c69967e4f7cadb9ea41d0eeae96ef22f82ee9aff410d384a216e063e2e56213b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Feb-21 19:18:42
Detected languages English - United States
Debug artifacts C:\Users\alper\source\repos\offset cekici\x64\Debug\ES.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious The PE is packed or was manually edited. Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc
The number of imports reported in the RICH header is inconsistent.
Suspicious The PE contains functions most legitimate programs don't use. Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Safe VirusTotal score: 0/72 (Scanned on 2026-03-03 18:16:43) All the AVs think this file is safe.

Hashes

MD5 8685b15c3097f6674cd3ff48087e56f8
SHA1 d08a978304e2332beb22ae9eb6ed4144cf0272c5
SHA256 c69967e4f7cadb9ea41d0eeae96ef22f82ee9aff410d384a216e063e2e56213b
SHA3 820d58f59e0c5e7748eb1a6d34413d89f0768e9d02b86bbe3b4c10fb214dd5b0
SSDeep 1536:VtzAJSc3RO8bEBUbEAGh+IiU6BEY7Apuj4x:nzAJS38bE3AGhEU6BE/pujO
Imports Hash 0bb5c555bf1ce0c698030796749e1aff

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2026-Feb-21 19:18:42
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x17c00
SizeOfInitializedData 0xf200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000116CC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.textbss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10000
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.text

MD5 bf6f5245b1cef7b30985608cc205bebe
SHA1 0c330d7e8bf8f3750d706cfee158648afe44281d
SHA256 7c6632c91133ad58d37d4f717e4e3e16aa70229f7ba3843f70f348a718731f77
SHA3 2c9b391a99d7aa9e397e50efd9dec2d8d99444fec39d20a64894a70463cf8d66
VirtualSize 0x17a5b
VirtualAddress 0x11000
SizeOfRawData 0x17c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.33812

.rdata

MD5 bab446bce5b1bd143788f95c96040ec3
SHA1 3a2a5882ea816eb1e5ae333e20de1ebb1a0c7570
SHA256 e83f0752b2fcc02c6969095c21be524985e062c98ae00dc3f3b040716fa37c7b
SHA3 688251d5a543c60b4a6524401dedd5bd24d4ce04fbd1b46a40788093684ad7a8
VirtualSize 0x7304
VirtualAddress 0x29000
SizeOfRawData 0x7400
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.29569

.data

MD5 b501bd5a7cef8d5bb82d90d52a6eb2bc
SHA1 db137ede6e2c8972aface1ab1e5e0a4f0a6eae03
SHA256 b124d58536fab76ff6f8f45663521de3343d5bd57fdc9b5e9c55b7f4171110f1
SHA3 fdb2c6765581426e9d8d72e030e0ad4295352e0e4a40f859ec0582ce1af1161b
VirtualSize 0xee0
VirtualAddress 0x31000
SizeOfRawData 0x800
PointerToRawData 0x1f400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.90257

.pdata

MD5 4a0ad1aada5dc9d247ed9bab343b39e0
SHA1 2945081a328b72fde0296d5dd73bb7a4baeeff42
SHA256 2c5febe843d8298f04d3043ba7e25767a120d7bcf7207666c74f8bfee239194d
SHA3 a09c9c6cd33d522a2eb8fa9f15800f4de9ff803ecc6f99b6f0ffb66eb20df191
VirtualSize 0x3000
VirtualAddress 0x32000
SizeOfRawData 0x3000
PointerToRawData 0x1fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.7201

.idata

MD5 66595f92ff7608c93c0418145bfe2cd9
SHA1 f512a2d345fe89245f896bb04c3738f15ddc2cbb
SHA256 ca0955be7faed5a7607ee552ad270714b8c4a40e3cec65009678b1393b795ba4
SHA3 42261f0deab7357898a2064fab952df273c36a135b6c667e38fff8bf2005951c
VirtualSize 0x2b33
VirtualAddress 0x35000
SizeOfRawData 0x2c00
PointerToRawData 0x22c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.36126

.msvcjmc

MD5 e6dfcf067340ff883255a5a78accf781
SHA1 3990b0b679cc4f3e7ac8e1fcd5c539d27adbe8b5
SHA256 7bf317ed55feb51e1cc6b1b4c0de63c94e6708e69495d13e20dd98285a50a000
SHA3 664f9d939d184d8a4300bde8a6a55e9f6acf4569208bebc86d841a94f4f0ce5d
VirtualSize 0x24d
VirtualAddress 0x38000
SizeOfRawData 0x400
PointerToRawData 0x25800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.843587

