×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2025-Feb-21 10:21:17
Debug artifacts
D:\Document\Pro Work\Old Application\getkrkinfo OL\krk\SaveKrk\obj\x86\Debug\SaveKrk.pdb
Comments
CompanyName
FileDescription
SaveKrk
FileVersion
1.0.0.0
InternalName
SaveKrk.exe
LegalCopyright
Copyright © 2013
LegalTrademarks
OriginalFilename
SaveKrk.exe
ProductName
SaveKrk
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious
No VirusTotal score.
This file has never been scanned on VirusTotal.
MD5
021ac76898c7de9e652e5ff07c03e941
SHA1
5359c81320a39187779678ec34c86c7d8e2f6f40
SHA256
cfab54dd4900b95d88feb98974924656c9879e982c48412afa6a20078b7e5a75
SHA3
096893b4121cc18ebd4781b6e7827d00f18c6eb08c5ab0af486c434f91d7f2ae
SSDeep
768:yheaqtyy1Xc2j3MEeH1URsHPmHKm28yMby6UMJxOesDi1irUkOrJtkggl0ae7TW:o8RfsvmHKm2DIy6RCQkQtkgglodQ/Qv
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
3
TimeDateStamp
2025-Feb-21 10:21:17
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Magic
PE32
LinkerVersion
80.0
SizeOfCode
0xe000
SizeOfInitializedData
0x800
SizeOfUninitializedData
0
AddressOfEntryPoint
0x0000FE7E (Section: .text)
BaseOfCode
0x2000
BaseOfData
0x10000
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
6.0
Win32VersionValue
0
SizeOfImage
0x14000
SizeOfHeaders
0x200
Checksum
0
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
464d3846f0e96d7f607c5789095c2288
SHA1
5d3b2700eb6324260d1b70457481c9e64dcbacc4
SHA256
6a275e953901f23ebc7c6d1f20fdf82a620511dcc50d67c6730bd5b140089950
SHA3
da203ab2af31c42632892170eb9e5f42ba736e9c1bfa60ae616c7fdc0f48ae52
VirtualSize
0xde84
VirtualAddress
0x2000
SizeOfRawData
0xe000
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
5.37328
MD5
f819c56d54b7393c3dac781068ba4762
SHA1
d944db4efe19bde44a7540b1ff81b7fa3e7f48c7
SHA256
28c4d4cb58fb0ce8a841cdba933a84bf960c1824d0fa74b323089087eeb0ebac
SHA3
9b5365af7cab7a40820b0cdb70a1922ac9e0dc0da4567d0a443588a1926b14af
VirtualSize
0x59c
VirtualAddress
0x10000
SizeOfRawData
0x600
PointerToRawData
0xe200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy
4.05194
MD5
d0253403a087eb7f28dad773081f770e
SHA1
e13f50927365dc5929d9741bc730c82fd562d5f5
SHA256
326c0e4441cf9c5b624058baf94ea10c9a040f8b2e0397803b0aafe43af3a4b1
SHA3
370d72f29e84dd174a0c6a87a275ffcd8e76667aeb4990f6f54f83b7b61b568e
VirtualSize
0xc
VirtualAddress
0x12000
SizeOfRawData
0x200
PointerToRawData
0xe800
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.0815394
Type
RT_VERSION
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x30c
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
3.26993
MD5
c480c4d5b70651421aabc24144fab8e7
SHA1
d46ea37f2b503877f56c73efaa2800dbdb495fa2
SHA256
f1781efaca00f0d411f2298ab7bca7b8daac6b289d1cfe050cc8a65a88e9e624
SHA3
f3c574055ec9bc52c32f655439f50607bdd6b6636fdd83889ecf30011f966c42
Type
RT_MANIFEST
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x1ea
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
5.00112
MD5
b7db84991f23a680df8e95af8946f9c9
SHA1
cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256
539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3
4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff
Signature
0xfeef04bd
StructVersion
0x10000
FileVersion
1.0.0.0
ProductVersion
1.0.0.0
FileFlags
(EMPTY)
FileOs
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType
VFT_APP
Language
UNKNOWN
Comments
CompanyName
FileDescription
SaveKrk
FileVersion (#2)
1.0.0.0
InternalName
SaveKrk.exe
LegalCopyright
Copyright © 2013
LegalTrademarks
OriginalFilename
SaveKrk.exe
ProductName
SaveKrk
ProductVersion (#2)
1.0.0.0
Assembly Version
1.0.0.0
Characteristics
0
TimeDateStamp
2025-Feb-21 10:21:17
Version
0.0
SizeofData
284
AddressOfRawData
0xfd10
PointerToRawData
0xdf10
Referenced File
D:\Document\Pro Work\Old Application\getkrkinfo OL\krk\SaveKrk\obj\x86\Debug\SaveKrk.pdb