6ac2023d5fdf694f863db651d018cf15a241dcf74bb14c45827a72fc00917865

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1994-Jul-29 04:43:18
Detected languages English - United States
Debug artifacts LiveCaptions.pdb
CompanyName Apple Captions Inc.
FileDescription AppleCaptions
FileVersion 1.0.0.0
InternalName AppleCaptions.exe
LegalCopyright © 2026 Apple Captions Inc. All rights reserved.
OriginalFilename AppleCaptions.exe
ProductName AppleCaptions
ProductVersion 1.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
Suspicious The PE is possibly packed. Unusual section name found: fothk
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegSetValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 0bfa00cf5ae99e4f38c4397b2c9a4201
SHA1 b82db49669a713c8db52761a8acf23a4928dcd2b
SHA256 6ac2023d5fdf694f863db651d018cf15a241dcf74bb14c45827a72fc00917865
SHA3 537a1f07151fa0288454c69fd0b536c459465bfcc65208fa2982836a474393c5
SSDeep 3072:A5YVH9YXjXffbpqSsR0WtEaWIRKHk42qfQk90m3x2atEzZB7Wjys/70z2kxOjbT:AyVH+XjHsRPDWIRQJrem3xVtEzzWjys
Imports Hash 6a04b9214c74e79d68dc9d8fa4051a28

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 1994-Jul-29 04:43:18
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xd000
SizeOfInitializedData 0x20000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001530 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x2e000
SizeOfHeaders 0x1000
Checksum 0x37a45
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x80000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 5e7615eeca5d2f4c022bd167d1f89079
SHA1 f2fc98e2c3e681f2d894adb5eb9a7856ce70e941
SHA256 4a75d031232cd8cafed2dbdc1c4de1e65ab3fbdf80a5de32e262b73eab26a03e
SHA3 70fdaae15507dd846171a137c89b61d01f506842848d95f7ed6283bb0916410e
VirtualSize 0xb34c
VirtualAddress 0x1000
SizeOfRawData 0xc000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.80432

fothk

MD5 2392d0aedee6a4d32a588dff3887b9bd
SHA1 703e66bf35664508b5622b4c6de9c0c23f81550f
SHA256 4fe7d9b8bdd452f78e67083c49127f40c4a641f285bcaac3f6e62e8a0eb933fe
SHA3 11b00252f6a284771b44ce9414283cf1d5b3ee90ffd9aeb760b53241c4b291ad
VirtualSize 0x1000
VirtualAddress 0xd000
SizeOfRawData 0x1000
PointerToRawData 0xd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 0.0159202

.rdata

MD5 fcf85e55576dc25386f1f9072ef04692
SHA1 d2247b85510d91544ed94c6cd7e476c536a23e18
SHA256 5ca14e75328a183ee6be74dc1b9f9a1bbc7d74ca9360073216a49616ea614996
SHA3 dfee66de0dee7e1684d446340ceaf7288217ac7582d15ed733b84042af9457f8
VirtualSize 0x456a
VirtualAddress 0xe000
SizeOfRawData 0x5000
PointerToRawData 0xe000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.3106

.data

MD5 f4f8996669436fc65486db3f0fdfca05
SHA1 ec601ec1b2034fb0dda7141bfa9eeba5bd649bcd
SHA256 c7fd1d8a592f933e6f4274a49db8b72675aa3c1781c09e6a22a1e541c403c4fa
SHA3 0855c5d843063fe9c4d05178f093e69f18a146d4a03208aae99afbdcbc1ed813
VirtualSize 0xf60
VirtualAddress 0x13000
SizeOfRawData 0x1000
PointerToRawData 0x13000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.62567

.pdata

MD5 3feec4e7d339ebf5b6339e7aae881160
SHA1 85c4184a6923a55d5e8e46725384d710be1aca62
SHA256 c519cbaa65490b6cc0fa1ed29a5a770fbb0c7e36f5d4cdc3a0f2d9dd21caa788
SHA3 52343714360163f16ae8156035bd31371a492c4e8c6ecc7f66d2df306b584b30
VirtualSize 0x102c
VirtualAddress 0x14000
SizeOfRawData 0x2000
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.71735

.rsrc

MD5 7cf8c02e571d05f792ab9610800b7f9b
SHA1 40cfd1e1d110d62ace80cb41ab906b76d7a4b014
SHA256 62a9d729917c2a3b633657e95a4d62585bf2e3316bdc7e68c9d33c50c2678333
SHA3 c771cd99e32841e0b31a7f0633ad0cb8aba094a20ddaeb7adefe64563eef4c79
VirtualSize 0x16919
VirtualAddress 0x16000
SizeOfRawData 0x17000
PointerToRawData 0x16000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.01961

.reloc

MD5 6319f96e5f48bd826e73ee4604263667
SHA1 b130fba80e16bd670c6831f9b8d17fb348552dd8
SHA256 76f00a05651e9e2bd6db72de9d32077a7aba82d7578c95d2a8a4e4c80ee29192
SHA3 b682c0dd28c8c23a755edb3d2ab47be1226e42e0103b56e9181914b3018a3a56
VirtualSize 0x138
VirtualAddress 0x2d000
SizeOfRawData 0x1000
PointerToRawData 0x2d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.575292

Imports

ADVAPI32.dll RegCreateKeyExW
RegSetValueExW
RegCloseKey
KERNEL32.dll GetModuleFileNameA
CreateSemaphoreExW
HeapFree
SetLastError
EnterCriticalSection
ReleaseSemaphore
GetModuleHandleExW
LeaveCriticalSection
InitializeCriticalSectionEx
WaitForThreadpoolTimerCallbacks
WaitForSingleObject
GetCurrentThreadId
ReleaseMutex
FormatMessageW
GetLastError
ReleaseSRWLockExclusive
OutputDebugStringW
CloseThreadpoolTimer
AcquireSRWLockExclusive
WaitForSingleObjectEx
OpenSemaphoreW
CloseHandle
SetThreadpoolTimer
ReleaseSRWLockShared
CreateThreadpoolTimer
HeapAlloc
GetProcAddress
CreateMutexExW
AcquireSRWLockShared
DeleteCriticalSection
GetCurrentProcessId
GetProcessHeap
GetModuleHandleW
WideCharToMultiByte
DebugBreak
IsDebuggerPresent
GetCommandLineW
LocalFree
RaiseException
GetSystemDirectoryW
CreateProcessW
LoadLibraryExW
FreeLibrary
InterlockedPushEntrySList
msvcp_win.dll ?_Xlength_error@std@@YAXPEBD@Z
api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_register_thread_local_exe_atexit_callback
_initterm_e
_initterm
api-ms-win-crt-private-l1-1-0.dll _o___std_exception_copy
_o___std_exception_destroy
_o___stdio_common_vswprintf
_o__callnewh
_o__cexit
_o__configthreadlocale
_o__configure_wide_argv
_o__crt_atexit
_o__errno
_o__exit
_o__get_wide_winmain_command_line
_o__initialize_onexit_table
_o__initialize_wide_environment
_o__invalid_parameter_noinfo
_o__invalid_parameter_noinfo_noreturn
_o__purecall
_o__register_onexit_function
_o__seh_filter_exe
_o__set_app_type
_o__set_fmode
_o__set_new_mode
_o__wcsicmp
_o_abort
_o_exit
_o_free
_o_iswspace
_o_malloc
_o_terminate
__C_specific_handler
__current_exception
__current_exception_context
__CxxFrameHandler3
_CxxThrowException
__std_terminate
__CxxFrameHandler4
memcmp
memcpy
_o___p__commode
memmove
api-ms-win-crt-string-l1-1-0.dll memset
ntdll.dll RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory
RoUninitialize
api-ms-win-shcore-obsolete-l1-1-0.dll CommandLineToArgvW
api-ms-win-core-winrt-string-l1-1-0.dll WindowsCreateStringReference
api-ms-win-core-com-l1-1-0.dll CoInitializeEx
api-ms-win-core-path-l1-1-0.dll PathCchAppend
api-ms-win-core-winrt-error-l1-1-0.dll RoOriginateError
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
api-ms-win-core-sysinfo-l1-1-0.dll GetSystemTimeAsFileTime
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
api-ms-win-core-errorhandling-l1-1-0.dll UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
TerminateProcess
GetStartupInfoW
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
api-ms-win-appmodel-runtime-internal-l1-1-7.dll AddDependencyToProcessPackageGraph
OLEAUT32.dll SysStringLen
SysFreeString
GetErrorInfo
SetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException

Delayed Imports

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71877
MD5 1ded8980671db5ed18045e1f1c2bc6fd
SHA1 618de9d64c88fc6dc62c1ebb23785135e40ecc8d
SHA256 223e0bcf52a7c16f6db82abed0451c1872dddfecf69466aac75fc62eb65f3509
SHA3 b6fb15203b798f9f70f2d2a9e38885b3ecf0545ecd99a5eb246964024ccadb10

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb576
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99112
Detected Filetype PNG graphic file
MD5 2e1b9bb85bcb35f81dcefe760ed9940c
SHA1 61852fc5e881a5a6552753a68b6f72cd0db9ebe3
SHA256 0031ecb23d3561f894489b777e64398392c9295b84256d67d709e39af65b372a
SHA3 d7e2578f70a0eebdf8b9b6b2978a7cfc29679725c3acf36c42ce53eb25635b68

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19893
MD5 a24c91d745ab698ded1e3ced1f5fa8be
SHA1 e8ae1e37c3e9b3d9763a9658e593b0a66c7dd976
SHA256 a549d3e48684744b7f94820c2451993079cc4ffc7a67609ff40e58d700d9d3d1
SHA3 bbee033fc488051daed7816fc9fc47274def5261e1fa6f12fd201e197e303104

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19103
MD5 7268f062a5a5d9445f4623cd898bb1d7
SHA1 983ac4aca019096b328d9a73959d82f4b9d66fbc
SHA256 43b56d9dd485f15bba5918d287843d89f3bb31e223d191d51852bb9deaf0faf8
SHA3 63f5405a1a77eb01f62735e871595f74cfecd372a1392cb62b7f020de3953912

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19858
MD5 31c8bd130953f7789681e7a3e540f6bb
SHA1 2a3b3284885020e8f795c60a966edc8f7313e142
SHA256 6dd52e4fdc4c8f949ee9fb7af506eeb20aafbebfb7d43ce30f6dd91e4a0c229f
SHA3 98f21096f4e5789e071257b3a82b48f7bc53f02af18d0d076cdee2e73f6a5d3f

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1449
MD5 2b4cd983d6e0affb262fade04a024691
SHA1 655e5c5dd5d4a462780b43118f04d9e097d42efe
SHA256 91c40c0fb3280662419f811c52a0aa6dea431a1d7a47416285dd7bae066a7a39
SHA3 c2ffdd4893e5b2978d4de1e6177e002f99b36ce84e51b99d9281a60a850fc316

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05727
MD5 15de4ba77746a8eaf4f0a8a2103ad1bc
SHA1 2140aa741724aaeb4b2a44531954775f0b43ab0d
SHA256 1e41543a9943e5c8c4e394068ee7ade6444a92235ed18d3ce18d66e0f0c26db7
SHA3 98a054e43fc1bbfb45e9c8adec7838c346ee2e0f3c1502894eb93590443c31d2

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24253
MD5 1f801737e30fb5eebafc6082b8793c90
SHA1 253c9ef9d770b77032329462f8eb20b2da6f25e0
SHA256 56bbcfd1a09d2a46da47288e66edebcdeeb58ded42e0fd0915ba0edc03549c61
SHA3 e45c1119f37c9d4803f2fd872abaf0685b2e41fc11a812d81c6000f2879e1019

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93253
MD5 c98d005f99341f354d8893cfd9aededb
SHA1 4baf7c72eebeedc84c741ab414fce58e63655fa5
SHA256 20b6bab5769943604ab09b4021888a73aa8026fd5a87e74b6944d91021a82919
SHA3 f0ee75ca6de24687eea0a7b8aeb5bb52048d806ba04031ee091d26f3d16646c3

1 (#3)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95799
Detected Filetype Icon file
MD5 1864b9775d5851fc019e4610cfc6e009
SHA1 d219380b05b5412ff9aa702a052a789cc732f9d1
SHA256 0f0474f3ef86f8ba6180d2e7a8133d6ec30407dcc2a85088d1e39a1cab47157c
SHA3 88effd561eaab818406940faeb97ceb22f50aee82856b242aa39980562a4d200

1 (#4)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x31c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31604
MD5 4c830b693222a626e8e098452dda7f33
SHA1 d22c7a437da37492e7e0a41779e094e285fe9ef2
SHA256 ce18c6d6e0da04b1ace9212a91385ee3ff7e284d81a9aa8db1f1b8fe1b33f588
SHA3 57364234422905f2cf86838c71708814685b97e58bf3696f58ef2a5adbb70505

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x4e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.76788
MD5 74e4fe237a7cecfbe64a53edda133310
SHA1 4492fcb17447ba631f3d9374feff5db812c14005
SHA256 fd32719b63156fec0edae7e5bfaee8a29381ec4542145023ec59e1150957aa03
SHA3 84e1998b7f56bd4696e6ed0ea1f0e53b7720e4a408d4b33a0c9e1f0f0df64211

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Apple Captions Inc.
FileDescription AppleCaptions
FileVersion (#2) 1.0.0.0
InternalName AppleCaptions.exe
LegalCopyright © 2026 Apple Captions Inc. All rights reserved.
OriginalFilename AppleCaptions.exe
ProductName AppleCaptions
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1994-Jul-29 04:43:18
Version 0.0
SizeofData 41
AddressOfRawData 0xf848
PointerToRawData 0xf848
Referenced File LiveCaptions.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 1994-Jul-29 04:43:18
Version 0.0
SizeofData 920
AddressOfRawData 0xf874
PointerToRawData 0xf874

UNKNOWN

Characteristics 0
TimeDateStamp 1994-Jul-29 04:43:18
Version 0.0
SizeofData 36
AddressOfRawData 0xfc34
PointerToRawData 0xfc34

UNKNOWN (#2)

Characteristics 0
TimeDateStamp 1994-Jul-29 04:43:18
Version 0.0
SizeofData 4
AddressOfRawData 0xfc58
PointerToRawData 0xfc58

TLS Callbacks

Load Configuration

Size 0x148
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400135c0
GuardCFCheckFunctionPointer 5368768304
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x779a88af
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 36
Unmarked objects (#2) 1
C objects (33145) 10
ASM objects (33145) 5
C++ objects (33145) 31
Imports (33145) 11
Total imports 1173
C objects (LTCG) (33145) 5
253 (33145) 1
Resource objects (33145) 1
Linker (33145) 1

Errors

Leave a comment

No comments yet.