Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2021-Jun-04 02:11:41 |
Detected languages |
English - United States
|
CompanyName | http://360auto.vn |
FileDescription | Auto Rise of Kingdoms |
FileVersion | 2.1.5.6 |
InternalName | Mobot |
LegalCopyright | Copyright (C) 2019 Mobot Company |
ProductName | Mobot Framework |
ProductVersion | 0, 0, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to AES Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/68 (Scanned on 2021-06-10 10:52:32) | APEX: Malicious |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x130 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2021-Jun-04 02:11:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x262e00 |
SizeOfInitializedData | 0xeda00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x002194E3 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x264000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x353000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
CryptAcquireContextW
CryptCreateHash CryptHashData CryptGetHashParam CryptDestroyHash CryptReleaseContext RegEnumKeyW RegSetValueExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegQueryValueW RegEnumValueW RegCloseKey RegOpenKeyExW RegQueryValueExW RegGetValueW RegSetKeyValueW RegEnumKeyExW CryptEncrypt RegDeleteTreeW CryptImportKey CryptDestroyKey CryptGenRandom CryptAcquireContextA |
---|---|
WS2_32.dll |
shutdown
setsockopt connect inet_addr htons socket WSAStartup listen ioctlsocket gethostname recv htonl ntohl ntohs WSACleanup sendto recvfrom freeaddrinfo getaddrinfo WSAIoctl getsockopt getsockname WSAGetLastError send accept getpeername bind WSASetLastError select closesocket __WSAFDIsSet |
CRYPT32.dll |
CertFreeCertificateContext
|
WLDAP32.dll |
#35
#79 #32 #27 #30 #22 #41 #50 #45 #60 #211 #46 #143 #200 #33 #26 #301 |
KERNEL32.dll |
CompareStringW
GetCurrentProcessId GlobalGetAtomNameW GetVersionExW lstrcmpA GetCurrentThread WritePrivateProfileStringW InitializeCriticalSection TlsAlloc TlsGetValue TlsSetValue TlsFree GlobalReAlloc GlobalHandle LocalReAlloc FileTimeToSystemTime GetThreadLocale FileTimeToLocalFileTime GetFileAttributesW GetFileAttributesExW GetFileSizeEx GetFileTime FlushFileBuffers GetFullPathNameW GetVolumeInformationW LockFile SetEndOfFile SetFilePointer UnlockFile DuplicateHandle GetCurrentProcess lstrcmpiW GetLocaleInfoW GetSystemDefaultUILanguage GetUserDefaultUILanguage GlobalFlags lstrcpyW GetCurrentDirectoryW SetErrorMode FindResourceExW GetWindowsDirectoryW VerifyVersionInfoW GetProfileIntW SearchPathW GetTempFileNameW GetUserDefaultLCID UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent ResetEvent QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW SystemTimeToTzSpecificLocalTime LocalAlloc LoadLibraryW LoadLibraryExW GetModuleHandleW OutputDebugStringA GlobalDeleteAtom ReleaseMutex FormatMessageW GlobalSize WaitForMultipleObjects GetFileType GetStdHandle ExpandEnvironmentStringsA VerifyVersionInfoA LoadLibraryA FreeResource GlobalFindAtomW WaitForSingleObjectEx SleepEx FreeLibrary GetTickCount64 FormatMessageA SetLastError VirtualQuery VirtualProtect ResumeThread GetExitCodeThread OpenThread GetCurrentThreadId DeviceIoControl PeekNamedPipe ExitProcess GetProcessHeap HeapDestroy DecodePointer HeapAlloc RaiseException HeapReAlloc HeapSize InitializeCriticalSectionEx HeapFree GetCommandLineW OpenMutexW GetModuleFileNameW CreateMutexW CopyFileW MoveFileExW