1943da99ebbe840ac89c3045fe24babb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-May-28 20:31:59
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .xdata
Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyExW
  • RegDeleteValueW
  • RegEnumKeyW
  • RegEnumValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 13739908 bytes of data starting at offset 0x60a00.
The overlay data has an entropy of 7.99999 and is possibly compressed or encrypted.
Overlay data amounts for 97.2002% of the executable.
Suspicious VirusTotal score: 2/74 (Scanned on 2024-09-05 01:20:01) Bkav: W64.AIDetectMalware
Trapmine: malicious.moderate.ml.score

Hashes

MD5 1943da99ebbe840ac89c3045fe24babb
SHA1 a4ca3555efc9b12e515403a79d7316ccb69a7377
SHA256 7c5b449226d2c3e8e65341baffb10b9393282d53b7f6fb164ed788ca2967bb99
SHA3 56e50d215458f96c7301f46e831c4afcec29794c1fe8a8af38399475419645b3
SSDeep 196608:OZh/vKV4AhS5RX0Ooll6Vv4eCklq7CZhKNbgANGvnU8T6slsWD7PdtSX6kcFCjuh:s/9AEuzC/rLWnNAnVmW/VtQ6kjjo
Imports Hash c0f430a142bcdc701f4a3bdc3d2c6a84

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2024-May-28 20:31:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x8c00
SizeOfInitializedData 0x12000
SizeOfUninitializedData 0x62400
AddressOfEntryPoint 0x0000000000004280 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x184000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7cf6f610c99062934db6cac50a0913cd
SHA1 7a47db77bbfc75dad1f3ba7173222cf9c4185949
SHA256 241267040de74135a45fc69ebf78b8274b8aa1df22f1b155a64a396d11782651
SHA3 cca3492d2e7500e2adfd589c16091cefb93b70e75b91857cfdb80c3177ee2641
VirtualSize 0x8a40
VirtualAddress 0x1000
SizeOfRawData 0x8c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.21263

.data

MD5 4b8519fdd76a33c15d8b4409f6c87bce
SHA1 f9128af6b8cf36ac9dfe717f7d477b4facf0ff85
SHA256 6d70acda05d3626c54b62d0e9e35076ae1f01fbfadf5cb4df43637c874211d0e
SHA3 5452f40403b233e4655ee2df055ad4c10a7d0b7302d0b95349741c3533551f35
VirtualSize 0x160
VirtualAddress 0xa000
SizeOfRawData 0x200
PointerToRawData 0x9000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.56844

.rdata

MD5 63be929adc5a8716d89598ff33a90f9f
SHA1 c3baf6e085ffb896e9d85ae611e303e28108d96e
SHA256 51188130e9d741a4e34e9657798179360d21f5168dfd0196c0b98dc0bd133576
SHA3 b343d636d63e6d9b64b42a8a13c90a1c91ed883adf95592b2401a070a3164a16
VirtualSize 0xe220
VirtualAddress 0xb000
SizeOfRawData 0xe400
PointerToRawData 0x9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.7852

.xdata

MD5 e1489c44cf7e3b0cabbe93248e89c929
SHA1 74df7614caec0b6e1985dcf13d6b1ca36331c94a
SHA256 b5fed2664d2ff8d7edcbeb893fc6761f11f70a4f6776a52ed2d4c6d4c59991b8
SHA3 4272984df865904bbb5c44c9821f009a68cab7a0858484c5d00388879e2eaab1
VirtualSize 0x4a4
VirtualAddress 0x1a000
SizeOfRawData 0x600
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.6611

.pdata

MD5 849d912a92b3f7a747684d5d980cf1bc
SHA1 5c1e93f895cad55bb6c0dd63fd3c7536a9097b34
SHA256 094e5083b15edb17a840303676b6c92cb805ede3ba6deca4f9211318d43a4cd0
SHA3 ab3697adc262630a00ced8de535008bc34d090601fd6170f15c710aa5dabffe7
VirtualSize 0x4f8
VirtualAddress 0x1b000
SizeOfRawData 0x600
PointerToRawData 0x17c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.05

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x62320
VirtualAddress 0x1c000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e401eb534270ad3e8ca74eb37a1ebb84
SHA1 ce60746b8363917e91d756a8151d27db79e47da1
SHA256 efff3de72fc1db6b4b0178c59d289cc97d27847127d988100c3f63ad19cf9ef3
SHA3 3aeafc253f1b5951cc333ee129b774a2277bb313a907dd0ddcf3ba591f992971
VirtualSize 0x1974
VirtualAddress 0x7f000
SizeOfRawData 0x1a00
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.6387

.ndata

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0xbc000
VirtualAddress 0x81000
SizeOfRawData 0x200
PointerToRawData 0x19c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 fb5611c1b4b8ac8086f2d05b6f861934
SHA1 9c86c06f9520b7a95cbcabfc349ea3115e1813ee
SHA256 18081faebf8c19526b3b54f4c9087d4e542921646b221446d744afc538c460fe
SHA3 71aa7cb27a0e558e553d6e2a2d0ea8c3e5b870a04250511afd47233dc09218fd
VirtualSize 0x46bf0
VirtualAddress 0x13d000
SizeOfRawData 0x46c00
PointerToRawData 0x19e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.89622

Imports

ADVAPI32.dll AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegCloseKey
RegCreateKeyExW
RegDeleteKeyExW
RegDeleteValueW
RegEnumKeyW
RegEnumValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
COMCTL32.dll ImageList_AddMasked
ImageList_Create
ImageList_Destroy
InitCommonControls
GDI32.dll CreateBrushIndirect
CreateFontIndirectW
DeleteObject
GetDeviceCaps
SelectObject
SetBkColor
SetBkMode
SetTextColor
KERNEL32.dll CloseHandle
CompareFileTime
CopyFileW
CreateDirectoryW
CreateFileW
CreateProcessW
CreateThread
DeleteFileW
ExitProcess
ExpandEnvironmentStringsW
FindClose
FindFirstFileW
FindNextFileW
FreeLibrary
GetCommandLineW
GetCurrentProcess
GetDiskFreeSpaceExW
GetExitCodeProcess
GetFileAttributesW
GetFileSize
GetFullPathNameW
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetPrivateProfileStringW
GetProcAddress
GetShortPathNameW
GetSystemDirectoryW
GetTempFileNameW
GetTempPathW
GetTickCount
GetUserDefaultUILanguage
GetVersionExW
GetWindowsDirectoryW
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
LoadLibraryExW
MoveFileExW
MoveFileW
MulDiv
MultiByteToWideChar
ReadFile
RemoveDirectoryW
SearchPathW
SetCurrentDirectoryW
SetEnvironmentVariableW
SetErrorMode
SetFileAttributesW
SetFilePointer
SetFileTime
Sleep
WaitForSingleObject
WideCharToMultiByte
WriteFile
WritePrivateProfileStringW
lstrcatW
lstrcmpW
lstrcmpiA
lstrcmpiW
lstrcpynW
lstrlenA
lstrlenW
ole32.dll CoCreateInstance
CoTaskMemFree
OleInitialize
OleUninitialize
SHELL32.dll SHBrowseForFolderW
SHCLSIDFromString
SHFileOperationW
SHGetFileInfoW
SHGetPathFromIDListW
ShellExecuteExW
USER32.dll AppendMenuW
BeginPaint
CallWindowProcW
CharNextA
CharNextW
CharPrevW
CheckDlgButton
CloseClipboard
CreateDialogParamW
CreatePopupMenu
CreateWindowExW
DefWindowProcW
DestroyWindow
DialogBoxParamW
DispatchMessageW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
ExitWindowsEx
FillRect
FindWindowExW
GetAsyncKeyState
GetClassInfoW
GetClientRect
GetDC
GetDlgItem
GetDlgItemTextW
GetMessagePos
GetSysColor
GetSystemMenu
GetSystemMetrics
GetWindowLongPtrW
GetWindowRect
InvalidateRect
IsDlgButtonChecked
IsWindow
IsWindowEnabled
IsWindowVisible
LoadCursorW
LoadImageW
MessageBoxIndirectW
OpenClipboard
PeekMessageW
PostQuitMessage
RegisterClassW
ReleaseDC
ScreenToClient
SendMessageTimeoutW
SendMessageW
SetClassLongPtrW
SetClipboardData
SetCursor
SetDlgItemTextW
SetForegroundWindow
SetTimer
SetWindowLongPtrW
SetWindowPos
SetWindowTextW
ShowWindow
SystemParametersInfoW
TrackPopupMenu
wsprintfW
wvsprintfW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76074
MD5 fb8a2dacef0874934f6cf113a3910141
SHA1 13d3f30b0f6e00f9bb2eed2521d8b3f75c8bd201
SHA256 74cc557872b569fc4824f13543ff52a216a308848bc40b06df3a9c384edbeda0
SHA3 f1b34113284b324470aa0f01670267eddc2a4df7d77acd3873081e68352fcef7

102

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71813
MD5 a69caf66f3f899403f8b25b02dc61908
SHA1 3e5db9186cf0f75be24676462d88170e5950d9c8
SHA256 7854e8d67a11148566ad37c5d23e1534e0990fe31a160e0e7da3ca751830bb50
SHA3 1eea945e3712b317143e07560f54b0b9a13b1fd6c2b57cab9176181a9aaf4f79

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62375
MD5 1d958df872e65e9a04f929c89155e3f3
SHA1 5fff638c5caa7a6f598bfbafd8d8e7fe4f5764cd
SHA256 e6065cad9c0f4a4c7ec1de33c05b192b04cb96ad6cfb0e2ae0188fcaea6ea7c3
SHA3 b29b01b665ef63d2e0f362ce3bf145b41d860ddb989398de87df16d48ac8483b

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68101
MD5 e700edcac942320c30a8ee2b65a74b60
SHA1 6bfbc8131d8ff3a7af45e0ecf0c91b3aa4d060c4
SHA256 6b21cf19a9e4a2a5def4c65e8e28e2120287e380bbfa6d2d8abdc5b7fbb48b62
SHA3 1272002933a5606eb67ea2d25281f6058d3964cbbbb1812d6aa40043495060cc

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84976
MD5 b756cf50afdc5a248bf9f3ff865177a6
SHA1 267b0f95a9f852b7af09e5d909a3febc24ca3ccb
SHA256 c47426270cabd4199bbff8e4fc363265990a8a935c023a8c7d6597a0378e5f5f
SHA3 1fb62d573cc8b6fdf137fd2c44249ba4f1c6d687bd878a786a395448d6069438

107

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.52183
MD5 6ffba239dcfcab2080195f23947b70aa
SHA1 bcda1ca8ee9bb9878bde83aa06c670bb5a4d5843
SHA256 a7e5ea849cb343e9b58de221aeb25c9dd4a3748070bfba879a30c4265fc39023
SHA3 a75544b4c3fcbcb32fe4e02d1a631e045b2e58516aa1065bb96cce681aea7030

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85529
MD5 f90fecb69f0cde5d64f508884dcb0404
SHA1 4baf5e55965823176fa6910a5ec9fdca077995f9
SHA256 45ac0526fc85b64bcbb69ca682b0ca4d866a5e42709deaed11ce79395fec63d7
SHA3 8e5819e3997885152c58d0ec124c1b14288188081f3719777d414d72f5b13e5a

202

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9709
MD5 574849c09594bf406fe5f0b24d9080b8
SHA1 38608268473fb2fcd3e0f2315a492c737546c946
SHA256 2bf6e20d1b7aac0364482a6e48f6429cf48b8c0f744d6ff1cecbb3297416c893
SHA3 e07659d8daf9e860f9bac52009287326aad72cc5806cf3825d64dc1fbb699ff9

203

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
MD5 41c7a6a3ac78ff6413d02f624fa5a976
SHA1 ba65ad0c98a82bc87a30fac3d9f71f21ae54838c
SHA256 d48a10fcf79cbe2e6cbc316798ca7db637c57c31d4cff53fb604fcfeb2e6b2f5
SHA3 763ba05351831c759bac86551b48f45d8b89287303982cf130cf9dbefc539d33

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97282
MD5 419ea9162fcc5265997d90f72ca53e63
SHA1 21d3ca59efcaa7947ad3ebc060c59b3127df1211
SHA256 b7e2e2820d910a969e2296c7cfc450c9fd05f948c7c20729c30ee381e75e1209
SHA3 aa48f268617437ccbc26b5ad72b218cf280715a4a9eeb564f76947f8057077f3

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04873
MD5 023218e558a88386c1ddf83aa27e5d16
SHA1 0abbcaed1865698c5e2925a11d08622cd9c61b61
SHA256 597dfe9fba32cc94839b5b78833cea16d6196f1f00162263a167628adfeaf7f0
SHA3 c4964b45ebe880f9e233043589220d5a052cc64ba8da9f78581ad31f95684152

207

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79455
MD5 f487ea2664475901e7728e27028f78e1
SHA1 05a70c71e7e06c712ca99e8ce88bf6dd5779bdf2
SHA256 e705e251daa451ade5cc3f36278401ce4eb8b3e32ca0a7d5b7e03f525934d770
SHA3 33f0ad42457a216bac4cb66e6209ff5ba1aa1b9895f7e906a6d70fb58c9ed675

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01911
MD5 582ba3154fb8191d8288acd25e778f6b
SHA1 891323673a8428a7a6a838c894bbb11060478145
SHA256 0d022bebfa690ce3fbf128bcfc44bf6936c2fd6626f9460da89ca49632368939
SHA3 4277a513a71389354d89d15fbc015f2009db12c53deda668d3c1dd315a40a9d1

302

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9709
MD5 574849c09594bf406fe5f0b24d9080b8
SHA1 38608268473fb2fcd3e0f2315a492c737546c946
SHA256 2bf6e20d1b7aac0364482a6e48f6429cf48b8c0f744d6ff1cecbb3297416c893
SHA3 e07659d8daf9e860f9bac52009287326aad72cc5806cf3825d64dc1fbb699ff9

303

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
MD5 41c7a6a3ac78ff6413d02f624fa5a976
SHA1 ba65ad0c98a82bc87a30fac3d9f71f21ae54838c
SHA256 d48a10fcf79cbe2e6cbc316798ca7db637c57c31d4cff53fb604fcfeb2e6b2f5
SHA3 763ba05351831c759bac86551b48f45d8b89287303982cf130cf9dbefc539d33

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97282
MD5 419ea9162fcc5265997d90f72ca53e63
SHA1 21d3ca59efcaa7947ad3ebc060c59b3127df1211
SHA256 b7e2e2820d910a969e2296c7cfc450c9fd05f948c7c20729c30ee381e75e1209
SHA3 aa48f268617437ccbc26b5ad72b218cf280715a4a9eeb564f76947f8057077f3

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04873
MD5 023218e558a88386c1ddf83aa27e5d16
SHA1 0abbcaed1865698c5e2925a11d08622cd9c61b61
SHA256 597dfe9fba32cc94839b5b78833cea16d6196f1f00162263a167628adfeaf7f0
SHA3 c4964b45ebe880f9e233043589220d5a052cc64ba8da9f78581ad31f95684152

307

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79455
MD5 f487ea2664475901e7728e27028f78e1
SHA1 05a70c71e7e06c712ca99e8ce88bf6dd5779bdf2
SHA256 e705e251daa451ade5cc3f36278401ce4eb8b3e32ca0a7d5b7e03f525934d770
SHA3 33f0ad42457a216bac4cb66e6209ff5ba1aa1b9895f7e906a6d70fb58c9ed675

