| filename | fax0010029826052014.scr | |
|---|---|---|
| size | 305664 (0x4aa00) | |
| md5 | d51669798d55ef5089da476a0cdf9c15 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xd0 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 5 | 8447 | 9502781 |
| 2 | 7274 | 13762615 |
| 10 | 8168 | 10813466 |
| 6 | 1735 | 11665442 |
| 10 | 8447 | 9109524 |
| 4 | 8047 | 393222 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
| id | lang | string |
|---|---|---|
| 14240 | 4108 | 趑뽕巇ᗄ틥狺疓ꙃⰨᤞ쎀ᘹ┥ |
| 2240 | 3081 | ac 01 02 43 45 3d 7b a4 6d d5 1f 07 6d 3a 5d 0b |...CE={.m...m:].|
08 44 2f 49 63 4b 88 f7 f8 fa 34 47 c2 f1 ef 41 |.D/IcK....4G...A|
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
00 00 00 00 00 00 00 |....... |
|
| 16320 | 3081 | 36 c0 a4 cd 09 e7 25 19 1e 0e 13 dd 14 35 18 60 |6.....%......5.`| 87 e2 fc 2c 23 74 33 c9 1f 76 a3 99 f0 35 9d 44 |...,#t3..v...5.D| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 00 00 00 00 00 00 00 00 00 |......... | |
| 10352 | 4108 | dc b6 a1 0f e3 a8 36 9a 96 10 b9 3c 10 a1 7d 5b |......6....<..}[| f4 b6 5c 2d c2 e7 02 e7 55 9d 36 8a da 4f ad 19 |..\-....U.6..O..| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 00 00 00 00 00 00 00 |....... | |
| 2752 | 3081 | Џᡑ硺뙧膅⟲媽塏룑冪 |
| 12912 | 4108 | 41 6a 09 15 ce ac cd 35 ea 4e b9 1d 49 6d 02 63 |Aj.....5.N..Im.c| be 8b 87 85 bf c5 fc 71 8a c2 bd b4 35 fe fb da |.......q....5...| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * |
| 8528 | 4108 | 옗볾ڊᒻ灧줼䟾ꡓ綤ì⥺枣 |
| 5488 | 4108 | 59 06 15 6a f9 74 c5 bb 53 84 77 50 5e 12 26 d4 |Y..j.t..S.wP^.&.| e1 5e 7c 3f 5e ce d0 1e 7e a5 e5 a5 84 ae ef 4b |.^|?^...~......K| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 00 00 00 00 00 00 00 00 00 00 00 |........... | |
| 6336 | 4108 | 먂擂갨뤃袼붺摩ꏄ䯞ꃹ൙ꦺ |
StringTable 040904B0
| CompanyName | Chime Softwares |
| ProductVersion | 10 |
| FileVersion | 10, 6, 7 |
| InternalName | Peso |
| LegalTrademarks | Faceqa Rovygy Xok Okekoca Cyjod Xikos Vivopak Usezeb |
| LegalCopyright | 2004 |
| OriginalFilename | Uyjamqdnj.exe |
| ProductName | Pesys |
| FileDescription | Agil Wyzeny Oviwu |
VS_FIXEDFILEINFO
| FileVersion | 10.6.0.0 |
| ProductVersion | 10.6.0.0 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 0x40004 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[!] string size(41950) > stringtable size(82). truncated to 80
[!] string size(856) > stringtable size(327). truncated to 325
[!] cannot convert "\x02CE={\xA4m\xD5\x1F\am:]\v\bD"... to UTF-16
[!] string size(98412) > stringtable size(521). truncated to 519
[!] cannot convert "\xA4\xCD\t\xE7%\x19\x1E\x0E\x13\xDD\x145\x18`\x87\xE2"... to UTF-16
[!] string size(93624) > stringtable size(135). truncated to 133
[!] cannot convert "\xA1\x0F\xE3\xA86\x9A\x96\x10\xB9<\x10\xA1}[\xF4\xB6"... to UTF-16
[!] string size(33232) > stringtable size(312). truncated to 310
[!] string size(54402) > stringtable size(112). truncated to 110
[!] cannot convert "\t\x15\xCE\xAC\xCD5\xEAN\xB9\x1DIm\x02c\xBE\x8B"... to UTF-16
[!] string size(44902) > stringtable size(200). truncated to 198
[!] string size(3250) > stringtable size(331). truncated to 329
[!] cannot convert "\x15j\xF9t\xC5\xBBS\x84wP^\x12&\xD4\xE1^"... to UTF-16
[!] string size(67032) > stringtable size(138). truncated to 136
[?] invalid VS_VERSIONINFO child type "w\x00F\x00t\x00"
offset:( 0x )