It looks like you're new here. If you want to get involved, click one of these buttons!
java -jar peanalyse <filename>
[/spoiler]************** PEAnalyser 0.1 by Deque@iExploit.org **************
analysing file: 7z.exe
PE signature offset: 232
PE signature correct: yes
----------------
COFF header info
----------------
characteristics:
* Image only, Windows CE, and Windows NT and later.
* Image only.
* Application can handle > 2 GB addresses.
machine type: x64
number of sections: 5
size of optional header: 240
time date stamp: Thu Nov 18 17:08:29 CET 2010
--------------------
Optional header info
--------------------
Standard fields
...............
address of entry point: 188096 (0x2dec0)
address of base of code: 4096 (0x1000)
magic number: 523 --> PE32+ executable
major linker version: 8 (0x8)
minor linker version: 0 (0x0)
size of code: 186368 (0x2d800)
size of initialized data: 105984 (0x19e00)
size of unitialized data: 0 (0x0)
Windows specific fields
.......................
checksum: 0 (0x0)
dll characteristics:
* Terminal Server aware.
file alignment in bytes: 512 (0x200)
image base: 4194304 (0x400000), default for Windows NT, 2000, XP, 95, 98 and Me
loader flags (reserved, must be zero): 0 (0x0)
major image version: 0 (0x0)
major operating system version: 4 (0x4)
major subsystem version: 5 (0x5)
minor image version: 0 (0x0)
minor operating system version: 0 (0x0)
minor subsystem version: 2 (0x2)
number of rva and sizes: 16 (0x10)
section alignment in bytes: 4096 (0x1000)
size of headers (MS DOS stub, PE header, and section headers): 1024 (0x400)
size of heap commit: 4096 (0x1000)
size of heap reserve: 1048576 (0x100000)
size of image in bytes: 307200 (0x4b000)
size of stack commit: 4096 (0x1000)
size of stack reserve: 1048576 (0x100000)
subsystem: The Windows character subsystem
win32 version value (reserved, must be zero): 0 (0x0)
Data directories
................
virtual_address/size
import table: 28(0x1c)/28
resource table: 16(0x10)/16
exception table: 8(0x8)/8
IAT: 192(0xc0)/192
-------------
Section Table
-------------
entry number 1:
...............
characteristics:
* The section contains executable code.
* The section can be executed as code.
name: .text
number of line numbers: 0 (0x0)
number of relocations: 0 (0x0)
pointer to line numbers: 0 (0x0)
pointer to raw data: 1024 (0x400)
pointer to relocations: 0 (0x0)
size of raw data: 186368 (0x2d800)
virtual address: 4096 (0x1000)
virtual size: 185900 (0x2d62c)
entry number 2:
...............
characteristics:
* The section contains initialized data.
name: .rdata
number of line numbers: 0 (0x0)
number of relocations: 0 (0x0)
pointer to line numbers: 0 (0x0)
pointer to raw data: 187392 (0x2dc00)
pointer to relocations: 0 (0x0)
size of raw data: 74752 (0x12400)
virtual address: 192512 (0x2f000)
virtual size: 74282 (0x1222a)
entry number 3:
...............
characteristics:
* The section contains initialized data.
* The section can be written to.
name: .data
number of line numbers: 0 (0x0)
number of relocations: 0 (0x0)
pointer to line numbers: 0 (0x0)
pointer to raw data: 262144 (0x40000)
pointer to relocations: 0 (0x0)
size of raw data: 2560 (0xa00)
virtual address: 270336 (0x42000)
virtual size: 11696 (0x2db0)
entry number 4:
...............
characteristics:
* The section contains initialized data.
name: .pdata
number of line numbers: 0 (0x0)
number of relocations: 0 (0x0)
pointer to line numbers: 0 (0x0)
pointer to raw data: 264704 (0x40a00)
pointer to relocations: 0 (0x0)
size of raw data: 18432 (0x4800)
virtual address: 282624 (0x45000)
virtual size: 17928 (0x4608)
entry number 5:
...............
characteristics:
* The section contains initialized data.
name: .rsrc
number of line numbers: 0 (0x0)
number of relocations: 0 (0x0)
pointer to line numbers: 0 (0x0)
pointer to raw data: 283136 (0x45200)
pointer to relocations: 0 (0x0)
size of raw data: 1024 (0x400)
virtual address: 303104 (0x4a000)
virtual size: 784 (0x310)