Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2018-Mar-02 12:17:54 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | MASM/TASM - sig2(h) |
Suspicious | PEiD Signature: |
FASM 1.5x
FASM v1.5x |
Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
Suspicious | The PE is possibly a dropper. |
Resource 101 is possibly compressed or encrypted.
Resources amount for 95.8121% of the executable. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2018-Mar-02 12:17:54 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x7000 |
SizeOfInitializedData | 0x10b000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000742D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x8000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x116000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.DLL |
GetTickCount
EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW GetModuleHandleW GetProcAddress UnhandledExceptionFilter QueryPerformanceCounter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead SetThreadPriority CreateThread Sleep GetConsoleTitleA QueryPerformanceFrequency GetModuleHandleA SetConsoleTitleA LoadResource LockResource FindResourceA SetUnhandledExceptionFilter SizeofResource CloseHandle |
---|---|
api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode calloc |
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
api-ms-win-crt-math-l1-1-0.dll |
sin
fabs _libm_sse2_atan_precise _libm_sse2_exp_precise __setusermatherr _ftol pow _except1 |
api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_get_initial_narrow_environment _set_app_type _seh_filter_exe _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv _controlfp_s terminate _invalid_parameter_noinfo_noreturn _register_thread_local_exe_atexit_callback _c_exit __p___argv __p___argc _exit _initterm_e exit |
api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __stdio_common_vfprintf _set_fmode |
api-ms-win-crt-time-l1-1-0.dll |
clock
|
api-ms-win-crt-utility-l1-1-0.dll |
rand
srand abs |
GDI32.dll |
CreateFontA
SelectObject ChoosePixelFormat SwapBuffers SetPixelFormat |
GLU32.dll |
gluBuild2DMipmaps
gluPerspective |
MSVCP140.dll |
?_Xlength_error@std@@YAXPBD@Z
?_Xbad_alloc@std@@YAXXZ ?_Xout_of_range@std@@YAXPBD@Z |
OPENGL32.dll |
glPolygonMode
glBindTexture glGenTextures glEnable glVertex3f glCullFace glEnd glTexCoord2f glGenLists glMatrixMode glCallLists glBlendFunc wglCreateContext glLoadIdentity glVertex3fv glTexParameteri glColor3fv glHint wglUseFontOutlinesA glPopAttrib glClearColor wglDeleteContext glTranslatef glRotatef glListBase glClearDepth glColor4f glMultMatrixf glDisable glLightfv glPushMatrix wglMakeCurrent glDeleteLists glGetFloatv glShadeModel glDepthFunc glPushAttrib glPointSize glTexGeni glClear glViewport glBegin glPopMatrix glDeleteTextures |
USER32.dll |
ReleaseDC
ShowCursor SetForegroundWindow FindWindowA PostQuitMessage UnregisterClassA PeekMessageA LoadIconA TranslateMessage SetFocus CreateWindowExA DefWindowProcA AdjustWindowRectEx DispatchMessageA LoadCursorA DestroyWindow GetDC GetSystemMetrics ShowWindow ChangeDisplaySettingsA MessageBoxA MoveWindow RegisterClassA |
VCRUNTIME140.dll |
memcpy
_except_handler4_common _CxxThrowException __std_exception_destroy __std_exception_copy memset __vcrt_InitializeCriticalSectionEx memmove __CxxFrameHandler3 |
WINMM.dll |
waveOutReset
waveOutWrite waveOutUnprepareHeader waveOutPrepareHeader waveOutOpen waveOutClose waveOutGetPosition |
StartAddressOfRawData | 0x413000 |
---|---|
EndAddressOfRawData | 0x413008 |
AddressOfIndex | 0x40bc4c |
AddressOfCallbacks | 0x40830c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40b00c |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0xba6d9759 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 14 |
Imports (VS2015 UPD3 build 24123) | 4 |
C objects (VC++ 6.0 SP5 build 8804) | 6 |
ASM objects (VS2015 UPD3 build 24123) | 4 |
C++ objects (VS2015 UPD3 build 24123) | 27 |
C objects (VS2015 UPD3 build 24123) | 13 |
Imports (65501) | 13 |
Total imports | 174 |
265 (VS2015 UPD3.1 build 24215) | 3 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
151 | 1 |
Linker (VS2015 UPD3.1 build 24215) | 1 |