Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-May-26 15:14:19 |
Detected languages |
English - United States
|
Debug artifacts |
D:\dev\factoryio2.5\_buildProj\build\bin\x86\Master\Factory IO_x86_Master_mono.pdb
|
FileVersion | 2019.3.14.2831115 |
ProductVersion | 2019.3.14.2831115 |
Unity Version | 2019.3.14f1_2b330bf6d2d8 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Real Games Unipessoal Lda
Issuer: DigiCert EV Code Signing CA (SHA2) |
Suspicious | VirusTotal score: 1/73 (Scanned on 2020-07-04 20:05:42) | Ikarus: Trojan-Ransom.FileCrypter |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2020-May-26 15:14:19 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x1c800 |
SizeOfInitializedData | 0x18000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005B19 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x37000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3ae11 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetModuleFileNameW
WriteConsoleW HeapSize CreateFileW GetLastError WideCharToMultiByte EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetLastError InitializeCriticalSectionAndSpinCount SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetModuleHandleW GetProcAddress EncodePointer DecodePointer MultiByteToWideChar LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess RaiseException RtlUnwind FreeLibrary LoadLibraryExW GetStdHandle WriteFile ExitProcess GetModuleHandleExW HeapAlloc HeapFree IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType CloseHandle FlushFileBuffers GetConsoleCP GetConsoleMode ReadFile GetFileSizeEx SetFilePointerEx ReadConsoleW HeapReAlloc FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle GetProcessHeap SetEndOfFile |
---|---|
UnityPlayer.dll |
UnityMain
|
Ordinal | 1 |
---|---|
Address | 0x2c004 |
Ordinal | 2 |
---|---|
Address | 0x2c000 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 2019.3.14.13067 |
ProductVersion | 2019.3.14.13067 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
FileVersion (#2) | 2019.3.14.2831115 |
ProductVersion (#2) | 2019.3.14.2831115 |
Unity Version | 2019.3.14f1_2b330bf6d2d8 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-26 15:14:19 |
Version | 0.0 |
SizeofData | 107 |
AddressOfRawData | 0x2a474 |
PointerToRawData | 0x29074 |
Referenced File | D:\dev\factoryio2.5\_buildProj\build\bin\x86\Master\Factory IO_x86_Master_mono.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-26 15:14:19 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x2a4e0 |
PointerToRawData | 0x290e0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-26 15:14:19 |
Version | 0.0 |
SizeofData | 804 |
AddressOfRawData | 0x2a4f4 |
PointerToRawData | 0x290f4 |
Size | 0xa4 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x42c038 |
SEHandlerTable | 0x42a410 |
SEHandlerCount | 25 |
XOR Key | 0xdf80878d |
---|---|
Unmarked objects | 0 |
ASM objects (26715) | 13 |
C++ objects (26715) | 172 |
C objects (26715) | 22 |
C objects (VS 2015/2017/2019 runtime 28117) | 17 |
ASM objects (VS 2015/2017/2019 runtime 28117) | 20 |
C++ objects (VS 2015/2017/2019 runtime 28117) | 77 |
Imports (VS2019 Update 4 (16.4.0-2) compiler 28314) | 2 |
Imports (26715) | 3 |
Total imports | 87 |
C++ objects (VS2019 Update 4 (16.4.0-2) compiler 28314) | 2 |
Exports (VS2019 Update 4 (16.4.0-2) compiler 28314) | 1 |
Resource objects (VS2019 Update 4 (16.4.0-2) compiler 28314) | 1 |
Linker (VS2019 Update 4 (16.4.0-2) compiler 28314) | 1 |