ce7e861ac1698054d08ce27060d2afc8

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2017-Dec-20 10:18:54
Detected languages English - United States
CompanyName fiki IT
FileDescription Collect and FTP McAfee Logs
FileVersion 3.2.0.50
InternalName HentMcLogs
LegalCopyright Finn Kisling-Møller 2016 - 2017
ProductVersion 3.2
ProgramID com.embarcadero.CollectMcLogFiles
ProductName CollectMcLogFiles

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowW
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegUnLoadKeyW
  • RegSetValueExW
  • RegSaveKeyW
  • RegRestoreKeyW
  • RegReplaceKeyW
  • RegQueryInfoKeyW
  • RegLoadKeyW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • CallNextHookEx
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetLogicalDriveStringsW
  • GetDriveTypeW
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Queries user information on remote machines:
  • NetWkstaGetInfo
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE's resources present abnormal characteristics. Resource WINDOWS is possibly compressed or encrypted.
The binary may have been compiled on a machine in the UTC+1 timezone.
Malicious The program tries to mislead users about its origins. The PE pretends to be from McAfee but is not signed!
Suspicious VirusTotal score: 1/64 (Scanned on 2018-03-23 05:32:00) Baidu: Win32.Trojan.WisdomEyes.16070401.9500.9814

Hashes

MD5 ce7e861ac1698054d08ce27060d2afc8
SHA1 b62a08d95c3c84f17965e3bcb726479671187871
SHA256 5e4c5987bf161eebd78b63e7229ed58eed874bdf7c867f2a7d68c58d45a75923
SHA3 906a9b1d421d3a76fdad89712096851c4d63f0341cd5bbfa3cd978de52d62968
SSDeep 49152:JgSKLNwSxGVBzFZwjmTSYMuZyWET8TcvS3zFIt:8GcjmMuZ8TP63mt
Imports Hash f48cfa8c4166264ff15bf15aa7475ab8

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 11
TimeDateStamp 2017-Dec-20 10:18:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x2f8c00
SizeOfInitializedData 0x8b800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002FA4A8 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x2fb000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x3a5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9ad2c5b607b5b596862841a47b093e8c
SHA1 da1fae855eab1dcdfd94a8c9a39636350299292a
SHA256 db5a1531e6b85d5192d5a89360f9345baa42eea6285453f961c499449d2c381c
SHA3 f45c914766ff3b2ee29a936bd369d33c6da0a2e465b5fe87bed2db13ea39853f
VirtualSize 0x2f652c
VirtualAddress 0x1000
SizeOfRawData 0x2f6600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.43744

.itext

MD5 82f75cdfc722b08e4088971686a3500a
SHA1 15e40a08436f761bb38c2d57f94b024b8322ae0b
SHA256 c3dffde9be92af5b9dc5c7bc6d77b2c9d4d0f2fde91c2f5f61d8476db90c989a
SHA3 97557b1f3f6ca4298ed64a673088165f20d40622338cfad283293b0a35de8099
VirtualSize 0x24f0
VirtualAddress 0x2f8000
SizeOfRawData 0x2600
PointerToRawData 0x2f6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.14913

.data

MD5 381f2dbe48a535fd9acbfab5fefb8dec
SHA1 981aed1154084b18c6f9338c83b481427ccc5e14
SHA256 26182b1c753852ee8302feea1d00848f7dd20770d1c02fba26986385a39331fa
SHA3 ef82244099a058ad4676810a3c86a755bb61ad3fb381a3eefae2bb2d841f62b2
VirtualSize 0xec58
VirtualAddress 0x2fb000
SizeOfRawData 0xee00
PointerToRawData 0x2f9000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.109

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1a088
VirtualAddress 0x30a000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 de701d5eec9001426837e920e77acc8f
SHA1 639c36d27942d50eb5676370c18e192fb40aaf74
SHA256 0f58d6430b5b942ae70665ac16229b47cf3761cd981272291783376485e02e7b
SHA3 80dace4765efa874faa7d4e16fa207ba47d57cecf1616ccbf0007dfd3efc0730
VirtualSize 0x3cf8
VirtualAddress 0x325000
SizeOfRawData 0x3e00
PointerToRawData 0x307e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.05777

.didata

MD5 a8d62641eda9e0a0e8b5c7f133dfd0e1
SHA1 f830e8d0c14c166c5c689d63602e5a0561e85881
SHA256 a2c779728473f112a828ee13dcd99f3a2858141c73924e905fb3bb21a8ca8e7c
SHA3 2f11b181c30765db627c30813b97534da544ff533395515e4e55af486b83ac24
VirtualSize 0xab8
VirtualAddress 0x329000
SizeOfRawData 0xc00
PointerToRawData 0x30bc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.90356

.edata

MD5 384aacca94a074853d1868209b20f5fb
SHA1 faa60bc22d609424174cb662cf217890a50c0741
SHA256 d373f7da7d7ee85ce010d127b3a286f5ade991af828fa5846ecff27f706970cb
SHA3 7e4bd770533a996920de4ed2e5ba067ec22ea8ddc99f89987b774d65d467d809
VirtualSize 0xa3
VirtualAddress 0x32a000
SizeOfRawData 0x200
PointerToRawData 0x30c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.0388

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x54
VirtualAddress 0x32b000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 61627196d17a62e81a93b2ba64d3c9db
SHA1 eb0e61d1b0610eece03c65823bef1c45c4fea123
SHA256 cac32841290597371c61071278f348375b8bd26005e6664e86cb67a5492f6986
SHA3 35a3bd941752e5eedf7f477db05c9d731ef69c0890acb61867e7fc25abce6b99
VirtualSize 0x5c
VirtualAddress 0x32c000
SizeOfRawData 0x200
PointerToRawData 0x30ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.35053

.reloc

MD5 7bf53a819cf5fd84f1ada54ab15557c8
SHA1 42e3a2f7906ab28f361c200c681fed0e7ffbb213
SHA256 f566f68ae2d5e2d8d230716ed0f3726e33d3ee97aed6a2d606c6f55f9b1d5a9c
SHA3 ed8e1c02ef6c06e41ea9622632d123ff44524e7a13d7460c6df185eba9ad0ab5
VirtualSize 0x42e04
VirtualAddress 0x32d000
SizeOfRawData 0x43000
PointerToRawData 0x30cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.70701

.rsrc

MD5 715a72bbb835f39973ca4094a46c1f40
SHA1 32c3adc5b2a58944530240e82148fd8a637abdbe
SHA256 6206974d262b49faba4abed2d2a2e0439e05a62583803bc284217f8a39975cdd
SHA3 e3cdf908cbb82cb87235940ce4154fa690c7cdc5a71b586ded94e992ef279af8
VirtualSize 0x34c00
VirtualAddress 0x370000
SizeOfRawData 0x34c00
PointerToRawData 0x34fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.35943

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll CharNextW
LoadStringW
kernel32.dll Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsDBCSLeadByteEx
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetConsoleOutputCP
GetConsoleCP
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
GetFileType
GetFileSize
CreateFileW
GetStdHandle
CloseHandle
kernel32.dll (#2) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsDBCSLeadByteEx
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetConsoleOutputCP
GetConsoleCP
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
GetFileType
GetFileSize
CreateFileW
GetStdHandle
CloseHandle
user32.dll (#2) CharNextW
LoadStringW
gdi32.dll UnrealizeObject
StretchDIBits
StretchBlt
StartPage
StartDocW
SetWorldTransform
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetRectRgn
SetROP2
SetPixel
SetGraphicsMode
SetEnhMetaFileBits
SetDIBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SetAbortProc
SelectPalette
SelectObject
SaveDC
RoundRect
RestoreDC
ResizePalette
Rectangle
RectVisible
RealizePalette
Polyline
Polygon
PolyBezierTo
PolyBezier
PlayEnhMetaFile
Pie
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetViewportOrgEx
GetTextMetricsW
GetTextExtentPointW
GetTextExtentPoint32W
GetTextColor
GetSystemPaletteEntries
GetStretchBltMode
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectW
GetNearestPaletteIndex
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileDescriptionW
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetCurrentPositionEx
GetCurrentObject
GetClipBox
GetBrushOrgEx
GetBkMode
GetBitmapBits
GdiFlush
FrameRgn
ExtTextOutW
ExtFloodFill
ExtCreateRegion
ExcludeClipRect
EnumFontsW
EnumFontFamiliesExW
EndPage
EndDoc
Ellipse
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreateRoundRectRgn
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateICW
CreateHalftonePalette
CreateFontIndirectW
CreateDIBitmap
CreateDIBSection
CreateDCW
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileW
CombineRgn
Chord
BitBlt
ArcTo
Arc
AngleArc
AbortDoc
version.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
kernel32.dll (#3) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsDBCSLeadByteEx
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetConsoleOutputCP
GetConsoleCP
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
GetFileType
GetFileSize
CreateFileW
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
kernel32.dll (#4) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsDBCSLeadByteEx
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetConsoleOutputCP
GetConsoleCP
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
GetFileType
GetFileSize
CreateFileW
GetStdHandle
CloseHandle
netapi32.dll NetApiBufferFree
NetWkstaGetInfo
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CoUninitialize
CoInitialize
IsEqualGUID
comctl32.dll InitializeFlatSB
FlatSB_SetScrollProp
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_GetScrollPos
FlatSB_GetScrollInfo
_TrackMouseEvent
ImageList_GetImageInfo
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Copy
ImageList_LoadImageW
ImageList_GetIcon
ImageList_Remove
ImageList_DrawEx
ImageList_Replace
ImageList_Draw
ImageList_SetOverlayImage
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_SetImageCount
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
user32.dll (#3) CharNextW
LoadStringW
msvcrt.dll memset
memcpy
shell32.dll Shell_NotifyIconW
winspool.drv OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
winspool.drv (#2) OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
kernel32.dll (delay-loaded) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsDBCSLeadByteEx
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetConsoleOutputCP
GetConsoleCP
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
SetCurrentDirectoryW
GetCurrentDirectoryW
CreateDirectoryW
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
GetFileType
GetFileSize
CreateFileW
GetStdHandle
CloseHandle

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0x3291c0
DelayImportAddressTable 0x3291f8
DelayImportNameTable 0x329300
BoundDelayImportTable 0x329408
UnloadDelayImportTable 0x3294dc
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0x30d630

__dbk_fcall_wrapper

Ordinal 2
Address 0x111c0

TMethodImplementationIntercept

Ordinal 3
Address 0x65958

WINDOWS

Type VCLSTYLE
Language English - United States
Codepage UNKNOWN
Size 0x8a99
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.82919
MD5 644aaeb9bac3f254e111cf10564e05ac
SHA1 49bd4f13cd993397acf933dfae960b0506bad131
SHA256 b7f62785cd661fd5f71545028453c73e36f4394bb34341e04fb71da80e81ca76
SHA3 481c4f6555db516cbfd1e96d33aa59d7a757ac6a5d0973af1e3d93810bb3d9ee

1

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.61679
MD5 c68fb06fd82eca9bfbf1ac7bd2c9140c
SHA1 ed6692f8bc77ea73fad92d754ede56781769ea23
SHA256 30df4ddb7d7ff020b05c161b16bafa7002c89871d8b05d132b9c06af0a21b693
SHA3 82c58a119e8e2a673482c184b659246eef0213f392df7af92269c62ff73d66a8

2

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

8

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.93773
MD5 588417a2ddd5cfb10a5759f7434af3b8
SHA1 bd394310bc376e6675ef88564d84f3a09439be25
SHA256 751c38a4553aea289bf93e5a98dc30be4e13874cae8a3d2f9e332e8a0d4412ff
SHA3 c209091765de86d873da3f41a9817daf4da4b95f7e52d56671db13942fc72f54

4057

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xc4
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.90719
MD5 4c81dde09530f11a521470120487c049
SHA1 82759c386206fbccdf4ae570263b484735552164
SHA256 1606e806fd1303484a73fe1d69cc869e0355eeacbbfcb3555bfe335f3f779b94
SHA3 3949d7822c2a19e6a82183bd2133b6308720cce9c587c7fc3130e09e5991a8f3

4058

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2d4
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.35488
MD5 2e8cd64f4609c68ecac8217107a2d062
SHA1 c7e7f5f94466d2e4ee6d26ca71c5a0e650454d00
SHA256 46985fe59f3c963bc13059ab9eb007b6d54948df5ca76b77806cf7de1498b914
SHA3 210f879e4bcd7c398fd2497c3cf4c01de93814faa3824c305502e1b4325884db

4059

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x474
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.37516
MD5 1ad25b6969b0a0d6bd6092ea9f10acc3
SHA1 22e5b285f6330bbe5acbc3745cde0115d37d3207
SHA256 87047e018e6b3cb593c1e3b9378233d6a1f713f2640ed5cebad272e4252464c1
SHA3 912e58267fcc290639b63b3c4841b6b3e5c86bdb6e2e21446e6ea8b55dc8de0f

4060

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x314
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.27225
MD5 fb162ff97d590c0203600970fb21719c
SHA1 08673538d5da221c8fde58024f86885055a11502
SHA256 62df953924e529419ee834bbb01ba6c5b8a31f7260e6560b7aa61f9a00315dd0
SHA3 486fb36b91e069d79e16b2e71956c5e6e475a554bba1fd3f76d41fe2ff2bb174

4061

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a4
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.28174
MD5 768cecaf7136fb31149a0534a457738f
SHA1 289b0ce9cf657819d7cc7a7afd1a88d30bc08c1c
SHA256 bdab102a686ddee6d97599d7d20191ba5fba25364483a74f26dbfc00bc9c7aa3
SHA3 3a147e2b46734c818c26b0f8cb1a919a8a5f267fb39a629bd61d07a1acece11c

4062

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x6f8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.31309
MD5 31b19a63bd13ea03f7e652dcfd9527be
SHA1 3952708dd9c3dc9cfe81783793b67951f3e02e88
SHA256 4d5a6092f75871de5d155a8a528d44f0b757287914d87a235cb556d035b37bb6
SHA3 6facfbcee3ce46f62f033ad28c57cbe8b2831f448d8a309459f24728ff99b21c

4063

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xb5c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.25247
MD5 eb50f012e4e438d731fb371f865cb4fb
SHA1 ea64e06b4dd8deca645c767b804d019b7aaf44c1
SHA256 505cd18806c45458fd944ca1aa04bef0df039f9eb2cd0fc79699654795bef7a9
SHA3 88189685c9d4ff97e3a73bb7dabca9b4e0c171a8d85d145023fd1df28eb8a6ff

4064

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x5e8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.28667
MD5 33d0cf49b39513136f4bf9f0f3587071
SHA1 6467cc5d70badfdbb1e6f20e79cbd3f711b57b9c
SHA256 7256edd63649aa1363e1050cca89482da848e8bb4e8a9f7d552105e98eba097c
SHA3 b56ec0e3d7d698543ab01ee4603bd78396842cf3c16f5879146a341fb31c785f

4065

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x588
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.28647
MD5 727d738ac8e4cb9d7687209bc8b011d0
SHA1 9867d8c2c47ba023365a2698d6118d785c41a395
SHA256 e5f84ad0609bd3e9b7f6be2ef7bcb2d5ce08407cab12736c30252066f214a5a9
SHA3 1ab1ae2a8100367446d24d617ecbf2de833cd765e44a9772dde509274284ef49

4066

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3fc
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.36688
MD5 81f42584b1edc24cfb02eac20d014479
SHA1 2e4421f9669e9cc9feb1f80650adf6fb24c63f25
SHA256 80e5c63c10ebd8facb0f5cd75db9d7b2ee7bf535a2721dd8003ede55fd1796e2
SHA3 99fde44a4d3d3bbb170a491fd8e5572c9e28627f6726888d23eb50b85c500d44

4067

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x384
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32298
MD5 4a7357df309f1ab269e75763e41b9248
SHA1 55e132001a0987bf2f4cab805b1351e7405db202
SHA256 794b18b83b1255816599b6dfd0b55521dda5355224e0bc6bef7dfe8cf8316d92
SHA3 b84a5dab96f3cbabe1f46968c17e72e9542830d17d3a4832444c562e60ca8991

4068

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x410
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32454
MD5 9e44d9d6436891797992dc62444748fe
SHA1 242322a9b6170c61b41a1db2ef4d33a536a8ab6e
SHA256 3551b8eb94e982c64c7446c21162f24ced9665db071df549118126668687a7a0
SHA3 7cc0a74081ad7b7449ea2ecaa8a6202d99a336e1f1e0c599b7e713beb7f75b2a

4069

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3f8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.37952
MD5 f766f4af0d96f4590c0b4bf74236ecc1
SHA1 49613f35665010998686dd4253dfdfa661ac6512
SHA256 acc7b7ae4f9329d1d43c51d43646c67d5bf5177c6d863d93d5e22a3b95cc922e
SHA3 ab009c47527cb36768d544c8df01f0b737203f4df6f3155ad70648b0e8a68199

4070

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x358
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.21279
MD5 5b4f64ed47cc2b8cee21b5d8b18130d5
SHA1 bce85ebe203c69c967ed349665c0d8b1bc00e8a6
SHA256 6f5c52c9b4357e1ee7cd03cb4f95911e0c21c9f9f6ebd8ca4641b989941eac5b
SHA3 20998d87de40ddf56a0c91a56ff43a862e00520e1cfb77e5d0115d35a88797f3

4071

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x394
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.22684
MD5 50853ebb1ad128302a940de306cbfa20
SHA1 1fb77f9dd39a6adbe64b4348ea02917cf4a74585
SHA256 95859b2bd694164a4b9806a1ae094bc79e0c54f69123072b59121e53aac6ad78
SHA3 98d3997fb33410f3ba6f5ac9ed862126d801529d6a4426b3a5f82f5ad8c71fbe

4072

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.39486
MD5 2626081429cb45e6a197b43ee982d2b2
SHA1 86bb68c0b0f6b2317e91cac4886b63a185794325
SHA256 33345be6feed267d26fbbf4563d00937423633d1e0c6e825894c77e17f899a12
SHA3 dbf4384370f8f1ec06d54c07853acd55725ec488a71e756d184d5cbc12f6521a

4073

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.30316
MD5 03c3cc6a5001ac3e2359c8bbea0d49fd
SHA1 be5b039666f8a8e00bd28afe65fd504cd0306af5
SHA256 453c4ddbee31fe857607d6c500976220539a2955cb7486ed8cda64a6992d84f2
SHA3 e252a673ff13ca32f35c45585f4a9100570dfe87bbec0edfbd79d78396a0d553

4074

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x350
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.26303
MD5 10dccb4417f15dbc5b67d7ff4df2e0fd
SHA1 6c3469173c000f3aa14194bd937e8279fa3dcc3f
SHA256 cba04d515243c55fd8c9655eeeb64a3af2bf425d3a52a5895eb8b4725a6be63b
SHA3 3fce79f403d42d1835975f685d27d580306e9cd3400d8c528f5b26256e44b829

4075

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x400
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.31326
MD5 5db47c4098fd6b87b6c1a01debcbaf60
SHA1 ff9c35f45761f6b3ab22e0da54e3c5489ad7109b
SHA256 e9aa0fa1982d34d56244f6f4a3c49cb4ce2996bb15638bc5721ca166b68a123d
SHA3 c23e3423c81cafbaf263989584c76fd90e777b40dfdbb673328d556264b2fd18

4076

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x10c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.45391
MD5 855a2a1c060f0f6a8ceb053339b48568
SHA1 9f36737acaf27ebb0e6e024e8c59940d0ec5bf41
SHA256 671d9a5e95a740c120a0fed4f5e1c1504a603a0d15e238859c72db99a72d3e4e
SHA3 a50b2933fb632ca3936fbfce43cfdd633c3175873ade740c37d2676e68fd1519

4077

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.40678
MD5 551790688117d8a4e47314298326697c
SHA1 93b51bd46ff30b032972805f78c910115a578454
SHA256 7c7d3cbecb7f71c5e43ef57ccfae7b00d71bea4a75717790da936f92c392d776
SHA3 49dbf1eef53c6a1ff4a7bd233104da01e16352ddb502c2041b9aa7d0af8ed239

4078

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e0
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.35084
MD5 02105fed6c29dd443ec4e5c0a204fdf8
SHA1 afb6ec81f03f10d3b8b49cb5f398be3239d9ac31
SHA256 f2ad4ac32d6b05063c2750c66c78f836f8e2a92bd92500de6ddc3eb5749dae36
SHA3 90273fcf3a682bf64e40ef1de92cf9f179a5f18be1648ee7abaad4f6d99821b2

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3e8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.30099
MD5 211028577fca82d781ad1321767a67b1
SHA1 e3c53f704e44141e0a7aac05ca5f11442c096ad8
SHA256 4abc958ce35c83bfb8c828280e84ddf9928a0926299087f14a6d63ed405d2977
SHA3 d2e08bcec2932f5d8617dd84657610a398bf137a0e6b986c48fb47ea0357f444

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3d0
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.28134
MD5 b1b450e115e08e3bc06c73737973f746
SHA1 7446476580e8a603d4a7d54d95ad79ee93b5400e
SHA256 f8b195cdae9404c398178b4e666af5d10ac6447e5e9d188877a123d57918952c
SHA3 63b1aa90890426ca6010f78c08a8ca2199a8c79150dba6ae358591c2d3fb3a64

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.26871
MD5 aa33fc8fb0dbaf8edbd6224d39f46447
SHA1 bfce9c34b39a1a1a658400fd0c5e6fe91f563f58
SHA256 59c7e5a35f77ed3401fbf0a6ba347a0a5b081f087b496a587ed7bc612b03ca50
SHA3 de7e332dc8787ecd639f7a5b7e6c168d696e2b9119c1273d247a34f7fc9ad6dd

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3cc
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32451
MD5 bdde6425fb7462034664a75239d19df4
SHA1 c3aa59e8a86b60ed3e04cf19323119e5f8f5c50f
SHA256 02c418bb6e0416619faaa92e41cdb4a8c21070feec4fe4ca8339fb73dbcd2f3a
SHA3 780eeb3c68cda480e830b404930e5ed731633218895f39ad97a0b76e5a00d096

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c0
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.48903
MD5 530f5138d65075b3a583d77849aa42ba
SHA1 2e0460322fc8951ae6a7e7df407531d1d666c5cd
SHA256 9147a6d53376a3835f2c237bd0e1570da458c5a9c26889571018a37d38b6faaa
SHA3 11494c8d9a1149096ece5531436d919c27ce87f3a3e3c372bc600ff815fbe4b0

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x434
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.27322
MD5 95039503a898d91da5859c1d625ae289
SHA1 dfb213d539dadbfddb5b026fed1feed8927636b5
SHA256 e6af1c2e2fd0868d5f5db69a8ae0ee44b37316d24738a565ff6e8e44818848d1
SHA3 954236203ddb23da7c5dc8317742a3b509cc7229bb26963905d22dbc747b1052

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x66c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.30286
MD5 6ae9d8c8c6a402b49f8a6588693f62e5
SHA1 46b47f3c2cb51b60bf83fced3dacd4bffc7ce439
SHA256 7c714c787c765fa7a5b3bddf1bb3bfd541d9a14980e7bdb565bf587d2befb188
SHA3 418a6ce2c8535bba8f84f7e825aaffee3417dbc85c9d69f2354f82e52e4adba3

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x448
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.18401
MD5 76d7c8337dff8dcd79280a92add4c21d
SHA1 2c9cd694b6520e2c81cf6760ab969ce4b9f2267b
SHA256 d431c2126c16afa86acede3f5bb29b7b0f9064d9c83ea788716b4b5c95da828e
SHA3 71e65887099203a00c0e1216f694134f4bec9fbf071d3509767e9fb04e2d7c62

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x34c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32654
MD5 e98475f23d563787a8f9dd291584a4fb
SHA1 2a1c26017bb0724a91343b5f90d954b69ed4dc12
SHA256 6d5c988887b3352a33fa61b6d18a0c5a1ffc7126ba842267f45896f6697c6974
SHA3 b819baf90a59ee82b4973a82d510f5f955db04be2c15e836124397a985f182bb

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x350
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.28978
MD5 003e2f86e097545b7910db128441a58d
SHA1 d34bd70154164523db6d46df662ab15fd819a1b5
SHA256 d302345447443a0a468e99432dc6ac37414475f9982245ccd8290000f9cbf75f
SHA3 f00f2e7760682ac6614baa6601c095e63fcbd1be3fd654e2ea02cfa69f30c97f

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x414
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.34769
MD5 82ab43e85bc735afbdf10f9a8197f28b
SHA1 db7f8bbbe4bc0cd30cc4207d7538c0021fea984e
SHA256 91c032eeb1cfd2d594bdcf96dd665c39b80877197d9f6aa1208ffd3299f01b15
SHA3 0890bf1a2c3381f709f0ff64a1b1d32806067aebc4fd60c6a1aebc717e6a0f04

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x148
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.30087
MD5 c252188606422991583f9dea8c7a8636
SHA1 2fff622b585356909842f9916e802f2cb9145fb1
SHA256 7542005a74103f4c52ac7cf93bba9cc0052a6fe6ced2a4724f3cf93ddb6a040e
SHA3 bcb69a19e5e591ee26b9ff195883dfc801680f9ca28bbade197952f4130d64e0

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.34889
MD5 41e84c55d83e38e1b0ccab4f95866254
SHA1 450faac12f2e13711bfc14c90b000d3cf66d9e5c
SHA256 e04403c92735b3fc70823791da7ca19ed2a76b68328a76743f07290479c44652
SHA3 5ebd657deaf91b038845ad4b68ebcec97e3c47da836a637a570e0d27d0a48024

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1f8
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.3829
MD5 5822b5b23e5754e3b050b0eff0407eb3
SHA1 72f85448cf4fe6f7c0b41a9c931d91706eadbf82
SHA256 9e5f1faa606494330030f5c13e152ab8237f25949156dd69b04f8a1c0f11b330
SHA3 5f4ed303a2a73783d08f4e86f3c53ed50974ee54f79fea4b1306f316e6c6a884

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x40c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32044
MD5 f99c1adba81b46ddaea9a92461239d73
SHA1 aa89678f64327ecf1e9acc5d34debcebf8067c9b
SHA256 f9ed8263a2347eb12b140d3a1fc44a084e63b882d168e1a8ca77d33280ec2549
SHA3 c6857eeb8445b6222f495c6470f1bd8d066c48766484e4d7b2c0c180444bf8c4

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x384
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.32615
MD5 84466111b5f73a0bc891562c866018be
SHA1 0addd4c1953c3ce80a8b8200cf7e6e5f1539435b
SHA256 bdba9e6e967a308b2e7d27f009e36fc117e37da8eea35715e7033716cde61bb1
SHA3 a325bb8e3948f5dc93527d99a1140c6307100be613480dfee5c0fd7e775a9043

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x318
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.33405
MD5 0cce9b165b6494fb6ca6af28cf356fa8
SHA1 623aafe23d80141cd55f913fd059d56bfa5cc37c
SHA256 91a1a79d1c5d33e5840ae5847f3e4e9dda646078e189940237ba3840c2c899fb
SHA3 af4b6e56b3bfdc31ffd148c554a46c800b70824578fa7bd3bc28aaa7d11d24b6

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x31c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.23257
MD5 b7d943eaf113f1472e06777675f30a58
SHA1 e6f429dd8eb3563a1133b49753bbb4ba4ee6e37d
SHA256 4dba5636f99bf92601bfc496523154ee96c03f046da80edaaf2fdbd9242bb255
SHA3 6fd686d149ef19be41703a291ed5a6b6e7c3a38c24f3d7fb3a65b95370c2cb73

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.75
MD5 fa1c96712ab8720f82ad4095daf7cee5
SHA1 abe71b9873e6e494a7d9de8f1f1985c550fc6b59
SHA256 10ca7c7ba673f29383bc50d1becb5fbeddddecaa6109de088da9a94c74d4f1c4
SHA3 c3be1ab5871e6568c50c4c2dd73e7c8c09d9e9451b256e9871c537b6da54a299

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xd2c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 5.44955
MD5 6f16d477938398927c44da5c781565e9
SHA1 31238eaffe48370664525be5322a43eb2c272616
SHA256 ea2acfbc39bd45a7aba322839e637883fbc7f6817bcaf38f192ea65b5c340d9f
SHA3 92848475ccb17c76a46ffcb09a13f4cb37d04b8df42faf16656d139e226f597b

PLATFORMTARGETS

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 1
MD5 25daad3d9e60b45043a70c4ab7d3b1c6
SHA1 0e356ba505631fbf715758bed27d503f8b260e3a
SHA256 47dc540c94ceb704a23875c11273e16bb0b8a87aed84de911f2133568115f254
SHA3 47b7fb6f259cfa242dc8e381efb31dad613f8bfe5a8a92f524d1a0a7058c56dc

TFORM1

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x994
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 5.46459
MD5 0b45860c8e4246b428a53c056d7089b7
SHA1 bbb15aa48a3fd0a2ab83ea5eac8b8115b02bfeb3
SHA256 54cbbb91ca3a1a41ef03806101957890718149d500f9af6463d06e27f0cc086d
SHA3 271c51bb2cfb1b1afa9f56f1117ead7e4cf5d7fbddde3b0cc02c05a5397cc25a

WINXCTRLS_MOMENTUMDOTS_BLACK_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1179
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.77734
Detected Filetype PNG graphic file
MD5 d882dbdf5d03f98044ac74ec799a34e2
SHA1 90e76301c2e598e19e1abd0d39c4b1cc74d9b646
SHA256 524e0ca31725e52611f57998f42d4f52e6a8f8198375532f667bb227e5897a60
SHA3 101f3730508102bf42bb9d0988f15dbcbe218d455db1f9f184e1ff84be2224da

WINXCTRLS_MOMENTUMDOTS_BLACK_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x176c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.76083
Detected Filetype PNG graphic file
MD5 89e9689f63582ab8fcff9b0ba4ae6ea0
SHA1 faf8956f9e113c8ffcf643a9c8d5c0b52673154e
SHA256 f3892aedfe54e26f0e4f229588377e5a5a99b6362f91ce53087d7a19c2baa96e
SHA3 e3db53093868ec4a20c07ed35a1d50567484c64df1404835151e6afe01195139

WINXCTRLS_MOMENTUMDOTS_BLACK_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2cf0
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.83701
Detected Filetype PNG graphic file
MD5 0412024bcb2e0685b7dc1be59885e51b
SHA1 e36ac5f8a3c1c68dba8ff13f2a6bc30fa341402d
SHA256 3722859e93d4148bb6b81466379080049e757ad5e8fc2820751af5c26923a15d
SHA3 93b5af391d28d95a1e93f8e479a3b6a37917a6be1677ab9416646473e5d2f565

WINXCTRLS_MOMENTUMDOTS_BLACK_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x3970
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.7282
Detected Filetype PNG graphic file
MD5 17c37fceff648ae7d2d48da91eeca302
SHA1 3b962aef65917e32433b2bde64a2daa299360d91
SHA256 d71daf885a730d5dcd16abe52a94534290a268a1500295dad05f6d358cb47a9f
SHA3 7ca0caa5d2e65b58ba6e57243b53ed89c23a48a533bb3992051a3cfe2a54dc76

WINXCTRLS_MOMENTUMDOTS_WHITE_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1403
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.82814
Detected Filetype PNG graphic file
MD5 2b21791ea84be17538c9689ddb699eff
SHA1 6008fba0615600cedc8493b330c0e9c13f1c1460
SHA256 cecda9052e5c0072dde2398956f518bc901a37d0ab8ac4873456f9e8e403c64d
SHA3 504d98d63aff2a660a6e9481a86202fbca4bf61eeb9d7ff8dd141b84b6e8a4dc

WINXCTRLS_MOMENTUMDOTS_WHITE_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x18ad
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.78366
Detected Filetype PNG graphic file
MD5 ac8637920d7abc08c61b61caa269bd53
SHA1 2684d1e405da7673a9ca5bd984c806b2d965c15d
SHA256 f039575f4fc31cedb0347a2f9c2818d561c259ed10dac360255776f0f4c0e853
SHA3 e233b74f5893b346850f736a76c563f46ecd6d08404a9fdca3115e682af61b4b

WINXCTRLS_MOMENTUMDOTS_WHITE_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x343f
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.83661
Detected Filetype PNG graphic file
MD5 bd2cd3e89e82d7916a35ef94eafddb97
SHA1 d67ca3fe8708874b0a4781872b5711fd71396740
SHA256 029d7a9a5c044a1e6304e68d70204420eb48084980b1c2023082b32897e67800
SHA3 254bb3caac5c14cf454e25e6e8bf044d54616cc28cea1d573657be2ba2a1626b

WINXCTRLS_MOMENTUMDOTS_WHITE_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x3ea6
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.71208
Detected Filetype PNG graphic file
MD5 a1fda5c18021febbdc70e95f56fc2c1b
SHA1 3831330b4522ab531cbaac1b7fe163731ce7c836
SHA256 d2844675eb4b8cd2eb25ed0a1120b71cd103c2cb02fb9302056096259ec38691
SHA3 fdd97476a2efafd8c23ede49ea0b0b5779373561b2c9eafeca37ea506cbaac01

WINXCTRLS_ROTATINGSECTOR_BLACK_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x509
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.77388
Detected Filetype PNG graphic file
MD5 37adfdc64e6db77a694bfd04b910facf
SHA1 de1675f695ddf19ecf50e69b26b165c0f2ebd3b1
SHA256 499b0f153daa27640c1211c8bb92c92acc0429bffe52c61476cd18e72d1d24a1
SHA3 b0c331129fcdf60c4591742584e4d76cd6b901ab4a97a18c4fde17f60c6435b3

WINXCTRLS_ROTATINGSECTOR_BLACK_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x64e
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.77975
Detected Filetype PNG graphic file
MD5 36667eedb00f081060095d03692b2e73
SHA1 27a944ba950d9539e908d1ead45077896834a45c
SHA256 9bfba3c2b3380a02be3d0255b7bf8c736917b23c28fe2635eaea565829ad166f
SHA3 b0d706d54500e426eb58152fa5ebe85bb89526af1d2ec888a856f035bd7b9523

WINXCTRLS_ROTATINGSECTOR_BLACK_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xb62
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.80865
Detected Filetype PNG graphic file
MD5 6c29b353958f2fc10263c1853a11842a
SHA1 3be46e4c363cc2b0fb7b2068fb8cb8645521e207
SHA256 c6ce0d60af2829d731b79aa9c97affea4b01ad6ea264fec3ff81ec3f9a890db1
SHA3 4886f3a0422dbe007575e65db5eb81df7cc0ddda594a9ba10372bbfb5a49f492

WINXCTRLS_ROTATINGSECTOR_BLACK_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xe43
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.77265
Detected Filetype PNG graphic file
MD5 51062090a1697db4045076d8f7ba786c
SHA1 97039cfd2541f3e1f28ec2848f5700118483c570
SHA256 e7e538e1c25a146c7183fbd6817825922154858bc20ca6177faac6b4de2048de
SHA3 86fdad75fd5e839df1420c27fecdf9ae5d2271119dfe3fb1854879cf886ae097

WINXCTRLS_ROTATINGSECTOR_WHITE_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x62f
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.80847
Detected Filetype PNG graphic file
MD5 6344267d150946642542130f80e863ee
SHA1 2512cee959b98898e18ed2c1b2d2dee039400fea
SHA256 77fc5d5d21b656746410ce349d6105e22d06ada5f4a617a6415813d4df441ac3
SHA3 1d933653af1712e51da3314e251b0c74ab56d20f03479ad0e3d5670a1505a427

WINXCTRLS_ROTATINGSECTOR_WHITE_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x6d3
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.79258
Detected Filetype PNG graphic file
MD5 aef3bbd2ea9c1b5f637b322b5214eb2b
SHA1 2a969d993d2cf8d2ec2fa2587823ddd4aff41cfd
SHA256 336fc147d295429335a873d3d83c36aa177ab1bd4c5eb7105f9abd92315a43b7
SHA3 80644606f13569ca93074f3ac536786cf600457618a7c273e7268d9778ebcaa8

WINXCTRLS_ROTATINGSECTOR_WHITE_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xe13
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.81895
Detected Filetype PNG graphic file
MD5 2dee3d28e4a13aab09d3924bf25f7dfd
SHA1 5225999940df7c143293fc4426e8fa84bba47736
SHA256 f735d7b665d7457dce3c5677da3bc5da2d55da0d9600a846f102052b8e9ef243
SHA3 7ad8c0e6157bd5ce177ac73e0e7a4b1226e4bd75091c94e4592e2e43d3e27b46

WINXCTRLS_ROTATINGSECTOR_WHITE_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xf5b
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.77384
Detected Filetype PNG graphic file
MD5 949f2ed6d4d3f5cdfd292e8b098ef2ab
SHA1 3c99fef7c85170ad187f201e299abc1b29db27dd
SHA256 de401d767c834ed47738466a68513ef3e31b21cbb7f8d6ec87c96f4f1d9caa2d
SHA3 dd3a399c1b091cb29ac798f4b8d5120fe76220d6d8070e297a90de641d1313f8

WINXCTRLS_SEARCHINDICATORS_AUDIO

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x26e
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.36907
Detected Filetype PNG graphic file
MD5 f697a68842cc763bbe21ca78456dcbc0
SHA1 7c9ca73740cf747fe8d393c71e42a7e99abca5d6
SHA256 e38d144564fa79cfe479107296fb66f616ea3263016366e7292919a0952f917d
SHA3 e0144def714bd324ed7238b77eafc2d4de332cc253de15bc4c844e864cfb092c

WINXCTRLS_SEARCHINDICATORS_TEXT

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x303
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.52279
Detected Filetype PNG graphic file
MD5 a4f8e4e60491193e16ef4c7a349f521e
SHA1 88b86f37a5e1886ac0072114ef5ca8bde5ca9419
SHA256 e9c387ce59a5f9aaca5747642057359eb17a1f26e5a96969a383d4aca75bed8c
SHA3 94d024ac253beec8699c3666603045112e5850b56ee1c8b33dc7157351b69554

WINXCTRLS_SECTORRING_BLACK_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x644
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.75684
Detected Filetype PNG graphic file
MD5 72af959063620fefef46d7450d0d8ee5
SHA1 005617ca9d68dd6300b81ae57f8852c9ba9a3fbe
SHA256 319e29848ef0d0ac620a182e2a110ef15ac1b479ba9d60ecd7ea150025631fa6
SHA3 372c6d04204d5c4b5605fc7515ed21f6caea728971832a430329593e2faa4df9

WINXCTRLS_SECTORRING_BLACK_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x823
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.76222
Detected Filetype PNG graphic file
MD5 e991069108598d266ee2e92e1a7f4e89
SHA1 86321149732f9345ec139ffbf2572f85a2b7e92b
SHA256 a36d591a0cde7cf7c5861de073e4d22eadf52ba336a263ae20b314973f57538f
SHA3 6c0315e702bf91b64005793b770a8f62479b384d474ccaac2ac8c441e5a45b4c

WINXCTRLS_SECTORRING_BLACK_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xe08
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.71504
Detected Filetype PNG graphic file
MD5 cccfc860bdf5d096b85ccf9dc0ddae22
SHA1 3aabc88a70f25b15a17d07746b16dafb3b3b8710
SHA256 7c49e2be6af69c8956a21399046219a56c83d52210d2cd181686c7b9283ba118
SHA3 7b347a40178365e242a781ab4b1228dca3d0fb3bec00ad2eaf37ecc1853b4efc

WINXCTRLS_SECTORRING_BLACK_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x117c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.54999
Detected Filetype PNG graphic file
MD5 1fc2a64f42f3949ea806c440d9063ab9
SHA1 1ed10727c587d28dfea9b446f19260bcbd89df5a
SHA256 dc5e84cbf7b6e4c680175fef4e196c9014679e142903e293cfcc3f1251e75b78
SHA3 8d92bea2ae92f5a501a2a3987d46cc7f78fa9543c9a5c6e9b44b0d58d95b0e4a

WINXCTRLS_SECTORRING_WHITE_24

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x787
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.74953
Detected Filetype PNG graphic file
MD5 30d81585f67c5d273d9f536c9a89103a
SHA1 fd9e5e8724d7415bf568a9fb4980e6ee3ab5308d
SHA256 18f5dfe840976df8b0460cd3c9f2b721fa8ce3d142dd87d7b56aaec2fe3a7490
SHA3 7a0e1ca30e6b28591bccd3d576154b5467beb7c951707a7a88b4be932ea3fe7d

WINXCTRLS_SECTORRING_WHITE_32

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x89c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.75246
Detected Filetype PNG graphic file
MD5 95a24e4f9732d59e2471b64d2e372c62
SHA1 a58f128ea6b435511400c135d158fc61823135d5
SHA256 ab07f6ae79aead9aee98716658cb5f6bed7974f49bc038b8dcf8d27e6d150d39
SHA3 89439e8eafd65e68036e54e70adf7ac1267a86831c83a5ca211f793f9710d271

WINXCTRLS_SECTORRING_WHITE_48

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1189
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.73253
Detected Filetype PNG graphic file
MD5 e4d31fbf496d828ebc8d223ec9ffc732
SHA1 7ec016ba9893277880806bc495b706274d1fe9ab
SHA256 cd5d6126b9eb7105fef22e3d3b4c15960ccf04945cad68b8d09c98d0bb3bc413
SHA3 d8655b818a3f826d4cb9c434a06625f4f7e2b2e4e1679ac2945ce009fef17331

WINXCTRLS_SECTORRING_WHITE_64

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1251
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 7.59365
Detected Filetype PNG graphic file
MD5 4fdb57cc5fc1f391b4e922ccf60f453c
SHA1 2878f655e7a46643bee0b413b4204ea497efca15
SHA256 530cc7f6e0845afc0727b030ff26ce151626be0a4e458fa47ebb917ed086cfe4
SHA3 22c751998d78357bd4521b6fdb2081e8806219185fd208346482e4696903c084

CAT_DRAG_COPY

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 b3dbdfe1835416bbc3f5065baca9aca9
SHA1 334d5af1355f6a13c35be4ad16e76baaecf209f1
SHA256 ec26c438d10e3e84ec855c47f07a176e6c11bbfae1557d526490711b80f087fe
SHA3 2409b439f48a139d3764b226eda46c6a629d5bd208991369ae0c85e37c17c71d
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x30c
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 3.41506
MD5 2d37aae5c0e33d3e670d779cb7322689
SHA1 416bd722debb3e9e5bd74317afaa27d51240508c
SHA256 f9329079d4da24a0352fddde8f269eff61878053a5956af884642083d9ee71c3
SHA3 39eece21511684bfcf6cfcbd5f46de05bace0eb5c1c27e986ef6bacf9ac9e2f6

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x5d9
TimeDateStamp 2017-Dec-20 11:18:54
Entropy 5.25594
MD5 0dfe1cd69be7369bbd354241808924e7
SHA1 94dce0272e41d7063b30674db9cd35521b211a83
SHA256 d7d4efe8c568889b69984f2d0a86f7fe030cfd17bca9f1e7a4658b9b06a31ff2
SHA3 22322b8a877d894b58bea8fd27dbe068b4a1c97b422d6c0bf39c3eaa2c8e877d

String Table contents

File name too long
Symbolic link path too long
Unsupported Operation
Unhandled Entity
TabSlidingWindowStream.Write: Not at end of stream
TabSlidingWindowStream.bsWriteChunk: seek failed
TabSlidingWindowStream.bsWriteChunk: write failed
TabSlidingWindowStream.Seek: invalid origin
TabSlidingWindowStream.Seek: invalid new position
added
deleted
extracted
freshened
moved
replaced
logging
Invalid Gzip
Bad CRC
Bad File Size
Invalid Tar
FCI cannot flush folder
FDI cannot enumerate files
FDI cannot create context
Invalid cab file template
Invalid file - not a cabinet file
VMS: request to read too many bytes [%d]
VMS: invalid origin %d, should be 0, 1, 2
VMS: Cannot open swap file %s
VMS: Failed to seek in swap file %s
VMS: Failed to read %d bytes from swap file %s
VMS: Failed to write %d bytes to swap file %s
VMS: request to write too many bytes [%d]
BBS: request to read too many bytes [%d]
BBS: New position is outside the buffer
BBS: Invalid Origin value
BBS: request to write too many bytes [%d]
Error reading archive
Invalid archive item index
Invalid archive size threshold
Unhandled Archive Type
Spanning not supported by this Archive type
Error creating Log File
Cannot load cabinet.dll
FCI cannot open file
FCI cannot read file
FCI cannot write file
FCI close file error
FCI file seek error
FCI file delete error
FCI cannot add file
FCI cannot create context
FCI cannot flush cabinet
Insert floppy
Spanned archives must be opened as file streams
Insert disk number %d of the spanned disk set
Cannot update an existing spanned disk set
Cannot make a self-extracting spanned disk set
Insert a blank floppy disk
Stream write error
Directory does not exist
Cannot inflate block
Invalid Stream
Error truncating Zip File
Failed CRC Check
Stub must be an executable
File not found
Invalid Local File Header entry
Archive does not exist - Filename is blank
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA)
This operation is not valid because the current image contains no valid header.
The new size provided for image resizing is invalid.
The "Portable Network Graphics" could not be created because invalid image type parameters have being provided.
Invalid file - not a PKZip file
Cannot extract file - newer version required
Cannot extract file - unsupported compression method
Cannot extract file - no extraction support provided
Cannot extract file - invalid password
Cannot insert file - no insertion support provided
Invalid Reduce Factor
Cannot insert file - duplicates stored name
Cannot insert file - unsupported compression method
Process aborted by user
Archive is busy - cannot process new requests
Insert the last disk in the spanned disk set
Could not decompress the image because it contains invalid compressed data.
Description:
The "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it again
This "Portable Network Graphics" image is not supported or it might be invalid.
(IHDR chunk is not the first)
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
There is no such palette entry.
This "Portable Network Graphics" image contains an unknown critical part which could not be decoded.
This "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.
This "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.
The chunks must be compatible to be assigned.
This "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.
This "Portable Network Graphics" image contains no data.
The program tried to add a existent critical chunk to the current image which is not allowed.
It's not allowed to add a new chunk because the current image is invalid.
The png image could not be loaded from the resource ID.
Some operation could not be performed because the system is out of resources. Close some windows and try again.
No FTP list parsers have been registered.
No Compressor is assigned.
Compressor is not ready.
Unsupported transfer mode.
Unsupported transfer type.
Destination file already exists.
The destination filename can not be empty
SSL IOHandler is required for this setting
This value can not be set while the client is connected.
SSL is not available on this server.
Start SSL negotiation command failed.
SSL negotiation failed.
Unknown OTP method
This "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)
The "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corrupted
This "Portable Network Graphics" image is invalid because it has missing image parts.
Transfer aborted
OnCustomFTPProxy required but not assigned
UseExtensionDataPort must be true for IPv6 connections.
UseExtensionDataPort must be true for NAT fasttracking.
Can not use active transfers with NAT fastracking.
Server sent invalid port number (%s)
No Site to Site transfers are permitted with a FTP NAT fastracked connection.
Can't use dataprotection on site to site transfer.
Transport protocols must be the same.
SSCN is not supported on both servers.
Can not set DataPortProtection after CCC issued.
Can not set DataPortProtection with unencrypted connections.
Can not set CCC without encyption.
Can not set AUTH without SSL.
Can not set AUTH while connected.
Transfer modes must be the same.
Maximum number of line allowed exceeded
The IOHandler already has a different Intercept assigned
Transparent proxy cannot bind.
UDP Not supported by this proxy.
Buffer terminator must be specified.
Buffer start position is invalid.
Cannot change a connected IOHandler.
No IOHandler of type %s is installed.
Reply Code is not valid: %s
Reply Code already exists: %s
Cannot use a non-socket IOHandler
Algorithm %s not permitted in FIPS mode
Unknown
Connection established
Starting FTP transfer
Transfer complete
%s: Circular links are not allowed
Not enough data in buffer. (%d/%d)
Too much data in buffer.
File "%s" not found
Not Connected
Object type not supported.
No data to read.
Read timed out.
Max line read attempts exceeded.
Accept timed out.
Max line length exceeded.
Set LargeStream to True to send streams greater than 2GB
Data is too large for stream
Connect timed out.
Cannot call TerminateAndWaitFor on FreeAndTerminate threads
Already connected.
UDP is not support in this SOCKS version.
Request rejected or failed.
Request rejected because SOCKS server cannot connect.
Request rejected because the client program and identd report different user-ids.
Unknown socks error.
Socks server did not respond.
Invalid socks authentication method.
Authentication error to socks server.
General SOCKS server failure.
Connection not allowed by ruleset.
Network unreachable.
Host unreachable.
Connection refused.
TTL expired.
Command not supported.
Address type not supported.
Directory not empty
Host not found.
Stack Class is undefined.
Stack already created.
Only one TIdAntiFreeze can exist per application.
Cannot change IPVersion when connected
Can not bind in port range (%d - %d)
Connection Closed Gracefully.
Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid IPv6 address
The requested IPVersion / Address family is not supported.
Not all bytes sent.
Package Size Too Big.
Set Size Exceeded.
Network is down.
Network is unreachable.
Net dropped connection or reset.
Software caused connection abort.
Connection reset by peer.
No buffer space available.
Socket is already connected.
Socket is not connected.
Cannot send or receive after socket is closed.
Too many references, cannot splice.
Connection timed out.
Connection refused.
Too many levels of symbolic links.
File name too long.
Host is down.
No route to host.
Too many open files.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Destination address required.
Message too long.
Protocol wrong type for socket.
Bad protocol option.
Protocol not supported.
Socket type not supported.
Operation not supported on socket.
Protocol family not supported.
Address family not supported by protocol family.
Address already in use.
Cannot assign requested address.
Invalid codepage (%d)
Failed attempting to retrieve time zone information.
Error on call to Winsock2 library function %s
Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
Connected.
Disconnecting.
Disconnected.
%s
Socket Error # %d
%s
Interrupted system call.
Bad file number.
Access denied.
Buffer fault.
Invalid argument.
%s parameter cannot be nil
A StyleHook class has not been registered for %s
Feature not supported by this style
Style '%s' is not registered
Cannot unregister the system style
Style not registered
Cannot call BeginInvoke on a control with no parent or window handle
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Cannot remove shell notification icon
%s requires Windows Vista or later
Button%d
RadioButton%d
Caption cannot be empty
Unable to load style '%s'
Unable to load styles: %s
Style '%s' already registered
Style class '%s' already registered
Style '%s' not found
Style class '%s' not found
Invalid style handle
Invalid style format
VCL Style File
Class '%s' is already registered for '%s'
Class '%s' is not registered for '%s'
Cannot open clipboard: %s
Text exceeds memo capacity
Operation not supported on selected printer
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Length of value array must be >= length of prompt array
Prompt array must not be empty
&Username
&Password
&Domain
Login
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
All
Clipboard does not support Icons
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
TIFF Images
JPEG Images
PNG Images
GIF Images
Warning
Error
Information
Confirm
&Yes
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
Unsupported stream format
Out of system resources
Canvas does not allow drawing
Text format flag '%s' not supported
Invalid image size
Invalid ImageList
Unable to Replace Image
Unable to Insert Image
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Observer is not available
Invalid date string: %s
Invalid time string: %s
Invalid time Offset string: %s
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid pixel format
Invalid image
Scan line index out of range
Cannot change the size of an icon
Cannot change the size of a WIC Image
Unknown picture file extension (.%s)
Unsupported clipboard format
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8
Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Argument must not be nil
Item not found
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Specified Login Credential Service not found
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Invalid Timeout value: %s
SpinCount out of range. Must be between 0 and %d
Timespan too long
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue
Value cannot be NaN
Negating the minimum value of a Timespan is invalid
Invalid Timespan format
Timespan element too long
No context-sensitive help installed
No help found for context %d
Unable to open Index
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Argument out of range
Input buffer exceeded for %s = %d, %s = %d
Invalid characters in path
Invalid characters in search pattern
The specified path is too long
The specified path was not found
The path format is not supported
The drive cannot be found
The specified file was not found
No help viewer that supports filters
Index out of range (%d). Must be >= 0 and < %d
String index out of range (%d). Must be >= %d and <= %d
Invalid UTF32 character value. Must be >= 0 and <= $10FFFF, excluding surrogate pair ranges
High surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properly
Low surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly
Length of Strings and Objects arrays must be equal
Class %s is not intended to be constructed
%s.Seek not implemented
Operation not allowed on sorted list
String expected
%s expected
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Cannot call CheckTerminated on an externally created thread
Cannot call SetReturnValue on an externally create thread
Parameter %s cannot be nil
Parameter %s cannot be a negative value
Line too long
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Number expected
ANSI or UTF8 encoding expected
%s on line %d
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Identifier expected
Unable to write to %s
Invalid binary value
Invalid file name - %s
Invalid stream format
'%s' is an invalid mask at (%d)
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
Invalid string constant
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
''%s'' expected
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
<unknown>
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
Too many open files
File access denied
Read beyond end of file
Disk full

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.2.0.50
ProductVersion 3.2.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName fiki IT
FileDescription Collect and FTP McAfee Logs
FileVersion (#2) 3.2.0.50
InternalName HentMcLogs
LegalCopyright Finn Kisling-Møller 2016 - 2017
ProductVersion (#2) 3.2
ProgramID com.embarcadero.CollectMcLogFiles
ProductName CollectMcLogFiles
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x72b000
EndAddressOfRawData 0x72b054
AddressOfIndex 0x6fbc18
AddressOfCallbacks 0x72c010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->