Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-May-26 12:36:00 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: ESET
Issuer: VeriSign Class 3 Code Signing 2010 CA |
Safe | VirusTotal score: 0/68 (Scanned on 2021-03-27 06:22:29) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2017-May-26 12:36:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 11.0 |
SizeOfCode | 0x10400 |
SizeOfInitializedData | 0x8800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001CBD (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x12000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x1b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x22067 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ExitProcess
IsDebuggerPresent GetStdHandle GetTickCount ReadConsoleA WriteConsoleA GetCommandLineA EncodePointer DecodePointer IsProcessorFeaturePresent GetLastError SetLastError InterlockedIncrement InterlockedDecrement GetCurrentThread GetCurrentThreadId GetModuleHandleExW GetProcAddress AreFileApisANSI MultiByteToWideChar WriteFile GetModuleFileNameW GetProcessHeap GetFileType InitializeCriticalSectionAndSpinCount DeleteCriticalSection GetStartupInfoW GetModuleFileNameA QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime GetEnvironmentStringsW FreeEnvironmentStringsW WideCharToMultiByte UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleW CreateSemaphoreW IsValidCodePage GetACP GetOEMCP GetCPInfo EnterCriticalSection LeaveCriticalSection FatalAppExitA HeapFree Sleep InterlockedExchange FreeLibrary LoadLibraryExW SetConsoleCtrlHandler OutputDebugStringW LoadLibraryW RtlUnwind GetStringTypeW HeapAlloc HeapReAlloc HeapSize GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FlushFileBuffers GetConsoleCP GetConsoleMode SetStdHandle SetFilePointerEx WriteConsoleW CloseHandle CreateFileW |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x418480 |
SEHandlerTable | 0x416ba0 |
SEHandlerCount | 3 |
XOR Key | 0x54fcb0d3 |
---|---|
Unmarked objects | 0 |
C++ objects (50929) | 21 |
ASM objects (50929) | 11 |
C objects (50929) | 87 |
Imports (VS2008 SP1 build 30729) | 3 |
Total imports | 80 |
C++ objects (VS2012 UPD3 build 60610) | 1 |
Linker (VS2012 UPD3 build 60610) | 1 |