99d4b1645dba8a73bb0530f0ebb8b1c7eacc6254affc19c8f9d65418fca586fa

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jun-08 09:22:03
Detected languages English - United States
TLS Callbacks 4 callback(s) detected.
CompanyName Leia, Inc.
FileDescription SR Service
FileVersion 57c9f88a7d v1.36.4.35453 2026-06-08T09:19:11Z
LegalCopyright Copyright © 2026 Leia, Inc.
ProductName SRService
ProductVersion 57c9f88a7d v1.36.4.35453 2026-06-08T09:19:11Z

Plugin Output

Suspicious PEiD Signature: PeStubOEP v1.x
Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VirtualPC presence:
  • 0f 3f 07 0b
Contains domain names:
  • https://www.wibu.com
  • www.wibu.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Microsoft's Cryptography API
Suspicious The PE is possibly packed. Unusual section name found: __wibu00
Unusual section name found: __wibu01
Unusual section name found: __wibu02
Unusual section name found: __wibu03
Unusual section name found: __wibu04
Unusual section name found: __wibu05
Unusual section name found: __wibu06
Unusual section name found: __wibu07
Unusual section name found: __wibu08
Unusual section name found: __wibu09
Unusual section name found: __wibu0a
Unusual section name found: __wibu0b
Unusual section name found: __wibu0c
Unusual section name found: __wibu0d
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
Uses Microsoft's cryptographic API:
  • CryptMsgClose
  • CryptMsgGetParam
  • CryptQueryObject
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32First
  • Process32Next
Info The PE is digitally signed. Signer: Leia
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 01fbbf814ca83064a1956fb824cc2c01 🔍
SHA1 98a5ac74b44950a7a40a3b04c6ed1c441521ebc3 🔍
SHA256 99d4b1645dba8a73bb0530f0ebb8b1c7eacc6254affc19c8f9d65418fca586fa 🔍
SHA3 8af1eae2bb522a9bc750f8f176bc2c755e6f4ed7c1e335d94e1c99cd8e83fb6b 🔍
SSDeep 196608:enFnlyO2KaY8JWifVpju9MkNHg84HBX6WImmMlOJdNE7aO0:endMOf1ifXju9DNA84HBX6AHl6EWR 🔍
Imports Hash 6e9a377734baab4aa7de3b0de93ada49 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x150

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 15
TimeDateStamp 2026-Jun-08 09:22:03
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xbb2800
SizeOfInitializedData 0x21f360
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000AD3C60 (Section: __wibu05)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xedf000
SizeOfHeaders 0x1000
Checksum 0xedeb0b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

__wibu00

MD5 4752cbefeedfa39e1137ba4ce9a27e00 🔍
SHA1 a420b906f1fa89f07a354adbeeeb1414bc321b9e 🔍
SHA256 80bc024de9795c10fbb664bb9becb270827d136b4095b47b9923f70c28248ec9 🔍
SHA3 6df873f8444a2de970442c9c675a8e3501247ec822df058774262a0a4200f507 🔍
VirtualSize 0xf0e00
VirtualAddress 0x1000
SizeOfRawData 0xf0e00
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.99981

__wibu01

MD5 522333a39bd2cd8b1e5dc5c4dc0ea88b 🔍
SHA1 e717b321ab2c9db94a3675d7f8969ba2c0994b24 🔍
SHA256 bb0703851113f173ca88f8c8eb17e430d3ba8e2dfb87d4df6a3fb3ce70579381 🔍
SHA3 f66853c16b653905a2d03faaf98da254e17b62f9931e856e84359f592845019e 🔍
VirtualSize 0x5b940
VirtualAddress 0xf2000
SizeOfRawData 0x5ba00
PointerToRawData 0xf1e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.96249

__wibu02

MD5 d9805bf5f77964be578331ae13fb5243 🔍
SHA1 087ff55043b9440546407bc1c29a31184ff50d60 🔍
SHA256 57f090789a27eb23fed5fd06b783d5af70daaa7a0807879fad2cd0cd0f429399 🔍
SHA3 c2fe71c94c1c4668bf2c946c9523e458986894cd67dbc031d271f814db0845dd 🔍
VirtualSize 0xe1d8
VirtualAddress 0x14e000
SizeOfRawData 0x8400
PointerToRawData 0x14d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99464

__wibu03

MD5 2e958394f77c3f3c065413b60a804632 🔍
SHA1 02cf104fec885eff3902c15df4bf78513935d780 🔍
SHA256 2861fde60dc60324033ec7c0ac93fa4fa2bf641971368aef1303f3ea0c613b79 🔍
SHA3 38af9b5d40e6b8d6844b58092299f8a36d1b6ee4750853b16c23e2aebd27442e 🔍
VirtualSize 0xb694
VirtualAddress 0x15d000
SizeOfRawData 0xb800
PointerToRawData 0x155c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.9887

.rsrc

MD5 7321a6533e002c9cf27a7b2ac32d82bb 🔍
SHA1 b670353c2635a01b33c4a6e27a1096127dec8f19 🔍
SHA256 ee607af049ace45279604594cce1882e5a0e67ed55102482845572653b14811a 🔍
SHA3 48068f24f9e8a9e16250bd3d5fa49f22c9745278b7ce06b4850fbdb4e1788464 🔍
VirtualSize 0x5ac30
VirtualAddress 0x169000
SizeOfRawData 0x5ae00
PointerToRawData 0x161400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.97508

__wibu04

MD5 68cfa6bc0732e83c2d3e2766466db7ed 🔍
SHA1 ad86bca5b0d03a3965843509c025af6372f14ab3 🔍
SHA256 c355eeef78f58b77e5ee520fba89aabaacdd3c9cc12d4c415eee6cf2c681259c 🔍
SHA3 4977b48cda026dd42068d5f2d301e62108980be14d4781afeac16883a61f55c7 🔍
VirtualSize 0x147c
VirtualAddress 0x1c4000
SizeOfRawData 0x1600
PointerToRawData 0x1bc200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 7.76111

__wibu05

MD5 c68b9940b7b467ad7125c0610af1bbdf 🔍
SHA1 347ee008caa327f6be979c34b2e27c585fa125be 🔍
SHA256 c9ea321702a22b12bfd5347a7aa4cdb666714eacebaccb252713ec32d4382e48 🔍
SHA3 527ad5cfcda9c8883d1ee009bf9be82f79946503b096398d379a09c8474757e1 🔍
VirtualSize 0x972000
VirtualAddress 0x1c6000
SizeOfRawData 0x971e00
PointerToRawData 0x1bd800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54277

__wibu06

MD5 49e071b3f8af6547bb5214157cccf37f 🔍
SHA1 035961b362e59a37ac205ac6368435414612c1fd 🔍
SHA256 d54f416f57934b9bd0a7f9a84122d91223dd2416c6b9df2eb8ca065724d86d63 🔍
SHA3 0939338823a4de66f3b6cb253e45a50f9034a2ac85db8243c0df3a398ef0f3e3 🔍
VirtualSize 0x105000
VirtualAddress 0xb38000
SizeOfRawData 0x104200
PointerToRawData 0xb2f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.33289

__wibu07

MD5 c590838b98cd31deb4a9ffbf9fc7b1ee 🔍
SHA1 fef66626d11120d9c5d48bd1b0ae5b31ca19a9f0 🔍
SHA256 a8fced9aeb3cae7b6ab57d27891aa92dd22d1beb2545e4456e4566142b13d045 🔍
SHA3 74149a9e48074f48d97572e19d2cb42d92251f15e52fc7ff3291142530e188b9 🔍
VirtualSize 0x59000
VirtualAddress 0xc3d000
SizeOfRawData 0x58200
PointerToRawData 0xc33800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.46301

__wibu08

MD5 d291ee99636321357ef5a60ac7225bc0 🔍
SHA1 8fbbe2cb9dc35f4678903ae6a2ef83348bff9831 🔍
SHA256 f091ef4a6bdd9e14f028aa95c5d191bf80c4e741725b4b2f9344fddecb8624f6 🔍
SHA3 0dc9340ff765e261a71c9adfd12a40a4adee24c76f671b92f8a001b86f9b4ba7 🔍
VirtualSize 0x2000
VirtualAddress 0xc96000
SizeOfRawData 0x1a00
PointerToRawData 0xc8ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.46774

__wibu09

MD5 f2a354cfe79889c173b8aedf52780242 🔍
SHA1 65a8fcb3b26230630eb82514d0c5302cd1b65e20 🔍
SHA256 e07d89509c987a86a35b2643878d63728a2e3e5d671600cffdbffe8e167fbccd 🔍
SHA3 c4c442aa0dae517e98b619e4d89294af56f8e3d60a54ff3addfef5432834ef73 🔍
VirtualSize 0x150000
VirtualAddress 0xc98000
SizeOfRawData 0x14fc00
PointerToRawData 0xc8d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_READ
Entropy 5.81896

__wibu0a

MD5 21e923bf1299bd480712b58f435eedea 🔍
SHA1 9eb6821fc21f804e53ef5779d315b3504d09f335 🔍
SHA256 88815a9b00ef1f32db56027dd4b772023a4fca65d874f4c01bafab07869db6a2 🔍
SHA3 b141f65917459f2b2d7e44bc6a38a8f94c4c7ccad8eacaa3b5ffbaf308681d52 🔍
VirtualSize 0x1000
VirtualAddress 0xde8000
SizeOfRawData 0x200
PointerToRawData 0xddd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0203931

__wibu0b

MD5 32c3f0c12cd3aa2c84e5a9847fe99b34 🔍
SHA1 66e143bfb35eb842d361c04933c50912cc20bbaa 🔍
SHA256 6b6ba555ef1e8ffcfe51f96f0e90a9abcd25712aa5656f7604b5bf4d39751f65 🔍
SHA3 9fd21616ef09e3c150c986cc5ad3eabc1ed5a5f4f887f9478885e843bcbae484 🔍
VirtualSize 0x1000
VirtualAddress 0xde9000
SizeOfRawData 0x200
PointerToRawData 0xddd200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 1.05012

__wibu0c

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x1000
VirtualAddress 0xdea000
SizeOfRawData 0x200
PointerToRawData 0xddd400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

__wibu0d

MD5 cf5cd9dc6caabd2b429796d3ba16a30b 🔍
SHA1 76405cc653e4824fcd3ab3629fa2c2c296f22c0b 🔍
SHA256 562091f4e3fbe6053f5503e4532b581802e4d7f5aafc05442b6353fbe71938c8 🔍
SHA3 53fb8b9a97922e3d82085bf0b89d4403e8a36e643fe584378d08f3c6914365d8 🔍
VirtualSize 0xf4000
VirtualAddress 0xdeb000
SizeOfRawData 0xf3c00
PointerToRawData 0xddd600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.09349

Imports

KERNEL32.dll AcquireSRWLockExclusive
AreFileApisANSI
CloseHandle
CompareStringEx
CompareStringW
CreateEventW
CreateFileW
CreateThread
CreateToolhelp32Snapshot
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
ExitThread
FileTimeToSystemTime
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FormatMessageA
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleCP
GetConsoleMode
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentThreadId
GetDateFormatW
GetDriveTypeW
GetEnvironmentStringsW
GetExitCodeThread
GetFileInformationByHandle
GetFileSizeEx
GetFileType
GetFullPathNameW
GetLastError
GetLocaleInfoEx
GetLocaleInfoW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
InitializeConditionVariable
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeSListHead
InitializeSRWLock
InterlockedFlushSList
InterlockedPushEntrySList
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
K32EnumProcessModules
LCMapStringEx
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LocalFree
MultiByteToWideChar
PeekNamedPipe
Process32First
Process32Next
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadConsoleW
ReadFile
ReleaseSRWLockExclusive
ResetEvent
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFileInformationByHandle
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
Sleep
SleepConditionVariableCS
SleepConditionVariableSRW
SwitchToThread
SystemTimeToTzSpecificLocalTime
TerminateProcess
Thread32First
Thread32Next
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryEnterCriticalSection
UnhandledExceptionFilter
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
USER32.dll CharUpperBuffA
wsprintfA
PSAPI.DLL GetModuleFileNameExA
POWRPROF.dll PowerReadFriendlyName
ADVAPI32.dll ConvertSidToStringSidA
ConvertStringSecurityDescriptorToSecurityDescriptorA
ntdll.dll RtlAddVectoredExceptionHandler
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlRemoveVectoredExceptionHandler
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
VERSION.dll GetFileVersionInfoA
GetFileVersionInfoSizeA
VerQueryValueA
WS2_32.dll WSACleanup
WSAStartup
__WSAFDIsSet
bind
closesocket
connect
gethostbyaddr
gethostbyname
gethostname
getpeername
htons
inet_addr
inet_ntoa
recv
recvfrom
select
send
sendto
setsockopt
socket
SHELL32.dll SHGetSpecialFolderLocation
ole32.dll CoTaskMemFree
CRYPT32.dll CertCloseStore
CertFindCertificateInStore
CertFreeCertificateContext
CertGetNameStringA
CertGetNameStringW
CryptMsgClose
CryptMsgGetParam
CryptQueryObject
IPHLPAPI.DLL GetIpAddrTable
WINTRUST.dll WinVerifyTrust

