9ef8241377343a46053354c93e7dfc97a39f8e14a6789024061777dca746e779

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-07 17:04:43
TLS Callbacks 1 callback(s) detected.
Debug artifacts PE_Example.pdb

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 b1e061d5f1060aa0c008affe41a8263a 🔍
SHA1 a659176fcb093c59743a58e1b9374b79e449e7cb 🔍
SHA256 9ef8241377343a46053354c93e7dfc97a39f8e14a6789024061777dca746e779 🔍
SHA3 5949997ce12a7549ed7660cb0152fd73d56932e7d37fc0ac015f09d30334be91 🔍
SSDeep 3072:lkwcnXk/RvrYlbe18oV311HtJ525kZcOG:lQXGvcNeWi/tP2OV 🔍
Imports Hash 2d0fbf441de293a1a5ccdd5421961a3c 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 5
TimeDateStamp 2026-Aug-07 17:04:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1de00
SizeOfInitializedData 0xd800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000001CF30 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 79c9970079857c923934f4d2bd4973ff 🔍
SHA1 49d0831ab72f3545edd2db4c3ce8f16f371ad18a 🔍
SHA256 36fc1fe80512a754e133f2d49419e283785185217679b8bd8b7dd563750ca1a9 🔍
SHA3 cbac9a82ccab1a1738a2988fb43d952f4ad48d45668758994084fcf4f6b70974 🔍
VirtualSize 0x1dd26
VirtualAddress 0x1000
SizeOfRawData 0x1de00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32405

.rdata

MD5 8fc9dff691898fa7cd134af5e3c5b4d8 🔍
SHA1 6812c3997d5bfde9af20c52ce83602ae61447927 🔍
SHA256 d8b814d6177586c836e75dae98d99996c3062a958e531791462739514f61dc2e 🔍
SHA3 12e26ea72c8e18e0f813187bb14223cff17a4f3e84a7de66f8ef7c01773ed4f9 🔍
VirtualSize 0xb7c6
VirtualAddress 0x1f000
SizeOfRawData 0xb800
PointerToRawData 0x1e200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.38843

.data

MD5 33a3046382c8a4c04ac73a78e91192c2 🔍
SHA1 ebb0f0391e42b00e7147bb0172b8b62eaaffc86c 🔍
SHA256 fbfee7e308e1b0ad64f02893274f9526fc589b067f153893725341f4d8941ab2 🔍
SHA3 f86c1637c2e4a6bb973cc102f278e22957caaeb943d71cb14ae0bbdb189e54c4 🔍
VirtualSize 0x2d0
VirtualAddress 0x2b000
SizeOfRawData 0x200
PointerToRawData 0x29a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.59134

.pdata

MD5 fd59aaee8b4e54be0e6a6428d307c8be 🔍
SHA1 944a6c080d0bebf1c2939fa9fd9ea369128f631e 🔍
SHA256 9a299735f431f4531bbee3fe869fbda7f4ff7067eeda17ef0742594387b2d3c9 🔍
SHA3 83b27aaccf4fd6a8c5c7cbc7caeec980a2ae06a133779593c66a83706cfe0004 🔍
VirtualSize 0x16ec
VirtualAddress 0x2c000
SizeOfRawData 0x1800
PointerToRawData 0x29c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.12105

.reloc

MD5 e559b3793a541ec2ab48f28c68f12148 🔍
SHA1 becefbaef9e641a70e6056d84888f04997aa125b 🔍
SHA256 a77853f9c8ef41da68fc979372a1da62db63ff08cc92a0ce6f12d0794da8b6e4 🔍
SHA3 1af78b17f19366b646c74d1c65dabd0091e6375f9eace140a2809b9aa6658a59 🔍
VirtualSize 0x3a4
VirtualAddress 0x2e000
SizeOfRawData 0x400
PointerToRawData 0x2b400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.19104

Imports

api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WaitOnAddress
WakeByAddressSingle
KERNEL32.dll GetModuleHandleW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
InitializeSListHead
GetLastError
CloseHandle
WaitForSingleObject
SetLastError
GetCurrentThreadId
GetProcessHeap
HeapFree
HeapReAlloc
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentProcess
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
GetStdHandle
AddVectoredExceptionHandler
SetThreadStackGuarantee
GetCurrentThread
GetCurrentDirectoryW
GetEnvironmentVariableW
GetCommandLineW
lstrlenW
GetProcAddress
WideCharToMultiByte
WaitForSingleObjectEx
LoadLibraryA
CreateMutexA
ReleaseMutex
HeapAlloc
GetModuleFileNameW
MultiByteToWideChar
WriteConsoleW
GetConsoleMode
GetConsoleOutputCP
IsProcessorFeaturePresent
FormatMessageW
GetModuleHandleA
GetSystemTimeAsFileTime
ntdll.dll NtWriteFile
RtlNtStatusToDosError
VCRUNTIME140.dll memcmp
__current_exception_context
memmove
_CxxThrowException
__C_specific_handler
__current_exception
memcpy
memset
__CxxFrameHandler3
api-ms-win-crt-runtime-l1-1-0.dll _initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_configure_narrow_argv
exit
_exit
_set_app_type
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
terminate
_seh_filter_exe
_initterm_e
_initialize_onexit_table
_register_onexit_function
_crt_atexit
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode

Delayed Imports

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-07 17:04:43
Version 0.0
SizeofData 39
AddressOfRawData 0x260fc
PointerToRawData 0x252fc
Referenced File PE_Example.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-07 17:04:43
Version 0.0
SizeofData 20
AddressOfRawData 0x26124
PointerToRawData 0x25324

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-07 17:04:43
Version 0.0
SizeofData 816
AddressOfRawData 0x26138
PointerToRawData 0x25338

TLS Callbacks

StartAddressOfRawData 0x140026488
EndAddressOfRawData 0x1400264e0
AddressOfIndex 0x14002b244
AddressOfCallbacks 0x14001f348
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014000E5F0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14002b100

RICH Header

XOR Key 0x9d8dcc9e
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 12
Imports (35207) 2
ASM objects (35207) 3
C objects (35207) 9
C++ objects (35207) 23
Imports (33145) 9
Total imports 181
Unmarked objects (#2) 51
Linker (35228) 1

Errors

Leave a comment

No comments yet.