| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-18 17:23:21 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 4 |
| TimeDateStamp | 2026-Apr-18 17:23:21 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x57e00 |
| SizeOfInitializedData | 0x5000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000056560 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x5f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
SetWindowPos
MonitorFromWindow PostMessageA GetSystemMetrics ShowWindow SetTimer EndPaint TrackMouseEvent SetWindowTextA GetMonitorInfoA DefWindowProcA GetWindowRect SetLayeredWindowAttributes TranslateMessage SendMessageA SetCursor SystemParametersInfoA GetClientRect PostQuitMessage RegisterClassExA UpdateWindow ReleaseCapture InvalidateRect ReleaseDC BeginPaint LoadCursorA AdjustWindowRectEx GetMessageA CreateWindowExA DispatchMessageA |
|---|---|
| GDI32.dll |
DeleteObject
GetDeviceCaps SelectObject CreateCompatibleBitmap DeleteDC |
| gdiplus.dll |
GdipCreatePen1
GdipDeletePen GdipDeleteFont GdipDeleteStringFormat GdipDeleteGraphics GdipFillRectangleI GdipCloneBrush GdipSetTextRenderingHint GdipCreateFromHDC GdipDrawString GdipDrawPath GdipFree GdipClosePathFigure GdipSetStringFormatAlign GdipFillPath GdipCreateSolidFill GdipCreateFont GdipSetStringFormatLineAlign GdipCreatePath GdipSetSmoothingMode GdipDeletePath GdipAlloc GdipDeleteBrush GdipCreateFontFamilyFromName GdipDrawRectangleI GdiplusStartup GdipSetStringFormatFlags GdiplusShutdown GdipGraphicsClear GdipCreateStringFormat GdipDeleteFontFamily GdipAddPathArcI |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
?_Xbad_function_call@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z |
| KERNEL32.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW CreateThread GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime GetCurrentProcess TerminateProcess GetTickCount GetTickCount64 MultiByteToWideChar OutputDebugStringA IsProcessorFeaturePresent InitializeSListHead |
| VCRUNTIME140.dll |
__std_exception_destroy
memmove memcpy __current_exception _CxxThrowException __C_specific_handler memcmp memset __std_exception_copy __current_exception_context |
| api-ms-win-crt-stdio-l1-1-0.dll |
fseek
__stdio_common_vfprintf fread fclose __acrt_iob_func __stdio_common_vsprintf_s _set_fmode __p__commode fopen ftell __stdio_common_vsscanf __stdio_common_vsprintf |
| api-ms-win-crt-math-l1-1-0.dll |
log
trunc __setusermatherr round fabs cos ceil _dtest sin fmod pow floor tan sqrt nan |
| api-ms-win-crt-runtime-l1-1-0.dll |
exit
_initterm_e terminate _initterm _get_narrow_winmain_command_line _register_thread_local_exe_atexit_callback abort _c_exit _errno _configure_narrow_argv _set_app_type _seh_filter_exe _cexit _invoke_watson _initialize_narrow_environment _initialize_onexit_table _crt_atexit _exit _register_onexit_function |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
isspace isalnum toupper isxdigit isdigit strcmp tolower isalpha |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
strtol strtod |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free malloc |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-18 17:23:21 |
| Version | 0.0 |
| SizeofData | 740 |
| AddressOfRawData | 0xb3c8 |
| PointerToRawData | 0xa7c8 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140059040 |
| XOR Key | 0x96387974 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 26 |
| Imports (35207) | 6 |
| Imports (33145) | 9 |
| Total imports | 172 |
| C++ objects (LTCG) (35225) | 1 |
| Linker (35225) | 1 |
No comments yet.