filename | Shadow.exe | |
---|---|---|
size | 3128832 (0x2fbe00) | |
md5 | b0b5222771b4dda3bbf4d3a81562267c | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x9ca000 | 0x9ca1c0 | 0x97ac2c | 0xcac310 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
oleaut32.dll | SafeArrayCreate | ||
advapi32.dll | RegQueryValueExW | ||
user32.dll | GetWindowTextLengthW | ||
kernel32.dll | GlobalDeleteAtom | ||
msimg32.dll | AlphaBlend | ||
gdi32.dll | SetMapMode | ||
version.dll | GetFileVersionInfoW | ||
mpr.dll | WNetOpenEnumW | ||
ole32.dll | OleUninitialize | ||
comctl32.dll | ImageList_Add | ||
shell32.dll | Shell_NotifyIconW | ||
comdlg32.dll | GetOpenFileNameW | ||
winspool.drv | OpenPrinterW | ||
oleacc.dll | LresultFromObject | ||
winmm.dll | timeGetTime | ||
wsock32.dll | socket | ||
user32.dll | MessageBoxA | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
kernel32.dll | LocalAlloc | ||
kernel32.dll | LocalFree | ||
kernel32.dll | GetModuleFileNameA | ||
kernel32.dll | ExitProcess |
ord | entry_va | function_name | |
---|---|---|---|
1 | 0xbf408 | EurekaLog_LastDelphiException | |
2 | 0xbf410 | EurekaLog_CallCreateThread | |
3 | 0xbf4a4 | EurekaLog_CallResumeThread | |
4 | 0xbf548 | EurekaLog_CallExitThread | |
5 | 0xbeb6c | EurekaLog_CallExceptObject | |
6 | 0xbe9d8 | EurekaLog_CallGeneralRaise | |
7 | 0xc0d78 | ExceptionManager | |
8 | 0xa0a90 | EurekaLog_PasswordRequestEvent | |
9 | 0xa0ad8 | EurekaLog_PasswordRequestEventEx | |
10 | 0xa0bac | EurekaLog_ExceptionNotifyEvent | |
11 | 0xa0c54 | EurekaLog_HandledExceptionNotifyEvent | |
12 | 0xa0cfc | EurekaLog_ExceptionActionNotifyEvent | |
13 | 0xa0da0 | EurekaLog_ExceptionErrorNotifyEvent | |
14 | 0xa0e44 | EurekaLog_CustomDataRequestEventEx | |
15 | 0xa0ee8 | EurekaLog_AttachedFilesRequestEvent | |
16 | 0xa0f8c | EurekaLog_CustomWebFieldsRequestEvent | |
17 | 0xa1030 | EurekaLog_CustomButtonClickEvent | |
18 | 0 | 50 8a 22 8d ca 3f ff 25 67 3c e5 61 9c 2a d5 55 |P."..?.%g<.a.*.U| d7 55 8f e6 09 20 94 3e d8 46 1c 03 38 53 1f 0a |.U... .>.F..8S..| d1 fe d6 2d 81 5c 3e 63 f5 fa 88 5e 06 74 91 46 |...-.\>c...^.t.F| 6d 13 b4 4a ed 6d 9b 2b 16 31 eb f1 25 89 db 79 |m..J.m.+.1..%..y| c8 c0 29 7c b1 1b ec 4c 39 ff 42 68 96 f6 c7 8c |..)|...L9.Bh....| 5e 11 68 06 48 b3 01 50 73 ec b5 49 ae be 26 93 |^.h.H..Ps..I..&.| 7a 13 cc e0 ba 39 26 3f 60 1d 8a aa 85 ac c2 7a |z....9&?`......z| a4 0e c2 6a 09 8d 1d 53 92 84 11 dd 61 88 4c b5 |...j...S....a.L.| 13 ae ba 15 9f a9 06 aa 02 16 98 24 2f 46 50 f4 |...........$/FP.| 1c 3a 1c 1b c5 c5 50 f0 7b f5 5a 59 ea 31 1e ce |.:....P.{.ZY.1..| a2 bd 30 28 0a 92 ac 15 15 a5 6c a8 15 25 c1 75 |..0(......l..%.u| 87 3d 15 10 b8 5e fc f6 97 36 b0 39 1f b6 ed 63 |.=...^...6.9...c| 1a e1 ac 7b 45 4f 40 17 f4 78 c5 df db 63 ed 0c |...{EO@..x...c..| 8a 30 8e 96 be 8a 89 47 b4 2b f6 cd f2 c8 95 8b |.0.....G.+......| 53 2f f4 c5 3f 6d e9 5c 63 2f 2b 44 4c ca 2f 58 |S/..?m.\c/+DL./X| af a1 ae 4f 5a b4 62 da 06 b0 d4 3e 82 cd 6f f1 |...OZ.b....>..o.| 08 2e 11 11 8d b0 d5 a7 84 5e e4 25 53 dc 62 90 |.........^.%S.b.| 63 93 e1 2e b0 77 f5 b9 20 94 b5 81 0d df 5c d6 |c....w.. .....\.| d6 d8 4d bc 67 0f 35 cb df 90 01 a7 01 ca e9 7f |..M.g.5.........| f6 7c d4 7a 8c a3 b6 06 fe 9b c9 67 f2 cb bf 0f |.|.z.......g....| 45 a1 3c 79 a7 b3 3d b2 61 41 51 c0 8a 7d ab 82 |E. |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x62fb20
[?] can't find file_offset of VA 0x62fc54
[?] can't find file_offset of VA 0x62fd88
[?] can't find file_offset of VA 0x62febc
[?] can't find file_offset of VA 0x62fff0
[?] can't find file_offset of VA 0x630124
[?] can't find file_offset of VA 0x630410
[?] can't find file_offset of VA 0x6306fc
[?] can't find file_offset of VA 0x6309e8
[?] can't find file_offset of VA 0x630cd4
[?] can't find file_offset of VA 0x630e08
[?] can't find file_offset of VA 0x630f3c
[?] can't find file_offset of VA 0x631070
[?] can't find file_offset of VA 0x63135c
[?] can't find file_offset of VA 0x631648
[?] can't find file_offset of VA 0x631934
[?] can't find file_offset of VA 0x631c20
[?] can't find file_offset of VA 0x631f0c
[?] can't find file_offset of VA 0x6321f8
[?] can't find file_offset of VA 0x63232c
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x6323e0
[?] can't find file_offset of VA 0x6325b0
[?] can't find file_offset of VA 0x632794
[?] can't find file_offset of VA 0x632964
[?] can't find file_offset of VA 0x632b34
[?] can't find file_offset of VA 0x632d04
[?] can't find file_offset of VA 0x632ed4
[?] can't find file_offset of VA 0x6330a4
[?] can't find file_offset of VA 0x633274
[?] can't find file_offset of VA 0x633444
[?] can't find file_offset of VA 0x633614
[?] can't find file_offset of VA 0x6338fc
[?] can't find file_offset of VA 0x633b2c
[?] can't find file_offset of VA 0x633d5c
[?] can't find file_offset of VA 0x633f8c
[?] can't find file_offset of VA 0x63421c
[?] can't find file_offset of VA 0x6344ac
[?] can't find file_offset of VA 0x634594
[?] can't find file_offset of VA 0x634abc
[?] can't find file_offset of VA 0x635310
[?] can't find file_offset of VA 0x635408
[?] can't find file_offset of VA 0x635930
[?] can't find file_offset of VA 0x635a18
[?] can't find file_offset of VA 0x635b10
[?] can't find file_offset of VA 0x636338
[?] can't find file_offset of VA 0x636420
[?] can't find file_offset of VA 0x6365d4
[?] can't find file_offset of VA 0x636788
[?] can't find file_offset of VA 0x63693c
[?] can't find file_offset of VA 0x637164
[?] can't find file_offset of VA 0x637e28
[?] can't find file_offset of VA 0x637f90
[?] can't find file_offset of VA 0x6387b8
[?] can't find file_offset of VA 0x638ce0
[?] can't find file_offset of VA 0x638da8
[?] can't find file_offset of VA 0x638e70
[?] can't find file_offset of VA 0x639358
[?] can't find file_offset of VA 0x639428
[?] can't find file_offset of VA 0x6394f8
[?] can't find file_offset of VA 0x6395c8
[?] can't find file_offset of VA 0x639698
[?] can't find file_offset of VA 0x639768
[?] can't find file_offset of VA 0x639838
[?] can't find file_offset of VA 0x639d20
[?] can't find file_offset of VA 0x63a208
[?] can't find file_offset of VA 0x63a6f0
[?] can't find file_offset of VA 0x63b3d8
[?] can't find file_offset of VA 0x63c0c0
[?] can't find file_offset of VA 0x63cda8
[?] can't find file_offset of VA 0x63d010
[?] can't find file_offset of VA 0x63d278
[?] can't find file_offset of VA 0x63d4e0
[?] can't find file_offset of VA 0x63e1c8
[?] can't find file_offset of VA 0x63eeb0
[?] can't find file_offset of VA 0x63fbd8
[?] can't find file_offset of VA 0x644704
[?] can't find file_offset of VA 0x64482c
[?] can't find file_offset of VA 0x644954
[?] can't find file_offset of VA 0x644a1c
[?] can't find file_offset of VA 0x644c84
[?] can't find file_offset of VA 0x6451c4
[?] can't find file_offset of VA 0x6452d8
[?] can't find file_offset of VA 0x64538c
[?] can't find file_offset of VA 0x645448
[?] can't find file_offset of VA 0x645508
[?] can't find file_offset of VA 0x6455c4
[?] can't find file_offset of VA 0x645680
[?] can't find file_offset of VA 0x645740
[?] can't find file_offset of VA 0x645800
[?] can't find file_offset of VA 0x645c90
[?] can't find file_offset of VA 0x645f4c
[?] can't find file_offset of VA 0x6460fc
[?] can't find file_offset of VA 0x646950
[?] can't find file_offset of VA 0x647278
[?] can't find file_offset of VA 0x647a94
[?] can't find file_offset of VA 0x6485c8
[?] can't find file_offset of VA 0x6488a0
[?] can't find file_offset of VA 0x648ce8
[?] can't find file_offset of VA 0x649058
[?] can't find file_offset of VA 0x649260
[?] can't find file_offset of VA 0x64950c
[?] too many errors getting resource data, stopped on 0 of 1
[?] can't find file_offset of VA 0x57ac2c