Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2027-Jul-20 00:47:34 |
Detected languages |
English - United States
|
Debug artifacts |
msoobe.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | MSOOBE EXE |
FileVersion | 10.0.15063.0 (WinBuild.160101.0800) |
InternalName | msoobe.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | msoobe.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.15063.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/69 (Scanned on 2021-02-18 23:56:05) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2027-Jul-20 00:47:34 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x20e00 |
SizeOfInitializedData | 0x13600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000200D0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x39000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3fc3b |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
EventRegister
EventUnregister RegUnLoadKeyW RegLoadKeyW OpenSCManagerW RegQueryValueExW GetTraceLoggerHandle GetTraceEnableFlags GetTraceEnableLevel RegisterTraceGuidsW UnregisterTraceGuids QueryServiceStatus CloseServiceHandle ControlService StartServiceW OpenServiceW RegDeleteKeyW |
---|---|
KERNEL32.dll |
LocalAlloc
GetVersionExW ExpandEnvironmentStringsW CreateDirectoryW GetFullPathNameW GetFileAttributesW LoadLibraryExW InitializeCriticalSection GetModuleFileNameW GetModuleFileNameA CreateSemaphoreExW HeapFree SetLastError ReleaseSemaphore GetModuleHandleExW WaitForSingleObject ReleaseMutex FormatMessageW GetLastError OutputDebugStringW WaitForSingleObjectEx OpenSemaphoreW CloseHandle HeapAlloc GetProcAddress CreateMutexExW GetCurrentProcessId GetProcessHeap GetModuleHandleW HeapSetInformation CreateMutexW OpenMutexW lstrcmpiW GetCurrentThreadId |
msvcrt.dll |
memmove
strtok_s _purecall __C_specific_handler _initterm __setusermatherr __CxxFrameHandler3 ?terminate@@YAXXZ memmove_s _cexit _exit exit __set_app_type __getmainargs _amsg_exit _XcptFilter _wtol ??1type_info@@UEAA@XZ memcmp _vsnprintf wcsrchr _wcsnicmp memcpy _CxxThrowException _onexit __dllonexit _unlock ?what@exception@@UEBAPEBDXZ _lock ??0exception@@QEAA@AEBQEBDH@Z _commode ??0exception@@QEAA@AEBQEBD@Z _callnewh malloc _fmode _vsnprintf_s ??0exception@@QEAA@AEBV0@@Z _ismbblead wcschr ??0exception@@QEAA@XZ ??1exception@@UEAA@XZ ??3@YAXPEAX@Z memcpy_s _vsnwprintf _acmdln memset |
PROPSYS.dll |
PropVariantToUInt32
PropVariantToBoolean PropVariantToStringAlloc PSCreateMemoryPropertyStore |
SHELL32.dll |
#102
SHGetFolderPathEx |
SHLWAPI.dll |
#278
SHCreateStreamOnFileW PathAppendW SHStrDupW #215 SHDeleteValueW #437 StrCmpIW SHSetThreadRef #460 SHCreateThreadRef SHEnumKeyExW #219 #631 |
api-ms-win-core-com-l1-1-1.dll |
PropVariantClear
CoTaskMemFree CoInitializeEx CoCreateInstance StringFromGUID2 CoGetApartmentType CoWaitForMultipleHandles CoTaskMemRealloc CoTaskMemAlloc CoGetMalloc CLSIDFromString CoSetProxyBlanket StringFromCLSID CoUninitialize |
api-ms-win-core-synch-l1-2-0.dll |
InitOnceComplete
AcquireSRWLockExclusive ReleaseSRWLockExclusive ReleaseSRWLockShared OpenEventW WaitForMultipleObjectsEx AcquireSRWLockShared SetEvent LeaveCriticalSection InitializeCriticalSectionEx EnterCriticalSection CreateEventExW InitOnceBeginInitialize DeleteCriticalSection Sleep ResetEvent CreateEventW |
api-ms-win-core-processthreads-l1-1-2.dll |
TerminateProcess
TlsAlloc GetCurrentProcess TlsSetValue TlsFree CreateThread GetStartupInfoW |
api-ms-win-core-rtlsupport-l1-2-0.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind |
api-ms-win-core-errorhandling-l1-1-1.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter RaiseException |
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
api-ms-win-core-sysinfo-l1-2-1.dll |
GetTickCount64
GetSystemTimeAsFileTime GetTickCount GetSystemTime |
api-ms-win-eventing-provider-l1-1-0.dll |
EventWriteTransfer
EventActivityIdControl EventSetInformation EventWrite |
api-ms-win-core-registry-l1-1-0.dll |
RegGetValueW
RegCloseKey RegEnumValueW RegEnumKeyExW RegCreateKeyExW RegQueryInfoKeyW RegDeleteTreeW RegSetValueExW RegOpenKeyExW |
api-ms-win-security-sddl-l1-1-0.dll |
ConvertStringSecurityDescriptorToSecurityDescriptorW
|
api-ms-win-core-string-l1-1-0.dll |
CompareStringOrdinal
|
api-ms-win-core-threadpool-l1-2-0.dll |
CallbackMayRunLong
CloseThreadpoolTimer WaitForThreadpoolTimerCallbacks SetThreadpoolTimer CreateThreadpoolTimer FreeLibraryWhenCallbackReturns TrySubmitThreadpoolCallback |
api-ms-win-core-file-l1-2-1.dll |
FlushFileBuffers
CreateFileW |
api-ms-win-core-libraryloader-l1-2-0.dll |
FreeLibrary
FreeLibraryAndExitThread |
api-ms-win-core-handle-l1-1-0.dll |
DuplicateHandle
|
OLEAUT32.dll |
SysAllocStringLen
SysAllocString SysFreeString VariantClear |
api-ms-win-core-localization-l1-2-1.dll |
GetThreadUILanguage
GetUserGeoID |
api-ms-win-core-libraryloader-l1-2-2.dll |
LoadLibraryW
|
api-ms-win-core-heap-l2-1-0.dll |
LocalFree
|
api-ms-win-core-synch-l1-2-1.dll |
CreateSemaphoreW
|
COMCTL32.dll |
#339
#334 #329 #386 #328 #336 |
MsCtfMonitor.DLL |
UninitLocalMsCtfMonitor
InitLocalMsCtfMonitor |
ntdll.dll |
WinSqmEndSession
WinSqmStartSession RtlFreeHeap RtlAllocateHeap WinSqmSetDWORD |
USER32.dll |
IsHungAppWindow
DefWindowProcW PostMessageW DestroyWindow PeekMessageW GetSystemMetrics DispatchMessageW EnumDisplaySettingsW PostQuitMessage PostThreadMessageW SetCursor LoadCursorW MsgWaitForMultipleObjectsEx TranslateMessage |
CRYPT32.dll |
CertFindCertificateInStore
CertCloseStore CryptDecodeObjectEx CryptBinaryToStringW CertFreeCertificateContext CertFindExtension CertOpenStore |
api-ms-win-service-management-l2-1-0.dll |
QueryServiceStatusEx
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.15063.0 |
ProductVersion | 10.0.15063.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | MSOOBE EXE |
FileVersion (#2) | 10.0.15063.0 (WinBuild.160101.0800) |
InternalName | msoobe.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | msoobe.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.15063.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2027-Jul-20 00:47:34 |
Version | 0.0 |
SizeofData | 35 |
AddressOfRawData | 0x2d218 |
PointerToRawData | 0x2c418 |
Referenced File | msoobe.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2027-Jul-20 00:47:34 |
Version | 0.0 |
SizeofData | 744 |
AddressOfRawData | 0x2d23c |
PointerToRawData | 0x2c43c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2027-Jul-20 00:47:34 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0xf4 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140032358 |
GuardCFCheckFunctionPointer | 5368855648 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x38aeeb5d |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 52 |
ASM objects (24610) | 4 |
C objects (24610) | 19 |
C++ objects (24610) | 8 |
Imports (24610) | 23 |
Total imports | 368 |
265 (24610) | 66 |
Resource objects (24610) | 1 |
Linker (24610) | 1 |