| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Jun-25 16:44:44 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Omar\Work\imgui\examples\example_win32_directx11\Release\example_win32_directx11.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/72 (Scanned on 2025-07-30 18:17:16) |
APEX:
Malicious
CrowdStrike: win/grayware_confidence_60% (D) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Jun-25 16:44:44 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xb7000 |
| SizeOfInitializedData | 0x3c800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000B6F4E (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xb8000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| KERNEL32.dll |
GetLocaleInfoA
LoadLibraryA QueryPerformanceFrequency GetProcAddress VerSetConditionMask FreeLibrary QueryPerformanceCounter Sleep GetModuleHandleW IsProcessorFeaturePresent GetCurrentProcessId GetModuleHandleA UnhandledExceptionFilter IsDebuggerPresent CreateEventW WaitForSingleObjectEx ResetEvent SetEvent DeleteCriticalSection LeaveCriticalSection EnterCriticalSection GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetCurrentProcess GlobalUnlock WideCharToMultiByte GlobalLock GlobalAlloc GlobalFree MultiByteToWideChar TerminateProcess SetUnhandledExceptionFilter CloseHandle |
| USER32.dll |
PeekMessageW
DispatchMessageW ShowWindow RegisterClassExW UnregisterClassW CreateWindowExW TranslateMessage MonitorFromPoint DefWindowProcW UpdateWindow GetKeyState GetMessageExtraInfo DestroyWindow PostQuitMessage ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetDC |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
ShellExecuteW
|
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| VCRUNTIME140.dll |
_except_handler4_common
memset __CxxFrameHandler3 strchr strstr __std_terminate memchr memmove __vcrt_InitializeCriticalSectionEx memcpy |
| api-ms-win-crt-stdio-l1-1-0.dll |
fwrite
_wfopen __stdio_common_vfprintf fseek fclose fflush __acrt_iob_func ftell __stdio_common_vsprintf fread _set_fmode __stdio_common_vsscanf __p__commode |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
strncpy
strncmp toupper |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
free malloc |
| api-ms-win-crt-runtime-l1-1-0.dll |
_exit
__p___argc __p___argv _c_exit _register_thread_local_exe_atexit_callback exit _initterm_e _initterm _controlfp_s _configure_narrow_argv _get_initial_narrow_environment _wassert _set_app_type _seh_filter_exe _cexit terminate _initialize_narrow_environment _crt_atexit _initialize_onexit_table _register_onexit_function |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-math-l1-1-0.dll |
_libm_sse2_pow_precise
_libm_sse2_log_precise _libm_sse2_sin_precise _libm_sse2_sqrt_precise ceil floor _CIfmod __setusermatherr _CIatan2 _except1 _libm_sse2_acos_precise _libm_sse2_cos_precise |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jun-25 16:44:44 |
| Version | 0.0 |
| SizeofData | 112 |
| AddressOfRawData | 0xe2428 |
| PointerToRawData | 0xe1828 |
| Referenced File | C:\Omar\Work\imgui\examples\example_win32_directx11\Release\example_win32_directx11.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jun-25 16:44:44 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xe2498 |
| PointerToRawData | 0xe1898 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jun-25 16:44:44 |
| Version | 0.0 |
| SizeofData | 784 |
| AddressOfRawData | 0xe24ac |
| PointerToRawData | 0xe18ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jun-25 16:44:44 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x4eb000 |
|---|---|
| EndAddressOfRawData | 0x4eb008 |
| AddressOfIndex | 0x4e8858 |
| AddressOfCallbacks | 0x4b82a0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x5c |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x4e400c |
| SEHandlerTable | 0x4e23e0 |
| SEHandlerCount | 18 |
| XOR Key | 0x7877881 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (24237) | 2 |
| ASM objects (24237) | 4 |
| C++ objects (24237) | 25 |
| C objects (24237) | 13 |
| Imports (65501) | 17 |
| Total imports | 153 |
| C++ objects (LTCG) (24245) | 8 |
| Resource objects (24245) | 1 |
| Linker (24245) | 1 |
No comments yet.