| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Aug-29 00:00:17 |
| Detected languages |
English - United States
|
| FileVersion | 1.1.33.10 |
| ProductVersion | 1.1.33.10 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. |
Unusual section name found: text
Unusual section name found: data |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/72 (Scanned on 2025-12-27 18:12:22) | McAfeeD: ti!6E1730E6AEB9 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2021-Aug-29 00:00:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0xdce00 |
| SizeOfInitializedData | 0x4b200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000CC550 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x133000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WSOCK32.dll |
gethostbyname
inet_addr WSACleanup gethostname WSAStartup |
|---|---|
| WINMM.dll |
mixerGetLineInfoW
mixerGetDevCapsW mixerOpen mciSendStringW joyGetPosEx mixerGetLineControlsW mixerGetControlDetailsW mixerSetControlDetails waveOutGetVolume mixerClose waveOutSetVolume joyGetDevCapsW |
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| COMCTL32.dll |
ImageList_Create
CreateStatusWindowW ImageList_ReplaceIcon ImageList_GetIconSize ImageList_Destroy ImageList_AddMasked |
| PSAPI.DLL |
GetProcessImageFileNameW
GetModuleBaseNameW GetModuleFileNameExW |
| WININET.dll |
InternetOpenW
InternetOpenUrlW InternetCloseHandle InternetReadFileExA InternetReadFile |
| KERNEL32.dll |
GetModuleFileNameW
GetSystemTimeAsFileTime FindResourceW SizeofResource LoadResource LockResource GetFullPathNameW GetShortPathNameW FindFirstFileW FindNextFileW FindClose FileTimeToLocalFileTime SetEnvironmentVariableW Beep MoveFileW OutputDebugStringW CreateProcessW GetFileAttributesW WideCharToMultiByte MultiByteToWideChar GetExitCodeProcess WriteProcessMemory ReadProcessMemory GetCurrentProcessId OpenProcess TerminateProcess SetPriorityClass SetLastError GetEnvironmentVariableW GetLocalTime GetDateFormatW GetTimeFormatW GetDiskFreeSpaceExW SetVolumeLabelW CreateFileW DeviceIoControl GetDriveTypeW GetVolumeInformationW GetDiskFreeSpaceW GetCurrentDirectoryW CreateDirectoryW ReadFile WriteFile DeleteFileW SetFileAttributesW LocalFileTimeToFileTime SetFileTime DeleteCriticalSection GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetSystemWindowsDirectoryW GetTempPathW EnterCriticalSection LeaveCriticalSection VirtualProtect QueryDosDeviceW CompareStringW RemoveDirectoryW CopyFileW GetCurrentProcess CreateToolhelp32Snapshot Process32FirstW Process32NextW FormatMessageW GetPrivateProfileStringW GetPrivateProfileSectionW GetPrivateProfileSectionNamesW WritePrivateProfileStringW WritePrivateProfileSectionW SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize IsWow64Process VirtualAllocEx VirtualFreeEx EnumResourceNamesW LoadLibraryExW GlobalSize HeapReAlloc EncodePointer HeapFree DecodePointer ExitProcess HeapAlloc IsValidCodePage FlsGetValue FlsSetValue FlsFree FlsAlloc UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry GetCPInfo GetVersionExW GetModuleHandleW FreeLibrary GetProcAddress LoadLibraryW GetLastError CreateMutexW CloseHandle GetExitCodeThread SetThreadPriority CreateThread GetStringTypeExW lstrcmpiW GetCurrentThreadId GlobalUnlock GlobalFree GlobalAlloc GlobalLock SetErrorMode InitializeCriticalSection SetCurrentDirectoryW Sleep GetTickCount MulDiv RtlCaptureContext HeapSetInformation GetVersion HeapCreate InitializeCriticalSectionAndSpinCount HeapSize HeapQueryInformation GetCommandLineW GetStartupInfoW RtlUnwindEx SetHandleCount GetStringTypeW RaiseException RtlPcToFileHeader LCMapStringW GetConsoleCP GetConsoleMode FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter GetOEMCP SetFilePointer FlushFileBuffers WriteConsoleW SetStdHandle GetFileSizeEx GetProcessHeap |
| USER32.dll |
MessageBeep
