| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Mar-07 10:30:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\builds\pc_1.3_1_1\pc\cod2\pc\CoD2SP_s.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: |
SafeDisc v4
SafeDisc 4 |
| Suspicious | The PE is possibly packed. | Section .text is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/67 (Scanned on 2026-02-11 03:26:40) |
APEX:
Malicious
CAT-QuickHeal: Trojan.Ghanarava.16412917750b1726 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 1970-Mar-07 10:30:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x16f000 |
| SizeOfInitializedData | 0x175b000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00155B43 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x16a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x18c4a46 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x10000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
GetUserNameA
|
|---|---|
| gdi32.dll |
CreateFontA
GetDeviceCaps SetDeviceGammaRamp CreateSolidBrush |
| kernel32.dll |
SetEndOfFile
GetTickCount SetStdHandle VirtualQuery GetSystemInfo VirtualProtect RaiseException GetOEMCP GetACP IsValidCodePage IsValidLocale EnumSystemLocalesA GetLocaleInfoA GetUserDefaultLCID GetCPInfo GetDateFormatA GetTimeFormatA GetStringTypeW GetStringTypeA HeapSize GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter RtlUnwind GetTimeZoneInformation GetFileType GetStdHandle LockResource GetLocaleInfoW IsBadWritePtr FatalAppExitA DeleteCriticalSection HeapCreate HeapDestroy SetFilePointer SetConsoleCtrlHandler LCMapStringW MultiByteToWideChar WideCharToMultiByte LCMapStringA TlsFree SetLastError GetCommandLineA GetStartupInfoA HeapReAlloc TerminateProcess ExitProcess GetFullPathNameA RemoveDirectoryA CreateDirectoryA FindNextFileA FindFirstFileA FileTimeToLocalFileTime FileTimeToSystemTime FindClose GetSystemTimeAsFileTime HeapAlloc HeapFree MoveFileA CompareStringA CompareStringW SetEnvironmentVariableA SetUnhandledExceptionFilter IsBadReadPtr FlushFileBuffers Module32Next SetPriorityClass MulDiv DeleteFileA GetCurrentProcessId CloseHandle GetVersionExA IsBadCodePtr CreateToolhelp32Snapshot GetCurrentDirectoryA GetModuleFileNameA LoadLibraryA GetCurrentThreadId Sleep GetFileAttributesA SetFileAttributesA VirtualFree VirtualAlloc GetCurrentProcess GetProcessAffinityMask TlsGetValue WaitForSingleObject SetEvent GetCurrentThread TlsSetValue CreateEventA InterlockedExchange ResetEvent WaitForMultipleObjects DuplicateHandle TlsAlloc SuspendThread ResumeThread CreateThread InitializeCriticalSection LeaveCriticalSection EnterCriticalSection GlobalMemoryStatus QueryPerformanceCounter GetProcAddress GetModuleHandleA QueryPerformanceFrequency CreateFileA SetErrorMode FreeLibrary GlobalSize GlobalLock SetThreadExecutionState FormatMessageA WriteFile GetDriveTypeA OpenProcess GlobalAlloc CreateProcessA ReadFile GlobalUnlock Module32First GetLastError |
| shell32.dll |
ShellExecuteA
|
| user32.dll |
MapVirtualKeyA
MonitorFromWindow RegisterClipboardFormatA PostQuitMessage SetWindowTextA CloseWindow MoveWindow GetMonitorInfoA SetClipboardData CallWindowProcA EnumThreadWindows ChangeDisplaySettingsA GetDesktopWindow ReleaseDC GetWindowLongA SetWindowLongA GetWindowTextA GetDC MessageBoxA ReleaseCapture PostMessageA GetCursorPos SetCursorPos GetForegroundWindow ShowCursor SetFocus SetForegroundWindow SetCapture GetWindowRect LoadCursorA OpenClipboard DispatchMessageA ShowWindow EmptyClipboard PeekMessageA GetClipboardData TranslateMessage LoadIconA RegisterClassExA CloseClipboard GetMessageA RegisterClassA AdjustWindowRect UpdateWindow LoadImageA GetSystemMetrics SetWindowPos DefWindowProcA CreateWindowExA SendMessageA DestroyWindow |
| winmm.dll |
timeBeginPeriod
timeGetTime timeEndPeriod |
| ws2_32.dll |
WSAGetLastError
inet_addr gethostbyname |
| d3d9.dll |
Direct3DCreate9
|
| mss32.dll |
_AIL_set_digital_master_reverb_levels@12
_AIL_sample_status@4 _AIL_3D_provider_attribute@12 _AIL_set_stream_playback_rate@8 _AIL_set_3D_sample_loop_count@8 _AIL_close_stream@4 _AIL_size_processed_digital_audio@16 _AIL_set_stream_reverb_levels@12 _AIL_set_3D_sample_distances@12 _AIL_3D_sample_offset@4 _AIL_set_sample_reverb_levels@12 _AIL_resume_sample@4 _AIL_3D_sample_status@4 _AIL_allocate_sample_handle@4 _AIL_sample_volume_levels@12 _AIL_stream_info@20 _AIL_init_sample@4 _AIL_stop_sample@4 _AIL_stream_ms_position@12 _AIL_set_3D_room_type@8 _AIL_set_sample_loop_count@8 _AIL_set_sample_playback_rate@8 _AIL_set_stream_loop_count@8 _AIL_set_preference@8 _AIL_stream_volume_levels@12 _AIL_set_sample_ms_position@8 _AIL_end_sample@4 _AIL_enumerate_3D_providers@12 _AIL_set_sample_adpcm_block_size@8 _AIL_set_3D_position@16 _AIL_allocate_3D_sample_handle@4 _AIL_set_3D_sample_offset@8 _AIL_open_stream@12 _AIL_set_3D_sample_playback_rate@8 _AIL_end_3D_sample@4 _AIL_set_3D_sample_volume@8 _AIL_stop_3D_sample@4 _AIL_set_stream_ms_position@8 _AIL_open_3D_provider@4 _AIL_resume_3D_sample@4 _AIL_3D_position@16 _AIL_stream_status@4 _AIL_sample_playback_rate@4 _AIL_load_sample_buffer@16 _AIL_set_sample_volume_levels@12 _AIL_sample_volume_pan@12 _AIL_minimum_sample_buffer_size@12 _AIL_sample_ms_position@12 _AIL_release_sample_handle@4 _AIL_set_DirectSound_HWND@8 _AIL_3D_sample_length@4 _AIL_set_redist_directory@4 _AIL_sample_buffer_ready@4 _AIL_3D_sample_playback_rate@4 _AIL_close_3D_provider@4 _AIL_stream_playback_rate@4 _AIL_set_stream_volume_levels@12 _AIL_set_3D_rolloff_factor@8 _AIL_set_file_callbacks@16 _AIL_stream_volume_pan@12 _AIL_set_sample_type@12 _AIL_last_error@0 _AIL_set_3D_distance_factor@8 _AIL_3D_sample_volume@4 _AIL_pause_stream@8 _AIL_set_sample_address@12 _AIL_set_3D_sample_info@8 _AIL_process_digital_audio@24 _AIL_WAV_info@8 _AIL_open_digital_driver@16 _AIL_startup@0 _AIL_digital_CPU_percent@4 _AIL_set_3D_sample_effects_level@8 _AIL_set_digital_master_room_type@8 _AIL_sample_position@4 _AIL_shutdown@0 |
| Call of Duty |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2006-Mar-31 03:37:27 |
| Version | 0.0 |
| SizeofData | 69 |
| AddressOfRawData | 0x1966b0 |
| PointerToRawData | 0x1966b0 |
| Referenced File | c:\builds\pc_1.3_1_1\pc\cod2\pc\CoD2SP_s.pdb |
| XOR Key | 0x1988d4c3 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2003 (.NET) build 3077) | 13 |
| 105 (2067) | 8 |
| ASM objects (VS2003 (.NET) build 3077) | 50 |
| C objects (VS2003 (.NET) build 3077) | 161 |
| Imports (9210) | 2 |
| Imports (2067) | 2 |
| Imports (VS2003 (.NET) build 4035) | 2 |
| C objects (VS2002 (.NET) build 9466) | 1 |
| Imports (VS2002 (.NET) build 9466) | 2 |
| Imports (2179) | 11 |
| Total imports | 265 |
| 100 (VS2003 (.NET) build 3077) | 260 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Linker (VS2003 (.NET) build 3077) | 1 |