Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1970-Jan-01 00:00:00 |
TLS Callbacks | 1 callback(s) detected. |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/70 (Scanned on 2019-11-18 20:09:59) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 3.0 |
SizeOfCode | 0x1affa0 |
SizeOfInitializedData | 0x1b3f4 |
SizeOfUninitializedData | 0x6c44 |
AddressOfEntryPoint | 0x0000000000015E20 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x100000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 1.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xfe8000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x1000000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetLastError
SetLastError GetTickCount ExitProcess GetStartupInfoA GetStdHandle GetCommandLineA GetCurrentProcessId GetCurrentThreadId GetCurrentProcess ReadProcessMemory GetModuleFileNameA GetModuleHandleA WriteFile ReadFile CloseHandle SetFilePointer SetEndOfFile FreeLibrary GetSystemInfo LoadLibraryA GetProcAddress CreateFileW GetFileAttributesW SetCurrentDirectoryW GetCurrentDirectoryW GetConsoleMode GetConsoleOutputCP GetOEMCP GetProcessHeap HeapAlloc HeapFree TlsAlloc TlsGetValue TlsSetValue CreateThread ExitThread LocalAlloc LocalFree Sleep SuspendThread ResumeThread TerminateThread WaitForSingleObject SetThreadPriority GetThreadPriority CreateEventA ResetEvent SetEvent InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection RaiseException MultiByteToWideChar WideCharToMultiByte GetACP GetConsoleCP RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind RtlUnwindEx EnumResourceTypesA EnumResourceNamesA EnumResourceLanguagesA FindResourceA FindResourceExA LoadResource SizeofResource LockResource FreeResource FormatMessageA GlobalAddAtomA GetWindowsDirectoryA GetVersionExA CompareStringA GetLocaleInfoA GetDateFormatA EnumCalendarInfoA GetEnvironmentStringsW FreeEnvironmentStringsW FormatMessageW GetModuleFileNameW GetCommandLineW CompareStringW GetLocaleInfoW GlobalAlloc GlobalReAlloc GlobalSize GlobalLock GlobalUnlock GetExitCodeProcess GlobalDeleteAtom MulDiv GetLocalTime PeekNamedPipe GetThreadLocale SetThreadLocale GetUserDefaultLCID |
---|---|
oleaut32.dll |
SysAllocStringLen
SysFreeString SysReAllocStringLen SafeArrayCreate SafeArrayRedim SafeArrayGetUBound SafeArrayGetLBound SafeArrayAccessData SafeArrayUnaccessData SafeArrayGetElement SafeArrayPutElement SafeArrayPtrOfIndex VariantChangeTypeEx VariantClear VariantCopy VariantInit |
user32.dll |
MessageBoxA
CharUpperBuffW CharLowerBuffW SendMessageA PostMessageA DefWindowProcA CallWindowProcA RegisterClassA UnregisterClassA GetClassInfoA CreateWindowExA RegisterClipboardFormatA GetClipboardFormatNameA CharToOemA CharUpperA CharUpperBuffA CharLowerA CharLowerBuffA GetMenuItemInfoA SetPropA GetPropA RemovePropA EnumPropsA GetWindowLongA SetWindowLongA SetClassLongPtrA GetClassNameA LoadBitmapA LoadCursorA LoadIconA LoadImageA SystemParametersInfoA DispatchMessageW PeekMessageW SendMessageW DefWindowProcW CallWindowProcW RegisterClassW UnregisterClassW GetClassInfoW CreateWindowExW InsertMenuItemW GetMenuItemInfoW SetMenuItemInfoW DrawTextW DrawStateW SetWindowTextW GetWindowTextW GetWindowTextLengthW MessageBoxW GetWindowLongPtrW SetWindowLongPtrW TranslateMessage PostQuitMessage GetDoubleClickTime IsWindow IsMenu DestroyWindow ShowWindow ShowWindowAsync ShowOwnedPopups SetWindowPos GetWindowPlacement SetWindowPlacement BeginDeferWindowPos DeferWindowPos EndDeferWindowPos IsWindowVisible IsIconic BringWindowToTop IsZoomed OpenClipboard CloseClipboard SetClipboardData GetClipboardData CountClipboardFormats EnumClipboardFormats EmptyClipboard IsClipboardFormatAvailable SetFocus GetActiveWindow GetFocus GetKeyState GetCapture SetCapture ReleaseCapture MsgWaitForMultipleObjects SetTimer KillTimer EnableWindow IsWindowEnabled GetSystemMetrics GetMenu SetMenu DrawMenuBar GetSystemMenu CreateMenu CreatePopupMenu DestroyMenu EnableMenuItem GetSubMenu GetMenuItemCount RemoveMenu DeleteMenu UpdateWindow SetActiveWindow GetForegroundWindow SetForegroundWindow WindowFromDC GetDC GetDCEx GetWindowDC ReleaseDC BeginPaint EndPaint GetUpdateRect SetWindowRgn InvalidateRect InvalidateRgn RedrawWindow ScrollWindowEx ShowScrollBar EnableScrollBar GetClientRect GetWindowRect AdjustWindowRectEx MessageBeep SetCursorPos SetCursor GetCursorPos CreateCaret DestroyCaret HideCaret ShowCaret SetCaretPos GetCaretPos ClientToScreen ScreenToClient MapWindowPoints WindowFromPoint GetSysColor GetSysColorBrush SetSysColors DrawFocusRect FillRect FrameRect SetRect InflateRect IntersectRect OffsetRect GetDesktopWindow GetParent SetParent EnumThreadWindows GetTopWindow GetWindowThreadProcessId GetLastActivePopup GetWindow CallNextHookEx DestroyCursor DestroyIcon CopyImage CreateIconIndirect GetIconInfo SetScrollInfo GetScrollInfo DrawEdge DrawFrameControl TrackPopupMenuEx ChildWindowFromPointEx FlashWindowEx |
gdi32.dll |
CreateFontIndirectA
EnumFontFamiliesA GetCharABCWidthsA GetTextExtentPointA GetTextMetricsA GetObjectA ExtTextOutA CreateFontIndirectW EnumFontFamiliesExW GetCharABCWidthsW GetTextExtentPoint32W GetTextExtentExPointW GetObjectW TextOutW ExtTextOutW GetRandomRgn Arc BitBlt Chord CombineRgn CreateBitmap CreateBrushIndirect CreateCompatibleBitmap CreateCompatibleDC CreateDIBitmap CreateEllipticRgn CreatePen CreatePenIndirect CreatePatternBrush CreateRectRgn CreateRoundRectRgn CreateSolidBrush DeleteDC DeleteObject Ellipse EqualRgn ExcludeClipRect ExtCreateRegion ExtFloodFill FillRgn GetROP2 GetBkColor GetBitmapBits GetClipBox GetClipRgn GetCurrentObject GetDeviceCaps GetDIBits GetMapMode GetObjectType GetPixel GetRegionData GetRgnBox GetStockObject GetTextAlign GetTextColor GetViewportExtEx GetViewportOrgEx GetWindowExtEx GetWindowOrgEx IntersectClipRect LineTo MaskBlt OffsetRgn PatBlt Pie PaintRgn PtInRegion RectInRegion RectVisible Rectangle RestoreDC RealizePalette RoundRect SaveDC SelectClipRgn ExtSelectClipRgn SelectObject SelectPalette SetBkColor SetBkMode SetMapMode SetPixel SetPolyFillMode StretchBlt SetRectRgn SetROP2 SetStretchBltMode SetTextCharacterExtra SetTextColor SetTextAlign CreateDIBSection SetArcDirection ExtCreatePen MoveToEx CreatePolygonRgn DPtoLP LPtoDP Polygon Polyline PolyBezier SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx OffsetViewportOrgEx SetBrushOrgEx GetDCOrgEx |
version.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
shell32.dll |
DragQueryFileA
DragQueryFileW DragFinish DragAcceptFiles |
ole32.dll |
OleInitialize
OleUninitialize |
comctl32.dll |
InitCommonControls
ImageList_Create ImageList_Destroy ImageList_GetImageCount ImageList_SetImageCount ImageList_Add ImageList_Replace ImageList_AddMasked ImageList_DrawEx ImageList_DrawIndirect ImageList_Remove ImageList_Copy ImageList_BeginDrag ImageList_EndDrag ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock _TrackMouseEvent |
StartAddressOfRawData | 0x100000000 |
---|---|
EndAddressOfRawData | 0x100000000 |
AddressOfIndex | 0x1001cc3f0 |
AddressOfCallbacks | 0x100da1000 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x00000001000151A0
|