MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

TLS

StringTable 040904b0

VS_FIXEDFILEINFO

offsetsizetypecomment
0996864EXE10/23/2019 21:16:01#
15c115HTM#
f36002925740BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 3922604 bytes (3831 KiB)


--
Type = 7z
Offset = 997044
Physical Size = 2925560
Headers Size = 601
Method = LZMA:12m BCJ2
Solid = +
Blocks = 2

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2020-06-23 03:24:18 ....A          129       119244  RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/dump.ini
2019-04-16 09:07:33 ....A           92               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/ofcdebug.ini
2019-04-16 08:58:43 ....A           44               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/run.ini
2020-06-23 03:23:02 ....A          182               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/upload.ini
2019-04-01 07:59:14 ....A       219596               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/curl-ca-bundle.crt
2019-04-08 06:48:26 ....A       307768      2805715  RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/7z.exe
2019-04-09 10:56:34 ....A       587984               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/7za.exe
2019-04-09 10:56:34 ....A      3599056               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/curl.exe
2019-04-16 09:40:48 ....A       137936               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/pribytes32.exe
2019-04-16 09:43:02 ....A       161488               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/pribytes64.exe
2019-04-16 08:43:30 ....A       649936               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/procdump.exe
2019-04-16 08:47:17 ....A       340176               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/procdump64.exe
2019-07-10 04:43:47 ....A      1067424               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/RPCollectFile.exe
2019-04-08 06:48:39 ....A      1167552               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/7z.dll
2019-04-09 10:56:34 ....A       945872               RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/libcurl.dll
2019-04-09 10:56:45 ....A            0            0  RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec/files.txt
2020-06-23 03:32:12 D....            0            0  RPCollectDump_tmlisten_30P_10Sec/RPCollectDump_tmlisten_30P_10Sec
2020-06-23 03:32:12 D....            0            0  RPCollectDump_tmlisten_30P_10Sec
------------------- ----- ------------ ------------  ------------------------
2020-06-23 03:32:12            9185235      2924959  16 files, 2 folders
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0xe6474