f05eefdaf443976b125b30efa4d20db11fba1aca2c7a5070298cedeaaf533640

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-May-13 22:09:04
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Comments Published under the GNU GPL
CompanyName Inkscape project
FileDescription Inkview vector graphics viewer
FileVersion 1.4.2
InternalName Inkview
LegalCopyright © 2025 Inkscape project
OriginalFilename inkview.exe
ProductName Inkview
ProductVersion 1.4.2

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .xdata
Suspicious The PE is possibly a dropper. Resources amount for 93.8195% of the executable.
Safe VirusTotal score: 0/65 (Scanned on 2025-10-22 10:00:00) All the AVs think this file is safe.

Hashes

MD5 577c9a0bf7df426bd59b1d8f6e009076
SHA1 05a5c03bd672bec095acbfa2e10c31466e56b995
SHA256 f05eefdaf443976b125b30efa4d20db11fba1aca2c7a5070298cedeaaf533640
SHA3 49eecc0525bfe26467ac231590655ebee12bbdabb915d8041db7554b9f265c30
SSDeep 1536:DkGkBuWUspbjg1b1bnsn4fH/4xGA6uaGSXS1DNBhzgVDkuHAuKu9uSgztFZzN:DknBzbg1RhoAuaM1DfwkDuOZFZJ
Imports Hash cb76b325771e3dcb0237f83edd5546da

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2025-May-13 22:09:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x1c00
SizeOfInitializedData 0x4c000
SizeOfUninitializedData 0x200
AddressOfEntryPoint 0x00000000000013F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x55000
SizeOfHeaders 0x400
Checksum 0x5284e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 63d47a07aa162edfc9620cc6487a27fe
SHA1 aa7c91a214a0549f031b255ec038126b9f71f718
SHA256 bfd97660ad1e0f1fe994397970600988b133b9977313f40aae09d24c9152c269
SHA3 58af9dd2207da0f2db5c79babb23c4a8b11bcbc3a60479765df7e5e5a99af09d
VirtualSize 0x1a30
VirtualAddress 0x1000
SizeOfRawData 0x1c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.73438

.data

MD5 ea608c1942780198454d9aa84cb283d7
SHA1 299a0487100ce5accbcbdc88fbd228c2bab17694
SHA256 df28c80986159956e741489892074bf42454474d9c763d2c198abf274fa47588
SHA3 2594bdd4dfa37de56d22eac8ef63fdee35db24b9ed7986f52bd5bdfc1cd1b7a6
VirtualSize 0xa0
VirtualAddress 0x3000
SizeOfRawData 0x200
PointerToRawData 0x2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.648016

.rdata

MD5 255f5338964d7425c83ea04edd7eb6d4
SHA1 9b75935d01e0cb480d97e62a55dcaa9f5a024c67
SHA256 40764799b188179dfe3562ba68c38546b67624f3ad1489b680b1ab4eff40e229
SHA3 1bf4c63b0cae1082978168723ced97e610f0dafcffebaaa5e2237dafcbe1fe91
VirtualSize 0xc00
VirtualAddress 0x4000
SizeOfRawData 0xc00
PointerToRawData 0x2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.83109

.pdata

MD5 47ce011f0525cc2f087a34c54d4bb3a9
SHA1 6aed33c548715309b80e8985cf31baeaeec16d3e
SHA256 f8bab4bab1bbfea7a820382ad70689dd5c566e5b16865322bc1567b9a2a33fe2
SHA3 700dabe99ce1161d87674e3646e65310bc57ec6efa73b1c45da6ebf0079cd38c
VirtualSize 0x228
VirtualAddress 0x5000
SizeOfRawData 0x400
PointerToRawData 0x2e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.36477

.xdata

MD5 d05ca6d2ebcdf8d8e321e5f801aa1137
SHA1 95ac5f0705ce688471d865c4c4af5b09cf0aacc6
SHA256 23887ccaf20f91a9dcf9680409037c4de7a48d65d5c6a7854101ff47c646f0d4
SHA3 785e2ec220ec1ac52988a1937ba062d503b98e626036de8dd102cdc7d5968d26
VirtualSize 0x1cc
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x3200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.63295

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x190
VirtualAddress 0x7000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e95b063ddfdcefbfb79a6c76d6608bda
SHA1 7369c8b6e5a9aa4290fedf2084d16a60f7244fd1
SHA256 3a4fbe2d799232c5e276b27d6278c241f69245a25c389ceeec9bcdef1b28bc75
SHA3 72e32d0bb983155b63d616ef28a73503e4c1a902c07c53952b3a4920dcc0a525
VirtualSize 0xb50
VirtualAddress 0x8000
SizeOfRawData 0xc00
PointerToRawData 0x3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.98932

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x9000
SizeOfRawData 0x200
PointerToRawData 0x4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 cf77e9ad582e483ac58d157ddb62718c
SHA1 32d90356d374c7374a1f88b65fce7e859835cfbd
SHA256 14d488d6e30ae12b3b37fc47287b0bc1ca281e45dcc74e4e3349cf1b5ae31de3
SHA3 7592be0d318194bb15309b99313eadd34eceea5178c56b1e92cf3bb3704f0ff8
VirtualSize 0x49b48
VirtualAddress 0xa000
SizeOfRawData 0x49c00
PointerToRawData 0x4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.98144

.reloc

MD5 773bff17ae8b2727b7a2049335aef553
SHA1 c9f0a2d01961026b7890a24f35e0aab47a8dc7a5
SHA256 2d9f49463291b2eade4c89e2a80e7f8d067d2488d5cbd564cb427633b5d6b058
SHA3 b9c815e4a174dcd677c6fbf5ea8b4314dd5eb00498f1bcb7178fe510572ed1d4
VirtualSize 0x6c
VirtualAddress 0x54000
SizeOfRawData 0x200
PointerToRawData 0x4de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.37356

Imports

libgcc_s_seh-1.dll _Unwind_Resume
libgtkmm-3.0-1.dll _ZN3Gtk11Application3runEiPPc
KERNEL32.dll DeleteCriticalSection
EnterCriticalSection
GetConsoleOutputCP
GetCurrentProcess
GetLastError
InitializeCriticalSection
IsProcessorFeaturePresent
LeaveCriticalSection
SetConsoleOutputCP
SetUnhandledExceptionFilter
Sleep
TerminateProcess
TlsGetValue
VirtualProtect
VirtualQuery
__C_specific_handler
api-ms-win-crt-environment-l1-1-0.dll __p__environ
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
free
malloc
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-private-l1-1-0.dll memcpy
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
_cexit
_configure_narrow_argv
_crt_atexit
_exit
_initialize_narrow_environment
_initterm
_initterm_e
_set_app_type
_set_invalid_parameter_handler
abort
exit
signal
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
_fileno
_setmode
_write
fflush
fwrite
api-ms-win-crt-string-l1-1-0.dll strlen
strncmp
api-ms-win-crt-utility-l1-1-0.dll rand_s
libstdc++-6.dll __gxx_personality_seh0
libinkscape_base.dll _ZN18InkviewApplicationC1Ev
_ZN18InkviewApplicationD1Ev

Delayed Imports

1000

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x328
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6287
MD5 fb1b103f54bcef6068ed27923a016be0
SHA1 19673adc8ac61675d90fe6f60303d61f1e96c7b6
SHA256 b08ef85bc2eff6ef7d7cc330f3ff5be6775a64a6777d19fabe96797a0ca74d92
SHA3 08a66403db2167e1655eae53011390e2c5ab5d340ef5244025a691dc37f0d1af
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.17753
MD5 5ffd601e14546c724211b70fb80e3d6f
SHA1 d25d1b18c3656a30be8ebe27e4e9b9a2ced93eb7
SHA256 b83fb972ebdd9c4e2b1d6d7912f51581ca5e38504cb7630d9966bedf5d70e818
SHA3 c15076ad35a9c15411a6502fbd7f1d061283ff3dc480b1980f941e223018131d

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.62628
MD5 1b6f5ebb9fdfaa330053adc2138c41d8
SHA1 16114442f29cfc425b056db9d5a7d4bd50dad58b
SHA256 6af8aefa35800b5442444d6f753fa48fbd779b984241d7c136f27bac0d0589b8
SHA3 8dc6208d378788aa3799e5504e540a737152aee937b674dae39327dfb12f35cf

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.75239
MD5 63bb2948e135935e5c4a81e29d8e3ea0
SHA1 93649f5a5d5a38bfe49a3abcc41b04dcbe1c556c
SHA256 f8d1caa383f1e767b5763266e7f10f1b0c1f2e4c2e0b45a1d745346b4b3427df
SHA3 f34832c2d9797c499172650270421f8d2bbddff4b41eab558fb90f735215ab64

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02514
MD5 dccbb8b050f70dea5736093019c5cdfd
SHA1 27c7616ed8a9c11c008faecf2b5a647879085585
SHA256 ce8befe3379380d70a5be5cb32b09c60294f6549bbc8e83c0af2c943cafe4a3e
SHA3 a26056dbb588ed52ea62a6b5483a72837cd649b6eb033cf6ecd7cd63c6c95947

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.38034
MD5 e5731f3f5563295e50e2e137a9cb75fa
SHA1 94c9bd2c4d11aaf9845d48f7164f5d2c6ae253e1
SHA256 63c7e38ac3d9a340b6ec0daa74dbcc2629dbf2b6f137f5b85696224c6606db83
SHA3 93f0cd09c4e7af76e97fbda0d28651e11cfd0b5d3ad309f2f38e9fd66f0304b3

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29468
MD5 b8169b5219e5733524351fbe8fa2d9dc
SHA1 36ce4ff14b8f76c9eced7d51f2e58d6dd5069e4e
SHA256 55adada4e339e05714e1051d7ee95a428fc9adca0b6005e766f27c19a05b4a94
SHA3 32dff5b0e7351cb121bf7b5f173c3fa7ce07d973b6d95b403c448380e26b0b43

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8587
MD5 a09bd0a0c6eb69a6f5b093cf8985ddd4
SHA1 2f06fb8a2501eead49c334e18ad057145f0b3eab
SHA256 a2d1db3d0f0c0e9a6e9801e6b850517a0cb4e686f5ca365100bcf9476e3fa3b3
SHA3 c71b332776ea0cdb702b5136d341eb0226d6bcd230d2cdfd4bf9cb379867dd3c

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.87067
MD5 3890398abd56463ad7cbcd2a7558a8e6
SHA1 e60604fd8e129e513522e85b8879900845b4a0c9
SHA256 dde1f375eb8e2a4bf2184acf63b46ce3654aaf5b43e9c10b0d38f697a95fb317
SHA3 d7e256612c7850f0f8f6efff419b259f5ca10db42053240bf1a5bb72aebad44f

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.87322
MD5 e5e7085998619eed30230c17509feff3
SHA1 2356ebd58861c9f1d659aba8a3e43afa8c623c30
SHA256 438dcbe59dca9737d738ae8a80c52968873ed241dfe9bbedb47423896a00616d
SHA3 50be5fb406fe5bb8c2fdcc3e9d340d85cab45e25bcf14101d17192dbc34f978f

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.7206
MD5 f794213909f427b6120bd358e9513fb9
SHA1 21a192b5fcb208cb0d6da1fcbe0be486149d0a8b
SHA256 c875106cab78f7aaac9de96503bd4bb1b02296ac2d0075de474e58a8f5e63a2b
SHA3 c191c1b4c809f3ddd956eacd55a20049ede2ae358d31a75af10545a1f7cd2ba7

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.78954
MD5 c2b3d63d6d6e3f9951a6620260591970
SHA1 408c540b1847d8ad165d7a21d6ccf3b16808078a
SHA256 b4cf2282f0a3f0d0ae47e05c6171fde6452809ff8d8ea8b371b54a9b3589ffdd
SHA3 b316fef9c7e0ebb5e1339143eeeedce1b7796ae312589e8b83cbde80e2475754

APPLICATION_ICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96809
Detected Filetype Icon file
MD5 69ba2fc9bb6374dd9f98febff7417ef6
SHA1 149b37e63e6231aeeffb4b1e3c9e789a5abb84db
SHA256 e2d25442598c58c7516e8f6d137da6b005dac3d1a31159fbe7f208efbb63ad54
SHA3 e7cf650ef07469db298230d476ce0acfecbe790c936d0638703d178046eb06bc

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x328
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41834
MD5 d175640d0b48d2106d54cadf23a0573e
SHA1 ec1def1151204264f48edb3f29fb56491d7cfcfe
SHA256 91dbc524858fed4a36987beac2c3543640bffb49180fa14409ff1f97499c5778
SHA3 99dd0d4ac4d93a8d9cd00cc9cfd3fb055ebc5e6f412c42d153af252b4170b114

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x316
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06238
MD5 cd73f0f22bfdb104f18968047d0efa5d
SHA1 8a6c4cd3c647f440e9aacd40913a9e1304d0b436
SHA256 8f93d9d9c4c8e231d157584913cc4d3fdfa0e263d358ca0e6997fa9be4d6a109
SHA3 335d169a53faa36afee08b7be715dead0f4d4a942d434fc8c7b043926cea32c5

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.4.2.0
ProductVersion 1.4.2.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Published under the GNU GPL
CompanyName Inkscape project
FileDescription Inkview vector graphics viewer
FileVersion (#2) 1.4.2
InternalName Inkview
LegalCopyright © 2025 Inkscape project
OriginalFilename inkview.exe
ProductName Inkview
ProductVersion (#2) 1.4.2
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x140009000
EndAddressOfRawData 0x140009008
AddressOfIndex 0x14000707c
AddressOfCallbacks 0x140004bd8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x00000001400015D0
0x00000001400015B0

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.