| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Oct-13 11:36:32 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\Dev\Project64-testing\bin\Release\pdb\Project64.pdb
|
| FileDescription | Project64 |
| FileVersion | .0.1.5664-2df3434 |
| InternalName | Project64 |
| LegalCopyright | Copyright (C) 2021 |
| OriginalFilename | Project64.exe |
| ProductName | Project64 |
| ProductVersion3.0.1.5664-2df3434 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/71 (Scanned on 2026-04-25 17:57:36) |
Jiangmin:
Trojan.Inject.clvj
Zillya: Trojan.GenKryptik.Win32.1157486 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2023-Oct-13 11:36:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x166e00 |
| SizeOfInitializedData | 0xc0800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00115125 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x168000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x268000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2303f8 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x1000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
lstrcmpiW
LoadLibraryExW GetModuleFileNameW FindResourceW MultiByteToWideChar GetCurrentProcess GetCurrentThread CreateIoCompletionPort GetQueuedCompletionStatus WriteFile ReadFile FindClose DuplicateHandle LoadLibraryA CreateDirectoryA RemoveDirectoryA FindFirstFileA FindNextFileA CancelIo FreeResource LockResource GetSystemTimeAsFileTime GetFileTime SystemTimeToTzSpecificLocalTime FileTimeToSystemTime CreateFileA ExitThread IsDebuggerPresent DebugBreak GetSystemDirectoryW GetVolumeInformationW GetComputerNameW GetVolumePathNameW GetExitCodeThread lstrcmpiA FindFirstChangeNotificationA FindCloseChangeNotification SetErrorMode lstrlenW GetVersionExW CompareStringW SizeofResource WriteConsoleW SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP IsValidCodePage FindFirstFileExA SetStdHandle GetCurrentDirectoryW DeleteFileW ReadConsoleW SetFilePointerEx GetConsoleMode GetConsoleCP EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetACP GetStdHandle ExitProcess GetModuleHandleExW GetFullPathNameA GetFullPathNameW GetTimeZoneInformation GetFileType GetDriveTypeW GetCommandLineW LoadResource RtlUnwind UnregisterWaitEx QueryDepthSList InterlockedFlushSList ReleaseSemaphore GetModuleHandleA FreeLibraryAndExitThread GetThreadTimes UnregisterWait RegisterWaitForSingleObject SetThreadAffinityMask GetProcessAffinityMask GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation GetThreadPriority SwitchToThread SignalObjectAndWait CreateTimerQueue GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter OutputDebugStringW IsProcessorFeaturePresent FlushInstructionCache InterlockedPushEntrySList InterlockedPopEntrySList InitializeSListHead GetCPInfo GetStringTypeW GetLocaleInfoW LCMapStringW GetTickCount TlsFree TlsSetValue TlsGetValue TlsAlloc EncodePointer TryEnterCriticalSection WaitForSingleObjectEx Process32NextW Process32FirstW CreateToolhelp32Snapshot TerminateProcess OpenProcess QueryPerformanceFrequency QueryPerformanceCounter SetThreadPriority InitializeCriticalSection VirtualFree VirtualAlloc SetFilePointer SetEndOfFile FlushFileBuffers GetFileSize CopyFileA DeleteFileA GetFileAttributesA SetFileAttributesA GetCurrentDirectoryA SetCurrentDirectoryA GetModuleFileNameA GetLocalTime WideCharToMultiByte SystemTimeToFileTime GetSystemTime WaitNamedPipeW CreateFileW PeekNamedPipe GetCurrentProcessId LoadLibraryExA VirtualQuery VirtualProtect GetSystemInfo ResetEvent InterlockedDecrement InterlockedIncrement FindNextChangeNotification FindFirstChangeNotificationW WaitForMultipleObjects CreateThread GlobalFree Sleep GlobalUnlock GlobalLock GlobalAlloc GetModuleHandleW GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc DecodePointer LoadLibraryW GetProcAddress FreeLibrary LeaveCriticalSection EnterCriticalSection SetLastError CreateEventW MulDiv CloseHandle WaitForSingleObject SetEvent DeleteCriticalSection InitializeCriticalSectionAndSpinCount GetLastError TerminateThread GetCurrentThreadId GetCommandLineA RaiseException |
|---|---|
| USER32.dll |
GetSysColorBrush
