| Architecture |
IMAGE_FILE_MACHINE_I386
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
1992-Jun-19 22:22:17
|
| Detected languages |
English - United States
|
| Comments |
This installation was built with Inno Setup.
|
| CompanyName |
Decepticon
|
| FileDescription |
Total War Three Kingdoms Setup
|
| FileVersion |
|
| LegalCopyright |
Decepticon
|
| ProductName |
Total War Three Kingdoms
|
| ProductVersion |
v.1.7.1
|
| Malicious |
The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
Can access the registry:
- RegQueryValueExA
- RegOpenKeyExA
- RegCloseKey
Possibly launches other programs:
Memory manipulation functions often used by packers:
- VirtualAlloc
- VirtualProtect
Functions related to the privilege level:
- OpenProcessToken
- AdjustTokenPrivileges
Can shut the system down or lock the screen:
|
| Suspicious |
The file contains overlay data. |
4449314 bytes of data starting at offset 0x14a00.
|
| MD5 |
7d5d9e08e0f048168db7fd529fcbf638
|
| SHA1 |
8822ffb93051b08b9595ad3a9514a19dd08917de
|
| SHA256 |
712ff8e1b0e486b852d0cbe998179f3dfefaba857da6394354c07214e5653e24
|
| SHA3 |
43cd1fe3bd7ea356d872fb65b14f00445eb84ddbd24dd7af285576945d371551
|
| SSDeep |
98304:wE1sc97xLiVPpX/GBmRlolahu1VVl5LuSYHgYY:/1BrLiPpPh4VlLXIgh
|
| Imports Hash |
4fb639b17a439bf0efa713bd4c6e715b
|
| e_magic |
MZ
|
| e_cblp |
0x50
|
| e_cp |
0x2
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0xf
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0x1a
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x100
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections |
8
|
| TimeDateStamp |
1992-Jun-19 22:22:17
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xe0
|
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic |
PE32
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0x9400
|
| SizeOfInitializedData |
0xb200
|
| SizeOfUninitializedData |
0
|
| AddressOfEntryPoint |
0x00009C14 (Section: CODE)
|
| BaseOfCode |
0x1000
|
| BaseOfData |
0xb000
|
| ImageBase |
0x400000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
1.0
|
| ImageVersion |
6.0
|
| SubsystemVersion |
4.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x1c000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve |
0x100000
|
| SizeofStackCommit |
0x4000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
0f1e58bee0e7f7b353de3dde9de0259d
|
| SHA1 |
cd63f5af7ca6959334a306e7d9bdb2cf56525e70
|
| SHA256 |
7890404ed39ba0d699a791a17047bae44bd2287e3e4fb71a80d5b0474f87dd00
|
| SHA3 |
bdaad60feea207f5cc9268aef0bf82e12020be650bb30e0f28a19f27697197a0
|
| VirtualSize |
0x9338
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x9400
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.55652
|
| MD5 |
e7dd09e5875d98f57a11be52cd2304a5
|
| SHA1 |
a46ccf47a822e3d4b226525beb4168bf5702df5b
|
| SHA256 |
f7f25afb75691a6bbdd6667a4ac9e9c8572311c6f2add8d017142497ebc963a2
|
| SHA3 |
eb69a46cd1b83ec238ceb21b9e96d639b91287df37ebdfa7a27e923664b46cde
|
| VirtualSize |
0x24c
|
| VirtualAddress |
0xb000
|
| SizeOfRawData |
0x400
|
| PointerToRawData |
0x9800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
2.7543
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0xe50
|
| VirtualAddress |
0xc000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0x9c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
bb5485bf968b970e5ea81292af2acdba
|
| SHA1 |
40a39d9e8c8cecd5356ab96745d82d2ebfe17cfb
|
| SHA256 |
d9ea6e80cc1edfdffa8d534a8c61448b19b74d683845b94ad6d9a543e5ceb8cf
|
| SHA3 |
09274dc071547ce3dc33528de99c9ad5a9eb119600e5a61b3127f74cde6dcfbf
|
| VirtualSize |
0x950
|
| VirtualAddress |
0xd000
|
| SizeOfRawData |
0xa00
|
| PointerToRawData |
0x9c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
4.43073
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x8
