Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-May-31 14:47:24 |
Detected languages |
English - United States
|
TLS Callbacks | 2 callback(s) detected. |
Debug artifacts |
D:\a\boiii-free\boiii-free\build\bin\x64\Release\boiii.pdb
|
CompanyName | momo5502 |
FileDescription | BOIII |
FileVersion | 1.0.5.1465 |
InternalName | something |
LegalCopyright | Copyright (C) 2022 momo5502. All rights reserved. |
OriginalFilename | boiii.exe |
ProductName | BOIII |
ProductVersion | 1.0.5 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses known Mersenne Twister constants Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. |
Resource 305 is possibly compressed or encrypted.
Resource 308 detected as a PE Executable. |
Suspicious | VirusTotal score: 1/72 (Scanned on 2025-01-26 21:45:46) | DrWeb: Trojan.MulDrop27.37231 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2024-May-31 14:47:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x14c400 |
SizeOfInitializedData | 0x190400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000010D384 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x170000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2e3000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
CRYPT32.dll |
CertFreeCertificateChainEngine
CertGetCertificateChain CryptDecodeObjectEx CertOpenStore CertFindCertificateInStore CertCloseStore CertEnumCertificatesInStore CryptStringToBinaryA CertFreeCertificateContext PFXImportCertStore CryptQueryObject CertFreeCertificateChain CertGetNameStringA CertFindExtension CertCreateCertificateChainEngine CryptProtectData CertAddCertificateContextToStore |
---|---|
KERNEL32.dll |
GetThreadContext
HeapDestroy HeapCreate MapViewOfFile CreateFileMappingW UnmapViewOfFile GetLargePageMinimum InitializeCriticalSection CreateThread GetCurrentProcessId TerminateProcess GetCurrentProcess OutputDebugStringA CreateMutexExA OpenProcess AddVectoredExceptionHandler GetProcAddress SetThreadContext RtlUnwind WriteConsoleW GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP GetACP IsValidCodePage HeapSize SetEndOfFile SetStdHandle HeapReAlloc SetFilePointerEx GetTimeZoneInformation EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetTickCount64 GetEnvironmentVariableA DeleteCriticalSection DecodePointer InitializeCriticalSectionEx GetTickCount GetVolumeInformationA ExitProcess VirtualProtect GetModuleHandleA MultiByteToWideChar GetCommandLineA Sleep GetExitCodeProcess WaitForSingleObject GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW FlsFree FlsSetValue FlsGetValue FlsAlloc HeapFree HeapAlloc GetConsoleOutputCP ReadConsoleW GetConsoleMode GetStdHandle FileTimeToSystemTime SystemTimeToTzSpecificLocalTime GetDriveTypeW GetFileType FreeLibraryAndExitThread ExitThread LoadLibraryExW CreateProcessA GetCurrentDirectoryA SetUnhandledExceptionFilter GetVersionExA GetCurrentThreadId SetEnvironmentVariableA GetConsoleWindow AllocConsole AttachConsole SetConsoleTitleA MulDiv GetProcessAffinityMask SetProcessAffinityMask CloseHandle GetLastError CreateMutexA TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount InterlockedPushEntrySList RtlUnwindEx GetStartupInfoW UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext InitializeSListHead GetStringTypeW GetCPInfo CompareStringEx LCMapStringEx EncodePointer GetSystemTimeAsFileTime GetModuleHandleExW IsProcessorFeaturePresent SleepConditionVariableSRW WakeAllConditionVariable CreateSymbolicLinkW GetFileInformationByHandleEx CreateHardLinkW MoveFileExW ReleaseSRWLockExclusive AcquireSRWLockExclusive SetLastError FormatMessageW GetSystemDirectoryA LoadLibraryA QueryPerformanceFrequency FreeLibrary EnterCriticalSection LeaveCriticalSection LocalFree WideCharToMultiByte VerifyVersionInfoW SleepEx MoveFileExA WaitForSingleObjectEx ReadFile GetFileSizeEx CreateFileA WriteFile PeekNamedPipe CreateFileW WaitNamedPipeW lstrlenW GetModuleFileNameW SizeofResource FindResourceA GetModuleHandleExA LockResource LoadResource VirtualFree VirtualAlloc GetSystemInfo FlushInstructionCache GetSystemFirmwareTable DeleteFileW MoveFileW VirtualQuery GetCommandLineW Thread32Next Thread32First SuspendThread ResumeThread CreateToolhelp32Snapshot GetThreadId OpenThread SetFilePointer GetTempPathA GetTempFileNameA FlushFileBuffers ReleaseMutex IsDebuggerPresent OutputDebugStringW RaiseException TryAcquireSRWLockExclusive GetExitCodeThread GetNativeSystemInfo FormatMessageA GetLocaleInfoEx GetCurrentDirectoryW CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW GetFileInformationByHandle GetFinalPathNameByHandleW GetFullPathNameW SetFileInformationByHandle AreFileApisANSI DeviceIoControl GetModuleHandleW CopyFileW QueryPerformanceCounter |
USER32.dll |
ShowWindow
PeekMessageW TranslateMessage DispatchMessageW ShowCursor IsWindow DestroyWindow DefWindowProcA GetWindowRect SetWindowPos SetWindowRgn SetFocus PostQuitMessage UnregisterClassA MessageBoxA GetClientRect RegisterClassExA SetForegroundWindow GetMessageA DispatchMessageA MoveWindow GetWindowLongPtrA SetProcessDPIAware GetWindowTextW GetSystemMetrics GetWindowTextA LoadIconA SetWindowLongPtrA SendMessageA CreateWindowExA SetWindowTextA UpdateWindow ReleaseDC GetDesktopWindow GetDC AdjustWindowRect LoadCursorA RegisterClassA |
GDI32.dll |
GetDeviceCaps
SetTextColor SetBkColor CreateSolidBrush DeleteObject CreateFontA CreateRoundRectRgn CreateBitmap |
ADVAPI32.dll |
CryptAcquireContextW
CryptGenRandom RegCreateKeyExA GetUserNameA RegCreateKeyExW CryptAcquireContextA CryptCreateHash CryptHashData CryptDestroyHash CryptGetHashParam CryptReleaseContext RegCloseKey RegQueryValueExW RegSetValueExW RegOpenKeyExA RegQueryValueExA GetCurrentHwProfileA |
SHELL32.dll |
SHGetKnownFolderPath
ShellExecuteA CommandLineToArgvW |
ole32.dll |
CoTaskMemFree
OleUninitialize CoCreateInstance CoUninitialize CoInitialize CoGetClassObject OleSetContainedObject OleInitialize |
OLEAUT32.dll |
VariantCopy
VariantClear VariantInit SysAllocString |
ntdll.dll |
NtQueryObject
VerSetConditionMask RtlPcToFileHeader |
WS2_32.dll |
WSAEventSelect
WSAResetEvent WSAWaitForMultipleEvents accept getsockopt listen WSAIoctl WSAGetLastError WSACloseEvent recv WSAEnumNetworkEvents getaddrinfo freeaddrinfo getpeername getsockname gethostbyname connect closesocket send WSASetLastError WSACreateEvent sendto recvfrom __WSAFDIsSet select ioctlsocket socket setsockopt htonl htons bind ntohs ntohl WSAStartup WSACleanup |
dwmapi.dll |
DwmSetWindowAttribute
|
bcrypt.dll |
BCryptGenRandom
|
dbghelp.dll |
MiniDumpWriteDump
|
Ordinal | 1 |
---|---|
Address | 0x1c0f44 |
Ordinal | 2 |
---|---|
Address | 0x1c0f40 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.5.1465 |
ProductVersion | 1.0.5.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | momo5502 |
FileDescription | BOIII |
FileVersion (#2) | 1.0.5.1465 |
InternalName | something |
LegalCopyright | Copyright (C) 2022 momo5502. All rights reserved. |
OriginalFilename | boiii.exe |
ProductName | BOIII |
ProductVersion (#2) | 1.0.5 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-31 14:47:24 |
Version | 0.0 |
SizeofData | 83 |
AddressOfRawData | 0x1aa9f8 |
PointerToRawData | 0x1a91f8 |
Referenced File | D:\a\boiii-free\boiii-free\build\bin\x64\Release\boiii.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-31 14:47:24 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x1aaa4c |
PointerToRawData | 0x1a924c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-May-31 14:47:24 |
Version | 0.0 |
SizeofData | 1164 |
AddressOfRawData | 0x1aaa60 |
PointerToRawData | 0x1a9260 |
StartAddressOfRawData | 0x1701aaf40 |
---|---|
EndAddressOfRawData | 0x1701ab31c |
AddressOfIndex | 0x1701e6664 |
AddressOfCallbacks | 0x17014f068 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
Callbacks |
0x000000017010CA00
0x000000017010CAB8 |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1701c0280 |
XOR Key | 0x7ba0f070 |
---|---|
Unmarked objects | 0 |
ASM objects (30795) | 7 |
C++ objects (30795) | 205 |
Unmarked objects (#2) | 1 |
253 (33218) | 7 |
C objects (33218) | 19 |
ASM objects (33218) | 21 |
C++ objects (33218) | 106 |
C objects (30795) | 27 |
C objects (CVTCIL) (30795) | 1 |
Imports (30795) | 29 |
Total imports | 378 |
C++ objects (LTCG) (33523) | 554 |
Exports (33523) | 1 |
Resource objects (33523) | 1 |
151 | 1 |
Linker (33523) | 1 |