Architecture |
Subsystem |
Compilation Date | 2024-Jan-09 11:38:31 |
Detected languages |
English - United States
TLS Callbacks | 2 callback(s) detected. |
Debug artifacts |
CompanyName | Tencent |
FileDescription | 腾讯应用宝 |
FileVersion | 1.0.1990.0 |
LegalCopyright | Copyright (C) 2022 Tencent. All Rights Reserved. |
InternalName | Androws |
ProductName | Androws |
ProductVersion | 1.0.1990.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
Malicious | VirusTotal score: 23/71 (Scanned on 2024-05-14 12:18:54) |
Win64:MalwareX-gen [Trj]
AhnLab-V3: Trojan/Win.Generic.C5621681 Antiy-AVL: Trojan[Backdoor]/Win32.Cobalt Avast: Win64:MalwareX-gen [Trj] Avira: TR/AVI.Agent.sxzag DeepInstinct: MALICIOUS ESET-NOD32: a variant of Win64/Agent_AGen.BSH F-Secure: Trojan.TR/AVI.Agent.sxzag Fortinet: W64/Agent_AGen.BSH!tr GData: Win64.Trojan.Agent.6VY0IB Google: Detected Ikarus: Trojan.Win64.Agent K7GW: Trojan ( 005b57581 ) Kaspersky: VHO:Backdoor.Win32.Cobalt.gen Kingsoft: Win32.Hack.Cobalt.gen Lionic: Trojan.Win32.Cobalt.m!c Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Backdoor.Cobalt!8.1233E (TFE:5:4s5NDUib3nB) Sangfor: Backdoor.Win32.Cobalt.Vpvv Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Varist: W64/ABRisk.KGEM-9291 ZoneAlarm: VHO:Backdoor.Win32.Cobalt.gen |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x158 |
Signature | PE |
Machine |
NumberofSections | 6 |
TimeDateStamp | 2024-Jan-09 11:38:31 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
Magic | PE32+ |
LinkerVersion | 14.0 |
SizeOfCode | 0x1ca800 |
SizeOfInitializedData | 0xa9600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000182360 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x414000 |
SizeOfHeaders | 0x400 |
Checksum | 0x41a539 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ResetEvent InitializeCriticalSectionAndSpinCount InitOnceBeginInitialize InitOnceComplete GetCPInfoExW FindFirstFileExW SetFileInformationByHandle IsDebuggerPresent GetStartupInfoW CopyFileW GetFileInformationByHandleEx ReleaseSRWLockExclusive RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter InitializeSListHead AcquireSRWLockShared ReleaseSRWLockShared AcquireSRWLockExclusive RtlLookupFunctionEntry FlushFileBuffers QueryPerformanceCounter FormatMessageA GetSystemTime GetSystemTimeAsFileTime SystemTimeToFileTime LockFileEx LocalFree UnlockFile HeapCompact DeleteFileA WaitForSingleObjectEx LoadLibraryA CreateFileA FlushViewOfFile OutputDebugStringW GetFileAttributesA GetDiskFreeSpaceA FormatMessageW GetTempPathA HeapValidate UnlockFileEx GetFullPathNameA InitializeCriticalSection LeaveCriticalSection LockFile OutputDebugStringA GetDiskFreeSpaceW GetFullPathNameW EnterCriticalSection HeapCreate TryEnterCriticalSection AreFileApisANSI VirtualFree VirtualAlloc GetTickCount GetCurrentThreadId GetTempPathW SetFileAttributesW CreateDirectoryW MoveFileExW GetFileInformationByHandle SetFilePointer SetEndOfFile GetFileSize FindNextFileW FindFirstFileW FindClose CreateSemaphoreW ReleaseSemaphore UnmapViewOfFile MapViewOfFile OpenFileMappingW CreateFileMappingW VirtualQuery SignalObjectAndWait CreateMutexW GetCommandLineA WideCharToMultiByte FreeLibrary LoadLibraryW GetFileAttributesExW GetModuleHandleA GetLocaleInfoW GetModuleFileNameW GetSystemDirectoryW GetCommandLineW Process32FirstW Process32NextW CreateToolhelp32Snapshot OpenProcess