| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| TLS Callbacks | 1 callback(s) detected. |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Suspicious | The PE is possibly packed. | Unusual section name found: /4 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. |
Resource TFRMKONFIG is possibly compressed or encrypted.
Resource TFRMSPLASH is possibly compressed or encrypted. |
| Suspicious | The file contains overlay data. | 19 bytes of data starting at offset 0x1425e00. |
| Safe | VirusTotal score: 0/68 (Scanned on 2021-09-16 16:36:16) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0x1425e00 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 3.0 |
| SizeOfCode | 0x9a4080 |
| SizeOfInitializedData | 0xb4dd4 |
| SizeOfUninitializedData | 0xf65ec8 |
| AddressOfEntryPoint | 0x00000000000034C0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x100000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2391000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x1000000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetStdHandle
GetConsoleMode TlsGetValue GetModuleFileNameW GetLastError SetLastError GetTickCount ExitProcess GetStartupInfoA GetCommandLineA GetCurrentProcessId GetCurrentThreadId GetCurrentProcess ReadProcessMemory GetModuleFileNameA GetModuleHandleA WriteFile ReadFile CloseHandle SetFilePointer SetEndOfFile GetSystemInfo LoadLibraryW LoadLibraryA GetProcAddress FreeLibrary FormatMessageW DeleteFileW MoveFileW CreateFileW GetFileAttributesW CreateDirectoryW SetCurrentDirectoryW GetCurrentDirectoryW GetFullPathNameW SetEnvironmentVariableW GetConsoleOutputCP GetOEMCP GetProcessHeap HeapAlloc HeapFree TlsAlloc TlsSetValue CreateThread ExitThread LocalAlloc LocalFree Sleep SuspendThread ResumeThread TerminateThread WaitForSingleObject SetThreadPriority GetThreadPriority CreateEventA ResetEvent SetEvent InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection GetEnvironmentStringsW FreeEnvironmentStringsW RaiseException MultiByteToWideChar WideCharToMultiByte GetACP GetConsoleCP RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind RtlUnwindEx GetEnvironmentStringsA FreeEnvironmentStringsA FormatMessageA CreateMutexA GetLogicalDriveStringsA LoadLibraryExA FindResourceA FindResourceExA EnumResourceTypesA EnumResourceNamesA EnumResourceLanguagesA GlobalAddAtomA GetProfileStringA GetDriveTypeA GetTempPathA GetTempFileNameA GetWindowsDirectoryA CreateFileA GetFileAttributesExA SetVolumeLabelA GetComputerNameA GetVersionExA CompareStringA GetLocaleInfoA GetDateFormatA EnumCalendarInfoA EnumSystemLocalesA EnumSystemCodePagesA GetShortPathNameW GetCommandLineW SetFileAttributesW CreateProcessW FindFirstFileW FindNextFileW CompareStringW GetLocaleInfoW GetDateFormatW FindFirstFileExW FreeResource LockResource GlobalAlloc GlobalReAlloc GlobalSize GlobalLock GlobalUnlock GlobalFree VirtualQuery GetProcessAffinityMask TerminateProcess GetExitCodeProcess GetExitCodeThread SetErrorMode LoadResource SizeofResource GlobalDeleteAtom LockFile UnlockFile FlushFileBuffers DeviceIoControl FindClose GetFileTime SetFileTime DuplicateHandle ClearCommBreak ClearCommError SetupComm EscapeCommFunction GetCommModemStatus GetCommState PurgeComm SetCommBreak SetCommMask SetCommState SetCommTimeouts WaitCommEvent MulDiv GetLocalTime GetTimeZoneInformation FileTimeToLocalFileTime LocalFileTimeToFileTime FileTimeToSystemTime FileTimeToDosDateTime DosDateTimeToFileTime CreatePipe PeekNamedPipe QueryPerformanceCounter QueryPerformanceFrequency GetCPInfo GetThreadLocale SetThreadLocale GetUserDefaultLCID GetDiskFreeSpaceExA GetOverlappedResult |
