Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Oct-22 11:17:07 |
Detected languages |
English - United States
|
Debug artifacts |
C:\wrkplace\tomcat-connectors-1.2.31-src\native\iis\Release_x86\isapi_redirect-1.2.31.pdb
|
Comments | The ASF licenses this file to You under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. |
CompanyName | Apache Software Foundation |
FileDescription | Apache Tomcat Connector |
FileVersion | 1.2.31 |
InternalName | isapi_redirector |
LegalCopyright | Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE file distributed with this work for additional information regarding copyright ownership. |
OriginalFilename | isapi_redirector.dll |
ProductName | Apache Tomcat isapi_redirector Connector |
ProductVersion | 1.2.31 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
Suspicious | The PE contains functions most legitimate programs don't use. |
Can access the registry:
|
Safe | VirusTotal score: 0/70 (Scanned on 2022-11-23 18:23:49) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2010-Oct-22 11:17:07 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x42800 |
SizeOfInitializedData | 0x17800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0003C4E0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x44000 |
ImageBase | 0x6a6b0000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x5d000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetLastError
CloseHandle WaitForSingleObject Sleep GetFileSizeEx GetModuleFileNameA CreateThread SetLastError InitializeCriticalSection UnmapViewOfFile ReleaseMutex MapViewOfFile CreateMutexA OpenMutexA OpenFileMappingA CreateFileMappingA GetCurrentThreadId DeleteCriticalSection EnterCriticalSection GetEnvironmentVariableA LeaveCriticalSection RtlUnwind GetSystemTimeAsFileTime GetCurrentProcessId GetTickCount QueryPerformanceCounter GetVersion SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess InterlockedCompareExchange InterlockedExchange OutputDebugStringA |
---|---|
ADVAPI32.dll |
RegOpenKeyExA
RegQueryValueExA RegCloseKey |
WS2_32.dll |
WSAIoctl
setsockopt socket recv shutdown WSAGetLastError ioctlsocket getsockopt __WSAFDIsSet select WSASetLastError connect inet_addr gethostbyname htons closesocket htonl getpeername send getsockname |
msvcrt.dll |
strtok
strchr isspace malloc _snprintf memset toupper strncpy time atoi difftime isdigit memcpy fflush fprintf _vsnprintf isxdigit tolower _get_osfhandle fputs strncmp strftime localtime strrchr isalnum atol strstr strncat strpbrk sprintf getenv fclose fgets fopen memmove qsort _ftime _mbsdec _ismbblead _XcptFilter _initterm _amsg_exit mbtowc __mb_cur_max isleadbyte localeconv _unlock _iob _lock _itoa wctomb ferror iswctype wcstombs __dllonexit _onexit realloc __badioinfo __pioinfo _read _fileno _lseeki64 _write _isatty ungetc free _pwctype __lc_collate_cp _wcsupr _wcslwr _strupr _strlwr _ecvt _gcvt _mbsupr _errno _mbslwr __CxxFrameHandler atof calloc _strdup _strnicmp _stricmp _stat _putenv _fdopen |
MSVCRT.dll |
_getpid
|
Ordinal | 1 |
---|---|
Address | 0x14560 |
Ordinal | 2 |
---|---|
Address | 0x144e0 |
Ordinal | 3 |
---|---|
Address | 0x13f40 |
Ordinal | 4 |
---|---|
Address | 0x13230 |
Ordinal | 5 |
---|---|
Address | 0xff00 |
Ordinal | 6 |
---|---|
Address | 0xf2e0 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.2.31.0 |
ProductVersion | 1.2.31.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
Comments | The ASF licenses this file to You under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. |
CompanyName | Apache Software Foundation |
FileDescription | Apache Tomcat Connector |
FileVersion (#2) | 1.2.31 |
InternalName | isapi_redirector |
LegalCopyright | Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE file distributed with this work for additional information regarding copyright ownership. |
OriginalFilename | isapi_redirector.dll |
ProductName | Apache Tomcat isapi_redirector Connector |
ProductVersion (#2) | 1.2.31 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Oct-22 11:17:07 |
Version | 0.0 |
SizeofData | 114 |
AddressOfRawData | 0x514a0 |
PointerToRawData | 0x500a0 |
Referenced File | C:\wrkplace\tomcat-connectors-1.2.31-src\native\iis\Release_x86\isapi_redirect-1.2.31.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x6a704a18 |
SEHandlerTable | 0x6a701520 |
SEHandlerCount | 2 |
XOR Key | 0xfbfe64ff |
---|---|
Unmarked objects | 0 |
105 (2067) | 9 |
ASM objects (VS2008 SP1 build 30729) | 10 |
C++ objects (VS2008 SP1 build 30729) | 13 |
Imports (VS2008 SP1 build 30729) | 4 |
Imports (VS2003 (.NET) build 4035) | 7 |
Total imports | 144 |
126 (VS2012 build 50727 / VS2005 build 50727) | 1 |
C objects (VS2008 SP1 build 30729) | 84 |
Exports (VS2008 SP1 build 30729) | 1 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |