Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-Nov-17 20:28:44 |
Detected languages |
English - United States
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/68 (Scanned on 2019-07-23 19:43:57) | Trapmine: suspicious.low.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2017-Nov-17 20:28:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 11.0 |
SizeOfCode | 0xb600 |
SizeOfInitializedData | 0x8000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000002540 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x18000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ExpandEnvironmentStringsA
CloseHandle GetLastError ResumeThread CreateProcessA GetThreadContext SetThreadContext VirtualAllocEx WriteProcessMemory Wow64GetThreadContext Wow64SetThreadContext VirtualFree CreateFileA GetFileSize VirtualAlloc MapViewOfFile UnmapViewOfFile CreateFileMappingA GetCommandLineA IsDebuggerPresent EncodePointer DecodePointer IsProcessorFeaturePresent EnterCriticalSection LeaveCriticalSection RtlUnwindEx HeapFree SetLastError GetCurrentThreadId ExitProcess GetModuleHandleExW GetProcAddress AreFileApisANSI MultiByteToWideChar GetStdHandle WriteFile GetModuleFileNameW GetProcessHeap GetFileType InitializeCriticalSectionAndSpinCount DeleteCriticalSection InitOnceExecuteOnce GetStartupInfoW GetModuleFileNameA QueryPerformanceCounter GetSystemTimeAsFileTime GetTickCount64 GetEnvironmentStringsW FreeEnvironmentStringsW WideCharToMultiByte RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter FlsAlloc FlsGetValue FlsSetValue FlsFree GetCurrentProcess TerminateProcess GetModuleHandleW Sleep IsValidCodePage GetACP GetOEMCP GetCPInfo WaitForSingleObject GetExitCodeProcess GetFileAttributesExW LoadLibraryExW OutputDebugStringW LoadLibraryW FlushFileBuffers GetConsoleCP GetConsoleMode HeapAlloc HeapReAlloc GetStringTypeW SetFilePointerEx SetEnvironmentVariableA HeapSize CompareStringEx LCMapStringEx SetStdHandle WriteConsoleW CreateFileW |
---|
Size | 0x70 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140011000 |
XOR Key | 0x307751a5 |
---|---|
Unmarked objects | 0 |
C++ objects (50628) | 33 |
C objects (50628) | 104 |
ASM objects (50628) | 7 |
Total imports | 98 |
185 (30716) | 3 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 7 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |