Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2015-Dec-12 10:09:23 |
Detected languages |
English - United States
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2015-Dec-12 10:09:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x16a00 |
SizeOfInitializedData | 0x6e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000798D (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x18000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x24274 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SETUPAPI.dll |
SetupDiGetClassDevsA
SetupDiEnumDeviceInterfaces SetupDiGetDeviceInterfaceDetailA SetupDiDestroyDeviceInfoList |
---|---|
KERNEL32.dll |
VirtualFree
GetProcessHeap SetEndOfFile CreateFileA DeviceIoControl CloseHandle CreateMutexA InterlockedIncrement InterlockedDecrement Sleep InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection RtlUnwind TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RaiseException GetLastError HeapFree ReadConsoleInputA SetConsoleMode GetConsoleMode GetCommandLineA LCMapStringA WideCharToMultiByte MultiByteToWideChar LCMapStringW GetCPInfo HeapAlloc GetModuleHandleW GetProcAddress TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError GetCurrentThreadId HeapCreate VirtualAlloc HeapReAlloc SetHandleCount GetStdHandle GetFileType GetStartupInfoA WriteFile GetConsoleCP FlushFileBuffers ReadFile SetFilePointer HeapSize ExitProcess GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetACP GetOEMCP IsValidCodePage GetLocaleInfoA GetStringTypeA GetStringTypeW GetUserDefaultLCID EnumSystemLocalesA IsValidLocale InitializeCriticalSectionAndSpinCount WriteConsoleA GetConsoleOutputCP WriteConsoleW SetStdHandle LoadLibraryA GetLocaleInfoW CreateFileW |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x41e8e0 |
SEHandlerTable | 0x41b8b0 |
SEHandlerCount | 38 |
XOR Key | 0x3b3757da |
---|---|
Unmarked objects | 0 |
ASM objects (VS2008 build 21022) | 17 |
C objects (VS2008 build 21022) | 124 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 5 |
Total imports | 99 |
C++ objects (VS2008 build 21022) | 56 |
Resource objects (VS2008 build 21022) | 1 |