Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2017-Feb-20 10:20:02 |
Detected languages |
English - United States
Russian - Russia |
CompanyName | TODO: <Company name> |
FileDescription | TODO: <File description> |
FileVersion | 1.0.0.1 |
InternalName | NewTempl.exe |
LegalCopyright | Copyright (C) 2017 |
OriginalFilename | NewTempl.exe |
ProductName | TODO: <Product name> |
ProductVersion | 1.0.0.1 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE is possibly packed. | Unusual section name found: .er |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | No VirusTotal score. | A scan if the file is currently queued. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2017-Feb-20 10:20:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x19200 |
SizeOfInitializedData | 0x13400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00006C58 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1b000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x169000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetLogicalDriveStringsA
QueryDosDeviceA GetLastError VirtualProtect WriteConsoleW FlushFileBuffers WideCharToMultiByte EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer SetLastError InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetModuleHandleW GetProcAddress MultiByteToWideChar GetStringTypeW LCMapStringW GetLocaleInfoW GetCPInfo UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead IsDebuggerPresent GetStartupInfoW RaiseException RtlUnwind FreeLibrary LoadLibraryExW HeapAlloc HeapReAlloc HeapFree GetStdHandle WriteFile GetModuleFileNameW ExitProcess GetModuleHandleExW GetACP IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetProcessHeap GetFileType CloseHandle FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle HeapSize GetConsoleCP GetConsoleMode SetFilePointerEx CreateFileW |
---|---|
SHELL32.dll |
SHGetFolderPathW
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.1 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Russian - Russia |
CompanyName | TODO: <Company name> |
FileDescription | TODO: <File description> |
FileVersion (#2) | 1.0.0.1 |
InternalName | NewTempl.exe |
LegalCopyright | Copyright (C) 2017 |
OriginalFilename | NewTempl.exe |
ProductName | TODO: <Product name> |
ProductVersion (#2) | 1.0.0.1 |
Resource LangID | Russian - Russia |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-20 10:20:02 |
Version | 0.0 |
SizeofData | 864 |
AddressOfRawData | 0x260f0 |
PointerToRawData | 0x246f0 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2017-Feb-20 10:20:02 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x5c |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x42806c |
SEHandlerTable | 0x426070 |
SEHandlerCount | 32 |
XOR Key | 0x5fb60089 |
---|---|
Unmarked objects | 0 |
241 (40116) | 12 |
243 (40116) | 134 |
242 (40116) | 29 |
ASM objects (VS2015 UPD3 build 24123) | 20 |
C++ objects (VS2015 UPD3 build 24123) | 51 |
C objects (VS2015 UPD3 build 24123) | 34 |
Imports (65501) | 5 |
Total imports | 92 |
265 (VS2015 UPD3 build 24210) | 3 |
Resource objects (VS2015 UPD3 build 24210) | 1 |
151 | 1 |
Linker (VS2015 UPD3 build 24210) | 1 |