Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Nov-18 11:41:56 |
Detected languages |
English - United States
|
CompanyName | Mario |
FileDescription | League Lobby |
FileVersion | 1.3.0.0 |
LegalCopyright | Mario |
OriginalFilename | LeagueLobbyPortable.exe |
ProductName | League Lobby |
ProductVersion | 1.3.0.0 |
Suspicious | PEiD Signature: | HQR data file |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses known Mersenne Twister constants Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. |
Unusual section name found: .qtmetad
Unusual section name found: .qtmimed |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/67 (Scanned on 2021-11-23 14:20:05) |
McAfee-GW-Edition:
BehavesLike.Win64.Dropper.vh
Ikarus: Trojan.Win64.Spy |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 9 |
TimeDateStamp | 2021-Nov-18 11:41:56 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.3 |
SizeOfCode | 0x96e600 |
SizeOfInitializedData | 0x4d1200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000092B368 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 1.3 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xe45000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WTSAPI32.dll |
WTSQuerySessionInformationW
WTSFreeMemory |
---|---|
UxTheme.dll |
IsThemeActive
SetWindowTheme GetThemeBool IsThemeBackgroundPartiallyTransparent GetThemeBackgroundRegion #47 IsAppThemed GetThemeTransitionDuration GetThemePropertyOrigin GetThemeMargins GetThemeEnumValue GetThemeInt GetThemeColor GetThemePartSize OpenThemeData GetCurrentThemeName CloseThemeData |
dwmapi.dll |
DwmIsCompositionEnabled
DwmGetWindowAttribute DwmEnableBlurBehindWindow DwmSetWindowAttribute |
GDI32.dll |
RemoveFontResourceExW
AddFontMemResourceEx GetStockObject GetTextMetricsW GetTextFaceW GetCharABCWidthsW GetCharABCWidthsFloatW GetGlyphOutlineW GetOutlineTextMetricsW GetTextExtentPoint32W GetCharABCWidthsI SetBkMode SetGraphicsMode SetTextColor SetTextAlign SetWorldTransform ExtTextOutW GetDIBits CombineRgn GetFontData EnumFontFamiliesExW CreateFontIndirectW GetObjectW GetBitmapBits CreateCompatibleDC CreateRectRgn DeleteDC DeleteObject GetRegionData RemoveFontMemResourceEx AddFontResourceExW SelectClipRgn SelectObject CreateDIBSection GdiFlush SwapBuffers GetPixelFormat DescribePixelFormat SetPixelFormat ChoosePixelFormat CreateBitmap CreateDCW CreateCompatibleBitmap GetDeviceCaps SetLayout OffsetRgn BitBlt |
OLEAUT32.dll |
SafeArrayPutElement
SysAllocString SafeArrayCreateVector SysFreeString |
IMM32.dll |
ImmSetCandidateWindow
ImmSetCompositionWindow ImmNotifyIME ImmGetOpenStatus ImmAssociateContextEx ImmAssociateContext ImmReleaseContext ImmGetContext ImmGetDefaultIMEWnd ImmGetVirtualKey ImmGetCompositionStringW |
USERENV.dll |
GetUserProfileDirectoryW
|
VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
NETAPI32.dll |
NetApiBufferFree
NetShareEnum |
WS2_32.dll |
select
__WSAFDIsSet ioctlsocket listen htonl accept WSACleanup WSAStartup WSAIoctl WSASetLastError socket setsockopt ntohs htons getsockopt getsockname getpeername connect bind WSAGetLastError send recv closesocket recvfrom sendto gethostname WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent freeaddrinfo getaddrinfo ntohl WSAAsyncSelect |
ADVAPI32.dll |
RegCloseKey
BuildTrusteeWithSidW GetNamedSecurityInfoW GetEffectiveRightsFromAclW LookupAccountSidW MapGenericMask GetLengthSid FreeSid DuplicateToken CopySid AllocateAndInitializeSid AccessCheck OpenProcessToken RegSetValueExW RegQueryInfoKeyW RegFlushKey RegEnumValueW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW GetTokenInformation GetSidSubAuthorityCount GetSidSubAuthority RegQueryValueExW RegOpenKeyExW CryptReleaseContext SystemFunction036 CryptEncrypt CryptImportKey CryptDestroyKey CryptDestroyHash CryptHashData CryptCreateHash CryptGenRandom CryptGetHashParam CryptAcquireContextA |
KERNEL32.dll |
RtlPcToFileHeader
