Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Aug-16 23:51:52 |
Detected languages |
English - New Zealand
English - United States |
Debug artifacts |
C:\Users\nev.NZWLGPC1490\Documents\Visual Studio 2017\Projects\ATLProject1\Debug\ATLProject1.pdb
|
CompanyName | TODO: <Company name> |
FileDescription | TODO: <File description> |
FileVersion | 1.0.0.1 |
LegalCopyright | TODO: (c) <Company name>. All rights reserved. |
InternalName | ATLProject1.exe |
OriginalFilename | ATLProject1.exe |
ProductName | TODO: <Product name> |
ProductVersion | 1.0.0.1 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: | References the BITS service |
Suspicious | The PE is possibly packed. | Section .textbss is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Custom Software Limited
Issuer: Go Daddy Secure Certificate Authority - G2 |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2018-Aug-16 23:51:52 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xc4e00 |
SizeOfInitializedData | 0x3c200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0005EB75 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x161000 |
SizeOfHeaders | 0x400 |
Checksum | 0x10b21e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CreateEventA
Sleep CreateThread GetCurrentThreadId FreeLibrary GetModuleFileNameA GetModuleHandleA GetModuleHandleW GetProcAddress LoadLibraryExA LoadResource SizeofResource FormatMessageA lstrcmpiA FindResourceA MultiByteToWideChar WideCharToMultiByte IsDBCSLeadByte OutputDebugStringA SetWaitableTimer CancelWaitableTimer WaitForSingleObject LocalFree CreateWaitableTimerA GetThreadLocale IsDebuggerPresent OutputDebugStringW EnterCriticalSection LeaveCriticalSection FlushFileBuffers SetFilePointerEx GetConsoleMode GetConsoleCP GetStringTypeW SetStdHandle SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCPInfo GetOEMCP GetACP IsValidCodePage FindNextFileW SetEvent DeleteCriticalSection InitializeCriticalSectionEx SetLastError GetLastError RaiseException CloseHandle DecodePointer LocalAlloc GetCommandLineA FindFirstFileExW FindClose HeapQueryInformation SetConsoleCtrlHandler WriteConsoleW GetFileType EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW CreateFileW GetDateFormatW HeapReAlloc HeapSize GetCurrentThread WriteFile GetStdHandle ExitProcess HeapValidate InitializeCriticalSectionAndSpinCount CreateEventW SwitchToThread TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetTickCount UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId InitializeSListHead HeapAlloc HeapFree GetProcessHeap VirtualQuery RtlUnwind InterlockedPushEntrySList InterlockedFlushSList GetModuleFileNameW LoadLibraryExW EncodePointer GetSystemInfo VirtualAlloc VirtualProtect GetModuleHandleExW |
---|---|
USER32.dll |
SetWindowTextA
TranslateMessage DispatchMessageA SendMessageA PostThreadMessageA UnregisterClassA CreateWindowExA CharUpperA CharNextA CharNextW GetSystemMetrics MessageBoxA GetMessageA |
ADVAPI32.dll |
RegSetValueExA
RegQueryInfoKeyW RegQueryInfoKeyA RegOpenKeyExA RegEnumKeyExA RegDeleteValueA RegDeleteKeyA RegCreateKeyExA RegCloseKey |
ole32.dll |
CoUninitialize
CoRegisterClassObject CoInitializeEx CoResumeClassObjects CoAddRefServerProcess CoReleaseServerProcess CoCreateInstance StringFromGUID2 CoTaskMemAlloc CoTaskMemRealloc CoTaskMemFree CoInitialize CoRevokeClassObject |
OLEAUT32.dll |
#163
#161 #277 #7 #6 #2 #186 |
ATLProject1 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.1 |
ProductVersion | 1.0.0.1 |
FileFlags |
VS_FF_DEBUG
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | TODO: <Company name> |
FileDescription | TODO: <File description> |
FileVersion (#2) | 1.0.0.1 |
LegalCopyright | TODO: (c) <Company name>. All rights reserved. |
InternalName | ATLProject1.exe |
OriginalFilename | ATLProject1.exe |
ProductName | TODO: <Product name> |
ProductVersion (#2) | 1.0.0.1 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Aug-16 20:57:33 |
Version | 0.0 |
SizeofData | 121 |
AddressOfRawData | 0x14b564 |
PointerToRawData | 0xef764 |
Referenced File | C:\Users\nev.NZWLGPC1490\Documents\Visual Studio 2017\Projects\ATLProject1\Debug\ATLProject1.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Aug-16 20:57:33 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x14b5e0 |
PointerToRawData | 0xef7e0 |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x54f0a0 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0xcc632d48 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2015/2017 runtime 25711) | 13 |
C++ objects (VS2015/2017 runtime 25711) | 154 |
ASM objects (VS2017 v15.6.6 compiler 26131) | 21 |
C objects (VS2017 v15.6.6 compiler 26131) | 17 |
Imports (VS2015/2017 runtime 25711) | 11 |
Total imports | 150 |
C++ objects (VS2017 v15.6.6 compiler 26131) | 56 |
C objects (VS2015/2017 runtime 25711) | 20 |
C objects (VS2017 v15.7.2 compiler 26429) | 1 |
C++ objects (VS2017 v15.7.2 compiler 26429) | 5 |
Resource objects (VS2017 v15.7.2 compiler 26429) | 1 |
151 | 1 |
Linker (VS2017 v15.7.2 compiler 26429) | 1 |