Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2018-Apr-30 12:00:00 |
Detected languages |
English - United States
|
CompanyName | Igor Pavlov |
FileDescription | 7-Zip Console |
FileVersion | 18.05 |
InternalName | 7z |
LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
OriginalFilename | 7z.exe |
ProductName | 7-Zip |
ProductVersion | 18.05 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/68 (Scanned on 2019-01-01 02:37:06) | Trapmine: malicious.moderate.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2018-Apr-30 12:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0x4cc00 |
SizeOfInitializedData | 0x26200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000004D010 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x75000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
OLEAUT32.dll |
#7
#9 #10 #2 #149 #6 #4 |
---|---|
USER32.dll |
CharUpperW
|
ADVAPI32.dll |
OpenProcessToken
GetFileSecurityW SetFileSecurityW RegOpenKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW RegCloseKey |
msvcrt.dll |
_exit
_c_exit _XcptFilter _onexit __dllonexit ??1type_info@@UEAA@XZ ?terminate@@YAXXZ __C_specific_handler _beginthreadex _isatty memcmp _purecall strlen memset wcsstr _cexit wcscmp strcmp memmove fflush fputc fputs _iob fgetc fclose free _CxxThrowException malloc __CxxFrameHandler memcpy __initenv exit __getmainargs _initterm __setusermatherr _commode _fmode __set_app_type |
KERNEL32.dll |
VirtualAlloc
VirtualFree WaitForSingleObject SetEvent InitializeCriticalSection FormatMessageW GetConsoleMode SetConsoleMode SetFileApisToOEM GetCommandLineW GetConsoleScreenBufferInfo SetConsoleCtrlHandler IsProcessorFeaturePresent GetProcessTimes LeaveCriticalSection EnterCriticalSection DeleteCriticalSection SetProcessAffinityMask OpenEventW UnmapViewOfFile MapViewOfFile OpenFileMappingW GetStdHandle GetSystemTimeAsFileTime FileTimeToDosDateTime GlobalMemoryStatusEx GetSystemInfo GetProcessAffinityMask FileTimeToLocalFileTime FileTimeToSystemTime CompareFileTime GetCurrentProcess GetDiskFreeSpaceW GetFileInformationByHandle SetEndOfFile WriteFile ReadFile SetFilePointer GetFileSize DeviceIoControl GetLogicalDriveStringsW GetFileAttributesW GetModuleHandleA GetLastError MultiByteToWideChar WideCharToMultiByte FreeLibrary LoadLibraryExW LoadLibraryW GetModuleFileNameW LocalFree CloseHandle SetFileTime CreateFileW SetFileAttributesW RemoveDirectoryW MoveFileW GetProcAddress GetModuleHandleW CreateDirectoryW DeleteFileW SetCurrentDirectoryW GetCurrentDirectoryW GetTempPathW SetLastError GetCurrentProcessId GetTickCount GetCurrentThreadId FindClose FindFirstFileW FindNextFileW |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 18.5.0.0 |
ProductVersion | 18.5.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Igor Pavlov |
FileDescription | 7-Zip Console |
FileVersion (#2) | 18.05 |
InternalName | 7z |
LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
OriginalFilename | 7z.exe |
ProductName | 7-Zip |
ProductVersion (#2) | 18.05 |
Resource LangID | English - United States |
---|
XOR Key | 0xad047f5b |
---|---|
Unmarked objects | 0 |
ASM objects (40310) | 1 |
Imports (40310) | 11 |
Total imports | 146 |
C++ objects (40310) | 75 |
C objects (40310) | 15 |
ASM objects (VS2010 SP1 build 40219) | 1 |
Resource objects (40310) | 1 |
Linker (40310) | 1 |