2c852b9d329284e85fca0e1cca876aca

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1988-Sep-10 18:43:53
Detected languages Chinese - Taiwan
English - United States
Italian - Italy
Japanese - Japan
Korean - Korea
Portuguese - Brazil
Process Default Language
TLS Callbacks 1 callback(s) detected.
Debug artifacts C:\teamcity-agent\work\ci_deploy_nbsninja_boot-x86_git\build.ninja\common\vs2017\x86\release\Installer\BootstrapperClient\BootstrapperClient.pdb
CompanyName Roblox Corporation
FileDescription Roblox
FileVersion 1, 6, 0, 5050420
LegalCopyright Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFilename Roblox.exe
ProductName Roblox Bootstrapper
ProductVersion 1, 6, 0, 5050420

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Contains references to internet browsers:
  • chrome.exe
Contains domain names:
  • adobe.com
  • ak.rbxcdn.com
  • amazonaws.com
  • cfly.rbxcdn.com
  • chromium.org
  • clientsettingscdn.roblox.com
  • clientsettingscdn.roblox.qq.com
  • crashes.rbxinfra.com
  • crashpad.chromium.org
  • http://ns.adobe.com
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://purl.org
  • http://www.roblox.com
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • http://www.winimage.com
  • http://www.winimage.com/zLibDll
  • https://127.0.0.1
  • https://crashpad.chromium.org
  • https://crashpad.chromium.org/
  • https://crashpad.chromium.org/bug/new
  • https://upload.crashes.rbxinfra.com
  • https://upload.crashes.rbxinfra.com/post
  • hw.rbxcdn.com
  • ll.rbxcdn.com
  • ns.adobe.com
  • nsroblox.roblox.com
  • rbxcdn.com
  • rbxcdn.qq.com
  • rbxinfra.com
  • roblox.com
  • roblox.qq.com
  • s3.amazonaws.com
  • setup-ak.rbxcdn.com
  • setup-cfly.rbxcdn.com
  • setup-hw.rbxcdn.com
  • setup-ll.rbxcdn.com
  • setup.rbxcdn.com
  • setup.rbxcdn.qq.com
  • setup.roblox.com
  • upload.crashes.rbxinfra.com
  • winimage.com
  • www.roblox.com
  • www.w3.org
  • www.winimage.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Microsoft's Cryptography API
Suspicious The PE is possibly packed. Unusual section name found: CPADinfo
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegQueryValueExA
  • RegQueryInfoKeyW
  • RegOpenKeyExA
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteKeyExW
  • RegDeleteKeyW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegDeleteValueW
  • RegCloseKey
  • SHDeleteKeyW
  • SHCopyKeyW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptDestroyHash
  • CryptAcquireContextW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • WinHttpSendRequest
  • WinHttpSetOption
  • WinHttpSetTimeouts
  • WinHttpOpenRequest
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpAddRequestHeaders
  • WinHttpReadData
  • WinHttpConnect
  • WinHttpCloseHandle
  • WinHttpOpen
  • WinHttpCrackUrl
  • WinHttpWriteData
  • InternetOpenW
  • InternetCloseHandle
  • InternetConnectW
  • InternetReadFile
  • InternetWriteFile
  • InternetQueryDataAvailable
  • InternetQueryOptionW
  • InternetSetOptionW
Leverages the raw socket API to access the Internet:
  • freeaddrinfo
  • inet_ntop
  • getaddrinfo
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
Info The PE is digitally signed. Signer: Roblox Corporation
Issuer: DigiCert EV Code Signing CA (SHA2)
Safe VirusTotal score: 0/67 (Scanned on 2021-12-01 18:37:22) All the AVs think this file is safe.

Hashes

MD5 2c852b9d329284e85fca0e1cca876aca
SHA1 1ac1b4dca085f47e47397cfbae9ab5fdcf304c0c
SHA256 3a8edc56b985cb0e13df87ec94d04c69e164498c7342be7348ee7681c9abddd3
SHA3 bd4c8fb884bc3966a6d4cbb4dfc0ffa799fc472a3f7c56ed8cc5d048b603afcc
SSDeep 49152:85pRmijePxH7vUVokYVyDnnihIXjJTBaIThG3ToNMrPMQVdACoTfFmstLvf:85pRB+d7gYVyDnnLzJ
Imports Hash 4b55af110e3322223ffbf8f637c383e8

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x128

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 1988-Sep-10 18:43:53
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x118800
SizeOfInitializedData 0x7d000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000CBE9E (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x11a000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x200000
SizeOfHeaders 0x400
Checksum 0x199f5f
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3dca734388122bb28d8bb7d9223a8f77
SHA1 6e048126c9c327becb122a77f29df491e1551036
SHA256 c06e1876aa14786c285ab59b0a925e41a0c5b45de74e89e92a5e442c522471fc
SHA3 ae53b0fd73d8037a7b4d569ba8af93b4c7a9e2c2f4dfdd012b91679233409103
VirtualSize 0x11861c
VirtualAddress 0x1000
SizeOfRawData 0x118800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54771

.rdata

MD5 886d8366720d4b0e721e590fcc5d1cf1
SHA1 a548f2d8330cddd2ba70e3274a84f2b47c4f89d0
SHA256 9eec4bc1a473ac8fc0b55bd86b786aa30f46e7a815a76a610edd884d541e2f78
SHA3 24168ec2f2b1306db5e46b1a315daf3588e880932166679e67e1a1e7306483da
VirtualSize 0x4b030
VirtualAddress 0x11a000
SizeOfRawData 0x4b200
PointerToRawData 0x118c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.6894

.data

MD5 697478f6399c17aa40db92cc8af998f0
SHA1 13c3bd01449e8a1b02ad74b865fdba00653f5c25
SHA256 db3707d117978ab814cbd5b03a8e5be31d3e6828f25b17db029dd8f703417b2c
SHA3 3904e0c2a5ae6b3724e4fd1a4031a4c6a581e043dc91d7aa0f01235cdb03d9f1
VirtualSize 0x6c3fc
VirtualAddress 0x166000
SizeOfRawData 0x6200
PointerToRawData 0x163e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.74738

CPADinfo

MD5 842689af09e7bf563672a4b43f1a2286
SHA1 87fd79e9cdafca9f691aeb6345b577953f4f53d0
SHA256 c6ab4dedabd0103aa45921ac166f6a9046356cb6073e10e06a3a8503472530cf
SHA3 abbb3e8624739cecd33afe9b57a68095eefc456c46e7dcc62374ca1c59012890
VirtualSize 0x28
VirtualAddress 0x1d3000
SizeOfRawData 0x200
PointerToRawData 0x16a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.122276

.rsrc

MD5 19de8f405884b72865e1bab40aeb958e
SHA1 3db243098705f18e31efbcadfdcf6a4070cee3fb
SHA256 22ecd139592a80dc8a1d4c9591111738f463d6aa29f4d4880dd030ccb4deede3
SHA3 f4325a00ac3ec5ab0fd1050e84552bd49dc03921d437d9b98c66d0f33485b6a0
VirtualSize 0x1db88
VirtualAddress 0x1d4000
SizeOfRawData 0x1dc00
PointerToRawData 0x16a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.94416

