423c8db505c3d5ef3bbf757db7489185

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2068-Jun-21 06:07:02
Detected languages English - United States
Debug artifacts wextract.pdb
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion 11.00.18362.1 (WinBuild.160101.0800)
InternalName Wextract
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WEXTRACT.EXE .MUI
ProductName Internet Explorer
ProductVersion 11.00.18362.1

Plugin Output

Suspicious PEiD Signature: FASM 1.5x
FASM v1.5x
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • Command.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExA
Can access the registry:
  • RegDeleteValueA
  • RegOpenKeyExA
  • RegQueryInfoKeyA
  • RegSetValueExA
  • RegCreateKeyExA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetDriveTypeA
  • GetVolumeInformationA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE header may have been manually modified. Resource CABINET detected as a CAB Installer file.
The resource timestamps differ from the PE header:
  • 1984-Jul-09 11:30:10
Resources amount for 99.5485% of the executable.
Info The PE is digitally signed. Signer: Bright Pattern
Issuer: Go Daddy Secure Certificate Authority - G2
Safe VirusTotal score: 0/68 (Scanned on 2020-08-12 00:48:41) All the AVs think this file is safe.

Hashes

MD5 423c8db505c3d5ef3bbf757db7489185
SHA1 b04ee5e6cace9113f41c10e1fbe9af7e49fe0ea5
SHA256 627e652cbbead7c03ca86f6f6e94bd29fa0e03fecf8aed998e33ae7eb2482980
SHA3 e3b1765194a9f5f15adfbb9473bba17278c9c8a2c6bcf1e0e290ee012a53c632
SSDeep 196608:FPHFmLGP+2ny5Z8c9q8dmYNOuHe6e57rfwE0RXE0mZkTHDy+rdB74dAZrr4PBQ:BFmCP+2KZ8ccSmYPzGoE50tTjTrzkdM1
Imports Hash 70b556b41b778b1a079ff04aed97c90f

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2068-Jun-21 06:07:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x6400
SizeOfInitializedData 0x964200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00006A00 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x970000
SizeOfHeaders 0x400
Checksum 0x97ab1e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x40000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 af345ff4844caf4b46f0d1de66ba215c
SHA1 8919b585a103c2f0fd9eed6a23025319806ac3bf
SHA256 a3f75bcd69d5a8b6e62fca16cbec17125b0814fc622e2c10930d1b67c3e58621
SHA3 e8e7d3a8b170c3e215ad3a7da0560dfbc2b4dc7bfad90ce1ba39539590cdaa8a
VirtualSize 0x62c4
VirtualAddress 0x1000
SizeOfRawData 0x6400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.30395

.data

MD5 7b9890a93c0516bb070e1170cfde54d5
SHA1 9c268b36dcf88164c756c6557ee5339ddd593e21
SHA256 f8c66e81a1fc8e3021ffdba20f5fd57b4efb06957d5262c03e4902f4261f9e15
SHA3 ddf319cab06e9cd66f57bf5daa68cf59781f55249f0f818119855d1ddf93afef
VirtualSize 0x1a48
VirtualAddress 0x8000
SizeOfRawData 0x200
PointerToRawData 0x6800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.97064

.idata

MD5 6dd96376163996642ea3177eb8f57ce1
SHA1 655048b76cfea1213fbdeae9fcb27de4ef76ea67
SHA256 41698c8d72d80d603607d936bed037d16cee28052a80a35f24da2d319cc1b3bc
SHA3 66322cf4085dad131b2c83dc4079313513569c11d2f02475995ebbffc6e5523e
VirtualSize 0x1052
VirtualAddress 0xa000
SizeOfRawData 0x1200
PointerToRawData 0x6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.0209

.rsrc

MD5 f41d339e4ba2d6c75d79ba4faa357b2f
SHA1 f6aaa2b5e49fa271b6e249fa3d2ee3b9128b347a
SHA256 95de2658a736849ab7449080510f9a0796d11b7c64e661fc9a6b269115e2660b
SHA3 2820c2287242e0d28547451eb985801eb1e17cecc66575a850c812d802428dd5
VirtualSize 0x963000
VirtualAddress 0xc000
SizeOfRawData 0x962400
PointerToRawData 0x7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99723

.reloc

MD5 ddba0788e55665f614e9118142a37359
SHA1 4c50e439979903b21c78ee07297da40caa25e64d
SHA256 2e581c471e99bbb8b7a5800d75b5da64d416ff7cc52629e23ac60b87f35d707f
SHA3 c0c2d8d4d9a86865979e03eed7237452120c9b80ce7f2a48382f1cc54a4534a4
VirtualSize 0x888
VirtualAddress 0x96f000
SizeOfRawData 0xa00
PointerToRawData 0x96a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.27286

Imports

ADVAPI32.dll GetTokenInformation
RegDeleteValueA
RegOpenKeyExA
RegQueryInfoKeyA
FreeSid
OpenProcessToken
RegSetValueExA
RegCreateKeyExA
LookupPrivilegeValueA
AllocateAndInitializeSid
RegQueryValueExA
EqualSid
RegCloseKey
AdjustTokenPrivileges
KERNEL32.dll _lopen
_llseek
CompareStringA
GetLastError
GetFileAttributesA
GetSystemDirectoryA
LoadLibraryA
DeleteFileA
GlobalAlloc
GlobalFree
CloseHandle
WritePrivateProfileStringA
IsDBCSLeadByte
GetWindowsDirectoryA
SetFileAttributesA
GetProcAddress
GlobalLock
LocalFree
RemoveDirectoryA
FreeLibrary
_lclose
CreateDirectoryA
GetPrivateProfileIntA
GetPrivateProfileStringA
GlobalUnlock
ReadFile
SizeofResource
WriteFile
GetDriveTypeA
lstrcmpA
SetFileTime
SetFilePointer
FindResourceA
CreateMutexA
GetVolumeInformationA
ExpandEnvironmentStringsA
GetCurrentDirectoryA
FreeResource
GetVersion
SetCurrentDirectoryA
GetTempPathA
LocalFileTimeToFileTime
CreateFileA
SetEvent
TerminateThread
GetVersionExA
LockResource
GetSystemInfo
CreateThread
ResetEvent
LoadResource
ExitProcess
GetModuleHandleW
CreateProcessA
FormatMessageA
GetTempFileNameA
DosDateTimeToFileTime
CreateEventA
GetExitCodeProcess
FindNextFileA
LocalAlloc
GetShortPathNameA
MulDiv
GetDiskFreeSpaceA
EnumResourceLanguagesA
GetTickCount
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetStartupInfoW
Sleep
FindClose
GetCurrentProcess
FindFirstFileA
WaitForSingleObject
GetModuleFileNameA
LoadLibraryExA
GDI32.dll GetDeviceCaps
USER32.dll SetWindowLongA
GetDlgItemTextA
DialogBoxIndirectParamA
ShowWindow
MsgWaitForMultipleObjects
SetWindowPos
GetDC
GetWindowRect
DispatchMessageA
GetDesktopWindow
CharUpperA
SetDlgItemTextA
ExitWindowsEx
MessageBeep
EndDialog
CharPrevA
LoadStringA
CharNextA
EnableWindow
ReleaseDC
SetForegroundWindow
PeekMessageA
GetDlgItem
SendMessageA
SendDlgItemMessageA
MessageBoxA
SetWindowTextA
GetWindowLongA
CallWindowProcA
GetSystemMetrics
msvcrt.dll _controlfp
?terminate@@YAXXZ
_acmdln
_initterm
__setusermatherr
_except_handler4_common
memcpy
_ismbblead
__p__fmode
_cexit
_exit
exit
__set_app_type
__getmainargs
_amsg_exit
__p__commode
_XcptFilter
memcpy_s
_vsnprintf
memset
COMCTL32.dll #17
Cabinet.dll #22
#23
#21
#20
VERSION.dll GetFileVersionInfoA
VerQueryValueA
GetFileVersionInfoSizeA

Delayed Imports

3001

Type AVI
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e1a
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.52241
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 f9035cf32b756fd6a452e9fdfd4a5dd9
SHA1 6912e88a3ee4d2c98ca69772cec564c6334fd9c4
SHA256 3bd1d253c90f7e82dc70dc1e4b869cc2e5e154e6b4079be93837e4a6c68044c0
SHA3 8cd00290363b6d3e609845f2e5828f3e2adaf35c4a97561bcf427bbd054401a6

