b36e982eaa49b4e42628dafd1aec9bf7

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Oct-10 22:09:13
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Steinberg
FileDescription Steinberg fake Soft-eLicenser bundle
FileVersion 1.19.2.0
LegalCopyright Team V.R private build
OriginalFileName
ProductName Steinberg fake Soft-eLicenser bundle
ProductVersion 1.19.2.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • 88nsm.com
  • adobe.com
  • http://ns.adobe.com
  • http://ns.adobe.com/bwf/bext/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://ns.adobe.com/xmp/1.0/DynamicMedia/
  • http://purl.org
  • http://www.iec.ch
  • http://www.jrsoftware.org
  • http://www.jrsoftware.org/ishelp/index.php?topic
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • jrsoftware.org
  • ns.adobe.com
  • www.iec.ch
  • www.jrsoftware.org
  • www.w3.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Queries user information on remote machines:
  • NetWkstaGetInfo
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 8020216 bytes of data starting at offset 0x12ae00.
The overlay data has an entropy of 7.83023 and is possibly compressed or encrypted.
Overlay data amounts for 86.7575% of the executable.
Suspicious VirusTotal score: 1/71 (Scanned on 2021-01-06 08:10:46) APEX: Malicious

Hashes

MD5 b36e982eaa49b4e42628dafd1aec9bf7
SHA1 d26c47b33fd7333c39be22f32f1de32844a0d60c
SHA256 2c83069b72fe22d95cc2848ec9881af0790bad12d641d613bd843d98fd30c5ae
SHA3 17dcac6d6729af545a3579fe0ec257e44b4c29a91b2c026b559a24e61570fde5
SSDeep 196608:TdUUq7axC6E7hsYAPhXiFcCxUUklh7TDJjHNlaB:7q7axC6whIpXRkUDHTZC
Imports Hash 3f3431d69c4f5d3273ae39cb1a749a89

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 10
TimeDateStamp 2019-Oct-10 22:09:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xa6a00
SizeOfInitializedData 0x84000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000A7ED0 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xa9000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 6.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x139000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f082ee6260fd65bd4406603aefa5b38a
SHA1 e0f4b76afa924a8a5b21fe616077583cf84959f6
SHA256 23f025c227c77eeb0d9528f3630e2ef35e8238656afbbc468dc811ccc89fae06
SHA3 4f45ebf8e13248afaab46f05af663284adf909345c957e23805bb8936a19ffe3
VirtualSize 0xa50e8
VirtualAddress 0x1000
SizeOfRawData 0xa5200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36928

.itext

MD5 01fc0e6510748ac1fa24729bd4c8d31d
SHA1 9da3b9a9415d729576d6cf4eaeb4d2788e04be69
SHA256 d9b6f33cf9c597a0127d9de95d2420483976312c63699a9f40600fb5cc18cf97
SHA3 530b67238759d1bd9696f00728ee38cdaed17c03dd01c5d8bf79087c00048488
VirtualSize 0x1668
VirtualAddress 0xa7000
SizeOfRawData 0x1800
PointerToRawData 0xa5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.95181

.data

MD5 34fa73ad8332bf3785e4314a4334a782
SHA1 bf2f52bbad084aad108e437a6104d4eaa44a9bb3
SHA256 7069dcca5a6c0de1dafd2f8e17471fef157ae8362f4a7d98be6bb6d5ce6679c5
SHA3 c49dff236676f18ec0046a2b5296fb463d456430d98794835dc8212fde45d8e8
VirtualSize 0x37a4
VirtualAddress 0xa9000
SizeOfRawData 0x3800
PointerToRawData 0xa6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.03517

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x6778
VirtualAddress 0xad000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 daddecfdccd86a491d85012d9e547c63
SHA1 f367f6a2458e60a453aff3785c35bb7410780012
SHA256 7d6771bdbac93daf39a8cc95f3624d31fd4f0322362772b014e54b6e1f4486f6
SHA3 f1d21fc9cf70bfd70b830c00f404789746dbf54e32ff9a3b4faeceee842a523d
VirtualSize 0xf1c
VirtualAddress 0xb4000
SizeOfRawData 0x1000
PointerToRawData 0xaa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.79161

.didata

MD5 be0581a07bd7d21a29f93f8752d3e826
SHA1 eda85c8f9bed972f5b31f8d22c2096155892382c
SHA256 e6a2ce4f084eb860889980231b50d56547c7aed0e88e0c226b1e678d8fffb84a
SHA3 23bdbf3a1b8f730503fde2afc0675f21437bdff8117a63507f75e57384f5c8c3
VirtualSize 0x1a4
VirtualAddress 0xb5000
SizeOfRawData 0x200
PointerToRawData 0xab600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.74582

.edata

MD5 c7a09d734ff63f677dfd4d18e3440fdf
SHA1 916cfc535f62b1781b7759d68e5f1f7f5c9e34fa
SHA256 bff1950c0353d245f103b20a53eafcb9ed41a4710aa8b53bf807cba0263c27a3
SHA3 85c2ddceef02d4c1055106295fe86fc5aa1c2b7791dcce6a10065f893460ca1b
VirtualSize 0x9a
VirtualAddress 0xb6000
SizeOfRawData 0x200
PointerToRawData 0xab800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.88107

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x18
VirtualAddress 0xb7000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 955f17d4899f3cf7664168fa46e1b316
SHA1 185fa7c540259f3824038cf55115adfcbef64123
SHA256 a9016383ebc84c7898f6530b3a125161e5e737f3351fa426ebcb364d7444a5c2
SHA3 de335a40845a2aafddfe0c559d17c3e71b47c39178c41f4838d9c866c8244597
VirtualSize 0x5d
VirtualAddress 0xb8000
SizeOfRawData 0x200
PointerToRawData 0xaba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.37999

.rsrc

MD5 68efd22627a6cf2c95b74738d92e1dea
SHA1 7bdc9fe6d049e1964ac1003bf620ef6268bea175
SHA256 484b2cefc65e9e3b30a3f4d6dc3278a554d9aa25e6fc387214696f4fc15e6c22
SHA3 03cbce0e67fe0f3032b1c7755bd4cd701cb8858613d6e5f55ae4fb0c88756ab6
VirtualSize 0x7f0a4
VirtualAddress 0xb9000
SizeOfRawData 0x7f200
PointerToRawData 0xabc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.30038

Imports

kernel32.dll GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxW
DestroyWindow
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SysAllocStringLen
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetLBound
SafeArrayGetUBound
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
VariantChangeType
SafeArrayCreate
netapi32.dll NetWkstaGetInfo
NetApiBufferFree
advapi32.dll RegQueryValueExW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegCloseKey
OpenProcessToken
RegOpenKeyExW
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xb5080
DelayImportAddressTable 0xb5090
DelayImportNameTable 0xb50b4
BoundDelayImportTable 0xb50d8
UnloadDelayImportTable 0xb50f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xb063c

__dbk_fcall_wrapper

Ordinal 2
Address 0xd3dc

TMethodImplementationIntercept

Ordinal 3
Address 0x53ac0

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x12428
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78624
MD5 f5a2b7f413b207d6cc0750b93a1db2da
SHA1 f5137178fbe0932b77dc1ef773814f9be62edda8
SHA256 887ab1d260b2a0a3aa09f26cc36cff8a29971889a1bfb6a508a6b8052f55183b
SHA3 362c5132b24c7533d8184a3a80fc1d742e371f4d943cf4395a15ab0303e71b51

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12259
MD5 fc816ea42fadc9c97fe9f5e6494d52ee
SHA1 29ea87f51e75c3ea78abb8d4264fbd54c7289094
SHA256 8bec1776bcd8353f7adb825e0ca64c6bd6af91604aca016391a8ba8639032709
SHA3 369d8c1bd6265c2b85c41914af5fcb3c1b96b5d019946fc7dbfec537c4bc0d93

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23717
MD5 60db8cd6e12066d9eded6e77a2d77cde
SHA1 9aee59dce30971845d63dc635c9fd29d719fcbb8
SHA256 9338cdec673fb437c72a56db089d4e4f6fb635ef41e8b7d4be92297e7e2aa643
SHA3 84ed529471ade77d894bf4105e6fc065243ee01898c86b853e6f8a3076e2c2c2

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37565
MD5 d1eb9d48d40b3291542a3c0c22d811a9
SHA1 edb945f277705e15aa061e84850f82c7f11d6232
SHA256 faabddf6cea131f68104575b365495bcfefc490d5e57ab443f62171eedea24d5
SHA3 39ca18539609ea7504a43ca66a16e06af43a715e96d36741d30c0f8ba1df146e

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42336
MD5 23d7f17f5c2ba544eeb27f8434c11039
SHA1 0ef0225b26676be61ae7810b8e2c380047b32fa5
SHA256 1579b611926c1c8a695842a8deb0f58c744a52c6a7e71caa0f03ec313093d6a3
SHA3 681962a9e9f5c75c231dd88692b035bcba3c687f8da989a4e8e2b0e57aafe9dd

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4319
MD5 85bde725d716757b732fa40f31caaee6
SHA1 d08c755982e6be178f389370b526332d540744e0
SHA256 e022f8848d19ec403d74f649b393f286347665c4ed305fd310a7f8eb2630b222
SHA3 72d8d7e6f5055345c3b3123c1b9e3656c228a76c8b7b11d496a02a8561be9fca

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5791
MD5 e10b7b34576da89545e362fbed8015ce
SHA1 efa8a559687057055d030dff31d4dccd3753fef9
SHA256 65a673936466abaa1f880b8379cfefe6c4776df141cebd854efd44b8509358e3
SHA3 564cf1bd345f3758aded080a3221366cb9ae09182106c0ac582befeca992d318

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70952
MD5 de4af9f645d9cab44c93888e819926d9
SHA1 1964dadffdb996b1e258d53b0d65f13f3dfb761f
SHA256 b2eff7acde8765f7ae5e584b93ed720d8ab74f85d3370a55bac531599b8ec1dd
SHA3 85ed0704c81a164fcef8c7d8515366af4a1c2ce722ffae8163ca6ac3b5c0d3d8

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.88566
MD5 84271b72d83124a5d7561659bc4aeb96
SHA1 7112435ccfdf52ff965b8bfa652bde6e4673dc58
SHA256 12b618387b92f7d8ccbff3feca569bc5674704f6e60c8664220dd0d07938e7bf
SHA3 70f2631e2733991bded487b086b7695933344111b148c8027a6fc8d7188158d3

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.72397
MD5 828010a28aa41b9135cbc1acfe4ebe80
SHA1 b11171af7c92f60cccfdffdc53693dce3f44885a
SHA256 26ab580fb860cf1f2fef5296edc1adf2bf6579f034e2a51b516cb6897d9e646f
SHA3 b8343cff4a4160836e1914fa6ddcef3e97df46a3c51aa8635b428bfcd0d4288d

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16547
MD5 98da6167be9a4eb3be8bab5877938ff2
SHA1 95641a365d88f070bcbd921d99bc1c034e92340e
SHA256 bb650ee3d30d21f22fc7853936b06be7cbfd05b4d88ed105d3e53774dae7f21f
SHA3 a9d9128c3f3c8d4c2c598c48390a012af7847fd0aadc64df63e86a25983aa7ad

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x260
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40938
MD5 21cba6c9d478ce13ad53587cdd7f21f8
SHA1 ed16991f4f735f8258ff195bed5f1641d1405cc9
SHA256 0852b5fce0c5b7ff53fe4c4163983daf8a2057d5481911c24253f330bfd65d9a
SHA3 434f4417d656f3e62678eccd5c3445487e21059d8fc5084f62fc19899ef6d1dd

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x45c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31153
MD5 09208f24be8c3f3b08c323e9836db5e6
SHA1 054aa93663138220373081b25672499d38cb2eaf
SHA256 4be11ded6c924c3181c0b2a17cbf6f017fbf2b074adadaae213a330711e22cd1
SHA3 9e72f2e022b1768e8723c2c93ceb39a4909564dee4d43bb3537ddd9ae9e381f3

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33977
MD5 aeb11111a0334d20d978e15c3eb3ebab
SHA1 19969a1f68d497f0114538352da478b41c3d2060
SHA256 99b7194bf59ac43cbbdc441ab7ca14ab0330449accd33730281da09bb96bcbe3
SHA3 b734c35baae6e8fb009f07d3a20892bde53b7db5335b1327e1118e89d657251b

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31895
MD5 4ac29bb5f7361e85771807112cd4ec93
SHA1 b164bf0882b60c0d7d4643495a2c1db5a20a1343
SHA256 2e6d8102640132ccabd2fa3c3a61c77c2b41a80d7f60013cf7149819c2b5c9d2
SHA3 ee5ab8846732cb786d250fc1780293072aff157ae61cf7f671eb4e6e29018bf7

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45
SHA1 30704560832bafa440df1fd20693653c2a30f815
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20462
MD5 fb9b54d86148feffff866f3c68c2984f
SHA1 f33a4594056c5543a88683fc7d439335ce94feb9
SHA256 acf10db4ad11935060a2dc7720c4059d0d7f697768e189fa093809e1a79b0858
SHA3 c0f222da998259bd11ce4ef44dfb97fbdc4ee0857921b860478101f5a5f902fc

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.70445
MD5 f97983dbc3cf6a7931453b752bcfa290
SHA1 87b29e94064d4cbce8c78f8067c7a76575ccf6da
SHA256 43e4cc413a02ac32e35a9acb1919da1e51f7a5d8da81bffadb8a5ce8a9eb58d7
SHA3 968bcafd1f7f982838d77097c878aba13cc7a9b4cec63b1dae7c807c2c773c2c

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x92
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02199
Detected Filetype Icon file
MD5 336f92ea0c544b78055e162547b0d6e7
SHA1 474328982a7972b847a824bbff175b4e70cc7837
SHA256 df615fdd5e1724dca6d2f152f7b84f79e4f8db8dbed803bde7219301cbad228d
SHA3 1692df4439e606c3e24fd7ae9932593a2aef54132c6e791e42db281b9ca4634c

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80986
MD5 f8e6b17b2b8d4409de08302ad4ff4a67
SHA1 b3919c7890b0910d4accfd52947b3b9e8cab4f97
SHA256 15b75d8796b730ca6eb27e55599475f6c9a1bddec4affe1a2d6334543598589d
SHA3 25ec686da8cd2a1b0978ce79a4d736cb412571e32b0e0fc074e72e7f8ffe8be4

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x62c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13965
MD5 f78a870573f5bf2f15570e286257fae7
SHA1 eaccbf47cd42836b0e21ab2196b86d98a28733ca
SHA256 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
SHA3 f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca

String Table contents

Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Argument out of range
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.19.2.0
ProductVersion 1.19.2.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Steinberg
FileDescription Steinberg fake Soft-eLicenser bundle
FileVersion (#2) 1.19.2.0
LegalCopyright Team V.R private build
OriginalFileName
ProductName Steinberg fake Soft-eLicenser bundle
ProductVersion (#2) 1.19.2.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4b7000
EndAddressOfRawData 0x4b7018
AddressOfIndex 0x4a9c14
AddressOfCallbacks 0x4b8010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!