481b984d3987044b47e3b7086a538fb0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Apr-02 03:20:09
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
Can access the registry:
  • RegDeleteValueA
  • RegOpenKeyExA
  • RegDeleteKeyA
  • RegEnumValueA
  • RegCloseKey
  • RegCreateKeyExA
  • RegSetValueExA
  • RegQueryValueExA
  • RegEnumKeyA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Changes object ACLs:
  • SetFileSecurityA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 16813506 bytes of data starting at offset 0xd600.
The overlay data has an entropy of 7.99999 and is possibly compressed or encrypted.
Overlay data amounts for 99.6752% of the executable.
Suspicious VirusTotal score: 1/73 (Scanned on 2024-07-05 14:46:34) Bkav: W32.AIDetectMalware

Hashes

MD5 481b984d3987044b47e3b7086a538fb0
SHA1 aca1c12d874eaffaeeafcf8ade1caa92393d2355
SHA256 cca6fecf0df279a8432ee64c7fe258cf7eabf0e2fba224631442037404f60024
SHA3 0d8e1f3ff4b923f4493c7d3101baafa186e1b937909caa2f53ef66f101d3e1bf
SSDeep 393216:SIFDrs6eI3kt98+x9iI/4TkhNhxQ1T4dFG23Ex5:ScDgykr50I/4ohZQ1eYSc5
Imports Hash b1a57b635b23ffd553b3fd1e0960b2bd

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xc8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2016-Apr-02 03:20:09
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x5e00
SizeOfInitializedData 0x1d600
SizeOfUninitializedData 0x400
AddressOfEntryPoint 0x0000326C (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x7000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x42000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 51e2544a6971f687f7a1241f613014c1
SHA1 1dc9b7d6bb158fee5b9f3b28181b389987a1c350
SHA256 3f5f7b309092988af8c9e92567926a5e523cad3af0051c20bdf29aad00a33510
SHA3 ead501114661f03aac31abc76b71034653f300508cc4ce3d8a5490f65fbe4151
VirtualSize 0x5c74
VirtualAddress 0x1000
SizeOfRawData 0x5e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41039

.rdata

MD5 4c84e530bf8db37146334e6c487170bf
SHA1 076dcc532f1c101e21550e104a20a7f8e4c30781
SHA256 3575075347d3cfff06e9f5c296d8c71c30f2fbcc62228eef437e236010397471
SHA3 0eec1a1d948468a2f710745acc56943954e864ce6901ed769f2e04c3dbddd8ea
VirtualSize 0x1196
VirtualAddress 0x7000
SizeOfRawData 0x1200
PointerToRawData 0x6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.20374

.data

MD5 75d996f724e5e900c022f56b3df3ae1b
SHA1 7b247661a46a3527556a9637ece6c600bf6777ec
SHA256 4a63c7ca63538039a0213c12377fc6b0d36530bb0eecc9d4d24728c851334352
SHA3 9e187facab9fe47c274f1195debae1114b0f20015ddbfe91134d735bc745713a
VirtualSize 0x1b058
VirtualAddress 0x9000
SizeOfRawData 0x600
PointerToRawData 0x7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.13053

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x17000
VirtualAddress 0x25000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 156a34e5cd30827b34e8088352ab25a5
SHA1 ddd54ef89eccddcb908d458503f62c69811940c1
SHA256 a24b0fc32dee4c2e972ffce048697ac0330ee1d82ffeabeb568d24e625106671
SHA3 e38e1cc364736e555075cc572c43334cc6d219ff6d1fd85891ace79b661b45e6
VirtualSize 0x5b78
VirtualAddress 0x3c000
SizeOfRawData 0x5c00
PointerToRawData 0x7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.44461

Imports

KERNEL32.dll GetTickCount
GetShortPathNameA
GetFullPathNameA
MoveFileA
SetCurrentDirectoryA
GetFileAttributesA
SetFileAttributesA
CompareFileTime
SearchPathA
CreateFileA
GetFileSize
GetModuleFileNameA
GetCurrentProcess
CopyFileA
ExitProcess
GetWindowsDirectoryA
Sleep
lstrcmpiA
lstrlenA
GetVersion
SetErrorMode
lstrcpynA
GetDiskFreeSpaceA
GlobalUnlock
GlobalLock
CreateThread
GetLastError
CreateDirectoryA
CreateProcessA
RemoveDirectoryA
GetTempFileNameA
lstrcatA
GetSystemDirectoryA
WaitForSingleObject
SetFileTime
CloseHandle
GlobalFree
lstrcmpA
ExpandEnvironmentStringsA
GetExitCodeProcess
GlobalAlloc
GetCommandLineA
GetTempPathA
GetProcAddress
FindFirstFileA
FindNextFileA
DeleteFileA
SetFilePointer
ReadFile
FindClose
GetPrivateProfileStringA
WritePrivateProfileStringA
WriteFile
MulDiv
MultiByteToWideChar
LoadLibraryExA
GetModuleHandleA
FreeLibrary
USER32.dll SetCursor
GetWindowRect
EnableMenuItem
GetSystemMenu
SetClassLongA
IsWindowEnabled
SetWindowPos
GetSysColor
EndDialog
ScreenToClient
LoadCursorA
CheckDlgButton
GetMessagePos
LoadBitmapA
CallWindowProcA
IsWindowVisible
CloseClipboard
SetForegroundWindow
GetWindowLongA
RegisterClassA
TrackPopupMenu
AppendMenuA
CreatePopupMenu
GetSystemMetrics
SetDlgItemTextA
GetDlgItemTextA
MessageBoxIndirectA
CharPrevA
DispatchMessageA
PeekMessageA
GetDC
EnableWindow
InvalidateRect
SendMessageA
DefWindowProcA
BeginPaint
GetClientRect
FillRect
DrawTextA
SystemParametersInfoA
CreateWindowExA
GetClassInfoA
DialogBoxParamA
CharNextA
ExitWindowsEx
SetTimer
PostQuitMessage
SetWindowLongA
SendMessageTimeoutA
LoadImageA
wsprintfA
GetDlgItem
FindWindowExA
IsWindow
SetClipboardData
EmptyClipboard
OpenClipboard
EndPaint
CreateDialogParamA
DestroyWindow
ShowWindow
SetWindowTextA
GDI32.dll SelectObject
SetBkMode
CreateFontIndirectA
SetTextColor
DeleteObject
GetDeviceCaps
CreateBrushIndirect
SetBkColor
SHELL32.dll SHGetSpecialFolderLocation
SHGetPathFromIDListA
SHBrowseForFolderA
SHGetFileInfoA
SHFileOperationA
ShellExecuteA
ADVAPI32.dll RegDeleteValueA
SetFileSecurityA
RegOpenKeyExA
RegDeleteKeyA
RegEnumValueA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegQueryValueExA
RegEnumKeyA
COMCTL32.dll ImageList_AddMasked
ImageList_Destroy
ImageList_Create
#17
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoCreateInstance

Delayed Imports

110

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x666
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82633
MD5 b6bf70baab40fe438feff063bfb9ff6f
SHA1 7d4659d43e08d368ddacd31945872461c0b06253
SHA256 0e90a9e4b8f3a5bf990e8aadfd8096ad7aeaf1a4e032ac7b6395ce191d61c142
SHA3 cab98fabaf20118d9a8a4d2bcff4383a7291a0e04ff11a8690e71eed619c75e7
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.28602
MD5 7223c9662398be480104401d4ca75ed0
SHA1 6c3830359f7536084a74dbfcb7db1b38c006e9a8
SHA256 3ea678698c0882fd6f193ccd4c2e4e875782d014bd9b6dceab17d845d60529c6
SHA3 6ca51ae74926408360ca196df5cdd95397691bea53916bbc6657fa31ed3b08fa

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.06944
MD5 fcd01aaaad1b7ec612c45718ee04ff84
SHA1 1ba930ef55cd4d828030d124e17abdf58320f5c0
SHA256 7c69a7a6a81a1a4e6f5faaa489df538333febf3e3905c169c7cd8f83ce3f3fe2
SHA3 5b1cf498fa5533dbed306ad756332c086cbacc7c66ef962a8ca7b1856ee87f53

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.33781
MD5 c56fb3cc85e03a020663673be38dea5c
SHA1 69dace2feba520424b550403127b137ad907fd76
SHA256 7e8ead76419dd81f992a0d579dfc6f9b4f2e476d96e5e011584c2a62a85ffdf2
SHA3 7e62facaa9eb113e829a0bd4e6ed15820fbf94058864685c9876fe7b02edc78b

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13165
MD5 ad68a2b1d2739688861906eb5d07c6e8
SHA1 a886b0b9826f6e56c770f5dbe2fae116a59b4468
SHA256 edd023e8331cc2bd63de453185190b4dcf685516fc77f3ac9d35069cb70b4630
SHA3 a73c342c3cddb74df77cd42d8da614b706891849bcf7f841bf7cbae3cf791b86

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.1985
MD5 45e283d2d48d1d03e95f699fe2bcbfb6
SHA1 ae2e7dd47c67ec70530ab43cb7d12a865a3efcf1
SHA256 0c49cc0a5a983dfa113cc509d48ec8ab6c5891e503dac710fdb5486de3feee85
SHA3 1e0e7cdde9d76251efb40fee58fb89a12eb9a99e147a15438d85ac838d6e0a27

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34146
MD5 4cab9376ec4701da71f80d4aeba2c240
SHA1 06e5e13b365af3f01b7bdca213f3e9ceb7e50879
SHA256 fe32e4619872af13373e6dd9db85348cd07eef4bedb58376d070d7210da98ff8
SHA3 bf7a8e758c26e1200ba0b3fbd42dd08ea028cb7fe6d448a4ece7974b3cccd7ff

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04232
MD5 21a4ab41cbf67f81a31f1ee4d8362ad7
SHA1 862e3ec0dbb7780391965b594656c93d3d639043
SHA256 a6ab81883d8b074d2df028d332baa4958e5655291a2f525fa26e0e2424594cfa
SHA3 ebff1e32c7b361d088b00377e8b83422392f8b42f4ab684f0af5e8565c40de1b

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56193
MD5 db6dd0434da4d7cac564518725167e09
SHA1 a65a1367d7cd96450f089a8f8108239bbcea9f5b
SHA256 c50631fc1f8425a95fd1edcc8e730d339e193a38f18d42372c32847a5ad2c016
SHA3 4e3be5455c51e1cb04836e318cb69ecdffd2deadd0f338d4bc985d8f5ca653ff

104

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67866
MD5 693e5fde9e50f9d2b6c4795f5b47f576
SHA1 502c331f05e8ca78ad66dab64fd17a25df2bfbd0
SHA256 ed2f2d936eb10234e9fe3c6f4e7a8172c05281796fdffcd21eb435ab89c656f5
SHA3 372550d961df1a704067fb4e07d96996b047d6973033d425fed1eb611d48753f

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67385
MD5 d1a92272fbd597e1aa19021483110d5a
SHA1 9f75072682b37c6c52361d8c988ebd06dd003f63
SHA256 15663576584c947d634dab9848defcc7d8f05eb0b7e7c6d52d81eca695fc7a6e
SHA3 704756797695ae34f6fae500852bca70e5066a1d1993348fe40ccf626235d0d6

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 5b3e1cb25be7a2dbae4f08f0d4794ed23dbd6ea37a3f9702be12dba588f42a7b

109

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70146
MD5 c44a8a56f0e7a140c0bcc4988f380bb0
SHA1 66dcbb7b922cf861460facf7223be2e2222dc254
SHA256 32a441f145ba6ee7fd9e31fb4973a2dab51b61a59479f8dcac3f0e3d6df84e8a
SHA3 f976491333b0027b657803dbb92b6da931c8266923f1c73e2c138ac07fc7512f

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92787
MD5 5dfa289639a3bcc0497da8db163f01fe
SHA1 6e2c6ea1e2594b66f563fb589276642c127e875f
SHA256 18466509968c3c0bf92ba410fea075def2b257a5a799a113cbc60f13e75f4b01
SHA3 85abdc8c431d91c72f3595a39881c96637ead09a0278d3cec0c1c9a8d873f031

203

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84487
MD5 12402b54eddc39fa3dae283957b4eb4c
SHA1 beccbeac143c7c78d7271c20c73df7e797c6224b
SHA256 4017b96a65ef43c2d6781adc75b048ed8568f3068b81ee971154b90886766250
SHA3 d1f0eb13adc7d47e9aa7da0e3a996fd742075668a840e149a5f391955e438793

204

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03655
MD5 dff8ecc5cf3bd0fb70266587cdf24989
SHA1 dc81b0883f520e5c9bd8f3e326b16203c447f2f6
SHA256 d31184bb359f7d20698e072a7b5d91e6625969f76498ce98aeeaab3311f51aaa
SHA3 27f7609102471ba26636b6f50f16df794c33176394b8968fade08d837458197b

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97219
MD5 8862e4aa98b1d5fc07fe6502e91d06d2
SHA1 729d8fc72945f0303e81dd04914b2721e90a035a
SHA256 ce653ba55bd5aaf5ac9e0929603095b8794a10190fa9ac917f204ae6fd697f95
SHA3 a95410994a75373358a9a7e88988f1d6b7585e93ea0b5deda9459bf0ecfed454

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10966
MD5 1ffe62afd7fe045c34a23ea5c9c7eb22
SHA1 ac211007f1f7a65d868d6e9e658d5ff26dec9c8e
SHA256 184073a317c843cbe92b68cfacebcf5d73dedb538b3f79c048090f3ee5b614ff
SHA3 f34fe335d0a39aedd236cfe40879f6624bc468df8195f5360c1d7267f2bd0113

209

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99117
MD5 b14b7ef6391a8d2558c31cd6679f164a
SHA1 3e61a6c35b5c147418197c37cb4b5c072c79551d
SHA256 3ea7883ad975696c5f837d85badd17a29ee5e929f9c91180b5a569cebe18ff87
SHA3 8a3e70e25f5e7d66b5041404f8f46e3dcbadd5b02bda2eba8563fc0f5ae5d67c

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06584
MD5 7ce8a17102daebb8d864cd1063e987d1
SHA1 072345a235d4947d36b53fd47da68e7e6a93fe62
SHA256 0fd40b240b9df8f2dece8947dabbebce898f12becca8e196136e4231efba2dc1
SHA3 59c7281c1d6dca36fed8a44ee5b408f11090812626d5c5fe1da3d72b526208ab

303

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.58011
MD5 088199de88ee4293982cec0b65748394
SHA1 ccce70fc022137c746dfb6bf52cd785b8675768d
SHA256 583b62d87b496612f7e10bf1da5113b8a4c83f0a2155184d03c0b2ec14fb5ed1
SHA3 855ba3bd893d691d7c7f704da34c23efd96142d6deefc65d3bdb0e2968f97d95

304

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x148
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7041
MD5 4956364f01e71a729be304c16bfe737d
SHA1 e42e31059712b82fdee961c212fa6fbf26d0c613
SHA256 9e7750d9a65f34b5c7f59fc38068a488c1ebe4da2b615336a0321ba149aeac2b
SHA3 09f7c4a6ed3f2145161e49d2efbcbefeec677befe1120bd94fa0658008dc0e49

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66995
MD5 327c4c7d72cfccbc825db2223fff0194
SHA1 ac964308ef6baa20aa381b269ecad756e98f5109
SHA256 c8908172569e23a001394e98e4dea3f5e1c57e8cb6f1703ec1c9983adbff35d0
SHA3 bd235e490c85fd86b25086046a00ea0d514984003ce377e6978dd87c040a780b

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96511
MD5 c33758ab32a791644973dfd60cbf6034
SHA1 ee7eb0a27279d39a959f5d35b6dfd4c18c7123fa
SHA256 6e7bca0054a1785929747807906d8527c2c2a231ca5975d8ebb3a3f98353f129
SHA3 8883e9e9fe2e8e33f0c0a0dcb5c13456e825a62100aa3e10099e225770ecc9ff

309

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xc4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75421
MD5 2d433f6195baf757120a05a885ff59ae
SHA1 7d58d761640332f6e5ff0a437d083778d2d52c8a
SHA256 3fb9c45c28ab454dbe51bed2e8f1e5a66f997043f84f61b9f221c3ed08d91ba4
SHA3 07842bd4c7c42e1e2e3312f9477d96884ff2987cdaba9d00b6ab8b37ff94b653

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03655
MD5 2802ee53bc08ac9a2cfaed81b3d79d05
SHA1 b7faac6a14545ea9c03651f69ae27cce0e62b010
SHA256 65fb71b054977a55435f45bbcddddedaa1e1cf43fdd9fc230938d625c3f7edcd
SHA3 1b03466617102ef078d2690bf5a361563eae8b960554205937f87a6c81d328c5

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6691
Detected Filetype Icon file
MD5 e624f041c921d299a6da3a8c5f48f989
SHA1 ffa07c86ac3dac45398ee07b26610dfb5c99d8ea
SHA256 fed46e06346fb8f64b14c18408a82caf955929ac0e65151630539dc5bd194584
SHA3 b51d47dbe9cbe18b1f520275504256022a827f919672b081943ae45cd4ff44c9

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21417
MD5 9c3b88e938f953ecc735c511d7a8facc
SHA1 0d23fc04046aa1fea468a9007ec9909c44667045
SHA256 5ab55ea1740dfd7dbd3104bc63e3c22f2c7ced0ac1b58e0be2535573d55f8402
SHA3 01bc560ae60a565dc11168c900acbebeb190eb4fb21a944fdb6623690dca1999

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd24651e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 152
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
<-- -->