Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-May-13 23:13:13 |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to AES Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Section .bss is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2018-May-13 23:13:13 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x29a00 |
SizeOfInitializedData | 0x3e600 |
SizeOfUninitializedData | 0x6a00 |
AddressOfEntryPoint | 0x0000000000010BC0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x74000 |
SizeOfHeaders | 0x400 |
Checksum | 0x6aa2f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetCurrentProcess
GetCurrentProcessId GetCurrentThreadId InitializeCriticalSection EnterCriticalSection LeaveCriticalSection GetFileSize GetStdHandle WriteFile ReadFile SetFilePointer FindClose CloseHandle GetSystemTimeAsFileTime FileTimeToLocalFileTime GetTickCount lstrcmpiA lstrcpynA lstrcpyA lstrcpyW lstrcatA lstrcatW lstrlenA lstrlenW LoadLibraryA GetModuleHandleA CreateDirectoryA CreateFileA DeleteFileW FindFirstFileW FindNextFileW MultiByteToWideChar WideCharToMultiByte SetConsoleTextAttribute WriteConsoleA FlushInstructionCache VirtualAlloc VirtualFree CreateThread GetLastError SetLastError Sleep CreateEventA GetModuleFileNameA GetModuleHandleW GetModuleHandleExA GetSystemDirectoryA AllocConsole GetProcessHeap HeapFree HeapReAlloc HeapAlloc VirtualProtectEx VirtualQuery CreateFileW VirtualProtect GetProcAddress |
---|---|
USER32.dll |
wsprintfW
wsprintfA wvsprintfA |
ADVAPI32.dll |
CryptGenKey
CryptExportKey CryptDecrypt CryptCreateHash CryptHashData CryptDestroyHash CryptSignHashA CryptDestroyKey |
SHELL32.dll |
SHGetSpecialFolderPathW
|
WS2_32.dll |
#51
#115 #1 #2 #3 #9 #12 #13 #15 #16 #19 #21 #23 |
Ordinal | 1 |
---|---|
Address | 0x299c0 |
Ordinal | 2 |
---|---|
Address | 0x29aa0 |
Ordinal | 3 |
---|---|
Address | 0x29b80 |
Ordinal | 4 |
---|---|
Address | 0x29c60 |
Ordinal | 5 |
---|---|
Address | 0x29d40 |
Ordinal | 6 |
---|---|
Address | 0x29e20 |
Ordinal | 7 |
---|---|
Address | 0x29f00 |
Ordinal | 8 |
---|---|
Address | 0x29fe0 |
Ordinal | 9 |
---|---|
Address | 0x2a0c0 |
Ordinal | 10 |
---|---|
Address | 0x2a1a0 |
Ordinal | 11 |
---|---|
Address | 0x2a280 |
Ordinal | 12 |
---|---|
Address | 0x2a360 |
Ordinal | 13 |
---|---|
Address | 0x2a440 |
Ordinal | 14 |
---|---|
Address | 0x2a520 |
Ordinal | 15 |
---|---|
Address | 0x2a600 |
Ordinal | 16 |
---|---|
Address | 0x2a6e0 |
Ordinal | 17 |
---|---|
Address | 0x2a7c0 |
XOR Key | 0xa40edfa7 |
---|---|
Unmarked objects | 0 |
Imports (40310) | 2 |
Imports (VS2008 SP1 build 30729) | 15 |
Total imports | 127 |
C objects (VS2017 v15.0 compiler 25017) | 14 |
C++ objects (VS2017 v15.0 compiler 25017) | 6 |
Exports (VS2017 v15.0 compiler 25017) | 1 |
Linker (VS2017 v15.0 compiler 25017) | 1 |