e_magic
0x5A4D ("MZ")
DOS signature - every PE starts with this
e_lfanew
0x00000080
Offset to PE header
Quick Check: If a file doesn't start with "MZ", it's not a valid Windows executable.
Signature
0x00004550 ("PE\0\0")
PE signature
Machine
0x8664 (AMD64)
Target architecture
TimeDateStamp
0x5F8A2B3C
Compilation time (can be faked)
Characteristics
0x0022
EXECUTABLE_IMAGE | LARGE_ADDRESS_AWARE
.text
VirtualSize: 0x1A00, RawSize: 0x1C00
Executable code
.rdata
VirtualSize: 0x0800, RawSize: 0x0A00
Read-only data, imports
.data
VirtualSize: 0x0400, RawSize: 0x0200
Initialized data
.enigma
VirtualSize: 0x2000, RawSize: 0x2000
Suspicious - non-standard section
00000000
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00
MZ..............
00000010
B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
........@.......
00000080
50 45 00 00 64 86 06 00 3C 2B 8A 5F 00 00 00 00
PE..d...<+._.....