Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2009-May-19 14:21:01 |
Detected languages |
English - United States
German - Germany |
FileDescription | Forward Executer |
FileVersion | 999, 999, 999, 999 |
InternalName | Forward Executer |
LegalCopyright | Copyright © 2009, Steinberg Media Technologies GmbH |
OriginalFilename | ForwardExecuter.exe |
ProductName | Forward Executer |
ProductVersion | 999, 999, 999, 999 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/70 (Scanned on 2021-01-02 05:25:35) | APEX: Malicious |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2009-May-19 14:21:01 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0xe000 |
SizeOfInitializedData | 0x6000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00002B35 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xf000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x16000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x19ec3 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetProcAddress
GetModuleHandleA ExitProcess GetCommandLineA HeapFree GetVersionExA HeapAlloc GetProcessHeap GetStartupInfoA RaiseException RtlUnwind TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetLastError TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement WriteFile GetStdHandle GetModuleFileNameA DeleteCriticalSection LeaveCriticalSection EnterCriticalSection LoadLibraryA InitializeCriticalSection MultiByteToWideChar ReadFile CloseHandle FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType HeapDestroy HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime VirtualAlloc HeapReAlloc GetCPInfo GetACP GetOEMCP IsValidCodePage Sleep HeapSize GetLocaleInfoA CreateFileA GetExitCodeProcess WaitForSingleObject CreateProcessA GetFileAttributesA SetFilePointer SetStdHandle GetConsoleCP GetConsoleMode FlushFileBuffers GetStringTypeA GetStringTypeW LCMapStringA LCMapStringW SetEndOfFile WriteConsoleA GetConsoleOutputCP WriteConsoleW CompareStringA CompareStringW SetEnvironmentVariableA |
---|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 999.999.999.999 |
ProductVersion | 999.999.999.999 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | German - Germany |
FileDescription | Forward Executer |
FileVersion (#2) | 999, 999, 999, 999 |
InternalName | Forward Executer |
LegalCopyright | Copyright © 2009, Steinberg Media Technologies GmbH |
OriginalFilename | ForwardExecuter.exe |
ProductName | Forward Executer |
ProductVersion (#2) | 999, 999, 999, 999 |
Resource LangID | German - Germany |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4120a0 |
SEHandlerTable | 0x410d30 |
SEHandlerCount | 10 |
XOR Key | 0xee368321 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 19 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 109 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 43 |
Imports (VS2003 (.NET) build 4035) | 3 |
Total imports | 92 |
114 (VS2012 build 50727 / VS2005 build 50727) | 1 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |