Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2019-Apr-24 22:18:38 |
Debug artifacts |
C:\projects\src\out\Default\osmesa.dll.pdb
|
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/67 (Scanned on 2019-10-31 00:58:57) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x78 |
e_cp | 0x1 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0 |
e_ss | 0 |
e_sp | 0 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x78 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2019-Apr-24 22:18:38 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.1 |
SizeOfCode | 0x1b5a00 |
SizeOfInitializedData | 0x11a400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000191300 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 4.1 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x2f0000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CloseHandle
CompareStringW CreateFileW DeleteCriticalSection EncodePointer EnterCriticalSection ExitProcess FindClose FindFirstFileExW FindNextFileW FlushFileBuffers FreeEnvironmentStringsW FreeLibrary GetACP GetCPInfo GetCommandLineA GetCommandLineW GetConsoleCP GetConsoleMode GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetEnvironmentStringsW GetFileType GetLastError GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoW GetStdHandle GetStringTypeW GetSystemTimeAsFileTime HeapAlloc HeapFree HeapQueryInformation HeapReAlloc HeapSize InitializeCriticalSection InitializeCriticalSectionAndSpinCount InitializeSListHead InterlockedFlushSList IsDebuggerPresent IsProcessorFeaturePresent IsValidCodePage LCMapStringW LeaveCriticalSection LoadLibraryExW MultiByteToWideChar OutputDebugStringA QueryPerformanceCounter RaiseException ReadConsoleW ReadFile RtlCaptureContext RtlLookupFunctionEntry RtlPcToFileHeader RtlUnwindEx RtlVirtualUnwind SetEndOfFile SetEnvironmentVariableW SetFilePointerEx SetLastError SetStdHandle SetUnhandledExceptionFilter TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnhandledExceptionFilter WideCharToMultiByte WriteConsoleW WriteFile |
---|
Ordinal | 1 |
---|---|
Address | 0x4ff6 |
Ordinal | 2 |
---|---|
Address | 0x44d4 |
Ordinal | 3 |
---|---|
Address | 0x44f8 |
Ordinal | 4 |
---|---|
Address | 0x4aea |
Ordinal | 5 |
---|---|
Address | 0x4f5a |
Ordinal | 6 |
---|---|
Address | 0x4d4b |
Ordinal | 7 |
---|---|
Address | 0x4ef8 |
Ordinal | 8 |
---|---|
Address | 0x4e3c |
Ordinal | 9 |
---|---|
Address | 0x4fac |
Ordinal | 10 |
---|---|
Address | 0x4b77 |
Ordinal | 11 |
---|---|
Address | 0x4d50 |
Ordinal | 12 |
---|---|
Address | 0x501e |
Ordinal | 13 |
---|---|
Address | 0x5057 |
Ordinal | 14 |
---|---|
Address | 0x5088 |
Ordinal | 15 |
---|---|
Address | 0x50df |
Ordinal | 16 |
---|---|
Address | 0x511e |
Ordinal | 17 |
---|---|
Address | 0x5155 |
Ordinal | 18 |
---|---|
Address | 0x50b9 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Apr-24 22:18:38 |
Version | 0.0 |
SizeofData | 67 |
AddressOfRawData | 0x2b5a58 |
PointerToRawData | 0x2b4858 |
Referenced File | C:\projects\src\out\Default\osmesa.dll.pdb |
Size | 0x100 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1802bb100 |