DeleteFileW GetTempPathW CreateDirectoryW GlobalUnlock GlobalLock GlobalFree GlobalAlloc MulDiv GetNativeSystemInfo ReadProcessMemory GetModuleHandleA GetProcAddress GetExitCodeProcess WriteFile SetNamedPipeHandleState WaitNamedPipeW Sleep SuspendThread FindClose FindNextFileW FindFirstFileW GetPrivateProfileStringW GetPrivateProfileIntW Process32NextW Process32FirstW CreateToolhelp32Snapshot TerminateProcess OpenProcess CreateProcessW MultiByteToWideChar LocalFree DeleteCriticalSection EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount GetLastError TerminateThread FindResourceW LoadResource LockResource SizeofResource ReadFile GetFileSize CreateFileW lstrlenW WideCharToMultiByte lstrlenA GetTickCount WaitForSingleObject SetEvent CloseHandle CreateThread CreateEventW GlobalAddAtomW VerSetConditionMask lstrcmpW GetSystemDirectoryW EncodePointer GetSystemDirectoryA SetThreadPriority OutputDebugStringW GetStringTypeW SwitchToThread GetCPInfo LCMapStringW RtlUnwind GetDriveTypeW GetFileInformationByHandle ExitThread FreeLibraryAndExitThread GetModuleHandleExW SetFilePointerEx GetCommandLineA SetStdHandle HeapQueryInformation GetSystemInfo VirtualAlloc QueryPerformanceFrequency GetConsoleMode ReadConsoleW GetConsoleCP GetDateFormatW GetTimeFormatW IsValidLocale EnumSystemLocalesW GetTimeZoneInformation FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW WriteConsoleW |
USER32.dll |
GetDoubleClickTime
CharUpperBuffW IsClipboardFormatAvailable GetUpdateRect DrawMenuBar DefFrameProcW DefMDIChildProcW TranslateMDISysAccel SubtractRect CreateMenu GetWindowRgn DestroyCursor DestroyAcceleratorTable MoveWindow GetMonitorInfoW MonitorFromWindow WinHelpW GetScrollInfo SetScrollInfo GetLastActivePopup GetTopWindow GetClassLongW EqualRect MapWindowPoints ScreenToClient MessageBoxW AdjustWindowRectEx GetWindowTextLengthW RemovePropW GetPropW SetPropW ShowScrollBar GetScrollRange SetScrollRange GetScrollPos SetScrollPos ScrollWindow EndPaint BeginPaint SetForegroundWindow SetActiveWindow TrackPopupMenu SetMenu GetMenu GetCapture GetDlgCtrlID GetDlgItem EndDeferWindowPos DeferWindowPos BeginDeferWindowPos SetWindowPlacement GetWindowPlacement IsChild GetClassInfoExW GetClassInfoW RegisterClassW GetMessageTime GetMessagePos RegisterWindowMessageW UnhookWindowsHookEx CallNextHookEx SetWindowsHookExW GetActiveWindow PeekMessageW DispatchMessageW TranslateMessage GetMessageW GetDesktopWindow RemoveMenu GetMenuStringW GetClassNameA GetWindowTextA UnregisterClassW CreateAcceleratorTableW IsIconic SendMessageTimeoutW GetForegroundWindow MessageBeep LockWindowUpdate SetWindowRgn SetLayeredWindowAttributes SetRect KillTimer SetTimer IsRectEmpty ReleaseCapture SetCapture PostMessageW EnableMenuItem GetMenuState CheckMenuItem GetMenuItemID DeleteMenu InsertMenuItemW InsertMenuW AppendMenuW LoadMenuW GetMenuItemCount GetSubMenu SetMenuItemInfoW GetMenuItemInfoW IsMenu GetKeyState CallWindowProcW GetWindowTextW UpdateWindow SetFocus SetWindowPos SetWindowTextW ValidateRect SetWindowLongW CreateWindowExW DestroyWindow GrayStringW DrawTextExW TabbedTextOutW SetParent GetParent SystemParametersInfoW GetWindowDC IsZoomed DefWindowProcW RedrawWindow IsWindowVisible FillRect DrawTextW GetFocus GetComboBoxInfo GetSysColor CreateIconIndirect GetIconInfo LoadBitmapW DrawIconEx OffsetRect FrameRect GetClientRect PtInRect ReleaseDC GetDC SendMessageW EnableWindow LoadCursorW SetCursor InvalidateRect GetWindowRect CopyRect GetCursorPos LoadIconW ShowWindow GetWindowLongW FindWindowA FindWindowExW GetKeyboardState ToUnicodeEx MapVirtualKeyExW IsCharLowerW GetKeyboardLayout WaitMessage PostThreadMessageW MonitorFromPoint UpdateLayeredWindow GetWindow GetWindowThreadProcessId GetClassNameW FindWindowW IsWindow wsprintfA RegisterClipboardFormatW DrawIcon CopyIcon SetCursorPos DrawFrameControl DrawEdge DrawStateW EmptyClipboard SetClipboardData CloseClipboard OpenClipboard SetClassLongW EnumDisplayMonitors NotifyWinEvent InvertRect HideCaret EnableScrollBar DrawFocusRect GetMenuDefaultItem GetNextDlgGroupItem InvalidateRgn CopyAcceleratorTableW CharNextW TrackMouseEvent GetSystemMenu UnionRect GetAsyncKeyState RealChildWindowFromPoint CopyImage CharUpperW GetSysColorBrush SetMenuDefaultItem ShowOwnedPopups MapDialogRect SetWindowContextHelpId PostQuitMessage SendDlgItemMessageA ReuseDDElParam UnpackDDElParam LoadImageW DestroyIcon SetRectEmpty CreatePopupMenu TranslateAcceleratorW LoadAcceleratorsW DestroyMenu GetSystemMetrics MapVirtualKeyW GetKeyNameTextW WindowFromPoint GetNextDlgTabItem EndDialog CreateDialogIndirectParamW IntersectRect InflateRect GetMenuCheckMarkDimensions SetMenuItemBitmaps ClientToScreen IsDialogMessageW IsWindowEnabled CheckDlgButton BringWindowToTop ModifyMenuW |
GDI32.dll |
Escape
GetBkMode GetStockObject FloodFill Rectangle CreateBitmap ExtTextOutW CreatePolygonRgn CreateRectRgn CombineRgn FillRgn FrameRgn RectVisible CopyMetaFileW CreateDCW SetBkColor SetTextColor CreateHatchBrush CreatePen CreatePatternBrush ExcludeClipRect GetClipBox GetObjectType GetPixel PtVisible CreateCompatibleBitmap TextOutW GetTextMetricsW SetBitmapBits GetBitmapBits CreateSolidBrush DeleteDC BitBlt SelectObject GetViewportExtEx GetWindowExtEx IntersectClipRect LineTo RestoreDC SaveDC SelectClipRgn ExtSelectClipRgn SelectPalette SetBkMode SetMapMode SetLayout GetLayout CreateCompatibleDC SetROP2 SetTextAlign MoveToEx SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx OffsetViewportOrgEx OffsetWindowOrgEx ScaleViewportExtEx ScaleWindowExtEx CreateRectRgnIndirect GetMapMode PatBlt SetRectRgn DPtoLP GetTextExtentPoint32W GetTextColor GetRgnBox EnumFontFamiliesExW CreatePalette GetNearestPaletteIndex GetPaletteEntries GetSystemPaletteEntries RealizePalette CreateDIBitmap EnumFontFamiliesW GetTextCharsetInfo SetPixel StretchBlt CreateDIBSection SetDIBColorTable CreateEllipticRgn Ellipse Polygon Polyline CreateRoundRectRgn LPtoDP OffsetRgn GetBoundsRect PtInRegion ExtFloodFill SetPaletteEntries SetPixelV GetWindowOrgEx GetViewportOrgEx GetTextFaceW DeleteObject RoundRect CreateFontIndirectW GetObjectW CreateFontW GetDeviceCaps SetPolyFillMode GetBkColor |
MSIMG32.dll |
AlphaBlend
TransparentBlt GradientFill |
WINSPOOL.DRV |
ClosePrinter
OpenPrinterW DocumentPropertiesW |
SHELL32.dll |
SHGetDesktopFolder
SHGetSpecialFolderLocation SHGetPathFromIDListW SHGetFileInfoW DragFinish DragQueryFileW Shell_NotifyIconW ShellExecuteW SHGetFolderPathW CommandLineToArgvW SHBrowseForFolderW SHAppBarMessage |
COMCTL32.dll |
InitCommonControlsEx
_TrackMouseEvent |
SHLWAPI.dll |
PathRemoveFileSpecW
StrStrIW PathFindFileNameW PathFindExtensionW PathIsUNCW PathStripToRootW StrFormatKBSizeW PathFileExistsW |
UxTheme.dll |
DrawThemeBackground
IsThemeBackgroundPartiallyTransparent DrawThemeParentBackground OpenThemeData CloseThemeData DrawThemeText IsAppThemed GetThemeColor GetCurrentThemeName GetWindowTheme GetThemeSysColor GetThemePartSize |
ole32.dll |
CoGetClassObject
StgCreateDocfileOnILockBytes CreateStreamOnHGlobal CoTaskMemAlloc CoTaskMemFree OleDuplicateData ReleaseStgMedium CoUninitialize CoInitializeEx CoCreateInstance CoCreateGuid CLSIDFromString CLSIDFromProgID CoInitialize StgOpenStorageOnILockBytes IsAccelerator OleTranslateAccelerator OleDestroyMenuDescriptor OleCreateMenuDescriptor OleLockRunning CoRegisterMessageFilter CoRevokeClassObject RevokeDragDrop RegisterDragDrop CoLockObjectExternal OleGetClipboard DoDragDrop OleIsCurrentClipboard OleFlushClipboard OleUninitialize OleInitialize CoFreeUnusedLibraries CreateILockBytesOnHGlobal CoDisconnectObject |
OLEAUT32.dll |
SysStringLen
SystemTimeToVariantTime VariantTimeToSystemTime SafeArrayDestroy VariantCopy SysAllocString VariantChangeType VariantClear VariantInit SysFreeString SysAllocStringLen OleCreateFontIndirect VarBstrFromDate LoadTypeLib |
oledlg.dll |
OleUIBusyW
|
gdiplus.dll |
GdipAlloc
GdipCloneBrush GdipFillPolygonI GdiplusStartup GdiplusShutdown GdipDrawImageRectI GdipCloneImage GdipDisposeImage GdipCreateBitmapFromResource GdipGetImageGraphicsContext GdipGetImagePixelFormat GdipGetImagePalette GdipGetImagePaletteSize GdipCreateBitmapFromStream GdipFree GdipCreateBitmapFromScan0 GdipBitmapLockBits GdipBitmapUnlockBits GdipDrawImageI GdipCreateBitmapFromHBITMAP GdipCreateSolidFill GdipRotateWorldTransform GdipTranslateWorldTransform GdipSetInterpolationMode GdipSetSmoothingMode GdipDrawImageRectRectI GdipGetImageWidth GdipGetImageHeight GdipSetImageAttributesColorMatrix GdipDisposeImageAttributes GdipCreateImageAttributes GdipDeleteGraphics GdipCreateFromHDC GdipDeleteBrush |
VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueA |
WININET.dll |
InternetReadFile
InternetOpenW InternetCloseHandle InternetConnectW InternetWriteFile InternetQueryDataAvailable InternetSetOptionW InternetGetLastResponseInfoW InternetSetStatusCallbackW HttpOpenRequestW HttpEndRequestW HttpSendRequestExW HttpSendRequestW HttpAddRequestHeadersW InternetSetFilePointer |
OLEACC.dll |
CreateStdAccessibleObject
AccessibleObjectFromWindow LresultFromObject |
IMM32.dll |
ImmGetContext
ImmReleaseContext ImmGetOpenStatus |
WINMM.dll |
PlaySoundW
|
Open |
Save As |
All Files (*.*) |
Untitled |
an unnamed file |
&Hide |
No error message is available. |
Attempted an unsupported operation. |
A required resource was unavailable. |
Out of memory. |
An unknown error has occurred. |
Encountered an improper argument. |
Incorrect filename. |
Failed to open document. |
Failed to save document. |
Save changes to %1? |
Failed to create empty document. |
The file is too large to open. |
Could not start print job. |
Failed to launch help. |
Internal application error. |
Command failed. |
Insufficient memory to perform operation. |
System registry entries have been removed and the INI file (if any) was deleted. |
Not all of the system registry entries (or INI file) were removed. |
This program requires the file %Ts, which was not found on this system. |
This program is linked to the missing export %Ts in the file %Ts. This machine may have an incompatible version of %Ts. |
Enter an integer. |
Enter a number. |
Enter an integer between %1 and %2. |
Enter a number between %1 and %2. |
Enter no more than %1 characters. |
Select a button. |
Enter an integer between 0 and 255. |
Enter a positive integer. |
Enter a date and/or time. |
Enter a currency. |
Enter a GUID. |
Enter a time. |
Enter a date. |
Unexpected file format. |
%1 |
Cannot find this file. |
Verify that the correct path and file name are given. |
Destination disk drive is full. |
Unable to read from %1, it is opened by someone else. |
Unable to write to %1, it is read-only or opened by someone else. |
Encountered an unexpected error while reading %1. |
Encountered an unexpected error while writing %1. |
%1: %2 |
Continue running script? |
Dispatch exception: %1 |
Unable to read write-only property. |
Unable to write read-only property. |
Unable to load mail system support. |
Mail system DLL is invalid. |
Send Mail failed to send message. |
No error occurred. |
An unknown error occurred while accessing %1. |
%1 was not found. |
%1 contains an incorrect path. |
Could not open %1 because there are too many open files. |
Access to %1 was denied. |
An incorrect file handle was associated with %1. |
Could not remove %1 because it is the current directory. |
Could not create %1 because the directory is full. |
Seek failed on %1 |
Encountered a hardware I/O error while accessing %1. |
Encountered a sharing violation while accessing %1. |
Encountered a locking violation while accessing %1. |
Disk full while accessing %1. |
Attempted to access %1 past its end. |
No error occurred. |
An unknown error occurred while accessing %1. |
Attempted to write to the reading %1. |
Attempted to access %1 past its end. |
Attempted to read from the writing %1. |
%1 has a bad format. |
%1 contained an unexpected object. |
%1 contains an incorrect schema. |
pixels |
Uncheck |
Check |
Mixed |
One or more auto-saved documents were found. |
These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
Do you want to recover these auto-saved documents? |
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
Recover the auto-saved documents |
Open the auto-saved versions instead of the explicitly saved versions |
Don't recover the auto-saved documents |
Use the last explicitly saved versions of the documents |
%Ts [Recovered] |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 2.1.5.6 |
ProductVersion | 0.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | http://360auto.vn |
FileDescription | Auto Rise of Kingdoms |
FileVersion (#2) | 2.1.5.6 |
InternalName | Mobot |
LegalCopyright | Copyright (C) 2019 Mobot Company |
ProductName | Mobot Framework |
ProductVersion (#2) | 0, 0, 0, 0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Jun-04 02:11:41 |
Version | 0.0 |
SizeofData | 956 |
AddressOfRawData | 0x2d0e74 |
PointerToRawData | 0x2d0074 |
StartAddressOfRawData | 0x6d1240 |
---|---|
EndAddressOfRawData | 0x6d1248 |
AddressOfIndex | 0x6f7834 |
AddressOfCallbacks | 0x664fa0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x6ee6ac |
SEHandlerTable | 0x6cfb50 |
SEHandlerCount | 1225 |
XOR Key | 0x50f7d1c3 |
---|---|
Unmarked objects | 0 |
ASM objects (26213) | 31 |
199 (41118) | 6 |
C objects (26213) | 38 |
C++ objects (26213) | 216 |
262 (26213) | 3 |
C objects (VS 2015/2017 runtime 26706) | 35 |
ASM objects (VS 2015/2017 runtime 26706) | 27 |
C++ objects (VS 2015/2017 runtime 26706) | 384 |
Total imports | 948 |
Imports (26213) | 47 |
C objects (27038) | 97 |
C++ objects (27043) | 8 |
C objects (VS2008 SP1 build 30729) | 10 |
265 (27043) | 128 |
Resource objects (27043) | 1 |
151 | 1 |
Linker (27043) | 1 |