Category | Started | Completed | Duration | Log |
---|---|---|---|---|
FILE | 2023-11-15 11:36:47 | 2023-11-15 11:36:47 | 0 seconds | Show Log |
File Name | cmdkey.exe |
---|---|
File Size | 45056 bytes |
File Type | PE32+ executable (console) x86-64, for MS Windows |
MD5 | 9f7d571f0a641aab8871c3f4afeb2731 |
SHA1 | 88fcbd42f8e56c5518e4e2c0c97380c51298f575 |
SHA256 | 85bfc4848711618d0636bc03ac0bab9de7a5f01e5bc402c3c3e7bc3dd5924e8b |
SHA512 | d57dd0698b6854265eba4a9c80cffafbd67428f38e8ed0513bcddd532468e6290b1f38655d44c375568eab9699f6e815f061921c98b231d370861c4f59c82154 |
CRC32 | 7D8A8FDD |
Ssdeep | 384:DkvKugGGgU4sFq5a2odLAqb/vBYQ/OP1lDprjmxE7G49WHwW:D0PU4qd5n4lDNL7G4i |
ClamAV | None matched |
Yara | None matched |
No signatures
No hosts contacted.
No domains contacted.
Image Base | 0x140000000 |
---|---|
Entry Point | 0x140001320 |
Reported Checksum | 0x00019a9a |
Actual Checksum | 0x00019a9a |
Minimum OS Version | 10.0 |
PDB Path | cmdkey.pdb |
Compile Time | 2067-10-05 20:01:51 |
LegalCopyright | \xa9 Microsoft Corporation. All rights reserved. |
---|---|
InternalName | cmdkey.exe |
FileVersion | 10.0.22621.1 (WinBuild.160101.0800) |
CompanyName | Microsoft Corporation |
ProductName | Microsoft\xae Windows\xae Operating System |
ProductVersion | 10.0.22621.1 |
FileDescription | Credential Manager Command Line Utility |
OriginalFilename | cmdkey.exe |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Size of Raw Data | Characteristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00002360 | 0x00003000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 5.09 |
.rdata | 0x00004000 | 0x00001792 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 3.40 |
.data | 0x00006000 | 0x00001100 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.12 |
.pdata | 0x00008000 | 0x000001c8 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 0.64 |
.didat | 0x00009000 | 0x00000010 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0000a000 | 0x00000830 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 2.61 |
.reloc | 0x0000b000 | 0x00000040 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 0.14 |
Name | Offset | Size | Language | Sub-language | Entropy | File type |
---|---|---|---|---|---|---|
MUI | 0x0000a768 | 0x000000c8 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.72 | data |
RT_VERSION | 0x0000a3a8 | 0x000003bc | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.45 | data |
RT_MANIFEST | 0x0000a0f0 | 0x000002b7 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.90 | XML document text |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP
JSON Report | Download |
---|
Task ID | 2436 |
---|---|
Mongo ID | 655501b12694ed5bda0b5ea1 |
Cuckoo release | 1.3-NG |