1386b9a87bbd39ef0d72093e97f30d52

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2007-Jul-23 09:57:38
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8.0
MASM/TASM - sig1(h)
MSVC++ v.8 (procedure 1 recognized - h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to internet browsers:
  • firefox.exe
  • iexplore.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • ardamax.com
  • http://www.ardamax.com
  • http://www.ardamax.com/keylogger/banned.html
  • http://www.ardamax.com/keylogger/purchase.html
  • www.ardamax.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowW
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegisterHotKey
Possibly launches other programs:
  • ShellExecuteW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
  • CreateFileA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • CallNextHookEx
  • MapVirtualKeyW
Has Internet access capabilities:
  • InternetGetLastResponseInfoW
  • InternetCloseHandle
  • InternetConnectW
  • InternetOpenW
Leverages the raw socket API to access the Internet:
  • #16
  • #19
  • #115
  • #9
  • #116
  • #55
  • #11
  • #52
  • #23
  • #3
  • #22
  • #18
  • #4
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Can take screenshots:
  • FindWindowW
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 27/45 (Scanned on 2012-12-24 14:35:16) MicroWorld-eScan: Application.Keylog.Ardamax.AD
McAfee: Keylog-Ardamax
K7AntiVirus: Riskware
NANO-Antivirus: Riskware.Win32.Ardamax.bojfh
Symantec: Spyware.Ardakey
Norman: W32/Obfuscated.C2!genr
Avast: Win32:Ardamax-KB [Spy]
ClamAV: Trojan.Spy.Ardamax-27
Kaspersky: not-a-virus:Monitor.Win32.Ardamax.bm
BitDefender: Application.Keylog.Ardamax.AD
SUPERAntiSpyware: Keylogger.Ardamax
Sophos: Ardamax
Comodo: Application.Win32.Monitor.Ardamax.~OI
F-Secure: Application.Keylog.Ardamax
VIPRE: Trojan.Win32.Generic.pak!cobra
AntiVir: TR/Spy.Ardamax.J
McAfee-GW-Edition: Keylog-Ardamax
Emsisoft: Application.Keylog.Ardamax.AD (B)
Jiangmin: TrojanSpy.Ardamax.awy
Microsoft: MonitoringTool:Win32/Ardamax
GData: Application.Keylog.Ardamax.AD
PCTools: 132
ESET-NOD32: a variant of Win32/KeyLogger.Ardamax.NAY
Rising: Trojan.Win32.Generic.12BD6759
Ikarus: Trojan-Spy.Ardamax.J
AVG: Ardamax.ML
Panda: Trj/CI.A

Hashes

MD5 1386b9a87bbd39ef0d72093e97f30d52
SHA1 0ed965454668c98a06fc2e7c90c5621662c23257
SHA256 9778f4959da49a5245857d9b7696cb887aba7564dbb80ccc0e74d3adb7cffdab
SHA3 173e134920401be91799c87053e2f2c9925c430008b00618aa4ab0005736c385
SSDeep 6144:fiCEwGq+0cmXdVbAgX4ijgF9ABiNXCbL/WVnNLpcPAa:PXGeXdVGKgF928a
Imports Hash 7577ce676514cb8115208fd948340902

DOS Header

e_magic MZ
e_cblp 0x45
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xc0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2007-Jul-23 09:57:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 8.0
SizeOfCode 0x58600
SizeOfInitializedData 0x1d800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00027C79 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x5a000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x7b000
SizeOfHeaders 0x400
Checksum 0x82db9
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c162ea878fb7c88bd2c51abe893a73c8
SHA1 f2c1588dd65c4be7d60cbbef7d700293a9408848
SHA256 081aeaf2340a178f43d90c0345076d52b97a77e2cf5e09589c1463cabe9fc252
SHA3 aead420ff454c0d8fe40a13e205dfbdb4de10bf3e5b9814d5cd9f2ae60c9fd88
VirtualSize 0x5854d
VirtualAddress 0x1000
SizeOfRawData 0x58600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66613

.rdata

MD5 fe6601e87a3a1a6118edea0a02096922
SHA1 10b91bb370cf15a8fc6864218e8ae7cbc0e335c6
SHA256 31f0e2633a08443bd5752074da732824f4ee45f6ef13dd8aa0d3114d41d5eedf
SHA3 d75ccf81d82515682f15489bd0e66f505839414437909d9394ecfccd2ed1c7cf
VirtualSize 0xf6f0
VirtualAddress 0x5a000
SizeOfRawData 0xf800
PointerToRawData 0x58a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.66243

.data

MD5 7020e936214a6d48f5c634893179bd5d
SHA1 ead2b09a057c2a30a1068fc10316f8a293edaa8e
SHA256 67c5daa055596a3a56194e10e171aedb572fa7f5206e7222b766eb1f0c3f9e6b
SHA3 9b2ce0797fe6270b68d4b69b2d8cdd159b2a1de2c6a3c2a866d2761345b495af
VirtualSize 0x4f20
VirtualAddress 0x6a000
SizeOfRawData 0x2200
PointerToRawData 0x68200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.71747

.rsrc

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xbdf0
VirtualAddress 0x6f000
SizeOfRawData 0xbe00
PointerToRawData 0x6a400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

Imports

SHLWAPI.dll UrlUnescapeW
StrDupW
PathRemoveExtensionW
PathStripPathW
PathRemoveFileSpecW
PathFindExtensionW
PathFindFileNameW
PathFileExistsW
StrCmpIW
StrFormatByteSizeW
WS2_32.dll #16
#19
#115
#9
#116
#55
#11
#52
#23
#3
#22
#18
#4
COMCTL32.dll InitCommonControlsEx
ImageList_Draw
ImageList_Create
ImageList_ReplaceIcon
CreatePropertySheetPageW
PropertySheetW
DestroyPropertySheetPage
ImageList_LoadImageW
ImageList_Destroy
ImageList_GetImageCount
_TrackMouseEvent
SHELL32.dll SHChangeNotify
ShellExecuteExW
SHFileOperationW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
Shell_NotifyIconW
ExtractIconW
DoEnvironmentSubstW
ShellExecuteW
WININET.dll InternetGetLastResponseInfoW
InternetCloseHandle
FtpPutFileW
FtpCreateDirectoryW
FtpRemoveDirectoryW
FtpDeleteFileW
FtpSetCurrentDirectoryW
InternetConnectW
InternetOpenW
MPR.dll WNetCancelConnection2W
WNetAddConnection2W
KERNEL32.dll GetStringTypeW
GetThreadLocale
IsProcessorFeaturePresent
InterlockedCompareExchange
SetEnvironmentVariableA
CompareStringA
lstrcpyW
lstrlenW
CreateFileW
lstrcmpW
DeleteFileW
SetLastError
GetModuleHandleW
GetProcAddress
lstrlenA
lstrcpyA
lstrcmpA
LoadLibraryW
GetVersion
MultiByteToWideChar
WideCharToMultiByte
FreeLibrary
CloseHandle
WriteFile
lstrcmpiW
GetDateFormatW
FindResourceExW
Sleep
VirtualAlloc
VirtualFree
GetSystemTimeAsFileTime
OpenProcess
SetProcessWorkingSetSize
GetCurrentProcess
GlobalLock
GlobalUnlock
lstrcpynW
lstrcatW
RemoveDirectoryW
CreateDirectoryW
SetFileAttributesW
CreateThread
SetThreadPriority
ResumeThread
GetLocalTime
SystemTimeToFileTime
CompareFileTime
GetModuleFileNameW
GetShortPathNameW
GetEnvironmentVariableW
SetPriorityClass
GetCurrentThread
SetProcessPriorityBoost
MoveFileExW
ExitProcess
GetCurrentProcessId
CreateMutexW
GetLastError
InitializeCriticalSection
RaiseException
FlushInstructionCache
LockResource
InterlockedIncrement
InterlockedDecrement
SizeofResource
LoadResource
FindResourceW
LoadLibraryExW
DeleteCriticalSection
CompareStringW
GetCurrentThreadId
LeaveCriticalSection
EnterCriticalSection
GetVersionExW
EnumResourceNamesW
LocalAlloc
LocalReAlloc
ReadFile
BeginUpdateResourceW
UpdateResourceW
EndUpdateResourceW
SetFilePointer
LocalFree
CreateToolhelp32Snapshot
Module32FirstW
Module32NextW
Process32FirstW
Process32NextW
GetWindowsDirectoryW
GetFileSize
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
SetEndOfFile
FormatMessageW
GetTimeZoneInformation
GetTimeFormatW
GetTickCount
OutputDebugStringW
GetComputerNameW
lstrcmpiA
CopyFileW
GetTempFileNameW
GetTempPathW
FileTimeToSystemTime
FileTimeToLocalFileTime
GetFileAttributesW
MoveFileW
HeapFree
HeapAlloc
HeapReAlloc
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetVersionExA
GetProcessHeap
GetStartupInfoW
HeapDestroy
HeapCreate
GetModuleHandleA
GetStdHandle
GetModuleFileNameA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
HeapSize
GetCPInfo
GetACP
GetOEMCP
GetTimeFormatA
GetDateFormatA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
RtlUnwind
InterlockedExchange
LoadLibraryA
GetConsoleCP
GetConsoleMode
GetLocaleInfoA
LCMapStringA
LCMapStringW
GetStringTypeA
VirtualQuery
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
FlushFileBuffers
USER32.dll ScrollWindow
MoveWindow
GetWindowRect
BeginPaint
EndPaint
GetDlgItem
DestroyIcon
EndDialog
RegisterWindowMessageW
GetAncestor
SendMessageTimeoutW
GetWindowTextLengthW
GetWindowTextW
SendMessageW
DdeInitializeW
DdeCreateStringHandleW
DdeConnect
DdeClientTransaction
DdeAccessData
DdeDisconnect
DdeFreeStringHandle
DdeUninitialize
GetWindowThreadProcessId
GetWindowModuleFileNameW
GetDlgCtrlID
IsWindowVisible
GetClassNameW
GetWindow
EnumWindows
SetClipboardViewer
ChangeClipboardChain
IsClipboardFormatAvailable
OpenClipboard
GetClipboardData
CloseClipboard
IsWindow
PostQuitMessage
GetCursorPos
SetForegroundWindow
FindWindowW
RegisterHotKey
UnregisterHotKey
GetDesktopWindow
GetForegroundWindow
GetWindowDC
DispatchMessageW
TranslateMessage
GetMessageW
DefWindowProcW
DrawFocusRect
SetRectEmpty
DeleteMenu
CheckMenuItem
GetSubMenu
LoadMenuW
LoadIconW
CallWindowProcW
DialogBoxParamW
InvalidateRect
SetWindowPos
GetMenu
AdjustWindowRectEx
RegisterClassExW
GetClassInfoExW
DestroyWindow
IsMenu
DestroyMenu
GetMenuItemCount
GetMenuItemInfoW
SetMenuItemInfoW
UpdateWindow
GetParent
GetClientRect
LoadStringW
CharNextW
DrawTextW
GetClassLongW
SetWindowLongW
ReleaseDC
SetCursor
LoadCursorW
GetSysColorBrush
SystemParametersInfoW
GetWindowLongW
InflateRect
DrawFrameControl
CreateWindowExW
SetDlgItemInt
ReleaseCapture
GetCapture
SetCapture
ScreenToClient
WindowFromPoint
GetMessagePos
GetKeyState
FrameRect
OffsetRect
DrawEdge
IsWindowEnabled
CharLowerW
PeekMessageW
PtInRect
GetFocus
ModifyMenuW
TrackPopupMenuEx
GetMonitorInfoW
MonitorFromPoint
MapWindowPoints
FillRect
UnhookWindowsHookEx
CallNextHookEx
SetWindowsHookExW
wsprintfW
MapVirtualKeyW
GetKeyNameTextW
UnregisterClassA
CopyRect
GetSystemMetrics
GetSysColor
TrackPopupMenu
MessageBoxW
LoadImageW
PostMessageW
KillTimer
SetTimer
GetDC
GetActiveWindow
EnableWindow
SetWindowTextW
SetDlgItemTextW
GetDlgItemInt
ShowWindow
GetDlgItemTextW
SetFocus
MessageBeep
GDI32.dll GetObjectW
CreateFontIndirectW
DeleteObject
PatBlt
CreateDIBSection
CreateCompatibleDC
SetBkColor
BitBlt
DeleteDC
CreateCompatibleBitmap
CreatePatternBrush
SetBrushOrgEx
GetDIBits
CreatePen
RealizePalette
CreateBitmap
GetTextMetricsW
CreateRectRgnIndirect
CombineRgn
ExcludeClipRect
SetTextColor
GetStockObject
CreateSolidBrush
CreateFontW
TextOutW
Polygon
SetPolyFillMode
SetBkMode
SelectObject
GetTextExtentPoint32W
comdlg32.dll GetSaveFileNameW
GetOpenFileNameW
ole32.dll CoTaskMemFree
CoCreateInstance
CoUninitialize
CoTaskMemAlloc
CoTaskMemRealloc
CoInitialize
OLEAUT32.dll #277
#6
UxTheme.dll (delay-loaded) GetThemeInt
DrawThemeBackground
OpenThemeData
CloseThemeData
GetThemeBackgroundContentRect

Delayed Imports

Attributes 0x1
Name UxTheme.dll
ModuleHandle 0x6cdc8
DelayImportAddressTable 0x6c0ec
DelayImportNameTable 0x672c8
BoundDelayImportTable 0x674c0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

201

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1428
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.68511
MD5 ce572b24f2c477c1f130eaea5df42b19
SHA1 55f3963d9ba4be633be19ed4304f3294103d5af4
SHA256 525da5df484bfc2311002481c749d375b3f0e5f2f38f1a7a829b84f00ecd9617
SHA3 d99a2968f48657a575326fb7557b6ec894caf2906f14ed504d259159504187de
Preview

202

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05543
MD5 328364de2050c5adca97a4c9f563fd95
SHA1 57741107d459b6f636e260d1ac986b31764ff8d6
SHA256 5f5e793e2523134abe92f56125c5e5eea04948ce044b79787f15a1eb8489865d
SHA3 2179584562679e6d367663cef89a1d4ba6a210452e5969a03ed8411c14c28626
Preview

203

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46621
MD5 c26c292125760fcd27ecf8819b2f4b3e
SHA1 2e5c8a433dca3c11cf6a545ba041383bef38ab34
SHA256 1a2ed27cb633848959f5ef479a1fddf57b3096ed1674301d324e78dd17431d2c
SHA3 21b5a71f4e8f5091b9d4b6452223fabc5b552880427e399cab2820f8b514f7a7
Preview

204

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x268
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2405
MD5 e82dee146b59dd804404c4c103fcf2ca
SHA1 ea51deb2fc07745a56e398afa1c238076560bb85
SHA256 b72019f7b068f64777721256befb27c9a8a933273f4e441d85181188a07b065c
SHA3 7ed6755b5c0ff6cabda3e227fdf3e04f238daae64dc5f2d7adbb03fdcd6edad7
Preview

207

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.96534
MD5 4e930f78fdfa221f73243b85d7a4990b
SHA1 6aa222b24396dee709cd01a5c702eaf46cbc0664
SHA256 29bc2abd51e6d95eb3d88b73371fa2567c2c49bba32b6ad4168c10b566b5b4f2
SHA3 6c07032c435f73741133064937561593ec0dc28d3a95932794825b39b0558c9f
Preview

208

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.67097
MD5 d1be0743fcd9293eceb8f8f7b06420b9
SHA1 2a8c72d2005156cf38d3a40fd1be7110afe1f858
SHA256 6d47208fdbc424346d7a7cfb6398d173f0b171b55077acb2ecb06013dc3fab16
SHA3 b0b3a15da1d924fbb9878fe9ce8f2896f2142409137ed37a98dadccfcfdb2cfe
Preview

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.69508
MD5 db0189e475c871c75fc5f482bcf0295c
SHA1 deca8e17911f5263d9f6380060d9434a9ff4f0cf
SHA256 0eb90fa304436f51a90a19e49221087eb611544758226ea06c3a197d4f39be7a
SHA3 dd80c6b6f1bbab83336981be3bf218011b4e4207af02c3cec0c9f3a08a7cc8af

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49889
MD5 4eab9137bf65919411caff4b36079229
SHA1 0cd702afeb1d172264fa5a83f60bff47dd4d7f67
SHA256 18bb9659209d95b04ad5738da2f7e4fcc4af7e48911a728059de734721561bcd
SHA3 e3f1b7cc445343b6fce75aa900070c5910d7dd517b4b3dd907957395d7ad56dd

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17623
MD5 df9e903852c3cb14a97500e2b1bb4bc1
SHA1 ddd1ab9ccbeed64c0c053a021e9942e58a426d75
SHA256 956acb706300ca7cc843bc415afa0d7333874f39cbc713e4488d2d62fec54245
SHA3 17cad19fd3cb44ae18205881acb60b67610af982c8d8eeffe85c181f0c6ea46e

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.89644
MD5 50bc49a4288455499f2c6808b26fad49
SHA1 84a0a0d5f4149dbece736c96a3c97a2f0d5c3e76
SHA256 32efa79fcffa478c777dbc26a0ee51a25324e3c34c21ddb8f256dcbb370a10e3
SHA3 2dad7d50ddad2ea342749ae6fb6b0ccf004ee89ed377308533ee5fae94ada235

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.22633
MD5 cb900197636cdee510fb0ddc2fe1631c
SHA1 40d80162742eb0181b360452c3adda98402ba42d
SHA256 41a3aad0c55d7e399812b636e89dcad771a2c363a150178aa2e4d4df46540747
SHA3 2771013c553fa02a9ad602df0e0877b63ca44a9e88507d9dc99e5f6f57d28aae

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.35708
MD5 89b0063cf79cbe5bdbc9df031356b2a8
SHA1 09d1e8f02cf9577155099961c4fe26dc6d95914f
SHA256 3f6bef9146b90c761fd10f3ab47a50e5480ad2080bf7c835d9d44eef0f1e728d
SHA3 9d940d7fdc35592201081395a7fa79444facc1cb6a2645ea93d773e35b269b13

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33417
MD5 d68495c6999c5387bb4c7e096f2edd7a
SHA1 c0f7141c8d97bea5a7b0038ba21c79a8d88f5fdf
SHA256 f0addd3f634b612ca503506748826651039bd91f3bad04628f0abe75e04a0571
SHA3 8d9b34b28149cc2451dbbad708daae623d15697bf0f0f669a0c607b1fd925492

8

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.20243
MD5 e68630519247b77a36773f23b3d04e6a
SHA1 05c8e647c1bb32f44fa61f9140117397eca11cb5
SHA256 c01c0c2b3e2f7898296344d971776fb05fb2d46330ab2a16fc2a186d27f4ade0
SHA3 91cf4400f932b902969f14471805d000714a987e055880ab111c43180c60991d

9

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31555
MD5 25e1a74ba216596a8b96b7ee67ffe6b3
SHA1 9f0bfeb5427e2580eead89f85e88c0ffb896718a
SHA256 7d44e0544d3c94217267f1be022d56ab35d5abd6a651349f7714e9eaba01201c
SHA3 1e4ca5bcc7af0aa3cedd99ef31e651e3af77c3e8ed5402b20380a43ea4de7b37

10

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.94597
MD5 e9a3816f7d7cb51be360453d58c23cd7
SHA1 f53462202cde298c4d519c86292319b51cc465df
SHA256 7acd6d66ae78f8e4a0253c9f7fc9f556e61ffb03e80c0d1eee63735e60206a86
SHA3 d8635f66890bfa7512118691db7a9994fe3964d631f1f70388563171b5150243

11

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13846
MD5 f73bab5c5ff3fcfafc604edfbd60892f
SHA1 48c1bcf72e70754b106cd989860ded260e623b76
SHA256 f73ae6fa92d142ba6ec8f65ec19ea0373073b0c50fe94f973b01f07d946fd0a8
SHA3 69d5796bb808406d404fcd67ade43f702f687d7f14dfb6250026bb321cb45f28

12

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06819
MD5 97b66a7f71d08301d8a48849a5b97656
SHA1 c428f8460b3198be745d56c7d08219b517844ab6
SHA256 9fbfe33d3c8aaa916a26203888cd0406e5dbb7d8d4dca3e43e5f46c2d5f65a6e
SHA3 1f51b23bd055ea5cb4a65fdcf197a6daea6b8d26c4b4a51e903611cf7da0f173

13

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98844
MD5 3782aa2df3dfb64afc4547a7a7ec8803
SHA1 fa3ddf53041a573eee60585f70903de1d00c10c3
SHA256 9a89fe0dce3686e98b44ebb94f48b3bf278bc03eb6d8da52d96233638ebc3bc5
SHA3 2907d3c5359794c53ecee07fe80a90dd329950f1ddeef37d7e632f465f397b09

14

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.12407
MD5 d3410fdf888dfefbe4742551a8b0ed85
SHA1 a599b14caef91200b09992b6b2374064581e6c7f
SHA256 be6327ff9bcfcc67381dae5929b0f0bb89bd68d8260df1e329d9c67cd7c81ccf
SHA3 20042ce20acc71fe844de5830adcc3e84ebd332752892138121da7e4605e280c

15

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01907
MD5 1d7a8a41bd46b9deecffc65adcc2b4a0
SHA1 4896eb7a1e227304ba37e485c795eda8e6786521
SHA256 c3756dde9c108e1750ffd21b85c1346bcd08072223826519c18584278ff64d3d
SHA3 8fbd39e9b6c1f0e61a08e3857b51ede26c7a26d7bcb9c16237c5fca853908911

16

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.19152
MD5 f2c3725eab1b73f245b6667de11dfa66
SHA1 00881177b8c48192fb8e2a61c03db077cb00190c
SHA256 ba2e1b9d098c047a29962c58b3aa2e2221c7c83ef74fafab5dc128b648ab9be6
SHA3 b8377ab3448d73e93f4bf9982f0eb929c55232d02cea6a225da2b158f568e390

17

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66147
MD5 fb23b731de75c43980e94de421bcadca
SHA1 0e4fe187c5ab5c83bc3f4fc340b8b65c1cbd2b57
SHA256 b81411ceedbc7936cda1cbf452023ff69d2a5c9b16eedd95737ab1f84eeb2dbb
SHA3 156615a407e8ad46c8ddeed65ebb5c36fec465e8e9a77b222edbfb4bb3f9b5c6

18

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9607
MD5 ac72b203548e46a59504876157561d63
SHA1 4760dab08ba4caa2ec33bb2d34d803f7e10cb9d9
SHA256 797c4b17a4afc27b5f67515c468e3102b644c07df13a385c736ceb4490083336
SHA3 f9a2eaab16427a8990807d3033f5fc46cb0631ff2a7ec72c50223a71baad63f8

19

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.14344
MD5 235b2828e5c86694406cbfa8535cbb19
SHA1 e5b064caf6e322fc5df55a2ff182729ad09c3117
SHA256 63bdb124324df77e3e763f71552983ef8e70c4b669b2df389f234594ccc21d83
SHA3 54fac87421dc202aec695d50ffe9e1f9f76bb1fc3d68218920deb6de0dd715d5

20

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9657
MD5 045c85f5aa6f0966f956d0596fa19b21
SHA1 a8c45016d8e2f8e1480ce198cd6efed12acd0e46
SHA256 c31baabc5494a6bce00407b5614939d2905180f6db22c22e73ed88fdf03528d8
SHA3 92e647ac785d1435fdefacf4db850dfd4aaf7ace3515abe9b9610cff5d5d2c8b

21

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25879
MD5 cfda12f5397c6512b612343e6b18f892
SHA1 f4652e6076081fa404d2c72012ed66eae7373d21
SHA256 6aa501a267e8d41e60d90f277ec95ca1793e08a0639601f3255fd50c0e66e6e1
SHA3 93ed55583625cfea7ef444f56def26a154a9b0d6ced82756f2e7c174576cd069

209

Type RT_MENU
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04518
MD5 fcc5723afd35b3ee2eb3309d909c20de
SHA1 83dae1fe4beb724b085a19c652d907269b2c5447
SHA256 8377573bf738ca100e38e544fbc4657e5869b962ec4e8d81c9471ee37c0625ee
SHA3 7ada48556e64b1bcb0f5306ea600ce59c7c080d49046af1d0e241d28703dd68a

240

Type RT_MENU
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83169
MD5 55ce3072d48fdaa7ec64d439db3312d9
SHA1 6ff4441f9bca21ffec6e136fafdfd51e3c144851
SHA256 5855171af2e417a09dad1f5b288d9ce56cafe158e4782ae148ab4952df765743
SHA3 d3fa5c491717ec0b2e9744c36e12c9b49d56551deb11c99266135c0c3a879c68

100

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31704
MD5 3404c5555d8476f8d1d0b20ce8233acb
SHA1 5fc3be17a689eb941942eada1f52bfbc2d4f87c4
SHA256 3d93de0ee97ba8a9b6a249fb472ade73073783db1e5e98e45c6689d0e536d55f
SHA3 c08c97f237946c2f2d4d7e75d90ade3529b3ff99742ea0ca7a20cfd6f3cb8bcd

106

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x298
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30567
MD5 0c63412e1868879715c921d61306152e
SHA1 603438503d83c851660d735907978f5c47fbc94d
SHA256 cdbc383da5b82b1fffe35befdecc393d4e14774ebd30667ab52b8a176d25f74d
SHA3 d58af32f17b7185790496c23e40ce384087cf765d56496586359ed44fef15d30

107

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2fe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27591
MD5 2586ee66168247832d2bec33bdb4b500
SHA1 a4180b9afd5333fb28f9d7bdf095d335fce23df7
SHA256 4fd7b2caa24233d4b098002353beb2e147402d7724f1cd388c97895d88e8f77e
SHA3 0001a0d5a78140c23426ffebe2b7036f34280d78b77c52692b43a366b25da313

145

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x196
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0737
MD5 8225bfe59be421f7f1521a482f669e20
SHA1 ed89238f864cf4e3df3c0466e8d6d8cc809a025e
SHA256 e887aab96cad2bf31491ca03d6f5050d491ca100150cb832e5298b06a8a9a77b
SHA3 3316d0ab40ccb6ef2f5af128b4053ea2815eb51311f45d2e8f4ebf5ecddf3422

205

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12157
MD5 69dba2ad1bf105ef1d94cbde0c9c6bf6
SHA1 cd5c76894d91b5717110d36593196a53ea199c86
SHA256 89880e6ed9129fdfa67f57f332679d0ff7f4ef4641a20334cf5ff05cccf24e02
SHA3 cbb8453deec9f21096172ddd605287d0928007872f913b455a81cbcab849f09f

206

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2591
MD5 611d62071ad39b2b12c95bea6b310592
SHA1 a3ba7b505571bcaef95d4c916c273f0ea86e4589
SHA256 b4862ab840a9bf0919ddf0f240437ba71eb8cd4b968353eb97959d7ca0a1b58e
SHA3 c72ea9a391d5c44a3887ab9a271181564b4c0ff8ff72b2a0c80fa9dd2052d2ea

223

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x252
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23831
MD5 d9e7b75b2e205e7c26968373449a68bc
SHA1 8120ee2373196ae974403932fb6288929dc05adb
SHA256 637fd8bdd3ba6beaeb89f6a5c6e1bec50f4f5f7ece0dc2b32d6f3280b791ba36
SHA3 11541c8d3a1e33f0a2b247cd8f6b0821f97156b7805e2c5d66d5430bab004487

224

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1fa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11814
MD5 3f3e98bd7a71a5e4854e4061f20873d5
SHA1 65a1678a66235b7cf9eaf4091709eb3b208d8caa
SHA256 e5df133acd6a2dd85aca74b9f1ccab04862ce15d681e78272bb1978502f2261f
SHA3 69e4c5fb8b691fa5242a58f0bc0983add284b9f70544155afaba9aa0cb8502a3

235

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13926
MD5 590f809d7fef2d9a47283782145c5735
SHA1 eb1dd4f1e48d48a3569f82358ce711fa0da83dd5
SHA256 4a0cbe76130b813a976ce869a3737d58ce288fcbcfe00aa2eb875e8e775d2a7d
SHA3 27ac19e4773849297fd80a9e4fe3f8558421b0bd5e4de07f4b8c6e3d3c0a9079

236

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15815
MD5 32dbc043d8e1802f82ce9bb12de31b36
SHA1 79421e089d3a720ef53d872869569ef18511d728
SHA256 e3dfd46404c123c05f0cb35c6f3c23f8de6a892351adbd8dab7ccb2863071572
SHA3 48303bdcbbb474304abb1d3f4d04e160801093ad0814c827ec3049eb0d0ae16c

237

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x354
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31077
MD5 c2de6bc05807cd957e18eec72b9ec3cd
SHA1 1aa05cca047388361cc3e4972b42d4d4185dcd9a
SHA256 61ba449d30ea1740a57599617464403ae3134f933fc7bfc80e88845579e5f39d
SHA3 8cccc0f4cfa701fa0afa59774a13c1679c73ce56fbedf7c86f032d276f4b9a68

238

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30675
MD5 7d0ff619288973e7d5903ed5411b5a49
SHA1 dfde4d82339e89db274d7bca8eb9569831244a8d
SHA256 bfd365774a99e0b2e1c589673b0aa77e8f2100346bf709367d1428ee83a695bb
SHA3 18337d4ecd09abcde7752a3721065e757aa2374a695bf518e6421ecd3caa325d

239

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x240
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23085
MD5 84a4952bbac71202d8da74e5d83a6b64
SHA1 cc8fb9dfbbd44c113f064991a03a361163929432
SHA256 863b35b299b8973268e37c4933e84fd04c5b78cdd5c48d6272b58b0c0ddf814f
SHA3 9d4e9eb325f1a67fec07efd8a6c3dad35a44f6eadc6bb659b047e71049111bf3

242

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x190
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31971
MD5 6f66837ccfbf2e3efec69a084877aa39
SHA1 ed4074c8e83f7908ebd4fec2b712e59231f3c46c
SHA256 7e20a18f9abf0a42c79fe268d8232190c8c8cba413d064fb072df89b1bffe0e4
SHA3 e78776e057d84621cfd18a730a46a4e0d2884c615eb9eb94b839840a87159b84

244

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x314
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24246
MD5 21f277ebf1c1a8d95722684791be6591
SHA1 73bb7611c0706c7d57b5096cfc33c919a9365278
SHA256 51edd5b28df46754cf9623702013fe963c5284263a917bcb6a97de85b908242e
SHA3 6f287e799dc17ab1b45745365f534d323d3854ae069dc36af933034fd380958c

268

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x126
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09107
MD5 e2a1ede78eca0976a7b5b1a63dbe4f65
SHA1 5dd4791bdc2d08e724b83a3f36cfd3963c1196ab
SHA256 76431019a98601c09734992ecb61de980c5c5f3ec5ef5567cd9675870205a218
SHA3 347f9779706ba024c753357f89a3180e84f58f62b63dca9175653f1f3912dcd8

269

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14526
MD5 50b6033fbd33bc7b52d64a91ca2bc96e
SHA1 ae6a3e03e6dead4c8c48ab3f13b72fc31a208166
SHA256 fc17f51b74e5ef02f1cb2106191bc3ad9aa4294d14b7e00e81a5481ed73d2c6f
SHA3 d0a168a9c15998310b0e1dd55bece92f3a56bb87596580a8ae076911c7afb653

270

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09484
MD5 7ab7e8bb0c922d4bd2516e1318be6ab9
SHA1 0163ea83f77e822b4276a4d5e9492a4384e2083c
SHA256 a019ab126a4bff6e3b8a8ac83c14e6673515e1fbafa4d33442cb03d3f85d3224
SHA3 77c8c955a070ea762d07e4530a1eb10ea5ec6d87a05ef285d096b348d506c705

271

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09691
MD5 29f34d7c1b1470b8fd04614ac481799c
SHA1 470bdf918336d8adf64966eac3601ddf6194a0b5
SHA256 9be135aa3dc39d0a77f0d01a7ad8408994a2f9060551618da43d36ad1b60c723
SHA3 d72fb71e8404dadf90dcc7bda4df8895b1cd78950868eafbf303f6e8a3d0d5a9

272

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x356
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34795
MD5 d03227178cfc8a77c8dfc3ade0deafe2
SHA1 9668f0bdbd98d252244d725b88c78b28e2cb808c
SHA256 58500252439ca1d9ece0434c1e5347abbdd9b89690dddb1a5b00fec9cdf6d708
SHA3 de8be7f1978891d579a31dd42fd185d3c0247f7ea9192a9e03b95e401d39eb32

273

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1e6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26825
MD5 a7887253a8e692c52283e3f0ca5e93c8
SHA1 2e4465e6363151b0b32bc0d6fc2becb1f96c8061
SHA256 9b5a0696f1f6bdbb11092895e55d7a646a48e56e6b81cc2e4783fdd43f4d37bf
SHA3 fbe05194f30963738941cd05cd9b695ceefa5919d3c7748dd4ab52fd63900944

274

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27829
MD5 92167afa2f995e0d60265c6cbe866274
SHA1 23e54343991f0b19987378de8192ca86d4749c22
SHA256 9b414759f43890631f3f386911b95c139d896225d910ca1d8526385dca606b33
SHA3 5d392d1ffb99080ba45e22604aaaecca16f57b8d72e17c48107dbd72c668bcac

276

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28036
MD5 f74b3af3f57417bc937aa775197f1850
SHA1 b5a2e7c58716afc079dd8f550b8868c8050d3b96
SHA256 e65e2fbacbb955c6ff16819c727cba0b8b13fe1d54abfb7f5efee1a8206c613a
SHA3 00ff1efa4b05cb3e44f7e15f3c01372d5f4422671b8e23930df8016549ef5089

277

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x240
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12977
MD5 13dd53a95ad5e4bbe063b7342500ae22
SHA1 b84b849461d15efc939ecd31a360a0443d10ceb4
SHA256 e2ca4d09b6dcd851a076a8e3b9d154502eae0b15fbb54c5b7044ee4828584275
SHA3 21503ded21551c0317583474df4e0b51de138915c8d3a7d7aab43db78dc0f4b5

278

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12432
MD5 cc8d7d139a224c21237ad992d68e68c4
SHA1 26f26e44f45bf5eb5ac20bccf4b90f55b06754fe
SHA256 e43d2990c97d07f7b5662e00ad07f4216507870c7be61865b5e190c662696c1e
SHA3 c5ffbf0b31afb64328daa2b0cc93321b07245dc9d6e702c1d754b63268f2da37

2049

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3169
MD5 09f97a7fcec55af84866336a0028ce57
SHA1 23f2f1a52fcbe0a92660aea55a99e991668674f3
SHA256 8317fcaddf207086e47c7f3a47689a10da024d96ff22b9ddd8b3c2d7f4d2c5ff
SHA3 0c57df5c84997ff4b00edb98de283418624396733d950ed24fa137cf99e5d327

2050

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.07875
MD5 bb30314f139483d92e24ff5999559875
SHA1 8ea573082b9ac11fb16b4e9a6b1aed1756c9b751
SHA256 9963347af76e3eb7fa163b40db4aa6694ec2da2f6024ce5b1be2dd5c7283a2eb
SHA3 c124965c5efd9b3495c46dccfab0796552dec200e6f821c6bf1fba52623026c5

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.84274
Detected Filetype Icon file
MD5 f64c60b749269fcf6659c450dda98486
SHA1 42945c3496bc4e1943a1a05926a9b5ee31d3e450
SHA256 ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1
SHA3 443830acdeb37f2b7f844756492b2b11f9fb93e9171617d8c799cebfd05cb37f

101

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.47702
Detected Filetype Icon file
MD5 29a1f473b6fc0b877ce30be83212f25a
SHA1 a66309103e9f7ff118fd964f2cd5ae04bbd4a322
SHA256 e5d571d7f26fa57c7e00290d0fa8aef8c1d519983e0aa5ecd75f5d4b41fa4cda
SHA3 c3b0b1b14385cdc2d88d02c11aaca33ca55d509d2fe1dce1777c05d32c0e8a30

213

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.9815
Detected Filetype Icon file
MD5 40c1414025bcc34e7ba97fd22bc9f5a4
SHA1 b53a6a13513b5205cef6fc6d7556ad80d8b62173
SHA256 d6659139f55adad2497df8d1a11fcd68324a00ccdadbc133ddd49fb79e9ccc1c
SHA3 88c00f73975983695c16e34c6a1750573250999152f5399a198b799e76349720

214

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 9b2193af49fdb53892356f594e9f18b9
SHA1 448aa28721dd65475b37505de8140d88d5aa1501
SHA256 9b8ca9c6a330d0d17d1108ab5442d60ea574817a65caa860cceb24313cc4f0e4
SHA3 46527c3333b02958fd025cfdaa12d481f8505aa77c1cd0b5f15348e870530116

215

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 5f51cbb6145d3a4c36cffa3b028b0199
SHA1 b2bbd2afcfa1c44725bf90df8948792d3bc7fb97
SHA256 fbb52a958caa73dce023ce27649d69f8886e86b5706e767153c41dde7b5eebf9
SHA3 93f253b05e0e42147b5a9000d421c3e105df42f9fafae5147c4e9a09958e3f79

216

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 9a2ecd931607a3e63110250c64f874ab
SHA1 c0beabb14c98fe6050b0ac4eba46fe7f70b54fd8
SHA256 ffc9a0fcfbfc61893fe969e4a73e6c1efd043cc724ad517dbad9b6244f653687
SHA3 47aa903a8e24ea84c4cdb70035df400db871e9eb126bb11fa8af894a19c5dee6

217

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 dd7714fdc92e60eb14afbe736c879ece
SHA1 1c93863334cb0ca1121434c897865c52bf67f54e
SHA256 770e691e35b6bdcb2534ad145bd2f470db38663f32a0f5bcb76fb5eff9fb2126
SHA3 d4af180c6c1e24df57680eb6a9f1e72db2bf903e8628cdeabfa76dc6ed4eddec

220

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 e0174ef5c8fccd4a4d45abd3504e0ec6
SHA1 5938b0aa15911d87802464702890615b3e4525cf
SHA256 56caa9da391ca0d9b44e55063ce13e183bf02cf7e5ea4810e7ffa0764277ae04
SHA3 d1184890970ddf5b0e5c31b397a81b16c1e87a56c53182b7e0bc12672264bfec

221

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 491f96c2ad766b65524c319b15d21115
SHA1 8550120bf17014eea8474f16c775b1466cd29123
SHA256 7840a0e3163f71f53b8a2c7a9cdfb8b1cf0eb248fa2bd091c209e21cdfe3a4b6
SHA3 9c669a27eb3819b2711953ec14c51fcf93b4b560bbccd9b3ed52c7e2b5f9d1c1

222

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 5818d9a284729028a1d4f1d676f3329b
SHA1 93efb6b9916842d1e994ca15c9912300104acbac
SHA256 aff79f25a88d4db8d0c782fdc2d47490efb54ae535d3ffb59a8fdc1fbe2a3dc3
SHA3 ef5ff82d7ee8136dcbaaf9ac4de90d7ea774c833f0e834e24c49c7d74d80e49f

225

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 9f4087082347d252104f4600769ba309
SHA1 da5f286ec9fcf68f774eeb46e9655debc6560d51
SHA256 f3a362475aa9e16f4742b3483987677440dc382b91a807978e8ec4c082c57e78
SHA3 d005d922c6e614d142b93d4d8957301e0aabdf867c6e650f24622ffdafdee3ac

226

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 0c0fa987ed2863249e70af81b53d05cb
SHA1 9cc2c4e2ace54403f16111a81a089a4c7a490fb3
SHA256 5056819d8f8fb64b2f9b6c7d25141f90f7f6e06e8362a354dafc9d04a9b782c2
SHA3 e0f518ce0e55ad00d2d2dac96c53bcef28e5699c97eb83835d26f11e297f26a3

227

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 05340238fb64a2571024a7e95d3cd40e
SHA1 de6c4bed1a74a0effc2126cc4df1b71e151232a2
SHA256 c84b141eb6e26f6008b2d4a27925c034237d4b08f675bf4050cda2d45ff28a52
SHA3 8ee8f11b175e1f85db399bd9b8103770002bb0f8319958613b44ef846ad95ec1

228

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 42cbd210d0b310758cd98dbcd8b050ce
SHA1 5e37de0ac7cd176a76307cc3b97a5ae8d522e781
SHA256 f0eac6fad3f08088012f8a3b738e3a3f17eb6dab6c18edec0ea49ac5725f84dd
SHA3 7ae1f8914232623d306922cad49a2fc1eac7eeca507b9484381aaf2f75ce99bc

229

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.86096
Detected Filetype Icon file
MD5 d8e0c603371c809b0cd4dbb742eb7c9f
SHA1 e0dd0765ca9c0b8487814ebf1406fecb3fd097d5
SHA256 98e66a10f4405c7d7c1d93fc44816b276689422b220fc4c13d57f2ada9fa3dc1
SHA3 596cd003ffd4831600c8a1f4e8b316000a2b0112bcdee271acb12543793c7ff9

230

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 97f88d68d586a1ebd5902d615919c887
SHA1 61d7e4486d94d4732dd7a734e82dd4fe48eb2816
SHA256 b9d346e7abc5c1aaf6f4d601d659a592165cb4a813d6dc14d699bfa9313fa8a6
SHA3 aeb6470e078e6d037bf25be16564681a0424e7bf623ae74adcd4bb93ff0a84c2

231

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 5e0ff891aaea743886077ca165552aac
SHA1 e059b4367bf90560710c7abf032db1f627255995
SHA256 b36c610769f8f0b753f5bec71bf1e0345ba920f36cd73ccdec421b5d01e17064
SHA3 9dbfa96571a54889630c946dcb53c5f8f62ace7320d08a814dfa489b82bfc98c

232

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 7f6663cb6a2da6fb7ced18e964a099dc
SHA1 5ed27be07c51c2fe8bf9e716d1adb889d1fdb62f
SHA256 4d6604cde49fecc947a0d6571b62dd9dbef94b54ad403ae0b8da4e864f69333a
SHA3 8a1391c920e5401985d4d7d58d422bc93fd126d9fb17759ead18d5b2336f14d7

233

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 47ae899bfbe9481316bf6d29ee9f35cc
SHA1 42bf892ee97b41d7e1f2cafca34a78bd90280c70
SHA256 fb5abac7fcd36c2344392dea11882ae9f1795345a83e57d97feb00f69d534792
SHA3 726cd090ea2e74f6469cd16cea518d8eedc3a7448209211d152f14935fb612b8

234

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 692fed5c1a4d47b17e9ddaf6db120bab
SHA1 a06b57d720971e6fe72b22a874c3a789e006ddb8
SHA256 674e3cf74b2e2deef3e5d7b938ba1b0e8cfd4d39ff0b47c8d36dc3810ab85d23
SHA3 17a8b86d1bec0de8609a3d3facc86a73bbbaf7ac8718c5e3a7643e6982a984d9

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60038
MD5 14763750f663b2aca86919309a519b0d
SHA1 2f81bd0617bef09506a9794f53d67be83c8f4184
SHA256 8a8bd20128f93cb9ba512ab098a7c01bf41d3f6ea67ce86211cb9174b60bfc0b
SHA3 055aefeddcbfcea4a36800b65a4bed4d8682f5b7194aad892c3756798a995b8f

201 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x12
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

202 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

203 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x12
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

204 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

207 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

208 (#2)

Type UNKNOWN
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

String Table contents

Log
Invisibility
Email
FTP
Security
Web Update
Options
Control
Network
Control
Screenshots
Chats

Version Info

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x46a3c0
SEHandlerTable 0x466480
SEHandlerCount 22

RICH Header

XOR Key 0xfc89f89
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 5
Imports (VS2003 (.NET) build 4035) 25
Total imports 432
C++ objects (VS2012 build 50727 / VS2005 build 50727) 79
ASM objects (VS2012 build 50727 / VS2005 build 50727) 49
C objects (VS2012 build 50727 / VS2005 build 50727) 222
114 (VS2012 build 50727 / VS2005 build 50727) 17
Resource objects (VS2012 build 50727 / VS2005 build 50727) 1
Linker (VS2012 build 50727 / VS2005 build 50727) 1

Errors

[*] Warning: Section .rsrc is larger than the executable! [*] Warning: Section .rsrc is larger than the executable! [*] Warning: Resource is empty! [*] Warning: Resource is empty! [*] Warning: Resource is empty! [*] Warning: Resource is empty! [*] Warning: Resource is empty! [*] Warning: Resource is empty! [*] Warning: Section .rsrc is larger than the executable!