d26b93e6ad36f9a9d0c9c98b393143bcf7e6344a1585b0accdeadabdce7eb4d1

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Suspicious The PE is possibly packed. The PE only has 0 import(s).
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 ee5ea4a6d44b2d408c78e7dc7322ea51
SHA1 db2ce534946b29e8e283a320b90c191ccfbaf90a
SHA256 d26b93e6ad36f9a9d0c9c98b393143bcf7e6344a1585b0accdeadabdce7eb4d1
SHA3 a2244df04a0d97c8ffac9ce772d114547ab3fb04e2a0788e70363d1d7995a112
SSDeep 3:GltlVg//t/vk/vt1lNl//vl7//llrllHldldt1l9tllFll0ldlvl//lvFy:ya3t/83kK
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0
e_cp 0
e_crlc 0
e_cparhdr 0
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x40

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 1
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x200
SizeOfInitializedData 0
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00001000 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x3000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7c91e9bf16a66fc2801543a68310a633
SHA1 a3ccd04a202e08b8cb11457157137cec2c4dd9c6
SHA256 3d64acbf4147b610d88c922fab5f77a63dfd402f80a365fa5a88a87ea6e37b88
SHA3 6556743fa36b6a609ba1a91139f47877092c4b3adf46defdbe62b9efd3f813e6
VirtualSize 0x1000
VirtualAddress 0x1000
SizeOfRawData 0x200
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 0.0203931

Imports

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment
AUTHMARK<i>au42</i> 18 hours ago
CMTMARK<b>bold9137</b>quote"apos'amp&lt;lt end
A 17 hours ago
ssti{{7*7}}x${9*9}y#{6*6}z