Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2015-Feb-12 18:50:20 |
Detected languages |
English - United States
Russian - Russia |
Debug artifacts |
P:\MultiLauncher\Release\MultiLauncher.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2015-Feb-12 18:50:20 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 11.0 |
SizeOfCode | 0x93000 |
SizeOfInitializedData | 0x115000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0005A8C5 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x94000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x1af000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ReleaseMutex
FreeResource FindResourceW FreeLibrary LoadResource LoadLibraryExW SizeofResource LockResource EndUpdateResourceW BeginUpdateResourceW UpdateResourceW ConnectNamedPipe CreateNamedPipeW GetLastError CreateThread FindFirstFileW PeekNamedPipe GetLogicalDriveStringsW GetModuleFileNameW FindClose FindNextFileW SetFileAttributesW ExpandEnvironmentStringsW GetModuleHandleW WaitForSingleObject CreateMutexW DeleteFileW GetFileAttributesW CopyFileW Sleep MoveFileExW GetTickCount SetLastError InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection VerSetConditionMask SleepEx VerifyVersionInfoA FormatMessageA GetProcAddress WaitForMultipleObjects GetFileType GetStdHandle LoadLibraryA ExpandEnvironmentStringsA WideCharToMultiByte InterlockedIncrement InterlockedDecrement MultiByteToWideChar GetStringTypeW GetCurrentThreadId EncodePointer DecodePointer InterlockedExchange DuplicateHandle GetCurrentProcess GetCurrentThread GetSystemTimeAsFileTime GetCommandLineW HeapFree FileTimeToLocalFileTime FindFirstFileExW FileTimeToSystemTime HeapAlloc GetCPInfo IsDebuggerPresent IsProcessorFeaturePresent GetDriveTypeW ExitThread SetFilePointerEx GetFileInformationByHandle GetCurrentProcessId RaiseException RtlUnwind InitializeCriticalSectionAndSpinCount CreateTimerQueue CreateTimerQueueTimer TlsGetValue UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess TlsAlloc TlsSetValue TlsFree GetStartupInfoW CreateSemaphoreW GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ExitProcess GetModuleHandleExW AreFileApisANSI GetProcessHeap QueryPerformanceCounter GetEnvironmentStringsW FreeEnvironmentStringsW HeapSize FlushFileBuffers GetConsoleCP GetConsoleMode GetFullPathNameW GetCurrentDirectoryW IsValidCodePage GetACP GetOEMCP GetTimeZoneInformation ReadConsoleW SetStdHandle DeleteTimerQueueTimer GetProcessAffinityMask SetThreadAffinityMask OutputDebugStringW SwitchToThread GetThreadTimes FreeLibraryAndExitThread GetModuleHandleA SetEvent CreateEventW SetThreadPriority GetVersionExW VirtualAlloc VirtualFree VirtualProtect ReleaseSemaphore InitializeSListHead InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList UnregisterWaitEx ChangeTimerQueueTimer GetNumaHighestNodeNumber RegisterWaitForSingleObject LoadLibraryW WriteConsoleW SetEndOfFile SetEnvironmentVariableA GetThreadPriority UnregisterWait SignalObjectAndWait ReadFile SetFilePointer CloseHandle CreateFileW HeapReAlloc WriteFile |
---|---|
ADVAPI32.dll |
CryptEncrypt
CryptGetHashParam CryptDestroyKey CryptReleaseContext CryptAcquireContextA CryptImportKey CryptCreateHash CryptHashData CryptDestroyHash RegSetValueExW RegCloseKey RegOpenKeyExW RegOpenKeyW RegQueryValueExW |
SHELL32.dll |
SHCreateDirectoryExW
ShellExecuteW |
WS2_32.dll |
socket
WSAIoctl getaddrinfo freeaddrinfo setsockopt sendto accept listen ioctlsocket gethostname ntohs htons getsockopt getsockname getpeername connect closesocket bind send recv WSASetLastError select __WSAFDIsSet WSAGetLastError WSACleanup WSAStartup recvfrom |
WLDAP32.dll |
#301
#200 #30 #79 #35 #33 #32 #27 #26 #22 #41 #50 #60 #211 #46 #143 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2015-Feb-12 18:50:20 |
Version | 0.0 |
SizeofData | 67 |
AddressOfRawData | 0xa4ce8 |
PointerToRawData | 0xa40e8 |
Referenced File | P:\MultiLauncher\Release\MultiLauncher.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2015-Feb-12 18:50:20 |
Version | 0.0 |
SizeofData | 16 |
AddressOfRawData | 0xa4d2c |
PointerToRawData | 0xa412c |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4aeea0 |
SEHandlerTable | 0x4a8160 |
SEHandlerCount | 219 |
XOR Key | 0x8b1b002b |
---|---|
Unmarked objects | 0 |
199 (41118) | 7 |
ASM objects (50929) | 38 |
C++ objects (50929) | 133 |
C objects (50929) | 240 |
C objects (VS2012 UPD4 build 61030) | 76 |
Imports (VS2008 SP1 build 30729) | 11 |
Total imports | 226 |
211 (VS2012 UPD4 build 61030) | 14 |
Resource objects (VS2012 UPD4 build 61030) | 1 |
151 | 1 |
Linker (VS2012 UPD4 build 61030) | 1 |