| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Mar-03 13:15:57 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C# v7.0 / Basic .NET .NET executable -> Microsoft |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
14466202 bytes of data starting at offset 0x4e600.
Overlay data amounts for 97.829% of the executable. |
| Malicious | VirusTotal score: 54/72 (Scanned on 2026-03-21 05:05:40) |
ALYac:
Trojan.MSIL.Basic.8.Gen
AVG: Win32:Evo-gen [Trj] Alibaba: Backdoor:MSIL/DCRat.8a298bad Antiy-AVL: Trojan/MSIL.Kryptik Arcabit: Trojan.Uztuby.19 [many] Avast: Win32:Evo-gen [Trj] Avira: TR/Dropper.Gen BitDefender: Trojan.Uztuby.19 Bkav: W32.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.1742475304f0282f CTX: exe.trojan.msil ClamAV: Win.Trojan.Uztuby-9855059-0 CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS DrWeb: VBS.Starter.321 ESET-NOD32: RAR/Agent.ER trojan Elastic: malicious (high confidence) Emsisoft: Trojan.Uztuby.19 (B) F-Secure: Trojan.TR/Dropper.Gen Fortinet: MSIL/Agent.ETF!tr.spy GData: Trojan.MSIL.Basic.8.Gen Google: Detected Ikarus: Trojan.VBS.Runner K7AntiVirus: Trojan ( 005ab6851 ) K7GW: Trojan ( 005ab6851 ) Kaspersky: UDS:Trojan.MSIL.Dnoper.gen Kingsoft: MSIL.Trojan.Dnoper.gen Lionic: Trojan.Win32.Uztuby.4!c Malwarebytes: Malware.AI.2171344435 MaxSecure: Trojan.Malware.237179085.susgen McAfeeD: ti!BA08FFAB0F30 MicroWorld-eScan: Trojan.Uztuby.19 Microsoft: Backdoor:MSIL/DCRat!rfn NANO-Antivirus: Trojan.Win32.Dnoper.kvsiqj Paloalto: generic.ml Panda: Trj/CI.A Rising: Trojan.Runner/SFX!1.FA4A (CLOUD) Sangfor: Backdoor.Msil.Dcrat.Vo5f SentinelOne: Static AI - Malicious SFX Skyhigh: BehavesLike.Win32.Dropper.vz Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT Tencent: Unk.Win32.Script.404755 TrellixENS: Artemis!5E7F11900420 TrendMicro-HouseCall: Trojan.Win32.VSX.PE04C9z VBA32: Trojan.MSIL.Dnoper VIPRE: Trojan.Uztuby.19 Varist: W32/MSIL_Agent.IKT.gen!Eldorado VirIT: Trojan.Win32.MSIL_Heur.A Yandex: Trojan.Dnoper!njiH9U/jBcQ alibabacloud: Backdoor:Win/Runner.NBM huorong: Backdoor/MSIL.DCRat.l |
| MD5 | 5e7f11900420d01e70e9814230f0282f 🔍 |
|---|---|
| SHA1 | 6bc28a385f2bcd89a24ce7a7dc8be90035974225 🔍 |
| SHA256 | ba08ffab0f3088d3c08f04ff9c699b8cf9063a5f7d56086234ca67697989a5c8 🔍 |
| SHA3 | 5a438b7200df8896696531b42cd767984ef66853c6341d172704ab3f53074e1d 🔍 |
| SSDeep | 49152:IBJJHgWEbPtx/O+9lrL9wJRs0fuW1jsLsJikoJstyyfcPhkCLpOHQQ:yYXbvW+jevfMQJi6+hiQQ 🔍 |
| Imports Hash | 1acd058df8508c59f4ea2adc65d18886 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2022-Mar-03 13:15:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x31c00 |
| SizeOfInitializedData | 0x3fe00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0001F530 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x33000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x75000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 2831bb8b11e3209658a53131886cdf98 🔍 |
|---|---|
| SHA1 | 619c1d2d3a247d5ea0748c89b0b9d66a30b6417c 🔍 |
| SHA256 | 48ab4eb5a4a945145c87706f46d698adf5afd5ef605ac539ab0ef6cdeb2fbcf7 🔍 |
| SHA3 | f7b884bd662fdb7c8c68f057d19097cbd8c120b89e99459db79c3b48bf659779 🔍 |
| VirtualSize | 0x31bdc |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x31c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.71296 |