TerminateProcess OpenMutexA ReleaseMutex GetExitCodeProcess SetEvent Sleep CreateEventW CreateProcessA GetModuleHandleW IsProcessorFeaturePresent GetProcAddress GetActiveProcessorCount GetSystemInfo CloseHandle DeleteFileW GetFileAttributesW CreateFileW WaitForSingleObject PeekNamedPipe CreatePipe WriteFile GetCurrentProcess ReadFile GlobalMemoryStatusEx GetPhysicallyInstalledSystemMemory GetProcessHeap DeleteCriticalSection HeapDestroy HeapAlloc HeapReAlloc GetLastError MultiByteToWideChar HeapSize InitializeCriticalSectionEx HeapFree VirtualProtect |
USER32.dll |
EnumDisplayDevicesA DefWindowProcW DestroyWindow CreateWindowExW RegisterClassW UnregisterClassW GetWindowRect GetDC GetSystemMetrics GetForegroundWindow |
GDI32.dll |
GetDeviceCaps ChoosePixelFormat |
SHELL32.dll |
ShellExecuteExW SHGetFolderPathW |
ole32.dll |
OLEAUT32.dll |
SysAllocStringLen SysFreeString |
ADVAPI32.dll |
SetSecurityDescriptorDacl RegCloseKey OpenProcessToken AdjustTokenPrivileges LookupPrivilegeValueW GetTokenInformation RegQueryValueExW RegOpenKeyExW RegSetValueExW RegCreateKeyExW |
PathAppendW StrRChrW StrCpyNW |
Signature | 0xfeef04bd |
StructVersion | 0x10000 |
FileVersion | 1.0.1990.0 |
ProductVersion | 1.0.1990.0 |
FileFlags | (EMPTY) |
FileOs |
FileType |
Language | UNKNOWN |
CompanyName | Tencent |
FileDescription | 腾讯应用宝 |
FileVersion (#2) | 1.0.1990.0 |
LegalCopyright | Copyright (C) 2022 Tencent. All Rights Reserved. |
InternalName | Androws |
ProductName | Androws |
ProductVersion (#2) | 1.0.1990.0 |
Resource LangID | English - United States |
Characteristics |
TimeDateStamp | 2024-Jan-09 11:38:31 |
Version | 0.0 |
SizeofData | 119 |
AddressOfRawData | 0x211640 |
PointerToRawData | 0x210240 |
Referenced File | E:\workplace\Androws\p-4ff796941325489e9c426b6fb216f108\build\bin\Release\AndrowsAssistant.pdb |
Characteristics |
TimeDateStamp | 2024-Jan-09 11:38:31 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x2116b8 |
PointerToRawData | 0x2102b8 |
Characteristics |
TimeDateStamp | 2024-Jan-09 11:38:31 |
Version | 0.0 |
SizeofData | 1028 |
AddressOfRawData | 0x2116cc |
PointerToRawData | 0x2102cc |
StartAddressOfRawData | 0x140211af0 |
EndAddressOfRawData | 0x140211c71 |
AddressOfIndex | 0x14025af80 |
AddressOfCallbacks | 0x1401d2740 |
SizeOfZeroFill | 0 |
Characteristics |
Callbacks |
0x0000000140182374 |
Size | 0x138 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14024cdb8 |
XOR Key | 0x54a12fbb |
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 20 |
Imports (VS2017 v15.8.9 compiler 26732) | 8 |
C objects (30034) | 10 |
ASM objects (30034) | 4 |
C++ objects (30034) | 43 |
Imports (30034) | 6 |
253 (28518) | 7 |
C++ objects (CVTCIL) (27412) | 1 |
C objects (27412) | 4 |
C objects (CVTCIL) (27412) | 1 |
Imports (VS2019 Update 11 (16.11.16-17) compiler 30146) | 12 |
C++ objects (VS2019 Update 11 (16.11.6-7) compiler 30137) | 28 |
C objects (VS2019 Update 11 (16.11.6-7) compiler 30137) | 1 |
C++ objects (VS2019 Update 11 (16.11.16-17) compiler 30146) | 27 |
C++ objects (30151) | 8 |
Imports (27412) | 21 |
Total imports | 1272 |
C++ objects (LTCG) (VS2019 Update 11 (16.11.16-17) compiler 30146) | 63 |
Exports (VS2019 Update 11 (16.11.16-17) compiler 30146) | 1 |
Resource objects (VS2019 Update 11 (16.11.16-17) compiler 30146) | 1 |
151 | 1 |
Linker (VS2019 Update 11 (16.11.16-17) compiler 30146) | 1 |