Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2013-Sep-02 17:12:32 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/74 (Scanned on 2024-08-04 23:27:05) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2013-Sep-02 17:12:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x53000 |
SizeOfInitializedData | 0xd800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00052CC0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x54000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x64000 |
SizeOfHeaders | 0x400 |
Checksum | 0x69ec2 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WS2_32.dll |
send
select __WSAFDIsSet sendto recvfrom ioctlsocket listen accept WSAStartup WSACleanup gethostname getaddrinfo freeaddrinfo getpeername WSAIoctl connect htons ntohs getsockname setsockopt recv bind socket WSASetLastError closesocket getsockopt WSAGetLastError |
---|---|
WLDAP32.dll |
#211
#301 #27 #33 #79 #30 #60 #26 #41 #46 #50 #22 #35 #32 #200 #143 |
KERNEL32.dll |
GetLastError
GetCurrentThreadId GetSystemTimeAsFileTime GetCurrentProcessId IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess InterlockedCompareExchange InterlockedExchange SetFileAttributesA GetFileAttributesA QueryPerformanceCounter GetTickCount WaitForMultipleObjects GetFileType LoadLibraryA GetProcAddress GetStdHandle ReadFile FreeLibrary PeekNamedPipe FormatMessageA Sleep ExpandEnvironmentStringsA CloseHandle InitializeCriticalSection LeaveCriticalSection WaitForSingleObject SetLastError EnterCriticalSection DeleteCriticalSection SleepEx GetVersionExA |
ADVAPI32.dll |
CryptDestroyHash
CryptCreateHash CryptAcquireContextA CryptReleaseContext CryptGetHashParam CryptHashData |
MSVCR90.dll |
fflush
fwrite strerror __sys_nerr atoi fseek _stricmp memmove_s ?what@exception@std@@UBEPBDXZ ??1exception@std@@UAE@XZ ??0exception@std@@QAE@XZ ??0exception@std@@QAE@ABQBD@Z _CxxThrowException rewind _invalid_parameter_noinfo printf fprintf ??3@YAXPAX@Z ftell _vscprintf exit ??2@YAPAXI@Z ?terminate@@YAXXZ _vsnprintf _unlock __dllonexit _encode_pointer _lock _onexit _decode_pointer _amsg_exit __getmainargs _cexit _exit _XcptFilter __initenv _initterm _initterm_e _configthreadlocale __setusermatherr _adjust_fdiv __p__commode __p__fmode __set_app_type _crt_debugger_hook _except_handler4_common ?_type_info_dtor_internal_method@type_info@@QAEXXZ _invoke_watson _controlfp_s _gmtime64 sprintf fputc memchr tolower getenv strncpy fread _stat64 _lseeki64 strtoul realloc malloc calloc free _beginthreadex strstr isxdigit islower isupper isdigit isalpha isprint isalnum isspace isgraph _time64 fclose strrchr fopen fgets strtol strchr __iob_func fputs _strtoi64 qsort memmove sscanf strncmp _errno _strdup _read _close _open _write _strnicmp _mkdir memcpy __CxxFrameHandler3 memset _fstat64 ??0exception@std@@QAE@ABV01@@Z |
MSVCP90.dll |
?replace@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@IIPBD@Z
?clear@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXXZ ?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBD@Z ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDI@Z ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIABV12@I@Z ?at@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEABDI@Z ?deallocate@?$allocator@D@std@@QAEXPADI@Z ?allocate@?$allocator@D@std@@QAEPADI@Z ?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z ??$?9DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z |
WINMM.dll |
timeGetTime
|
Ordinal | 1 |
---|---|
Address | 0xa160 |
Ordinal | 2 |
---|---|
Address | 0xa220 |
Ordinal | 3 |
---|---|
Address | 0xaa50 |
Ordinal | 4 |
---|---|
Address | 0xa1d0 |
Ordinal | 5 |
---|---|
Address | 0x9e80 |
Ordinal | 6 |
---|---|
Address | 0xa620 |
Ordinal | 7 |
---|---|
Address | 0x9f20 |
Ordinal | 8 |
---|---|
Address | 0xa870 |
Ordinal | 9 |
---|---|
Address | 0xa510 |
Ordinal | 10 |
---|---|
Address | 0xa8e0 |
Ordinal | 11 |
---|---|
Address | 0x9ed0 |
Ordinal | 12 |
---|---|
Address | 0x37820 |
Ordinal | 13 |
---|---|
Address | 0xad80 |
Ordinal | 14 |
---|---|
Address | 0xaa10 |
Ordinal | 15 |
---|---|
Address | 0xcc10 |
Ordinal | 16 |
---|---|
Address | 0xd020 |
Ordinal | 17 |
---|---|
Address | 0xced0 |
Ordinal | 18 |
---|---|
Address | 0xade0 |
Ordinal | 19 |
---|---|
Address | 0x2b580 |
Ordinal | 20 |
---|---|
Address | 0x16750 |
Ordinal | 21 |
---|---|
Address | 0x9e20 |
Ordinal | 22 |
---|---|
Address | 0x9cd0 |
Ordinal | 23 |
---|---|
Address | 0x9d90 |
Ordinal | 24 |
---|---|
Address | 0x26d10 |
Ordinal | 25 |
---|---|
Address | 0x26f00 |
Ordinal | 26 |
---|---|
Address | 0x26ec0 |
Ordinal | 27 |
---|---|
Address | 0x26bf0 |
Ordinal | 28 |
---|---|
Address | 0x26e80 |
Ordinal | 29 |
---|---|
Address | 0x272c0 |
Ordinal | 30 |
---|---|
Address | 0x2a770 |
Ordinal | 31 |
---|---|
Address | 0x294a0 |
Ordinal | 32 |
---|---|
Address | 0x27a00 |
Ordinal | 33 |
---|---|
Address | 0x29640 |
Ordinal | 34 |
---|---|
Address | 0x272a0 |
Ordinal | 35 |
---|---|
Address | 0x292f0 |
Ordinal | 36 |
---|---|
Address | 0x27560 |
Ordinal | 37 |
---|---|
Address | 0x29e50 |
Ordinal | 38 |
---|---|
Address | 0x2a0c0 |
Ordinal | 39 |
---|---|
Address | 0x2a100 |
Ordinal | 40 |
---|---|
Address | 0x2a140 |
Ordinal | 41 |
---|---|
Address | 0x37ca0 |
Ordinal | 42 |
---|---|
Address | 0x2a280 |
Ordinal | 43 |
---|---|
Address | 0x27bd0 |
Ordinal | 44 |
---|---|
Address | 0x26db0 |
Ordinal | 45 |
---|---|
Address | 0x26fa0 |
Ordinal | 46 |
---|---|
Address | 0x26f70 |
Ordinal | 47 |
---|---|
Address | 0x26b90 |
Ordinal | 48 |
---|---|
Address | 0x26f40 |
Ordinal | 49 |
---|---|
Address | 0x32e40 |
Ordinal | 50 |
---|---|
Address | 0x32bc0 |
Ordinal | 51 |
---|---|
Address | 0x32bf0 |
Ordinal | 52 |
---|---|
Address | 0x37d30 |
Ordinal | 53 |
---|---|
Address | 0x33070 |
Ordinal | 54 |
---|---|
Address | 0x33120 |
Ordinal | 55 |
---|---|
Address | 0x377d0 |
Ordinal | 56 |
---|---|
Address | 0x377f0 |
Ordinal | 57 |
---|---|
Address | 0xaa30 |
Ordinal | 58 |
---|---|
Address | 0x48690 |
Ordinal | 59 |
---|---|
Address | 0x48790 |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x462018 |
SEHandlerTable | 0x45ecd0 |
SEHandlerCount | 33 |
XOR Key | 0x91554324 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 4 |
150 (20413) | 13 |
ASM objects (VS2008 SP1 build 30729) | 11 |
C objects (VS2008 SP1 build 30729) | 22 |
C++ objects (VS2008 SP1 build 30729) | 4 |
Total imports | 289 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 13 |
137 (VS2008 SP1 build 30729) | 119 |
Exports (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |