d01b789b535c91834b646750a431ba06

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jun-24 15:04:40
Debug artifacts D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExA
  • LoadLibraryExW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Suspicious The file contains overlay data. 5988622 bytes of data starting at offset 0x49800.
The overlay data has an entropy of 7.99997 and is possibly compressed or encrypted.
Overlay data amounts for 95.2135% of the executable.
Malicious VirusTotal score: 27/69 (Scanned on 2018-12-29 14:01:21) MicroWorld-eScan: Trojan.GenericKD.40712756
CAT-QuickHeal: Trojan.IGENERIC
McAfee: Artemis!D01B789B535C
Cylance: Unsafe
AegisLab: Trojan.Multi.Generic.4!c
Invincea: heuristic
Cyren: W32/Trojan.ZYVW-4925
Symantec: Trojan.Gen.2
TrendMicro-HouseCall: TROJ_GEN.R002H09KC18
Kaspersky: UDS:DangerousObject.Multi.Generic
BitDefender: Trojan.GenericKD.40712756
Ad-Aware: Trojan.GenericKD.40712756
F-Secure: Trojan.GenericKD.40712756
McAfee-GW-Edition: BehavesLike.Win32.Backdoor.tc
Fortinet: W32/Generic.AC.423184
Trapmine: malicious.high.ml.score
Emsisoft: Trojan.GenericKD.40712756 (B)
F-Prot: W32/Dropper.BJYD
Arcabit: Trojan.Generic.D26D3A34
ZoneAlarm: UDS:DangerousObject.Multi.Generic
Microsoft: Trojan:Win32/Skeeyah
ALYac: Trojan.GenericKD.40712756
VBA32: Trojan.Skeeyah
Yandex: Trojan.PowerShell!
GData: Trojan.GenericKD.40712756
CrowdStrike: malicious_confidence_90% (W)
Qihoo-360: HEUR/QVM10.2.05A9.Malware.Gen

Hashes

MD5 d01b789b535c91834b646750a431ba06
SHA1 c0759aaaeb6699f5ca7db99c285ec5b644f99438
SHA256 33045a644de0843fddb723d7de1fde6684fd5627d46e86891a9d9c2460520655
SHA3 9fe1908b568c9aa11f10568ab03333bf483f6dc3c743a664e6a4b529f45e727d
SSDeep 98304:aYK0xy8HT8tHBQx4CrTY/5KHAyQkLudPenDVxAHcswNAi/7CPCcPbruUpaduS:doUT8g4CrTmAFx0w627CqmfuUpadJ
Imports Hash f247d1ff7c13ddb9ec49eb86d120cfb2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2018-Jun-24 15:04:40
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x2e800
SizeOfInitializedData 0x1ac00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001D4F9 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x30000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x6d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7ae56743cb1c1dd0729dabc1fbbec9d0
SHA1 02a6ed439bbef233a55f98e395d00a48c8200c57
SHA256 f408e3c30454c88b2a7ecdd0653129107c0d4abffc89c44cdb2935d3a4d6620f
SHA3 ba7dd4675de550f8cd69a37fcfcc52470f8e31eebfab865a20f2db2965e5debd
VirtualSize 0x2e7e4
VirtualAddress 0x1000
SizeOfRawData 0x2e800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.70246

.rdata

MD5 7da63e6bffa0fa279d3c6eb4326c2e77
SHA1 91363eb6d65b35f831d4784a7c19db80a46c55ba
SHA256 419067bb4ef32323e5a86e477244633f0e3c2ec1eb7bd1d6eaed7eb283eaecc2
SHA3 f0471dfd337cb265e229ce54db65425ae2ba00e62db90048a34801735226d017
VirtualSize 0x9a8c
VirtualAddress 0x30000
SizeOfRawData 0x9c00
PointerToRawData 0x2ec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.12921

.data

MD5 49870b8f6c92b732d5bdaabfa8a62f09
SHA1 8cdbb99d7bb9ca16a151afb7a6ea8bd91c32199f
SHA256 ffe37965676db4ce026b6b88e67fcc955835116293ec789294b3eafe644e5bfc
SHA3 b0fb176fffc36743b821b60a1623ab73c3d4261824e10754c9ec1978a150c7b6
VirtualSize 0x203a0
VirtualAddress 0x3a000
SizeOfRawData 0xc00
PointerToRawData 0x38800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.23928

.gfids

MD5 cf920c8d17007b5704457275f243772b
SHA1 fcdea58d90f0c47c3cf20c356383e5bf45685490
SHA256 487bbeb872be17f55190fc0b099333e033514aefa576a3fd917d32a09441e237
SHA3 fd6be8cb2c9565204d07bbf5669cb9cd8ad6e305b60ced51968447096abf9e46
VirtualSize 0xe8
VirtualAddress 0x5b000
SizeOfRawData 0x200
PointerToRawData 0x39400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.0785

.rsrc

MD5 61ea61c101cb7bba31b8b6b7ddd33eb6
SHA1 bd03c63adc368e9de3697289d66d574721c3368b
SHA256 b8f78f8df4869b6879f32dee09d6e2ffa0090a2eb8b3824a4fb77ff6928fdfb7
SHA3 bc0d2043043978a39f71da49d577ddcc8affd69a9155b099e5580e8bb311cbd5
VirtualSize 0xe060
VirtualAddress 0x5c000
SizeOfRawData 0xe200
PointerToRawData 0x39600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.80069

.reloc

MD5 fbe01bd488742411bc1b9dd44c08c65c
SHA1 9df4544fd986332ababedae78c06581b44402227
SHA256 9dc9499fa3d3b80c2f1889c2c9fd72a115007769b715079b616d2483d7857687
SHA3 07c21cb6608497a61a72cfaa5108fdacaa9c66c9434b246b481a77451c4649fc
VirtualSize 0x1fd0
VirtualAddress 0x6b000
SizeOfRawData 0x2000
PointerToRawData 0x47800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.68222

Imports

KERNEL32.dll GetLastError
SetLastError
GetCurrentProcess
DeviceIoControl
SetFileTime
CloseHandle
CreateDirectoryW
RemoveDirectoryW
CreateFileW
DeleteFileW
CreateHardLinkW
GetShortPathNameW
GetLongPathNameW
MoveFileW
GetFileType
GetStdHandle
WriteFile
ReadFile
FlushFileBuffers
SetEndOfFile
SetFilePointer
SetFileAttributesW
GetFileAttributesW
FindClose
FindFirstFileW
FindNextFileW
GetVersionExW
GetCurrentDirectoryW
GetFullPathNameW
FoldStringW
GetModuleFileNameW
GetModuleHandleW
FindResourceW
FreeLibrary
GetProcAddress
GetCurrentProcessId
ExitProcess
SetThreadExecutionState
Sleep
LoadLibraryW
GetSystemDirectoryW
CompareStringW
AllocConsole
FreeConsole
AttachConsole
WriteConsoleW
GetProcessAffinityMask
CreateThread
SetThreadPriority
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
ReleaseSemaphore
WaitForSingleObject
CreateEventW
CreateSemaphoreW
GetSystemTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
LocalFileTimeToFileTime
FileTimeToSystemTime
GetCPInfo
IsDBCSLeadByte
MultiByteToWideChar
WideCharToMultiByte
GlobalAlloc
GetTickCount
LockResource
GlobalLock
GlobalUnlock
GlobalFree
LoadResource
SizeofResource
SetCurrentDirectoryW
GetExitCodeProcess
GetLocalTime
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
OpenFileMappingW
GetCommandLineW
SetEnvironmentVariableW
ExpandEnvironmentStringsW
GetTempPathW
MoveFileExW
GetLocaleInfoW
GetTimeFormatW
GetDateFormatW
GetNumberFormatW
SetFilePointerEx
GetConsoleMode
GetConsoleCP
HeapSize
SetStdHandle
GetProcessHeap
RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
TerminateProcess
RtlUnwind
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
QueryPerformanceFrequency
GetModuleHandleExW
GetModuleFileNameA
GetACP
HeapFree
HeapAlloc
HeapReAlloc
GetStringTypeW
LCMapStringW
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
DecodePointer
gdiplus.dll GdiplusShutdown
GdiplusStartup
GdipCreateHBITMAPFromBitmap
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromStream
GdipDisposeImage
GdipCloneImage
GdipFree
GdipAlloc
USER32.dll (delay-loaded) WaitForInputIdle
IsWindowVisible
DialogBoxParamW
EndDialog
SetDlgItemTextW
GetDlgItemTextW
PostMessageW
SetFocus
SetForegroundWindow
GetSysColor
LoadBitmapW
LoadIconW
DestroyIcon
IsDialogMessageW
wvsprintfW
GetClassNameW
FindWindowExW
MessageBoxW
ReleaseDC
GetDC
SendMessageW
LoadCursorW
CopyRect
MapWindowPoints
UpdateWindow
DestroyWindow
IsWindow
CreateWindowExW
RegisterClassExW
DefWindowProcW
PeekMessageW
DispatchMessageW
TranslateMessage
GetMessageW
CharUpperW
OemToCharBuffA
LoadStringW
GetWindow
SetProcessDefaultLayout
SetWindowLongW
GetWindowLongW
GetWindowRect
GetClientRect
GetWindowTextW
GetSystemMetrics
SetWindowPos
GetParent
SetWindowTextW
EnableWindow
GetDlgItem
SendDlgItemMessageW
ShowWindow

Delayed Imports

Attributes 0x1
Name USER32.dll
ModuleHandle 0x59930
DelayImportAddressTable 0x3aa80
DelayImportNameTable 0x383f4
BoundDelayImportTable 0x38b18
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

101

Type PNG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb45
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87356
Detected Filetype PNG graphic file
MD5 63486a769bbe3f49d5848b9c69734a25
SHA1 e48bd36c2f23c238206bdddf3ebb6d6862905710
SHA256 a91f4373ceebadfc70b3bd0758848918f928c3c76562e3d9d531574796fd9e9c
SHA3 7e9dc73ef6ee0ce127eee80c5daf334bd98ed2d2f262376ed7760866816d815b

102

Type PNG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x15a9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.80129
Detected Filetype PNG graphic file
MD5 e6ccfb6d9ffd4e1a907a47761c64bd79
SHA1 d6a2994dedae3527a878140aa60dcaa087b90445
SHA256 27d3a1a2da49dc535cc10806abaae9dfa49e4f5f44a40540ead50e065b99ca68
SHA3 11423dcd0ab4c11695ad71f56e4fcdfc4b20a38cc6ac653ab7575f7dd024d0e5

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.97409
MD5 c357a2678e5234d9d0d93b80fff556eb
SHA1 f575af42db3045470df63787d678b61b3f696637
SHA256 573c9bd29dea90ed994bad702ec79c41e98e1c8fb54b7964ec05ed1e64efefd1
SHA3 74ecef77dbd4ce361c6226d842d49a2c28a318af22f9dc81baa2524ab14bdda9

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.10026
MD5 e55630d67fb64ba59f51d8266d31ff01
SHA1 b7b5b8c32742d7c3e2ef39fd5432eb22fd378048
SHA256 85fe3ae58f9c30ca21251517164585fbb10f8490f0790dd15859438c1ca59729
SHA3 9282845cf7d52c29ac721534751a56a1fcb3e2c625c186a4934cd6956ba317a7

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25868
MD5 73a958fb4dece366b7cf2f80de03528f
SHA1 f091434598195479caeb051cd932b64076d7840e
SHA256 32bd1078137a5367d204b941cf6d970abbe1a520ac9e54b63d56f7e2f8a326ae
SHA3 932882004db4780e9e260450182e91296e4ade6d07f3e1a3382f5d80b2b7b86e

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02609
MD5 e768244eed218cd473905b37afb09cce
SHA1 340c145b2b5a4393aa4b09bbdda14a84259b6c7b
SHA256 6e296a4f88254d5c4e4f1871f425e8d9c5ca08846d5c90cb3bc9ceee89c91ae3
SHA3 f0a0dda5ab093a3211b8d4608dec0f9fd7ebcad96d357a449ae4b74d12051f4b

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.18109
MD5 45fbeb8fc40ffa66db2f901c50a7ab8a
SHA1 d302538cba2599add5c8d0070cd2c5b3f077cf6a
SHA256 574ed44e93b206d0b5b4354fba244af5a573796db738e34ca37a6e061b0fed3f
SHA3 da977a245bb5f556f77ef1ddb5b59f96e6fc9225db7d2048eadc5441a692ae48

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.04307
MD5 da87510c3aabe7851c7c5d0493dbb14a
SHA1 4c59f617d7cebc871df1417f61c64a98556eda99
SHA256 91b392c6bd14fa9d9bcab2afc2b37825779abae8b32443ce0a5ee0d9793f8fe2
SHA3 582d345c2dd3b6dfa7daef53c039faa49be1b9cc8f749b08ca35fe6493b3bb46

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3d71
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94547
Detected Filetype PNG graphic file
MD5 7b678b6cb96c363d9e0adc3a1b3b4893
SHA1 c7e817672b686eb66bf5907da1efaef1dec8e06e
SHA256 6f86849b026f0c45c0c8a1145048960bbdefdaea3beac030f114b1ff16057994
SHA3 350e01112644403dd6d571343e7b00aa3d24e1b6fac796956f564355dde57fa9

ASKNEXTVOL

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.02876
MD5 3ee25eea0e6cf16e46690372af7e0308
SHA1 ae60fa327324766e67edca5e559b956d9e493790
SHA256 22500ef2a135d37bd2c621829dad1552d50016b453b1997d04e615e0ec1ef216
SHA3 dd6073aa6a8bffec51afbc9cb9829174fc12e84a7e782cd392ddd84192eb2515

GETPASSWORD1

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.85959
MD5 ab1e159c891c85ffa2ff4e42dbdce0b2
SHA1 45f99b8d53de4257a170fca85279f853bfb1afc5
SHA256 f7b702c1128f2227f654cc2dbc50a77ddc3734840ca4df27ebf584a6a0550e7d
SHA3 0e0ba16bea1ffe195602dc13ef069146c0ce7e9b8d0f7ddaab2a8ba45b015ecd

LICENSEDLG

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xf2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70073
MD5 350b91b0ea3545d6ad49f0367e9a04bb
SHA1 5cd337b363aab7ac673ccbcef4bd7a0976017063
SHA256 45cee74bb0ad2163281ee43d7735874b78c9ba6d7f5ea17d1a5ab7dbd1a1fd88
SHA3 69001591be0330e0a9b9207fabe921342465d6552ab1531152793e7e30473181

RENAMEDLG

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.64483
MD5 b6b4b2e3f4069b4f1608259cf4467df3
SHA1 ac512eaaff83037d463771b91c6d13fe3c7c514f
SHA256 aade63bc86225019a3b2feddeacf077ae506708de985057683c52e8557b75a8a
SHA3 f88c7e9c8bdb0139e30aeabcdd63dc3aa81c6077ef36a194c6221e871d2a2d80

REPLACEFILEDLG

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x318
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81741
MD5 780660c74ba3dc217087a15ad3d00bf0
SHA1 77200416c2ee6c9ddb1ce77950819befa7285e9e
SHA256 78b15cf144efe21e09226309dc2f9ce02b760613f0c7751612e521bdc0251582
SHA3 c5c4f2808e58723d29ce52ca74e35dc8b254763f8487f6b6242a6a71a881e917

STARTDLG

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.07801
MD5 59dd2a53464fdebd4dce6dbd784d5a0a
SHA1 ed0d3337ee64ef5608fe043d288d2fc07d4f8103
SHA256 4542776fba1ca386e3dbd8d7d53d3f43fb0679acef9e06f73aa81d25a366401b
SHA3 b6d79a6a4bc545b09588c67b5a9fddf325009814b064a241a27dadcd908e2e1c

7 (#2)

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.66634
MD5 84a2aa6fb93d661b02dd9fae67ce46a4
SHA1 a0d1a1952b83298a000a8ba5977f8efc4c86051a
SHA256 ec2cb06bbc07bf68507a8f11833a113290c501e50326464bcea8d04df617731a
SHA3 19a6131e2b7854011efb80a854c3796528dc49310847d92b644e7d8d7287ff82

8

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.71728
MD5 a2aa034f25589077320a2cdfe5e79159
SHA1 786c0972867d2256fd9fb4da7c434e92490307a4
SHA256 73a938be272bcf485024a2f1bd64de6cd171d1b2e382a71a6d5265bbd0a27f51
SHA3 85ce382c4586156f28fbdb295da379caa92ac7faa66324863d7cc9bd0024fefe

9

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.74776
MD5 45b629d6a53b73f52e4ea95a2244d7e3
SHA1 55db80c66250f6d3e04aff6132a0127167b28b18
SHA256 4e6c75dfc000a4282b1da415bdc86aef9d113f8539b281791beaa6b406118822
SHA3 70385b0607596f5919b7572b47ea6226ed9a9c23b8fa0008d2c24d741935aea0

10

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xdc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55807
MD5 d792ceea3def3f71682eb1eea04b403c
SHA1 a920b6a80ab4780f87b408cdf108a1ac82996509
SHA256 c7ce5dce1f5c60c9f0669551ba5a5d2cfa52dfdf47ca831ccf62d4aa55af4c24
SHA3 6aa103f2885b802f04287d341ba808f97f54fec9ad12a3b19cebda7f6ce023f0

11

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.90128
MD5 781e937b1c8a76f1f6636e7995e9f530
SHA1 d52420e1c4e52e6d94dd21b37dc246715c32dab9
SHA256 dc29ad613c94c8be457bc1d2504a62084a39e58faa7c4fe33ea059a7981728a1
SHA3 b1b46a21d92666994763b9be97637914c7b0aa833af90d6b941d1a535a56ee6f

12

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x164
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68258
MD5 c35f74b91635985b1b9c2a034066d48e
SHA1 0ca2026561a14649488829292a3cf65d72e8076d
SHA256 bc0a87bc2f823765b06c9308580fb4e7c09a3c584a7cb9355b190ff35c238649
SHA3 95baa54f914fd53ffa861353f14caf33195490bee711f1d758b52f1747252ac5

13

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54875
MD5 b8e62045ff311a4b2b08bbafa47fbe0f
SHA1 e74cc3372acedde577d1a025346c4019c8129ea2
SHA256 c85c5567a389d9e7dd0cfd79349be5a6b54813529845c6f11a60d01ee7129fda
SHA3 4a71e772463cb0bbd9708fec3e7b8ebefee54da03f7558774eae1883621cf9b8

14

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.61995
MD5 a4a9a568a83d61c47d19aefd97e27852
SHA1 aa65a41a2f60b7de1b35bb6655f02cf408d04ff9
SHA256 83f265e852184711ffb09f50939bba25cb14013804eaea4c516cc544b81afe4c
SHA3 aef4a78e8dd8b7a4dc071796053e6ec6933e3e272fdb64863675150c1dc4a9bd

15

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4037
MD5 efde73c917066f48e2ce0d399a2b8b8d
SHA1 5ee91d6c6ba3e722cd8affb7fb94c8612c09f8e0
SHA256 8a5ed5de64061a372ea6c5e485d96e8b214e9881a4091697c466cd545ee2bda6
SHA3 44a7160dc77a24d8120e635da43412fc6314281cc16f2fc15ec89bccdcac2fa3

16

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xf2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44164
MD5 d9a5ecdb0b9730d60d8e55ffe7f99bbc
SHA1 c92da39964285869b84a7cfeac3932be4d96e0c8
SHA256 80876e8e6e5898acbac0da9244755847995939100031ba92b3af591fc62a0ea2
SHA3 fa10b91b3cea4d7e60b9e14b9876afa55c88942d425229b856d5d4cfa2afb3f3

100

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71858
Detected Filetype Icon file
MD5 216b6c99a73c9bdc965962e9c7ced2ec
SHA1 3432d1355ff9f39aa7c8832ef6e37ff118bce043
SHA256 4fd3c618bd4aea3ab42334f2e9375a22a7ef5e7ebf6da9f69c2249d6b6584ffe
SHA3 015714e195a897ffdf3e2b709ed0d7e6c07d80c9624587ab4e16effef840af5d

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x753
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25329
MD5 8ddcbbd6b8c80eef68bf9305e59fa1f3
SHA1 014923abccec57fa3ad16f65feb0de2b8cbc8408
SHA256 1b7b67e5d8927449d8f7be80a0e5ba5f03d25670035027c0cb71abce27da6810
SHA3 e5c4bfc7e92f1b945363bb9ad2aabbe4324074ac295d08722e743d6e7c524b69

String Table contents

Выберите папку для извлечения
Извлечение %s
Пропуск %s
Неожиданный конец архива
Повреждён заголовок файла "%s"
Обнаружен повреждённый заголовок
Повреждён главный заголовок архива
Повреждён заголовок комментария архива
Повреждён комментарий архива
Недостаточно памяти
Неизвестный метод в %s
Невозможно открыть %s
Невозможно создать %s
Невозможно создать папку %s
Ошибка контрольной суммы в зашифрованном файле %s. Файл повреждён или указан неверный пароль.
Ошибка контрольной суммы в %s
Ошибка контрольной суммы сжатых данных в %s
Ошибка записи файла %s (возможно, нет места на диске)
Ошибка чтения файла %s
Ошибка закрытия файла
Отсутствует необходимый том
Архив повреждён или имеет неизвестный формат
Извлечение из %s
Следующий том
Повреждён заголовок архива
Закрыть
Ошибка
Ошибки при выполнении операции.
См. окно с информацией
байт
изменён
папка недоступна
Некоторые файлы не были созданы.
Закройте все программы, перезагрузите Windows и повторите установку
Некоторые инсталляционные файлы повреждены.
Загрузите новую копию и повторите установку
Все файлы
<ul><li>Нажмите кнопку <b><i>Установить</i></b>, чтобы начать извлечение.</li><br><br>
<ul><li>Нажмите кнопку <b><i>Извлечь</i></b>, чтобы начать извлечение.</li><br><br>
<li>Кнопка <b><i>Обзор</i></b> позволяет выбрать папку назначения
в дереве папок. Имя папки также можно ввести
вручную.</li><br><br>
<li>Если папки назначения не существует, то она будет
создана автоматически до начала процесса извлечения.</li></ul>
Архив повреждён
Извлечение файлов в папку %s
Извлечение файлов во временную папку
Извлечь
Ход извлечения
Максимум символов в пути и имени файла: %d
Неизвестный метод шифрования в %s
Указан неверный пароль.
Невозможно скопировать %s в %s.
Невозможно создать символическую ссылку %s
Невозможно создать жёсткую ссылку %s
Сначала нужно распаковать целевой объект ссылки
Попробуйте запустить этот самораспаковывающийся архив от имени администратора
Приостановить
Продолжить
Предупреждение о безопасности
Удалите %s из папки %s. Пока это не будет сделано, запускать %s небезопасно.

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2018-Jun-24 15:04:40
Version 0.0
SizeofData 81
AddressOfRawData 0x37128
PointerToRawData 0x35d28
Referenced File D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2018-Jun-24 15:04:40
Version 0.0
SizeofData 20
AddressOfRawData 0x3717c
PointerToRawData 0x35d7c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2018-Jun-24 15:04:40
Version 0.0
SizeofData 944
AddressOfRawData 0x37190
PointerToRawData 0x35d90

TLS Callbacks

Load Configuration

Size 0x5c
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x43a1c8
SEHandlerTable 0x437090
SEHandlerCount 38

RICH Header

XOR Key 0x70329d92
Unmarked objects 0
241 (40116) 13
243 (40116) 139
242 (40116) 24
ASM objects (VS2015 UPD3 build 24123) 22
C objects (VS2015 UPD3 build 24123) 19
C++ objects (VS2015 UPD3 build 24123) 44
C objects (VS2008 SP1 build 30729) 10
Imports (VS2008 SP1 build 30729) 5
Total imports 267
C++ objects (VS2015 UPD3.1 build 24215) 48
Exports (VS2015 UPD3.1 build 24215) 1
Resource objects (VS2015 UPD3 build 24210) 1
Linker (VS2015 UPD3.1 build 24215) 1

Errors