.reloc

MD5 e33313690761462c9fad54161e966a39
SHA1 59ed30ea77c8ff99629c82682977839696e495f4
SHA256 87fa4b7768564de59f3bb5c7f5196453571b11d42e60a0fef58ef58ecb47ee32
SHA3 beaf0b75342497dcfe16e1dde6a5115c2b75d076fe164eb89b9617e219b8675d
VirtualSize 0xdde8
VirtualAddress 0x1f2000
SizeOfRawData 0xde00
PointerToRawData 0x187e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.64658

Imports

POWRPROF.dll CallNtPowerInformation
WINHTTP.dll WinHttpSendRequest
WinHttpSetOption
WinHttpSetTimeouts
WinHttpOpenRequest
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpAddRequestHeaders
WinHttpReadData
WinHttpConnect
WinHttpCloseHandle
WinHttpOpen
WinHttpCrackUrl
WinHttpWriteData
KERNEL32.dll FindResourceA
CopyFileW
MoveFileW
VerifyVersionInfoW
GetSystemTimeAsFileTime
GetStdHandle
FindClose
FindFirstFileW
FindNextFileW
GetDiskFreeSpaceExW
RemoveDirectoryW
SetFileAttributesW
Sleep
GetCurrentProcess
TerminateProcess
GetExitCodeProcess
GetCurrentThread
CreateProcessW
OpenProcess
GetSystemTime
GetLocalTime
GetTickCount
GetVersionExW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
FreeLibrary
GetModuleFileNameW
LoadLibraryW
lstrlenW
BeginUpdateResourceW
UpdateResourceA
EndUpdateResourceW
SystemTimeToFileTime
GetGeoInfoW
GetUserGeoID
GetUserDefaultLCID
FreeConsole
AttachConsole
GetConsoleScreenBufferInfo
SetConsoleTextAttribute
CreateSemaphoreA
WaitForSingleObjectEx
ReleaseSemaphore
DuplicateHandle
GetModuleHandleA
K32EnumProcesses
K32GetProcessImageFileNameW
GetCommandLineW
GetShortPathNameW
SetLastError
CreateSemaphoreW
IsDebuggerPresent
GetCurrentProcessId
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
IsWow64Process
QueryPerformanceCounter
QueryPerformanceFrequency
FileTimeToSystemTime
FlushFileBuffers
GetFileSizeEx
SetFileTime
lstrcpyW
OpenEventA
LoadLibraryA
GetFileTime
FormatMessageA
GetSystemInfo
WaitForMultipleObjectsEx
SetWaitableTimer
ResumeThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetLogicalProcessorInformation
CreateWaitableTimerA
GetFileType
WideCharToMultiByte
LocalFree
CreateThread
GetExitCodeThread
GetVersion
SetProcessShutdownParameters
SetConsoleCtrlHandler
LockFileEx
SetEndOfFile
UnlockFileEx
GetProcessTimes
SuspendThread
GetProcessId
GetThreadContext
IsProcessorFeaturePresent
GetTimeZoneInformation
GetThreadLocale
GetSystemDefaultLCID
InitializeCriticalSection
VirtualQueryEx
ReadProcessMemory
SetNamedPipeHandleState
TransactNamedPipe
CreateNamedPipeW
WaitNamedPipeW
ConnectNamedPipe
DisconnectNamedPipe
CreateIoCompletionPort
GetQueuedCompletionStatus
PostQueuedCompletionStatus
UnregisterWaitEx
RegisterWaitForSingleObject
SetFilePointerEx
FindFirstFileExW
OutputDebugStringW
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
InitOnceExecuteOnce
MultiByteToWideChar
SetThreadPriority
SignalObjectAndWait
CreateTimerQueue
WriteConsoleW
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetOEMCP
GetACP
IsValidCodePage
GetFullPathNameW
GetCurrentDirectoryW
SetStdHandle
EnumSystemLocalesW
IsValidLocale
ExitProcess
SystemTimeToTzSpecificLocalTime
PeekNamedPipe
GetFileInformationByHandle
GetDriveTypeW
GetModuleHandleExW
FreeLibraryAndExitThread
lstrcmpW
ExitThread
GetConsoleOutputCP
ReadConsoleW
GetConsoleMode
GetCommandLineA
LoadLibraryExW
InterlockedFlushSList
InterlockedPushEntrySList
RtlUnwind
GetCPInfo
GetStringTypeW
GetLocaleInfoW
LCMapStringW
CompareStringW
SwitchToThread
EncodePointer
InitializeSListHead
GetStartupInfoW
UnhandledExceptionFilter
LocalAlloc
InitializeCriticalSectionEx
GetTempPathW
WriteFile
ReadFile
GetFileSize
VerSetConditionMask
GetCurrentThreadId
FindResourceW
SizeofResource
LockResource
LoadResource
FindResourceExW
GetFileAttributesW
CreateFileW
CreateDirectoryW
MulDiv
FormatMessageW
SleepEx
CreateEventA
GetProcAddress
GetModuleHandleW
OpenEventW
CreateEventW
CreateMutexW
WaitForSingleObject
ReleaseMutex
ResetEvent
SetEvent
CloseHandle
DeleteFileW
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
GetProcessHeap
HeapSize
HeapFree
HeapReAlloc
HeapAlloc
HeapDestroy
GetLastError
RaiseException
DecodePointer
GetThreadPriority
CreateTimerQueueTimer
ChangeTimerQueueTimer
DeleteTimerQueueTimer
GetNumaHighestNodeNumber
GetProcessAffinityMask
SetThreadAffinityMask
UnregisterWait
GetThreadTimes
VirtualAlloc
VirtualProtect
VirtualFree
InterlockedPopEntrySList
QueryDepthSList
SetUnhandledExceptionFilter
USER32.dll GetSystemMetrics
KillTimer
ReleaseDC
BeginPaint
GetDlgCtrlID
GetDlgItem
DrawTextW
SetTimer
EnableWindow
EndPaint
FillRect
LoadIconW
LoadBitmapW
PostMessageW
IsWindowVisible
SetForegroundWindow
GetWindowTextW
UnregisterClassW
CharUpperW
CharNextW
AllowSetForegroundWindow
MessageBoxExW
SendMessageW
DefWindowProcW
CallWindowProcW
CreateWindowExW
ShowWindow
GetDC
InvalidateRect
GetWindowRect
MessageBoxW
GetWindowLongW
MessageBoxA
RegisterClassW
SetWindowLongW
GetParent
GetMessageW
TranslateMessage
PostQuitMessage
DispatchMessageW
PostThreadMessageW
LoadAcceleratorsW
TranslateAcceleratorW
GetWindowThreadProcessId
SetWindowTextW
EnumWindows
DestroyWindow
GDI32.dll SetDCPenColor
SetDCBrushColor
SelectObject
RoundRect
SetBkMode
GetStockObject
CreatePen
GetDeviceCaps
DeleteObject
CreateSolidBrush
CreateFontW
SetTextColor
Rectangle
SHELL32.dll ShellExecuteW
SHGetFolderPathAndSubDirW
CommandLineToArgvW
Shell_NotifyIconA
ShellExecuteExW
#165
ole32.dll CoCreateGuid
StringFromGUID2
CoUninitialize
CoInitialize
CreateStreamOnHGlobal
CoCreateInstance
ADVAPI32.dll CryptReleaseContext
RegQueryValueExA
RegQueryInfoKeyW
RegOpenKeyExA
RegFlushKey
RegEnumValueW
RegEnumKeyExW
RegDeleteKeyExW
RegDeleteKeyW
GetUserNameW
OpenProcessToken
RegCreateKeyExW
RegSetValueExW
RegQueryValueExW
RegOpenKeyExW
RegDeleteValueW
RegCloseKey
CryptGetHashParam
CryptCreateHash
CryptHashData
CryptDestroyHash
BuildSecurityDescriptorW
BuildExplicitAccessWithNameW
ConvertStringSecurityDescriptorToSecurityDescriptorW
ImpersonateNamedPipeClient
RevertToSelf
SystemFunction036
GetTokenInformation
CryptAcquireContextW
SHLWAPI.dll PathAddBackslashW
SHDeleteKeyW
StrCmpNW
StrStrW
StrCmpW
PathFileExistsW
PathRemoveExtensionW
SHCopyKeyW
PathAppendW
PathRemoveFileSpecW
VERSION.dll GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
SensApi.dll IsNetworkAlive
WININET.dll HttpSendRequestExW
HttpEndRequestW
HttpQueryInfoA
HttpAddRequestHeadersW
InternetOpenW
InternetCloseHandle
InternetConnectW
InternetReadFile
InternetWriteFile
InternetQueryDataAvailable
HttpQueryInfoW
InternetQueryOptionW
InternetSetOptionW
HttpOpenRequestW
HttpAddRequestHeadersA
HttpSendRequestW
WS2_32.dll freeaddrinfo
inet_ntop
getaddrinfo
COMCTL32.dll #345
InitCommonControlsEx
_TrackMouseEvent
gdiplus.dll GdipAlloc
GdipFree
GdiplusStartup
GdiplusShutdown
GdipDisposeImage
GdipCreateBitmapFromStream
GdipCreateHBITMAPFromBitmap
GdipCloneImage
WINMM.dll timeSetEvent
timeGetDevCaps
timeBeginPeriod
timeGetTime

Delayed Imports

157

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x299
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.30906
Detected Filetype PNG graphic file
MD5 8c1df45f2214ab429392c89f6ec792bf
SHA1 ca2e99d5385a7f2035caecb3493c7a142eef749c
SHA256 2e512a3f77e5109f3a858cad954651cdf9d711e6a5fd1afc7b2c4c886e85e514
SHA3 af54f74632baaf08a0af61755e39f0726ae09cef1a1803d2d821d39e27bc1dfd

158

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x332
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.56743
Detected Filetype PNG graphic file
MD5 ce26e1488fce5a594efabdf51cd47925
SHA1 0157a0ed2f580e12c9b922eb7fe6c350d18f7991
SHA256 5bd023524116a046c4ccbaa5f0135f01a72c6bd601c4292db7bb49e167b5dbeb
SHA3 6e836d983d6dbaaf3d2e45146165dd7c150854f32ac65d5cafaa509462d9b053

159

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.4739
Detected Filetype PNG graphic file
MD5 f08ce75a5892e86ce83d1b4c054ee896
SHA1 3aa8f46e1928e439479ebe940bd1af3b0d5284d1
SHA256 73203ef33f691d679c82b4dfef0d188b6b31d8ab3f06026e6dedb05980e638b9
SHA3 ac5c2926fe0a2856f3ee842110e9e32487502b604589ae750c07720287236864

160

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x3b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62047
Detected Filetype PNG graphic file
MD5 1e898dd99415c425afe1edc7e859eed6
SHA1 2b8c1dcc27c9d7099919fda1a3c96567d1bb4e14
SHA256 25ec614d94423b40b76303b7ba4b56c94dc058ce7711ef82b769f16c68a2536e
SHA3 c74607f4f72e94103afda78683cbc6a197d2ee387802c18a4597add281c8338b

162

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x1ad8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9464
Detected Filetype PNG graphic file
MD5 ee081cde1cb3698aeb8575abbcaff3d7
SHA1 b83a7167ca3d01e5ae8fa5653bffa108caf9a482
SHA256 bbadcb7e7c630a43d281a73a91002997e362bb19fd6f89d1b69d43118b467d94
SHA3 702870ba66185890e4e99435d97d3e2232578e2a0c406690340f563d3fad430f

165

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x312b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89949
Detected Filetype PNG graphic file
MD5 d58608cf177502899208d58030976b5b
SHA1 603abd110eb42a934d2a0638fea9039a2f64e25d
SHA256 af332373ae218f1784a047de961018f482f8b9e9ab8b596eedb8794cb6f87b39
SHA3 d228e8eb9a3137922bdad614af4fd5d5c1df5893591234a32fddd79b0c84d65c

166

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x47a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.66343
Detected Filetype PNG graphic file
MD5 4f66cbb001c6e79e2aacb1003000d0d6
SHA1 a11f198d1c57b979eeab2f78a247e7ad88550718
SHA256 61beb9171d057cea7fd106a5c3c8fe78e1c461d9b1975c89c33d335a9f1f5a65
SHA3 185d1048e46446435e35577bb7a6473e992029733ab48042b51c4677a7d3a351

167

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x516
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.7187
Detected Filetype PNG graphic file
MD5 5e904dd75bdacec2b246cfa4d8cbee03
SHA1 4c3e8b3c2722cb081972dbbf92c4703e01dc1dd8
SHA256 145ad8a8f0a483286b272cddbf9f4b930a212025f3656302a944903b9cb01f8b
SHA3 058938d703a480c7d000e25b68f6ec8b85a667240199cfa95e47541c8a80ce00

168

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x336
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63294
Detected Filetype PNG graphic file
MD5 db87d4655fbcd0ff8f26c46171cc72ac
SHA1 00bfb143eecc22db3a56243a190fd0f38e83df23
SHA256 3d3872e70c747708de53ddf8649e7d714576a48eb79598c7210661c8411a8693
SHA3 c9415bc372a72775525cc50782b63d903a59d98a8d89114f86c4feee9f3dfee4

169

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x363
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.61217
Detected Filetype PNG graphic file
MD5 3b27679d47b7e05555c6e80a0fe63e86
SHA1 18add382f2c04e3752183003798fd007bbac1139
SHA256 5c101b99f8c8a9d9a5643f3e245b0881c43cff20abd5c9cac0e7b85d2c770f90
SHA3 09f6771ca460beb86b865737de0c400dc16721be6ae4e820189860a7119e611f

170

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x1230
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90587
Detected Filetype PNG graphic file
MD5 3bc8df1ae36711f8b8748d79a5d269a5
SHA1 35990d40b195ff2a0ef602020b1c6fbf16dcff71
SHA256 c5ee8e1e4f45b66dcb4b7508b4035538b316fd53e397393d6524864ec06987e9
SHA3 72b50ebeaa64d1b662143bec410e7197e69e4bdcd4cee534247febdd81d53e4e

171

Type PNG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x1134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91517
Detected Filetype PNG graphic file
MD5 555c74ca373bfe2e9b4ad3a1c690c426
SHA1 af701a3e684430af4360b166fc6932dfa7670fcc
SHA256 b36ed6a0908d9ad02fc18adb4c41bbb674f353ab404bf74bc15f0538a15ffa4d
SHA3 0d3135adae9cfc11d6a30ebf14905345b296fa6bf66bdca2e40c9a7799f50284

1

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.16757
MD5 123367216c387bd6d494138055f597e9
SHA1 d70e0bb2799ba617c27ed930908b4ea54212b9a1
SHA256 9f6b68b5e3817495a7cf75f6510b5a89b0c65f6103862fed0c4b042d6af4c0bf
SHA3 841d40939ceaf042492213a26981ca40ee0ced4f2fed7200cd0425dbac262ecc

2

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x78da
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93851
Detected Filetype PNG graphic file
MD5 a1c844c311b19a93a94d5eab273d7ab9
SHA1 93890bf109e8bfecda5921615a7afe679c3d30db
SHA256 699bb645edeb8dbbf70248927add1290b5b95ebff2a3b7db1f2ff6367a789de0
SHA3 7a8207abd5ed39ead1093f7142d96329cfdafa397fda29d3b3e189da858eeb18

3

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.77404
MD5 9b3dd0bfd8bf44a3b1b41995613bfcf8
SHA1 5e53027f6427dc6a3aecb079d2ff2ba015532597
SHA256 801c8c54cd503df17ae61d1ed49558c40938b5b17a42abaa162f9ccde1dcbd77
SHA3 9117ef8b5f33f987038641bedefc440b16fc72f03366a483b462d3ba3c799bbf

4

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x4120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.46883
MD5 6546a71e40bf3db06d085b9603bfd85c
SHA1 9828ec3709e1e5da236e9ed49d2a78c8a0fbd020
SHA256 ddfa3abebe9adb6367e4d2df8bbf6cfc17c55bf4baa3f1d1aac2f23565f014fa
SHA3 b020f05c1e87248e4facdaba8f1c58374693aa660b34cf74fe10f6ae88aff0fb

5

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.5291
MD5 184de50834826e4b931684668e1bdf5c
SHA1 81e2ceca85b44f710dcf7f5c6eb5df3a8aafa403
SHA256 4cead00ec0a0286695856c1101d9eae0bad58eee6eb5085edbd4da579239c6d2
SHA3 ce62f6588d2e8eec5be74abb0c8e90d4c090341c3549d4b4025b5e3d617dc311

130

Type RT_DIALOG
Language Process Default Language
Codepage Latin 1 / Western European
Size 0xfe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12907
MD5 d1abf688811da87c83e01743b3c1f726
SHA1 91a4d79a3dd276f4242f59889f2118bd25f8b5d7
SHA256 67ad3549b7386a7df9fcf2825450c74c99f089bbe81fa88898ad895c5d272805
SHA3 155eb34f9fc1cbd8baf42af1955bffa1c1159299a561d2c95c38314e07051d41

7

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.85602
MD5 822fd5c191e71b7d5cbd9af52d686aa8
SHA1 bb56dcaa48868826d2b5ca1dd7770c1a3ee489d7
SHA256 dbcc872a6e603832ec0dea6713d1e0b5cd47aaef5e770c919a3cc862b975e9ec
SHA3 0c5d2315c44e81c1bdafca1678357e2935a8061d9c0320ca8825bd9dc1d9e0c6

7 (#2)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x21c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44789
MD5 b7bfeb430e8a287e5fa4cb641874f6d0
SHA1 9acd7dc6b06931159af85e8c44836c0d2ae83a57
SHA256 5ca83a7c4b19aac413277fcc984673551abf71a09389f793df184dddb4948d25
SHA3 bb01371e744afa87cef36f1bc4deeb0bcfe25a3a08fd3a52eb8ca39a58347472

7 (#3)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x220
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40784
MD5 d97478bb26e241ae15e6ff60b50650cb
SHA1 c1a3eaa11acd8f731cb3a4edd98ef3825453de93
SHA256 e79c771ba76ec34c7de698d5e2129162006ee7d2fba679a00035cbca3c9b1550
SHA3 d58820b6a8747024d9619f5af1d484ed83f30e269407cd18ee6177f7cc42f514

7 (#4)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x236
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48305
MD5 b3868872ba55c2f767aefc8f831a5b07
SHA1 f3a97ee0f080ed149fc0537054ec95bd9b646541
SHA256 b2292beca2a38107b00d9162790d36a1d9dcfa1825d47828b34e5dab647591b9
SHA3 9d81613373df5470e5bc0aa3be3e631e391c49acb896d86e5e2504e1b8221c11

7 (#5)

Type RT_STRING
Language Chinese - Taiwan
Codepage Latin 1 / Western European
Size 0xe6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06832
MD5 775849b036d1ac2cf0c639d0ee932719
SHA1 0aae7bae5e2384b8786ced04e9a30e40e7fdb16c
SHA256 091ffb41fa1d502496e47b9b652c2aea5387aefd17f1c2cbe4eb9641601d2069
SHA3 5a219997b3c58279e819bb705c3f8915b7263e4c1b53b1707e9855637c80fccb

7 (#6)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x212
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51877
MD5 56478327cd4f86abcb59e54afe5bb1b8
SHA1 7813814dfa89b1798a9c39c630ab947e6b3fccb2
SHA256 37c061e88616019269f7f9c64d9a2e9532a0c428e857e6a386db41e7bdae8812
SHA3 7ace259139e5bcd13864b6b4513705c538b913c759b76dd800783ef169fbd5c8

7 (#7)

Type RT_STRING
Language Italian - Italy
Codepage Latin 1 / Western European
Size 0x234
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29444
MD5 c64516984014d906f0b1698d814ac988
SHA1 161726ed480fd63237691fcd8e12b1bc9c9b8a1a
SHA256 94277fd3c9bb7db1028ed1a3837bd06b46a83be50822a22f53d3e61b7305f807
SHA3 f7fed1cab01c524414a72af373bd1a90fcc0885447c39ed9d8f7c6b220475723

7 (#8)

Type RT_STRING
Language Japanese - Japan
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56947
MD5 db9106eed2f443f1ae4cf7eaf7fd7721
SHA1 4e47b063f8905d09371618dec723f1eb4273fd69
SHA256 3056af14a64ff587ca6fecde513181a17bfd6218c29146149fa325c5280fb088
SHA3 530462cf9f187aed0b6711385e562089596889df50a2c07659c57b199006eb57

7 (#9)

Type RT_STRING
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x11c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.78527
MD5 b635400cafbaf1889406d08b9b831cea
SHA1 9802960273ed8c25f01eaf9b9b1d9653b02ff807
SHA256 c9a5eefbd265f23cd84f70844603a474b66a918d07dcf36e33edd2fb480fcad6
SHA3 929465d56cab159191f65a7fc54688539092e79252eaad7721ba159d002948a7

7 (#10)

Type RT_STRING
Language Portuguese - Brazil
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38178
MD5 5461f60c196f792aa22edd958dfe0972
SHA1 d6a2a0e47fc3676b024e074a44c25397abbdc142
SHA256 09aef5011a5a4341708b22f9f6ddaf3947cda52b5d51ca0cb49c8b74fbdf7b1f
SHA3 cf33ed35a4d15b22c596878441c1e38dfb4acea38804aeaf75db89eab95f562b

8

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.30154
MD5 983159c9c6aeda694d1276f38947a2e5
SHA1 8af8a68a70b22a73eb384529a74e18cc9731ad64
SHA256 ee34da116d2d344298467ea82208ba6ac97c36a094fcfc175368c705c41cb27e
SHA3 2099508e292864b1d72e6a2780612739e46de5f72aa5eaf0b8b908f392b33e20

8 (#2)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.372
MD5 56935ee3de2c2f3c8bdc5191ad280a92
SHA1 2380a2242c43e813a75ea41d955f421a438f06cb
SHA256 693e2da88e830f5d7556e3c181d9d6327289a1f56fcb1cdc2a14568276a76274
SHA3 2dced0651a772aac286cf15daf676817f83803a1f2a42f5ed251a9cc62cafe24

8 (#3)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x406
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33363
MD5 904b93dda3e3df29a489cbddcfcc731a
SHA1 9dedf0972c7500674bd1d0ca11a8e9c6c7db4d55
SHA256 5ee04efda42c9ad4f49dd381deca6d57a799cc997c8fb6cd14387682a85fb380
SHA3 b3ee633080e4b00c5c088bde213b6dde3cd3a3356597cb9cfc894443723c9c66

8 (#4)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x47c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40355
MD5 2de356cb3852465787e0ae2b122caae9
SHA1 0b2ea9663fc191c710524d9babc6febbb47df3cd
SHA256 e02a9b5354e98f7e3d6acaccc54ca00f914ccff1e23d2a4a37957452c8716fa7
SHA3 6dfb3fbf8b83d4e38b9229459e9fc1813d2fd53a3e368584d469f1884f2514fd

8 (#5)

Type RT_STRING
Language Chinese - Taiwan
Codepage Latin 1 / Western European
Size 0x1bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.36127
MD5 b00b06085f562a4a14d24a44d85f9d4f
SHA1 2da5504e8fe775015ecf3d099d454599c62bcc2c
SHA256 fa14f04adb6926c6fc2d1a9aca8ed6fdfc06e27ccdcaed220bd2a682dc319d04
SHA3 381136f9c20772ca914998eba09668f2d04b7d98172a9b942e9f56e73d2c841f

8 (#6)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38224
MD5 e093b2a67f480dd187d2eef15446f7f1
SHA1 a6ef54324bc09513c240d1da0cffdae512d476da
SHA256 aa754f1307678e7886f6b2b8dd4db5020ff27cde39b4d4392da1fe58b46de8df
SHA3 1bdd3ef728fe9d750d30fc2eb1b6c10cf02d4f09ccb9766ab30419158e44b2bb

8 (#7)

Type RT_STRING
Language Italian - Italy
Codepage Latin 1 / Western European
Size 0x46e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32568
MD5 0de277d72ac2432a439e9e5211131b3a
SHA1 76ccc2302509f08ec4c1e2466e0ddfb7aeb2f19a
SHA256 2cad48da47450c358509f380b5cb49b9745803adc887e47b25397d9bcbd130f7
SHA3 8267bb9b53374c631a3d2ff80af1b7e59e0c6ffab3a40061d9d0a7a34feeb483

8 (#8)

Type RT_STRING
Language Japanese - Japan
Codepage Latin 1 / Western European
Size 0x236
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98014
MD5 b9980eb6a28a3d4d9bbf497bec1e83ae
SHA1 eaab2112c6b7c0f0c92cec4b5593706ffef2e35b
SHA256 97752553994a2cb25d25ca5ef0a9073fb56552575b2ecba3b6bca75ee5b88c74
SHA3 c9792faa54fe2d980ee6d261fbad643623928455e0dd768c4dd52936bbbeb240

8 (#9)

Type RT_STRING
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x266
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.08119
MD5 70da5f69e5905ed622fa9467d9de495c
SHA1 ac5e8e1c0a4918b59d694312faefc7da42669ee4
SHA256 baaa73499c69780a840e58777fd2bf5aa7269064284ba8d583c88ab49394f938
SHA3 edec130e8b01dc5647e6e0acced4640e3a30fe7737d5555da07e90a896aa6dac

8 (#10)

Type RT_STRING
Language Portuguese - Brazil
Codepage Latin 1 / Western European
Size 0x454
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3442
MD5 e4f983ce797bb5c83a082bd1c1489457
SHA1 155225df4da2d145ac9de8ad06f3de96f3ba6af4
SHA256 d4e606dadd311def083eb3d4d75300e3f475362718b18827f5d0d06560e23c21
SHA3 1977ff8eb377fe2d81127cfb151e75e9934c70759a0ba40b5fb55d36fffd11e5

9

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x176
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91787
MD5 4447ed90c9f5fccb56430f97630c8d3b
SHA1 9e4f692d246695c83d33255d1cf31e2421c9b321
SHA256 8aab438ede4dae8f9172d4b5344959add5286a0d1fc3d6635312d69a255aeef7
SHA3 736d3f1e300381e806161cf04b16bd6a2957aa19e6e9226426cb3b175e5f6caa

9 (#2)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15951
MD5 735eb907685bc9e056389c8f6c4b3989
SHA1 8d2b1cd986ab125181aeef0445bd413511408691
SHA256 2cd91ce9fb31ae408fdd7c0d81e374d458437721994a1258fa2aa5533bfd739a
SHA3 8de02913e72bf3f4b1a5e069a2696620def0f0533c6312bfaf4b1d8070adae44

9 (#3)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11118
MD5 4ed06230852d705beb3a9696a80c6d9d
SHA1 c755e9d91428647ff273b33186e8fecb91f4e3b7
SHA256 f0c8d1a66b6eb806b5f1d5d0abf1cd74bbaec51e8f4907a9baaa8f04a341ad7e
SHA3 e22ca22966c02b01768e30573ce94ee71ba777a9fec38c43980add9309d2f990

9 (#4)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x32a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10321
MD5 707d33caab0ad8c53bd1e8f460d362f3
SHA1 ec1bbc57717dbca8fb8525c75dcdf99760d308e2
SHA256 8d46fecc1d3993270a2ddcb60e989b0cf106cdd524942ddd0216a339513a3ad3
SHA3 a595bf8882c261164708b62e5b6a4386b1228df99346e2f961a1a9edae8c608a

9 (#5)

Type RT_STRING
Language Chinese - Taiwan
Codepage Latin 1 / Western European
Size 0x164
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.85322
MD5 302c680a1b949d1caf7fc93d495517bc
SHA1 f4604c1fcf247bfc4808b8db69e5b087e16e935d
SHA256 7a7ea46e33c24b219b983943b8f9c94d467650512da3c2e96c76ed57bd5fe336
SHA3 d0ee60087ed37677f699d1b28a8f3c979a887f67913659b6479ecc00d2092326

9 (#6)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x29c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08483
MD5 4a0be20d8d0f6bc45d873c44fb1beb74
SHA1 ba138bac8c8e3daf868f4475d201dcc9086ac9b9
SHA256 9e1d7c696de26e0b2399e86f7b592a7babd1dd956a9fe8b40ab50b3b310edb30
SHA3 aac9dd5688834f5a3b7a1e5a75b8151d6cdfa095e7dc3d3c459bb139840af67f

9 (#7)

Type RT_STRING
Language Italian - Italy
Codepage Latin 1 / Western European
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07555
MD5 e5b954d7a059e73ac52054da48d1c49e
SHA1 2ab8b2dbb8c2a8f6f5398e0a7f952fd09f9b0687
SHA256 8cddee50f99bd33a6dafb3fa605dd1faa4e19e4f8011694cc890a99ace144041
SHA3 2fc6beca6c2c2ea4eaa8dd0f8ff4bc4aec8417b3d30a54e35b67f2af8609511a

9 (#8)

Type RT_STRING
Language Japanese - Japan
Codepage Latin 1 / Western European
Size 0x1b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.37743
MD5 1537ab2d79ae4c5a43590e835ccb164c
SHA1 46aa49963b92a5ca21507272e83973608a7db9e9
SHA256 e36e00715c06a3139d860ddc1fa038d10c1b6cd9d31bb77665a89aad5bdc272a
SHA3 4a303b754fdb2e90809e755c1da23567675ea40eecf12e9700138c7ad9a4bf52

9 (#9)

Type RT_STRING
Language Korean - Korea
Codepage Latin 1 / Western European
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.62923
MD5 fd289e241d4460e980ed193ee11ece7f
SHA1 0e5856030461dab486095cfa77e8c72804547c54
SHA256 984f74f62e0ce3ac4533448e1cb8f4cedf1dea298872b9a0d4d2e6b54c18234d
SHA3 ac56f157727beb42d235796e6b1172893f6060241dce8e3445437a267a5eb06e

9 (#10)

Type RT_STRING
Language Portuguese - Brazil
Codepage Latin 1 / Western European
Size 0x29a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0813
MD5 ee8425cddbdfa1741bd7df70a6ef1d53
SHA1 d20487e45b912ab52c1ff5ec6f2f6924c55875db
SHA256 f8266a4b2d108b1f447c8698073559e978e28c673e447f16cc4377055b715b98
SHA3 626aaac814fb921a0b059d7046256e12a1d907f0b7ddb09b9b4060e3a552602e

11

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.10136
MD5 3cc1fd8bb98a60d73606e185ee29d78e
SHA1 31f7ac71520b50c32e26f2c2febf9615438c4bd6
SHA256 99cc367ca9f2c9fa7a2efa34c068262dcacd68dc16e0b103648e87b026139698
SHA3 93be0f363d7b2ddf9254e0fefc514bd9bd064c50efc554eeb5ddba69163017cb

12

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.38158
Detected Filetype Icon file
MD5 3bffe5c452dd015972f5ddb8457b92de
SHA1 414473c71cc8d6282b8a7eb954b666646065ea95
SHA256 e10955ef9dee62a5ca43578478bd4917bdfb2212b80742cd0843ce2e4f54a989
SHA3 7dde3971da69b58695aa5a0d654796e99e0e7d74c640cf7c65ffbb85121b1940

131

Type RT_ACCELERATOR
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2
MD5 89f0636f6e66627ef5529a478982c33e
SHA1 af1c3b7b4ba6e1718d2b6f2bef1f4740bca81393
SHA256 0e690e70c2c1e194b5534bbcfada8039486f6e4baebf26a3e7e29d43737012a9
SHA3 8f6d3dae032358c523cd9963714b6e5bc9d98d88c4e0913df15eabfccb47eb30

2 (#2)

Type RT_GROUP_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78815
Detected Filetype Icon file
MD5 6c13897f2c0637fc8924184b5f7039e7
SHA1 00541fb1339cfe44795fedc2dfb7652e45ffd27e
SHA256 3fcc92b225a1f07e00eaf9425af2aa7eb602b237a410c413be18156c31e49e8a
SHA3 08a50d628d22f3c58f4d678cedefd8e18120cb360e3aaeaa2b3a12d9475abc7c

1 (#2)

Type RT_VERSION
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42445
MD5 f2e3ddc19188e5095a44854fed004f4a
SHA1 2ad0857c15a064121e093ae1c82a0770c34d0de8
SHA256 00da95625df78822710bc0c2180bed7e307bfc6845c8b197e7269ee82c7b371c
SHA3 207b049388525b8573ec1d18b84b237051649665bf57d534b7b23d2fa2e700e6

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x3f2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28732
MD5 01cac5546ccdf5c8b8583bbf7027000b
SHA1 ef824c96f593c42a7af1db63e535a063922cba0b
SHA256 85028b9c1c709330726018e04ff3dfdc3594e12a0de6dd46e2df7408ec361c79
SHA3 67d2e6c0f6af3025698acbf30b5d1fb82ed1db615f9b22579e2b8243dc392b8b

String Table contents

ROBLOX 已成功安装!
点击'开始游戏'按钮即可加入行动!
ROBLOX STUDIO 已成功安装!
Click "运行 Studio" 开始制作你的新游戏!
下载并安装 %s
正在运行文件检查...
ROBLOX WURDE ERFOLGREICH INSTALLIERT!
Klicke auf 'Spielen' und stürze dich in die Action!
ROBLOX STUDIO WURDE ERFOLGREICH INSTALLIERT!
Klicke auf "Studio starten" und erschaffe dein neues Spiel!
Roblox herunterladen und installieren
Dateien werden geprüft ...
¡ROBLOX SE HA INSTALADO CORRECTAMENTE!
¡Haz clic en el botón Jugar en cualquier juego para unirte a la acción!
¡ROBLOX STUDIO SE HA INSTALADO CORRECTAMENTE!
¡Haz clic en Lanzar Studio para crear tu nuevo juego!
Descargar e instalar %s
Verificando el archivo ...
ROBLOX A ÉTÉ INSTALLÉ AVEC SUCCÈS !
Cliquez sur « Jouer » sur n'importe quel jeu pour plonger dans l'action !
ROBLOX STUDIO A ÉTÉ INSTALLÉ AVEC SUCCÈS !
Cliquez sur « Lancer Studio » pour créer votre nouveau jeu !
Télécharger et installer Roblox
Vérification du fichier...
ROBLOX 已成功安裝!
在任何遊戲按一下「開始遊戲」按鈕以加入行動!
ROBLOX STUDIO 已成功安裝!
按一下「啟動 Studio 」來製作您的新遊戲!
下載並安裝 Roblox
檔案檢查進行中…
setup.roblox.com
www.roblox.com
ROBLOX IS SUCCESSFULLY INSTALLED!
Click the 'Play' button on any game to join the action!
ROBLOX STUDIO IS SUCCESSFULLY INSTALLED!
Click "Launch Studio" to make your new game!
Download and install %s
Performing file check...
Roblox È STATO INSTALLATO CON SUCCESSO!
Clicca sul pulsante Gioca di uno qualsiasi dei giochi per iniziare!
Roblox STUDIO È STATO INSTALLATO CON SUCCESSO!
Clicca su Avvia Studio per creare il tuo nuovo gioco!
Scarica e installa roblox
Esecuzione del controllo dei file...
Robloxが正常にインストールされました!
いずれかのゲームに参加するには、「プレイ」ボタンをクリック!
Roblox Studioが正常にインストールされました!
新しいゲームを作成するには、「Studioを起動」をクリック!
Robloxのダウンロードとインストール
ファイルチェックを実行中...
ROBLOX 설치에 성공했어요!
원하는 게임의 '플레이' 버튼을 클릭하여 시작하세요!
ROBLOX STUDIO 설치에 성공했어요!
새 게임을 만들려면 "Studio 시작"을 클릭하세요!
Roblox 다운로드 및 설치
파일 확인 중...
ROBLOX FOI INSTALADO COM SUCESSO!
Clique no botão Jogar em qualquer jogo para entrar na ação!
ROBLOX STUDIO FOI INSTALADO COM SUCESSO!
Clique em Iniciar Studio para criar seu novo jogo!
Baixe e instale Roblox
Verificando o arquivo...
文件检查完毕
启动 %s ...
%s 已是最新版本
正在升级 %s ...
正在安装 %s ...
正在连接至 %s ...
下载最新版引导程序?
正在获取最新版本的 %s ...
请稍候 ...
正在关闭 %s
正在卸载 %s ...
%s 已卸载
正在配置 %s ...
取消
7 月 7 日开始,Roblox 应用程序将会需要 DirectX 10 以上功能级别的支持。若要继续使用 Roblox 应用程序,请使用符合 Roblox 系统需求的设备。
Dateiprüfung abgeschlossen
%s wird gestartet ...
%s ist auf dem neuesten Stand
%s wird aufgewertet ...
%s wird installiert ...
Verbindung zu %s wird hergestellt ...
Neuesten Bootstrapper herunterladen?
Neueste Version von %s wird beschafft ...
Bitte warten ...
%s wird abgeschaltet
%s wird deinstalliert ...
%s wurde deinstalliert
%s wird konfiguriert ...
Okay
Abbrechen
Ab dem 7. Juli erfordert die Roblox-App Unterstützung von DirectX 10 oder höherer Feature-Levels. Um die Roblox-App weiterhin benutzen zu können, verwende bitte ein Gerät, das die Systemanforderungen von Roblox erfüllt.
Verificación del archivo finalizada
Inicializando %s ...
Roblox está actualizado
Actualizando %s ...
Instalando %s ...
Conectando a %s ...
¿Descargar el programa de arranque más reciente?
Obteniendo la versión más reciente de %s ...
Espera...
Cerrando %s
Desinstalando %s ...
%s ha sido desintalado
Configurando %s ...
Aceptar
Cancelar
A partir del 7 de julio, la aplicación de Roblox requerirá DirectX 10 o superior. Para seguir usándola, utiliza un dispositivo compatible con los requisitos de sistema de Roblox.
Vérification du fichier terminée
Lancement de : %s...
%s est à jour
Amélioration de : %s...
Installation de : %s...
Connexion à : %s...
Télécharger le plus récent bootstrapper ?
Récupération de : %s…
Veuillez patienter...
Fermeture de : %s
Désinstallation de : %s...
%s a été désinstallé
Configuration de : %s...
OK
Annuler
Le 7 juillet, l'application Roblox nécessitera la prise en charge du niveau DirectX 10 ou un niveau de fonctionnalité supérieur. Pour continuer à utiliser l'application Roblox, utiliser un appareil compatible avec les exigences du système de Roblox.
檔案檢查完成
正在啟動 %s …
%s 已是最新版本
正在升級 %s …
正在安裝 %s …
正在連線到 %s …
下載最新的bootstrapper?
正在擷取最新的 %s …
請稍後 …
正在關閉 %s
正在卸載 %s …
%s 已安裝
正在設定 %s …
確定
取消
Roblox 應用程式從 7 月 7 日開始將需要 DirectX 10 以上才可運行。若要繼續使用 Roblox 應用程式,請使用符合 Roblox 系統需求的裝置。
File check complete
Starting %s ...
%s is up-to-date
Upgrading %s ...
Installing %s ...
Connecting to %s ...
Download the latest bootstrapper?
Getting the latest %s ...
Please Wait ...
Shutting down %s
Uninstalling %s ...
%s has been uninstalled
Configuring %s ...
OK
Cancel
On July 7, the Roblox application will require DirectX 10 or higher feature level support. To keep using the Roblox application, please use a device that is compatible with Roblox’s system requirements.
Controllo dei file completato
Avviamento di %s...
%s è aggiornato
Aggiornamento di %s...
Installazione di %s...
Connessione in corso a %s...
Scarica l'ultimo bootstrapper?
Recupero ultimi aggiornamenti di %s...
Attendere prego...
Chiusura di %s
Disinstallazione di %s...
%s è stato disinstallato
Configurazione di %s...
OK
Annulla
Il 7 luglio, l'applicazione Roblox richiederà DirectX 10 o il supporto di livello di funzionalità superiore. Per continuare a utilizzare l'applicazione Roblox, utilizzare un dispositivo compatibile con i requisiti di sistema di Roblox.
ファイルチェックが完了
%sを開始中...
%sは最新です
%sをアップグレード中...
%sをインストール中...
%sに接続中...
最新のブートストラッパーをダウンロードしますか?
最新の%sを取得中...
お待ちください...
%s をシャットダウン中
%sをアンインストール中...
%sをアンインストールしました
%sを設定中...
OK
キャンセル
7月7日から、RobloxアプリにはDirectX 10以降の機能レベルサポートが必要になります。Robloxアプリを使用し続けるには、Roboxのシステム要件と互換性のあるデバイスをお使いください。
파일 확인 중...
%s 시작 중...
%s이(가) 최신 상태네요
%s 업그레이드 중...
%s 설치 중...
%s에 연결 중...
최신 bootstrapper를 다운로드할까요?
최신 %s을(를) 가져오는 중...
잠시 기다려주세요...
%s 종료 중
%s 삭제 중...
%s이(가) 삭제되었어요
%s 구성 중...
확인
취소
오는 7월 7일부터, Roblox 응용 프로그램 사용에는 DirectX 10 이상의 기능 수준 지원이 필요합니다. Roblox 응용 프로그램을 계속 사용하려면 Roblox의 시스템 요구 사항과 호환되는 기기를 사용하세요.
Verificação concluída
Iniciando %s...
%s está atualizado
Fazendo upgrade %s...
Instalando %s...
Conectando-se ao %s...
Baixar a versão mais recente do bootstrapper?
Obtendo a versão mais recente do %s...
Aguarde...
Desligando %s
Desinstalando %s...
%s foi desinstalado
Configurando %s...
OK
Cancelar
A partir de 7 de julho, o aplicativo da Roblox terá como requerimento o suporte de nível de recursos para DirectX 10 ou superior. Para continuar utilizando o aplicativa da Roblox, utilize um dispositivo que seja compatível com este requisito de sistema.
请注意,出于安全原因,Roblox 的下一个更新版本中将不再支持 Windows XP 或 Vista 系统。若要继续使用 Roblox,请更新至 Windows 7 或更高版本。
请注意,出于安全原因,Roblox 将不再支持 Windows XP 或 Vista 系统。若要继续使用 Roblox,请更新至 Windows 7 或更高版本。
Bitte beachte, dass Roblox in der nächsten Version aus Sicherheitsgründen Windows XP oder Vista nicht mehr unterstützen wird. Um Roblox weiterhin zu spielen, aktualisiere bitte auf Windows 7 oder höher.
Bitte beachte, dass Roblox aus Sicherheitsgründen Windows XP oder Vista nicht mehr unterstützt. Um Roblox weiterhin zu spielen, aktualisiere bitte auf Windows 7 oder höher.
Por razones de seguridad, el próximo lanzamiento de Roblox dejará de ser compatible con Windows XP o Vista. Para seguir jugando Roblox, actualiza a Windows 7 o a una versión superior.
Por razones de seguridad, Roblox ya no es compatible con Windows XP o Vista. Para seguir jugando Roblox, actualiza a Windows 7 o a una versión superior.
Note que, pour des raisons de sécurité, dans la prochaine mise à jour, Roblox ne supportera plus Windows XP ou Vista. Pour continuer à jouer à Roblox, il faut faire une mise à niveau vers Windows 7 ou supérieur.
Note que, pour des raisons de sécurité, Roblox ne supporte plus Windows XP ou Vista. Pour continuer à jouer à Roblox, il faut faire une mise à niveau vers Windows 7 ou supérieur.
為了保護使用者的安全,Roblox 在下一個版本裡不再支援 Windows XP 或 Vista。若要繼續使用 Roblox,請升級到 Windows 7 或更高版本。
為了保護使用者的安全,Roblox 已不再支援 Windows XP 或 Vista。若要繼續使用 Roblox,請升級到 Windows 7 或更高版本。
Please note that for security reasons, in the next release Roblox will no longer support Windows XP or Vista. To keep playing Roblox, please upgrade to Windows 7 or above.
Please note that for security reasons, Roblox no longer supports Windows XP or Vista. To keep playing Roblox, please upgrade to Windows 7 or above.
Per motivi di sicurezza, col prossimo aggiornamento Roblox non supporterà più Windows XP o Vista. Per continuare a giocare a Roblox, aggiorna a Windows 7 o superiore.
Per motivi di sicurezza, Roblox non supporta più Windows XP o Vista. Per continuare a giocare a Roblox, aggiorna a Windows 7 o superiore.
セキュリティのため、次にリリースするRobloxはWindows XPまたはVistaに対応しなくなりますのでご注意ください。Robloxをプレイし続けるには、Windows 7以降にアップグレードしてください。
セキュリティのため、RobloxはWindows XPまたはVistaに対応しておりませんのでご注意ください。Robloxをプレイし続けるには、Windows 7以降にアップグレードしてください。
다음 릴리스부터 Roblox는 보안상의 이유로 인해 Windows XP 및 Vista를 지원하지 않을 예정입니다. Roblox를 계속해서 플레이하려면 Windows 7 이상으로 업그레이드하세요.
Roblox는 보안상의 이유로 인해 Windows XP 및 Vista를 더 이상 지원하지 않습니다. Roblox를 계속해서 플레이하려면 Windows 7 이상으로 업그레이드하세요.
Please note that for security reasons, in the next release Roblox will no longer support Windows XP or Vista. To keep playing Roblox, please upgrade to Windows 7 or above
Please note that for security reasons, Roblox no longer supports Windows XP or Vista. To keep playing Roblox, please upgrade to Windows 7 or above.
VANILLA

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.6.0.4148
ProductVersion 1.6.0.4148
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Roblox Corporation
FileDescription Roblox
FileVersion (#2) 1, 6, 0, 5050420
LegalCopyright Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFilename Roblox.exe
ProductName Roblox Bootstrapper
ProductVersion (#2) 1, 6, 0, 5050420
Resource LangID Process Default Language

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1988-Sep-10 18:43:53
Version 0.0
SizeofData 169
AddressOfRawData 0x155788
PointerToRawData 0x154388
Referenced File C:\teamcity-agent\work\ci_deploy_nbsninja_boot-x86_git\build.ninja\common\vs2017\x86\release\Installer\BootstrapperClient\BootstrapperClient.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 1988-Sep-10 18:43:53
Version 0.0
SizeofData 20
AddressOfRawData 0x155834
PointerToRawData 0x154434

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 1988-Sep-10 18:43:53
Version 0.0
SizeofData 1020
AddressOfRawData 0x155848
PointerToRawData 0x154448

UNKNOWN

Characteristics 0
TimeDateStamp 1988-Sep-10 18:43:53
Version 0.0
SizeofData 36
AddressOfRawData 0x155c44
PointerToRawData 0x154844

TLS Callbacks

StartAddressOfRawData 0x555c78
EndAddressOfRawData 0x555c84
AddressOfIndex 0x5d11c0
AddressOfCallbacks 0x51ab60
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks 0x00488AE0

Load Configuration

Size 0xa0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x5669f4
SEHandlerTable 0x554e80
SEHandlerCount 578

RICH Header

XOR Key 0xfe598225
Unmarked objects 0
ASM objects (27412) 19
C++ objects (27412) 197
C objects (VS 2015/2017 runtime 26706) 40
ASM objects (VS 2015/2017 runtime 26706) 28
C++ objects (VS 2015/2017 runtime 26706) 126
C objects (27412) 27
262 (27412) 1
Imports (27412) 39
Total imports 427
C objects (27045) 8
ASM objects (27045) 2
C++ objects (27045) 133
C++ objects (27040) 60
Resource objects (27040) 1
Linker (27040) 1

Errors

<-- -->