Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Sep-13 13:35:21 |
Detected languages |
English - United States
|
Debug artifacts |
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Connectwise
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2024-Sep-13 13:35:21 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x9e00 |
SizeOfInitializedData | 0x8000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001489 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x15000 |
SizeOfHeaders | 0x400 |
Checksum | 0x21686 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LocalFree
GetProcAddress LoadLibraryA Sleep LocalAlloc GetModuleFileNameW DecodePointer UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW RaiseException GetStdHandle WriteFile GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte ExitProcess GetModuleHandleExW GetACP CloseHandle HeapAlloc HeapFree FindClose FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW LCMapStringW SetStdHandle GetFileType GetStringTypeW GetProcessHeap HeapSize HeapReAlloc FlushFileBuffers GetConsoleCP GetConsoleMode SetFilePointerEx WriteConsoleW CreateFileW |
---|---|
CRYPT32.dll |
CertDeleteCertificateFromStore
CryptMsgGetParam CertCloseStore CryptQueryObject CertAddCertificateContextToStore CertFindAttribute CertFreeCertificateContext CertCreateCertificateContext CertOpenSystemStoreA |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 99 |
AddressOfRawData | 0xff50 |
PointerToRawData | 0xf150 |
Referenced File | C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xffb4 |
PointerToRawData | 0xf1b4 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 680 |
AddressOfRawData | 0xffc8 |
PointerToRawData | 0xf1c8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xc0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x411000 |
SEHandlerTable | 0x40fec0 |
SEHandlerCount | 2 |
XOR Key | 0x1a0d1864 |
---|---|
Unmarked objects | 0 |
241 (40116) | 10 |
243 (40116) | 122 |
242 (40116) | 24 |
C++ objects (33218) | 37 |
C objects (33218) | 18 |
ASM objects (33218) | 18 |
Imports (VS2008 SP1 build 30729) | 5 |
Total imports | 97 |
C objects (LTCG) (33523) | 1 |
Resource objects (33523) | 1 |
Linker (33523) | 1 |