830c273a4670d4366c95b5cd9edbe5bef817675a9629c880992183f97eff2a3f

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Apr-16 23:05:49
Detected languages English - United States
Comments PCRE is a library of functions to support regular expressions whose syntax and semantics are as close as possible to those of the Perl 5 language.
FileDescription Perl-Compatible Regular Expressions (UTF-16, 64-bit)
FileVersion 10.32
InternalName PCRE2
LegalCopyright Copyright (C) 1997-2019
OriginalFilename libpcre2-16-0.dll
ProductName PCRE2 Dynamic Link Library
ProductVersion 10.32

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Safe VirusTotal score: 0/70 (Scanned on 2026-06-14 17:24:43) All the AVs think this file is safe.

Hashes

MD5 4e8b364f8a7c832576695629f568fffe
SHA1 a11ff5f52964e54c22e33f400365ce118edab0e7
SHA256 830c273a4670d4366c95b5cd9edbe5bef817675a9629c880992183f97eff2a3f
SHA3 3679f152c4a783e1462bea49d4c64347c2e1313032321e15ff8df90d530176c9
SSDeep 3072:QS+l2raOv2OkVGVbtnhA1C67E/AnTnSnXNrsA4FQ51ViUk5u:QS+l2nuO0GPKQQKAnTSnXtVvV
Imports Hash 915fdfd8a6fa1b8baac1b51b1aaf2671

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2019-Apr-16 23:05:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 9.0
SizeOfCode 0x25c00
SizeOfInitializedData 0x8a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000021ADC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x33000
SizeOfHeaders 0x400
Checksum 0x3099e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e23d55e2994ac77f972735ad60f39097
SHA1 e90cbc33cc258b39534c1bc48f2a522fe082d75b
SHA256 53ae4e047b4af3b96fc123f1ea909ba91db81bde62f4403581add3a72ca674df
SHA3 e85fc875bdeed5f9723df4bb1a911f1c1ed4adfe5458d552c00e1634079debfb
VirtualSize 0x25b1e
VirtualAddress 0x1000
SizeOfRawData 0x25c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.28164

.rdata

MD5 9d629927413db35db2f72b10cf1feec1
SHA1 60fe5b787b64a904dac53207b0432f6cc7310164
SHA256 bbc78dc3a669743fda7c21ffae6eb36f8ff98ba96665f69171e60fc5a33ea357
SHA3 51a0d8a203c69c0b882f0bf90a1006c4eac3c202aa00abb938b428490853f5a4
VirtualSize 0x5d31
VirtualAddress 0x27000
SizeOfRawData 0x5e00
PointerToRawData 0x26000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.61028

.data

MD5 48302366b323550c292d5bc04a67350b
SHA1 c6bb21238a28fb63b0f0c84cc06af8e1541a97ce
SHA256 a39b723e4f550b585259e0e1f34a04a5981c36b079efdfec78cc4ded160de83f
SHA3 f4e411baae7d3cf26c89b53f12348922a2b67dcfd7470d31e0b0e465939c1602
VirtualSize 0x2258
VirtualAddress 0x2d000
SizeOfRawData 0x1200
PointerToRawData 0x2be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.40507

.pdata

MD5 94264a9065d343d53b5f017de55bd730
SHA1 6ff9e1a796cf891ad9806dcfcb4ccce3a9f2b971
SHA256 7464b5d29e478ef02beb4dabdae34bf04a6f1b3545f270bce91eaa06c764ad8e
SHA3 276eaf7d1aba7d769e96e3d16c182d58baf1fef66373add0153b3427dfb9ba85
VirtualSize 0xca8
VirtualAddress 0x30000
SizeOfRawData 0xe00
PointerToRawData 0x2d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84469

.rsrc

MD5 1070db060ed90f80aadd7037a53e4a3e
SHA1 7b3991c62bf8fef0f50ca4f13de5e7886e4aabd7
SHA256 805dee294a05d93fdebaf93aa8244c3c1b3fba042f14b6e1cc05a26043c0e6c7
SHA3 5e3562d588ba499e1c76f83615cb77774ff113ab2782d74021e64d31f4db493b
VirtualSize 0x62c
VirtualAddress 0x31000
SizeOfRawData 0x800
PointerToRawData 0x2de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.47926

