| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1994-Jul-29 04:43:18 |
| Detected languages |
English - United States
|
| Debug artifacts |
LiveCaptions.pdb
|
| CompanyName | Apple Captions Inc. |
| FileDescription | AppleCaptions |
| FileVersion | 1.0.0.0 |
| InternalName | AppleCaptions.exe |
| LegalCopyright | © 2026 Apple Captions Inc. All rights reserved. |
| OriginalFilename | AppleCaptions.exe |
| ProductName | AppleCaptions |
| ProductVersion | 1.0.0.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 8.0 |
| Suspicious | The PE is possibly packed. | Unusual section name found: fothk |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 1994-Jul-29 04:43:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd000 |
| SizeOfInitializedData | 0x20000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001530 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2e000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x37a45 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCreateKeyExW
RegSetValueExW RegCloseKey |
|---|---|
| KERNEL32.dll |
GetModuleFileNameA
CreateSemaphoreExW HeapFree SetLastError EnterCriticalSection ReleaseSemaphore GetModuleHandleExW LeaveCriticalSection InitializeCriticalSectionEx WaitForThreadpoolTimerCallbacks WaitForSingleObject GetCurrentThreadId ReleaseMutex FormatMessageW GetLastError ReleaseSRWLockExclusive OutputDebugStringW CloseThreadpoolTimer AcquireSRWLockExclusive WaitForSingleObjectEx OpenSemaphoreW CloseHandle SetThreadpoolTimer ReleaseSRWLockShared CreateThreadpoolTimer HeapAlloc GetProcAddress CreateMutexExW AcquireSRWLockShared DeleteCriticalSection GetCurrentProcessId GetProcessHeap GetModuleHandleW WideCharToMultiByte DebugBreak IsDebuggerPresent GetCommandLineW LocalFree RaiseException GetSystemDirectoryW CreateProcessW LoadLibraryExW FreeLibrary InterlockedPushEntrySList |
| msvcp_win.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
_register_thread_local_exe_atexit_callback _initterm_e _initterm |
| api-ms-win-crt-private-l1-1-0.dll |
_o___std_exception_copy
_o___std_exception_destroy _o___stdio_common_vswprintf _o__callnewh _o__cexit _o__configthreadlocale _o__configure_wide_argv _o__crt_atexit _o__errno _o__exit _o__get_wide_winmain_command_line _o__initialize_onexit_table _o__initialize_wide_environment _o__invalid_parameter_noinfo _o__invalid_parameter_noinfo_noreturn _o__purecall _o__register_onexit_function _o__seh_filter_exe _o__set_app_type _o__set_fmode _o__set_new_mode _o__wcsicmp _o_abort _o_exit _o_free _o_iswspace _o_malloc _o_terminate __C_specific_handler __current_exception __current_exception_context __CxxFrameHandler3 _CxxThrowException __std_terminate __CxxFrameHandler4 memcmp memcpy _o___p__commode memmove |
| api-ms-win-crt-string-l1-1-0.dll |
memset
|
| ntdll.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind |
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
RoUninitialize |
| api-ms-win-shcore-obsolete-l1-1-0.dll |
CommandLineToArgvW
|
| api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsCreateStringReference
|
| api-ms-win-core-com-l1-1-0.dll |
CoInitializeEx
|
| api-ms-win-core-path-l1-1-0.dll |
PathCchAppend
|
| api-ms-win-core-winrt-error-l1-1-0.dll |
RoOriginateError
|
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTimeAsFileTime
|
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
|
| api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetCurrentProcess
TerminateProcess GetStartupInfoW |
| api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
|
| api-ms-win-appmodel-runtime-internal-l1-1-7.dll |
AddDependencyToProcessPackageGraph
|
| OLEAUT32.dll |
SysStringLen
SysFreeString GetErrorInfo SetErrorInfo |
| api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Apple Captions Inc. |
| FileDescription | AppleCaptions |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | AppleCaptions.exe |
| LegalCopyright | © 2026 Apple Captions Inc. All rights reserved. |
| OriginalFilename | AppleCaptions.exe |
| ProductName | AppleCaptions |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1994-Jul-29 04:43:18 |
| Version | 0.0 |
| SizeofData | 41 |
| AddressOfRawData | 0xf848 |
| PointerToRawData | 0xf848 |
| Referenced File | LiveCaptions.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1994-Jul-29 04:43:18 |
| Version | 0.0 |
| SizeofData | 920 |
| AddressOfRawData | 0xf874 |
| PointerToRawData | 0xf874 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1994-Jul-29 04:43:18 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0xfc34 |
| PointerToRawData | 0xfc34 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1994-Jul-29 04:43:18 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0xfc58 |
| PointerToRawData | 0xfc58 |
| Size | 0x148 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400135c0 |
| GuardCFCheckFunctionPointer | 5368768304 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x779a88af |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 36 |
| Unmarked objects (#2) | 1 |
| C objects (33145) | 10 |
| ASM objects (33145) | 5 |
| C++ objects (33145) | 31 |
| Imports (33145) | 11 |
| Total imports | 1173 |
| C objects (LTCG) (33145) | 5 |
| 253 (33145) | 1 |
| Resource objects (33145) | 1 |
| Linker (33145) | 1 |
No comments yet.