cad3e11f580c2dc35503e6ee11833c94

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Apr-06 14:39:04
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Audacity Team
FileDescription Audacity 2.4.2 Setup
FileVersion 2.4.2.0
LegalCopyright Copyright © 2018. All rights reserved.
ProductName Audacity
ProductVersion 2,4,2,0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for Qemu presence:
  • qEmU
Contains domain names:
  • http://www.jrsoftware.org
  • http://www.jrsoftware.org/ishelp/index.php?topic
  • jrsoftware.org
  • www.jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: James Crook
Issuer: Certum Code Signing CA SHA2
Safe VirusTotal score: 0/69 (Scanned on 2020-10-26 16:06:13) All the AVs think this file is safe.

Hashes

MD5 cad3e11f580c2dc35503e6ee11833c94
SHA1 522ff2efcc2dc89b6de70c6a0cc486e53b4a7afc
SHA256 1f20cd153b2c322bf1ff9941e4e5204098abdc7da37250ce3fb38612b3e927ba
SHA3 1ae0d05e28bfca46ecff5f6e70f508fc8ef7d137461e1a0f17c2935a0822e806
SSDeep 786432:UExoV4pAY+v1ORovBWG64+89877O7Z3Ki5:UvV4yoBp4MO7Zai5
Imports Hash c60f9a83fcd28ab2eb686b76b194eb79

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2016-Apr-06 14:39:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x10400
SizeOfInitializedData 0x37c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000117DC (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x12000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x52000
SizeOfHeaders 0x400
Checksum 0x1adef20
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a33e9ff7181115027d121cd377c28c8f
SHA1 3dafbb4f2d1eb2164e193102e863ce4d7cabb6fb
SHA256 11a963697f424d62b984f4a71b5b39a9212a2ccb07f320d98d9f84c2da74c6dd
SHA3 bbce6153972c468732c03e48ffedf4b9b99d797d71f95bd5d8f4ee36d07e1c60
VirtualSize 0xf244
VirtualAddress 0x1000
SizeOfRawData 0xf400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37521

.itext

MD5 caec456c18277b579a94c9508daf36ec
SHA1 2f9d566890abd0f66230a92bedf71afe6d110b37
SHA256 7f26d734f1c91987ba9e8f9100bb4d742f5bfef70e88763bbdbc3ce181bf6651
SHA3 605449a83d564b3e3ea04477d56bf1743e6e9291b044840ece0da5415286d99c
VirtualSize 0xf64
VirtualAddress 0x11000
SizeOfRawData 0x1000
PointerToRawData 0xf800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.7322

.data

MD5 746954890499546d73dce0e994642192
SHA1 2e71d1453d5d7fed43fd87a4ad48ae14c4969c6f
SHA256 42f6faae65550b06e3ebbb5a5a19d6ac41911ca2690b14db237928bc63453d96
SHA3 d09fd6a8611aa14419fd79e31a73c6450925b40bc6763fc86da372570a251699
VirtualSize 0xc88
VirtualAddress 0x12000
SizeOfRawData 0xe00
PointerToRawData 0x10800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.29672

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x56bc
VirtualAddress 0x13000
SizeOfRawData 0
PointerToRawData 0x11600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e9b9c0328fd9628ad4d6ab8283dcb20e
SHA1 fd2927174e310130a51bdd648aefde6f89fe0007
SHA256 68a126ba6dddfa52cdc395cca81ae415921071acf02f75b7c00faf9d90353760
SHA3 8d72ac9fda0d2c851f62aab12f92db53db9fb187e522555aa7e82502850ce7a2
VirtualSize 0xe04
VirtualAddress 0x19000
SizeOfRawData 0x1000
PointerToRawData 0x11600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.59781

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0x12600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3dffc444ccc131c9dcee18db49ee6403
SHA1 45d8f890e32cc1adf7ded113fd19004c8869f419
SHA256 821b0bda5922cc6f5fb74fb3a160e39c97727c21beb1ecf4f96e3bcfad9edbe3
SHA3 426ea652dcd361ec016030230ec1c87a2bc522f69cfb4c2af6313465cb2c516f
VirtualSize 0x18
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x12600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.rsrc

MD5 22f801841cc01d8415ab2cd1a6b789d6
SHA1 7a833011e709271f6e5fc6dc61d4324c78437014
SHA256 15b314a9ef8c56004dae869bfe9a95038b01d727393e40ee02d649b3be203641
SHA3 4b0b747aa0314c5c953fdc90d9df1e6179a1a5d9bc1e875cc7057e4ca11083b3
VirtualSize 0x35bd0
VirtualAddress 0x1c000
SizeOfRawData 0x35c00
PointerToRawData 0x12800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.97152

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x91f1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97985
Detected Filetype PNG graphic file
MD5 80c3a453e038a77edd5b60d086293d6b
SHA1 750ba21d1fd53bed2109635c599b52b81d33a480
SHA256 464f2b4faaf1feb2e653ba90f3b206ac87f0a3c7fae3d9ae5ad27651d9f79209
SHA3 184bc2284dfdb5074d8297091573352bb7642fa3d6ba4af9ede080f8347c989f

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42593
MD5 ad52c3eee5410809f5bbd644ef526929
SHA1 53273f57b8189c78215cb17d101e323ff32602fc
SHA256 36700f46e3a8cff4d54d7bcb9b3a32d5db722be2075d797ee8be7736f284e17a
SHA3 059da358f2399d7cda051a4402520388ae6218132526b8f715b58b20a1307cd2

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.61921
MD5 19a64ad4ca1bfced34e39bcd4d5de7dc
SHA1 3bd6b55158a8edf9d557ca0efc930bb0e24a6f1f
SHA256 c9f2bfe65a3a2c94b81832f300b7e8f45ddd48e6239c1ecbbead356484763224
SHA3 32b3aa0d68e8f2deb288cfb86f9abf33e25e31ee35f34c24da45abaf05294ee1

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.88888
MD5 8c37403bfd66becbbff87945f4e3efc3
SHA1 11cd3ad8ff5f91916efbff6f0ad35d06eeb46672
SHA256 390644416c12beb16abdc0c4896183c3186ad1ad6447ce7cd1af4db1f0a6ef04
SHA3 114be0b09838f2188fc6eb2a2405984e631f1230439f8fe3c177ab9f39fd4d61

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.15301
MD5 a7e31423760060dc5326c6d84c148fc0
SHA1 94a18c0e4d11f4ac277feca94124f6f06d6fa1fe
SHA256 bac380ffdf0eeb43931df7ae65fc113eac32e909d81a36b8a86c2a0105358e35
SHA3 d0776ae6b656de39580d34c4d95fa7c551ab50d511805f4b0d0836661dd7d026

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.49424
MD5 5a3668ac538a58291288752d5210a59c
SHA1 0927503605a8f62431f0faadc143fc9c13987194
SHA256 a4f7cb35b56a0362770320846dec42b943fd9ab8c51458c05f80be38a9e5e596
SHA3 37a5fea4812de820b9c7f59c52a7433b425452a35c8f73c292c42400ea1609c8

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.73073
MD5 83a02d91c72d3245eb28d5eefa12891c
SHA1 9ec3ba77c5c19761b253765e8872139e48cec7a7
SHA256 c1d4190e7f93ceddaea057e98e78a024cd94f1347dea791857e02fbe9cded506
SHA3 e99e9375972094a2c8e68d4d71b144ca4efe2cd6a88720c12c78f1c4bacde58a

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.03793
MD5 1d1bcd65dc0111c327eb0c3b89f3d171
SHA1 cf22e83ba3440753557450aa639d855f88203765
SHA256 494606bbd5fc498a6e0097de44e5b8f78b127ae0411ffb869ed92f3db8213127
SHA3 33a754da8bfd40419f60e3456744674ed8200ad29a599a52f37d7fc226cad4cc

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89346
MD5 bcb94d374ce5d92fdda79f756c74cb17
SHA1 36552ad41d01d5a472a879365ed779905c65bd7d
SHA256 1f02c34f98cf85ea58643dba9ca6263eae2fb6cf89d0a910513d687346f017ec
SHA3 a46b93b8f573bab522e6bd4166f2bb7ac8aca018d9b7d19376a5420c96668dfd

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91713
MD5 205ca3d3d4f82c15aba987f3b7ade242
SHA1 a3fe0b1b1dc8983a4f055129358db789008db953
SHA256 a34653432c31257535584224505df5fdfd1e8c734c6bf703fd73133da4db1638
SHA3 7686fa48f149410bdb47e6930d5af49ad0b0502e1d10df912f8f6ac62c9a8803

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x148
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95909
MD5 3f37b85f46cae653e543c1ef70bcdb23
SHA1 19107ad4bfa14f064a8cea5c576db6cef5387ff2
SHA256 28cbcd2c22467a407bbe07c2d7b7f1c2cd3f990677a6975e6a7b51ed0c5fca7c
SHA3 4dfb77df817e7cf7a77ba4b0e62708f503f53f0b17f9b15456def9c722ee30b6

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56031
MD5 e518b8ae009986dd90363fcc61d7fff7
SHA1 24ed3f9f44fce167e79b53ea5f9b0505c4d567e1
SHA256 34ea1c2173226ecc593f8a2b0224c51ebbee1928715bda9339eec7717a822b89
SHA3 519dec097566117a56d9c49b0a711e82451c0f81fbb53f042549a61cd51122e6

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25287
MD5 ac85ded4e576ce909f5460536b63a4f1
SHA1 07e0380006e58eec02eaaa047a58aceeef1552d3
SHA256 e1d818d622875ce2cf81883816ef982aa05a724c46f82b3e67875e0bc24228b1
SHA3 d70f10064348a4608f8b92740e05f739736144b222db3aa5c51187c75c5cc4eb

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26919
MD5 519a33f5d2b4442ef3caf6d4501995fb
SHA1 e54df9d112555eb11a132bfee15b69ac186b422e
SHA256 80bc91470ef70d527d0c4e0824945bc3b17ff84f464bca425661c3e7e1972ce7
SHA3 88c911ed5f1b1354c3379baaaef2540d70c370fd877f536d069dc0ea55cd0b13

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33268
MD5 234c2763997eec9c8a72ef190b928d68
SHA1 089fcaabba97f63455ce8a47e2d5d07fa56ba55b
SHA256 33ef72f38fc1fe2842c44e11bb351f94385bb186fee0fadbefc9364ed52aeb93
SHA3 10cbb07d784f332702d9d3451649950c1af6fb999ac1c2dac82df168cba5f302

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x150
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17906
MD5 9247d9dfc002426bf15a38569e1117d6
SHA1 724fbe0b18bf415f1871fbc45570b1ba809b1acd
SHA256 05efbff33471fec1389d42d84ee0572448b1dabb86c18ee38dd6463ff7f927af
SHA3 908ebb293645b24313fed4562495cebabd348ab84dceaded2145fa135e0ee180

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.78553
MD5 5e8e2d3cd6a59c2c46def8bb05f773a7
SHA1 f3475c4448884eb52a2c8fe9631d874b077c4dba
SHA256 d00449c43e3e2ef1bc012483ba8b5d5d4f8777c0f55a07deaa759bc69aa6d2b8
SHA3 843c12e1005f7dc85d497313accdb1411962ab234131e21591fb570320be1b0d

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08637
Detected Filetype Icon file
MD5 3f41b2c248ec44219b828fd66505c9d7
SHA1 015c93501685ebd0de8cf8a6c0090854526fae71
SHA256 5a088186736623e57f8e172cc44942ed8e2b8c527f9890385954d78767e34753
SHA3 ac9c6bd4cfb4e139a0feac395307a518f9dc598ce177177b275e920a6c3ecbf8

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x4f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79913
MD5 8b571ba848723af9b81ca42ece10ef3a
SHA1 8ab00ea1717c5514f960e1822cc6b970ab0e780c
SHA256 f1aad98aa3f0507fd6b3176e2917fa861f4a9e34d6cc4391b5b8ba075c565895
SHA3 fc161f94dad362b69c62b83b2890c47149956f27e1cdd08c73905b74956670e5

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x62c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13965
MD5 f78a870573f5bf2f15570e286257fae7
SHA1 eaccbf47cd42836b0e21ab2196b86d98a28733ca
SHA256 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
SHA3 f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca

String Table contents

Friday
Saturday
Invalid file name - %s
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
Invalid variant type conversion
Invalid variant operation
Invalid argument
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Jan
Feb
Mar
Apr
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.4.2.0
ProductVersion 2.4.2.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Audacity Team
FileDescription Audacity 2.4.2 Setup
FileVersion (#2) 2.4.2.0
LegalCopyright Copyright © 2018. All rights reserved.
ProductName Audacity
ProductVersion (#2) 2,4,2,0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x41a000
EndAddressOfRawData 0x41a008
AddressOfIndex 0x4127ac
AddressOfCallbacks 0x41b010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->