Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-May-10 18:29:54 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\Inode Firewall\OneDrive\Documents\Présentations\SEC102\2017\PGSE\SEC102_Laura\bin\Debug\proclist.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | The PE contains functions most legitimate programs don't use. |
Manipulates other processes:
|
Safe | VirusTotal score: 0/72 (Scanned on 2020-05-14 14:25:07) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2017-May-10 18:29:54 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5200 |
SizeOfInitializedData | 0x4600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000102D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x10000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetStdHandle
CloseHandle OpenProcess ReadConsoleA K32EnumProcesses K32EnumProcessModulesEx K32GetModuleBaseNameA K32GetModuleFileNameExA K32GetModuleInformation K32GetProcessImageFileNameA FreeLibrary VirtualQuery GetProcessHeap HeapFree HeapAlloc GetLastError GetModuleHandleW GetStartupInfoW InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter WideCharToMultiByte MultiByteToWideChar RaiseException IsDebuggerPresent GetProcAddress |
---|---|
VCRUNTIME140D.dll |
memset
_except_handler4_common __vcrt_GetModuleFileNameW __vcrt_GetModuleHandleW __vcrt_LoadLibraryExW __std_type_info_destroy_list |
ucrtbased.dll |
_configthreadlocale
_set_new_mode __p__commode __stdio_common_vsprintf_s _seh_filter_dll _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _crt_at_quick_exit _controlfp_s terminate _wmakepath_s _wsplitpath_s wcscpy_s exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv __setusermatherr _set_app_type _seh_filter_exe _CrtDbgReportW _CrtDbgReport __stdio_common_vfprintf __acrt_iob_func realloc malloc free _c_exit _cexit __p___argv __p___argc _set_fmode _exit _register_thread_local_exe_atexit_callback |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-May-10 18:29:54 |
Version | 0.0 |
SizeofData | 135 |
AddressOfRawData | 0x87d4 |
PointerToRawData | 0x6dd4 |
Referenced File | C:\Users\Inode Firewall\OneDrive\Documents\Présentations\SEC102\2017\PGSE\SEC102_Laura\bin\Debug\proclist.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-May-10 18:29:54 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x885c |
PointerToRawData | 0x6e5c |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40a174 |
SEHandlerTable | 0x4086d0 |
SEHandlerCount | 1 |
XOR Key | 0x67cdf58a |
---|---|
Unmarked objects | 0 |
239 (40116) | 2 |
Imports (VS2015 UPD3 build 24123) | 2 |
ASM objects (VS2015 UPD3 build 24123) | 1 |
C++ objects (VS2015 UPD3 build 24123) | 23 |
C objects (VS2015 UPD3 build 24123) | 13 |
Imports (65501) | 3 |
Total imports | 77 |
C objects (VS2015 UPD3.1 build 24215) | 1 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |