Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2020-May-20 20:57:01 |
Debug artifacts |
F:\workspace\_work\1\s\artifacts\obj\win-x86.Release\corehost\cli\apphost\Release\apphost.pdb
|
CompanyName | Timeless |
FileDescription | Timeless |
FileVersion | 1.0.0.0 |
InternalName | Timeless.dll |
LegalCopyright | |
OriginalFilename | Timeless.dll |
ProductName | Timeless |
ProductVersion | 1.0.0 |
Assembly Version | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
22938946 bytes of data starting at offset 0x21c00.
Overlay data amounts for 99.401% of the executable. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2020-May-20 20:57:01 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x15000 |
SizeOfInitializedData | 0xc800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00011690 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x16000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x25000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x180000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FindClose
FindFirstFileExW FindNextFileW GetFileAttributesExW GetFullPathNameW GetTempPathW GetLastError InitializeCriticalSection EnterCriticalSection LeaveCriticalSection GetEnvironmentVariableW GetCurrentProcess IsWow64Process GetModuleFileNameW GetModuleHandleExW GetProcAddress LoadLibraryExW LoadLibraryA MultiByteToWideChar WideCharToMultiByte FreeLibrary RtlUnwind RaiseException OutputDebugStringW GetModuleHandleW GetCurrentProcessId Sleep RemoveDirectoryW DeleteCriticalSection CreateDirectoryW InitializeSListHead GetCurrentThreadId QueryPerformanceCounter IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter LCMapStringW GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc SwitchToThread InitializeCriticalSectionAndSpinCount SetLastError DecodePointer EncodePointer GetStringTypeW |
---|---|
USER32.dll |
MessageBoxW
|
SHELL32.dll |
ShellExecuteW
|
ADVAPI32.dll |
RegOpenKeyExW
RegCloseKey ReportEventW RegisterEventSourceW DeregisterEventSource RegGetValueW |
api-ms-win-crt-runtime-l1-1-0.dll |
terminate
_controlfp_s _register_thread_local_exe_atexit_callback _errno _c_exit __p___wargv _seh_filter_exe __p___argc _configure_wide_argv _cexit _crt_atexit _exit exit _register_onexit_function _initialize_onexit_table _set_app_type _initterm_e _initterm _get_initial_wide_environment _invalid_parameter_noinfo_noreturn _initialize_wide_environment abort |
api-ms-win-crt-heap-l1-1-0.dll |
calloc
free _set_new_mode _callnewh malloc |
api-ms-win-crt-math-l1-1-0.dll |
frexp
__setusermatherr |
api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__stdio_common_vsprintf_s __p__commode fflush _wfopen __stdio_common_vfwprintf fputws fclose fread fseek fwrite __acrt_iob_func fputwc __stdio_common_vswprintf |
api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
memset strcspn wcsncmp _wcsicmp _wcsnicmp wcsnlen _wcsdup |
api-ms-win-crt-locale-l1-1-0.dll |
__pctype_func
setlocale ___mb_cur_max_func ___lc_codepage_func ___lc_locale_name_func localeconv _unlock_locales _lock_locales _configthreadlocale |
api-ms-win-crt-filesystem-l1-1-0.dll |
_wrename
_wremove |
api-ms-win-crt-convert-l1-1-0.dll |
wcstoul
_wtoi |
api-ms-win-crt-time-l1-1-0.dll |
_time64
wcsftime _gmtime64 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Timeless |
FileDescription | Timeless |
FileVersion (#2) | 1.0.0.0 |
InternalName | Timeless.dll |
LegalCopyright | |
OriginalFilename | Timeless.dll |
ProductName | Timeless |
ProductVersion (#2) | 1.0.0 |
Assembly Version | 1.0.0.0 |
Resource LangID | UNKNOWN |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-20 20:57:01 |
Version | 0.0 |
SizeofData | 118 |
AddressOfRawData | 0x1d534 |
PointerToRawData | 0x1c934 |
Referenced File | F:\workspace\_work\1\s\artifacts\obj\win-x86.Release\corehost\cli\apphost\Release\apphost.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-20 20:57:01 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x1d5ac |
PointerToRawData | 0x1c9ac |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-May-20 20:57:01 |
Version | 0.0 |
SizeofData | 856 |
AddressOfRawData | 0x1d5c0 |
PointerToRawData | 0x1c9c0 |
StartAddressOfRawData | 0x41d928 |
---|---|
EndAddressOfRawData | 0x41d930 |
AddressOfIndex | 0x420e34 |
AddressOfCallbacks | 0x416280 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x420534 |
SEHandlerTable | 0x41d400 |
SEHandlerCount | 77 |
GuardCFCheckFunctionPointer | 4284968 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xc8c41d4a |
---|---|
Unmarked objects | 0 |
ASM objects (VS 2015/2017 runtime 26706) | 13 |
C++ objects (VS 2015/2017 runtime 26706) | 61 |
C objects (VS 2015/2017 runtime 26706) | 32 |
Imports (VS2008 SP1 build 30729) | 18 |
Imports (VS2015/2017 runtime 25711) | 9 |
Total imports | 165 |
C++ objects (27039) | 13 |
Linker (27039) | 1 |