| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-01 17:18:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\Misc\HSource\ProjectFolder\ProjectFiles\HectraBootstrapperCPP\Release\HectraBootstrapper.pdb
|
| CompanyName | Hectra Nonporation |
| FileDescription | Hectra Bootstrapper |
| FileVersion | 2.0.0.0 |
| InternalName | HectraBS |
| LegalCopyright | Copyright (C) 2026 |
| OriginalFilename | HectraBootstrapper.exe |
| ProductName | Hectra |
| ProductVersion | 2.0.0.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Hectra Nonporation
Issuer: Hectra Nonporation |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-May-01 17:18:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xb4e00 |
| SizeOfInitializedData | 0x118c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0003901D (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xb6000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1d1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1d13f2 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetConsoleCtrlHandler
ReadConsoleW SetStdHandle HeapReAlloc EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetTimeFormatW GetDateFormatW IsValidCodePage HeapFree GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetTimeZoneInformation SetFilePointerEx GetFileSizeEx WriteFile GetStdHandle GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap SetEndOfFile HeapSize WriteConsoleW GetModuleHandleW FindResourceW LoadResource LockResource GetTickCount64 SizeofResource WideCharToMultiByte MoveFileExW CreateProcessW LocalFree GetLastError Sleep GetModuleFileNameW HeapAlloc GetModuleFileNameA ResumeThread ExitThread SystemTimeToFileTime TzSpecificLocalTimeToSystemTime ReadFile FileTimeToSystemTime SystemTimeToTzSpecificLocalTime PeekNamedPipe GetFileType GetDriveTypeW GetModuleHandleExW ExitProcess RaiseException RtlUnwind WaitForSingleObject LoadLibraryW SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW CreateFileW DeleteFileW FindClose FindFirstFileExW FindNextFileW GetDiskFreeSpaceExW GetFileAttributesW GetFileAttributesExW GetFileInformationByHandle GetFullPathNameW RemoveDirectoryW SetFileAttributesW SetFileTime GetTempPathW AreFileApisANSI CloseHandle SetLastError DeviceIoControl GetProcAddress CreateDirectoryExW CopyFileW CreateHardLinkW MultiByteToWideChar FormatMessageW EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection DeleteCriticalSection GetCurrentThreadId DuplicateHandle WaitForSingleObjectEx GetCurrentProcess SwitchToThread GetCurrentThread GetExitCodeThread GetNativeSystemInfo GetStringTypeW QueryPerformanceCounter QueryPerformanceFrequency InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount EncodePointer DecodePointer CompareStringW LCMapStringW GetLocaleInfoW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent SetEvent ResetEvent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId InitializeSListHead CreateTimerQueue SignalObjectAndWait CreateThread SetThreadPriority GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetProcessAffinityMask SetThreadAffinityMask RegisterWaitForSingleObject UnregisterWait OutputDebugStringW GetThreadTimes FreeLibrary FreeLibraryAndExitThread GetModuleHandleA LoadLibraryExW GetVersionExW VirtualAlloc VirtualProtect VirtualFree SetProcessAffinityMask ReleaseSemaphore InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList UnregisterWaitEx WaitForMultipleObjectsEx RtlCaptureStackBackTrace |
|---|---|
| USER32.dll |
LoadImageW
BeginPaint PtInRect PostQuitMessage InvalidateRect EndPaint EnableWindow FindWindowW SetForegroundWindow DrawIconEx GetMessageW DefWindowProcW DestroyWindow FillRect CreateWindowExW GetSystemMetrics MessageBeep RegisterClassExW ShowWindow IsWindow DispatchMessageW SetTimer DestroyIcon TranslateMessage LoadCursorW SetCursor SetWindowLongW GetClientRect DrawTextW |
| GDI32.dll |
BitBlt
AddFontMemResourceEx CreateCompatibleBitmap SelectObject CreateCompatibleDC StretchBlt CreateFontW DeleteDC TextOutW GetTextExtentPoint32W SetTextColor SetBkMode CreatePen GetObjectW SetStretchBltMode DeleteObject CreateSolidBrush RemoveFontMemResourceEx RoundRect |
| ADVAPI32.dll |
RegDeleteKeyW
RegCreateKeyExW RegDeleteTreeW RegSetValueExW RegCloseKey |
| SHELL32.dll |
SHGetFolderPathW
ShellExecuteW SHChangeNotify CommandLineToArgvW |
| WINHTTP.dll |
WinHttpQueryDataAvailable
WinHttpConnect WinHttpSetTimeouts WinHttpSendRequest WinHttpCloseHandle WinHttpOpenRequest WinHttpReadData WinHttpQueryHeaders WinHttpOpen WinHttpReceiveResponse |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.0.0 |
| ProductVersion | 2.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Hectra Nonporation |
| FileDescription | Hectra Bootstrapper |
| FileVersion (#2) | 2.0.0.0 |
| InternalName | HectraBS |
| LegalCopyright | Copyright (C) 2026 |
| OriginalFilename | HectraBootstrapper.exe |
| ProductName | Hectra |
| ProductVersion (#2) | 2.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-01 17:18:02 |
| Version | 0.0 |
| SizeofData | 120 |
| AddressOfRawData | 0xcda98 |
| PointerToRawData | 0xccc98 |
| Referenced File | D:\Misc\HSource\ProjectFolder\ProjectFiles\HectraBootstrapperCPP\Release\HectraBootstrapper.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-01 17:18:02 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xcdb10 |
| PointerToRawData | 0xccd10 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-01 17:18:02 |
| Version | 0.0 |
| SizeofData | 940 |
| AddressOfRawData | 0xcdb24 |
| PointerToRawData | 0xccd24 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-01 17:18:02 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x4cdee0 |
|---|---|
| EndAddressOfRawData | 0x4cdee8 |
| AddressOfIndex | 0x4dd09c |
| AddressOfCallbacks | 0x4b641c |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4d9074 |
| SEHandlerTable | 0x4cd1a0 |
| SEHandlerCount | 574 |
| XOR Key | 0x15c52413 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (27412) | 21 |
| C++ objects (27412) | 187 |
| C objects (27412) | 24 |
| ASM objects (VS 2015/2017 runtime 26706) | 24 |
| C++ objects (VS 2015/2017 runtime 26706) | 123 |
| C objects (VS 2015/2017 runtime 26706) | 38 |
| Imports (27412) | 13 |
| Total imports | 227 |
| C++ objects (LTCG) (27054) | 5 |
| Resource objects (27054) | 1 |
| 151 | 1 |
| Linker (27054) | 1 |
No comments yet.