| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Feb-21 19:18:42 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\alper\source\repos\offset cekici\x64\Debug\ES.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | The PE is packed or was manually edited. |
Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc The number of imports reported in the RICH header is inconsistent. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2026-03-03 18:16:43) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2026-Feb-21 19:18:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x17c00 |
| SizeOfInitializedData | 0xf200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000116CC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3c000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
CloseHandle
OpenProcess WideCharToMultiByte SetConsoleTitleA CreateToolhelp32Snapshot Process32FirstW Process32NextW GetCurrentProcess GetModuleHandleA AllocConsole K32GetModuleInformation FreeLibrary VirtualQuery GetProcessHeap HeapFree HeapAlloc GetLastError GetModuleHandleW GetStartupInfoW InitializeSListHead GetSystemTimeAsFileTime GetCurrentProcessId QueryPerformanceCounter IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext MultiByteToWideChar RaiseException IsDebuggerPresent GetCurrentThreadId GetProcAddress |
|---|---|
| MSVCP140D.dll |
?always_noconv@codecvt_base@std@@QEBA_NXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setf@ios_base@std@@QEAAHHH@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xbad_alloc@std@@YAXXZ ??1_Lockit@std@@QEAA@XZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??0_Lockit@std@@QEAA@H@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?ignore@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Xout_of_range@std@@YAXPEBD@Z ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?uncaught_exception@std@@YA_NXZ ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ |
| VCRUNTIME140_1D.dll |
__CxxFrameHandler4
|
| VCRUNTIME140D.dll |
__vcrt_GetModuleFileNameW
__current_exception __std_type_info_destroy_list __C_specific_handler_noexcept __current_exception_context __vcrt_GetModuleHandleW _CxxThrowException __std_exception_destroy __std_exception_copy memmove memcpy __C_specific_handler __vcrt_LoadLibraryExW |
| ucrtbased.dll |
malloc
_seh_filter_exe _set_app_type __setusermatherr _configure_narrow_argv _initialize_narrow_environment _get_initial_narrow_environment _initterm _initterm_e exit _exit _set_fmode __p___argc __p___argv _cexit _c_exit _register_thread_local_exe_atexit_callback _configthreadlocale _set_new_mode __p__commode _seh_filter_dll _initialize_onexit_table _register_onexit_function _execute_onexit_table _crt_atexit _crt_at_quick_exit _callnewh strcat_s __stdio_common_vsprintf_s terminate _wmakepath_s _wsplitpath_s wcscpy_s _CrtDbgReportW _free_dbg _unlock_file _lock_file ungetc setvbuf fwrite _fseeki64 fsetpos fputc fgetpos fgetc fflush fclose freopen_s _get_stream_buffer_pointers __acrt_iob_func _CrtDbgReport _invoke_watson strlen _stricmp strcpy_s _malloc_dbg fread |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-21 19:11:43 |
| Version | 0.0 |
| SizeofData | 83 |
| AddressOfRawData | 0x2d688 |
| PointerToRawData | 0x1c688 |
| Referenced File | C:\Users\alper\source\repos\offset cekici\x64\Debug\ES.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-21 19:11:43 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x2d6dc |
| PointerToRawData | 0x1c6dc |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140031040 |
| XOR Key | 0xa5fd8118 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (35207) | 3 |
| C objects (35207) | 11 |
| C++ objects (35207) | 31 |
| Imports (35207) | 6 |
| Imports (33145) | 5 |
| Total imports | 170 |
| C++ objects (35223) | 3 |
| Resource objects (35223) | 1 |
| Linker (35223) | 1 |
No comments yet.