| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Apr-02 22:19:08 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Apr-02 22:19:08 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x44e00 |
| SizeOfInitializedData | 0x1da00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000BF30 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x46000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x67000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
VirtualProtect
GetModuleHandleA Sleep LoadLibraryA CloseHandle CreateThread GetProcAddress GetComputerNameA GetConsoleMode GetConsoleOutputCP FlushFileBuffers WideCharToMultiByte EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar LCMapStringEx GetStringTypeW GetCPInfo IsProcessorFeaturePresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind RaiseException InterlockedFlushSList GetLastError SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW ExitProcess GetModuleHandleExW GetModuleFileNameW HeapAlloc HeapValidate GetSystemInfo GetStdHandle GetFileType WriteFile OutputDebugStringW WriteConsoleW HeapFree HeapReAlloc HeapSize HeapQueryInformation GetProcessHeap FlsAlloc FlsGetValue FlsSetValue FlsFree LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetFilePointerEx SetStdHandle CreateFileW |
|---|---|
| USER32.dll |
GetAsyncKeyState
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-02 22:19:08 |
| Version | 0.0 |
| SizeofData | 812 |
| AddressOfRawData | 0x5c138 |
| PointerToRawData | 0x5b338 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-02 22:19:08 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1005e040 |
| SEHandlerTable | 0x1005bf74 |
| SEHandlerCount | 60 |
| XOR Key | 0x4829b8c9 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 14 |
| C++ objects (33145) | 160 |
| C objects (33145) | 22 |
| ASM objects (35207) | 19 |
| C objects (35207) | 14 |
| C++ objects (35207) | 71 |
| Imports (33145) | 7 |
| Total imports | 107 |
| C++ objects (LTCG) (35219) | 1 |
| Resource objects (35219) | 1 |
| Linker (35219) | 1 |
No comments yet.