Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2018-Jul-01 01:37:51 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\Frédéric\Desktop\Interpreteur_C++\VSProject\Debug\InterpreteurMonCplusplus.pdb
|
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | The PE is possibly packed. | Section .textbss is both writable and executable. |
Info | The PE contains common functions which appear in legitimate applications. |
Possibly launches other programs:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 9 |
TimeDateStamp | 2018-Jul-01 01:37:51 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x49000 |
SizeOfInitializedData | 0x11000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00021406 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x7f000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
MSVCP140D.dll |
?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ
?always_noconv@codecvt_base@std@@QBE_NXZ ?is@?$ctype@D@std@@QBE_NFD@Z ?tolower@?$ctype@D@std@@QBEDD@Z ?tolower@?$ctype@D@std@@QBEPBDPADPBD@Z ?_Getcat@?$ctype@D@std@@SAIPAPBVfacet@locale@2@PBV42@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PBD1AAPBDPAD3AAPAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QBEHAAU_Mbstatet@@PAD1AAPAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SAIPAPBVfacet@locale@2@PBV42@@Z ?good@ios_base@std@@QBE_NXZ ?eof@ios_base@std@@QBE_NXZ ?flags@ios_base@std@@QBEHXZ ?width@ios_base@std@@QBE_JXZ ?width@ios_base@std@@QAE_J_J@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QBE?AVlocale@2@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAPAD0PAH001@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?_Init@locale@std@@CAPAV_Locimp@12@_N@Z ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@D@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UAE@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QAE_N_N@Z ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?_Fiopen@std@@YAPAU_iobuf@@PBDHH@Z ?_Decref@facet@locale@std@@UAEPAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UAEXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z ?_BADOFF@std@@3_JB ?id@?$ctype@D@std@@2V0locale@2@A ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?id@?$collate@D@std@@2V0locale@2@A ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@N@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QAEAAV01@AA_N@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QAEAAV01@AAH@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QAEAAV01@AA_K@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QAEAAV01@AAN@Z ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QAEHXZ ?ignore@?$basic_istream@DU?$char_traits@D@std@@@std@@QAEAAV12@_JH@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?global@locale@std@@SA?AV12@ABV12@@Z ?_Makeloc@_Locimp@locale@std@@CAPAV123@ABV_Locinfo@3@HPAV123@PBV23@@Z ??0_Lockit@std@@QAE@H@Z ?_New_Locimp@_Locimp@locale@std@@CAPAV123@_N@Z ??1facet@locale@std@@MAE@XZ ??0facet@locale@std@@IAE@I@Z ??Bid@locale@std@@QAEIXZ ??3_Crt_new_delete@std@@SAXPAX@Z ??2_Crt_new_delete@std@@SAPAXI@Z ?c_str@?$_Yarn@D@std@@QBEPBDXZ ??4?$_Yarn@D@std@@QAEAAV01@PBD@Z ?_W_Getmonths@_Locinfo@std@@QBEPBGXZ ?_W_Getdays@_Locinfo@std@@QBEPBGXZ ?_Getmonths@_Locinfo@std@@QBEPBDXZ ?_Getdays@_Locinfo@std@@QBEPBDXZ ?_Getcvt@_Locinfo@std@@QBE?AU_Cvtvec@@XZ ?_Getcoll@_Locinfo@std@@QBE?AU_Collvec@@XZ ?_Getname@_Locinfo@std@@QBEPBDXZ ??1_Locinfo@std@@QAE@XZ ??0_Locinfo@std@@QAE@HPBD@Z ??0_Locinfo@std@@QAE@PBD@Z _Strxfrm _Strcoll _Mbrtowc ?_Xruntime_error@std@@YAXPBD@Z ?_Xout_of_range@std@@YAXPBD@Z ?_Xlength_error@std@@YAXPBD@Z ?_Xbad_alloc@std@@YAXXZ ?_Debug_message@std@@YAXPB_W0I@Z ?uncaught_exceptions@std@@YAHXZ ??1_Lockit@std@@QAE@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ |
---|---|
VCRUNTIME140D.dll |
memcpy
memmove memset strchr __std_exception_copy __std_exception_destroy _CxxThrowException __CxxFrameHandler3 __vcrt_InitializeCriticalSectionEx _except_handler4_common __std_type_info_destroy_list __vcrt_GetModuleFileNameW __vcrt_GetModuleHandleW __vcrt_LoadLibraryExW memcmp memchr |
ucrtbased.dll |
_register_onexit_function
_execute_onexit_table _crt_atexit _crt_at_quick_exit _cexit _CrtDbgReport _seh_filter_exe _set_app_type __setusermatherr _get_initial_narrow_environment _initterm _initterm_e exit _exit _set_fmode __p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback _configthreadlocale _set_new_mode _initialize_narrow_environment terminate strcpy_s strcat_s __stdio_common_vsprintf_s _controlfp_s _wmakepath_s _wsplitpath_s wcscpy_s _configure_narrow_argv fsetpos fputc fgetpos fgetc fflush fclose _get_stream_buffer_pointers wcslen system _errno realloc free _invalid_parameter_noinfo _invalid_parameter _initialize_onexit_table _seh_filter_dll malloc _callnewh _malloc_dbg _free_dbg _CrtDbgReportW _calloc_dbg strlen strcmp _unlock_file _lock_file ungetc setvbuf fwrite __p__commode _fseeki64 |
KERNEL32.dll |
CloseHandle
EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW GetProcAddress IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW RaiseException MultiByteToWideChar WideCharToMultiByte GetCurrentProcess TerminateProcess QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetLastError HeapAlloc HeapFree GetProcessHeap VirtualQuery FreeLibrary |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jun-30 19:29:06 |
Version | 0.0 |
SizeofData | 114 |
AddressOfRawData | 0x7013c |
PointerToRawData | 0x4f53c |
Referenced File | C:\Users\Frédéric\Desktop\Interpreteur_C++\VSProject\Debug\InterpreteurMonCplusplus.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jun-30 19:29:06 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x701b0 |
PointerToRawData | 0x4f5b0 |
StartAddressOfRawData | 0x479000 |
---|---|
EndAddressOfRawData | 0x479208 |
AddressOfIndex | 0x475888 |
AddressOfCallbacks | 0x46a928 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x475010 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x50518d7f |
---|---|
Unmarked objects | 0 |
ASM objects (VS2015/2017 runtime 25810) | 1 |
C objects (VS2015/2017 runtime 25810) | 13 |
Imports (VS2015/2017 runtime 25810) | 5 |
C++ objects (VS2015/2017 runtime 25810) | 32 |
Imports (VS2017 v15.?.? build 25203) | 4 |
Total imports | 217 |
C++ objects (VS2017 v15.5.5 build 25835) | 2 |
Resource objects (VS2017 v15.5.5 build 25835) | 1 |
Linker (VS2017 v15.5.5 build 25835) | 1 |