Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Jun-22 09:43:19 |
Detected languages |
English - United States
|
TLS Callbacks | 3 callback(s) detected. |
CompanyName | |
FileDescription | |
FileVersion | 1.0.0.0 |
LegalCopyright | |
OriginalFilename | ICDWConfig.exe |
ProductName | ICDWConfig |
ProductVersion | 1.0.0.0 |
Suspicious | PEiD Signature: | HQR data file |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .qtmetad
Unusual section name found: .qtmimed Unusual section name found: .xdata |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 176 bytes of data starting at offset 0x1369d50. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 12 |
TimeDateStamp | 2020-Jun-22 09:43:19 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0xe52400 |
SizeOfInitializedData | 0x1369a00 |
SizeOfUninitializedData | 0x1800 |
AddressOfEntryPoint | 0x00000000000014C0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x1372000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1371412 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x200000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
AccessCheck
AllocateAndInitializeSid BuildTrusteeWithSidW CopySid DuplicateToken FreeSid GetEffectiveRightsFromAclW GetLengthSid GetNamedSecurityInfoW GetTokenInformation LookupAccountSidW MapGenericMask OpenProcessToken RegCloseKey RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegFlushKey RegNotifyChangeKeyValue RegOpenKeyExW RegQueryInfoKeyW RegQueryValueExW RegSetValueExW SystemFunction036 |
---|---|
bcrypt.dll |
BCryptCloseAlgorithmProvider
BCryptDecrypt BCryptDestroyKey BCryptEncrypt BCryptGenerateSymmetricKey BCryptOpenAlgorithmProvider BCryptSetProperty |
CRYPT32.dll |
CertAddStoreToCollection
CertCloseStore CertDuplicateCertificateContext CertFindCertificateInStore CertFindChainInStore CertFreeCertificateChain CertFreeCertificateContext CertGetCertificateChain CertOpenStore CertOpenSystemStoreW CertVerifyTimeValidity PFXImportCertStore |
dwmapi.dll |
DwmEnableBlurBehindWindow
DwmGetWindowAttribute DwmIsCompositionEnabled DwmSetWindowAttribute |
GDI32.dll |
AddFontMemResourceEx
AddFontResourceExW BitBlt ChoosePixelFormat CombineRgn CreateBitmap CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateFontIndirectW CreateRectRgn DeleteDC DeleteObject DescribePixelFormat EnumFontFamiliesExW ExtTextOutW GdiFlush GetBitmapBits GetCharABCWidthsFloatW GetCharABCWidthsW GetDIBits GetDeviceCaps GetFontData GetGlyphOutlineW GetObjectW GetOutlineTextMetricsW GetPixelFormat GetRegionData GetStockObject GetTextExtentPoint32W GetTextFaceW GetTextMetricsW OffsetRgn RemoveFontMemResourceEx RemoveFontResourceExW SelectClipRgn SelectObject SetBkMode SetGraphicsMode SetLayout SetPixelFormat SetTextAlign SetTextColor SetWorldTransform SwapBuffers |
IMM32.dll |
ImmAssociateContext
ImmAssociateContextEx ImmGetCompositionStringW ImmGetContext ImmGetDefaultIMEWnd ImmGetOpenStatus ImmGetVirtualKey ImmNotifyIME ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionWindow |
IPHLPAPI.DLL |
ConvertInterfaceIndexToLuid
ConvertInterfaceLuidToIndex ConvertInterfaceLuidToNameW ConvertInterfaceNameToLuidW GetAdaptersAddresses GetNetworkParams |
KERNEL32.dll |
AddVectoredExceptionHandler
CancelIoEx CheckRemoteDebuggerPresent ClearCommBreak ClearCommError CloseHandle CompareStringEx CompareStringW CopyFileW CreateDirectoryW CreateEventA CreateEventW CreateFileA CreateFileMappingW CreateFileW CreateMutexW CreateProcessW CreateSemaphoreA CreateThread DeleteCriticalSection DeleteFileW DeviceIoControl DuplicateHandle EnterCriticalSection EscapeCommFunction ExitProcess ExpandEnvironmentStringsW FileTimeToSystemTime FindClose FindCloseChangeNotification FindFirstChangeNotificationW FindFirstFileExW FindFirstFileW FindNextChangeNotification FindNextFileW FlushFileBuffers FormatMessageW FreeLibrary GetCommModemStatus GetCommState GetCommTimeouts GetCommandLineW GetConsoleWindow GetCurrencyFormatW GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDriveTypeW GetExitCodeProcess GetFileAttributesExW GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSize GetFileType GetFullPathNameW GetGeoInfoW GetHandleInformation GetLastError GetLocalTime GetLocaleInfoW GetLogicalDrives GetLongPathNameW GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetNativeSystemInfo GetProcAddress GetProcessAffinityMask GetStartupInfoA GetStartupInfoW GetSystemDirectoryW GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetTempPathW GetThreadContext GetThreadPriority GetTickCount64 GetTimeFormatW GetTimeZoneInformation GetUserDefaultLCID GetUserDefaultLangID GetUserGeoID GetUserPreferredUILanguages GetVolumeInformationW GetVolumePathNamesForVolumeNameW GlobalAlloc GlobalFree GlobalLock GlobalSize GlobalUnlock InitializeCriticalSection IsDBCSLeadByteEx IsDebuggerPresent LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryW LocalFree MapViewOfFile MoveFileExW MoveFileW MultiByteToWideChar OpenProcess OutputDebugStringA OutputDebugStringW PurgeComm QueryPerformanceCounter QueryPerformanceFrequency RaiseException RaiseFailFastException ReadFile ReadFileEx RegisterWaitForSingleObject ReleaseMutex ReleaseSemaphore RemoveDirectoryW RemoveVectoredExceptionHandler ResetEvent ResumeThread RtlCaptureContext RtlLookupFunctionEntry RtlUnwindEx RtlVirtualUnwind SetCommBreak SetCommMask SetCommState SetCommTimeouts SetCurrentDirectoryW SetEndOfFile SetErrorMode SetEvent SetFilePointer SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetProcessAffinityMask SetThreadContext SetThreadPriority SetUnhandledExceptionFilter Sleep SleepEx SuspendThread SwitchToThread SystemTimeToFileTime TerminateProcess TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection TzSpecificLocalTimeToSystemTime UnmapViewOfFile UnregisterWaitEx VirtualAlloc VirtualFree VirtualProtect VirtualQuery WTSGetActiveConsoleSessionId WaitForMultipleObjects WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteFile WriteFileEx __C_specific_handler lstrcmpW |
msvcrt.dll |
___lc_codepage_func
___mb_cur_max_func __argc __argv __doserrno __getmainargs __initenv __iob_func __lconv_init __set_app_type __setusermatherr _acmdln _aligned_free _aligned_malloc _amsg_exit _beginthreadex _cexit _close _close _commode _endthreadex _errno _filelengthi64 _fileno _fmode _get_osfhandle _getdrive _gmtime64 _initterm _localtime64 _lock _lseeki64 _mktime64 _onexit _open_osfhandle _putenv _read _read _setjmp _strdup _strnicmp _timezone _tzset _tzname _ultoa _unlock _vscprintf _vsnprintf _waccess _wassert _wchmod _wgetdcwd _wgetenv_s _write _write abort acos asin atan atof atoi bsearch calloc exit fclose feof ferror fflush fgetpos fgets frexp fopen fprintf fputc fputs fread free fseek fsetpos ftell fwrite getc getenv islower ispunct isspace isupper iswctype isxdigit localeconv log10 longjmp malloc memchr memcmp memcpy memmove memset printf remove puts qsort rand realloc setlocale signal sprintf srand sscanf strcat strchr strcmp strcoll strcpy strerror strftime strlen strncmp strncpy strrchr strstr strtol strtoul strxfrm tan tolower toupper towlower towupper ungetc vfprintf wcscmp wcscoll wcsftime wcslen wcsncmp wcsrchr wcsxfrm |
NETAPI32.dll |
NetApiBufferFree
NetShareEnum |
ole32.dll |
CoCreateGuid
CoCreateInstance CoGetMalloc CoInitialize CoInitializeEx CoLockObjectExternal CoTaskMemFree CoUninitialize DoDragDrop OleFlushClipboard OleGetClipboard OleInitialize OleIsCurrentClipboard OleSetClipboard OleUninitialize RegisterDragDrop ReleaseStgMedium RevokeDragDrop StringFromGUID2 |
OLEAUT32.dll |
SafeArrayCreateVector
SafeArrayPutElement SysAllocString SysFreeString |
Secur32.dll |
AcceptSecurityContext
AcquireCredentialsHandleW ApplyControlToken DecryptMessage DeleteSecurityContext EncryptMessage FreeContextBuffer FreeCredentialsHandle InitializeSecurityContextW QueryContextAttributesW |
SETUPAPI.dll |
CM_Get_DevNode_Status
CM_Get_Device_IDW CM_Get_Parent SetupDiDestroyDeviceInfoList SetupDiEnumDeviceInfo SetupDiGetClassDevsW SetupDiGetDeviceRegistryPropertyW SetupDiOpenDevRegKey |
SHELL32.dll |
CommandLineToArgvW
SHBrowseForFolderW SHCreateItemFromIDList SHCreateItemFromParsingName SHFileOperationW SHGetFileInfoW SHGetKnownFolderIDList SHGetKnownFolderPath SHGetMalloc SHGetPathFromIDListW SHGetStockIconInfo ShellExecuteW Shell_NotifyIconGetRect Shell_NotifyIconW |
USER32.dll |
AdjustWindowRectEx
AppendMenuW AttachThreadInput BeginPaint CallNextHookEx ChangeClipboardChain ChangeWindowMessageFilterEx CharNextExA ChildWindowFromPointEx ClientToScreen CloseTouchInputHandle CreateCaret CreateCursor CreateIconIndirect CreateMenu CreatePopupMenu CreateWindowExW DefWindowProcW DestroyCaret DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageW DrawIconEx DrawMenuBar EnableMenuItem EndPaint EnumDisplayDevicesW EnumDisplayMonitors EnumWindows FindWindowA FlashWindowEx GetAncestor GetAsyncKeyState GetCapture GetCaretBlinkTime GetClassInfoW GetClientRect GetClipboardFormatNameW GetCursor GetCursorInfo GetCursorPos GetDC GetDesktopWindow GetDoubleClickTime GetFocus GetForegroundWindow GetIconInfo GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardState GetMenu GetMenuItemInfoW GetMessageExtraInfo GetMonitorInfoW GetParent GetQueueStatus GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTouchInputInfo GetUpdateRect GetWindow GetWindowLongPtrW GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId HideCaret InsertMenuW InvalidateRect IsChild IsHungAppWindow IsIconic IsTouchWindow IsWindow IsWindowEnabled IsWindowVisible IsZoomed KillTimer LoadCursorW LoadIconW LoadImageW MapVirtualKeyW MessageBeep MessageBoxW ModifyMenuW MonitorFromPoint MonitorFromWindow MoveWindow MsgWaitForMultipleObjectsEx PeekMessageW PostMessageW RealGetWindowClassW RegisterClassExW RegisterClassW RegisterClipboardFormatW RegisterDeviceNotificationW RegisterPowerSettingNotification RegisterTouchWindow RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu ScreenToClient SendMessageW SetCapture SetCaretPos SetClipboardViewer SetCursor SetCursorPos SetFocus SetForegroundWindow SetLayeredWindowAttributes SetMenu SetMenuItemInfoW SetParent SetTimer SetWindowLongPtrW SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowCaret ShowWindow SystemParametersInfoW ToAscii ToUnicode TrackMouseEvent TrackPopupMenu TrackPopupMenuEx TranslateMessage UnhookWindowsHookEx UnregisterClassW UnregisterDeviceNotification UnregisterPowerSettingNotification UnregisterTouchWindow UpdateLayeredWindow UpdateLayeredWindowIndirect WindowFromPoint |
USERENV.dll |
GetUserProfileDirectoryW
|
UxTheme.dll |
CloseThemeData
DrawThemeBackgroundEx GetCurrentThemeName GetThemeBackgroundRegion GetThemeBool GetThemeColor GetThemeEnumValue GetThemeInt GetThemeMargins GetThemePartSize GetThemePropertyOrigin GetThemeTransitionDuration IsAppThemed IsThemeActive IsThemeBackgroundPartiallyTransparent OpenThemeData SetWindowTheme |
VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
WINMM.dll |
PlaySoundW
timeKillEvent timeSetEvent |
WS2_32.dll |
WSAAccept
WSAAsyncSelect WSACleanup WSAConnect WSAGetLastError WSAHtonl WSAIoctl WSANtohl WSANtohs WSARecv WSARecvFrom WSASend WSASendTo WSASocketW WSAStartup __WSAFDIsSet bind closesocket freeaddrinfo getaddrinfo gethostname getnameinfo getpeername getsockname getsockopt htonl htons listen ntohl select setsockopt |
WTSAPI32.dll |
WTSFreeMemory
WTSQuerySessionInformationW |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | |
FileDescription | |
FileVersion (#2) | 1.0.0.0 |
LegalCopyright | |
OriginalFilename | ICDWConfig.exe |
ProductName | ICDWConfig |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0x175f000 |
---|---|
EndAddressOfRawData | 0x175f008 |
AddressOfIndex | 0x175598c |
AddressOfCallbacks | 0x175e040 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x0000000000523AD0
0x0000000000523AA0 0x0000000000542C00 |