bd639bc838e0aa9f17d822798f559eec646a7025015ff537d27a369db6858661

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Mar-20 21:32:59
Detected languages English - United States
Debug artifacts C:\Users\admin\Desktop\vcpkg\vcpkg\buildtrees\zlib\x64-windows-rel\zlib.pdb
FileDescription zlib data compression library
FileVersion 1.3.1
InternalName zlib1.dll
LegalCopyright (C) 1995-2022 Jean-loup Gailly & Mark Adler
OriginalFilename zlib1.dll
ProductName zlib
ProductVersion 1.3.1
Comments For more information visit http://www.zlib.net/

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://www.zlib.net
  • http://www.zlib.net/
  • www.zlib.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Safe VirusTotal score: 0/71 (Scanned on 2026-08-10 14:24:31) All the AVs think this file is safe.

Hashes

MD5 543aa24c9a56e4027e0a3e33f5b8d968 🔍
SHA1 4d7fa01535e0b6792ddb470308f7d5c0745b8cb0 🔍
SHA256 bd639bc838e0aa9f17d822798f559eec646a7025015ff537d27a369db6858661 🔍
SHA3 d319fa8ea6e3eb681fb1287b6502d29e51eacb83229063330784213866186744 🔍
SSDeep 1536:eFQ5SVDXNVLIXUcZEpmrfJ7wl8lj6IOcIOZiA2clI/:2kSZ9Jf8Ep27w6ISZiA2c2 🔍
Imports Hash d879d2294039900ef484e0f01607f882 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Mar-20 21:32:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.3
SizeOfCode 0xda00
SizeOfInitializedData 0x8a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000000DDF0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 1.3
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1a000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 02146c00f9b0d4f2d7712a0c8616df4b 🔍
SHA1 f6d4f1eca981d4279692295c09328ff5754dee23 🔍
SHA256 76a2f9f64a666b7006eca2a1e2df6fceb05dab604756205b136e12bc325747d5 🔍
SHA3 09a5cd664419b924b2acb4b410991ae7295278aa61e6278ee0519a8348b4008f 🔍
VirtualSize 0xd838
VirtualAddress 0x1000
SizeOfRawData 0xda00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37767

.rdata

MD5 d129d4109348bdc3345429846c3d95f7 🔍
SHA1 1f9e4b5a5e4aa9100225a67e023fbada55e15a1d 🔍
SHA256 80a83a3910ae070f94a8d1c6ec2751c31c6762801a44d6a780c6d9d756c4e179 🔍
SHA3 6c37ba8569c239bbe2c6ed1c5efe9f761a3135f061be32b08dc15ab17a1e3097 🔍
VirtualSize 0x6cf0
VirtualAddress 0xf000
SizeOfRawData 0x6e00
PointerToRawData 0xde00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.48772

.data

MD5 48a354b3236c6ccad2f66a93edebce32 🔍
SHA1 aa1c261cdca769a5f5e471dceddbe89b020e1396 🔍
SHA256 bb3b36cfed04653810abd799b29aaeff6045ab2995b21b6e0d3dd5388423b783 🔍
SHA3 da796986eaa89f07acb16b86ad0f66b12449049495d9906973bf55c08f578939 🔍
VirtualSize 0x680
VirtualAddress 0x16000
SizeOfRawData 0x200
PointerToRawData 0x14c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.517653

.pdata

MD5 6986d52de0d1a9d859d32bbd99d18414 🔍
SHA1 5ca3d2b1ba3df2a643d639144273378d5868a9c7 🔍
SHA256 7c9310a5300688066ae344e449f934bcca82cf6974760d3d598d16cbbe2c4bd5 🔍
SHA3 30ae38e34fb6b8b7baebb3b73ec234d89979c59d44af7402e58b5f79631ac9b6 🔍
VirtualSize 0xb40
VirtualAddress 0x17000
SizeOfRawData 0xc00
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.69242

.rsrc

MD5 caad595b3519a43a2dcf6a52c482cbf1 🔍
SHA1 626362c808713d55b28f4fa0466c63e52c8c0bc1 🔍
SHA256 1208ca200ce6b3b3c4ddf100d0740d9af8f4c7c6688fab669c7ee4d8d808ef9e 🔍
SHA3 612946170fb5aae85ca2a45c203aac209134b99ab7ac68f2718db88ecd1d6a96 🔍
VirtualSize 0x550
VirtualAddress 0x18000
SizeOfRawData 0x600
PointerToRawData 0x15a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.83827

.reloc

MD5 f958f0a05b1f5aac7176466510e618a8 🔍
SHA1 a2ce74b19118f095c497ad38d224f0ae75b326ae 🔍
SHA256 94187298cb0302c74316922f490e0b866e27cbe9cf998cf46502bb73a28e7820 🔍
SHA3 c8775718b634786345f58c2d7e46b98c1cec4827537647b72dbb584a092788bc 🔍
VirtualSize 0x6c
VirtualAddress 0x19000
SizeOfRawData 0x200
PointerToRawData 0x16000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.51459

Imports

VCRUNTIME140.dll __std_type_info_destroy_list
__C_specific_handler
memmove
memchr
memset
memcpy
api-ms-win-crt-stdio-l1-1-0.dll _wopen
_write
_read
_close
__stdio_common_vsprintf
_open
_lseeki64
api-ms-win-crt-heap-l1-1-0.dll malloc
free
api-ms-win-crt-convert-l1-1-0.dll wcstombs
api-ms-win-crt-runtime-l1-1-0.dll _errno
strerror
_execute_onexit_table
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_seh_filter_dll
_initterm_e
_initterm
_cexit
KERNEL32.dll DisableThreadLibraryCalls
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
InitializeSListHead
RtlCaptureContext
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter

Delayed Imports

adler32

Ordinal 1
Address 0x1000

adler32_combine

Ordinal 2
Address 0x1010

adler32_z

Ordinal 3
Address 0x1100

compress

Ordinal 4
Address 0x13e0

compress2

Ordinal 5
Address 0x1400

compressBound

Ordinal 6
Address 0x1500

crc32

Ordinal 7
Address 0x1520

crc32_combine

Ordinal 8
Address 0x1530

crc32_combine_gen

Ordinal 9
Address 0x15a0

crc32_combine_op

Ordinal 10
Address 0x15b0

crc32_z

Ordinal 11
Address 0x15f0

deflate

Ordinal 12
Address 0x2a20

deflateBound

Ordinal 13
Address 0x3490

deflateCopy

Ordinal 14
Address 0x3650

deflateEnd

Ordinal 15
Address 0x38a0

deflateGetDictionary

Ordinal 16
Address 0x39e0

deflateInit2_

Ordinal 17
Address 0x3ab0

deflateInit_

Ordinal 18
Address 0x3d50

deflateParams

Ordinal 19
Address 0x3d90

deflatePending

Ordinal 20
Address 0x3f60

deflatePrime

Ordinal 21
Address 0x3fe0

deflateReset

Ordinal 22
Address 0x4110

deflateResetKeep

Ordinal 23
Address 0x41e0

deflateSetDictionary

Ordinal 24
Address 0x42e0

deflateSetHeader

Ordinal 25
Address 0x4530

deflateTune

Ordinal 26
Address 0x45a0

get_crc_table

Ordinal 27
Address 0x1aa0

gzbuffer

Ordinal 28
Address 0x5740

gzclearerr

Ordinal 29
Address 0x5780

gzclose

Ordinal 30
Address 0x5230

gzclose_r

Ordinal 31
Address 0x64f0

gzclose_w

Ordinal 32
Address 0x7080

gzdirect

Ordinal 33
Address 0x65a0

gzdopen

Ordinal 34
Address 0x57e0

gzeof

Ordinal 35
Address 0x5870

gzerror

Ordinal 36
Address 0x5890

gzflush

Ordinal 37
Address 0x7150

gzfread

Ordinal 38
Address 0x65e0

gzfwrite

Ordinal 39
Address 0x71c0

gzgetc

Ordinal 40
Address 0x6660

gzgetc_

Ordinal 41
Address 0x66e0

gzgets

Ordinal 42
Address 0x6750

gzoffset

Ordinal 43
Address 0x58e0

gzoffset64

Ordinal 44
Address 0x5950

gzopen

Ordinal 45
Address 0x59b0

gzopen64

Ordinal 46
Address 0x59b0

gzopen_w

Ordinal 47
Address 0x59c0

gzprintf

Ordinal 48
Address 0x7240

gzputc

Ordinal 49
Address 0x7270

gzputs

Ordinal 50
Address 0x7340

gzread

Ordinal 51
Address 0x6880

gzrewind

Ordinal 52
Address 0x59d0

gzseek

Ordinal 53
Address 0x5a30

gzseek64

Ordinal 54
Address 0x5a60

gzsetparams

Ordinal 55
Address 0x73d0

gztell

Ordinal 56
Address 0x5c30

gztell64

Ordinal 57
Address 0x5c90

gzungetc

Ordinal 58
Address 0x68f0

gzvprintf

Ordinal 59
Address 0x74e0

gzwrite

Ordinal 60
Address 0x7670

inflate

Ordinal 61
Address 0x76c0

inflateBack

Ordinal 62
Address 0x9d10

inflateBackEnd

Ordinal 63
Address 0xace0

inflateBackInit_

Ordinal 64
Address 0xad30

inflateCodesUsed

Ordinal 65
Address 0x8f60

inflateCopy

Ordinal 66
Address 0x8fb0

inflateEnd

Ordinal 67
Address 0x91b0

inflateGetDictionary

Ordinal 68
Address 0x9230

inflateGetHeader

Ordinal 69
Address 0x92e0

inflateInit2_

Ordinal 70
Address 0x9330

inflateInit_

Ordinal 71
Address 0x9430

inflateMark

Ordinal 72
Address 0x9440

inflatePrime

Ordinal 73
Address 0x94c0

inflateReset

Ordinal 74
Address 0x9540

inflateReset2

Ordinal 75
Address 0x9650

inflateResetKeep

Ordinal 76
Address 0x9720

inflateSetDictionary

Ordinal 77
Address 0x97e0

inflateSync

Ordinal 78
Address 0x98d0

inflateSyncPoint

Ordinal 79
Address 0x9a90

inflateUndermine

Ordinal 80
Address 0x9ae0

inflateValidate

Ordinal 81
Address 0x9b30

uncompress

Ordinal 82
Address 0xd5a0

uncompress2

Ordinal 83
Address 0xd5c0

zError

Ordinal 84
Address 0xd720

zlibCompileFlags

Ordinal 85
Address 0xd770

zlibVersion

Ordinal 86
Address 0xd780

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x32c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47687
MD5 058c57a3a049103a08753978c77952e4 🔍
SHA1 6056b352103f04de622cd963aee1c9c8cbdbdac5 🔍
SHA256 bb25c0ac214a9e7aac891ca54327ef3ada383e4f7b1b40c9e7ae955f3d23de1e 🔍
SHA3 18d551ad80f8c8c989ca717b15a9acb7285fc0fca152e8bb10eca08bc2580193 🔍

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.3.1.0
ProductVersion 1.3.1.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
FileDescription zlib data compression library
FileVersion (#2) 1.3.1
InternalName zlib1.dll
LegalCopyright (C) 1995-2022 Jean-loup Gailly & Mark Adler
OriginalFilename zlib1.dll
ProductName zlib
ProductVersion (#2) 1.3.1
Comments For more information visit http://www.zlib.net/
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Mar-20 21:32:59
Version 0.0
SizeofData 100
AddressOfRawData 0x13f70
PointerToRawData 0x12d70
Referenced File C:\Users\admin\Desktop\vcpkg\vcpkg\buildtrees\zlib\x64-windows-rel\zlib.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Mar-20 21:32:59
Version 0.0
SizeofData 20
AddressOfRawData 0x13fd4
PointerToRawData 0x12dd4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Mar-20 21:32:59
Version 0.0
SizeofData 600
AddressOfRawData 0x13fe8
PointerToRawData 0x12de8

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x180016000

RICH Header

XOR Key 0xe7e45676
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 8
Imports (34321) 3
253 (34321) 4
ASM objects (34321) 3
C objects (34321) 8
C++ objects (34321) 12
Imports (33140) 2
Total imports 49
C objects (34808) 15
Exports (34808) 1
Resource objects (34808) 1
151 1
Linker (34808) 1

Errors

Leave a comment

No comments yet.