| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2010-Jun-11 22:59:03 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\SimCity4\SC4000Projects\Ep1\out\ReleaseSRT\SimCity 4.pdb
|
| CompanyName | Maxis |
| LegalCopyright | Copyright © 2003 Maxis. All Rights Reserved |
| FileDescription | SimCity 4 |
| OriginalFilename | SimCity 4.exe |
| FileVersion | 1.1.641.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: LBMPEG_D
Unusual section name found: .data1 Unusual section name found: STLPORT_ |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-25 00:48:40) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x140 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2010-Jun-11 22:59:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x679000 |
| SizeOfInitializedData | 0x148000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x005F15DC (Section: .text) |
| BaseOfCode | 0x7000 |
| BaseOfData | 0x680000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7c8000 |
| SizeOfHeaders | 0x7000 |
| Checksum | 0x73b9b4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyExA RegSetValueExA RegCreateKeyExA GetUserNameA |
|---|---|
| WSOCK32.dll |
connect
accept recv getsockopt setsockopt inet_ntoa getsockname bind shutdown WSAAsyncSelect select __WSAFDIsSet socket closesocket WSACleanup WSAStartup ioctlsocket WSAGetLastError gethostbyname getpeername send listen |
| WININET.dll |
InternetOpenA
InternetSetOptionA HttpOpenRequestA InternetGetCookieA InternetOpenUrlA InternetConnectA InternetSetCookieA HttpSendRequestA InternetReadFile InternetQueryDataAvailable InternetCloseHandle |
| KERNEL32.dll |
HeapAlloc
ExitProcess GetCommandLineA GetVersion SetPriorityClass GetCurrentProcess SetEvent CloseHandle FindCloseChangeNotification FindNextChangeNotification WaitForMultipleObjects CreateEventA FindFirstChangeNotificationA CreateProcessA OutputDebugStringA Sleep GetProcAddress LoadLibraryA FreeLibrary VirtualQuery VirtualAlloc VirtualFree GetSystemInfo GetModuleFileNameA IsBadReadPtr GetModuleHandleA GetVersionExA SetErrorMode SetProcessAffinityMask GetProcessAffinityMask DeleteFileA MultiByteToWideChar GetWindowsDirectoryA GlobalFree GlobalAlloc GetTickCount CreateMutexA WaitForSingleObject ReleaseMutex SetThreadPriority CreateThread GetFileInformationByHandle FileTimeToLocalFileTime FileTimeToSystemTime SearchPathA GetLocaleInfoW GetExitCodeProcess IsBadCodePtr SetConsoleCtrlHandler IsValidCodePage IsValidLocale VirtualProtect GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter HeapCreate HeapDestroy GetTimeZoneInformation TlsGetValue TlsSetValue TlsFree SetLastError TlsAlloc HeapSize SetStdHandle GetStdHandle SetHandleCount GetOEMCP GetACP ExitThread CreateDirectoryA GetFullPathNameA GetCurrentDirectoryA GetDateFormatA GetTimeFormatA HeapReAlloc GetStartupInfoA GetSystemTimeAsFileTime RtlUnwind GetStringTypeA LCMapStringA EnumSystemLocalesA CompareStringW GetCPInfo LCMapStringW GetStringTypeW CreateFileMappingA MapViewOfFile UnmapViewOfFile GetFileType InterlockedExchange GetLocaleInfoA FindResourceA SizeofResource LoadResource LockResource InterlockedIncrement InterlockedDecrement ResetEvent PulseEvent InitializeCriticalSection LeaveCriticalSection EnterCriticalSection DeleteCriticalSection CompareStringA GetUserDefaultLCID GlobalSize GlobalLock GlobalUnlock QueueUserAPC GetExitCodeThread SuspendThread ResumeThread GetLocalTime GetCurrentThreadId GetCurrentProcessId SetUnhandledExceptionFilter TerminateProcess RaiseException IsBadWritePtr RemoveDirectoryA FindNextFileA FindClose CopyFileA MoveFileA SetFileAttributesA GetFileAttributesA CreateFileA ReadFile GetVolumeInformationA GetTempPathA FlushFileBuffers SetEndOfFile WriteFile SetFilePointer GetFileSize lstrcmpiA lstrlenA lstrcpynA WideCharToMultiByte SetEnvironmentVariableA HeapFree GetProcessHeap PeekNamedPipe GetComputerNameA GlobalMemoryStatus GetLogicalDriveStringsA GetDriveTypeA GetPriorityClass GetCurrentThread GetThreadPriority QueryPerformanceCounter QueryPerformanceFrequency SleepEx GetSystemDirectoryA FindFirstFileA GetLastError FormatMessageA LocalFree LoadLibraryW |
| USER32.dll |
CreateCursor
ScreenToClient GetCursorPos CharUpperBuffA CharLowerBuffA SetClipboardViewer SendMessageA EmptyClipboard WaitForInputIdle RegisterWindowMessageA SetClassLongA OffsetRect FillRect ReleaseCapture GetCapture SetCapture PostMessageA SetClipboardData OpenClipboard IsClipboardFormatAvailable GetClipboardData SetFocus SetWindowTextA IsWindowVisible MoveWindow EnumWindows GetWindowTextA GetSystemMetrics GetAsyncKeyState SystemParametersInfoA CloseClipboard ChangeClipboardChain BeginPaint GetDesktopWindow DestroyWindow GetClassInfoA LoadCursorA LoadIconA RegisterClassA CreateWindowExA SetWindowLongA GetWindowLongA DefWindowProcA GetKeyState MessageBoxA SetWindowsHookExA UnhookWindowsHookEx CallNextHookEx GetForegroundWindow GetActiveWindow wsprintfA ClientToScreen SetCursorPos ShowCursor DispatchMessageA TranslateMessage WaitMessage PeekMessageA PostQuitMessage UnregisterClassA ReleaseDC GetClientRect GetDC EnumDisplaySettingsA UpdateWindow ShowWindow ChangeDisplaySettingsA SetRect RedrawWindow DrawMenuBar GetWindowRect AdjustWindowRect GetMenu MapWindowPoints SetWindowPos SetCursor DestroyCursor GetIconInfo LoadImageA LoadCursorFromFileA KillTimer SetTimer AdjustWindowRectEx InvalidateRect IsIconic EndPaint GetWindowPlacement |
| GDI32.dll |
DeleteDC
CreateCompatibleDC CreateDIBSection GdiFlush GetDeviceCaps GetObjectA BitBlt DeleteObject ChoosePixelFormat SetPixelFormat SwapBuffers SetStretchBltMode GetDIBits SelectObject GetStockObject |
| SHELL32.dll |
ShellExecuteA
SHGetSpecialFolderLocation SHGetPathFromIDListA SHGetMalloc |
| DSOUND.dll |
#1
#2 |
| WINMM.dll |
mmioGetInfo
mmioAdvance mmioClose mmioDescend mmioSeek mmioAscend mmioRead mmioOpenA mmioSetInfo |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
| OPENGL32.dll |
glNormalPointer
glColor4f glEnableClientState glGetString glDrawArrays glTexCoordPointer glGetError glColorPointer glPixelStorei wglGetCurrentContext wglCreateContext wglMakeCurrent wglDeleteContext glOrtho glFlush wglGetCurrentDC wglGetProcAddress glDrawElements glReadBuffer glReadPixels glScissor glViewport glLightfv glPolygonOffset glTexGenfv glTexGeni glGetFloatv glGetBooleanv glIsEnabled glLoadIdentity glLoadMatrixf glMatrixMode glAreTexturesResident glPrioritizeTextures glIsTexture glDeleteTextures glGenTextures glDisable glColorMaterial glEnable glLightModelfv glMaterialfv glFogfv glFogi glGetTexLevelParameteriv glTexSubImage2D glGetIntegerv glTexParameteri glTexEnvfv glTexEnvi glVertexPointer glTexImage2D glBindTexture glShadeModel glAlphaFunc glBlendFunc glStencilOp glStencilMask glStencilFunc glDepthMask glColorMask glDepthFunc glClearStencil glClearDepth glClearColor glClear glDisableClientState |
| MSVFW32.dll |
ICLocate
ICDecompress ICSendMessage |
| IMM32.dll |
ImmGetOpenStatus
ImmReleaseContext ImmSetOpenStatus ImmNotifyIME ImmSetCompositionStringW ImmGetCompositionStringW ImmGetCandidateListW ImmGetContext |
| Ordinal | 1 |
|---|---|
| Address | 0x50ddfd |
| Ordinal | 2 |
|---|---|
| Address | 0x66d82c |
| FnordID:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.641.0 |
| ProductVersion | 1.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Maxis |
| LegalCopyright | Copyright © 2003 Maxis. All Rights Reserved |
| FileDescription | SimCity 4 |
| OriginalFilename | SimCity 4.exe |
| FileVersion (#2) | 1.1.641.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2010-Jun-11 22:59:03 |
| Version | 0.0 |
| SizeofData | 84 |
| AddressOfRawData | 0x700ab4 |
| PointerToRawData | 0x700ab4 |
| Referenced File | c:\SimCity4\SC4000Projects\Ep1\out\ReleaseSRT\SimCity 4.pdb |
| XOR Key | 0x5a1ae47a |
|---|---|
| Unmarked objects | 0 |
| 105 (2067) | 8 |
| ASM objects (VS2003 (.NET) build 3077) | 60 |
| C objects (VS2002 (.NET) build 9466) | 1 |
| C++ objects (VS2002 (.NET) build 9466) | 18 |
| C objects (VS2003 (.NET) build 3077) | 251 |
| C objects (2179) | 3 |
| Imports (9210) | 2 |
| C objects (9178) | 1 |
| Imports (2067) | 2 |
| 49 (9044) | 142 |
| Imports (2179) | 23 |
| Total imports | 432 |
| 19 (9049) | 9 |
| Unmarked objects (#2) | 120 |
| 42 (8803) | 17 |
| C++ objects (VS2003 (.NET) build 3077) | 712 |
| Exports (VS2003 (.NET) build 3077) | 1 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.