Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2087-Jul-22 17:17:47 |
Detected languages |
English - United States
|
Debug artifacts |
wdapp.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Windows Device Application Management |
FileVersion | 10.0.22000.4429 (WinBuild.160101.0800) |
InternalName | WdApp.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WdApp.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.22000.4429 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/73 (Scanned on 2024-09-30 16:19:35) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2087-Jul-22 17:17:47 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x33000 |
SizeOfInitializedData | 0x29000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000002FA60 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x5d000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x66809 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
OutputDebugStringW
WaitForSingleObjectEx OpenSemaphoreW CloseHandle HeapAlloc GetProcAddress CreateMutexExW GetCurrentProcessId GetProcessHeap GetModuleHandleW DebugBreak IsDebuggerPresent CreateFileW DeviceIoControl RaiseException LocalFree GetLastError GetVolumeNameForVolumeMountPointW DeleteFileW LoadLibraryExW DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection Sleep CreateEventW GetTickCount64 SetEvent GetFullPathNameW GetFileAttributesW SetConsoleCtrlHandler OpenPackageInfoByFullName GetPackageApplicationIds ClosePackageInfo FormatMessageW ReleaseMutex GetCurrentThreadId WaitForSingleObject GetModuleHandleExW ReleaseSemaphore SetLastError HeapFree CreateSemaphoreExW LocalAlloc GetModuleFileNameA FreeLibraryAndExitThread CreateThread WaitForMultipleObjectsEx FreeLibrary AcquireSRWLockShared AcquireSRWLockExclusive ReleaseSRWLockShared ReleaseSRWLockExclusive CreateProcessW CopyFileW GetTempPathW CreateEventExW LockResource SizeofResource LoadResource FindResourceW |
---|---|
msvcrt.dll |
_onexit
??1type_info@@UEAA@XZ __CxxFrameHandler3 _vsnwprintf memcpy_s ??3@YAXPEAX@Z _itow_s __dllonexit ?terminate@@YAXXZ _commode _exit exit _fmode __set_app_type __wgetmainargs __C_specific_handler _initterm __setusermatherr iswalnum _wsetlocale _XcptFilter __crtLCMapStringW _amsg_exit _cexit abort _wcsdup memset __uncaught_exception calloc __pctype_func _ismbblead ___lc_codepage_func ___lc_handle_func _errno ___mb_cur_max_func _unlock _lock setlocale memmove memcpy _CxxThrowException ??0exception@@QEAA@AEBQEBDH@Z _callnewh ??0bad_cast@@QEAA@PEBD@Z ??1bad_cast@@UEAA@XZ ??0bad_cast@@QEAA@AEBV0@@Z ??0exception@@QEAA@AEBQEBD@Z ?what@exception@@UEBAPEBDXZ ??_V@YAXPEAX@Z wcscpy_s fflush wcschr toupper _wcsnicmp free malloc _wcsicmp vswprintf_s wcsnlen wprintf _vsnprintf_s ??0exception@@QEAA@AEBV0@@Z ??0exception@@QEAA@XZ memcmp ??1exception@@UEAA@XZ _purecall iswdigit iswalpha |
ntdll.dll |
RtlCaptureContext
RtlSubscribeWnfStateChangeNotification RtlQueryWnfStateData RtlUnsubscribeWnfStateChangeNotification RtlLookupFunctionEntry RtlVirtualUnwind |
api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsConcatString
WindowsDuplicateString WindowsIsStringEmpty WindowsCreateStringReference WindowsGetStringRawBuffer WindowsDeleteString WindowsCreateString |
api-ms-win-core-com-l1-1-0.dll |
CoTaskMemAlloc
CoCreateInstance StringFromGUID2 IIDFromString CoTaskMemFree CLSIDFromString |
api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
RoActivateInstance RoInitialize RoUninitialize |
api-ms-win-core-string-l1-1-0.dll |
MultiByteToWideChar
WideCharToMultiByte GetStringTypeW |
api-ms-win-core-util-l1-1-0.dll |
DecodePointer
EncodePointer |
api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter |
api-ms-win-core-processthreads-l1-1-0.dll |
TerminateProcess
GetCurrentProcess |
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTimeAsFileTime
GetTickCount |
SHLWAPI.dll |
PathIsURLW
SHCreateStreamOnFileEx SHCreateStreamOnFileW |
api-ms-win-appmodel-unlock-l1-1-0.dll |
IsDeveloperModeEnabled
|
XSAPI.dll |
XsReadXvcInfoXVD
|
ADVAPI32.dll |
NotifyServiceStatusChangeW
QueryServiceStatusEx OpenServiceW OpenSCManagerW CloseServiceHandle RegQueryValueExW RegCloseKey RegGetValueW RegEnumValueW RegOpenKeyExW |
OLEAUT32.dll |
SysFreeString
SysAllocStringLen VariantClear VariantInit SysStringLen |
api-ms-win-core-winrt-error-l1-1-0.dll |
SetRestrictedErrorInfo
|
api-ms-win-core-winrt-error-l1-1-1.dll |
RoGetMatchingRestrictedErrorInfo
|
XmlLite.dll |
CreateXmlWriter
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.22000.4429 |
ProductVersion | 10.0.22000.4429 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Windows Device Application Management |
FileVersion (#2) | 10.0.22000.4429 (WinBuild.160101.0800) |
InternalName | WdApp.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WdApp.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.22000.4429 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2087-Jul-22 17:17:47 |
Version | 0.0 |
SizeofData | 34 |
AddressOfRawData | 0x41dac |
PointerToRawData | 0x41dac |
Referenced File | wdapp.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2087-Jul-22 17:17:47 |
Version | 0.0 |
SizeofData | 672 |
AddressOfRawData | 0x41dd0 |
PointerToRawData | 0x41dd0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2087-Jul-22 17:17:47 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0x42070 |
PointerToRawData | 0x42070 |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14004b230 |
GuardCFCheckFunctionPointer | 5368927616 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x32c59ff8 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 28 |
ASM objects (29395) | 4 |
C++ objects (29395) | 24 |
C objects (29395) | 68 |
Imports (29395) | 15 |
Total imports | 218 |
C++ objects (LTCG) (29395) | 23 |
Resource objects (29395) | 1 |
Linker (29395) | 1 |