Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2024-Dec-13 21:46:56 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\rythe\OneDrive\Desktop\cm_internal\output\Release\ambition_Release.pdb
|
CompanyName | Tsuda Kageyu |
FileDescription | MinHook - The Minimalistic API Hook Library for x64/x86 |
FileVersion | 1.3.3.0 |
InternalName | MinHookD |
LegalCopyright | Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved. |
LegalTrademarks | Tsuda Kageyu |
ProductName | MinHook DLL |
ProductVersion | 1.3.3.0 |
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/71 (Scanned on 2025-01-10 10:26:52) | Cynet: Malicious (score: 100) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2024-Dec-13 21:46:56 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xcea00 |
SizeOfInitializedData | 0x49e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000CD88C (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x11b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FreeLibrary
QueryPerformanceCounter VirtualFree VirtualAlloc GetSystemInfo VirtualQuery HeapCreate VirtualProtect HeapFree GetCurrentProcess Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot Sleep HeapReAlloc CloseHandle HeapAlloc HeapDestroy GetThreadContext GetCurrentProcessId GlobalUnlock QueryPerformanceFrequency SetThreadContext OpenThread FreeLibraryAndExitThread DisableThreadLibraryCalls FreeConsole CreateThread Beep AllocConsole WideCharToMultiByte InitializeSListHead GetSystemTimeAsFileTime IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive GlobalLock GlobalFree GetProcAddress LoadLibraryA GetLocaleInfoA FlushInstructionCache GetModuleHandleA GlobalAlloc MultiByteToWideChar |
---|---|
USER32.dll |
CallWindowProcA
SetWindowLongPtrA GetAsyncKeyState DestroyWindow CreateWindowExA UnregisterClassA RegisterClassExA GetKeyState GetMessageExtraInfo LoadCursorA DefWindowProcA ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout SetClipboardData GetClipboardData EmptyClipboard CloseClipboard GetForegroundWindow GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos OpenClipboard SetCursor SetCapture |
SHELL32.dll |
ShellExecuteA
|
MSVCP140.dll |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?good@ios_base@std@@QEBA_NXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z |
IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
D3DCOMPILER_43.dll |
D3DCompile
|
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
memchr
memcmp __C_specific_handler __current_exception __current_exception_context __intrinsic_setjmp _CxxThrowException __std_type_info_destroy_list memmove memcpy longjmp strrchr strchr strstr __std_terminate __std_exception_copy memset __std_exception_destroy |
api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsprintf
__stdio_common_vfprintf fseek fclose fflush __acrt_iob_func ftell fread __stdio_common_vsscanf fopen fwrite _wfopen freopen_s |
api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
api-ms-win-crt-string-l1-1-0.dll |
strcmp
strncpy strncmp |
api-ms-win-crt-heap-l1-1-0.dll |
free
calloc _callnewh malloc |
api-ms-win-crt-runtime-l1-1-0.dll |
terminate
_initterm _initterm_e _cexit _execute_onexit_table _register_onexit_function _initialize_onexit_table _crt_atexit _invalid_parameter_noinfo_noreturn _seh_filter_dll _configure_narrow_argv _initialize_narrow_environment |
api-ms-win-crt-math-l1-1-0.dll |
fmaxf
asinf sinf roundf atan2f fminf ceilf cosf fmodf sqrtf powf acosf |
api-ms-win-crt-convert-l1-1-0.dll |
strtol
atof |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.3.3.0 |
ProductVersion | 1.3.3.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Tsuda Kageyu |
FileDescription | MinHook - The Minimalistic API Hook Library for x64/x86 |
FileVersion (#2) | 1.3.3.0 |
InternalName | MinHookD |
LegalCopyright | Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved. |
LegalTrademarks | Tsuda Kageyu |
ProductName | MinHook DLL |
ProductVersion (#2) | 1.3.3.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Dec-13 21:46:56 |
Version | 0.0 |
SizeofData | 104 |
AddressOfRawData | 0xf59f8 |
PointerToRawData | 0xf47f8 |
Referenced File | C:\Users\rythe\OneDrive\Desktop\cm_internal\output\Release\ambition_Release.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Dec-13 21:46:56 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xf5a60 |
PointerToRawData | 0xf4860 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Dec-13 21:46:56 |
Version | 0.0 |
SizeofData | 832 |
AddressOfRawData | 0xf5a74 |
PointerToRawData | 0xf4874 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Dec-13 21:46:56 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x1800f5dd8 |
---|---|
EndAddressOfRawData | 0x1800f5de0 |
AddressOfIndex | 0x18010e974 |
AddressOfCallbacks | 0x1800d0660 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x180106040 |
XOR Key | 0x506f3d0 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 16 |
Imports (21202) | 2 |
253 (33731) | 1 |
ASM objects (33731) | 4 |
C objects (33731) | 8 |
C++ objects (33731) | 22 |
Imports (33731) | 6 |
C objects (VS2022 Update 7 (17.7.4) compiler 32825) | 24 |
Imports (33136) | 13 |
Total imports | 208 |
C++ objects (LTCG) (33811) | 26 |
Resource objects (33811) | 1 |
151 | 1 |
Linker (33811) | 1 |