Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Jan-04 20:12:16 |
Detected languages |
English - United States
Process Default Language Swedish - Sweden |
Debug artifacts |
C:\Users\Henrik\Documents\c++\debugging-ane\Debug ANE\Release\windebug.pdb
|
CompanyName | Henrik Andersson |
FileDescription | Windebug ANE Core dll |
FileVersion | 0.23.0.3 |
InternalName | WinDebug.dll |
LegalCopyright | Copyright Henrik "Henke37" Andersson (C) 2015 |
OriginalFilename | WinDebug.dll |
ProductName | Windows debugging ANE |
ProductVersion | 0.23.0.3 |
Info | Matching compiler(s): | Microsoft Visual C++ v6.0 DLL |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2016-Jan-04 20:12:16 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 11.0 |
SizeOfCode | 0xce00 |
SizeOfInitializedData | 0x7200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000D1F3 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xe000 |
ImageBase | 0x37de0000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x17000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
Adobe AIR.dll |
FREGetObjectAsBool
FREGetObjectAsDouble FREGetObjectAsInt32 FREGetArrayLength FREGetArrayElementAt FREAcquireBitmapData FREInvalidateBitmapDataRect FREReleaseBitmapData FRESetContextNativeData FRESetObjectProperty FREGetObjectAsUTF8 FREGetObjectType FRENewObjectFromInt32 FREReleaseByteArray FREAcquireByteArray FREGetObjectProperty FRENewObject FREDispatchStatusEventAsync FREGetContextActionScriptData FRENewObjectFromUint32 FRENewObjectFromBool FRECallObjectMethod FRENewObjectFromUTF8 FREGetContextNativeData FREGetObjectAsUint32 |
---|---|
PSAPI.DLL |
GetPerformanceInfo
GetProcessMemoryInfo EnumPageFilesW GetDeviceDriverFileNameW EnumDeviceDrivers QueryWorkingSet InitializeProcessForWsWatch GetMappedFileNameW GetWsChangesEx |
dbghelp.dll |
SymEnumTypesW
MiniDumpWriteDump SymCleanup SymGetModuleBase64 StackWalk64 SymRefreshModuleList SymSetOptions SymFromIndexW SymGetTypeInfo SymGetOptions SymEnumTypesByNameW SymInitializeW SymFromNameW SymFunctionTableAccess64 SymSetSearchPathW SymGetLineFromAddrW64 SymGetSearchPathW SymFromAddrW |
wevtapi.dll |
EvtClearLog
EvtRender EvtNextChannelPath EvtNext EvtClose EvtQuery EvtOpenChannelEnum |
WS2_32.dll |
#14
#15 |
IPHLPAPI.DLL |
GetTcpTable2
|
KERNEL32.dll |
DecodePointer
EncodePointer IsDebuggerPresent DebugSetProcessKillOnExit CloseHandle GetThreadContext SetThreadContext ReadProcessMemory OpenThread GetProcessId Module32FirstW CreateToolhelp32Snapshot Module32NextW DebugActiveProcess QueryPerformanceCounter OpenProcess ContinueDebugEvent WaitForDebugEvent GetCurrentProcess GetLastError CreateRemoteThread FileTimeToSystemTime WideCharToMultiByte MultiByteToWideChar lstrlenW FormatMessageW LocalFree Heap32ListNext Heap32Next Heap32First Heap32ListFirst Process32FirstW Process32NextW Thread32First Thread32Next GetThreadSelectorEntry VirtualQueryEx VirtualFreeEx VirtualProtectEx VirtualAllocEx WriteProcessMemory CreateFileW GetProcAddress OutputDebugStringW UnregisterWait SetProcessAffinityMask SetPriorityClass GetProcessDEPPolicy GetProcessPriorityBoost QueryFullProcessImageNameW SetProcessPriorityBoost GetProcessTimes GetPriorityClass GetProcessHandleCount GetExitCodeProcess TerminateProcess FlushInstructionCache RegisterWaitForSingleObject DebugBreakProcess GetProcessAffinityMask CheckRemoteDebuggerPresent FreeLibrary LoadLibraryW GetProcessVersion GetCurrentProcessId VirtualFree VirtualAlloc SetLastError GetSystemDEPPolicy IsProcessorFeaturePresent GetLargePageMinimum GetSystemInfo GetVersion GetProcessIdOfThread TerminateThread GetThreadPriorityBoost SetThreadPriority SetThreadPriorityBoost GetExitCodeThread SetThreadIdealProcessor GetThreadPriority GetThreadId GetCurrentThreadId GetThreadTimes SuspendThread ResumeThread WaitForSingleObject RaiseException InterlockedExchange LoadLibraryExA GetSystemTimeAsFileTime DisableThreadLibraryCalls DebugActiveProcessStop |
USER32.dll |
IsHungAppWindow
GetWindowInfo WindowFromPoint FindWindowW GetClassLongW EnumWindows GetWindowTextLengthW GetDC GetGUIThreadInfo GetWindowLongW ReleaseDC PrintWindow GetGuiResources GetWindowTextW IsWindowUnicode EnumChildWindows IsWindowVisible GetWindowThreadProcessId EnumThreadWindows GetWindowRect GetWindowDC GetClientRect GetClassInfoW |
GDI32.dll |
CreateBitmap
CreateCompatibleDC DeleteObject SelectObject GetDIBits |
ADVAPI32.dll |
OpenProcessToken
RegEnumValueW RegOpenKeyExW RegEnumKeyExW RegSetValueExW RegCloseKey GetKernelObjectSecurity GetAclInformation CopySid InitializeSecurityDescriptor ConvertStringSidToSidW SetSecurityDescriptorDacl GetAce LookupAccountSidW SetKernelObjectSecurity InitializeAcl FreeSid AddAce GetLengthSid ConvertSidToStringSidW GetSecurityDescriptorDacl CloseServiceHandle OpenSCManagerW EnumServicesStatusExW RegDeleteValueW LookupPrivilegeValueW AdjustTokenPrivileges RegQueryInfoKeyW RegDeleteKeyW RegGetValueW |
ole32.dll |
CoUninitialize
StringFromGUID2 CoCreateInstance CoInitialize |
MSVCR110.dll |
??3@YAXPAX@Z
free realloc ??1type_info@@UAE@XZ _crt_debugger_hook __crtUnhandledException __crtTerminateProcess __CppXcptFilter _amsg_exit _malloc_crt _initterm ??_U@YAPAXI@Z ?terminate@@YAXXZ _lock _unlock _calloc_crt __dllonexit _onexit __clean_type_info_names_internal _except_handler4_common memcpy __CxxFrameHandler3 _CxxThrowException ??_V@YAXPAX@Z ??2@YAPAXI@Z malloc _initterm_e memset ??1exception@std@@UAE@XZ |
MSVCP110.dll |
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z ?_Xbad_alloc@std@@YAXXZ |
mscoree.dll (delay-loaded) |
CLRCreateInstance
GetVersionFromProcess CreateDebuggingInterfaceFromVersion |
Attributes | 0x1 |
---|---|
Name | mscoree.dll |
ModuleHandle | 0x13180 |
DelayImportAddressTable | 0x13170 |
DelayImportNameTable | 0x10994 |
BoundDelayImportTable | 0x109f8 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x6e60 |
Ordinal | 2 |
---|---|
Address | 0x6e90 |
Ordinal | 3 |
---|---|
Address | 0x5e90 |
Ordinal | 4 |
---|---|
Address | 0x6e40 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 0.23.0.3 |
ProductVersion | 0.23.0.3 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | UNKNOWN |
CompanyName | Henrik Andersson |
FileDescription | Windebug ANE Core dll |
FileVersion (#2) | 0.23.0.3 |
InternalName | WinDebug.dll |
LegalCopyright | Copyright Henrik "Henke37" Andersson (C) 2015 |
OriginalFilename | WinDebug.dll |
ProductName | Windows debugging ANE |
ProductVersion (#2) | 0.23.0.3 |
Resource LangID | Swedish - Sweden |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Jan-04 20:12:16 |
Version | 0.0 |
SizeofData | 99 |
AddressOfRawData | 0x100e8 |
PointerToRawData | 0xf2e8 |
Referenced File | C:\Users\Henrik\Documents\c++\debugging-ane\Debug ANE\Release\windebug.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Jan-04 20:12:16 |
Version | 0.0 |
SizeofData | 16 |
AddressOfRawData | 0x1014c |
PointerToRawData | 0xf34c |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x37df3018 |
SEHandlerTable | 0x37df0370 |
SEHandlerCount | 16 |
XOR Key | 0x7acd1148 |
---|---|
Unmarked objects | 0 |
Imports (50929) | 4 |
ASM objects (50929) | 2 |
C objects (50929) | 12 |
188 (30716) | 1 |
C++ objects (50929) | 7 |
C objects (50323) | 1 |
185 (30716) | 20 |
Imports (VS2008 SP1 build 30729) | 3 |
Total imports | 256 |
210 (VS2012 UPD4 build 61030) | 64 |
Exports (VS2012 UPD4 build 61030) | 1 |
Resource objects (VS2012 UPD4 build 61030) | 1 |
151 | 1 |
Linker (VS2012 UPD4 build 61030) | 1 |