.00cfg

MD5 4465ffde770cb3638ace7fee706ad702
SHA1 031655e282d9143f85eec613342716d6f90b2a25
SHA256 701779b1159966a6cd58a656380b6b308ddf72e107233b7c264389a9cd873079
SHA3 64feec727564e2bb628c03767cccb51977bcd29f9a83d6ed61e680a0ea0aa5ff
VirtualSize 0x175
VirtualAddress 0x39000
SizeOfRawData 0x200
PointerToRawData 0x25c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.47403

.rsrc

MD5 33ec2ec350cd406db5ac6c60a88c1bec
SHA1 7023ada5f30453a8634d218f54fa8e4e9f9f8849
SHA256 d4b70466583f1fb747a9bd3b3903c02115c7925e457f0622a97c333cba4a9643
SHA3 bcc3eb233a3f79a4aad34fa1f964b3f5465882b9ca6649ef62eebb75e6adde7f
VirtualSize 0x43c
VirtualAddress 0x3a000
SizeOfRawData 0x600
PointerToRawData 0x25e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.14297

.reloc

MD5 a9981e22e540bc6c49a01029ee8f64ff
SHA1 ea2c4a137725ac0407450d000a48253a5acaec26
SHA256 859cb210d12908500a15ec987734e7110c39902c88e5b3330401c7d88e07131e
SHA3 778ff4a134fbe316c9a90cbfd3c25cd4295b7d78be8230e7cfa0eae3dcc5ecc1
VirtualSize 0x469
VirtualAddress 0x3b000
SizeOfRawData 0x600
PointerToRawData 0x26400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.90005

Imports

KERNEL32.dll CloseHandle
OpenProcess
WideCharToMultiByte
SetConsoleTitleA
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
GetCurrentProcess
GetModuleHandleA
AllocConsole
K32GetModuleInformation
FreeLibrary
VirtualQuery
GetProcessHeap
HeapFree
HeapAlloc
GetLastError
GetModuleHandleW
GetStartupInfoW
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentProcessId
QueryPerformanceCounter
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
MultiByteToWideChar
RaiseException
IsDebuggerPresent
GetCurrentThreadId
GetProcAddress
MSVCP140D.dll ?always_noconv@codecvt_base@std@@QEBA_NXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setf@ios_base@std@@QEAAHHH@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Id_cnt@id@locale@std@@0HA
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_alloc@std@@YAXXZ
??1_Lockit@std@@QEAA@XZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?ignore@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?uncaught_exception@std@@YA_NXZ
?good@ios_base@std@@QEBA_NXZ
?flags@ios_base@std@@QEBAHXZ
?width@ios_base@std@@QEBA_JXZ
?width@ios_base@std@@QEAA_J_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
VCRUNTIME140_1D.dll __CxxFrameHandler4
VCRUNTIME140D.dll __vcrt_GetModuleFileNameW
__current_exception
__std_type_info_destroy_list
__C_specific_handler_noexcept
__current_exception_context
__vcrt_GetModuleHandleW
_CxxThrowException
__std_exception_destroy
__std_exception_copy
memmove
memcpy
__C_specific_handler
__vcrt_LoadLibraryExW
ucrtbased.dll malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_seh_filter_dll
_initialize_onexit_table
_register_onexit_function
_execute_onexit_table
_crt_atexit
_crt_at_quick_exit
_callnewh
strcat_s
__stdio_common_vsprintf_s
terminate
_wmakepath_s
_wsplitpath_s
wcscpy_s
_CrtDbgReportW
_free_dbg
_unlock_file
_lock_file
ungetc
setvbuf
fwrite
_fseeki64
fsetpos
fputc
fgetpos
fgetc
fflush
fclose
freopen_s
_get_stream_buffer_pointers
__acrt_iob_func
_CrtDbgReport
_invoke_watson
strlen
_stricmp
strcpy_s
_malloc_dbg
fread

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Feb-21 19:11:43
Version 0.0
SizeofData 83
AddressOfRawData 0x2d688
PointerToRawData 0x1c688
Referenced File C:\Users\alper\source\repos\offset cekici\x64\Debug\ES.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Feb-21 19:11:43
Version 0.0
SizeofData 20
AddressOfRawData 0x2d6dc
PointerToRawData 0x1c6dc

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140031040

RICH Header

XOR Key 0xa5fd8118
Unmarked objects 0
ASM objects (35207) 3
C objects (35207) 11
C++ objects (35207) 31
Imports (35207) 6
Imports (33145) 5
Total imports 170
C++ objects (35223) 3
Resource objects (35223) 1
Linker (35223) 1

Errors

[*] Warning: Section .textbss has a size of 0!
Leave a comment

No comments yet.