6e9fc6ddb2078d0ae89d285b1e450a81

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Feb-05 14:07:15
Detected languages Dutch - Belgium
English - United States
CompanyName Image-Line
FileDescription FL Studio
FileVersion 21.2.3.4004
InternalName FL
LegalCopyright Copyright © 2012-2023 by Image-Line. All rights reserved.
OriginalFilename FL.exe
ProductName FL Studio
ProductVersion 21.2.3.4004

Plugin Output

Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Suspicious The PE is possibly packed. Unusual section name found: .03L
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
Uses Microsoft's cryptographic API:
  • CryptMsgClose
  • CryptQueryObject
  • CryptMsgGetParam
  • CryptDecodeObject
Enumerates local disk drives:
  • GetDriveTypeW
Info The PE is digitally signed. Signer: Image Line
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/73 (Scanned on 2025-03-15 05:02:10) All the AVs think this file is safe.

Hashes

MD5 6e9fc6ddb2078d0ae89d285b1e450a81
SHA1 173d5a59a3aa703b0cb44175c22f514d506d2779
SHA256 6fab3fe596e30167df15522db303f8b64be64f53bdbbab01569abd3985e61c9d
SHA3 382a2a298f096f2b61922aa3909849a504062fbc203d27983b3a3d5c9abc9f44
SSDeep 49152:NbQUGvbm3zQVV95iEOvjDc1kjPc8aqj/2YjXvcL/2NXydBbszpozS/EADO:GUEbm6V95RQjDpjVLj/TXySp6HMO
Imports Hash a2bc8e51a684c5d127dd3115d7025f50

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2024-Feb-05 14:07:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x58000
SizeOfInitializedData 0x48200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000309E4 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2f4000
SizeOfHeaders 0x400
Checksum 0x2e6e4d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 aaa6dc8e071578de6da7d63e3388a248
SHA1 14925d4c416eed2f9210f350516ba8a1c0b745df
SHA256 540a370d4b35c9ed0b83903b16b613c6233812ce9149e4a072e6a32e67020251
SHA3 79cba762d82b60d225f3e60f5bf2c726d98a2f23792eaa06561db5e41c85a509
VirtualSize 0x57eb0
VirtualAddress 0x1000
SizeOfRawData 0x58000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50558

.rdata

MD5 e9fa9f572bc98c9baf875d71abd85a28
SHA1 7a5d94bb53e2978c62a7d73930d504d418a49f24
SHA256 bbb6e108985673ee27641a9bde3833bf46a7766c080708cf1e3ca56c30e178c7
SHA3 ab28cc63d585491c8386a4a8babb8ef01a13054f7f9b56eeff4b30435b0b9307
VirtualSize 0x1737a
VirtualAddress 0x59000
SizeOfRawData 0x17400
PointerToRawData 0x58400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.20207

.data

MD5 986d0ee7b5dd34eb7d614e65c899927b
SHA1 afbc9c5e8d471cebe71d29eec1ac1dc61974b4ea
SHA256 7d76581108e590192b9806f2624f6bff927ce84c85619f970e54af156bf52674
SHA3 8293055d52c33c96cd9ba7618e99fcbaaa761e96d46034610fb8fd23cf0229fb
VirtualSize 0x13304
VirtualAddress 0x71000
SizeOfRawData 0x1c00
PointerToRawData 0x6f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.59213

.pdata

MD5 73cf346e5a125cc91029dab66c73486c
SHA1 fb3aff9c39eb2b80b993e55ae85a3defde5fbc36
SHA256 6a7f3aa0c7f05429117bb5c8ae97385ea27c484b8d7f0063b5626f4dd16d3a70
SHA3 d88a562ab05a97eafaa587927ec447a1bf316d3a8b33b9637bc4a67ced72f0a5
VirtualSize 0x3474
VirtualAddress 0x85000
SizeOfRawData 0x3600
PointerToRawData 0x71400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.82054

_RDATA

MD5 494a0c4f270b4860b568db3b3bdc2f6c
SHA1 fe302be8a10ffc8ac1fab45d36368f9010655114
SHA256 5f7ba816a8153082bc53c96392ca128ee389ee8e7fffcccf714cd7e81e3fd415
SHA3 11d42e359f626759cf09f622cec0ef16d687efe88b61a0fe6de75d683044ca6f
VirtualSize 0xf4
VirtualAddress 0x89000
SizeOfRawData 0x200
PointerToRawData 0x74a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.44455

.03L

MD5 14f53d2c73a393a18b136f84cfdf2dda
SHA1 83642512f28293278ddd0eb8c5e7773828e7d162
SHA256 5c7a8142ffa3b914bac36414b403fe7af2a69085a3ab64c5d92f66f0ca684d57
SHA3 1532b13a868cafc9e5b3126badc1b2564f4654dcad8ec6b164ead2ae8e2cee51
VirtualSize 0x24e684
VirtualAddress 0x8a000
SizeOfRawData 0x24e800
PointerToRawData 0x74c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.23743

.reloc

MD5 6ec3f36c1d206c94489b0be4497a6555
SHA1 d6b777884f641074d05d8ecfec7f935fd3f1922a
SHA256 8a65c696ddf2f60849e3827ed5f088e486abba31b201e30f3f10f21f2dc31c10
SHA3 08dfbd21f337ce56f1e92e14b2b635f984fc03a830b3d4e017ed50141b9a11d4
VirtualSize 0xda0
VirtualAddress 0x2d9000
SizeOfRawData 0xe00
PointerToRawData 0x2c3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.4751

.rsrc

MD5 4cdb0315ae34196d4eab1b4e31206dae
SHA1 ddbe9a49b931b1e889ff62eb1c89a9f8e875f18a
SHA256 bcb3e318e4e6447611ab1ed702bff52a3d414c96546f9688b477fcb037efe9be
SHA3 2b8e610dd6e5ab1823f95d47b6b908909efeeaaed1d137a0414fbc6f13a1d6c5
VirtualSize 0x1930b
VirtualAddress 0x2da000
SizeOfRawData 0x19400
PointerToRawData 0x2c4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.12809

Imports

KERNEL32.dll MultiByteToWideChar
WideCharToMultiByte
LoadLibraryW
GetProcAddress
FreeLibrary
SetCurrentDirectoryW
GetModuleHandleW
LocalAlloc
lstrcmpA
CloseHandle
HeapSize
GetConsoleOutputCP
GetLastError
GetFileAttributesW
FindClose
GetModuleFileNameW
FlushFileBuffers
GetProcessHeap
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
FindNextFileW
WriteConsoleW
LocalFree
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
GetLocaleInfoEx
GetStringTypeW
CompareStringEx
GetCPInfo
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
ExitProcess
GetModuleHandleExW
GetStdHandle
WriteFile
GetCurrentDirectoryW
HeapFree
HeapAlloc
GetFullPathNameW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
SetStdHandle
SetFilePointerEx
GetConsoleMode
HeapReAlloc
GetTimeZoneInformation
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
USER32.dll MessageBoxA
ADVAPI32.dll RegCloseKey
RegQueryValueExW
RegOpenKeyExW
WINTRUST.dll WinVerifyTrust
CRYPT32.dll CryptMsgClose
CertFreeCertificateContext
CryptQueryObject
CertCloseStore
CryptMsgGetParam
CertFindCertificateInStore
CertGetNameStringW
CryptDecodeObject

Delayed Imports

1

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.83396
MD5 b107141cdc0859607cc514e8b208c356
SHA1 e27bb0e3a87f714d446dd6dc79bd30569d172ebb
SHA256 9c96112d9b436627bf20915782706d481e5cd126e7f77a6666f6c80e875863ef
SHA3 3516ee4e2ebdc4c64d91eebd464bf745e0566aca61453958264d3db85b3a0db3

2

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.92422
MD5 2621f637c6c7d0db8be0f69b563ef5dd
SHA1 ed475266e4db6dec5875133c99f0111deb04bceb
SHA256 16f12d2959fb3a02b8312fb7cd936df48feb5abce7a9fd35c17cbb2a28fd78a7
SHA3 08df889b2c7ebffb12ff0a9181022a2bbd43fa937024c242cb6b75c7753288be

3

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.89934
MD5 12bdcee5f0cfe1f8ffa9e2c0a1adeaba
SHA1 6bf2e26f8a0ad541e15d8edf2054cc73e80fba4f
SHA256 ec589108c42affb2db8dbfbf0db3effa6efcf9b4ea834a6d0e5396e15c3db35a
SHA3 a2bc7e13313f7aa6c2a623626025da071ae008692bdd591c77c3c8538d7767db

4

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.27241
MD5 50b99b94a377a591f430e82790b9b033
SHA1 b2448a7e594efa6e1bd2b7f489ebc9f5f8c058b5
SHA256 c9b2f06a01be81320a68e8799fb513a9607c7755ff0f8a1cb43a70f2cd158dd2
SHA3 a955bf24223c22c8d3fa59488948ecee734fc7a08d84a9b1243e88c287cc8904

5

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.83024
MD5 a6f033789027461f3a5a336c283526b4
SHA1 6d8cac98e418b0a174ab0e28babe88cddd3c5b31
SHA256 020cb115105db53d9ad24c38b458f95b142f41a97a29471e9e5e9ebbd9d8d259
SHA3 fc445bc4d35dcd9bb631d00f748f1649335b85d6ef6e7417489d1a5a680343a1

6

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0xbe87
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92352
Detected Filetype PNG graphic file
MD5 4995ff1475023a731f41bbdaf9b472c5
SHA1 5aa323494b6a70e6c288ed5775b5f341cae0c953
SHA256 33bb59435d329b932e692090741162d919d9fdb5ac6f0d06fbfee1e1af13ab09
SHA3 2710ca1e48ae6fda01ef509b05b38c543cf52087cc08411672c3c7a5d076746f

