Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- HEADER:0000000140000000 ; Input MD5 : 2AAF5CB13C9ECC0F1ED5EDF0D2AC94BF
- HEADER:0000000140000000 ; Input CRC32 : 46D6C669
- HEADER:0000000140000000
- HEADER:0000000140000000 ; IMAGE_DOS_HEADER
- HEADER:0000000140000000 ; PDB File Name : C:\Users\Mats\Desktop\h1z1 hk\injector\x64\Release\lsassmmap.pdb
- HEADER:0000000140000000
- HEADER:0000000140000000 include uni.inc ; see unicode subdir of ida for info on unicode
- HEADER:0000000140000000
- HEADER:0000000140000000 .686p
- HEADER:0000000140000000 .mmx
- HEADER:0000000140000000 .model flat
- HEADER:0000000140000000
- HEADER:0000000140000000 ; ===========================================================================
- HEADER:0000000140000000
- HEADER:0000000140000000 ; Segment type: Pure data
- HEADER:0000000140000000 HEADER segment page public 'DATA' use64
- HEADER:0000000140000000 assume cs:HEADER
- HEADER:0000000140000000 ;org 140000000h
- HEADER:0000000140000000 __ImageBase dw 5A4Dh ; DATA XREF: HEADER:0000000140000120o
- HEADER:0000000140000000 ; HEADER:0000000140000124o ...
- HEADER:0000000140000000 ; PE magic number
- HEADER:0000000140000002 dw 90h ; Bytes on last page of file
- HEADER:0000000140000004 dw 3 ; Pages in file
- HEADER:0000000140000006 dw 0 ; Relocations
- HEADER:0000000140000008 dw 4 ; Size of header in paragraphs
- HEADER:000000014000000A dw 0 ; Minimum extra paragraphs needed
- HEADER:000000014000000C dw 0FFFFh ; Maximum extra paragraphs needed
- HEADER:000000014000000E dw 0 ; Initial (relative) SS value
- HEADER:0000000140000010 dw 0B8h ; Initial SP value
- HEADER:0000000140000012 dw 0 ; Checksum
- HEADER:0000000140000014 dw 0 ; Initial IP value
- HEADER:0000000140000016 dw 0 ; Initial (relative) CS value
- HEADER:0000000140000018 dw 40h ; File address of relocation table
- HEADER:000000014000001A dw 0 ; Overlay number
- HEADER:000000014000001C dw 4 dup(0) ; Reserved words
- HEADER:0000000140000024 dw 0 ; OEM identifier (for e_oeminfo)
- HEADER:0000000140000026 dw 0 ; OEM information; e_oemid specific
- HEADER:0000000140000028 dw 0Ah dup(0) ; Reserved words
- HEADER:000000014000003C off_14000003C dd 0F8h ; DATA XREF: sub_14000380C+15r
- HEADER:000000014000003C ; File address of new exe header
- HEADER:0000000140000040 db 0Eh, 1Fh, 0BAh, 0Eh, 0, 0B4h, 9, 0CDh, 21h, 0B8h, 1 ; DOS Stub code
- HEADER:0000000140000040 db 4Ch, 0CDh, 21h, 54h, 68h, 69h, 73h, 20h, 70h, 72h, 6Fh
- HEADER:0000000140000040 db 67h, 72h, 61h, 6Dh, 20h, 63h, 61h, 2 dup(6Eh), 6Fh
- HEADER:0000000140000040 db 74h, 20h, 62h, 65h, 20h, 72h, 75h, 6Eh, 20h, 69h, 6Eh
- HEADER:0000000140000040 db 20h, 44h, 4Fh, 53h, 20h, 6Dh, 6Fh, 64h, 65h, 2Eh, 2 dup(0Dh)
- HEADER:0000000140000040 db 0Ah, 24h, 7 dup(0), 0C2h, 5Ch, 0E1h, 15h, 86h, 3Dh
- HEADER:0000000140000040 db 8Fh, 46h, 86h, 3Dh, 8Fh, 46h, 86h, 3Dh, 8Fh, 46h, 32h
- HEADER:0000000140000040 db 0A1h, 7Eh, 46h, 83h, 3Dh, 8Fh, 46h, 32h, 0A1h, 7Ch
