| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Sep-17 15:18:15 |
| Detected languages |
English - United States
Portuguese - Brazil |
| Debug artifacts |
D:\Cosas Agu\Sources\Trabajos\Trabajo Naldo\eMU\DataServer\Release\DataServer_EX301\DataServer.pdb
|
| CompanyName | MuEMU |
| FileDescription | DataServer |
| FileVersion | 1.0.0.0 |
| InternalName | DataServer |
| LegalCopyright | Copyright © MuEMU.pl 2015 |
| OriginalFilename | DataServer.exe |
| ProductName | MuEMU DataServer |
| ProductVersion | 1.0.0.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Leverages the raw socket API to access the Internet:
|
| Suspicious | VirusTotal score: 1/70 (Scanned on 2022-09-21 05:42:16) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2017-Sep-17 15:18:15 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x15c00 |
| SizeOfInitializedData | 0x52000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00015BEA (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x17000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x13a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6abb7 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetLocalTime
CreateFileA SetFilePointer WriteFile GetFileSize ReadFile GetCurrentThreadId GetCurrentProcessId GetCurrentProcess SetErrorMode SetUnhandledExceptionFilter TerminateThread CreateIoCompletionPort GetLastError CreateThread SetThreadPriority GetSystemInfo CreateDirectoryA ReleaseSemaphore GetQueuedCompletionStatus WaitForSingleObject ExitProcess GetSystemTimeAsFileTime QueryPerformanceCounter IsDebuggerPresent UnhandledExceptionFilter TerminateProcess GetStartupInfoW HeapSetInformation InterlockedCompareExchange Sleep InterlockedExchange DecodePointer EncodePointer CloseHandle GetTickCount GetPrivateProfileIntA GetPrivateProfileStringA LeaveCriticalSection EnterCriticalSection DeleteCriticalSection CreateSemaphoreA InitializeCriticalSection |
|---|---|
| USER32.dll |
RegisterClassExA
CreateWindowExA ShowWindow UpdateWindow LoadCursorA MessageBoxA DestroyWindow DefWindowProcA PostQuitMessage LoadIconA DispatchMessageA TranslateMessage TranslateAcceleratorA GetMessageA LoadAcceleratorsA SetTimer SetWindowTextA wsprintfA LoadStringA GetDC FillRect ReleaseDC DialogBoxParamA EndDialog GetClientRect |
| GDI32.dll |
DeleteObject
GetStockObject TextOutA SetTextColor SelectObject SetBkMode CreateFontA CreateSolidBrush |
| ODBC32.dll |
#26
#75 #7 #31 #36 #11 #20 #18 #8 #4 #16 #13 #72 #24 |
| MSVCP100.dll |
?_Xout_of_range@std@@YAXPBD@Z
??1_Container_base12@std@@QAE@XZ ?_Swap_all@_Container_base12@std@@QAEXAAU12@@Z ?_Xlength_error@std@@YAXPBD@Z |
| WS2_32.dll |
WSAStartup
WSAGetLastError closesocket WSASocketA htonl htons bind listen socket WSASend WSARecv inet_ntoa WSAAccept |
| dbghelp.dll |
MiniDumpWriteDump
|
| MSVCR100.dll |
_stricmp
_CxxThrowException memcpy memset _controlfp_s _invoke_watson ?_type_info_dtor_internal_method@type_info@@QAEXXZ _except_handler4_common _crt_debugger_hook __set_app_type _fmode _commode __setusermatherr _configthreadlocale _initterm_e _initterm _acmdln exit _ismbblead _XcptFilter _exit _cexit __getmainargs _amsg_exit ?terminate@@YAXXZ _onexit _lock __dllonexit _unlock asctime_s _localtime64_s _time64 strncpy_s _atoi64 atof isalnum isalpha atoi isdigit isspace ??_V@YAXPAX@Z vsprintf_s __CxxFrameHandler3 tolower ??3@YAXPAX@Z ??2@YAPAXI@Z ??0exception@std@@QAE@ABV01@@Z ?what@exception@std@@UBEPBDXZ ??1exception@std@@UAE@XZ ??0exception@std@@QAE@ABQBD@Z memmove strcpy_s strstr |
| DataServer |
| DATASERVER |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | MuEMU |
| FileDescription | DataServer |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | DataServer |
| LegalCopyright | Copyright © MuEMU.pl 2015 |
| OriginalFilename | DataServer.exe |
| ProductName | MuEMU DataServer |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | Portuguese - Brazil |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Sep-17 15:18:15 |
| Version | 0.0 |
| SizeofData | 123 |
| AddressOfRawData | 0x1a250 |
| PointerToRawData | 0x19250 |
| Referenced File | D:\Cosas Agu\Sources\Trabajos\Trabajo Naldo\eMU\DataServer\Release\DataServer_EX301\DataServer.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x41d018 |
| SEHandlerTable | 0x41ace0 |
| SEHandlerCount | 26 |
| XOR Key | 0x46fe6491 |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 1 |
| ASM objects (VS2010 build 30319) | 3 |
| C objects (VS2010 build 30319) | 19 |
| Imports (VS2010 build 30319) | 4 |
| C++ objects (VS2010 build 30319) | 6 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 164 |
| 175 (VS2010 build 30319) | 41 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |