Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
1992-Jun-19 22:22:17
|
Detected languages |
Dutch - Netherlands
English - United States
|
Comments |
This installation was built with Inno Setup.
|
CompanyName |
Spicebrains
|
FileDescription |
Instant Eyedropper Setup
|
FileVersion |
|
LegalCopyright |
|
ProductName |
Instant Eyedropper
|
ProductVersion |
|
Malicious |
The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
Can access the registry:
- RegQueryValueExA
- RegOpenKeyExA
- RegCloseKey
Possibly launches other programs:
Memory manipulation functions often used by packers:
- VirtualAlloc
- VirtualProtect
Functions related to the privilege level:
- OpenProcessToken
- AdjustTokenPrivileges
Can shut the system down or lock the screen:
|
Suspicious |
The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Suspicious |
The file contains overlay data. |
450410 bytes of data starting at offset 0xe200.
The overlay data has an entropy of 7.99955 and is possibly compressed or encrypted.
Overlay data amounts for 88.617% of the executable.
|
Suspicious |
VirusTotal score: 1/66 (Scanned on 2018-04-22 23:54:46) |
Comodo:
ApplicUnwnt.UnclassifiedMalware
|
MD5 |
ffe1d8a056314f74882553e579a701f3
|
SHA1 |
3451f71bdad5c2d9564720223399b97622dd2b4d
|
SHA256 |
7f06171798fe3342fe6d221c1e9a0832f9ea53cc9ddf2e9d200091c36da0c31c
|
SHA3 |
217bc571bfa791cfac9bed1289f757d3702495c31f00286095af2a5df0642d94
|
SSDeep |
12288:z7blMlDYjzFo514ZMc/HHWVsC67azlqqnHTEknjMxIoYlnlz:z7blSDoK4ZMmHWSC67aRq8Imj4Y3
|
Imports Hash |
4fb639b17a439bf0efa713bd4c6e715b
|
e_magic |
MZ
|
e_cblp |
0x50
|
e_cp |
0x2
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0xf
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0x1a
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0x100
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
8
|
TimeDateStamp |
1992-Jun-19 22:22:17
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic |
PE32
|
LinkerVersion |
2.0
|
SizeOfCode |
0xa200
|
SizeOfInitializedData |
0x4600
|
SizeOfUninitializedData |
0
|
AddressOfEntryPoint |
0x0000AA98 (Section: CODE)
|
BaseOfCode |
0x1000
|
BaseOfData |
0xc000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
1.0
|
ImageVersion |
6.0
|
SubsystemVersion |
4.0
|
Win32VersionValue |
0
|
SizeOfImage |
0x15000
|
SizeOfHeaders |
0x400
|
Checksum |
0
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x100000
|
SizeofStackCommit |
0x4000
|
SizeofHeapReserve |
0x100000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
b7ea439d9c6d5ec722056c9243fb3054
|
SHA1 |
448f38293276fdd5721deb66e9aab64e7eb86e6d
|
SHA256 |
8dc9c5aff1094b9c32e5e1e4f2567c0561560e81ce7040feec84f47df300a68b
|
SHA3 |
ac4c695be004bcb61b4e66c1b4a6562923db157c4eff44e64b019db2da7afc5f
|
VirtualSize |
0xa1d0
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0xa200
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
Entropy |
6.64375
|
MD5 |
9b2268ed5360951559d8041925d025fb
|
SHA1 |
92b3d0f7133ed41638b2883a6d2532b467edd641
|
SHA256 |
10055601ebbcbac194087162d139e75df13b0fb03d864c09e46dd3b940e61293
|
SHA3 |
28c7e8568b88a3bc640ef25fc571f8514205d55885052ca4b815cce95bb13a8d
|
VirtualSize |
0x250
|
VirtualAddress |
0xc000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0xa600
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
2.74012
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0xe94
|
VirtualAddress |
0xd000
|
SizeOfRawData |
0
|
PointerToRawData |
0xaa00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
df5f31e62e05c787fd29eed7071bf556
|
SHA1 |
3cfc95ebff0ce7dd7301eecc34bb84ee23beede8
|
SHA256 |
6b5e5c1868fa49411f0994cb6d66861b9a3df383e1bbe66616bb298966bfb9ce
|
SHA3 |
c4dfb0eb61fd84119a56f4451dbab23dbbc70e162d8912f4b492f5553ac46874
|
VirtualSize |
0x97c
|
VirtualAddress |
0xe000
|
SizeOfRawData |
0xa00
|
PointerToRawData |
0xaa00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
4.48608
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0x8
|
VirtualAddress |
0xf000
|
SizeOfRawData |
0
|
PointerToRawData |
0xb400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
14dfa4128117e7f94fe2f8d7dea374a0
|
SHA1 |
2b87a504cb33a3fbd0e12d47b5e2e300f8257779
|
SHA256 |
568b1f939a2cb9e982ceec1c3b15a6e8af6c345ba9094b98a61725bc71f4791c
|
SHA3 |
e94f4e299914230cc15cd9ab73bf3781bd6c8c9d3b80f85bd7ef74b7bbcb3e55
|
VirtualSize |
0x18
|
VirtualAddress |
0x10000
|
SizeOfRawData |
0x200
|
PointerToRawData |
0xb400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
Entropy |
0.190489
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0x91c
|
VirtualAddress |
0x11000
|
SizeOfRawData |
0
|
PointerToRawData |
0
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
MD5 |
cc3692632109139db5d0d2c0f44b7fe4
|
SHA1 |
2e37308129f0d2b740c4c2ce754351f581bdcd47
|
SHA256 |
0b22483c3d7af30eb31ae5bc3fddb911e4f5178a90255c761a8e966dad903709
|
SHA3 |
adc6cd9793c5e3fa65a657e531ab8a75351da37ef2ae7f2716294bd160c07d49
|
VirtualSize |
0x2c00
|
VirtualAddress |
0x12000
|
SizeOfRawData |
0x2c00
|
PointerToRawData |
0xb600
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
Entropy |
4.58247
|
kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
user32.dll |
MessageBoxA
|
oleaut32.dll |
VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
|
advapi32.dll |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
user32.dll (#2) |
MessageBoxA
|
comctl32.dll |
InitCommonControls
|
advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
Type |
RT_ICON
|
Language |
Dutch - Netherlands
|
Codepage |
UNKNOWN
|
Size |
0x128
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.25755
|
MD5 |
c5af786bfd9fd1c53c8fe9f0bd9ce38b
|
SHA1 |
4f6f7d9973b47063aa5353225a2bc5a76aa2a96a
|
SHA256 |
f59f62e7843b3ff992cf769a3c608acd4a85a38b3b302cda8507b75163659d7b
|
SHA3 |
e178a71f02edb18e31bf550d484b2cba8d865e1e9796065addb07855ce5627f9
|
Type |
RT_ICON
|
Language |
Dutch - Netherlands
|
Codepage |
UNKNOWN
|
Size |
0x568
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.47151
|
MD5 |
0a451222f7037983439a58e3b44db529
|
SHA1 |
6881cba71174502883d53a8885fb90dad81fd0c0
|
SHA256 |
dc785b2a3e4ea82bd34121cc04e80758e221f11ee686fcfd87ce49f8e6730b22
|
SHA3 |
d5599c242df5383add3fb330d42b31f1751594b36bbf52195e7d1dd564e7f0e3
|
Type |
RT_ICON
|
Language |
Dutch - Netherlands
|
Codepage |
UNKNOWN
|
Size |
0x2e8
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.91708
|
MD5 |
90ed3aac2a942e3067e6471b32860e77
|
SHA1 |
b849a2b9901473810b5d74e6703be78c3a7e64e3
|
SHA256 |
ca8fc96218d0a7e691dd7b95da05a27246439822d09b829af240523b28fd5bb3
|
SHA3 |
3f02085a0d69091556ede0b585f45145adce9849e175d8177c2f0fe0891a1bd8
|
Type |
RT_ICON
|
Language |
Dutch - Netherlands
|
Codepage |
UNKNOWN
|
Size |
0x8a8
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.91366
|
MD5 |
af05dd5bd4c3b1fc94922c75ed4f9519
|
SHA1 |
f54685a8a314e6f911c75cf7554796212fb17c3e
|
SHA256 |
3bbacbad1458254c59ad7d0fd9bea998d46b70b8f8dcfc56aad561a293ffdae3
|
SHA3 |
150dba8cc825d5c0e9ff3c59015533288d19931847210338a3ef7cdc390c0e78
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0x2f2
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.21823
|
MD5 |
bbf4b644f9dd284b35eb31573d0df2f7
|
SHA1 |
4f9885ae629e83464e313af5254ef86f01accd0b
|
SHA256 |
2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
|
SHA3 |
ebed2e4a929600c1460761d462143feb092840986b31c9748d3aeb8174d4205e
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0x30c
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.31515
|
MD5 |
ac2a0551cb90f91d779ee8622682dfb1
|
SHA1 |
ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
|
SHA256 |
840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
|
SHA3 |
58a85f5c53df73aa79e5f5a36aa151ca0d9da4d450ebc2975a3ee827b46342a5
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0x2ce
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.25024
|
MD5 |
c99b474c52df3049dfb38b5308f2827d
|
SHA1 |
7375e693629ce6bbd1a0419621d094bcd2c67bb7
|
SHA256 |
26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
|
SHA3 |
c6013febd14dd876e3b81111ec17dd2724dbf4147b0ad7be9d03259bcb59fef3
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0x68
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
2.86149
|
MD5 |
aec4e28ea9db1361160cde225d158108
|
SHA1 |
249013a10cde021c713ba2dc8912f9e05be35735
|
SHA256 |
d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
|
SHA3 |
a067c4d88d719ed8d568951acb776bd798b691a8b153f8d94ba0574ede1fbf4c
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0xb4
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.20731
|
MD5 |
c76a8843204c0572bca24ada35abe8c7
|
SHA1 |
066052030d0a32310da8cb5a51d0590960a65f32
|
SHA256 |
00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
|
SHA3 |
07523cf88b3803ea41acfeb3c9c0c4b5b4b9fb6f9a3232802491d8de1b6c9166
|
Type |
RT_STRING
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0xae
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
3.04592
|
MD5 |
4bd4f3f6d918ba49d8800ad83d277a86
|
SHA1 |
1f5e4c73965fea1d1f729efbe7568dcd081a2168
|
SHA256 |
34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
|
SHA3 |
2d01c56a5bf0b390addf4fb5b6ae02f9a64bd03ffd300d3763615bbb8ec911fe
|
Type |
RT_RCDATA
|
Language |
UNKNOWN
|
Codepage |
UNKNOWN
|
Size |
0x2c
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
4.59457
|
MD5 |
1d08419675f857e4c336baf520779b67
|
SHA1 |
8e515ae2fd16c8026e64f19d349cb6dd88bd81c0
|
SHA256 |
544d049165392ab65e6992552bd940c556942272c524156941427c3cac7c78e0
|
SHA3 |
df43c1f3abdaecd3ab40a8deb773123deb262bcb29affdb64ddae83dac905515
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x3e
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
2.64576
|
Detected Filetype |
Icon file
|
MD5 |
f6262f462f61a1af1cac10cf4b790e5a
|
SHA1 |
4aa3239c2c59fa5f246b0dd68da564e529b98ff4
|
SHA256 |
44b095a62d7e401671f57271e6cada367bb55cf7b300ef768b3487b841facd3c
|
SHA3 |
f2a1d165133c29eba349014fa5f8059ddebe1aba5b220fb89f1a474e95c482ca
|
Type |
RT_VERSION
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x4f4
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
2.56815
|
MD5 |
fdea99e378aa2bd04c0e9abe3ea1a938
|
SHA1 |
e4cff9fa9ca677aae780cfe809cf05862ba48be4
|
SHA256 |
c28504da86995d76792927c0b8a037b69db6cff37a85cc27448ee4604b265048
|
SHA3 |
5aaa960401be7dfc97359b9dd2fc844fd6ddce478302195abf8bcdec732fb6c7
|
Type |
RT_MANIFEST
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x62c
|
TimeDateStamp |
2016-Feb-07 13:36:44
|
Entropy |
5.13965
|
MD5 |
f78a870573f5bf2f15570e286257fae7
|
SHA1 |
eaccbf47cd42836b0e21ab2196b86d98a28733ca
|
SHA256 |
356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
|
SHA3 |
f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca
|
'%s' is not a valid integer value |
'%s' is not a valid floating point value |
'%s' is not a valid date |
'%s' is not a valid time |
'%s' is not a valid date and time |
Invalid argument to time encode |
Invalid argument to date encode |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Stack overflow |
Control-C hit |
Privileged instruction |
Operation aborted |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Invalid variant type conversion |
Invalid variant operation |
Variant method calls not supported |
Read |
Write |
Format result longer than 4096 characters |
Format string too long |
Error creating variant array |
Variant is not an array |
Variant array index out of bounds |
External exception %x |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
0.0.0.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language |
UNKNOWN
|
Comments |
This installation was built with Inno Setup.
|
CompanyName |
Spicebrains
|
FileDescription |
Instant Eyedropper Setup
|
FileVersion (#2) |
|
LegalCopyright |
|
ProductName |
Instant Eyedropper
|
ProductVersion (#2) |
|
Resource LangID |
English - United States
|
StartAddressOfRawData |
0x40f000
|
EndAddressOfRawData |
0x40f008
|
AddressOfIndex |
0x40d3d0
|
AddressOfCallbacks |
0x410010
|
SizeOfZeroFill |
0
|
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks |
(EMPTY)
|
[*] Warning: Section BSS has a size of 0!
[*] Warning: Section .tls has a size of 0!
[*] Warning: Section .reloc has a size of 0!