| MD5 | 042f11346230ca5aa360727d9908e809 🔍 |
|---|---|
| SHA1 | 6ecf068cbcb8b25488348341dfe9cd146d7efff1 🔍 |
| SHA256 | 804be68858db0f2910995e054d0b06401bf2307ec560f54907bb8ba21ba5c264 🔍 |
| SHA3 | 15ebd860c1f7d09d414d35040e874f69a6c050f4f65c79de0acf3ca1433bf69a 🔍 |
| VirtualSize | 0xaec0 |
| VirtualAddress | 0x33000 |
| SizeOfRawData | 0xb000 |
| PointerToRawData | 0x32000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.26161 |
| MD5 | 9670b581969e508258d8bc903025de5e 🔍 |
|---|---|
| SHA1 | f645e3c9267ab7df17b1b1f7196a59a1fa9b097a 🔍 |
| SHA256 | 61a9b234e0eb47b75e277198852d787ab0677398946412062da997ea34b45359 🔍 |
| SHA3 | 4ad2b0e47cd3e4b6eafc7aab43b88769f0211bc63e1377e4a62c40cae66eb273 🔍 |
| VirtualSize | 0x24720 |
| VirtualAddress | 0x3e000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x3d000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.38746 |
| MD5 | c83554035c63bb446c6208d0c8fa0256 🔍 |
|---|---|
| SHA1 | 08a8f0e687db994f8484fd20dc56094f4c219de5 🔍 |
| SHA256 | 76ffd51987e2d394a7ae70be547b72a23f2b104468405cd051dc2b7e73e3f6d9 🔍 |
| SHA3 | 2ce238220246ebdcf4a730c0b2ad857a31049b7f8fd0484c02e162336635e5f1 🔍 |
| VirtualSize | 0x190 |
| VirtualAddress | 0x63000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x3e000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.33273 |
| MD5 | ba08fbcd0ed7d9e6a268d75148d9914b 🔍 |
|---|---|
| SHA1 | a881e58590da632c259501ba5202ebc259ffaa84 🔍 |
| SHA256 | 6f18536450ae11716b056708d997652da7812a3ad9da7495aaff2c1386c20236 🔍 |
| SHA3 | b7a71c3ec387ea49a7aa248faace057cc34d1163fc36785a625ee646fecce0f8 🔍 |
| VirtualSize | 0xdff8 |
| VirtualAddress | 0x64000 |
| SizeOfRawData | 0xe000 |
| PointerToRawData | 0x3e200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.63866 |
| MD5 | 40b5e17755fd6fdd34de06e5cdb7f711 🔍 |
|---|---|
| SHA1 | f1f4ef62479ee5ed243652eb278d24f467b2beee 🔍 |
| SHA256 | 824ed1373fce7f28dce8809ae4783590146ee39d9586acc5b6c5d9f99de32673 🔍 |
| SHA3 | 37ae9c7438b7baf668f18cdb122c461e56e7760d0fe13734c1bed0d2f37d15d5 🔍 |
| VirtualSize | 0x233c |
| VirtualAddress | 0x72000 |
| SizeOfRawData | 0x2400 |
| PointerToRawData | 0x4c200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.62301 |
| KERNEL32.dll |
GetLastError
SetLastError FormatMessageW GetCurrentProcess DeviceIoControl SetFileTime CloseHandle CreateDirectoryW RemoveDirectoryW CreateFileW DeleteFileW CreateHardLinkW GetShortPathNameW GetLongPathNameW MoveFileW GetFileType GetStdHandle WriteFile ReadFile FlushFileBuffers SetEndOfFile SetFilePointer SetFileAttributesW GetFileAttributesW FindClose FindFirstFileW FindNextFileW InterlockedDecrement GetVersionExW GetCurrentDirectoryW GetFullPathNameW FoldStringW GetModuleFileNameW GetModuleHandleW FindResourceW FreeLibrary GetProcAddress GetCurrentProcessId ExitProcess SetThreadExecutionState Sleep LoadLibraryW GetSystemDirectoryW CompareStringW AllocConsole FreeConsole AttachConsole WriteConsoleW GetProcessAffinityMask CreateThread SetThreadPriority InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection SetEvent ResetEvent ReleaseSemaphore WaitForSingleObject CreateEventW CreateSemaphoreW GetSystemTime SystemTimeToTzSpecificLocalTime TzSpecificLocalTimeToSystemTime SystemTimeToFileTime FileTimeToLocalFileTime LocalFileTimeToFileTime FileTimeToSystemTime GetCPInfo IsDBCSLeadByte MultiByteToWideChar WideCharToMultiByte GlobalAlloc LockResource GlobalLock GlobalUnlock GlobalFree LoadResource SizeofResource SetCurrentDirectoryW GetExitCodeProcess GetLocalTime GetTickCount MapViewOfFile UnmapViewOfFile CreateFileMappingW OpenFileMappingW GetCommandLineW SetEnvironmentVariableW ExpandEnvironmentStringsW GetTempPathW MoveFileExW GetLocaleInfoW GetTimeFormatW GetDateFormatW GetNumberFormatW DecodePointer SetFilePointerEx GetConsoleMode GetConsoleCP HeapSize SetStdHandle GetProcessHeap FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP RaiseException GetSystemInfo VirtualProtect VirtualQuery LoadLibraryExA IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW QueryPerformanceCounter GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead TerminateProcess LocalFree RtlUnwind EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW QueryPerformanceFrequency GetModuleHandleExW GetModuleFileNameA GetACP HeapFree HeapAlloc HeapReAlloc GetStringTypeW LCMapStringW FindFirstFileExA FindNextFileA IsValidCodePage |
|---|---|
| OLEAUT32.dll |
SysAllocString
SysFreeString VariantClear |
| gdiplus.dll |
GdipAlloc
GdipDisposeImage GdipCloneImage GdipCreateBitmapFromStream GdipCreateBitmapFromStreamICM GdipCreateHBITMAPFromBitmap GdiplusStartup GdiplusShutdown GdipFree |
| USER32.dll (delay-loaded) |
PostMessageW
WaitForInputIdle IsWindowVisible DialogBoxParamW EndDialog GetDlgItemTextW DispatchMessageW SetFocus SetForegroundWindow GetSysColor LoadBitmapW LoadIconW DestroyIcon IsDialogMessageW TranslateMessage GetMessageW wvsprintfW CopyImage GetClassNameW FindWindowExW MessageBoxW ReleaseDC GetDC SendMessageW LoadCursorW CopyRect MapWindowPoints UpdateWindow DestroyWindow IsWindow CreateWindowExW RegisterClassExW DefWindowProcW CharUpperW OemToCharBuffA LoadStringW GetWindow SetProcessDefaultLayout SetWindowLongW GetWindowLongW GetWindowRect GetClientRect GetSystemMetrics SetDlgItemTextW SetWindowPos GetParent SetWindowTextW EnableWindow GetDlgItem PeekMessageW SendDlgItemMessageW ShowWindow |
| Attributes | 0x1 |
|---|---|
| Name | USER32.dll |
| ModuleHandle | 0x61cc0 |
| DelayImportAddressTable | 0x630a0 |
| DelayImportNameTable | 0x3c7ac |
| BoundDelayImportTable | 0x3cee0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Type |
PNG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xb45 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.87356 |
| Detected Filetype | PNG graphic file |
| MD5 | 63486a769bbe3f49d5848b9c69734a25 🔍 |
| SHA1 | e48bd36c2f23c238206bdddf3ebb6d6862905710 🔍 |
| SHA256 | a91f4373ceebadfc70b3bd0758848918f928c3c76562e3d9d531574796fd9e9c 🔍 |
| SHA3 | 7e9dc73ef6ee0ce127eee80c5daf334bd98ed2d2f262376ed7760866816d815b 🔍 |
| Type |
PNG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x15a9 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.80129 |
| Detected Filetype | PNG graphic file |
| MD5 | e6ccfb6d9ffd4e1a907a47761c64bd79 🔍 |
| SHA1 | d6a2994dedae3527a878140aa60dcaa087b90445 🔍 |
| SHA256 | 27d3a1a2da49dc535cc10806abaae9dfa49e4f5f44a40540ead50e065b99ca68 🔍 |
| SHA3 | 11423dcd0ab4c11695ad71f56e4fcdfc4b20a38cc6ac653ab7575f7dd024d0e5 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x568 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.97409 |
| MD5 | c357a2678e5234d9d0d93b80fff556eb 🔍 |
| SHA1 | f575af42db3045470df63787d678b61b3f696637 🔍 |
| SHA256 | 573c9bd29dea90ed994bad702ec79c41e98e1c8fb54b7964ec05ed1e64efefd1 🔍 |
| SHA3 | 74ecef77dbd4ce361c6226d842d49a2c28a318af22f9dc81baa2524ab14bdda9 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x8a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.10026 |
| MD5 | e55630d67fb64ba59f51d8266d31ff01 🔍 |
| SHA1 | b7b5b8c32742d7c3e2ef39fd5432eb22fd378048 🔍 |
| SHA256 | 85fe3ae58f9c30ca21251517164585fbb10f8490f0790dd15859438c1ca59729 🔍 |
| SHA3 | 9282845cf7d52c29ac721534751a56a1fcb3e2c625c186a4934cd6956ba317a7 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xea8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.25868 |
| MD5 | 73a958fb4dece366b7cf2f80de03528f 🔍 |
| SHA1 | f091434598195479caeb051cd932b64076d7840e 🔍 |
| SHA256 | 32bd1078137a5367d204b941cf6d970abbe1a520ac9e54b63d56f7e2f8a326ae 🔍 |
| SHA3 | 932882004db4780e9e260450182e91296e4ade6d07f3e1a3382f5d80b2b7b86e 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x468 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.02609 |
| MD5 | e768244eed218cd473905b37afb09cce 🔍 |
| SHA1 | 340c145b2b5a4393aa4b09bbdda14a84259b6c7b 🔍 |
| SHA256 | 6e296a4f88254d5c4e4f1871f425e8d9c5ca08846d5c90cb3bc9ceee89c91ae3 🔍 |
| SHA3 | f0a0dda5ab093a3211b8d4608dec0f9fd7ebcad96d357a449ae4b74d12051f4b 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.18109 |
| MD5 | 45fbeb8fc40ffa66db2f901c50a7ab8a 🔍 |
| SHA1 | d302538cba2599add5c8d0070cd2c5b3f077cf6a 🔍 |
| SHA256 | 574ed44e93b206d0b5b4354fba244af5a573796db738e34ca37a6e061b0fed3f 🔍 |
| SHA3 | da977a245bb5f556f77ef1ddb5b59f96e6fc9225db7d2048eadc5441a692ae48 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.04307 |
| MD5 | da87510c3aabe7851c7c5d0493dbb14a 🔍 |
| SHA1 | 4c59f617d7cebc871df1417f61c64a98556eda99 🔍 |
| SHA256 | 91b392c6bd14fa9d9bcab2afc2b37825779abae8b32443ce0a5ee0d9793f8fe2 🔍 |
| SHA3 | 582d345c2dd3b6dfa7daef53c039faa49be1b9cc8f749b08ca35fe6493b3bb46 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x3d71 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.94547 |
| Detected Filetype | PNG graphic file |
| MD5 | 7b678b6cb96c363d9e0adc3a1b3b4893 🔍 |
| SHA1 | c7e817672b686eb66bf5907da1efaef1dec8e06e 🔍 |
| SHA256 | 6f86849b026f0c45c0c8a1145048960bbdefdaea3beac030f114b1ff16057994 🔍 |
| SHA3 | 350e01112644403dd6d571343e7b00aa3d24e1b6fac796956f564355dde57fa9 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x286 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.419 |
| MD5 | 8edc9d9954c16d9083b44657a62c353e 🔍 |
| SHA1 | bb567f7e6b33d5d976abe26b9da4e403c3182dc4 🔍 |
| SHA256 | 8f25d7b09ecff6d3389a7742dc2a9e3187bdf010877d5512b7bab24566c3fca9 🔍 |
| SHA3 | 140be6b67eed1b2eba6651eb7fb1ed127c202df3b0cbe5ef1d2a3299fbb2c3fb 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x13a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.33594 |
| MD5 | 846493df763dc8986b2a7a908694aa5c 🔍 |
| SHA1 | 7113017d3f8ab15f721836f8cac36a3dde424962 🔍 |
| SHA256 | a6cb648be2175544ba05cd1c0d9f5b45b1d344915c503f01495f744708ebf6fc 🔍 |
| SHA3 | c524ff060d297a1a5d5a072ad50e5440ed3119f05de91aaf5f372a6d6a5e642b 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xec |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.16133 |
| MD5 | 4da01a070e57545f97e0d84bcf1524e5 🔍 |
| SHA1 | eeeadb106e138aa26b66d276f84c8d076a31142e 🔍 |
| SHA256 | 44e6a8daef1ac762f8016fc4c8aec52bad42f589b6d8a25d430a619610dd0028 🔍 |
| SHA3 | a018ce14f68b06cbed4adb1bf6714f3b6c1aa64fa2afa2215e037aa654f9fcee 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x12e |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.09135 |
| MD5 | 43b0cc5d14bc75c453a11cb013864a38 🔍 |
| SHA1 | 6990aed36ba67f0d6d34a63c3d9fd9dc2487db01 🔍 |
| SHA256 | 237fb4fcfacd77cffde8221c92f0726c849afc96cd0bfd833f50b78552f7b22b 🔍 |
| SHA3 | a5ace4978d8258be5a68d7db48bc472ffa5cb949b4bb7c64f35348b5b34bb9e2 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x338 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.31634 |
| MD5 | 59053a2d4069a360fc73761849e1318c 🔍 |
| SHA1 | 541edef52f27a7178cac477eb3803cb4820d31ae 🔍 |
| SHA256 | 19561beb5029c85d95648f15c598b028a4f8a00bc36f452c5428308693ed748e 🔍 |
| SHA3 | a1fea8b8bfc45c410ebcfcc73afd1716c6c2abb2889e8a170e221a7ac702bb59 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x252 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.51642 |
| MD5 | 8f7f380b1a69743aac7181d97f60324b 🔍 |
| SHA1 | e6a444d1fb41f3a3bfec6dee720ee63e2337fcfe 🔍 |
| SHA256 | ad7a2ec8f4ae2bad71bc363e13eb5a809b2936f010f453b986ea04a5605c630a 🔍 |
| SHA3 | 313019b4cd37222ade46ea6cfb35e136befe0a6e755a2d02590745173e2199d6 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1e2 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.1586 |
| MD5 | 2ee005bf14efd62d866ca276e73b47aa 🔍 |
| SHA1 | e098ed7de14a3221722e8c25ada1cb901ce85978 🔍 |
| SHA256 | 450b4d82a86dba50acea995d6356e0174a242081f2c2438f6f88c29038f7097d 🔍 |
| SHA3 | 3bd4b237507bdbc645d985837c718b5df99fa6c91e862fe59f7295cd82c7d0b0 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1cc |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.11685 |
| MD5 | 91984a8521454b1758674f2f0765e695 🔍 |
| SHA1 | f48b0e0ca433d99226abe5cb9f1421b5dc204d31 🔍 |
| SHA256 | 89051dca472bd5ebb7b344c05150755b6e3d32cb0dffea086c04186820b188d2 🔍 |
| SHA3 | c7c2157fcb23e3b9253e37f60afe11361c625e3d5e0535bbbf988387d2cd517c 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1b8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.11236 |
| MD5 | de2fde7dcddbe30df25bfcf234a301c3 🔍 |
| SHA1 | 749b1a50cbed02bb7fd1fd277333340996b22c6f 🔍 |
| SHA256 | dd64405d95bedf0c5a998dba963360b3b9dd01d1482179c2b1d33ddb465841eb 🔍 |
| SHA3 | 18b764b7d6b4bd748a55e961d11738a5fc2eb831e2be55cb21dd535e29ca9aeb 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x146 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.99727 |
| MD5 | 06aeb5ae44f152010b502d79d78da978 🔍 |
| SHA1 | 765389e59fc961fb9782413bccd6218c0ed29c95 🔍 |
| SHA256 | 1e87eca343221966ecd9472109f3baf9081c821e3f4e905aa34eb8bce73af4e7 🔍 |
| SHA3 | dda651f9f04eded147d6b4d66801eb000f7f83f5e6161c919beca8e51e7b6f8a 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x46c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.21979 |
| MD5 | 1be38e8c51c46677f97f7e62d11e717e 🔍 |
| SHA1 | b4bbba99c20a80c523e001e056d1a7bccf98de2e 🔍 |
| SHA256 | 42fee2a4c1761b5d51e875cc86bf87d276e6d21ab4a93cd450f8263dcdd58c36 🔍 |
| SHA3 | 3446bf7ba6c34ddd25d212e2bd1d9e092ce3d7dfbf314ab0ee577eff4219bc49 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x166 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.12889 |
| MD5 | 70f271b2edd6a05942b95abced225c10 🔍 |
| SHA1 | dd3de2dc38efaf506c8c902edc3c6639651babbf 🔍 |
| SHA256 | d5755fffe2a9a4baf3593b8fba9a029b23bcc08e77c8d98e07b93baee6b9e6de 🔍 |
| SHA3 | 99f9038fe42c25749482786e85b1f0ee5dda044080bf4ea4b311b333a3098c63 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x152 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.01704 |
| MD5 | f82916fbe2aea69eafe68b9796d66a02 🔍 |
| SHA1 | 0163aae109725b0ddb7740b3f648da2777463e55 🔍 |
| SHA256 | abbb67522b7822276112f9a351d05701b2b62f2317592dd8ac7c921809de2ccc 🔍 |
| SHA3 | bb63fc32a6057e9ffc74dc8c5276a24af66b86604daede76ce69550e41999599 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.94627 |
| MD5 | 30e6552170bc691f678f7acef9e80e0c 🔍 |
| SHA1 | 8b2d788087dcb89391aca01e923a041f91bbb58b 🔍 |
| SHA256 | 9259a6b6d2959b4dc26b0563c2e15fca703e6bf343e2016ed314a992617f1904 🔍 |
| SHA3 | c36395577d2aeb1248c26a8b5a5db48646b2ca0c999cc6e8bdba8678cefc97d7 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xbc |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.83619 |
| MD5 | 09b30c86fe6cd7c8fe6d5d5fdd8b0a3e 🔍 |
| SHA1 | ba24c6e94ca7607f3fa91f71142d64d2e2938152 🔍 |
| SHA256 | f63fabe3ed749afb7b1719755170afe965f37e216834adf90dec051811afe657 🔍 |
| SHA3 | f4baf857de57ba1229f413a1165ec8e17dfa3e973f315fda2a082f79a3f64948 🔍 |
| Type |
RT_STRING
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xd6 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.80514 |
| MD5 | 3a1b603eaeaa7aca84afab706054807b 🔍 |
| SHA1 | 577ba4baf69c0cc5867167174746fc35fb11e8fd 🔍 |
| SHA256 | cfa68e1c4fe3e613725ec1c45a80c2e4855c07e2d4587c8cf46fac05a78c0145 🔍 |
| SHA3 | dc50fd5dad67b49d6067255f83399ab84ccc7adc2476f3b4db2c652fa24c5169 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.71858 |
| Detected Filetype | Icon file |
| MD5 | 216b6c99a73c9bdc965962e9c7ced2ec 🔍 |
| SHA1 | 3432d1355ff9f39aa7c8832ef6e37ff118bce043 🔍 |
| SHA256 | 4fd3c618bd4aea3ab42334f2e9375a22a7ef5e7ebf6da9f69c2249d6b6584ffe 🔍 |
| SHA3 | 015714e195a897ffdf3e2b709ed0d7e6c07d80c9624587ab4e16effef840af5d 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x753 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.25329 |
| MD5 | 8ddcbbd6b8c80eef68bf9305e59fa1f3 🔍 |
| SHA1 | 014923abccec57fa3ad16f65feb0de2b8cbc8408 🔍 |
| SHA256 | 1b7b67e5d8927449d8f7be80a0e5ba5f03d25670035027c0cb71abce27da6810 🔍 |
| SHA3 | e5c4bfc7e92f1b945363bb9ad2aabbe4324074ac295d08722e743d6e7c524b69 🔍 |
| Select destination folder |
| Extracting %s |
| Skipping %s |
| Unexpected end of archive |
| The file "%s" header is corrupt |
| Corrupt header is found |
| Main archive header is corrupt |
| The archive comment header is corrupt |
| The archive comment is corrupt |
| Not enough memory |
| Unknown method in %s |
| Cannot open %s |
| Cannot create %s |
| Cannot create folder %s |
| Checksum error in the encrypted file %s. Corrupt file or wrong password. |
| Checksum error in %s |
| Packed data checksum error in %s |
| Write error in the file %s |
| Read error in the file %s |
| File close error |
| The required volume is absent |
| The archive is either in unknown format or damaged |
| Extracting from %s |
| Next volume |
| The archive header is corrupt |
| Close |
| Error |
| Errors encountered while performing the operation |
| Look at the information window for more details |
| bytes |
| modified on |
| folder is not accessible |
| Some files could not be created. |
| You can try to repeat the installation after closing other applications and restarting Windows. |
| Some installation files are corrupt. |
| Please download a fresh copy and retry the installation |
| All files |
| <ul><li>Press <b>Install</b> button to start extraction.</li><br><br> |
| <ul><li>Press <b>Extract</b> button to start extraction.</li><br><br> |
| <li>Use <b>Browse</b> button to select the destination |
| folder from the folders tree. It can be also entered |
| manually.</li><br><br> |
| <li>If the destination folder does not exist, it will be |
| created automatically before extraction.</li></ul> |
| The archive is corrupt |
| Extracting files to %s folder |
| Extracting files to temporary folder |
| Extract |
| Extraction progress |
| Total path and file name length must not exceed %d characters |
| Unknown encryption method in %s |
| The specified password is incorrect. |
| Incorrect password for %s |
| Cannot copy %s to %s. |
| Cannot create symbolic link %s |
| Cannot create hard link %s |
| You need to unpack the link target first |
| You may need to run this self-extracting archive as administrator |
| Pause |
| Continue |
| Security warning |
| Please remove %s from folder %s. It is unsecure to run %s until it is done. |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Mar-03 13:15:57 |
| Version | 0.0 |
| SizeofData | 81 |
| AddressOfRawData | 0x3b3dc |
| PointerToRawData | 0x3a3dc |
| Referenced File | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Mar-03 13:15:57 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x3b430 |
| PointerToRawData | 0x3a430 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2022-Mar-03 13:15:57 |
| Version | 0.0 |
| SizeofData | 964 |
| AddressOfRawData | 0x3b444 |
| PointerToRawData | 0x3a444 |
| Size | 0xbc |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x43e7ac |
| SEHandlerTable | 0x43b2f8 |
| SEHandlerCount | 40 |
| GuardCFCheckFunctionPointer | 4403832 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xbe0d3e3c |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 13 |
| 243 (40116) | 142 |
| 242 (40116) | 24 |
| 253 (30625) | 2 |
| C objects (30625) | 19 |
| ASM objects (30625) | 23 |
| C++ objects (30625) | 52 |
| C objects (VS2008 SP1 build 30729) | 11 |
| Imports (VS2008 SP1 build 30729) | 7 |
| Total imports | 277 |
| C++ objects (VS2022 (17.0.5) compiler 30709) | 49 |
| Exports (VS2022 (17.0.5) compiler 30709) | 1 |
| Resource objects (VS2022 (17.0.5) compiler 30709) | 1 |
| Linker (VS2022 (17.0.5) compiler 30709) | 1 |
No comments yet.