7

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49085
MD5 f56909ebdcbdb63d88688844c60bbf0c
SHA1 2b9e9989321adced9ba8a77bc9bf50aced2d1877
SHA256 90af34728784180417581a8bdd86913ea42771a849d86729869f619f52e59217
SHA3 b70a22f8be680f0eabc850694f78c04688dc69ce86674de97f796e57801a91b5

8

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.5967
MD5 6133469538aa207b64dcdc6e63af4cd3
SHA1 e15e66e2752e6b7586aae992807990a910d05faa
SHA256 bca66c7bbaf55700b0158182e17375f304f07920c67e6440978db7abf88ba67c
SHA3 5acb917ded135098b8ac52852e3b8faf1d6ad12420d6d16f9d8c9eb81754bffc

9

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.68084
MD5 a63e2a0adb3d78bc0b2a8afd89b8396b
SHA1 610ad2cf2f91ae230681abcdc2e727a4c961312c
SHA256 986ee4cdb71a7c30dab1c0ddcbded2dc02c0938354c2f5d36c9af10889392d1d
SHA3 dd0bdd6affe58c076d11d5b8a9e01a6ec93747047335aaf7cedd2890bed46fdc

10

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.83905
MD5 314d258975d4463a1ac36eaa3e78d571
SHA1 e5dfdded8657854dad59f7b4c09d42c081760c55
SHA256 ff4edc0d28d124e0d3f4778e831d39cddf816176f8999a6d25a1b215eeea1bb3
SHA3 2535709be9faac49fcdbf694cac7b4c8ac3de9b43d8a822ca7c702ce5ba6209a

11

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.98311
MD5 ce9414b98effb0c84b244872d19b3191
SHA1 4be9911a3bdc6c89676df0f1e6e6adf919a4a103
SHA256 5fb67afaf69a7c826cb7b14cc6821fa50d490ada4f9dcf1c371709b374f3fef7
SHA3 ae56c5823905b2e5397e4ebfadd91b5b51cfe89f451bc7e15bfc1dfed0f5237f

12

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.05319
MD5 cdffcaa6e595ab719b17a35fba08a3c0
SHA1 5ab314bd948619951ce808df0a73566f364724dc
SHA256 07b5b764ac2c556f7017cdad54f6c25aa8fe8b4558a54a9f6cdd8f2aa174c9f8
SHA3 33b29c3d4f03ca76eaf3772d2c9a7e4117745ea097d2f0f2da0ef2ba22cc994b

13

Type RT_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.09598
MD5 740cc6c8ed4dbc339efa9365b2d0aa1d
SHA1 aa1dc62da50556d8b2ab86db1bcdc9a1f0a5f692
SHA256 7c403df78d591cf46186c6274dbfb5b217af7c552a20f4da22c17f79718cedf0
SHA3 56735178752515dae848cb12718a9dd0136de6df6b82297b2c324f048617d81a

102

Type RT_GROUP_ICON
Language Dutch - Belgium
Codepage UNKNOWN
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11665
Detected Filetype Icon file
MD5 cabf6239529d8843852c8637e06cca1c
SHA1 18d1662b29bd2f5eb2b78261cc0b1405519a02e8
SHA256 25152b5bb426e945f6f2ab14584bc5e10328b3e7ee6fe1d141bf7af4ce861c95
SHA3 a5f2f9f6f264d09ee28f798a44f27b3dafd11dc065ab9d07ad7d232eed45c207

1 (#2)

Type RT_VERSION
Language Dutch - Belgium
Codepage UNKNOWN
Size 0x2f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47376
MD5 795d148f771f44bfa19e6fe764f42738
SHA1 5bf6f7d9fd71a050a774dd7f472eecf1d5fdcf72
SHA256 4519cbabfa52071ddb790560892bbf6ed12361c9db2aa3646a8f983311833f04
SHA3 e3288d93e2f5a2b8547a60d9314ab66d584b2ed80a4e1e48f5225cab78cedff8

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x513
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3514
MD5 1a85b21c4b9e955dd08e67e9401646a5
SHA1 c4e93727e7a407213b97933c6e9d908a5e1b8164
SHA256 d491e3819d0f02b8ccf555931e27020e90358c969df8afca12fb6ad6e35affb1
SHA3 6ab204e6a569a4effe3e20fdab6119777dbeabdb0fa545b5dd062ff80e711c45

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 21.2.3.4004
ProductVersion 21.2.3.4004
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Image-Line
FileDescription FL Studio
FileVersion (#2) 21.2.3.4004
InternalName FL
LegalCopyright Copyright © 2012-2023 by Image-Line. All rights reserved.
OriginalFilename FL.exe
ProductName FL Studio
ProductVersion (#2) 21.2.3.4004
Resource LangID Dutch - Belgium

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140071020

RICH Header

Errors