| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-25 21:53:04 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | PeStubOEP v1.x |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-25 21:53:04 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x5aa00 |
| SizeOfInitializedData | 0x3d800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0003D304 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x5c000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
FreeLibrary
GetProcAddress GetSystemInfo IsProcessorFeaturePresent WriteFile GetLastError CreateFileW HeapAlloc GetProcessHeap HeapFree HeapReAlloc HeapSize SetEndOfFile GetStringTypeW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW FindFirstFileExW QueryPerformanceCounter FlushFileBuffers SetFilePointerEx GetFileSizeEx ReadConsoleW GetConsoleMode GetConsoleOutputCP SetStdHandle DecodePointer GetStdHandle LCMapStringW InitializeCriticalSectionEx FlsFree FlsSetValue FlsGetValue FlsAlloc GetModuleFileNameW ReadFile GetModuleHandleExW ExitProcess GetFileType LoadLibraryExW TlsFree TlsSetValue CloseHandle WriteConsoleW TlsGetValue TlsAlloc WideCharToMultiByte MultiByteToWideChar AllocConsole VirtualProtect FindClose InitializeCriticalSectionAndSpinCount DeleteCriticalSection UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsDebuggerPresent GetStartupInfoW GetModuleHandleW GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RaiseException RtlUnwind InterlockedFlushSList SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection |
|---|---|
| USER32.dll |
GetKeyState
DefWindowProcA SetFocus |
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyA RegCloseKey |
| Ordinal | 1 |
|---|---|
| Address | 0x329e0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-25 21:53:04 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x838d0 |
| PointerToRawData | 0x826d0 |
| StartAddressOfRawData | 0x10083c5c |
|---|---|
| EndAddressOfRawData | 0x10083c64 |
| AddressOfIndex | 0x10093a1c |
| AddressOfCallbacks | 0x1005c20c |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10090380 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0x4404de4 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 41 |
| C++ objects (33145) | 190 |
| ASM objects (35207) | 29 |
| C objects (35207) | 20 |
| C++ objects (35207) | 40 |
| C objects (33145) | 26 |
| C objects (9178) | 1 |
| C objects (2067) | 9 |
| 18 (8444) | 6 |
| C++ objects (9178) | 109 |
| Imports (9210) | 3 |
| Imports (33145) | 14 |
| Total imports | 212 |
| C++ objects (35227) | 98 |
| Exports (35227) | 1 |
| Resource objects (35227) | 1 |
| Linker (35227) | 1 |
No comments yet.