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.52735
MD5 adadb72f403c8ba4e5204fb6e2de5c7c 🔍
SHA1 c02593a1880a8fb5f35d2e2d1dddbb80ed4b350b 🔍
SHA256 35bf7ebbbaf44df8ec46692514dddd273856fa11a1c1d719670aa4a6fe6aa78a 🔍
SHA3 bf8a75df07630b17ee4f6f6748fc630e084ebe68d616cdfd470b4691ee9fda75 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2938
MD5 7d65f231a86a59c65771a0e2cb38311f 🔍
SHA1 00154e84473cf32fd0f4a52bd722ab822e28732e 🔍
SHA256 c3f54746fab48f7dcf85b94672046012c083873e17766100e0a503bccf793605 🔍
SHA3 0cb8d21d045efd821e20dfced6aef187fe26622aeb31339eea1c854e450b3237 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.18237
MD5 113a19dceefcc661817c89dd62985487 🔍
SHA1 bb31fc91f57036e253f88bf723e1b8e1e73778a9 🔍
SHA256 e4f4605b1d85b0966c95af8c8ea6950c9d94d6ef24b7129815c1de35615452ce 🔍
SHA3 7f22f3efeba8e45f59e822207731cf19a5aaba38b4264fc62c09c8c4ad23ab96 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02061
MD5 cbe27133be2154696ae5c26038aef1a9 🔍
SHA1 189590d84faf6ad257960190e60c2bc87b01fa58 🔍
SHA256 bfe949930a6c5f23db824e42743432d3c26bbab56f6dccb146eebd58116e530d 🔍
SHA3 c0ca52850ce51934c2ef8dd536b07a59ae2cdf54260e6e06c4a94497a34d76a8 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.88769
MD5 aeaefaaaaca33f02dfde92caac0bc913 🔍
SHA1 4e137ec3125f0354327173607f49b4ca33abe2fe 🔍
SHA256 af8a060b6a929910a7225d473cee591f0c371456e69603b089365bbb81f5edfe 🔍
SHA3 d5c691adca0b812f4f5cfbc8a1a57b09f4092df375e54704561496f1fb59e7f6 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92992
MD5 aa1502dc59478d1f333f1c5746d0965a 🔍
SHA1 0a6942eaef07bad2003dfd34e4de36cac644b4a1 🔍
SHA256 19f90e4869894bb676d1834ef39521ae92832e111026e4193ff68c70e4c26a82 🔍
SHA3 a0e7967e366ffd1ef62b3a8e1827e694a33849785cb7d5bceab89c4850e93cc6 🔍

IDI_ICON1

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76511
Detected Filetype Icon file
MD5 61e58469fe660c213ebc6e2cc66cbafc 🔍
SHA1 c47479da87d8390f935b337e91bdbedcc739b3eb 🔍
SHA256 c369bebe3271775e43301281caa7efcd03938e3bc1f620212d6c5617edaad403 🔍
SHA3 7c04647ad931cbf1b5c005cebc686d11b461a50e14ba9aa560e6cc1749adcb2f 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.56694
MD5 a3fae2961ee49be57568c200341b34ee 🔍
SHA1 2fb8dad20482c31d3b1ff347dd037dc8e2e5c1de 🔍
SHA256 2e7a16be5b5c40b69c24c8b46754f1235a088e3d2774567289a0fb7a0de66e9c 🔍
SHA3 624a1f6d9b48f6a6b18bf5582839b096197ea8cbcdf9ddc33881a071a5b6a362 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.36.4.35453
ProductVersion 1.36.4.35453
FileFlags (EMPTY)
FileOs (EMPTY)
FileType VFT_UNKNOWN
Language English - United States
CompanyName Leia, Inc.
FileDescription SR Service
FileVersion (#2) 57c9f88a7d v1.36.4.35453 2026-06-08T09:19:11Z
LegalCopyright Copyright © 2026 Leia, Inc.
ProductName SRService
ProductVersion (#2) 57c9f88a7d v1.36.4.35453 2026-06-08T09:19:11Z
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x140e7e690
EndAddressOfRawData 0x140e7e880
AddressOfIndex 0x140b39668
AddressOfCallbacks 0x140c981b0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_64BYTES
Callbacks 0x00000001403820D0
0x0000000140ADBA80
0x00000001407DE6C0
0x0000000140B24480

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14014e258
GuardCFCheckFunctionPointer 5369705024
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xcca67a3
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
C objects (VS2015 UPD3.1 build 24215) 70
C++ objects (VS2015 UPD3.1 build 24215) 127
Imports (VS 2015/2017/2019 runtime 29913) 2
C objects (VS 2015/2017 runtime 26706) 10
ASM objects (VS 2015/2017 runtime 26706) 3
C++ objects (VS 2015/2017 runtime 26706) 36
Imports (VS 2015/2017 runtime 26706) 4
C objects (33145) 1
ASM objects (27045) 1
C++ objects (27045) 43
C objects (27045) 32
Imports (VS2017 v15.9.5-6 compiler 27026) 2
Imports (33145) 30
Imports (27045) 2
Imports (27054) 13
Total imports 681
C++ objects (27054) 49
Exports (27054) 1
Resource objects (27054) 1
151 1
Linker (27054) 1

Errors

[!] Error: Could not read PDB file information of invalid magic number. [*] Warning: 17 invalid export(s) not shown.
Leave a comment

No comments yet.