| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-Jul-23 14:45:32 |
| Detected languages |
English - United States
|
| Debug artifacts |
E:\06. Command & Control\05. ShadowSpecter\ShadowSpecter\x64\Debug\ShadowSpecter.pdb
|
| CompanyName | N/A |
| FileDescription | N/A |
| FileVersion | 1.2.0.3 |
| InternalName | zoom.exe |
| OriginalFilename | zoom.exe |
| ProductName | Zoom |
| ProductVersion | 1.2.0.3 |
| Author | 분쇄기 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Section .textbss is both writable and executable. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Possibly launches other programs:
|
| Suspicious | VirusTotal score: 1/72 (Scanned on 2025-03-28 12:08:32) | Elastic: malicious (high confidence) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2024-Jul-23 14:45:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x6d200 |
| SizeOfInitializedData | 0x31000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000338CE (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd5000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CreatePipe
Sleep CreateProcessW MultiByteToWideChar LoadResource GetLastError SizeofResource FindResourceW ReleaseSRWLockShared AcquireSRWLockExclusive AcquireSRWLockShared TryAcquireSRWLockExclusive SetHandleInformation CloseHandle WriteFile ReadFile GetFileSize CreateFileA WideCharToMultiByte LockResource GetComputerNameA TryAcquireSRWLockShared GetProcAddress FreeLibrary VirtualQuery GetProcessHeap HeapFree LocalFree RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind HeapAlloc UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent RaiseException QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetStartupInfoW GetModuleHandleW ReleaseSRWLockExclusive |
|---|---|
| USER32.dll |
GetDesktopWindow
GetWindowRect |
| ADVAPI32.dll |
SetServiceStatus
RegisterServiceCtrlHandlerW OpenServiceW OpenSCManagerW CreateServiceW CloseServiceHandle GetUserNameA StartServiceCtrlDispatcherW |
| ole32.dll |
CoSetProxyBlanket
CoInitializeSecurity CoUninitialize CoCreateInstance CoInitializeEx |
| OLEAUT32.dll |
SysStringLen
SysFreeString VariantClear GetErrorInfo VariantInit VariantChangeType SetErrorInfo CreateErrorInfo SysAllocString |
| MSVCP140D.dll |
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A ?uncaught_exception@std@@YA_NXZ ?_Xout_of_range@std@@YAXPEBD@Z ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Xbad_function_call@std@@YAXXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xinvalid_argument@std@@YAXPEBD@Z _Query_perf_counter _Query_perf_frequency ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ ?_Xbad_alloc@std@@YAXXZ ??Bid@locale@std@@QEAA_KXZ ??3_Crt_new_delete@std@@SAXPEAX@Z ??2_Crt_new_delete@std@@SAPEAX_K@Z ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z ?_W_Getmonths@_Locinfo@std@@QEBAPEBGXZ ?_W_Getdays@_Locinfo@std@@QEBAPEBGXZ ?_Getmonths@_Locinfo@std@@QEBAPEBDXZ ?_Getdays@_Locinfo@std@@QEBAPEBDXZ ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ _Mbrtowc ?_Xlength_error@std@@YAXPEBD@Z ?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z |
| NETAPI32.dll |
NetApiBufferFree
NetGetJoinInformation |
| WINHTTP.dll |
WinHttpConnect
WinHttpReceiveResponse WinHttpSendRequest WinHttpOpenRequest WinHttpOpen WinHttpCloseHandle WinHttpReadData WinHttpQueryDataAvailable |
| VCRUNTIME140D.dll |
__vcrt_LoadLibraryExW
memcmp memcpy memmove __std_exception_copy __std_exception_destroy _CxxThrowException memchr __current_exception __current_exception_context __C_specific_handler __C_specific_handler_noexcept __std_type_info_destroy_list __vcrt_GetModuleFileNameW __vcrt_GetModuleHandleW memset |
| VCRUNTIME140_1D.dll |
__CxxFrameHandler4
|
| ucrtbased.dll |
_register_thread_local_exe_atexit_callback
_configthreadlocale _set_new_mode __p__commode _seh_filter_dll _initialize_onexit_table _register_onexit_function free _crt_atexit _crt_at_quick_exit _free_dbg strcpy_s strcat_s __stdio_common_vsprintf_s _wmakepath_s _wsplitpath_s _cexit _execute_onexit_table strtol exit _wassert localeconv strtoull strtoll strtod _dtest terminate _errno __stdio_common_vsprintf remove strlen wcslen _CrtDbgReport __p___argv __p___argc _set_fmode _exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv _calloc_dbg _c_exit __setusermatherr _set_app_type _seh_filter_exe _callnewh _CrtDbgReportW _invalid_parameter wcscpy_s malloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.2.0.3 |
| ProductVersion | 1.2.0.3 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | N/A |
| FileDescription | N/A |
| FileVersion (#2) | 1.2.0.3 |
| InternalName | zoom.exe |
| OriginalFilename | zoom.exe |
| ProductName | Zoom |
| ProductVersion (#2) | 1.2.0.3 |
| Author | 분쇄기 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jul-23 14:45:32 |
| Version | 0.0 |
| SizeofData | 109 |
| AddressOfRawData | 0xb3584 |
| PointerToRawData | 0x80b84 |
| Referenced File | E:\06. Command & Control\05. ShadowSpecter\ShadowSpecter\x64\Debug\ShadowSpecter.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jul-23 14:45:32 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xb35f4 |
| PointerToRawData | 0x80bf4 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400c3040 |
| XOR Key | 0xf61c169f |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33731) | 4 |
| C objects (33731) | 10 |
| C objects (30795) | 1 |
| C++ objects (33731) | 41 |
| Imports (33731) | 6 |
| Imports (30795) | 17 |
| Total imports | 197 |
| C++ objects (33812) | 3 |
| Resource objects (33812) | 1 |
| 151 | 1 |
| Linker (33812) | 1 |
No comments yet.