Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2022-Dec-07 22:09:48 |
Detected languages |
English - United States
|
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
E:\Projects\RSAPatch\x64\Release\RSAPatch.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/70 (Scanned on 2022-12-19 22:47:33) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2022-Dec-07 22:09:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xb400 |
SizeOfInitializedData | 0x9200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000000B3B0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1a000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetModuleFileNameA
VirtualProtect Sleep CreateFileA DisableThreadLibraryCalls CloseHandle CreateThread GetCurrentProcessId GetSystemDirectoryA LoadLibraryA GetProcAddress GetStdHandle WriteConsoleA SetConsoleMode GetModuleHandleA AttachConsole AllocConsole VirtualQuery VirtualFree VirtualAlloc FlushInstructionCache SetThreadContext GetThreadContext ResumeThread SuspendThread GetCurrentThreadId GetCurrentThread GetCurrentProcess GetLastError SetLastError GetCurrentDirectoryW AreFileApisANSI MultiByteToWideChar WideCharToMultiByte LocalFree FormatMessageA GetLocaleInfoEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead |
---|---|
USER32.dll |
EnumWindows
GetWindowThreadProcessId GetClassNameA |
MSVCP140.dll |
?always_noconv@codecvt_base@std@@QEBA_NXZ
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Xout_of_range@std@@YAXPEBD@Z ?_Winerror_map@std@@YAHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?id@?$ctype@D@std@@2V0locale@2@A ?_Xlength_error@std@@YAXPEBD@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Syserror_map@std@@YAPEBDH@Z ??Bid@locale@std@@QEAA_KXZ |
ntdll.dll |
NtProtectVirtualMemory
NtQuerySection |
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
__std_terminate
__current_exception __std_exception_destroy __C_specific_handler memcpy memset __current_exception_context __std_type_info_destroy_list _CxxThrowException __std_exception_copy memmove |
api-ms-win-crt-stdio-l1-1-0.dll |
ungetc
setvbuf fgetpos fread fwrite _get_stream_buffer_pointers __stdio_common_vsnprintf_s fsetpos fgetc fclose _fseeki64 fputc fflush |
api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _callnewh |
api-ms-win-crt-runtime-l1-1-0.dll |
_initialize_narrow_environment
_configure_narrow_argv _seh_filter_dll _initialize_onexit_table _register_onexit_function _execute_onexit_table terminate _crt_atexit _invalid_parameter_noinfo _initterm _cexit _invalid_parameter_noinfo_noreturn _initterm_e _errno |
api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
api-ms-win-crt-convert-l1-1-0.dll |
strtoul
|
api-ms-win-crt-string-l1-1-0.dll |
strcmp
|
api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
|
Ordinal | 1 |
---|---|
Address | 0x7150 |
Ordinal | 2 |
---|---|
Address | 0x7156 |
Ordinal | 3 |
---|---|
Address | 0x715c |
Ordinal | 4 |
---|---|
Address | 0x7162 |
Ordinal | 5 |
---|---|
Address | 0x7168 |
Ordinal | 6 |
---|---|
Address | 0x716e |
Ordinal | 7 |
---|---|
Address | 0x7174 |
Ordinal | 8 |
---|---|
Address | 0x717a |
Ordinal | 9 |
---|---|
Address | 0x7180 |
Ordinal | 10 |
---|---|
Address | 0x7186 |
Ordinal | 11 |
---|---|
Address | 0x718c |
Ordinal | 12 |
---|---|
Address | 0x7192 |
Ordinal | 13 |
---|---|
Address | 0x7198 |
Ordinal | 14 |
---|---|
Address | 0x719e |
Ordinal | 15 |
---|---|
Address | 0x71a4 |
Ordinal | 16 |
---|---|
Address | 0x71aa |
Ordinal | 17 |
---|---|
Address | 0x71b0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Dec-07 22:09:48 |
Version | 0.0 |
SizeofData | 70 |
AddressOfRawData | 0xecb0 |
PointerToRawData | 0xd4b0 |
Referenced File | E:\Projects\RSAPatch\x64\Release\RSAPatch.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Dec-07 22:09:48 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xecf8 |
PointerToRawData | 0xd4f8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Dec-07 22:09:48 |
Version | 0.0 |
SizeofData | 912 |
AddressOfRawData | 0xed0c |
PointerToRawData | 0xd50c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Dec-07 22:09:48 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x18000f0c0 |
---|---|
EndAddressOfRawData | 0x18000f0c1 |
AddressOfIndex | 0x180012494 |
AddressOfCallbacks | 0x18000d508 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
Callbacks |
0x0000000180004130
|
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x180012020 |
XOR Key | 0x60587787 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 14 |
C objects (31823) | 8 |
ASM objects (31823) | 3 |
C++ objects (31823) | 22 |
Imports (31823) | 6 |
C++ objects (VS2019 Update 7 (16.7.1) compiler 29111) | 3 |
Imports (30795) | 7 |
Total imports | 196 |
C++ objects (LTCG) (31933) | 3 |
ASM objects (VS2022 Update 3 (17.3.4-5) compiler 31630) | 1 |
Exports (31933) | 1 |
Resource objects (31933) | 1 |
Linker (31933) | 1 |