| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-Jul-29 09:12:22 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
d:\Webhost\29-07-2024\WindowsBuilds\OSD_NATIVE\8799050\osdeployer\ONPREMISE\OSD_SRC\agent\x64\Release\ImageCreator.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: text
Unusual section name found: data |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ZOHO Corporation Private Limited
Issuer: GlobalSign GCC R45 CodeSigning CA 2020 |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2024-Jul-29 09:12:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x78a400 |
| SizeOfInitializedData | 0x358400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000530860 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xae9000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xae9dde |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| CRYPT32.dll |
CryptMsgGetParam
CryptQueryObject CertEnumCertificatesInStore CertGetCertificateContextProperty CertDuplicateCertificateContext PFXImportCertStore PFXVerifyPassword CertGetNameStringA CryptStringToBinaryA CertCreateCertificateContext CertDeleteCertificateFromStore CertFindCertificateInStore CertFreeCertificateContext CertCloseStore CertAddCertificateContextToStore CertGetNameStringW CertOpenStore |
|---|---|
| WS2_32.dll |
WSAStartup
WSAGetLastError WSACleanup __WSAFDIsSet select getsockopt gethostbyname WSAPoll recvfrom shutdown sendto getpeername gethostname ntohl getprotobyname inet_addr WSASocketA htonl recv WSASetLastError send connect setsockopt bind listen accept socket WSAIoctl closesocket getaddrinfo htons freeaddrinfo getnameinfo ioctlsocket ntohs getsockname |
| IPHLPAPI.DLL |
ConvertLengthToIpv4Mask
GetAdapterIndex GetAdaptersInfo GetAdaptersAddresses |
| NETAPI32.dll |
DsRoleGetPrimaryDomainInformation
NetLocalGroupGetMembers NetApiBufferFree NetLocalGroupEnum NetGetJoinInformation DsGetDcNameW DsRoleFreeMemory |
| NTDSAPI.dll |
DsFreeDomainControllerInfoW
DsBindW DsGetDomainControllerInfoW DsUnBindW |
| KERNEL32.dll |
GetNativeSystemInfo
GetFileAttributesW DeleteFileW GetVersion CreateProcessW GetExitCodeProcess LoadLibraryW GetProcAddress GetModuleHandleW TerminateProcess GetDiskFreeSpaceExW CreateDirectoryW Sleep GetCurrentDirectoryW GetCurrentProcess GetTempPathW RemoveDirectoryW lstrlenW WideCharToMultiByte lstrlenA CreateSemaphoreW ReleaseSemaphore GetDiskFreeSpaceW GetDriveTypeW GetVolumeInformationW FormatMessageW GetVolumePathNamesForVolumeNameW FindFirstVolumeW CreateFileW DeviceIoControl FindVolumeClose FindNextVolumeW SetFilePointer ReadFile FreeLibrary FileTimeToSystemTime SystemTimeToTzSpecificLocalTime SetVolumeMountPointW GetWindowsDirectoryA GetFileSize DeleteVolumeMountPointW GetModuleFileNameW WriteFile SetFilePointerEx ReadFileEx WriteFileEx CopyFileW VirtualAlloc VirtualFree GetEnvironmentVariableW GetVersionExW CreateNamedPipeW ConnectNamedPipe DisconnectNamedPipe GetSystemTime SystemTimeToFileTime LocalFree FindFirstFileW FindNextFileW FindClose GetSystemTimeAsFileTime FlushViewOfFile GetProcessHeap OutputDebugStringW OutputDebugStringA WaitForSingleObjectEx UnmapViewOfFile UnlockFileEx UnlockFile SetEndOfFile QueryPerformanceCounter MapViewOfFile LockFileEx LockFile GetTickCount HeapCompact HeapValidate HeapSize HeapReAlloc HeapFree HeapDestroy HeapCreate HeapAlloc GetVersionExA GetTempPathA GetSystemInfo GetFullPathNameW GetFullPathNameA GetFileAttributesExW GetFileAttributesA GetDiskFreeSpaceA GetCurrentProcessId FormatMessageA FlushFileBuffers DeleteFileA CreateFileMappingW CreateFileMappingA CreateFileA AreFileApisANSI TryEnterCriticalSection GetCurrentThreadId CreateEventA QueryPerformanceFrequency GetThreadTimes GetCurrentThread GetFileAttributesExA GetCurrentDirectoryA CompareFileTime GetExitCodeThread SetCurrentDirectoryW GetModuleHandleExW SetLastError TlsGetValue TlsSetValue InitializeCriticalSectionAndSpinCount TlsAlloc TlsFree CreateFiber SwitchToFiber DeleteFiber GetStdHandle GetFileType RaiseException RtlVirtualUnwind ConvertThreadToFiber ConvertFiberToThread SetCriticalSectionSpinCount SwitchToThread SetHandleInformation GetProcessAffinityMask ExpandEnvironmentStringsA ReadConsoleA ReadConsoleW GetConsoleMode SetConsoleMode CreateTimerQueue DeleteTimerQueueTimer DeleteTimerQueueEx CreateTimerQueueTimer GetTimeZoneInformation OpenProcess FindFirstFileA SetFileAttributesA FindNextFileA RemoveDirectoryA SetFileAttributesW GetFileSizeEx CreateToolhelp32Snapshot Process32NextW Process32FirstW GlobalMemoryStatusEx GetComputerNameExW GetSystemFirmwareTable GetComputerNameW GetFirmwareEnvironmentVariableW GetLocalTime FlsFree FlsSetValue FlsGetValue RtlCaptureContext IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter MultiByteToWideChar SetThreadPriority ReleaseMutex CreateMutexW FindResourceExW FindResourceW LoadResource LockResource SizeofResource DeleteCriticalSection CloseHandle GetLastError CreateEventW InitializeCriticalSection WaitForSingleObject SetEvent LeaveCriticalSection ResetEvent EnterCriticalSection GetWindowsDirectoryW FlsAlloc GetLocaleInfoW SetHandleCount GetStartupInfoW HeapSetInformation GetACP GetOEMCP IsValidCodePage CompareStringW GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW SetConsoleCtrlHandler SetStdHandle GetFileInformationByHandle CreateThread GetFileTime MoveFileW PeekNamedPipe WriteConsoleW GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale SetEnvironmentVariableA CreateSemaphoreA DuplicateHandle GetModuleHandleA WaitForMultipleObjectsEx MoveFileExW SetWaitableTimer OpenEventA CreateWaitableTimerA IsDBCSLeadByteEx FoldStringW GetDateFormatW GetTimeFormatW GetCurrencyFormatW WaitForMultipleObjects LoadLibraryA LCMapStringW GetTimeFormatA GetDateFormatA GetConsoleCP FindFirstFileExA GetDriveTypeA FileTimeToLocalFileTime ExitProcess RtlUnwindEx RtlLookupFunctionEntry RtlPcToFileHeader GetCPInfo ResumeThread GetCommandLineA ExitThread DecodePointer EncodePointer GetStringTypeW |
| USER32.dll |
GetProcessWindowStation
GetSystemMetrics GetUserObjectInformationW wsprintfW MessageBoxW |
| ADVAPI32.dll |
RegLoadKeyW
RegOpenKeyExW RegEnumKeyExW RegCloseKey RegUnLoadKeyW RegCreateKeyExW RegSetValueExW RegQueryValueExW GetTokenInformation RegDeleteKeyW LookupPrivilegeValueW AdjustTokenPrivileges RegGetKeySecurity GetSecurityDescriptorDacl RegSetKeySecurity RegQueryInfoKeyW RegRenameKey LookupAccountSidW ConvertStringSidToSidW ConvertSidToStringSidW RegQueryValueW QueryServiceStatusEx CloseServiceHandle OpenServiceW OpenSCManagerW CryptGetHashParam CryptHashData InitiateSystemShutdownW OpenThreadToken DuplicateToken CreateWellKnownSid CheckTokenMembership CryptGetUserKey CryptDestroyHash CryptDecrypt CryptDestroyKey CryptCreateHash CryptGetProvParam CryptEnumProvidersW CryptSignHashW CryptAcquireContextW CryptExportKey CryptSetHashParam ReportEventW DeregisterEventSource RegisterEventSourceW RegQueryValueExA RegOpenKeyExA CryptGenRandom CryptReleaseContext CryptAcquireContextA GetSidSubAuthority GetSidSubAuthorityCount SetNamedSecurityInfoW SetSecurityDescriptorDacl InitializeSecurityDescriptor GetNamedSecurityInfoW GetAce GetAclInformation GetSecurityDescriptorSacl GetSecurityDescriptorGroup GetSecurityDescriptorOwner RegOpenKeyW RegDeleteValueW RegEnumValueW OpenProcessToken |
| SHELL32.dll |
SHFileOperationW
SHCreateDirectoryExW |
| ole32.dll |
CoUninitialize
CoCreateInstance CoInitializeSecurity CoSetProxyBlanket StringFromGUID2 CoInitialize CoCreateGuid |
| OLEAUT32.dll |
SysAllocString
SysFreeString VariantInit VariantClear |
| SHLWAPI.dll |
