| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2019-Feb-21 16:00:00 |
| Detected languages |
English - United States
|
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip Standalone Console |
| FileVersion | 19.00 |
| InternalName | 7za |
| LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
| OriginalFilename | 7za.exe |
| ProductName | 7-Zip |
| ProductVersion | 19.00 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 Uses constants related to AES |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-03 10:59:26) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2019-Feb-21 16:00:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0xcea00 |
| SizeOfInitializedData | 0x51600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000CD730 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x123000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| OLEAUT32.dll |
SysStringLen
VariantClear VariantCopy SysAllocString SysFreeString SysAllocStringLen |
|---|---|
| USER32.dll |
CharUpperW
CharPrevExA |
| ADVAPI32.dll |
GetFileSecurityW
SetFileSecurityW OpenProcessToken LookupPrivilegeValueW AdjustTokenPrivileges SystemFunction036 |
| msvcrt.dll |
_exit
_c_exit _XcptFilter _onexit __dllonexit ??1type_info@@UEAA@XZ ?terminate@@YAXXZ __C_specific_handler _beginthreadex _isatty realloc strlen memset wcsstr strstr wcscmp _cexit memmove fflush fputc fputs _iob fgetc fclose free _CxxThrowException malloc memcmp _purecall __CxxFrameHandler memcpy exit __getmainargs __initenv _initterm __setusermatherr _commode _fmode __set_app_type strcmp |
| KERNEL32.dll |
ResetEvent
CreateSemaphoreW CreateEventW ReleaseSemaphore InitializeCriticalSection GetVersionExW SetEvent SetFileAttributesW WaitForSingleObject VirtualFree VirtualAlloc QueryPerformanceCounter LocalFileTimeToFileTime GetConsoleMode SetConsoleMode SetFileApisToOEM GetCommandLineW GetConsoleScreenBufferInfo SetConsoleCtrlHandler IsProcessorFeaturePresent GetProcessTimes DeleteCriticalSection SetProcessAffinityMask OpenEventW UnmapViewOfFile MapViewOfFile OpenFileMappingW WaitForMultipleObjects LeaveCriticalSection EnterCriticalSection GetStdHandle GetSystemTimeAsFileTime FileTimeToDosDateTime DosDateTimeToFileTime GlobalMemoryStatusEx GetSystemInfo GetProcessAffinityMask FileTimeToLocalFileTime FileTimeToSystemTime CompareFileTime GetCurrentProcess GetDiskFreeSpaceW GetFileInformationByHandle SetEndOfFile WriteFile ReadFile SetFilePointer GetFileSize DeviceIoControl GetLastError MultiByteToWideChar WideCharToMultiByte FreeLibrary LoadLibraryW GetModuleFileNameW LocalFree FormatMessageW CloseHandle SetFileTime CreateFileW RemoveDirectoryW MoveFileW GetProcAddress GetModuleHandleW CreateDirectoryW DeleteFileW SetCurrentDirectoryW GetCurrentDirectoryW GetTempPathW SetLastError GetCurrentProcessId GetTickCount GetCurrentThreadId FindClose FindFirstFileW FindNextFileW GetModuleHandleA GetFileAttributesW GetLogicalDriveStringsW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 19.0.0.0 |
| ProductVersion | 19.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip Standalone Console |
| FileVersion (#2) | 19.00 |
| InternalName | 7za |
| LegalCopyright | Copyright (c) 1999-2018 Igor Pavlov |
| OriginalFilename | 7za.exe |
| ProductName | 7-Zip |
| ProductVersion (#2) | 19.00 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0xfb814440 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (40310) | 1 |
| Imports (40310) | 11 |
| Total imports | 144 |
| C++ objects (40310) | 185 |
| C objects (40310) | 48 |
| ASM objects (VS2010 SP1 build 40219) | 4 |
| Resource objects (40310) | 1 |
| Linker (40310) | 1 |
No comments yet.