| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2020-Aug-08 17:42:47 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\STEAM\SRC\KittyHawk\Output_Binaries\x64\Release\SimConnect\SimConnect.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 8.0
MASM/TASM - sig1(h) |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Can access the registry:
|
| Safe | VirusTotal score: 0/70 (Scanned on 2023-01-21 14:49:43) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2020-Aug-08 17:42:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x9e00 |
| SizeOfInitializedData | 0x4400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000A080 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x13000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WS2_32.dll |
getsockopt
shutdown WSAStartup WSACleanup WSAGetLastError WSARecv WSASend getaddrinfo closesocket freeaddrinfo connect setsockopt socket |
|---|---|
| SHLWAPI.dll |
PathCombineA
|
| USER32.dll |
GetWindowThreadProcessId
PostMessageA |
| ADVAPI32.dll |
RegOpenKeyExA
RegCloseKey RegQueryValueExA |
| SHELL32.dll |
SHGetFolderPathA
|
| KERNEL32.dll |
UnhandledExceptionFilter
IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext InitializeSListHead DisableThreadLibraryCalls SetUnhandledExceptionFilter GetCurrentThreadId lstrcmpiA QueryPerformanceFrequency QueryPerformanceCounter BindIoCompletionCallback IsProcessorFeaturePresent GetSystemTimeAsFileTime WaitNamedPipeA GetPrivateProfileSectionA ReadFile WriteFile CloseHandle GetLastError CancelIo InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection CreateEventA GetCurrentDirectoryA CreateFileA SetEvent Sleep GetCurrentProcessId GetModuleHandleA GetModuleHandleExA GetProcAddress GetPrivateProfileStringA |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z |
| VCRUNTIME140.dll |
__std_type_info_destroy_list
memcpy memmove memset _CxxThrowException __CxxFrameHandler3 memcmp __C_specific_handler __std_exception_copy __std_exception_destroy |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__stdio_common_vfprintf __stdio_common_vsprintf |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free malloc |
| api-ms-win-crt-runtime-l1-1-0.dll |
_execute_onexit_table
_configure_narrow_argv _seh_filter_dll _initterm_e _initterm _initialize_onexit_table _cexit _invalid_parameter_noinfo_noreturn _initialize_narrow_environment |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
|
| Ordinal | 1 |
|---|---|
| Address | 0x4ce0 |
| Ordinal | 2 |
|---|---|
| Address | 0x4f20 |
| Ordinal | 3 |
|---|---|
| Address | 0x50f0 |
| Ordinal | 4 |
|---|---|
| Address | 0x5300 |
| Ordinal | 5 |
|---|---|
| Address | 0x5460 |
| Ordinal | 6 |
|---|---|
| Address | 0x5530 |
| Ordinal | 7 |
|---|---|
| Address | 0x5600 |
| Ordinal | 8 |
|---|---|
| Address | 0x5740 |
| Ordinal | 9 |
|---|---|
| Address | 0x5830 |
| Ordinal | 10 |
|---|---|
| Address | 0x5940 |
| Ordinal | 11 |
|---|---|
| Address | 0x5b10 |
| Ordinal | 12 |
|---|---|
| Address | 0x5b60 |
| Ordinal | 13 |
|---|---|
| Address | 0x5c90 |
| Ordinal | 14 |
|---|---|
| Address | 0x5d80 |
| Ordinal | 15 |
|---|---|
| Address | 0x5e70 |
| Ordinal | 16 |
|---|---|
| Address | 0x5f60 |
| Ordinal | 17 |
|---|---|
| Address | 0x6050 |
| Ordinal | 18 |
|---|---|
| Address | 0x60a0 |
| Ordinal | 19 |
|---|---|
| Address | 0x6170 |
| Ordinal | 20 |
|---|---|
| Address | 0x6260 |
| Ordinal | 21 |
|---|---|
| Address | 0x6330 |
| Ordinal | 22 |
|---|---|
| Address | 0x6440 |
| Ordinal | 23 |
|---|---|
| Address | 0x6550 |
| Ordinal | 24 |
|---|---|
| Address | 0x6760 |
| Ordinal | 25 |
|---|---|
| Address | 0x67a0 |
| Ordinal | 26 |
|---|---|
| Address | 0x67f0 |
| Ordinal | 27 |
|---|---|
| Address | 0x6920 |
| Ordinal | 28 |
|---|---|
| Address | 0x6a40 |
| Ordinal | 29 |
|---|---|
| Address | 0x6b60 |
| Ordinal | 30 |
|---|---|
| Address | 0x6ce0 |
| Ordinal | 31 |
|---|---|
| Address | 0x6e20 |
| Ordinal | 32 |
|---|---|
| Address | 0x6f70 |
| Ordinal | 33 |
|---|---|
| Address | 0x7060 |
| Ordinal | 34 |
|---|---|
| Address | 0x7130 |
| Ordinal | 35 |
|---|---|
| Address | 0x72e0 |
| Ordinal | 36 |
|---|---|
| Address | 0x73b0 |
| Ordinal | 37 |
|---|---|
| Address | 0x74d0 |
| Ordinal | 38 |
|---|---|
| Address | 0x7600 |
| Ordinal | 39 |
|---|---|
| Address | 0x7730 |
| Ordinal | 40 |
|---|---|
| Address | 0x7830 |
| Ordinal | 41 |
|---|---|
| Address | 0x7900 |
| Ordinal | 42 |
|---|---|
| Address | 0x79f0 |
| Ordinal | 43 |
|---|---|
| Address | 0x7bf0 |
| Ordinal | 44 |
|---|---|
| Address | 0x7e10 |
| Ordinal | 45 |
|---|---|
| Address | 0x7f30 |
| Ordinal | 46 |
|---|---|
| Address | 0x8000 |
| Ordinal | 47 |
|---|---|
| Address | 0x8130 |
| Ordinal | 48 |
|---|---|
| Address | 0x8270 |
| Ordinal | 49 |
|---|---|
| Address | 0x8340 |
| Ordinal | 50 |
|---|---|
| Address | 0x8410 |
| Ordinal | 51 |
|---|---|
| Address | 0x84e0 |
| Ordinal | 52 |
|---|---|
| Address | 0x85b0 |
| Ordinal | 53 |
|---|---|
| Address | 0x8770 |
| Ordinal | 54 |
|---|---|
| Address | 0x8840 |
| Ordinal | 55 |
|---|---|
| Address | 0x8960 |
| Ordinal | 56 |
|---|---|
| Address | 0x8a80 |
| Ordinal | 57 |
|---|---|
| Address | 0x8b80 |
| Ordinal | 58 |
|---|---|
| Address | 0x8c70 |
| Ordinal | 59 |
|---|---|
| Address | 0x8d60 |
| Ordinal | 60 |
|---|---|
| Address | 0x8f40 |
| Ordinal | 61 |
|---|---|
| Address | 0x90d0 |
| Ordinal | 62 |
|---|---|
| Address | 0x91f0 |
| Ordinal | 63 |
|---|---|
| Address | 0x92e0 |
| Ordinal | 64 |
|---|---|
| Address | 0x9430 |
| Ordinal | 65 |
|---|---|
| Address | 0x9530 |
| Ordinal | 66 |
|---|---|
| Address | 0x9620 |
| Ordinal | 67 |
|---|---|
| Address | 0x9740 |
| Ordinal | 68 |
|---|---|
| Address | 0x9830 |
| Ordinal | 69 |
|---|---|
| Address | 0x9900 |
| Ordinal | 70 |
|---|---|
| Address | 0x99d0 |
| Ordinal | 71 |
|---|---|
| Address | 0x9aa0 |
| Ordinal | 72 |
|---|---|
| Address | 0x9bb0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-08 17:42:47 |
| Version | 0.0 |
| SizeofData | 101 |
| AddressOfRawData | 0xbb4c |
| PointerToRawData | 0xad4c |
| Referenced File | D:\STEAM\SRC\KittyHawk\Output_Binaries\x64\Release\SimConnect\SimConnect.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-08 17:42:47 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xbbb4 |
| PointerToRawData | 0xadb4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-08 17:42:47 |
| Version | 0.0 |
| SizeofData | 632 |
| AddressOfRawData | 0xbbc8 |
| PointerToRawData | 0xadc8 |
| Size | 0x100 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18000f010 |
| XOR Key | 0x94c742bc |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 8 |
| Imports (VS 2015/2017 runtime 26706) | 4 |
| C++ objects (VS 2015/2017 runtime 26706) | 18 |
| C objects (VS 2015/2017 runtime 26706) | 7 |
| ASM objects (VS 2015/2017 runtime 26706) | 1 |
| Imports (VS2017 v14.15 compiler 26715) | 13 |
| Total imports | 92 |
| C++ objects (VS2017 v15.9.7-10 compiler 27027) | 4 |
| Exports (VS2017 v15.9.7-10 compiler 27027) | 1 |
| Resource objects (VS2017 v15.9.7-10 compiler 27027) | 1 |
| Linker (VS2017 v15.9.7-10 compiler 27027) | 1 |