Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Oct-25 17:19:32 |
TLS Callbacks | 1 callback(s) detected. |
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/71 (Scanned on 2024-02-12 17:05:48) | Jiangmin: TrojanDropper.Dapato.adsa |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 5 |
TimeDateStamp | 2023-Oct-25 17:19:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xdc5800 |
SizeOfInitializedData | 0x560800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000D6AD9C (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x132a000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntdll.dll |
RtlLookupFunctionEntry
RtlVirtualUnwind RtlCaptureContext NtCreateFile RtlNtStatusToDosError NtCancelIoFileEx NtWriteFile NtDeviceIoControlFile NtReadFile |
---|---|
kernel32.dll |
SystemTimeToFileTime
GetCurrentProcess GetNativeSystemInfo LocalFree UnmapViewOfFile FindClose TryAcquireSRWLockExclusive FreeLibrary SetThreadErrorMode LoadLibraryExW GetProcAddress ReleaseSRWLockShared AcquireSRWLockShared GetCurrentProcessId GetExitCodeProcess WakeAllConditionVariable PostQueuedCompletionStatus GetSystemInfo SystemTimeToTzSpecificLocalTime lstrlenW GlobalLock CreateSemaphoreW Sleep FormatMessageW CreateConsoleScreenBuffer WaitForSingleObject GetFileInformationByHandle CreateFileMappingW MapViewOfFile DuplicateHandle VirtualProtect CreateIoCompletionPort GetQueuedCompletionStatusEx ReadConsoleInputW CreateFileW GetStdHandle WaitForMultipleObjects FillConsoleOutputAttribute FillConsoleOutputCharacterA GetLastError SetConsoleMode GetConsoleMode GetModuleHandleA SleepConditionVariableSRW WakeConditionVariable GetNumberOfConsoleInputEvents SetConsoleActiveScreenBuffer SetConsoleTextAttribute FreeEnvironmentStringsW ReleaseMutex CompareStringOrdinal TzSpecificLocalTimeToSystemTime IsProcessorFeaturePresent SetLastError GetCurrentDirectoryW GetEnvironmentVariableW GetConsoleScreenBufferInfo GetCommandLineW SetFilePointerEx GetOverlappedResult TerminateProcess QueryPerformanceFrequency SetConsoleCursorPosition ReadFileEx SleepEx WriteFileEx WaitForSingleObjectEx LoadLibraryA CreateMutexA FindNextFileW GetFileInformationByHandleEx SetFileInformationByHandle CreateDirectoryW FindFirstFileW DeleteFileW MoveFileExW RemoveDirectoryW DeviceIoControl GetFinalPathNameByHandleW SetConsoleCursorInfo SetHandleInformation GetModuleHandleW GetModuleFileNameW SetCurrentDirectoryW ExitProcess GetFullPathNameW CreateNamedPipeW CreateEventW ReadFile CancelIo GetEnvironmentStringsW GetSystemDirectoryW GetWindowsDirectoryW CreateProcessW GetFileAttributesW WriteConsoleW ReadConsoleW CreateThread GetSystemTimeAsFileTime CreatePipe RegisterWaitForSingleObject UnregisterWaitEx AcquireSRWLockExclusive CloseHandle AddVectoredExceptionHandler ReleaseSRWLockExclusive ReleaseSemaphore QueryPerformanceCounter SwitchToThread GlobalUnlock GlobalFree GlobalAlloc GetCurrentThread HeapReAlloc HeapFree GetProcessHeap HeapAlloc MultiByteToWideChar GetCurrentThreadId InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter WideCharToMultiByte SetFileCompletionNotificationModes GlobalSize GetProcessId SetThreadStackGuarantee |
bcrypt.dll |
BCryptGenRandom
|
advapi32.dll |
RegEnumKeyExW
GetNamedSecurityInfoW SystemFunction036 CheckTokenMembership RegQueryValueExW RegOpenKeyExW EqualSid IsWellKnownSid OpenThreadToken OpenProcessToken RegCloseKey GetTokenInformation |
ole32.dll |
CoTaskMemFree
CoCreateInstance CoInitializeEx |
oleaut32.dll |
GetErrorInfo
SysStringLen SysFreeString |
user32.dll |
ToUnicodeEx
GetKeyboardLayout SetClipboardData CloseClipboard GetClipboardData EmptyClipboard GetForegroundWindow GetWindowThreadProcessId OpenClipboard |
shell32.dll |
SHGetFolderPathW
SHGetKnownFolderPath |
ws2_32.dll |
closesocket
listen WSAGetLastError getsockopt WSAIoctl recv send WSASend bind connect socket ioctlsocket WSAStartup WSACleanup freeaddrinfo getaddrinfo WSASocketW getsockname shutdown |
userenv.dll |
GetUserProfileDirectoryW
|
VCRUNTIME140.dll |
__CxxFrameHandler3
memmove memcmp __current_exception_context __current_exception __C_specific_handler memcpy _CxxThrowException memset |
api-ms-win-crt-runtime-l1-1-0.dll |
strerror
_set_app_type _register_thread_local_exe_atexit_callback terminate _c_exit _cexit _crt_atexit __p___argv __p___argc _exit exit _initterm_e _wassert _initterm _get_initial_narrow_environment _seh_filter_exe _register_onexit_function _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table |
api-ms-win-crt-string-l1-1-0.dll |
iswctype
strncmp strlen wcslen |
api-ms-win-crt-math-l1-1-0.dll |
pow
_fdopen __setusermatherr fmod |
api-ms-win-crt-heap-l1-1-0.dll |
realloc
malloc calloc free _set_new_mode |
api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
__acrt_iob_func fclose fputc __stdio_common_vsprintf _set_fmode __stdio_common_vfprintf fputs |
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-25 17:19:32 |
Version | 0.0 |
SizeofData | 836 |
AddressOfRawData | 0x10322c8 |
PointerToRawData | 0x1030ec8 |
StartAddressOfRawData | 0x141032630 |
---|---|
EndAddressOfRawData | 0x1410328c8 |
AddressOfIndex | 0x141277fc0 |
AddressOfCallbacks | 0x140dc7878 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks |
0x0000000140C9F6C0
|
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x141277c18 |
XOR Key | 0xe02fd0cc |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 12 |
Imports (VS 2015-2022 runtime 32533) | 2 |
253 (VS 2015-2022 runtime 32533) | 1 |
C++ objects (VS 2015-2022 runtime 32533) | 24 |
C objects (VS 2015-2022 runtime 32533) | 10 |
ASM objects (VS 2015-2022 runtime 32533) | 4 |
Imports (30148) | 18 |
Imports (30795) | 3 |
Total imports | 244 |
C objects (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
Unmarked objects (#2) | 1040 |
Linker (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |