02e8a01d6f45a8ee3044d82279d5fb28

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-22 18:20:43
Detected languages English - United States
Debug artifacts W:\Work2\Common\CrashRpt_v.1.4.3_r1645\x64\Release\CrashSender1403.pdb
FileDescription Crash Report Delivery Module
FileVersion 1.4.0.3
InternalName CrashSender
LegalCopyright Copyright 2003-2013 The CrashRpt Project Authors
OriginalFilename CrashSender.exe
ProductName CrashRpt
ProductVersion 1.4.0.3

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • code.google.com
  • google.com
  • hotmail.com
  • http://code.google.com
  • http://code.google.com/p/crashrpt/wiki/FAQ
  • http://www.winimage.com
  • http://www.winimage.com/zLibDll
  • winimage.com
  • www.winimage.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegDeleteValueW
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegSetValueExW
  • RegEnumValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
  • RegQueryValueExW
  • RegOpenKeyExW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Has Internet access capabilities:
  • InternetSetOptionW
  • InternetQueryOptionW
  • InternetOpenW
  • InternetWriteFile
  • InternetReadFile
  • InternetConnectW
  • InternetCloseHandle
Leverages the raw socket API to access the Internet:
  • htonl
  • connect
  • closesocket
  • htons
  • inet_addr
  • inet_ntoa
  • send
  • socket
  • gethostbyaddr
  • gethostbyname
  • getservbyport
  • getservbyname
  • WSAStartup
  • WSACleanup
  • WSASetLastError
  • WSAGetLastError
  • ntohs
  • recv
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Manipulates other processes:
  • Process32NextW
  • OpenProcess
  • ReadProcessMemory
  • Process32FirstW
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDC
Info The PE is digitally signed. Signer: FLASH-INTEGRO LLC
Issuer: Sectigo Public Code Signing CA R36
Safe VirusTotal score: 0/72 (Scanned on 2022-11-18 08:34:51) All the AVs think this file is safe.

Hashes

MD5 02e8a01d6f45a8ee3044d82279d5fb28
SHA1 353d41dc0478d6b6ac9af164290424ead51b0fe0
SHA256 5a451420bc0e46ee558c57c854fac4cfbbce1613a53bfc6b283ba14515b7c883
SHA3 253e695be3ff3101d3285abc6ef8fe49c4f40eae345fbfc33936ec1885593b9e
SSDeep 24576:TvYV9VzdcFWq7v8SDar8ob3Zm4iib2jTQtWEaFwnw2U:TvYjYFWq7ESDbob7iibET2M
Imports Hash fabcb48095c657e0ea2238cd24900024

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2021-Sep-22 18:20:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xb5c00
SizeOfInitializedData 0x5b800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000B1F88 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x114000
SizeOfHeaders 0x400
Checksum 0x11975b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 248bb37345be34aed7a60cb0417182a9
SHA1 8b45b1cf8e0c92fb81b2fef4a159da6f6fccaf1c
SHA256 8ee98a2eaace23927f0a7954f41472c8428b77c31283b374b2a962c795056db8
SHA3 9407c4255e70de07a0c57e6fd0ea4e1fc3ec3847b1ec4e1deb973c4f35caa76c
VirtualSize 0xb5b80
VirtualAddress 0x1000
SizeOfRawData 0xb5c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49134

.rdata

MD5 ad8c99ecfb0346bc3c94be1b0c658f5d
SHA1 ea6dd4547ccada88e6d28709c57e22e9f4887702
SHA256 587028fe0d651edaf56495729d8fb01884da8f92ba1ad1bc1cd3fc85e7c7ad87
SHA3 70750648c8910586b42603c7c411f7d7753658f1ef7cb1aeec77018eef800911
VirtualSize 0x39010
VirtualAddress 0xb7000
SizeOfRawData 0x39200
PointerToRawData 0xb6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.66917

.data

MD5 73de73d862e8e0c989fafacb68d34675
SHA1 25a660ee0bfd2937442534795797197783649069
SHA256 98a8b2f72702800785d77196ddfbeeae7fbcd64c8f6cbececbec4ba9a92f92ed
SHA3 3ac1c3df2ccce2ab9d6eed907696c462187f45d34cc8140348f019f4ac3bc623
VirtualSize 0x1f28
VirtualAddress 0xf1000
SizeOfRawData 0x1800
PointerToRawData 0xef200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.03802

.pdata

MD5 7ee0a63e6481ff236411420400e2af14
SHA1 45efe312f9d716215cabb9074283cbdeefa704e0
SHA256 78d45a7fc7a4ff3a788cbeea3928069e208e3bbbd1998f5d73f6bf555afde494
SHA3 7733ed489b8f93835ed2d01522a2e1539a32a8cb494cae204689f0c5b3a666ea
VirtualSize 0x6d74
VirtualAddress 0xf3000
SizeOfRawData 0x6e00
PointerToRawData 0xf0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.97341

.rsrc

MD5 bf7c30f31279e62020059a8099e9caa0
SHA1 fbea1b255af3b886d3419b5ddbc8f14bac82b529
SHA256 18f6b9684ca019df9ddf40458636c782a61dc2168b4066a053ecd77d359443a2
SHA3 98f43cc78210c14ac2b58edebce28c30e1222c894a7ead33130f055b009d13f5
VirtualSize 0x18c30
VirtualAddress 0xfa000
SizeOfRawData 0x18e00
PointerToRawData 0xf7800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.8444

.reloc

MD5 d68f77c64e0f028f861f6419ccee6397
SHA1 ae66c8b8430ab5ada722445ff823148e9ef64efa
SHA256 5c317f137a1ccb3a4c26794b985184a47649ddb9cb14a9f512166795cdbd615b
SHA3 33c9c00722a26843c24f2fdbedc87a082e93de6f4d56f7d9f520d232e0a89af5
VirtualSize 0x8c0
VirtualAddress 0x113000
SizeOfRawData 0xa00
PointerToRawData 0x110600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.11671

Imports

PSAPI.DLL GetProcessMemoryInfo
WS2_32.dll htonl
connect
closesocket
htons
inet_addr
inet_ntoa
send
socket
gethostbyaddr
gethostbyname
getservbyport
getservbyname
WSAStartup
WSACleanup
WSASetLastError
WSAGetLastError
ntohs
recv
DNSAPI.dll DnsQuery_W
DnsFree
WININET.dll InternetSetOptionW
HttpOpenRequestW
HttpSendRequestExW
HttpEndRequestW
HttpQueryInfoW
InternetQueryOptionW
InternetOpenW
InternetWriteFile
InternetReadFile
InternetConnectW
InternetCloseHandle
RPCRT4.dll UuidToStringA
RpcStringFreeA
GDI32.dll CreateHalftonePalette
TextOutW
SetViewportOrgEx
CreateDCW
GetDIBits
GetObjectW
GetDIBColorTable
CreateDIBSection
SetStretchBltMode
StretchBlt
SetDIBits
SelectPalette
SelectClipRgn
SetLayout
CreateCompatibleBitmap
CreateCompatibleDC
CreateFontIndirectW
RealizePalette
DeleteDC
DeleteObject
GetStockObject
SelectObject
SetBkMode
SetTextColor
CreatePen
Polygon
CreateSolidBrush
SetBkColor
BitBlt
CreateFontW
CreatePalette
CreateRectRgn
SHELL32.dll Shell_NotifyIconW
SHGetFileInfoW
ExtractIconW
ShellExecuteW
CommandLineToArgvW
SHGetSpecialFolderPathW
SHFileOperationW
COMDLG32.dll GetSaveFileNameW
GetOpenFileNameW
VERSION.dll VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
KERNEL32.dll Sleep
GlobalUnlock
GlobalLock
GetSystemDirectoryA
LoadLibraryA
GetTimeZoneInformation
VirtualFree
VirtualAlloc
FlushInstructionCache
IsDebuggerPresent
EncodePointer
HeapAlloc
LoadLibraryExA
InitializeCriticalSection
Process32NextW
HeapFree
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetProcessHeap
InitializeSListHead
InterlockedPopEntrySList
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
InterlockedPushEntrySList
CloseHandle
GetSystemInfo
CreateFileMappingW
OpenFileMappingW
MapViewOfFile
UnmapViewOfFile
lstrlenW
CreateDirectoryW
GetFileAttributesW
GetFileAttributesExW
GetTempFileNameW
GetTempPathW
DebugBreak
OutputDebugStringW
GetLastError
FreeLibrary
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
LoadLibraryW
GlobalAlloc
GlobalFree
FormatMessageW
lstrlenA
GetPrivateProfileStringW
WritePrivateProfileStringW
SystemTimeToTzSpecificLocalTime
SystemTimeToFileTime
MultiByteToWideChar
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
SetEvent
ResetEvent
WaitForSingleObject
CreateEventW
WideCharToMultiByte
CreateFileW
FindClose
FindFirstFileW
FindNextFileW
GetFileSizeEx
GetFullPathNameW
SetLastError
GetProcessTimes
OpenProcess
GetSystemTime
ReadProcessMemory
CopyFileW
FileTimeToSystemTime
GetCommandLineW
DecodePointer
RaiseException
GetCurrentThreadId
LoadLibraryExW
LoadResource
SizeofResource
FindResourceW
MulDiv
lstrcmpW
lstrcmpiW
CompareStringW
GetVersionExW
GetFileInformationByHandle
ReadFile
WriteFile
CreateMutexW
GetCurrentProcess
GetCurrentProcessId
TerminateProcess
GetExitCodeProcess
CreateThread
CreateProcessW
CreateToolhelp32Snapshot
Process32FirstW
GetSystemTimeAsFileTime
USER32.dll CallWindowProcW
UnregisterClassW
CreateWindowExW
IsWindow
DestroyWindow
ShowWindow
SetWindowPos
IsWindowVisible
CreateDialogParamW
GetDlgItem
GetDlgCtrlID
SetFocus
GetFocus
GetKeyState
GetCapture
SetCapture
ReleaseCapture
IsWindowEnabled
DrawTextW
UpdateWindow
ReleaseDC
BeginPaint
EndPaint
InvalidateRect
RedrawWindow
GetWindowTextW
GetWindowTextLengthW
SetCursor
GetCursorPos
ScreenToClient
GetSysColor
GetSysColorBrush
DrawFocusRect
FillRect
SetRectEmpty
OffsetRect
PtInRect
GetWindowLongPtrW
SetWindowLongPtrW
GetDesktopWindow
GetParent
GetClassNameW
LoadCursorW
DestroyIcon
LoadImageW
SystemParametersInfoW
EndDialog
GetActiveWindow
SendMessageW
DestroyMenu
EnableMenuItem
GetSubMenu
DeleteMenu
TrackPopupMenu
GetClientRect
SetWindowTextW
CheckMenuRadioItem
MonitorFromPoint
MonitorFromWindow
GetMonitorInfoW
PostQuitMessage
FlashWindow
DialogBoxParamW
EnableWindow
GetMenu
DrawIcon
DrawTextExW
AdjustWindowRectEx
MessageBoxW
CopyRect
LoadIconW
GetIconInfo
IsDialogMessageW
PostMessageW
SetProcessDefaultLayout
CharUpperW
SetTimer
KillTimer
DrawTextExA
SetScrollInfo
GetScrollInfo
AnimateWindow
OpenClipboard
CloseClipboard
SetClipboardData
EmptyClipboard
GetSystemMetrics
IntersectRect
EnumWindows
GetWindowThreadProcessId
EnumDisplayMonitors
GetCursorInfo
PeekMessageW
GetDC
CharNextW
MoveWindow
LoadStringW
SetMenuItemInfoW
DispatchMessageW
TranslateMessage
GetMessageW
DefWindowProcW
GetGuiResources
GetWindow
SetWindowLongW
GetWindowLongW
MapWindowPoints
LoadMenuW
GetWindowRect
ADVAPI32.dll RegCloseKey
RegDeleteValueW
RegEnumKeyExW
RegQueryInfoKeyW
RegSetValueExW
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueW
RegEnumValueW
RegDeleteKeyW
RegCreateKeyExW
RegQueryValueExW
RegOpenKeyExW
ole32.dll CoCreateGuid
CoUninitialize
CoTaskMemAlloc
CoInitialize
CoTaskMemFree
CoTaskMemRealloc
CoCreateInstance
OLEAUT32.dll SysFreeString
VarUI4FromStr
VarDateFromStr
VarR8FromStr
VarDecCmp
VarDecFromStr
VarI4FromStr
COMCTL32.dll ImageList_ReplaceIcon
ImageList_Create
ImageList_Remove
InitCommonControlsEx
_TrackMouseEvent
MSVCP140.dll ?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
VCRUNTIME140.dll memchr
__std_type_info_destroy_list
__intrinsic_setjmp
__current_exception_context
__current_exception
__C_specific_handler
longjmp
strchr
__std_terminate
_purecall
memcmp
wcsstr
wcsrchr
wcschr
memmove
_CxxThrowException
__std_exception_destroy
__std_exception_copy
memset
memcpy
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _execute_onexit_table
_errno
_invalid_parameter_noinfo
terminate
_register_thread_local_exe_atexit_callback
_crt_at_quick_exit
_c_exit
_crt_atexit
_seh_filter_dll
_configure_narrow_argv
_exit
_initialize_narrow_environment
_initterm_e
_initialize_onexit_table
_set_app_type
abort
_seh_filter_exe
_invalid_parameter_noinfo_noreturn
exit
_register_onexit_function
_configure_wide_argv
_initterm
_get_wide_winmain_command_line
_initialize_wide_environment
_cexit
api-ms-win-crt-string-l1-1-0.dll iswdigit
wcscpy_s
strncpy
isspace
strncmp
isalpha
tolower
wcstok_s
toupper
wcscmp
wcscspn
wcslen
strcat_s
strcpy_s
isdigit
wcsncmp
wcspbrk
strlen
strncpy_s
_wcsicmp
strcpy
isalnum
wcsncpy_s
strcmp
iswspace
api-ms-win-crt-heap-l1-1-0.dll _recalloc
malloc
free
calloc
_callnewh
realloc
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll _wtoi
atoi
_wtol
atof
strtoul
strtod
api-ms-win-crt-environment-l1-1-0.dll getenv
_wdupenv_s
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__stdio_common_vsprintf
fflush
__stdio_common_vsnprintf_s
fseek
fopen_s
ferror
fputc
ftell
_set_fmode
__p__commode
tmpfile
rewind
fopen
_wfopen
_ftelli64
_fseeki64
__stdio_common_vsprintf_s
fwrite
fread
feof
__stdio_common_vfwprintf
__stdio_common_vfprintf
fclose
_wfopen_s
__stdio_common_vswprintf_s
__stdio_common_vsscanf
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
_gmtime64_s
strftime
_time64
_gmtime64
wcsftime
api-ms-win-crt-filesystem-l1-1-0.dll _wstat64i32
api-ms-win-crt-utility-l1-1-0.dll rand
srand
labs
qsort
abs
api-ms-win-crt-math-l1-1-0.dll pow
fabs
ceil
__setusermatherr
ceilf
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.66245
MD5 bf7e2ea27aa1ba504088de35c2028d9f
SHA1 97f1668043a5aed8b13554d5babb7a7bbd7f19a6
SHA256 7b8972642c4a0e40c793c4cdff3af987120887d09edbe8e6e44a568b07f3a679
SHA3 02a037692b2f14ee0c4c3f2ab1a257a35092544ef6511d1c138d59096a8b694e

