| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2017-Sep-15 22:20:38 |
| Detected languages |
English - United Kingdom
English - United States |
| Debug artifacts |
F:\work\build\win_32-linkMT-callFast-x86_32\cl_16.00.40219.01\rel\armar\armar.pdb
|
| FileVersion | 5.06.0.63 |
| CompanyName | ARM Limited |
| LegalCopyright | Copyright (C) 2017 |
| ProductName | 5.06 |
| ProductVersion | 5.06.0 |
| Copyright | Copyright (C) ARM Ltd 2017 . All Rights Reserved |
| FileDescription | The ARM Librarian |
| InternalName | standard armar for win_32-x86_32-rel |
| OriginalFilename | armar |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to Blowfish |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ARM Ltd
Issuer: GlobalSign Extended Validation CodeSigning CA - SHA256 - G3 |
| Safe | VirusTotal score: 0/64 (Scanned on 2023-11-20 05:09:58) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2017-Sep-15 22:20:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x13f400 |
| SizeOfInitializedData | 0x47600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000FA5E1 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x141000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x193ec2 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x800000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| SHLWAPI.dll |
PathRemoveFileSpecA
PathCombineA PathFileExistsA |
|---|---|
| KERNEL32.dll |
GetProcessHeap
SetEndOfFile WideCharToMultiByte MultiByteToWideChar GetComputerNameA GetModuleFileNameA CreateFileA SetInformationJobObject GetFileAttributesExA WriteFile AssignProcessToJobObject GetFileAttributesA CreateProcessA TerminateProcess ReadFile CreateJobObjectA GetStdHandle FindFirstFileA FindFirstFileExA GetLastError GetProcAddress VirtualAlloc CompareStringW CreatePipe GetModuleHandleA VirtualProtect GetCurrentDirectoryA GetVersionExA CloseHandle GetVersion GetCurrentProcessId DeleteFileA GetPrivateProfileIntA GetPrivateProfileStringA GetFullPathNameA ReleaseMutex WaitForSingleObject CreateMutexA MoveFileExA SystemTimeToFileTime GetSystemTimeAsFileTime QueryPerformanceCounter QueryPerformanceFrequency FreeLibrary LoadLibraryA SetFileAttributesA MoveFileA InterlockedIncrement InterlockedDecrement InterlockedCompareExchange InterlockedExchange EncodePointer DecodePointer Sleep InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection HeapFree GetTimeFormatA GetDateFormatA GetModuleHandleW ExitProcess GetCommandLineA HeapSetInformation CreateFileW HeapAlloc DuplicateHandle GetCurrentProcess HeapReAlloc GetDriveTypeW FileTimeToSystemTime FileTimeToLocalFileTime FindNextFileA CreateDirectoryA SetEnvironmentVariableA SetCurrentDirectoryA FindClose GetDriveTypeA RaiseException RtlUnwind GetTimeZoneInformation GetCPInfo LCMapStringW UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent HeapCreate HeapDestroy TlsAlloc TlsGetValue TlsSetValue TlsFree SetLastError GetCurrentThreadId GetCurrentThread SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW FatalAppExitA GetConsoleCP GetConsoleMode HeapSize GetACP GetOEMCP IsValidCodePage GetModuleFileNameW GetLocaleInfoW SetConsoleCtrlHandler LoadLibraryW FreeEnvironmentStringsW GetEnvironmentStringsW GetTickCount SetFilePointer IsProcessorFeaturePresent FlushFileBuffers SetStdHandle GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale GetStringTypeW GetCurrentDirectoryW SetCurrentDirectoryW SetEnvironmentVariableW GetFileInformationByHandle PeekNamedPipe WriteConsoleW |
| ADVAPI32.dll |
GetUserNameA
|
| Ordinal | 1 |
|---|---|
| Address | 0xdaff0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.6.0.63 |
| ProductVersion | 5.6.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 5.06.0.63 |
| CompanyName | ARM Limited |
| LegalCopyright | Copyright (C) 2017 |
| ProductName | 5.06 |
| ProductVersion (#2) | 5.06.0 |
| Copyright | Copyright (C) ARM Ltd 2017 . All Rights Reserved |
| FileDescription | The ARM Librarian |
| InternalName | standard armar for win_32-x86_32-rel |
| OriginalFilename | armar |
| Resource LangID | English - United Kingdom |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Sep-15 22:20:38 |
| Version | 0.0 |
| SizeofData | 106 |
| AddressOfRawData | 0x16f548 |
| PointerToRawData | 0x16dd48 |
| Referenced File | F:\work\build\win_32-linkMT-callFast-x86_32\cl_16.00.40219.01\rel\armar\armar.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x581000 |
| SEHandlerTable | 0x572580 |
| SEHandlerCount | 713 |
| XOR Key | 0x903b524f |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 1 |
| ASM objects (VS2010 SP1 build 40219) | 34 |
| Imports (VS2008 SP1 build 30729) | 7 |
| Total imports | 133 |
| C objects (VS2010 SP1 build 40219) | 203 |
| C++ objects (VS2010 SP1 build 40219) | 85 |
| 175 (VS2010 SP1 build 40219) | 106 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.