| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2015-Oct-24 06:03:50 |
| Detected languages |
English - United States
Process Default Language |
| Debug artifacts |
Embedded COFF debugging symbols
|
| CompanyName | Activision Blizzard, Inc. |
| FileDescription | Call of Duty(R): World at War Campaign/Coop |
| FileVersion | 1.7 |
| LegalCopyright | Copyright (C) 2008-2009 |
| ProductName | Call of Duty(R): World at War Game |
| ProductVersion | 1.7x |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 MSVC++ v.8 (procedure 1 recognized - h) |
| Suspicious | PEiD Signature: | Crunch 4 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. |
Resource 2 is possibly compressed or encrypted.
Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-18 21:04:42) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2015-Oct-24 06:03:50 |
| PointerToSymbolTable | 0x4c415421 |
| NumberOfSymbols | 727274529 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x3f0000 |
| SizeOfInitializedData | 0x160000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x003AF316 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3eb000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4abac02 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x705fb0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x20000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
RegSetValueExA
CryptGenRandom CryptReleaseContext CryptAcquireContextA RegOpenKeyA RegCreateKeyA RegQueryValueExA RegCloseKey |
|---|---|
| ddraw.dll |
DirectDrawEnumerateExA
DirectDrawCreateEx |
| dsound.dll |
DirectSoundCaptureCreate
DirectSoundCreate8 |
| gdi32.dll |
CreateSolidBrush
CreateFontA GetDeviceCaps SetDeviceGammaRamp |
| kernel32.dll |
GetLocaleInfoA
GetStringTypeW GetStringTypeA GetTickCount GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA SetEnvironmentVariableW SetEnvironmentVariableA FlushFileBuffers GetTimeZoneInformation SetFilePointer GetFileType LockResource GetConsoleMode GetConsoleCP HeapSize GetStdHandle DeleteCriticalSection HeapCreate HeapDestroy LCMapStringW WideCharToMultiByte LCMapStringA QueryPerformanceFrequency QueryPerformanceCounter CloseHandle SleepEx GetLastError ReadFileEx GetFileSize CreateFileA DebugBreak GetSystemTimeAsFileTime InterlockedExchange SuspendThread ResumeThread CreateThread ResetEvent Sleep CreateEventA GetCurrentProcess SetThreadIdealProcessor WaitForSingleObject GetProcessAffinityMask SetEvent GetCurrentThreadId SetThreadPriority SetThreadAffinityMask RaiseException GetCurrentThread DuplicateHandle SetFileAttributesA GetFileAttributesA SetStdHandle VirtualAlloc LeaveCriticalSection EnterCriticalSection GetModuleFileNameA GetModuleHandleA TryEnterCriticalSection InitializeCriticalSection GetProcAddress SetProcessAffinityMask GetThreadPriority GlobalMemoryStatus CreateProcessA FormatMessageA ReadFile WriteFile GetDriveTypeA SetErrorMode OpenProcess SetUnhandledExceptionFilter GlobalUnlock GetCurrentDirectoryA CreateToolhelp32Snapshot GlobalSize Module32First OutputDebugStringA Module32Next GlobalLock GetVersionExA GetCurrentProcessId DeleteFileA LoadLibraryW MultiByteToWideChar FreeLibrary MulDiv SetPriorityClass SetThreadExecutionState LoadLibraryA SwitchToThread InterlockedIncrement InterlockedDecrement CompareFileTime ReleaseMutex CreateMutexA WriteConsoleA GetConsoleOutputCP WriteConsoleW HeapFree HeapAlloc ExitProcess RtlUnwind MoveFileA TerminateProcess UnhandledExceptionFilter IsDebuggerPresent FileTimeToSystemTime FileTimeToLocalFileTime CreateDirectoryA GetFullPathNameA HeapReAlloc GetCommandLineA GetProcessHeap GetStartupInfoA GetCPInfo GetACP GetOEMCP IsValidCodePage TlsGetValue TlsAlloc TlsSetValue TlsFree RestoreLastError CompareStringA CompareStringW SetEndOfFile InterlockedCompareExchange IsProcessorFeaturePresent RemoveDirectoryA FindClose GetSystemTime SystemTimeToFileTime FindNextFileA VirtualFree VirtualQuery FindFirstFileA |
