| filename | editor.exe | |
|---|---|---|
| size | 36005289 (0x22565a9) | |
| md5 | 7d923fad12afba9ebcf251415c7c08e3 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Sections
Data Directory
TLS
| raw start | raw end | index | callbks | zero fill | flags | |
|---|---|---|---|---|---|---|
| 0x400000 | 0x400000 | 0x654fd0 | 0x73c000 | 0 | 0 |
| offset | size | type | comment | |
|---|---|---|---|---|
| 15c1 | 15 | HTM | # | |
| 286ccc | 4449 | GIF | (0 x 0) | # |
| 2e4fcc | 600 | PNG | (16 x 16) | # |
| 2e5244 | 594 | PNG | (16 x 16) | # |
| 2e54a4 | 680 | PNG | (16 x 16) | # |
| 2e575c | 477 | PNG | (16 x 16) | # |
| 37b5bc | 18454 | PNG | (256 x 256) | # |
| 37fe08 | 565 | PNG | (16 x 16) | # |
| 380040 | 513 | PNG | (16 x 16) | # |
| 380244 | 702 | PNG | (16 x 16) | # |
| 380504 | 478 | PNG | (16 x 16) | # |
| 3806e4 | 568 | PNG | (16 x 16) | # |
| 38091c | 962 | PNG | (16 x 16) | # |
| 380ce0 | 660 | PNG | (16 x 16) | # |
| 380f74 | 653 | PNG | (16 x 16) | # |
| 381204 | 597 | PNG | (16 x 16) | # |
| 38145c | 694 | PNG | (16 x 16) | # |
| 381714 | 843 | PNG | (16 x 16) | # |
| 381a60 | 585 | PNG | (16 x 16) | # |
| 381cac | 743 | PNG | (16 x 16) | # |
| 381f94 | 504 | PNG | (16 x 16) | # |
| 38218c | 841 | PNG | (16 x 16) | # |
| 3824d8 | 504 | PNG | (16 x 16) | # |
| 382c18 | 406 | PNG | (16 x 16) | # |
| 382db0 | 2082 | PNG | (32 x 32) | # |
| 3835d4 | 1541 | PNG | (32 x 32) | # |
| 383bdc | 1826 | PNG | (32 x 32) | # |
| 384300 | 1298 | PNG | (32 x 32) | # |
| 384814 | 697 | PNG | (16 x 16) | # |
| 384ad0 | 255 | PNG | (16 x 16) | # |
| 384bd0 | 586 | PNG | (16 x 16) | # |
| 384e1c | 606 | PNG | (16 x 16) | # |
| 38507c | 290 | PNG | (16 x 16) | # |
| 3851a0 | 534 | PNG | (16 x 16) | # |
| 3853b8 | 742 | PNG | (16 x 16) | # |
| 3856a0 | 772 | PNG | (16 x 16) | # |
| 3859a4 | 570 | PNG | (16 x 16) | # |
| 385be0 | 645 | PNG | (16 x 16) | # |
| 385e68 | 534 | PNG | (16 x 16) | # |
| 386080 | 365 | PNG | (16 x 16) | # |
| 3861f0 | 514 | PNG | (16 x 16) | # |
| 3863f4 | 787 | PNG | (16 x 16) | # |
| 386708 | 458 | PNG | (16 x 16) | # |
| 3868d4 | 438 | PNG | (16 x 16) | # |
| 386a8c | 582 | PNG | (16 x 16) | # |
| 386cd4 | 511 | PNG | (16 x 16) | # |
| 386ed4 | 2864 | PNG | (9 x 9) | # |
| 387a04 | 619 | PNG | (16 x 16) | # |
| 387c70 | 591 | PNG | (16 x 16) | # |
| 38d676 | 1078 | BMP | (16 x 16) | # |
| 38db06 | 1078 | BMP | (16 x 16) | # |
| 38dfc4 | 1078 | BMP | (16 x 16) | # |
| 38e451 | 1078 | BMP | (16 x 16) | # |
| 38e8e1 | 1078 | BMP | (16 x 16) | # |
| 38ed73 | 1078 | BMP | (16 x 16) | # |
| 38f225 | 1078 | BMP | (16 x 16) | # |
| 38f6be | 1078 | BMP | (16 x 16) | # |
| 38fb87 | 1078 | BMP | (16 x 16) | # |
| 39001e | 1078 | BMP | (16 x 16) | # |
| 3904db | 1078 | BMP | (16 x 16) | # |
| 397216 | 1078 | BMP | (16 x 16) | # |
| 397709 | 1078 | BMP | (16 x 16) | # |
| 397bad | 1078 | BMP | (16 x 16) | # |
| 398076 | 1078 | BMP | (16 x 16) | # |
| 39853b | 1078 | BMP | (16 x 16) | # |
| 398971 | 32234552 | BIN | overlay data past EOF | # |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
offset:( 0x )