cd515ccd8f121fe16c324d30e354fd68

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Jan-14 11:26:02
Detected languages English - United States
Comments https://cli.heroku.com
CompanyName Salesforce.com
FileDescription CLI Application
FileVersion 6.14.36.0
LegalCopyright 2017
ProductName Heroku CLI
ProductVersion 6.14.36.0

Plugin Output

Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExA
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExA
  • RegDeleteKeyA
  • RegDeleteValueA
  • RegEnumKeyA
  • RegEnumValueA
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegSetValueExA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Changes object ACLs:
  • SetFileSecurityA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Heroku
Issuer: DigiCert SHA2 Assured ID Code Signing CA
Suspicious VirusTotal score: 1/66 (Scanned on 2017-11-10 02:23:38) TrendMicro-HouseCall: Suspicious_GEN.F47V1021

Hashes

MD5 cd515ccd8f121fe16c324d30e354fd68
SHA1 5602c8f3bf1c1545eaf98c037615b2f52dca2451
SHA256 bf8aa97566f88892830656badc74117dd00268e78a13b2a305034e28979c1fba
SHA3 8f179a368585e9fac83bdbafded09d8e54535bd56b28f10f3387ffdee836f5e7
SSDeep 393216:WCTXtOUj5nRN+pQVDLEl48HphzEUpz/6gc7lN5emN7e3NeypTkEdtjSo:WCztf5nfGQVKphz9pj6Rpemo9LpX3D
Imports Hash ffe3cc63e5a1efb4d2f4cc004c584646

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 7
TimeDateStamp 2016-Jan-14 11:26:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x8a00
SizeOfInitializedData 0x9800
SizeOfUninitializedData 0x25a00
AddressOfEntryPoint 0x0000414F (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x51000
SizeOfHeaders 0x400
Checksum 0x12dd890
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1d1c4acf5293f85c261f8fb875cd51ee
SHA1 c368c16995455f4b67ebd2a6a7887937d4fe29b5
SHA256 a9a24a183f6c4b954bf35139a9175349edba073a006e7e74aa940edc12b907c1
SHA3 ef8462bb13515410a12d25edf8f959c0f2ebd859752232ce3f05585a5ce70f82
VirtualSize 0x894c
VirtualAddress 0x1000
SizeOfRawData 0x8a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.02599

.data

MD5 27e012e26d45935fea074258b60c8610
SHA1 8a5ec79d780c1d07b6a1258cdb8a6c86566eb3ec
SHA256 b98f30ce6c87f671d2d6aad6298e24d7bd6933b962f49b01c7cb0f1fcfbd25a9
SHA3 daa32ed3bd859fe7b7cde820598ac5b52f30ccbd8b0607b9dffd93958d8a4383
VirtualSize 0xe8
VirtualAddress 0xa000
SizeOfRawData 0x200
PointerToRawData 0x8e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.61136

.rdata

MD5 dbd31467672d55f2d52b92dbb50266fd
SHA1 769048305e974b7af1193493af9adbd16341a483
SHA256 32f2f8929912d0024218e28ced421d1bb5d9b6bfbf12798c65c3cf475beeb9d3
SHA3 d5482fd5626ad6077fd77767cb0015dedbab2825ff7e78f834f04c8528ed75f4
VirtualSize 0x6aa4
VirtualAddress 0xb000
SizeOfRawData 0x6c00
PointerToRawData 0x9000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.22298

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x25a00
VirtualAddress 0x12000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 706f0154352b0c7904f923b5c884a308
SHA1 eaaf19b50945fe9fe1fcf2b4e7344833f71ea1ec
SHA256 79e6980bee7002ed6ad8b3d472032d44c7df125388ddc4af44900254099fd709
SHA3 aa5ffaa16e23466236d4b50512e6c16ce95b948aad4bf6caf9546aaf8bae4378
VirtualSize 0x1298
VirtualAddress 0x38000
SizeOfRawData 0x1400
PointerToRawData 0xfc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.20415

.ndata

MD5 0f343b0931126a20f133d67c2b018a3b
SHA1 60cacbf3d72e1e7834203da608037b1bf83b40e8
SHA256 5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef
SHA3 6841b2c10aa6e5f7a384143e4de58fbc9aa28a4b742e9ad4ed14ba148a723a43
VirtualSize 0x12000
VirtualAddress 0x3a000
SizeOfRawData 0x400
PointerToRawData 0x11000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 e2e2a7ddbf30b6dec86a629ec74c580f
SHA1 eb09eda8fa9e4e16e69c04d8b4efd84d9dabce27
SHA256 4d24fcff06d0665c2c847d18794b6cd0516866f300cab6164da8d05b2e4c5189
SHA3 5ce1c6fea97a2730aa364ea06dfbe1c49394cefaa420a19dc4f85be9d61c1d7e
VirtualSize 0x4e40
VirtualAddress 0x4c000
SizeOfRawData 0x5000
PointerToRawData 0x11400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.67842

Imports

ADVAPI32.dll RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
SetFileSecurityA
COMCTL32.DLL ImageList_AddMasked
ImageList_Create
ImageList_Destroy
InitCommonControls
GDI32.dll CreateBrushIndirect
CreateFontIndirectA
DeleteObject
GetDeviceCaps
SelectObject
SetBkColor
SetBkMode
SetTextColor
KERNEL32.dll CloseHandle
CompareFileTime
CopyFileA
CreateDirectoryA
CreateFileA
CreateProcessA
CreateThread
DeleteFileA
ExitProcess
ExpandEnvironmentStringsA
FindClose
FindFirstFileA
FindNextFileA
FreeLibrary
GetCommandLineA
GetCurrentProcess
GetDiskFreeSpaceA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFullPathNameA
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSystemDirectoryA
GetTempFileNameA
GetTempPathA
GetTickCount
GetVersion
GetWindowsDirectoryA
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
LoadLibraryA
LoadLibraryExA
MoveFileA
MulDiv
MultiByteToWideChar
ReadFile
RemoveDirectoryA
SearchPathA
SetCurrentDirectoryA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
Sleep
WaitForSingleObject
WriteFile
WritePrivateProfileStringA
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
ole32.dll CoCreateInstance
CoTaskMemFree
OleInitialize
OleUninitialize
SHELL32.dll SHBrowseForFolderA
SHFileOperationA
SHGetFileInfoA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
ShellExecuteA
USER32.dll AppendMenuA
BeginPaint
CallWindowProcA
CharNextA
CharPrevA
CheckDlgButton
CloseClipboard
CreateDialogParamA
CreatePopupMenu
CreateWindowExA
DefWindowProcA
DestroyWindow
DialogBoxParamA
DispatchMessageA
DrawTextA
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
ExitWindowsEx
FillRect
FindWindowExA
GetClassInfoA
GetClientRect
GetDC
GetDlgItem
GetDlgItemTextA
GetMessagePos
GetSysColor
GetSystemMenu
GetSystemMetrics
GetWindowLongA
GetWindowRect
InvalidateRect
IsWindow
IsWindowEnabled
IsWindowVisible
LoadBitmapA
LoadCursorA
LoadImageA
MessageBoxIndirectA
OpenClipboard
PeekMessageA
PostQuitMessage
RegisterClassA
ScreenToClient
SendMessageA
SendMessageTimeoutA
SetClassLongA
SetClipboardData
SetCursor
SetDlgItemTextA
SetForegroundWindow
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
ShowWindow
SystemParametersInfoA
TrackPopupMenu
wsprintfA

Delayed Imports

110

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x666
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82633
MD5 b6bf70baab40fe438feff063bfb9ff6f
SHA1 7d4659d43e08d368ddacd31945872461c0b06253
SHA256 0e90a9e4b8f3a5bf990e8aadfd8096ad7aeaf1a4e032ac7b6395ce191d61c142
SHA3 cab98fabaf20118d9a8a4d2bcff4383a7291a0e04ff11a8690e71eed619c75e7
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.26612
MD5 0ec0a0948a526b9c7eebe39bb02b6b0b
SHA1 867b304f20fd74abeb5c30515837f1c41cd3bf8f
SHA256 d442adb90ba296c7e617d2f58d6fa6f308bcd8ef65e5e9c66db4dd27f93fcfbe
SHA3 5bc458755a2ca5c7475620389d9b6b67952973c4366c6777d45c969b8bc67cd4

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9993
MD5 6b224e01af48ec8e4c17a59d9534e885
SHA1 de787d2a1e840618ba2c7eb69d28f6966c404d1d
SHA256 50279c9885b490e74b49ac0273940b6e0891b62fc9ffb5c52e35422a694f248b
SHA3 71b543301bccda64ba61a27873c952890233e0cbec10e0b59245fc303bcfadbc

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.24459
MD5 ca82d899b1d402941b5c92ed9028cd95
SHA1 fb329ec4455d5caf1753305debcc14ab6ebb9015
SHA256 9da1013c864092e49c2676b3ba68a0d4513457d77d251730ed73cc5f4a4813b1
SHA3 768277223731ffdcb799e50961d0afccf23bbae54118d53b834617ccbd0c5cd9

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01502
MD5 05e60fd47096a729dda2aaa4ab05ebc7
SHA1 de8ec9b484fa4f565b14f55503c9cd95231b633b
SHA256 61f762babde9942f43ee97154b8734efeed0632a6ea778dc395793ae3e3e7507
SHA3 f8ba0d4a91389414904cc66226099f27f482055e90ba449e2396193f139713d8

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.16057
MD5 d9ee3a2962251a241bce41b0524cfc0e
SHA1 2ba919aaa7237367a158e4b95385ab1ee07643d8
SHA256 69e6579a37fcaec037634e7fecbfc6a26093ea81dc4bd555d8a12187d2cd0866
SHA3 a1699668464f7edf9a748dfc264f9d30e3c69a228be0a18cade30c14aa6c77ba

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34146
MD5 53482d364aa2d4ae7ca05199dad7651a
SHA1 ccb213408acc7f5ddb94753e6410be23aab5cedd
SHA256 ff06189b43a5c1d6cc5d1b7cbf6ab56b1157ec52807945d652274a211462cba5
SHA3 60659e39ef3f267c267093f8bc4c87ed61eea4ef96ac0f583184f580844573e5

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04232
MD5 636ad42555a835e3a94209043df4a45a
SHA1 c878613bda5cba6cb5769846e60229890c5df248
SHA256 491e52ded039ec6684277e6f1f820e288763ae6d20e682bcfffb6cee4518ac23
SHA3 4b79e60727e0f7be7495c59fb949e22bd753cff6e145e4694257a21a7b5dba8c

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62375
MD5 1d958df872e65e9a04f929c89155e3f3
SHA1 5fff638c5caa7a6f598bfbafd8d8e7fe4f5764cd
SHA256 e6065cad9c0f4a4c7ec1de33c05b192b04cb96ad6cfb0e2ae0188fcaea6ea7c3
SHA3 b29b01b665ef63d2e0f362ce3bf145b41d860ddb989398de87df16d48ac8483b

104

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x164
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71935
MD5 2de2fa53c2e2f329f3a995cc58448ddb
SHA1 f215410a91ec1e1e668b5f5a0568531e57015244
SHA256 22155b56f411d51b493246c84e5a72b48944455f474e5f168bbca41b063d4ae0
SHA3 6f54b0b6f964a3a9f7f29842299e997eacce92d6562364753c6df64c45631bd9

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x23e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.72007
MD5 4e06b9c226906d7d31f90453697d36c0
SHA1 5d9a8b5dd5fe583227a0ab81fba83d98c4eb5452
SHA256 4b8679b0520596391355fd3b18c8b5979337aaa321c322f951fde6c053a6d845
SHA3 c3546d405a8722220c4e5652e54350941e3f2cadc30fdfc258fe377d9fef6354

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x104
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84976
MD5 b756cf50afdc5a248bf9f3ff865177a6
SHA1 267b0f95a9f852b7af09e5d909a3febc24ca3ccb
SHA256 c47426270cabd4199bbff8e4fc363265990a8a935c023a8c7d6597a0378e5f5f
SHA3 1fb62d573cc8b6fdf137fd2c44249ba4f1c6d687bd878a786a395448d6069438

107

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.52183
MD5 6ffba239dcfcab2080195f23947b70aa
SHA1 bcda1ca8ee9bb9878bde83aa06c670bb5a4d5843
SHA256 a7e5ea849cb343e9b58de221aeb25c9dd4a3748070bfba879a30c4265fc39023
SHA3 a75544b4c3fcbcb32fe4e02d1a631e045b2e58516aa1065bb96cce681aea7030

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85566
MD5 1807dc5fe3cfb87e40df7c76d9703eaa
SHA1 460227de69e0d2e4c18384d6524f79a0a39c8f23
SHA256 64fd74a2dff360aa5de58a37eca25a95ca90314423c9d0b60ab6571957494b7d
SHA3 53411e23f44f08cf494211c5799515ef1100879de8f9a04ec2ae8ce4240c4563

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6691
Detected Filetype Icon file
MD5 e624f041c921d299a6da3a8c5f48f989
SHA1 ffa07c86ac3dac45398ee07b26610dfb5c99d8ea
SHA256 fed46e06346fb8f64b14c18408a82caf955929ac0e65151630539dc5bd194584
SHA3 b51d47dbe9cbe18b1f520275504256022a827f919672b081943ae45cd4ff44c9

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x280
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32325
MD5 ec472499449bc19c6c5746eafb111867
SHA1 1087f45538c2cbd756eb3ba5c3690bd0c7505d7b
SHA256 64725bb9fe46dfccd59b86e601e9b79dd0c34f2b549e1aca0fda353344c4cb6e
SHA3 af2327c10db61220c5cc9bbea7de4c5546dd0c9c476198acd9d369f4f8d399fe

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21582
MD5 5b2c3b4d5ac5e80ae816850d1dbd2e5d
SHA1 229b37cda6ce1ab9b7f0cc0214ebca119acf2b0e
SHA256 76e46ce5823e1f58e52ad45c6ea223503e86f1dcbe6c637c238cc447e6b5fb5a
SHA3 f834d72f9e02213fc49bdcfa9ccc07e1797f6c0c3b67f5fa06c32afabba94ec1

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 6.14.36.0
ProductVersion 6.14.36.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments https://cli.heroku.com
CompanyName Salesforce.com
FileDescription CLI Application
FileVersion (#2) 6.14.36.0
LegalCopyright 2017
ProductName Heroku CLI
ProductVersion (#2) 6.14.36.0
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
<-- -->