Source: NSudo.exe |
ReversingLabs: Detection: 52% |
Source: NSudo.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: |
Binary string: E:\Projects\NSudo\Output\Release\x64\NSudo.pdbSS source: NSudo.exe |
Source: |
Binary string: E:\Projects\NSudo\Output\Release\x64\NSudo.pdb source: NSudo.exe |
Source: NSudo.exe |
String found in binary or memory: https://forums.mydigitallife.net/threads/59268/ |
Source: NSudo.exe |
String found in binary or memory: https://github.com/M2Team/NSudo |
Source: classification engine |
Classification label: mal48.winEXE@0/0@0/0 |
Source: NSudo.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: NSudo.exe |
ReversingLabs: Detection: 52% |
Source: NSudo.exe |
String found in binary or memory: -Help |
Source: NSudo.exe |
String found in binary or memory: -Install |
Source: NSudo.exe |
String found in binary or memory: -Help Show this content. |
Source: NSudo.exe |
String found in binary or memory: -Install Copy NSudo to the Windows directory and add the context menu. |
Source: NSudo.exe |
String found in binary or memory: -Help Affiche l'aide. |
Source: NSudo.exe |
String found in binary or memory: -Install Copie NSudo dans le r |
Source: NSudo.exe |
Static PE information: Image base 0x140000000 > 0x60000000 |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: NSudo.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: NSudo.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: |
Binary string: E:\Projects\NSudo\Output\Release\x64\NSudo.pdbSS source: NSudo.exe |
Source: |
Binary string: E:\Projects\NSudo\Output\Release\x64\NSudo.pdb source: NSudo.exe |
Source: NSudo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: NSudo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: NSudo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: NSudo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: NSudo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |