| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1998-Sep-01 23:39:46 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Age of Empires, the Rise of Rome |
| FileVersion | 00.04.2.0901 |
| InternalName | EMPIRES |
| LegalCopyright | Copyright © Microsoft Corp. 1998 |
| OriginalFilename | EMPIRESX.EXE |
| ProductName | Age of Empires, the Rise of Rome |
| ProductVersion | 1.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C 5.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: THIS_COD
Unusual section name found: THIS_DAT Unusual section name found: Inf32Dat |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-14 09:25:37) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 8 |
| TimeDateStamp | 1998-Sep-01 23:39:46 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 5.0 |
| SizeOfCode | 0x144e00 |
| SizeOfInitializedData | 0x2a0200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0012BEC0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x147000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3e9000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| VERSION.dll |
GetFileVersionInfoSizeA
VerQueryValueA GetFileVersionInfoA |
|---|---|
| KERNEL32.dll |
FindFirstFileA
FindClose WinExec OutputDebugStringA VirtualFree GetTempPathA GetTempFileNameA UnmapViewOfFile CreateFileA CreateFileMappingA MapViewOfFile CompareStringA IsDBCSLeadByte GetVersionExA FileTimeToSystemTime GetProcAddress _llseek _lread GlobalAlloc GetModuleHandleA FindResourceA LoadResource LockResource GlobalHandle GlobalUnlock GlobalReAlloc GlobalLock GlobalFree _hread _lclose GetLastError GetModuleFileNameA UnhandledExceptionFilter FreeEnvironmentStringsA GetVolumeInformationA MulDiv SetEnvironmentVariableA WriteFile SetFilePointer GetFileType ReadFile FileTimeToLocalFileTime FindNextFileA GetLocalTime GetSystemTime GetTimeZoneInformation DeleteFileA HeapFree HeapAlloc RtlUnwind FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW SetUnhandledExceptionFilter IsBadReadPtr IsBadWritePtr IsBadCodePtr CompareStringW WideCharToMultiByte GetFullPathNameA ExitProcess TerminateProcess GetCurrentProcess GetStartupInfoA GetCommandLineA GetVersion HeapDestroy HeapCreate VirtualAlloc FlushFileBuffers SetHandleCount GetStdHandle GetCPInfo GetACP GetOEMCP HeapSize ReleaseMutex GetStringTypeA GetStringTypeW MultiByteToWideChar SetStdHandle SetEndOfFile CreateMutexA LCMapStringA LCMapStringW RaiseException HeapReAlloc GetCurrentDirectoryA OpenFile GlobalMemoryStatus LoadLibraryA FreeLibrary CloseHandle GetDriveTypeA |
| USER32.dll |
GetMessageA
TranslateMessage FindWindowA DestroyWindow InvalidateRect PeekMessageA DispatchMessageA CharUpperA RegisterClassA LoadIconA UpdateWindow SetWindowPos GetClientRect GetWindowRect CreateWindowExA GetSystemMetrics GetWindowThreadProcessId GetKeyState ReleaseDC GetDC BringWindowToTop GetLastActivePopup LoadStringA SetForegroundWindow IsIconic GetUpdateRect ValidateRect FillRect ScreenToClient GetCursorPos SetClassLongA SetCursor GetWindowTextA GetKeyboardState GetAsyncKeyState GetForegroundWindow DrawTextA IsClipboardFormatAvailable SendMessageA SystemParametersInfoA ShowWindow SetFocus SetTimer LoadCursorA OpenClipboard GetClipboardData CloseClipboard GetCaretBlinkTime DrawTextExA CallWindowProcA MoveWindow GetFocus MessageBeep GetWindowLongA SetSysColors GetSysColor SetCursorPos MessageBoxA SetRect ClientToScreen WinHelpA GetActiveWindow PostMessageA SetWindowLongA GetCapture ReleaseCapture SetCapture SetWindowTextA KillTimer PostQuitMessage DefWindowProcA |
| GDI32.dll |
CreatePalette
GetPaletteEntries GetDeviceCaps GetTextMetricsA SelectObject CreateFontIndirectA GetStockObject RealizePalette SelectPalette DeleteDC CreateICA GetObjectA DeleteObject GetNearestPaletteIndex SetPaletteEntries ResizePalette GetSystemPaletteEntries CreateRectRgn SelectClipRgn TextOutA SetTextColor GetTextExtentPoint32A SetBkMode SetBkColor LineTo MoveToEx CreatePen |
| ADVAPI32.dll |
RegSetValueExA
RegQueryValueExA RegCloseKey RegCreateKeyExA |
| DPLAYX.dll |
#1
#4 #2 |
| DSOUND.dll |
DirectSoundCreate
|
| DDRAW.dll |
DirectDrawCreate
|
| WINMM.dll |
mixerGetLineControlsA
mixerGetControlDetailsA mixerClose mixerGetLineInfoA timeKillEvent timeEndPeriod timeBeginPeriod timeSetEvent mixerSetControlDetails mixerOpen mmioGetInfo mmioAdvance mmioSetInfo mmioOpenA mmioDescend mmioRead mmioAscend mciSendCommandA timeGetTime mixerGetNumDevs mciGetErrorStringA mmioClose mmioSeek |
| IMM32.dll |
ImmReleaseContext
ImmNotifyIME ImmGetContext ImmAssociateContext ImmSetOpenStatus |
| MSVFW32.dll |
ICInfo
MCIWndCreateA |
| ole32.dll |
CoInitialize
CoCreateInstance CoUninitialize |
| WSOCK32.dll |
WSAStartup
gethostbyname gethostname WSACleanup |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.4.2.901 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Age of Empires, the Rise of Rome |
| FileVersion (#2) | 00.04.2.0901 |
| InternalName | EMPIRES |
| LegalCopyright | Copyright © Microsoft Corp. 1998 |
| OriginalFilename | EMPIRESX.EXE |
| ProductName | Age of Empires, the Rise of Rome |
| ProductVersion (#2) | 1.0 |
| Resource LangID | English - United States |
|---|
No comments yet.