Architecture |
Subsystem |
Compilation Date | 2025-Feb-04 12:04:18 |
Detected languages |
English - United States
Info | Matching compiler(s): | MASM/TASM - sig2(h) |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
Machine |
NumberofSections | 5 |
TimeDateStamp | 2025-Feb-04 12:04:18 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 14.0 |
SizeOfCode | 0xc800 |
SizeOfInitializedData | 0xac00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000141C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xe000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
DllCharacteristics |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SDL3.dll |
SDL_Delay SDL_SetRenderVSync SDL_RenderPresent SDL_RenderClear SDL_Init SDL_CreateWindowAndRenderer SDL_EnterAppMainCallbacks SDL_RunApp |
KERNEL32.dll |
DecodePointer WriteConsoleW HeapSize CreateFileW FlushFileBuffers GetProcessHeap LCMapStringW UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RaiseException RtlUnwind GetLastError SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW GetStdHandle WriteFile GetModuleFileNameW ExitProcess HeapFree HeapAlloc HeapReAlloc CloseHandle GetConsoleMode SetFilePointerEx GetFileType GetConsoleOutputCP FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle GetStringTypeW |
Characteristics |
TimeDateStamp | 2025-Feb-04 12:04:18 |
Version | 0.0 |
SizeofData | 752 |
AddressOfRawData | 0x152ac |
PointerToRawData | 0x13eac |
Size | 0xc0 |
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x417040 |
SEHandlerTable | 0x4151dc |
SEHandlerCount | 10 |
XOR Key | 0x496f0314 |
Unmarked objects | 0 |
ASM objects (30795) | 10 |
C++ objects (30795) | 153 |
C objects (30795) | 20 |
ASM objects (34321) | 20 |
C objects (34321) | 18 |
C++ objects (34321) | 41 |
Imports (30795) | 2 |
Imports (34436) | 3 |
Total imports | 91 |
C++ objects (34436) | 2 |
Resource objects (34436) | 1 |
Linker (34436) | 1 |