| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Apr-27 09:00:00 |
| Detected languages |
English - United States
|
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip Reduced Standalone Console |
| FileVersion | 26.01 |
| InternalName | 7zr |
| LegalCopyright | Igor Pavlov : Public domain |
| OriginalFilename | 7zr.exe |
| ProductName | 7-Zip |
| ProductVersion | 26.01 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to AES |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-06-09 18:18:32) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Apr-27 09:00:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x7aa00 |
| SizeOfInitializedData | 0x23800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00071D00 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7c000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| OLEAUT32.dll |
VariantCopy
SysAllocStringLen SysAllocString SysFreeString SysStringLen VariantClear |
|---|---|
| USER32.dll |
CharUpperW
|
| ADVAPI32.dll |
OpenProcessToken
GetFileSecurityW SetFileSecurityW RegQueryValueExW RegCloseKey RegOpenKeyExW AdjustTokenPrivileges LookupPrivilegeValueW |
| MSVCRT.dll |
_controlfp
__set_app_type __p__fmode __p__commode _adjust_fdiv __setusermatherr _initterm __getmainargs __p___initenv exit _XcptFilter _exit _onexit __dllonexit ??1type_info@@UAE@XZ ?terminate@@YAXXZ _except_handler3 _beginthreadex realloc _ftol _isatty _get_osfhandle memset strlen wcscmp wcsstr strcmp memmove fputs fputc fflush fgetc _iob free malloc memcmp _purecall memcpy _CxxThrowException __CxxFrameHandler |
| KERNEL32.dll |
WaitForSingleObject
ResumeThread SetThreadAffinityMask CreateEventW SetEvent ResetEvent CreateSemaphoreW ReleaseSemaphore InitializeCriticalSection SetFileAttributesW InterlockedIncrement GetVersion VirtualFree VirtualAlloc SetConsoleMode GetVersionExW SetFileApisToOEM GetCommandLineW GetConsoleScreenBufferInfo SetConsoleCtrlHandler DeleteCriticalSection EnterCriticalSection LeaveCriticalSection QueryPerformanceFrequency QueryPerformanceCounter GetProcessTimes OpenEventW OpenFileMappingW MapViewOfFile UnmapViewOfFile GetConsoleMode SetProcessAffinityMask GetSystemTimeAsFileTime FileTimeToDosDateTime IsProcessorFeaturePresent GlobalMemoryStatus GetSystemInfo GetProcessAffinityMask FileTimeToLocalFileTime FileTimeToSystemTime CompareFileTime GetModuleHandleW GetCurrentProcess GetDiskFreeSpaceExW GetDiskFreeSpaceW SetEndOfFile WriteFile ReadFile GetLastError MultiByteToWideChar WideCharToMultiByte FreeLibrary LoadLibraryW GetModuleFileNameW LocalFree FormatMessageW CloseHandle SetFileTime CreateFileW RemoveDirectoryW MoveFileW MoveFileWithProgressW CreateHardLinkW CreateDirectoryW DeleteFileW SetLastError SetCurrentDirectoryW GetCurrentDirectoryW GetTempPathW GetCurrentProcessId GetTickCount GetCurrentThreadId GetFileInformationByHandle GetStdHandle FindClose FindFirstFileW FindNextFileW GetProcAddress GetModuleHandleA GetFileAttributesW GetLogicalDriveStringsW GetFileSize SetFilePointer DeviceIoControl |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 26.1.0.0 |
| ProductVersion | 26.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip Reduced Standalone Console |
| FileVersion (#2) | 26.01 |
| InternalName | 7zr |
| LegalCopyright | Igor Pavlov : Public domain |
| OriginalFilename | 7zr.exe |
| ProductName | 7-Zip |
| ProductVersion (#2) | 26.01 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x66c7639d |
|---|---|
| Unmarked objects | 0 |
| C++ objects (8047) | 3 |
| 14 (7299) | 8 |
| C objects (8047) | 11 |
| Linker (8047) | 2 |
| C objects (2190) | 1 |
| Total imports | 155 |
| Imports (2179) | 9 |
| C++ objects (VS98 SP6 build 8804) | 135 |
| C objects (VS2010 SP1 build 40219) | 23 |
| C objects (VS98 SP6 build 8804) | 3 |
| C objects (35226) | 4 |
| ASM objects (VS2019 Update 8 (16.8.4) compiler 29336) | 5 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.