| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2015-Nov-26 06:23:42 |
| Detected languages |
English - United States
Korean - Korea |
| CompanyName | NEXTORIC |
| FileDescription | GameClient |
| FileVersion | 1, 0, 0, 1842 |
| InternalName | GameClient 201507281618 |
| LegalCopyright | Copyright (C) NEXTORIC |
| LegalTrademarks | ProjectMV |
| OriginalFilename | GameClient |
| ProductName | ProjectMV |
| ProductVersion | 1, 0, 0, 0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ 8 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA256 Uses constants related to SHA512 |
| Malicious | The file headers were tampered with. |
Unusual section name found: .import
The RICH header checksum is invalid. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 6018824 bytes of data starting at offset 0x4e6af8. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0x7556 |
| e_oeminfo | 0x4e14 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2015-Nov-26 06:23:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x8f2c00 |
| SizeOfInitializedData | 0x195600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0082CC03 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x8f4000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xcb2000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x4f6483 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
RegOpenKeyExA
RegOpenKeyExW RegCreateKeyExW RegSetValueExW RegCloseKey RegQueryValueExW RegDeleteValueW RegQueryValueExA |
|---|---|
| dinput8.dll |
DirectInput8Create
|
| gdi32.dll |
DeleteObject
SetTextColor GetStockObject SetBkMode SetBkColor GetTextExtentPoint32W EnumFontsW GetDeviceCaps CreateFontIndirectW SelectObject |
| imm32.dll |
ImmSetConversionStatus
ImmReleaseContext ImmGetContext ImmGetCompositionStringA ImmGetDefaultIMEWnd ImmGetOpenStatus ImmIsIME ImmSetCompositionStringW ImmNotifyIME ImmGetIMEFileNameA ImmGetCandidateListW ImmGetCompositionStringW ImmAssociateContext ImmGetCandidateListA ImmGetConversionStatus |
| iphlpapi.dll |
GetAdaptersInfo
|
| kernel32.dll |
MulDiv
SetEndOfFile CreateThread ExitThread GetCurrentThreadId CreateProcessW GetCurrentProcessId GetCommandLineW GetFileTime LocalFree DeviceIoControl CreateFileA GetVolumeInformationA GetWindowsDirectoryA IsDBCSLeadByteEx CompareStringA GetVersionExA GlobalUnlock GlobalWire GetWindowsDirectoryW TerminateThread ResumeThread SetCurrentDirectoryW lstrlenW DuplicateHandle InterlockedCompareExchange GetFileInformationByHandle GetVersion QueryPerformanceFrequency GetLocalTime SetFileAttributesW FlushFileBuffers ReadFile GetFileSize SetStdHandle GetConsoleMode GetConsoleCP SetFilePointer GetLocaleInfoA LoadLibraryW InterlockedExchange HeapReAlloc RtlUnwind CreateFileW SleepEx IsDebuggerPresent WaitForSingleObject CreateMutexW GetVersionExW FindClose FindNextFileW FindFirstFileW GetCurrentDirectoryW CreateDirectoryW DeleteCriticalSection InitializeCriticalSection CompareStringW HeapFree GetProcessHeap HeapAlloc GetSystemTimeAsFileTime QueryPerformanceCounter GetFileType InitializeCriticalSectionAndSpinCount SetHandleCount GetEnvironmentStringsW FreeEnvironmentStringsW GetStringTypeW LCMapStringW GetCurrentThread SetLastError TlsFree TlsSetValue TlsGetValue TlsAlloc IsValidCodePage GetOEMCP GetACP GetCPInfo HeapCreate GetCurrentProcess TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter GetStdHandle WriteFile ExitProcess HeapSize IsProcessorFeaturePresent RaiseException GetStartupInfoW HeapSetInformation DecodePointer EncodePointer GetProcAddress LoadLibraryA FreeLibrary LeaveCriticalSection EnterCriticalSection SetEvent CloseHandle CreateEventW CopyFileW GetModuleHandleW GetModuleFileNameW GlobalFree MultiByteToWideChar lstrcmpW WideCharToMultiByte GlobalAlloc GetTickCount InterlockedDecrement InterlockedIncrement GetLastError OutputDebugStringW VirtualQuery Sleep WriteConsoleW DeleteFileW |
| oleaut32.dll |
VariantInit
SysFreeString SafeArrayCreate SafeArrayDestroy SafeArrayAccessData VariantClear SysAllocString |
| rpcrt4.dll |
RpcStringFreeA
UuidCreate UuidToStringA |
| shell32.dll |
SHGetFolderLocation
ShellExecuteW SHFree SHBindToParent SHGetSpecialFolderPathW |
| shlwapi.dll |
SHDeleteKeyW
StrRetToBufW |
| user32.dll |
GetCaretBlinkTime
GetFocus PostMessageA SendMessageA SetClipboardData EmptyClipboard CloseClipboard GetClipboardData OpenClipboard ReleaseCapture SetCapture SetCursor GetMenu PeekMessageW GetWindowLongW TranslateMessage GetClientRect SetWindowPos MapVirtualKeyW GetAsyncKeyState GetKeyState SystemParametersInfoW SetTimer KillTimer LoadImageW DialogBoxParamW SendDlgItemMessageW GetDlgItemTextW GetWindowRect GetDlgItem ScreenToClient MoveWindow SetDlgItemTextW ShowWindow GetSystemMetrics MsgWaitForMultipleObjectsEx CreateDialogParamW DestroyWindow IsDialogMessageW LoadIconW LoadCursorW RegisterClassExW CreateWindowExW UpdateWindow PostQuitMessage AdjustWindowRect DefWindowProcW EnableWindow InvalidateRect GetDesktopWindow GetMessageW GetDC SetFocus SetWindowTextW ReleaseDC GetWindowTextW GetKeyboardLayout CharNextW IsWindowUnicode SetWindowLongW MessageBoxW ShowCursor IsWindow DispatchMessageW PostMessageW SendMessageW GetPhysicalCursorPos EndDialog |
| version.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW GetFileVersionInfoSizeA GetFileVersionInfoA VerQueryValueA |
| wininet.dll |
InternetQueryDataAvailable
InternetOpenUrlW InternetOpenW InternetSetStatusCallbackW InternetCloseHandle InternetReadFile |
| winmm.dll |
timeBeginPeriod
timeGetTime timeEndPeriod |
| ws2_32.dll |
WSACreateEvent
WSAWaitForMultipleEvents WSAResetEvent WSAEnumNetworkEvents WSASocketW closesocket WSACloseEvent send connect WSAEventSelect WSAGetLastError gethostbyname inet_addr WSACleanup WSAStartup ntohs ntohs recv getsockname getpeername |
| d3d9.dll |
Direct3DCreate9
|
| d3dx9_31.dll |
D3DXGetFVFVertexSize
D3DXCreateTextureFromFileInMemoryEx D3DXGetImageInfoFromFileInMemory D3DXSaveSurfaceToFileInMemory D3DXGatherFragments D3DXCreateFragmentLinker D3DXCompileShader D3DXGetShaderConstantTable D3DXLoadSurfaceFromFileInMemory |
| dbghelp.dll |
MiniDumpWriteDump
|
| fmod_event.dll |
?update@EventSystem@FMOD@@QAG?AW4FMOD_RESULT@@XZ
?release@EventSystem@FMOD@@QAG?AW4FMOD_RESULT@@XZ |
| fmodex.dll |
?setVolume@ChannelGroup@FMOD@@QAG?AW4FMOD_RESULT@@M@Z
?setMute@ChannelGroup@FMOD@@QAG?AW4FMOD_RESULT@@_N@Z ?setDSPBufferSize@System@FMOD@@QAG?AW4FMOD_RESULT@@IH@Z ?setPriority@Channel@FMOD@@QAG?AW4FMOD_RESULT@@H@Z ?setCallback@Channel@FMOD@@QAG?AW4FMOD_RESULT@@P6G?AW43@PAUFMOD_CHANNEL@@W4FMOD_CHANNEL_CALLBACKTYPE@@PAX2@Z@Z ?playSound@System@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_CHANNELINDEX@@PAVSound@2@_NPAPAVChannel@2@@Z ?setMode@Sound@FMOD@@QAG?AW4FMOD_RESULT@@I@Z ?getMode@Sound@FMOD@@QAG?AW4FMOD_RESULT@@PAI@Z ?setPaused@Channel@FMOD@@QAG?AW4FMOD_RESULT@@_N@Z ?setVolume@Channel@FMOD@@QAG?AW4FMOD_RESULT@@M@Z ?update@System@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?release@ChannelGroup@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?set3DAttributes@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PBUFMOD_VECTOR@@0@Z ?release@Sound@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?stop@Channel@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?createChannelGroup@System@FMOD@@QAG?AW4FMOD_RESULT@@PBDPAPAVChannelGroup@2@@Z ?setSpeakerMode@System@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_SPEAKERMODE@@@Z ?getOpenState@Sound@FMOD@@QAG?AW4FMOD_RESULT@@PAW4FMOD_OPENSTATE@@PAIPA_N@Z ?setUserData@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAX@Z ?setChannelGroup@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAVChannelGroup@2@@Z FMOD_Channel_GetUserData FMOD_Debug_SetLevel FMOD_Debug_GetLevel ?getDriverInfo@System@FMOD@@QAG?AW4FMOD_RESULT@@HPADHPAUFMOD_GUID@@@Z ?setSoftwareFormat@System@FMOD@@QAG?AW4FMOD_RESULT@@HW4FMOD_SOUND_FORMAT@@HHW4FMOD_DSP_RESAMPLER@@@Z ?init@System@FMOD@@QAG?AW4FMOD_RESULT@@HIPAX@Z ?setFileSystem@System@FMOD@@QAG?AW4FMOD_RESULT@@P6G?AW43@PBDHPAIPAPAX2@ZP6G?AW43@PAX4@ZP6G?AW43@44I14@ZP6G?AW43@4I4@ZP6G?AW43@PAUFMOD_ASYNCREADINFO@@4@Z5H@Z ?isPlaying@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PA_N@Z ?getMode@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAI@Z ?getChannelsPlaying@System@FMOD@@QAG?AW4FMOD_RESULT@@PAH@Z ?close@System@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?release@System@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?createSound@System@FMOD@@QAG?AW4FMOD_RESULT@@PBDIPAUFMOD_CREATESOUNDEXINFO@@PAPAVSound@2@@Z ?createStream@System@FMOD@@QAG?AW4FMOD_RESULT@@PBDIPAUFMOD_CREATESOUNDEXINFO@@PAPAVSound@2@@Z ?setMode@Channel@FMOD@@QAG?AW4FMOD_RESULT@@I@Z ?getPaused@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PA_N@Z ?setPan@Channel@FMOD@@QAG?AW4FMOD_RESULT@@M@Z FMOD_System_Create ?getVersion@System@FMOD@@QAG?AW4FMOD_RESULT@@PAI@Z ?getDriverCaps@System@FMOD@@QAG?AW4FMOD_RESULT@@HPAIPAH1PAW4FMOD_SPEAKERMODE@@@Z ?getFrequency@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAM@Z ?setFrequency@Channel@FMOD@@QAG?AW4FMOD_RESULT@@M@Z ?set3DMinMaxDistance@Channel@FMOD@@QAG?AW4FMOD_RESULT@@MM@Z ?setLoopCount@Channel@FMOD@@QAG?AW4FMOD_RESULT@@H@Z ?stop@ChannelGroup@FMOD@@QAG?AW4FMOD_RESULT@@XZ |
| ole32.dll |
CoInitializeEx
CoUninitialize CoTaskMemAlloc CoCreateInstance |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1842 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_UNKNOWN
|
| Language | UNKNOWN |
| CompanyName | NEXTORIC |
| FileDescription | GameClient |
| FileVersion (#2) | 1, 0, 0, 1842 |
| InternalName | GameClient 201507281618 |
| LegalCopyright | Copyright (C) NEXTORIC |
| LegalTrademarks | ProjectMV |
| OriginalFilename | GameClient |
| ProductName | ProjectMV |
| ProductVersion (#2) | 1, 0, 0, 0 |
| Resource LangID | UNKNOWN |
|---|
| StartAddressOfRawData | 0xe9b000 |
|---|---|
| EndAddressOfRawData | 0xe9b015 |
| AddressOfIndex | 0xe99e00 |
| AddressOfCallbacks | 0xcf5e94 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
| XOR Key | 0x4598576e |
|---|---|
| Unmarked objects | 0 |
| Linker (VC++ 6.0 SP5 imp/exp build 8447) | 4 |
| C++ objects (VS2010 build 30319) | 4 |
| C objects (VS2003 (.NET) build 4035) | 2 |
| C++ objects (VS2003 (.NET) build 4035) | 1 |
| Imports (VS2003 (.NET) build 4035) | 6 |
| ASM objects (VS2010 SP1 build 40219) | 58 |
| C++ objects (VS2010 SP1 build 40219) | 77 |
| C objects (VS2010 SP1 build 40219) | 177 |
| C objects (VS2008 SP1 build 30729) | 9 |
| Imports (VS2008 SP1 build 30729) | 33 |
| Total imports | 379 |
| 175 (VS2010 SP1 build 40219) | 818 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.