filename | duke3d.exe | |
---|---|---|
size | 6752400 (0x670890) | |
md5 | 7c029e14225a43bcbd11afdd0ce99868 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x140 |
DOS stub
00000000: 56 4c 56 00 01 00 00 00 90 08 67 00 d0 bc f6 57 |VLV.......g....W| 00000010: 00 ac be 64 a8 57 34 04 d3 4d 63 a0 5d 51 42 35 |...d.W4..Mc.]QB5| 00000020: 23 2f dc 4d f6 7c 22 fb e7 2d 5a d3 43 67 05 8c |#/.M.|"..-Z.Cg..| 00000030: 55 80 8e 5d fc c2 01 3e 5e bd 03 a1 76 a9 89 db |U..]...>^...v...| 00000040: 3b 52 11 4a 4c e8 4a a1 79 00 48 d4 5f 4c 67 1d |;R.JL.J.y.H._Lg.| 00000050: f4 4a e7 65 c6 57 ab 31 48 32 f4 53 e1 d7 58 9f |.J.e.W.1H2.S..X.| 00000060: 92 c9 47 fd b9 16 0c 1a e9 91 2b 89 69 ab 02 9e |..G.......+.i...| 00000070: 2c 06 ad 1a d6 0c 30 50 d0 20 eb c5 c0 46 53 0c |,.....0P. ...FS.| 00000080: d8 7b 89 c6 58 66 fd b4 62 bf df cb 5a 75 25 9e |.{..Xf..b...Zu%.| 00000090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 00000100:
PE Header
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x1e74000 | 0x1e74008 | 0x9d8928 | 0x649714 | 0 | 0x300000 |
type | name | size | cp | |
---|---|---|---|---|
ICON | #1 | 1128 | 0 | |
ICON | #2 | 4264 | 0 | |
ICON | #3 | 16936 | 0 | |
ICON | #4 | 67624 | 0 | |
ICON | #5 | 270376 | 0 | |
GROUP_ICON | #101 | 76 | 0 | |
MANIFEST | #1 | 381 | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x5d8928