Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Aug-14 09:09:31 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\nishikigoi\source\repos\sqlite3\Debug\sqlite3.pdb
|
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE is possibly packed. |
Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 9 |
TimeDateStamp | 2019-Aug-14 09:09:31 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xfc200 |
SizeOfInitializedData | 0x19000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0007E5BE (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x198000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
AreFileApisANSI
CloseHandle CreateFileA CreateFileMappingW CreateFileW CreateMutexW DeleteFileA DeleteFileW FlushFileBuffers FlushViewOfFile FormatMessageA FormatMessageW FreeLibrary GetCurrentProcessId GetDiskFreeSpaceA GetDiskFreeSpaceW GetFileAttributesA GetFileAttributesExW GetFileAttributesW GetFileSize GetFullPathNameA GetFullPathNameW GetLastError GetProcAddress GetProcessHeap GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetTempPathA GetTempPathW GetTickCount HeapAlloc HeapCompact HeapCreate HeapDestroy HeapFree HeapReAlloc HeapSize HeapValidate LoadLibraryA LoadLibraryW LocalFree LockFile LockFileEx MapViewOfFile MultiByteToWideChar OutputDebugStringA OutputDebugStringW QueryPerformanceCounter ReadFile SetEndOfFile SetFilePointer Sleep SystemTimeToFileTime UnlockFile UnlockFileEx UnmapViewOfFile WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteFile InitializeCriticalSection EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection DeleteCriticalSection GetCurrentThreadId GetModuleHandleW GetStartupInfoW InitializeSListHead DisableThreadLibraryCalls RaiseException IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter VirtualQuery |
---|---|
VCRUNTIME140D.dll |
memcmp
memcpy memmove memset strrchr __std_type_info_destroy_list _except_handler4_common __vcrt_GetModuleFileNameW __vcrt_GetModuleHandleW __vcrt_LoadLibraryExW |
ucrtbased.dll |
_beginthreadex
_endthreadex _CrtDbgReport _CrtDbgReportW _except1 _initterm _initterm_e strcpy_s strcat_s __stdio_common_vsprintf_s _seh_filter_dll _localtime64_s _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _crt_at_quick_exit _cexit terminate _wmakepath_s _wsplitpath_s wcscpy_s free strncmp strlen strcspn strcmp fputs fclose fopen_s realloc _msize malloc _configure_narrow_argv |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Aug-14 09:09:31 |
Version | 0.0 |
SizeofData | 83 |
AddressOfRawData | 0x1895ec |
PointerToRawData | 0x10abec |
Referenced File | C:\Users\nishikigoi\source\repos\sqlite3\Debug\sqlite3.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Aug-14 09:09:31 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x189640 |
PointerToRawData | 0x10ac40 |
Size | 0xa4 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1018bbd4 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0x8e5eb46a |
---|---|
Unmarked objects | 0 |
Imports (27316) | 2 |
C++ objects (27316) | 18 |
C objects (27316) | 11 |
ASM objects (27316) | 10 |
Imports (26213) | 5 |
Total imports | 124 |
C objects (VS2019 RTM compiler 27508) | 1 |
Resource objects (VS2019 RTM compiler 27508) | 1 |
Linker (VS2019 RTM compiler 27508) | 1 |