Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Feb-01 12:47:41 |
TLS Callbacks | 3 callback(s) detected. |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 9 |
TimeDateStamp | 2024-Feb-01 12:47:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x22600 |
SizeOfInitializedData | 0x2fe00 |
SizeOfUninitializedData | 0xc00 |
AddressOfEntryPoint | 0x000010BA (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x24000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 1.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x38000 |
SizeOfHeaders | 0x400 |
Checksum | 0x33b16 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x200000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
ChoosePixelFormat
SetPixelFormat |
---|---|
KERNEL32.dll |
AddVectoredExceptionHandler
CloseHandle CreateEventA CreateSemaphoreA DeleteCriticalSection DuplicateHandle EnterCriticalSection FreeLibrary GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetHandleInformation GetLastError GetModuleHandleA GetModuleHandleW GetProcAddress GetProcessAffinityMask GetStartupInfoA GetSystemTimeAsFileTime GetThreadContext GetThreadPriority GetTickCount InitializeCriticalSection IsDBCSLeadByteEx IsDebuggerPresent LeaveCriticalSection LoadLibraryA MultiByteToWideChar OpenProcess OutputDebugStringA QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReleaseSemaphore RemoveVectoredExceptionHandler ResetEvent ResumeThread SetEvent SetLastError SetProcessAffinityMask SetThreadContext SetThreadPriority SetUnhandledExceptionFilter Sleep SuspendThread TlsAlloc TlsGetValue TlsSetValue TryEnterCriticalSection VirtualProtect VirtualQuery WaitForMultipleObjects WaitForSingleObject WideCharToMultiByte |
msvcrt.dll |
__getmainargs
__initenv __mb_cur_max __p__acmdln __p__commode __p__fmode __set_app_type __setusermatherr _amsg_exit _beginthreadex _cexit _endthreadex _errno _initterm _iob _ismbblead _onexit _setjmp3 _strdup _ultoa _vsnprintf _vsnwprintf abort atoi calloc exit fgetwc fprintf fputc fputs free fwrite getc getenv localeconv longjmp malloc memcpy memmove memset memcmp printf realloc setlocale signal strchr strcmp strerror strlen strncmp strtoul vfprintf wcslen |
OPENGL32.DLL |
glBegin
glClear glColor3f glEnd glFlush glVertex2i glViewport wglCreateContext wglDeleteContext wglMakeCurrent |
USER32.dll |
AdjustWindowRect
BeginPaint CreateWindowExW DefWindowProcA DestroyWindow DispatchMessageA EndPaint GetDC GetMessageA GetMonitorInfoA GetWindowLongA GetWindowRect LoadCursorA LoadIconA MessageBoxW MonitorFromWindow PostMessageA PostQuitMessage RegisterClassExW ReleaseDC SetWindowLongA SetWindowPos ShowWindow TranslateMessage UpdateWindow |
StartAddressOfRawData | 0x435000 |
---|---|
EndAddressOfRawData | 0x435004 |
AddressOfIndex | 0x431050 |
AddressOfCallbacks | 0x43401c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
0x0040B998
0x0040BA2F 0x004183AC |