d4661f3dbf9bcace65731c9b9b076ca5

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Apr-23 03:28:44
Detected languages English - United States
CompanyName Lost Marble LLC
LegalCopyright Copyright © 1999-2021 Lost Marble LLC. All Rights Reserved.
FileDescription Moho
FileVersion 13.5
ProductName Moho
ProductVersion 13.5

Plugin Output

Suspicious This PE is packed with VMProtect Unusual section name found: .vmp0
Unusual section name found: .vmp1
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • LoadLibraryA
  • LoadLibraryW
  • GetProcAddress
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
  • system
Can create temporary files:
  • GetTempPathA
  • CreateFileW
  • GetTempPathW
  • CreateFileA
Has Internet access capabilities:
  • WinHttpGetIEProxyConfigForCurrentUser
  • WinHttpCloseHandle
  • WinHttpOpen
  • WinHttpGetProxyForUrl
Functions related to the privilege level:
  • CheckTokenMembership
Enumerates local disk drives:
  • GetVolumeInformationW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Can use the microphone to record audio:
  • waveInOpen
Queries user information on remote machines:
  • NetWkstaGetInfo
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious VirusTotal score: 2/70 (Scanned on 2022-09-10 21:51:02) Trapmine: malicious.high.ml.score
Sophos: Generic ML PUA (PUA)

Hashes

MD5 d4661f3dbf9bcace65731c9b9b076ca5
SHA1 283abb80561e0963cd88500dae43eb14a428acc0
SHA256 d718b04ef5b34b0393712c6333eeef001472a11bf5a73ecf425da5abcd1796e2
SHA3 b6eb764fd83cc1bccb0bf349b6d88c1a6556bdfba9f4c848b218716f1cca31a8
SSDeep 196608:vXx4I6QqnAw5oH4udHl2pMEMCfzUTvyPqSqpN/9prEajnPAdS2rYD:4Qzw5opHkpbMCfzY6ANFRSS2a
Imports Hash 84022f98b0463696c54e4d795adff4ea

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x168

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2021-Apr-23 03:28:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x8b3600
SizeOfInitializedData 0x497c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000E809EB (Section: .vmp1)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x158b000
SizeOfHeaders 0x400
Checksum 0x86f474
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8b34fc
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.rdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1a1554
VirtualAddress 0x8b5000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.data

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x12c958
VirtualAddress 0xa57000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.pdata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x4d778
VirtualAddress 0xb84000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ

.vmp0

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x14a755
VirtualAddress 0xbd2000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ

.vmp1

MD5 4c8dd1c00e57b1255a4221b63f577425
SHA1 ca8fa23b328b1293af9624d98a07a22186f42dec
SHA256 d8d53e8285f195908a4ed0a75b0945b821ae190e193f1248cf7fd91d779d940d
SHA3 b05e107a92e314b9e17d4bfe1f2f8d13b60a4e6364cd93ce1735faa7aaa11ee6
VirtualSize 0x6fca50
VirtualAddress 0xd1d000
SizeOfRawData 0x6fcc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.90856

.reloc

MD5 96e024c6183d8a1869a1b9a3a14ddb72
SHA1 d33672148a999c2ae368fbc64c3e43e80173c05c
SHA256 260ca57658aa968104dcceb2bfa58475f4c8459636b161bd9130d8ac87d79ed7
SHA3 0956893aeb7f101f569fcb61af2d9446675bfab7b6a41b16240c06f3083c6d91
VirtualSize 0xd0
VirtualAddress 0x141a000
SizeOfRawData 0x200
PointerToRawData 0x6fd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.2067

.rsrc

MD5 fef0af25173c0653aa28094c5f5ece38
SHA1 32e69175e35322b34f068880570946fcc464f96e
SHA256 247b0062bcd3e7c662784714f79e15c67383a0452afa0d902005a72d4fbef54a
SHA3 df4fbff099d394cc7c4fd4fd57dc563616d248873548035eabe3dd281a134639
VirtualSize 0x16f2f6
VirtualAddress 0x141b000
SizeOfRawData 0x16f400
PointerToRawData 0x6fd200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.7388

Imports

OPENGL32.dll glColor4f
glTexParameterfv
glTexEnvf
glOrtho
wglMakeCurrent
wglDeleteContext
glLoadIdentity
wglCreateContext
glMatrixMode
glColor3f
glViewport
glGetString
glTexSubImage2D
glTexImage2D
glDeleteTextures
glTexParameteri
glGenTextures
glBindTexture
glClearStencil
glPolygonStipple
glColor4ub
glRasterPos2i
glIsEnabled
glVertex2f
glReadPixels
glClearColor
glPixelZoom
glBegin
glColorMask
glBlendFunc
glStencilFunc
glLineWidth
glDrawPixels
glVertex3dv
glTexCoord2f
glEnd
glEnable
glClear
glStencilOp
glDisable
glVertex3f
GLU32.dll gluTessCallback
gluDeleteTess
gluTessEndPolygon
gluTessProperty
gluNewTess
gluTessBeginContour
gluTessBeginPolygon
gluTessEndContour
gluTessVertex
gluErrorString
libfbxsdk.dll ?AddPose@FbxScene@fbxsdk@@QEAA_NPEAVFbxPose@2@@Z
??0FbxMatrix@fbxsdk@@QEAA@AEBVFbxAMatrix@1@@Z
??1FbxMatrix@fbxsdk@@QEAA@XZ
?GetDeformerCount@FbxGeometry@fbxsdk@@QEBAHW4EDeformerType@FbxDeformer@2@@Z
?GetDeformer@FbxGeometry@fbxsdk@@QEBAPEAVFbxDeformer@2@HW4EDeformerType@32@PEAVFbxStatus@2@@Z
?GetCluster@FbxSkin@fbxsdk@@QEAAPEAVFbxCluster@2@H@Z
?FbxGetDataTypeFromEnum@fbxsdk@@YAAEBVFbxDataType@1@W4EFbxType@1@@Z
?GetErrorString@FbxStatus@fbxsdk@@QEBAPEBDXZ
?Create@FbxDocumentInfo@fbxsdk@@SAPEAV12@PEAVFbxManager@2@PEBD@Z
?Create@FbxCamera@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?SetFormat@FbxCamera@fbxsdk@@QEAAXW4EFormat@12@@Z
?SetAspect@FbxCamera@fbxsdk@@QEAAXW4EAspectRatioMode@12@NN@Z
?SetApertureMode@FbxCamera@fbxsdk@@QEAAXW4EApertureMode@12@@Z
?Create@FbxAnimStack@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?Create@FbxExporter@fbxsdk@@SAPEAV12@PEAVFbxManager@2@PEBD@Z
?Export@FbxExporter@fbxsdk@@QEAA_NPEAVFbxDocument@2@_N@Z
?WriterIsFBX@FbxIOPluginRegistry@fbxsdk@@QEBA_NH@Z
?GetWriterFormatCount@FbxIOPluginRegistry@fbxsdk@@QEBAHXZ
?GetWriterFormatDescription@FbxIOPluginRegistry@fbxsdk@@QEBAPEBDH@Z
?GetNativeWriterFormat@FbxIOPluginRegistry@fbxsdk@@QEAAHXZ
?Create@FbxIOSettings@fbxsdk@@SAPEAV12@PEAVFbxManager@2@PEBD@Z
?SetBoolProp@FbxIOSettings@fbxsdk@@QEAAXPEBD_N@Z
?Create@FbxManager@fbxsdk@@SAPEAV12@XZ
?GetVersion@FbxManager@fbxsdk@@SAPEBD_N@Z
?GetFileFormatVersion@FbxManager@fbxsdk@@SAXAEAH00@Z
?GetIOPluginRegistry@FbxManager@fbxsdk@@QEBAPEAVFbxIOPluginRegistry@2@XZ
?Create@FbxScene@fbxsdk@@SAPEAV12@PEAVFbxManager@2@PEBD@Z
?GetRootNode@FbxScene@fbxsdk@@QEBAPEAVFbxNode@2@XZ
?GetGlobalSettings@FbxScene@fbxsdk@@QEAAAEAVFbxGlobalSettings@2@XZ
?SetCurrentAnimationStack@FbxScene@fbxsdk@@QEAAXPEAVFbxAnimStack@2@@Z
?Create@FbxProperty@fbxsdk@@SA?AV12@PEAVFbxObject@2@AEBVFbxDataType@2@PEBD2_NPEA_N@Z
??1FbxProperty@fbxsdk@@QEAA@XZ
?FbxAllocSize@fbxsdk@@YA_K_K0@Z
??BFbxString@fbxsdk@@QEBAPEBDXZ
??1FbxString@fbxsdk@@QEAA@XZ
?GetCurve@FbxProperty@fbxsdk@@QEAAPEAVFbxAnimCurve@2@PEAVFbxAnimLayer@2@PEBD1_N@Z
??0FbxColor@fbxsdk@@QEAA@NNNN@Z
??0FbxVector4@fbxsdk@@QEAA@NNNN@Z
?SetLimbNodeColor@FbxSkeleton@fbxsdk@@QEAA_NAEBVFbxColor@2@@Z
?SetSkeletonType@FbxSkeleton@fbxsdk@@QEAAXW4EType@12@@Z
?Create@FbxSkeleton@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?SetNodeAttribute@FbxNode@fbxsdk@@QEAAPEAVFbxNodeAttribute@2@PEAV32@@Z
?GetCurveNode@FbxProperty@fbxsdk@@QEAAPEAVFbxAnimCurveNode@2@PEAVFbxAnimLayer@2@_N@Z
?Set@FbxProperty@fbxsdk@@IEAA_NPEBXAEBW4EFbxType@2@_N@Z
?AddChild@FbxNode@fbxsdk@@QEAA_NPEAV12@@Z
?Create@FbxNode@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?Create@FbxSurfaceLambert@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
??4FbxAMatrix@fbxsdk@@QEAAAEAV01@AEBV01@@Z
??1FbxAMatrix@fbxsdk@@QEAA@XZ
??0FbxAMatrix@fbxsdk@@QEAA@XZ
??0FbxString@fbxsdk@@QEAA@PEBD@Z
?Add@FbxPose@fbxsdk@@QEAAHPEAVFbxNode@2@AEBVFbxMatrix@2@_N2@Z
?AddCluster@FbxSkin@fbxsdk@@QEAA_NPEAVFbxCluster@2@@Z
?Create@FbxSkin@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?AddDeformer@FbxGeometry@fbxsdk@@QEAAHPEAVFbxDeformer@2@@Z
?ConnectSrcObject@FbxProperty@fbxsdk@@QEAA_NPEAVFbxObject@2@W4EType@FbxConnection@2@@Z
??XFbxVector4@fbxsdk@@QEAAAEAV01@N@Z
??YFbxVector4@fbxsdk@@QEAAAEAV01@AEBV01@@Z
?Set@FbxVector4@fbxsdk@@QEAAXNNNN@Z
?Create@FbxLayerElementMaterial@fbxsdk@@SAPEAV12@PEAVFbxLayerContainer@2@PEBD@Z
?SetScale@FbxTexture@fbxsdk@@QEAAXNN@Z
?SetRotation@FbxTexture@fbxsdk@@QEAAXNNN@Z
?SetTranslation@FbxTexture@fbxsdk@@QEAAXNN@Z
?SetTextureUse@FbxTexture@fbxsdk@@QEAAXW4ETextureUse@12@@Z
?SetMappingType@FbxTexture@fbxsdk@@QEAAXW4EMappingType@12@@Z
?SetAlphaSource@FbxTexture@fbxsdk@@QEAAXW4EAlphaSource@12@@Z
?GetName@FbxProperty@fbxsdk@@QEBA?AVFbxString@2@XZ
?FbxFree@fbxsdk@@YAXPEAX@Z
?SetSecondDouble@FbxTime@fbxsdk@@QEAAXN@Z
??1FbxColor@fbxsdk@@QEAA@XZ
?ModifyFlag@FbxProperty@fbxsdk@@QEAAXW4EFlags@FbxPropertyFlags@2@_N@Z
?SetAmbientColor@FbxGlobalSettings@fbxsdk@@QEAAXVFbxColor@2@@Z
?SetDefaultCamera@FbxGlobalSettings@fbxsdk@@QEAA_NPEBD@Z
?Create@FbxAnimLayer@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
??4FbxString@fbxsdk@@QEAAAEBV01@PEBD@Z
?Find@FbxString@fbxsdk@@QEBAHPEBD_K@Z
?GetName@FbxObject@fbxsdk@@QEBAPEBDXZ
?FbxRealloc@fbxsdk@@YAPEAXPEAX_K@Z
?SetIsBindPose@FbxPose@fbxsdk@@QEAAX_N@Z
?GetLink@FbxCluster@fbxsdk@@QEAAPEAVFbxNode@2@XZ
?GetParent@FbxNode@fbxsdk@@QEAAPEAV12@XZ
?GetNodeAttribute@FbxNode@fbxsdk@@QEAAPEAVFbxNodeAttribute@2@XZ
?SetRotationPivot@FbxNode@fbxsdk@@QEAAXW4EPivotSet@12@VFbxVector4@2@@Z
?SetScalingPivot@FbxNode@fbxsdk@@QEAAXW4EPivotSet@12@VFbxVector4@2@@Z
?Create@FbxPose@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?SetSwapUV@FbxTexture@fbxsdk@@QEAAX_N@Z
?SetMaterialUse@FbxFileTexture@fbxsdk@@QEAAXW4EMaterialUse@12@@Z
?SetFileName@FbxFileTexture@fbxsdk@@QEAA_NPEBD@Z
?Create@FbxFileTexture@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?EndPolygon@FbxMesh@fbxsdk@@QEAAXXZ
?AddPolygon@FbxMesh@fbxsdk@@QEAAXHH@Z
?BeginPolygon@FbxMesh@fbxsdk@@QEAAXHHH_N@Z
?Create@FbxMesh@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?SetMaterials@FbxLayer@fbxsdk@@QEAAXPEAVFbxLayerElementMaterial@2@@Z
?GetLayer@FbxLayerContainer@fbxsdk@@QEAAPEAVFbxLayer@2@H@Z
??0FbxVector2@fbxsdk@@QEAA@NN@Z
?CreateElementUV@FbxGeometryBase@fbxsdk@@QEAAPEAVFbxLayerElementUV@2@PEBDW4EType@FbxLayerElement@2@@Z
?Add@FbxLayerElementArray@fbxsdk@@QEAAHPEBXW4EFbxType@2@@Z
?AddMaterial@FbxNode@fbxsdk@@QEAAHPEAVFbxSurfaceMaterial@2@@Z
?EvaluateGlobalTransform@FbxNode@fbxsdk@@QEAAAEAVFbxAMatrix@2@VFbxTime@2@W4EPivotSet@12@_N2@Z
?SetShadingMode@FbxNode@fbxsdk@@QEAAXW4EShadingMode@12@@Z
?SetTransformLinkMatrix@FbxCluster@fbxsdk@@QEAAXAEBVFbxAMatrix@2@@Z
?SetTransformMatrix@FbxCluster@fbxsdk@@QEAAXAEBVFbxAMatrix@2@@Z
?AddControlPointIndex@FbxCluster@fbxsdk@@QEAAXHN@Z
?SetLink@FbxCluster@fbxsdk@@QEAAXPEBVFbxNode@2@@Z
?SetLinkMode@FbxCluster@fbxsdk@@QEAAXW4ELinkMode@12@@Z
?Create@FbxCluster@fbxsdk@@SAPEAV12@PEAVFbxObject@2@PEBD@Z
?GetClusterCount@FbxSkin@fbxsdk@@QEBAHXZ
?Destroy@FbxObject@fbxsdk@@QEAAX_N@Z
?SetDocumentInfo@FbxDocument@fbxsdk@@QEAAXPEAVFbxDocumentInfo@2@@Z
libsndfile-1.dll #3
#19
#17
#71
#39
lm-external-libs.dll soundtouch_setChannels
soundtouch_putSamples
soundtouch_setSampleRate
soundtouch_setPitch
soundtouch_createInstance
soundtouch_flush
soundtouch_setSetting
soundtouch_receiveSamples
pthreadVC2.dll pthread_setcanceltype
pthread_attr_destroy
pthread_attr_init
pthread_setcancelstate
pthread_win32_process_attach_np
pthread_attr_setstacksize
pthread_attr_setdetachstate
pthread_win32_process_detach_np
ptw32_push_cleanup
pthread_testcancel
pthread_exit
pthread_create
WinSparkle.dll win_sparkle_get_automatic_check_for_updates
win_sparkle_set_automatic_check_for_updates
win_sparkle_check_update_with_ui
win_sparkle_cleanup
win_sparkle_set_shutdown_request_callback
win_sparkle_set_appcast_url
win_sparkle_init
FreeImage.dll FreeImage_SetTagKey
FreeImage_GetTagKey
FreeImage_GetScanLine
FreeImage_DeleteTag
FreeImage_SetTagType
FreeImage_CloseMultiBitmap
FreeImage_SetTagValue
FreeImage_ColorQuantizeEx
FreeImage_CreateTag
FreeImage_AppendPage
FreeImage_Unload
FreeImage_SetTagCount
FreeImage_SetTransparencyTable
FreeImage_GetPalette
FreeImage_OpenMultiBitmap
FreeImage_GetColorsUsed
FreeImage_SetTagLength
FreeImage_GetTagValue
FreeImage_GetPageCount
FreeImage_LockPage
FreeImage_UnlockPage
FreeImage_GetMetadata
FreeImage_GetBPP
FreeImage_ConvertToRawBits
FreeImage_GetWidth
FreeImage_GetVersion
FreeImage_Save
FreeImage_Load
FreeImage_GetCopyrightMessage
FreeImage_SetTransparent
FreeImage_ConvertFromRawBits
FreeImage_ConvertTo24Bits
FreeImage_GetHeight
FreeImage_SetMetadata
FreeImage_ConvertToFloat
FreeImage_ToneMapping
FreeImage_Allocate
FreeImage_Initialise
KERNEL32.dll UnlockFileEx
GetFullPathNameA
LockFile
GetDiskFreeSpaceW
HeapCreate
AreFileApisANSI
GetEnvironmentVariableW
CreateThread
GetACP
GetOEMCP
GetVolumeInformationW
QueryPerformanceCounter
MapViewOfFile
CreateFileMappingW
GetSystemTimeAsFileTime
QueryPerformanceFrequency
GetTimeZoneInformation
FormatMessageW
SetFileAttributesW
UnmapViewOfFile
SetEndOfFile
SetFilePointer
TryEnterCriticalSection
GetPrivateProfileStringA
WriteFile
ResetEvent
FormatMessageA
LoadLibraryExA
GetModuleFileNameA
LoadLibraryA
InitializeCriticalSection
GetTempPathA
SetFileTime
OutputDebugStringW
GetFullPathNameW
GetFileSize
ReadFile
GetVersion
GlobalAddAtomW
GlobalDeleteAtom
SetThreadExecutionState
SleepEx
ReadDirectoryChangesW
QueueUserAPC
WaitForSingleObjectEx
CreateFileW
lstrcpynW
CancelIo
FindClose
FindNextFileW
FindFirstFileW
GlobalAlloc
MulDiv
AllocConsole
GlobalUnlock
GetDateFormatW
GetCurrentProcessId
GetTimeFormatW
GlobalLock
GlobalFree
GlobalSize
AttachConsole
GetVersionExW
GetCurrentProcess
GetCommandLineW
SetPriorityClass
WideCharToMultiByte
NormalizeString
MultiByteToWideChar
GetThreadId
GetSystemInfo
ReleaseMutex
GetCurrentThreadId
CreateMutexA
CreateMutexW
SetThreadPriority
GetSystemTime
SystemTimeToFileTime
GetExitCodeProcess
GetTempPathW
GetModuleFileNameW
MoveFileW
InitOnceComplete
InitOnceBeginInitialize
InitializeCriticalSectionAndSpinCount
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
HeapValidate
GetDiskFreeSpaceA
GetFileAttributesA
CreateFileA
DeleteFileA
HeapCompact
UnlockFile
CreateFileMappingA
LockFileEx
FlushFileBuffers
InitializeSListHead
VerifyVersionInfoW
CopyFileW
OutputDebugStringA
GetNativeSystemInfo
GetCurrentDirectoryW
SetCurrentDirectoryW
GetLongPathNameW
WaitForSingleObject
CreateProcessW
WaitForMultipleObjects
CreateEventW
Sleep
SetEvent
CloseHandle
CreateMemoryResourceNotification
GetTickCount
CreateDirectoryW
HeapFree
EnterCriticalSection
ExpandEnvironmentStringsW
RemoveDirectoryW
LeaveCriticalSection
InitializeCriticalSectionEx
LocalAlloc
GetFileAttributesW
HeapSize
GetLastError
GetFileAttributesExW
FileTimeToSystemTime
DeleteFileW
HeapReAlloc
LoadLibraryW
HeapAlloc
HeapDestroy
GetProcAddress
LocalFree
DeleteCriticalSection
VerSetConditionMask
GetProcessHeap
GetModuleHandleW
FreeLibrary
USER32.dll GetDoubleClickTime
MapWindowPoints
EmptyClipboard
DestroyIcon
GetAsyncKeyState
ShowWindow
GetWindowPlacement
SetWindowTextW
AdjustWindowRectEx
DefWindowProcW
FillRect
GetWindowTextLengthW
RegisterClassExW
CloseWindow
GetMessageTime
BeginPaint
EndPaint
ScreenToClient
SetFocus
GetCursorPos
RegisterClipboardFormatW
GetClientRect
DestroyCursor
CreateCursor
GetKeyState
LoadIconW
OpenClipboard
CloseClipboard
GetClipboardData
wsprintfW
IsClipboardFormatAvailable
PostQuitMessage
SetProcessDPIAware
ReleaseDC
GetGUIThreadInfo
GetWindowRect
GetSystemMetrics
GetDesktopWindow
MessageBeep
WaitMessage
SetTimer
UnregisterClassW
LoadStringW
SystemParametersInfoW
GetMessageW
DispatchMessageW
PeekMessageW
TranslateMessage
GetPropW
SendMessageW
EnumWindows
BringWindowToTop
SetForegroundWindow
PostMessageW
RemovePropW
SetPropW
SetCapture
SetClipboardData
SetCursor
ShutdownBlockReasonCreate
SetRect
KillTimer
RegisterWindowMessageW
ShutdownBlockReasonDestroy
ReleaseCapture
EnableWindow
GetWindowTextW
MonitorFromPoint
EnumDisplayMonitors
GetMonitorInfoW
EnumDisplaySettingsW
UpdateLayeredWindow
CallWindowProcW
DestroyWindow
SetWindowPos
SetWindowLongPtrW
CreateWindowExW
GetWindowLongPtrW
RegisterClassW
LoadCursorW
GetDC
InvalidateRect
GDI32.dll CreateSolidBrush
SetBkColor
GetPixel
BitBlt
CreateDIBSection
CreateCompatibleDC
GetObjectW
DescribePixelFormat
GetStockObject
ChoosePixelFormat
SwapBuffers
SetPixelFormat
CreateRectRgn
CombineRgn
StretchDIBits
GetDeviceCaps
DeleteDC
RealizePalette
SelectPalette
CreatePalette
SelectObject
GetTextFaceW
CreateFontW
GetTextMetricsW
GetTextExtentPoint32W
SetTextColor
SetBkMode
DeleteObject
SelectClipRgn
ExtTextOutW
COMDLG32.dll GetSaveFileNameW
GetOpenFileNameW
ADVAPI32.dll SetSecurityDescriptorDacl
RegOpenKeyExW
RegQueryValueExW
CheckTokenMembership
AllocateAndInitializeSid
SetEntriesInAclW
FreeSid
InitializeSecurityDescriptor
RegCloseKey
SHELL32.dll SHCreateDirectoryExW
SHOpenFolderAndSelectItems
#155
#190
ShellExecuteW
SHFileOperationW
DragQueryFileW
CommandLineToArgvW
SHGetFolderPathW
SHGetFileInfoW
SHCreateItemFromParsingName
ole32.dll CoInitializeEx
ReleaseStgMedium
OleUninitialize
CoTaskMemFree
OleInitialize
CoTaskMemAlloc
CoTaskMemRealloc
CoCreateInstance
CoUninitialize
OleSetContainedObject
OleCreate
DoDragDrop
RegisterDragDrop
RevokeDragDrop
PropVariantClear
OLEAUT32.dll VariantInit
SysAllocString
VariantClear
MSVCP140.dll ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xbad_function_call@std@@YAXXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
??0task_continuation_context@Concurrency@@AEAA@XZ
_Mtx_current_owns
_Cnd_unregister_at_thread_exit
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_init_in_situ
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
_Query_perf_frequency
?_Throw_future_error@std@@YAXAEBVerror_code@1@@Z
?_Throw_Cpp_error@std@@YAXH@Z
?_Throw_C_error@std@@YAXH@Z
?_Rethrow_future_exception@std@@YAXVexception_ptr@1@@Z
?_Syserror_map@std@@YAPEBDH@Z
_Cnd_timedwait
?__ExceptionPtrToBool@@YA_NPEBX@Z
_Mtx_destroy_in_situ
?__ExceptionPtrDestroy@@YAXPEAX@Z
_Mtx_lock
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrRethrow@@YAXPEBX@Z
_Mtx_init_in_situ
_Cnd_register_at_thread_exit
_Cnd_wait
_Query_perf_counter
_Xtime_get_ticks
_Mtx_unlock
_Cnd_broadcast
_Cnd_destroy_in_situ
?_Xout_of_range@std@@YAXPEBD@Z
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z
?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
??Bid@locale@std@@QEAA_KXZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
SHLWAPI.dll #219
PathCreateFromUrlW
PathIsRelativeW
PathCombineW
RPCRT4.dll UuidToStringA
RpcStringFreeA
UuidCreate
UuidToStringW
RpcStringFreeW
WINHTTP.dll WinHttpGetIEProxyConfigForCurrentUser
WinHttpCloseHandle
WinHttpOpen
WinHttpGetProxyForUrl
WINTRUST.dll WinVerifyTrust
NETAPI32.dll NetWkstaGetInfo
NetApiBufferFree
MFPlat.DLL MFCreateMediaType
MFInitMediaTypeFromWaveFormatEx
MFTUnregisterLocal
MFTRegisterLocal
MFCalculateImageSize
MFCreateSample
MFCreateMemoryBuffer
MFTEnum
MFFrameRateToAverageTimePerFrame
MFStartup
MFCreateAttributes
MFCreateSourceResolver
MFCreateWaveFormatExFromMFMediaType
MFShutdown
MFTEnumEx
MFReadWrite.dll MFCreateSinkWriterFromURL
MFCreateSourceReaderFromURL
MF.dll MFCreateVideoRendererActivate
MFCreateTopology
MFCreateTopologyNode
MFCreateTopoLoader
MFCreateMediaSession
MFCreateAudioRendererActivate
WINMM.dll waveOutPrepareHeader
waveInStart
waveInAddBuffer
waveOutGetPosition
timeGetTime
waveOutGetNumDevs
waveInMessage
waveInReset
waveOutOpen
waveInOpen
waveInUnprepareHeader
waveOutReset
waveOutRestart
waveOutGetDevCapsW
waveInGetNumDevs
waveOutMessage
waveInGetDevCapsW
waveOutClose
waveOutGetErrorTextW
waveOutWrite
waveInGetErrorTextW
waveInPrepareHeader
waveInClose
waveOutUnprepareHeader
waveOutPause
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll longjmp
strrchr
strstr
__C_specific_handler
_purecall
__std_exception_copy
__std_exception_destroy
__std_terminate
strchr
__intrinsic_setjmp
memcpy
memcmp
memchr
__RTDynamicCast
memmove
_CxxThrowException
memset
__current_exception_context
__current_exception
api-ms-win-crt-stdio-l1-1-0.dll ftell
fread
fseek
fgetc
fwrite
ferror
_wfopen
__stdio_common_vfprintf
puts
fgetpos
tmpnam
__stdio_common_vfscanf
feof
fsetpos
__p__commode
_set_fmode
_fseeki64
_ftelli64
_popen
__acrt_iob_func
setvbuf
tmpfile
_pclose
rewind
clearerr
__stdio_common_vfprintf_s
fputs
ungetc
getc
fgets
fopen
fclose
__stdio_common_vsprintf
__stdio_common_vsscanf
fflush
freopen
_locking
__stdio_common_vsnprintf_s
_getcwd
_fileno
_setmode
api-ms-win-crt-string-l1-1-0.dll tolower
toupper
isalpha
strspn
isalnum
_strnicmp
strncpy_s
strncat
isupper
strncpy
iswalpha
_stricmp
isprint
strcat_s
wcscpy_s
strcoll
ispunct
iscntrl
isxdigit
isgraph
strpbrk
islower
isdigit
isspace
strncmp
strcpy_s
strcmp
api-ms-win-crt-heap-l1-1-0.dll calloc
_callnewh
free
malloc
_msize
realloc
_aligned_malloc
_set_new_mode
_aligned_free
api-ms-win-crt-runtime-l1-1-0.dll perror
abort
_initterm
_get_wide_winmain_command_line
_invalid_parameter_noinfo_noreturn
_initialize_wide_environment
terminate
_beginthreadex
exit
_configure_wide_argv
_initterm_e
strerror
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_errno
_register_onexit_function
_initialize_onexit_table
system
_endthreadex
_exit
_register_thread_local_exe_atexit_callback
_c_exit
api-ms-win-crt-utility-l1-1-0.dll srand
rand
qsort_s
qsort
api-ms-win-crt-time-l1-1-0.dll _difftime64
_utime64
clock
_mktime64
strftime
_gmtime64
_localtime64
_ctime64
_localtime64_s
_time64
api-ms-win-crt-conio-l1-1-0.dll _getch
api-ms-win-crt-filesystem-l1-1-0.dll remove
_splitpath
_wsplitpath
rename
_stat64i32
_chdir
_stat64
_waccess
_wmkdir
_rmdir
_mkdir
_findnext64i32
_findclose
_findfirst64i32
_fstat64i32
api-ms-win-crt-locale-l1-1-0.dll localeconv
_configthreadlocale
setlocale
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
_finite
_hypot
acos
acosf
asin
atan
_isnan
atan2f
ceil
cos
cosf
cosh
exp
floor
frexp
ldexp
modf
atan2
fmod
log
log10
log10f
pow
powf
sin
hypot
sinf
sinh
sqrt
sqrtf
tan
tanf
tanh
ceilf
api-ms-win-crt-environment-l1-1-0.dll getenv
_wgetenv
api-ms-win-crt-convert-l1-1-0.dll atof
strtof
wcstombs
strtoul
strtol
strtod
atol
atoi
api-ms-win-crt-multibyte-l1-1-0.dll _ismbcalpha
KERNEL32.dll (#2) UnlockFileEx
GetFullPathNameA
LockFile
GetDiskFreeSpaceW
HeapCreate
AreFileApisANSI
GetEnvironmentVariableW
CreateThread
GetACP
GetOEMCP
GetVolumeInformationW
QueryPerformanceCounter
MapViewOfFile
CreateFileMappingW
GetSystemTimeAsFileTime
QueryPerformanceFrequency
GetTimeZoneInformation
FormatMessageW
SetFileAttributesW
UnmapViewOfFile
SetEndOfFile
SetFilePointer
TryEnterCriticalSection
GetPrivateProfileStringA
WriteFile
ResetEvent
FormatMessageA
LoadLibraryExA
GetModuleFileNameA
LoadLibraryA
InitializeCriticalSection
GetTempPathA
SetFileTime
OutputDebugStringW
GetFullPathNameW
GetFileSize
ReadFile
GetVersion
GlobalAddAtomW
GlobalDeleteAtom
SetThreadExecutionState
SleepEx
ReadDirectoryChangesW
QueueUserAPC
WaitForSingleObjectEx
CreateFileW
lstrcpynW
CancelIo
FindClose
FindNextFileW
FindFirstFileW
GlobalAlloc
MulDiv
AllocConsole
GlobalUnlock
GetDateFormatW
GetCurrentProcessId
GetTimeFormatW
GlobalLock
GlobalFree
GlobalSize
AttachConsole
GetVersionExW
GetCurrentProcess
GetCommandLineW
SetPriorityClass
WideCharToMultiByte
NormalizeString
MultiByteToWideChar
GetThreadId
GetSystemInfo
ReleaseMutex
GetCurrentThreadId
CreateMutexA
CreateMutexW
SetThreadPriority
GetSystemTime
SystemTimeToFileTime
GetExitCodeProcess
GetTempPathW
GetModuleFileNameW
MoveFileW
InitOnceComplete
InitOnceBeginInitialize
InitializeCriticalSectionAndSpinCount
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
HeapValidate
GetDiskFreeSpaceA
GetFileAttributesA
CreateFileA
DeleteFileA
HeapCompact
UnlockFile
CreateFileMappingA
LockFileEx
FlushFileBuffers
InitializeSListHead
VerifyVersionInfoW
CopyFileW
OutputDebugStringA
GetNativeSystemInfo
GetCurrentDirectoryW
SetCurrentDirectoryW
GetLongPathNameW
WaitForSingleObject
CreateProcessW
WaitForMultipleObjects
CreateEventW
Sleep
SetEvent
CloseHandle
CreateMemoryResourceNotification
GetTickCount
CreateDirectoryW
HeapFree
EnterCriticalSection
ExpandEnvironmentStringsW
RemoveDirectoryW
LeaveCriticalSection
InitializeCriticalSectionEx
LocalAlloc
GetFileAttributesW
HeapSize
GetLastError
GetFileAttributesExW
FileTimeToSystemTime
DeleteFileW
HeapReAlloc
LoadLibraryW
HeapAlloc
HeapDestroy
GetProcAddress
LocalFree
DeleteCriticalSection
VerSetConditionMask
GetProcessHeap
GetModuleHandleW
FreeLibrary
USER32.dll (#2) GetDoubleClickTime
MapWindowPoints
EmptyClipboard
DestroyIcon
GetAsyncKeyState
ShowWindow
GetWindowPlacement
SetWindowTextW
AdjustWindowRectEx
DefWindowProcW
FillRect
GetWindowTextLengthW
RegisterClassExW
CloseWindow
GetMessageTime
BeginPaint
EndPaint
ScreenToClient
SetFocus
GetCursorPos
RegisterClipboardFormatW
GetClientRect
DestroyCursor
CreateCursor
GetKeyState
LoadIconW
OpenClipboard
CloseClipboard
GetClipboardData
wsprintfW
IsClipboardFormatAvailable
PostQuitMessage
SetProcessDPIAware
ReleaseDC
GetGUIThreadInfo
GetWindowRect
GetSystemMetrics
GetDesktopWindow
MessageBeep
WaitMessage
SetTimer
UnregisterClassW
LoadStringW
SystemParametersInfoW
GetMessageW
DispatchMessageW
PeekMessageW
TranslateMessage
GetPropW
SendMessageW
EnumWindows
BringWindowToTop
SetForegroundWindow
PostMessageW
RemovePropW
SetPropW
SetCapture
SetClipboardData
SetCursor
ShutdownBlockReasonCreate
SetRect
KillTimer
RegisterWindowMessageW
ShutdownBlockReasonDestroy
ReleaseCapture
EnableWindow
GetWindowTextW
MonitorFromPoint
EnumDisplayMonitors
GetMonitorInfoW
EnumDisplaySettingsW
UpdateLayeredWindow
CallWindowProcW
DestroyWindow
SetWindowPos
SetWindowLongPtrW
CreateWindowExW
GetWindowLongPtrW
RegisterClassW
LoadCursorW
GetDC
InvalidateRect

Delayed Imports

initLibModule

Ordinal 1
Address 0x64e0f0

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x27e7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93937
Detected Filetype PNG graphic file
MD5 d7c1cd21c951df4a96ef8f0261279583
SHA1 92ab8a75dff799d95955eacc5380b62766a1355a
SHA256 bb8b361524747339dfd9cf62adaaa208500b534838af03b064271feae1a2df20
SHA3 2a36993ac80d8f62f16c4951a68983d65ebc5d115b9f55d6ea012de936de33b2

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07753
MD5 db1c6b98fd8ec6bd98809697767a752c
SHA1 237e8d7f1131b221126eaf7412adfc26fdb6da75
SHA256 1e0e16a83b327ebe468a5d13f019b726c8f4a982f010ad171550646d7d42345c
SHA3 f43ba0df7b868b6e65c31a91cbd5c5f47e43c5ca18015edac82765e5b32943d1

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29759
MD5 f5cfa58d2a417d238e1a09b6166a9955
SHA1 cdf42291738a17731b6427545bbaa57951962b80
SHA256 3f315e2b2922f9937a69fd129c264041c1dda88a3e782e816cfd70bed34ebe21
SHA3 5c1cf56857fda85a60db22f51e61483cfb4d23658135d8e48fbf448dba997637

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44097
MD5 ba9a309e1e493d2eafcd513115cd0e90
SHA1 cf29ba23e10900e6aa22e8d036a0854015cf1e02
SHA256 bc5cc6266d8dee7294567bc184a46edbbe2d811db715f0b9fa232fa102b2cb93
SHA3 86410c97389a73aebb10692e41f077f5764fa71906162d78937aa916476e55cf

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.64117
MD5 067fae1ea9f885bd1c69833e235f377e
SHA1 db8980ab00b76065f32b6609402c1cee9766dd67
SHA256 7de34f8a83a953717e992f687398b4193c96214ed2ef7271a56627672fde1d58
SHA3 0f47a9622ac9f658fe1b16df52fda8090339388d9cf8c61db5cf807e7ddec696

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.1075
MD5 c81ba56d36ba7e7af02da45bcc2583c0
SHA1 f5d52b2938e8757c00abb96e29dee2400ffc34ad
SHA256 690a714930411d460f5502e470875a1220e1c4b239721216a6f7fc85e5543811
SHA3 19acc9d1c8cd7f46155e10e50060f503cc5327d3b638926504eea61effeb615c

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x27e7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93937
Detected Filetype PNG graphic file
MD5 d7c1cd21c951df4a96ef8f0261279583
SHA1 92ab8a75dff799d95955eacc5380b62766a1355a
SHA256 bb8b361524747339dfd9cf62adaaa208500b534838af03b064271feae1a2df20
SHA3 2a36993ac80d8f62f16c4951a68983d65ebc5d115b9f55d6ea012de936de33b2

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07753
MD5 db1c6b98fd8ec6bd98809697767a752c
SHA1 237e8d7f1131b221126eaf7412adfc26fdb6da75
SHA256 1e0e16a83b327ebe468a5d13f019b726c8f4a982f010ad171550646d7d42345c
SHA3 f43ba0df7b868b6e65c31a91cbd5c5f47e43c5ca18015edac82765e5b32943d1

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29759
MD5 f5cfa58d2a417d238e1a09b6166a9955
SHA1 cdf42291738a17731b6427545bbaa57951962b80
SHA256 3f315e2b2922f9937a69fd129c264041c1dda88a3e782e816cfd70bed34ebe21
SHA3 5c1cf56857fda85a60db22f51e61483cfb4d23658135d8e48fbf448dba997637

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44097
MD5 ba9a309e1e493d2eafcd513115cd0e90
SHA1 cf29ba23e10900e6aa22e8d036a0854015cf1e02
SHA256 bc5cc6266d8dee7294567bc184a46edbbe2d811db715f0b9fa232fa102b2cb93
SHA3 86410c97389a73aebb10692e41f077f5764fa71906162d78937aa916476e55cf

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.64117
MD5 067fae1ea9f885bd1c69833e235f377e
SHA1 db8980ab00b76065f32b6609402c1cee9766dd67
SHA256 7de34f8a83a953717e992f687398b4193c96214ed2ef7271a56627672fde1d58
SHA3 0f47a9622ac9f658fe1b16df52fda8090339388d9cf8c61db5cf807e7ddec696

12

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.1075
MD5 c81ba56d36ba7e7af02da45bcc2583c0
SHA1 f5d52b2938e8757c00abb96e29dee2400ffc34ad
SHA256 690a714930411d460f5502e470875a1220e1c4b239721216a6f7fc85e5543811
SHA3 19acc9d1c8cd7f46155e10e50060f503cc5327d3b638926504eea61effeb615c

13

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91094
Detected Filetype PNG graphic file
MD5 176a14fbfc6aff8f4231989fdd10c5ae
SHA1 410c580634c150781ffe8ee70b6377ec328ee4dc
SHA256 ae0dd122c9cf16c86b13e9e6d8c865520c368aa534bf81fa47d8eb2a7ff2e8ca
SHA3 f9d9efef0e34babafafbce16283cd1e816f00ad4ca7a995164139f8f19cd8fa2

14

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44044
MD5 b930f795fe1c98e426b96af4f32481d4
SHA1 10987cf029ee0c48385d3c62a495c0e6a13b161e
SHA256 8b61c108868dae55b0d2e9d7674229e099669470cf29ec3dac41b06c77c08406
SHA3 1a5f5ab9508f29074e7d002b0db2c8c8fc853823575e16953b68c72757de23e7

15

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75369
MD5 e9c23d32b6f6ef3e8ba2b0dd34246895
SHA1 186bedb4db5842ef078f7aec2d0ccfb425b27238
SHA256 a4d834667dc5ee7a7df6a8e482a0cc4e951b1ac61972e030343825181b6dd950
SHA3 0bfbf66e9a4285c61b48217b984f099a11cf06283a174a150cf3c1fbd5b2efb4

16

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.9531
MD5 752ce2c44fec6586408d32c73aab9a59
SHA1 36d88c1fd99cd9930c8d3e3868ef412e57ea7ccb
SHA256 abbcf17016a49d3cfac9d26656adec1c75e8439b65a4f913ac65e80ebcab3084
SHA3 84a31447b690527d3b4d1534eceb3ade64f2189b37ec5ff73758b9a06cd63674

17

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.17785
MD5 40bb471c7419b90f98acdedd9f304c2d
SHA1 06e9b99a564e04b35027de9d8f61bd4b8ce5ea69
SHA256 d7d4d8c65e31b313eff48e7c4552a59136d0622b0b6767586e11cd3ec0d57dd2
SHA3 a1d655b077f25e8c90633b0b79076f45a6d88422dfcdddb98bfa9c3a655dcbd7

18

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.55485
MD5 9660e9311f2737b016774f07a5ff056f
SHA1 67570989cb747a61f84b32dee3e04778fc0cf972
SHA256 58550df48dfedad71a4d7e17fb6e0930613b17d04cbf28b284c9aac26b56d1e7
SHA3 e4e3e6f861222a543b640c6db4fafaef679035e6a766299d3e3637ebfbfc47c2

19

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92062
MD5 73283e5ec88eb221bcf0968a5773acb4
SHA1 ed4d7cf233ecb73f6bb330b032815c3607f6f6a1
SHA256 02f14522673c495e53945bf64da7f347f18c306150ea65b387f6d4ad85b683b2
SHA3 2bcdcb7d7fb2c136706a5a07a64b0ed7e823915a8f09056ab26dbff6374f6d87

20

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27851
MD5 45ef4582811ee1d00f47fbe646a6ade4
SHA1 22e37c406922057ae3e26f94b1c5cc1ba315292e
SHA256 5c7657c3ade3c2ebcda9519ab31f2894843c3433155b73ac024a03715c18b79a
SHA3 46f98c546c337e051eb00c10bb399c02bb5b116c3e002e237a0bd3ea4268f9ba

21

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.8232
MD5 b51a7e5acd507bb8626ead55527e30f9
SHA1 2da9f16f1906eeda739ba011d3b0c49c17d09917
SHA256 7ab864884cf71248db4886ff5d78e3977ee2c84c2259af6866ab5b787c778c4a
SHA3 ab822ca20871eedf81a6fd2dbe03afb29794f3e6a59dc0650988ab3c978da240

22

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.17173
MD5 c64bd327414ca9fe5103de429747b240
SHA1 275d31bb9a5592610bf543d7c661af0e6b2c735c
SHA256 fc9971409aa869589bce279d694763876bafe6416ff901949e14179c7fa17f8d
SHA3 0dfd8ea99e6e05a465890ab913a1736a9dfba36ade381a5605d8841dec125ce4

23

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.49584
MD5 02f1385a548868ea37378d755c08a1c4
SHA1 23886099a435b7b090e2cdc315bd1bcee006571e
SHA256 46882985cc666d269b28259766337ce913ca3826c5616b1a6721348fb639ccdc
SHA3 4d1b4c9245655682e362865e857c1ecf6b9e97dc94292f82ace63422f551e072

24

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11195
MD5 63497a6bbe3b081364055cd258fb118d
SHA1 b54856f354e52ef51caff926b3f856c45ec7a99b
SHA256 9673bfba939925ed252915a55c25e1cfd03151bf988f880171f8f791738cdb23
SHA3 1a2a90dd45e8a0addebda16681335327468d7faf09015f0f3269d8f1a59d692c

