| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Dec-04 22:50:58 |
| Detected languages |
English - United States
|
| CompanyName | Don HO don.h@free.fr |
| FileDescription | Notepad++ |
| FileVersion | 8.7.4 |
| InternalName | notepad++.exe |
| LegalCopyright | Copyleft 1998-2023 by Don HO |
| OriginalFilename | notepad++.exe |
| ProductName | Notepad++ |
| ProductVersion | 8.7.4 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Notepad\+\+
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-05 02:35:46) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2024-Dec-04 22:50:58 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x471c00 |
| SizeOfInitializedData | 0x3acc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000041D3BC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x822000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x827acb |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
ImageList_GetIconSize
ImageList_Draw ImageList_EndDrag ImageList_DragShowNolock ImageList_DragEnter ImageList_DragMove ImageList_BeginDrag ImageList_Remove #17 ImageList_SetIconSize ImageList_AddMasked InitCommonControlsEx ImageList_GetIcon ImageList_Destroy ImageList_Create ImageList_ReplaceIcon _TrackMouseEvent #381 #412 #411 #410 ImageList_GetImageInfo #413 |
|---|---|
| SHLWAPI.dll |
AssocQueryStringW
ColorRGBToHLS PathStripPathW PathAddExtensionW PathAppendW ColorAdjustLuma PathRemoveExtensionW PathCombineW PathIsRelativeW PathFindFileNameW PathCompactPathExW PathGetDriveNumberW PathMatchSpecW PathFindExtensionW PathIsNetworkPathW PathRemoveFileSpecW ColorHLSToRGB |
| SHELL32.dll |
SHCreateItemFromParsingName
SHFileOperationW DragQueryFileW DragQueryPoint DragFinish ShellExecuteW #165 SHGetFolderPathW Shell_NotifyIconW |
| dbghelp.dll |
ImageNtHeader
|
| VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW VerQueryValueW |
| CRYPT32.dll |
CertNameToStrW
CertGetCertificateContextProperty CertGetNameStringW CertFindCertificateInStore CryptMsgGetParam CertCloseStore CryptQueryObject CryptMsgClose |
| WINTRUST.dll |
WinVerifyTrust
|
| SensApi.dll |
IsDestinationReachableW
IsNetworkAlive |
| WININET.dll |
InternetCrackUrlW
|
| UxTheme.dll |
EndBufferedAnimation
SetWindowTheme GetThemeTransitionDuration DrawThemeParentBackground CloseThemeData GetThemePartSize DrawThemeBackground OpenThemeData GetThemeFont GetThemeBackgroundContentRect EnableThemeDialogTexture DrawThemeTextEx BufferedPaintStopAllAnimations BeginBufferedAnimation BufferedPaintRenderAnimation |
| dwmapi.dll |
DwmSetWindowAttribute
|
| KERNEL32.dll |
WriteFile
GetTimeFormatEx WaitForSingleObject CreateFileW GetDateFormatEx GetFileAttributesW FormatMessageW GetDiskFreeSpaceExW TerminateThread GlobalAlloc CloseHandle CreateThread GetLocalTime GetCurrentDirectoryW SetFilePointerEx FlushFileBuffers GetFinalPathNameByHandleW SetFileTime FindFirstStreamW FormatMessageA lstrcpynW ExpandEnvironmentStringsW SetCurrentDirectoryW SizeofResource LockResource LoadResource FindResourceW FreeLibrary CreateEventW SetEvent ResetEvent CopyFileW GetCurrentProcess GetCurrentProcessId CreateMutexW ReleaseMutex Sleep GetApplicationRestartSettings UnregisterApplicationRestart lstrcmpiA RegisterApplicationRestart GetFileAttributesExW WaitForMultipleObjects CopyFileExW GetVersionExW GetSystemInfo UnmapViewOfFile CreateFileMappingW MapViewOfFile VerSetConditionMask VerifyVersionInfoW lstrcpynA SetLastError GetTempPathW CancelIo WaitForSingleObjectEx GlobalLock SleepEx ReadDirectoryChangesW GetLocaleInfoA LCMapStringW GetTickCount GetStringTypeExW LCMapStringA GetStringTypeExA GetUserDefaultLCID LoadLibraryA LCMapStringEx GetLocaleInfoEx DecodePointer EncodePointer DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection GetNativeSystemInfo SleepConditionVariableSRW WakeAllConditionVariable GetModuleHandleExW CloseThreadpoolWork SubmitThreadpoolWork CreateThreadpoolWork FreeLibraryWhenCallbackReturns