Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2016-May-21 03:09:54 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\Paul\Documents\Visual Studio 2013\Projects\Keylogger\Release\Keylogger.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2016-May-21 03:09:54 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0xe600 |
SizeOfInitializedData | 0xe200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000029F5 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x10000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x21000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
Sleep
GetModuleFileNameW CopyFileW CreateEventW GetLastError GetModuleHandleW WriteConsoleW SetStdHandle FlushFileBuffers SetFilePointerEx GetConsoleMode GetConsoleCP GetStringTypeW LCMapStringW HeapReAlloc InitializeSListHead CloseHandle GetCurrentProcess GetCurrentThread GetCurrentThreadId GetSystemTimeAsFileTime EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer ExitProcess GetModuleHandleExW GetProcAddress MultiByteToWideChar WideCharToMultiByte HeapAlloc IsDebuggerPresent IsProcessorFeaturePresent GetCommandLineA RaiseException RtlUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter SetLastError InitializeCriticalSectionAndSpinCount TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetStartupInfoW LoadLibraryExW HeapFree SetEvent HeapSize GetStdHandle WriteFile IsValidCodePage GetACP GetOEMCP GetCPInfo GetProcessHeap GetFileType GetModuleFileNameA QueryPerformanceCounter GetCurrentProcessId GetEnvironmentStringsW FreeEnvironmentStringsW OutputDebugStringW GetThreadTimes CreateFileW |
---|---|
SHELL32.dll |
SHGetSpecialFolderPathW
|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-May-21 03:09:54 |
Version | 0.0 |
SizeofData | 108 |
AddressOfRawData | 0x15f78 |
PointerToRawData | 0x14978 |
Referenced File | C:\Users\Paul\Documents\Visual Studio 2013\Projects\Keylogger\Release\Keylogger.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-May-21 03:09:54 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x15fe4 |
PointerToRawData | 0x149e4 |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x418294 |
SEHandlerTable | 0x416420 |
SEHandlerCount | 12 |
XOR Key | 0xa1362910 |
---|---|
Unmarked objects | 0 |
ASM objects (20806) | 29 |
C++ objects (20806) | 108 |
C objects (20806) | 141 |
Imports (VS2008 SP1 build 30729) | 9 |
Total imports | 139 |
229 (VS2013 build 21005) | 3 |
Resource objects (VS2013 build 21005) | 1 |
Linker (VS2013 build 21005) | 1 |