filename | out.exe | |
---|---|---|
size | 776192 (0xbd800) | |
md5 | 96fca1be228dafa4c5a8822022fd5d82 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xd8 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x52c81 | 0 | RWX CODE | |
.data | 0x54000 | 0x40c0 | 0 | RW- IDATA | |
.rsrc | 0x59000 | 0x62790 | 0 | RW- IDATA | |
.hdata | 0xbfb24 | 0x7000 | 0x6400 | RWX CODE IDATA |
Data Directory
offset | size | type | comment | |
---|---|---|---|---|
0 | 26624 | EXE | 07/13/2009 23:41:22 | # |
15c1 | 15 | HTM | # | |
643c0 | 27569 | PNG | (256 x 256) | # |
736c8 | 4657 | PNG | (750 x 400) | # |
74900 | 5454 | PNG | (938 x 500) | # |
75e50 | 6855 | PNG | (1125 x 600) | # |
77918 | 4069 | PNG | (190 x 50) | # |
78900 | 4372 | PNG | (238 x 63) | # |
79a18 | 4523 | PNG | (285 x 75) | # |
7abc8 | 2995 | PNG | (190 x 50) | # |
7b780 | 3105 | PNG | (238 x 63) | # |
7c3a8 | 3128 | PNG | (285 x 75) | # |
7cfe0 | 4215 | PNG | (385 x 50) | # |
7e058 | 4561 | PNG | (482 x 63) | # |
7f230 | 4718 | PNG | (578 x 75) | # |
804a0 | 3040 | PNG | (385 x 50) | # |
81080 | 3121 | PNG | (482 x 63) | # |
81cb8 | 3222 | PNG | (578 x 75) | # |
82950 | 4656 | PNG | (190 x 151) | # |
83b80 | 4877 | PNG | (238 x 188) | # |
84e90 | 5159 | PNG | (285 x 227) | # |
862b8 | 3256 | PNG | (190 x 151) | # |
86f70 | 3396 | PNG | (238 x 188) | # |
87cb8 | 3578 | PNG | (285 x 227) | # |
88ab8 | 4918 | PNG | (385 x 151) | # |
89df0 | 5201 | PNG | (482 x 188) | # |
8b248 | 5560 | PNG | (578 x 227) | # |
8c800 | 3380 | PNG | (385 x 151) | # |
8d538 | 3792 | PNG | (482 x 188) | # |
8e408 | 3830 | PNG | (578 x 227) | # |
8f300 | 3749 | PNG | (68 x 16) | # |
901a8 | 3969 | PNG | (88 x 21) | # |
91130 | 4164 | PNG | (104 x 25) | # |
92178 | 3774 | PNG | (68 x 16) | # |
93038 | 4003 | PNG | (88 x 21) | # |
93fe0 | 4204 | PNG | (104 x 25) | # |
95050 | 4427 | PNG | (136 x 27) | # |
961a0 | 4856 | PNG | (172 x 34) | # |
97498 | 5178 | PNG | (204 x 41) | # |
988d8 | 4955 | PNG | (292 x 27) | # |
99c38 | 5592 | PNG | (364 x 34) | # |
9b210 | 6209 | PNG | (440 x 41) | # |
9ca58 | 4189 | PNG | (136 x 27) | # |
9dab8 | 4595 | PNG | (172 x 34) | # |
9ecb0 | 4981 | PNG | (204 x 41) | # |
a0028 | 4706 | PNG | (136 x 59) | # |
a1290 | 5512 | PNG | (172 x 73) | # |
a2818 | 6595 | PNG | (204 x 89) | # |
a41e0 | 4126 | PNG | (136 x 27) | # |
a5200 | 4529 | PNG | (172 x 34) | # |
a63b8 | 4932 | PNG | (204 x 41) | # |
a7700 | 3097 | PNG | (385 x 62) | # |
a8320 | 3232 | PNG | (481 x 77) | # |
a8fc0 | 3349 | PNG | (578 x 93) | # |
a9cd8 | 3023 | PNG | (73 x 91) | # |
aa8a8 | 3056 | PNG | (92 x 113) | # |
ab498 | 3168 | PNG | (110 x 137) | # |
ac0f8 | 2965 | PNG | (190 x 27) | # |
acc90 | 3012 | PNG | (238 x 33) | # |
ad858 | 3066 | PNG | (285 x 41) | # |
ae458 | 3496 | PNG | (296 x 242) | # |
af200 | 3871 | PNG | (454 x 303) | # |
b0120 | 4243 | PNG | (545 x 363) | # |
b11b8 | 3653 | PNG | (296 x 308) | # |
b2000 | 4117 | PNG | (454 x 385) | # |
b3018 | 4586 | PNG | (545 x 461) | # |
b4208 | 3827 | PNG | (363 x 342) | # |
b5100 | 4246 | PNG | (454 x 428) | # |
b6198 | 4766 | PNG | (545 x 513) | # |
b7438 | 2921 | PNG | (34 x 27) | # |
b7fa8 | 2957 | PNG | (43 x 33) | # |
b8b38 | 2993 | PNG | (51 x 41) | # |
b96e9 | 16663 | BIN | overlay data past EOF | # |
Scanning the drive for archives: 1 file, 776192 bytes (758 KiB) Errors: 1
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 16
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 232
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 262492
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 339472
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 65558
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 8208
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 32
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 403360
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 72
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 80
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 1600
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 132
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 344080
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 364560
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 24964
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 262
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 65811
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 342
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 11216
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 3432
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 29095
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 378889
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 51234
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 1342
[?] too many errors getting resource data, stopped on 30 of 47359
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 39225
[?] too many errors getting resource data, stopped on 426 of 65535
[?] can't find file_offset of VA 0x905a4d
[?] can't find file_offset of VA 0x4550
[?] can't find file_offset of VA 0xef840fc0
[?] can't find file_offset of VA 0x6c5f0242
[?] can't find file_offset of VA 0x35ff0105
[?] can't find file_offset of VA 0x40c0
[?] can't find file_offset of VA 0x17c5
[?] can't find file_offset of VA 0x7381fe3d
[?] can't find file_offset of VA 0x16a0100
[?] can't find file_offset of VA 0xb8
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x2f
[?] can't find file_offset of VA 0xfffad0b5
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0xeba1f0e
[?] can't find file_offset of VA 0x77e6f671
[?] can't find file_offset of VA 0xa0d0d2e
[?] can't find file_offset of VA 0x20656220
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x75722065
[?] can't find file_offset of VA 0x1
[?] can't find file_offset of VA 0x85fffff9
[?] can't find file_offset of VA 0xc9124c
[?] can't find file_offset of VA 0xc8126d
[?] can't find file_offset of VA 0x4c6a45
[?] can't find file_offset of VA 0xb9000189
[?] can't find file_offset of VA 0x4c686369
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x4a5bc622
[?] can't find file_offset of VA 0x10200e0
[?] can't find file_offset of VA 0xa6000005
[?] can't find file_offset of VA 0xf9e9fc5d
[?] can't find file_offset of VA 0x1000
[?] can't find file_offset of VA 0x1000600
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0xcd612
[?] can't find file_offset of VA 0x2000
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x107e89fc
[?] can't find file_offset of VA 0x5300025a
[?] can't find file_offset of VA 0xff25d3ff
[?] can't find file_offset of VA 0x2bc06ff6
[?] can't find file_offset of VA 0xca5e836
[?] can't find file_offset of VA 0x47e8920
[?] can't find file_offset of VA 0x15df77ec
[?] can't find file_offset of VA 0xffeb3fe8
[?] can't find file_offset of VA 0x51adc
[?] can't find file_offset of VA 0x9768
[?] can't find EntryPoint RVA (0x9768) file offset
[?] can't find file_offset of VA 0x9768
[?] can't find EntryPoint RVA (0x9768) file offset
[?] can't find file_offset of VA 0x51adc
[?] can't find file_offset of VA 0x9768
[?] can't find EntryPoint RVA (0x9768) file offset
[?] can't find file_offset of VA 0x51adc
[?] can't find file_offset of VA 0x59000
[?] can't find file_offset of VA 0xbc000
[?] can't find file_offset of VA 0x53c24
[?] can't find file_offset of VA 0x30160
[?] can't find file_offset of VA 0x270
[?] can't find file_offset of VA 0x1000
[?] can't find file_offset of VA 0x51a5c
[?] can't find file_offset of VA 0x51adc