Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2023-Feb-20 18:06:23 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\Corey\Downloads\HMDM-master (1)234\hmdm\x64\Release\HMDM-MSREXEC.pdb
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2023-Feb-20 18:06:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xa600 |
SizeOfInitializedData | 0x39e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000000A408 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x48000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
SetThreadPriority
GetCurrentThread LoadLibraryA SetPriorityClass GetPriorityClass IsProcessorFeaturePresent FormatMessageA GetProcAddress LoadLibraryExA VirtualAlloc VirtualFree CloseHandle CreateFileA DeviceIoControl GetThreadPriority GetCurrentProcess GetLocaleInfoEx InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId CreateFileW GetFileAttributesW GetFullPathNameW SetFileInformationByHandle GetTempPathW AreFileApisANSI GetLastError GetFileInformationByHandleEx MultiByteToWideChar WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount DeleteCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsDebuggerPresent QueryPerformanceCounter GetCurrentProcessId LocalFree |
---|---|
ADVAPI32.dll |
LookupPrivilegeValueW
AdjustTokenPrivileges RegCloseKey RegOpenKeyA RegDeleteKeyA RegSetValueExA OpenProcessToken RegCreateKeyA |
ntdll.dll |
NtLoadDriver
RtlInitAnsiString NtUnloadDriver RtlAnsiStringToUnicodeString NtQuerySystemInformation |
MSVCP140.dll |
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ ??Bid@locale@std@@QEAA_KXZ ?_Xbad_function_call@std@@YAXXZ ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Xout_of_range@std@@YAXPEBD@Z ?_Winerror_map@std@@YAHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Xlength_error@std@@YAXPEBD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Syserror_map@std@@YAPEBDH@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ |
dbghelp.dll |
ImageDirectoryEntryToData
|
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
_CxxThrowException
memset __current_exception_context __current_exception __C_specific_handler __std_exception_copy __std_exception_destroy memchr memcmp memcpy __std_terminate memmove |
api-ms-win-crt-stdio-l1-1-0.dll |
getchar
__p__commode _get_stream_buffer_pointers _set_fmode _fseeki64 fread fsetpos ungetc fputc setvbuf fgetpos fwrite __acrt_iob_func fclose fgetc fflush __stdio_common_vfprintf |
api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode malloc _callnewh |
api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
api-ms-win-crt-time-l1-1-0.dll |
_time64
|
api-ms-win-crt-runtime-l1-1-0.dll |
exit
_initterm _get_initial_narrow_environment _exit _invalid_parameter_noinfo_noreturn _set_app_type _seh_filter_exe _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv _register_thread_local_exe_atexit_callback _c_exit __p___argv terminate _initterm_e __p___argc |
api-ms-win-crt-string-l1-1-0.dll |
_stricmp
strncmp |
api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Feb-20 18:06:23 |
Version | 0.0 |
SizeofData | 102 |
AddressOfRawData | 0xe570 |
PointerToRawData | 0xcf70 |
Referenced File | C:\Users\Corey\Downloads\HMDM-master (1)234\hmdm\x64\Release\HMDM-MSREXEC.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Feb-20 18:06:23 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xe5d8 |
PointerToRawData | 0xcfd8 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Feb-20 18:06:23 |
Version | 0.0 |
SizeofData | 912 |
AddressOfRawData | 0xe5ec |
PointerToRawData | 0xcfec |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Feb-20 18:06:23 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x14000e9a0 |
---|---|
EndAddressOfRawData | 0x14000e9a8 |
AddressOfIndex | 0x1400184b4 |
AddressOfCallbacks | 0x14000c628 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140012050 |
XOR Key | 0x76400f70 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 20 |
C objects (VS2022 Update 3 (17.3.0) compiler 31616) | 10 |
ASM objects (VS2022 Update 3 (17.3.0) compiler 31616) | 3 |
C++ objects (VS2022 Update 3 (17.3.0) compiler 31616) | 31 |
Imports (VS2022 Update 3 (17.3.0) compiler 31616) | 6 |
Imports (30795) | 9 |
Total imports | 215 |
C++ objects (LTCG) (31631) | 3 |
ASM objects (31631) | 1 |
Resource objects (31631) | 1 |
151 | 1 |
Linker (31631) | 1 |