Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Oct-25 10:05:07 |
Detected languages |
English - United States
|
Debug artifacts |
d:\build\ob\bora-14943755\bora-vmsoft\build\release-x64\svga\wddm\src\service\Win8Release\x64\bin\vm3dservice.pdb
|
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: VMware
Issuer: VeriSign Class 3 Code Signing 2010 CA |
Safe | VirusTotal score: 0/67 (Scanned on 2021-09-07 12:45:24) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2019-Oct-25 10:05:07 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x65a00 |
SizeOfInitializedData | 0x1d200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000004600 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x88000 |
SizeOfHeaders | 0x400 |
Checksum | 0x9710b |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetProcAddress
GetModuleHandleW FreeLibrary RtlUnwind RtlCaptureStackBackTrace SetEndOfFile WriteConsoleW GetTickCount64 VerifyVersionInfoW ReadConsoleW ReadFile SetFilePointerEx GetFileSizeEx SetConsoleCtrlHandler GetProcessHeap GetStringTypeW SetStdHandle SetEnvironmentVariableW HeapSize LoadLibraryW ProcessIdToSessionId GetCurrentProcessId HeapReAlloc VerSetConditionMask FreeEnvironmentStringsW GetEnvironmentStringsW FindClose FindFirstFileA FindNextFileA GetCurrentThreadId GetLocalTime GetLastError FatalExit RtlCaptureContext CreateDirectoryW CreateFileW DeleteFileW GetTempPathW CloseHandle RaiseException GetCurrentProcess MoveFileW RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW EncodePointer RtlPcToFileHeader GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetFileType HeapFree FlushFileBuffers GetConsoleCP GetConsoleMode HeapAlloc MultiByteToWideChar GetCurrentThread GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW WideCharToMultiByte OutputDebugStringW FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW |
---|---|
USER32.dll |
RegisterWindowMessageW
GetMessageW EnumDisplayDevicesW LoadCursorW SetRect AdjustWindowRectEx GetClientRect UpdateWindow ShowWindow CreateWindowExW RegisterClassExW UnregisterClassW PostQuitMessage DefWindowProcW GetSystemMetrics EnumDisplaySettingsW GetMonitorInfoW EnumDisplayMonitors TranslateMessage DispatchMessageW |
GDI32.dll |
CreateDCW
|
ADVAPI32.dll |
SetServiceStatus
RegisterServiceCtrlHandlerW RegQueryValueExA RegCloseKey RegOpenKeyExA StartServiceCtrlDispatcherW |
dwmapi.dll |
DwmIsCompositionEnabled
|
dbghelp.dll |
SymFromAddr
SymSetSearchPath MiniDumpWriteDump SymGetSearchPath StackWalk64 SymSetOptions SymCleanup SymFunctionTableAccess64 SymGetModuleBase64 SymGetLineFromAddr64 SymInitialize |
WINMM.dll |
timeGetTime
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Oct-25 10:05:07 |
Version | 0.0 |
SizeofData | 138 |
AddressOfRawData | 0x7360c |
PointerToRawData | 0x7240c |
Referenced File | d:\build\ob\bora-14943755\bora-vmsoft\build\release-x64\svga\wddm\src\service\Win8Release\x64\bin\vm3dservice.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Oct-25 10:05:07 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x73698 |
PointerToRawData | 0x72498 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Oct-25 10:05:07 |
Version | 0.0 |
SizeofData | 784 |
AddressOfRawData | 0x736ac |
PointerToRawData | 0x724ac |
Size | 0x108 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14007c018 |
GuardCFCheckFunctionPointer | 5369132176 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x915dafce |
---|---|
Unmarked objects | 0 |
C objects (26715) | 10 |
ASM objects (26715) | 5 |
C++ objects (26715) | 159 |
ASM objects (27316) | 8 |
C objects (27316) | 16 |
C++ objects (27316) | 37 |
C++ objects (VS2015 UPD1 build 23506) | 1 |
ASM objects (VS2017 v15.9.7-10 compiler 27027) | 1 |
Imports (26213) | 15 |
Total imports | 139 |
C objects (VS2017 v15.9.7-10 compiler 27027) | 8 |
Resource objects (VS2017 v15.9.7-10 compiler 27027) | 1 |
Linker (VS2017 v15.9.7-10 compiler 27027) | 1 |