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.62548
MD5 a7be74ffe9d0cc084cd2b0c2b6d64056
SHA1 af56618235c0003dc06f9cfaba559d296fb2e1f4
SHA256 54aa584403bc13a424e33b1eb8b5ba9ee453f29816987951c4fdbb83d3b61c74
SHA3 98e98b125bd44423c13462997df4be0d93e6b0ee4931d880de47e527bed22be1

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9137
MD5 acbd8dfff414bfae090e310b4dc14280
SHA1 7708fbb4a74a777a2e4847297967d254131d5b53
SHA256 67f1839514c376a7a868fd9a030a2333a283ea708228352d0be84002a1d08488
SHA3 20f93cfe52113df86b5832669f6b503b2b0720563065cfb5660bc09e480b23de

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.90985
MD5 dd88d4e06a0d97560dfa9d097ad76127
SHA1 1fc21215047fbd0566c11aa9bdc7dc02e6ccc0d2
SHA256 a4379b766da7b3804c1e7e54d4777c85e4a8aaecfa2add0f39967b437a846251
SHA3 41bb8dc42ebd79517cbfeffba63c35a95ec85db36927aad7ff2449d8e85772e1

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.6666
MD5 d31d9f9440c8d933a9a83beedb660761
SHA1 3d37659a3f809c58f04f45a31c2df0a0a845e6df
SHA256 e5b748bce7ba049f21fb2391eba4ec4320e842757c6f4cce83f754ed81e823a9
SHA3 1d9917549cec9ab49764f32c6d41960e6a81f182806d4b72dcf43ecbc77c8177

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.05702
MD5 d615a0eaf41c664d4c6619c38746151a
SHA1 e5a7deabad11b15b01ff8cb93170e397eb00ee29
SHA256 0c0e61914cfae02cb2b6b512e18eaaf84884fd26bd3c26489f44c76c5c946475
SHA3 af9c20ebcaa64e6ab7e6aa7783d71db15aebf7d6190c9b096eff088f6f713c57

214

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x358
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35352
MD5 ad25c51ae6bfce01b9cc1afc9d7db2f7
SHA1 d6ef8933428ea61ac742a7c91b187bf287a5f30f
SHA256 50a6946e436a7af1db7d2cad6127e39695c13abe0bab08142dffe35ca18a56c8
SHA3 c72e742e9d917ff6ef47f7a3cf4637ecc1743601aa12bfa8bf834794d84c2cac

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x224
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31443
MD5 90e74dddfad6ef149aeb795332c80c48
SHA1 c982921335ade15ad692bb2170d5a534cc30f3a5
SHA256 b790be6e92e6f22d4352a3c705898c163c5c6e7f1032da3ef442cf205771de02
SHA3 e16bc2afb4e9a9442dba85194ec3f3b0d7c73ad98c00a4a2dab2830b088793ed

212

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x620
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36671
MD5 ef0e708c084af2f27e88dc6cbf3b803c
SHA1 accddceba289d8d19835fc0492bbf932a6b88559
SHA256 4496236344b0733ab63e67022f27ec4501a504841a55302b6e50835a7e50d0bd
SHA3 ccdae26c1190da6da0756b6e0097fba027db985dc01febc858a156b9927dc857

213

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x176
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24866
MD5 95b7d2f76641f2a76658bb3dd0c13636
SHA1 4ed3306b3210457b56e42e4582aca34a7972affb
SHA256 cad0c599d2835a85248321e8d24fd1ef9ec9c583a818376b9593f928fa3f3568
SHA3 7f735d5608b4037fef9092e774f84f2d5a59bd8acdbefe019d32192ed865b122

215

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x2d8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37352
MD5 0fadb81ca59f23fe92a3d6c049e7489a
SHA1 a4a16155b0731193f138a3e3b5fc0abdb28c71ca
SHA256 c93457525f46ee0e49218fe08bba8b7348886ffb1263a241ed903b29288353fd
SHA3 07cd6a27d3fe88a497ef585d547cfb7646566ae4fadf75d73ec27d4b571f2885

216

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.156
MD5 d708a4e102602ce2317450a87bb36603
SHA1 3306df6ffa5bfedfdc5e09c8d2e0bf4ee169f703
SHA256 27e951166f855ea16a7333fcf1258fa65eb6a31c0db91a2aeb8ec5d7ebf4c033
SHA3 3919bedb5b8e37257b06a49d1ccacfeb106f9c616630afa9ba040f6c97d565f1

217

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x102
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97411
MD5 98e7fdea1d9e5ad85f12b12619900fb3
SHA1 b75fe4f7e76c8bb9785674946a307dd09a64243f
SHA256 d4c11a7ed24ea24c980f5548492ab991d62c18900c0920e086f2e3eb5058a3c9
SHA3 a4b4f4cf083be1e22c77ae600e64bc1bd0c81db9f54050b88cee36f1af773eef

9

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x36
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.48679
MD5 97acce9c02a068e7defbb2ad246a575b
SHA1 84602fdf39cd3467e9ec76b2825abbb9b9a298f8
SHA256 35b01583d55c9c7874a2445a74b9879ad8d83e98595bb1c9ce0632c34c95e1d9
SHA3 b3d09c5448b736eee49c04e6146a85d56929fc0381efe1117391f386b3be708c

63

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x8a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03671
MD5 0eba987e21aa656da4118e29378c8464
SHA1 f55a870ecd2c41b992b99e803dcc6449727e9062
SHA256 e4febac274ad5873082b4e0a448edb5ca2029113a016721e94b6ec6575f831a4
SHA3 a28077cefd4e2f45b9a9d496a15f6a5a401bdcd7015f7cc2b801e764152305bb

3585

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.960953
MD5 aafa5ef370ac2381a1fd0e31018b4cd8
SHA1 330cc36d16e3f57176bdbfb4d70f28790d34c2f2
SHA256 16152d0e4b46613de57df670b3396bfd8f45877fecfa949f6f33082eaabdace2
SHA3 90bdfd5e7733f55ca1436a4d696fd9951167a524b979d6434b91cc90e23d3da7

3601

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x53e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55011
MD5 d95d68144e6c8504ad44b4eb8a2f1644
SHA1 1442ec96a96650c96be1d31bb594f590ebc7d1ff
SHA256 08fe21635d1a47813865b5ea24464c530776b8ebc544a67c3c21e9ccca9554bb
SHA3 e09111c997a781f509b7907f3aea4236ff070d8cf00b028355bae59744553624

3603

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x328
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19961
MD5 7d399439e7b818bb49bfd91f785c3f11
SHA1 95b21eddefe681749a89915bbeca3f20fd12a64d
SHA256 fc3f6f769e88ce894bba9f4078aaea4a47db8284f3fafb6ff844f8a5406feaba
SHA3 5ee8b07ab8ecb2df03557d64bc9f8ab6691f473f340ab7b81c13fc2e489318b2

3604

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x27c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14802
MD5 6db7537e63cb311e34ad0a04e6cd1389
SHA1 451b45265229cbeabd40ea0742094c061d25df41
SHA256 037d278a2fd218fdc53acb609b840b64c1512caef97e6dba2c809ac931539826
SHA3 b685ab446c3d0ae398fa3ec00af267482281865bc2e744891f5075c566ed62bf

3605

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x106
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99043
MD5 fec8e1b460825c18cb521771be463033
SHA1 da23982da2da4da2f37eaaab723615d20a035b61
SHA256 5b8e0bfb7c789c6bfdc4be2af9f36346c0e41e7ad22c8edcc661af0e8b53dbd2
SHA3 7b86c6cd1a0a3df09d80db4ebaa5fb785da3df9228b39db214233545ba4d745f

3606

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83557
MD5 2a450fc19a27fc2e3c519b56c448763f
SHA1 c5fff493b3264c9058855d1642e146f4a6cf66e0
SHA256 f4d2054bad5a30d07ffde08fafdf7a0deed4e343526816a67ecbbd068b84ad81
SHA3 612c621a553741864d1b823de4ac6aa953fceb8ad68f7ec419ca4dd035f5db1b

3825

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x1f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04777
MD5 e0d2d9d8a0bf3bbd508e8282f458cdec
SHA1 9ac6aeaed327d8cbfec6a735f700676a8bc01607
SHA256 0cce65df387f67147c75ac921bc6512fb5fc8dc86d3a60a2e0c2ba2d4845539b
SHA3 2beb42630a13e63841d88462346139c8690eab66df2f0da4fd53a96e753a9d6c

3826

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77295
MD5 1395536b8eeb3e9a41172fc129faa8e9
SHA1 fa92508a54f1eb856881a9311c167310102e8805
SHA256 1981ad13f198af2761bff700f4efe7ec35f717041f9290b5005a22a07c6b45d9
SHA3 d66127cdc3524b2cace7fcba1ee625b207f08af062c28d504a52c48d034647fb

3838

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x44
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.92392
MD5 af6d78d601d2232fb1459c98ad905312
SHA1 45669d5630d6f4f44bda1da7b78c31c91e5c2749
SHA256 9e6c52a92a02ae957fecfc81726b6a5a93b5c687f57d2985fc2b66ef3be215b8
SHA3 2fdd97d5d26dc1590a151fa178dc5481e5f45bba9fdf5df93ad23676d90e159f

128

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0x70
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94747
MD5 0b4f5e6c2b2423486088a8e08e184edb
SHA1 2cec5761667eb71ef78d1ab3704fe09235ee54f4
SHA256 6913343cd8c147d53027bf3e8693e6553c4eab0e623a65e0b96e7c2179558f9a
SHA3 a6cbca1b1b0d1a4d4c7a97a099b6a7fc381f4e432d441296e7930a70dd816dba

128 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62308
Detected Filetype Icon file
MD5 5c84b5099ac46312565be1aa2e21eff0
SHA1 25f00759b0e6641f9b423e6a52556c2e4e2796c3
SHA256 816cc8c77a0adb35a7432b2bac047e9834bfd21b0ef96c612e5f8bc4f0986620
SHA3 17e6deff600599725f4cf3c95b7472cf6ca993cdc40907ae04b6209f5619547f

218

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.51432
Detected Filetype Icon file
MD5 eadb7c1258c2d4ef58364d63d8ed92e9
SHA1 2f89b195c63902cfc79b186bfccac0b673dd8fdd
SHA256 4f30564778fe75138c2241026c4b8199d71ab3532b04daa93e2af2c9c85df261
SHA3 e489d4e77fc4b93269dcf895712378d49bdc7b58841e0b57aaf0f38d415b242f

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41257
MD5 e59e301161e40102f4e60b023e53b29f
SHA1 7a8e2dc66f8c8ea404a6ccc914a6a8a0a5d3d722
SHA256 bc59eb81e0102bffbd3ef5ea07b37fbe190f5ead81079e6445627d7bf1d48737
SHA3 f3162afe6b58d40b5a81f8265989de2ea041692d0b85aa2711e4536903db5f39

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x282
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.0672
MD5 b2ced3969f764cf58d1e3f898073333a
SHA1 d4e26a5bc1ae0f1b8c21554308ee5a20614e6a56
SHA256 1d8a782b70eaa4d474727b0c68e8dfb3105966bac2fd3ed0c23df96388957674
SHA3 ce1e576a590d4453de91b4877643a36e09055955d3cca3f8571b549853470182

String Table contents

CrashSender
Name
Description
Type
Size
Crash Dump
Crash Log
Symbol File
Ready
Create a new document
New
Open an existing document
Open
Close the active document
Close
Save the active document
Save
Save the active document with a new name
Save As
Change the printing options
Page Setup
Change the printer and printing options
Print Setup
Print the active document
Print
Display full pages
Print Preview
{\bnsi\bnsicpg1252\deff0\deflang1033{\fonttbl{\f0\fswiss\fcharset0 Microsoft Sans Serif;}}
{\*\generator Msftedit 5.41.15.1503;}\viewkind4\uc1\pard\f0\fs30 %s has stopped working}
Please enter a valid E-mail address. For example, name@hotmail.com.
Zip Files (*.zip)
Content-Type: Multipart/form-data; boundary=%s
-----------------7d31389b0426
Erase the selection
Erase
Erase everything
Erase All
Copy the selection and put it on the Clipboard
Copy
Cut the selection and put it on the Clipboard
Cut
Find the specified text
Find
Insert Clipboard contents
Paste
Repeat the last action
Repeat
Replace specific text with different text
Replace
Select the entire document
Select All
Undo the last action
Undo
Redo the previously undone action
Redo
Open another window for the active document
New Window
Arrange icons at the bottom of the window
Arrange Icons
Arrange windows so they overlap
Cascade Windows
Arrange windows as non-overlapping tiles
Tile Windows
Arrange windows as non-overlapping tiles
Tile Windows
Split the active window into panes
Split
Display program information, version number and copyright
About
Quit the application; prompts to save documents
Exit
Switch to the next window pane
Next Pane
Switch back to the previous window pane
Previous Pane
Change the window size
Change the window position
Reduce the window to an icon
Enlarge the window to full size
Switch to the next document window
Switch to the previous document window
Close the active window and prompts to save the documents
Restore the window to normal size
Activate Task List
Activate this window
Open this document

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.4.0.3
ProductVersion 1.4.0.3
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
FileDescription Crash Report Delivery Module
FileVersion (#2) 1.4.0.3
InternalName CrashSender
LegalCopyright Copyright 2003-2013 The CrashRpt Project Authors
OriginalFilename CrashSender.exe
ProductName CrashRpt
ProductVersion (#2) 1.4.0.3
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2021-Sep-22 18:20:43
Version 0.0
SizeofData 95
AddressOfRawData 0xdf2bc
PointerToRawData 0xde2bc
Referenced File W:\Work2\Common\CrashRpt_v.1.4.3_r1645\x64\Release\CrashSender1403.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2021-Sep-22 18:20:43
Version 0.0
SizeofData 20
AddressOfRawData 0xdf31c
PointerToRawData 0xde31c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Sep-22 18:20:43
Version 0.0
SizeofData 904
AddressOfRawData 0xdf330
PointerToRawData 0xde330

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400f10c8

RICH Header

XOR Key 0x655f6721
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (28518) 1
C objects (30034) 10
ASM objects (30034) 4
Imports (30034) 6
C++ objects (30034) 36
C objects (27412) 1
Imports (27412) 31
Total imports 457
C objects (LTCG) (VS2019 Update 11 (16.11.0-3) compiler 30133) 96
C++ objects (VS2019 Update 11 (16.11.0-3) compiler 30133) 20
Resource objects (VS2019 Update 11 (16.11.0-3) compiler 30133) 1
151 1
Linker (VS2019 Update 11 (16.11.0-3) compiler 30133) 1

Errors

<-- -->