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.0699
MD5 1119ea8ccf13471c5cb7981c00112bd1
SHA1 5311a1759e6269a3cb555795379241550dc70baf
SHA256 689e072bec88a4f92eeadc6ada816cbcbedc4de9e76b27c38183f820bcc11e04
SHA3 2829f8159ff036d9f6a40b9fad5416e1c3458ad61e83e0139a92c36620b75e99

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.15864
MD5 46db957427f76e2faed509fa0f083815
SHA1 9f062ff76b99cdbbdbc040adca1ec94fd7e0ebf8
SHA256 3032bc8ec0d2b10c731ce65338958a69401a6ea5c13bf43236be1cadfaaa796f
SHA3 d64af304edb5ed919be1e617b3194ad9d40d97f07942bc10ffe3529713358797

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.07737
MD5 53892c6e1aa6882a0e541da89c8bed9b
SHA1 74093737e0c001a618623b84ae2a7c0ae105870b
SHA256 c6f49cc3ab503756f46a301d8543d1ed4db7e037b4df86407d24de6542a9b241
SHA3 28c5ddd935a6f3e2a9112068eb23447d12c5b75a05fabd52aba335a36d3cd694

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.50949
MD5 77c3fdd8ab3a5023f948ef9dc0a75588
SHA1 3c10786225e3af4724ad179081ab67b7bdddb002
SHA256 472af970994f80d1368af62de093894cdef4e2ea76f661eabc49e4f7e41a5860
SHA3 c7ef5cf31e71ee1211fe1b9ec1aab03e0cc3d9c88d358837f2bf4982d8e83469

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.56662
MD5 9291ba83d585b4e27b489e5e6c0b9e6d
SHA1 6a1823c83ba0ee8a9088c2d96c951ff7b0aad0ed
SHA256 828bf50bd62a7fca6f0ee8d03970215d1550d31a4f9382b1608b76742ef8aa95
SHA3 2201c2224048249b39ff38a95ea21061ad85214a9912fb00474b96082ce81112

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.94251
MD5 dd6416457884b08fb3b97e48cd8b296d
SHA1 460407ba589b388b7095dac3cba861d07d0bc32d
SHA256 5a2bcb6347493ac6873330f55603ae586a8b21ab1a7137f7b326b6e682827892
SHA3 ff855ab2a14ba17cb2d90b6bdaee4e2257ee959788fa22e7a62a25a86fe401ec

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.99361
MD5 d9189a0ae5a4ce576b2cd6a3aee869d2
SHA1 546acefecec2664dafd9c62b84211d32c5c25ddc
SHA256 563e2c3128746f769950f3ccb9267525888c91c6437692a719541acd71afad5c
SHA3 4589be5962a881128d7157d9d319ba7ed7c15b7a5c322de0ce2ec6b795bf4191

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.37828
MD5 ff4b77125d8d6dd0bb13557a6e043d70
SHA1 4f401d2b2fdd25337757c115b0c3d16850ee90df
SHA256 4429f0eabd35418cb2022378e73ee2e766841d35aca4a8b7369359d1341304fe
SHA3 915504672b75c8aa786fa9065ade3aaccb2a03a46fe59b92c0f65e502ae43196

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xd9d2
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 7.98515
Detected Filetype PNG graphic file
MD5 d58effc60f9809303be37c9da12ec938
SHA1 5f5d1459f715b6d7ac0c9f5e6c86112d02c611a8
SHA256 f169eed8248d8f9efd20dd716790f2b3bb0547687546811b4137be21b5c63b71
SHA3 927f706c7c34a5b18477f72fb37fca3487c206f65f015b40463be7083a461c7b

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.33023
MD5 6f18b3932aca200c19eda2c0a8389fe2
SHA1 454e38e44e9570502d4134818f983e6b3514c595
SHA256 ebfd8bce706bc334ada961a2489fb266101c8960e05bd20fbf2e8ee66af64060
SHA3 2f401e2395d28434ceed9c91f17de1595dcfd794e537304dd0c8867ea9c4be60

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.61313
MD5 56e519ddae3afada70d9d5afc3e20414
SHA1 584a6b17a1a2174921a185cc123bb8e609f0f0ba
SHA256 fa6b2f5422746f7377a3ed24f2b108f04f963caa0cc096c51cb49ac74266b107
SHA3 1896fe210c328289e0e771e497715e6c92d6e2545625858358002ceb5d1c7ee9

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.90788
MD5 5102430eabaa9f88a657c8a2d9a00547
SHA1 6f202d879a72db4c054632a883f9d3c3d1a28dac
SHA256 6f44d16ede32521ef7336056baff805a3305f225430de3bd01203ff0625c23d1
SHA3 5e8efdae85f063f0502553f6fe4fd93d6882663a77b5513c8e06b5e23f1f99a0

13

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 4.85349
MD5 6948b3a73688c3ea8fbd7f533a579e25
SHA1 931d017e52aa63fec9f1401436e07e3df2573e1b
SHA256 8561da4d70ae051d1f146859ba0b50467258730daae8af73726e0700c034b737
SHA3 2e6fc86970dfb7e8d036900a05d4c89591b3ab0a597a5074ea56489aa68d3414

2001

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2f2
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.25575
MD5 733ab5b92105575b10e4716e64f874a7
SHA1 84177368dd4658cebdc991269a7584907f5dcc57
SHA256 ea6588cf6a9eaa2daaeace3bcd90ad19cfaca72505c0cbba9f10a0db2923d888
SHA3 7ed0210cc660b29977851bb04b3cf3c27eb4ea9953117e019b774d7b974ec128

2002

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b0
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.16025
MD5 57c16fb56b83819ba4b6267c6dddb013
SHA1 1477b9eb543fbd469c392064e4147d47e74dbb46
SHA256 1abfad902cece4ff79c75ee25d79fe254e3c6af72c161295c7ba006e56cd74b1
SHA3 941c199bcd737811c390814980c5ac4b546ef6538677f9599de9e7afed0bcb46

2003

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x166
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.99713
MD5 dc468a007b317c7439d83a5985cea5a7
SHA1 3d89aacc7eebd8c046e2f0e95f66b2b54d577568
SHA256 ec8a0548b6bb169afe513ec8a366e746255c3556fe66c95067756fb3ec8b895b
SHA3 505917a9fccb89b46551e12f0ced60758a952248cd6f0f7c69967e2e6eabea8d

2004

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1c0
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.11992
MD5 a5187dc5894162b201fe774046408732
SHA1 81611f2aa32cfc8b03f00856f319870e97554b7d
SHA256 a3565ee9a8656bbdf37e3a50d14d954280cba4895576687a261200aefa1b5b39
SHA3 f9fe30ec54d6b149fa57e2cff2eeece6354e12fb7903c85ec221418ac11e94d0

2005

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x130
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.97326
MD5 ecc5f63aedee66cebcda9ed8fcb3e9f7
SHA1 60fadb22b7c1ac3638b8a4d12e2cbe174941ac71
SHA256 238d6c2e50312c555901a61e92afad3c7c6b42b9abd5acdda68658c2e2b48678
SHA3 b0eb2e4784dc0ae082c941596324510ddcdcd045da590b9db81d1c41f08f02da

2006

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x120
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.97672
MD5 42e1aa8919d27f02bcfc6981dbe5248e
SHA1 ec432b9979fad89557dd0b0ff1de774750f03f76
SHA256 cc21e9115c14c21af11786ff781dcf25c81beda500acf4966d0ddc7260610b06
SHA3 a11e5a0307464c1c66d9615a47d5568ab6bcd39c6bd6858842ad3c535272a129

63

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x8c
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.48958
MD5 ad0fe039aecc9c8af6f573923f182a0a
SHA1 b4fd492a37127d31fc36b7bd07084cc2f1ae18a1
SHA256 29b228ae95784d37b8729fe88e3bf1346c4b1339231dd1e9f702fab0654c5b1f
SHA3 7a67b4664ab18841c125d33dbe110fe774b16f91d1471094307c0ac35be5d8a8

76

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x520
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.2674
MD5 0f3f664bff00f8c4a1b42349d2956963
SHA1 d0ec056db75705bd79b7ebf1767c91dce955d79a
SHA256 7cc882dbb9f1315968f31bf40b57a535ff468271e253575752e03cb4aaa25f0c
SHA3 a81b1ab97bb98d4fb6d1619bf8bdee495b3176693e77305e438805563e952b91

77

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x5cc
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.29977
MD5 5f3ef55a113dc5f00ffc647e8be50df1
SHA1 cf04ac59ce78d6b2ffde0990ef76cf40ee1c439b
SHA256 3f715c8970d240cb57ba8ae8914ea8385b42728ffd48a3916493422a80cc3ed4
SHA3 fdabc44cd05ee45599b1e28ee3ca323cd6768db6606bffe95ceb6025b31b4d2f

80

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b0
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.27174
MD5 1f268a77ca8f853ff0c410e622706bef
SHA1 75afb11daf446704dddb5ef5fe39b2009aecf01d
SHA256 39023f15fbabf4be02e0d84a76c363003374b11076406f84cd8f92e49aecd3ba
SHA3 5e684d700849b8552f5449c5869807ce32caa8ae657695824e4a41be4a2ee55d

83

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x44a
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.2912
MD5 586fc633195baca29ef84b9271b42689
SHA1 69d5712401f0ca87f897c68f3a07ee9e01de8a25
SHA256 c1a5490b8a26165048de894aacdcd25e09cec0c4aebc5ff1d435f2cc4757118b
SHA3 04492be8d1f2fd83ad6633ec69825c302118f6039586e9f2bd804e00fdcc0913

85

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ce
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.13591
MD5 949714f4f3946ad108bb0817d170c459
SHA1 01b3524390968f27c27943e9f06f145b8527f8de
SHA256 59d8ad57a3629edd20c7b298a6e3604eeb95dfc7c507ad7e329ea0bff7a571ff
SHA3 6447983c227f98b8cd5f4045d58626cd5f965fa8e9cb99c33a68a58136ceb655

ADMQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

CABINET

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x946bf1
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 7.99777
Detected Filetype CAB Installer file
MD5 96b9b6071bb3d29224930265e1e432af
SHA1 b87936ad5c740211db8c9300e4607358815d8bf7
SHA256 8c90521795bdd2dd525dba952dd22c706a1225dbd2297aeee4cc4aa155057bc6
SHA3 7fd5c8879a6943cdb88348622452e58b09b67605ed385c97f28d42d91d654360

EXTRACTOPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 0.811278
MD5 edcfae989540fd42e4b8556d5b723bb6
SHA1 8e146c3c4e33449f95a49679795f74f7ae19ecc1
SHA256 9d9f290527a6be626a8f5985b26e19b237b44872b03631811df4416fc1713178
SHA3 60c2a8073325723836f33d900267acbb341b4a1ed9cac675e75df2abbad4207b

FILESIZES

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 1.85164
MD5 db3a179881fe10a49177a47a64af3ebe
SHA1 78a7ad88a0ebdf58c82b1adcf2890ac33cb3a1d1
SHA256 4d2db538006bc1fdfb9146421756dd08ccb662924ae8082ca6c1ddb18e97ff1e
SHA3 68e2113d1b568f022dbf57e84b07d75969ccf1d1f6f8a9619f153b93702f2612

FINISHMSG

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x64
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 4.28303
MD5 421557539161822e357b3bbbd6d8d0e3
SHA1 f1ba0b0f43fdb56bae36dd709a4369c54911e523
SHA256 e4c042e2130574ed5fa32e3bc39816d01d117850407be715f300fad35de0a48d
SHA3 92534bdea44be08850a5ced8c32933fabcc2ae9cae20a76affa10440d4d925bb

LICENSE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

PACKINSTSPACE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

POSTRUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

REBOOT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

RUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x41
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 4.71324
MD5 95ccebe08c26eaa795a57e0159fab972
SHA1 af2aed60e909d849195623d31babdb77c9742277
SHA256 3369fe6c2647d1afb8cfc142ca6367f754658e2532072fe97b5a98b9fa462da1
SHA3 ab181f3ff115730b898107dc67273c4829ad618b72ad4d4ad0d637f638cb2e89

SHOWWINDOW

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

TITLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x21
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.96834
MD5 c2f4a9c338c45c70cf3ed49122384fe3
SHA1 97cb63dac9c66c3b37f0b5323c83e36e9bdf4db6
SHA256 eaa57b6ed442c6c18a35719e6c383477c303be90ef78c003b3551da69ee66174
SHA3 7ef9c2dd882024e906553e85622395784d7339fb27d121fa4c92416af22806a7

UPROMPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

USRQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

3000

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.06903
Detected Filetype Icon file
MD5 fd33ac51d62922419e4891a00f6e6efa
SHA1 8cb942ccc95430628eb8200da35c0a5c8240de84
SHA256 f327fb34dd8f0143903c681df662ae88c1b36483647d54b9ca074aae9b7620e3
SHA3 6752df93dd0adf3e0e172480a7ed20eb5b97bff02646dd17b7eb6880745049c3

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x408
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 3.41677
MD5 f9755a3ae45eeb0212977d1db7b34c55
SHA1 a4b2a586a735b99b54a523fab46f125e966db774
SHA256 0639e05a8c81bdc929157e660cca80188512cc14cc1329520554684191300318
SHA3 ebc09991d89305d9171313b08d032a5ada69f1fb6a1b7766fb5962d7101f4eef

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7e2
TimeDateStamp 1984-Jul-09 11:30:10
Entropy 5.00338
MD5 634f0840178e0547100a2b1d9dc715d0
SHA1 84630da6d3de53091e22d22d9edfd3db6aabd96a
SHA256 d19e438a66982e9cc16d3384fb999d9fb637ffba4a14601bba893ef1feee66cc
SHA3 85213375e8765a50ec479e50d15b36113c82606422498b984f9d22809e3d622e

String Table contents

Please select a folder to store the extracted files.
%s
Failed to get disk space information from: %s.
System Message: %s.
A required resource cannot be located.
Are you sure you want to cancel?
Unable to retrieve operating system version information.
Memory allocation request failed.
Unable to create extraction thread.
Cabinet is not valid.
Filetable full.
Can not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.
That folder is invalid. Please make sure the folder exists and is writable.
You must specify a folder with fully qualified pathname or choose Cancel.
Could not update folder edit box.
Could not load functions required for browser dialog.
Could not load Shell32.dll required for browser dialog.
Error creating process <%s>. Reason: %s
The cluster size in this system is not supported.
A required resource appears to be corrupted.
Windows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %s
GetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used.
Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Do you still want to continue?
Error retrieving Windows folder
NT Shutdown: OpenProcessToken error.
NT Shutdown: AdjustTokenPrivileges error.
NT Shutdown: ExitWindowsEx error.
Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.
The setup program could not retrieve the volume information for drive (%s) .
System message: %s.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.
The installation program appears to be damaged or corrupted. Contact the vendor of this application.
Command line option syntax error. Type Command /? for Help.
Command line options:
/Q -- Quiet modes for package,
/T:<full path> -- Specifies temporary working folder,
/C -- Extract files only to the folder when used also with /T.
/C:<Cmd> -- Override Install Command defined by author.
You must restart your computer before the new settings will take effect.
Do you want to restart your computer now?
Another copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator.
The folder '%s' does not exist. Do you want to create it?
Another copy of the '%s' package is already running on your system. You can only run one copy at a time.
The '%s' package is not compatible with the version of Windows you are running.
The '%s' package is not compatible with the version of the file: %s on your system.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 11.0.18362.1
ProductVersion 11.0.18362.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion (#2) 11.00.18362.1 (WinBuild.160101.0800)
InternalName Wextract
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WEXTRACT.EXE .MUI
ProductName Internet Explorer
ProductVersion (#2) 11.00.18362.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2068-Jun-21 06:07:02
Version 0.0
SizeofData 37
AddressOfRawData 0x1474
PointerToRawData 0x874
Referenced File wextract.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2068-Jun-21 06:07:02
Version 0.0
SizeofData 472
AddressOfRawData 0x149c
PointerToRawData 0x89c

UNKNOWN

Characteristics 0
TimeDateStamp 2068-Jun-21 06:07:02
Version 0.0
SizeofData 36
AddressOfRawData 0x1674
PointerToRawData 0xa74

TLS Callbacks

Load Configuration

Size 0xa4
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x408004
SEHandlerTable 0x401470
SEHandlerCount 1
GuardCFCheckFunctionPointer 4235912
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xf79b7f43
Unmarked objects 0
C++ objects (26715) 1
ASM objects (26715) 1
C objects (26715) 20
Imports (26715) 17
Total imports 158
264 (26715) 9
Resource objects (26715) 1
Linker (26715) 1

Errors

<-- -->