IsProcessorFeaturePresent RaiseException RtlPcToFileHeader InitOnceBeginInitialize InitOnceComplete QueryPerformanceFrequency QueryPerformanceCounter GetStringTypeW TryAcquireSRWLockExclusive AcquireSRWLockExclusive ReleaseSRWLockExclusive GlobalUnlock GetDateFormatW GetSystemTimeAsFileTime SystemTimeToTzSpecificLocalTime lstrcpyW ReplaceFileW MoveFileExW GetTimeFormatW DeleteFileW QueueUserAPC SetFileAttributesW GetLongPathNameW GetFullPathNameW CompareFileTime CreateDirectoryW FindClose lstrlenW FindNextFileW FindFirstFileW WideCharToMultiByte MultiByteToWideChar GlobalFree GetVersion GetACP GetModuleFileNameW MulDiv lstrcmpW GetCurrentThreadId LocalFree GetLastError LocalAlloc LoadLibraryExW lstrcmpiW GetModuleHandleW FileTimeToSystemTime GetProcAddress VirtualProtect CompareStringEx GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsDebuggerPresent GetStartupInfoW InitializeSListHead RtlUnwindEx InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree ExitProcess ReadFile ExitThread FreeLibraryAndExitThread GetStdHandle HeapAlloc HeapFree GetFileType GetConsoleMode ReadConsoleW FlsAlloc FlsGetValue FlsSetValue RtlUnwind FlsFree CompareStringW GetLocaleInfoW IsValidLocale EnumSystemLocalesW GetTimeZoneInformation GetFileSizeEx GetConsoleOutputCP IsValidCodePage GetOEMCP HeapReAlloc FindFirstFileExW GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap SetStdHandle HeapSize SetEndOfFile WriteConsoleW GlobalSize |
| USER32.dll |
SetRectEmpty
GetCapture LoadBitmapW RegisterWindowMessageW ScrollWindow RemovePropW GetPropW InsertMenuItemW KillTimer GetCaretBlinkTime AppendMenuA GetMessageTime GetKeyboardLayout ValidateRect SetTimer DestroyCursor MsgWaitForMultipleObjects NotifyWinEvent GetUpdateRgn SystemParametersInfoA GetDoubleClickTime DrawTextA MonitorFromPoint AdjustWindowRectEx LoadStringW LoadStringA ChildWindowFromPointEx GetDlgItemTextA SetScrollInfo GetScrollInfo GetWindowTextLengthW GetMessageW DeferWindowPos UnregisterClassW RegisterClassExW TrackPopupMenu BeginDeferWindowPos DispatchMessageW MessageBoxA TranslateMessage LoadIconW EndDeferWindowPos FlashWindowEx PostQuitMessage BringWindowToTop SetCapture ReleaseCapture GetActiveWindow RedrawWindow IsChild SetParent GetSysColorBrush FindWindowExW CallNextHookEx UnhookWindowsHookEx SetWindowsHookExW GetMenuState GetMenuItemCount CreatePopupMenu SetMenuItemInfoW DestroyMenu InsertMenuW TrackPopupMenuEx CheckMenuItem EnableMenuItem CreateMenu IsWindow EmptyClipboard SetClipboardData GetDlgItemInt SetDlgItemInt CreateDialogParamW IsWindowVisible ShowWindow ClientToScreen RegisterClipboardFormatW SetClipboardViewer MessageBoxW OpenClipboard ChangeClipboardChain CloseClipboard GetClipboardData IsClipboardFormatAvailable GetMonitorInfoW ShowScrollBar PostMessageW GetMenu DestroyWindow HideCaret CreateWindowExW MessageBeep GetScrollPos GetWindowPlacement CreateDialogIndirectParamW SetCaretPos GetScrollRange CreateCaret RegisterClassW SetWindowPlacement DrawTextExW LoadCursorW DestroyCaret SetCursor SetScrollRange ShowCaret SetScrollPos DrawEdge UpdateWindow DrawFrameControl ToAscii MoveWindow EndDialog DestroyIcon DialogBoxIndirectParamW SetFocus DestroyAcceleratorTable TranslateAcceleratorW DrawMenuBar IsZoomed AppendMenuW ShowCursor CreateAcceleratorTableW IsCharLowerW CharUpperW CharLowerW IsCharAlphaNumericW IsCharAlphaW SetForegroundWindow IsIconic ModifyMenuW DrawIconEx DialogBoxParamW EnableWindow GetDC LoadImageW GetMenuItemInfoW DefWindowProcW GetWindowRect GetFocus InflateRect SetWindowPos EnumChildWindows FillRect ScreenToClient GetSystemMetrics GetMenuBarInfo OffsetRect MapWindowPoints TrackMouseEvent FrameRect DrawFocusRect GetSysColor IsWindowEnabled IntersectRect GetClassNameW GetWindowDC EnumThreadWindows GetComboBoxInfo GetClientRect DrawTextW GetParent PtInRect InvalidateRect ChildWindowFromPoint ReleaseDC GetCursorPos BeginPaint EndPaint GetWindowTextW CallWindowProcW SetWindowLongPtrW SendMessageW SetWindowTextW GetWindowLongPtrW GetDlgCtrlID SetDlgItemTextW GetDlgItemTextW SendDlgItemMessageW SetDlgItemTextA GetDlgItem wsprintfW SetPropW SystemParametersInfoW GetAncestor GetMenuItemID SetLayeredWindowAttributes FindWindowW GetLastActivePopup LoadMenuW GetClassNameA GetWindowTextA IsDialogMessageW SetMenu CheckMenuRadioItem MonitorFromWindow DeleteMenu GetSubMenu GetMenuStringW RemoveMenu GetIconInfo CreateIconIndirect WindowFromPoint LockWindowUpdate mouse_event GetDesktopWindow MonitorFromRect GetKeyboardState SetMenuItemBitmaps GetWindowLongW GetDCEx GetKeyState |
| GDI32.dll |
OffsetWindowOrgEx
LineTo RestoreDC MoveToEx CreateHatchBrush CreateFontW GetTextMetricsW Rectangle SetROP2 GetROP2 GetPixel SetWindowOrgEx CreateBitmap CreatePatternBrush PatBlt SetBrushOrgEx SetDIBits GetDIBits EnumFontFamiliesExW EndPage DPtoLP StartDocW ExtTextOutW BitBlt EndDoc StartPage RectVisible GetTextExtentPointW CombineRgn Ellipse Polygon ExtCreatePen GetTextExtentExPointA GdiAlphaBlend GetTextExtentExPointW GetTextExtentPoint32A CreateDIBSection ExtTextOutA CreateCompatibleBitmap SaveDC CreateCompatibleDC IntersectClipRect GetDeviceCaps GetObjectW SelectObject GetClipRgn GetStockObject CreateRectRgnIndirect Polyline CreateRectRgn GetTextExtentPoint32W SetTextColor SetBkMode CreatePen SelectClipRgn ExcludeClipRect SetBkColor CreateSolidBrush CreateFontIndirectW RoundRect SetTextAlign DeleteDC DeleteObject |
| COMDLG32.dll |
PrintDlgW
ChooseColorW |
| ADVAPI32.dll |
CryptReleaseContext
CryptGetHashParam CryptDestroyHash CryptHashData CryptCreateHash CryptAcquireContextW RegGetValueW RegQueryValueExW RegOpenKeyExW RegCloseKey CheckTokenMembership FreeSid AllocateAndInitializeSid RegDeleteValueW RegSetValueExW RegEnumKeyExW RegCreateKeyExW RegDeleteKeyW RegQueryInfoKeyW IsTextUnicode |
| ole32.dll |
RevokeDragDrop
RegisterDragDrop OleInitialize DoDragDrop OleUninitialize ReleaseStgMedium CoUninitialize CoInitialize CoTaskMemFree CoCreateInstance CLSIDFromProgID |
| OLEAUT32.dll |
SysAllocStringLen
SysFreeString |
| IMM32.dll |
ImmSetCandidateWindow
ImmSetCompositionStringW ImmEscapeW ImmGetCompositionStringW ImmSetCompositionWindow ImmSetCompositionFontW ImmReleaseContext ImmGetContext ImmNotifyIME |
| Ordinal | 1 |
|---|---|
| Address | 0x30fdf0 |
| Ordinal | 2 |
|---|---|
| Address | 0x30fd20 |
| Ordinal | 3 |
|---|---|
| Address | 0x30fdc0 |
| Ordinal | 4 |
|---|---|
| Address | 0x30fd40 |
| Ordinal | 5 |
|---|---|
| Address | 0x30fed0 |
| Ordinal | 6 |
|---|---|
| Address | 0x30fee0 |
| Ordinal | 7 |
|---|---|
| Address | 0x30fe80 |
| Ordinal | 8 |
|---|---|
| Address | 0x6fe00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 8.7.4.0 |
| ProductVersion | 8.7.4.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Don HO don.h@free.fr |
| FileDescription | Notepad++ |
| FileVersion (#2) | 8.7.4 |
| InternalName | notepad++.exe |
| LegalCopyright | Copyleft 1998-2023 by Don HO |
| OriginalFilename | notepad++.exe |
| ProductName | Notepad++ |
| ProductVersion (#2) | 8.7.4 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Dec-04 22:50:58 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0x527cc8 |
| PointerToRawData | 0x526cc8 |
| StartAddressOfRawData | 0x140528128 |
|---|---|
| EndAddressOfRawData | 0x140528130 |
| AddressOfIndex | 0x14058658c |
| AddressOfCallbacks | 0x140474758 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1405732c0 |
| XOR Key | 0xef2bb1e4 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 10 |
| C++ objects (30795) | 192 |
| 253 (33731) | 5 |
| C objects (33731) | 19 |
| ASM objects (33731) | 12 |
| C++ objects (33731) | 109 |
| C objects (30795) | 31 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 39 |
| Total imports | 621 |
| C++ objects (LTCG) (33811) | 305 |
| Exports (33811) | 1 |
| Resource objects (33811) | 1 |
| 151 | 26 |
| Linker (33811) | 1 |
No comments yet.