| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Apr-11 17:22:42 |
| Detected languages |
English - United States
Malay - Malaysia |
| Debug artifacts |
D:\Developments\Games\SmartSteamEmu\x64\Release\SmartSteamLoader_x64.pdb
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
Can access the registry:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 75.3569% of the executable. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2017-Apr-11 17:22:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0xce00 |
| SizeOfInitializedData | 0xa9600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000008D38 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xba000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x4a47c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetPrivateProfileIntW
GetPrivateProfileStringW FindFirstFileW FindClose GetCommandLineW GetModuleFileNameW GetCurrentDirectoryW GetPrivateProfileSectionNamesW GetCurrentProcessId OpenProcess CreateThread CreateProcessW ResumeThread WaitForSingleObject GetExitCodeThread Sleep MultiByteToWideChar GetLastError DecodePointer EncodePointer GetStartupInfoW TerminateProcess UnhandledExceptionFilter GetSystemTimeAsFileTime GetCurrentThreadId GetTickCount QueryPerformanceCounter RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent SetUnhandledExceptionFilter WideCharToMultiByte OpenFileMappingA CreateSemaphoreW SetEvent CreateEventA MapViewOfFile CreateFileMappingA CloseHandle GetCurrentProcess UnmapViewOfFile |
|---|---|
| USER32.dll |
TranslateMessage
SendMessageW PostQuitMessage DestroyWindow DispatchMessageW CreateDialogParamW IsDialogMessageW GetMessageW ShowWindow MoveWindow GetDesktopWindow GetWindowRect MessageBoxW |
| ADVAPI32.dll |
RegQueryValueExA
RegCloseKey RegSetValueExW RegQueryValueExW RegCreateKeyExA RegOpenKeyExA SetSecurityDescriptorDacl InitializeSecurityDescriptor RegSetValueExA |
| SHELL32.dll |
CommandLineToArgvW
|
| MSVCP100.dll |
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z |
| PSAPI.DLL |
GetModuleFileNameExW
|
| WINTRUST.dll |
WinVerifyTrust
|
| MSVCR100.dll |
_wcsicmp
memset memcmp _CxxThrowException memcpy __CxxFrameHandler3 ??3@YAXPEAX@Z memmove ??0exception@std@@QEAA@AEBV01@@Z ?what@exception@std@@UEBAPEBDXZ ??1exception@std@@UEAA@XZ ??0exception@std@@QEAA@AEBQEBD@Z ??2@YAPEAX_K@Z _wputenv _vswprintf_c_l tolower _wtoi fopen_s fread fclose atoi sprintf_s memchr ??_V@YAXPEAX@Z __C_specific_handler _unlock __dllonexit _lock _onexit _amsg_exit __getmainargs _XcptFilter _exit _ismbblead _cexit exit _acmdln _initterm _initterm_e _configthreadlocale __setusermatherr _commode _fmode __set_app_type __crt_debugger_hook ?terminate@@YAXXZ ?_type_info_dtor_internal_method@type_info@@QEAAXXZ |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Apr-11 17:22:42 |
| Version | 0.0 |
| SizeofData | 97 |
| AddressOfRawData | 0x13958 |
| PointerToRawData | 0x12b58 |
| Referenced File | D:\Developments\Games\SmartSteamEmu\x64\Release\SmartSteamLoader_x64.pdb |
| XOR Key | 0x1ed76732 |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 2 |
| ASM objects (VS2010 SP1 build 40219) | 3 |
| C objects (VS2010 SP1 build 40219) | 18 |
| Imports (VS2010 SP1 build 40219) | 4 |
| C++ objects (VS2010 SP1 build 40219) | 13 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 118 |
| 175 (VS2010 SP1 build 40219) | 6 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.