| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2022-Jul-01 19:22:20 |
| Detected languages |
English - United States
|
| FileVersion | 2.1.0.0 |
| ProductVersion | 2.1.0.0 |
| FileDescription | StopTheLag |
| CompanyName | StopTheLag |
| LegalCopyright | Danilo @ 2025 all rights reserved. |
| ProductName | StopTheLag |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 38288 bytes of data starting at offset 0x19000. |
| Malicious | VirusTotal score: 7/72 (Scanned on 2025-09-25 09:57:18) |
Cylance:
Unsafe
DeepInstinct: MALICIOUS McAfeeD: ti!0F6C2A0EBDE5 SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Infected.ch Trapmine: malicious.high.ml.score TrellixENS: Artemis!4C51E5A0E006 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2022-Jul-01 19:22:20 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x13000 |
| SizeOfInitializedData | 0x5000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000C880 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb24000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x1a4ee |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetWindowsDirectoryA
GetTempPathA GetModuleFileNameA GetStdHandle SetConsoleMode GetConsoleMode Sleep SetConsoleCursorInfo SetConsoleCursorPosition SetConsoleTextAttribute GetTickCount GetVolumeInformationA GetLastError GetProcAddress LoadLibraryA ReadConsoleInputA WriteConsoleA LCMapStringW ExitProcess TerminateProcess GetCurrentProcess GetCommandLineA GetVersion SetHandleCount GetFileType GetStartupInfoA ReadFile SetFilePointer HeapFree CloseHandle GetFileAttributesA GetModuleHandleA WriteFile UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree RtlUnwind HeapAlloc SetStdHandle FlushFileBuffers VirtualAlloc HeapReAlloc CreateFileA GetExitCodeProcess WaitForSingleObject CreateProcessA MultiByteToWideChar GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP SetEndOfFile CompareStringA CompareStringW SetEnvironmentVariableA LCMapStringA |
|---|---|
| WINMM.dll |
timeGetTime
|
| WS2_32.dll |
WSAStartup
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.1.0.0 |
| ProductVersion | 2.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | UNKNOWN |
| FileVersion (#2) | 2.1.0.0 |
| ProductVersion (#2) | 2.1.0.0 |
| FileDescription | StopTheLag |
| CompanyName | StopTheLag |
| LegalCopyright | Danilo @ 2025 all rights reserved. |
| ProductName | StopTheLag |
| Resource LangID | UNKNOWN |
|---|
| XOR Key | 0x1a1e39b4 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 4 |
| 14 (7299) | 14 |
| C objects (VS98 build 8168) | 97 |
| 19 (8034) | 7 |
| Total imports | 68 |
| C++ objects (VS98 build 8168) | 2 |
| Resource objects (VS98 cvtres build 1720) | 1 |
No comments yet.