filename | rohanclient.exe | |
---|---|---|
size | 4326400 (0x420400) | |
md5 | 4743cb52b8092f53e5312bba40def617 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 2 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0x3819f6f4 |
reserved3 | 0x1eb0610 |
reserved4 | 0 |
reserved5 | 0x82e7d059 |
reserved6 | 0x46bb93a |
lfanew | 0x130 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0a 24 00 00 00 00 00 00 00 00 |mode...$........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000f0:
PE Header
Sections
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x96506d | 0x95 | |
RESOURCE | 0x963000 | 0x1388 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 | |
0 | 0x100000 |
id | lang | string |
---|---|---|
20000 | 1042 | 聛议츅߈뢀ল鋊靔髿힃铬㋌੶築⼵碪蒰ヷ榤Ҷ⫣ﭫ눋 |
20096 | 1042 | ⏧鵘ﷷ축뼉ᯡ俬⽙瑳ᷗ慉㿞럄녆╦㕜㝂塁珹⦗ҭ梨࣏䂠洖舥ල몫洗꿃ㅰ厓⬳ႅฉꑾ漨䈰쓃 |
20192 | 1042 | 26 48 3f c1 3a 79 83 7d 8c 84 9c 03 5a 3c 9d 1b |&H?.:y.}....Z<..| b0 04 94 c2 bc 17 b9 35 a8 42 19 75 2c 39 f6 86 |.......5.B.u,9..| 9d ab 0b 46 36 e4 77 ee ef db d8 3f 93 e6 |...F6.w....?.. | |
30000 | 1042 | 1f 47 f4 43 7c 08 2e a8 bb a7 53 80 26 90 ce 6d |.G.C|.....S.&..m| fb 44 ee ad 1f 94 29 b3 cf 45 b5 bf fd 94 fe 54 |.D....)..E.....T| 23 93 ae 3d df 0e 3d f9 a2 f0 7c 9f 8c 99 1a 7a |#..=..=...|....z| 2b 95 8d cf 4e 8b cb 09 9e 47 28 c7 1e ad 64 23 |+...N....G(...d#| 9b e9 e5 a4 37 13 13 f8 15 b1 2d d9 a8 75 a9 44 |....7.....-..u.D| 24 60 0d 67 9c b2 |$`.g.. | |
30992 | 1042 | a6 e0 b7 82 25 0e d0 84 e7 97 ed de df 77 a8 60 |....%........w.`| c3 ed 0f 94 e6 59 ec 6d 41 ae b2 20 a8 89 63 2b |.....Y.mA.. ..c+| 64 f4 f4 51 f4 37 39 fb f8 83 74 95 dd 23 79 17 |d..Q.79...t..#y.| 70 44 e7 ff 22 33 d3 b1 fb 44 cf 19 76 9d 77 24 |pD.."3...D..v.w$| fb 40 52 13 81 a0 76 e1 |.@R...v. | |
32096 | 1042 | 맛樋긵刎稝㓚뢈▇櫘ͷ迲镖Ӧ蘭宺䚪㘧ꇦ䚔ꆇ熈꾯ネ횁䖃뫮 |
32192 | 1042 | e4 c6 47 88 ca 01 e5 1b d6 18 72 ee 30 c4 c8 1d |..G.......r.0...| 97 7c 3a 44 47 d7 f0 32 bf 7d ef 24 d6 33 d7 fd |.|:DG..2.}.$.3..| 43 34 da 6f bb 18 df 49 70 a4 7e a2 a9 88 0c a7 |C4.o...Ip.~.....| df 5c f3 82 c7 d7 67 37 3a b7 d7 e2 da d6 4d 83 |.\....g7:.....M.| dd 94 58 df 52 b1 e3 d5 40 47 c0 98 2a f6 cc bb |..X.R...@G..*...| ec 3d ff 4a 9d fe c0 2e 1a 00 ab e5 f7 d8 68 b1 |.=.J..........h.| 2e 85 01 84 9b 4f ff b5 d3 4e |.....O...N | |
32208 | 1042 | 15 5a e9 e2 ac 74 d5 46 fe 3a 3b a9 7d 7c df f5 |.Z...t.F.:;.}|..| 8e 45 da ae 36 8a f4 f0 6f 61 12 ab df f7 1d 21 |.E..6...oa.....!| 10 61 d2 ba a8 0c 78 0f ed 9a f5 5a c4 61 07 16 |.a....x....Z.a..| 67 d2 15 65 04 50 00 33 a2 dd 94 8d 2c 4b 6f 20 |g..e.P.3....,Ko | 22 d2 0d b9 aa d3 d9 79 be b0 f4 c8 61 26 19 1d |"......y....a&..| |
32288 | 1042 | 62 15 4c 3f 2c e6 b1 c5 6d d5 ec 8d 22 14 6b 45 |b.L?,...m...".kE| 1e 4a 1c 8b 29 33 36 48 cd c3 64 c2 6f 73 34 1b |.J..)36H..d.os4.| 78 d0 2c da |x.,. | |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | lstrcpy | ||
comctl32.dll | InitCommonControls |
StringTable 040904B0
CompanyName | DarkGamerz |
FileDescription | Rohan Online Game |
FileVersion | 1, 0, 5, 001 |
InternalName | RohanClient |
LegalCopyright | Copyright (C) 2005 |
OriginalFilename | RohanClient |
ProductName | Rohan |
ProductVersion | 1, 0, 5, 001 |
VS_FIXEDFILEINFO
FileVersion | 1.0.5.1 |
ProductVersion | 1.0.5.1 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 0 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[!] string size(42846) > stringtable size(52). truncated to 50
[!] string size(31768) > stringtable size(92). truncated to 90
[!] string size(36940) > stringtable size(46). truncated to 44
[!] cannot convert "?\xC1:y\x83}\x8C\x84\x9C\x03Z<\x9D\e\xB0\x04"... to UTF-16
[!] string size(36414) > stringtable size(86). truncated to 84
[!] cannot convert "\xF4C|\b.\xA8\xBB\xA7S\x80&\x90\xCEm\xFBD"... to UTF-16
[!] string size(115020) > stringtable size(72). truncated to 70
[!] cannot convert "\xB7\x82%\x0E\xD0\x84\xE7\x97\xED\xDE\xDFw\xA8`\xC3\xED"... to UTF-16
[!] string size(33700) > stringtable size(60). truncated to 58
[!] string size(101832) > stringtable size(106). truncated to 104
[!] cannot convert "G\x88\xCA\x01\xE5\e\xD6\x18r\xEE0\xC4\xC8\x1D\x97|"... to UTF-16
[!] string size(46122) > stringtable size(80). truncated to 78
[!] cannot convert "\xE9\xE2\xACt\xD5F\xFE:;\xA9}|\xDF\xF5\x8EE"... to UTF-16
[!] string size(10948) > stringtable size(36). truncated to 34
[!] cannot convert "L?,\xE6\xB1\xC5m\xD5\xEC\x8D\"\x14kE\x1EJ"... to UTF-16
[?] can't find file_offset of VA 0x0