Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 1999-Apr-27 13:03:38 |
Debug artifacts |
BETA.exe
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 94336 bytes of data starting at offset 0x4e800. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 1999-Apr-27 13:03:38 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x3fc00 |
SizeOfInitializedData | 0x7b7200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00033F10 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x41000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x7fa000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
HeapReAlloc
SetErrorMode SetConsoleCtrlHandler SetLastError RaiseException InterlockedExchange GetLocalTime GetFileType SystemTimeToFileTime FileTimeToLocalFileTime GetLastError GetStdHandle CloseHandle FormatMessageA DeleteFileA CreateFileA WaitForSingleObject SetThreadPriority CreateProcessA SetEndOfFile SetFilePointer WriteFile ReadFile GetTempFileNameA GetTempPathA GetFullPathNameA GetFileInformationByHandle GetCommandLineA GetVersion ExitProcess TerminateProcess GetCurrentProcess HeapAlloc GetACP HeapFree UnhandledExceptionFilter GetModuleFileNameA FreeEnvironmentStringsA MultiByteToWideChar FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW WideCharToMultiByte GetCPInfo GetOEMCP SetHandleCount GetStartupInfoA HeapDestroy HeapCreate VirtualFree RtlUnwind GetProcAddress GetModuleHandleA LCMapStringA LCMapStringW GetTimeZoneInformation GetStringTypeA GetStringTypeW FlushFileBuffers VirtualAlloc LoadLibraryA CompareStringA CompareStringW SetEnvironmentVariableA SetStdHandle |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 1999-Apr-27 13:03:38 |
Version | 0.0 |
SizeofData | 272 |
AddressOfRawData | 0 |
PointerToRawData | 0x4e800 |
Referenced File | BETA.exe |
Characteristics |
0
|
---|---|
TimeDateStamp | 1999-Apr-27 13:03:38 |
Version | 0.0 |
SizeofData | 7744 |
AddressOfRawData | 0 |
PointerToRawData | 0x4e910 |