b0bd642c39665cb5bb927c9e61285ee2

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-May-16 00:20:28
Detected languages Czech - Czech Republic
English - United States
Debug artifacts D:\JiRoAgent-1\2\s\Shared\Compiled\Win32\Release\STEventService.pdb
FileDescription Event Service
FileVersion 11,4,6,0
InternalName Event Service
OriginalFilename STEventService.exe
ProductName Event Service
ProductVersion 11.4.6

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to AES
Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. Unusual section name found: .orpc
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegNotifyChangeKeyValue
  • RegDeleteKeyExW
  • RegEnumValueW
  • RegQueryValueExW
  • RegDeleteValueW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegOpenKeyExW
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegCloseKey
  • RegDeleteKeyW
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
  • GetTempPathA
Leverages the raw socket API to access the Internet:
  • WSACleanup
  • FreeAddrInfoW
  • GetNameInfoW
  • ntohl
  • WSAStartup
  • InetNtopW
  • GetAddrInfoW
  • htonl
Interacts with services:
  • CreateServiceW
  • QueryServiceStatusEx
  • QueryServiceConfigW
  • ChangeServiceConfigW
  • DeleteService
  • ControlService
  • OpenServiceW
  • OpenSCManagerW
Enumerates local disk drives:
  • GetDriveTypeW
  • GetVolumeInformationW
Manipulates other processes:
  • OpenProcess
Info The PE is digitally signed. Signer: Safetica a.s.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/73 (Scanned on 2024-06-06 23:44:39) All the AVs think this file is safe.

Hashes

MD5 b0bd642c39665cb5bb927c9e61285ee2
SHA1 dd0e23937eec4e531544f58d0bed38ac6fdcb563
SHA256 27395a47c98ed0c23937514363c5ad0556eda6d9fac266cd9b6bff0fbc7ae6e7
SHA3 e9669ab79c273d7d10f51963b7f09fac5bfb644ce9b163d167d8dccf06a12e29
SSDeep 49152:OjmMtcfdI3qcuuPvHq9+xKP3oS3jxpNKI0lS8PEBRU2bR1:OEGTu8vHPKYI0cBy2n
Imports Hash f8cd6559de3fcbbd9c5c7dbb293591c9

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2024-May-16 00:20:28
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x1a4600
SizeOfInitializedData 0x83c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00156F91 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x1a7000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x22d000
SizeOfHeaders 0x400
Checksum 0x230e6d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6c9407ae5255faf2035b59fbd82de802
SHA1 c13ab6d1307ed738df5fe6064d5143c5a9064dc9
SHA256 c128940c0221953258f5512e036604b62d6120dd61cabac5a18e24ce177803a4
SHA3 71056e61833ca0e6195f2f3a6db52b56aae4bb629889cf1bb83e113d39083e42
VirtualSize 0x1a42fc
VirtualAddress 0x1000
SizeOfRawData 0x1a4400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.61926

.orpc

MD5 8e5d80723395151f31c71a24a5d4b4fc
SHA1 bfba542885b73ae00ff4a29692e8261112b886f8
SHA256 7061f5c5fba67400c84831f200b5950b0f03fe28865002ec0643f5c21bd9a6b2
SHA3 e77dfcd008520d6ec397e2bddda6f894ecdeeebad3a7da493fb13b3ceffe7013
VirtualSize 0x124
VirtualAddress 0x1a6000
SizeOfRawData 0x200
PointerToRawData 0x1a4800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 3.72964

.rdata

MD5 c84e1d7380fbd76c308f3bc966574f78
SHA1 4114b138d3fd57d957ee97f1de867a0d6dc1e59c
SHA256 c3f6cddcffff3ec2f249f4991e20004efe0543383990cf8a91906f26284f9173
SHA3 1f1021946a355494cf29351cc97495949028cf48b4a9675cab73569c7643282e
VirtualSize 0x58006
VirtualAddress 0x1a7000
SizeOfRawData 0x58200
PointerToRawData 0x1a4a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.99763

.data

MD5 47cb7fa622ba17aef801ce35284160de
SHA1 96cd0dd5e19d0ede2cce9601d21e47c98960a4a2
SHA256 bc039c4092949c069b8f965ad50bdeea37f7d0cd5763866b692535cc6aac9e84
SHA3 93f653123cb64214009ea3d2912e9e14b8955f278d9aab4a0253e659fdd682a9
VirtualSize 0x10360
VirtualAddress 0x200000
SizeOfRawData 0xd400
PointerToRawData 0x1fcc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.92995

.rsrc

MD5 a8636b710d844dffae0f6db1465eb7b2
SHA1 460f8675882d4fb95d309b6d62f27593a3ab6dcb
SHA256 0d0d71aa539714b6c66e3f6907f75a8bac1422b44062964215c8a114b49de5ed
SHA3 24c7b22af857332047106793a346b8d0a9eaf56d588217ba59e68d91efdc0719
VirtualSize 0xaf00
VirtualAddress 0x211000
SizeOfRawData 0xb000
PointerToRawData 0x20a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.73067

.reloc

MD5 c0ae8f0ad71b7a58a2cd5d5b04b7d373
SHA1 d5c3f3f4d94d02ce56e96bbba26141a4e7ae19b5
SHA256 963c5e57a9e4afaef11398531dc207d9e92ed9e632878dd5de47cbed4c018fa6
SHA3 5c7dde9e3e42b7c0b970a32a78b989d14f88b27c9bcee702e9ca197738c791dd
VirtualSize 0x105d0
VirtualAddress 0x21c000
SizeOfRawData 0x10600
PointerToRawData 0x215000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.67803

Imports

RPCRT4.dll CStdStubBuffer_IsIIDSupported
IUnknown_QueryInterface_Proxy
CStdStubBuffer_Disconnect
CStdStubBuffer_DebugServerRelease
NdrOleAllocate
CStdStubBuffer_QueryInterface
CStdStubBuffer_CountRefs
IUnknown_Release_Proxy
RpcServerRegisterIf2
RpcServerUseProtseqEpW
CStdStubBuffer_Connect
RpcServerUnregisterIfEx
NdrServerCall2
CStdStubBuffer_AddRef
NdrOleFree
CStdStubBuffer_DebugServerQueryInterface
IUnknown_AddRef_Proxy
CStdStubBuffer_Invoke
NdrCStdStubBuffer_Release
NdrDllGetClassObject
RpcServerUnregisterIf
KERNEL32.dll RaiseException
GetCommandLineW
GetCurrentThread
GetTickCount
GetCurrentThreadId
SetLastError
WideCharToMultiByte
GetCurrentProcessId
WaitForSingleObject
Sleep
LocalFree
GetCurrentProcess
DuplicateHandle
CreateEventW
SetEvent
InitializeCriticalSection
OpenProcess
CloseHandle
InitializeCriticalSectionEx
GetModuleFileNameW
LoadLibraryExW
lstrcmpiW
GetModuleHandleW
GetProcAddress
DecodePointer
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
MultiByteToWideChar
GetLastError
FindResourceW
LoadResource
QueryDosDeviceW
SizeofResource
GetProcessHeap
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
HeapDestroy
GetVolumePathNamesForVolumeNameW
GetDriveTypeW
GetFileTime
LocalAlloc
FreeLibrary
CreateThread
GetVolumeInformationW
GetVolumePathNameW
WriteConsoleW
SetStdHandle
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetOEMCP
GetACP
IsValidCodePage
ReadConsoleW
GetFileSizeEx
SetFilePointerEx
GetConsoleMode
GetConsoleOutputCP
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetFileType
GetStdHandle
CreateFileMappingW
MapViewOfFile
OpenFileMappingW
UnmapViewOfFile
LockResource
FindResourceExW
GetLocalTime
WaitForMultipleObjects
GetCurrentDirectoryW
GetFullPathNameW
FindFirstFileW
FindNextFileW
FindClose
DeleteFileW
FileTimeToLocalFileTime
GetModuleHandleExW
GetUserDefaultUILanguage
SetErrorMode
CreateFileA
LoadLibraryA
DeleteFileA
AddVectoredExceptionHandler
ExitProcess
IsBadReadPtr
SetUnhandledExceptionFilter
GetDiskFreeSpaceExW
ResetEvent
CreateFileW
DeviceIoControl
ReadFile
WriteFile
SetFilePointer
GetFileInformationByHandle
FileTimeToSystemTime
GetFileSize
SystemTimeToFileTime
GetTimeFormatW
GetDateFormatW
GetTimeZoneInformation
VerSetConditionMask
VerifyVersionInfoW
GetNativeSystemInfo
FormatMessageW
MoveFileW
GetSystemTime
AreFileApisANSI
TryEnterCriticalSection
HeapCreate
GetDiskFreeSpaceW
OutputDebugStringA
LockFile
GetFullPathNameA
SetEndOfFile
UnlockFileEx
GetTempPathW
CreateMutexW
GetFileAttributesW
HeapValidate
GetTempPathA
GetDiskFreeSpaceA
GetFileAttributesA
GetFileAttributesExW
OutputDebugStringW
FlushViewOfFile
WaitForSingleObjectEx
GetSystemInfo
LoadLibraryW
HeapCompact
UnlockFile
LockFileEx
GetSystemTimeAsFileTime
FormatMessageA
QueryPerformanceCounter
FlushFileBuffers
TerminateProcess
QueueUserWorkItem
UnhandledExceptionFilter
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
InitializeSListHead
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
GetStringTypeW
QueryPerformanceFrequency
CreateDirectoryW
FindFirstFileExW
SwitchToThread
ReleaseSRWLockShared
AcquireSRWLockShared
GetLocaleInfoEx
EncodePointer
LCMapStringEx
CompareStringEx
GetCPInfo
RtlUnwind
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetConsoleCtrlHandler
ExitThread
FreeLibraryAndExitThread
USER32.dll GetDesktopWindow
CharNextW
PostThreadMessageW
CharUpperW
LoadStringW
GetMessageW
TranslateMessage
DispatchMessageW
ADVAPI32.dll InitializeSecurityDescriptor
RegNotifyChangeKeyValue
FreeSid
AllocateAndInitializeSid
SetEntriesInAclW
GetLengthSid
InitializeAcl
SetSecurityDescriptorSacl
RegDeleteKeyExW
RegEnumValueW
EnumDependentServicesW
CreateServiceW
QueryServiceStatusEx
QueryServiceConfigW
ChangeServiceConfigW
DeleteService
ControlService
CloseServiceHandle
OpenServiceW
OpenSCManagerW
StartServiceCtrlDispatcherW
RegQueryValueExW
DeregisterEventSource
ReportEventW
RegisterEventSourceW
RegisterServiceCtrlHandlerW
SetServiceStatus
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
SetSecurityDescriptorDacl
ole32.dll CoTaskMemAlloc
CoInitializeSecurity
CoRegisterClassObject
CoRegisterPSClsid
CoRevokeClassObject
CoTaskMemRealloc
CoAddRefServerProcess
CoUninitialize
CoInitializeEx
CoResumeClassObjects
StringFromGUID2
CoCreateInstance
CoReleaseServerProcess
CoTaskMemFree
OLEAUT32.dll VariantTimeToSystemTime
VarUdateFromDate
BSTR_UserSize
BSTR_UserFree
BSTR_UserUnmarshal
BSTR_UserMarshal
VarUI4FromStr
UnRegisterTypeLib
SysAllocString
VariantClear
LoadTypeLib
SysStringLen
RegisterTypeLib
SysFreeString
SystemTimeToVariantTime
SHLWAPI.dll PathAddBackslashW
PathAppendW
PathFileExistsW
PathRemoveBackslashW
VERSION.dll VerQueryValueW
GetFileVersionInfoExW
GetFileVersionInfoSizeExW
USERENV.dll GetProfilesDirectoryW
SHELL32.dll SHCreateDirectoryExW
SHGetFolderPathW
SHGetSpecialFolderPathW
NETAPI32.dll NetShareGetInfo
NetApiBufferFree
Netbios
MPR.dll WNetGetUniversalNameW
ncrypt.dll BCryptOpenAlgorithmProvider
BCryptDestroyHash
BCryptHashData
BCryptGetProperty
BCryptFinishHash
BCryptCloseAlgorithmProvider
BCryptCreateHash
IPHLPAPI.DLL GetAdaptersInfo
WS2_32.dll WSACleanup
FreeAddrInfoW
GetNameInfoW
ntohl
WSAStartup
InetNtopW
GetAddrInfoW
htonl

Delayed Imports

201

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x355
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28105
MD5 4c9050e68c6a444116d7dd97a638c0f3
SHA1 9bfc42eaca2f70df9d1ff9b80ab619be808b15ca
SHA256 fe56970fc8959cf77c923beb0be1cd8e7a8aefdd983d547bdcb3b2713e8b9e45
SHA3 d5fdcb5d5ec847b835ef3bccf17ede53b2a1a2a00d69fcd33ecd9fb8405c5bb4

206

Type REGISTRY
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x15f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33268
MD5 65fa37118a4ae6dad0ab22c53a88ad5b
SHA1 bdbd044e5363909e2a2b13869930bfd418dab941
SHA256 358a9c974de512a926ca1e855762d8e61ae9329b8677d02145cf3888effbaad4
SHA3 01e7d42d6226fe933d9c1600c77d696e5cbc1b349d7f657105cc93abe5e1fd41

207

Type REGISTRY
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x15f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.32153
MD5 0957d0e96f8a133645b4413bf19b1bb9
SHA1 2056019ceef5987a2069b6e3b646f683e96b9261
SHA256 d21f22c7e64613024d6ca424bcc0f76f8d4dd6da3f0b1b3f6cbb5dd08207690a
SHA3 690b67aea9bb57e5430f497f981d5b757cba5b56137e6c190e5af406fa3bb9ab

210

Type REGISTRY
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x163
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.31139
MD5 a473be31794affdd1eef46d8c0bac4c8
SHA1 a57cc793e792b2de1d032debd5a0d6c45acdd199
SHA256 1d7d7260e008a79fae609cd30dfac5def19e4445f5f0ffa112abddc26e1d5bbf
SHA3 504289b10eab75c2889a15f352470923a9c50926d0d0c1f39594244f15db8281

104

Type SQL
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x432
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46757
MD5 11235824addf5d5498cb377cd8a7fbdf
SHA1 2e76fae7b547053182b707293db4ec25311c4559
SHA256 297d955a1a1ecfdab5277f5acd8a110679443afeff24ed494a46b1527c285b4b
SHA3 0bfed0bc051fd292e30f91bf46aa3e55ca66d6b235bf8141b94efd3be309dcff

118

Type SQL
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31125
MD5 2301f528273aa977922dbb42c8eaa811
SHA1 15a42a5b380bc0dc44ec58b00d7d7645bffa4471
SHA256 e5ada27f022d9fee3cb13df6960d3070362ab6e683fe22e1c9aa36c092956ee7
SHA3 39b0d8d968ce26f443ddd6ccfaee7064f620c89933c5bd00f0107cf8020de8c7

134

Type SQL
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x35c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46878
MD5 9d322ac9cb4763d16ea71255b055533d
SHA1 88fc677c4ccd6a9841a843ae706c0287f946fabe
SHA256 c2ba6fac9d8977959ce608ee8762c42c35c3a9a6a9584ee8775a18e82b8c5960
SHA3 7916e41160452c1d1b92122cad53de62fd7855ac9b618b989aac151309157214

165

Type SQL
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xe2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.427
MD5 eff4ebf1bd772bb4606e87c3abb96da0
SHA1 33d61845cbb87681a38b434fc1b0c2a790b7adb0
SHA256 ac52333a27b2d2ea686e00a784659ddad5ecd715b9cc63821dc4341189bea5e1
SHA3 c8619cb7f820fea6781a40ea934a194d3c244b99caae27f58a947cfee5a7dfb7

212

Type SQL
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x72
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39444
MD5 9b68d20dd796ee856a31b0e2f6d6a96e
SHA1 980f56942e146ed52e71bcb0edc8ec977705cce7
SHA256 8193b6248ce917a9ca26e01531b4ddc57be084f6d7a219c18c4e904c5d8c467a
SHA3 a2015cd44b6175163932854c2b0a4ee7e89868db65c763377755b7e7dce8d208

1

Type TYPELIB
Language English - United States
Codepage UNKNOWN
Size 0x1e80
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.30936
MD5 a4b96c469d689983de140a54cecab2da
SHA1 a9e2ed2109cd513548d8dcee1f5bdc025c4f604a
SHA256 e50719ea16bc4ccebdaaf59f1bc7ecfe39f327319e702972317de0b69525e7cc
SHA3 9eb0e1924eae482ba8b835f9f485365dc2a9011d93e1852b64e37b1aeb9a2cdb

4

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02695
MD5 cab67e9ca149fb79ab4473998412b951
SHA1 2e793d35537bfb5d3f042ed0626d3b119d50519a
SHA256 fbeb3be87e80cb8e1d2af3d8140796c1bb80c6c7056f60897088ff9e355c3867
SHA3 0e72f5537421764effb2ed98e536358bb7e86eed7b0936e606e8d45559685684

5

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74274
MD5 9fa8a914823ac7e5370652146901f4f1
SHA1 eb3224109abb341b6e464d2606fdbed1a7160bc6
SHA256 f64ccc0582bc7c66af8b40049e485e8e241335261ec95ace909293ba50b2e4a3
SHA3 bb348af06514e27cd1fa21ad524dfd037edcd3b36ef4cc6ab24c4a8ec38995ff

6

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34038
MD5 d78a341fa7444ba9ccb74ad0c943d0ac
SHA1 a3fdcb001587c47b72f06441087455e8027baca1
SHA256 652988945185cf5d604d9b48de66288d82d8ed0acdd134398e90d002d2d9fc72
SHA3 2ddf8193c735adcec9a83d3a9032dc70796778b1d0c967a43789f1a6bb3da15f

7

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34004
MD5 07618c451f53db89991c3fb7c567a568
SHA1 0d5cd2bb85bb88024b832f68bdbadd1e69938138
SHA256 0b0e16c38a3d5a85566e67b1d9a7e720e4dee27e163b06099d3d7dfa5dbed9ee
SHA3 f4d98de638008ce348a7ef0cb3feb13207cf5b3eaea4f1ee1d71b3a22397fba4

8

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.51649
MD5 9936fbf67a1d9f755c37852015d09527
SHA1 426016ba6a10cc2634ab7357e4223793c51aa304
SHA256 368f9cb089d206a8b61251f0c85eeda97ee08a56b33be8579246e964d3af6169
SHA3 6bdb1e7d667efe7812e162384a6341edec73311ee7dfcb122adf0cc0f08e7a8f

9

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45401
MD5 ffacff1dbee315221fd131e951d8e151
SHA1 d2eb9800a1f60d3ea7225fec706d809cf477885b
SHA256 6440c3a38dcfb81d45bc6be31b776fdae116dd7a2933b407b67132f6cfa0e6eb
SHA3 dbe125dd582d83c13a62c87798c900fdc43d97b581935e320c14f9cc761a3868

10

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34864
MD5 fa681900dd51c997aa67a2c5a4704099
SHA1 b48ebfd25835cb260b5e4f8e7085ea3da102c48a
SHA256 9882a8462ce9de3cc9a5d0ca48c8c4f7ca97f1f846f0c10e6655e33c9734b152
SHA3 157fb750ffc808227ced340c81ed1c1c1e15b05dd0e831678b871515870e0a8b

11

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34505
MD5 0a12283479aa8a8677dd27bb0f584a34
SHA1 63679153c4d14fc591d1286cc98ff5044a5b589d
SHA256 322e92d75b3fec9e16b81466f4cf111d298b80812d5b238f4ee032c025a02050
SHA3 d6fc5e08b9d51b2cc80c1a2a34ca495e28edd0ca1bc65f317958b773c675de7e

12

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34864
MD5 d0293b6f84ea96f2662fa2f8e2fd44de
SHA1 240ad776d40208f067dda60701affa3d162cb3bb
SHA256 8db6df648274a0fc3d28430367216e1c17c364ca613066cbb0e133637e92ba62
SHA3 d92c1c2bfba803073152e14d6846474d13ccef3f04aa8670540389efa7c7d995

13

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.31114
MD5 49ca9d25ceb458297ddf84fff64c8d55
SHA1 fbd6d992b7e2a59c9e24372ea8d30a5dcdbd46f9
SHA256 f9c81ce9b4176b305c554a15f0ca2b98b11be76c1f13ef22169999aa07e9612f
SHA3 03f7002b636940864ef7d399ba60fb8de3f455da32f311ee39cdf6602c5d348b

14

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33609
MD5 27fc5529ad790189bbf410c7e3a70fb7
SHA1 ea2456c9b26f884a7f7abb051f460ec98cb9451c
SHA256 601635482a9b1864ea0c61ce0282c5c9fe1d014aa95dbb4f60770f1c2b6df3da
SHA3 24ab306744896452b2a7f7055c97671ab0aad3965342b3d0cead7a6cb640238d

15

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81313
MD5 858a63dc597812b0885e8a8f9689227c
SHA1 0a816cd0e6f10038f43bde278eb613f1c7281b33
SHA256 2bf742d2beb4c56dd6eb68347dd8ee28da85bed9e6d165b36c6edb91da01d5d6
SHA3 6974d714fd124f0de87b6f088039e52bcf3123b5e6ae24c7c61864b70b894963

16

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81491
MD5 ff43eaab521694d0356618a92cd83b55
SHA1 f1ed8d456a5a3d87d1a8349e992c99e22bf3624e
SHA256 cfc4ff9e46fbb61f61b68f36adc6593b137233d1cbaa50fe37e5653f0cb20396
SHA3 7069692bfbe0c043b33390a40f8033c3d0aa3092c3b1ca1b01fc899dc760ec48

17

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10016
MD5 4bfaa5ad112338fc90bf84b1ba21859d
SHA1 f175fb276720b4f98bc75dd3edc8c53ed563bdf4
SHA256 c4a6e3a7a346baecb09a0c49268eb44f388382a7866a4e912b53d48fa3b34c26
SHA3 eb1f5efadebebc4b756ef49661343ee08641f53184ad8ee83e33d6665028a00d

18

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.97052
MD5 654a61b5fd300aaf86c52a3c48035005
SHA1 e16bdc1b4309abd682e2d0b52aaf370a77ad6a86
SHA256 f273e554605a89aa0994c9d42bc2569be3db5b19b2900dacb30f3218ed1174a0
SHA3 50582dc2bd6d1a2632564b2d3c6fdc1877e401924754069bc2dfccf3e2896340

19

Type RT_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.22699
MD5 b6946159ef4680b2b03d58bdf3dc83f6
SHA1 b949690a6e071a1fe43cb83a15d5104d1fa9fe0d
SHA256 ebaf4bcc0f0d7ca9a3458ea52520d2dd10811069241940b9b2e79ac1a4c3ca5c
SHA3 4b1152fe0fd4581cc8716682bff8f14d7c903ab6b5414d52876bd37fc58eb0c5

30994

Type RT_BITMAP
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.23666
MD5 8cf65be17e506ff24c2177078f88b56e
SHA1 3e397dc7597caeb844df0ea760b64231c8ce3dbf
SHA256 e7c0005285d1ab59732d5f99f77a9bdd6342b01cf44437ebd7a07611a227e272
SHA3 7da4c7aab356574679f0f9107740f01647864c846c04f699deef67577fd6aded
Preview

30996

Type RT_BITMAP
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87621
MD5 5a9c81cdbf480cf01daa71ba0e233c5f
SHA1 28e04c01584654e1974347d1baa462b2784e9c47
SHA256 abdf36bde89a26349f5741c17c235dacea88d441d8662ba16a598dc50c3c4864
SHA3 99dec83590ac444359a5a6f8924dae5615d93f4df527e10a8a61319ce3a5beaf
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.93821
MD5 21b993f0c965d20cc8fa75137ca13bff
SHA1 f92431288b7b5819af7ae8c8a6bbd7877711bda7
SHA256 400016dbe3cdeb69ca8bfffc333d9a5f40bd99d65467cc9d60000ad5d76d8eb9
SHA3 c6d631e5bc6086ef309e98cf8d02de7cf83c6316a8fceee671b29a402e497647

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.12345
MD5 df11c3ae7f2fc0242172ffb5357adf0e
SHA1 e59029985abdd826b0e127bd0938d7844aa40fc1
SHA256 e4d42b3c7885b0605b53d5bff8dc4fd2e0657f38a3ab0b84f16e6a59bcdeaaa1
SHA3 786f20d16a4726522fdef875844467a79a2730b017c00ce349bc5ee11fd7ec58

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45057
MD5 4027a6a5afaa51b68860cef53aa0353d
SHA1 4b2b9ce0f81ab4b23cfb3d4463841c0c1c32c4e3
SHA256 921146a8cb097a2acced8f94d49f1f48ea62eec59219187c3a98a2ffe24ea3ee
SHA3 c3ab42c3ebb6961073e868204b5c7bebf554876d8f1b65f932c7c9264da292e0

30721

Type RT_DIALOG
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06676
MD5 ad7b15160c8bf80910606d417f40fef5
SHA1 9752acb8e012635c4356f7f2a20191d656b53faf
SHA256 6e113fd8e9f3156ae68251c6076beb9b59fe29e589d06398e7019802521f69d3
SHA3 50c74f1eeba91cb4ecc237c0b18cd2f6c0e2b6064e8d13ce1a779160c03b5d48

30734

Type RT_DIALOG
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x34
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.41669
MD5 72723d63b211c60717138184c1675b66
SHA1 ecd2be6587bb32a080e51b5c3f3a816e8b637c85
SHA256 4cf716efaf68e0cb2ec45ec55d291050b5712b05653cae68edbb999f803d2a98
SHA3 6031fa1100e39d04c89ed42890fe9833adb0503fe1857940533b7356aec9d306

