Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Nov-16 09:29:57 |
Detected languages |
English - United States
German - Germany |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2017-Nov-16 09:29:57 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xca00 |
SizeOfInitializedData | 0x1ee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001E0D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xe000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x31000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
HeapFree
InitializeCriticalSectionEx HeapSize GetLastError HeapReAlloc RaiseException HeapAlloc DecodePointer DeleteCriticalSection GetProcessHeap WideCharToMultiByte MultiByteToWideChar CreateMutexA Sleep lstrcmpiW WriteConsoleW FlushFileBuffers SetFilePointerEx GetConsoleMode GetConsoleCP GetStringTypeW SetStdHandle FreeEnvironmentStringsW CloseHandle EnterCriticalSection LeaveCriticalSection CreateEventW GetModuleHandleW GetProcAddress UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead OutputDebugStringW EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW SetLastError RtlUnwind ExitProcess GetModuleHandleExW GetModuleFileNameA GetStdHandle WriteFile GetACP GetFileType LCMapStringW FindClose FindFirstFileExA FindNextFileA IsValidCodePage GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW CreateFileW |
---|---|
USER32.dll |
MessageBoxW
|
ole32.dll |
CoUninitialize
CoCreateInstance CLSIDFromProgID CoInitializeEx |
OLEAUT32.dll |
#8
#12 #9 #2 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Nov-16 09:29:57 |
Version | 0.0 |
SizeofData | 920 |
AddressOfRawData | 0x27e94 |
PointerToRawData | 0x26c94 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Nov-16 09:29:57 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x42b000 |
---|---|
EndAddressOfRawData | 0x42b008 |
AddressOfIndex | 0x429c38 |
AddressOfCallbacks | 0x40e184 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x42900c |
SEHandlerTable | 0x427e70 |
SEHandlerCount | 9 |
XOR Key | 0x3e292404 |
---|---|
Unmarked objects | 0 |
241 (40116) | 9 |
243 (40116) | 124 |
242 (40116) | 24 |
C++ objects (23013) | 2 |
ASM objects (VS2015 UPD3 build 24123) | 19 |
C++ objects (VS2015 UPD3 build 24123) | 39 |
C objects (VS2015 UPD3 build 24123) | 18 |
C objects (65501) | 3 |
Imports (65501) | 9 |
Total imports | 110 |
265 (VS2015 UPD3.1 build 24215) | 8 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
151 | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |