| Architecture |
IMAGE_FILE_MACHINE_I386
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
1992-Jun-19 22:22:17
|
| Detected languages |
English - United States
|
| Suspicious |
PEiD Signature: |
PECompact v2.xx
|
| Suspicious |
The PE is possibly packed. |
Section .text is both writable and executable.
Section .rsrc is both writable and executable.
The PE only has 4 import(s).
|
| Info |
The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
|
| Suspicious |
The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
| Malicious |
VirusTotal score: 38/72 (Scanned on 2025-11-03 07:16:55) |
APEX:
Malicious
Antiy-AVL:
Trojan/Win32.Agent
Bkav:
W32.AIDetectMalware
CAT-QuickHeal:
Trojan.Ghanarava.1713390083deec1a
ClamAV:
Win.Trojan.Agent-480293
CrowdStrike:
win/grayware_confidence_60% (W)
Cylance:
Unsafe
Cynet:
Malicious (score: 100)
DeepInstinct:
MALICIOUS
ESET-NOD32:
Win32/HackTool.Patcher.AR potentially unsafe
Fortinet:
Riskware/Generic_PUA_PF.AR
K7AntiVirus:
Unwanted-Program ( 004d46cd1 )
K7GW:
Unwanted-Program ( 004d46cd1 )
Kingsoft:
Win32.HackTool.Patcher.AR
Lionic:
Trojan.Win32.Banload.ldg4
Malwarebytes:
Malware.Heuristic.2014
MaxSecure:
Trojan.Malware.300983.susgen
McAfeeD:
ti!A5562CA64088
Microsoft:
Program:Win32/Ymacco
NANO-Antivirus:
Trojan.Win32.Agent.vgehs
Panda:
Generic Malware
Rising:
Trojan.Win32.Generic.1568E975 (C64:YzY0OpLuZSu1487C)
SUPERAntiSpyware:
Hack.Tool/Gen-Patcher
Sangfor:
PUP.Win32.Agent.V7lh
SentinelOne:
Static AI - Malicious PE
Skyhigh:
BehavesLike.Win32.Generic.cc
Sophos:
Generic Reputation PUA (PUA)
Symantec:
ML.Attribute.HighConfidence
Trapmine:
malicious.high.ml.score
TrellixENS:
GenericRXAA-AA!CEF35B285ADA
TrendMicro:
TROJ_GEN.R014C0OJM25
TrendMicro-HouseCall:
TROJ_GEN.R014C0OJM25
VirIT:
Trojan.Win32.Delf.CMF
Xcitium:
Malware@#2d2wabmocsuz6
Yandex:
Trojan.Agent!8kMp6aiwl/U
Zillya:
Tool.Patcher.Win32.16193
alibabacloud:
HackTool:Win/Patcher.AV
tehtris:
Generic.Malware
|
| MD5 |
cef35b285ada330986862e2473deec1a
|
| SHA1 |
f5611189ab195060b96608c06c23b3b3e8512dc8
|
| SHA256 |
a5562ca6408898d35f9b6a553cd73dbe8152cb7b1c20a2dc50fff97ab9f84806
|
| SHA3 |
a5108bbcab04a76f8efd64f6de9c565fa2295e03cc2ecc48317701e691851d23
|
| SSDeep |
3072:w5TOYq4VYsvM2uGKcpeRllBvvGdZuMsJSrSS+Cbc0jrRlN2sntN6Jz:U9FVYmuGTpeRllBnyZuMsMrSlH0jFlN
|
| Imports Hash |
09d0478591d4f788cb3e5ea416c25237
|
| e_magic |
MZ
|
| e_cblp |
0x50
|
| e_cp |
0x2
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0xf
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0x1a
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x100
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections |
2
|
| TimeDateStamp |
1992-Jun-19 22:22:17
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xe0
|
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic |
PE32
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0x57400
|
| SizeOfInitializedData |
0x10800
|
| SizeOfUninitializedData |
0
|
| AddressOfEntryPoint |
0x00001000 (Section: .text)
|
| BaseOfCode |
0x1000
|
| BaseOfData |
0x59000
|
| ImageBase |
0x400000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
4.0
|
| ImageVersion |
0.0
|
| SubsystemVersion |
4.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x73000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0x36f06
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve |
0x100000
|
| SizeofStackCommit |
0x4000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
3503cc6264f562179bfa85abf59a72a0
|
| SHA1 |
604c6b08bcc1259b6434582e29dfb77e8aa39cf8
|
| SHA256 |
842ed07335c6a6edf0d0a9eecdcf9ecd1e1d19be32d8bf6c18d96535cc6142ca
|
| SHA3 |
f960abb7f4e26d80d93a087422f06208604c922d2b112f36629a8d7c06cb8005
|
| VirtualSize |
0x70000
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x26200
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0x32434550
|
| PointerToLineNumbers |
0x4f10
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
7.99819
|
| MD5 |
1418e2b189e44311ef621eb9ec27fd4d
|
| SHA1 |
b8a54a0808a9b1527e42ad707b1ce44c507ae773
|
| SHA256 |
ea8c0001f00e8c2cf4a08b6a0befd6143b920e23ab9764c9a8c64d0a3bde33ba
|
| SHA3 |
1d435eca991ce77de05f8298d8ccd9cb6a789b0fcab8082defa29877e85d9c92
|
| VirtualSize |
0x2000
|
| VirtualAddress |
0x71000
|
| SizeOfRawData |
0x1e00
|
| PointerToRawData |
0x26600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
6.19621
|
| kernel32.dll |
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x134
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x8a8
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
5.25741
|
| MD5 |
3e7672a02e9b80fc9bb273704ced7eff
|
| SHA1 |
c39076209b53609c9047c82fa1ea5d6bf9d8d0b5
|
| SHA256 |
4c8d8c55d1e80b2dc3388d062a19d54b2c74d64f852f0d722980797401a55664
|
| SHA3 |
447104421e7b9815b86d1efb2d673b5b38f21a0e1c05a32d4884e5e5741a3183
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x200
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0xdc
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0xd8
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x338
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x3c0
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x370
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x3cc
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x214
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0xcc
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x194
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x3c4
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x338
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x294
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_RCDATA
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x10
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_RCDATA
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x20c
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_RCDATA
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x295e
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_CURSOR
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
0
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| Type |
RT_GROUP_ICON
|
| Language |
English - United States
|
| Codepage |
UNKNOWN
|
| Size |
0x14
|
| TimeDateStamp |
2006-Aug-24 07:01:24
|
| Entropy |
1.92322
|
| Detected Filetype |
Icon file
|
| MD5 |
1e8d7babcb25aa6de69d1cdefec818f1
|
| SHA1 |
e7466aaf3f5cac68be2f6ff8db11798603f0f5bf
|
| SHA256 |
63fea0fb3188d0214c93c7c26a91ec00dd531ba7ce80b475aa36d9fe26e20fbc
|
| SHA3 |
dcdfa379a95da2012f3f78fa4724d9efb31bb1fcfcd9e884275ba62a50928177
|
| StartAddressOfRawData |
0x472d3c
|
| EndAddressOfRawData |
0x472d70
|
| AddressOfIndex |
0x472d34
|
| AddressOfCallbacks |
0x472d38
|
| SizeOfZeroFill |
0
|
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
(EMPTY)
|
[!] Error: Resource 1 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 1 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 1 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 2 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 2 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 2 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 3 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 3 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 3 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 5 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 5 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 5 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 6 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 6 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 6 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4084 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4084 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4084 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4085 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4085 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4085 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4086 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4086 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4086 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4087 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4087 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4087 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4088 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4088 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4088 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4089 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4089 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4089 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4090 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4090 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4090 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4091 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4091 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4091 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4092 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4092 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4092 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4093 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4093 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4093 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4094 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4094 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4094 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4095 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4095 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4095 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4096 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4096 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4096 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32761 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32761 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32761 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32762 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32762 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32762 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32763 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32763 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32763 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32764 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32764 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32764 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32765 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32765 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32765 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32766 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32766 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32766 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32767 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32767 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32767 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[*] Warning: Resource DVCLAL is empty!
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[*] Warning: Resource PACKAGEINFO is empty!
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[*] Warning: Resource TXPL is empty!
[*] Warning: Resource 32761 is empty!
[*] Warning: Resource 32762 is empty!
[*] Warning: Resource 32763 is empty!
[*] Warning: Resource 32764 is empty!
[*] Warning: Resource 32765 is empty!
[*] Warning: Resource 32766 is empty!
[*] Warning: Resource 32767 is empty!
[!] Error: Resource 1 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 1 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 2 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 2 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 3 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 3 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 5 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 5 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 6 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 6 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4084 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4084 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4085 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4085 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4086 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4086 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4087 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4087 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4088 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4088 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4089 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4089 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4090 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4090 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4091 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4091 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4092 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4092 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4093 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4093 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4094 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4094 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4095 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4095 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4096 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 4096 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource DVCLAL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource PACKAGEINFO is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource TXPL is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32761 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32761 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32762 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32762 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32763 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32763 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32764 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32764 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32765 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32765 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32766 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32766 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32767 is bigger than the PE. Not trying to load it in memory.
[!] Error: Resource 32767 is bigger than the PE. Not trying to load it in memory.