Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Jan-08 16:38:13 |
Detected languages |
English - United States
|
Debug artifacts |
G:\Shared\Dropbox\Projects\WIN\SmoothScroll\x64\Release\SmoothScroll.pdb
|
CompanyName | Balázs Galambosi |
FileDescription | SmoothScroll |
FileVersion | 1.2.4.0 |
InternalName | SmoothScroll.exe |
LegalCopyright | Copyright (C) 2019 Balázs Galambosi |
OriginalFilename | SmoothScroll.exe |
ProductName | SmoothScroll |
ProductVersion | 1.2.4.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Bal\xC3\xA1zs Galambosi
Issuer: Sectigo RSA Code Signing CA |
Safe | VirusTotal score: 0/71 (Scanned on 2024-03-27 23:49:46) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2020-Jan-08 16:38:13 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xeb800 |
SizeOfInitializedData | 0x129e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000934EC (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x219000 |
SizeOfHeaders | 0x400 |
Checksum | 0x20c74e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
libexpat.dll |
#2
#19 #52 #31 #25 #21 #12 #63 #16 |
---|---|
WININET.dll |
InternetSetStatusCallbackW
HttpQueryInfoA InternetCloseHandle InternetOpenW InternetSetOptionW InternetOpenUrlA InternetQueryOptionA InternetReadFileExW InternetConnectW HttpOpenRequestW InternetCrackUrlA HttpSendRequestW InternetReadFile |
RPCRT4.dll |
RpcStringFreeW
UuidCreate UuidToStringW |
KERNEL32.dll |
GetLastError
lstrlenW LocalSize HeapDestroy HeapSize HeapReAlloc HeapFree HeapAlloc GetProcessHeap SizeofResource LockResource LoadResource FindResourceW FindResourceExW EnterCriticalSection LeaveCriticalSection FindFirstFileW FindNextFileW FindClose GetModuleFileNameW CreateDirectoryW DeleteFileW GetTempPathW CloseHandle CreateEventW SetEvent WaitForSingleObject VerSetConditionMask VerifyVersionInfoW FormatMessageA OutputDebugStringA InitializeCriticalSection DeleteCriticalSection FindResourceA Sleep RaiseException ResumeThread CreateSemaphoreW CreateJobObjectW SetInformationJobObject OpenProcess UnregisterWaitEx GetExitCodeProcess TerminateProcess InitializeCriticalSectionEx DecodePointer GetVersionExW GetVersion AssignProcessToJobObject RegisterWaitForSingleObject CreateProcessW LoadLibraryA GetProcAddress FreeLibrary FlushFileBuffers DisconnectNamedPipe ConnectNamedPipe CreateNamedPipeW GetNamedPipeClientProcessId ReadFile WriteFile GetFileAttributesW IsThreadpoolTimerSet SetThreadpoolTimer WaitForThreadpoolTimerCallbacks CloseThreadpoolTimer CreateThreadpoolTimer GetCurrentThreadId ReleaseSemaphore CreateThread SetPriorityClass GetCurrentProcess SetThreadPriority GetCurrentThread GetExitCodeThread TerminateThread QueryPerformanceFrequency QueryPerformanceCounter GetModuleHandleW LoadLibraryW GetThreadPriority GetPriorityClass SuspendThread CreateToolhelp32Snapshot Process32NextW GetCurrentProcessId LocalAlloc QueryFullProcessImageNameW MultiByteToWideChar CreateFileW SetFileTime LocalFileTimeToFileTime CreateFileA DosDateTimeToFileTime GetFileTime SetFilePointer VirtualAlloc LoadLibraryExW GetModuleHandleA FreeLibraryAndExitThread GetThreadTimes UnregisterWait SetThreadAffinityMask GetProcessAffinityMask GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation SignalObjectAndWait CreateTimerQueue InitializeSListHead GetStartupInfoW IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext ResetEvent GetLocaleInfoW LCMapStringW CompareStringW InterlockedPushEntrySList GetCPInfo GetTickCount GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError SwitchToThread WaitForSingleObjectEx DuplicateHandle EncodePointer RtlPcToFileHeader TryEnterCriticalSection GetStringTypeW WideCharToMultiByte OutputDebugStringW IsDebuggerPresent FormatMessageW LocalFree VirtualProtect VirtualFree InterlockedFlushSList QueryDepthSList RtlUnwindEx ExitProcess GetModuleHandleExW ExitThread SetConsoleCtrlHandler GetDriveTypeW GetFullPathNameW FindFirstFileExW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime GetFileInformationByHandle GetFileType PeekNamedPipe GetStdHandle GetCurrentDirectoryW GetFileAttributesExW SetStdHandle IsValidCodePage GetDateFormatW InterlockedPopEntrySList GetTimeFormatW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetConsoleCP GetConsoleMode GetFileSizeEx SetFilePointerEx GetTimeZoneInformation GetCommandLineW ReadConsoleW GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetEndOfFile WriteConsoleW Process32FirstW RtlUnwind |
USER32.dll |
EndPaint
UpdateWindow ShowWindow LoadCursorW DispatchMessageW TranslateMessage TranslateAcceleratorW LoadAcceleratorsW PostQuitMessage GetDesktopWindow BeginPaint SetMenuItemInfoW DrawMenuBar RemoveMenu GetGUIThreadInfo IsHungAppWindow GetRawInputData GetMessageW SendInput WindowFromPoint GetKeyState CallNextHookEx MonitorFromWindow UnhookWindowsHookEx MessageBoxA BringWindowToTop IsWindowVisible GetWindow SystemParametersInfoW GetWindowRect DefWindowProcW GetMenuItemID TrackPopupMenu SetForegroundWindow GetCursorPos SetMenuDefaultItem DestroyMenu GetSubMenu LoadMenuW LoadStringW KillTimer SetTimer LoadIconW DestroyWindow CreateWindowExW RegisterClassExW RegisterWindowMessageW EnumWindows GetWindowThreadProcessId PostMessageW GetMonitorInfoW GetShellWindow PostThreadMessageW SetWindowsHookExW GetForegroundWindow |
GDI32.dll |
DeleteDC
CreateDCW |
ADVAPI32.dll |
CryptHashData
CryptAcquireContextW RegDeleteValueA RegOpenKeyExA RegSetValueExW RegCreateKeyExA RegDeleteValueW RegQueryValueExW RegCreateKeyExW RegCloseKey CryptDestroyHash CryptDestroyKey CryptReleaseContext RegCreateKeyW RegGetValueW CryptCreateHash |
SHELL32.dll |
CommandLineToArgvW
ShellExecuteW SHGetSpecialFolderPathW SHFileOperationW ShellExecuteExW Shell_NotifyIconW |
ole32.dll |
CoInitializeEx
CoUninitialize CoCreateInstance |
WINMM.dll |
timeBeginPeriod
timeGetTime timeEndPeriod |
WTSAPI32.dll |
WTSRegisterSessionNotification
WTSUnRegisterSessionNotification |
SHLWAPI.dll |
SHDeleteKeyW
PathFileExistsW PathFindFileNameW |
VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoExW GetFileVersionInfoSizeExW GetFileVersionInfoW |
CRYPT32.dll |
CryptStringToBinaryA
CryptDecodeObjectEx CryptImportPublicKeyInfo |
SmoothScroll |
SMOOTHSCROLL |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.2.4.0 |
ProductVersion | 1.2.4.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Balázs Galambosi |
FileDescription | SmoothScroll |
FileVersion (#2) | 1.2.4.0 |
InternalName | SmoothScroll.exe |
LegalCopyright | Copyright (C) 2019 Balázs Galambosi |
OriginalFilename | SmoothScroll.exe |
ProductName | SmoothScroll |
ProductVersion (#2) | 1.2.4.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-08 16:38:13 |
Version | 0.0 |
SizeofData | 97 |
AddressOfRawData | 0x1201a4 |
PointerToRawData | 0x11eda4 |
Referenced File | G:\Shared\Dropbox\Projects\WIN\SmoothScroll\x64\Release\SmoothScroll.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-08 16:38:13 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x120208 |
PointerToRawData | 0x11ee08 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-08 16:38:13 |
Version | 0.0 |
SizeofData | 968 |
AddressOfRawData | 0x12021c |
PointerToRawData | 0x11ee1c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-08 16:38:13 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x140120608 |
---|---|
EndAddressOfRawData | 0x140120610 |
AddressOfIndex | 0x140159c28 |
AddressOfCallbacks | 0x1400ee108 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x100 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140141080 |
XOR Key | 0xbc04e94f |
---|---|
Unmarked objects | 0 |
ASM objects (26213) | 13 |
C++ objects (26213) | 206 |
ASM objects (VS 2015/2017 runtime 26706) | 9 |
C objects (VS 2015/2017 runtime 26706) | 38 |
C++ objects (VS 2015/2017 runtime 26706) | 130 |
C objects (26213) | 23 |
C objects (CVTCIL) (26213) | 1 |
Imports (26213) | 26 |
Imports (VS2017 v15.8.5-8 compiler 26730) | 3 |
Total imports | 360 |
C objects (VS2015 UPD3.1 build 24215) | 6 |
C++ objects (LTCG) (VS2017 v15.9.12-13 compiler 27031) | 40 |
Resource objects (VS2017 v15.9.12-13 compiler 27031) | 1 |
151 | 1 |
Linker (VS2017 v15.9.12-13 compiler 27031) | 1 |