| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1998-Mar-30 13:29:08 |
| Detected languages |
English - United Kingdom
|
| CompanyName | Codemasters Software Co. |
| FileDescription | LMA Manager 2007 Executable |
| FileVersion | 1, 0, 0, 1 |
| InternalName | LMA Manager 2007 |
| LegalCopyright | Copyright (C) 2007 Codemasters Software Co. |
| OriginalFilename | LMA_2007.exe |
| ProductName | LMA Manager 2007 |
| ProductVersion | 1, 0, 0, 1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
| Suspicious | PEiD Signature: | Crunch 4 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The file headers were tampered with. |
Unusual section name found: .sforce3
Section .sforce3 is both writable and executable. Unusual section name found: .brick Section .brick is both writable and executable. Unusual section name found: .RDATA Section .RDATA is both writable and executable. Section .idata is both writable and executable. Unusual section name found: .brick Section .brick is both writable and executable. Section .rsrc is both writable and executable. Unusual section name found: .start Section .start is both writable and executable. Unusual section name found: .brick Section .brick is both writable and executable. Section .idata is both writable and executable. Unusual section name found: .brick Section .brick is both writable and executable. Unusual section name found: .RLD0\x00\x14 Section .RLD0\x00\x14 is both writable and executable. Unusual section name found: .brick Section .brick is both writable and executable. Unusual section name found: .RLD1\x00\x14 Section .RLD1\x00\x14 is both writable and executable. The RICH header checksum is invalid. The number of imports reported in the RICH header is inconsistent. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 4591472 bytes of data starting at offset 0x2cb090. |
| Malicious | VirusTotal score: 4/70 (Scanned on 2026-07-27 09:24:36) |
CrowdStrike:
win/grayware_confidence_60% (D)
Ikarus: PUA.GameHack.Reloaded Symantec: Trojan.Gen.2 Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x140 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x140 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 13 |
| TimeDateStamp | 1998-Mar-30 13:29:08 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 75.0 |
| SizeOfCode | 0x3d8000 |
| SizeOfInitializedData | 0x1a2000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0038F1A1 (Section: .brick) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3d9000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x13c0000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x2cb5c7 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
RegQueryValueExA
RegOpenKeyExA RegCreateKeyExA RegCloseKey |
|---|---|
| dinput8.dll |
DirectInput8Create
|
| dsound.dll |
DirectSoundCreate8
|
| gdi32.dll |
GetStockObject
|
| kernel32.dll |
EnumSystemLocalesA
GetUserDefaultLCID FileTimeToSystemTime FileTimeToLocalFileTime GetLocalTime InitializeCriticalSection DeleteCriticalSection LeaveCriticalSection EnterCriticalSection WaitForSingleObject SetEvent CreateEventA CloseHandle Sleep GetLastError CreateMutexA GetCommandLineA TerminateThread FindClose FindFirstFileA CreateThread FindNextFileA TryEnterCriticalSection GetVersionExA CompareFileTime WriteFile CreateFileA GetCurrentDirectoryA CreateDirectoryA ReadFile GetFileSize SetCurrentDirectoryA OutputDebugStringA GetVolumeInformationA SetFilePointer GetOverlappedResult GetFileAttributesA ReleaseSemaphore CreateSemaphoreA SetThreadPriority InterlockedExchange InterlockedDecrement InterlockedIncrement QueryPerformanceFrequency QueryPerformanceCounter FreeLibrary GetProcAddress LoadLibraryA CancelIo FlushFileBuffers DeleteFileA IsValidLocale GetDiskFreeSpaceA GetModuleHandleA GetLocaleInfoA ExitProcess RaiseException GetCurrentProcess GlobalFree GlobalUnlock GlobalLock GlobalAlloc GetEnvironmentStringsW WideCharToMultiByte FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter GetStdHandle IsBadWritePtr VirtualAlloc VirtualFree HeapCreate HeapDestroy FatalAppExitA HeapSize GetModuleFileNameA LockResource GetSystemTimeAsFileTime GetCurrentProcessId GetTickCount TlsGetValue TlsSetValue TlsFree GetCurrentThread GetCurrentThreadId SetLastError TlsAlloc ResumeThread ExitThread HeapReAlloc HeapFree GetStartupInfoA TerminateProcess HeapAlloc RtlUnwind GetFileType VirtualProtect GetSystemInfo VirtualQuery LCMapStringA MultiByteToWideChar DeviceIoControl IsValidCodePage SetStdHandle SetConsoleCtrlHandler GetTimeZoneInformation SetEndOfFile GetLocaleInfoW LCMapStringW SetUnhandledExceptionFilter IsBadReadPtr GetDateFormatA GetTimeFormatA GetStringTypeW GetStringTypeA GetCPInfo GetOEMCP GetACP CompareStringA CompareStringW GetExitCodeProcess SetEnvironmentVariableA IsBadCodePtr |
| shell32.dll |
ShellExecuteEx
ShellExecuteA |
| user32.dll |
GetClipboardData
OpenClipboard EmptyClipboard SetClipboardData CloseClipboard ShowCursor SetCursorPos MsgWaitForMultipleObjects SetWindowLongA GetClientRect GetSystemMetrics GetForegroundWindow GetKeyState GetKeyboardLayout GetKeyboardState MapVirtualKeyExA ToAsciiEx AdjustWindowRectEx LoadIconA LoadCursorA RegisterClassA CreateWindowExA UpdateWindow PostQuitMessage ShowWindow GetWindowRect SetWindowPos GetCursorPos DefWindowProcA DestroyWindow UnregisterClassA TranslateMessage DispatchMessageA PeekMessageA GetMessageA MessageBoxA GetActiveWindow SendMessageA SetFocus |
| version.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
| winmm.dll |
timeGetTime
|
| binkw32.dll |
_BinkCopyToBuffer@28
_BinkOpen@8 _BinkSetSoundSystem@8 _BinkOpenDirectSound@4 _BinkNextFrame@4 _BinkWait@4 _BinkDoFrame@4 _BinkClose@4 |
| d3d9.dll |
Direct3DCreate9
|
| d3dx9_28.dll |
D3DXCreateEffectPool
D3DXCreateCubeTextureFromFileInMemory D3DXLoadSurfaceFromSurface D3DXCreateEffectFromFileA D3DXCreateTextureFromFileInMemory |
| ole32.dll |
CoTaskMemFree
CoCreateGuid CoCreateInstance CoTaskMemAlloc CoInitialize CoUninitialize |
| lma2k7.dll |
F
|
| Ordinal | 1 |
|---|---|
| Address | 0x51f0 |
| Ordinal | 2 |
|---|---|
| Address | 0x76a8 |
| Ordinal | 3 |
|---|---|
| Address | 0x6b90 |
| Ordinal | 4 |
|---|---|
| Address | 0x4651 |
| Ordinal | 5 |
|---|---|
| Address | 0x344a |
| Ordinal | 6 |
|---|---|
| Address | 0x8661 |
| Ordinal | 7 |
|---|---|
| Address | 0x3193 |
| Ordinal | 8 |
|---|---|
| Address | 0x538f |
| Ordinal | 9 |
|---|---|
| Address | 0x12a8 |
| Ordinal | 10 |
|---|---|
| Address | 0x982c |
| Ordinal | 11 |
|---|---|
| Address | 0x3cec |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | UNKNOWN |
| CompanyName | Codemasters Software Co. |
| FileDescription | LMA Manager 2007 Executable |
| FileVersion (#2) | 1, 0, 0, 1 |
| InternalName | LMA Manager 2007 |
| LegalCopyright | Copyright (C) 2007 Codemasters Software Co. |
| OriginalFilename | LMA_2007.exe |
| ProductName | LMA Manager 2007 |
| ProductVersion (#2) | 1, 0, 0, 1 |
| Resource LangID | English - United Kingdom |
|---|
| XOR Key | 0x9862a740 |
|---|---|
| Unmarked objects | 0 |
| 105 (2067) | 1 |
| ASM objects (VS2003 (.NET) build 3077) | 49 |
| C objects (VS2003 (.NET) build 4035) | 3 |
| C++ objects (8830) | 1 |
| C objects (2179) | 3 |
| Imports (9210) | 2 |
| Imports (2067) | 2 |
| C objects (VS2003 (.NET) build 3077) | 154 |
| 48 (9044) | 93 |
| Imports (2179) | 12 |
| Imports (VS2003 (.NET) build 4035) | 8 |
| C objects (9178) | 2 |
| Imports (VS2003 (.NET) build 3077) | 3 |
| Total imports | 196 |
| C++ objects (VS2003 (.NET) build 3077) | 635 |
| Exports (VS2003 (.NET) build 3077) | 1 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.