|
| VirtualAddress |
0xe000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0xa600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
9ba824905bf9c7922b6fc87a38b74366
|
| SHA1 |
f43ee83e6afa1c343ff6db68e13efde43471cbb6
|
| SHA256 |
ad44157821ba24c07dd44f66940dd75adee9d6919a0577c5a75aa502637dddaa
|
| SHA3 |
370eba5499bce03a18d462f5b9e6ee4598126f2a2243cc5fa1590c7c7245c5d7
|
| VirtualSize |
0x18
|
| VirtualAddress |
0xf000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0xa600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| Entropy |
0.204488
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x8b0
|
| VirtualAddress |
0x10000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0xa800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| MD5 |
1a329c92420712f03cabd42b3a487d5b
|
| SHA1 |
7cfdd0489d15f6f625b6efbe8beeef5c015eea32
|
| SHA256 |
f6e65c0fcc593238a9383b92603e4939b26928b94717d20fa09a76cadba31a71
|
| SHA3 |
e854d389c333139686cec4e86ee8957d5e8ea6205332cb4beeb699c0f354168a
|
| VirtualSize |
0xa04c
|
| VirtualAddress |
0x11000
|
| SizeOfRawData |
0xa200
|
| PointerToRawData |
0xa800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| Entropy |
4.25693
|
| kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
| user32.dll |
MessageBoxA
|
| oleaut32.dll |
VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
|
| advapi32.dll |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
| kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
| user32.dll (#2) |
MessageBoxA
|
| comctl32.dll |
InitCommonControls
|
| advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2e8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.82837
|
| MD5 |
25d6ad3a4d2181cd4643f663ad8021ab
|
| SHA1 |
51c5ba8110f6a41e252194678ceabddf405917ca
|
| SHA256 |
d47d70d1464d85b28230ed47edcc28f28559feed794f17da7f9c4d25a1870524
|
| SHA3 |
b429ef4ae241233f6fa6dd9bfbf05c459a042316c3be008a2980a478faf0addb
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x128
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.67558
|
| MD5 |
6763ab19171b06ac737f959d1fd65bf0
|
| SHA1 |
25e98fcf3f5e33ae57e540f0b24f679bf02c90e3
|
| SHA256 |
2f597281c59acb81da4db5d7f7a0ec4060517a62e28a76e40b45b5b96d9c4885
|
| SHA3 |
014375e2738316b2181de8299f85893c699325db82ce516bc96469c9f60b0f28
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xea8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
4.89827
|
| MD5 |
03cb28c621511d2623c295c558e9782f
|
| SHA1 |
21d5bba93898887e90bb01f065a5f25b10472a72
|
| SHA256 |
584236b052ecc4ba8a02d44aeeac346cc5b807239fb5e2c7f46f961cec2359bd
|
| SHA3 |
852ea0c178864b5d8ee6df23906ee211b56d4609a5f201b8a83069180a271ce7
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x8a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.51539
|
| MD5 |
8c92b6bb5cfee595e19db36973435c63
|
| SHA1 |
a84c1ee38311ad71a8752ace13ccaad2892ed3ab
|
| SHA256 |
6101039b2a2e54b0cf59aaad5fbc967a46862bc271bc5793058c4c2b2ed98d97
|
| SHA3 |
1234953b03f19173ba8a99a78850088791c942dd4482e510211c7cc35255a996
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x568
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.15892
|
| MD5 |
07ab40232a754ed2c0c15f56192dde9b
|
| SHA1 |
72a8b142843ed9ba3c1366a0c2dd830dc5dcf0b0
|
| SHA256 |
a46669b7090cad24527074dfd013eb298836b9dff9db55f781cc3589705f9312
|
| SHA3 |
27f58ef50cacda60d91b08ee15dab02815a9587a93fb666ee8706572a6043dfd
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x25a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.26966
|
| MD5 |
55db13156d52e71e247bf594cef9be66
|
| SHA1 |
e1ed9f3fb7e19f63cd4d16074f11f7b992036a35
|
| SHA256 |
5f428fc081986f24be631756b8b5e4c7113241a91d36b22240d6fc847b758a86
|
| SHA3 |
aa21f2495f864196a61c8f85e531571186e981d4254b1c8f9e3320ab92f5ce30
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x1a68
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.60483
|
| MD5 |
d1f895b65364542e3fe539ca366de5be
|
| SHA1 |
102279d92ae4c85aacd085b5680359c7636cef39
|
| SHA256 |
9cf88dfb9851ae399493e1e42a1162367d3eacd46dda30781bf260feca009112
|
| SHA3 |
f93618994ebf3504f711c274e1c3c6c8412cfaba51d27883da64f8d47a6f4d42
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x10a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.72355
|
| MD5 |
d2d493f4e91c327c9c37201326dca452
|
| SHA1 |
c0412588649c619fa09f17ecebdf917c530dc068
|
| SHA256 |
b97446fcd9e86758aa319cc241e1288fc2bd3d89dfb80e581d173f6fc643d298
|
| SHA3 |
086298815cd53c84e551d83b4110e211a66f692df98332483d3e1eac73497667
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x988
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.75794
|
| MD5 |
4c54402688c6359279c8b4724ba62786
|
| SHA1 |
62e0c9ba9f11a8b84610efc99e7c2d194425713f
|
| SHA256 |
640c1804ccd1f401283694b42f0e887deddb60fb8632f2839d79d50ba7fc850e
|
| SHA3 |
321d0218457e5b76d2e8feef657c69c87c5a6db4c1fd9ddf06319a69a1dc4f5f
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x6b8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.81688
|
| MD5 |
dfdeffd191f83bb3c5276fd21b959021
|
| SHA1 |
fb50663ab9544ffda973be17e8b7412d999f3a89
|
| SHA256 |
d734a5446401d6b72abd67a5dff4aa38f205576f3e4a9a7fa360f9961d1b9efd
|
| SHA3 |
5a1a37f9c5a8136a04d622af7e7a2adbab7ab73b892e0ae3fe077e5f575f7f21
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x468
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.84944
|
| MD5 |
17b21007300b6143ae9580bc38b2a167
|
| SHA1 |
7b3fdeddc9f2209d04bb787a9f74a29cf0c71475
|
| SHA256 |
97b2c6129aa9f2c73bc1e163da3e7b3e5938a3eab39188cd981fab04ec5d3d2c
|
| SHA3 |
9e18f0d999f1cf6a6469c07cb9596917582a3c8f8ce6889eb51d1b9a8d26ca64
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2f2
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.21823
|
| MD5 |
bbf4b644f9dd284b35eb31573d0df2f7
|
| SHA1 |
4f9885ae629e83464e313af5254ef86f01accd0b
|
| SHA256 |
2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
|
| SHA3 |
ebed2e4a929600c1460761d462143feb092840986b31c9748d3aeb8174d4205e
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x30c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.31515
|
| MD5 |
ac2a0551cb90f91d779ee8622682dfb1
|
| SHA1 |
ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
|
| SHA256 |
840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
|
| SHA3 |
58a85f5c53df73aa79e5f5a36aa151ca0d9da4d450ebc2975a3ee827b46342a5
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2ce
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.25024
|
| MD5 |
c99b474c52df3049dfb38b5308f2827d
|
| SHA1 |
7375e693629ce6bbd1a0419621d094bcd2c67bb7
|
| SHA256 |
26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
|
| SHA3 |
c6013febd14dd876e3b81111ec17dd2724dbf4147b0ad7be9d03259bcb59fef3
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x68
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.86149
|
| MD5 |
aec4e28ea9db1361160cde225d158108
|
| SHA1 |
249013a10cde021c713ba2dc8912f9e05be35735
|
| SHA256 |
d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
|
| SHA3 |
a067c4d88d719ed8d568951acb776bd798b691a8b153f8d94ba0574ede1fbf4c
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xb4
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.20731
|
| MD5 |
c76a8843204c0572bca24ada35abe8c7
|
| SHA1 |
066052030d0a32310da8cb5a51d0590960a65f32
|
| SHA256 |
00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
|
| SHA3 |
07523cf88b3803ea41acfeb3c9c0c4b5b4b9fb6f9a3232802491d8de1b6c9166
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xae
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.04592
|
| MD5 |
4bd4f3f6d918ba49d8800ad83d277a86
|
| SHA1 |
1f5e4c73965fea1d1f729efbe7568dcd081a2168
|
| SHA256 |
34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
|
| SHA3 |
2d01c56a5bf0b390addf4fb5b6ae02f9a64bd03ffd300d3763615bbb8ec911fe
|
| Type |
RT_RCDATA
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
4.56808
|
| MD5 |
e470d49c079b0d7f0cd72f84c34c26e5
|
| SHA1 |
a73c7387b9c1fae4acb995f1abd9fe2e2dea5cb1
|
| SHA256 |
2f673a582960542d3e43a7060cb9ed787bf1b7a3c835bd4f317603450b145d71
|
| SHA3 |
34716a15a65e6bdccb5245085e3b2152c65470a1b168e05ddc02f28d80f8358e
|
| Type |
RT_GROUP_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xa0
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.05962
|
| MD5 |
4804d177e6b5147ac6e8b30e8f0a42d8
|
| SHA1 |
02983acdfb2bcce6009e508874e5065707323b91
|
| SHA256 |
3de0cfb642dcf11bf4923c5d97a8a438cf03f0b4726d13599f082fbc05b59dc3
|
| SHA3 |
33f11b400a0f293fb122ae7d2033be46f482968a0cf019c21d6e98c06aa57ffa
|
| Type |
RT_VERSION
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4b8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.74817
|
| MD5 |
a836d0bb6aa04c5f5fc53ad158c85730
|
| SHA1 |
7b7c2b98803b8ebc56b2b5fac192b29ff871f9ac
|
| SHA256 |
8e6019a0cd8ec1f43e4915fdc722570855031aacc6fc42da45bf3ecf3c313d30
|
| SHA3 |
793d5b9036818da034d49b80a423c681dd93f6112fdfe4ad5f82f57ad887399c
|
| Type |
RT_MANIFEST
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x560
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.06505
|
| MD5 |
a55a7d7c9ff1dedb9adde63011baa3dd
|
| SHA1 |
292e1726ad2fb93963565934fd3778a46f91ecf9
|
| SHA256 |
2cf04736815666b1c1b91422e56e0a431c9e03075b7f543325fd16b88cff1b9e
|
| SHA3 |
9e3955461fcb3b2d303ad2a473b4f1c4012a882a3e303ba6e7b0170fbb09819e
|
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%s' is not a valid date |
| '%s' is not a valid time |
| '%s' is not a valid date and time |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Invalid filename |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Invalid variant type conversion |
| Invalid variant operation |
| Variant method calls not supported |
| Read |
| Write |
| Format result longer than 4096 characters |
| Format string too long |
| Error creating variant array |
| Variant is not an array |
| Variant array index out of bounds |
| External exception %x |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Signature |
0xfeef04bd
|
| StructVersion |
0x10000
|
| FileVersion |
0.0.0.0
|
| ProductVersion |
0.0.0.0
|
| FileFlags |
(EMPTY)
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language |
UNKNOWN
|
| Comments |
This installation was built with Inno Setup.
|
| CompanyName |
Decepticon
|
| FileDescription |
Total War Three Kingdoms Setup
|
| FileVersion (#2) |
|
| LegalCopyright |
Decepticon
|
| ProductName |
Total War Three Kingdoms
|
| ProductVersion (#2) |
v.1.7.1
|
| Resource LangID |
English - United States
|
| StartAddressOfRawData |
0x40e000
|
| EndAddressOfRawData |
0x40e008
|
| AddressOfIndex |
0x40c3d0
|
| AddressOfCallbacks |
0x40f010
|
| SizeOfZeroFill |
0
|
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
(EMPTY)
|
[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted!
[*] Warning: Section BSS has a size of 0!
[*] Warning: Section .tls has a size of 0!
[*] Warning: Section .reloc has a size of 0!
[*] Warning: Please edit the configuration file with your VirusTotal API key.
[!] Error: Could not load yara_rules/bitcoin.yara!
Could not load company_names.yara!
[!] Error: Could not load yara_rules/monero.yara!
[!] Error: Could not load yara_rules/findcrypt.yara!
[!] Error: Could not load yara_rules/compilers.yara!
[!] Error: Could not load yara_rules/suspicious_strings.yara!
[!] Error: Could not load yara_rules/domains.yara!
[!] Error: Could not load yara_rules/peid.yara!