b10666bcf5b383e97382a22801ed46bb

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages English - United States
Russian - Russia
CompanyName
FileDescription Setup
FileVersion 1.0.0.0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion 1.0.0.0
Comments This installation was built with Actual Installer: http://www.actualinstaller.com

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • actualinstaller.com
  • google.com
  • http://www.actualinstaller.com
  • http://www.google.com
  • www.actualinstaller.com
  • www.google.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
  • RegSetValueExA
  • RegQueryInfoKeyA
  • RegFlushKey
  • RegEnumKeyExA
  • RegDeleteValueA
  • RegDeleteKeyA
  • RegCreateKeyExA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Has Internet access capabilities:
  • InternetOpenUrlA
  • InternetOpenA
  • InternetCloseHandle
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDCEx
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Battleping
Issuer: Sectigo RSA Code Signing CA
Malicious VirusTotal score: 10/70 (Scanned on 2020-11-24 23:24:17) McAfee: Artemis!B10666BCF5B3
Zillya: Adware.ConvertAD.Win32.24377
Sangfor: Malware
K7AntiVirus: Riskware ( 0040eff71 )
K7GW: Riskware ( 0040eff71 )
Cyren: W32/MSIL_Kryptik.AHX.gen!Eldorado
DrWeb: Trojan.DownLoader26.22635
McAfee-GW-Edition: Artemis
VBA32: TrojanDropper.Agent
Ikarus: Trojan-Spy.MSIL.AgentTesla

Hashes

MD5 b10666bcf5b383e97382a22801ed46bb
SHA1 16d7c33f1ff9fc56df261d421f0fe9ad42faad35
SHA256 964961d5851602eea127c9faf33f16f4e377c5d8e24ac64fd5456abaf2a6599a
SHA3 f2dc3ccd28647c466a68291208abebcc872e2c9109b90cebffa121c3bc282337
SSDeep 98304:yB/anNsM+OV5ZBD2oCpvWzU210vtKqnycdGjgE5RKiWQyxKV11V1SM7Cydw/x3:SdM++/Kv8ivtPycdPE50iWBKV11V1SMK
Imports Hash 1fa81de70b75cc3e70b66a1c607b3b53

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x88c00
SizeOfInitializedData 0x22600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00089B7C (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x8a000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xb1000
SizeOfHeaders 0x400
Checksum 0x599ae9
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 9febbdf56b87cf56fa32359e62847b11
SHA1 165e5d476e2a346dfda72b87f816e316cf574560
SHA256 9a0953dea35b300eedf5bca88c486a9366ed5e8334e659e5abf1b92c3210632e
SHA3 e5a7e61d7e3195a997c08f1feb4be8c7c51316ab51143e4a1a52fb0fb9188a39
VirtualSize 0x88be4
VirtualAddress 0x1000
SizeOfRawData 0x88c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.5101

DATA

MD5 c71f0ef97e7671a40d16a34911ce1b94
SHA1 e1321776c87a9905576b583a1058a763dc30477e
SHA256 0953aa2d8bce1a433fd9410cf6db3953a8f88dd12d26b485e9b9e1970f967605
SHA3 0cf4b3d54b6f5806b3ad0b996c38fdd6b638a38d667b1791be7b3861ef455aa2
VirtualSize 0x1e24
VirtualAddress 0x8a000
SizeOfRawData 0x2000
PointerToRawData 0x89000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.12616

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xd25
VirtualAddress 0x8c000
SizeOfRawData 0
PointerToRawData 0x8b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 7bf3f7fdeb2e26dc01af7b615d408d0a
SHA1 be26b32e7d70f2d37c9862a7e42ba7a192946a05
SHA256 4a45d75cabba8921ec6790405f32d97f4703ceebec3c05637c8c28664f3d2ed5
SHA3 9361b6c3ba00c453941d476eba448e506dc9fd0e4e78e829657df1eb565184c4
VirtualSize 0x2ac8
VirtualAddress 0x8d000
SizeOfRawData 0x2c00
PointerToRawData 0x8b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.97152

