Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2018-Jan-23 09:34:48 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/72 (Scanned on 2024-04-01 16:35:05) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2018-Jan-23 09:34:48 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xe400 |
SizeOfInitializedData | 0x8600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000027CB (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x10000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1a000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
lua51.dll |
lua_gettop
luaJIT_version_2_1_0_beta3 luaL_openlibs luaL_traceback luaL_newstate luaL_loadbuffer luaL_loadfile luaL_where luaL_callmeta lua_sethook lua_concat lua_error lua_gc lua_cpcall lua_pcall lua_call lua_rawseti lua_setfield lua_createtable lua_rawgeti lua_getfield lua_gettable lua_pushboolean lua_pushcclosure lua_pushfstring lua_pushstring lua_pushlstring lua_pushnil lua_objlen lua_tolstring lua_toboolean lua_type lua_isstring lua_insert lua_remove lua_pushvalue lua_settop lua_close |
---|---|
KERNEL32.dll |
TlsAlloc
DecodePointer ReadConsoleW ReadFile WriteConsoleW CreateFileW CloseHandle HeapReAlloc HeapSize SetFilePointerEx GetProcessHeap GetStringTypeW SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetCPInfo GetOEMCP IsValidCodePage FindNextFileA FindFirstFileExA FindClose GetConsoleMode GetConsoleCP FlushFileBuffers GetFileType LCMapStringW CompareStringW UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead IsDebuggerPresent GetStartupInfoW GetModuleHandleW RtlUnwind GetLastError SetLastError EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount RaiseException TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW SetConsoleCtrlHandler GetStdHandle WriteFile GetModuleFileNameA MultiByteToWideChar WideCharToMultiByte ExitProcess GetModuleHandleExW GetCommandLineA GetCommandLineW GetACP HeapFree HeapAlloc |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jan-23 09:34:48 |
Version | 0.0 |
SizeofData | 616 |
AddressOfRawData | 0x14eec |
PointerToRawData | 0x136ec |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x416004 |
SEHandlerTable | 0x414ee0 |
SEHandlerCount | 3 |
XOR Key | 0xf7e397b1 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v15.?.? build 25203) | 10 |
C++ objects (VS2017 v15.?.? build 25203) | 139 |
C objects (VS2017 v15.?.? build 25203) | 18 |
Imports (VS2017 v15.?.? build 25203) | 2 |
ASM objects (VS2015/2017 runtime 25810) | 18 |
C++ objects (VS2015/2017 runtime 25810) | 29 |
C objects (VS2015/2017 runtime 25810) | 17 |
Imports (VS2017 v15.5.3-4 build 25834) | 3 |
Total imports | 122 |
C objects (VS2017 v15.5.3-4 build 25834) | 1 |
Linker (VS2017 v15.5.3-4 build 25834) | 1 |