cfab54dd4900b95d88feb98974924656c9879e982c48412afa6a20078b7e5a75

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Feb-21 10:21:17
Debug artifacts D:\Document\Pro Work\Old Application\getkrkinfo OL\krk\SaveKrk\obj\x86\Debug\SaveKrk.pdb
Comments
CompanyName
FileDescription SaveKrk
FileVersion 1.0.0.0
InternalName SaveKrk.exe
LegalCopyright Copyright © 2013
LegalTrademarks
OriginalFilename SaveKrk.exe
ProductName SaveKrk
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET executable -> Microsoft
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 021ac76898c7de9e652e5ff07c03e941
SHA1 5359c81320a39187779678ec34c86c7d8e2f6f40
SHA256 cfab54dd4900b95d88feb98974924656c9879e982c48412afa6a20078b7e5a75
SHA3 096893b4121cc18ebd4781b6e7827d00f18c6eb08c5ab0af486c434f91d7f2ae
SSDeep 768:yheaqtyy1Xc2j3MEeH1URsHPmHKm28yMby6UMJxOesDi1irUkOrJtkggl0ae7TW:o8RfsvmHKm2DIy6RCQkQtkgglodQ/Qv
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2025-Feb-21 10:21:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 80.0
SizeOfCode 0xe000
SizeOfInitializedData 0x800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000FE7E (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x10000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x14000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 464d3846f0e96d7f607c5789095c2288
SHA1 5d3b2700eb6324260d1b70457481c9e64dcbacc4
SHA256 6a275e953901f23ebc7c6d1f20fdf82a620511dcc50d67c6730bd5b140089950
SHA3 da203ab2af31c42632892170eb9e5f42ba736e9c1bfa60ae616c7fdc0f48ae52
VirtualSize 0xde84
VirtualAddress 0x2000
SizeOfRawData 0xe000
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.37328

.rsrc

MD5 f819c56d54b7393c3dac781068ba4762
SHA1 d944db4efe19bde44a7540b1ff81b7fa3e7f48c7
SHA256 28c4d4cb58fb0ce8a841cdba933a84bf960c1824d0fa74b323089087eeb0ebac
SHA3 9b5365af7cab7a40820b0cdb70a1922ac9e0dc0da4567d0a443588a1926b14af
VirtualSize 0x59c
VirtualAddress 0x10000
SizeOfRawData 0x600
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.05194

.reloc

MD5 d0253403a087eb7f28dad773081f770e
SHA1 e13f50927365dc5929d9741bc730c82fd562d5f5
SHA256 326c0e4441cf9c5b624058baf94ea10c9a040f8b2e0397803b0aafe43af3a4b1
SHA3 370d72f29e84dd174a0c6a87a275ffcd8e76667aeb4990f6f54f83b7b61b568e
VirtualSize 0xc
VirtualAddress 0x12000
SizeOfRawData 0x200
PointerToRawData 0xe800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0815394

Imports

mscoree.dll _CorExeMain

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x30c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26993
MD5 c480c4d5b70651421aabc24144fab8e7
SHA1 d46ea37f2b503877f56c73efaa2800dbdb495fa2
SHA256 f1781efaca00f0d411f2298ab7bca7b8daac6b289d1cfe050cc8a65a88e9e624
SHA3 f3c574055ec9bc52c32f655439f50607bdd6b6636fdd83889ecf30011f966c42

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName
FileDescription SaveKrk
FileVersion (#2) 1.0.0.0
InternalName SaveKrk.exe
LegalCopyright Copyright © 2013
LegalTrademarks
OriginalFilename SaveKrk.exe
ProductName SaveKrk
ProductVersion (#2) 1.0.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Feb-21 10:21:17
Version 0.0
SizeofData 284
AddressOfRawData 0xfd10
PointerToRawData 0xdf10
Referenced File D:\Document\Pro Work\Old Application\getkrkinfo OL\krk\SaveKrk\obj\x86\Debug\SaveKrk.pdb

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.