.reloc

MD5 f2cdea03038aa7f5dd3da7c68327e952
SHA1 30a356f1913f2f6b2bae5acce648a36cb3c8a4bf
SHA256 06458874fa39e99b292fdd65f78086ce755a0fa0450d301809a7babbd00c9614
SHA3 16d1d70c3da94af26a3e3f555a2da292f70ad4dae8cf57c1007a10080859a404
VirtualSize 0x3da
VirtualAddress 0x32000
SizeOfRawData 0x400
PointerToRawData 0x2e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.27718

Imports

KERNEL32.dll HeapAlloc
GetLastError
HeapFree
GetCurrentThreadId
FlsSetValue
GetCommandLineA
GetModuleHandleW
Sleep
GetProcAddress
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
HeapSetInformation
HeapCreate
HeapDestroy
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
DecodePointer
FlsGetValue
FlsFree
SetLastError
FlsAlloc
LCMapStringA
WideCharToMultiByte
MultiByteToWideChar
LCMapStringW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
RtlUnwindEx
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
EnterCriticalSection
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapReAlloc
HeapSize

Delayed Imports

pcre2_callout_enumerate_16

Ordinal 1
Address 0x1cac0

pcre2_code_copy_16

Ordinal 2
Address 0x2270

pcre2_code_copy_with_tables_16

Ordinal 3
Address 0x22e0

pcre2_code_free_16

Ordinal 4
Address 0x23a0

pcre2_compile_16

Ordinal 5
Address 0xb3c0

pcre2_compile_context_copy_16

Ordinal 6
Address 0xc910

pcre2_compile_context_create_16

Ordinal 7
Address 0xc610

pcre2_compile_context_free_16

Ordinal 8
Address 0xca50

pcre2_config_16

Ordinal 9
Address 0xc350

pcre2_convert_context_copy_16

Ordinal 10
Address 0xca00

pcre2_convert_context_create_16

Ordinal 11
Address 0xc800

pcre2_convert_context_free_16

Ordinal 12
Address 0xca50

pcre2_converted_pattern_free_16

Ordinal 13
Address 0x200d0

pcre2_dfa_match_16

Ordinal 14
Address 0x15b80

pcre2_general_context_copy_16

Ordinal 15
Address 0xc8c0

pcre2_general_context_create_16

Ordinal 16
Address 0xc5a0

pcre2_general_context_free_16

Ordinal 17
Address 0xca50

pcre2_get_error_message_16

Ordinal 18
Address 0x16960

pcre2_get_mark_16

Ordinal 19
Address 0x1c5f0

pcre2_get_ovector_count_16

Ordinal 20
Address 0x1c610

pcre2_get_ovector_pointer_16

Ordinal 21
Address 0x1c600

pcre2_get_startchar_16

Ordinal 22
Address 0x1c620

pcre2_jit_compile_16

Ordinal 23
Address 0x16b90

pcre2_jit_free_unused_memory_16

Ordinal 24
Address 0x16bb0

pcre2_jit_match_16

Ordinal 25
Address 0x16b90

pcre2_jit_stack_assign_16

Ordinal 26
Address 0x16bb0

pcre2_jit_stack_create_16

Ordinal 27
Address 0x16ba0

pcre2_jit_stack_free_16

Ordinal 28
Address 0x16bb0

pcre2_maketables_16

Ordinal 29
Address 0x16bc0

pcre2_match_16

Ordinal 30
Address 0x1b630

pcre2_match_context_copy_16

Ordinal 31
Address 0xc990

pcre2_match_context_create_16

Ordinal 32
Address 0xc710

pcre2_match_context_free_16

Ordinal 33
Address 0xca50

pcre2_match_data_create_16

Ordinal 34
Address 0x1c560

pcre2_match_data_create_from_pattern_16

Ordinal 35
Address 0x1c5a0

pcre2_match_data_free_16

Ordinal 36
Address 0xca50

pcre2_pattern_convert_16

Ordinal 37
Address 0xe0f0

pcre2_pattern_info_16

Ordinal 38
Address 0x1c760

pcre2_serialize_decode_16

Ordinal 39
Address 0x1cf30

pcre2_serialize_encode_16

Ordinal 40
Address 0x1cd60

pcre2_serialize_free_16

Ordinal 41
Address 0x200d0

pcre2_serialize_get_number_of_codes_16

Ordinal 42
Address 0x1d140

pcre2_set_bsr_16

Ordinal 43
Address 0xca70

pcre2_set_callout_16

Ordinal 44
Address 0xcae0

pcre2_set_character_tables_16

Ordinal 45
Address 0xcb10

pcre2_set_compile_extra_options_16

Ordinal 46
Address 0xcad0

pcre2_set_compile_recursion_guard_16

Ordinal 47
Address 0xcae0

pcre2_set_depth_limit_16

Ordinal 48
Address 0xcb20

pcre2_set_glob_escape_16

Ordinal 49
Address 0xcb50

pcre2_set_glob_separator_16

Ordinal 50
Address 0xcb30

pcre2_set_heap_limit_16

Ordinal 51
Address 0xcaf0

pcre2_set_match_limit_16

Ordinal 52
Address 0xcb00

pcre2_set_max_pattern_length_16

Ordinal 53
Address 0xca90

pcre2_set_newline_16

Ordinal 54
Address 0xcaa0

pcre2_set_offset_limit_16

Ordinal 55
Address 0xcb10

pcre2_set_parens_nest_limit_16

Ordinal 56
Address 0xcac0

pcre2_set_recursion_limit_16

Ordinal 57
Address 0xcb20

pcre2_set_recursion_memory_management_16

Ordinal 58
Address 0x16ba0

pcre2_substitute_16

Ordinal 59
Address 0x1ed70

pcre2_substring_copy_byname_16

Ordinal 60
Address 0x20640

pcre2_substring_copy_bynumber_16

Ordinal 61
Address 0x20270

pcre2_substring_free_16

Ordinal 62
Address 0x200d0

pcre2_substring_get_byname_16

Ordinal 63
Address 0x20720

pcre2_substring_get_bynumber_16

Ordinal 64
Address 0x203f0

pcre2_substring_length_byname_16

Ordinal 65
Address 0x20580

pcre2_substring_length_bynumber_16

Ordinal 66
Address 0x1fed0

pcre2_substring_list_free_16

Ordinal 67
Address 0x200d0

pcre2_substring_list_get_16

Ordinal 68
Address 0x1ff70

pcre2_substring_nametable_scan_16

Ordinal 69
Address 0x200f0

pcre2_substring_number_from_name_16

Ordinal 70
Address 0x20260

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47277
MD5 e46274e6866a42d4e9334d6f498c3ccb
SHA1 671f06f360a0a5f8087b37e1294a57470a643c29
SHA256 d8bfd622b871a5ae3fe9e20275404df0ddd8e1246371f1b54b4947dd46ac634c
SHA3 67e74129ef112b681c8af2ddea08f5e93152a298d49dbeffa4757e9f893e468d

2

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x15a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79597
MD5 24d3b502e1846356b0263f945ddd5529
SHA1 bac45b86a9c48fc3756a46809c101570d349737d
SHA256 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e
SHA3 1244ed60820da52dc4b53880ec48e3b587dbdbd9545f01fa2b1c0fcfea1d5e9e

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.32.0.0
ProductVersion 10.32.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
Comments PCRE is a library of functions to support regular expressions whose syntax and semantics are as close as possible to those of the Perl 5 language.
FileDescription Perl-Compatible Regular Expressions (UTF-16, 64-bit)
FileVersion (#2) 10.32
InternalName PCRE2
LegalCopyright Copyright (C) 1997-2019
OriginalFilename libpcre2-16-0.dll
ProductName PCRE2 Dynamic Link Library
ProductVersion (#2) 10.32
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x66d1c99e
Unmarked objects 0
C++ objects (VS2008 SP1 build 30729) 26
ASM objects (VS2008 SP1 build 30729) 9
Imports (VS2012 build 50727 / VS2005 build 50727) 3
Total imports 75
C objects (VS2008 SP1 build 30729) 95
Exports (VS2008 SP1 build 30729) 1
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.