|---|---|
| oleaut32.dll |
SysAllocStringLen
SysFreeString SysReAllocStringLen SafeArrayCreate SafeArrayRedim SafeArrayGetUBound SafeArrayGetLBound SafeArrayAccessData SafeArrayUnaccessData SafeArrayGetElement SafeArrayPutElement SafeArrayPtrOfIndex VariantChangeTypeEx VariantClear VariantCopy VariantInit |
| user32.dll |
MessageBoxA
CharUpperBuffW CharLowerBuffW PeekMessageA SendMessageA PostMessageA DefWindowProcA CallWindowProcA RegisterClassA UnregisterClassA GetClassInfoA CreateWindowExA RegisterClipboardFormatA GetClipboardFormatNameA CharToOemA OemToCharA CharToOemBuffA OemToCharBuffA CharUpperA CharUpperBuffA CharLowerA CharLowerBuffA GetMenuItemInfoA SetPropA GetPropA RemovePropA EnumPropsA GetWindowLongA SetWindowLongA GetClassLongPtrA SetClassLongPtrA FindWindowA GetClassNameA LoadBitmapA LoadCursorA LoadIconA LoadImageA SystemParametersInfoA DispatchMessageW PeekMessageW SendMessageW PostMessageW DefWindowProcW CallWindowProcW RegisterClassW UnregisterClassW GetClassInfoW CreateWindowExW InsertMenuItemW GetMenuItemInfoW SetMenuItemInfoW DrawTextW DrawStateW SetWindowTextW GetWindowTextW GetWindowTextLengthW MessageBoxW GetWindowLongPtrW SetWindowLongPtrW TranslateMessage PostQuitMessage GetDoubleClickTime IsWindow IsMenu DestroyWindow ShowWindow ShowWindowAsync ShowOwnedPopups MoveWindow SetWindowPos GetWindowPlacement SetWindowPlacement BeginDeferWindowPos DeferWindowPos EndDeferWindowPos IsWindowVisible IsIconic BringWindowToTop IsZoomed GetDlgItem OpenClipboard CloseClipboard SetClipboardData GetClipboardData CountClipboardFormats EnumClipboardFormats EmptyClipboard IsClipboardFormatAvailable SetFocus GetActiveWindow GetFocus GetKeyState GetCapture SetCapture ReleaseCapture MsgWaitForMultipleObjects SetTimer KillTimer EnableWindow IsWindowEnabled GetSystemMetrics GetMenu SetMenu DrawMenuBar GetSystemMenu CreateMenu CreatePopupMenu DestroyMenu EnableMenuItem GetSubMenu GetMenuItemCount RemoveMenu DeleteMenu UpdateWindow SetActiveWindow GetForegroundWindow SetForegroundWindow WindowFromDC GetDC GetDCEx GetWindowDC ReleaseDC BeginPaint EndPaint GetUpdateRect SetWindowRgn InvalidateRect InvalidateRgn RedrawWindow ScrollWindowEx ShowScrollBar EnableScrollBar GetClientRect GetWindowRect AdjustWindowRectEx MessageBeep SetCursorPos SetCursor GetCursorPos ClipCursor CreateCaret GetCaretBlinkTime DestroyCaret HideCaret ShowCaret SetCaretPos GetCaretPos ClientToScreen ScreenToClient MapWindowPoints WindowFromPoint GetSysColor GetSysColorBrush SetSysColors DrawFocusRect FillRect FrameRect SetRect InflateRect IntersectRect OffsetRect IsRectEmpty PtInRect GetDesktopWindow GetParent SetParent EnumThreadWindows GetTopWindow GetWindowThreadProcessId GetLastActivePopup GetWindow CallNextHookEx DestroyCursor DestroyIcon CopyImage CreateIconIndirect GetIconInfo SetScrollInfo GetScrollInfo DrawEdge DrawFrameControl TrackPopupMenuEx ChildWindowFromPointEx FlashWindowEx |
| advapi32.dll |
GetUserNameA
RegQueryInfoKeyA RegSetValueExW RegQueryValueExW RegCreateKeyExW RegEnumKeyExW RegEnumValueW RegOpenKeyExW RegCloseKey RegFlushKey |
| gdi32.dll |
CreateFontIndirectA
EnumFontFamiliesA GetCharABCWidthsA GetTextExtentPointA CreateEnhMetaFileA GetEnhMetaFileDescriptionA GetTextMetricsA StartDocA GetObjectA ExtTextOutA CreateFontIndirectW CreateICW EnumFontFamiliesExW GetCharABCWidthsW GetTextExtentPoint32W GetTextExtentExPointW ResetDCW StartDocW GetObjectW TextOutW ExtTextOutW CreateDCW GetRandomRgn Arc BitBlt Chord CombineRgn CreateBitmap CreateBrushIndirect CreateCompatibleBitmap CreateCompatibleDC CreateDIBitmap CreateEllipticRgn CreatePen CreatePenIndirect CreatePatternBrush CreateRectRgn CreateRoundRectRgn CreateSolidBrush DeleteDC DeleteObject Ellipse EqualRgn ExcludeClipRect ExtCreateRegion ExtFloodFill FillRgn GetROP2 GetBkColor GetBitmapBits GetClipBox GetClipRgn GetCurrentObject GetDeviceCaps GetDIBits GetMapMode GetObjectType GetPixel GetRegionData GetRgnBox GetStockObject GetTextAlign GetTextColor GetViewportExtEx GetViewportOrgEx GetWindowExtEx GetWindowOrgEx IntersectClipRect LineTo MaskBlt OffsetRgn PatBlt Pie PaintRgn PtInRegion RectInRegion RectVisible Rectangle RestoreDC RealizePalette RoundRect SaveDC SelectClipRgn ExtSelectClipRgn SelectObject SelectPalette SetBkColor SetBkMode SetMapMode SetPixel SetPolyFillMode StretchBlt SetRectRgn StretchDIBits SetROP2 SetStretchBltMode SetTextCharacterExtra SetTextColor SetTextAlign SetTextJustification CloseEnhMetaFile DeleteEnhMetaFile GetEnhMetaFileHeader PlayEnhMetaFile CreateDIBSection EndDoc StartPage EndPage AbortDoc SetAbortProc BeginPath CloseFigure EndPath SetArcDirection StrokePath ExtCreatePen MoveToEx CreatePolygonRgn DPtoLP LPtoDP Polygon Polyline PolyBezier SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx OffsetViewportOrgEx SetBrushOrgEx GetDCOrgEx ChoosePixelFormat |
| version.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
| shell32.dll |
DragQueryFileA
ShellExecuteA DragQueryFileW ShellExecuteW DragFinish DragAcceptFiles SHGetPathFromIDListW SHBrowseForFolderW |
| ole32.dll |
CoCreateGuid
CoTaskMemFree IsEqualGUID OleInitialize OleUninitialize CoUninitialize CoCreateInstance CoInitialize CoGetMalloc CoTaskMemAlloc GetErrorInfo |
| comctl32.dll |
InitCommonControls
ImageList_Create ImageList_Destroy ImageList_GetImageCount ImageList_SetImageCount ImageList_Add ImageList_Replace ImageList_AddMasked ImageList_DrawEx ImageList_DrawIndirect ImageList_Remove ImageList_Copy ImageList_BeginDrag ImageList_EndDrag ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock _TrackMouseEvent FlatSB_GetScrollInfo FlatSB_GetScrollPos FlatSB_SetScrollPos FlatSB_SetScrollInfo FlatSB_SetScrollProp InitializeFlatSB |
| shlwapi.dll |
AssocQueryStringW
|
| comdlg32.dll |
ChooseColorA
CommDlgExtendedError GetOpenFileNameW GetSaveFileNameW PrintDlgW PageSetupDlgW |
| winspool.drv |
DeviceCapabilitiesA
DeviceCapabilitiesW OpenPrinterW ClosePrinter DocumentPropertiesW EnumPrintersW GetPrinterA StartDocPrinterA StartPagePrinter EndDocPrinter EndPagePrinter AbortPrinter WritePrinter |
| imm32.dll |
ImmGetContext
ImmReleaseContext ImmGetCompositionStringW ImmNotifyIME |
| StartAddressOfRawData | 0x100000000 |
|---|---|
| EndAddressOfRawData | 0x100000000 |
| AddressOfIndex | 0x100a5add0 |
| AddressOfCallbacks | 0x1021c5000 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0000000100003440
|
No comments yet.