sudo binwalk -e ZRY_115.exe DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 0 0x0 Microsoft executable, portable (PE) 179 0xB3 Copyright string: "Copyright (C) 2000 CW Sandmann (sandmann@clio.rice.edu)." 256 0x100 Copyright string: "Copyright (C) 1993-1995 DJ Delorie." 349 0x15D Copyright string: "copyright" 20743 0x5107 Copyright string: "Copyright (C) 1996-2010 the UPX Team. All Rights Reserved. $" 498349 0x79AAD 7-zip archive data, version 0.2 1630821 0x18E265 Microsoft executable, portable (PE) 1631485 0x18E4FD Microsoft executable, portable (PE) 1773237 0x1B0EB5 UEFI PI Firmware Volume, volume size: 266240, header size: 0, revision: 0, EFI Firmware File System, GUID: 7A9354D9-0468-444A-CE81-0BF617D890DF 1777400 0x1B1EF8 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 25838 bytes 1784563 0x1B3AF3 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 12633 bytes 1788013 0x1B486D LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 34997 bytes 1797141 0x1B6C15 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 16043 bytes 1801530 0x1B7D3A LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 16257 bytes 1805993 0x1B8EA9 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 20299 bytes 1811308 0x1BA36C LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 25715 bytes 1817580 0x1BBBEC LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 98515 bytes 1837043 0x1C07F3 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 98515 bytes 1856506 0x1C53FA LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 113317 bytes 1876177 0x1CA0D1 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 138152 bytes 1898755 0x1CF903 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 184919 bytes 1926070 0x1D63B6 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 21950 bytes 1929706 0x1D71EA LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 10793 bytes 1931985 0x1D7AD1 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 28916 bytes 1936418 0x1D8C22 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 13171 bytes 1939182 0x1D96EE LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 13615 bytes 1942119 0x1DA267 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 17149 bytes 1945512 0x1DAFA8 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 22131 bytes 1949451 0x1DBF0B LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 22366 bytes 1953914 0x1DD07A LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 10741 bytes 1957106 0x1DDCF2 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 29493 bytes 1962409 0x1DF1A9 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 13174 bytes 1966166 0x1E0056 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 13396 bytes 1970243 0x1E1043 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 16860 bytes 1974891 0x1E226B LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 21499 bytes 1980300 0x1E378C LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 23659 bytes 1987082 0x1E520A LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 10116 bytes 1991299 0x1E6283 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 32111 bytes 2000040 0x1E84A8 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 12845 bytes 2005248 0x1E9900 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 13082 bytes 2010589 0x1EADDD LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 16990 bytes 2016950 0x1EC6B6 LZMA compressed data, properties: 0x5D, dictionary size: 8388608 bytes, uncompressed size: 22167 bytes 2092725 0x1FEEB5 UEFI PI Firmware Volume, volume size: 3014656, header size: 0, revision: 0, EFI Firmware File System v2, GUID: 8C8CE578-8A3D-4F1C-3599-896185C32DD3 2092845 0x1FEF2D LZMA compressed data, properties: 0x5D, dictionary size: 16777216 bytes, uncompressed size: 10878992 bytes 5107381 0x4DEEB5 UEFI PI Firmware Volume, volume size: 229376, header size: 0, revision: 0, Variable Storage, GUID: FFF12B8D-7696-4C8B-85A9-2747075B4F50 5320381 0x512EBD UEFI PI Firmware Volume, volume size: 229376, header size: 0, revision: 0, Variable Storage, GUID: FFF12B8D-7696-4C8B-85A9-2747075B4F50 5320579 0x512F83 Certificate in DER format (x509 v3), header length: 4, sequence length: 907 5321602 0x513382 Certificate in DER format (x509 v3), header length: 4, sequence length: 1512 5323162 0x51399A Certificate in DER format (x509 v3), header length: 4, sequence length: 911 5324187 0x513D9B Certificate in DER format (x509 v3), header length: 4, sequence length: 1495 5325730 0x5143A2 Certificate in DER format (x509 v3), header length: 4, sequence length: 1552 5327330 0x5149E2 Certificate in DER format (x509 v3), header length: 4, sequence length: 903 5328281 0x514D99 Certificate in DER format (x509 v3), header length: 4, sequence length: 759 5329088 0x5150C0 Certificate in DER format (x509 v3), header length: 4, sequence length: 766 5330622 0x5156BE Certificate in DER format (x509 v3), header length: 4, sequence length: 913 5500597 0x53EEB5 Intel x86 or x64 microcode, sig 0x000406e2, pf_mask 0xc0, 2015-04-15, rev 0x0028, size 86016 5586613 0x553EB5 Intel x86 or x64 microcode, sig 0x000406e3, pf_mask 0xc0, 2016-01-05, rev 0x0074, size 95232 5682869 0x56B6B5 Intel x86 or x64 microcode, sig 0x000506e0, pf_mask 0x22, 2014-09-24, rev 0x0012, size 80896 5764789 0x57F6B5 Intel x86 or x64 microcode, sig 0x000506e1, pf_mask 0x22, 2015-03-18, rev 0x001e, size 75776 5840565 0x591EB5 Intel x86 or x64 microcode, sig 0x000506e3, pf_mask 0x36, 2016-01-05, rev 0x0074, size 95232 5936821 0x5A96B5 Intel x86 or x64 microcode, sig 0x000506e2, pf_mask 0x14, 2015-06-03, rev 0x002a, size 76800 6614709 0x64EEB5 UEFI PI Firmware Volume, volume size: 1310720, header size: 0, revision: 0, EFI Firmware File System v2, GUID: 8C8CE578-8A3D-4F1C-3599-896185C32DD3 6618837 0x64FED5 Microsoft executable, portable (PE) 6624853 0x651655 Microsoft executable, portable (PE) 6626837 0x651E15 CRC32 polynomial table, little endian 6643157 0x655DD5 Microsoft executable, portable (PE) 6682965 0x65F955 Microsoft executable, portable (PE) 6688341 0x660E55 Microsoft executable, portable (PE) 6690005 0x6614D5 Microsoft executable, portable (PE) 6692725 0x661F75 Microsoft executable, portable (PE) 6696053 0x662C75 Microsoft executable, portable (PE) 6700373 0x663D55 Microsoft executable, portable (PE) 6702581 0x6645F5 Microsoft executable, portable (PE) 6703573 0x6649D5 Microsoft executable, portable (PE) 6704597 0x664DD5 Microsoft executable, portable (PE) 6705749 0x665255 Microsoft executable, portable (PE) 6708565 0x665D55 Microsoft executable, portable (PE) 6714741 0x667575 Microsoft executable, portable (PE) 6716149 0x667AF5 Microsoft executable, portable (PE) 6718277 0x668345 CRC32 polynomial table, little endian 6729461 0x66AEF5 Microsoft executable, portable (PE) 6731533 0x66B70D CRC32 polynomial table, little endian 6740309 0x66D955 Microsoft executable, portable (PE) 6742517 0x66E1F5 Microsoft executable, portable (PE) 6743669 0x66E675 Microsoft executable, portable (PE) 6745749 0x66EE95 Microsoft executable, portable (PE) 6746901 0x66F315 Microsoft executable, portable (PE) 6753493 0x670CD5 Microsoft executable, portable (PE) 6757141 0x671B15 Microsoft executable, portable (PE) 6757685 0x671D35 SHA256 hash constants, little endian 6767733 0x674475 Microsoft executable, portable (PE) 6773525 0x675B15 Microsoft executable, portable (PE) 6787205 0x679085 LZMA compressed data, properties: 0x5D, dictionary size: 16777216 bytes, uncompressed size: 131088 bytes 6862453 0x68B675 Microsoft executable, portable (PE) 6877013 0x68EF55 Microsoft executable, portable (PE) 6878381 0x68F4AD CRC32 polynomial table, little endian 6880501 0x68FCF5 Microsoft executable, portable (PE) 6929525 0x69BC75 Microsoft executable, portable (PE) 6930069 0x69BE95 SHA256 hash constants, little endian 6945269 0x69F9F5 Microsoft executable, portable (PE) 6946605 0x69FF2D CRC32 polynomial table, little endian 6973301 0x6A6775 Microsoft executable, portable (PE) 6974453 0x6A6BF5 Microsoft executable, portable (PE) 6980469 0x6A8375 Microsoft executable, portable (PE) 6981557 0x6A87B5 Microsoft executable, portable (PE) 6983413 0x6A8EF5 Microsoft executable, portable (PE) 6985813 0x6A9855 CRC32 polynomial table, little endian 6993397 0x6AB5F5 Microsoft executable, portable (PE) 6999797 0x6ACEF5 Microsoft executable, portable (PE) 7002461 0x6AD95D CRC32 polynomial table, little endian 7009909 0x6AF675 Microsoft executable, portable (PE) 7011605 0x6AFD15 Microsoft executable, portable (PE) 7013461 0x6B0455 Microsoft executable, portable (PE) 7029493 0x6B42F5 Microsoft executable, portable (PE) 7033173 0x6B5155 Microsoft executable, portable (PE) 7050036 0x6B9334 mcrypt 2.2 encrypted data, algorithm: blowfish-448, mode: CBC, keymode: 8bit 7334773 0x6FEB75 Microsoft executable, portable (PE) 7417941 0x713055 Microsoft executable, portable (PE) 7916549 0x78CC05 Microsoft executable, portable (PE) 7938919 0x792367 Copyright string: "copyright information and URL." 7938995 0x7923B3 Copyright string: "copyright information and URL." 8436558 0x80BB4E Certificate in DER format (x509 v3), header length: 4, sequence length: 766 8585846 0x830276 Certificate in DER format (x509 v3), header length: 4, sequence length: 766