Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jun-22 11:38:48 |
Detected languages |
Japanese - Japan
|
Debug artifacts |
d:\(◆開発用ディレクトリ)\[▼作業用]プログラム\RPGドライブプログラム+◆Editor - 20180525_ver2.22版_SteamKit版込\Rpgドライブプログラム\Release\Game2.23.pdb
|
Comments | http://silversecond.net/ |
CompanyName | SilverSecond |
FileDescription | Game |
FileVersion | ver2.23 |
InternalName | Game |
LegalCopyright | Copyright (C) SmokingWOLF All rights reserved. |
OriginalFilename | Game.exe |
ProductName | WOLF RPG Editor |
ProductVersion | 1, 0, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC Microsoft Visual C++ |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/69 (Scanned on 2022-07-26 04:58:19) | Trapmine: malicious.moderate.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2018-Jun-22 11:38:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x3b3000 |
SizeOfInitializedData | 0x798000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000FFD78 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x3b4000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb4c000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SHLWAPI.dll |
PathIsDirectoryA
|
---|---|
KERNEL32.dll |
lstrlenA
CreateFileA GetLastError WriteFile FlushFileBuffers InitializeCriticalSection GetDiskFreeSpaceExA RaiseException GetFileAttributesA FindNextFileW FindFirstFileW GetExitCodeThread Sleep CloseHandle RemoveDirectoryA CopyFileA DeleteFileA GlobalLock GlobalUnlock GlobalAlloc lstrcpyA GetModuleFileNameA GetCurrentDirectoryA FindFirstFileA FindNextFileA FindClose SetCurrentDirectoryA CreateDirectoryA GetTickCount GetLocaleInfoA GetACP InterlockedExchange GetVersionExA GetModuleFileNameW LoadLibraryW GetProcAddress FreeLibrary lstrlenW DeleteCriticalSection VirtualProtect GetFileSize GetTempFileNameW ReleaseSemaphore CreateSemaphoreA lstrcpynW MulDiv lstrcpyW lstrcmpW GetThreadPriority RtlUnwind ExitProcess GetSystemTimeAsFileTime HeapFree HeapAlloc GetModuleHandleA TerminateProcess GetCurrentProcess MoveFileA MultiByteToWideChar ExitThread GetCurrentThreadId CreateThread GetStartupInfoA GetCommandLineA TlsAlloc SetLastError GetCurrentThread TlsFree TlsSetValue TlsGetValue QueryPerformanceCounter GetCurrentProcessId EnterCriticalSection LeaveCriticalSection ReadFile SetHandleCount GetStdHandle GetFileType SetFilePointer HeapReAlloc HeapSize HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr SetUnhandledExceptionFilter GetOEMCP GetCPInfo GetUserDefaultLCID EnumSystemLocalesA IsValidLocale IsValidCodePage GetStringTypeA GetStringTypeW LCMapStringA WideCharToMultiByte LCMapStringW GetTimeZoneInformation UnhandledExceptionFilter VirtualQuery FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW IsBadReadPtr IsBadCodePtr LoadLibraryA SetStdHandle SetCurrentDirectoryW GetSystemInfo SetEndOfFile GetLocaleInfoW CompareStringA CompareStringW SetEnvironmentVariableA InterlockedIncrement InterlockedDecrement ResetEvent WaitForSingleObject CreateEventA SetEvent CreateFileW DeleteFileW GetTempPathW GlobalSize GlobalFree FileTimeToSystemTime FileTimeToLocalFileTime GetVersionExW QueryPerformanceFrequency OutputDebugStringW GlobalMemoryStatus GetLocalTime GetProcessHeap SetThreadPriority SuspendThread ResumeThread GetCurrentDirectoryW WaitForMultipleObjects |
USER32.dll |
MessageBoxA
SetFocus ShowWindow SetWindowPos GetWindowRect CreateDialogParamA SetMenu SetWindowTextW SetClassLongW LoadIconW SystemParametersInfoW UpdateWindow SetWindowRgn SendMessageW GetMenuItemInfoW GetMenuItemCount PostMessageW ShowCursor SetCursorPos MessageBoxW GetClientRect FillRect ChangeDisplaySettingsA SetForegroundWindow AttachThreadInput GetWindowThreadProcessId GetForegroundWindow SetActiveWindow AdjustWindowRectEx SetWindowLongW DrawMenuBar MoveWindow DefWindowProcW SetCursor PostQuitMessage EndPaint BeginPaint DestroyMenu BringWindowToTop RegisterClassExW LoadCursorW GetWindowLongW FindWindowW UnregisterClassW UnhookWindowsHookEx GetDesktopWindow DispatchMessageW TranslateMessage TranslateAcceleratorW IsDialogMessageW PeekMessageW KillTimer GetMonitorInfoW EnumDisplaySettingsW GetKeyboardState PostThreadMessageA GetQueueStatus RegisterWindowMessageA MsgWaitForMultipleObjects GetDC ReleaseDC GetCursorPos MonitorFromPoint EnumDisplayMonitors GetMonitorInfoA CharNextA ClientToScreen ClipCursor GetSystemMetrics SendMessageA GetAsyncKeyState IsClipboardFormatAvailable GetClipboardData OpenClipboard EmptyClipboard SetClipboardData CloseClipboard DestroyWindow GetDlgItem GetScrollPos SendDlgItemMessageA |
GDI32.dll |
AddFontResourceExA
RemoveFontResourceExA DeleteObject CombineRgn CreateRectRgn GetObjectA DeleteDC SelectObject CreateCompatibleDC CreateDIBSection GetStockObject CreateSolidBrush SetDIBitsToDevice StretchDIBits CreateDCW Rectangle GetGlyphOutlineW GetTextMetricsA GetObjectW CreateFontW SetBkMode SetBkColor SetTextColor GetCharacterPlacementW TextOutW GetTextExtentPoint32W EnumFontFamiliesExW GetDeviceCaps |
SHELL32.dll |
ShellExecuteA
DragAcceptFiles DragFinish DragQueryFileW DragQueryFileA |
WININET.dll |
InternetReadFile
HttpQueryInfoA InternetOpenUrlA InternetOpenA InternetCloseHandle |
WINMM.dll |
timeGetTime
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 2.24.2018.622 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Japanese - Japan |
Comments | http://silversecond.net/ |
CompanyName | SilverSecond |
FileDescription | Game |
FileVersion (#2) | ver2.23 |
InternalName | Game |
LegalCopyright | Copyright (C) SmokingWOLF All rights reserved. |
OriginalFilename | Game.exe |
ProductName | WOLF RPG Editor |
ProductVersion (#2) | 1, 0, 0, 0 |
Resource LangID | Japanese - Japan |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jun-22 11:38:48 |
Version | 0.0 |
SizeofData | 226 |
AddressOfRawData | 0x43dca4 |
PointerToRawData | 0x43dca4 |
Referenced File | d:\(◆開発用ディレクトリ)\[▼作業用]プログラム\RPGドライブプログラム+◆Editor - 20180525_ver2.22版_SteamKit版込\Rpgドライブプログラム\Release\Game2.23.pdb |
XOR Key | 0x2eaee973 |
---|---|
Unmarked objects | 0 |
C objects (VS98 SP6 build 8804) | 196 |
C++ objects (VS98 SP6 build 8804) | 64 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 76 |
105 (2067) | 2 |
C++ objects (VS2003 (.NET) build 3077) | 27 |
ASM objects (VS2003 (.NET) build 3077) | 58 |
C objects (VS2003 (.NET) build 3077) | 186 |
Imports (2067) | 2 |
Imports (2179) | 8 |
Imports (9210) | 5 |
Total imports | 288 |
97 (VS2003 (.NET) build 3077) | 2 |
98 (VS2003 (.NET) build 3077) | 3 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |