Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Oct-03 12:52:43 |
Detected languages |
English - United Kingdom
English - United States |
CompanyName | Sokpop Collective |
FileDescription | |
FileVersion | 1.1.5.0 |
InternalName | GameMaker:Studio Windows C++ Runner |
LegalCopyright | |
PrivateBuild | 01.00.00.00 |
ProductName | |
ProductVersion | 1.1.5.0 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 |
Suspicious | The PE is possibly packed. | Unusual section name found: .mydata |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/68 (Scanned on 2018-10-26 10:03:18) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2018-Oct-03 12:52:43 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 11.0 |
SizeOfCode | 0x57e000 |
SizeOfInitializedData | 0xa18800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00300852 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x57f000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x11f1000 |
SizeOfHeaders | 0x400 |
Checksum | 0xf90e1c |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WININET.dll |
InternetConnectA
HttpOpenRequestA HttpSendRequestA InternetCanonicalizeUrlA InternetCrackUrlA InternetOpenA HttpQueryInfoA InternetReadFile InternetCloseHandle InternetGetConnectedState |
---|---|
d3dx9_43.dll |
D3DXGetPixelShaderProfile
D3DXGetImageInfoFromFileInMemory D3DXCreateTextureFromFileInMemoryEx D3DXCreateTextureFromFileW D3DXGetVertexShaderProfile D3DXCompileShader |
dbghelp.dll |
SymFromAddr
SymInitialize |
WINMM.dll |
joyGetPos
joyGetDevCapsA joyGetPosEx mciSendStringA mciGetErrorStringA |
WS2_32.dll |
ntohs
htonl htons getpeername __WSAFDIsSet select freeaddrinfo WSAGetLastError closesocket sendto connect inet_addr shutdown WSAStartup getsockopt setsockopt ioctlsocket socket bind getaddrinfo send recvfrom inet_ntoa recv accept listen |
gdiplus.dll |
GdiplusStartup
GdiplusShutdown |
COMCTL32.dll |
InitCommonControlsEx
|
KERNEL32.dll |
GetTempPathA
FindFirstFileExW SetFileAttributesW GetFileAttributesExW ReadFile HeapWalk HeapValidate FileTimeToSystemTime SystemTimeToTzSpecificLocalTime GetTimeZoneInformation FindFirstFileExA LoadLibraryExA GetDriveTypeW SetEnvironmentVariableW SetEnvironmentVariableA GetFileInformationByHandle PeekNamedPipe MoveFileExW ReadConsoleW SetFilePointer FindNextFileA FileTimeToLocalFileTime lstrlenA CreateDirectoryW GetFileAttributesW FindFirstFileW RemoveDirectoryW FindNextFileW FindClose CreateProcessW GetExitCodeProcess GlobalAlloc GlobalLock GlobalUnlock SetPriorityClass SetThreadPriority DeleteFileW GetExitCodeThread FormatMessageW LocalFree GetCurrentDirectoryW GlobalMemoryStatusEx GetSystemInfo GetLocaleInfoW GetUserDefaultLCID GetVersionExW SetEndOfFile TlsAlloc EncodePointer DecodePointer GetCommandLineA GetLastError HeapFree InterlockedDecrement ExitProcess GetModuleHandleExW GetProcAddress AreFileApisANSI MultiByteToWideChar HeapSize Sleep IsProcessorFeaturePresent SetLastError InterlockedIncrement GetCurrentThread GetCurrentThreadId GetStdHandle WriteFile GetModuleFileNameW GetProcessHeap GetFileType InitializeCriticalSectionAndSpinCount DeleteCriticalSection InitOnceExecuteOnce GetStartupInfoW GetModuleFileNameA QueryPerformanceCounter GetSystemTimeAsFileTime GetTickCount64 GetEnvironmentStringsW FreeEnvironmentStringsW WideCharToMultiByte UnhandledExceptionFilter SetUnhandledExceptionFilter FlsAlloc FlsGetValue FlsSetValue FlsFree GetCurrentProcess TerminateProcess GetModuleHandleW IsDebuggerPresent EnterCriticalSection LeaveCriticalSection InterlockedExchange FreeLibrary LoadLibraryExW IsValidCodePage GetACP GetOEMCP GetCPInfo HeapAlloc HeapReAlloc RtlUnwind OutputDebugStringW LoadLibraryW GetTimeFormatEx GetDateFormatEx CompareStringEx GetLocaleInfoEx GetUserDefaultLocaleName LCMapStringEx IsValidLocaleName EnumSystemLocalesEx GetStringTypeW RaiseException FlushFileBuffers GetConsoleCP GetConsoleMode SetStdHandle SetFilePointerEx WriteConsoleW CloseHandle CreateFileW ExpandEnvironmentStringsW MoveFileA GetFullPathNameW SetErrorMode GetCommandLineW GetCurrentProcessId RtlCaptureStackBackTrace GetTickCount QueryPerformanceFrequency WaitForSingleObject SetWaitableTimer CreateWaitableTimerW TlsSetValue CreateThread GetConsoleWindow SetCurrentDirectoryA GetCurrentDirectoryA GetEnvironmentVariableW |
USER32.dll |
DialogBoxParamW
GetDlgItem DrawTextW ScreenToClient keybd_event EndDialog GetDlgItemTextW SetDlgItemTextW wsprintfW GetFocus GetAsyncKeyState SetDlgItemTextA GetRawInputDeviceInfoA GetRawInputDeviceList EnumDisplayDevicesA CreateDialogParamW SetClipboardData MessageBoxA PostMessageW IsDialogMessageW DispatchMessageW TranslateMessage PeekMessageW SetFocus GetActiveWindow GetKeyState SetCapture ReleaseCapture DefWindowProcW GetWindowRect GetClientRect SetCursor SendMessageW CreateWindowExW RegisterClassExW LoadCursorW LoadImageW AdjustWindowRectEx GetSystemMetrics SetWindowPos SetForegroundWindow BringWindowToTop ShowWindow DestroyWindow MessageBoxW EnumDisplaySettingsW ChangeDisplaySettingsW GetCursorPos SetCursorPos SetWindowLongW UpdateWindow EnumDisplaySettingsExW ReleaseDC GetDC SetWindowTextW MoveWindow ClientToScreen GetMonitorInfoW MapWindowPoints SetWindowTextA IsClipboardFormatAvailable CloseClipboard GetClipboardData OpenClipboard EmptyClipboard GetForegroundWindow |
GDI32.dll |
GetDeviceCaps
SelectObject |
COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW |
ADVAPI32.dll |
RegCloseKey
RegOpenKeyExW RegQueryValueExW |
SHELL32.dll |
SHGetFolderPathW
ShellExecuteW |
ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
OLEAUT32.dll |
SysAllocString
SysFreeString VariantClear |
VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW VerQueryValueW |
d3d9.dll (delay-loaded) |
Direct3DCreate9
Direct3DCreate9Ex |
Attributes | 0x1 |
---|---|
Name | d3d9.dll |
ModuleHandle | 0x1174c04 |
DelayImportAddressTable | 0xf1eaa0 |
DelayImportNameTable | 0x683f0c |
BoundDelayImportTable | 0x683f40 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
OLE initialization failed. Make sure that the OLE libraries are the correct version. |
Windows sockets initialization failed. |
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.1.5.0 |
ProductVersion | 1.1.5.0 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United Kingdom |
CompanyName | Sokpop Collective |
FileDescription | |
FileVersion (#2) | 1.1.5.0 |
InternalName | GameMaker:Studio Windows C++ Runner |
LegalCopyright | |
PrivateBuild | 01.00.00.00 |
ProductName | |
ProductVersion (#2) | 1.1.5.0 |
Resource LangID | English - United Kingdom |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x12d3f68 |
SEHandlerTable | 0xa7e130 |
SEHandlerCount | 430 |
XOR Key | 0x2ff3172b |
---|---|
Unmarked objects | 0 |
189 (30716) | 1 |
190 (30716) | 1 |
Imports (21202) | 2 |
C++ objects (VS2008 SP1 build 30729) | 307 |
C objects (VS2008 SP1 build 30729) | 129 |
199 (41118) | 5 |
ASM objects (50628) | 66 |
C++ objects (50628) | 78 |
C objects (50628) | 232 |
Total imports | 296 |
185 (30716) | 31 |
Unmarked objects (#2) | 515 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |