| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-06 14:32:10 |
| Detected languages |
Process Default Language
|
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/72 (Scanned on 2026-03-20 16:08:16) | MaxSecure: Trojan.Malware.300983.susgen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Dec-06 14:32:10 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x82e00 |
| SizeOfInitializedData | 0x68800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000624FB (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x84000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xef000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
#17
|
|---|---|
| WINMM.dll |
timeBeginPeriod
joyGetDevCapsW joyGetPosEx timeEndPeriod |
| KERNEL32.dll |
WideCharToMultiByte
GlobalAddAtomW GlobalDeleteAtom lstrlenW GetCommandLineW GetExitCodeProcess GlobalAlloc GlobalLock GlobalUnlock SetErrorMode GetCurrentDirectoryW GlobalFree LoadLibraryW SetStdHandle GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA FindNextFileA FindFirstFileExA DecodePointer GetFileType LCMapStringW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetOEMCP IsValidCodePage GetStringTypeW GetCPInfo HeapFree HeapReAlloc HeapAlloc MultiByteToWideChar GetModuleFileNameA GetModuleHandleExW ExitProcess SetEnvironmentVariableW DeleteFileW GetACP DeleteCriticalSection LeaveCriticalSection EnterCriticalSection EncodePointer RtlUnwind InitializeSListHead GetCurrentThreadId GetCurrentProcessId GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter GetSystemTimeAsFileTime TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError QueryPerformanceFrequency QueryPerformanceCounter LoadLibraryExA GetModuleHandleW VirtualQuery VirtualProtect GetSystemInfo RaiseException SetCurrentDirectoryW FindNextFileW CreateMutexW WriteFile GetModuleFileNameW Sleep ReleaseMutex WaitForSingleObject FindClose FindFirstFileW CloseHandle SetFilePointer GetLastError ReadFile CreateFileW CreateDirectoryW GetTempFileNameW GetTempPathW WriteConsoleW RemoveDirectoryW GetVersionExW GetLocaleInfoW FreeLibrary GetProcAddress LoadLibraryExW HeapSize GetConsoleCP GetConsoleMode SetFilePointerEx FlushFileBuffers GetStdHandle |
| USER32.dll |
OffsetRect
DestroyWindow PostQuitMessage DrawTextW FillRect GetUpdateRect DefMDIChildProcW EndPaint BeginPaint InflateRect GetClassNameW GetDlgItemTextW SendDlgItemMessageW EndDialog GetDlgItem SetDlgItemTextW DrawEdge MapVirtualKeyW GetInputState DrawMenuBar SetMenuInfo DestroyMenu LoadMenuIndirectW GetMenuItemCount SetWindowPlacement GetWindowPlacement EndDeferWindowPos DeferWindowPos BeginDeferWindowPos GetDesktopWindow GetSystemMenu UpdateWindow GetWindow RegisterClassW GetTabbedTextExtentW ModifyMenuW GetMenuStringW DialogBoxIndirectParamW GetMenuItemID RegisterClassExW LoadImageW LoadIconW GetMonitorInfoW MonitorFromWindow GetSystemMetrics RedrawWindow IsIconic IsDialogMessageW SetTimer GetClipboardData CloseClipboard SetClipboardData EmptyClipboard OpenClipboard IsClipboardFormatAvailable CheckMenuItem EnableMenuItem GetMenu PtInRect PostMessageW InvalidateRect SetFocus GetFocus CallWindowProcW RemovePropW SetPropW SetWindowLongW GetPropW MessageBoxW GetParent GetActiveWindow ShowCursor SetCapture ReleaseCapture GetKeyState GetWindowRect GetWindowDC SetCursorPos ClientToScreen ScreenToClient GetCursorPos LoadStringW MapWindowPoints SetWindowPos IsZoomed GetWindowLongW AdjustWindowRectEx SendMessageW LockWindowUpdate ShowWindow IsWindowVisible GetClientRect SetWindowTextW wsprintfW IntersectRect KillTimer DestroyIcon GetSubMenu DeleteMenu GetMenuState LoadCursorW SetCursor SystemParametersInfoW GetSysColor ReleaseDC CreateIconIndirect GetDC MsgWaitForMultipleObjects DispatchMessageW TranslateMessage TranslateMDISysAccel GetMessageW PeekMessageW DialogBoxParamW |
| GDI32.dll |
CreatePalette
SelectPalette RealizePalette EnumFontFamiliesExW GetStockObject SelectObject GetTextExtentPointW GetDeviceCaps GetObjectW CreateFontIndirectW DeleteObject CreatePen Rectangle LineTo SetBkColor ExtTextOutW SetTextColor SetBkMode CreateRectRgn GetClipRgn ExcludeClipRect SelectClipRgn SetDIBits CreateCompatibleBitmap CreateSolidBrush CreateBitmap |
| COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
| SHELL32.dll |
DragFinish
DragQueryFileW ShellExecuteExW DragAcceptFiles |
| MMFS2.dll (delay-loaded) |
#3
#172 #831 #19 #1033 #1145 #425 #1144 #423 #430 #1146 #121 #31 #1105 #255 #281 #174 #419 #688 #192 #120 #333 #80 #468 #280 #67 #125 #249 #276 #366 #959 #945 #123 #124 #11 #1049 #1036 #173 #493 #487 #372 #520 #585 #341 #342 #417 #355 #610 #445 #344 #50 #62 #34 #982 #1106 #1017 #876 #361 #32 #63 #832 #742 #102 #101 #17 #16 #103 #753 #536 #47 #756 #757 #343 #686 #443 #1000 #265 #1068 #162 #765 #1069 #379 #661 #1031 #433 #184 #191 #825 #201 #158 #177 #186 #163 #176 #189 #1073 #183 #153 #1072 #10 #9 #6 #8 #7 #766 #64 #43 #65 #66 #264 #587 #448 #286 #568 #169 #849 #571 #701 #703 #170 #51 #74 #83 #97 #81 #979 #79 #187 #82 #76 #78 #106 #107 #105 #168 #691 #75 #241 #272 #245 #274 #363 #645 #584 #519 #356 #739 #713 #137 #554 #155 #786 #619 #462 #761 #411 #1120 #469 #1134 #95 #1123 #1126 #94 #1124 #1125 #98 #91 #24 #59 #61 #60 #70 #69 #68 #819 #820 #77 #72 #389 #755 #795 #1054 #1077 #204 #205 #1071 #203 #195 #198 #196 #199 #808 #813 #809 #807 #811 #810 #814 #812 #826 #827 #828 #422 #803 #806 #800 #802 #804 #798 #805 #799 #801 #797 #830 #829 #607 #1074 #494 #1130 #1029 #611 #1081 #27 #39 #29 #834 #1101 #1007 #837 #896 #975 #953 #893 #986 #954 #895 #1048 #929 #677 #412 #234 #612 #678 #413 #679 #1118 #680 #573 #414 #415 #416 #232 #972 #681 #476 #620 #762 #236 #114 #104 #171 #789 #790 #46 #111 #42 #113 #115 #254 #785 #722 #328 #116 #90 #84 #1010 #92 #1008 #1011 #117 #997 #996 #998 #108 #109 #73 #110 #71 #913 #859 #878 #994 #894 #974 #882 #948 #991 #269 #267 #268 #976 #1006 #985 #1037 #794 #1053 #1128 #35 #1080 #18 #340 #14 #984 #5 #418 #750 #695 #23 #1070 #373 #740 #546 #4 #1055 #2 #1104 |
| Attributes | 0x1 |
|---|---|
| Name | MMFS2.dll |
| ModuleHandle | 0x9d940 |
| DelayImportAddressTable | 0x9d420 |
| DelayImportNameTable | 0x99cec |
| BoundDelayImportTable | 0x9a208 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x9d2b0 |
| Ordinal | 2 |
|---|---|
| Address | 0x9d2b4 |
| Modules |
| 3f4c2ea3-bbc2-4c40-9f38-b0098ab92bcb |
| Cannot initialize application. |
| Error while opening file. |
| Not enough memory! |
| File error! |
| Cannot find %s! |
| Cannot load %s. This object might need an external program or library not yet installed. |
| There is not enough available space in the temporary drive. Free some disk space and try again. |
| This application has been built with an incompatible version of Clickteam Fusion. |
| Unknown format! |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.0.296.9 |
| ProductVersion | 3.0.296.9 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Process Default Language |
| Resource LangID | Process Default Language |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 14:32:10 |
| Version | 0.0 |
| SizeofData | 884 |
| AddressOfRawData | 0x98bb8 |
| PointerToRawData | 0x97db8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 14:32:10 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x49c014 |
| SEHandlerTable | 0x498b20 |
| SEHandlerCount | 38 |
| XOR Key | 0xdacfcce7 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 46 |
| 243 (40116) | 139 |
| 242 (40116) | 35 |
| ASM objects (VS 2015/2017 runtime 26706) | 20 |
| C objects (VS 2015/2017 runtime 26706) | 20 |
| C++ objects (VS 2015/2017 runtime 26706) | 43 |
| Imports (VS2008 SP1 build 30729) | 15 |
| Total imports | 618 |
| C++ objects (LTCG) (27053) | 43 |
| Exports (27053) | 1 |
| Resource objects (27053) | 1 |
| Linker (27053) | 1 |
No comments yet.