| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Mar-01 20:00:26 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\GitHub\TS helper tools\Release\The Sims 2 Launcher.pdb
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2026-03-27 02:59:26) |
APEX:
Malicious
Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Mar-01 20:00:26 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x10600 |
| SizeOfInitializedData | 0xe400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00005545 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x12000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x22000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteConsoleW
CreateFileW HeapReAlloc HeapSize GetModuleHandleW GetConsoleOutputCP FlushFileBuffers GetStringTypeW SetStdHandle GetProcessHeap CloseHandle WaitForSingleObject GetModuleFileNameW GetConsoleMode GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW WideCharToMultiByte MultiByteToWideChar GetCurrentThreadId ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW QueryPerformanceCounter EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection GetSystemTimeAsFileTime GetProcAddress UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetCurrentProcessId InitializeSListHead RtlUnwind RaiseException GetLastError SetLastError EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary LoadLibraryExW CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetStdHandle WriteFile HeapAlloc HeapFree LCMapStringW GetFileType SetFilePointerEx FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW DecodePointer |
|---|---|
| USER32.dll |
EnableWindow
GetWindowRect SetWindowPos SendMessageW EndDialog OffsetRect CopyRect LoadIconW SendMessageA GetDlgItem GetDesktopWindow DialogBoxParamW |
| ADVAPI32.dll |
RegGetValueA
RegCreateKeyExA RegSetValueExA RegCloseKey |
| SHELL32.dll |
ShellExecuteExW
|
| ole32.dll |
CoInitializeEx
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-01 20:00:26 |
| Version | 0.0 |
| SizeofData | 82 |
| AddressOfRawData | 0x18e00 |
| PointerToRawData | 0x17800 |
| Referenced File | D:\GitHub\TS helper tools\Release\The Sims 2 Launcher.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-01 20:00:26 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x18e54 |
| PointerToRawData | 0x17854 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-01 20:00:26 |
| Version | 0.0 |
| SizeofData | 944 |
| AddressOfRawData | 0x18e68 |
| PointerToRawData | 0x17868 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Mar-01 20:00:26 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x419228 |
|---|---|
| EndAddressOfRawData | 0x419230 |
| AddressOfIndex | 0x41c05c |
| AddressOfCallbacks | 0x4121c8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x41b040 |
| SEHandlerTable | 0x418c2c |
| SEHandlerCount | 19 |
| XOR Key | 0x5c072697 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 10 |
| C++ objects (30795) | 145 |
| C objects (30795) | 20 |
| C objects (33218) | 18 |
| ASM objects (33218) | 22 |
| C++ objects (33218) | 56 |
| Imports (30795) | 11 |
| Total imports | 138 |
| C++ objects (LTCG) (33521) | 1 |
| Resource objects (33521) | 1 |
| 151 | 1 |
| Linker (33521) | 1 |
No comments yet.