Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 1970-Jan-01 00:00:00 |
TLS Callbacks | 2 callback(s) detected. |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
Suspicious | The PE is possibly packed. | Unusual section name found: .xdata |
Suspicious | The PE contains functions most legitimate programs don't use. |
Possibly launches other programs:
|
Safe | VirusTotal score: 0/69 (Scanned on 2023-03-01 15:04:19) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 11 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x5c6200 |
SizeOfInitializedData | 0x742200 |
SizeOfUninitializedData | 0x1000 |
AddressOfEntryPoint | 0x00000000000014D0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x74a000 |
SizeOfHeaders | 0x400 |
Checksum | 0x74edda |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x1000000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
BitBlt
CreateCompatibleBitmap CreateCompatibleDC DeleteDC DeleteObject GetDIBits GetDeviceCaps SelectObject SetDIBitsToDevice |
---|---|
KERNEL32.dll |
CloseHandle
CreateDirectoryA CreateDirectoryW CreateEventA CreateFileA CreateMutexA CreateProcessA CreateThread DeleteCriticalSection DeleteFileA DeleteFileW EnterCriticalSection FileTimeToSystemTime FindClose FindFirstFileA FindNextFileA FormatMessageA GetCurrentThreadId GetEnvironmentVariableW GetFileAttributesA GetFileAttributesW GetFileTime GetLastError GetLocalTime GetShortPathNameA GetStartupInfoA GetSystemInfo GetSystemTimeAsFileTime InitializeCriticalSection IsDBCSLeadByteEx LeaveCriticalSection MultiByteToWideChar ReleaseMutex SearchPathA SetEvent SetUnhandledExceptionFilter Sleep TerminateThread TlsGetValue VirtualProtect VirtualQuery WaitForSingleObject WideCharToMultiByte |
msvcrt.dll |
__C_specific_handler
___lc_codepage_func ___mb_cur_max_func __getmainargs __initenv __iob_func __set_app_type __setusermatherr _acmdln _amsg_exit _cexit _commode _errno _filelengthi64 _fileno _fmode _getpid _initterm _lock _onexit _setjmp _setmode _unlock _wfopen abort acos asin atan calloc cosh exit fclose fflush fgetc fgetpos fopen fprintf fputc fread free fseek fsetpos ftell fwrite getc getenv islower isspace isupper isxdigit localeconv log10 longjmp malloc memchr memcpy memmove memset qsort realloc remove rename rewind setlocale signal sinh strchr strcmp strcpy strerror strlen strncmp strncpy strrchr strstr strtol strtoul system tan tanh tolower ungetc vfprintf wcslen |
libwinpthread-1.dll |
pthread_create
pthread_exit pthread_join |
SHELL32.dll |
SHGetSpecialFolderPathA
|
USER32.dll |
AdjustWindowRect
ChangeDisplaySettingsA CreateWindowExA DefWindowProcA DestroyWindow DispatchMessageA EnumDisplaySettingsA GetDC GetDesktopWindow GetMessageA GetWindowLongPtrA GetWindowRect PeekMessageA ReleaseDC SetForegroundWindow SetWindowLongPtrA SetWindowPos SetWindowTextA ShowCursor ShowWindow TrackMouseEvent |
libgcc_s_seh-1.dll |
_Unwind_Resume
|
libgomp-1.dll |
GOMP_atomic_end
GOMP_atomic_start GOMP_barrier GOMP_critical_end GOMP_critical_name_end GOMP_critical_name_start GOMP_critical_start GOMP_parallel omp_get_max_threads omp_get_num_threads omp_get_thread_num omp_set_num_threads |
libstdc++-6.dll |
_ZNSt9exceptionD2Ev
_ZSt9terminatev _ZTVN10__cxxabiv117__class_type_infoE _ZTVN10__cxxabiv120__si_class_type_infoE _ZdaPv _ZdlPv _Znay _Znwy __cxa_allocate_exception __cxa_begin_catch __cxa_end_catch __cxa_free_exception __cxa_guard_abort __cxa_guard_acquire __cxa_guard_release __cxa_rethrow __cxa_throw __cxa_throw_bad_array_new_length __gxx_personality_seh0 |
libcurl-4.dll |
curl_easy_cleanup
curl_easy_init curl_easy_perform curl_easy_setopt |
libfftw3-3.dll |
fftw_cleanup_threads
fftw_destroy_plan fftw_execute fftw_free fftw_init_threads fftw_malloc fftw_plan_dft_1d fftw_plan_dft_2d fftw_plan_dft_3d fftw_plan_many_dft fftw_plan_with_nthreads |
libjpeg-8.dll |
jpeg_CreateCompress
jpeg_CreateDecompress jpeg_destroy jpeg_destroy_compress jpeg_destroy_decompress jpeg_finish_compress jpeg_finish_decompress jpeg_read_header jpeg_read_scanlines jpeg_set_defaults jpeg_set_quality jpeg_start_compress jpeg_start_decompress jpeg_std_error jpeg_stdio_dest jpeg_stdio_src jpeg_write_scanlines |
libpng16-16.dll |
png_create_info_struct
png_create_read_struct png_create_write_struct png_destroy_read_struct png_destroy_write_struct png_get_IHDR png_get_valid png_init_io png_read_end png_read_image png_read_info png_read_update_info png_set_IHDR png_set_expand_gray_1_2_4_to_8 png_set_filler png_set_gray_to_rgb png_set_interlace_handling png_set_longjmp_fn png_set_palette_to_rgb png_set_sig_bytes png_set_tRNS_to_alpha png_sig_cmp png_write_end png_write_image png_write_info |
libtiff-5.dll |
TIFFClose
TIFFComputeStrip TIFFDefaultStripSize TIFFFileName TIFFGetField TIFFGetFieldDefaulted TIFFIsTiled TIFFOpen TIFFReadDirectory TIFFReadEncodedStrip TIFFReadRGBAImage TIFFReadTile TIFFSetDirectory TIFFSetErrorHandler TIFFSetField TIFFSetWarningHandler TIFFStripSize TIFFTileSize TIFFWriteDirectory TIFFWriteEncodedStrip _TIFFfree _TIFFmalloc |
zlib1.dll |
compress
compressBound uncompress |
StartAddressOfRawData | 0x140747000 |
---|---|
EndAddressOfRawData | 0x140747008 |
AddressOfIndex | 0x1407421dc |
AddressOfCallbacks | 0x140746038 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x0000000140339370
0x0000000140339340 |