Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Nov-25 20:57:14 |
Detected languages |
English - United States
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to Blowfish Uses constants related to TEA |
Suspicious | The PE is possibly packed. | Unusual section name found: .bind |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2019-Nov-25 20:57:14 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x2ca400 |
SizeOfInitializedData | 0x88200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000FDB310 (Section: .bind) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x1008000 |
SizeOfHeaders | 0x400 |
Checksum | 0x355a23 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WINMM.dll |
timeBeginPeriod
timeGetTime timeEndPeriod |
---|---|
USER32.dll |
EnumDisplaySettingsA
GetMonitorInfoA ChangeDisplaySettingsExA FillRect MessageBoxA EnumDisplayMonitors ChangeDisplaySettingsA CloseClipboard GetClipboardData OpenClipboard MapVirtualKeyA PeekMessageA ReleaseDC GetWindowLongA UnregisterClassA ShowCursor TranslateMessage GetDC SendMessageA GetClientRect LoadIconA PostQuitMessage RegisterClassExA GetWindowLongPtrA DestroyWindow DefWindowProcA GetDesktopWindow SetWindowPos CreateWindowExA LoadCursorA AdjustWindowRect CallWindowProcA UpdateWindow ShowWindow LoadImageA SetWindowTextA DispatchMessageA SetWindowLongPtrA |
steam_api64.dll |
SteamAPI_UnregisterCallResult
SteamAPI_GetHSteamPipe SteamInternal_CreateInterface SteamInternal_ContextInit SteamAPI_RestartAppIfNecessary SteamAPI_RunCallbacks SteamAPI_Init SteamAPI_Shutdown SteamAPI_RegisterCallResult SteamAPI_GetHSteamUser |
KERNEL32.dll |
GetTickCount
QueryPerformanceCounter RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind CloseHandle GetFileTime CreateFileA GlobalUnlock GlobalSize GlobalLock GetStartupInfoA TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetCurrentThreadId GetSystemTimeAsFileTime GetCurrentProcessId FreeLibrary GetProcAddress LoadLibraryA Sleep AllocConsole FreeConsole SetCurrentDirectoryA GetStdHandle GetModuleFileNameA |
GDI32.dll |
BitBlt
ChoosePixelFormat SwapBuffers CreateDIBSection CreateCompatibleDC SelectObject DescribePixelFormat SetPixelFormat CreateSolidBrush GetStockObject DeleteObject SetBkColor GetDeviceCaps SetTextColor |
SHELL32.dll |
SHGetPathFromIDListA
Shell_NotifyIconA SHGetSpecialFolderLocation |
ole32.dll |
CoTaskMemFree
|
MSVCR90.dll |
floorf
sprintf vsprintf memmove free malloc strchr strncpy strrchr sscanf tolower atol strncat strstr fopen fread fwrite fclose fprintf __iob_func printf ftell rename remove _findnext64i32 _findclose _findfirst64i32 _time64 _purecall atan2f atoi _mkdir setvbuf _open_osfhandle _localtime64 _fdopen calloc realloc ldexp qsort exit memchr memset memcpy _create_locale _atof_l _free_locale atof asin atan2 sin cos isspace __CxxFrameHandler3 strcpy strcat strcmp log ceil fmod sqrt pow atan tan acos exp rand srand floor fflush ferror getenv tmpfile fputs _sprintf_l memcmp fscanf feof fgets _stricmp _strnicmp _rmdir _access _strupr ??3@YAXPEAX@Z _amsg_exit __getmainargs __C_specific_handler _XcptFilter _exit _ismbblead _cexit _acmdln _initterm _initterm_e _configthreadlocale __setusermatherr _commode _fmode _encode_pointer __set_app_type __crt_debugger_hook ?terminate@@YAXXZ ?_type_info_dtor_internal_method@type_info@@QEAAXXZ _unlock __dllonexit _lock _onexit _decode_pointer _nextafterf ceilf sinf cosf vfprintf _vsnprintf _snprintf abort _HUGE ??2@YAPEAX_K@Z strlen sqrtf fseek powf |
OPENGL32.dll |
glDepthMask
glFogfv glDisableClientState glTexGeni glTexCoordPointer glEnableClientState glColorPointer glNormalPointer glVertexPointer glGetFloatv glGetIntegerv wglGetProcAddress glGetString glViewport glTexEnvi glClearColor glCullFace glFrontFace glDepthFunc glReadPixels glFlush glReadBuffer glClear glVertex3f glColor3fv glTexImage2D glTexParameterf glTexParameteri glGenTextures glPixelStorei glTexSubImage2D glDeleteTextures glDrawElements glTexGenfv glTexEnvfv glColor3f glColor4f glPolygonMode glColorMaterial glMaterialfv glScissor glMultMatrixf glOrtho glNormal3f glFrustum glMaterialf glLightfv glLightModelfv glFogf glFogi wglMakeCurrent wglGetCurrentContext wglShareLists wglCreateContext wglGetCurrentDC wglDeleteContext glCopyTexSubImage2D glBlendFunc glBindTexture glEnable glDisable glGetError glLoadMatrixf glMatrixMode glLoadIdentity glBegin glColor4ubv glTexCoord2fv glVertex3fv glEnd glAlphaFunc |
DINPUT8.dll |
DirectInput8Create
|
OpenAL32.dll |
alSourcePause
alGetError alGenSources alGetProcAddress alcGetError alGetString alcMakeContextCurrent alcCreateContext alcGetIntegerv alcIsExtensionPresent alcOpenDevice alcCloseDevice alcDestroyContext alcGetString alDeleteSources alListenerfv alListener3f alBufferData alSourcePlay alSource3f alSourcef alSourceQueueBuffers alSourcei alSourceStop alGenBuffers alDeleteBuffers alSourceUnqueueBuffers alGetSourcef alGetSourcei |
WS2_32.dll |
#10
#21 #9 #3 #17 #20 #8 #52 #57 #115 #15 #2 #116 #14 #23 |
ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegQueryValueExA |