| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2016-Oct-18 09:34:35 |
| Detected languages |
English - United States
Russian - Russia |
| Debug artifacts |
D:\dmr\basic_dll\Release\basic_dll.pdb
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE is possibly a dropper. | Resources amount for 83.9592% of the executable. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2016-Oct-18 09:34:35 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 11.0 |
| SizeOfCode | 0x13e00 |
| SizeOfInitializedData | 0xba600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000095AE (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x15000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
LocalAlloc
LocalFree WideCharToMultiByte InitializeCriticalSectionAndSpinCount LoadResource LockResource SizeofResource FindResourceW FindResourceExW CloseHandle GetModuleHandleA CreateFileA WaitForSingleObject FindResourceA GetFileSize CreateProcessA SetFilePointer WriteFile SetEndOfFile RaiseException GetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection HeapDestroy HeapAlloc HeapReAlloc HeapFree HeapSize GetProcessHeap CreateFileW GetCommandLineA GetCurrentThreadId EncodePointer DecodePointer RtlUnwind IsDebuggerPresent IsProcessorFeaturePresent GetConsoleCP GetConsoleMode ReadFile MultiByteToWideChar ReadConsoleW SetLastError InterlockedIncrement InterlockedDecrement ExitProcess GetModuleHandleExW GetProcAddress AreFileApisANSI GetStdHandle GetFileType GetStartupInfoW GetModuleFileNameA QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime GetEnvironmentStringsW FreeEnvironmentStringsW UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleW Sleep GetModuleFileNameW SetFilePointerEx SetStdHandle WriteConsoleW FlushFileBuffers IsValidCodePage GetACP GetOEMCP GetCPInfo LoadLibraryExW OutputDebugStringW LoadLibraryW LCMapStringW GetStringTypeW |
|---|---|
| USER32.dll |
PostMessageA
|
| Ordinal | 1 |
|---|---|
| Address | 0x53f0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2016-Oct-18 09:34:35 |
| Version | 0.0 |
| SizeofData | 63 |
| AddressOfRawData | 0x1a5d0 |
| PointerToRawData | 0x197d0 |
| Referenced File | D:\dmr\basic_dll\Release\basic_dll.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2016-Oct-18 09:34:35 |
| Version | 0.0 |
| SizeofData | 16 |
| AddressOfRawData | 0x1a610 |
| PointerToRawData | 0x19810 |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1001c180 |
| SEHandlerTable | 0x1001a970 |
| SEHandlerCount | 23 |
| XOR Key | 0x35334070 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (50929) | 15 |
| C objects (50929) | 112 |
| Imports (VS2008 SP1 build 30729) | 5 |
| Total imports | 97 |
| C++ objects (50929) | 47 |
| 211 (VS2012 UPD4 build 61030) | 3 |
| Exports (VS2012 UPD4 build 61030) | 1 |
| Resource objects (VS2012 UPD4 build 61030) | 1 |
| 151 | 1 |
| Linker (VS2012 UPD4 build 61030) | 1 |
No comments yet.