Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Oct-01 16:42:34 |
Detected languages |
English - United States
|
Debug artifacts |
G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb
|
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to AES |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 11/71 (Scanned on 2024-10-01 16:43:00) |
ALYac:
Gen:Variant.Zusy.562532
Arcabit: Trojan.Zusy.D89564 BitDefender: Gen:Variant.Zusy.562532 Bkav: W32.AIDetectMalware CTX: exe.unknown.zusy Emsisoft: Gen:Variant.Zusy.562532 (B) FireEye: Gen:Variant.Zusy.562532 GData: Gen:Variant.Zusy.562532 Jiangmin: Trojan.Agent.exve MicroWorld-eScan: Gen:Variant.Zusy.562532 VIPRE: Gen:Variant.Zusy.562532 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x160 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2024-Oct-01 16:42:34 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x436600 |
SizeOfInitializedData | 0x1caa400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x003E1432 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x438000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x20e4000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoA GetFileVersionInfoSizeA |
---|---|
WINMM.dll |
timeGetTime
|
WS2_32.dll |
socket
recv send inet_ntoa gethostbyname WSAAsyncSelect connect setsockopt inet_addr closesocket WSAStartup WSAGetLastError htons |
DDRAW.dll |
DirectDrawCreate
|
KERNEL32.dll |
InitializeCriticalSection
FindFirstFileA FindClose GetCurrentDirectoryA SetCurrentDirectoryA GlobalAlloc GlobalFree GlobalLock CreateDirectoryA GlobalUnlock GetFileSize EnterCriticalSection LeaveCriticalSection WaitForSingleObject SetEvent CreateEventA GetLocaleInfoA CompareStringA GetSystemDirectoryA WaitForSingleObjectEx FindNextFileA GetCurrentThreadId FormatMessageA LocalFree FileTimeToLocalFileTime GlobalMemoryStatusEx IsDBCSLeadByte GetSystemInfo TerminateProcess GetVolumeInformationA CheckRemoteDebuggerPresent IsDebuggerPresent GetProcessHeap ExitProcess DeleteCriticalSection GetThreadContext DecodePointer WriteConsoleW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW CreateDirectoryW DeleteFileW FlushFileBuffers GetOEMCP GetACP Sleep GetFileSizeEx HeapAlloc SetEndOfFile SetStdHandle GetTimeZoneInformation EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW GetSystemTime GetStdHandle FindNextFileW FindFirstFileExW GetCurrentDirectoryW SetCurrentDirectoryW SetEnvironmentVariableW GetFullPathNameW SystemTimeToTzSpecificLocalTime GetDriveTypeW GetConsoleOutputCP ReadConsoleW GetConsoleMode SetFilePointerEx GetFileType GetModuleHandleExW FreeLibraryAndExitThread ExitThread LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc SetLastError CreateThread RaiseException HeapReAlloc GetCurrentThread HeapSize InitializeCriticalSectionEx OutputDebugStringA HeapFree VirtualProtect GetVersionExA DeviceIoControl CreateIoCompletionPort CancelIo GetModuleHandleA GetLocalTime FileTimeToSystemTime QueryPerformanceCounter MultiByteToWideChar GetModuleFileNameW lstrlenW WaitNamedPipeW GetCurrentProcessId CloseHandle GetLastError CreateFileW PeekNamedPipe RtlUnwind VirtualAlloc VirtualFree InterlockedCompareExchange InterlockedExchange GetTempPathW GetModuleHandleW UnmapViewOfFile CreateFileMappingA MapViewOfFile OutputDebugStringW WideCharToMultiByte FreeLibrary GetProcAddress lstrcpyA QueryPerformanceFrequency LoadLibraryA CreateFileA lstrlenA GetFullPathNameA GetModuleFileNameA GetPrivateProfileStringA WritePrivateProfileStringA GetTickCount GetCPInfo CompareStringEx LCMapStringEx EncodePointer WriteFile ReadFile IsValidCodePage GetFileInformationByHandle GetPrivateProfileIntA GetCurrentProcess lstrcmpiA GetComputerNameA GetCommandLineA IsBadReadPtr SetUnhandledExceptionFilter CopyFileA InitializeCriticalSectionAndSpinCount ResetEvent CreateEventW UnhandledExceptionFilter IsProcessorFeaturePresent GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive TryEnterCriticalSection InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableCS SleepConditionVariableSRW GetExitCodeThread GetStringTypeW |
USER32.dll |
TranslateMessage
SetFocus SetRect MessageBoxA GetWindowTextLengthA UnregisterClassA EnumWindows GetWindowTextA GetClassNameA UpdateWindow RegisterClassExA PostQuitMessage PeekMessageA GetClientRect SystemParametersInfoA LoadIconA SetCursor LoadStringA PostMessageA CreateWindowExA GetDC SetWindowTextA GetDesktopWindow wvsprintfW GetKeyboardLayout ClientToScreen ShowCursor SetCursorPos OffsetRect CopyRect GetWindowRect SetWindowPos ScreenToClient SetWindowLongA MoveWindow GetCursorPos PtInRect GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData FlashWindowEx ReleaseDC wsprintfA DefWindowProcA DefWindowProcW GetMessageA DispatchMessageA GetFocus LoadCursorA DestroyWindow FillRect GetSystemMetrics ShowWindow AdjustWindowRect SendMessageA |
GDI32.dll |
GetTextExtentPoint32W
MoveToEx ExtTextOutA SetTextAlign CreateFontIndirectW CreateFontIndirectA GetFontLanguageInfo GetTextMetricsW SetBkMode GetCharacterPlacementW GetCharacterPlacementA GetGlyphOutlineA GetTextMetricsA GetObjectW GetObjectA CreateSolidBrush CreateDIBSection SetTextColor SetBkColor SetMapMode CreateFontA SetDeviceGammaRamp GetTextExtentPoint32A GetDeviceGammaRamp ExtTextOutW CreateDCA BitBlt CreateCompatibleBitmap SelectObject CreateCompatibleDC DeleteDC DeleteObject |
ADVAPI32.dll |
RegOpenKeyA
GetUserNameA RegCloseKey RegOpenKeyExA RegCreateKeyExW RegQueryValueExA RegSetValueExW |
SHELL32.dll |
SHBrowseForFolderA
SHGetMalloc ShellExecuteA SHGetPathFromIDListA |
ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize |
OLEAUT32.dll |
SysStringLen
VariantInit SystemTimeToVariantTime VariantClear |
IPHLPAPI.DLL |
GetAdaptersInfo
|
gdiplus.dll |
GdiplusShutdown
GdiplusStartup GdipSaveImageToFile GdipCloneImage GdipAlloc GdipCreateBitmapFromHBITMAP GdipDisposeImage GdipFree |
IMM32.dll |
ImmIsIME
ImmGetCandidateListW ImmNotifyIME ImmSetConversionStatus ImmGetOpenStatus ImmAssociateContext ImmGetIMEFileNameA ImmGetCompositionStringW ImmGetProperty ImmGetConversionStatus ImmReleaseContext ImmGetContext |
d3d9.dll |
Direct3DCreate9
|
DINPUT8.dll |
DirectInput8Create
|
DSOUND.dll |
#11
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_STATIC_LIB
|
Language | UNKNOWN |
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion (#2) | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:42:34 |
Version | 0.0 |
SizeofData | 107 |
AddressOfRawData | 0x49d5dc |
PointerToRawData | 0x49bfdc |
Referenced File | G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:42:34 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x49d648 |
PointerToRawData | 0x49c048 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:42:34 |
Version | 0.0 |
SizeofData | 956 |
AddressOfRawData | 0x49d65c |
PointerToRawData | 0x49c05c |
StartAddressOfRawData | 0x89da28 |
---|---|
EndAddressOfRawData | 0x89da30 |
AddressOfIndex | 0x8c444c |
AddressOfCallbacks | 0x838d54 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xbc |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x8b0348 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x6ddff1 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 46 |
C++ objects (27412) | 228 |
Imports (VS2003 (.NET) build 4035) | 2 |
C objects (VS2003 (.NET) build 4035) | 1 |
C objects (2067) | 12 |
18 (8444) | 6 |
253 (28518) | 3 |
C++ objects (30034) | 94 |
C objects (30034) | 22 |
ASM objects (30034) | 29 |
C objects (30154) | 10 |
C objects (27412) | 35 |
Imports (9210) | 6 |
C objects (9178) | 2 |
C++ objects (VS2003 (.NET) build 4035) | 127 |
Imports (27412) | 29 |
Total imports | 416 |
C objects (VC++ 6.0 SP5 build 8804) | 78 |
C++ objects (LTCG) (30154) | 472 |
Resource objects (30154) | 1 |
151 | 1 |
Linker (30154) | 1 |