Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Oct-01 17:03:14 |
Detected languages |
English - United States
|
Debug artifacts |
G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb
|
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to AES |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x160 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2024-Oct-01 17:03:14 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x434400 |
SizeOfInitializedData | 0x1ca9e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x003DF394 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x436000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x20e2000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoA GetFileVersionInfoSizeA |
---|---|
WINMM.dll |
timeGetTime
|
WS2_32.dll |
WSAAsyncSelect
connect setsockopt send htons socket WSAStartup recv closesocket gethostbyname inet_addr inet_ntoa WSAGetLastError |
DDRAW.dll |
DirectDrawCreate
|
KERNEL32.dll |
WaitForSingleObject
SetEvent CreateEventA GetLocaleInfoA CompareStringA LoadLibraryA GetProcAddress FreeLibrary GetSystemDirectoryA WaitForSingleObjectEx CreateThread GetVolumeInformationA FindNextFileA GetCurrentThreadId FormatMessageA LocalFree FileTimeToLocalFileTime GetCommandLineW CreateDirectoryW DeleteFileW FlushFileBuffers GetOEMCP GetACP IsValidCodePage GetFileSizeEx SetEndOfFile SetStdHandle GetTimeZoneInformation EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW GetTempPathW GetStdHandle ExitProcess FindNextFileW FindFirstFileExW WritePrivateProfileStringA SetCurrentDirectoryW SetEnvironmentVariableW GetFullPathNameW SystemTimeToTzSpecificLocalTime GetFileInformationByHandle GetSystemInfo GetConsoleOutputCP ReadConsoleW GetConsoleMode SetFilePointerEx GetFileType GetModuleHandleExW FreeLibraryAndExitThread ExitThread LoadLibraryExW TlsFree TlsSetValue LeaveCriticalSection TlsAlloc SetLastError RtlUnwind VirtualAlloc VirtualFree InterlockedCompareExchange InterlockedExchange UnmapViewOfFile CreateFileMappingA MapViewOfFile TerminateProcess GetProcessHeap DeleteCriticalSection DecodePointer HeapAlloc RaiseException HeapReAlloc HeapSize InitializeCriticalSectionEx HeapFree GetVersionExA CreateIoCompletionPort CancelIo EnterCriticalSection GetTickCount Sleep MultiByteToWideChar GetModuleFileNameW lstrlenW WaitNamedPipeW GetCurrentProcessId CloseHandle GetLastError OutputDebugStringA CreateFileW PeekNamedPipe WriteFile ReadFile GetModuleHandleA GetModuleFileNameA GetLocalTime FileTimeToSystemTime OutputDebugStringW QueryPerformanceCounter WideCharToMultiByte GetFileSize GlobalUnlock CreateDirectoryA GlobalLock GlobalFree GlobalAlloc SetCurrentDirectoryA GetCurrentDirectoryA FindClose FindFirstFileA InitializeCriticalSection GetSystemTime GetModuleHandleW GlobalMemoryStatusEx TlsGetValue IsDBCSLeadByte lstrcpyA QueryPerformanceFrequency CreateFileA lstrlenA GetFullPathNameA GetDriveTypeW GetPrivateProfileStringA GetCPInfo CompareStringEx LCMapStringEx EncodePointer GetEnvironmentStringsW FreeEnvironmentStringsW GetCurrentDirectoryW WriteConsoleW GetPrivateProfileIntA GetCurrentProcess lstrcmpiA GetComputerNameA GetCommandLineA IsBadReadPtr SetUnhandledExceptionFilter CopyFileA InitializeCriticalSectionAndSpinCount ResetEvent CreateEventW UnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive TryEnterCriticalSection InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableCS SleepConditionVariableSRW GetExitCodeThread GetStringTypeW |
USER32.dll |
LoadStringA
SetRect UnregisterClassA GetDC SetWindowTextA GetDesktopWindow wvsprintfW GetKeyboardLayout ClientToScreen ShowCursor SetCursorPos OffsetRect CopyRect GetWindowRect SetWindowPos ScreenToClient SetWindowLongA MoveWindow GetCursorPos PtInRect GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData FlashWindowEx ReleaseDC wsprintfA PostMessageA DefWindowProcW GetMessageA DispatchMessageA GetFocus LoadCursorA DestroyWindow FillRect GetSystemMetrics ShowWindow MessageBoxA AdjustWindowRect DefWindowProcA CreateWindowExA SetFocus TranslateMessage SendMessageA SetCursor LoadIconA SystemParametersInfoA GetClientRect PeekMessageA PostQuitMessage RegisterClassExA UpdateWindow |
GDI32.dll |
GetObjectW
GetTextMetricsA GetGlyphOutlineA GetCharacterPlacementA GetCharacterPlacementW SetBkMode GetTextMetricsW GetFontLanguageInfo CreateFontIndirectA CreateFontIndirectW SetTextAlign ExtTextOutA MoveToEx ExtTextOutW CreateDIBSection SetTextColor SetBkColor SetMapMode CreateFontA SetDeviceGammaRamp GetTextExtentPoint32A GetDeviceGammaRamp GetTextExtentPoint32W CreateDCA BitBlt CreateCompatibleBitmap SelectObject CreateCompatibleDC DeleteDC DeleteObject CreateSolidBrush GetObjectA |
ADVAPI32.dll |
RegSetValueExW
RegOpenKeyA RegCreateKeyExW RegCloseKey RegQueryValueExA GetUserNameA RegOpenKeyExA |
SHELL32.dll |
SHGetMalloc
SHGetPathFromIDListA ShellExecuteA SHBrowseForFolderA |
ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize |
OLEAUT32.dll |
VariantClear
SystemTimeToVariantTime SysStringLen VariantInit |
gdiplus.dll |
GdipSaveImageToFile
GdipAlloc GdiplusShutdown GdiplusStartup GdipFree GdipDisposeImage GdipCreateBitmapFromHBITMAP GdipCloneImage |
IMM32.dll |
ImmGetContext
ImmReleaseContext ImmGetConversionStatus ImmGetProperty ImmGetCompositionStringW ImmGetIMEFileNameA ImmAssociateContext ImmGetOpenStatus ImmSetConversionStatus ImmNotifyIME ImmGetCandidateListW ImmIsIME |
d3d9.dll |
Direct3DCreate9
|
DINPUT8.dll |
DirectInput8Create
|
DSOUND.dll |
#11
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_STATIC_LIB
|
Language | UNKNOWN |
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion (#2) | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 17:03:14 |
Version | 0.0 |
SizeofData | 107 |
AddressOfRawData | 0x49b4cc |
PointerToRawData | 0x499ccc |
Referenced File | G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 17:03:14 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x49b538 |
PointerToRawData | 0x499d38 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 17:03:14 |
Version | 0.0 |
SizeofData | 956 |
AddressOfRawData | 0x49b54c |
PointerToRawData | 0x499d4c |
StartAddressOfRawData | 0x89b918 |
---|---|
EndAddressOfRawData | 0x89b920 |
AddressOfIndex | 0x8c238c |
AddressOfCallbacks | 0x836d24 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xbc |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x8ae348 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x182965c7 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 46 |
C++ objects (27412) | 227 |
Imports (VS2003 (.NET) build 4035) | 2 |
C objects (VS2003 (.NET) build 4035) | 1 |
C objects (2067) | 12 |
18 (8444) | 6 |
253 (28518) | 3 |
C++ objects (30034) | 94 |
C objects (30034) | 22 |
ASM objects (30034) | 29 |
C objects (30154) | 10 |
C objects (27412) | 35 |
Imports (9210) | 6 |
C objects (9178) | 2 |
C++ objects (VS2003 (.NET) build 4035) | 127 |
Imports (27412) | 27 |
Total imports | 407 |
C objects (VC++ 6.0 SP5 build 8804) | 78 |
C++ objects (LTCG) (30154) | 472 |
Resource objects (30154) | 1 |
151 | 1 |
Linker (30154) | 1 |