ClientToScreen GetCursorInfo GetLastInputInfo GetSystemMenu GetMenuItemCount GetMenuItemID GetSubMenu GetMenuStringW ExitWindowsEx SetMenu FlashWindow GetPropW SetPropW RemovePropW MapWindowPoints RedrawWindow SetWindowLongPtrW SetParent GetClassInfoExW DefDlgProcW GetAncestor UpdateWindow GetMessagePos GetClassLongPtrW CallWindowProcW CheckRadioButton IntersectRect GetUpdateRect PtInRect CreateDialogIndirectParamW GetWindowLongPtrW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW SetMenuDefaultItem RemoveMenu SetMenuItemInfoW IsMenu GetMenuItemInfoW CreateMenu CreatePopupMenu SetMenuInfo AppendMenuW DestroyMenu TrackPopupMenuEx GetDesktopWindow CopyImage CreateIconIndirect CreateIconFromResourceEx EnumClipboardFormats GetWindow BringWindowToTop MessageBoxW GetTopWindow GetQueueStatus SetDlgItemTextW LoadAcceleratorsW EnableMenuItem GetMenu CreateWindowExW RegisterClassExW LoadCursorW DestroyIcon IsCharAlphaW IsZoomed VkKeyScanExW MapVirtualKeyExW GetKeyboardLayoutNameW ActivateKeyboardLayout GetGUIThreadInfo GetWindowTextW mouse_event WindowFromPoint GetSystemMetrics keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey PostQuitMessage SendMessageTimeoutW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx GetKeyboardLayout CallNextHookEx CharLowerW ReleaseDC GetDC OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard PostMessageW FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow CountClipboardFormats SetWindowLongW ScreenToClient IsDialogMessageW GetDlgItem SendDlgItemMessageW DialogBoxParamW SetForegroundWindow DefWindowProcW FillRect DrawIconEx GetSysColorBrush GetSysColor RegisterWindowMessageW GetMonitorInfoW EnumDisplayMonitors SetClipboardViewer IsIconic SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow EnumWindows GetWindowTextLengthW EnableWindow InvalidateRect SetLayeredWindowAttributes SetWindowPos SetWindowRgn SetFocus SetActiveWindow EnumChildWindows MoveWindow GetWindowRect GetClientRect SystemParametersInfoW AdjustWindowRectEx DrawTextW SetRect GetIconInfo SetWindowTextW IsWindowVisible BlockInput GetMessageW SetTimer GetParent GetDlgCtrlID CharUpperW IsClipboardFormatAvailable CheckMenuItem LoadImageW MapVirtualKeyW ChangeClipboardChain DestroyWindow |
| GDI32.dll |
GetPixel
GetClipRgn GetCharABCWidthsW SetBkMode CreatePatternBrush SetBrushOrgEx EnumFontFamiliesExW CreateDIBSection GdiFlush SetBkColor ExcludeClipRect SetTextColor GetClipBox BitBlt CreateCompatibleBitmap GetSystemPaletteEntries GetDIBits CreateCompatibleDC CreatePolygonRgn CreateRectRgn CreateRoundRectRgn CreateEllipticRgn DeleteDC GetObjectW GetTextMetricsW GetTextFaceW SelectObject GetStockObject CreateDCW CreateSolidBrush CreateFontW FillRgn GetDeviceCaps DeleteObject |
| COMDLG32.dll |
CommDlgExtendedError
GetSaveFileNameW GetOpenFileNameW |
| ADVAPI32.dll |
RegDeleteKeyW
RegSetValueExW RegCreateKeyExW RegQueryValueExW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW GetUserNameW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegOpenKeyExW RegCloseKey RegConnectRegistryW RegDeleteValueW |
| SHELL32.dll |
DragQueryPoint
SHEmptyRecycleBinW SHFileOperationW SHGetPathFromIDListW SHBrowseForFolderW SHGetDesktopFolder SHGetMalloc SHGetFolderPathW ShellExecuteExW Shell_NotifyIconW DragFinish DragQueryFileW ExtractIconW |
| ole32.dll |
OleInitialize
OleUninitialize CoCreateInstance CoInitialize CoUninitialize CLSIDFromString CLSIDFromProgID CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
| OLEAUT32.dll |
SafeArrayGetLBound
GetActiveObject SysStringLen OleLoadPicture SafeArrayUnaccessData SafeArrayGetElemsize SafeArrayAccessData SafeArrayUnlock SafeArrayPtrOfIndex SafeArrayLock SafeArrayGetDim SafeArrayDestroy SafeArrayGetUBound VariantCopyInd SafeArrayCopy SysAllocString VariantChangeType VariantClear SafeArrayCreate SysFreeString |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.33.10 |
| ProductVersion | 1.1.33.10 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 1.1.33.10 |
| ProductVersion (#2) | 1.1.33.10 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x17a34758 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 SP1 build 40219) | 53 |
| C objects (VS2010 SP1 build 40219) | 144 |
| C objects (VS2008 SP1 build 30729) | 6 |
| 135 (VS2008 SP1 build 30729) | 1 |
| Imports (VS2008 SP1 build 30729) | 29 |
| Total imports | 467 |
| ASM objects (VS2010 SP1 build 40219) | 23 |
| 175 (VS2010 SP1 build 40219) | 43 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.