Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
2017-Dec-26 10:04:58
|
Detected languages |
English - United Kingdom
|
Suspicious |
PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
|
Suspicious |
The PE is packed with UPX |
Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
|
Suspicious |
The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
Memory manipulation functions often used by packers:
- VirtualProtect
- VirtualAlloc
|
Info |
The PE's resources present abnormal characteristics. |
Resource 7 is possibly compressed or encrypted.
Resource 8 is possibly compressed or encrypted.
Resource 9 is possibly compressed or encrypted.
Resource 10 is possibly compressed or encrypted.
Resource 11 is possibly compressed or encrypted.
Resource 12 is possibly compressed or encrypted.
Resource 313 is possibly compressed or encrypted.
Resource SCRIPT is possibly compressed or encrypted.
|
Malicious |
VirusTotal score: 15/72 (Scanned on 2024-03-22 08:26:28) |
APEX:
Malicious
AVG:
Script:SNH-gen [Trj]
Antiy-AVL:
Trojan[Packed]/Win32.Autoit
Avast:
Script:SNH-gen [Trj]
Bkav:
W32.AIDetectMalware
DeepInstinct:
MALICIOUS
FireEye:
Generic.mg.86bfedca5f8bb667
Fortinet:
W32/PossibleThreat
MaxSecure:
Trojan.Malware.3411146.susgen
McAfee:
Artemis!86BFEDCA5F8B
Sangfor:
Trojan.Win32.Agent.V5c8
SentinelOne:
Static AI - Malicious PE
Skyhigh:
BehavesLike.Win32.TrojanAitInject.hc
Trapmine:
malicious.high.ml.score
tehtris:
Generic.Malware
|
MD5 |
86bfedca5f8bb6679b6ad9a19bec93cb
|
SHA1 |
e902d25fb3c5a3509dedcc6fae725af281d3ee34
|
SHA256 |
61c5ece3b7f78f32ec41fc02c10b4ca4e619962e1a58b173d6295d407ca5f956
|
SHA3 |
fbcba1bb1c04cb0a527ffa6ff278e73b34af3141aa736110dbb1a10b31cacb4e
|
SSDeep |
12288:qozGdX0M4ornOmZIzfMwHHQmRROXKWEIbiQyFR8:q4GHnhIzOaWEFVFG
|
Imports Hash |
fc6683d30d9f25244a50fd5357825e79
|
e_magic |
MZ
|
e_cblp |
0x90
|
e_cp |
0x3
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0x110
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
3
|
TimeDateStamp |
2017-Dec-26 10:04:58
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic |
PE32
|
LinkerVersion |
12.0
|
SizeOfCode |
0x56000
|
SizeOfInitializedData |
0x27000
|
SizeOfUninitializedData |
0xa8000
|
AddressOfEntryPoint |
0x000FE9D0 (Section: UPX1)
|
BaseOfCode |
0xa9000
|
BaseOfData |
0xff000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
5.1
|
ImageVersion |
0.0
|
SubsystemVersion |
5.1
|
Win32VersionValue |
0
|
SizeOfImage |
0x126000
|
SizeOfHeaders |
0x1000
|
Checksum |
0
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x400000
|
SizeofStackCommit |
0x1000
|
SizeofHeapReserve |
0x400000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0xa8000
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
a63b9be855a207504ec393bcbbaf79cb
|
SHA1 |
75475f7e9b97397fff0c2e9641c24e4219ece0b6
|
SHA256 |
c92d0c6e17a7a2a2444bf42c8995ddc8cd13a50f84296ff1744fabf4d625abfc
|
SHA3 |
29664e21026daa3c1c86737e38550a84734a6ddfcb7a5b6a14daa328a89d5076
|
VirtualSize |
0x56000
|
VirtualAddress |
0xa9000
|
SizeOfRawData |
0x55c00
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.93721
|
MD5 |
9fc3d30211f6b259ff65b42e4deb6336
|
SHA1 |
d12c098e4f80a7bca26a8fe93476db87c6afe92f
|
SHA256 |
227813ab4c791d2896ad49309bdc4d424a1ffe4a8ee90b7ab57fa45611243622
|
SHA3 |
6b7a5fa0f28c47fb8d5106b9ede130ab1dab7c5ff1e90c73f897d28db9c4b4ba
|
VirtualSize |
0x27000
|
VirtualAddress |
0xff000
|
SizeOfRawData |
0x27000
|
PointerToRawData |
0x56000
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.75443
|
KERNEL32.DLL |
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
|
ADVAPI32.dll |
GetAce
|
COMCTL32.dll |
ImageList_Remove
|
COMDLG32.dll |
GetOpenFileNameW
|
GDI32.dll |
LineTo
|
IPHLPAPI.DLL |
IcmpSendEcho
|
MPR.dll |
WNetUseConnectionW
|
ole32.dll |
CoGetObject
|
OLEAUT32.dll |
VariantInit
|
PSAPI.DLL |
GetProcessMemoryInfo
|
SHELL32.dll |
DragFinish
|
USER32.dll |
GetDC
|
USERENV.dll |
LoadUserProfileW
|
UxTheme.dll |
IsThemeActive
|
VERSION.dll |
VerQueryValueW
|
WININET.dll |
FtpOpenFileW
|
WINMM.dll |
timeGetTime
|
WSOCK32.dll |
connect
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.66371
|
MD5 |
d6f27bf763eb666af934477958acf362
|
SHA1 |
f724ee386cda31b32b5c88e08b9abf562c016a57
|
SHA256 |
62ba0b2575098d4428c9a99bd060ef7572071698bf9d03b4bd430f5f691378e5
|
SHA3 |
6f4a250c7a91ddfcc872e14b8ed1e4aa33a5ebb3280f7d021b47aa46edfb9586
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.05883
|
MD5 |
78f30e363a0499f530d057b4d639d36e
|
SHA1 |
360bd6476101b0cddc23d2c7eade326c1b16ceaf
|
SHA256 |
08bcba5aa989c988ea18f8101c84daaee58d4f0b584535a85186c8b98b66147e
|
SHA3 |
001ac9f6e8e52f9c3eb7101189fb953e2f4babfdea5b6e26b23b99173af38de4
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.25499
|
MD5 |
ad424f5f5d5ff4460343686c61e4f75e
|
SHA1 |
29a1f0faadc42f1b9f9767d8c724fdc58dd165c8
|
SHA256 |
245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9
|
SHA3 |
4f3a627ee7d533397f7f5c70bb2dafa8857150e674cb31edd96949c7905de509
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x2e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.65355
|
MD5 |
60719bac037d0712f35c5c90be495c9d
|
SHA1 |
a3041d7ee6ba7615452806f77a1c943595c21191
|
SHA256 |
30d1e986d0b31def6f13e53ff02c031bfbefcf963d61d5ad650b172ad7e860c7
|
SHA3 |
20b10baff88665c15ede11f5f30b5422805da2105be8358b0a1b3a41e89b13c6
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.43704
|
MD5 |
982c00bdd1b0ecc4c6ae5e68d8f1b87a
|
SHA1 |
489bbfba215b27140f141a2f394b0e65062cf357
|
SHA256 |
4035501adf394316fef967f0a20eedbf34126242bbeb9cbaad501af59aebd797
|
SHA3 |
84b3279e6fdd3055caf0f08cad67c578b24c6efc055823442d2d8a2f4a3cf547
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0xea8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
4.16139
|
MD5 |
9366bb6f5fa80ec08957cad372d3facc
|
SHA1 |
16ceb7528f7b4306ecc56beb210331e415759c79
|
SHA256 |
7b310c0be8d06ce48affcc4f9aed1c0d788031b2a2f4ae57b69b66234a20d812
|
SHA3 |
471da3b7ffcb18564e3e4540ccbf2367ea343c40f28eab72e41caa70f1cd8871
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x8a8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
4.07494
|
MD5 |
82837923a319386e182d74bceffdcd9a
|
SHA1 |
23bef5e2545d16d60bd84c8dc592698c6d6e9ca5
|
SHA256 |
34b88a55636fba814081ad56bda0f029a6a48647de3c0aa7c01ed483e8829832
|
SHA3 |
082d792ee6346e3ba3fcbc617a8365f6f5a4a32d518afee86445eef4fdfb5eca
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x568
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.18302
|
MD5 |
68d9845aa5d81b5ec9af61f410e35b16
|
SHA1 |
792b2a2e934bea082f9fa18aecc9cf7c56fec0cb
|
SHA256 |
e3462f80eb7b3b4010ea0ab4fb82033a565632230555ec565e1ee7ae8c01c04f
|
SHA3 |
3fbf18c6eae48b380506d26d691dd958d8d6c215e0c66402ea65e822fafc4da1
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x25a8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
4.52312
|
MD5 |
2a1613d0845d00b916aa58adf0d41788
|
SHA1 |
9b80e5a340e2b46e6c1d1f5cdc71f70987a6362e
|
SHA256 |
c3a9d3b89fe9d0197f5d20a9a00f2e69c9218c57b95f21bd16d193d264725d1d
|
SHA3 |
6be13a8f2c46fc7d016e5e1338619a9c6aab8a2538fb392ad95ca1860d53663d
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x10a8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
4.65168
|
MD5 |
9ea19e6905b73670bf173b6ed270f52d
|
SHA1 |
0990bc33abfc67bf30fa225c39caac330248ce4e
|
SHA256 |
1d07a182ee09e1ae5120d258c03c8cdd17797e00bca1e3c4d923b03c37c7cf1a
|
SHA3 |
6f95f1bd2ea42683b37b905d1215789ccae50a552cdf454d0f859234f5789216
|
Type |
RT_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x468
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
4.39178
|
MD5 |
37ead5d2c4490f465242d3a884f19c37
|
SHA1 |
144dbce865b6cfccb00c3a1f2767639b166d90c7
|
SHA256 |
e11a688c6e3fecdb7bcdccaa350aa6fb9bffa50e81751ce4c38b6a26db692634
|
SHA3 |
97917334c00067d77ca349a361aeb6c9408e4dfda72615f0735be852c777ccf0
|
Type |
RT_MENU
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x50
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
6.00306
|
MD5 |
01db856c49c8b0080f30d28c082465f3
|
SHA1 |
6cf2082937601a693843328740ad5ae2e08dbf7b
|
SHA256 |
7ff33827c18751a0b6e792198bb0d13ab684afd2cb29b4a1a973af2ac4a10af9
|
SHA3 |
34e367c79b236f0efccfab25d7541651770a62fe58e1fe0e7cd3ba64ed3b6cf3
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x594
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.77937
|
MD5 |
587cb61e4322e7e6050f762e027fcc16
|
SHA1 |
bcc4c0a606821a7527298c71b550d7270edc5eeb
|
SHA256 |
a15d84882e6bce5712db514cb300c891952a8543cb4bf615d83f33000a49f158
|
SHA3 |
e1bd9ff13c039bdc6b62506c183a4f1abd7f30896a8787f9960e5fae256a2eec
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x68a
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.82744
|
MD5 |
8a436008bf0c608d75b04addbb1ffa7d
|
SHA1 |
9054f77f80b46f2eb99dc200cfb142360d4806df
|
SHA256 |
cf2c4ee873a376e2328990945774257b0452f6c97f663fc0d237206c82cff669
|
SHA3 |
656bf40a8c93a132a55ce2dd6191f51ab96d8ae468c76c7eb7810d9b4430df84
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x490
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.78161
|
MD5 |
34f1ac2c6163cf690034c321fd244e32
|
SHA1 |
8c4e8c15e149948dc3ea09a5485b043161837f2a
|
SHA256 |
592067e15875fcfe0bde30bdb7883ffa0b795e31bce87c495b8817215c269b80
|
SHA3 |
c3f85e2bb99824b34e08e61a8c414d73371d71fcba2e111abe240fc0336a2ea8
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x5fc
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.79327
|
MD5 |
9f65e8b37cceda777e0a98b7a02d5c34
|
SHA1 |
3d8704a3a693852c10aa919a712bb4baf107b8cd
|
SHA256 |
89f0006dc45e4328f395f91ae3801325f90af1e3cc3075f2dd35c555ae72ea99
|
SHA3 |
ee8bf5517141b363f960333801b14b5a770369c20a1eb1b4ceee347c2c810a8c
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x65c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.7708
|
MD5 |
f4af699dced110103c5f79e3189de2a9
|
SHA1 |
ab6fd0966c635533f05c9143a89185cebdae3af4
|
SHA256 |
8829299d56064b833419722fb2ed3ff9118b74293ada5731d0666bf505355fee
|
SHA3 |
b5e06e017f524333f99c1fca2277ffb0a4954dd7589f8be14f2e269f27607315
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x466
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.68374
|
MD5 |
672f19916011fe91a2325f5314a5c5bf
|
SHA1 |
035860fc25f6d3e0540fa06e42158531d5639b0c
|
SHA256 |
3f583925020201edcab7584a2fac51db2d551afd3d3c92f9704f9a2f230cec67
|
SHA3 |
22881a93c3d118fef7e32d1e769db4a5a538f9142e4f727b834637e2b0f0107c
|
Type |
RT_STRING
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x158
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.19888
|
MD5 |
f96fae2ae5d3d1aa410e9961d1e9c25c
|
SHA1 |
f6fde1475748e8d2f27f19f8f2689b48e5367ee7
|
SHA256 |
5b07ee07810ee41d4bd059992b2c146afad973be7188f523159cedf189aa7510
|
SHA3 |
2a47df41bec7bf2ff49f1279eb6944632000ee982648fa82f28f21a5fb5ce220
|
Type |
RT_RCDATA
|
Language |
UNKNOWN
|
Codepage |
Latin 1 / Western European
|
Size |
0x20130
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.99875
|
MD5 |
68e708ba58b02fba02117b0b0ee62d83
|
SHA1 |
674c9db909fef8d205143b214f7dc41687819bf4
|
SHA256 |
6e1c3b01c2bc5a9efe39795d70b4737e735fb138b5dfc3cf9c4c6be672e47ffe
|
SHA3 |
2dcf8347a835c558c9adc8cf76d607a43024611c34c941e1e7bcffc58df73c74
|
Type |
RT_GROUP_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x76
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.8695
|
Detected Filetype |
Icon file
|
MD5 |
c88fc27c85891ac172b4d141b24c12ad
|
SHA1 |
342ea9dc007660254454fef30878c99bb3f9b525
|
SHA256 |
d886ef46aff4ad878304045ca0de6c140dac34f39440a4fa421968522ec6398b
|
SHA3 |
8b6669089819d1c4a15a968c334b83ee57e42664e4d850e8a37e958e1deeb036
|
Type |
RT_GROUP_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x14
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.02322
|
Detected Filetype |
Icon file
|
MD5 |
7a9605cb416b1a091d889b9d9f37ec66
|
SHA1 |
866c01641d672b6cd69901c1e055f174f47b35bb
|
SHA256 |
6bcce1250099cc08d574211b3debabb0244cd2641f6d960538e7ddc97d319164
|
SHA3 |
af43e622bf6c842d1ada2985f8e68920ff7b22d8a0b1a12871968c23b5065651
|
Type |
RT_GROUP_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x14
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
1.84274
|
Detected Filetype |
Icon file
|
MD5 |
f64c60b749269fcf6659c450dda98486
|
SHA1 |
42945c3496bc4e1943a1a05926a9b5ee31d3e450
|
SHA256 |
ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1
|
SHA3 |
443830acdeb37f2b7f844756492b2b11f9fb93e9171617d8c799cebfd05cb37f
|
Type |
RT_GROUP_ICON
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x14
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.02322
|
Detected Filetype |
Icon file
|
MD5 |
60f05e3b8ea9e18928923bdbcc112277
|
SHA1 |
d97726a6e9c326a37507f879feca7e152157839c
|
SHA256 |
7698ef362b288a7e3b96304ca50814b42518cba38598db9dbb36d8b90212d76a
|
SHA3 |
390fd88c6012552aecc7f109e733a1bf00339b8b3758127752832484c9f13ce6
|
Type |
RT_VERSION
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0xdc
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.77862
|
MD5 |
410f594f3ad95b1dd20e08e299b97c51
|
SHA1 |
523aa56f00d4d21ffcbd0f82cda655d88349a740
|
SHA256 |
ebfbc032f504c40d9098735ecfd8c80d996de100b07130e2855b9125e1f57fe5
|
SHA3 |
e785abf691c076cc1fc9cd02b8b7cc3ea433971151b12bd00999ac83071094c5
|
Type |
RT_MANIFEST
|
Language |
English - United Kingdom
|
Codepage |
Latin 1 / Western European
|
Size |
0x3fa
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
5.39264
|
MD5 |
79ff2b6cfbaed20d0761e88f8b47dc80
|
SHA1 |
7ef2897a5a54be6eb3e82c3a936d070dc001e537
|
SHA256 |
2fb51dac382441e19215b5016eddd256a4fdf99d325fe691d77a6e450988ecbe
|
SHA3 |
02bda12ac26ccf7986d96ff43cdceb70ea576bb4a29fba484a5200fb71103412
|
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
0.0.0.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language |
English - United Kingdom
|
Resource LangID |
English - United Kingdom
|
Size |
0x48
|
TimeDateStamp |
1970-Jan-01 00:00:00
|
Version |
0.0
|
GlobalFlagsClear |
(EMPTY)
|
GlobalFlagsSet |
(EMPTY)
|
CriticalSectionDefaultTimeout |
0
|
DeCommitFreeBlockThreshold |
0
|
DeCommitTotalFreeThreshold |
0
|
LockPrefixTable |
0
|
MaximumAllocationSize |
0
|
VirtualMemoryThreshold |
0
|
ProcessAffinityMask |
0
|
ProcessHeapFlags |
(EMPTY)
|
CSDVersion |
0
|
Reserved1 |
0
|
EditList |
0
|
SecurityCookie |
0x4bed50
|
SEHandlerTable |
0
|
SEHandlerCount |
0
|
XOR Key |
0xc1fc1252
|
Unmarked objects |
0
|
C++ objects (20806) |
2
|
199 (41118) |
1
|
ASM objects (VS2013 build 21005) |
51
|
C objects (VS2013 build 21005) |
177
|
C++ objects (VS2013 build 21005) |
53
|
C objects (VS2008 SP1 build 30729) |
9
|
Imports (VS2008 SP1 build 30729) |
37
|
Total imports |
544
|
234 (VS2013 UPD5 build 40629) |
80
|
ASM objects (VS2013 UPD5 build 40629) |
1
|
Resource objects (VS2013 build 21005) |
1
|
151 |
1
|
Linker (VS2013 UPD5 build 40629) |
1
|
[*] Warning: Section UPX0 has a size of 0!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!
[*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8!