| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2019-Dec-18 14:10:46 |
| Detected languages |
English - United States
|
| Debug artifacts |
G:\ade\build\sb_0-37309218-1576677305.38\release\client\RelWithDebInfo\mysql.pdb
|
| FileVersion | 5.7.29.0 |
| ProductVersion | 5.7.29.0 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: | HQR data file |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2023-12-23 17:30:36) | All the AVs think this file is safe. |
| MD5 | fb4102f858e3d6e182b0cca9af57e937 🔍 |
|---|---|
| SHA1 | 953c0db7c88f9fcde33d83f114c289ca2e3b1c80 🔍 |
| SHA256 | 60e0d5c8d0213d882cb8419281d180f0a80a334815a8e06f580e88ab8c78038c 🔍 |
| SHA3 | 8d26e13b22492ba526453d903825e973162eb27e6554ceef8287df0520df95fc 🔍 |
| SSDeep | 49152:LtGVMwVBPy/pblDzglwfvdL+6Clr6ZxBz0H3v19b1BH+cf184rpK67M8pdNgTWB:ZGewI4Svg6ClrIBzkv1PTt8FmNJ7Q 🔍 |
| Imports Hash | b93c4e33f67fb47be2b3f1c0276453e6 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2019-Dec-18 14:10:46 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0x1cec00 |
| SizeOfInitializedData | 0x4dc600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000001CEEC0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x6ae000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | bb32a47148c40d479dfd611a846e31e4 🔍 |
|---|---|
| SHA1 | a42985dc99242f9761a2204b6a7df0a8361c63ed 🔍 |
| SHA256 | 876c05f404827d4fddefdc28f21dd07f309a7e823c3171bdcd4282b2ef08aa33 🔍 |
| SHA3 | 16d668e6230f8801ed44f3c7612e77c4c976b3602a79cc8472b9b99d577be19a 🔍 |
| VirtualSize | 0x1cebff |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x1cec00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.36392 |
| MD5 | cd746c675f550c4f19629a1ad46c0829 🔍 |
|---|---|
| SHA1 | c1d8792d84ccb55e16d2f767f5091cf4abc45ddf 🔍 |
| SHA256 | 99f8bdb6281724bc72cd1a6f4f3f4d693f0084b4a35f096b24075455818204f8 🔍 |
| SHA3 | 7e15b05c9cd8c0540cf8ed78c27a9a836398b7b1c308b0bb24e8ea31f867f754 🔍 |
| VirtualSize | 0x369e90 |
| VirtualAddress | 0x1d0000 |
| SizeOfRawData | 0x36a000 |
| PointerToRawData | 0x1cf000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.16417 |
| MD5 | 1b304e392d5bedca325b90d1fdd74e07 🔍 |
|---|---|
| SHA1 | a424bffef25920a2a05b7bf868900211d2d00ef2 🔍 |
| SHA256 | a39bbedd7c299c8c0549745fac4096784127572007c31b571d9a0baa89d44ddf 🔍 |
| SHA3 | c6c4d6ed1c89db96e690cfc59d89154bb8b4b311a651b11de0ba2cb10387fee9 🔍 |
| VirtualSize | 0x147e80 |
| VirtualAddress | 0x53a000 |
| SizeOfRawData | 0x81800 |
| PointerToRawData | 0x539000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.11107 |
| MD5 | 7da1a780d3b0339a15aa83a249147695 🔍 |
|---|---|
| SHA1 | 6786e9d466eb362010338d016fc18c47840fbfec 🔍 |
| SHA256 | dfa453d8a24dff8f2e7513edbcdd74d4573737d5f2195277d8a2547298a72100 🔍 |
| SHA3 | a0bf5529aaa7a2d239b5e13581fe263e0f2edb854f073e1323aaabb196c1a94d 🔍 |
| VirtualSize | 0x211bc |
| VirtualAddress | 0x682000 |
| SizeOfRawData | 0x21200 |
| PointerToRawData | 0x5ba800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.28401 |
| MD5 | e125fb7ca8976dbbd366fe77d700e938 🔍 |
|---|---|
| SHA1 | add43cca841094075aa8284a6e7897e462472eb2 🔍 |
| SHA256 | 7a36f2f4440a1740874b3b2eb812f6f4b6ff23f097363aa8920e4db09e08c75d 🔍 |
| SHA3 | 39812b16814616d9236bd40272d35f7a71ab47498de7b7d1528944f7b7db9690 🔍 |
| VirtualSize | 0x368 |
| VirtualAddress | 0x6a4000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x5dba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.98613 |
| MD5 | 7aff9dcc73406d4f1c674327998d2f0e 🔍 |
|---|---|
| SHA1 | 7633f86a40c1259d0b7cc594c735099571016c03 🔍 |
| SHA256 | 93559178d2d1a2cc0423893e0eb202a74eda3296095034ce4a383b892fbf5565 🔍 |
| SHA3 | 53fc09d8d73d2e53f9e4adab73580a1339d7459b1e5102064123fb269349f4fa 🔍 |
| VirtualSize | 0x8ef4 |
| VirtualAddress | 0x6a5000 |
| SizeOfRawData | 0x9000 |
| PointerToRawData | 0x5dbe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.45684 |
| KERNEL32.dll |
IsProcessorFeaturePresent
IsDebuggerPresent DecodePointer EncodePointer GetEnvironmentVariableW ReadConsoleA LoadLibraryW ConvertThreadToFiber ConvertFiberToThread FindClose FindFirstFileW FindNextFileW FormatMessageW GetSystemTime SystemTimeToFileTime GetFileType GetVersion GetModuleHandleW MultiByteToWideChar WideCharToMultiByte CreateFiber SwitchToFiber DeleteFiber InitializeCriticalSectionAndSpinCount WaitForMultipleObjects CancelIo GetOverlappedResult PeekNamedPipe GetModuleHandleExW GetLogicalDrives SetLastError GetFullPathNameA GetFileAttributesA FormatMessageA LoadLibraryExA FreeLibrary CreateEventA LoadLibraryA GetCurrentProcess DuplicateHandle WriteFile SetFilePointerEx SetEndOfFile ReadFile GetFileSizeEx GetFileAttributesExA FlushFileBuffers TerminateThread TlsFree TlsSetValue TlsGetValue TlsAlloc DeleteCriticalSection InitializeCriticalSection GetProcAddress GetModuleHandleA GetWindowsDirectoryA GetSystemDirectoryA GetConsoleCP WaitNamedPipeA OpenFileMappingA UnmapViewOfFile MapViewOfFile GetCurrentThreadId GetCurrentProcessId OpenEventA CreateMutexA WaitForSingleObject ReleaseMutex SetEvent SetNamedPipeHandleState WriteConsoleW SetConsoleMode ReadConsoleW GetConsoleMode LocalFree GetCommandLineW GetStdHandle GetSystemTimeAsFileTime QueryPerformanceFrequency QueryPerformanceCounter CloseHandle CreateFileA GetModuleFileNameA GetLastError GetLocaleInfoA LeaveCriticalSection EnterCriticalSection SetConsoleCtrlHandler DisconnectNamedPipe Sleep |
|---|---|
| ADVAPI32.dll |
CryptGetUserKey
RegisterEventSourceW EqualSid GetUserNameW CryptDecrypt CryptCreateHash CryptSetHashParam CryptSignHashW CryptDestroyHash CryptExportKey DeregisterEventSource RegisterEventSourceA CryptAcquireContextW CryptGetProvParam CryptDestroyKey CryptReleaseContext CryptEnumProvidersW LookupAccountNameW IsValidSid GetTokenInformation RegOpenKeyExA RegEnumValueA RegSetValueExA RegCreateKeyA RegCloseKey ReportEventW |
| CRYPT32.dll |
CertDuplicateCertificateContext
CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertOpenStore CertGetCertificateContextProperty CertFreeCertificateContext |
| Secur32.dll |
AcquireCredentialsHandleA
FreeCredentialsHandle DeleteSecurityContext InitializeSecurityContextW GetUserNameExW FreeContextBuffer CompleteAuthToken |
| MSVCP120.dll |
?_Xbad_alloc@std@@YAXXZ
?_Xout_of_range@std@@YAXPEBD@Z ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAPEBDH@Z ?_Xlength_error@std@@YAXPEBD@Z |
| MSVCR120.dll |
_unlock
