861f080d9dd5e2cf0535bd7ad2b95d00

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2092-Nov-20 02:06:03
Debug artifacts d:\Temp\Rails\obj\Release\Rails.pdb
FileDescription
FileVersion 0.0.0.0
InternalName Rails.exe
LegalCopyright
OriginalFilename Rails.exe
ProductVersion 0.0.0.0
Assembly Version 0.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Safe VirusTotal score: 0/69 (Scanned on 2020-10-02 17:09:56) All the AVs think this file is safe.

Hashes

MD5 861f080d9dd5e2cf0535bd7ad2b95d00
SHA1 e26de95a89b2587f67bf612c0a7c6b131ea5bf9a
SHA256 b752da787d3cc47b91eec5b70f2ca5eb8d1d45650208ade3ca1f98464d65f8ed
SHA3 9268523319ff21aebaa2e0cda6f0d514bec44aa6c2db631f1ac795995d1e4cc1
SSDeep 48:6kantjPV/HjOmNbU+jJF5wAly8+GUSiGbL2AHkOulSTXqcpfbNtm:K1V/HjNbvP5wDGUSiGJqkTtzNt
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2092-Nov-20 02:06:03
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 48.0
SizeOfCode 0xa00
SizeOfInitializedData 0x800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00002816 (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x4000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x8000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 403007b75d27c2e3cb29e53a41811d24
SHA1 bea2ae6b6e282143f6d2541249791226333f7895
SHA256 7b7cc07371aa02e7dda7058525dfb12744466f947afd636487cdf89c67a95bec
SHA3 3bd9c5310ea31ffa0f78875429d8500dd6fdf3e206d3291c8d87bd75f733c211
VirtualSize 0x81c
VirtualAddress 0x2000
SizeOfRawData 0xa00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.42426

.rsrc

MD5 e96b51ee4a8fcc0fa5d02872f719423f
SHA1 57e2ccef6692cbddad9f93d708526b2e4eb7c53d
SHA256 2516b6b340ca5c9d8784ef646fb9bc0f453afe940f2c39cc5713a17c2f1e3c92
SHA3 dd01e773c24fd5eb379469a18bfc8a76d24b1cc06b110c5268b244e0496ec534
VirtualSize 0x4cc
VirtualAddress 0x4000
SizeOfRawData 0x600
PointerToRawData 0xc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.68541

.reloc

MD5 ed6c2e6aa43a2d28630f43d15fe5a290
SHA1 b20f83a0c4001153ca94cf2b622250fe98b9d53d
SHA256 6c200a3d85f4b2f7e4aef48b90ed14331c1262107d1e3d8cba052bd3bc1a07aa
SHA3 d4fb5c0273b9bad476f1e3acde527fe069fa94acd82da410b618a7c7b2e1cee8
VirtualSize 0xc
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0815394

Imports

mscoree.dll _CorExeMain

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x23c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14608
MD5 70c22bfcc914f1db121212bb7486e528
SHA1 97cef007f76b6f7dc419a4c4d33a5d8863e09f2c
SHA256 182cd01813d160a1c1814cd49db31757031b40967639028a5da1c93e90066adb
SHA3 2c3f3d510e9c622a79f3ce0a8edc0213c3789258c47670ca041e5d2cf0ff23fc

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription
FileVersion (#2) 0.0.0.0
InternalName Rails.exe
LegalCopyright
OriginalFilename Rails.exe
ProductVersion (#2) 0.0.0.0
Assembly Version 0.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2085-Jan-13 07:16:31
Version 0.0
SizeofData 60
AddressOfRawData 0x2788
PointerToRawData 0x988
Referenced File d:\Temp\Rails\obj\Release\Rails.pdb

UNKNOWN

Characteristics 0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

RICH Header

Errors

<-- -->