Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2013-May-09 14:21:53 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2013-May-09 14:21:53 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0xca00 |
SizeOfInitializedData | 0x4e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00002613 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xe000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x14000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GenerateConsoleCtrlEvent
GetExitCodeProcess WaitForSingleObject CreateProcessA SetConsoleCtrlHandler GetModuleFileNameA EnterCriticalSection LeaveCriticalSection GetModuleHandleW Sleep GetProcAddress ExitProcess GetCommandLineA GetStartupInfoA SetHandleCount GetStdHandle GetFileType DeleteCriticalSection TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetLastError HeapFree HeapAlloc GetCPInfo InterlockedIncrement InterlockedDecrement GetACP GetOEMCP IsValidCodePage TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError GetCurrentThreadId WriteFile LoadLibraryA InitializeCriticalSectionAndSpinCount FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime RtlUnwind HeapReAlloc VirtualAlloc GetConsoleCP GetConsoleMode FlushFileBuffers LCMapStringA MultiByteToWideChar LCMapStringW GetStringTypeA GetStringTypeW GetLocaleInfoA SetFilePointer HeapSize CloseHandle WriteConsoleA GetConsoleOutputCP WriteConsoleW SetStdHandle CreateFileA CompareStringA CompareStringW SetEnvironmentVariableA ReadFile SetEndOfFile GetProcessHeap GetFileAttributesA |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x411280 |
SEHandlerTable | 0x40f4d0 |
SEHandlerCount | 3 |
XOR Key | 0x8bae32a0 |
---|---|
Unmarked objects | 0 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 3 |
Total imports | 91 |
150 (20413) | 4 |
C++ objects (VS2008 build 21022) | 36 |
ASM objects (VS2008 build 21022) | 18 |
C objects (VS2008 build 21022) | 113 |
Resource objects (VS2008 build 21022) | 1 |