Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2029-Oct-13 15:59:23 |
Debug artifacts |
Embedded COFF debugging symbols
|
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | PEiD Signature: | ASPack v2.12 |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE is packed with Aspack |
Section .text is both writable and executable.
Unusual section name found: .aspack |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2029-Oct-13 15:59:23 |
PointerToSymbolTable | 0x446b6361 |
NumberOfSymbols | 1562469737 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xd9000 |
SizeOfInitializedData | 0x51000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000AE62D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xda000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x12d000 |
SizeOfHeaders | 0x600 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
lstrlenA
GlobalMemoryStatus GetCommandLineA GetModuleHandleA GetVersion GetProcAddress CopyFileA LoadLibraryA SetErrorMode FreeLibrary GlobalAlloc GlobalFree InterlockedExchange FindNextFileA CompareFileTime DeleteFileA MoveFileA CreateDirectoryA FindFirstFileA FindClose Sleep GetTickCount HeapFree IsBadWritePtr GetEnvironmentVariableA GetCurrentProcess SetConsoleCtrlHandler SetEnvironmentVariableA CompareStringW CompareStringA IsBadCodePtr IsBadReadPtr SetEndOfFile SetStdHandle FlushFileBuffers GetEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsW GetStartupInfoA GetFileAttributesA FileTimeToSystemTime FileTimeToLocalFileTime GetCurrentThreadId GetModuleFileNameA SetConsoleTitleA GetConsoleScreenBufferInfo GetStdHandle GetVersionExA GetSystemInfo GetCurrentProcessId MultiByteToWideChar RtlUnwind HeapReAlloc HeapAlloc ExitProcess TerminateProcess UnhandledExceptionFilter RaiseException GetLastError GetTimeZoneInformation GetSystemTime GetLocalTime VirtualFree VirtualAlloc CloseHandle WriteFile ReadFile SetFilePointer SetHandleCount GetFileType CreateFileA WideCharToMultiByte LCMapStringA LCMapStringW SetUnhandledExceptionFilter HeapSize FreeEnvironmentStringsA HeapDestroy HeapCreate GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP |
---|---|
USER32.dll |
PeekMessageA
GetMessageA ClientToScreen EndPaint ToAscii GetActiveWindow MessageBoxA DispatchMessageA TranslateMessage DestroyWindow FindWindowA CreateWindowExA UnregisterClassA RegisterClassA ShowWindow InvalidateRect SetFocus SetWindowsHookExA ClipCursor UnhookWindowsHookEx SetCursorPos CallNextHookEx GetKeyboardState SendMessageA FillRect BeginPaint DefWindowProcA SetCursor GetClientRect SetWindowPos GetSystemMetrics SetForegroundWindow |
ADVAPI32.dll |
RegOpenKeyExA
RegOpenKeyA RegSetValueExA RegCloseKey RegCreateKeyExA RegQueryValueExA |
WINMM.dll |
timeKillEvent
timeSetEvent mmioOpenA mmioClose mmioAscend mmioRead mmioDescend mmioSeek mmioSetInfo mmioAdvance mmioGetInfo timeGetTime |
DSOUND.dll |
#1
|
GDI32.dll |
DeleteObject
SelectObject CreateSolidBrush |
XOR Key | 0x4f643850 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
14 (7299) | 37 |
C objects (8047) | 139 |
C++ objects (8047) | 19 |
C++ objects (VS98 build 8168) | 20 |
48 (9044) | 62 |
Unmarked objects (#2) | 4 |
19 (8034) | 13 |
Total imports | 138 |
49 (9044) | 140 |