Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Jul-21 08:39:13 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\rafou\source\repos\NajiN\x64\Debug\Hammer.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | The PE is possibly packed. |
Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc |
Info | The PE contains common functions which appear in legitimate applications. |
Can create temporary files:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 10 |
TimeDateStamp | 2021-Jul-21 08:39:13 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x29600 |
SizeOfInitializedData | 0x18400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000012050 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
DecodePointer
RaiseException GetLastError SetLastError InitializeCriticalSectionEx DeleteCriticalSection FreeLibrary VirtualQuery GetProcessHeap HeapFree HeapAlloc InitializeSListHead GetSystemTimeAsFileTime GetCurrentProcessId QueryPerformanceCounter GetModuleHandleW GetStartupInfoW IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetCurrentThreadId LeaveCriticalSection EnterCriticalSection OutputDebugStringW IsDebuggerPresent WideCharToMultiByte MultiByteToWideChar CreateSymbolicLinkW GetFileInformationByHandleEx CreateHardLinkW MoveFileExW CopyFileW CreateDirectoryExW DeviceIoControl CloseHandle AreFileApisANSI GetTempPathW SetFileTime SetFilePointerEx SetFileInformationByHandle SetFileAttributesW SetEndOfFile GetFullPathNameW GetFinalPathNameByHandleW GetFileInformationByHandle GetFileAttributesExW GetFileAttributesW GetDiskFreeSpaceExW FindNextFileW FindFirstFileExW FindClose CreateFileW CreateDirectoryW GetCurrentDirectoryW SetCurrentDirectoryW FormatMessageA LocalFree GetProcAddress |
---|---|
USER32.dll |
UnregisterClassW
|
ole32.dll |
CoInitialize
CoTaskMemAlloc CoCreateInstance CoUninitialize |
OLEAUT32.dll |
SafeArrayGetVartype
SafeArrayCopy SafeArrayUnlock SafeArrayLock SafeArrayGetLBound SafeArrayGetUBound SafeArrayDestroy SafeArrayCreate SysFreeString SysAllocString SysAllocStringLen |
MSVCP140D.dll |
?_W_Getmonths@_Locinfo@std@@QEBAPEBGXZ
?_W_Getdays@_Locinfo@std@@QEBAPEBGXZ ?_Getmonths@_Locinfo@std@@QEBAPEBDXZ ?_Getdays@_Locinfo@std@@QEBAPEBDXZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ _Mbrtowc ?_Winerror_map@std@@YAHH@Z ?_Syserror_map@std@@YAPEBDH@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z |
VCRUNTIME140D.dll |
_CxxThrowException
memset memcpy __std_exception_destroy __std_exception_copy memcmp memmove __C_specific_handler __C_specific_handler_noexcept __current_exception_context __std_type_info_destroy_list __vcrt_LoadLibraryExW __vcrt_GetModuleHandleW __vcrt_GetModuleFileNameW __current_exception |
VCRUNTIME140_1D.dll |
__CxxFrameHandler4
|
ucrtbased.dll |
__stdio_common_vsprintf_s
strcat_s strcpy_s _initterm_e _initterm _callnewh _cexit _crt_at_quick_exit _crt_atexit _execute_onexit_table _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv __stdio_common_vsnwprintf_s _recalloc _errno wcscpy_s _malloc_dbg _free_dbg terminate ___lc_codepage_func _wsplitpath_s _wcsicmp _calloc_dbg mbstowcs_s strlen _CrtDbgReport _invalid_parameter malloc _wmakepath_s __stdio_common_vswprintf_s __stdio_common_vswprintf _CrtDbgReportW wcslen free _seh_filter_dll _invalid_parameter_noinfo |
Ordinal | 1 |
---|---|
Address | 0x12e1f |
Ordinal | 2 |
---|---|
Address | 0x12807 |
Ordinal | 3 |
---|---|
Address | 0x12316 |
Ordinal | 4 |
---|---|
Address | 0x12c03 |
Ordinal | 5 |
---|---|
Address | 0x123c5 |
Ordinal | 6 |
---|---|
Address | 0x122fd |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jul-21 08:39:13 |
Version | 0.0 |
SizeofData | 79 |
AddressOfRawData | 0x435e8 |
PointerToRawData | 0x30fe8 |
Referenced File | C:\Users\rafou\source\repos\NajiN\x64\Debug\Hammer.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jul-21 08:39:13 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x43638 |
PointerToRawData | 0x31038 |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x18004a058 |
XOR Key | 0x54f0f7d8 |
---|---|
Unmarked objects | 0 |
C objects (30034) | 9 |
ASM objects (30034) | 3 |
C++ objects (30034) | 26 |
Imports (30034) | 6 |
Imports (27412) | 11 |
Total imports | 146 |
C++ objects (30038) | 5 |
Exports (30038) | 1 |
Resource objects (30038) | 1 |
151 | 1 |
Linker (30038) | 1 |