Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2015-Mar-12 11:34:49 |
Comments | |
CompanyName | |
FileDescription | ConsoleApplication3 |
FileVersion | 1.0.0.0 |
InternalName | ConsoleApplication3.exe |
LegalCopyright | Copyright © 2018 |
LegalTrademarks | |
OriginalFilename | ConsoleApplication3.exe |
ProductName | ConsoleApplication3 |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to AES Uses constants related to Blowfish |
Suspicious | The PE is possibly packed. | Unusual section name found: .marx |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2015-Mar-12 11:34:49 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0xf000 |
SizeOfInitializedData | 0x11000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000F7FC (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x10000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x21000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WINMM.dll |
timeKillEvent
timeGetDevCaps timeSetEvent |
---|---|
KERNEL32.dll |
GetModuleFileNameA
LoadLibraryA GetCurrentProcess GetProcAddress GetModuleHandleA VirtualFree VirtualAlloc CloseHandle UnmapViewOfFile MapViewOfFile CreateFileMappingA GetFileSize CreateFileA TerminateProcess FreeLibrary LoadLibraryExA SearchPathA GetSystemInfo OutputDebugStringA GetCommandLineA GetVersionExA RtlUnwind HeapAlloc HeapFree ExitProcess WriteFile GetStdHandle UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetLastError GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoA DeleteCriticalSection TlsAlloc SetLastError GetCurrentThreadId VirtualProtect TlsFree TlsSetValue TlsGetValue HeapDestroy HeapCreate InterlockedExchange VirtualQuery LeaveCriticalSection EnterCriticalSection HeapReAlloc IsBadWritePtr QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetACP GetOEMCP GetCPInfo InitializeCriticalSection SetUnhandledExceptionFilter IsBadReadPtr IsBadCodePtr LCMapStringA MultiByteToWideChar LCMapStringW HeapSize GetStringTypeA GetStringTypeW GetLocaleInfoA |
USER32.dll |
MessageBoxA
|
mscoree.dll |
_CorExeMain
|
ole32.dll |
CoInitialize
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
Comments | |
CompanyName | |
FileDescription | ConsoleApplication3 |
FileVersion (#2) | 1.0.0.0 |
InternalName | ConsoleApplication3.exe |
LegalCopyright | Copyright © 2018 |
LegalTrademarks | |
OriginalFilename | ConsoleApplication3.exe |
ProductName | ConsoleApplication3 |
ProductVersion (#2) | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Resource LangID | UNKNOWN |
---|
XOR Key | 0x4fb6b3e |
---|---|
Unmarked objects | 0 |
Imports (2148) | 2 |
105 (2067) | 1 |
ASM objects (VS2003 (.NET) build 3077) | 23 |
C objects (VS2003 (.NET) build 3077) | 86 |
C objects (VS98 SP6 build 8804) | 13 |
C++ objects (VS98 SP6 build 8804) | 1 |
Imports (2067) | 2 |
Imports (2179) | 7 |
Total imports | 93 |
C++ objects (VS2003 (.NET) build 3077) | 11 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |