| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Oct-14 11:26:56 |
| Debug artifacts |
D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
|
| CompanyName | SecHex |
| FileDescription | SecHex-GUI |
| FileVersion | 1.0.0.0 |
| InternalName | SecHex-GUI.dll |
| LegalCopyright | |
| OriginalFilename | SecHex-GUI.dll |
| ProductName | Spoofy |
| ProductVersion | 1.0.0 |
| Assembly Version | 1.0.0.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/72 (Scanned on 2025-07-17 00:22:10) |
Malwarebytes:
RiskWare.Agent
Webroot: W32.Hack.Tool |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2024-Oct-14 11:26:56 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x18600 |
| SizeOfInitializedData | 0xf200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000014050 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x180000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FindNextFileW
GetCurrentProcess GetModuleHandleExW GetModuleFileNameW LeaveCriticalSection GetEnvironmentVariableW FindClose MultiByteToWideChar GetLastError GetFileAttributesExW GetFullPathNameW GetProcAddress DeleteCriticalSection WideCharToMultiByte IsWow64Process LoadLibraryExW FreeLibrary TlsFree TlsSetValue TlsGetValue TlsAlloc EnterCriticalSection FindFirstFileExW OutputDebugStringW LoadLibraryA GetModuleHandleW InitializeCriticalSectionAndSpinCount SetLastError RaiseException RtlPcToFileHeader RtlUnwindEx InitializeSListHead GetCurrentProcessId IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetStringTypeW SwitchToThread GetCurrentThreadId InitializeCriticalSectionEx EncodePointer DecodePointer LCMapStringEx QueryPerformanceCounter GetSystemTimeAsFileTime |
|---|---|
| USER32.dll |
MessageBoxW
|
| SHELL32.dll |
ShellExecuteW
|
| ADVAPI32.dll |
RegOpenKeyExW
RegGetValueW DeregisterEventSource RegisterEventSourceW ReportEventW RegCloseKey |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
__p___wargv _initterm _get_initial_wide_environment _initialize_wide_environment _errno _configure_wide_argv _invalid_parameter_noinfo_noreturn _set_app_type _seh_filter_exe _c_exit exit _cexit _register_thread_local_exe_atexit_callback _crt_atexit _exit _initterm_e abort _register_onexit_function _initialize_onexit_table terminate |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
__stdio_common_vsprintf_s setvbuf _wfopen _set_fmode __stdio_common_vswprintf __acrt_iob_func fputwc fputws __stdio_common_vfwprintf fflush |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free malloc calloc |
| api-ms-win-crt-string-l1-1-0.dll |
wcsnlen
strcpy_s _wcsdup strcspn wcsncmp toupper |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
wcstoul |
| api-ms-win-crt-locale-l1-1-0.dll |
__pctype_func
_unlock_locales localeconv _lock_locales ___lc_codepage_func ___mb_cur_max_func _configthreadlocale setlocale ___lc_locale_name_func |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
frexp |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64_s
wcsftime _time64 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | SecHex |
| FileDescription | SecHex-GUI |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | SecHex-GUI.dll |
| LegalCopyright | |
| OriginalFilename | SecHex-GUI.dll |
| ProductName | Spoofy |
| ProductVersion (#2) | 1.0.0 |
| Assembly Version | 1.0.0.0 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Oct-15 03:29:49 |
| Version | 0.0 |
| SizeofData | 109 |
| AddressOfRawData | 0x1ff78 |
| PointerToRawData | 0x1e978 |
| Referenced File | D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Oct-15 03:29:49 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1ffe8 |
| PointerToRawData | 0x1e9e8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Oct-15 03:29:49 |
| Version | 0.0 |
| SizeofData | 964 |
| AddressOfRawData | 0x1fffc |
| PointerToRawData | 0x1e9fc |
| StartAddressOfRawData | 0x1400203e0 |
|---|---|
| EndAddressOfRawData | 0x1400203f0 |
| AddressOfIndex | 0x140025940 |
| AddressOfCallbacks | 0x14001a4c8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140024020 |
| GuardCFCheckFunctionPointer | 5368816648 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x4ad45e8d |
|---|---|
| Unmarked objects | 0 |
| C objects (30034) | 12 |
| ASM objects (30034) | 10 |
| C++ objects (30034) | 83 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (29395) | 9 |
| Total imports | 205 |
| C++ objects (LTCG) (30154) | 10 |
| Linker (30154) | 1 |
No comments yet.