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10
VirtualAddress 0x90000
SizeOfRawData 0
PointerToRawData 0x8dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3526610601542676f3b5dc98fe2e8564
SHA1 ffbe703f3c0714bc40ab6f10f2171be97518a027
SHA256 f9fa887aa3ad2dec82eb6d3088bcbaa7617ea93f61bcea162df0a4b37971d02f
SHA3 9fab1ae592b731937ffb9d550d0dee6c75e1fb8fad25d1a16abde56be0f09fcb
VirtualSize 0x18
VirtualAddress 0x91000
SizeOfRawData 0x200
PointerToRawData 0x8dc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.164765

.reloc

MD5 024ad1e514669df0442b956b46c79094
SHA1 3ba21c5debcbefd07f1cf5712f37eeb726b557e8
SHA256 c283c4f547ca40ae2af8f12dceaf53b9b1e47cd9c28d7771a9c2502280648225
SHA3 0243b77859de7c95b6436751098ea67d756f60f596d92df54c552535a1ccc179
VirtualSize 0xa3fc
VirtualAddress 0x92000
SizeOfRawData 0xa400
PointerToRawData 0x8de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.70283

.rsrc

MD5 3673d389c2e7cac7428e2a0d99409733
SHA1 615b5bb8661fe1a5724f3b04e378f62e2f1dc5a0
SHA256 6295f3d94f4a86ecfb18493e93404e0b3cd75d71300f70192ca9330148da780b
SHA3 d24ac948dbcef8146d08505cd4b3fc94e15cd0433effa5ade84100080fdb9f9b
VirtualSize 0x132a0
VirtualAddress 0x9d000
SizeOfRawData 0x13400
PointerToRawData 0x98200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 5.3294

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
RemoveDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
RemoveDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#3) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
RemoveDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
version.dll VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
gdi32.dll UnrealizeObject
StretchBlt
StartPage
StartDocA
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetMapMode
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SetAbortProc
SelectPalette
SelectObject
SelectClipRgn
SaveDC
RoundRect
RestoreDC
RemoveFontResourceA
Rectangle
RectVisible
RealizePalette
Polyline
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPointA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExtTextOutA
ExcludeClipRect
EndPage
EndDoc
Ellipse
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateICA
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateDCA
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
AddFontResourceA
user32.dll (#2) GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
kernel32.dll (#4) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
RemoveDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
CreateDirectoryA
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoCreateInstance
CoUninitialize
CoInitialize
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
winspool.drv OpenPrinterA
EnumPrintersA
DocumentPropertiesA
ClosePrinter
shell32.dll ShellExecuteExA
ShellExecuteA
wininet.dll InternetOpenUrlA
InternetOpenA
InternetCloseHandle
shell32.dll (#2) ShellExecuteExA
ShellExecuteA
comdlg32.dll GetOpenFileNameA

Delayed Imports

1

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

1 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.02498
MD5 50ec2bf71b8ec3f66355adb739d2e600
SHA1 b477797da37cadad824d82390d29d48490ae8938
SHA256 be1e2a93566f43ed274ce459fa760c5f591e55d7d7843b7c3834734774117c09
SHA3 a384acd705e6d90b6861b3d53742661abedb5b5f1ed31331c8d6e5cbd5748237

2 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.27095
MD5 e717a28c8692de8e4b5bc8fe9f59a5e4
SHA1 b97b4283f221f4d13839634aa2bd23e8db768537
SHA256 d6c8413871f428d2f8285342bda6f5040a92bbdb3be96fa54c3001763f0c83b9
SHA3 0ecee1b0e9be56b47a115db84b9d8cc0f2deda1ded33fc86cacac71ed8293979

3 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91152
MD5 6e102528c88610c19c51833198a46daa
SHA1 3caf61eb3173462c2aa4566e3dcf70ad3c0008ae
SHA256 d04ffeb2277486fe2a509bc70a29e86aa228862e2116b0158e64e67bb8202887
SHA3 fc1acdf93e8ef3fd38394c565705d28780fdc43fd0770c970665b76342ac36fb

4 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.63207
MD5 00c1150f56235f57f12e2e2c759d6a0d
SHA1 6847e9964332bdecb6ee5a111f59bd6fc83a3d64
SHA256 ee2aeec27bd1ecf5a73089b873ed8a4272c395e0ae1a21f6c91e97a24bf6e1f1
SHA3 4b071d487dd2a78ed08e8f5daf675cfccace27c5e7c7b341b9a55fe66b718747

5 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.8896
MD5 7d7de28a6f9a02d21176f2318fb5fb4c
SHA1 b605711c3ad36d60cb0f2f9a57d2b57fbf637587
SHA256 21f7a70f9f58a8fb4668b3351765b610b02ad579006b194f145e52b1a42291ca
SHA3 de071fc689dce577d5efbd144d10a8a27129d4f888ce8ec5f764330bc02a8c3c

6 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.03907
MD5 4ded2d37210ad9c25fd590900e93a791
SHA1 04322f0cfad7ef2bda62990fcec7388ed9736f43
SHA256 49bc3d9a27857d590a638b2b2059046f045b656cbf4164ebdec1e54504a4a557
SHA3 f1e4cbefdfc7365a41f6b45fba45797bc7e979e2d809a37ded5a6723267dd80a

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x52
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

4077

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78503
MD5 e4543cfb07f2228067c97bd88f6eed62
SHA1 0f2d76587031771aa655130f88e404e37d0d59e3
SHA256 e308b7d4640dcb6e102fd2cb414bf93e7cebcc3dd33c4b6256df1ecfba35336f
SHA3 fdd981ec35fe6527667a22ba1e564b80f77caec057cc8515094140aef1ff7098

4078

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16895
MD5 17262851f09d5425e24963d245cd4504
SHA1 bec02cea3d9384e4ea57f13f1308c8e00bcff9a4
SHA256 32694f373b3428879bffaecf3735dc2472363330c92b9373a5228b8407f4f5c5
SHA3 06f765ef75a00ba3c898c091b6382d307ecd94d5211f129800f9bda06dd272d8

4079

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x390
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26295
MD5 93e402f5c0b416358a6a62c7228b58d1
SHA1 51ff71e109b7bd663bf990a22e87576e9d862f1e
SHA256 b2f77adb96481b09d4b4dd3bc0a815d3a58dfbe9bc7d63dd9c05f24c60dc1e0d
SHA3 941763887badf10bbd52b18485362b849259b74e41d3f408eba66c4b5c684eed

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2512
MD5 b50f4a515ca066ecf1ae1482bbc18e3c
SHA1 7bcd39fb50225c39ad1392b08a1f82531f212528
SHA256 0786f3de2979888999d726c9e0e721fb46744d5937ad5007dda66d0897a18a4a
SHA3 8c185141b446a09f627b88cb594a96e6e7a783dcebd5f38f239e075827f775bc

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x180
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25214
MD5 5ce19ed726183729b7403215bf1540ad
SHA1 51a249aebab06f77a6bb99508cc33b5b84758d14
SHA256 c4caac67e1880b936a1d526bff96830a06b3eef3b804f3d633dac0976a551493
SHA3 831954a74adc8cdc99d5b14395ad8f9a240777b2d4a0b14f1ff5129d13090223

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23057
MD5 0bf08b81929be93f4c7f1d1c8c6a6423
SHA1 d80e55d30e9a60004b5eaf51cb8c54d54fb702eb
SHA256 1b87d5c0e84df306c6701eb6adeb6b3f48ff06ad5eb645a2d1605c13cb907a3b
SHA3 92824fdf7172fb195a025bf4effb95e9f92fa76daaebf6d8093aad6052a8e1c9

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x340
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21875
MD5 a9951e585ddf7cf061042bdfd276f881
SHA1 429acbff79b3909c3b24ebfaa40e86cd403b062c
SHA256 e0884054435079e12dc2b9ff074cdcb86e451c00975a07baddd137e35fe678b2
SHA3 69bb3b3a1619eef13b2285763a080cc7b2a9bd156c5617f11e03d5eae26e2de1

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13114
MD5 11dd2bfd92ae80c2f06b20f7fb836e3f
SHA1 aa004b97bebbcdc59ee62051d321e24c90d29759
SHA256 220d12ee183f1434eadfaca0b19ce5fe7fc621dfc3185280b3d4ed2be2b1d444
SHA3 7aebf67425129b344af88fdcf3bd19aecdc20041c29674c6b846d60d35ba1cb1

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13655
MD5 446ddc0c9c57d95ac2369739229cf5bb
SHA1 3e7c02af245ccfbb95531ed16191c561b6313a83
SHA256 785d2a1bd786844e67300efff946de1b219281ee904aac0ddeb2c546200911d6
SHA3 3bd05670cec0e84cda4b0dd9703687930bab830595398c2fa7913561b28a304c

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x224
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26079
MD5 0f2451e331c5e88bd99f0b3c38b931f1
SHA1 f8b06c9319b353b196c7b59dd695ef3f6a5d3688
SHA256 921b69c6ab217e399ba60a9748221ae1c2e64fc092d9d89339df94804c927082
SHA3 55c4322bc68c05ddd2491a5ae7db3367e16b33b590e64d2c641046764a5c9a54

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x404
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19828
MD5 a48d3a2b67fc74f68ab0ece70b481b4c
SHA1 31ccb0b46df22b59d3d690c9cf1f1903fdf3d38d
SHA256 7cb45bee3e5f78dd8d4cf0354c31ca88530f669099497bac487ef08207efa085
SHA3 cc6c544b116ba294e1d3561ace65f56bba8abf76f8941b73163c25f16ae4a9dd

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18867
MD5 72a5df9daf8c1ea170259eca9d63dcf0
SHA1 92df8c59a28886e8b3efc7df18fa54c332ef7856
SHA256 7ffcaa3f10042908bf6c05eb0dab3c60c162d40e43dbf6a14d7d113609a5fe0b
SHA3 2b90c7ac61c0e96a30ae299bc201f52040c6703cbd23325ab860ca86d754380c

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23337
MD5 ce481f3af75accb25c426eca42f29b94
SHA1 7cc2a923de46555996479cb96488de46c1382bc1
SHA256 d01fbe06c8ac4e98796a56c849ed417c2f45018af9c9758277133a1cb2d9000b
SHA3 d2ce192c025db93a848e13b8b39a8d2427333c34fbd2775457b4c385929247a2

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23611
MD5 0b3b3f84ec000a2d065f410a90e9f178
SHA1 7d75d5ee3ed4a201d43d6041e56873100b8f0b97
SHA256 e516a87fc7a398deb771cd84b35e4b885d97316daf61d88ece59626f08244f44
SHA3 28cc5ec45b6ae4c6c0c0888f70529515b6884edc57e1949a732422968e63a232

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94991
MD5 76b269d85b322790b6a99e3f8b603311
SHA1 1361ca26f29c62b7b591f79ea677c71a38aa98b8
SHA256 369c5223029ea6d1b17b7f24a8d84c10f528457e79be3349a6c55efd0e8f0e02
SHA3 5ef9310cf2c895a94d39a4f7bab21bb432404fd4ded0240fe78a324936bac55e

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94916
MD5 24f859ee6a1b2a0281d58e744c4d931c
SHA1 d0768e52c1cd646ea9ad0e752d71dcb2709ea74e
SHA256 968bbd325d5403ab654fd9308ea2497bce206395d77c4729d07b638480b7cc47
SHA3 4df3e7394f0291d46352f6b60d17d78c8da7ff6d1e3deb8e52dd43c51ab1e2da

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x29c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24887
MD5 beb27ef60a5afdc347e0e4a364d69113
SHA1 9fed1a50dfeb3a075306669d3638bdfafdd32d97
SHA256 0d3137dd56cde6d3d1fd0a6e4aa514928ce0eb20cd0a43fdb18ab8cd0bf63b9f
SHA3 9592b7419fb95fd098445018c2357185cf59d1f3051a410eccd0f4da66f7a822

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22093
MD5 061ef920f02530d7fed3484f267bf2cd
SHA1 bfc2a198b6ce5e1b746dfc395ce7d03c0305ce44
SHA256 77e4b2d44652277ed54a8967667dd0cf7af92932f1940e0124cf3cb8c7f67927
SHA3 4e135eefc2a1274de929f47cfd220d37b244b57cedffaf93e3b4d5ba745d92a6

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23637
MD5 8356cff46d5d2eb6e943dfab8796b058
SHA1 2b4e803199a60cb6685e918c7c50f9314a0e5a0a
SHA256 db3fa427c11963222426e133f94d1db76de1f8a09a33cda71e9241cc69a12704
SHA3 bc5ab850b88d515ad2affc860f262b521306aaca02c7a3bd211602261ef16486

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x314
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12118
MD5 7217b6b6ee273616858467d7261c7d96
SHA1 5a31a93c1c95efd080efc3601518d2e69c91b93f
SHA256 d10704e50b2f6387284c4242cfe62af0bdfcabfb17429ffe617b77804f1fd017
SHA3 6e6e61dcd0b4584d03df4ed0734437fe6cd315b0887e14a3bbcc1e3706e5028f

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.26084
MD5 3b8b894c45c3a8b0865e9e982245ffda
SHA1 443cb45dfd41ff17c1cc39fef5c8dbf55a9ae77c
SHA256 fed515f7a5e76fa5adc54ca540c3bb85fda01c77d00bb443d5314f8f64f2b93f
SHA3 39c8fe9c9c0a29bce94230faee42f5dd2ec226b0f0f3e091e07df2ed727e8fd9

TFORM1

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x704d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.75843
MD5 a67bf7605d23e56ffa3eeb91e2efaa6b
SHA1 63c9a11fd3dd5c6a622aaeff74028bcc4f0fc55a
SHA256 ae9aa8dbce6589a0f652f0cd44504b92f5b5067e0196597af9f1c0b8c929ddb5
SHA3 fce03c375f58cd862718b5adce8c96cb0e13a7a4fbf71cd7eff24136f928c151

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.69913
Detected Filetype Icon file
MD5 fc8846589a152507308beb48ead7a796
SHA1 787c24f9fbf50523b34bcb328ed56d33c4e7ffd7
SHA256 4a2d022975e1b62b89e1e757b73f563b68b21b71edf8cac8dbbf062b2cb2d2fe
SHA3 8ddbf8de92320682fb04bf04b166aab2b443a9fd6055b504b0c29ee44468a9c9

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31712
MD5 9817c26e520d0304d3931fb53cdebdb2
SHA1 0cb89490c5acd0d13270aebc0d4591a36020781a
SHA256 7327c3ae7f5fdeb7ff5e7f0194abc514daa445fa86d8af5aec703f9856eda6ea
SHA3 2d83dde713c3295a16623ecd7a6688408fdc9d22a58271d72fb791bdfa78c5d8

1 (#4)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x31c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.277
MD5 1d19a29bd091c2d89f431debb255a993
SHA1 2e81479c882cd51fa58207000b4f4379c78b511b
SHA256 c7bfe1230b8b6fb8360f5f6b3403b71b4a59cdca28f5ec4b8390710514d72cba
SHA3 2b46c10ad57924dd16db4a8a2aaee95bce6b7f20082da8f69fbfb772bc307e12

1 (#5)

Type RT_MANIFEST
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x4a2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.34983
MD5 962716bb47235f541de46a8114feadee
SHA1 323c605db6570df887a73415dd4aaa8e611fd96c
SHA256 9e091430f14e64731edc7b1781db8fd00d1a80d8642a48997c52669197e0c996
SHA3 f4139d48353ba890e8fa3452a0402aebf04ef01e64a38e3b2c3b89b389c4fd31

String Table contents

Cabinet returned on fdintNEXT_CABINET is incorrect
FDI aborted
FDI error
Could not create a temporary file
Unknown compression type
Could not create cabinet file
Client requested abort
Failure compressing data
FCI error
No error
Cabinet not found
Cabinet file does not have the correct format
Cabinet file has an unknown version number
Cabinet file is corrupt
Could not allocate enough memory
Unknown compression type in a cabinet folder
Failure decompressing data from a cabinet file
Failure writing to target file
Cabinets in a set do not have the same RESERVE sizes
3D Light
Window Background
Window Frame
Window Text
RichEdit line insertion error
Failed to Load Stream
Failed to Save Stream
No help keyword specified.
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
No error
Failure opening file to be stored in cabinet
Failure reading file to be stored in cabinet
Out of memory in FCI
Button Text
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Scroll Bar
3D Dark Shadow
Yellow
Blue
Fuchsia
Aqua
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
Button Highlight
Button Shadow
Listbox (%s) style must be virtual in order to set Count
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No topic-based help system installed
Black
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Red
Lime
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
Unable to insert a line
Clipboard does not support Icons
Cannot open clipboard
Text exceeds memo capacity
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error setting %s.Count
N&o to All
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Cannot drag a form
Metafiles
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer selected is not valid
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Cannot change the size of an icon
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Saturday
Unable to create directory
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid stream format
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input

Version Info

TLS Callbacks

StartAddressOfRawData 0x490000
EndAddressOfRawData 0x490010
AddressOfIndex 0x48a0cc
AddressOfCallbacks 0x491010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Multiple nodes using the name Version Info in a dictionary.
<-- -->