
mixerSetControlDetails
waveOutGetVolume joyGetPosEx mixerGetControlDetailsW mixerOpen mixerGetDevCapsW mixerGetLineControlsW waveOutSetVolume mixerClose mciSendStringW joyGetDevCapsW mixerGetLineInfoW |
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
| COMCTL32.dll |
ImageList_Create
CreateStatusWindowW ImageList_ReplaceIcon ImageList_GetIconSize ImageList_Destroy ImageList_AddMasked |
| PSAPI.DLL |
GetModuleFileNameExW
GetProcessImageFileNameW GetModuleBaseNameW |
| KERNEL32.dll |
LockResource
FindFirstFileW FindNextFileW FindClose FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW WideCharToMultiByte MultiByteToWideChar GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess TerminateProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW GetDiskFreeSpaceW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW CreateDirectoryW ReadFile WriteFile DeleteFileW SetFileAttributesW LocalFileTimeToFileTime SetFileTime GetFileSizeEx GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetWindowsDirectoryW GetTempPathW GetFullPathNameW GetShortPathNameW EnterCriticalSection LeaveCriticalSection VirtualProtect LoadResource CompareStringW RemoveDirectoryW CopyFileW GetCurrentProcess FormatMessageW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize IsWow64Process VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount RtlUnwindEx RaiseException EncodePointer RtlPcToFileHeader InitializeSListHead QueryPerformanceCounter IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext CreateEventW WaitForSingleObjectEx ResetEvent SetEvent GetCommandLineW ExitProcess GetModuleHandleExW HeapSize HeapReAlloc HeapQueryInformation HeapFree HeapAlloc SizeofResource FindResourceW GetSystemTimeAsFileTime GetModuleFileNameW DeleteCriticalSection GetCPInfo GetVersionExW FreeLibrary LoadLibraryW GetModuleHandleW GetProcAddress GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread GetStringTypeExW lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock GetCurrentDirectoryW SetErrorMode InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount MulDiv TlsSetValue TlsFree LCMapStringW GetStringTypeW GetConsoleCP GetConsoleMode GetProcessHeap FindFirstFileExW IsValidCodePage GetCommandLineA GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers WriteConsoleW QueryDosDeviceW ReadConsoleW |
| USER32.dll |
RedrawWindow
SetWindowLongPtrW SetParent GetClassInfoExW GetAncestor UpdateWindow GetMessagePos GetClassLongPtrW DefDlgProcW CallWindowProcW CheckRadioButton IntersectRect GetUpdateRect PtInRect CreateDialogIndirectParamW GetWindowLongPtrW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu GetMenuItemInfoW CreateMenu CreatePopupMenu SetMenuInfo AppendMenuW DestroyMenu TrackPopupMenuEx GetDesktopWindow CopyImage CreateIconIndirect CreateIconFromResourceEx EnumClipboardFormats GetWindow BringWindowToTop MessageBoxW GetTopWindow MoveWindow GetQueueStatus GetWindowRect GetClientRect SystemParametersInfoW AdjustWindowRectEx DrawTextW SetRect GetIconInfo MapWindowPoints IsWindowVisible LoadImageW ChangeClipboardChain SetClipboardViewer LoadAcceleratorsW EnableMenuItem GetMenu CreateWindowExW RegisterClassExW LoadCursorW DestroyIcon DestroyWindow IsCharAlphaW MapVirtualKeyW ClientToScreen MapVirtualKeyExW GetKeyboardLayoutNameW ActivateKeyboardLayout GetGUIThreadInfo GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW ReleaseDC GetDC OpenClipboard GetClipboardData GetClipboardFormatNameW RemovePropW SetPropW GetPropW FlashWindow SetMenu ExitWindowsEx GetMenuStringW GetSubMenu GetMenuItemID GetMenuItemCount GetSystemMenu GetLastInputInfo SetWindowTextW GetCursor CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow MessageBeep SetDlgItemTextW GetDlgItem SendDlgItemMessageW DialogBoxParamW SetForegroundWindow DefWindowProcW FillRect DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW IsIconic IsZoomed EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetLayeredWindowAttributes SetWindowPos SetWindowRgn CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable SetFocus SetActiveWindow VkKeyScanExW EnumChildWindows CheckMenuItem |
| GDI32.dll |
GetPixel
GetClipRgn GetCharABCWidthsW SetBkMode CreatePatternBrush SetBrushOrgEx EnumFontFamiliesExW CreateDIBSection GdiFlush SetBkColor ExcludeClipRect SetTextColor GetClipBox BitBlt CreateCompatibleBitmap GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush CreateFontW FillRgn GetDeviceCaps DeleteObject |
| COMDLG32.dll |
CommDlgExtendedError
GetSaveFileNameW GetOpenFileNameW |
| ADVAPI32.dll |
RegDeleteKeyW
RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW RegDeleteValueW |
| SHELL32.dll |
DragQueryPoint
SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW ExtractIconW |
| ole32.dll |
OleInitialize
OleUninitialize CoCreateInstance CoInitialize CoUninitialize CLSIDFromString CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
| OLEAUT32.dll |
SafeArrayGetLBound
GetActiveObject SysStringLen OleLoadPicture SafeArrayUnaccessData SafeArrayGetElemsize SafeArrayAccessData SafeArrayUnlock SafeArrayPtrOfIndex SafeArrayLock SafeArrayGetDim SafeArrayDestroy SafeArrayGetUBound VariantCopyInd SafeArrayCopy SysAllocString VariantChangeType VariantClear SafeArrayCreate SysFreeString |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.30.3 |
| ProductVersion | 1.1.30.3 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 1.1.30.03 |
| ProductVersion (#2) | 1.1.30.03 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Apr-04 21:13:43 |
| Version | 0.0 |
| SizeofData | 948 |
| AddressOfRawData | 0xf083c |
| PointerToRawData | 0xef83c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Apr-04 21:13:43 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14010f000 |
|---|---|
| EndAddressOfRawData | 0x14010f008 |
| AddressOfIndex | 0x1401008f8 |
| AddressOfCallbacks | 0x1400c4f40 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x94 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400fd018 |
| XOR Key | 0xc5a45a01 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 19 |
| 243 (40116) | 140 |
| 242 (40116) | 23 |
| ASM objects (VS2015 UPD3 build 24123) | 8 |
| C++ objects (VS2015 UPD3 build 24123) | 40 |
| C objects (VS2015 UPD3 build 24123) | 20 |
| C objects (VS2008 SP1 build 30729) | 6 |
| 135 (VS2008 SP1 build 30729) | 1 |
| Imports (VS2008 SP1 build 30729) | 27 |
| Total imports | 462 |
| ASM objects (VS2015 UPD3 build 24210) | 2 |
| C++ objects (LTCG) (VS2015 UPD3.1 build 24215) | 42 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |
No comments yet.