Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Nov-20 09:37:55 |
Detected languages |
English - United States
|
Debug artifacts |
explorer.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Windows Explorer |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | explorer |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | EXPLORER.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/71 (Scanned on 2019-04-27 02:57:32) |
SentinelOne:
DFI - Suspicious PE
CrowdStrike: win/malicious_confidence_60% (D) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2010-Nov-20 09:37:55 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.1 |
SizeOfCode | 0xaf600 |
SizeOfInitializedData | 0x1cf400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00030EFA (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb0000 |
ImageBase | 0xe70000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 6.1 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x281000 |
SizeOfHeaders | 0x600 |
Checksum | 0x286a68 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0xe000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
RegCloseKey
RegCreateKeyW RegGetValueW RegOpenKeyExW GetTraceEnableFlags GetTraceEnableLevel GetTraceLoggerHandle RegisterTraceGuidsW UnregisterTraceGuids RegCreateKeyExW RegQueryValueExW EventRegister EventUnregister EventWrite EventEnabled GetLengthSid GetTokenInformation OpenProcessToken RegSetValueExW RegDeleteKeyExW TraceMessage RegOpenKeyW RegDeleteValueW RegEnumValueW RegQueryInfoKeyW ConvertStringSidToSidW CloseServiceHandle OpenServiceW OpenSCManagerW RegEnumKeyExW CreateWellKnownSid StartServiceW CryptAcquireContextW CryptCreateHash CryptHashData CryptGetHashParam CryptDestroyHash CryptReleaseContext StartTraceW EnableTraceEx StopTraceW LsaLookupSids IsValidSid GetSidSubAuthorityCount GetSidSubAuthority LsaOpenPolicy LsaFreeMemory LsaClose OpenThreadToken ConvertSidToStringSidW ConvertStringSecurityDescriptorToSecurityDescriptorW CheckTokenMembership QueryServiceStatus |
---|---|
KERNEL32.dll |
LoadLibraryExA
DelayLoadFailureHook CreateFileW GetFileSize ReadFile RaiseException FlushInstructionCache SetLastError OpenThread GetSystemTimeAsFileTime GetLocaleInfoW GetTimeFormatW GetDateFormatW GetLocalTime InterlockedCompareExchange FindFirstFileW lstrcmpiW FindNextFileW FindClose GetFileAttributesW GetSystemTime SystemTimeToFileTime ExpandEnvironmentStringsW InterlockedIncrement InterlockedDecrement GetLastError SetInformationJobObject CreateJobObjectW GetPriorityClass SetPriorityClass SearchPathW GetSystemDefaultUILanguage UnmapViewOfFile MapViewOfFile GetTimeZoneInformation GetDynamicTimeZoneInformation GetBinaryTypeW QueryPerformanceFrequency QueueUserWorkItem GetTickCount64 MulDiv GetLongPathNameW GetThreadPriority MultiByteToWideChar GlobalGetAtomNameW GetCurrentThread SetThreadPriority LoadLibraryExW GetProductInfo TerminateThread CreateIoCompletionPort GetQueuedCompletionStatus DeleteFileW GetWindowsDirectoryW GetProcessId CompareStringW QueryFullProcessImageNameW CompareFileTime CreateFileMappingW ResetEvent WideCharToMultiByte GlobalAlloc GlobalLock GlobalUnlock GlobalFree DuplicateHandle GetCurrentDirectoryW WaitForMultipleObjects GetComputerNameW DeactivateActCtx ActivateActCtx ReleaseActCtx CreateActCtxW FindResourceExW LoadResource LockResource OpenProcess CloseHandle LocalFree LocalAlloc QueryInformationJobObject Sleep ResumeThread AssignProcessToJobObject CreateThread CreateProcessW WaitForSingleObject FreeLibrary GetProcAddress LoadLibraryW GetUserDefaultUILanguage CreateEventW lstrlenW HeapFree HeapAlloc GetProcessHeap GetCurrentProcess HeapSetInformation GetVersionExW DeleteCriticalSection InitializeCriticalSection HeapDestroy GetPrivateProfileStringW GetModuleFileNameW GetCommandLineW GetSystemDirectoryW ExitProcess RegisterApplicationRestart SetProcessShutdownParameters GetStartupInfoW ReleaseMutex CreateMutexW SetErrorMode SetProcessDEPPolicy GetUserDefaultLangID SetEvent LeaveCriticalSection EnterCriticalSection GetTickCount OpenEventW SetTermsrvAppInstallMode GetCurrentProcessId GetModuleHandleW GetCurrentThreadId QueryPerformanceCounter UnhandledExceptionFilter TerminateProcess CompareStringOrdinal GetModuleHandleA SetUnhandledExceptionFilter InterlockedExchange VirtualAlloc VirtualFree LoadLibraryA |
GDI32.dll |
GetStockObject
SetWindowOrgEx StretchBlt GetTextMetricsW CombineRgn Polyline CreatePen GetTextColor ExtCreateRegion GetRegionData SetLayout GetLayout GetTextExtentPoint32W OffsetRgn LPtoDP GetRgnBox OffsetViewportOrgEx GdiFlush ExtTextOutW SetDIBits CreateRectRgn GetClipRgn IntersectClipRect GetViewportOrgEx SetViewportOrgEx SelectClipRgn GetBkColor SetBkMode CreateBitmap PatBlt CreateCompatibleBitmap OffsetWindowOrgEx SetBkColor SetTextColor GetTextExtentPointW GetClipBox CreateDIBSection GetObjectW CreateRectRgnIndirect DeleteObject CreateCompatibleDC SelectObject BitBlt GetDeviceCaps CreateFontIndirectW DeleteDC GdiAlphaBlend |
USER32.dll |
PtInRect
GetWindowRect GetWindow SendMessageW EnumChildWindows GetWindowLongW CharPrevW CharNextW GetSystemMetrics CreateWindowExW DialogBoxParamW GetClassInfoW GetClassInfoExW GetMenuItemInfoW GetMenuItemCount GetClassNameW GetKeyboardLayout ActivateKeyboardLayout IsChild InsertMenuW GetMenuStringW SetMenuItemInfoW InsertMenuItemW IsWinEventHookInstalled IsProcessDPIAware GetNextDlgGroupItem GetNextDlgTabItem GetDlgCtrlID MoveWindow IsRectEmpty UnionRect ChildWindowFromPointEx GetGUIThreadInfo SetClassLongW GetClassLongW WindowFromDC CharUpperW UnregisterClassW FrameRect GetWindowDC SendMessageCallbackW UpdateLayeredWindow GetUserObjectInformationW GetThreadDesktop GetProcessWindowStation GetIconInfo ShowWindowAsync FlashWindowEx EndTask SetThreadDesktop GetMenuState SetScrollInfo GetScrollInfo SetScrollPos BringWindowToTop DeregisterShellHookWindow IsZoomed CloseDesktop OpenInputDesktop RegisterShellHookWindow InternalGetWindowText GetWindowInfo GetLayeredWindowAttributes SetLayeredWindowAttributes GetCaretBlinkTime UnhookWindowsHookEx CallNextHookEx SetWindowsHookExW GetUpdateRect SystemParametersInfoW FindWindowW ReleaseDC GetDC DispatchMessageW TranslateMessage GetMessageW DestroyMenu GetMenuDefaultItem CreatePopupMenu PostMessageW MsgWaitForMultipleObjectsEx PeekMessageW SetWindowLongW ShutdownBlockReasonCreate LoadStringW DestroyWindow PostQuitMessage SetWindowPos KillTimer SetTimer SetPropW ShowWindow MapWindowPoints RegisterClassW LoadCursorW SetActiveWindow UpdateLayeredWindowIndirect GetLastInputInfo SendDlgItemMessageW EndDialog GetDesktopWindow GetShellWindow DestroyIcon GetMonitorInfoW CopyRect ModifyMenuW CheckMenuItem EnableMenuItem GhostWindowFromHungWindow DeleteMenu ReleaseCapture GetCursorPos DefWindowProcW TrackMouseEvent GetDoubleClickTime InvalidateRect LockWorkStation TileWindows UpdateWindow CascadeWindows GetWindowTextW TrackPopupMenu ClientToScreen WindowFromPoint AppendMenuW EndPaint DrawEdge FillRect LockSetForegroundWindow InflateRect IsWindowVisible GetForegroundWindow GetParent WaitMessage RegisterWindowMessageW TrackPopupMenuEx GetClientRect MonitorFromRect EqualRect SubtractRect RedrawWindow EnumDisplayMonitors SetWindowTextW IntersectRect GetWindowPlacement SendNotifyMessageW RemovePropW SetWindowCompositionAttribute HungWindowFromGhostWindow SetFocus SendMessageTimeoutW EnumWindows UnregisterHotKey RegisterHotKey MonitorFromWindow IsWindow SetCursor GetAsyncKeyState SetForegroundWindow ChildWindowFromPoint SetCursorPos GetMessagePos IsIconic LoadIconW DeferWindowPos OffsetRect GetWindowThreadProcessId ScreenToClient GetAncestor MonitorFromPoint SetRectEmpty ChangeWindowMessageFilterEx LoadAcceleratorsW TranslateAcceleratorW GetKeyState SetWindowRgn GetWindowRgnBox LoadImageW GetFocus GetActiveWindow MessageBeep BeginPaint SwitchToThisWindow GetLastActivePopup EndDeferWindowPos BeginDeferWindowPos SetWindowPlacement IsHungAppWindow RegisterClipboardFormatW SetRect GetSysColorBrush GetPropW AllowSetForegroundWindow LoadMenuW GetSubMenu RemoveMenu SetMenuDefaultItem GetCapture DrawIconEx GetMessageExtraInfo SetGestureConfig AdjustWindowRect CalculatePopupWindowPosition DrawTextW SetCapture CallWindowProcW CheckDlgButton IsDlgButtonChecked IsWindowEnabled GetDlgItemInt SetDlgItemInt GetDlgItem EnableWindow SetWinEventHook MsgWaitForMultipleObjects RegisterClassExW CopyIcon AdjustWindowRectEx GetSysColor DrawFocusRect NotifyWinEvent ExitWindowsEx GetSystemMenu |
msvcrt.dll |
_controlfp
?terminate@@YAXXZ _onexit _lock __dllonexit _unlock _except_handler4_common __set_app_type __p__fmode memcpy memmove _CIsin _ftol2 _CIcos _wtoi wcsncmp _wcsnicmp _wcsicmp bsearch __p__commode __setusermatherr _amsg_exit _initterm _wcmdln exit _XcptFilter _exit _cexit __wgetmainargs _ftol2_sse malloc _CIsqrt ceil realloc wcschr iswalpha wcsstr free _vsnwprintf memset |
ntdll.dll |
WinSqmSetString
NtQueryInformationProcess NtSetInformationProcess WinSqmIsOptedIn NtOpenThreadToken NtOpenProcessToken NtClose WinSqmAddToStreamEx NtSetSystemInformation WinSqmAddToStream WinSqmEventEnabled WinSqmSetDWORD EtwEventWrite EtwEventEnabled NtQueryInformationToken RtlGetProductInfo |
SHLWAPI.dll |
SHStrDupA
StrCmpW #236 #439 PathCommonPrefixW PathRemoveExtensionW #487 PathIsFileSpecW #154 #476 #217 StrRetToStrW #215 AssocCreate #632 StrRetToBufW AssocQueryStringW #467 PathQuoteSpacesW #24 #560 SHDeleteKeyW #433 SHRegGetUSValueW #631 #213 PathIsNetworkPathW #559 #548 #184 #630 SHOpenRegStream2W #212 #197 #165 #478 #413 #157 PathRemoveFileSpecW #292 #629 #279 #193 SHRegGetBoolUSValueW #204 #460 PathGetDriveNumberW PathFileExistsW PathIsDirectoryW #479 #163 PathFindExtensionW StrChrIW #278 #240 PathAppendW SHDeleteValueW #16 SHSetValueW #635 #618 PathRemoveArgsW PathRemoveBlanksW StrCmpNIW #174 PathGetArgsW PathFindFileNameW SHGetValueW SHCreateThreadRef SHSetThreadRef PathCombineW SHRegGetValueW #158 #10 #8 #9 StrToIntW #270 StrChrW #176 #199 #175 #172 #164 #219 SHStrDupW PathStripToRootW #256 #168 #12 StrTrimW StrCmpNW SHQueryInfoKeyW SHCreateStreamOnFileW #178 #484 #177 #571 #225 #237 PathIsPrefixW #437 StrCmpIW PathParseIconLocationW PathIsRootW #156 #509 #510 AssocQueryKeyW PathStripPathW ChrCmpIW StrStrIW #388 |
SHELL32.dll |
#134
#22 #162 SHGetPropertyStoreForWindow #894 #181 SHGetStockIconInfo #265 #241 #6 #895 #88 #193 #787 #790 #840 Shell_GetCachedImageIndexW #154 #902 #74 SHGetLocalizedName SHCreateDataObject #165 #885 #814 #152 #849 #818 SHCreateShellItemArrayFromShellItem SHGetKnownFolderPath SHCreateShellItemArrayFromIDLists #102 #28 SHBindToFolderIDListParentEx SHGetFileInfoW #727 SHCreateItemWithParent #747 #85 #100 #18 #190 SHGetFolderLocation #155 SHParseDisplayName SHGetSpecialFolderPathW #723 ShellExecuteExW SHGetKnownFolderIDList SHBindToObject #89 #200 #68 #245 #176 #680 #201 #660 #188 #899 #892 SHGetNameFromIDList SHCreateShellItem #67 #19 #17 #16 #753 #4 #2 #896 #61 #64 SHGetPathFromIDListW ShellExecuteW SHEnableServiceObject #132 SHGetIDListFromObject #886 SHChangeNotifyRegisterThread #21 #25 #645 #644 SHUpdateRecycleBinIcon #60 #137 SHCreateItemFromIDList #711 #731 SHFileOperationW SHGetFolderPathEx #733 #91 #254 #54 #244 SHGetPathFromIDListA SHGetFolderPathW SHBindToParent #893 SHAddToRecentDocs Shell_NotifyIconW Shell_NotifyIconGetRect ExtractIconExW SHEvaluateSystemCommandTemplate SHChangeNotify SHCreateItemFromParsingName #95 DragQueryFileW #850 #23 SHGetSpecialFolderLocation SHBindToFolderIDListParent |
ole32.dll |
OleInitialize
StringFromGUID2 CoRegisterMessageFilter RegisterDragDrop RevokeDragDrop OleUninitialize CoRevokeClassObject CoCreateFreeThreadedMarshaler CreateBindCtx PropVariantClear ReleaseStgMedium CoInitializeEx CreateStreamOnHGlobal CoRegisterClassObject CoCreateInstance CoTaskMemFree CoGetInterfaceAndReleaseStream CoMarshalInterThreadInterfaceInStream CoUninitialize CoInitialize CoGetMalloc CoTaskMemAlloc CLSIDFromString CoFreeUnusedLibraries |
OLEAUT32.dll |
#150
#4 #2 #8 #9 #6 |
EXPLORERFRAME.dll |
#110
#111 |
UxTheme.dll |
BeginBufferedPaint
IsCompositionActive IsAppThemed GetThemeMetric CloseThemeData OpenThemeData SetWindowTheme DrawThemeBackground GetThemeTextExtent DrawThemeText DrawThemeParentBackground GetWindowTheme GetThemePartSize GetThemeBackgroundContentRect EndBufferedPaint GetThemeMargins DrawThemeTextEx BufferedPaintInit BufferedPaintUnInit IsThemeActive #86 GetThemeRect IsThemePartDefined GetThemeBackgroundRegion GetThemeColor GetThemeBool DrawThemeIcon GetBufferedPaintBits BufferedPaintClear GetThemeBackgroundExtent |
POWRPROF.dll |
CallNtPowerInformation
GetPwrCapabilities PowerDeterminePlatformRole |
dwmapi.dll |
#113
#105 DwmEnableBlurBehindWindow DwmIsCompositionEnabled DwmSetWindowAttribute #127 DwmQueryThumbnailSourceSize DwmUnregisterThumbnail DwmUpdateThumbnailProperties #114 #124 |
slc.dll |
SLGetWindowsInformationDWORD
|
gdiplus.dll |
GdipAlloc
GdiplusStartup GdiplusShutdown GdipFree GdipDeleteGraphics GdipDisposeImage GdipGetImageWidth GdipGetImageHeight GdipCreateBitmapFromHBITMAP GdipCreateFromHDC GdipSetCompositingMode GdipSetInterpolationMode GdipDrawImageRectI GdipCloneImage |
Secur32.dll |
GetUserNameExW
|
RPCRT4.dll |
RpcBindingFree
RpcBindingSetAuthInfoExW RpcStringFreeW RpcBindingFromStringBindingW RpcStringBindingComposeW I_RpcExceptionFilter NdrClientCall2 |
PROPSYS.dll |
PropVariantToUInt32
PropVariantToStringAlloc PropVariantToUInt64 PropVariantToBoolean VariantToStringAlloc VariantToStringWithDefault PropVariantToString VariantToBooleanWithDefault VariantToInt32WithDefault PSCreateMemoryPropertyStore PropVariantToInt64 |
WINMM.dll (delay-loaded) |
PlaySoundW
|
Attributes | 0x1 |
---|---|
Name | WINMM.dll |
ModuleHandle | 0xb24d8 |
DelayImportAddressTable | 0xb1000 |
DelayImportNameTable | 0xabe9c |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.1.7601.17514 |
ProductVersion | 6.1.7601.17514 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Windows Explorer |
FileVersion (#2) | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | explorer |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | EXPLORER.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.1.7601.17514 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:37:55 |
Version | 0.0 |
SizeofData | 37 |
AddressOfRawData | 0xb049c |
PointerToRawData | 0xafa9c |
Referenced File | explorer.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:37:55 |
Version | 565.6526 |
SizeofData | 4 |
AddressOfRawData | 0xb0498 |
PointerToRawData | 0xafa98 |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0x1000 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0xf21090 |
SEHandlerTable | 0xed8848 |
SEHandlerCount | 1 |
XOR Key | 0xdacc77ee |
---|---|
Unmarked objects | 0 |
ASM objects (VS2008 SP1 build 30729) | 8 |
Imports (VS2008 SP1 build 30729) | 41 |
Total imports | 1077 |
C++ objects (VS2008 SP1 build 30729) | 144 |
C objects (VS2008 SP1 build 30729) | 43 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |