| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2014-Feb-11 11:19:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\Users\nailmu\Dev\Prj\Utils\rplc\vc2010\output\nhcolor.pdb
|
| Comments | Colored output for console |
| CompanyName | nhutils |
| FileDescription | nhcolor |
| FileVersion | 1, 0, 0, 0 |
| InternalName | nhcolor |
| LegalCopyright | Copyright © 2014 |
| OriginalFilename | nhcolor.exe |
| ProductName | nhutils nhcolor |
| ProductVersion | 1, 0, 0, 0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/68 (Scanned on 2026-09-09 04:00:10) | All the AVs think this file is safe. |
| MD5 | 4aa5852907b3898fb9e73bed1bfcae02 🔍 |
|---|---|
| SHA1 | f75a60fcf38120ab06e30c132b9ba302ebdcc712 🔍 |
| SHA256 | 99ca449f1904eca1817ba983b169e291825eb42201e8ebe1ee22250cb4b20d0d 🔍 |
| SHA3 | 1992f864e2abb6e76895f3016f130792a853c00896435484a58aa633198b8e01 🔍 |
| SSDeep | 3072:/jxULGKRYFdkDsm4EI+TkehOufW70NxOIes8Rz2zgftPfHn/vE1:/jxULtYMDE2Tkobe70NM9Ftfc1 🔍 |
| Imports Hash | a1fcfb935423a093fb3cf1888df9946e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2014-Feb-11 11:19:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x24e00 |
| SizeOfInitializedData | 0x13600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000B7DD (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x26000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x395ff |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 5ba9b88ce6e5a638af394f9207eb9c58 🔍 |
|---|---|
| SHA1 | 4820db8c8453d7ff1618a0fc81a183331ac81509 🔍 |
| SHA256 | bc776af4567e016fd124af1667e46eaf5afb82c671378fbe87a74902934340d7 🔍 |
| SHA3 | c94ae7c5ae1cbf32477b0704609b7ba894659275e29914f4f3af4753aa7f62e1 🔍 |
| VirtualSize | 0x24d82 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x24e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.57122 |
| MD5 | e1843bee940a5a67d8930275f72f60fd 🔍 |
|---|---|
| SHA1 | 43ccd6a68717cdee447f6a77275c6c1bf02d36d4 🔍 |
| SHA256 | b931e75ada109b3fbbd539e436534a2682f3ae16880d522e06199c15b5abac31 🔍 |
| SHA3 | 319e506abdf6d41f789354cf6b4e1115785d22fdc7f280bb0906aa1c23505c4b 🔍 |
| VirtualSize | 0x8b2e |
| VirtualAddress | 0x26000 |
| SizeOfRawData | 0x8c00 |
| PointerToRawData | 0x25200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.57191 |
| MD5 | af07afc496a1eaaf43c27d3cbfe981e8 🔍 |
|---|---|
| SHA1 | 8272379c9fc82a5900efe683917e9a3feb3bbec1 🔍 |
| SHA256 | f003ac6b6b62f7671cd2b09148636b78d9c01f55b6d3d2b8313e6f3a6d2beca3 🔍 |
| SHA3 | 338a6e0bdc7f5da31ae19310bcaaa42246fba48739ff080fd7ed20eca1716af4 🔍 |
| VirtualSize | 0x4ccc |
| VirtualAddress | 0x2f000 |
| SizeOfRawData | 0x1c00 |
| PointerToRawData | 0x2de00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.96346 |
| MD5 | 9df7f10f95444b743534e09de57c9658 🔍 |
|---|---|
| SHA1 | 4abd73ca064d20068a691cb0e019d8f6f25744eb 🔍 |
| SHA256 | bf616687345a95663444a50db01e7200dafc68f870bf43b088620d2cadfef7c4 🔍 |
| SHA3 | 035e01cf59006a84ca056aa1ccdbb286a9deb7ebee6cb4e86588735f9bcd0cb1 🔍 |
| VirtualSize | 0x674 |
| VirtualAddress | 0x34000 |
| SizeOfRawData | 0x800 |
| PointerToRawData | 0x2fa00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.7384 |
| MD5 | 935399a571b9d6353d1f26e82591047f 🔍 |
|---|---|
| SHA1 | 8c3976462830cc0a23104e03c38359101869b6c0 🔍 |
| SHA256 | 083bde72c8084a65fe4ccf99440e28a595efeb78e51c17868bad78f1d7f032d4 🔍 |
| SHA3 | 24bda8e9d8293031651a9db49ca7192a3b07ba2b3773e70c83a6443decb7003e 🔍 |
| VirtualSize | 0x856c |
| VirtualAddress | 0x35000 |
| SizeOfRawData | 0x8600 |
| PointerToRawData | 0x30200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 2.71664 |
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection LeaveCriticalSection lstrlenA HeapAlloc GetProcessHeap GetLastError HeapFree HeapReAlloc HeapSize lstrcpynA GetLocaleInfoA GetLocaleInfoW GetLocalTime FormatMessageW GetConsoleScreenBufferInfo GetStdHandle SetConsoleTextAttribute CloseHandle WriteFile SetFilePointer ReadFile FlushFileBuffers CreateFileW GetTickCount GetCurrentProcessId GetCommandLineW InitializeCriticalSection GetCPInfo RaiseException RtlUnwind LCMapStringW TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent IsProcessorFeaturePresent HeapCreate GetProcAddress GetModuleHandleW ExitProcess InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree SetLastError GetCurrentThreadId GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime GetConsoleCP GetConsoleMode GetACP GetOEMCP IsValidCodePage GetUserDefaultLCID EnumSystemLocalesA IsValidLocale LoadLibraryW WriteConsoleW SetStdHandle Sleep DecodePointer EncodePointer GetStringTypeW MultiByteToWideChar InterlockedExchange InterlockedCompareExchange InterlockedDecrement InterlockedIncrement HeapSetInformation WideCharToMultiByte |
|---|---|
| ODBC32.dll |
#15
#110 #2 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x368 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.30488 |
| MD5 | 3ae5b4653662d2afda6f98af16116d5e 🔍 |
| SHA1 | 1ed317c538703087be339367161cf2a7684ff4a4 🔍 |
| SHA256 | 15c2e781d72c24f726ad51ca1f9bb804c6e13ccfe6bca06a6ee4e353b53c48a6 🔍 |
| SHA3 | 1189fee93d06c1fa14ee9b1d9d0be15b61d880a527862955f2dcf1cc000dc675 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x26c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.01246 |
| MD5 | 7d471a416c480c691b70ebd2c1b966f8 🔍 |
| SHA1 | fe3c58a7469c95dc915b8c028fc016d27be8f300 🔍 |
| SHA256 | d9e9362080b827810db09aa7091f2a82a4b0b874018a131707f572454649484e 🔍 |
| SHA3 | 1bce59de66f97843559f9b4e808b330b1396514cfa695ae32b07434f756fc208 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | Colored output for console |
| CompanyName | nhutils |
| FileDescription | nhcolor |
| FileVersion (#2) | 1, 0, 0, 0 |
| InternalName | nhcolor |
| LegalCopyright | Copyright © 2014 |
| OriginalFilename | nhcolor.exe |
| ProductName | nhutils nhcolor |
| ProductVersion (#2) | 1, 0, 0, 0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2014-Feb-11 11:19:02 |
| Version | 0.0 |
| SizeofData | 85 |
| AddressOfRawData | 0x2a348 |
| PointerToRawData | 0x29548 |
| Referenced File | D:\Users\nailmu\Dev\Prj\Utils\rplc\vc2010\output\nhcolor.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x42f660 |
| SEHandlerTable | 0x42b110 |
| SEHandlerCount | 199 |
| XOR Key | 0x6bfbd6d8 |
|---|---|
| Unmarked objects | 0 |
| 152 (20115) | 1 |
| ASM objects (VS2010 build 30319) | 23 |
| C++ objects (VS2010 build 30319) | 128 |
| C objects (VS2010 build 30319) | 151 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 186 |
| 175 (VS2010 build 30319) | 1 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |
No comments yet.