By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

PE (Portable Executable)

File header

Characteristics 0x10f Relocation info stripped, File is executable, Line numbers stripped, Local symbols stripped, 32 bit word machine
Machine 0x14c Intel 386 or later processors and compatible processors
Number of sections 0x3 3
Number of symbols 0x0 0
Pointer to symbol table 0x0 0
Size of optional header 0xe0 224B
Time date stamp 0x54f5b819 2015-03-03 13:33:13.000Z
Signature 0x4550 PE

Optional header

Address of entrypoint 0x135f10 1269520
Base of code 0xc9000 823296
Base of data 0x137000 1273856
Checksum 0x7af91 503697
Dll characteristics 0x0 0
File alignment 0x200 512
Image base 0x400000 4194304
Loader flags 0x0 0
Magic 0x10b PE32
Major image version 0x0 0
Major linker version 0x6 6
Major os version 0x4 4
Major subsystem version 0x4 ?
Minor image version 0x0 0
Minor linker version 0x0 0
Minor os version 0x0 0
Minor subsystem version 0x0 Unknown
Number of rva and sizes 0x10 16B
Section alignment 0x1000 4096
Size of code 0x6e000 440.00KB
Size of headers 0x1000 4.00KB
Size of heap commit 0x1000 4.00KB
Size of heap reserve 0x100000 1.00MB
Size of image 0x13f000 1.25MB
Size of initialized data 0x8000 32.00KB
Size of stack commit 0x1000 4.00KB
Size of stack reserve 0x100000 1.00MB
Size of uninitialized data 0xc8000 800.00KB
Subsystem 0x2 Windows GUI
Win32 version value 0x0 0

Data Directory

SizeVirtual Address
Export Directory 0x0 0x0
Import Directory 0x3c4 0x13e568
Resource Directory 0x7568 0x137000
Exception Directory 0x0 0x0
Security Directory 0x21f0 0x75000
Base Relocation Table 0x0 0x0
Debug Directory 0x0 0x0
Architecture specific 0x0 0x0
RVA of GlobalPointer 0x0 0x0
TLS Directory 0x0 0x0
Load Config Directory 0x0 0x0
Bound Import Directory 0x0 0x0
Import Address Table 0x0 0x0
Delay Import Descriptors 0x0 0x0
COM Runtime Descriptor 0x0 0x0
Reserved 0x0 0x0