Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2013-Dec-07 21:16:01 |
Detected languages |
German - Germany
|
Debug artifacts |
ParkdaleCmd.dbg
|
Comments | http://j.mp/the_sz |
CompanyName | CompSoft |
FileDescription | ParkdaleCmd |
FileVersion | 1.01 |
InternalName | ParkdaleCmd |
LegalCopyright | Copyright © 2013 |
LegalTrademarks | |
OriginalFilename | ParkdaleCmd.exe |
PrivateBuild | |
ProductName | CompSoft ParkdaleCmd |
ProductVersion | 1.01 |
SpecialBuild | The SZ |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to AES Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 272 bytes of data starting at offset 0x41000. |
Safe | VirusTotal score: 0/62 (Scanned on 2017-05-15 09:59:40) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2013-Dec-07 21:16:01 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x1b000 |
SizeOfInitializedData | 0x27000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00010514 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1c000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x43000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x411e4 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
LocalFree
GetCommandLineA GetSystemTime GetLocalTime FileTimeToSystemTime FileTimeToLocalFileTime GetDateFormatA GetTimeFormatA GetTickCount GetModuleFileNameA LocalAlloc MulDiv SetUnhandledExceptionFilter GetThreadSelectorEntry GetCurrentProcessId GetVersionExA GetCurrentThreadId LoadLibraryA FreeLibrary GetProcAddress Sleep CreateThread TerminateThread GetEnvironmentVariableA GetVolumeInformationA CreateEventA SetEvent WaitForMultipleObjectsEx InitializeCriticalSection DeleteCriticalSection EnterCriticalSection QueryPerformanceCounter TerminateProcess RtlUnwind HeapFree HeapAlloc GetVersion ExitProcess HeapReAlloc RaiseException HeapSize TlsSetValue TlsAlloc SetLastError TlsGetValue HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW SetHandleCount GetStdHandle GetFileType GetStartupInfoA GetCPInfo GetACP GetOEMCP LCMapStringA LCMapStringW IsBadReadPtr IsBadCodePtr GetStringTypeA GetStringTypeW SetStdHandle OpenFileMappingA CreateFileMappingA MapViewOfFile SetEndOfFile SetFilePointer UnmapViewOfFile FlushFileBuffers WriteFile ReadFile DeleteFileA CreateDirectoryA SetFileAttributesA GetWindowsDirectoryA GetCurrentProcess GetTempPathA GetFileSize SetErrorMode GetFileAttributesA CreateFileA CloseHandle InterlockedIncrement InterlockedDecrement MultiByteToWideChar GetThreadLocale GetStringTypeExA WideCharToMultiByte lstrlenA FormatMessageA GetModuleHandleA RemoveDirectoryA LeaveCriticalSection GetLastError |
---|---|
WINMM.dll |
timeGetTime
|
VERSION.dll |
VerQueryValueA
GetFileVersionInfoA GetFileVersionInfoSizeA |
USER32.dll |
GetKeyState
GetDlgCtrlID InflateRect GetSysColor GetWindowTextA GetWindowTextLengthA PtInRect GetCursorPos PostMessageA WindowFromPoint FrameRect FillRect GetDC DrawTextA ReleaseDC TranslateMessage DispatchMessageA MsgWaitForMultipleObjects MapDialogRect SetTimer KillTimer PeekMessageA PostQuitMessage DestroyWindow GetParent ScreenToClient CharNextA ShowWindow InvalidateRect GetClientRect MapWindowPoints LoadCursorA SetCursor SetWindowPos GetForegroundWindow DialogBoxIndirectParamA RemovePropA GetWindowLongA SetWindowLongA SetWindowTextA GetSystemMetrics LoadImageA LoadIconA GetDlgItem SetDlgItemTextA GetDlgItemTextA EndDialog SystemParametersInfoA SendMessageA CreateWindowExW CallWindowProcA GetPropA SetPropA BeginPaint DrawEdge EndPaint GetWindowRect DrawFocusRect SendDlgItemMessageA |
GDI32.dll |
GetTextExtentPoint32A
SetBkMode SetBkColor CreateSolidBrush SetStretchBltMode StretchBlt BitBlt CreateFontA EnumFontFamiliesExA DeleteObject RestoreDC GetStockObject SetTextColor CreateCompatibleDC GetDeviceCaps GetObjectA CreateFontIndirectA SaveDC SelectObject GetTextMetricsA DeleteDC |
ADVAPI32.dll |
CryptAcquireContextA
RegCloseKey RegQueryValueExA RegOpenKeyExA CryptReleaseContext CryptGenRandom |
SHELL32.dll |
ShellExecuteExA
|
ole32.dll |
CoSetProxyBlanket
OleRun CoInitializeSecurity CoUninitialize CoCreateInstance CoInitialize |
OLEAUT32.dll |
#6
#2 #9 #148 #8 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.1.1 |
ProductVersion | 1.0.1.1 |
FileFlags |
VS_FF_SPECIALBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | German - Germany |
Comments | http://j.mp/the_sz |
CompanyName | CompSoft |
FileDescription | ParkdaleCmd |
FileVersion (#2) | 1.01 |
InternalName | ParkdaleCmd |
LegalCopyright | Copyright © 2013 |
LegalTrademarks | |
OriginalFilename | ParkdaleCmd.exe |
PrivateBuild | |
ProductName | CompSoft ParkdaleCmd |
ProductVersion (#2) | 1.01 |
SpecialBuild | The SZ |
Resource LangID | German - Germany |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2013-Dec-07 21:16:01 |
Version | 0.0 |
SizeofData | 272 |
AddressOfRawData | 0 |
PointerToRawData | 0x41000 |
Referenced File | ParkdaleCmd.dbg |
XOR Key | 0xac55e266 |
---|---|
Unmarked objects | 0 |
C objects (VS98 build 8168) | 1 |
14 (7299) | 28 |
C objects (VS98 SP6 build 8804) | 141 |
C++ objects (8798) | 3 |
37 (8755) | 2 |
C objects (9178) | 3 |
Imports (9210) | 19 |
Total imports | 344 |
C++ objects (VS98 SP6 build 8804) | 54 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |