| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2017-Sep-15 22:49:09 |
| Detected languages |
English - United Kingdom
English - United States |
| Debug artifacts |
F:\work\build\win_32-linkMT-callFast-x86_32\cl_16.00.40219.01\rel\armcc\armcc.pdb
|
| FileVersion | 5.06.0.151 |
| CompanyName | ARM Limited |
| LegalCopyright | Copyright (C) 2017 |
| ProductName | 5.06 |
| ProductVersion | 5.06.0 |
| Copyright | Copyright (C) ARM Ltd 2017 . All Rights Reserved |
| FileDescription | The ARM C/C++ Compiler |
| InternalName | standard armcc for win_32-x86_32-rel ;(;valgrind=false;) |
| OriginalFilename | armcc |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to Blowfish Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .textidx
Unusual section name found: .fnp_dir Unusual section name found: .fnp_mar |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ARM Ltd
Issuer: GlobalSign Extended Validation CodeSigning CA - SHA256 - G3 |
| Safe | VirusTotal score: 0/72 (Scanned on 2023-11-05 09:09:31) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2017-Sep-15 22:49:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0xaef800 |
| SizeOfInitializedData | 0x45a000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0099BC9B (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xaf1000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1872000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xf51a46 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x800000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey GetUserNameA OpenSCManagerA CryptReleaseContext CryptDestroyKey CryptGenKey CryptGetUserKey CryptAcquireContextA CryptDestroyHash RegSetValueExA CryptEncrypt CryptDeriveKey CryptHashData CryptCreateHash RegCreateKeyA CryptDecrypt OpenServiceA QueryServiceStatus RegCreateKeyExA CloseServiceHandle RegQueryInfoKeyA RegEnumKeyExA GetUserNameW RegSetValueExW RegQueryValueExW RegEnumValueA RegDeleteValueA StartServiceA |
|---|---|
| MPR.dll |
WNetGetUniversalNameA
|
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| ole32.dll |
CoInitializeSecurity
CoInitializeEx CoCreateGuid CoCreateInstance CoSetProxyBlanket CoUninitialize |
| SHLWAPI.dll |
PathRemoveBackslashW
PathRemoveFileSpecA PathFileExistsA PathCombineA |
| COMCTL32.dll |
#17
|
| NETAPI32.dll |
Netbios
|
| WS2_32.dll |
WSACleanup
htonl setsockopt ioctlsocket send recv closesocket WSAGetLastError socket connect select __WSAFDIsSet inet_addr getnameinfo getsockopt getaddrinfo freeaddrinfo gethostname gethostbyname inet_ntoa htons WSAStartup |
| KERNEL32.dll |
GetCurrentDirectoryW
PeekNamedPipe GetFileInformationByHandle FlushFileBuffers GetConsoleMode GetConsoleCP HeapDestroy HeapCreate IsProcessorFeaturePresent FatalAppExitA GetStartupInfoW SetHandleCount InitializeCriticalSectionAndSpinCount GetCurrentThread GetCurrentThreadId TlsFree TlsSetValue TlsGetValue TlsAlloc IsValidCodePage GetProcAddress LoadLibraryA GetCurrentProcessId CreateFileA SetFilePointer GetLocaleInfoA UnmapViewOfFile VirtualQuery MapViewOfFileEx FormatMessageA WriteFile GetLastError GetTempFileNameA CreateFileMappingA CloseHandle GetVersion GetTempPathA MapViewOfFile FreeLibrary GetCurrentProcess WaitForSingleObject CreateRemoteThread GetCommandLineA OpenProcess ReadProcessMemory GetExitCodeThread DuplicateHandle OpenFileMappingA ExpandEnvironmentStringsA GetExitCodeProcess CreateProcessA GetComputerNameA SystemTimeToFileTime QueryPerformanceCounter GetSystemTimeAsFileTime QueryPerformanceFrequency SetInformationJobObject GetFileAttributesExA AssignProcessToJobObject GetFileAttributesA TerminateProcess ReadFile CreateJobObjectA GetStdHandle FindFirstFileA FindFirstFileExA VirtualAlloc SetFileAttributesA CreatePipe SetCurrentDirectoryW VirtualProtect GetCurrentDirectoryA GetVersionExA DeleteFileA GetModuleFileNameA WideCharToMultiByte MultiByteToWideChar GetPrivateProfileIntA GetPrivateProfileStringA Sleep GetFullPathNameA GetSystemDirectoryA ReleaseMutex HeapSize MoveFileExA GetLocalTime GetVolumeInformationA GetSystemDefaultLangID GetUserDefaultLangID LocalFree DeviceIoControl GetTickCount FreeEnvironmentStringsA lstrlenA GetEnvironmentStrings GetWindowsDirectoryA SetErrorMode SetHandleInformation GetCommandLineW GetEnvironmentVariableA GetEnvironmentVariableW GetTimeZoneInformation GetProcessTimes FindFirstFileW FindNextFileW FindNextFileA FindClose ResetEvent CreateEventA SetEvent GetDriveTypeA VirtualFree SetLastError LeaveCriticalSection EnterCriticalSection InitializeCriticalSection DeleteCriticalSection SetNamedPipeHandleState WaitNamedPipeA SleepEx GetOEMCP GetACP GetLocaleInfoW GetModuleFileNameW IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter LCMapStringW LoadLibraryW CreateThread ResumeThread ExitThread DeleteFileW GetFileAttributesW MoveFileW MoveFileA CreateFileW GetFileType RaiseException SetCurrentDirectoryA SetEnvironmentVariableA CreateDirectoryA GetDateFormatA GetTimeFormatA HeapReAlloc GetCPInfo FindFirstFileExW GetDriveTypeW HeapSetInformation RtlUnwind SetConsoleCtrlHandler ExitProcess GetModuleHandleW FileTimeToLocalFileTime FileTimeToSystemTime HeapAlloc HeapFree DecodePointer EncodePointer InterlockedExchange SetStdHandle FreeEnvironmentStringsW GetUserDefaultLCID EnumSystemLocalesA IsValidLocale GetStringTypeW GetFullPathNameW SetEnvironmentVariableW GetEnvironmentStringsW SetEndOfFile GetProcessHeap CreateMutexA WriteConsoleW GetModuleHandleA InterlockedCompareExchange InterlockedDecrement InterlockedIncrement CompareStringW |
| USER32.dll |
wsprintfA
GetClientRect ScreenToClient CreateDialogIndirectParamA ShowWindow DialogBoxIndirectParamA SetFocus GetFocus EndDialog GetDlgItemTextA GetDlgItemTextW SetDlgItemTextA MessageBeep GetWindowLongA SendMessageA GetDlgItem GetWindowRect EnableWindow GetSystemMetrics GetActiveWindow MessageBoxA CharUpperW GetParent SetWindowTextA MoveWindow |
| SHELL32.dll |
#680
|
| OLEAUT32.dll |
VariantInit
VariantClear SysAllocString SysFreeString SysStringLen SysAllocStringLen |
| COMDLG32.dll |
GetOpenFileNameA
|
| dhcpcsvc.DLL |
DhcpRequestParams
|
| Ordinal | 1 |
|---|---|
| Address | 0x94bd20 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.6.0.151 |
| ProductVersion | 5.6.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 5.06.0.151 |
| CompanyName | ARM Limited |
| LegalCopyright | Copyright (C) 2017 |
| ProductName | 5.06 |
| ProductVersion (#2) | 5.06.0 |
| Copyright | Copyright (C) ARM Ltd 2017 . All Rights Reserved |
| FileDescription | The ARM C/C++ Compiler |
| InternalName | standard armcc for win_32-x86_32-rel ;(;valgrind=false;) |
| OriginalFilename | armcc |
| Resource LangID | English - United Kingdom |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Sep-15 22:49:09 |
| Version | 0.0 |
| SizeofData | 106 |
| AddressOfRawData | 0xe94680 |
| PointerToRawData | 0xe93280 |
| Referenced File | F:\work\build\win_32-linkMT-callFast-x86_32\cl_16.00.40219.01\rel\armcc\armcc.pdb |
| XOR Key | 0x380d14ef |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 13 |
| ASM objects (VS2010 SP1 build 40219) | 48 |
| C objects (VS2008 SP1 build 30729) | 2 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 138 |
| Total imports | 278 |
| Imports (VS2008 SP1 build 30729) | 29 |
| Unmarked objects (#2) | 1 |
| C++ objects (VS2010 SP1 build 40219) | 99 |
| 175 (VS2010 SP1 build 40219) | 603 |
| C objects (VS2010 SP1 build 40219) | 495 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.