ede138f13dfc895eca2062996f6e51b7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-27 05:15:44
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName Binary Fortress Software
FileDescription FileSeek
FileVersion 7.1.0.0
InternalName FileSeek.dll
LegalCopyright Copyright © 2007-2025 Binary Fortress Software
OriginalFilename FileSeek.dll
ProductName FileSeek
ProductVersion 7.1.0.0
Assembly Version 7.1.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Info The PE is digitally signed. Signer: Binary Fortress Software Ltd.
Issuer: Microsoft ID Verified CS AOC CA 01
Safe VirusTotal score: 0/70 (Scanned on 2026-01-22 20:47:44) All the AVs think this file is safe.

Hashes

MD5 ede138f13dfc895eca2062996f6e51b7
SHA1 0636f351a342c422ed55ef68669ad6e8155a957f
SHA256 5e8e1be9386886c202ff76c1fdd4e362f63ba9861c0b5031ef05a6c5ae00686c
SHA3 3d2cf4c44e0c02e5a2a8f8ef0646a1e6c8f99cc66a80f4841707f5a687e6043f
SSDeep 3072:nqvmgiYSo4k8uIPzlSRwa/WB26mrIgfT3cQtI:n6ok83LlMvQUIgfTDa
Imports Hash bb3ac2c21e02c68abcad237dc3fa6d00

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Oct-27 05:15:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x16400
SizeOfInitializedData 0x33800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000011AB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4e000
SizeOfHeaders 0x400
Checksum 0x55ac5
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3ed5512b293aa5ccb14a2730a5a29785
SHA1 df85598271374ab44b618dd3406484df92cd74ce
SHA256 b55ea7f36007bb04f989c752a29e245bead9bdfc3913702e9f05cc1b26272d3e
SHA3 eac0d6142726512bc274619ea3ba58da9a701cbd4d73d4a2d5ed47b15533630a
VirtualSize 0x1627c
VirtualAddress 0x1000
SizeOfRawData 0x16400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.34417

.rdata

MD5 97f56458aeb5042fc110de6a7f14cf6a
SHA1 ab490304af2852e10170a79b9630ff6e6d663e11
SHA256 d33d88b28c92a6263f19e61ae3d4e00ce32d83fa52284044480b3e3a9c06c25e
SHA3 39afd2c8c38fa0f4c43be7d346d8e15b632cee9b5327339fd3bfcac42dc90c2b
VirtualSize 0xbd1e
VirtualAddress 0x18000
SizeOfRawData 0xbe00
PointerToRawData 0x16800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.83271

.data

MD5 502476630ead3a0362a5cca4f0cade20
SHA1 08a2d6819928e48a40af063e59bd7de3f11f637c
SHA256 74b4912c235ea5f134344ff89b5e505ab7922e89626c8dbed38f15668d70bcfe
SHA3 00b36174219eb4eae52f3ad77f064aba7199fdbceaa92bcdfd76e8c7889587e1
VirtualSize 0x1838
VirtualAddress 0x24000
SizeOfRawData 0xa00
PointerToRawData 0x22600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.37579

.pdata

MD5 c20628de244b4ad26d738fc5023ef5c1
SHA1 c4b6e73956dda9cc2bfc4b9f53d3cc6e8b6181be
SHA256 26d28ab08308ebbe19dea4673b4bd8cd46120a4826971710fa82c36ef53f389e
SHA3 d76843777bf9942d2219f35c7159ac599bcae19ec5b1fe5d9dc464b35914811a
VirtualSize 0x141c
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x23000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84522

.reloc

MD5 37812f81534460a128d06d0d29b2cb00
SHA1 8dcae4bb04c6e5e5d5a68d9e1d0bdc85c923ad95
SHA256 7d1932eae9901ec74760eb2c44a2df4a20f3a8bfb1a595db5dd20e43af7c73cf
SHA3 fa934fd7324404a9d4dd0c78dee6a4cbae71cf80f9cf2820ab6a74fe3716a019
VirtualSize 0x338
VirtualAddress 0x28000
SizeOfRawData 0x400
PointerToRawData 0x24600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80573

.rsrc

MD5 541d89197bf5019b68dbac7f4ec4c1d5
SHA1 952c6c45e39266c3c48bb79d60783cb0923b2dab
SHA256 51625fa27eabea87659dafb018d6a440e3555ef1b352f794d6e87bbfd7da0a50
SHA3 75cee9bc4bc4bae561c171202823ef3c5ab868288f07b0eb2bd6b37f428d0973
VirtualSize 0x244b0
VirtualAddress 0x29000
SizeOfRawData 0x24600
PointerToRawData 0x24a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.6659

Imports

KERNEL32.dll FreeLibrary
LoadLibraryExW
OutputDebugStringW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
GetModuleHandleW
MultiByteToWideChar
GetFileAttributesExW
LoadLibraryA
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetProcAddress
GetWindowsDirectoryW
FindResourceW
GetLastError
ActivateActCtx
FindClose
CreateActCtxW
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
__p___argc
_exit
exit
_initterm_e
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_errno
_initialize_onexit_table
abort
_c_exit
_register_thread_local_exe_atexit_callback
terminate
__p___wargv
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
_set_fmode
fputwc
__p__commode
fputws
_wfsopen
fflush
__stdio_common_vfwprintf
__stdio_common_vsnwprintf_s
__stdio_common_vswprintf
setvbuf
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
free
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll wcsncmp
toupper
strcmp
strlen
_wcsdup
wcsnlen
strcpy_s
api-ms-win-crt-convert-l1-1-0.dll wcstoul
_wtoi
api-ms-win-crt-time-l1-1-0.dll wcsftime
_gmtime64_s
_time64
api-ms-win-crt-locale-l1-1-0.dll ___mb_cur_max_func
_configthreadlocale
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_lock_locales
setlocale
_unlock_locales
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1469
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70313
Detected Filetype PNG graphic file
MD5 fdbdaca51e36504e0ef7809cebddc378
SHA1 8520f6c12216c5b3e382defe1ff2e8efe2fa02b3
SHA256 32072c8891dc6a7b49aaa1cfa13404eb6c9a9265e14763fb1d8b273505fa4552
SHA3 8118badba865d61190e79a24c94f6d4449b683847063b49b85f7922b90adbdb6

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.05621
MD5 a4e6eb961a8c14eaf0903227af934931
SHA1 7327740b12b521793c7cd450c08586ba47144143
SHA256 7168dcacc70cfb2035ec20bcb3371f097b939a4d53d4d77cc3150bd00f0389a2
SHA3 5741d5bd6b8a653506ca9b48bc2ec2344e561a10560c611b91bc5cd544b544b3

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.14273
MD5 4d1510092dd3bdf3c309a25e0a24a2d2
SHA1 08fdc36b61f7ab836f08c0a5190a748eb050adee
SHA256 3c9ec0470757014ea296f0b3fc1edbf0c11f368f33a63027d3a4c224e4e1f27d
SHA3 21b41c80bcba1b940513c418f12c61165e85e9ba8e8e8350a0270019f592aeb8

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.27333
MD5 63c65fb47e35d6d6d4b1c27bc1675299
SHA1 74c80b20202a545e97a9fcc64ed980e62b3a612c
SHA256 86657dc6a0964480411c71799d458fd9507fa3e1bec5ae27a2437034f8cba692
SHA3 466fd8bf4dee409419ef82844842bac362494b3e6e91f547641e3541478c63d0

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.37622
MD5 2a181ad231f35be454b6df8960a114f8
SHA1 0a2e5262226907b63befc1f98ed6e1f83e182d5e
SHA256 85b98f50d40ee5ac6026d95548ab48e767694c9e2deefccaf5fbe7eb9e528867
SHA3 cb7446c1c2fb0b82e4f81ec52c4682812238d0985c171e5b70cf599df362f43b

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.61187
MD5 11834e6909812225090478c0d5b90d5d
SHA1 cc5535eccf3344cace32f9ba61f0184cf2740f4a
SHA256 d5bc098fd1df804df1261960ad834f05a90b1e668e57ad99ae39be6318395b60
SHA3 35351dd8c25a95fc58bb78138f7cb425a83650333489a8a92a845b6c277ea40e

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82315
MD5 278dfdc90400d86ec4085f7e51774597
SHA1 64e9c17f78cecea8b55e6b57c4b9122aeb685b81
SHA256 8fd9179754d3920c32bfdc4cc8741846a35fe7d1cf59187157745c2c8232fdb3
SHA3 64ce4b87889c2726945225f9ec92e93dab57c1c417a9f1fd55613e326e9cd4c0

8

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06434
MD5 80e6ff148a38a7f95d026b47d19ee06a
SHA1 0c78ccef3a44b3d46f06ea4b1e0b4a5cfec45bdc
SHA256 c10222a8250e3715e5534bab12879dc73d295bf14374b755ba5ff549f4ef5232
SHA3 37ea496892d7b07c33a4afa41a7e22ea4b236c868b295e4a43845cfe527fe3e2

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97321
Detected Filetype Icon file
MD5 107aed948bec775a805f5143713728f1
SHA1 1d53f63207a9698bd17a553b71c5183bc2097283
SHA256 8d4f56aee5ef2ce8d5f6afa7a4497c358f1a765202f4c66614b939d276f75597
SHA3 74c19c46bcc0113f2bc536413b6257d9a2e9008777890b4ddf32da0a310bb0f0

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x340
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32705
MD5 8fcf5daeb712b1d1651cf8174d60c9e7
SHA1 7a15d11a6be8fe24cac6de0bb46e4ad523978362
SHA256 4adf1c6c310c620e86d17572f2452a6c5caee0939f9610c9ad5f8053838f5062
SHA3 ac2dd81f543d1f0a86fc553841108197ab11295f57e19b8b3545102908ea228b

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6d2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.41989
MD5 40d5238c93738bbd647c9703a5a3b3d7
SHA1 9a33dbb2d72e6cf50a02078fc8a0a4b31d6450b5
SHA256 b9f73e288f31986744cee8e8a1acdbccb19cc7d0ecc9b0fab0973cf7c3ea9355
SHA3 046fed6110fba93429910c30896cdcd3f71ca9d9a4eb2b6353f744cef1416c85

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 7.1.0.0
ProductVersion 7.1.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Binary Fortress Software
FileDescription FileSeek
FileVersion (#2) 7.1.0.0
InternalName FileSeek.dll
LegalCopyright Copyright © 2007-2025 Binary Fortress Software
OriginalFilename FileSeek.dll
ProductName FileSeek
ProductVersion (#2) 7.1.0.0
Assembly Version 7.1.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-27 21:40:13
Version 0.0
SizeofData 109
AddressOfRawData 0x2079c
PointerToRawData 0x1ef9c
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-27 21:40:13
Version 0.0
SizeofData 20
AddressOfRawData 0x2080c
PointerToRawData 0x1f00c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-27 21:40:13
Version 0.0
SizeofData 988
AddressOfRawData 0x20820
PointerToRawData 0x1f020

TLS Callbacks

StartAddressOfRawData 0x140020c48
EndAddressOfRawData 0x140020c58
AddressOfIndex 0x140025820
AddressOfCallbacks 0x1400184f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024080
GuardCFCheckFunctionPointer 5368808480
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x55c57ab0
Unmarked objects 0
ASM objects (35207) 10
C objects (35207) 12
C++ objects (35207) 87
Imports (VS2008 SP1 build 30729) 16
Imports (33140) 9
Total imports 204
C++ objects (LTCG) (35215) 10
Linker (35215) 1

Errors