Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2007-Oct-29 08:14:12 |
Detected languages |
Korean - Korea
|
CompanyName | WebZen |
FileDescription | main |
FileVersion | 1, 4, 10, 0 |
InternalName | main |
LegalCopyright | Copyright ⓒ 2002 |
OriginalFilename | main.exe |
ProductName | WebZen mu main |
ProductVersion | 1, 0, 0, 1 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 6/73 (Scanned on 2024-11-18 01:35:42) |
Bkav:
W32.AIDetectMalware
Cylance: Unsafe Gridinsoft: Trojan.Win32.Gen.vb!n McAfee: Artemis!065D7B9160DB Panda: PUP/FreeGames Webroot: W32.Malware.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2007-Oct-29 08:14:12 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x355000 |
SizeOfInitializedData | 0x36200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00355A90 (Section: .text) |
BaseOfCode | 0x400 |
BaseOfData | 0x356400 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x799c000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
IMM32.dll |
ImmGetIMEFileNameA
ImmGetDefaultIMEWnd ImmGetCompositionStringA ImmGetCompositionWindow ImmGetDescriptionA ImmGetContext ImmGetOpenStatus ImmSetOpenStatus ImmGetConversionStatus ImmSetConversionStatus ImmReleaseContext ImmSetCompositionWindow |
---|---|
DSOUND.dll |
#1
#2 |
OPENGL32.dll |
glColor4f
glDisable glEnd glVertex2f glTexCoord2f glColor4ub glBegin glColor3f glTexImage2D glBindTexture glFlush glClear glPopMatrix glAlphaFunc glDepthFunc glTranslatef glRotatef glLoadIdentity glPushMatrix glMatrixMode glVertex3fv glColor3fv glFogf glFogfv glClearColor glVertex3f glDepthMask glPolygonMode glFrontFace glStencilFunc glColorMask glStencilOp glTexParameteri glTexEnvf glScalef glGetFloatv glReadPixels glBlendFunc glViewport glFogi wglDeleteContext wglMakeCurrent glGetString wglCreateContext glTexEnvi glGenTextures glGetIntegerv glDeleteTextures glEnable |
GLU32.dll |
gluPerspective
gluOrtho2D |
WINMM.dll |
mmioAscend
mmioOpenA mmioClose timeGetTime mmioDescend mmioRead timeGetDevCaps timeBeginPeriod mmioWrite timeEndPeriod |
KERNEL32.dll |
ReleaseMutex
TerminateThread CreateThread OpenMutexA EnterCriticalSection LeaveCriticalSection lstrcatA OpenEventA GetComputerNameA lstrcmpA ExitProcess VirtualAlloc VirtualFree VirtualProtect LoadLibraryExA GetTempFileNameA GetTempPathA HeapFree GetProcessHeap HeapAlloc GetFileInformationByHandle FlushFileBuffers GetTickCount IsBadReadPtr lstrlenA GlobalUnlock GlobalLock OutputDebugStringA GetCurrentThreadId Sleep MoveFileA GetFileAttributesA CreateFileA GetCommandLineA CloseHandle ReadFile GetFileSize GetLastError GetPrivateProfileStringA GetCurrentDirectoryA DeleteFileA CopyFileA SetFileAttributesA Process32Next TerminateProcess OpenProcess Process32First CreateToolhelp32Snapshot WinExec FindClose FindFirstFileA CreateMutexA GetLocalTime GetModuleFileNameA DuplicateHandle WriteFile GetSystemDirectoryA lstrcmpiA GetVersionExA QueryPerformanceCounter SetProcessAffinityMask SetThreadPriority SetPriorityClass GetProcessAffinityMask GetThreadPriority GetPriorityClass GetCurrentThread GetCurrentProcess QueryPerformanceFrequency FreeLibrary GetProcAddress LoadLibraryA GlobalMemoryStatus SetConsoleMode GetStdHandle AllocConsole FreeConsole SetConsoleTitleA GetConsoleTitleA SetConsoleCursorPosition FillConsoleOutputAttribute FillConsoleOutputCharacterA GetConsoleScreenBufferInfo SetConsoleTextAttribute ReadConsoleOutputA GetCurrentProcessId WaitForSingleObject CreateEventA CreateProcessA WaitForMultipleObjects GetExitCodeProcess GetModuleHandleA ResetEvent ResumeThread SetEndOfFile DeleteCriticalSection InitializeCriticalSection SetEvent WideCharToMultiByte CreateFileMappingA UnmapViewOfFile MapViewOfFile FileTimeToLocalFileTime FileTimeToSystemTime GetFullPathNameA FindNextFileA RemoveDirectoryA CreateDirectoryA GetThreadContext lstrcpynA Module32First Module32Next SetUnhandledExceptionFilter GetACP GetOEMCP SetHandleCount GetFileType TlsGetValue GetEnvironmentVariableA HeapDestroy HeapCreate IsBadWritePtr IsValidLocale IsValidCodePage GetLocaleInfoA EnumSystemLocalesA GetUserDefaultLCID UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW GetStringTypeA GetStringTypeW IsBadCodePtr SetEnvironmentVariableA SetConsoleCtrlHandler GetLocaleInfoW SetStdHandle CreatePipe PeekNamedPipe lstrcpyA InterlockedExchange InterlockedDecrement InterlockedIncrement MultiByteToWideChar RtlUnwind RaiseException GetTimeZoneInformation GetSystemTime GetStartupInfoA GetVersion GetSystemTimeAsFileTime HeapReAlloc FatalAppExitA LCMapStringA LCMapStringW GetCPInfo CompareStringA CompareStringW HeapSize TlsSetValue TlsAlloc TlsFree SetLastError SetFilePointer |
USER32.dll |
ShowWindow
GetDC SetWindowPos SetWindowTextA GetWindowTextA GetCaretPos GetWindowLongA SendMessageA CallWindowProcA OpenClipboard GetClipboardData IsWindowVisible SetWindowLongA DestroyWindow GetFocus SetRect GetActiveWindow GetCursorPos ScreenToClient GetDoubleClickTime PtInRect OffsetRect MessageBoxA PostMessageA GetAsyncKeyState GetScrollPos CreateWindowExA SetTimer IntersectRect GetDesktopWindow SetWindowsHookExA UnhookWindowsHookEx CallNextHookEx GetWindowRect RegisterHotKey UnregisterHotKey SetCursorPos FindWindowA ShowCursor ChangeDisplaySettingsA ReleaseDC SystemParametersInfoA ReleaseCapture SetCapture DefWindowProcA PostQuitMessage EndPaint BeginPaint KillTimer RegisterClassA LoadCursorA LoadIconA SetForegroundWindow GetSystemMetrics SetScrollPos SetFocus AdjustWindowRect IsIconic DispatchMessageA TranslateMessage GetMessageA PeekMessageA UpdateWindow EnumDisplaySettingsA GetKeyboardLayoutNameA GetKeyboardLayout wvsprintfA EnumChildWindows RemoveMenu DrawMenuBar GetSystemMenu GetClassNameA GetWindowThreadProcessId CloseClipboard wsprintfA |
GDI32.dll |
SwapBuffers
GetStockObject SetPixelFormat ChoosePixelFormat SetBkColor CreateDIBSection SelectObject GetTextExtentPoint32A CreateFontA DeleteObject SetTextColor DeleteDC TextOutA CreateCompatibleDC GetTextExtentPointA |
ADVAPI32.dll |
SetSecurityDescriptorDacl
CryptGetHashParam CryptDeriveKey CryptDecrypt CryptImportKey CryptCreateHash CryptHashData CryptVerifySignatureA CryptDestroyHash CryptDestroyKey CryptReleaseContext CryptAcquireContextA RegDeleteKeyA GetUserNameA RegDeleteValueA RegEnumValueA RegOpenKeyExA RegSetValueExA RegCreateKeyExA InitializeSecurityDescriptor RegQueryValueExA RegCloseKey |
SHELL32.dll |
ShellExecuteA
|
ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
WS2_32.dll |
gethostbyname
WSAAsyncSelect setsockopt socket shutdown recv WSASend WSAStartup WSACleanup send WSAGetLastError inet_addr htons connect closesocket |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
wzAudio.dll |
wzAudioStop
wzAudioPlay wzAudioGetStreamOffsetRange wzAudioDestroy wzAudioOption wzAudioCreate |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.4.10.0 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Korean - Korea |
CompanyName | WebZen |
FileDescription | main |
FileVersion (#2) | 1, 4, 10, 0 |
InternalName | main |
LegalCopyright | Copyright ⓒ 2002 |
OriginalFilename | main.exe |
ProductName | WebZen mu main |
ProductVersion (#2) | 1, 0, 0, 1 |
Resource LangID | Korean - Korea |
---|
XOR Key | 0xc4c0f08b |
---|---|
Unmarked objects | 0 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 2 |
12 (7291) | 4 |
14 (7299) | 44 |
C++ objects (8047) | 24 |
C objects (8047) | 184 |
C++ objects (VS98 SP6 build 8804) | 17 |
C objects (VS98 build 8168) | 44 |
C++ objects (9178) | 1 |
Imports (9210) | 2 |
Total imports | 381 |
19 (8034) | 25 |
C++ objects (VC++ 6.0 SP5 build 8804) | 174 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |