| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Sep-12 03:59:40 |
| Debug artifacts |
C:\Users\ana\code\Squirrel\Squirrel.Windows\src\StubExecutable\bin\Release\StubExecutable.pdb
|
| Comments | Contrail |
| CompanyName | Contrail |
| FileDescription | Contrail |
| FileVersion | 2.4.3 |
| InternalName | Contrail.dll |
| LegalCopyright | Copyright © Contrail 2026 |
| LegalTrademarks | |
| OriginalFilename | Contrail.dll |
| ProductName | Contrail |
| ProductVersion | 2.4.3 |
| Assembly Version | 2.4.3.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Lars Pinkenburg
Issuer: Certum Code Signing 2021 CA |
| Safe | VirusTotal score: 0/68 (Scanned on 2026-05-20 01:29:17) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2018-Sep-12 03:59:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1b000 |
| SizeOfInitializedData | 0x5ec00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000087FC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1c000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x84ae4 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetModuleFileNameW
GetModuleHandleW FindFirstFileW FindNextFileW FindClose CreateProcessW WriteConsoleW FlushFileBuffers SetFilePointerEx GetConsoleMode WideCharToMultiByte GetLastError MultiByteToWideChar GetStringTypeW EncodePointer DecodePointer SetLastError InitializeCriticalSectionAndSpinCount SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetProcAddress EnterCriticalSection LeaveCriticalSection DeleteCriticalSection LCMapStringW GetLocaleInfoW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead RtlUnwind RaiseException FreeLibrary LoadLibraryExW ExitProcess GetModuleHandleExW GetStdHandle WriteFile GetACP HeapFree HeapAlloc IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapReAlloc GetFileType FindFirstFileExW IsValidCodePage GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW GetProcessHeap CloseHandle SetStdHandle HeapSize GetConsoleCP CreateFileW |
|---|---|
| USER32.dll |
AllowSetForegroundWindow
WaitForInputIdle |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.4.3.0 |
| ProductVersion | 2.4.3.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Comments | Contrail |
| CompanyName | Contrail |
| FileDescription | Contrail |
| FileVersion (#2) | 2.4.3 |
| InternalName | Contrail.dll |
| LegalCopyright | Copyright © Contrail 2026 |
| LegalTrademarks | |
| OriginalFilename | Contrail.dll |
| ProductName | Contrail |
| ProductVersion (#2) | 2.4.3 |
| Assembly Version | 2.4.3.0 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Sep-12 03:59:40 |
| Version | 0.0 |
| SizeofData | 118 |
| AddressOfRawData | 0x29a74 |
| PointerToRawData | 0x28e74 |
| Referenced File | C:\Users\ana\code\Squirrel\Squirrel.Windows\src\StubExecutable\bin\Release\StubExecutable.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Sep-12 03:59:40 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x29aec |
| PointerToRawData | 0x28eec |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Sep-12 03:59:40 |
| Version | 0.0 |
| SizeofData | 808 |
| AddressOfRawData | 0x29b00 |
| PointerToRawData | 0x28f00 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Sep-12 03:59:40 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x42c068 |
| SEHandlerTable | 0x429990 |
| SEHandlerCount | 57 |
| XOR Key | 0x8febeeac |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 13 |
| 243 (40116) | 135 |
| 242 (40116) | 29 |
| 199 (41118) | 1 |
| ASM objects (VS 2015/2017 runtime 26706) | 20 |
| C++ objects (VS 2015/2017 runtime 26706) | 60 |
| C objects (VS 2015/2017 runtime 26706) | 34 |
| Imports (65501) | 5 |
| Total imports | 93 |
| C++ objects (LTCG) (VS2017 v15.8.1 compiler 26726) | 4 |
| Resource objects (VS2017 v15.8.1 compiler 26726) | 1 |
| 151 | 1 |
| Linker (VS2017 v15.8.1 compiler 26726) | 1 |
No comments yet.