Architecture |
Subsystem |
Compilation Date | 2024-Sep-13 13:35:21 |
Detected languages |
English - United States
Debug artifacts |
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
Info | The PE is digitally signed. |
Signer: Connectwise
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
Machine |
NumberofSections | 5 |
TimeDateStamp | 2024-Sep-13 13:35:21 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 14.0 |
SizeOfCode | 0x9e00 |
SizeOfInitializedData | 0x8000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001489 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x15000 |
SizeOfHeaders | 0x400 |
Checksum | 0x21686 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetProcAddress LoadLibraryA Sleep LocalAlloc GetModuleFileNameW DecodePointer UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW RaiseException GetStdHandle WriteFile GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte ExitProcess GetModuleHandleExW GetACP CloseHandle HeapAlloc HeapFree FindClose FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW LCMapStringW SetStdHandle GetFileType GetStringTypeW GetProcessHeap HeapSize HeapReAlloc FlushFileBuffers GetConsoleCP GetConsoleMode SetFilePointerEx WriteConsoleW CreateFileW |
CRYPT32.dll |
CryptMsgGetParam CertCloseStore CryptQueryObject CertAddCertificateContextToStore CertFindAttribute CertFreeCertificateContext CertCreateCertificateContext CertOpenSystemStoreA |
Characteristics |
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 99 |
AddressOfRawData | 0xff50 |
PointerToRawData | 0xf150 |
Referenced File | C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb |
Characteristics |
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xffb4 |
PointerToRawData | 0xf1b4 |
Characteristics |
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 680 |
AddressOfRawData | 0xffc8 |
PointerToRawData | 0xf1c8 |
Characteristics |
TimeDateStamp | 2024-Sep-13 13:35:21 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xc0 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x411000 |
SEHandlerTable | 0x40fec0 |
SEHandlerCount | 2 |
XOR Key | 0x1a0d1864 |
Unmarked objects | 0 |
241 (40116) | 10 |
243 (40116) | 122 |
242 (40116) | 24 |
C++ objects (33218) | 37 |
C objects (33218) | 18 |
ASM objects (33218) | 18 |
Imports (VS2008 SP1 build 30729) | 5 |
Total imports | 97 |
C objects (LTCG) (33523) | 1 |
Resource objects (33523) | 1 |
Linker (33523) | 1 |