RaiseException EncodePointer DecodePointer LCMapStringEx GetStringTypeW GetCPInfo VirtualFree VirtualAlloc CreateMutexW ReleaseMutex GetUserGeoID GetGeoInfoW GetTimeZoneInformation WriteFileEx CancelIoEx ReadFileEx GetModuleHandleExW FindNextFileW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter InitializeCriticalSectionAndSpinCount IsDebuggerPresent GetSystemTimeAsFileTime InitializeSListHead RtlUnwindEx RtlUnwind LoadLibraryExW SystemTimeToTzSpecificLocalTime ExitThread FreeLibraryAndExitThread GetCommandLineA SetFileAttributesW SetStdHandle GetConsoleMode ReadConsoleW GetConsoleOutputCP HeapAlloc HeapFree HeapReAlloc IsValidLocale EnumSystemLocalesW IsValidCodePage GetACP GetOEMCP SetEnvironmentVariableW GetProcessHeap HeapSize MoveFileExW GetLastError SetLastError FormatMessageW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection SleepEx QueryPerformanceFrequency GetSystemDirectoryA FreeLibrary GetModuleHandleA GetProcAddress LoadLibraryA QueryPerformanceCounter GetTickCount Sleep MultiByteToWideChar WideCharToMultiByte MoveFileExA CloseHandle WaitForSingleObjectEx GetEnvironmentVariableA GetStdHandle GetFileType ReadFile PeekNamedPipe WaitForMultipleObjects VerSetConditionMask VerifyVersionInfoA CreateFileA GetFileSizeEx lstrcmpW GetCurrentThreadId GetModuleHandleW LocalFree WTSGetActiveConsoleSessionId ExpandEnvironmentStringsW CreateProcessW CheckRemoteDebuggerPresent OpenProcess GlobalAlloc GlobalUnlock GlobalLock GetLocaleInfoW LoadLibraryW GlobalSize GetCurrentProcessId GetUserDefaultLangID CreateFileW SetFilePointer WriteFile CreateFileMappingW MapViewOfFile UnmapViewOfFile GetLongPathNameW GetVolumeInformationW GetDriveTypeW GetConsoleWindow ExitProcess InitializeCriticalSection OutputDebugStringW GetCurrentProcess TerminateProcess IsProcessorFeaturePresent CompareStringEx GetCommandLineW GetSystemTime GetLocalTime SetEvent CreateEventW GetSystemDirectoryW DuplicateHandle WaitForSingleObject SwitchToThread CreateThread GetCurrentThread SetThreadPriority GetThreadPriority TerminateThread ResumeThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemInfo ResetEvent GetDateFormatW GetTimeFormatW GetCurrencyFormatW GetUserDefaultLCID GetUserPreferredUILanguages GetFileAttributesExW GetTickCount64 GetStartupInfoW GetModuleFileNameW GetEnvironmentStringsW FreeEnvironmentStringsW ConnectNamedPipe CreateNamedPipeW GetExitCodeProcess UnregisterWaitEx RegisterWaitForSingleObject GetCurrentDirectoryW CreateDirectoryW DeleteFileW FindClose FindFirstFileW GetFileAttributesW GetFileInformationByHandle GetFullPathNameW GetLogicalDrives RemoveDirectoryW SetFileTime GetTempPathW GetVolumePathNamesForVolumeNameW SetErrorMode DeviceIoControl CopyFileW MoveFileW WriteConsoleW TzSpecificLocalTimeToSystemTime FileTimeToSystemTime SystemTimeToFileTime GetFileInformationByHandleEx FlushFileBuffers SetEndOfFile SetFilePointerEx CompareStringW LCMapStringW FindCloseChangeNotification FindFirstChangeNotificationW FindNextChangeNotification FindFirstFileExW |
ole32.dll |
CoGetMalloc
ReleaseStgMedium CoTaskMemFree DoDragDrop CoCreateInstance StringFromGUID2 CoCreateGuid OleGetClipboard OleSetClipboard CoInitialize CoInitializeEx CoUninitialize OleUninitialize OleInitialize RevokeDragDrop RegisterDragDrop CoLockObjectExternal OleFlushClipboard OleIsCurrentClipboard |
SHELL32.dll |
Shell_NotifyIconGetRect
Shell_NotifyIconW SHBrowseForFolderW SHGetKnownFolderIDList SHGetPathFromIDListW CommandLineToArgvW SHCreateItemFromParsingName SHCreateItemFromIDList ShellExecuteW #727 SHGetStockIconInfo SHGetFileInfoW SHGetMalloc SHGetKnownFolderPath |
USER32.dll |
GetWindowTextW
CloseTouchInputHandle GetTouchInputInfo GetAsyncKeyState GetMessageExtraInfo TrackMouseEvent RealGetWindowClassW ChangeWindowMessageFilterEx MessageBoxW DrawIconEx TranslateMessage DispatchMessageW GetQueueStatus MsgWaitForMultipleObjectsEx SetTimer KillTimer SetWindowsHookExW UnhookWindowsHookEx CallNextHookEx PostThreadMessageW CharNextExA RegisterDeviceNotificationW UnregisterDeviceNotification EnumWindows GetSystemMetrics SystemParametersInfoW DefWindowProcW DestroyWindow GetDC ReleaseDC GetSysColor GetDesktopWindow GetDoubleClickTime IsWindow MessageBeep GetCaretBlinkTime UpdateLayeredWindowIndirect SendMessageW PostMessageW AttachThreadInput CreateWindowExW IsChild ShowWindow UpdateLayeredWindow SetLayeredWindowAttributes FlashWindowEx MoveWindow SetWindowPos GetWindowPlacement SetWindowPlacement IsWindowVisible IsIconic SetFocus RegisterTouchWindow UnregisterTouchWindow IsTouchWindow GetCapture SetCapture ReleaseCapture GetMenu GetSystemMenu EnableMenuItem GetForegroundWindow SetForegroundWindow BeginPaint EndPaint GetUpdateRect SetWindowRgn InvalidateRect SetWindowTextW GetClientRect GetWindowRect AdjustWindowRectEx SetCursor ClientToScreen ScreenToClient GetWindowLongW SetWindowLongW GetWindowLongPtrW SetWindowLongPtrW GetParent SetParent GetWindowThreadProcessId GetWindow DestroyCursor DestroyIcon MonitorFromPoint GetAncestor GetKeyboardLayoutList RegisterPowerSettingNotification UnregisterPowerSettingNotification UnregisterClassW GetClassInfoW RegisterClassExW GetFocus GetCursorPos WindowFromPoint ChildWindowFromPointEx GetSysColorBrush LoadImageW SetMenu DrawMenuBar CreateMenu CreatePopupMenu DestroyMenu InsertMenuW AppendMenuW ModifyMenuW RemoveMenu TrackPopupMenu GetMenuItemInfoW SetMenuItemInfoW MonitorFromWindow GetMonitorInfoW EnumDisplayMonitors LoadIconW GetClipboardFormatNameW SetClipboardViewer ChangeClipboardChain RegisterClipboardFormatW GetKeyboardLayout RegisterWindowMessageW IsWindowEnabled CreateCaret DestroyCaret HideCaret ShowCaret SetCaretPos FindWindowA PeekMessageW IsZoomed GetKeyState GetKeyboardState ToAscii ToUnicode MapVirtualKeyW TrackPopupMenuEx RegisterClassW EnumDisplayDevicesW SetCursorPos GetCursor LoadCursorW CreateCursor CreateIconIndirect GetIconInfo GetCursorInfo IsHungAppWindow |
WINMM.dll |
timeSetEvent
timeKillEvent PlaySoundW |
WLDAP32.dll |
#143
#217 #46 #211 #60 #45 #50 #41 #22 #26 #27 #32 #33 #35 #79 #30 #200 #301 |
CRYPT32.dll |
CertEnumCertificatesInStore
CertCloseStore CertOpenStore CertFindCertificateInStore CertFreeCertificateContext CryptStringToBinaryA PFXImportCertStore CryptDecodeObjectEx CertAddCertificateContextToStore CertFreeCertificateChain CertGetCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject CertGetNameStringA CertFindExtension |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.3.0.0 |
ProductVersion | 1.3.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Mario |
FileDescription | League Lobby |
FileVersion (#2) | 1.3.0.0 |
LegalCopyright | Mario |
OriginalFilename | LeagueLobbyPortable.exe |
ProductName | League Lobby |
ProductVersion (#2) | 1.3.0.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Nov-18 11:41:56 |
Version | 0.0 |
SizeofData | 1052 |
AddressOfRawData | 0xcacd30 |
PointerToRawData | 0xcab730 |
StartAddressOfRawData | 0x140cad170 |
---|---|
EndAddressOfRawData | 0x140cad17c |
AddressOfIndex | 0x140d6c668 |
AddressOfCallbacks | 0x140971510 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140d4d9f8 |
XOR Key | 0xd24cee07 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 26 |
C++ objects (27412) | 202 |
253 (28518) | 7 |
C objects (30034) | 19 |
ASM objects (30034) | 12 |
C++ objects (30034) | 88 |
C objects (27412) | 45 |
C objects (CVTCIL) (27412) | 1 |
Imports (27412) | 37 |
Total imports | 576 |
C++ objects (VS2019 Update 8 (16.8.4) compiler 29336) | 736 |
C objects (VS2019 Update 8 (16.8.4) compiler 29336) | 341 |
C++ objects (VS2019 Update 10 (16.10.4) compiler 30040) | 5 |
C++ objects (VS2019 Update 11 (16.11.4-5) compiler 30136) | 3 |
Resource objects (VS2019 Update 11 (16.11.4-5) compiler 30136) | 1 |
151 | 1 |
Linker (VS2019 Update 11 (16.11.4-5) compiler 30136) | 1 |