SetCaretPos ShowCaret HideCaret DestroyCaret CreateCaret ScrollDC GetClassInfoExW RegisterClassExW GetClassInfoW IsClipboardFormatAvailable GetSystemMenu SystemParametersInfoW GetClassNameW InflateRect OffsetRect CopyRect DrawFocusRect GetSysColor EndPaint BeginPaint SendMessageW SetWindowPos EndDialog GetDlgItem DrawTextW GetDC SetWindowTextW DestroyIcon PtInRect DrawIconEx UpdateWindow ReleaseCapture SetCapture GetCapture GetFocus TrackMouseEvent SetRectEmpty GetClientRect GetWindowRect MapWindowPoints SetWindowLongW UnregisterClassW CreateWindowExW IsWindow MsgWaitForMultipleObjects AdjustWindowRect DeleteMenu InsertMenuW CreateAcceleratorTableW AppendMenuW CreatePopupMenu CreateMenu TranslateAcceleratorW DestroyAcceleratorTable IsMenu IsDlgButtonChecked CheckDlgButton IsDialogMessageW LoadIconW GetDesktopWindow SetRect ShowCursor RemovePropW ValidateRect SetMenu GetSystemMetrics IsZoomed RegisterClassW PostQuitMessage PeekMessageW DispatchMessageW TranslateMessage GetMessageW RemoveMenu SetForegroundWindow CharNextW IsIconic SetScrollInfo GetClipboardData GetKeyState GetTopWindow SetParent GetPropW SetPropW LoadCursorW WindowFromPoint SetCursor GetWindowTextW SetWindowTextA CheckMenuItem KillTimer SetTimer EmptyClipboard SetClipboardData CloseClipboard OpenClipboard GetDlgItemTextW SendDlgItemMessageW wsprintfW FillRect ScreenToClient AdjustWindowRectEx EnableMenuItem GetMenu BringWindowToTop MoveWindow CallWindowProcW DefWindowProcW GetWindowTextLengthW GetMonitorInfoW MonitorFromWindow GetWindow LoadImageW LoadBitmapW GetParent SetMenuItemInfoW GetMenuItemInfoW TrackPopupMenu GetSubMenu DestroyMenu LoadMenuW SetFocus SetDlgItemTextW CreateDialogParamW SetWindowPlacement GetWindowPlacement PostMessageW GetMessagePos MessageBoxW GetActiveWindow DialogBoxParamW GetScrollInfo CallNextHookEx UnhookWindowsHookEx SetWindowsHookExW GetWindowLongW GetCursorPos GetScrollRange SetScrollRange GetScrollPos SetScrollPos RedrawWindow InvalidateRect ReleaseDC EnableWindow GetDlgCtrlID IsWindowVisible ShowWindow DestroyWindow IsWindowEnabled |
| GDI32.dll |
GetObjectW
GetTextMetricsW LineTo SetPixel MoveToEx SetBkColor SetDCBrushColor CreateFontW SetTextColor BitBlt CreateCompatibleBitmap CreateCompatibleDC EnumFontsW SetMapMode ExtTextOutW PatBlt StretchBlt SetBkMode SelectObject Rectangle GetStockObject GetDeviceCaps CreateFontIndirectW CreatePen CreateSolidBrush TextOutW DeleteDC DeleteObject |
| COMDLG32.dll |
GetSaveFileNameW
GetSaveFileNameA GetOpenFileNameA |
| ole32.dll |
CoTaskMemRealloc
CoTaskMemAlloc CoCreateInstance CoUninitialize CoInitialize CoTaskMemFree |
| OLEAUT32.dll |
VarUI4FromStr
|
| COMCTL32.dll |
PropertySheetW
CreateStatusWindowW ImageList_AddMasked ImageList_Create |
| MSWSOCK.dll |
AcceptEx
|
| WININET.dll |
HttpQueryInfoW
HttpSendRequestW HttpOpenRequestW InternetConnectW InternetCloseHandle InternetOpenW |
| ADVAPI32.dll (delay-loaded) |
RegCloseKey
RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegOpenKeyExW RegQueryInfoKeyW RegSetValueExW RegQueryValueExW |
| Attributes | 0x1 |
|---|---|
| Name | ADVAPI32.dll |
| ModuleHandle | 0x1c1fe0 |
| DelayImportAddressTable | 0x1c1584 |
| DelayImportNameTable | 0x1b84b4 |
| BoundDelayImportTable | 0x1b8644 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.0.1.5664 |
| ProductVersion | 3.0.1.5664 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | Project64 |
| FileVersion (#2) | .0.1.5664-2df3434 |
| InternalName | Project64 |
| LegalCopyright | Copyright (C) 2021 |
| OriginalFilename | Project64.exe |
| ProductName | Project64 |
| ProductVersion3.0.1.5664-2df3434 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-13 11:36:32 |
| Version | 0.0 |
| SizeofData | 79 |
| AddressOfRawData | 0x1a0040 |
| PointerToRawData | 0x19f240 |
| Referenced File | D:\Dev\Project64-testing\bin\Release\pdb\Project64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-13 11:36:32 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1a0090 |
| PointerToRawData | 0x19f290 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-13 11:36:32 |
| Version | 0.0 |
| SizeofData | 1132 |
| AddressOfRawData | 0x1a00a4 |
| PointerToRawData | 0x19f2a4 |
| StartAddressOfRawData | 0x5ff000 |
|---|---|
| EndAddressOfRawData | 0x5ff008 |
| AddressOfIndex | 0x5fa6a4 |
| AddressOfCallbacks | 0x5686c0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x5c |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x5bf694 |
| SEHandlerTable | 0x59efd0 |
| SEHandlerCount | 1052 |
| XOR Key | 0xca130d27 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 36 |
| 243 (40116) | 178 |
| 242 (40116) | 44 |
| 199 (41118) | 1 |
| ASM objects (VS2015 UPD3 build 24123) | 31 |
| C++ objects (23013) | 3 |
| C objects (VS2015 UPD3 build 24123) | 43 |
| C objects (VS2015 UPD3.1 build 24215) | 26 |
| C++ objects (VS2015 UPD3 build 24123) | 124 |
| C objects (VS2008 SP1 build 30729) | 1 |
| Imports (VS2008 SP1 build 30729) | 19 |
| Total imports | 425 |
| C++ objects (VS2015 UPD3.1 build 24215) | 170 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |
No comments yet.