| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Jun-06 04:09:14 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Benjamin\source\repos\Adv\Git\win\..\Release\Git.pdb
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .voltbl |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2026-08-09 00:50:51) |
AhnLab-V3:
Adware/Win.Mplug.C4534169
Bkav: W32.Malware.EF0DDA93 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2021-Jun-06 04:09:14 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x53c00 |
| SizeOfInitializedData | 0x4f800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000129A5 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xaa000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| Glk.dll |
#1
#100 #105 #87 #69 #71 #78 #70 #77 #79 #51 #52 #2 #50 #48 #44 #40 #41 #125 #122 #42 #31 #29 #26 #30 #28 #67 #111 #114 #116 #113 #118 #117 #136 #88 |
|---|---|
| KERNEL32.dll |
CloseHandle
CompareStringW CreateFileA CreateFileMappingA CreateFileW DecodePointer DeleteCriticalSection EncodePointer EnterCriticalSection EnumSystemLocalesW ExitProcess FindClose FindFirstFileExW FindNextFileW FlushFileBuffers FreeEnvironmentStringsW FreeLibrary GetACP GetCPInfo GetCommandLineA GetCommandLineW GetConsoleCP GetConsoleMode GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetEnvironmentStringsW GetFileAttributesA GetFileSize GetFileSizeEx GetFileType GetLastError GetLocaleInfoW GetModuleFileNameA GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoW GetStdHandle GetStringTypeW GetSystemTimeAsFileTime GetTimeFormatW GetUserDefaultLCID HeapAlloc HeapFree HeapReAlloc HeapSize InitializeCriticalSectionAndSpinCount InitializeSListHead InterlockedFlushSList InterlockedPushEntrySList IsDebuggerPresent IsProcessorFeaturePresent IsValidCodePage IsValidLocale LCMapStringW LeaveCriticalSection LoadLibraryExW MapViewOfFile MultiByteToWideChar OutputDebugStringW QueryPerformanceCounter RaiseException ReadConsoleW ReadFile RtlUnwind SetConsoleCtrlHandler SetEnvironmentVariableW SetFilePointerEx SetLastError SetStdHandle SetUnhandledExceptionFilter TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnhandledExceptionFilter UnmapViewOfFile WideCharToMultiByte WriteConsoleW WriteFile |
| USER32.dll |
MessageBoxA
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Jun-06 04:09:14 |
| Version | 0.0 |
| SizeofData | 86 |
| AddressOfRawData | 0x693ac |
| PointerToRawData | 0x683ac |
| Referenced File | C:\Users\Benjamin\source\repos\Adv\Git\win\..\Release\Git.pdb |
| Size | 0xb8 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x46bbb4 |
| SEHandlerTable | 0x469402 |
| SEHandlerCount | 7 |
No comments yet.