a0fecf755b431ab05a070692cd681ecc

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1999-May-03 05:55:29
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentVersion\Run
Suspicious The PE is possibly packed. Unusual section name found: .itext
Section .rsrc is both writable and executable.
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
  • RegSetValueExA
  • RegFlushKey
  • RegCreateKeyExA
Possibly launches other programs:
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Enumerates local disk drives:
  • GetLogicalDriveStringsA
  • GetDriveTypeA
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowA
  • CreateCompatibleDC
  • BitBlt
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 66/72 (Scanned on 2025-01-28 01:42:46) ALYac: Win32.Grenam.Dam.G
APEX: Malicious
AVG: Win32:Renamer-F [Trj]
Acronis: suspicious
AhnLab-V3: Trojan/Win32.Renamer.R54474
Antiy-AVL: Virus/Win32.Renamer.j
Arcabit: Win32.Grenam.Dam.G
Avast: Win32:Renamer-F [Trj]
Avira: W32/Renamer.A
Baidu: Win32.Worm.Delf.bi
BitDefender: Win32.Grenam.Dam.G
Bkav: W32.FakeExeYHPtv.Worm
CAT-QuickHeal: W32.Grenam.A9
CTX: exe.unknown.grenam
ClamAV: Win.Virus.Gnamer-1
CrowdStrike: win/malicious_confidence_100% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
DrWeb: Win32.HLLC.Sorrypic.1
ESET-NOD32: Win32/Delf.NRJ
Elastic: malicious (high confidence)
Emsisoft: Win32.Grenam.Dam.G (B)
F-Secure: Malware.W32/Renamer.A
FireEye: Generic.mg.a0fecf755b431ab0
Fortinet: W32/Injector.2F48!tr
GData: Win32.Trojan.PSE.1CER05K
Google: Detected
Gridinsoft: Trojan.Win32.Grenam.sd!s1
Ikarus: Virus.Win32.Renamer
Jiangmin: Worm/Delf.yc
K7AntiVirus: Trojan ( 000c8b551 )
K7GW: Trojan ( 004d4f8e1 )
Kaspersky: Virus.Win32.Renamer.j
Malwarebytes: Generic.Malware.AI.DDS
MaxSecure: Virus.W32.Renamer.J
McAfee: W32/Gnamer
McAfeeD: Real Protect-LS!A0FECF755B43
MicroWorld-eScan: Win32.Grenam.Dam.G
Microsoft: Virus:Win32/Grenam.VA!MSR
NANO-Antivirus: Trojan.Win32.Renamer.lnwkz
Panda: W32/Renamer.F.worm
Rising: Worm.Renamer!1.DE00 (CLASSIC)
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Skyhigh: BehavesLike.Win32.Gnamer.hh
Sophos: W32/Renamer-K
Symantec: W32.Tapin
TACHYON: Worm/W32.DP-Renamer.534016
Tencent: Worm.Win32.Grenam.ha
Trapmine: malicious.high.ml.score
TrendMicro: Trojan.Win32.GRENAM.SM
TrendMicro-HouseCall: Trojan.Win32.GRENAM.SM
VBA32: TScope.Trojan.Delf
VIPRE: Win32.Grenam.Dam.G
Varist: W32/Delf.EA.gen!Eldorado
ViRobot: Win32.Renamer.A
VirIT: Worm.Win32.Delf.KHX
Webroot: W32.Virus.Gen
Xcitium: TrojWare.Win32.Delf.NRJ@4palta
Yandex: Trojan.GenAsa!bFkr50Cc7zI
Zillya: Worm.Delf.Win32.1913
Zoner: Trojan.Win32.87681
alibabacloud: Worm:Win/Delf.3d32b358
huorong: Worm/Grenam.c$GA
tehtris: Generic.Malware

Hashes

MD5 a0fecf755b431ab05a070692cd681ecc
SHA1 e1477eb69b2592936858cd626ecccde5411a54c0
SHA256 643be7e3293b13cdce6b3b322039b1ced42083212eb9f2600053f299f36d62b8
SHA3 8ce9457572835d0fd7454415e240fd30540d2d6b462f1ee1f7ae16174347c2cd
SSDeep 12288:bFMIztyCK5x8CBmn+RrNbEyWYa0Ie1vUx9VX:HZyCA8CBmn+RrNj9ay5IX
Imports Hash 4f4a6de94eaf71d7800eff9037c49f26

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 9
TimeDateStamp 1999-May-03 05:55:29
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x70c00
SizeOfInitializedData 0x11600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00072814 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x73000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x8d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4fcb1ba34cb14fd1f89872150222ae04
SHA1 83a77591c36218fdb02b3b04e44df07b2caee953
SHA256 965e74e12ae1e53352dc0ba83a105dc93ad9466bef6c24a7eead6214d2edbc74
SHA3 e1345466283d2b3e162f6c3f3575c23a44ce6b5bba6171e3676c498e45ab1290
VirtualSize 0x7002c
VirtualAddress 0x1000
SizeOfRawData 0x70200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57494

.itext

MD5 a55cb933bb4acf9de8ba7ac965575ef4
SHA1 042e613425fa75b30db3cc8d75d9f53bfd0dc245
SHA256 dc5a28a1732c782fca3bdc4aa3dd598e2d20ac0729fca2beb96ec02400b0e322
SHA3 2948e21d86a3beaaa1f057c0460e0c03b6bf01f9a7cb63887d8d80e9f805741e
VirtualSize 0xa00
VirtualAddress 0x72000
SizeOfRawData 0xa00
PointerToRawData 0x70600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.69331

.data

MD5 dc9b863276062b2e2c1e1ffe56d7d0b8
SHA1 7d89966e77809e15c63724353fee40180ad92d51
SHA256 c932abdeb9ebf89678f463c6fecc2fef65cbd574962f2cc5e692e2428520f78a
SHA3 a6b5a204a11dd5202142dbd0325675db2faa74232ac47598a49f9e2ccb7bc52a
VirtualSize 0x24cc
VirtualAddress 0x73000
SizeOfRawData 0x2600
PointerToRawData 0x71000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.31691

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x4ce8
VirtualAddress 0x76000
SizeOfRawData 0
PointerToRawData 0x73600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 aa8abe6176103dc524e88e85de4efcee
SHA1 9518b713efe6bec989ce19d0e62d8fcc034b6d10
SHA256 b9e09508543884fbefa7d4accf84c34f117b52a00940a5e4e00846256f0c99d7
SHA3 bb1e45f027432b11a1994ac81d40d4b7ab09b58b2d2a6701c84de78792d14415
VirtualSize 0x2a64
VirtualAddress 0x7b000
SizeOfRawData 0x2c00
PointerToRawData 0x73600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.10468

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x34
VirtualAddress 0x7e000
SizeOfRawData 0
PointerToRawData 0x76200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 74f253aa9f19b5b236f8efef4cfa8a49
SHA1 869de46776083cccfac0c9cf4538348ed91c9589
SHA256 025e77e87e189053162ba69f2dd32055644de9daa0eb93d381fae45aa8df573a
SHA3 e0fafa21ac2239c8a1aa8f278b97bfa7573ae7bfab5a3f11b02ed8927234151a
VirtualSize 0x18
VirtualAddress 0x7f000
SizeOfRawData 0x200
PointerToRawData 0x76200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.reloc

MD5 f0d825167de67ca2352628a4f816af30
SHA1 561407b3c252e5c870143a81025e53cf2e4732f1
SHA256 ae70bd06b91215f5f92bc2e9a478bbe79494349420822ecea0b07bed783a05da
SHA3 2c758b575d3dee432e26322e2b62e03cb9ab54da193540d5b1ff617bf8070164
VirtualSize 0x6630
VirtualAddress 0x80000
SizeOfRawData 0x6800
PointerToRawData 0x76400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.65867

.rsrc

MD5 22dc11cacff633e762d7efff08cd6593
SHA1 a02d95be771c9499e7c57b5f889e2ef9647fe17e
SHA256 e945178b7989760c6c7a5ecc799147b1366639c98b774007d4e9956333d270a4
SHA3 a8564117e6a63e3679a528a35edd71783fe59e3ad6c3baf11208d64eaa043415
VirtualSize 0x583c
VirtualAddress 0x87000
SizeOfRawData 0x5a00
PointerToRawData 0x7cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.45102

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
user32.dll GetKeyboardType
DestroyWindow
LoadStringA
MessageBoxA
CharNextA
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
CompareStringA
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
CompareStringA
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll (#2) GetKeyboardType
DestroyWindow
LoadStringA
MessageBoxA
CharNextA
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RestoreDC
RectVisible
RealizePalette
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
GdiFlush
ExcludeClipRect
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
version.dll VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
CompareStringA
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll CoTaskMemFree
StringFromCLSID
CoCreateInstance
CoUninitialize
CoInitialize
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
CompareStringA
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll _TrackMouseEvent
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_DragShowNolock
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
shell32.dll ShellExecuteA
ExtractIconA
shell32.dll (#2) ShellExecuteA
ExtractIconA

Delayed Imports

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

1 (#2)

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.24256
MD5 5afe8dc7e8c9505504dcf233831bce3f
SHA1 ed180ac464cb3d6a0a89c9bd716afba17c822eb8
SHA256 cdef58361cf79577ee61142effa9b335dcf3191b7a7838f67db72a96fc0eaf86
SHA3 001b0e611e9d6df5b4209c911965d489ec38f5a0a918a972b1184da629470015

1 (#3)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.40538
MD5 a5bb70273d9bcfd7d384951e2930c261
SHA1 786d0662a0982f081d88364f09e5bd48bc7c16c7
SHA256 018a990d2a62197a15a398152ae1582dbc874487d1396ba106afe22ca601a813
SHA3 f4982fec16cbfa0e06c65bdb627838cb0829f495d8d863e2cd821182828e4b1b

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.74878
MD5 0f50ef7bc69b3c293c2d202e9b39a57a
SHA1 87b36facb282e692ede90c1c7c8ef08b6587db1c
SHA256 c46cd2160aaa5d652e153e2993f72d7dd310beb52b411ec24b0dfc137b50cfda
SHA3 5dbcfca7340f80a055d490c2759d1c89683a3b516bf5c5565ad0a028024a4e15

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34199
MD5 c40aaadc09a8746bca5fd789c40b6a23
SHA1 93a1b1bddcac345278e0268fd8be62fb40834e3c
SHA256 6c7ee9d1593c43e6c691ae41827ce98318e649624cf5f2093819fcad60c5374f
SHA3 fffa9893c994b1534e257f47d703a139d0e061bae3e692085fcdfd4cc9e59fa0

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46183
MD5 424aba466e276648572c1408de227561
SHA1 40582332710bf8981c25ab4e2538907d0f8b4c0c
SHA256 8800fbd9199428531f3c0fb4d8d1e2359c8eb58996221c2782d447237b0c675b
SHA3 d11fdea921396f32da959a569234e6392a9b4c7e690735abbb6f337ab20b9de9

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39804
MD5 6213769fa998e280c4732c6768d64087
SHA1 d88262a10bff26bc93c9b2610097979498464121
SHA256 2d2f805190e85cc73c696c922a79da114d0aed7f9f56765480d64544f147fbef
SHA3 050a5dcfe7e6d0e08f16d81ea318d8d3b1c7bc89c5be64d52cdda1dd29cf3c01

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x410
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29998
MD5 018668aef26f0da0ce845e7285e672cd
SHA1 4cedfb171ba0f56449a044f0ae8faf4245932a8e
SHA256 80d66077f94c594d76b9bb820dfaed12750b73f05be8b35f3244fe76339b13ac
SHA3 ede4910964610305da49545b1ad9a99f627a489d8a5aba2bc4afbbe933dacc1d

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x394
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27467
MD5 9da3e381fe6959069a442c6f5ef2033c
SHA1 004285f516e5faf51a7714532b62b5f097db8627
SHA256 58827a5b4e2443c974b4807454257350e62d4e9adbc826b4d558cc5ca1ab1522
SHA3 f0d85099133de342d098c347c7dab01897ccba1a3587a1118e21781a9b6390db

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26349
MD5 df98630e3fe3c0d47b68caab47d07e90
SHA1 bed7ac11c6b233ce09c8e2b4c5542aae080c6b40
SHA256 cff6dd1babf74c7ead1275bfe2b2976a4c5ac30d23f0cd9afd2904b0de05b585
SHA3 f767db3391ea400034b47023fb24b3ca6ae3b9d8bb86a0d5249a89ab11f1ffef

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3cc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30897
MD5 2ff6bcc921d0cab45268750d108e69a7
SHA1 29f52de905f9d5e8a20dfca4fc0e9c1dd3529529
SHA256 087600d3c31fce113162d59f3d624b445147a2673643f7c49f98d3872bad8ef2
SHA3 c5ef146e0384144ce42fb9540fc76efe2c3829e3467465f5e387a9c1f79bbcf1

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36965
MD5 f47bffa834e57da05fb11629df61304f
SHA1 081551ac187c830537ec96cd3d59ca1c9bb919ab
SHA256 4d674818463c06668afec8d5f0a8a6030d1c305c9c67d92d7d9944049879a373
SHA3 75a40f5f677126c9d820a9b14b17bae3debd820e85052c84ea6659c4c35db812

