| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1997-Sep-17 08:26:05 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Age of Empires |
| FileVersion | 00.08.68.0917 |
| InternalName | EMPIRES |
| LegalCopyright | Copyright © Microsoft Corp. 1997 |
| OriginalFilename | EMPIRES.EXE |
| ProductName | Age of Empires |
| ProductVersion | 1.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: THIS_COD
Unusual section name found: THIS_DAT Unusual section name found: Inf32Dat |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-14 09:25:32) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 9 |
| TimeDateStamp | 1997-Sep-17 08:26:05 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 4.0 |
| SizeOfCode | 0x148800 |
| SizeOfInitializedData | 0x1d6a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00135670 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x324000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
VirtualAlloc
HeapAlloc GetProcessHeap VirtualLock HeapFree IsBadCodePtr MapViewOfFileEx OpenFileMappingA EnterCriticalSection VirtualQuery VirtualQueryEx OpenMutexA UnmapViewOfFile VirtualFree ReleaseMutex CreateEventA SetEvent GetVersion LeaveCriticalSection CompareStringA WaitForSingleObject GetSystemInfo GetTempFileNameA GetDriveTypeA GetVolumeInformationA MulDiv CloseHandle FreeLibrary LoadLibraryA GlobalMemoryStatus GetCurrentDirectoryA OpenFile GetTempPathA WinExec FindFirstFileA FileTimeToSystemTime MapViewOfFile CreateFileA CreateFileMappingA OutputDebugStringA GetVersionExA GetProcAddress _llseek GlobalAlloc _lread FindResourceA GetModuleHandleA GlobalReAlloc LoadResource LockResource GlobalHandle GlobalLock GlobalUnlock _lclose GlobalFree _hread GetLastError IsDBCSLeadByte CreateMutexA GetCurrentThreadId InitializeCriticalSection DeleteCriticalSection ReadFile OpenProcess GetCurrentProcess SetFilePointer FindNextFileA GetFileType FileTimeToLocalFileTime ExitProcess RtlUnwind TerminateProcess GetSystemTime GetTimeZoneInformation GetLocalTime WriteFile DeleteFileA GetFullPathNameA GetStartupInfoA FindClose SetEnvironmentVariableA GetCommandLineA SetEndOfFile SetHandleCount GetStringTypeW GetStdHandle SetStdHandle GetCPInfo GetACP GetOEMCP MultiByteToWideChar LCMapStringA WideCharToMultiByte LCMapStringW RaiseException FlushFileBuffers GetStringTypeA CompareStringW UnhandledExceptionFilter GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW HeapDestroy HeapCreate SetUnhandledExceptionFilter IsBadReadPtr IsBadWritePtr |
|---|---|
| USER32.dll |
GetWindowRect
ScreenToClient SetRect DrawTextA FindWindowA SetSysColors GetForegroundWindow GetKeyState LoadCursorA CallWindowProcA GetSysColor IsClipboardFormatAvailable GetWindowLongA SetWindowLongA GetClientRect MoveWindow InvalidateRect ReleaseDC GetDC ClientToScreen GetAsyncKeyState GetKeyboardState PostMessageA SetCursorPos GetCursorPos ShowWindow SystemParametersInfoA LoadStringA GetMessageA DispatchMessageA TranslateMessage PeekMessageA RegisterClassA LoadIconA UpdateWindow SetWindowPos GetSystemMetrics BringWindowToTop GetLastActivePopup SetForegroundWindow GetUpdateRect FillRect GetWindowTextA SetCursor SetClassLongA MessageBoxA CharUpperA CreateWindowExA DestroyWindow SetTimer SetFocus OpenClipboard GetClipboardData CloseClipboard SendMessageA GetFocus GetActiveWindow DrawTextExA ReleaseCapture MessageBeep GetCapture KillTimer SetCapture SetWindowTextA GetWindowThreadProcessId PostQuitMessage DefWindowProcA WinHelpA IsIconic ValidateRect GetCaretBlinkTime |
| GDI32.dll |
SelectClipRgn
SelectObject GetStockObject MoveToEx SetBkMode TextOutA GetPaletteEntries DeleteObject DeleteDC SetTextColor CreateICA RealizePalette GetDeviceCaps GetTextExtentPoint32A CreatePen SelectPalette CreateFontIndirectA SetBkColor GetTextMetricsA CreatePalette GetNearestPaletteIndex ResizePalette GetObjectA CreateRectRgn GetSystemPaletteEntries SetPaletteEntries LineTo |
| ADVAPI32.dll |
RegCreateKeyExA
RegCloseKey RegSetValueExA RegQueryValueExA |
| DPLAYX.dll |
#1
#2 #4 |
| DSOUND.dll |
DirectSoundCreate
|
| DDRAW.dll |
DirectDrawCreate
|
| WINMM.dll |
mmioAdvance
mmioSetInfo mmioGetInfo mixerClose mixerGetControlDetailsA timeGetTime mciSendCommandA mciGetErrorStringA mixerSetControlDetails timeKillEvent timeEndPeriod timeBeginPeriod timeSetEvent mixerGetLineControlsA mmioRead mmioAscend mmioSeek mmioOpenA mmioDescend mixerOpen mmioClose mixerGetNumDevs mixerGetLineInfoA |
| IMM32.dll |
ImmReleaseContext
ImmNotifyIME ImmSetOpenStatus ImmAssociateContext ImmGetContext |
| MSVFW32.dll |
MCIWndCreateA
ICInfo |
| ole32.dll |
CoCreateInstance
CoInitialize CoUninitialize |
| WSOCK32.dll |
gethostname
WSAStartup WSACleanup gethostbyname |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.8.68.917 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Age of Empires |
| FileVersion (#2) | 00.08.68.0917 |
| InternalName | EMPIRES |
| LegalCopyright | Copyright © Microsoft Corp. 1997 |
| OriginalFilename | EMPIRES.EXE |
| ProductName | Age of Empires |
| ProductVersion (#2) | 1.0 |
| Resource LangID | English - United States |
|---|
No comments yet.