| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1998-Oct-17 06:11:47 |
| Detected languages |
English - United States
|
| CompanyName | Blizzard Entertainment |
| FileDescription | Starcraft |
| FileVersion | Version 1.12 |
| InternalName | Starcraft |
| LegalCopyright | Copyright © 1998 |
| OriginalFilename | Starcraft.exe |
| ProductName | Starcraft |
| ProductVersion | Version 1.04 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C 5.0 MASM/TASM - sig1(h) Microsoft Visual C++ |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 |
| Malicious | The file headers were tampered with. | The RICH header checksum is invalid. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource 202 is possibly compressed or encrypted. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xc0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 1998-Oct-17 06:11:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 5.0 |
| SizeOfCode | 0x102600 |
| SizeOfInitializedData | 0x1fa400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000E5B30 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x104000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x300000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| storm.dll |
#140
#106 #119 #109 #130 #115 #138 #137 #139 #123 #102 #122 #121 #128 #127 #462 #134 #117 #120 #105 #261 #257 #264 #275 #468 #437 #440 #436 #443 #438 #432 #354 #351 #523 #524 #529 #525 #452 #334 #331 #332 #255 #258 #272 #266 #502 #133 #118 #103 #116 #424 #421 #252 #321 #451 #112 #107 #457 #454 #458 #386 #389 #393 #390 #385 #383 #314 #216 #422 #425 #206 #211 #431 #221 #434 #445 #125 #113 #222 #357 #346 #506 #208 #114 #505 #323 #325 #269 #265 #253 #267 #268 #463 #276 #274 #342 #423 #426 #482 #442 #465 #503 #350 #356 #401 #501 #256 #453 #260 #313 #403 |
|---|---|
| SHELL32.dll |
FindExecutableA
ShellExecuteA SHGetSpecialFolderLocation SHGetPathFromIDListA |
| KERNEL32.dll |
HeapDestroy
GetFileType GetStdHandle HeapCreate SetHandleCount GetOEMCP GetACP GetCPInfo GetEnvironmentStringsW GetEnvironmentStrings RtlUnwind UnhandledExceptionFilter WriteFile HeapFree HeapSize HeapAlloc HeapReAlloc GetCurrentProcess TerminateProcess FreeEnvironmentStringsA FreeEnvironmentStringsW TlsGetValue GetLocaleInfoA LCMapStringW LCMapStringA WideCharToMultiByte MultiByteToWideChar ExitProcess GetVersion GetStartupInfoA SetConsoleCtrlHandler ExitThread TlsSetValue CreateThread InterlockedIncrement InterlockedDecrement GetLocalTime GetSystemTime GetTimeZoneInformation FreeLibrary GetFileSize RaiseException SetLastError EnterCriticalSection SetFileAttributesA CompareStringW GetStringTypeA GetStringTypeW SetStdHandle FlushFileBuffers CreateFileA SetFilePointer SetEndOfFile ReadFile GetLocaleInfoW CompareStringA TlsAlloc SetEnvironmentVariableA LoadLibraryA GetProcAddress GetCurrentThreadId SetEvent GetDateFormatA GetTimeFormatA LeaveCriticalSection DeleteCriticalSection InitializeCriticalSection GetModuleFileNameA FindClose FindNextFileA FindFirstFileA DeleteFileA GetTickCount IsBadWritePtr Sleep IsBadReadPtr GetModuleHandleA VirtualQuery lstrcpynA FormatMessageA SetUnhandledExceptionFilter GetLastError CloseHandle WaitForMultipleObjects MulDiv CreateDirectoryA GetLogicalDriveStringsA FileTimeToSystemTime FileTimeToLocalFileTime GetFileAttributesA WaitForSingleObject VirtualProtect VirtualAlloc CreateEventA VirtualFree GetDriveTypeA LockResource GetCommandLineA GlobalMemoryStatus GetDiskFreeSpaceA GetSystemInfo LoadResource SizeofResource FindResourceA CompareFileTime |
| USER32.dll |
DefWindowProcA
SendMessageA ClipCursor LoadStringA LoadAcceleratorsA PtInRect DestroyAcceleratorTable ReleaseCapture SetCapture PostMessageA GetKeyState SetFocus FindWindowA ShowCursor SetCursorPos GetCursorPos SetCursor LoadCursorA EndPaint BeginPaint IsIconic DispatchMessageA TranslateMessage PeekMessageA GetMessageA TranslateAcceleratorA GetWindow GetClassNameA GetForegroundWindow GetDesktopWindow SetRect GetActiveWindow ReleaseDC GetDC GetDlgItem GetWindowLongA InvalidateRect OffsetRect GetWindowRect GetParent SendDlgItemMessageA ShowWindow EnableWindow UpdateWindow DrawTextA GetSysColor GetFocus ScreenToClient GetClientRect SetWindowLongA MessageBoxA SetWindowTextA SetActiveWindow SetForegroundWindow EnumWindows GetWindowThreadProcessId KillTimer SetTimer DialogBoxParamA SetDlgItemTextA SetWindowPos EndDialog CreateWindowExA GetSystemMetrics RegisterClassA LoadIconA GetTopWindow GetLastActivePopup |
| GDI32.dll |
GetDeviceCaps
MoveToEx TextOutA GetPaletteEntries GetStockObject DeleteDC GetTextExtentPoint32A SelectObject CreateCompatibleDC CreateFontIndirectA GetObjectA DeleteObject GetTextMetricsA ExtTextOutA GetTextExtentExPointA SetTextColor SetBkColor SetTextAlign CreateFontA |
| VERSION.dll |
GetFileVersionInfoA
VerQueryValueA GetFileVersionInfoSizeA |
| ADVAPI32.dll |
GetUserNameA
RegDeleteValueA RegOpenKeyA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.12.0.0 |
| ProductVersion | 1.0.4.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Blizzard Entertainment |
| FileDescription | Starcraft |
| FileVersion (#2) | Version 1.12 |
| InternalName | Starcraft |
| LegalCopyright | Copyright © 1998 |
| OriginalFilename | Starcraft.exe |
| ProductName | Starcraft |
| ProductVersion (#2) | Version 1.04 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0xc87c0da9 |
|---|---|
| Unmarked objects | 0 |
| Resource objects (VS97 SP3 cvtres 5.00.1668) | 1 |
| Unmarked objects (#2) | 684 |
| Imports (VS97 SP3 link 5.10.7303) | 116 |
No comments yet.