- HEADER:0000000140000040 db 46h, 0FDh, 3Dh, 8Fh, 46h, 32h, 0A1h, 7Dh, 46h, 8Bh
- HEADER:0000000140000040 db 3Dh, 8Fh, 46h, 0BDh, 63h, 8Ch, 47h, 8Eh, 3Dh, 8Fh, 46h
- HEADER:0000000140000040 db 0BDh, 63h, 8Bh, 47h, 94h, 3Dh, 8Fh, 46h, 0BDh, 63h
- HEADER:0000000140000040 db 8Ah, 47h, 0A2h, 3Dh, 8Fh, 46h, 5Bh, 0C2h, 44h, 46h
- HEADER:0000000140000040 db 83h, 3Dh, 8Fh, 46h, 86h, 3Dh, 8Eh, 46h, 0E0h, 3Dh, 8Fh
- HEADER:0000000140000040 db 46h, 11h, 63h, 8Ah, 47h, 87h, 3Dh, 8Fh, 46h, 14h, 63h
- HEADER:0000000140000040 db 70h, 46h, 87h, 3Dh, 8Fh, 46h, 11h, 63h, 8Dh, 47h, 87h
- HEADER:0000000140000040 db 3Dh, 8Fh, 46h, 52h, 69h, 63h, 68h, 86h, 3Dh, 8Fh, 46h
- HEADER:0000000140000040 db 8 dup(0)
- HEADER:00000001400000F8 ; IMAGE_NT_HEADERS
- HEADER:00000001400000F8 dd 4550h ; Signature
- HEADER:00000001400000FC ; IMAGE_FILE_HEADER
- HEADER:00000001400000FC dw 8664h ; Machine
- HEADER:00000001400000FE dw 7 ; Number of sections
- HEADER:0000000140000100 dd 5902B3EDh ; Time stamp: Fri Apr 28 03:15:57 2017
- HEADER:0000000140000104 dd 0 ; Pointer to symbol table
- HEADER:0000000140000108 dd 0 ; Number of symbols
- HEADER:000000014000010C dw 0F0h ; Size of optional header
- HEADER:000000014000010E dw 22h ; Characteristics
- HEADER:0000000140000110 ; IMAGE_OPTIONAL_HEADER
- HEADER:0000000140000110 dw 20Bh ; Magic number
- HEADER:0000000140000112 db 0Eh ; Major linker version
- HEADER:0000000140000113 db 0 ; Minor linker version
- HEADER:0000000140000114 dd 14A00h ; Size of code
- HEADER:0000000140000118 dd 2C400h ; Size of initialized data
- HEADER:000000014000011C dd 0 ; Size of uninitialized data
- HEADER:0000000140000120 dd rva start ; Address of entry point
- HEADER:0000000140000124 dd rva sub_140001000 ; Base of code
- HEADER:0000000140000128 dq offset __ImageBase ; Image base
- HEADER:0000000140000130 dd 1000h ; Section alignment
- HEADER:0000000140000134 dd 200h ; File alignment
- HEADER:0000000140000138 dw 6 ; Major operating system version
- HEADER:000000014000013A dw 0 ; Minor operating system version
- HEADER:000000014000013C dw 0 ; Major image version
- HEADER:000000014000013E dw 0 ; Minor image version
- HEADER:0000000140000140 dw 6 ; Major subsystem version
- HEADER:0000000140000142 dw 0 ; Minor subsystem version
- HEADER:0000000140000144 dd 0 ; Reserved 1
- HEADER:0000000140000148 dd 46000h ; Size of image
- HEADER:000000014000014C dd 400h ; Size of headers
- HEADER:0000000140000150 dd 0 ; Checksum
- HEADER:0000000140000154 dw 3 ; Subsystem
- HEADER:0000000140000156 dw 8160h ; Dll characteristics
- HEADER:0000000140000158 dq 100000h ; Size of stack reserve
- HEADER:0000000140000160 dq 1000h ; Size of stack commit
- HEADER:0000000140000168 dq 100000h ; Size of heap reserve
- HEADER:0000000140000170 dq 1000h ; Size of heap commit
- HEADER:0000000140000178 dd 0 ; Loader flag
- HEADER:000000014000017C dd 10h ; Number of data directories
- HEADER:0000000140000180 dd 2 dup(0) ; Export Directory
- HEADER:0000000140000188 ; Import Directory
- HEADER:0000000140000188 dd rva __IMPORT_DESCRIPTOR_KERNEL32 ; Virtual address
- HEADER:000000014000018C dd 3Ch ; Size
- HEADER:0000000140000190 ; Resource Directory
- HEADER:0000000140000190 dd rva unk_140044000 ; Virtual address
- HEADER:0000000140000194 dd 1E0h ; Size
- HEADER:0000000140000198 ; Exception Directory
- HEADER:0000000140000198 dd rva ExceptionDir ; Virtual address
- HEADER:000000014000019C dd 1530h ; Size
- HEADER:00000001400001A0 dd 2 dup(0) ; Security Directory
- HEADER:00000001400001A8 ; Base Relocation Table
- HEADER:00000001400001A8 dd rva unk_140045000 ; Virtual address
- HEADER:00000001400001AC dd 664h ; Size
- HEADER:00000001400001B0 ; Debug Directory
- HEADER:00000001400001B0 dd rva dword_14001E020 ; Virtual address
- HEADER:00000001400001B4 dd 54h ; Size
- HEADER:00000001400001B8 dd 2 dup(0) ; Architecture Specific Data
- HEADER:00000001400001C0 dd 2 dup(0) ; RVA of GP
- HEADER:00000001400001C8 dd 2 dup(0) ; TLS Directory
- HEADER:00000001400001D0 ; Load Configuration Directory
- HEADER:00000001400001D0 dd rva _load_config_used ; Virtual address
- HEADER:00000001400001D4 dd 94h ; Size
- HEADER:00000001400001D8 dd 2 dup(0) ; Bound Import Directory in headers
- HEADER:00000001400001E0 ; Import Address Table
- HEADER:00000001400001E0 dd rva AdjustTokenPrivileges ; Virtual address
- HEADER:00000001400001E4 dd 2B0h ; Size
- HEADER:00000001400001E8 dd 2 dup(0) ; Delay Load Import Descriptors
- HEADER:00000001400001F0 dd 2 dup(0) ; COM Runtime descriptor
- HEADER:00000001400001F8 dd 2 dup(0) ; Image data directory 15
- HEADER:0000000140000200 ; IMAGE_SECTION_HEADER
- HEADER:0000000140000200 db '.text',0,0,0 ; Name
- HEADER:0000000140000208 dd 14A00h ; Virtual size
- HEADER:000000014000020C dd rva sub_140001000 ; Virtual address
- HEADER:0000000140000210 dd 14A00h ; Size of raw data
- HEADER:0000000140000214 dd 400h ; Pointer to raw data
- HEADER:0000000140000218 dd 0 ; Pointer to relocations
- HEADER:000000014000021C dd 0 ; Pointer to line numbers
- HEADER:0000000140000220 dw 0 ; Number of relocations
- HEADER:0000000140000222 dw 0 ; Number of linenumbers
- HEADER:0000000140000224 dd 60000020h ; Characteristics
- HEADER:0000000140000228 ; IMAGE_SECTION_HEADER
- HEADER:0000000140000228 db '.rdata',0,0 ; Name
- HEADER:0000000140000230 dd 0A526h ; Virtual size
- HEADER:0000000140000234 dd rva AdjustTokenPrivileges ; Virtual address
- HEADER:0000000140000238 dd 0A600h ; Size of raw data
- HEADER:000000014000023C dd 14E00h ; Pointer to raw data
- HEADER:0000000140000240 dd 0 ; Pointer to relocations
- HEADER:0000000140000244 dd 0 ; Pointer to line numbers
- HEADER:0000000140000248 dw 0 ; Number of relocations
- HEADER:000000014000024A dw 0 ; Number of linenumbers
- HEADER:000000014000024C dd 40000040h ; Characteristics
- HEADER:0000000140000250 ; IMAGE_SECTION_HEADER
- HEADER:0000000140000250 db '.data',0,0,0 ; Name
- HEADER:0000000140000258 dd 1FB48h ; Virtual size
- HEADER:000000014000025C dd rva dword_140021000 ; Virtual address
- HEADER:0000000140000260 dd 1EA00h ; Size of raw data
- HEADER:0000000140000264 dd 1F400h ; Pointer to raw data
- HEADER:0000000140000268 dd 0 ; Pointer to relocations
- HEADER:000000014000026C dd 0 ; Pointer to line numbers
- HEADER:0000000140000270 dw 0 ; Number of relocations
- HEADER:0000000140000272 dw 0 ; Number of linenumbers
- HEADER:0000000140000274 dd 0C0000040h ; Characteristics
- HEADER:0000000140000278 ; IMAGE_SECTION_HEADER
- HEADER:0000000140000278 db '.pdata',0,0 ; Name
- HEADER:0000000140000280 dd 1530h ; Virtual size
- HEADER:0000000140000284 dd rva ExceptionDir ; Virtual address
- HEADER:0000000140000288 dd 1600h ; Size of raw data
- HEADER:000000014000028C dd 3DE00h ; Pointer to raw data
- HEADER:0000000140000290 dd 0 ; Pointer to relocations
- HEADER:0000000140000294 dd 0 ; Pointer to line numbers
- HEADER:0000000140000298 dw 0 ; Number of relocations
- HEADER:000000014000029A dw 0 ; Number of linenumbers
- HEADER:000000014000029C dd 40000040h ; Characteristics
- HEADER:00000001400002A0 ; IMAGE_SECTION_HEADER
- HEADER:00000001400002A0 db '.gfids',0,0 ; Name
- HEADER:00000001400002A8 dd 0E4h ; Virtual size
- HEADER:00000001400002AC dd rva unk_140043000 ; Virtual address
- HEADER:00000001400002B0 dd 200h ; Size of raw data
- HEADER:00000001400002B4 dd 3F400h ; Pointer to raw data
- HEADER:00000001400002B8 dd 0 ; Pointer to relocations
- HEADER:00000001400002BC dd 0 ; Pointer to line numbers
- HEADER:00000001400002C0 dw 0 ; Number of relocations
- HEADER:00000001400002C2 dw 0 ; Number of linenumbers
- HEADER:00000001400002C4 dd 40000040h ; Characteristics
- HEADER:00000001400002C8 ; IMAGE_SECTION_HEADER
- HEADER:00000001400002C8 db '.rsrc',0,0,0 ; Name
- HEADER:00000001400002D0 dd 1E0h ; Virtual size
- HEADER:00000001400002D4 dd rva unk_140044000 ; Virtual address
- HEADER:00000001400002D8 dd 200h ; Size of raw data
- HEADER:00000001400002DC dd 3F600h ; Pointer to raw data
- HEADER:00000001400002E0 dd 0 ; Pointer to relocations
- HEADER:00000001400002E4 dd 0 ; Pointer to line numbers
- HEADER:00000001400002E8 dw 0 ; Number of relocations
- HEADER:00000001400002EA dw 0 ; Number of linenumbers
- HEADER:00000001400002EC dd 40000040h ; Characteristics
- HEADER:00000001400002F0 ; IMAGE_SECTION_HEADER
- HEADER:00000001400002F0 db '.reloc',0,0 ; Name
- HEADER:00000001400002F8 dd 664h ; Virtual size
- HEADER:00000001400002FC dd rva unk_140045000 ; Virtual address
- HEADER:0000000140000300 dd 800h ; Size of raw data
- HEADER:0000000140000304 dd 3F800h ; Pointer to raw data
- HEADER:0000000140000308 dd 0 ; Pointer to relocations
- HEADER:000000014000030C dd 0 ; Pointer to line numbers
- HEADER:0000000140000310 dw 0 ; Number of relocations
- HEADER:0000000140000312 dw 0 ; Number of linenumbers
- HEADER:0000000140000314 dd 42000040h ; Characteristics
- HEADER:0000000140000318 align 1000h
- HEADER:0000000140000318 HEADER ends
- HEADER:0000000140000318
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement