4e725ca49e5238cefa4ec21127269b8a

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2021-Oct-14 07:37:35
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Unusual section name found: .debug
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegOpenKeyExW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
  • GetLogicalDriveStringsW
Queries user information on remote machines:
  • NetWkstaGetInfo
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC+8 timezone.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 4e725ca49e5238cefa4ec21127269b8a
SHA1 13915f62b6011a7eafd8d7296a0168eb330755b2
SHA256 6d33356363dd759ee83f2a11ad9512663343b8e1d9b00d44042f29904f625442
SHA3 52823b637bf2baf819d2af33adb0df420e7ce4751e4ff2b0984bc43e47dc74ea
SSDeep 98304:w88leXtTs0r67+Ahb6QC0bGg/PdAgpDhllfx:w7e5Jo+DCBDlJ
Imports Hash 5b8750f202570d0e33d587b9ca84334b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 12
TimeDateStamp 2021-Oct-14 07:37:35
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x1e3000
SizeOfInitializedData 0x6f46ea
SizeOfUninitializedData 0
AddressOfEntryPoint 0x001E405C (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x1e5000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x8f6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 688bb8cc9a12032d207d5040ed82c829
SHA1 da9ff95bc39bf5dddab382506337b15528ea0384
SHA256 f1c6acbdb8f5b340cf09a52bc6ad96c54621a5b47bf802e4c1ee82c58ab5d5d0
SHA3 ec2f92d5acb4f55c3f923ca162bc01918db20aec600de02ebbbb2da66c6efb49
VirtualSize 0x1e1a14
VirtualAddress 0x1000
SizeOfRawData 0x1e1c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41999

.itext

MD5 e9f9d90ad2bd69e134a74bdbefa208e4
SHA1 7aac9e0e78b1b7ef1f06f123193cb6076664ce0b
SHA256 a5465e7e07b4093cb9bb6c07d13f8b662dd93b2677b709bc6a1bb30a3e3770f0
SHA3 084d70cfef370f208b4d56884c47b2176544283a6fb02bc595d878db5cdccbc1
VirtualSize 0x1380
VirtualAddress 0x1e3000
SizeOfRawData 0x1400
PointerToRawData 0x1e2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.21623

.data

MD5 26673a1b056e415a4f256841d32ce391
SHA1 c84128038f5eb2244657672280e1ba7b61375eb8
SHA256 7520f90535ee16e2b0e928c025525e2e959179338cb76dab4042ca87dee90788
SHA3 e1cb03746efacc8e368646362d9dbaa4d205b257083191891015991e9d511f18
VirtualSize 0x1d368
VirtualAddress 0x1e5000
SizeOfRawData 0x1d400
PointerToRawData 0x1e3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.71283

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x672c
VirtualAddress 0x203000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 8a80b5e5cba41f29a148fe33ae0499d6
SHA1 e04f10b82883089f6b5d6611e8d9656d13694e34
SHA256 e39c1607ad552759f23068e43c8f1e05934a0b3b306bc83188684065fbbae7bf
SHA3 7ea5a56c58daf2933c09ce486edd0ebfa631f791dc5cf7b9b8e71ef830136e52
VirtualSize 0x124a
VirtualAddress 0x20a000
SizeOfRawData 0x1400
PointerToRawData 0x200800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.81015

.didata

MD5 830edbd66113402db54ac26cc80b7c56
SHA1 5addffcecb53c57fc963300d473d70467039da3c
SHA256 c1bbf7b2179e2ed45f51ef2dc188b0922713d08f84c6cbce08540ae716fd4ad1
SHA3 35d59a3e7b03b882359150b14ba4a22116e3c68c665ac5e862cd20af5628b369
VirtualSize 0x2ba
VirtualAddress 0x20c000
SizeOfRawData 0x400
PointerToRawData 0x201c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.78112

.edata

MD5 97a939a8ce3ecee0919e9147277e2207
SHA1 36762c42d4dcc956cfb1f73b4452474a6c2227b2
SHA256 9f4fb1fcb3c90e67a13d9eb970887ed28da44131708929eaacecb4ff1d2e1497
SHA3 e3f85b43c8cde3baa65642fe4c51f64db6be2225ba1760dffbed3e281cee7f11
VirtualSize 0xa2
VirtualAddress 0x20d000
SizeOfRawData 0x200
PointerToRawData 0x202000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.00001

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10028
VirtualAddress 0x20e000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 553bc9aaed939768cdf7762f81991efc
SHA1 70a899590b110993511152a73eea300c2188eb73
SHA256 86030276f4ea16dbc43a913e95b1a5c1ed3ac2e6827250d3c14217644d629a77
SHA3 a03e4508e5ce68caceccb6c25af0280ca5be660f52df6c866409cdab9d53d113
VirtualSize 0x5d
VirtualAddress 0x21f000
SizeOfRawData 0x200
PointerToRawData 0x202200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.36906

.reloc

MD5 5b43a59f10f6c5fd91dfb2b02965017d
SHA1 e25162d761ae5257407bf0488a1eb8f7ddf0c9e3
SHA256 64b1a3b5f6c57a1a896f2a51758db4b36fc65c9f62e1a628dbef5af669ff86a0
SHA3 9f162e446c60c57920d40a6f45febfc3d4998ad042dfe649a27b4caf0458b919
VirtualSize 0x29c70
VirtualAddress 0x220000
SizeOfRawData 0x29e00
PointerToRawData 0x202400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.7009

.rsrc

MD5 cec698dd19ee5e90ca785738854a5aa5
SHA1 a43dd90d1b31ba4369d91583e4eff07d09c2b836
SHA256 6b28d0361a9789af12f64729c303691bddb3b311806cc0f217ecba71d0add10b
SHA3 2a70c08940932a4e5afa77014909654126bebdf120149416b59dbd8aab6c2320
VirtualSize 0x4000
VirtualAddress 0x24a000
SizeOfRawData 0x4000
PointerToRawData 0x22c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71545

.debug

MD5 c244f4ff52666c16649f433de2bc6d7e
SHA1 45d1695205d36882a621eaf12f7d53236f10a554
SHA256 6f38ec640c426ef263a20ddb90130dbf67dd2ac98d795b0f6cadd1d5139a8563
SHA3 8d1f5caece3634a4159ac7e6f9107f56051a6acb798a8bab6af22cc87b77a6bc
VirtualSize 0x6a78ea
VirtualAddress 0x24e000
SizeOfRawData 0x6a78ea
PointerToRawData 0x230200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.33898

Imports

kernel32.dll GetFileType
QueryDosDeviceW
GetACP
CloseHandle
LocalFree
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
EnumSystemLocalesW
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
SystemTimeToTzSpecificLocalTime
GetModuleHandleW
FreeLibrary
TryEnterCriticalSection
HeapDestroy
FileTimeToDosDateTime
ReadFile
HeapSize
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
MapViewOfFile
LoadLibraryA
ResetEvent
GetVolumeInformationW
FreeResource
GetDriveTypeW
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
OutputDebugStringW
GetCurrentThread
GetLogicalDrives
GetQueuedCompletionStatus
GetFileAttributesExW
CreateIoCompletionPort
LoadLibraryExW
LockResource
FileTimeToSystemTime
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetThreadPriority
GetCurrentProcess
SetThreadPriority
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetLogicalDriveStringsW
GetVersionExW
VerifyVersionInfoW
HeapCreate
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
GetConsoleOutputCP
UnmapViewOfFile
GetConsoleCP
lstrlenW
SetEndOfFile
QueryPerformanceCounter
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
GetLocaleInfoW
CreateFileW
DeleteFileW
IsDBCSLeadByteEx
GetLocalTime
WaitForSingleObject
WriteFile
CreateFileMappingW
ExitThread
DeleteCriticalSection
GetDateFormatW
TlsGetValue
PostQueuedCompletionStatus
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
SHFolder.dll SHGetFolderPathW
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
user32.dll CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
CharLowerBuffW
LoadStringW
CharUpperW
PeekMessageW
GetSystemMetrics
MessageBoxW
oleaut32.dll SysAllocStringLen
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetLBound
SafeArrayGetUBound
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
VariantChangeType
SafeArrayCreate
msvcrt.dll isupper
isalpha
isalnum
toupper
memchr
memcmp
memcpy
memset
isprint
isspace
iscntrl
isxdigit
ispunct
isgraph
islower
tolower
netapi32.dll NetWkstaGetInfo
NetApiBufferFree
advapi32.dll RegQueryValueExW
RegCloseKey
RegOpenKeyExW
kernel32.dll (delay-loaded) GetFileType
QueryDosDeviceW
GetACP
CloseHandle
LocalFree
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
EnumSystemLocalesW
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
SystemTimeToTzSpecificLocalTime
GetModuleHandleW
FreeLibrary
TryEnterCriticalSection
HeapDestroy
FileTimeToDosDateTime
ReadFile
HeapSize
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
MapViewOfFile
LoadLibraryA
ResetEvent
GetVolumeInformationW
FreeResource
GetDriveTypeW
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
OutputDebugStringW
GetCurrentThread
GetLogicalDrives
GetQueuedCompletionStatus
GetFileAttributesExW
CreateIoCompletionPort
LoadLibraryExW
LockResource
FileTimeToSystemTime
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetThreadPriority
GetCurrentProcess
SetThreadPriority
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetLogicalDriveStringsW
GetVersionExW
VerifyVersionInfoW
HeapCreate
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
GetConsoleOutputCP
UnmapViewOfFile
GetConsoleCP
lstrlenW
SetEndOfFile
QueryPerformanceCounter
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
GetLocaleInfoW
CreateFileW
DeleteFileW
IsDBCSLeadByteEx
GetLocalTime
WaitForSingleObject
WriteFile
CreateFileMappingW
ExitThread
DeleteCriticalSection
GetDateFormatW
TlsGetValue
PostQueuedCompletionStatus
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0x20c0a0
DelayImportAddressTable 0x20c0b4
DelayImportNameTable 0x20c0f4
BoundDelayImportTable 0x20c134
UnloadDelayImportTable 0x20c164
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0x206640

__dbk_fcall_wrapper

Ordinal 2
Address 0x11944

TMethodImplementationIntercept

Ordinal 3
Address 0x66ba4

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 2.99968
MD5 4663c27974fb5f8795f962e2dd4f3a30
SHA1 efbe6743b0dc5651fc27894c73e1cbd8cf40b000
SHA256 bc8b3590b3c0905f0fc295548f28d5b14b5b84c7b8c8385302951ca7ede9a678
SHA3 d6e650bee54f6e2a375010d22d57fdef365896e457b7c0472c5b98be2d2e01a2

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4fc
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.28769
MD5 13805cf3bb04b60f28e4052a97042a33
SHA1 3adadc47370d75fb24a39a3be9c79a39b5f52a2b
SHA256 e04595bafe9597c1b1290a19edaf88c26aff93e6cf4f0ea58b13480680f2f12c
SHA3 0f8ebd9c71f4f96b2c2fb4f2e2fc9101d5a0d0c39e79c7126f6e9c85b9bf3c94

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3cc
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.33735
MD5 4a0a54364bc9ff9697d167bbfb9fb09b
SHA1 16a1d44a0cb829b822d7a97fee26e3962b0025cb
SHA256 cddc7998b09b2f7be79a6a884da77ac7696af0dc4f46e8ab083ba69dabd7046a
SHA3 6f525b23ec536ca8224fb719080f3cec77edc0b5072fd7014c1cc96cb726bd00

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3ac
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.50572
MD5 761b800f34f37dc4637918ee3865be08
SHA1 312e939755d17dfc9453ac3a23d8ac0dd6dd1b68
SHA256 de36af4006c80fa70cd91d47eccc9a4f5f1267476b76c98c909e52d77bf5b67b
SHA3 1f7d21d7cf8bae7248cb66487ae02d70537ca021f68313e92ac573a832df9a7a

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x48c
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.31739
MD5 d52d9070b0fc4f92fa432cf69d199362
SHA1 d8f88da3efb4ad607c95eef865b99b6d84cf4152
SHA256 6a31149548f696109fcca7753817157007aeec9d9f0aa78a2c502d7c831a0ea3
SHA3 e5c85b13eeed5c07ff65d18d8929526b007684e872b9f6e3babfaa4c4aa980ff

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x514
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.2541
MD5 9a2572114ea128750ca40832b90363df
SHA1 7fd57276e9c255065a0748032f9ccabbca471daa
SHA256 55752cb118848ffefc5ca37873ccee29287c0c452e14263e4f74bc1c094c566b
SHA3 762714a6af39759059773ebb481b23ae976e3385ec2f3b0f654579cf23275feb

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x418
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.19342
MD5 445cb23f70e2b04a0776dbeee0d30934
SHA1 26028f93671c5efe41c20794584a2fff18950029
SHA256 fe2f7a9e9fd7c0476215b94a6439687c7396b2a13795224345b92fc9d76d8aa5
SHA3 fa5cefadeb8e3b9c1b1259859d97d1973fc18ba2d76fa93a4dbd3b7be76d23f5

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.30982
MD5 e7866b45c6f42522e662027bffa5950b
SHA1 c6b7160dffa2fb594413d344747a576b8aff613c
SHA256 a01d9e64c447d45c9abb1c6bf7e3c3306cbe0af4316d5adafdd797383799243a
SHA3 5746a4479766b308d4a16d8945c0536e6d44c6f6f0df3af4496abe2f9a5c771b

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x414
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.33177
MD5 72544da48aa11f42964e49d5c6a23826
SHA1 81da7ddfae8a5c8a6f96064616a7705de389b079
SHA256 25e60a9bdca41ea245ca5cc6670a56dd99a2e1982e833d5cf61d472f0adb5792
SHA3 9814a47a5ca62bd197ff604db98817fbe06b4fbd2790ed8d9db5c6d07a347e58

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.2023
MD5 2c445e7460778069a108bfa6e5838bf4
SHA1 ada7c52ba585077d914fb80b269ec8a841801795
SHA256 67fa84ed1924419c10197924c66863e6a229a1e590b17e32bde70bb75a809f82
SHA3 266c4ad63b3566332930feba77a9fb887467da0eb433709aa903dd5b70f234ec

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xb8
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.34911
MD5 4a1e6314536c88cfa0467bf5b0cc0dd1
SHA1 34d0696c00ac0a6e0171d94cdb9cb2b3bc662afb
SHA256 dbd0defe0cb0baca38eba086f1db49f41b260ac4f9cd2d6cdaed54074f04e2f9
SHA3 f1cc84f17e27543fee905fa4c85e54deef05696a42b067f54e122085710e76d2

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x298
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.3725
MD5 c720cb619e54e5f7f44478a85c79c55e
SHA1 682251e8a19c36f18c28e6c94fb5a6869290145d
SHA256 70d6cea09f844aacee85056fcc922123c3be4674c6c6a802a41dab839de2db91
SHA3 85f75d3a86a498c7488dd14d2e4fdd8fd0a46cd55d76aea721a71745f02922c9

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x438
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.32918
MD5 1c7f005c9ae3c60a300e62a3601eea01
SHA1 6263f2ba9d40cda16fb9d626e52b7ec74ad5a0ec
SHA256 7ff4a2a1035d4ea7371ac7d6cc32f027cdcd2fbc06c14cdf54e456c207b31e82
SHA3 638dcee5e02a5b4be4c56c55ae93f36d8067506b6e44372a389f8b92b7a4359d

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x350
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.3058
MD5 464fd6395c72e0d48ad250379aa62ab6
SHA1 14792fd465aa43b9a65538705b9080ed07e01ef5
SHA256 4e3e0c03fcd499c838cadae55da9d1258c9fa76aaa39901e229b31966b0eb194
SHA3 65b24699feea12410bf526e7b1a1a5b2a247a2db3a62118a643e4fb9e2a9236a

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2dc
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.30831
MD5 69b75cc43e1ff0fdffd1f62575f88c04
SHA1 574639ae63aa49a1d45e60757bf4f7adf5830ebe
SHA256 7213141dbdea59541b27e027959135152d624593c6c5a621a23751b796c2d65b
SHA3 50f30b0e0ec4eaf8f7d7f22e8232b4bb520dceeddff4cd7d162fc8e520ca587f

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x334
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 3.20265
MD5 216f43cfb001c9715718c24277b13b91
SHA1 2ac8e77975964ca29e2bd8f456cfc7bcd8c33840
SHA256 77c479e83f59fb0e4d155840502b83de743af2c57e3b7643393028064001911a
SHA3 fee5bae2016b18dece8bdbaee1504dcef02f4cb381ed4481e7ce904c942e1a59

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x4f4
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 5.04794
MD5 032a37f0ae21a85f920a90006bc8c771
SHA1 f226648671c30f17b87cc239e0b9fef3dacc8557
SHA256 21d570887f15b8dba50cd1c1829f85db3ca00ac757b9944dea585e47adf9ba7e
SHA3 24b52592b43222522ec6b471b74964475a509e66f9b034daa415693310c6f00f

PLATFORMTARGETS

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 1
MD5 25daad3d9e60b45043a70c4ab7d3b1c6
SHA1 0e356ba505631fbf715758bed27d503f8b260e3a
SHA256 47dc540c94ceb704a23875c11273e16bb0b8a87aed84de911f2133568115f254
SHA3 47b7fb6f259cfa242dc8e381efb31dad613f8bfe5a8a92f524d1a0a7058c56dc

TDM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x68
TimeDateStamp 2021-Oct-14 15:37:34
Entropy 4.75586
MD5 ab99c41b5535a9cbe66981656770a3c4
SHA1 60950c28100abab7ff3d3251aa11176679c8400e
SHA256 86fc0712359e83f9c85681aeef39ca473b8d0bd705853bc7f9e51f714e4f0d66
SHA3 a89f5b939b18b2a21e4cdcc768f51c83fab3f3915f39f3f59633472c74d90141

String Table contents

Strings parameter cannot be nil
Invalid index type
Index out of bounds (%d)
Invalid group name (%s)
Invalid time string: %s
Invalid time Offset string: %s
MD5: Cannot update a finalized hash
Error decoding URL style (%%XX) encoded string at position %d
Invalid URL encoded character (%s) at position %d
Cannot construct an ITask in this manner
At least one task in array nil
Cannot start a task that has already completed
One or more tasks were cancelled
One or more errors occurred
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
A regular expression specified in RegEx is required
Error in regular expression at offset %d: %s
Error studying the regex: %s
Successful match required
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8
Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Invalid date string: %s
Unbalanced stack or queue operation
Item not found
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
SpinCount out of range. Must be between 0 and %d
Invalid Reset Count: %d
Invalid Count: %d
Invalid Decrement Count: %d
Invalid Increment Count: %d
Decrement amount will cause invalid results: Count: %d, CurCount: %d
Count already max: Amount: %d, CurCount: %d
Countdown already reached zero (0)
Timespan too long
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue
Value cannot be NaN
Negating the minimum value of a Timespan is invalid
Invalid Timespan format
Timespan element too long
Argument out of range
Argument must not be nil
Cannot call SetReturnValue on an externally create thread
Parameter %s cannot be a negative value
Input buffer exceeded for %s = %d, %s = %d
Invalid characters in path
Invalid characters in file name
The specified path is too long
The specified path was not found
The path format is not supported
The drive cannot be found
The specified file was not found
The specified file already exists
The given "%s" local time is invalid (situated within the missing period prior to DST).
Length of Strings and Objects arrays must be equal
Source and Destination arrays must not be the same
Class %s is not intended to be constructed
Invalid Timeout value: %s
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Property is read-only
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Cannot call CheckTerminated on an externally created thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Unable to create directory
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Operation Cancelled
Ancestor for '%s' not found
Cannot assign a %s to a %s
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Format string too long
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
<unknown>
'%s' is not a valid integer value
'%s' is not a valid integer value for %s type
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied

Version Info

TLS Callbacks

StartAddressOfRawData 0x60e000
EndAddressOfRawData 0x61e028
AddressOfIndex 0x5e5c20
AddressOfCallbacks 0x61f010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->