| oleaut32.dll |
SysAllocString
|
| psapi.dll |
GetProcessMemoryInfo
|
| shell32.dll |
SHGetFolderPathA
ShellExecuteA |
| user32.dll |
CallWindowProcA
LoadImageA UpdateWindow AdjustWindowRect DestroyWindow RegisterClassA MoveWindow CreateWindowExA DefWindowProcA SetWindowPos MapVirtualKeyA GetMessageA CloseClipboard GetMonitorInfoA RegisterClipboardFormatA SendMessageA GetClipboardData DispatchMessageA OpenClipboard PeekMessageA RegisterClassExA MonitorFromWindow PostQuitMessage GetSystemMetrics TranslateMessage LoadCursorA SetWindowTextA LoadIconA ShowWindow SetFocus ShowCursor GetForegroundWindow SetCursorPos ClientToScreen GetCursorPos ScreenToClient GetWindowRect PostMessageA GetActiveWindow MessageBoxA GetDC GetWindowTextA SetWindowLongA GetWindowLongA ReleaseDC GetDesktopWindow ChangeDisplaySettingsA EnumThreadWindows MonitorFromPoint EnumDisplayMonitors AdjustWindowRectEx IsWindow CloseWindow |
| winmm.dll |
timeEndPeriod
mixerGetNumDevs mixerClose mixerGetLineInfoA mixerOpen mixerGetLineControlsA waveInGetNumDevs mixerSetControlDetails mixerGetControlDetailsA timeGetTime timeBeginPeriod |
| ws2_32.dll |
htons
inet_ntoa getsockname select __WSAFDIsSet |
| wsock32.dll |
inet_addr
send WSAGetLastError htons htonl ioctlsocket connect closesocket WSAStartup socket bind recv gethostbyname sendto setsockopt gethostname recvfrom |
| xinput1_3.dll |
XInputGetState
XInputGetCapabilities XInputSetState |
| binkw32.dll |
_BinkClose@4
_BinkGetRects@8 _BinkSetMemory@8 _BinkRegisterFrameBuffers@8 _BinkWait@4 _BinkOpen@8 _BinkNextFrame@4 _BinkGetFrameBuffersInfo@8 _BinkSetSoundTrack@8 _BinkControlBackgroundIO@8 _BinkGetRealtime@12 _BinkDoFrame@4 _BinkOpenDirectSound@4 _BinkSetIOSize@4 _BinkSetSoundOnOff@8 _BinkPause@8 _BinkSetVolume@12 _BinkGetError@0 _BinkSetSoundSystem@8 |
| d3d9.dll |
D3DPERF_BeginEvent
Direct3DCreate9 D3DPERF_EndEvent |
| d3dx9_37.dll |
D3DXCompileShader
D3DXGetShaderConstantTable D3DXCreateBuffer D3DXGetShaderInputSemantics D3DXGetShaderOutputSemantics |
| faultrep.dll |
ReportFault
|
| ole32.dll |
CoTaskMemAlloc
CLSIDFromString CoUninitialize CoInitialize CoCreateInstance CoInitializeEx CoTaskMemFree |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.7.0.0 |
| ProductVersion | 1.7.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| CompanyName | Activision Blizzard, Inc. |
| FileDescription | Call of Duty(R): World at War Campaign/Coop |
| FileVersion (#2) | 1.7 |
| LegalCopyright | Copyright (C) 2008-2009 |
| ProductName | Call of Duty(R): World at War Game |
| ProductVersion (#2) | 1.7x |
| Resource LangID | Process Default Language |
|---|
| StartAddressOfRawData | 0x4e56000 |
|---|---|
| EndAddressOfRawData | 0x4e56028 |
| AddressOfIndex | 0x4e54760 |
| AddressOfCallbacks | 0x7eba3c |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
| XOR Key | 0x3ebf2ead |
|---|---|
| Unmarked objects | 0 |
| 126 (50327) | 7 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 62 |
| ASM objects (VS2003 (.NET) build 3077) | 1 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 378 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 261 |
| Imports (VS2008 build 21022) | 2 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 6 |
| Imports (VS2003 (.NET) build 4035) | 29 |
| Total imports | 306 |
| 114 (VS2012 build 50727 / VS2005 build 50727) | 758 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |