Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2000-Oct-06 02:50:24 |
Debug artifacts |
ke\Debug\CarMake.pdb
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
InstallShield 2000 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 45 bytes of data starting at offset 0x111000. |
Safe | VirusTotal score: 0/69 (Scanned on 2018-09-30 16:52:08) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2000-Oct-06 02:50:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xf7000 |
SizeOfInitializedData | 0x3c000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00078E80 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x134000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FindFirstFileA
GetTickCount Sleep GetModuleFileNameA SetConsoleTitleA GetConsoleScreenBufferInfo GetStdHandle GetModuleHandleA GetVersionExA FreeLibrary GetProcAddress LoadLibraryA GetSystemInfo GlobalMemoryStatus FileTimeToSystemTime FileTimeToLocalFileTime ExitProcess TerminateProcess GetCurrentProcess RtlUnwind IsBadWritePtr IsBadReadPtr HeapValidate GetStartupInfoA GetCommandLineA GetVersion GetLastError GetFileAttributesA CloseHandle WriteFile ReadFile SetFilePointer SetHandleCount GetFileType GetCurrentProcessId InterlockedDecrement OutputDebugStringA InterlockedIncrement HeapAlloc HeapReAlloc HeapFree HeapDestroy HeapCreate VirtualFree VirtualAlloc FindClose MultiByteToWideChar LCMapStringA LCMapStringW RaiseException UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW FlushFileBuffers SetStdHandle SetEndOfFile SetConsoleCtrlHandler SetUnhandledExceptionFilter IsBadCodePtr GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP CompareStringA CompareStringW SetEnvironmentVariableA FindNextFileA DebugBreak CreateFileA WideCharToMultiByte |
---|---|
USER32.dll |
CreateWindowExA
GetClientRect SetFocus SetWindowPos GetSystemMetrics SetForegroundWindow SendMessageA InvalidateRect ShowWindow RegisterClassA UnregisterClassA FillRect FindWindowA DestroyWindow GetMessageA PeekMessageA DispatchMessageA TranslateMessage SetCursor DefWindowProcA BeginPaint EndPaint |
GDI32.dll |
DeleteObject
SelectObject CreateSolidBrush |
Characteristics |
0
|
---|---|
TimeDateStamp | 2000-Oct-06 02:49:19 |
Version | 0.0 |
SizeofData | 45 |
AddressOfRawData | 0 |
PointerToRawData | 0x111000 |
Referenced File | ke\Debug\CarMake.pdb |
XOR Key | 0x43cb13f1 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
14 (7299) | 37 |
C objects (VS98 build 8168) | 175 |
Unmarked objects (#2) | 1 |
19 (8034) | 7 |
Total imports | 98 |
C++ objects (VS98 build 8168) | 90 |