Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2033-Jan-25 08:22:26 |
Detected languages |
English - United States
|
Debug artifacts |
WMNetMgr.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Windows Media Network Plugin Manager DLL |
FileVersion | 12.0.16299.15 (WinBuild.160101.0800) |
InternalName | WMNetMgr.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WMNetMgr.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 12.0.16299.15 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE is possibly packed. | Unusual section name found: .didat |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2033-Jan-25 08:22:26 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x106a00 |
SizeOfInitializedData | 0x38000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0003C8D0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x108000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x142000 |
SizeOfHeaders | 0x400 |
Checksum | 0x128687 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
msvcrt.dll |
strncpy_s
strtoul strcpy_s strcat_s strchr sprintf_s _beginthreadex _vsnprintf qsort srand wcsrchr wcstok wcspbrk iswcntrl wcsstr _ltow wcstoul wcstol _ultow _ultow_s swscanf _ltoa_s _ultoa_s strncmp _strnicmp tolower calloc _wtoi sscanf_s strstr isspace memmove strpbrk _atoi64 rand iswspace wcsftime time gmtime wcsncmp _stricmp iswxdigit isdigit isalpha iswdigit iswalpha isxdigit strnlen _unlock __dllonexit _onexit memset memchr _i64tow_s _ui64tow_s wcschr toupper towupper __CxxFrameHandler3 _wcsicmp _vsnwprintf _ftol2 _ftol2_sse memcmp _callnewh _XcptFilter _amsg_exit _initterm ?terminate@@YAXXZ _except_handler4_common towlower _wcsnicmp _purecall wcscpy_s realloc wcscat_s malloc free _lock _ltow_s _strlwr _strupr iswupper strrchr atoi strcspn strspn _ui64tow memcpy |
---|---|
WMASF.DLL |
#9
#7 #5 ASFSendTimeToTime ASFGetTimeBase #11 |
KERNEL32.dll |
lstrcmpiW
lstrcpynW VirtualProtect VirtualAlloc VirtualQuery GetSystemInfo MultiByteToWideChar SizeofResource LoadResource FindResourceExW GetModuleFileNameW LoadLibraryW DisableThreadLibraryCalls HeapDestroy lstrcpyW CreateEventW CloseHandle WaitForSingleObject GetTickCount Sleep ResetEvent GetCurrentThreadId SetEvent HeapFree GetProcessHeap HeapAlloc WideCharToMultiByte OpenMutexW CreateDirectoryW DeleteFileW FindResourceW LockResource CreateFileW WriteFile FreeResource WaitForSingleObjectEx UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime SetLastError InitializeCriticalSectionAndSpinCount IsDebuggerPresent IsProcessorFeaturePresent LoadLibraryA GetSystemDirectoryA GetVersionExA SetThreadPriority FreeLibraryAndExitThread GetModuleHandleA GetCurrentThread CreateEventA VirtualFree ReleaseSemaphore HeapSize CreateSemaphoreA TlsAlloc TlsFree TlsGetValue SetThreadAffinityMask TlsSetValue GetExitCodeThread GetSystemDefaultLCID LocalFree FormatMessageW GetVersionExW CreateFileA DeleteFileA CopyFileA CopyFileW SetFilePointer SetEndOfFile GetStdHandle GlobalLock GlobalUnlock GlobalAlloc GlobalFree GetFileSize ReadFile GetLocalTime SystemTimeToFileTime GetComputerNameW lstrlenW OpenProcess GetExitCodeProcess QueryPerformanceFrequency GetThreadLocale FileTimeToSystemTime GetModuleHandleExA LocalAlloc LoadLibraryExA GetVersion GetModuleHandleW GetTempFileNameW ExpandEnvironmentStringsW GetFileAttributesW GetTempPathW SearchPathW CompareFileTime GetWindowsDirectoryW GetLocaleInfoA GetSystemTime CreateThread LoadLibraryExW GetProcAddress GetLastError FreeLibrary LeaveCriticalSection EnterCriticalSection DeleteCriticalSection InitializeCriticalSection WaitForMultipleObjects CreateIoCompletionPort PostQueuedCompletionStatus GetQueuedCompletionStatus RaiseException AcquireSRWLockExclusive ReleaseSRWLockExclusive GetModuleHandleExW DebugBreak |
USER32.dll |
CharNextW
PostQuitMessage CreateWindowExA DefWindowProcA RegisterClassA GetWindowLongA SetWindowLongA PostMessageA DestroyWindow DispatchMessageA GetMessageA CharPrevW |
ADVAPI32.dll |
RegOpenKeyExW
RegDeleteKeyA RegEnumKeyA UnregisterTraceGuids RegisterTraceGuidsW GetTraceEnableLevel GetTraceEnableFlags GetTraceLoggerHandle RegCreateKeyExA RegDeleteKeyW TraceEvent DeregisterEventSource ReportEventW RegisterEventSourceW IsTextUnicode RegQueryValueExW RegQueryValueExA RegOpenKeyExA RegDeleteValueW RegCreateKeyExW RegSetValueExW RegEnumValueW RegQueryInfoKeyW RegEnumKeyExW RegCloseKey RegEnumKeyW |
ole32.dll |
CLSIDFromString
StringFromGUID2 CreateStreamOnHGlobal CoCreateGuid CoInitializeEx CoUninitialize CoCreateInstance CoTaskMemAlloc CoTaskMemRealloc CoTaskMemFree CoInitialize |
WS2_32.dll (delay-loaded) |
#2
#3 #52 #22 #13 #112 #5 #11 #6 #51 #20 #16 #56 #23 #12 #55 #57 #7 getaddrinfo getnameinfo freeaddrinfo #8 #9 #10 #21 #111 #17 #4 #19 #1 #101 WSAEnumNetworkEvents #14 WSAEventSelect #116 #115 #15 |
Attributes | 0x1 |
---|---|
Name | WS2_32.dll |
ModuleHandle | 0x109c74 |
DelayImportAddressTable | 0x1240a4 |
DelayImportNameTable | 0x107528 |
BoundDelayImportTable | 0x10777c |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x3b5f0 |
Ordinal | 2 |
---|---|
Address | 0x3b430 |
Ordinal | 3 |
---|---|
Address | 0x4f050 |
Ordinal | 4 |
---|---|
Address | 0x4f070 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 12.0.16299.15 |
ProductVersion | 12.0.16299.15 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Windows Media Network Plugin Manager DLL |
FileVersion (#2) | 12.0.16299.15 (WinBuild.160101.0800) |
InternalName | WMNetMgr.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WMNetMgr.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 12.0.16299.15 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2033-Jan-25 08:22:26 |
Version | 0.0 |
SizeofData | 37 |
AddressOfRawData | 0x16a08 |
PointerToRawData | 0x15e08 |
Referenced File | WMNetMgr.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2033-Jan-25 08:22:26 |
Version | 0.0 |
SizeofData | 1252 |
AddressOfRawData | 0x16a30 |
PointerToRawData | 0x15e30 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2033-Jan-25 08:22:26 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x10105b64 |
---|---|
EndAddressOfRawData | 0x10105b6c |
AddressOfIndex | 0x10109c70 |
AddressOfCallbacks | 0x10005534 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x101094d8 |
SEHandlerTable | 0x10010870 |
SEHandlerCount | 99 |
GuardCFCheckFunctionPointer | 269624388 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xbb138816 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v15.?.? build 25203) | 12 |
C objects (VS2017 v15.?.? build 25203) | 16 |
Total imports | 385 |
Imports (VS2017 v15.?.? build 25203) | 13 |
C++ objects (VS2017 v15.?.? build 25203) | 8 |
Exports (VS2017 v15.?.? build 25203) | 1 |
270 (VS2017 v15.?.? build 25203) | 208 |
Resource objects (VS2017 v15.?.? build 25203) | 1 |
Linker (VS2017 v15.?.? build 25203) | 1 |