_calloc_crt _setmode __C_specific_handler _onexit __crt_debugger_hook __crtUnhandledException __crtTerminateProcess __crtCaptureCurrentContext __crtCapturePreviousContext _XcptFilter _amsg_exit __getmainargs __set_app_type _cexit _configthreadlocale __setusermatherr _initterm_e _initterm __initenv _fmode _commode ?terminate@@YAXXZ __crtSetUnhandledExceptionFilter ?_type_info_dtor_internal_method@type_info@@QEAAXXZ raise _exit _vsnprintf _vsnwprintf wcsstr _strdup _stat64i32 strspn strcspn toupper realloc sscanf memchr _CxxThrowException ??2@YAPEAX_K@Z _purecall strtok_s strncpy strncat _localtime64_s _stat64 _fstat64 fopen _umask qsort _findnext64i32 _findfirst64i32 _findclose _endthreadex _beginthreadex strerror_s strcat_s ftell fseek fread ferror _lock _set_abort_behavior fputc fgets _strtoui64 _strtoi64 strcmp _getch _cputs iscntrl isspace ldiv strnlen _get_osfhandle _tzset _set_invalid_parameter_handler freopen _open_osfhandle _dup2 _close atoi strtol strncmp malloc free calloc memmove memcpy floor __CxxFrameHandler3 _time64 _localtime64 _ctime64 clock _hypot strtoul getenv exit _errno sprintf vfprintf puts putchar putc printf perror fwrite fputs fprintf _fileno fflush fclose __iob_func strtok strstr strrchr strpbrk _strnicmp strerror strchr ??3@YAXPEAX@Z memset memcmp _gmtime64_s _wfopen ??_V@YAXPEAX@Z _stricmp signal feof _dup _isatty _putenv _getcwd _chdir __dllonexit _fdopen |
| bcrypt.dll |
BCryptGenRandom
|
| USER32.dll |
GetProcessWindowStation
GetUserObjectInformationW MessageBoxW |
| SHELL32.dll |
CommandLineToArgvW
|
| WS2_32.dll |
bind
closesocket getsockname socket WSAGetLastError getaddrinfo freeaddrinfo __WSAFDIsSet ntohs ioctlsocket getpeername getsockopt htonl recv select send setsockopt shutdown WSASetLastError WSAIoctl getnameinfo gethostbyname listen accept WSACleanup WSAStartup getservbyname connect |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x148 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.15359 |
| MD5 | 0647928d45c832f979e2061ce7cce312 🔍 |
| SHA1 | f2e3b7d36f8f184fff3e9fac1939ea1fc29fce3a 🔍 |
| SHA256 | 7b92ee264ecec94b5ba3ee604127ee80e479397ddaa9eb5956acb2848c674960 🔍 |
| SHA3 | bb6de2f3753c6a30ea8acf58dab11551a0f7009f71d4bf7cf5149c3fd5a172f9 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.7.29.0 |
| ProductVersion | 5.7.29.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 5.7.29.0 |
| ProductVersion (#2) | 5.7.29.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Dec-18 14:10:46 |
| Version | 0.0 |
| SizeofData | 105 |
| AddressOfRawData | 0x50d4c0 |
| PointerToRawData | 0x50c4c0 |
| Referenced File | G:\ade\build\sb_0-37309218-1576677305.38\release\client\RelWithDebInfo\mysql.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Dec-18 14:10:46 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x50d52c |
| PointerToRawData | 0x50c52c |
| Size | 0x70 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1405bb610 |
| XOR Key | 0x3aff63ad |
|---|---|
| Unmarked objects | 0 |
| 199 (41118) | 12 |
| ASM objects (20806) | 2 |
| C objects (20806) | 19 |
| 221 (20806) | 4 |
| C++ objects (20806) | 7 |
| C objects (VS2013 UPD5 build 40629) | 108 |
| C objects (VS2010 SP1 build 40219) | 565 |
| Imports (65501) | 17 |
| Total imports | 306 |
| C++ objects (VS2013 UPD5 build 40629) | 18 |
| Resource objects (VS2013 build 21005) | 1 |
| 151 | 1 |
| Linker (VS2013 UPD5 build 40629) | 1 |
No comments yet.