| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Oct-03 14:34:12 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA256 Uses constants related to AES |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Oct-03 14:34:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xcd200 |
| SizeOfInitializedData | 0x3d600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000008E228 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x111000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
EnterCriticalSection
WaitForMultipleObjects LeaveCriticalSection WaitForSingleObject PostQueuedCompletionStatus GetLastError SetEvent TerminateThread TlsAlloc CloseHandle QueueUserAPC LocalFree DeleteCriticalSection TlsFree FormatMessageA ReadFile GetFileSizeEx SetWaitableTimer TlsSetValue SetLastError WriteFile InitializeCriticalSectionAndSpinCount GetQueuedCompletionStatus GetCurrentThreadId CreateEventW SetFileInformationByHandle DeleteFileW CancelIoEx SleepEx TlsGetValue CreateIoCompletionPort CreateFileW GetFileAttributesW SetFileAttributesW GetDriveTypeW GetConsoleScreenBufferInfo SetConsoleTextAttribute GetCommandLineW GetStdHandle WriteConsoleA GetDynamicTimeZoneInformation Sleep GetConsoleMode GetFileAttributesA GetSystemInfo GetCurrentProcessId GetCurrentProcess GetProcessId OpenProcess ResetEvent GetLogicalDriveStringsW MultiByteToWideChar WideCharToMultiByte SetEndOfFile WriteConsoleW SetStdHandle GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP IsValidCodePage GetTimeZoneInformation ReadConsoleW GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileType EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW HeapFree HeapSize HeapReAlloc GetLocaleInfoEx RtlPcToFileHeader RaiseException CreateDirectoryW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW AreFileApisANSI GetModuleHandleW GetProcAddress GetFileInformationByHandleEx QueryPerformanceCounter QueryPerformanceFrequency ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableSRW GetStringTypeW WaitForSingleObjectEx GetExitCodeThread InitializeCriticalSectionEx GetSystemTimeAsFileTime EncodePointer DecodePointer LCMapStringEx CompareStringEx GetCPInfo RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead RtlUnwindEx FreeLibrary LoadLibraryExW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetModuleFileNameW HeapAlloc RtlUnwind |
|---|---|
| SHELL32.dll |
CommandLineToArgvW
ShellExecuteW |
| ole32.dll |
CoCreateInstance
CoUninitialize CoInitializeEx CoSetProxyBlanket |
| OLEAUT32.dll |
VariantClear
SysAllocString SysFreeString VariantInit |
| WS2_32.dll |
WSAStartup
WSACleanup |
| SHLWAPI.dll |
PathIsNetworkPathW
|
| MPR.dll |
WNetGetConnectionW
|
| WTSAPI32.dll |
WTSEnumerateProcessesW
WTSFreeMemory |
| RstrtMgr.DLL |
RmShutdown
RmStartSession RmEndSession RmRegisterResources RmGetList |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-03 14:34:12 |
| Version | 0.0 |
| SizeofData | 1008 |
| AddressOfRawData | 0xea014 |
| PointerToRawData | 0xe8614 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Oct-03 14:34:12 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400ea428 |
|---|---|
| EndAddressOfRawData | 0x1400ea444 |
| AddressOfIndex | 0x1401020b0 |
| AddressOfCallbacks | 0x1400cf780 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400fa368 |
| XOR Key | 0xf6913746 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (27412) | 6 |
| C objects (27412) | 19 |
| C++ objects (27412) | 181 |
| C objects (CVTCIL) (27412) | 1 |
| C objects (VS 2015-2022 runtime 32533) | 16 |
| ASM objects (VS 2015-2022 runtime 32533) | 10 |
| C++ objects (VS2022 Update 7 (17.7.0-3) compiler 32822) | 3 |
| C objects (VS2022 Update 7 (17.7.0-3) compiler 32822) | 23 |
| C++ objects (VS 2015-2022 runtime 32533) | 100 |
| Imports (27412) | 19 |
| Total imports | 206 |
| C++ objects (LTCG) (VS2022 Update 7 (17.7.0-3) compiler 32822) | 9 |
| Resource objects (VS2022 Update 7 (17.7.0-3) compiler 32822) | 1 |
| Linker (VS2022 Update 7 (17.7.0-3) compiler 32822) | 1 |
No comments yet.