Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Aug-08 13:28:46 |
FileDescription | Neot Lion Studio |
FileVersion | 4.77.11.23 |
InternalName | Neot Lion Studio |
LegalCopyright | Neot Lion Studio |
OriginalFilename | Neot Lion Studio |
PrivateBuild | Neot Lion Studio |
ProductName | Neot Lion Studio |
ProductVersion | 4.77.11.23 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2018-Aug-08 13:28:46 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 99.0 |
SizeOfCode | 0x8c400 |
SizeOfInitializedData | 0x32800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001124F (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x8e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xc1000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
DestroyWindow
LoadIconW SendMessageW CreateWindowExW MessageBoxW |
---|---|
SHELL32.dll |
ShellExecuteExW
SHChangeNotify |
ADVAPI32.dll |
GetTokenInformation
OpenProcessToken RegCloseKey RegSetValueExW RegCreateKeyExW RegDeleteKeyW |
KERNEL32.dll |
GetLocaleInfoW
GetConsoleOutputCP CompareStringA CompareStringW SetEnvironmentVariableA CreateFileA CloseHandle WriteConsoleA InterlockedIncrement VirtualAlloc HeapSetInformation GetCommandLineW DecodePointer EncodePointer DeleteCriticalSection LeaveCriticalSection EnterCriticalSection RaiseException GetProcessHeap HeapSize HeapReAlloc HeapFree HeapAlloc HeapDestroy GetStartupInfoW TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter GetCPInfo GetACP GetOEMCP IsValidCodePage LCMapStringW IsProcessorFeaturePresent GetStringTypeW SetFilePointer GetConsoleCP GetConsoleMode SetStdHandle FlushFileBuffers WriteConsoleW WaitForSingleObject LocalFree GetLastError MultiByteToWideChar GetModuleFileNameW GetVersionExW WideCharToMultiByte GetSystemTimeAsFileTime GetProcAddress InterlockedDecrement GetTimeFormatA GetDateFormatA GetCommandLineA GetVersionExA GetStartupInfoA SetHandleCount GetStdHandle GetFileType GetCurrentProcess IsDebuggerPresent RtlUnwind GetModuleHandleA GetTimeZoneInformation ExitProcess TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError GetCurrentThreadId Sleep GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale GetStringTypeA WriteFile GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetCurrentProcessId ReadFile InitializeCriticalSection LCMapStringA LoadLibraryA |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.2.0.551 |
ProductVersion | 1.2.0.551 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
FileDescription | Neot Lion Studio |
FileVersion (#2) | 4.77.11.23 |
InternalName | Neot Lion Studio |
LegalCopyright | Neot Lion Studio |
OriginalFilename | Neot Lion Studio |
PrivateBuild | Neot Lion Studio |
ProductName | Neot Lion Studio |
ProductVersion (#2) | 4.77.11.23 |
Resource LangID | UNKNOWN |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x48e04c |
SEHandlerTable | 0x402c40 |
SEHandlerCount | 3 |
XOR Key | 0xd16c6316 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 22 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 111 |
Imports (VS2003 (.NET) build 4035) | 9 |
Total imports | 110 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 29 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Resource objects (VS2008 build 21022) | 1 |