Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-Feb-21 01:17:35 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\nitro_000\documents\visual studio 2015\Projects\Task3\Debug\Task3.pdb
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
Suspicious | The PE is packed or was manually edited. |
Section .textbss is both writable and executable.
The number of imports reported in the RICH header is inconsistent. |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2017-Feb-21 01:17:35 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xb9400 |
SizeOfInitializedData | 0x29600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00055EEC (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x13b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FormatMessageW
WideCharToMultiByte EnterCriticalSection LeaveCriticalSection DeleteCriticalSection MultiByteToWideChar GetCPInfo EncodePointer DecodePointer SetLastError InitializeCriticalSectionAndSpinCount CreateEventW Sleep TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount GetModuleHandleW GetProcAddress CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW CloseHandle SetEvent ResetEvent WaitForSingleObjectEx IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead GetCurrentProcess TerminateProcess RaiseException RtlUnwind GetLastError FreeLibrary LoadLibraryExW InterlockedPushEntrySList InterlockedFlushSList GetConsoleMode GetNumberOfConsoleInputEvents PeekConsoleInputA ReadConsoleInputA SetConsoleMode HeapAlloc HeapFree HeapReAlloc ExitProcess GetModuleHandleExW GetModuleFileNameA GetModuleFileNameW GetStdHandle WriteFile GetCommandLineA GetCommandLineW GetACP GetCurrentThread GetDateFormatW GetTimeFormatW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType CreateFileW GetProcessHeap FlushFileBuffers GetConsoleCP ReadFile SetFilePointerEx SetConsoleCtrlHandler GetTimeZoneInformation FindClose FindFirstFileExA FindFirstFileExW FindNextFileA FindNextFileW IsValidCodePage GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableA SetEnvironmentVariableW OutputDebugStringA OutputDebugStringW CreateThread SetStdHandle ReadConsoleW WriteConsoleW HeapSize SetEndOfFile CreateProcessA |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-21 00:52:16 |
Version | 0.0 |
SizeofData | 103 |
AddressOfRawData | 0x125f10 |
PointerToRawData | 0xd0710 |
Referenced File | C:\Users\nitro_000\documents\visual studio 2015\Projects\Task3\Debug\Task3.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-21 00:52:16 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x125f78 |
PointerToRawData | 0xd0778 |
StartAddressOfRawData | 0x532000 |
---|---|
EndAddressOfRawData | 0x532208 |
AddressOfIndex | 0x52e848 |
AddressOfCallbacks | 0x50fb84 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x52c084 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x7b01012c |
---|---|
Unmarked objects | 0 |
241 (40116) | 14 |
243 (40116) | 157 |
242 (40116) | 29 |
ASM objects (VS2015 UPD3 build 24123) | 22 |
C++ objects (VS2015 UPD3 build 24123) | 58 |
C objects (VS2015 UPD3 build 24123) | 34 |
Imports (65501) | 3 |
Total imports | 98 |
C++ objects (VS2015 UPD3.1 build 24215) | 1 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |