| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2004-Dec-17 08:58:40 |
| Detected languages |
English - United States
|
| FileVersion | 2, 0, 0, 24 |
| ProductName | CoD RconTool Install Program |
| ProductVersion | 2, 0, 0, 24 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
15289224 bytes of data starting at offset 0x2d000.
The overlay data has an entropy of 7.99862 and is possibly compressed or encrypted. Overlay data amounts for 98.8088% of the executable. |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-08 01:54:27) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2004-Dec-17 08:58:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x20000 |
| SizeOfInitializedData | 0xc000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0001A05E (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x21000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2d000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetDriveTypeA
GetModuleFileNameA GetVersionExA GetVersion CompareStringA GetTimeZoneInformation IsBadCodePtr IsBadReadPtr SetUnhandledExceptionFilter GetStringTypeW GetStringTypeA GetFileType GetStdHandle SetHandleCount GetEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter GetOEMCP GetACP GetCPInfo LCMapStringW LCMapStringA GetCurrentProcess HeapReAlloc VirtualAlloc VirtualFree HeapCreate HeapDestroy GetEnvironmentVariableA GetCommandLineA GetStartupInfoA FileTimeToLocalFileTime FileTimeToSystemTime FindNextFileA RemoveDirectoryA MoveFileA RtlUnwind DeleteFileA SetEnvironmentVariableA CreateDirectoryA HeapFree HeapAlloc HeapCompact TerminateProcess ExitProcess GetFileAttributesA SetFileAttributesA MoveFileExA GetModuleHandleA FormatMessageA CopyFileA SetFileTime OpenFile SetErrorMode GetPrivateProfileStringA WritePrivateProfileStringA GetTickCount GetFullPathNameA FindFirstFileA FindClose MultiByteToWideChar WideCharToMultiByte GetLocalTime GetTempPathA GetShortPathNameA CompareStringW Sleep GetExitCodeProcess GetCurrentDirectoryA SetCurrentDirectoryA CreateProcessA lstrcatA lstrlenA WinExec LoadLibraryA GetProcAddress FreeLibrary GetDiskFreeSpaceA GlobalAlloc GlobalLock GlobalUnlock GlobalFree CloseHandle SetFilePointer WriteFile ReadFile CreateFileA GetLastError GetWindowsDirectoryA IsBadWritePtr GetSystemDirectoryA |
|---|---|
| USER32.dll |
ExitWindowsEx
IsIconic RedrawWindow PostQuitMessage DialogBoxParamA AdjustWindowRectEx PostMessageA EndDialog CheckDlgButton BringWindowToTop GetLastActivePopup FindWindowA RegisterClassA SendMessageA GetWindow LoadCursorA DefWindowProcA LoadIconA GetSysColor ScreenToClient GetWindowRect GetDlgItem EndPaint BeginPaint GetClientRect FillRect DrawTextA GetSystemMetrics SetTimer KillTimer SendDlgItemMessageA GetFocus GetDlgItemTextA IsClipboardFormatAvailable OpenClipboard GetClipboardData CloseClipboard IsDlgButtonChecked CheckRadioButton SetFocus GetParent UpdateWindow IsWindowVisible InvalidateRect CreateDialogParamA GetMessageA IsDialogMessageA TranslateMessage DispatchMessageA SetDlgItemTextA SetWindowTextA SetWindowPos ShowWindow DestroyWindow CreateWindowExA GetWindowLongA IsWindowEnabled EnableWindow CallWindowProcA ValidateRect SetWindowLongA GetClassNameA MessageBoxA PeekMessageA wsprintfA |
| GDI32.dll |
DeleteDC
GetDeviceCaps GetSystemPaletteEntries CreatePalette DeleteObject ExtTextOutA CreateFontIndirectA GetStockObject BitBlt SelectObject CreateCompatibleBitmap CreateCompatibleDC RealizePalette SelectPalette CreateHalftonePalette CreateDIBPatternBrush CreateSolidBrush SetBrushOrgEx SetStretchBltMode StretchDIBits SetTextColor SetBkMode SetBkColor RemoveFontResourceA AddFontResourceA |
| comdlg32.dll |
GetOpenFileNameA
|
| ADVAPI32.dll |
RegDeleteKeyA
OpenProcessToken LookupPrivilegeValueA AdjustTokenPrivileges RegCreateKeyA RegEnumKeyExA RegCloseKey RegDeleteValueA RegSetValueExA RegOpenKeyExA RegQueryValueA RegOpenKeyA RegQueryValueExA |
| SHELL32.dll |
DragQueryFileA
DragFinish ShellExecuteA SHBrowseForFolderA SHGetSpecialFolderLocation SHGetPathFromIDListA SHGetMalloc DragAcceptFiles |
| ole32.dll |
CoGetMalloc
CoCreateInstance OleInitialize OleUninitialize |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA VerFindFileA |
| COMCTL32.dll |
#17
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.0.24 |
| ProductVersion | 2.0.0.24 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 2, 0, 0, 24 |
| ProductName | CoD RconTool Install Program |
| ProductVersion (#2) | 2, 0, 0, 24 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0xbdd646f1 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 2 |
| C++ objects (8047) | 8 |
| 14 (7299) | 20 |
| C objects (8047) | 72 |
| C objects (VC++ 6.0 SP5 build 8804) | 15 |
| C objects (2190) | 2 |
| Imports (2179) | 19 |
| Total imports | 217 |
| 49 (9044) | 2 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.