| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2078-May-03 19:06:54 |
| Detected languages |
English - United States
|
| Debug artifacts |
setup.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Remote Desktop Connection Installer |
| FileVersion | 10.0.25989.1000 (WinBuild.160101.0800) |
| InternalName | setup.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | setup.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.25989.1000 |
| Info | Matching compiler(s): | Microsoft Visual C++ 8.0 |
| Suspicious | The PE is possibly packed. | Unusual section name found: fothk |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2011 |
| Safe | VirusTotal score: 0/65 (Scanned on 2026-01-13 05:01:53) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2078-May-03 19:06:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x25000 |
| SizeOfInitializedData | 0x1c000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000014990 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x42000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x4509b |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetThreadPreferredUILanguages
GetEnvironmentStringsW WaitForSingleObject GetCurrentThreadId ReleaseMutex FormatMessageW GetLastError OutputDebugStringW WaitForSingleObjectEx OpenSemaphoreW CloseHandle HeapAlloc GetProcAddress CreateMutexExW GetCurrentProcessId GetProcessHeap GetModuleHandleW GetCommandLineW DebugBreak IsDebuggerPresent RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent EnterCriticalSection LeaveCriticalSection DeleteCriticalSection GetStdHandle GetFileType GetStartupInfoW ExitProcess FreeLibrary FlsAlloc FlsGetValue FlsSetValue FlsFree FreeEnvironmentStringsW GetSystemTimeAsFileTime LoadLibraryExW LCMapStringW IsValidCodePage GetACP GetOEMCP GetCPInfo GetStringTypeW MultiByteToWideChar WideCharToMultiByte SetFilePointerEx SetStdHandle FlushFileBuffers WriteFile GetConsoleOutputCP GetConsoleMode GetModuleFileNameW HeapSize HeapReAlloc RaiseException CreateFileW WriteConsoleW SetEvent ResetEvent CreateEventW QueryPerformanceCounter InitializeSListHead RtlUnwindEx RtlUnwind RtlPcToFileHeader EncodePointer InitializeCriticalSectionEx GetCommandLineA FindFirstFileExW GetModuleHandleExW ReleaseSemaphore SetLastError HeapFree CreateSemaphoreExW InitializeCriticalSectionAndSpinCount FindFirstFileW LocalFree FindNextFileW FindClose GetModuleFileNameA |
|---|---|
| COMCTL32.dll |
TaskDialogIndirect
|
| ole32.dll |
CoCreateInstance
CoTaskMemFree CoUninitialize CoInitializeEx CoTaskMemAlloc |
| DismApi.DLL |
DismCloseSession
DismOpenSession DismInitialize DismDelete DismShutdown DismEnableFeature DismGetFeatureInfo |
| api-ms-win-core-path-l1-1-0.dll |
PathCchRemoveExtension
PathAllocCombine |
| api-ms-win-core-featurestaging-l1-1-0.dll |
RecordFeatureUsage
UnsubscribeFeatureStateChangeNotification SubscribeFeatureStateChangeNotification |
| SHELL32.dll |
SHGetKnownFolderPath
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.25989.1000 |
| ProductVersion | 10.0.25989.1000 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Remote Desktop Connection Installer |
| FileVersion (#2) | 10.0.25989.1000 (WinBuild.160101.0800) |
| InternalName | setup.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | setup.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.25989.1000 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2078-May-03 19:06:54 |
| Version | 0.0 |
| SizeofData | 34 |
| AddressOfRawData | 0x36f08 |
| PointerToRawData | 0x36f08 |
| Referenced File | setup.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2078-May-03 19:06:54 |
| Version | 0.0 |
| SizeofData | 1108 |
| AddressOfRawData | 0x36f2c |
| PointerToRawData | 0x36f2c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2078-May-03 19:06:54 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x373a8 |
| PointerToRawData | 0x373a8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2078-May-03 19:06:54 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x373cc |
| PointerToRawData | 0x373cc |
| StartAddressOfRawData | 0x1400373f0 |
|---|---|
| EndAddressOfRawData | 0x1400373f8 |
| AddressOfIndex | 0x14003cb70 |
| AddressOfCallbacks | 0x140028830 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14003bb88 |
| GuardCFCheckFunctionPointer | 5368874824 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xa49411fa |
|---|---|
| Unmarked objects | 0 |
| Imports (32595) | 2 |
| Total imports | 132 |
| Imports (VS2008 SP1 build 30729) | 15 |
| Unmarked objects (#2) | 1 |
| C objects (32595) | 29 |
| ASM objects (32595) | 15 |
| C++ objects (32595) | 188 |
| C++ objects (LTCG) (32595) | 3 |
| Resource objects (32595) | 1 |
| Linker (32595) | 1 |