| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2023-Mar-16 07:56:45 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\MyWork\Git\WebDispatcher11_2_SFR\WebDispatcherV2\plugin\source\DispatcherPluginProj\firebreath\NativeMessageHost\RelWithDebInfo\FireWyrmNativeMessageHost.pdb
|
| CompanyName | Kodiak Networks Motorola Solutions |
| FileDescription | WebDispatcher Plugin |
| FileVersion | 1.0.0.0 |
| InternalName | FireWyrm.exe |
| LegalCopyright | Copyright (C) 2023 Kodiak Networks Motorola Solutions |
| OriginalFilename | FireWyrm.exe |
| ProductName | WebDispatcher |
| ProductVersion | 1.0.0.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: KODIAK NETWORKS INDIA PRIVATE LIMITED
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/75 (Scanned on 2024-08-01 15:20:50) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2023-Mar-16 07:56:45 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0xe4000 |
| SizeOfInitializedData | 0x5da00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000055000 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x146000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x143dab |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetLastError
GetProcAddress DecodePointer DeleteCriticalSection RaiseException WaitForMultipleObjectsEx WriteConsoleW GetTimeZoneInformation UnregisterWaitEx InitializeCriticalSectionAndSpinCount LoadLibraryW FreeLibrary SetStdHandle GetFullPathNameW FindFirstFileW SetEndOfFile MoveFileExW SetFilePointerEx CreateDirectoryW GetModuleHandleW SetFileTime CreateDirectoryExW CopyFileW GetFileAttributesW CreateFileW GetTempPathW GetCurrentDirectoryW SetLastError FindClose SetCurrentDirectoryW RemoveDirectoryW DeviceIoControl FindNextFileW GetFileTime GetFileAttributesExW GetDiskFreeSpaceExW CloseHandle DeleteFileW GetFileInformationByHandle SetFileAttributesW WideCharToMultiByte MultiByteToWideChar AreFileApisANSI FormatMessageA LocalFree DuplicateHandle WaitForSingleObject GetCurrentProcess GetCurrentThread GetCurrentThreadId GetExitCodeThread GetSystemTimeAsFileTime EncodePointer EnterCriticalSection LeaveCriticalSection GetStringTypeW HeapFree HeapAlloc GetCPInfo GetCommandLineA IsProcessorFeaturePresent IsDebuggerPresent RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter CreateEventW Sleep TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetStartupInfoW GetTickCount CreateSemaphoreW CreateThread ExitThread LoadLibraryExW RtlPcToFileHeader RtlUnwindEx CreateTimerQueue TryEnterCriticalSection RtlCaptureStackBackTrace SetEvent WaitForSingleObjectEx SignalObjectAndWait SwitchToThread SetThreadPriority GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait FatalAppExitA GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ExitProcess GetModuleHandleExW HeapSize GetFileType GetStdHandle FlushFileBuffers WriteFile GetConsoleCP GetConsoleMode GetProcessHeap ReadFile ReadConsoleW GetModuleFileNameW GetModuleFileNameA QueryPerformanceCounter GetCurrentProcessId GetEnvironmentStringsW FreeEnvironmentStringsW IsValidCodePage GetACP GetOEMCP SetConsoleCtrlHandler HeapReAlloc OutputDebugStringW GetThreadTimes FreeLibraryAndExitThread GetModuleHandleA GetVersionExW VirtualAlloc VirtualFree VirtualProtect SetProcessAffinityMask ReleaseSemaphore InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList SetEnvironmentVariableA |
|---|---|
| USER32.dll |
UnregisterClassW
|
| OLEAUT32.dll |
SysFreeString
|
| ADVAPI32.dll |
RegEnumKeyExW
RegOpenKeyExW RegQueryValueExW RegCloseKey |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Kodiak Networks Motorola Solutions |
| FileDescription | WebDispatcher Plugin |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | FireWyrm.exe |
| LegalCopyright | Copyright (C) 2023 Kodiak Networks Motorola Solutions |
| OriginalFilename | FireWyrm.exe |
| ProductName | WebDispatcher |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Mar-16 07:56:45 |
| Version | 0.0 |
| SizeofData | 185 |
| AddressOfRawData | 0xfce40 |
| PointerToRawData | 0xfc240 |
| Referenced File | C:\MyWork\Git\WebDispatcher11_2_SFR\WebDispatcherV2\plugin\source\DispatcherPluginProj\firebreath\NativeMessageHost\RelWithDebInfo\FireWyrmNativeMessageHost.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Mar-16 07:56:45 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xfcefc |
| PointerToRawData | 0xfc2fc |
| Size | 0x70 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140126640 |
| XOR Key | 0x10495348 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (20806) | 14 |
| C++ objects (20806) | 134 |
| C objects (20806) | 211 |
| Imports (65501) | 9 |
| Total imports | 154 |
| 229 (VS2013 build 21005) | 14 |
| Resource objects (VS2013 build 21005) | 1 |
| 151 | 1 |
| Linker (VS2013 build 21005) | 1 |
No comments yet.