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01911
MD5 582ba3154fb8191d8288acd25e778f6b
SHA1 891323673a8428a7a6a838c894bbb11060478145
SHA256 0d022bebfa690ce3fbf128bcfc44bf6936c2fd6626f9460da89ca49632368939
SHA3 4277a513a71389354d89d15fbc015f2009db12c53deda668d3c1dd315a40a9d1

402

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9709
MD5 574849c09594bf406fe5f0b24d9080b8
SHA1 38608268473fb2fcd3e0f2315a492c737546c946
SHA256 2bf6e20d1b7aac0364482a6e48f6429cf48b8c0f744d6ff1cecbb3297416c893
SHA3 e07659d8daf9e860f9bac52009287326aad72cc5806cf3825d64dc1fbb699ff9

403

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
MD5 41c7a6a3ac78ff6413d02f624fa5a976
SHA1 ba65ad0c98a82bc87a30fac3d9f71f21ae54838c
SHA256 d48a10fcf79cbe2e6cbc316798ca7db637c57c31d4cff53fb604fcfeb2e6b2f5
SHA3 763ba05351831c759bac86551b48f45d8b89287303982cf130cf9dbefc539d33

405

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97282
MD5 419ea9162fcc5265997d90f72ca53e63
SHA1 21d3ca59efcaa7947ad3ebc060c59b3127df1211
SHA256 b7e2e2820d910a969e2296c7cfc450c9fd05f948c7c20729c30ee381e75e1209
SHA3 aa48f268617437ccbc26b5ad72b218cf280715a4a9eeb564f76947f8057077f3

406

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04873
MD5 023218e558a88386c1ddf83aa27e5d16
SHA1 0abbcaed1865698c5e2925a11d08622cd9c61b61
SHA256 597dfe9fba32cc94839b5b78833cea16d6196f1f00162263a167628adfeaf7f0
SHA3 c4964b45ebe880f9e233043589220d5a052cc64ba8da9f78581ad31f95684152

407

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79455
MD5 f487ea2664475901e7728e27028f78e1
SHA1 05a70c71e7e06c712ca99e8ce88bf6dd5779bdf2
SHA256 e705e251daa451ade5cc3f36278401ce4eb8b3e32ca0a7d5b7e03f525934d770
SHA3 33f0ad42457a216bac4cb66e6209ff5ba1aa1b9895f7e906a6d70fb58c9ed675

411

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01911
MD5 582ba3154fb8191d8288acd25e778f6b
SHA1 891323673a8428a7a6a838c894bbb11060478145
SHA256 0d022bebfa690ce3fbf128bcfc44bf6936c2fd6626f9460da89ca49632368939
SHA3 4277a513a71389354d89d15fbc015f2009db12c53deda668d3c1dd315a40a9d1

502

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85266
MD5 b4a711ea331ef37edbdcfba3261c7d6f
SHA1 e0637b9d34f0f7e6062d57c16b4966b82992c017
SHA256 a840add98ce3e545a78516701570cc7f667edceafb59fdd5067fcf5f7f1a1f50
SHA3 1dd7bb05d075b71ea1a2a58dc99c4a011966c0dadf66d50d7f92671018a15f7f

503

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x13c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71382
MD5 b9f31ba298d1432fa65b231a9c33e095
SHA1 c0c2437792a50bc52698d77bb7141e9ff6930ce2
SHA256 e0df4f9534a90644b5069398e79e9c8833816af5aa12a0b00816bc4f8576ca07
SHA3 f9122e3304365e4cab94e3889cddf528714da50a967333996d29418f5000aae3

505

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x23e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73501
MD5 bb84fc652a0c575d3332f80571027aac
SHA1 8ef2f68b3b10b1b55130e02579f0d2678a99bffe
SHA256 0584a06be674dbd386c13d735b6d3b7bdb82442be4f09d49606d3254c04b3fae
SHA3 bddf1e857e1094d978fe54aca68b375b6d27c3d9a3d9cb85067653689c3c13af

