| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2024-Apr-09 19:33:50 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC+2 timezone. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 2024-Apr-09 19:33:50 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xc1400 |
| SizeOfInitializedData | 0x1d800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000C2CB4 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xc3000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xed000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
MessageBoxA
CharNextW LoadStringW |
| kernel32.dll |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| kernel32.dll (#2) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| user32.dll (#2) |
MessageBoxA
CharNextW LoadStringW |
| kernel32.dll (#3) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| kernel32.dll (#4) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| kernel32.dll (#5) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| kernel32.dll (delay-loaded) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsDBCSLeadByteEx IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetConsoleOutputCP GetConsoleCP GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile SetFilePointer SetEndOfFile ReadFile GetFileType GetFileSize CreateFileW GetStdHandle CloseHandle |
| Attributes | 0x1 |
|---|---|
| Name | kernel32.dll |
| ModuleHandle | 0xd3060 |
| DelayImportAddressTable | 0xd306c |
| DelayImportNameTable | 0xd308c |
| BoundDelayImportTable | 0xd30ac |
| UnloadDelayImportTable | 0xd30c4 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| %s is not a valid BCD value |
| Could not parse SQL TimeStamp string |
| Invalid SQL date/time values |
| Dataset not in edit or insert mode |
| Cannot perform this operation on a closed dataset |
| Cannot perform this operation on an empty dataset |
| Cannot modify a read-only dataset |
| Nested dataset must inherit from %s |
| False |
| True |
| Parameter '%s' not found |
| Unable to load bind parameters |
| Field '%s' is of an unsupported type |
| SQL not supported |
| Execute not supported |
| Operation not allowed on a unidirectional dataset |
| Unassigned variant value |
| Record not found |
| BCD overflow |
| Type mismatch for field '%s', expecting: %s actual: %s |
| Size mismatch for field '%s', expecting: %d actual: %d |
| Invalid variant type or size for field '%s' |
| Value of field '%s' is out of range |
| Field '%s' must have a value |
| Field '%s' has no dataset |
| Field '%s' cannot be a calculated or lookup field |
| Field '%s' cannot be modified |
| Duplicate index name '%s' |
| No index for fields '%s' |
| Index '%s' not found |
| Duplicate name '%s' in %s |
| Circular datalinks are not allowed |
| Lookup information for field '%s' is incomplete |
| DataSource cannot be changed |
| Cannot perform this operation on an open dataset |
| Source file open error, skipped. |
| Skipped, destination file exists. |
| DELETED |
| Invalid field size |
| Invalid FieldKind |
| Field '%s' is of an unknown type |
| Field name missing |
| Duplicate field name '%s' |
| Field '%s' not found |
| Cannot access field '%s' as type %s |
| Invalid value for field '%s' |
| %g is not a valid value for field '%s'. The allowed range is %g to %g |
| %s is not a valid value for field '%s'. The allowed range is %s to %s |
| '%s' is not a valid integer value for field '%s' |
| '%s' is not a valid boolean value for field '%s' |
| '%s' is not a valid floating point value for field '%s' |
| No single cast observer with ID %s was added to the observer collection |
| No multi cast observer with ID %s was added to the observer collection |
| dbf2csv |
| 1.00 |
| Copyright (c) 2024 TinyCthulu |
| https://github.com/TinyCthulhu/dbf2csv |
| Unknown command. Type: "dbf2csv -help" for help. |
| <source_name> not declared, type: "dbf2csv -help" for help. |
| Too many parameters. Type: "dbf2csv -help" for help. |
| Invalid parameter, file "%s" does not exist. |
| Error in parameter <%s>, source directory is invalid. |
| Error in parameter <%s>, <destination_name> is invalid. |
| No matching files. |
| %d out of %d file(s) converted. |
| Error: cannot convert itself. |
| Error while reading record data. |
| %s (Version %d.%d, Build %d, %5:s) |
| %s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
| 32-bit Edition |
| 64-bit Edition |
| Windows |
| Windows Vista |
| Windows Server 2008 |
| Windows 7 |
| Windows Server 2008 R2 |
| Windows 2000 |
| Windows XP |
| Windows Server 2003 |
| Windows Server 2003 R2 |
| Observer is not supported |
| Cannot have multiple single cast observers added to the observers collection |
| The object does not implement the observer interface |
| The given "%s" local time is invalid (situated within the missing period prior to DST). |
| Length of Strings and Objects arrays must be equal |
| Timespan too long |
| The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue |
| Value cannot be NaN |
| Negating the minimum value of a Timespan is invalid |
| Invalid Timespan format |
| Timespan element too long |
| ''%s'' is not a valid date |
| ''%s'' is not a valid date and time |
| ''%s'' is not a valid integer value |
| ''%s'' is not a valid time |
| Invalid argument to time encode |
| Argument out of range |
| Item not found |
| Duplicates not allowed |
| Invalid property value |
| List capacity out of bounds (%d) |
| List count out of bounds (%d) |
| List index out of bounds (%d) |
| Out of memory while expanding memory stream |
| %s has not been registered as a COM class |
| Error reading %s%s%s: %s |
| Stream read error |
| Property is read-only |
| Resource %s not found |
| %s.Seek not implemented |
| Operation not allowed on sorted list |
| %s not in a class registration group |
| Property %s does not exist |
| Stream write error |
| The specified file was not found |
| Cannot assign a %s to a %s |
| Can't write to a read-only resource stream |
| Class %s not found |
| A class named %s already exists |
| List does not allow duplicates ($0%x) |
| A component named %s already exists |
| String list does not allow duplicates |
| Cannot create file "%s". %s |
| Cannot open file "%s". %s |
| Invalid file name - %s |
| Invalid stream format |
| ''%s'' is not a valid component name |
| Invalid property value |
| Invalid property element: %s |
| Invalid property path |
| Invalid property type: %s |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Invalid source array |
| Invalid destination array |
| Character index out of bounds (%d) |
| Start index out of bounds (%d) |
| Invalid count (%d) |
| Invalid destination index (%d) |
| Invalid code page |
| Invalid encoding name |
| Ancestor for '%s' not found |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Monitor support function not initialized |
| Feature not implemented |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s |
| Read |
| Write |
| Format string too long |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid NULL variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Custom variant type (%s%.4x) is out of range |
| Custom variant type (%s%.4x) already used by %s |
| Custom variant type (%s%.4x) is not usable |
| Too many custom variant types have been registered |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| <unknown> |
| '%s' is not a valid floating point value |
| '%d.%d' is not a valid timestamp |
| '%s' is not a valid GUID value |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| StartAddressOfRawData | 0x4d4000 |
|---|---|
| EndAddressOfRawData | 0x4d4014 |
| AddressOfIndex | 0x4c3c0c |
| AddressOfCallbacks | 0x4d5010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.