| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Aug-02 19:46:28 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Suspicious | PEiD Signature: |
FASM 1.5x
FASM v1.5x |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2018-Aug-02 19:46:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xbc00 |
| SizeOfInitializedData | 0xee00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: .code) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xd000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1d000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.DLL |
GetModuleHandleW
HeapCreate HeapDestroy ExitProcess HeapFree HeapAlloc InitializeCriticalSection HeapReAlloc LoadLibraryW GetProcAddress FreeLibrary EnterCriticalSection LeaveCriticalSection GetCurrentProcessId SetLastError GetVersionExW CreateFileW GetFileSize ReadFile CloseHandle GlobalFree GlobalAlloc WriteFile DeleteFileW TlsAlloc DeleteCriticalSection InterlockedCompareExchange Sleep InterlockedExchange |
|---|---|
| COMCTL32.DLL |
InitCommonControlsEx
ImageList_Replace ImageList_Add ImageList_ReplaceIcon ImageList_Remove ImageList_AddMasked ImageList_Destroy ImageList_Create |
| GDI32.DLL |
GetStockObject
GetObjectType GetObjectW DeleteObject SetBkColor SetTextColor SelectObject GetTextExtentPoint32W CreateCompatibleBitmap CreateDCW CreateCompatibleDC DeleteDC SetStretchBltMode StretchBlt CreateSolidBrush GetDeviceCaps CreateBitmap SetPixel CreateDIBSection GetDIBits BitBlt |
| gdiplus.dll |
GdipDeleteFont
GdipDeleteGraphics GdipDeletePath GdipDeleteMatrix GdipDeletePen GdipDeleteStringFormat GdipFree GdipGetDpiX GdipGetDpiY |
| MSVCRT.dll |
memset
_CIlog wcslen wcsncmp wcscmp fabs malloc free ceil floor memcpy fseek ftell fread fclose pow ??3@YAXPAX@Z _wcsnicmp wcsncpy _wcsdup _wcsicmp tolower wcscpy _vsnwprintf |
| OLE32.DLL |
RevokeDragDrop
|
| USER32.DLL |
DestroyWindow
GetWindowLongW GetIconInfo SetWindowPos InvalidateRect UpdateWindow RedrawWindow CallWindowProcW ReleaseCapture BeginPaint DrawStateW EndPaint SetCapture GetWindowRect ScreenToClient SendMessageW GetSystemMetrics CreateWindowExW SetWindowLongW ValidateRect GetParent MapWindowPoints IsWindowEnabled GetSysColor GetSysColorBrush GetDC ReleaseDC GetWindowTextLengthW GetWindowTextW GetWindow SetWindowTextW SetRect DrawTextW GetPropW RemovePropW DefWindowProcW SetPropW MoveWindow FillRect SetActiveWindow DestroyIcon LoadIconW LoadCursorW PeekMessageW MsgWaitForMultipleObjects GetMessageW GetActiveWindow TranslateAcceleratorW TranslateMessage DispatchMessageW RegisterClassW AdjustWindowRectEx ShowWindow CreateAcceleratorTableW UnregisterClassW IsWindowVisible SetFocus GetFocus GetKeyState GetClassNameW GetWindowThreadProcessId IsChild EnumChildWindows DefFrameProcW GetClientRect DestroyAcceleratorTable PostMessageW CreateIconFromResourceEx CreateIconFromResource RegisterWindowMessageW |
No comments yet.