File Information
File Nameinvoice_2024.exe
File Size28,672 bytes
Entry Point0047A000
EP SectionUPX1
File Offset00027200
Packer / Compiler Detection
PackerUPX 3.95 [LZMA] → Mark Adler
* Multi-Scan 결과: UPX 외 추가 패킹 없음
Sections
Name
VSize
VOffset
RSize
Flags
UPX0
00009000
00001000
00000000
E0000060
UPX1
00005000
0000A000
00004E00
E0000060
.rsrc
00001000
0000F000
00000400
C0000040
Import Table (Stub)
KERNEL32.DLL
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
* 언패킹 후 실제 IAT 확인 필요 (upx -d 실행)
Timestamp (IMAGE_NT_HEADERS)
TimeDateStamp678A1CE4 → Wed Nov 13 03:22:44 2024
Linker Version6.0
Import Table (언패킹 후)
KERNEL32.DLL
CreateFileA
WriteFile, ReadFile, CloseHandle
CreateRemoteThread
VirtualAllocEx
WriteProcessMemory
OpenProcess
WININET.DLL
InternetOpenA
InternetOpenUrlA
InternetReadFile
ADVAPI32.DLL
RegOpenKeyExA
RegSetValueExA
CreateServiceA