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33625
MD5 cc22f1ac30dcdeae9cd72ed8abbb02cc
SHA1 9ed70b6c75879d40481e525a275d4b99d75abc56
SHA256 93aef43aba52d60e77b3bbd23dda80f9fe6e1be314a87b02feca051426a10ba7
SHA3 8a7657f317d99f5180257945fed83bf07fa87ee81355373bedd142df395b9a6e

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x194
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40367
MD5 9ce62fb7054fbf904693dcb512ce2774
SHA1 fee9df4d7a19a4cfdff18952ab1e09bfc4c5117e
SHA256 b29ed2e2012cfb9d05450a66efdde177aa99c3b1285123b59dc968e61cc62d5b
SHA3 7c0dc1f311399709a21f9a77c62012bcb5b01964285dfb4b39afdfad80e858ad

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27129
MD5 f7e7144c4fdf02bd6e4215699f257c5e
SHA1 57899d0450e159decb918dd60256dc0cc50ada4e
SHA256 7740574ac0c927564e0349f625185a83541479859cd49c2601ecd67cfc0dad36
SHA3 cde60323c2d249b0e497f83e8d0fc7799a89408b89d42fe9d5ef8f1ebb27fddb

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35594
MD5 bc06ca47ee6f8d20c4389834f53a44f4
SHA1 102cf0807762abbf7250c533692c282d045a5239
SHA256 e78299e236878f8931b75a5cb1ef7a566f6d2e204d6a3ab5a40d01df44709545
SHA3 c9ace61db2f1daf8a5203b1d42290d62e58289f030e2946a1e32b002ccdf530c

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29371
MD5 0a399d0f0d06f3807ce2b2bb95a277c8
SHA1 5142268d23a5b4e39d181255166bb1ef41141548
SHA256 b48888f35b371cfb0451cb3a85d8eaafdd440c96c3631acd94b1855c34a25b64
SHA3 3867a5cc562325ef1216b90bf3f340d06f0ef28dcbd9d3191ea47617856abe85

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27025
MD5 cc059da0cc759a80a268dfad4f274483
SHA1 a0a0a87acf73ad5f7c82a71a998fc337781773b2
SHA256 90265eb57205dc14068d9735975c633fe948c10a9defc0a7f0eb3d52edecd1ba
SHA3 aef947e28aafa6b42a1ed9c913e5247a84ba4f7163e0681d764268e11a8fac1d

TDM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60539
MD5 70523644975b6f5b2488e6b22c7819b5
SHA1 f558ddbc7109d0d7e897d5bcabff4baa5d702cdb
SHA256 a349e81a13efa29dc2cb771d6c678666deb187d45a15f1947604f8db3ecf2ef8
SHA3 0d98c927aab1597955d3a7fb85c98bd52a45e55508803ab9d452a1f22ad1127c

TFRMMAIN

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25377
MD5 54210713c81f97f3744ae2077e157d91
SHA1 eea70690b1483b69e950fbc8168b26da74d4bbaf
SHA256 e82151a2dfdb02cfaee426506ad670038f8b8b85e5e380e1e86c775c38c22354
SHA3 ac51ac930ab231f577ead4a48c64c53f6c6941f0cb7bf6b1efafdf57cb823ae3

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 6f191f45d2ea96b2d22e9eafa1a55bd7
SHA1 aa9a0930cb6ae38dd9645dbd2e85cf3796ed2977
SHA256 f01c223e6cf0e0f5c1d990ad720488af398180adb1b92e61c2144cf11d3130f8
SHA3 ab7f66f51b1cb5a30df00c2674a3a04e8323578947f36708e2e82dd5d04f0416

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x352
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91814
MD5 1f8b6f4c785e03abafeb46c2b518bbc2
SHA1 cbda183acc66a84b5218233b1682c9f05242c837
SHA256 d9fe4d54fc5d8a32651e8e84f97c8b6f32b58719bf4f881db56fbb357a891cfe
SHA3 311cf54819955f28d69e1be277dd9173b08f574800991dd1ffc7309c50ca8921

String Table contents

JPEG Image File
Shift+
Ctrl+
Alt+
Clipboard does not support Icons
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Cannot change the size of a JPEG image
JPEG error #%d
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Metafiles
Enhanced Metafiles
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid pixel format
Scan line index out of range
Cannot change the size of an icon
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No help found for context
No topic-based help system installed
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format
''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
'%s' is not a valid integer value
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow

Version Info

TLS Callbacks

StartAddressOfRawData 0x47e000
EndAddressOfRawData 0x47e034
AddressOfIndex 0x4737d8
AddressOfCallbacks 0x47f010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted! [*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!