| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-27 15:58:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\dogu1\OneDrive\Documents\first\build\Debug\first.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-Feb-27 15:58:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xfb800 |
| SizeOfInitializedData | 0x52400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000003157 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x154000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WideCharToMultiByte
CreateFileW CloseHandle ReadConsoleW ReadFile SetFilePointerEx GetFileSizeEx InitOnceExecuteOnce GetConsoleOutputCP FlushFileBuffers HeapQueryInformation HeapReAlloc LCMapStringW CompareStringW GetTimeFormatW GetConsoleMode OutputDebugStringA GetDateFormatW VirtualProtect IsDebuggerPresent RaiseException MultiByteToWideChar RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GetStartupInfoW GetModuleHandleW GetLastError HeapAlloc HeapFree GetProcessHeap VirtualQuery FreeLibrary GetProcAddress RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList GetModuleFileNameW LoadLibraryExW RtlPcToFileHeader SetLastError EncodePointer EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetStdHandle GetFileType GetModuleHandleExW WriteConsoleW WriteFile ExitProcess HeapSize HeapValidate GetSystemInfo OutputDebugStringW SetConsoleCtrlHandler GetCurrentThread FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle GetStringTypeW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetTempPathW FlsAlloc FlsGetValue FlsSetValue FlsFree IsThreadAFiber InitializeCriticalSectionEx RtlUnwind |
|---|---|
| USER32.dll |
TranslateMessage
DispatchMessageA PeekMessageA DefWindowProcA MessageBoxA ShowWindow CreateWindowExA RegisterClassA PostQuitMessage |
| ole32.dll |
PropVariantClear
CoCreateInstance |
| D3DCOMPILER_47.dll |
D3DCompileFromFile
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-27 14:39:37 |
| Version | 0.0 |
| SizeofData | 86 |
| AddressOfRawData | 0x134860 |
| PointerToRawData | 0x133460 |
| Referenced File | C:\Users\dogu1\OneDrive\Documents\first\build\Debug\first.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-27 14:39:37 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1348b8 |
| PointerToRawData | 0x1334b8 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14013f000 |
| XOR Key | 0xe84489c1 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 8 |
| C++ objects (33145) | 154 |
| ASM objects (35207) | 9 |
| C objects (35207) | 16 |
| C++ objects (35207) | 55 |
| C objects (33145) | 13 |
| Imports (33145) | 11 |
| Total imports | 111 |
| C++ objects (35221) | 2 |
| Resource objects (35221) | 1 |
| Linker (35221) | 1 |
No comments yet.