Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Feb-09 22:00:17 |
Detected languages |
English - United States
|
Debug artifacts |
d:\build\ob\bora-17592369\bora-vmsoft\build\release-x64\svga\wddm\src\service\Win8Release\x64\bin\vm3dservice.pdb
|
CompanyName | VMware, Inc. |
FileDescription | VMware SVGA Helper Service |
FileVersion | 8.17.02.0014 |
InternalName | vm3dservice.exe |
LegalCopyright | Copyright (C) 1998-2020 VMware, Inc. |
OriginalFilename | vm3dservice.exe |
ProductName | VMware SVGA 3D |
ProductVersion | 8.17.02.0014 - build-17592369 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Suspicious | The PE is possibly packed. | Unusual section name found: .gehcont |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: VMware
Issuer: DigiCert Assured ID Code Signing CA-1 |
Suspicious | VirusTotal score: 1/69 (Scanned on 2023-03-09 21:14:45) | Zillya: Trojan.GenCBL.Win32.11189 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x128 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2021-Feb-09 22:00:17 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x69200 |
SizeOfInitializedData | 0x21000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000006030 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x90000 |
SizeOfHeaders | 0x400 |
Checksum | 0x8fbb0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
VerifyVersionInfoW
WTSGetActiveConsoleSessionId FreeLibrary GetTickCount64 ProcessIdToSessionId RtlUnwind RtlCaptureStackBackTrace SetEndOfFile WriteConsoleW HeapReAlloc HeapSize ReadConsoleW ResumeThread SetFilePointerEx LoadLibraryW SetConsoleCtrlHandler GetProcessHeap GetStringTypeW SetStdHandle SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW GetProcAddress GetFileSizeEx GetModuleHandleW GetCurrentThreadId TerminateProcess GetCurrentProcessId GetCurrentProcess GetLastError CloseHandle ReadFile VerSetConditionMask FindFirstFileExW OutputDebugStringW WideCharToMultiByte MultiByteToWideChar GetConsoleMode GetConsoleOutputCP FindClose FindFirstFileA FindNextFileA GetLocalTime FatalExit RtlCaptureContext CreateDirectoryW CreateFileW DeleteFileW GetTempPathW RaiseException MoveFileW RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW EncodePointer RtlPcToFileHeader CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetFileType HeapFree HeapAlloc GetCurrentThread GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FlushFileBuffers |
---|---|
USER32.dll |
OpenInputDesktop
CloseDesktop GetMessageW SetThreadDesktop UnhookWinEvent SetWinEventHook EnumDisplayDevicesW LoadCursorW SetRect AdjustWindowRectEx GetClientRect UpdateWindow ShowWindow CreateWindowExW RegisterClassExW UnregisterClassW PostQuitMessage DefWindowProcW UnregisterPowerSettingNotification RegisterPowerSettingNotification DispatchMessageW TranslateMessage EnumDisplayMonitors RegisterWindowMessageW GetUserObjectInformationA GetSystemMetrics EnumDisplaySettingsW GetMonitorInfoW GetThreadDesktop |
GDI32.dll |
CreateDCW
DeleteDC |
ADVAPI32.dll |
StartServiceCtrlDispatcherW
SetServiceStatus RegisterServiceCtrlHandlerExA SetTokenInformation DuplicateTokenEx OpenProcessToken CreateProcessAsUserW RegOpenKeyExA RegCloseKey RegQueryValueExA |
SHELL32.dll |
SHGetFolderPathW
|
dwmapi.dll |
DwmIsCompositionEnabled
|
WTSAPI32.dll |
WTSRegisterSessionNotification
|
dbghelp.dll |
SymFunctionTableAccess64
MiniDumpWriteDump SymSetSearchPath SymGetSearchPath StackWalk64 SymSetOptions SymCleanup SymFromAddr SymGetModuleBase64 SymGetLineFromAddr64 SymInitialize |
WINMM.dll |
timeGetTime
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 8.17.2.14 |
ProductVersion | 8.17.2.14 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DRV
|
FileSubtype | VFT2_DRV_DISPLAY |
Language | English - United States |
CompanyName | VMware, Inc. |
FileDescription | VMware SVGA Helper Service |
FileVersion (#2) | 8.17.02.0014 |
InternalName | vm3dservice.exe |
LegalCopyright | Copyright (C) 1998-2020 VMware, Inc. |
OriginalFilename | vm3dservice.exe |
ProductName | VMware SVGA 3D |
ProductVersion (#2) | 8.17.02.0014 - build-17592369 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Feb-09 22:00:17 |
Version | 0.0 |
SizeofData | 138 |
AddressOfRawData | 0x79fa4 |
PointerToRawData | 0x785a4 |
Referenced File | d:\build\ob\bora-17592369\bora-vmsoft\build\release-x64\svga\wddm\src\service\Win8Release\x64\bin\vm3dservice.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Feb-09 22:00:17 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x7a030 |
PointerToRawData | 0x78630 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Feb-09 22:00:17 |
Version | 0.0 |
SizeofData | 804 |
AddressOfRawData | 0x7a044 |
PointerToRawData | 0x78644 |
Size | 0x130 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140083018 |
GuardCFCheckFunctionPointer | 5369148744 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xa98cb5c3 |
---|---|
Unmarked objects | 0 |
C objects (27412) | 11 |
ASM objects (27412) | 5 |
C++ objects (27412) | 161 |
ASM objects (VS 2015/2017/2019 runtime 28920) | 9 |
C objects (VS 2015/2017/2019 runtime 28920) | 16 |
C++ objects (VS 2015/2017/2019 runtime 28920) | 37 |
C++ objects (VS2015 UPD1 build 23506) | 1 |
ASM objects (VS2017 v15.9.7-10 compiler 27027) | 1 |
C++ objects (CVTCIL) (26213) | 1 |
Imports (26213) | 19 |
Total imports | 160 |
C objects (VS2017 v15.9.7-10 compiler 27027) | 8 |
Resource objects (VS2017 v15.9.7-10 compiler 27027) | 1 |
151 | 1 |
Linker (VS2017 v15.9.7-10 compiler 27027) | 1 |