Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2008-Nov-10 09:40:34 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. | Resource 1 detected as a PE Executable. |
Malicious | The file contains overlay data. |
1310582 bytes of data starting at offset 0x287600.
The file contains a Zip Compressed Archive after the PE data. |
Safe | VirusTotal score: 0/71 (Scanned on 2019-05-06 20:49:35) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2008-Nov-10 09:40:34 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x2200 |
SizeOfInitializedData | 0x285000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00002B28 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x4000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x28b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x510d |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
MSVCR90.dll |
_controlfp_s
_invoke_watson strncpy _except_handler4_common _decode_pointer _onexit _lock __dllonexit _unlock ?terminate@@YAXXZ __set_app_type _encode_pointer __p__fmode __p__commode _adjust_fdiv __setusermatherr _configthreadlocale _initterm_e _initterm __initenv exit _XcptFilter _exit _cexit __getmainargs _amsg_exit realloc bsearch qsort memset memcpy setbuf getenv atoi malloc free _snprintf strncmp strrchr fprintf __iob_func _crt_debugger_hook _stricmp _strdup |
---|---|
KERNEL32.dll |
LocalFree
IsDebuggerPresent UnhandledExceptionFilter GetCurrentProcess TerminateProcess GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter SetUnhandledExceptionFilter InterlockedCompareExchange Sleep InterlockedExchange HeapAlloc IsBadReadPtr SetLastError GetProcessHeap HeapFree VirtualFree VirtualProtect VirtualAlloc FreeLibrary GetModuleHandleA OutputDebugStringA GetFullPathNameA LoadLibraryA GetProcAddress UnmapViewOfFile CreateFileA GetFileSize CreateFileMappingA CloseHandle MapViewOfFile FindResourceA LoadResource LockResource GetModuleFileNameA GetLastError FormatMessageA |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x405a58 |
SEHandlerTable | 0x4041d0 |
SEHandlerCount | 1 |
XOR Key | 0xd2ba5881 |
---|---|
Unmarked objects | 0 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
150 (20413) | 2 |
Imports (VS2008 build 21022) | 3 |
Total imports | 84 |
ASM objects (VS2008 build 21022) | 1 |
C++ objects (VS2008 build 21022) | 2 |
C objects (VS2008 build 21022) | 25 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 build 21022) | 1 |