506

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xfc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97765
MD5 d2a0986c6adcef818eacd8b162644796
SHA1 787a226000bc65732645cd2196b4b53f78953e85
SHA256 57611c1e1f0903663cac8f39f7b08a40701735ca5ff69a63a55a2c4fe68df4f3
SHA3 8762419a853aa332268a3f62d3ecae09f07409872b10db1bd5f941ea55dcc160

507

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x98
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67356
MD5 20fb1c16c2fb378f7898586b5fead1f1
SHA1 422ebb7d48e88efe0018bab324b8d22daf843913
SHA256 fac1657ebf59503492e63acd008993e2f4e99eeea783438c2bc439d5ec61d061
SHA3 108352320e2fcffcb3038a953d93e57625136e0d5fec98ea3d32dd26c05f5758

511

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05265
MD5 5b5041058b8da985d7372f73ad1ad3de
SHA1 3ccfee7f0bc27975f37a4b83fe5fcb86b48f94a5
SHA256 95ecd179a6ff70d220eb881584a2473441e8acc62d16e02ffce93c742bb27a5b
SHA3 ab58f2f99298f21a71a2450509702c94df90f97f3ff49ad2fb61dcfebf90b1dc

602

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62197
MD5 1ed2fb1101579baf34b084389badb21d
SHA1 1fd06fc03e8ce1d2a1fa3d2aaa75859b92e96a94
SHA256 7fbf793fc596333bb6b11552851aa26641d5a314d225807679428703e29e8e3c
SHA3 b66674c6ca649a2b29fd887414284ea545014b728ddf144f4f2ee6942d3ada45

603

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56226
MD5 0302370b412c769ceb6b0fd381367883
SHA1 a6dd03f3ea1ba6f9ac7505fa21ecc599ceaf67a6
SHA256 517285748774fc94f5d79726361098036518c785ed63bdba50a0c892f7818b71
SHA3 0a821e65740280fedcc60d4213c9bd3f5a876a18804b4ab985cb369b3df7f6ad

605

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x232
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63488
MD5 5e39d4be865dd284a7f9624c0dd571f2
SHA1 df972e64a06f5074b1e7513515dd50ed4efed4a7
SHA256 9580e0cebbdc24bf896b22faa77d7751b51173d07fdd1e0d4a6e09c21d0f1ef6
SHA3 de74920253fe9c196832f7d6880833d4a1192eda06d18a727030c23a48446cf3

606

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80191
MD5 8bee3f9ac54d2fac61f37eafe56c1c1b
SHA1 ff2aec7dfd4585300bf95261c7ecc3347e2cde13
SHA256 a583b73fb1b5e826d9c5709c6caae3c3a04ee9125301e7740c3e655cce6952d4
SHA3 e0fd335d8427b9cf627d7c71b049aaeb954b9dbd21d6c01da7c8be968b5b544b

607

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x8c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4032
MD5 f18e5bc6afd9a34529db189b07c43af9
SHA1 7cee0818fb1ce1230b47efa7bbc2b2798da71974
SHA256 4d809a7f62bab96e41b9d541bf9326843e646b24d3d6dd621e2f543d79b6db0b
SHA3 c854006aa1dbd4f7fe6de00f4abe8688c4373e8ac1597e6b6a56587f8061936b

611

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88052
MD5 26336280647f084ce791c1ac1435094c
SHA1 017c3e619dbfa558b6fe8148c774d46fb3dcfaba
SHA256 80f10c203d2d7ef0deedb89ba928232b52047ab6fa7b71deb0c225b02d015eea
SHA3 3eddb7883e9492e6a82676a762523dfc0267ed747fd7adec406e411c35be8155

702

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9709
MD5 574849c09594bf406fe5f0b24d9080b8
SHA1 38608268473fb2fcd3e0f2315a492c737546c946
SHA256 2bf6e20d1b7aac0364482a6e48f6429cf48b8c0f744d6ff1cecbb3297416c893
SHA3 e07659d8daf9e860f9bac52009287326aad72cc5806cf3825d64dc1fbb699ff9

703

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
MD5 41c7a6a3ac78ff6413d02f624fa5a976
SHA1 ba65ad0c98a82bc87a30fac3d9f71f21ae54838c
SHA256 d48a10fcf79cbe2e6cbc316798ca7db637c57c31d4cff53fb604fcfeb2e6b2f5
SHA3 763ba05351831c759bac86551b48f45d8b89287303982cf130cf9dbefc539d33

705

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97282
MD5 419ea9162fcc5265997d90f72ca53e63
SHA1 21d3ca59efcaa7947ad3ebc060c59b3127df1211
SHA256 b7e2e2820d910a969e2296c7cfc450c9fd05f948c7c20729c30ee381e75e1209
SHA3 aa48f268617437ccbc26b5ad72b218cf280715a4a9eeb564f76947f8057077f3

706

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04873
MD5 023218e558a88386c1ddf83aa27e5d16
SHA1 0abbcaed1865698c5e2925a11d08622cd9c61b61
SHA256 597dfe9fba32cc94839b5b78833cea16d6196f1f00162263a167628adfeaf7f0
SHA3 c4964b45ebe880f9e233043589220d5a052cc64ba8da9f78581ad31f95684152

707

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79455
MD5 f487ea2664475901e7728e27028f78e1
SHA1 05a70c71e7e06c712ca99e8ce88bf6dd5779bdf2
SHA256 e705e251daa451ade5cc3f36278401ce4eb8b3e32ca0a7d5b7e03f525934d770
SHA3 33f0ad42457a216bac4cb66e6209ff5ba1aa1b9895f7e906a6d70fb58c9ed675

711

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01911
MD5 582ba3154fb8191d8288acd25e778f6b
SHA1 891323673a8428a7a6a838c894bbb11060478145
SHA256 0d022bebfa690ce3fbf128bcfc44bf6936c2fd6626f9460da89ca49632368939
SHA3 4277a513a71389354d89d15fbc015f2009db12c53deda668d3c1dd315a40a9d1

802

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63447
MD5 fab97a8381f73abc22dadd71f1e3ddc6
SHA1 1b7b6407f406adeb2d987f1e56bf4c253f39a239
SHA256 532e2112c57a72219970c759f62865067d6d31b4e1acf97280cd8e9aaee2b59f
SHA3 a0a71bed82f24790856fa562cfdfbc200a2caaaa8b595251b244661ce7897b28

803

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.545
MD5 86e700d5c53effbac2b967b33f35d824
SHA1 c9bb42a67350d01fe14019c9c4ea4bbb0b6a8584
SHA256 7d256f5d76bc52ec3b05d3c4a1b26dd3bd14ba7df6f16c93708a7f9805ea71df
SHA3 f7d4b652501f56adf5a5a2279f9fced26418c53fecbba457ae97f57525f513c2

805

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x232
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63241
MD5 2d68d7418ea4a2767a6f81e2aeb3e2f5
SHA1 662e0732346c42c3e8ec50650a3cb0d19da70990
SHA256 40e86a5e8657f6bc00bdc072887a17284ba8ad36f7e29f6da54136055abb0f1d
SHA3 07af2fd62e2035ec9f16926bc43cd139ed52d6419a11827ba8c3b2bfa160df42

806

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77471
MD5 b815bbabf37bddc6e8b9e55c9d31f12b
SHA1 ac49638a242bb5bb65f8aa883f5934ddf3580df9
SHA256 8bec95cdc0c8dbab7674b2e376399f0fd92d68c97a2c5226b97d99b1d5b16d0d
SHA3 c902ae29cce87d60bb6eb412f97a6d9a43b7098b78c7f2a9af18e3610bd9b516

807

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x8c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4032
MD5 9b3723824cb53db37937eae597b204e4
SHA1 4c8e5e1eb9c1ac7330ed5b1a86b7017659f2ddcf
SHA256 8ec647f9650b79179d5afc3e2bd8ecaa4b4617ada8c69c22382321a16f2153e0
SHA3 adae96de10c1b72db08f70fe15ca3214c3f374b2af3305eef7d58ba569766e0e

811

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88398
MD5 4f322b12f9655024a0906f87e3e0edc0
SHA1 9be699fbc8240382e0a511fbe95d9b86aa6570b1
SHA256 c53f8150b6af1f60fd252048650f3406f021642e6f64fde00722c24203526009
SHA3 c19a99f087b00520218c32864a1b2f3bda8192eb2f23b783c073feb9370aefd2

902

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77222
MD5 ac4c0f9289476de2ac0063307fdb2b5d
SHA1 c7ba5d223d0dec4e73bad3b6c259a41c9ce3bb21
SHA256 41e897b69ea656aada8496cd365ce0a68e8cac392fa204d05decbc8e5ceb5fb4
SHA3 5ecbed8eedefa8abfec5d36a2cf6c49a7b1ef789b478f6be6173123bc539fd6e

903

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64846
MD5 04d92c3a96df602b7f17f63db4380f65
SHA1 d8fc31914937318d8842429b0a6386c134b40109
SHA256 7c9baf41a9ac37fc0ce7b753aaa5b5b56f7796721cd66e11f78971217b285480
SHA3 bfe69dc0c1936744a7cfd634cfeb740e8b772fa798d6172a646266b6161d5b95

905

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x236
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68859
MD5 15fbb1db77a94b95910ec16a3815f022
SHA1 84515af02e462fa64a7b9ddc45309a384f977b6a
SHA256 1444a3e389e0799bd4bd414d5e764b480c28810cf85e9454abdffb205a1978bb
SHA3 bc110efe588f162d085f252779f0073da54b5613be1aaae38453b01cb9488d79

906

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90125
MD5 1277ef407c41099729b0e3d9fba944bf
SHA1 2072cc8f373c2225f6a4423f9ceb02edfcd34381
SHA256 d977042372b07a78905efafea3ba2b05737545ee73daa0a1d276cca3a08b2d06
SHA3 25ddba05e397413cf9354d6ceead55dc570ab2ee8a79a99693353c9039735e50

907

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x90
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.57512
MD5 08b86cd771567bfb5592cee9a624f8db
SHA1 c6ad899a33a52c7aaaa2413bba825f00a80f0c58
SHA256 35a4541f6a8d718c035768b617d0f2f59e7b57653058ad2cc0e7ddb77d9513e6
SHA3 59c16e6302f73e702aa57c613ca8a6831f081642b82011aa81f85fa54eb2ae31

911

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99097
MD5 4ea3c0528e8872806b75117b8257bb17
SHA1 54c0573b48c0b2c44239bc365eaf91dfb5064320
SHA256 1fab8c3f5dac78fc7a483bbf0c2ae66fec321440c022b72ab05d83ef336fbf60
SHA3 dc2a06b34489b71579bf0a951b2e085b1dd3a54b7403edae786a31584cd07b2d

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.67095
Detected Filetype Icon file
MD5 464cb94db3a2622922a9562865009ae8
SHA1 dbe17c767d942f219df59f9eae77b213c15eab70
SHA256 8affd1fa69a6c5a5b54e504d72d4e9a0eba9b7d702a445ea1399a5978794719a
SHA3 3e0e32110c6c0f3323eeeb5e4a6cbb7a8db52ab14e0f065384fb4eedac4fbcda

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x42e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28813
MD5 801ca73a087b948a8991dc4901c4dac6
SHA1 c7198cc2c47a562ad414c4a567fd18b2598f070b
SHA256 fb7414194d1b352675ad29558198470e4abb09321104a4c9289d4265c61e83a2
SHA3 9791e84b00fcf8f56a9552005aacd6b5abb53eabcbae494f383974013b6d3fdf

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
<-- -->