Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2023-Oct-18 17:05:02 |
Detected languages |
English - United States
|
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
D:\3.7 Work\Eternity-main\src-tauri\target\release\deps\cultivation.pdb
|
FileDescription | Eternity |
FileVersion | 1.1.1 |
ProductVersion | 1.1.1 |
ProductName | Eternity |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/71 (Scanned on 2024-02-12 11:12:20) |
Google:
Detected
Ikarus: Trojan.Win64.CoinMiner |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2023-Oct-18 17:05:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xa98c00 |
SizeOfInitializedData | 0x5e1600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000A60210 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x107e000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
kernel32.dll |
GetProcAddress
FreeLibrary GetCurrentProcessId Sleep TryAcquireSRWLockExclusive SetLastError PostQueuedCompletionStatus GetHandleInformation CreateIoCompletionPort GetQueuedCompletionStatusEx InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared InitOnceExecuteOnce GetTickCount64 SetFileCompletionNotificationModes GetLastError IsDBCSLeadByte GetCPInfo RtlVirtualUnwind WideCharToMultiByte MultiByteToWideChar CompareStringW AreFileApisANSI GetCurrentProcess TzSpecificLocalTimeToSystemTime GetSystemInfo GetProcessHeap HeapFree HeapAlloc OpenProcess SystemTimeToFileTime SystemTimeToTzSpecificLocalTime FileTimeToLocalFileTime QueryPerformanceFrequency GetProcessTimes GetSystemTimes GetProcessIoCounters GetExitCodeProcess QueryPerformanceCounter LocalFree VirtualQueryEx ReadProcessMemory GetSystemTimeAsFileTime SetFileTime ReleaseSemaphore GlobalMemoryStatusEx GetModuleFileNameW FoldStringW CreateHardLinkW GetModuleHandleW GetLogicalDrives LocalFileTimeToFileTime GetSystemTime GetCurrentDirectoryW SetEndOfFile GetCurrentThreadId UnhandledExceptionFilter ReadFile IsProcessorFeaturePresent InitializeSListHead GetFileType WaitForSingleObject SetConsoleCtrlHandler CreateSemaphoreA GetVolumeInformationW FileTimeToSystemTime IsDebuggerPresent FlushFileBuffers GetStdHandle RtlUnwindEx RtlPcToFileHeader RaiseException SleepConditionVariableSRW GetModuleHandleA CreateEventW SetFilePointer GetFullPathNameW LoadLibraryA RemoveDirectoryW GetShortPathNameW GetCurrentThread GetLongPathNameW GetTempPathW lstrlenW ReadConsoleW WriteConsoleW CreateProcessW GetWindowsDirectoryW WaitForMultipleObjects CreateNamedPipeW ExitProcess SetCurrentDirectoryW CancelIo CopyFileExW GetFinalPathNameByHandleW MoveFileExW GetConsoleMode WriteFile GetFileInformationByHandleEx CreateMutexA WaitForSingleObjectEx HeapReAlloc WakeConditionVariable WakeAllConditionVariable GetProcessId TerminateProcess TlsFree ReadFileEx SleepEx WriteFileEx SetFilePointerEx SetFileInformationByHandle GetCommandLineW SetEnvironmentVariableW GetEnvironmentStringsW RtlLookupFunctionEntry RtlCaptureContext SwitchToThread SetThreadStackGuarantee AddVectoredExceptionHandler CompareStringOrdinal ReleaseMutex FreeEnvironmentStringsW SetUnhandledExceptionFilter GetFileInformationByHandle EncodePointer SetThreadPriority FindNextFileW GlobalLock GlobalUnlock FindFirstFileW FindClose GlobalAlloc InitializeCriticalSectionAndSpinCount MoveFileW DeviceIoControl SetFileAttributesW GetFileAttributesW GetDriveTypeW GetDiskFreeSpaceExW OutputDebugStringA OutputDebugStringW TlsAlloc TlsGetValue ReleaseSRWLockExclusive AcquireSRWLockExclusive LoadLibraryExW TlsSetValue GetEnvironmentVariableW DeleteFileW CreateFileW CreateDirectoryW GetProcessAffinityMask FormatMessageW CreateThread CreateSemaphoreW ResetEvent SetEvent DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection GetVersionExW GetSystemDirectoryW LoadLibraryW SetHandleInformation SetThreadExecutionState DuplicateHandle CreatePipe CloseHandle GetOverlappedResult |
---|---|
ws2_32.dll |
closesocket
select WSAStartup WSAIoctl getaddrinfo ioctlsocket freeaddrinfo WSACleanup getsockname accept getpeername WSASocketW bind connect listen getsockopt WSADuplicateSocketW shutdown recv socket send WSASend WSAGetLastError setsockopt |
user32.dll |
SetWindowTextW
MonitorFromPoint EnumDisplayMonitors ClientToScreen SystemParametersInfoA GetTouchInputInfo GetWindowLongPtrW IsWindowVisible ClipCursor GetClipCursor GetAncestor AdjustWindowRectEx GetMenu GetWindowRect SetCapture GetMessageW ScreenToClient CloseTouchInputHandle SetWindowLongPtrW SendInput GetAsyncKeyState MsgWaitForMultipleObjectsEx RegisterRawInputDevices GetKeyState RegisterClassExW RegisterWindowMessageA MessageBoxW MapVirtualKeyExW SetMenu VkKeyScanW TrackMouseEvent GetClientRect SendMessageW GetCursorPos SetForegroundWindow EnumChildWindows GetUpdateRect CreateIcon MapVirtualKeyW PostThreadMessageW AppendMenuW ValidateRect RegisterHotKey DestroyIcon UnregisterHotKey SetMenuItemInfoW CreateMenu PostQuitMessage CreateAcceleratorTableW DestroyWindow TranslateAcceleratorW GetDC IsProcessDPIAware GetKeyboardLayout ToUnicodeEx GetRawInputData OpenClipboard GetClipboardData CloseClipboard EmptyClipboard GetWindowLongW RegisterClipboardFormatA SetClipboardData DefWindowProcW DestroyAcceleratorTable GetMessageA DispatchMessageA PostMessageW EnableMenuItem DispatchMessageW TranslateMessage MonitorFromRect SetWindowPos SetCursor CheckMenuItem CharToOemBuffW ShowWindow SetWindowLongW MonitorFromWindow CharLowerW CharUpperW OemToCharBuffA OemToCharA CharToOemA GetKeyboardState GetForegroundWindow PeekMessageW RedrawWindow RegisterTouchWindow GetSystemMetrics IsWindow CreateWindowExW FlashWindowEx GetActiveWindow SetCursorPos ShowCursor LoadCursorW InvalidateRgn GetWindowPlacement SetWindowPlacement ChangeDisplaySettingsExW ReleaseCapture GetMonitorInfoW |
advapi32.dll |
RegGetValueW
EventUnregister EventWriteTransfer EventSetInformation EventRegister OpenServiceW OpenSCManagerW StartServiceW CheckTokenMembership AllocateAndInitializeSid AdjustTokenPrivileges LookupPrivilegeValueW SetFileSecurityW CloseServiceHandle RegOpenKeyExW RegSetValueExW ControlService QueryServiceStatusEx LookupAccountSidW CopySid GetLengthSid IsValidSid SystemFunction036 RegCloseKey RegQueryValueExW GetTokenInformation OpenProcessToken FreeSid |
shell32.dll |
SHGetKnownFolderPath
ShellExecuteW SHCreateItemFromParsingName CommandLineToArgvW DragFinish DragQueryFileW |
secur32.dll |
LsaFreeReturnBuffer
AcquireCredentialsHandleA DecryptMessage DeleteSecurityContext LsaEnumerateLogonSessions LsaGetLogonSessionData QueryContextAttributesW FreeCredentialsHandle EncryptMessage AcceptSecurityContext InitializeSecurityContextW FreeContextBuffer ApplyControlToken |
crypt32.dll |
CertEnumCertificatesInStore
CertDuplicateCertificateContext CertFreeCertificateChain CertDuplicateCertificateChain CertAddCertificateContextToStore CertOpenStore CertGetCertificateChain CertVerifyCertificateChainPolicy CertCloseStore CertDuplicateStore CertFreeCertificateContext |
comctl32.dll |
RemoveWindowSubclass
SetWindowSubclass DefSubclassProc |
ole32.dll |
CoInitializeEx
CoSetProxyBlanket OleInitialize CreateStreamOnHGlobal RegisterDragDrop CoUninitialize CoInitializeSecurity CoCreateInstance RevokeDragDrop CoTaskMemFree CoTaskMemAlloc |
gdi32.dll |
CreateRectRgn
GetDeviceCaps DeleteObject |
dwmapi.dll |
DwmEnableBlurBehindWindow
|
powrprof.dll |
CallNtPowerInformation
|
oleaut32.dll |
SysFreeString
SysAllocString SetErrorInfo SysStringLen GetErrorInfo VariantClear |
ntdll.dll |
RtlGetVersion
NtQueryInformationProcess NtQuerySystemInformation NtCreateFile RtlGetNtVersionNumbers NtCancelIoFileEx NtDeviceIoControlFile RtlNtStatusToDosError NtWriteFile NtReadFile |
psapi.dll |
GetPerformanceInfo
GetModuleFileNameExW |
pdh.dll |
PdhAddEnglishCounterW
PdhGetFormattedCounterValue PdhOpenQueryA PdhCollectQueryData PdhRemoveCounter PdhCloseQuery |
iphlpapi.dll |
GetIfEntry2
FreeMibTable GetIfTable2 GetAdaptersAddresses |
netapi32.dll |
NetUserGetLocalGroups
NetUserGetInfo NetUserEnum NetApiBufferFree |
uxtheme.dll |
SetWindowTheme
|
bcrypt.dll |
BCryptGenRandom
|
api-ms-win-crt-math-l1-1-0.dll |
trunc
round floor __setusermatherr |
api-ms-win-crt-heap-l1-1-0.dll |
malloc
realloc _set_new_mode calloc _callnewh free |
api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
_wcsicmp wcsncpy wcslen strlen wcspbrk wcsncmp |
api-ms-win-crt-runtime-l1-1-0.dll |
_wassert
_errno abort terminate _crt_atexit _configure_narrow_argv _cexit _initialize_narrow_environment _register_onexit_function exit _initialize_onexit_table _get_initial_narrow_environment _set_app_type _seh_filter_exe _register_thread_local_exe_atexit_callback _initterm_e _exit _c_exit __p___argc __p___argv _initterm |
api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode __stdio_common_vswprintf |
api-ms-win-crt-convert-l1-1-0.dll |
_ultow_s
wcstol |
api-ms-win-crt-time-l1-1-0.dll |
clock
|
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.1.1.0 |
ProductVersion | 1.1.1.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
FileDescription | Eternity |
FileVersion (#2) | 1.1.1 |
ProductVersion (#2) | 1.1.1 |
ProductName | Eternity |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-18 17:05:02 |
Version | 0.0 |
SizeofData | 96 |
AddressOfRawData | 0xd6a52c |
PointerToRawData | 0xd6952c |
Referenced File | D:\3.7 Work\Eternity-main\src-tauri\target\release\deps\cultivation.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-18 17:05:02 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xd6a58c |
PointerToRawData | 0xd6958c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2023-Oct-18 17:05:02 |
Version | 0.0 |
SizeofData | 1084 |
AddressOfRawData | 0xd6a5a0 |
PointerToRawData | 0xd695a0 |
StartAddressOfRawData | 0x140d6aa00 |
---|---|
EndAddressOfRawData | 0x140d6ad5c |
AddressOfIndex | 0x140f97c20 |
AddressOfCallbacks | 0x140a9afd0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks |
0x00000001409C2000
|
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140f903c8 |
XOR Key | 0xab269c6c |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 20 |
C++ objects (VS 2015-2022 runtime 32533) | 49 |
C objects (VS 2015-2022 runtime 32533) | 16 |
ASM objects (VS 2015-2022 runtime 32533) | 9 |
Total imports | 575 |
Imports (30148) | 47 |
C++ objects (VS2022 Update 7 (17.7.4) compiler 32825) | 44 |
C objects (VS2022 Update 7 (17.7.4) compiler 32825) | 53 |
Unmarked objects (#2) | 1132 |
Resource objects (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |
Linker (VS2022 Update 7 (17.7.4) compiler 32825) | 1 |