| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Mar-09 10:50:30 |
| Detected languages |
English - United States
|
| CompanyName | Embarcadero Technologies, Inc. |
| FileDescription | Embarcadero Memory Manager |
| FileVersion | 25.0.29899.2631 |
| InternalName | Borlndmm |
| LegalCopyright | Copyright © 1996,2018 Embarcadero Technologies, Inc. |
| OriginalFilename | Borlndmm.Dll |
| ProductVersion | 25.0 |
| ProductName | Embarcadero Memory Manager |
| InternalRevision | 92631000 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .didata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC-8 timezone. |
| Info | The PE is digitally signed. |
Signer: Idera
Issuer: Symantec Class 3 SHA256 Code Signing CA |
| Safe | VirusTotal score: 0/67 (Scanned on 2018-07-13 00:38:41) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2018-Mar-09 10:50:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 8.2 |
| SizeOfCode | 0x11800 |
| SizeOfInitializedData | 0x6400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000F780 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x41000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 5.2 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x29000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x24a8a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0 |
| SizeofStackCommit | 0 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x2000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
GetLastError
RtlUnwindEx GetACP CompareStringW LocalFree CloseHandle TlsAlloc WideCharToMultiByte GetTickCount MultiByteToWideChar LoadLibraryA GetVersion VirtualFree RaiseException GetStartupInfoW ExitProcess SwitchToThread InitializeCriticalSection VirtualAlloc WriteFile RtlUnwind GetSystemInfo GetCommandLineW GetProcAddress DeleteCriticalSection TlsGetValue GetStdHandle GetVersionExW TlsSetValue GetModuleHandleW FreeLibrary LocalAlloc GetCurrentThreadId UnhandledExceptionFilter TlsFree VirtualQuery SetThreadLocale Sleep |
|---|---|
| user32.dll |
MessageBoxA
|
| oleaut32.dll |
SysFreeString
|
| kernel32.dll (delay-loaded) |
GetLastError
RtlUnwindEx GetACP CompareStringW LocalFree CloseHandle TlsAlloc WideCharToMultiByte GetTickCount MultiByteToWideChar LoadLibraryA GetVersion VirtualFree RaiseException GetStartupInfoW ExitProcess SwitchToThread InitializeCriticalSection VirtualAlloc WriteFile RtlUnwind GetSystemInfo GetCommandLineW GetProcAddress DeleteCriticalSection TlsGetValue GetStdHandle GetVersionExW TlsSetValue GetModuleHandleW FreeLibrary LocalAlloc GetCurrentThreadId UnhandledExceptionFilter TlsFree VirtualQuery SetThreadLocale Sleep |
| Attributes | 0x1 |
|---|---|
| Name | kernel32.dll |
| ModuleHandle | 0x22060 |
| DelayImportAddressTable | 0x22078 |
| DelayImportNameTable | 0x220a8 |
| BoundDelayImportTable | 0x220d8 |
| UnloadDelayImportTable | 0x220f8 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x1c1b8 |
| Ordinal | 2 |
|---|---|
| Address | 0xbee0 |
| Ordinal | 3 |
|---|---|
| Address | 0xf750 |
| Ordinal | 4 |
|---|---|
| Address | 0xf740 |
| Ordinal | 5 |
|---|---|
| Address | 0xf180 |
| Ordinal | 6 |
|---|---|
| Address | 0xf760 |
| Ordinal | 7 |
|---|---|
| Address | 0xb140 |
| Ordinal | 8 |
|---|---|
| Address | 0xb120 |
| Ordinal | 9 |
|---|---|
| Address | 0xb110 |
| Ordinal | 10 |
|---|---|
| Address | 0xe9c0 |
| Ordinal | 11 |
|---|---|
| Address | 0xe960 |
| Ordinal | 12 |
|---|---|
| Address | 0xe490 |
| Ordinal | 13 |
|---|---|
| Address | 0xe110 |
| Ordinal | 14 |
|---|---|
| Address | 0xdef0 |
| Ordinal | 15 |
|---|---|
| Address | 0xdb20 |
| Ordinal | 16 |
|---|---|
| Address | 0xf710 |
| Ordinal | 17 |
|---|---|
| Address | 0xf6f0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 25.0.29899.2631 |
| ProductVersion | 25.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS_OS232
VOS_OS232_PM32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Embarcadero Technologies, Inc. |
| FileDescription | Embarcadero Memory Manager |
| FileVersion (#2) | 25.0.29899.2631 |
| InternalName | Borlndmm |
| LegalCopyright | Copyright © 1996,2018 Embarcadero Technologies, Inc. |
| OriginalFilename | Borlndmm.Dll |
| ProductVersion (#2) | 25.0 |
| ProductName | Embarcadero Memory Manager |
| InternalRevision | 92631000 |
| Resource LangID | English - United States |
|---|
No comments yet.