| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Nov-24 09:07:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Git Repositories\GWToolboxpp2\bin\RelWithDebInfo\GWToolbox.pdb
|
| CompanyName | gwdevhub |
| FileDescription | Launcher for GWToolbox |
| FileVersion | |
| InternalName | GWToolbox |
| LegalCopyright | Guild Wars and all associated logos and designs are trademarks or registered trademarks of NCsoft Corporation. All other trademarks are the property of their respective owners. |
| OriginalFilename | GWToolbox.exe |
| ProductName | GWToolbox++ Launcher |
| ProductVersion | 4.2 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/72 (Scanned on 2025-04-16 04:32:40) | MaxSecure: Trojan.Malware.300983.susgen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2024-Nov-24 09:07:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2eee00 |
| SizeOfInitializedData | 0xae800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000011EF (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2f0000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3a2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
|---|---|
| WS2_32.dll |
gethostname
ioctlsocket sendto recvfrom freeaddrinfo getaddrinfo listen htonl select __WSAFDIsSet WSAIoctl socket setsockopt recv htons getsockname getpeername connect bind accept WSACleanup WSAStartup inet_ntop WSASetLastError ntohs inet_pton WSAGetLastError closesocket WSAWaitForMultipleEvents WSASetEvent WSAResetEvent WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt gethostbyname |
| bcrypt.dll |
BCryptGenRandom
|
| ADVAPI32.dll |
RegCreateKeyExW
RegDeleteKeyW RegSetValueExW RegGetValueW OpenProcessToken AdjustTokenPrivileges CheckTokenMembership FreeSid LookupPrivilegeValueW RegCloseKey CryptAcquireContextW CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash CryptAcquireContextA CryptGenRandom AllocateAndInitializeSid |
| CRYPT32.dll |
CertCloseStore
CertOpenStore CertEnumCertificatesInStore CertFindCertificateInStore CryptStringToBinaryW PFXImportCertStore CryptDecodeObjectEx CertAddCertificateContextToStore CertFindExtension CertGetNameStringW CryptQueryObject CertCreateCertificateChainEngine CertFreeCertificateChainEngine CertGetCertificateChain CertFreeCertificateChain CertOpenSystemStoreA CertFreeCertificateContext |
| KERNEL32.dll |
LoadLibraryExW
GetModuleHandleExW GetDriveTypeW SystemTimeToTzSpecificLocalTime FileTimeToSystemTime CreateThread ExitThread ResumeThread FreeLibraryAndExitThread SetFilePointerEx GetConsoleMode ReadConsoleW GetConsoleOutputCP GetCurrentThread HeapFree HeapReAlloc HeapAlloc GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FlushFileBuffers SetStdHandle SetEndOfFile GetTimeZoneInformation SetConsoleCtrlHandler OutputDebugStringW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap CloseHandle GetLastError WaitForSingleObject GetExitCodeThread CreateRemoteThreadEx VirtualAllocEx DeleteFileW VirtualFreeEx GetModuleHandleW GetProcAddress CreateFileW GetFileSizeEx GetProcessId OpenProcess ReadProcessMemory QueryFullProcessImageNameW K32EnumProcesses K32EnumProcessModules K32GetModuleBaseNameW K32GetModuleInformation GetCommandLineW GetCurrentDirectoryW GetCurrentProcess ExitProcess GetModuleFileNameW SetEvent CreateEventW WriteFile GetComputerNameW Sleep ReleaseSRWLockExclusive AcquireSRWLockExclusive SetLastError FormatMessageW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection QueryPerformanceFrequency GetSystemDirectoryW FreeLibrary LoadLibraryW SleepEx QueryPerformanceCounter GetTickCount MultiByteToWideChar WideCharToMultiByte MoveFileExW WaitForSingleObjectEx GetEnvironmentVariableA GetStdHandle GetFileType ReadFile PeekNamedPipe WaitForMultipleObjects GetCurrentProcessId VerSetConditionMask GetModuleHandleA VerifyVersionInfoW FindClose FindFirstFileA FindNextFileA InitializeCriticalSection PulseEvent FormatMessageA TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount InterlockedFlushSList InterlockedPushEntrySList RtlUnwind RaiseException GetStartupInfoW IsDebuggerPresent InitializeSListHead IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter GetStringTypeW CloseThreadpoolWait SetThreadpoolWait CreateThreadpoolWait CloseThreadpoolTimer WaitForThreadpoolTimerCallbacks SetThreadpoolTimer CreateThreadpoolTimer FreeLibraryWhenCallbackReturns GetTickCount64 WriteConsoleW HeapSize ResetEvent WriteProcessMemory CreateEventA GetSystemTimeAsFileTime GetCurrentProcessorNumber FlushProcessWriteBuffers CreateSemaphoreExW CreateEventExW InitOnceExecuteOnce LocalFree GetLocaleInfoEx SetCurrentDirectoryW CreateDirectoryW FindFirstFileW FindFirstFileExW FindNextFileW GetDiskFreeSpaceExW GetFileAttributesW GetFileAttributesExW GetFileInformationByHandle GetFinalPathNameByHandleW GetFullPathNameW SetFileAttributesW SetFileInformationByHandle SetFileTime GetTempPathW AreFileApisANSI DeviceIoControl CreateDirectoryExW CopyFileW CreateHardLinkW GetFileInformationByHandleEx CreateSymbolicLinkW TryAcquireSRWLockExclusive GetCurrentThreadId EncodePointer DecodePointer CompareStringEx GetCPInfo LCMapStringEx |
| USER32.dll |
SendMessageW
SetForegroundWindow SystemParametersInfoW LoadIconW SetWindowLongW GetWindowLongW GetSysColorBrush MsgWaitForMultipleObjects ShowWindow RegisterClassW PeekMessageW DefWindowProcW TranslateMessage GetClassNameW EnumWindows MessageBoxW GetWindow GetWindowThreadProcessId GetTopWindow SendMessageA MessageBoxA DestroyWindow CreateWindowExW DispatchMessageW |
| GDI32.dll |
GetStockObject
SetBkMode CreateFontIndirectW DeleteObject |
| SHELL32.dll |
SHGetFolderPathW
ShellExecuteExW CommandLineToArgvW SHFileOperationW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.2.0.0 |
| ProductVersion | 4.2.0.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| CompanyName | gwdevhub |
| FileDescription | Launcher for GWToolbox |
| FileVersion (#2) | |
| InternalName | GWToolbox |
| LegalCopyright | Guild Wars and all associated logos and designs are trademarks or registered trademarks of NCsoft Corporation. All other trademarks are the property of their respective owners. |
| OriginalFilename | GWToolbox.exe |
| ProductName | GWToolbox++ Launcher |
| ProductVersion (#2) | 4.2 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Nov-24 09:07:02 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x3398e8 |
| PointerToRawData | 0x338ae8 |
| Referenced File | C:\Git Repositories\GWToolboxpp2\bin\RelWithDebInfo\GWToolbox.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Nov-24 09:07:02 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x339944 |
| PointerToRawData | 0x338b44 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x743cc0 |
| SEHandlerTable | 0x7390ac |
| SEHandlerCount | 386 |
| XOR Key | 0xba955a75 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 20 |
| C++ objects (30795) | 197 |
| C objects (30795) | 23 |
| 253 (34321) | 7 |
| ASM objects (34321) | 25 |
| C objects (34321) | 19 |
| C++ objects (34321) | 82 |
| C objects (34433) | 167 |
| Imports (30795) | 19 |
| Total imports | 282 |
| C++ objects (34433) | 19 |
| Resource objects (34433) | 1 |
| 151 | 1 |
| Linker (34433) | 1 |
No comments yet.