Sample files count | 1 |
Created files count | 1 |
Modified files count | 0 |
File Properties | |
---|---|
Names | Explorer Pro.exe (Sample File) |
Size | 3.19 MB (3340288 bytes) |
Hash Values | MD5: be66787e9a1933b319e3694b4c348e38 SHA1: 05ed9e77fc98cfce1bb9e4acad1b95f4167c5129 SHA256: ce7ddc6318d4e76ef0ad3d9b1a8f8ad90eb77a0bf53ab49e8440a0fb0b67aa39 |
Actions |
|
File Properties | |
---|---|
Image Base | 0x400000 |
Entry Point | 0x4d0014 |
Size Of Code | 0x98800 |
Size Of Initialized Data | 0x26000 |
Size Of Uninitialized Data | 0x0 |
Format | x86 |
Type | Executable |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 1973-12-21 14:23:07 |
Compiler/Packer | Themida/WinLicense V1.8.0.2 + -> Oreans Technologies |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
0x401000 | 0xb3000 | 0x51600 | 0x1000 | CNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE | 7.99 | |
.rsrc | 0x4b4000 | 0x1ae38 | 0x7000 | 0x52600 | CNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE | 7.54 |
.idata | 0x4cf000 | 0x1000 | 0x200 | 0x59600 | CNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE | 1.43 |
xp | 0x4d0000 | 0x2db000 | 0x2d6000 | 0x59800 | CNT_CODE, CNT_INITIALIZED_DATA, MEM_EXECUTE, MEM_READ, MEM_WRITE | 4.57 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset |
---|---|---|---|---|
CreateFileA | 0x0 | 0x4cf000 | 0xcf000 | 0x59600 |
ExitProcess | 0x0 | 0x4cf004 | 0xcf004 | 0x59604 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset |
---|---|---|---|---|
InitCommonControls | 0x0 | 0x4cf00c | 0xcf00c | 0x5960c |
File Properties | |
---|---|
Names | c:\program files\common files\microsoft shared\msinfo\fieleway.txt (Created File) |
Size | 0.04 KB (46 bytes) |
Hash Values | MD5: 5718f05d3bdebb944ec1c02d56ff3a63 SHA1: 035e87a09dad57fd972df857579fdb65f36a1395 SHA256: 444ea6025185bf690be65b937723cd74ec2cf1030fc42f7a8f191ff6a238a5d6 |
Actions |
|
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox
with deactivated setting "security.fileuri.strict_origin_policy".