| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Oct-23 21:30:53 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\devel\projects\bink\build\bink2w64.pdb
|
| CompanyName | RAD Game Tools, Inc. |
| FileDescription | RAD Video Tools |
| FileVersion | 2.7d/1.300d |
| LegalCopyright | Copyright (C) 1994-2017, RAD Game Tools, Inc. |
| LegalTrademarks | Bink and Smacker are trademarks of RAD Game Tools, Inc. |
| ProductName | Bink and Smacker |
| ProductVersion | 2.7d/1.300d |
| Comments | Thank you for using RAD Game Tools! |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: .l1
Section .l1 is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
5632 bytes of data starting at offset 0x5f5f0.
The overlay data has an entropy of 7.71333 and is possibly compressed or encrypted. |
| Safe | VirusTotal score: 0/70 (Scanned on 2026-05-07 07:00:07) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2017-Oct-23 21:30:53 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x3fa00 |
| SizeOfInitializedData | 0x37a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000037F68 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6aaf5 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| USER32.dll |
GetWindowLongPtrA
GetTopWindow GetWindowLongA GetDesktopWindow GetActiveWindow GetWindowThreadProcessId GetWindow MessageBoxA |
|---|---|
| KERNEL32.dll |
GetStringTypeW
GetStringTypeA LCMapStringW MultiByteToWideChar LCMapStringA GetSystemTimeAsFileTime RtlUnwindEx GetWindowsDirectoryA GetSystemDirectoryA GetModuleFileNameA SetErrorMode Sleep GetProcAddress LoadLibraryA GetSystemInfo GetModuleHandleA GetCurrentProcessId OutputDebugStringA QueryPerformanceCounter GetTickCount GetEnvironmentVariableA QueryPerformanceFrequency CreateFileA SetFilePointer ReadFile CloseHandle RemoveVectoredExceptionHandler WaitForSingleObject GetCurrentThread InitializeCriticalSection LeaveCriticalSection CreateSemaphoreA SetThreadPriority ReleaseSemaphore RaiseException GetLastError EnterCriticalSection AddVectoredExceptionHandler GetThreadPriority CreateMutexA DeleteCriticalSection GetCurrentThreadId ReleaseMutex ResumeThread CreateThread HeapAlloc HeapFree HeapCreate HeapSize InitializeCriticalSectionAndSpinCount WriteFile HeapReAlloc HeapDestroy GetLocaleInfoA FlsSetValue GetCommandLineA TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetCPInfo GetACP GetOEMCP IsValidCodePage EncodePointer DecodePointer FlsGetValue FlsFree SetLastError FlsAlloc GetModuleHandleW ExitProcess SetHandleCount GetStdHandle GetFileType GetStartupInfoA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW HeapSetInformation |
| ole32.dll |
CoCreateInstance
CoInitializeEx |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod timeGetTime waveOutWrite waveOutPause waveOutRestart waveOutReset waveOutSetVolume waveOutUnprepareHeader waveOutOpen waveOutPrepareHeader waveOutClose |
| 1911.dll |
Initialize
|
| Ordinal | 1 |
|---|---|
| Address | 0x51c0 |
| Ordinal | 2 |
|---|---|
| Address | 0x8d30 |
| Ordinal | 3 |
|---|---|
| Address | 0xa190 |
| Ordinal | 4 |
|---|---|
| Address | 0xa570 |
| Ordinal | 5 |
|---|---|
| Address | 0x7850 |
| Ordinal | 6 |
|---|---|
| Address | 0x78a0 |
| Ordinal | 7 |
|---|---|
| Address | 0x8630 |
| Ordinal | 8 |
|---|---|
| Address | 0xeb60 |
| Ordinal | 9 |
|---|---|
| Address | 0xe780 |
| Ordinal | 10 |
|---|---|
| Address | 0xeba0 |
| Ordinal | 11 |
|---|---|
| Address | 0x8550 |
| Ordinal | 12 |
|---|---|
| Address | 0x8c60 |
| Ordinal | 13 |
|---|---|
| Address | 0x4b10 |
| Ordinal | 14 |
|---|---|
| Address | 0x4e90 |
| Ordinal | 15 |
|---|---|
| Address | 0x5070 |
| Ordinal | 16 |
|---|---|
| Address | 0x8870 |
| Ordinal | 17 |
|---|---|
| Address | 0x9020 |
| Ordinal | 18 |
|---|---|
| Address | 0x9600 |
| Ordinal | 19 |
|---|---|
| Address | 0x97c0 |
| Ordinal | 20 |
|---|---|
| Address | 0x93f0 |
| Ordinal | 21 |
|---|---|
| Address | 0xa1d0 |
| Ordinal | 22 |
|---|---|
| Address | 0x9eb0 |
| Ordinal | 23 |
|---|---|
| Address | 0x9e90 |
| Ordinal | 24 |
|---|---|
| Address | 0x9e70 |
| Ordinal | 25 |
|---|---|
| Address | 0x8980 |
| Ordinal | 26 |
|---|---|
| Address | 0xf630 |
| Ordinal | 27 |
|---|---|
| Address | 0x86d0 |
| Ordinal | 28 |
|---|---|
| Address | 0x7660 |
| Ordinal | 29 |
|---|---|
| Address | 0xc110 |
| Ordinal | 30 |
|---|---|
| Address | 0xcab0 |
| Ordinal | 31 |
|---|---|
| Address | 0x9ed0 |
| Ordinal | 32 |
|---|---|
| Address | 0xafd0 |
| Ordinal | 33 |
|---|---|
| Address | 0x7700 |
| Ordinal | 34 |
|---|---|
| Address | 0xf640 |
| Ordinal | 35 |
|---|---|
| Address | 0x2abc0 |
| Ordinal | 36 |
|---|---|
| Address | 0x2b3b0 |
| Ordinal | 37 |
|---|---|
| Address | 0x9260 |
| Ordinal | 38 |
|---|---|
| Address | 0x5000 |
| Ordinal | 39 |
|---|---|
| Address | 0x5020 |
| Ordinal | 40 |
|---|---|
| Address | 0xe380 |
| Ordinal | 41 |
|---|---|
| Address | 0xe390 |
| Ordinal | 42 |
|---|---|
| Address | 0x97f0 |
| Ordinal | 43 |
|---|---|
| Address | 0x4ad0 |
| Ordinal | 44 |
|---|---|
| Address | 0x4b30 |
| Ordinal | 45 |
|---|---|
| Address | 0x4b20 |
| Ordinal | 46 |
|---|---|
| Address | 0x4b50 |
| Ordinal | 47 |
|---|---|
| Address | 0x4b40 |
| Ordinal | 48 |
|---|---|
| Address | 0xa540 |
| Ordinal | 49 |
|---|---|
| Address | 0xd090 |
| Ordinal | 50 |
|---|---|
| Address | 0x9dd0 |
| Ordinal | 51 |
|---|---|
| Address | 0x4b60 |
| Ordinal | 52 |
|---|---|
| Address | 0xa390 |
| Ordinal | 53 |
|---|---|
| Address | 0x4350 |
| Ordinal | 54 |
|---|---|
| Address | 0x4400 |
| Ordinal | 55 |
|---|---|
| Address | 0x4b70 |
| Ordinal | 56 |
|---|---|
| Address | 0x98e0 |
| Ordinal | 57 |
|---|---|
| Address | 0xa380 |
| Ordinal | 58 |
|---|---|
| Address | 0x9840 |
| Ordinal | 59 |
|---|---|
| Address | 0xa550 |
| Ordinal | 60 |
|---|---|
| Address | 0x8680 |
| Ordinal | 61 |
|---|---|
| Address | 0xe370 |
| Ordinal | 62 |
|---|---|
| Address | 0xf7f0 |
| Ordinal | 63 |
|---|---|
| Address | 0xa5c0 |
| Ordinal | 64 |
|---|---|
| Address | 0xa5b0 |
| Ordinal | 65 |
|---|---|
| Address | 0xf810 |
| Ordinal | 66 |
|---|---|
| Address | 0xf820 |
| Ordinal | 67 |
|---|---|
| Address | 0xf880 |
| Ordinal | 68 |
|---|---|
| Address | 0xf8a0 |
| Ordinal | 69 |
|---|---|
| Address | 0xf890 |
| Ordinal | 70 |
|---|---|
| Address | 0x90e0 |
| Ordinal | 71 |
|---|---|
| Address | 0xe490 |
| Ordinal | 72 |
|---|---|
| Address | 0xe4a0 |
| Ordinal | 73 |
|---|---|
| Address | 0xced0 |
| 1.300d |
| Copyright (C) 1994-2017, RAD Game Tools, Inc. |
| 2.7d |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.7.3.0 |
| ProductVersion | 2.7.3.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | RAD Game Tools, Inc. |
| FileDescription | RAD Video Tools |
| FileVersion (#2) | 2.7d/1.300d |
| LegalCopyright | Copyright (C) 1994-2017, RAD Game Tools, Inc. |
| LegalTrademarks | Bink and Smacker are trademarks of RAD Game Tools, Inc. |
| ProductName | Bink and Smacker |
| ProductVersion (#2) | 2.7d/1.300d |
| Comments | Thank you for using RAD Game Tools! |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Oct-23 21:30:53 |
| Version | 0.0 |
| SizeofData | 66 |
| AddressOfRawData | 0x478b8 |
| PointerToRawData | 0x466b8 |
| Referenced File | C:\devel\projects\bink\build\bink2w64.pdb |
| XOR Key | 0x3fc55b84 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2008 SP1 build 30729) | 27 |
| C objects (VS2008 SP1 build 30729) | 78 |
| Imports (VS2008 SP1 build 30729) | 9 |
| Total imports | 123 |
| ASM objects (VS2008 SP1 build 30729) | 10 |
| 137 (VS2008 SP1 build 30729) | 37 |
| Linker (VS2008 build 21022) | 1 |
| Exports (VS2008 SP1 build 30729) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.