PathRemoveFileSpecW
PathFileExistsW PathFindFileNameW StrTrimW PathStripToRootW PathFileExistsA PathAppendW PathCombineW |
| MPR.dll |
WNetAddConnection2W
WNetCancelConnection2W |
| msi.dll |
#248
#246 |
| SETUPAPI.dll |
SetupOpenInfFileW
SetupCloseInfFile SetupGetStringFieldW SetupFindFirstLineW SetupFindNextLine CM_Locate_DevNodeW SetupDiEnumDeviceInfo SetupDiDestroyDeviceInfoList SetupDiGetClassDevsW SetupDiGetDevicePropertyW SetupDiGetDeviceInstanceIdW CM_Get_DevNode_Status CM_Get_DevNode_Registry_Property_ExW |
| WINHTTP.dll |
WinHttpSetCredentials
WinHttpOpenRequest WinHttpSendRequest WinHttpQueryDataAvailable WinHttpReadData WinHttpReceiveResponse WinHttpQueryHeaders WinHttpConnect WinHttpOpen WinHttpSetOption WinHttpWriteData WinHttpAddRequestHeaders WinHttpSetStatusCallback WinHttpCloseHandle WinHttpQueryOption |
| WINMM.dll |
timeGetDevCaps
timeBeginPeriod |
| PSAPI.DLL |
GetProcessImageFileNameW
GetProcessMemoryInfo |
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
| Ordinal | 1 |
|---|---|
| Address | 0x119200 |
| Ordinal | 2 |
|---|---|
| Address | 0x122a60 |
| Ordinal | 3 |
|---|---|
| Address | 0x123710 |
| Ordinal | 4 |
|---|---|
| Address | 0x122950 |
| Ordinal | 5 |
|---|---|
| Address | 0x11a360 |
| Ordinal | 6 |
|---|---|
| Address | 0x11b000 |
| Ordinal | 7 |
|---|---|
| Address | 0x11a300 |
| Ordinal | 8 |
|---|---|
| Address | 0x11b250 |
| Ordinal | 9 |
|---|---|
| Address | 0x119240 |
| Ordinal | 10 |
|---|---|
| Address | 0x11b050 |
| Ordinal | 11 |
|---|---|
| Address | 0x11d240 |
| Ordinal | 12 |
|---|---|
| Address | 0x122af0 |
| Ordinal | 13 |
|---|---|
| Address | 0x11cfa0 |
| Ordinal | 14 |
|---|---|
| Address | 0x11dad0 |
| Ordinal | 15 |
|---|---|
| Address | 0x11ecb0 |
| Ordinal | 16 |
|---|---|
| Address | 0x11c950 |
| Ordinal | 17 |
|---|---|
| Address | 0x11d2a0 |
| Ordinal | 18 |
|---|---|
| Address | 0x11cc70 |
| Ordinal | 19 |
|---|---|
| Address | 0x11e150 |
| Ordinal | 20 |
|---|---|
| Address | 0x11d260 |
| Ordinal | 21 |
|---|---|
| Address | 0x11d260 |
| Ordinal | 22 |
|---|---|
| Address | 0x11d260 |
| Ordinal | 23 |
|---|---|
| Address | 0x11b0b0 |
| Ordinal | 24 |
|---|---|
| Address | 0x122b50 |
| Ordinal | 25 |
|---|---|
| Address | 0x11b090 |
| Ordinal | 26 |
|---|---|
| Address | 0x122b10 |
| Ordinal | 27 |
|---|---|
| Address | 0x11c8e0 |
| Ordinal | 28 |
|---|---|
| Address | 0x123780 |
| Ordinal | 29 |
|---|---|
| Address | 0x11d280 |
| Ordinal | 30 |
|---|---|
| Address | 0x119230 |
| Ordinal | 31 |
|---|---|
| Address | 0x122940 |
| Ordinal | 32 |
|---|---|
| Address | 0x1191e0 |
| Ordinal | 33 |
|---|---|
| Address | 0x1191f0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jul-29 09:12:22 |
| Version | 0.0 |
| SizeofData | 143 |
| AddressOfRawData | 0x9209d0 |
| PointerToRawData | 0x91f1d0 |
| Referenced File | d:\Webhost\29-07-2024\WindowsBuilds\OSD_NATIVE\8799050\osdeployer\ONPREMISE\OSD_SRC\agent\x64\Release\ImageCreator.pdb |
| StartAddressOfRawData | 0x140acc000 |
|---|---|
| EndAddressOfRawData | 0x140acc001 |
| AddressOfIndex | 0x140a5b228 |
| AddressOfCallbacks | 0x14078df20 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0000000140582D60
|
| XOR Key | 0x8ee04cbf |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 SP1 build 40219) | 320 |
| 152 (20115) | 3 |
| ASM objects (VS2010 build 30319) | 15 |
| C objects (VS2008 SP1 build 30729) | 1 |
| 135 (VS2008 SP1 build 30729) | 3 |
| C++ objects (VS2010 build 30319) | 164 |
| C objects (VS2010 build 30319) | 286 |
| ASM objects (VS2010 SP1 build 40219) | 29 |
| C objects (VS2010 SP1 build 40219) | 23 |
| Imports (VS2008 SP1 build 30729) | 41 |
| Total imports | 508 |
| 175 (VS2010 build 30319) | 750 |
| Exports (VS2010 build 30319) | 1 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |