| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-19 16:46:03 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/69 (Scanned on 2026-06-19 18:24:10) |
APEX:
Malicious
Sophos: Generic ML PUA (PUA) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Jun-19 16:46:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x176600 |
| SizeOfInitializedData | 0xad200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000631E (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x178000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x228000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1b6913 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| alogg.dll |
alogg_adjust_ogg
alogg_destroy_ogg alogg_poll_ogg alogg_stop_ogg alogg_create_ogg_from_buffer alogg_play_ex_ogg alogg_get_length_msecs_ogg |
|---|---|
| alleg43.dll |
#533
#222 #655 #657 #753 #562 #843 #624 #889 #694 #746 #452 #844 #411 #445 #460 #749 #649 #104 #103 #731 #662 #105 #653 #823 #459 #176 #181 #179 #796 #690 #540 #21 #792 #818 #781 #504 #509 #512 #566 #507 #949 #514 #800 #297 #261 #645 #640 #854 #651 #706 #709 #747 #550 #208 #591 #816 #622 #264 #619 #807 #857 #620 #614 #680 #221 #582 #299 #304 #192 #856 #679 #764 |
| KERNEL32.dll |
QueryPerformanceCounter
WideCharToMultiByte DecodePointer EncodePointer DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId SetEndOfFile WriteConsoleW CreateFileW HeapSize HeapReAlloc SetStdHandle GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW FindClose ReadConsoleW ReadFile EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW VirtualProtect FlsFree FlsSetValue FlsGetValue FlsAlloc CloseHandle GetConsoleMode GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileSizeEx GetFileType HeapAlloc HeapFree WriteFile GetStdHandle GetModuleFileNameW GetModuleHandleExW ExitProcess LoadLibraryExW GetProcAddress FreeLibrary TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError GetLastError RaiseException RtlUnwind GetCPInfo MultiByteToWideChar Sleep CopyFileW GetCurrentProcessId GetModuleHandleW GetStartupInfoW IsDebuggerPresent GetStringTypeW UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent LCMapStringEx |
| SHELL32.dll |
ShellExecuteW
|
| VCOMP140.DLL |
_vcomp_set_num_threads
_vcomp_atomic_add_i4 _vcomp_barrier _vcomp_enter_critsect _vcomp_for_dynamic_init _vcomp_for_dynamic_next _vcomp_for_static_end _vcomp_for_static_init _vcomp_for_static_simple_init _vcomp_fork _vcomp_leave_critsect _vcomp_master_begin _vcomp_master_end _vcomp_reduction_r8 omp_get_thread_num |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-19 16:46:03 |
| Version | 0.0 |
| SizeofData | 872 |
| AddressOfRawData | 0x18a9ac |
| PointerToRawData | 0x1893ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-19 16:46:03 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x590040 |
| SEHandlerTable | 0x58a5f4 |
| SEHandlerCount | 176 |
| XOR Key | 0x9d68a5ed |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 21 |
| C++ objects (33145) | 176 |
| C objects (33145) | 25 |
| Imports (35207) | 2 |
| ASM objects (35207) | 23 |
| C objects (35207) | 17 |
| C++ objects (35207) | 81 |
| Imports (33145) | 4 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 5 |
| Total imports | 195 |
| C++ objects (LTCG) (35222) | 28 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.