| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Jan-24 08:13:24 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
D:\git-SDK\windows\out_unicode\x64\Release\NtUniSdkAppsFlyer.pdb
|
| CompanyName | |
| FileDescription | |
| FileVersion | 1.0.0.0 |
| InternalName | NtUniSdkAppsFlyer.dll |
| LegalCopyright | |
| OriginalFilename | NtUniSdkAppsFlyer.dll |
| ProductName | |
| ProductVersion | 1.0.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: NetEase (Hangzhou) Network Co.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/74 (Scanned on 2024-07-23 07:28:02) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x140 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2024-Jan-24 08:13:24 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1e4400 |
| SizeOfInitializedData | 0xf1200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000018D774 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2de000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2e4e0d |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegOpenKeyExW
RegQueryValueExW RegCloseKey RegSetValueExW CryptGenRandom CryptEnumProvidersW CryptSignHashW CryptDestroyHash CryptCreateHash CryptDecrypt CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptDestroyKey CryptReleaseContext CryptAcquireContextW ReportEventW RegisterEventSourceW DeregisterEventSource |
|---|---|
| WS2_32.dll |
ioctlsocket
gethostname getnameinfo shutdown htonl ntohl recvfrom listen accept freeaddrinfo getaddrinfo WSAIoctl setsockopt ntohs htons getsockopt getsockname getpeername connect closesocket bind send recv WSASetLastError select __WSAFDIsSet socket WSAGetLastError WSACleanup WSAStartup WSASetEvent sendto |
| USER32.dll |
CreateWindowExW
RegisterClassExW UnregisterClassW PostQuitMessage DefWindowProcW WaitMessage PostMessageW PeekMessageW DispatchMessageW DestroyWindow GetWindowThreadProcessId GetWindow IsWindowVisible CallMsgFilterW GetQueueStatus MsgWaitForMultipleObjectsEx SetTimer GetProcessWindowStation GetUserObjectInformationW MessageBoxW TranslateMessage KillTimer |
| WLDAP32.dll |
#200
#143 #46 #211 #60 #45 #50 #41 #22 #26 #301 #27 #30 #79 #35 #33 #32 |
| CRYPT32.dll |
CertCloseStore
CertEnumCertificatesInStore CertGetCertificateContextProperty CertFreeCertificateContext CertDuplicateCertificateContext CertFindCertificateInStore CertOpenStore |
| KERNEL32.dll |
GetConsoleCP
WriteConsoleW GetModuleFileNameA SetFilePointerEx ExitThread SetConsoleCtrlHandler ExitProcess SystemTimeToTzSpecificLocalTime GetDriveTypeW RtlUnwindEx RtlPcToFileHeader CreateTimerQueue UnregisterWaitEx QueryDepthSList InterlockedFlushSList InterlockedPushEntrySList InterlockedPopEntrySList ReleaseSemaphore DuplicateHandle VirtualProtect VirtualFree VirtualAlloc LoadLibraryExW FreeLibraryAndExitThread GetThreadTimes GetACP FlushFileBuffers GetFileAttributesExW HeapSize SetEndOfFile FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCommandLineA HeapReAlloc IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetEnvironmentStringsW SetStdHandle FreeEnvironmentStringsW GetLastError SetLastError FormatMessageA GetTickCount InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection FreeLibrary GetProcAddress Sleep SleepEx GetStdHandle GetFileType WriteFile GetModuleHandleW MultiByteToWideChar CloseHandle WaitForSingleObject VerSetConditionMask GetSystemDirectoryA GetModuleHandleA LoadLibraryA VerifyVersionInfoA ExpandEnvironmentStringsA ReadFile PeekNamedPipe WaitForMultipleObjects GetEnvironmentVariableW WideCharToMultiByte InitializeCriticalSectionAndSpinCount GetCurrentThreadId TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleExW FormatMessageW GetSystemTime SystemTimeToFileTime FindClose FindFirstFileW FindNextFileW GetSystemTimeAsFileTime QueryPerformanceCounter GetCurrentProcessId GlobalMemoryStatus LoadLibraryW GetConsoleMode SetConsoleMode ReadConsoleA ReadConsoleW GetCurrentThread UnregisterWait GetFullPathNameW RegisterWaitForSingleObject SetThreadAffinityMask GetProcessAffinityMask GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation GetThreadPriority SwitchToThread SignalObjectAndWait WaitForSingleObjectEx OutputDebugStringW InitializeSListHead GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry SetEnvironmentVariableA GetModuleFileNameW RtlCaptureContext GetCPInfo GetStringTypeW GetLocaleInfoW LCMapStringW CompareStringW EncodePointer CreateThread RaiseException DecodePointer CreateEventW SetEvent TerminateThread SetThreadPriority PostQueuedCompletionStatus GetTimeZoneInformation HeapFree GetCommandLineW CreateFileW HeapAlloc GetProcessHeap GetCurrentProcess CreateMutexW GetVersionExW GetCurrentDirectoryW TryEnterCriticalSection FileTimeToLocalFileTime FileTimeToSystemTime CreateIoCompletionPort GetQueuedCompletionStatus |
| ole32.dll |
CoCreateGuid
|
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| WINMM.dll |
timeGetTime
|
| Ordinal | 1 |
|---|---|
| Address | 0x16170 |
| Ordinal | 2 |
|---|---|
| Address | 0x162e0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | Chinese - PRC |
| CompanyName | |
| FileDescription | |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | NtUniSdkAppsFlyer.dll |
| LegalCopyright | |
| OriginalFilename | NtUniSdkAppsFlyer.dll |
| ProductName | |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jan-24 08:13:24 |
| Version | 0.0 |
| SizeofData | 89 |
| AddressOfRawData | 0x27c254 |
| PointerToRawData | 0x27aa54 |
| Referenced File | D:\git-SDK\windows\out_unicode\x64\Release\NtUniSdkAppsFlyer.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jan-24 08:13:24 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x27c2b0 |
| PointerToRawData | 0x27aab0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jan-24 08:13:24 |
| Version | 0.0 |
| SizeofData | 852 |
| AddressOfRawData | 0x27c2c4 |
| PointerToRawData | 0x27aac4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jan-24 08:13:24 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x94 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1802afc58 |
| XOR Key | 0x6a036040 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 15 |
| 243 (40116) | 194 |
| 242 (40116) | 29 |
| C++ objects (23013) | 2 |
| 199 (41118) | 8 |
| ASM objects (VS2015 UPD3 build 24123) | 8 |
| C++ objects (VS2015 UPD3 build 24123) | 107 |
| C objects (VS2015 UPD3 build 24123) | 38 |
| C++ objects (VS2015 UPD3.1 build 24215) | 29 |
| Imports (VS2008 SP1 build 30729) | 14 |
| C objects (VS2015 UPD3.1 build 24215) | 531 |
| Total imports | 307 |
| Imports (27412) | 11 |
| C objects (VS2015 build 23026) | 119 |
| C++ objects (LTCG) (VS2015 UPD3.1 build 24215) | 12 |
| Exports (VS2015 UPD3.1 build 24215) | 1 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| 151 | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |