5a81e02f2751031ab678b5b00745cf8f

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-Jul-09 07:58:13
Detected languages Dutch - Netherlands
English - United States
Comments This installation was built with Inno Setup.
CompanyName Creepy Jar
FileDescription Green Hell MULTi18 - ElAmigos Setup
FileVersion
LegalCopyright
ProductName Green Hell MULTi18 - ElAmigos
ProductVersion 1.9.2

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://www.jrsoftware.org
  • http://www.jrsoftware.org/ishelp/index.php?topic
  • jrsoftware.org
  • www.jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 2556150 bytes of data starting at offset 0x65c00.
The overlay data has an entropy of 7.99993 and is possibly compressed or encrypted.
Overlay data amounts for 85.9812% of the executable.
Safe VirusTotal score: 0/70 (Scanned on 2021-02-01 09:22:41) All the AVs think this file is safe.

Hashes

MD5 5a81e02f2751031ab678b5b00745cf8f
SHA1 f59876e8fd82974f779485c52b3990aa802a9d09
SHA256 7830c45937bb745501bdd300736b0471b7f27719fc153315b33756f7b90648c2
SHA3 ff7df3eee3ac85e3fb92c43e0cc9640cd202213123e42724422acb4f2041994b
SSDeep 49152:FNoG9qJ+k1be7lcDhPW3RlWVUKGoizEnlzJ9Gp2l72rTzEUCRT7LPKV:sGQs8XNiRlWVdh0cDcxgvLPKV
Imports Hash c60f9a83fcd28ab2eb686b76b194eb79

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2014-Jul-09 07:58:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xfe00
SizeOfInitializedData 0x55a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000113BC (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x12000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x70000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3a126e478661f20816f9d9285615f98e
SHA1 e446317d7cb464e9ab9c259129ffb390c0e85bbc
SHA256 dc180f94aef37a4dd045f59040ace3a17d4c009644bba1492300cff94a1ab660
SHA3 cfda01e42a8e06ccf82d4a430132d82477efc589570aa87e785cede7d31e76fd
VirtualSize 0xf12c
VirtualAddress 0x1000
SizeOfRawData 0xf200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39148

.itext

MD5 ba48b9b17b3dd8b92da3bd93f20ddb34
SHA1 3ee09b4d597b2047cd658a1acfa454edb77e09c7
SHA256 32890d767e5e23e3e538c87cbb41ff5ce98dd329c069467c4cd556fb5ba618c9
SHA3 ec46821fa99cbddc600875f6eb7e4b34240d0f2e3167c9a37af603f6fb6a06d7
VirtualSize 0xb44
VirtualAddress 0x11000
SizeOfRawData 0xc00
PointerToRawData 0xf600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.73207

.data

MD5 d7fd5f4b562d7961758f3d6a8c834fd0
SHA1 04e9419b80ec90dff0906e2b7ef0749593fd8648
SHA256 54a41d6d92705a381f85668d43ece5cf07750f582985eb152fb62bbbb5800a78
SHA3 553391203f25d793c5f95e0efccdaa93bbfd3da8cb5515cec8f8b4871f3739f0
VirtualSize 0xc88
VirtualAddress 0x12000
SizeOfRawData 0xe00
PointerToRawData 0x10200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.24631

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x56b4
VirtualAddress 0x13000
SizeOfRawData 0
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 93d91a2b90e60bd758fc0c4908856ae1
SHA1 391bdc96affa3aca04b3ed0fdce8edbd5a888a76
SHA256 87a62dbf1079da4759be08abcac1d4057824eb72be12cddad633200a6df3d267
SHA3 74535fa748cef59b8fbcbc2f73db78b397a804d24d3ee6adbefe0cdd3bd86d35
VirtualSize 0xdd0
VirtualAddress 0x19000
SizeOfRawData 0xe00
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.97188

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0x11e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3dffc444ccc131c9dcee18db49ee6403
SHA1 45d8f890e32cc1adf7ded113fd19004c8869f419
SHA256 821b0bda5922cc6f5fb74fb3a160e39c97727c21beb1ecf4f96e3bcfad9edbe3
SHA3 426ea652dcd361ec016030230ec1c87a2bc522f69cfb4c2af6313465cb2c516f
VirtualSize 0x18
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x11e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.rsrc

MD5 b63bbf4c4f6be3c4631018e87d350b18
SHA1 be0664acf782c60ef9bdd7786bb6c190539b09cb
SHA256 7e45bb1d76ed09ba7ee7e3ccd255e96454845a63b5ff70c8bdfc28e06fc7540e
SHA3 bb85678d27487d8987c0cc8e13b2ff4f78892930b80c73a419da6caf4a800f35
VirtualSize 0x54000
VirtualAddress 0x1c000
SizeOfRawData 0x53c00
PointerToRawData 0x12000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.36308

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.34332
MD5 41c80817762945cf32a10b1a6363b4d1
SHA1 13f245db84ba879acf3dbb7c33333cec22f3d211
SHA256 3a77e15c4fb3682fe1932eba68bf4ef532f0e49ad3083878c1920f6f7ae87fc8
SHA3 51eba9136d92a603970eca10fe0cd6f9980002b389b9b24cc8440af96528a56e

1 (#2)

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25755
MD5 c5af786bfd9fd1c53c8fe9f0bd9ce38b
SHA1 4f6f7d9973b47063aa5353225a2bc5a76aa2a96a
SHA256 f59f62e7843b3ff992cf769a3c608acd4a85a38b3b302cda8507b75163659d7b
SHA3 e178a71f02edb18e31bf550d484b2cba8d865e1e9796065addb07855ce5627f9

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.43071
MD5 58f2c543d38d3999116ebf62cee740d2
SHA1 0c7038c8cece18a2411c05ee08a1155349b3e509
SHA256 c379d88989ece23dda41410ce3bcf5b7df7a730f6410bb63e297f1fb266b9860
SHA3 82c94a77fe57db017184fdf11a5a2bb1a79a562e36e2408c3e4b913e14f800ca

2 (#2)

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47151
MD5 0a451222f7037983439a58e3b44db529
SHA1 6881cba71174502883d53a8885fb90dad81fd0c0
SHA256 dc785b2a3e4ea82bd34121cc04e80758e221f11ee686fcfd87ce49f8e6730b22
SHA3 d5599c242df5383add3fb330d42b31f1751594b36bbf52195e7d1dd564e7f0e3

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.44378
MD5 cc74836fbf05269dca27fe9bb5f6cb71
SHA1 7b83185149b7f82dba90370dea75319fbcfdeafe
SHA256 5e4b17f641b7c469e833ff28b599a7d82a9b0b5fbd434c7f4dba8e67173e7525
SHA3 0b5b4581c7c377142d42f218d5a3b23e1b05155b981214f386d9560227683194

3 (#2)

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.91708
MD5 90ed3aac2a942e3067e6471b32860e77
SHA1 b849a2b9901473810b5d74e6703be78c3a7e64e3
SHA256 ca8fc96218d0a7e691dd7b95da05a27246439822d09b829af240523b28fd5bb3
SHA3 3f02085a0d69091556ede0b585f45145adce9849e175d8177c2f0fe0891a1bd8

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.40861
MD5 4f2587ad377845f65bd1f9d0cb9cc437
SHA1 119f30da04fac8641ca8e878b61ae5faaf05b9a9
SHA256 51b61f47cb9a5442ca6f99e8a6129c92eb94586a391ce88299e513cdd657f5a9
SHA3 62f36663c57da462aa366ce006b68404b5b6994927361a47fb269ca9eea7471c

4 (#2)

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.91366
MD5 af05dd5bd4c3b1fc94922c75ed4f9519
SHA1 f54685a8a314e6f911c75cf7554796212fb17c3e
SHA256 3bbacbad1458254c59ad7d0fd9bea998d46b70b8f8dcfc56aad561a293ffdae3
SHA3 150dba8cc825d5c0e9ff3c59015533288d19931847210338a3ef7cdc390c0e78

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.4258
MD5 ab50c6c893cc9b6fcb3208e8f36f932a
SHA1 ede511c667937a40056208baed2513037f16da73
SHA256 20bb8c7b0173e38d9a68fc23940af193f409ee16b76bfda97d5c74ea8006b872
SHA3 de136d452c01206982f94c3f3b2d8c05cf3cb25cf0493ce06185bf935ebcc8fc

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.41402
MD5 ea57eeac142b651b55b4edc48c6961af
SHA1 27a7bd49c8d78cbff01d67c1690ab0104ab515c1
SHA256 738f933c79cfd01b53b0fa557488674cc1ec26a53d85b8fa81e900819863dfce
SHA3 53da440982aa4c8830a482e01514052cc7205ee5c5e6a0bc7942934328daf13a

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.40165
MD5 eda6951d3760de1542ba3d69687f1c37
SHA1 1cbc52f7faabeab4732df42d60affb6d86a90afc
SHA256 6c0d4fa9eba5493c03f80c4070dfcdda904d4a966bf3deebf22f4125e7d76089
SHA3 39f3128f53775042925bb827ac67483cc830a6f46755a34ef7703fa54974f8ca

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x26569
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99515
Detected Filetype PNG graphic file
MD5 9532b73af2326d4cb8d1d5885e9c6c59
SHA1 e9552cfaf7db3fff937d7b5e2abc8e956d233006
SHA256 ace8ec7a07c72389b6be1685db3eb4d4f5125dd4ab5565ec1c3e71bbee4d6e89
SHA3 bddda38211f979b9bc69aa810dc5d6db8c192d09adec60541ba733f4d55a9242

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56031
MD5 e518b8ae009986dd90363fcc61d7fff7
SHA1 24ed3f9f44fce167e79b53ea5f9b0505c4d567e1
SHA256 34ea1c2173226ecc593f8a2b0224c51ebbee1928715bda9339eec7717a822b89
SHA3 519dec097566117a56d9c49b0a711e82451c0f81fbb53f042549a61cd51122e6

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25287
MD5 ac85ded4e576ce909f5460536b63a4f1
SHA1 07e0380006e58eec02eaaa047a58aceeef1552d3
SHA256 e1d818d622875ce2cf81883816ef982aa05a724c46f82b3e67875e0bc24228b1
SHA3 d70f10064348a4608f8b92740e05f739736144b222db3aa5c51187c75c5cc4eb

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26919
MD5 519a33f5d2b4442ef3caf6d4501995fb
SHA1 e54df9d112555eb11a132bfee15b69ac186b422e
SHA256 80bc91470ef70d527d0c4e0824945bc3b17ff84f464bca425661c3e7e1972ce7
SHA3 88c911ed5f1b1354c3379baaaef2540d70c370fd877f536d069dc0ea55cd0b13

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33268
MD5 234c2763997eec9c8a72ef190b928d68
SHA1 089fcaabba97f63455ce8a47e2d5d07fa56ba55b
SHA256 33ef72f38fc1fe2842c44e11bb351f94385bb186fee0fadbefc9364ed52aeb93
SHA3 10cbb07d784f332702d9d3451649950c1af6fb999ac1c2dac82df168cba5f302

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x150
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17906
MD5 8383ba160a86b918ac500521efb456a7
SHA1 f22c6fdd31aa68c5f9e247f8ccf0f565e14a0189
SHA256 abd66b63471de2699c97d06e41cfe0702144237079f76a9e0bd965b1a1862231
SHA3 efd13cc0570151797c6c4b7e4b3761f636efa32240f45d0558ce27bb27985147

11111

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.65899
MD5 5122144b9d53156c4e57b17a1a053780
SHA1 288d913edb40ee38f7454d06c29ed27ae22c9dfc
SHA256 51ead3f34c17e52674857e24bf87d957761ac454b56a26b27c6030e276a35008
SHA3 ee47b53174c5d98cc396a6109bfac8f2c8cdf6f3be52fe814722b2137949bb2f

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01865
Detected Filetype Icon file
MD5 2328936c925901d04838effec3fab136
SHA1 cb75b5acf3e5191a1bfdcefc7e0206be7650f708
SHA256 a66b80427e3b6568923ff5e56791230c0418beb870d1ce4ef7fefe21d2c2a4c0
SHA3 d2e3c382b92784c90c2f7c0ef9b24c07428b2575d9b5aa9bceb68573536aec00

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x4f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70171
MD5 827f4025b1e66990852b6cdfcc213074
SHA1 88bac0eeadca5477c31d226040a04d50c4d0e6ae
SHA256 ffb0f2610130eb7af539e94a87facf86b28db5fbab7dfc1050a421a09d1090d0
SHA3 62e9185b693a622fc671934d10f0406a6019c3a0d47e3f2c9a1d3c80e0c8f2ee

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x5e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11919
MD5 a561f3d4bfa3931040422a49ec17c06e
SHA1 9a27136c8b8073f832d2f3a9239a49f0c14cfaf6
SHA256 8d51d4405593fb12ba0d4a2708507e2300b363f7ce3cf538cb65c25cc1d3044f
SHA3 5ef4d8131a8cc50f1295dc3ebde9c211384f3ca41c657f5c8b18fd6b3a5c7c75

String Table contents

Friday
Saturday
Invalid file name - %s
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
Invalid variant type conversion
Invalid variant operation
Invalid argument
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Jan
Feb
Mar
Apr
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Creepy Jar
FileDescription Green Hell MULTi18 - ElAmigos Setup
FileVersion (#2)
LegalCopyright
ProductName Green Hell MULTi18 - ElAmigos
ProductVersion (#2) 1.9.2
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x41a000
EndAddressOfRawData 0x41a008
AddressOfIndex 0x4127ac
AddressOfCallbacks 0x41b010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Raw bytes from section .text could not be obtained.
<-- -->