Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2021-Sep-10 15:34:01 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2021-Sep-10 15:34:01 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x15e00 |
SizeOfInitializedData | 0x9600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001867 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x17000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x22000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntdll.dll |
RtlUnwind
DbgPrintEx |
---|---|
USER32.dll |
DestroyWindow
TranslateMessage SetParent GetDesktopWindow SetWindowLongA SetForegroundWindow SwitchToThisWindow SendInput ShowWindow DispatchMessageA CreateWindowExW RegisterClassExW UnregisterClassW DefWindowProcW GetMessageA |
KERNEL32.dll |
FreeLibrary
WriteConsoleW CreateFileW ReadConsoleW ReadFile CloseHandle HeapReAlloc HeapSize SetFilePointerEx GetFileSizeEx GetConsoleMode GetConsoleOutputCP FlushFileBuffers GetStringTypeW SetStdHandle SetEnvironmentVariableW FreeEnvironmentStringsW DebugBreak OutputDebugStringA HeapAlloc HeapFree GetProcessHeap Sleep GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess GetEnvironmentStringsW WideCharToMultiByte GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree DecodePointer GetProcAddress LoadLibraryExW RaiseException GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW CompareStringW LCMapStringW GetFileType FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar |
Characteristics |
0
|
---|---|
TimeDateStamp | 2021-Sep-10 15:34:01 |
Version | 0.0 |
SizeofData | 616 |
AddressOfRawData | 0x1ce08 |
PointerToRawData | 0x1c008 |
Size | 0xbc |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x41e078 |
SEHandlerTable | 0x41ce00 |
SEHandlerCount | 2 |
XOR Key | 0x12157f53 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 10 |
C++ objects (27412) | 147 |
C objects (27412) | 18 |
C++ objects (VS 2015/2017/2019 runtime 29804) | 37 |
C objects (VS 2015/2017/2019 runtime 29804) | 17 |
ASM objects (VS 2015/2017/2019 runtime 29804) | 17 |
Imports (27412) | 7 |
Total imports | 99 |
C objects (VS2019 Update 9 (16.9.2-3) compiler 29913) | 1 |
Linker (VS2019 Update 9 (16.9.2-3) compiler 29913) | 1 |