| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Sep-17 15:20:37 |
| Detected languages |
English - United States
Portuguese - Brazil |
| Debug artifacts |
D:\Cosas Agu\Sources\Trabajos\Trabajo Naldo\eMU\JoinServer\Release\JoinServer_EX301\JoinServer.pdb
|
| CompanyName | MuEMU |
| FileDescription | JoinServer |
| FileVersion | 1.0.0.0 |
| InternalName | JoinServer |
| LegalCopyright | Copyright © MuEMU.pl 2015 |
| OriginalFilename | JoinServer.exe |
| ProductName | MuEMU JoinServer |
| ProductVersion | 1.0.0.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Leverages the raw socket API to access the Internet:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 80.0356% of the executable. |
| Suspicious | VirusTotal score: 1/68 (Scanned on 2023-10-13 23:27:16) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2017-Sep-17 15:20:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x9400 |
| SizeOfInitializedData | 0x51200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000094DA (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xb000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x136000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x66771 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetLocalTime
CreateFileA SetFilePointer WriteFile GetFileSize ReadFile GetCurrentThreadId GetCurrentProcessId GetCurrentProcess SetErrorMode SetUnhandledExceptionFilter TerminateThread CreateIoCompletionPort GetLastError CreateThread SetThreadPriority GetSystemInfo CreateDirectoryA ReleaseSemaphore GetQueuedCompletionStatus WaitForSingleObject ExitProcess GetSystemTimeAsFileTime QueryPerformanceCounter IsDebuggerPresent UnhandledExceptionFilter TerminateProcess GetStartupInfoW HeapSetInformation InterlockedCompareExchange Sleep InterlockedExchange DecodePointer EncodePointer IsProcessorFeaturePresent CloseHandle GetPrivateProfileIntA GetPrivateProfileStringA LeaveCriticalSection EnterCriticalSection DeleteCriticalSection InitializeCriticalSection CreateSemaphoreA GetTickCount |
|---|---|
| USER32.dll |
wsprintfA
LoadStringA SetWindowTextA LoadAcceleratorsA GetMessageA GetDC TranslateAcceleratorA TranslateMessage DispatchMessageA LoadIconA LoadCursorA RegisterClassExA CreateWindowExA ShowWindow UpdateWindow DialogBoxParamA MessageBoxA DestroyWindow DefWindowProcA PostQuitMessage EndDialog GetClientRect ReleaseDC FillRect SetTimer |
| GDI32.dll |
CreateFontA
DeleteObject SetBkMode SelectObject SetTextColor TextOutA GetStockObject CreateSolidBrush |
| ODBC32.dll |
#18
#75 #7 #31 #36 #11 #20 #8 #4 #26 #16 #13 #24 |
| MSVCP100.dll |
?_Swap_all@_Container_base12@std@@QAEXAAU12@@Z
??1_Container_base12@std@@QAE@XZ ?_Xout_of_range@std@@YAXPBD@Z ?_Xlength_error@std@@YAXPBD@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z ?uncaught_exception@std@@YA_NXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ ?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A |
| WS2_32.dll |
socket
WSAStartup sendto gethostbyname inet_addr WSAAccept inet_ntoa WSARecv WSASend listen bind htons htonl WSASocketA closesocket WSAGetLastError |
| dbghelp.dll |
MiniDumpWriteDump
|
| MSVCR100.dll |
_time64
_localtime64_s asctime_s tolower _unlock __dllonexit _lock _onexit ?terminate@@YAXXZ _amsg_exit __getmainargs _cexit _exit _XcptFilter _ismbblead exit _acmdln _initterm _initterm_e _configthreadlocale __setusermatherr _commode _fmode __set_app_type _crt_debugger_hook strncpy_s __CxxFrameHandler3 _CxxThrowException memcpy memset atoi _stricmp isalnum _except_handler4_common isalpha atof isdigit isspace ??_V@YAXPAX@Z vsprintf_s memmove ??2@YAPAXI@Z _controlfp_s ??0exception@std@@QAE@ABQBD@Z _invoke_watson ?_type_info_dtor_internal_method@type_info@@QAEXXZ strcpy_s ??3@YAXPAX@Z ??0exception@std@@QAE@ABV01@@Z ?what@exception@std@@UBEPBDXZ ??1exception@std@@UAE@XZ |
| JoinServer |
| JOINSERVER |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MuEMU |
| FileDescription | JoinServer |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | JoinServer |
| LegalCopyright | Copyright © MuEMU.pl 2015 |
| OriginalFilename | JoinServer.exe |
| ProductName | MuEMU JoinServer |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | Portuguese - Brazil |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Sep-17 15:20:37 |
| Version | 0.0 |
| SizeofData | 123 |
| AddressOfRawData | 0xd0f0 |
| PointerToRawData | 0xb8f0 |
| Referenced File | D:\Cosas Agu\Sources\Trabajos\Trabajo Naldo\eMU\JoinServer\Release\JoinServer_EX301\JoinServer.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x40f018 |
| SEHandlerTable | 0x40d5a0 |
| SEHandlerCount | 23 |
| XOR Key | 0x7a295219 |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 1 |
| ASM objects (VS2010 build 30319) | 4 |
| C objects (VS2010 build 30319) | 20 |
| Imports (VS2010 build 30319) | 4 |
| C++ objects (VS2010 build 30319) | 6 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 188 |
| 175 (VS2010 build 30319) | 18 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |