filename | HandBrake.exe | |
---|---|---|
size | 1116160 (0x110800) | |
md5 | bf33740072a296bd9674c0041af37f44 | |
type | PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Signature | PE |
Machine | 0x8664 |
NumberOfSections | 2 |
TimeDateStamp | 0x58ea9d2f |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics | 0x22 |
Magic | 0x20b |
LinkerVersion | 48.0 |
SizeOfCode | 0xf2200 |
SizeOfInitializedData | 0x1e400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0 |
BaseOfCode | 0x2000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x2000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Reserved1 | 0 |
SizeOfImage | 0x116000 |
SizeOfHeaders | 0x200 |
CheckSum | 0 |
Subsystem | 2 |
DllCharacteristics | 0x8560 |
SizeOfStackReserve | 0x400000 |
SizeOfStackCommit | 0x4000 |
SizeOfHeapReserve | 0x100000 |
SizeOfHeapCommit | 0x2000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 0x10 |
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x2000 | 0xf2048 | 0xf2200 | R-X CODE | |
.rsrc | 0xf6000 | 0x1e218 | 0x1e400 | R-- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0 | 0 | |
RESOURCE | 0xf6000 | 0x1e218 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0xf3f08 | 0x1c | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0x2000 | 0x48 |
type | name | size | cp | |
---|---|---|---|---|
ICON | #1 | 1320 | 0 | |
ICON | #2 | 5160 | 0 | |
ICON | #3 | 11560 | 0 | |
ICON | #4 | 101404 | 0 | |
GROUP_ICON | #32512 | 62 | 0 | |
VERSION | #1 | 1012 | 0 | |
MANIFEST | #1 | 2441 | 0 |
StringTable 000004b0
Comments | HandBrake is an open-source, GPL-licensed, multiplatform,video transcoder. |
CompanyName | HandBrake Team |
FileDescription | HandBrake |
FileVersion | 1.0.7.0 |
InternalName | HandBrake.exe |
LegalCopyright | Copyright © 2003-2017 HandBrake Team |
LegalTrademarks | |
OriginalFilename | HandBrake.exe |
ProductName | HandBrake |
ProductVersion | 1.0.7.0 |
Assembly Version | 1.0.7.0 |
VS_FIXEDFILEINFO
FileVersion | 1.0.7.0 |
ProductVersion | 1.0.7.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
offset | size | type | comment | |
---|---|---|---|---|
15c1 | 15 | HTM | # | |
7aabd | 101404 | PNG | (256 x 256) | # |
9d7da | 3113 | PNG | (64 x 64) | # |
9e408 | 801 | PNG | (32 x 32) | # |
9e72e | 979 | PNG | (20 x 20) | # |
9eb06 | 2736 | PNG | (40 x 40) | # |
9f5bb | 3998 | PNG | (64 x 64) | # |
a055e | 3963 | PNG | (32 x 32) | # |
a14de | 1087 | PNG | (30 x 30) | # |
a1922 | 1038 | PNG | (16 x 16) | # |
a1d35 | 314 | PNG | (16 x 16) | # |
a1e74 | 1267 | PNG | (16 x 16) | # |
a236c | 3106 | PNG | (48 x 48) | # |
a2f93 | 4504 | PNG | (64 x 64) | # |
a4130 | 1289 | PNG | (32 x 32) | # |
a463e | 5185 | PNG | (64 x 64) | # |
a5a84 | 217 | PNG | (16 x 16) | # |
a5b62 | 328 | PNG | (32 x 32) | # |
a5caf | 235 | PNG | (16 x 16) | # |
a5d9f | 314 | PNG | (32 x 32) | # |
a5ede | 2385 | PNG | (32 x 32) | # |
a6834 | 6776 | PNG | (64 x 64) | # |
a82b1 | 34363 | PNG | (128 x 133) | # |
b08f1 | 10108 | PNG | (64 x 67) | # |
b3072 | 3447 | PNG | (64 x 64) | # |
b3dee | 802 | PNG | (24 x 24) | # |
b4115 | 806 | PNG | (32 x 32) | # |
b4440 | 1318 | PNG | (32 x 32) | # |
b496b | 3929 | PNG | (64 x 64) | # |
b58c9 | 1401 | PNG | (32 x 32) | # |
b5e47 | 1394 | PNG | (32 x 32) | # |
b63be | 1166 | PNG | (18 x 18) | # |
b6851 | 3457 | PNG | (25 x 22) | # |
b75d7 | 3304 | PNG | (64 x 64) | # |
b82c4 | 3884 | PNG | (64 x 64) | # |
b91f5 | 1069 | PNG | (32 x 32) | # |
c0b12 | 985 | PNG | (20 x 20) | # |
c0ef0 | 1341 | PNG | (32 x 32) | # |
c1432 | 618 | PNG | (16 x 16) | # |
c16a1 | 350 | PNG | (16 x 16) | # |
f6c08 | 101404 | PNG | (256 x 256) | # |
10f824 | 4060 | BIN | overlay data past EOF | # |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x0
[?] can't find EntryPoint RVA (0x0) file offset
[?] can't find file_offset of VA 0x0
[?] can't find EntryPoint RVA (0x0) file offset
[?] can't find file_offset of VA 0x0
[?] can't find EntryPoint RVA (0x0) file offset