Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Nov-20 22:37:22 |
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
hooks.pdb
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 5 |
TimeDateStamp | 2024-Nov-20 22:37:22 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x3a000 |
SizeOfInitializedData | 0x1e200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000383EC (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x5b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
---|---|
ntdll.dll |
RtlCaptureContext
RtlNtStatusToDosError RtlVirtualUnwind RtlLookupFunctionEntry NtWriteFile |
KERNEL32.dll |
SetUnhandledExceptionFilter
UnhandledExceptionFilter IsDebuggerPresent InitializeSListHead DisableThreadLibraryCalls CreateMutexA LoadLibraryA WaitForSingleObjectEx ReadProcessMemory GetTickCount GetSystemTimeAsFileTime CreateWaitableTimerExA CreateWaitableTimerExW GetCurrentThreadId CloseHandle GetCurrentProcess GetProcessId CreateToolhelp32Snapshot VirtualAllocEx Thread32Next Thread32First Module32Next Module32First VirtualFreeEx WriteProcessMemory DuplicateHandle RegisterWaitForSingleObject UnregisterWait CreateEventA WaitForSingleObject SetEvent ResetEvent WriteFile PeekNamedPipe ReadFile GetThreadContext SetThreadContext OpenThread SuspendThread ResumeThread GetLastError HeapCreate HeapAlloc HeapReAlloc HeapFree Sleep GetCurrentProcessId FlushInstructionCache VirtualProtect GetModuleHandleW GetProcAddress GetSystemInfo VirtualAlloc VirtualFree VirtualQuery QueryPerformanceCounter SetLastError GetCurrentDirectoryW GetEnvironmentVariableW GetStdHandle TerminateProcess lstrlenW ReleaseMutex GetProcessHeap IsProcessorFeaturePresent GetConsoleMode FormatMessageW MultiByteToWideChar WriteConsoleW WideCharToMultiByte |
USER32.dll |
PeekMessageW
PeekMessageA IsWindowVisible EnumThreadWindows GetKeyState |
VCRUNTIME140.dll |
memcpy
memset _CxxThrowException __CxxFrameHandler3 __std_type_info_destroy_list __C_specific_handler memcmp memmove |
api-ms-win-crt-string-l1-1-0.dll |
strlen
|
api-ms-win-crt-math-l1-1-0.dll |
round
|
api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_initterm_e _seh_filter_dll _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _execute_onexit_table _cexit |
api-ms-win-crt-heap-l1-1-0.dll |
free
|
Ordinal | 1 |
---|---|
Address | 0x91c0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Nov-20 22:37:22 |
Version | 0.0 |
SizeofData | 34 |
AddressOfRawData | 0x4b0b4 |
PointerToRawData | 0x4a4b4 |
Referenced File | hooks.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Nov-20 22:37:22 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x4b0d8 |
PointerToRawData | 0x4a4d8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Nov-20 22:37:22 |
Version | 0.0 |
SizeofData | 772 |
AddressOfRawData | 0x4b0ec |
PointerToRawData | 0x4a4ec |
StartAddressOfRawData | 0x18004b410 |
---|---|
EndAddressOfRawData | 0x18004b4b8 |
AddressOfIndex | 0x180055ad4 |
AddressOfCallbacks | 0x18003b3d8 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks |
0x0000000180025290
|
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x180055880 |
XOR Key | 0x56d93619 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 8 |
Imports (33808) | 2 |
ASM objects (33808) | 4 |
C objects (33808) | 8 |
C++ objects (33808) | 17 |
Imports (30795) | 10 |
Total imports | 211 |
C objects (34120) | 4 |
Unmarked objects (#2) | 52 |
Exports (34120) | 1 |
Linker (34120) | 1 |