Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Nov-18 17:55:10 |
Detected languages |
English - United States
|
CompanyName | Mojang |
FileDescription | The Minecraft Launcher |
FileVersion | 3.2.0.0 |
LegalCopyright | |
ProductName | SKlauncher |
ProductVersion | 3.2.0 |
OriginalFilename | SKlauncher-3.2-x64.exe |
InternalName | SKlauncher |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains obfuscated function names:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
1284608 bytes of data starting at offset 0x56600.
The overlay data has an entropy of 7.90742 and is possibly compressed or encrypted. Overlay data amounts for 78.4062% of the executable. |
Suspicious | VirusTotal score: 1/70 (Scanned on 2024-02-11 19:51:29) | tehtris: Generic.Malware |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2022-Nov-18 17:55:10 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x3bc00 |
SizeOfInitializedData | 0x29e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000021394 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x68000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
SetForegroundWindow
MessageBoxA ExitWindowsEx EnumWindows IsIconic ShowWindow MessageBoxW GetLastActivePopup IsWindowVisible GetWindowThreadProcessId MonitorFromPoint |
---|---|
ADVAPI32.dll |
AdjustTokenPrivileges
InitializeSecurityDescriptor SetSecurityDescriptorDacl OpenProcessToken GetTokenInformation ConvertSidToStringSidA RegEnumKeyExA RegOpenKeyExA RegQueryValueExA RegCreateKeyExA RegSetValueExA RegCloseKey LookupPrivilegeValueA |
ole32.dll |
CreateStreamOnHGlobal
CoCreateInstance CoInitializeEx GetHGlobalFromStream CoUninitialize |
KERNEL32.dll |
GetStringTypeW
GetStringTypeA HeapReAlloc QueryPerformanceCounter GetTimeZoneInformation EnumSystemLocalesA IsValidLocale InitializeCriticalSectionAndSpinCount WriteConsoleA SetStdHandle CompareStringA CompareStringW GetLocaleInfoW SetEndOfFile GetLocaleInfoA SetCurrentDirectoryA HeapCreate HeapSetInformation IsValidCodePage GetOEMCP GetACP GetLastError CreateFileW SetFilePointer WriteFile ReadFile GetProcAddress LoadLibraryA GetUserDefaultLCID CloseHandle CreateFileA CreateDirectoryA FlushFileBuffers WriteConsoleW GetFileType GetStdHandle GetLongPathNameW ExitProcess RemoveDirectoryA MultiByteToWideChar AreFileApisANSI FindClose FindFirstFileA FindFirstFileW TerminateProcess GetExitCodeProcess CreateProcessW GetWindowsDirectoryW SetHandleInformation CreatePipe GetShortPathNameA GetModuleFileNameA GetShortPathNameW GetModuleFileNameW GetCurrentProcessId GetLongPathNameA FoldStringW GetWindowsDirectoryA GetEnvironmentVariableW GetEnvironmentVariableA GetTempPathW GetTempPathA GetTempFileNameA GetFullPathNameW GetFullPathNameA FindNextFileA DeleteFileA LoadLibraryW FreeEnvironmentStringsW GetEnvironmentStringsW FreeEnvironmentStringsA GetEnvironmentStrings GetExitCodeThread WaitForSingleObject CreateThread GetConsoleOutputCP SetEnvironmentVariableA GetProcessHeap GetCurrentDirectoryA GetVersionExA CreateProcessA SearchPathA GetSystemTimeAsFileTime EnterCriticalSection InitializeCriticalSection LeaveCriticalSection Sleep GetMailslotInfo CreateMailslotA GetCommandLineW CreateSemaphoreA LocalFree GetCurrentProcess LocalAlloc SizeofResource LockResource LoadResource FindResourceA GlobalUnlock GlobalSize GlobalLock GetTickCount AllocConsole GetModuleHandleA LoadLibraryExA SetEnvironmentVariableW SetCurrentDirectoryW WideCharToMultiByte DeleteCriticalSection UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext RaiseException RtlPcToFileHeader RtlUnwindEx CreateDirectoryW RemoveDirectoryW HeapAlloc HeapFree DebugBreak GetCommandLineA GetStartupInfoA LCMapStringA LCMapStringW GetCPInfo EncodePointer DecodePointer FlsGetValue FlsSetValue FlsFree SetLastError GetCurrentThreadId FlsAlloc HeapSize GetModuleHandleW GetConsoleCP GetConsoleMode SetHandleCount |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.2.0.0 |
ProductVersion | 3.2.0.0 |
FileFlags |
VS_FF_DEBUG
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | UNKNOWN |
CompanyName | Mojang |
FileDescription | The Minecraft Launcher |
FileVersion (#2) | 3.2.0.0 |
LegalCopyright | |
ProductName | SKlauncher |
ProductVersion (#2) | 3.2.0 |
OriginalFilename | SKlauncher-3.2-x64.exe |
InternalName | SKlauncher |
Resource LangID | UNKNOWN |
---|
XOR Key | 0x78cfa1b2 |
---|---|
Unmarked objects | 0 |
150 (20413) | 4 |
ASM objects (VS2008 build 21022) | 13 |
C objects (VS2008 build 21022) | 176 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 9 |
Total imports | 189 |
C++ objects (VS2008 build 21022) | 91 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 build 21022) | 1 |