91dbda9a63a5f142da135923991d778bda1077a3bb747d1d7ffd18d24c8de4c7

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2020-May-06 07:16:38
Detected languages English - United States
Debug artifacts D:\EC2019_Master\Output\Pdb\Gifsicle.pdb

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • gmail.com
Info The PE is digitally signed. Signer: \xE6\xB7\xB1\xE5\x9C\xB3\xE5\xB8\x82\xE5\x85\xAD\xE5\xBA\xA6\xE4\xBA\xBA\xE5\x92\x8C\xE7\xA7\x91\xE6\x8A\x80\xE6\x9C\x89\xE9\x99\x90\xE5\x85\xAC\xE5\x8F\xB8
Issuer: DigiCert EV Code Signing CA
Safe VirusTotal score: 0/71 (Scanned on 2026-09-08 02:19:34) All the AVs think this file is safe.

Hashes

MD5 ade175d969ca494fa68de364eebc26f0 🔍
SHA1 e85693784ad52c0614bf28a586aa5e88b0c4a2e7 🔍
SHA256 91dbda9a63a5f142da135923991d778bda1077a3bb747d1d7ffd18d24c8de4c7 🔍
SHA3 08b9481bf50e1fd4adf3f4dacd893e0b5ca321141ae58409dcba37dd5027656b 🔍
SSDeep 3072:qRsIj73fJcgLLMoW2hDbSxtIL1acBibFMDTOzy+3YWnc7qM3fuw:I72g3M9ODbSxtIpacMRMl+3Fncow 🔍
Imports Hash 88da5702b5892907ea8f176a707ff5fb 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2020-May-06 07:16:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0x25000
SizeOfInitializedData 0x9600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000254DE (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x26000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x31000
SizeOfHeaders 0x400
Checksum 0x3cdb6
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ca70e50f13bba50563c7de415cd63fdc 🔍
SHA1 d62c858b73ab7e61569c684c56a764f1b81fcfe9 🔍
SHA256 99eccba402247c521cdb60931eed8fb7fdae1423a2eeae4e499a20702c5dd887 🔍
SHA3 11e742243484a9bb3b8a42a2185a0cbd3a5d520cdb611fcdcdb80d0d7403f8d9 🔍
VirtualSize 0x24f9f
VirtualAddress 0x1000
SizeOfRawData 0x25000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.21431

.rdata

MD5 6e26162f5e1cbabdefd2b5a2d1d611ee 🔍
SHA1 18fb02f1c6d0d80f330ae6a5c9caf1a42f6a17c3 🔍
SHA256 0852f109d15198c813984aebe2b823d693837e94c670dd8370a63b389d1a54c4 🔍
SHA3 621588066b4956d22c3d604283c7be077de38e92e195aea693523dd6e0f16c62 🔍
VirtualSize 0x2854
VirtualAddress 0x26000
SizeOfRawData 0x2a00
PointerToRawData 0x25400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.25666

.data

MD5 708f24a9ee3e89b8ccadcf6d33fabeb4 🔍
SHA1 5761176c34c92fb7d1082bc574519c26b27b14d4 🔍
SHA256 c4a5f0e8e2f7c06502922e7df3c60850558ea498426caa952ddfe43cffbc95e6 🔍
SHA3 b816bf7f17604a056c87c1ec38c984f10088dbef3354a93dfdb0cc0d8d067640 🔍
VirtualSize 0x4d44
VirtualAddress 0x29000
SizeOfRawData 0x4400
PointerToRawData 0x27e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.96173

.rsrc

MD5 2ff1daafc0d7823debd0f1aa5f75e360 🔍
SHA1 c8a98c69c2d215172a9a5e2cce171b60f545a7b3 🔍
SHA256 a8736cd21a0c1fff4161e1004d2e7f5010602e0421eb84660147b1960a41836b 🔍
SHA3 b988915cf802308fcad1c24bb76ddfeddb40c0c6f934a1cdd6da07aec2bade0d 🔍
VirtualSize 0x1e0
VirtualAddress 0x2e000
SizeOfRawData 0x200
PointerToRawData 0x2c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 683864bb6301b53d0d03edeb9dbc90f9 🔍
SHA1 0043d4070dceed90bd968b661fe8574b05d0bddb 🔍
SHA256 330f489a6c6840af12ee14f3ede549e4d16fa555fd5aee008e95d827cf894890 🔍
SHA3 8b4ff289aeb8880cedda24796b191472848d33d40180ff317a956cf105af43db 🔍
VirtualSize 0x1a2c
VirtualAddress 0x2f000
SizeOfRawData 0x1c00
PointerToRawData 0x2c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.58109

Imports

MSVCR120.dll __iob_func
strchr
strtol
tolower
fwrite
strrchr
realloc
strtoul
getenv
fprintf
exit
fputc
ungetc
fread
ftell
getc
sscanf
strerror
_isatty
_snprintf
_errno
printf
fopen
isdigit
_fileno
_setmode
fclose
qsort
rand
putc
fflush
strstr
strspn
feof
tmpnam
_pclose
_popen
remove
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
_XcptFilter
_amsg_exit
__getmainargs
__set_app_type
_exit
_cexit
_configthreadlocale
__setusermatherr
_initterm_e
_initterm
__initenv
_fmode
_commode
?terminate@@YAXXZ
__crtSetUnhandledExceptionFilter
_lock
_unlock
_calloc_crt
__dllonexit
_onexit
_invoke_watson
_controlfp_s
_except_handler4_common
fputs
malloc
isspace
free
strncmp
memmove
sprintf
fgets
strtod
_CIatan2
_libm_sse2_pow_precise
_libm_sse2_sin_precise
_libm_sse2_sqrt_precise
ceil
floor
memcmp
memcpy
memset
_except1
KERNEL32.dll GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
EncodePointer
IsProcessorFeaturePresent
IsDebuggerPresent
DecodePointer

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-May-06 07:16:38
Version 0.0
SizeofData 65
AddressOfRawData 0x28100
PointerToRawData 0x27500
Referenced File D:\EC2019_Master\Output\Pdb\Gifsicle.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2020-May-06 07:16:38
Version 0.0
SizeofData 20
AddressOfRawData 0x28144
PointerToRawData 0x27544

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x429000
SEHandlerTable 0x428160
SEHandlerCount 1

RICH Header

XOR Key 0x567562e6
Unmarked objects 0
221 (VS2013 build 21005) 3
ASM objects (VS2013 build 21005) 4
C objects (VS2013 build 21005) 20
C++ objects (VS2013 build 21005) 2
Imports (VS2008 SP1 build 30729) 2
Total imports 92
228 (VS2013 UPD4 build 31101) 13
Resource objects (VS2013 build 21005) 1
Linker (VS2013 UPD4 build 31101) 1

Errors

Leave a comment

No comments yet.