By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

PE (Portable Executable)

File header

Characteristics 0x2022 File is executable, Large Address Aware, File is a DLL
Machine 0x8664 x64
Number of sections 0x9 9
Number of symbols 0x0 0
Pointer to symbol table 0x0 0
Size of optional header 0xf0 240B
Time date stamp 0x66609e3b 2024-06-05 17:19:55.000Z
Signature 0x4550 PE

Optional header

Address of entrypoint 0x7efb78 8321912
Base of code 0x1000 4096
Checksum 0x6af6b7 7009975
Dll characteristics 0x160 352
File alignment 0x200 512
Image base 0x180000000 6442450944
Loader flags 0x0 0
Magic 0x20b PE32+
Major image version 0x0 0
Major linker version 0xe 14
Major os version 0x6 6
Major subsystem version 0x6 ?
Minor image version 0x0 0
Minor linker version 0x28 40
Minor os version 0x0 0
Minor subsystem version 0x0 Unknown
Number of rva and sizes 0x10 16B
Section alignment 0x1000 4096
Size of code 0x39800 230.00KB
Size of headers 0x400 1.00KB
Size of heap commit 0x1000 4.00KB
Size of heap reserve 0x100000 1.00MB
Size of image 0xb35000 11.21MB
Size of initialized data 0x94c00 595.00KB
Size of stack commit 0x1000 4.00KB
Size of stack reserve 0x100000 1.00MB
Size of uninitialized data 0x0 0B
Subsystem 0x2 Windows GUI
Win32 version value 0x0 0

Data Directory

SizeVirtual Address
Export Directory 0xc4f 0x9495f8
Import Directory 0x230 0x9c7678
Resource Directory 0x5e5 0xb34000
Exception Directory 0x531c 0xb2d140
Security Directory 0x1ae8 0x6a6000
Base Relocation Table 0xd0 0xb33000
Debug Directory 0x0 0x0
Architecture specific 0x0 0x0
RVA of GlobalPointer 0x0 0x0
TLS Directory 0x28 0x9968b0
Load Config Directory 0x140 0xb2d000
Bound Import Directory 0x0 0x0
Import Address Table 0x1e0 0x48d000
Delay Import Descriptors 0x0 0x0
COM Runtime Descriptor 0x0 0x0
Reserved 0x0 0x0