13 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x3c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.64209
MD5 51e39e4fea602b328964a4d5512f058e
SHA1 cfb7e82da1d73204708cc38ee64b6313f36eeb98
SHA256 5634850e18f48ad8f62311e079766c26aa43871fda3fc30d189e8550c45a90b4
SHA3 5194c9c286751179e4d8f1fb6fa7fa54f77bbe94e7fdcec9b320fed8554eded4

3841

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x82
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81705
MD5 8bb814f43734537868736a6df5dcc012
SHA1 3ae7a8f8678bc2aed76f745960730097032389b6
SHA256 d91dc4e26fd86def5ee907c72f32457bea07d21fa618012245f641d08501548d
SHA3 73fabbc3aad03738eda288b6d45b076e7f94f1ff8de37df5ac4d6e7dc7a48f98

3842

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.960953
MD5 0131ce1c2237957b6926d5097b0af63d
SHA1 2ce37b98065cc4de92e99eb0777e0e1159102068
SHA256 05e0d5787611ed4f643733e3e6e62d00f426422b5d3e443ceebac22e9d294bc4
SHA3 9ee7bcb02f48332a4fac72465297312ef9c765b03edf2ab24a4b3de0840bda6c

3843

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x184
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08634
MD5 58655591099de216feb4cc512012d318
SHA1 4001db00e1535b26b506e6d033e9759351ae6874
SHA256 9665348f07508c6c2a568fc90ec4c04736668adc3521e311a4c7659973d92313
SHA3 296c00546a67204c06806ff85a9e3e065559b2b85b22fec4166afc19cad4b6f9

3857

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x4ee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27024
MD5 8bb8d06e4cc7bf37b4af2a26f3a1d813
SHA1 a17d97834a5141a7094de1d27224e2b14b94b498
SHA256 fcb87f4b1b4178dae839137498027a0cfdf4247d1b49e741b5015313a2cd6a2d
SHA3 1d35bf4d5121f58b146895c17013001a95be7563b0a5f0267afa8c442c8bb300

3858

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x264
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11275
MD5 3dbecd982474b9072ecd4aefe7406857
SHA1 ee81b0d03aebe1cde90de59031771f416d29eef2
SHA256 eaa0b4fe4704e193dd2ed1f8de1cb20e1001034fdb30307ee44aa664966d4ffc
SHA3 9053da012393a18a8a9012e2ab17735c7c864f0463086c9439c3a74a37ed7ee7

3859

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x2da
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16694
MD5 9e3221160c33e15054ff236daf2263d7
SHA1 cf41e0cdd3377698f819c4ef95ab56de40c57a5a
SHA256 cffcd4956911b3d50eef378cb051e598baba0db48246b07780af03b01c67c64d
SHA3 663e17de8922b049f83fdeca37a68d626bb83566bc377d85be42c653707a2b74

3860

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x8a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71087
MD5 5988b72b85cd1c121906b20e7526fdf2
SHA1 45efa4995e9c25a32e3f47a15b63a813cc6e8fc4
SHA256 35b5abb90316b4017d5531e031cbf15bae6e8dd46f6dd221701693a22a7795be
SHA3 afa115b83c9f9b2f16ce1e14424b4e2cf6216cbcee84835e0b5cec4a23510a93

3865

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63903
MD5 5fbbd2a5f564e043553889eec9147920
SHA1 2ddafabdf2bf5b62090419f07f731c4d02f0d987
SHA256 1b8660b0c53b94f3e029de58e56d08c8097a080244e9dc65d4155a9b603820d8
SHA3 1a90cf149f1fc5cfa9cd3f82f9a079ec48c7f7ce76dc4be601e538ae5c052ab9

3866

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87807
MD5 a0838b75a6ffc345212d18178663bb7d
SHA1 a90a0eccdf4cc4c50f430195695a3b65adefe5e8
SHA256 31bff9afbf08a8869318cd946a1d73a4425afefc5693c6e06671bde1e86de1dc
SHA3 ad576d2bedb8e173fb207310f244bee3ad8c898a2101cb67da930fadf80ec7d0

3867

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x4a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24671
MD5 7e0e2d984d6d743b4d90b04758507505
SHA1 bec6af6197b875caf3064c7e053b64044904c1bb
SHA256 2b5551644093e58a4af74928fb744bd735fa2ef5f99824e6918ff9f6a33a3803
SHA3 08f040ebd50cc1809f91378999331d0d19e7364612041db3805a0ff1d37050e5

3868

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10695
MD5 cd11e247927c7360d3447bbb2e01d326
SHA1 0e6b76a1cf9824dac91fad3a346388589987cb9a
SHA256 e9212b16f2d3292d0b0eb67134a70778ff1b0aede4918831e5bdba3f950db2a7
SHA3 7a0a3e741ea89b752fca14451f1e9b9ac5600d99a7408d04c7835e30688f8fcf

3869

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.07875
MD5 4b18eed800e2806db8e0aacb95fd54f2
SHA1 8b09634f818d6823f6466717f3863cbb466d97c1
SHA256 0714c554acd308b38c3d6319f7e470f76a16d712f696545eacac2bdc725dfb95
SHA3 067dea0fda55e331beab407da1e0e79a9d71fe8a8d0c965384d459ce0a8d499a

3887

Type RT_STRING
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x53e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18003
MD5 c260fc0560cc8c7d1a979db82f172142
SHA1 0cf7de555da00d9160b2311a25c459da7de598f9
SHA256 a5e23c6071b4faf115605493d1fd2e238c1d915b412f869aa6a7a77726f56082
SHA3 b5f76ff984cfc414e534d6bcd71dce53168b5371571326279bbae2c616c0abfe

30977

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.25451
Detected Filetype Cursor file
MD5 9244000dcf389837295888fefab8dce1
SHA1 e46c5acc929847e1e35a047fb6a8e58113b7a67c
SHA256 f9cb2c13ebaaa826fc9e85033fffe3259f22f28d9cff2d53f9086d2f3bfafaed
SHA3 d81bc09070362bbc36790e17a1e37ad835c048f46dc284a9012423edae50f3ab
Preview

30998

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 5df05404b0dab444d7bc0fe0bee0d519
SHA1 ecbc2591eaf234bcc87df4731b5e26266728ff6d
SHA256 28b8110695851e5280ff55cb78507b03e8b74dd370b8e122179c82b56f7e5f37
SHA3 f18323f0f4e67af79d43a527df26273c9f7e53e73b1ba51cd426cff3412927d2
Preview

30999

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

31000

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 e6a3323fcb21bc5b90ee077f41a24061
SHA1 91e468b891f8306afeb6ac33bc31d67efb2cbe9d
SHA256 a92f60b25322592e7ddd13d88e4006c097666f4d87c8cb0c21ffdccd53b31d78
SHA3 ffc4266780334ccca3790e5f703fab0a138d252e16d1ad1145c1929f51d31d38
Preview

31001

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 ebb32ed08b06ab16f79c997b7963c57c
SHA1 c87e290caff3cf222d5ec678a51927ff22637949
SHA256 9c17b4621412d6ded24a76aed74d4425ae61f86b6d4092ca1e28ca66b7c71399
SHA3 fb70f94bf4a64a26f2d83b588fe2a233796083fd03aae7835387aeba2646b847
Preview

31002

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1529a8ec9965ecf3256d6d4550712406
SHA1 9bd0fc7e667f3d49f5098ecc2bff01987f3e1503
SHA256 12a5b9052dd16bed260343bc4352d436167c991c54497c5af441304646549386
SHA3 0799f15ab0007d5497ea80dbae86635472c9d085ffbb6c095b71d1e8acebc81b
Preview

31003

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 b3dbdfe1835416bbc3f5065baca9aca9
SHA1 334d5af1355f6a13c35be4ad16e76baaecf209f1
SHA256 ec26c438d10e3e84ec855c47f07a176e6c11bbfae1557d526490711b80f087fe
SHA3 2409b439f48a139d3764b226eda46c6a629d5bd208991369ae0c85e37c17c71d
Preview

31004

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 22a9b94eda22d068a6823a72268fdada
SHA1 7923c0aa606f67498391ecdb828292fcc3bc3ed6
SHA256 a2f0549cca7170ae03ba042464efe62365fba38c20049e439871c9e5ce0f914f
SHA3 565227501bdf04ce5d2afeb14e48062d4cdd6de7b76c62d26a15f6e4a34ba5c1
Preview

31005

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

31006

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 d1c93cf23f34157f8c97800528b9bb99
SHA1 ab9e40c42ad0de11e11fdde5de49bd0adaa9bc2b
SHA256 8a495f17bc472bfc5e6923d9efa687848fac027ad60694f9c3f10a4f7b194924
SHA3 10b44e07ad4f8d644f73b4d71370ae8c337e8bfdac89efebff20378ad61e0758
Preview

31007

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 446e8ff2a515c84d93ca4cbcf405d300
SHA1 98de0236185240e011430a5dd8e262ed8f991ec2
SHA256 ef309b720f166673cad840a88e7636e9161ad91415cc7c176010cebba07757e5
SHA3 d345fed6ee7f3afa40aba48106f47450bde6ac4c3d47db78cbfb11e4368be613
Preview

31008

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1cd71148c4a650e298e26668e22c3733
SHA1 5aeaabee3ae2ad999e9ed91c85119a42c83473c6
SHA256 4ecc7f2578fd7b137c04f85ffcbd67d6eab0bc8b1df4246cebd2a2aa517f3c60
SHA3 89ccb4ca5392e186b8eeb9848f78a12843e40792c3500e104225869bf9be1894
Preview

31009

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 8e242da1769c2307f276e393dec0e7d9
SHA1 da604259954e8cda5931a679e081bfad9a9fd772
SHA256 ee63d4681e7622067fd29005c6cc67b456031eb723c7239f05f1cb097af0ef98
SHA3 e6021bdef60731a607f9445b3c004fcdac812f44b42aeb8e32fee72204be4572
Preview

31010

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 87f676ebb80763bfd77a413c2fb00f0d
SHA1 23736a18a1d4330cb9ea762fb7deaef881b6ec2c
SHA256 da738753c27f2708bd2257f8cac3385a4ccb0df1341b76acfda07fa980cfb4bd
SHA3 d90e5655540ffc0671429e2c3ff78ba0f7a100727622de4185f897a4aa996c3b
Preview

31011

Type RT_GROUP_CURSOR
Language Czech - Czech Republic
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 8408eef234acfcac8a26e706cc35d85c
SHA1 5ecdc1e1be3f1e941b1ca11b45943aafe135c517
SHA256 3f02dcac38fffe306e1825846e2bc0458ee712696310d051e3a69ebda8330cc3
SHA3 0406ff4480e84661d58a225cdf84931c95f7ebf6fea388a3cb6bedbc0343b421
Preview

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 1ec6a7b3300970378c29695a6cc13d36
SHA1 99ce74251d19d800608e30bed6e0d793931da56e
SHA256 77a1efb6136f52dd2372987b13bf486aa75baeacb93bad009aa3e284c57b8694
SHA3 7a94ba315b3ab461cec9dad3048599d32b0e597047f9655159bd6dfdc694e4a3

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x2bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29058
MD5 f5ed27469bb32b993b238c8bc681c73b
SHA1 575de8574bc9ba64518eeeabdad4eb43ee660e30
SHA256 e2aefd3982608f10d9d891c4bac8c94c1518de4a9c6e986aa1310ae48ff089d0
SHA3 14cd17d9847f2f67d4de5ab535e7b992aec3187848077e3caaf42fd4ecfd6f6b

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

String Table contents

STEventService
Open
Save As
All Files (*.*)
Untitled
an unnamed file
&Hide
No error message is available.
Attempted an unsupported operation.
A required resource was unavailable.
Out of memory.
An unknown error has occurred.
Encountered an improper argument.
Incorrect filename.
Failed to open document.
Failed to save document.
Save changes to %1?
Failed to create empty document.
The file is too large to open.
Could not start print job.
Failed to launch help.
Internal application error.
Command failed.
Insufficient memory to perform operation.
System registry entries have been removed and the INI file (if any) was deleted.
Not all of the system registry entries (or INI file) were removed.
This program requires the file %Ts, which was not found on this system.
This program is linked to the missing export %Ts in the file %Ts. This machine may have an incompatible version of %Ts.
Enter an integer.
Enter a number.
Enter an integer between %1 and %2.
Enter a number between %1 and %2.
Enter no more than %1 characters.
Select a button.
Enter an integer between 0 and 255.
Enter a positive integer.
Enter a date and/or time.
Enter a currency.
Enter a GUID.
Enter a time.
Enter a date.
Unexpected file format.
%1
Cannot find this file.
Verify that the correct path and file name are given.
Destination disk drive is full.
Unable to read from %1, it is opened by someone else.
Unable to write to %1, it is read-only or opened by someone else.
Encountered an unexpected error while reading %1.
Encountered an unexpected error while writing %1.
%1: %2
Continue running script?
Dispatch exception: %1
Unable to read write-only property.
Unable to write read-only property.
Unable to load mail system support.
Mail system DLL is invalid.
Send Mail failed to send message.
No error occurred.
An unknown error occurred while accessing %1.
%1 was not found.
%1 contains an incorrect path.
Could not open %1 because there are too many open files.
Access to %1 was denied.
An incorrect file handle was associated with %1.
Could not remove %1 because it is the current directory.
Could not create %1 because the directory is full.
Seek failed on %1
Encountered a hardware I/O error while accessing %1.
Encountered a sharing violation while accessing %1.
Encountered a locking violation while accessing %1.
Disk full while accessing %1.
Attempted to access %1 past its end.
No error occurred.
An unknown error occurred while accessing %1.
Attempted to write to the reading %1.
Attempted to access %1 past its end.
Attempted to read from the writing %1.
%1 has a bad format.
%1 contained an unexpected object.
%1 contains an incorrect schema.
pixels
Uncheck
Check
Mixed
One or more auto-saved documents were found.
These are more recently saved than the currently open documents and contain changes that were made before the application closed.
Do you want to recover these auto-saved documents?
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.
Recover the auto-saved documents
Open the auto-saved versions instead of the explicitly saved versions
Don't recover the auto-saved documents
Use the last explicitly saved versions of the documents
%Ts [Recovered]

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 11.4.6.0
ProductVersion 11.4.6.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription Event Service
FileVersion (#2) 11,4,6,0
InternalName Event Service
OriginalFilename STEventService.exe
ProductName Event Service
ProductVersion (#2) 11.4.6
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-May-16 00:20:28
Version 0.0
SizeofData 92
AddressOfRawData 0x1f1f34
PointerToRawData 0x1ef934
Referenced File D:\JiRoAgent-1\2\s\Shared\Compiled\Win32\Release\STEventService.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-May-16 00:20:28
Version 0.0
SizeofData 20
AddressOfRawData 0x1f1f90
PointerToRawData 0x1ef990

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-May-16 00:20:28
Version 0.0
SizeofData 1028
AddressOfRawData 0x1f1fa4
PointerToRawData 0x1ef9a4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2024-May-16 00:20:28
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x5f23b8
EndAddressOfRawData 0x5f23c0
AddressOfIndex 0x610348
AddressOfCallbacks 0x5a75f8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x60000c
SEHandlerTable 0x5f14e0
SEHandlerCount 597

RICH Header

XOR Key 0xadab6cb3
Unmarked objects 0
ASM objects (29395) 13
C++ objects (29395) 193
C++ objects (VS 2015-2022 runtime 32533) 108
C objects (VS 2015-2022 runtime 32533) 19
ASM objects (VS 2015-2022 runtime 32533) 25
C objects (29395) 28
C objects (CVTCIL) (29395) 1
Imports (29395) 33
Total imports 448
C objects (LTCG) (32826) 64
Resource objects (32826) 1
151 1
Linker (32826) 1

Errors

<-- -->