25

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e0d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92607
Detected Filetype PNG graphic file
MD5 f9e79c980db5cd008c45782aeb73f159
SHA1 ee044db41b5fbdba24508c60ba17557c2392e429
SHA256 3e38513c621040c855c5ce35469fd5a6f4adda614665b79d409db969b11cb8d7
SHA3 605386a4b85c9cb392e830169a6048385e00f40bd23bec6d9862ba3d96c27cc7

26

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70868
MD5 c2db91467f49a93da48aa4dde7e3802e
SHA1 cd4f946465d30ef0f6dc10cb95ac32bbed9d50bf
SHA256 106ef2de274bdc357455e1294a400db3a9aaaff38736c5b22f2553fe2c45d120
SHA3 44794d7cc947f6853d735d66179ba0b93ea9b7e469127f3e3fc8476430da6f3c

27

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.02464
MD5 afe2743d49e3ae110eb5da3e4b84188e
SHA1 11d871ada28487cfff12df9880f9458db0be13b1
SHA256 19c97bbd969acb12ced1219bd1050efae5bd5b4c3a1a474904959dfc3f8ea5c9
SHA3 e9147ec6792211a8aa9d111467cbeb1a905c836f8cbf646704608a3ee429836c

28

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.26123
MD5 5226507400c2f647c6713391f082a314
SHA1 160ac081b4d8d1d2dd9e47473b998e7fe4348fd7
SHA256 e6fae4f944592437858ce1f3301e89938f7522c8a607750ba67e89e75ec7a5ce
SHA3 5e104a495808b5ca25e9a0295ae08d831ee2754530483f8916f45402b005acdc

29

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56986
MD5 ee814755b9d8a65333391517d8887cd2
SHA1 6cb511e1ee8c7f10d47382a33359e24db4856323
SHA256 f21911fd7d46642de1c334a33331d78d80d527a9ae58f4d694552ccbc65a9c17
SHA3 a4f5b0429aee0ec61b82d08bd9d3dae794b8cc1f5ea0a767dc2e6291b0ba32bb

30

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1931
MD5 5709cc53416b53961cde345261567485
SHA1 26a538df20b45b49be35faac2c2cd963c9ea29f6
SHA256 a557f3388bc4e81e53de64cb2fb08c5f37dd3f7e38c339207c5ae779d35600d8
SHA3 917002dd3d496966e781f1e4f1b419eea22a1c475ef729fc3fa9c26e51655ea6

31

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3a93
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94997
Detected Filetype PNG graphic file
MD5 d5961e7f25580042fb3ab8791c5b150e
SHA1 a8ca5875b7d4cbde067ccf6db456db7e758f784f
SHA256 10b0e61f8a6f47723f07b86d6b518dfe00e32ba01f510dbe3a3ce758a1873c01
SHA3 5dcadce8e4ea402126603d5dc821c8fc44a4e81badbfcbe8dcb9935b281dba20

32

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.80651
MD5 5f9d9576b1275bdacbf6044db3dade7a
SHA1 714b484983d5fce906d4f9e8f37d7e48f315bf95
SHA256 186dbc8a8385c6108adc8c8690dc1ab4af6f827bab51ae9243b8996f48eabeac
SHA3 deb03539690eba3b3ffe155484330ed9264075c74f4858b26affc55f15a0c2ba

33

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.10938
MD5 92b830fda5324bd676d9b1ba2e2fb261
SHA1 74239b6b7378855d7364da4a9517050122d0bf8d
SHA256 1eba17ae11834e48609c00ccf840370a1e84d401ce5cfddbb5604ee896335c8d
SHA3 4dd7832a2307f2847476bfa14027ae63f77ad7fd8f7c66af5b137368eaac0302

34

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.33895
MD5 072a53880f51481f35258e11073c6d86
SHA1 ab4e272315d76a44999a32cba29c09d6f4e0f089
SHA256 1007767bd1dcac904ea5d24dbccda097b1e00cedbb176f06b9b80a42db25dceb
SHA3 632f4d00dd356f4ccf7442f2ea45278d6efbd1270c25c949e4f7a36dbee107b2

35

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56143
MD5 bb38995b10f5f02abfa465f272986654
SHA1 b769a8f91fb83a5c2271408af81606634a810501
SHA256 daf3d7c9d4c12d9f4773028a8607aec3780d4a93c492c42772359d278b63bfff
SHA3 5f04f94c46eab9f3ac5c60024e2b72724583745ce61e60bd800596c5304f8d66

36

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01611
MD5 6e97dbf79f6e876c3bd9b50044a71802
SHA1 c0003c8b56af5f605146379d3cd4dec59d360023
SHA256 a8fbb4cb546f88d2b7ffe403db1ac88bf3d2fcc89cf57e75938bb7e27f1946f6
SHA3 d48b2317f8ee9af5a628cfb08470012f2bf565da76700af95227126b64893da6

37

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e1b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93564
Detected Filetype PNG graphic file
MD5 134febe673acb4b73a70fb5a3898119b
SHA1 301ea8fdcf1acf5c7bd1dcf6c2ad0a011b219686
SHA256 a8b83c662935748c2b3ced751ebc4218f765ea596a200be1b0885000801f8347
SHA3 572753013d83d8e3b10cc60e89023c75d2eb26410ebb6558e6a37d248202525a

38

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10304
MD5 d1130e4ba049a12c5fba5f59b9ef6c32
SHA1 9c9f64e4bdc3b54712389a281e4b0ec06b405da5
SHA256 8d9cc1c63a2293265f80b5c3837dbf2de2e84b606ba9cb235b42fa4557e487ab
SHA3 959058a398f0891f9078362a4ea44f08876de3a06cd3c0c9cfa63559947a98b2

39

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42044
MD5 96794ba2ea488b1521ce106c12641e73
SHA1 3df533fc4c7401653fdde69c6fa4c46b99f613f6
SHA256 16c19d88c44aecebd7d584676475f98a2f6dad196c5d7b9fa7785d8475398464
SHA3 b076a2d3af5bc1bce639eb65ee434c7fc7b371ba7ae4f22710acb43795d1fa97

40

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.67964
MD5 8fdd7d8459a08bd71662911b8fd26e02
SHA1 a1f3d6c0707c030f1dde6c63af5a4b0dc2ac5a6f
SHA256 e18c404c69a9be6701ce1ae6be1e7f2667fcdbabd71b5ae51631eeaca9d425d9
SHA3 c915c9f46ae6cb0ec45075e9e641153c8b098233529880c1cebf5498ceb71a40

41

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.98546
MD5 ce42234bf093f75383162c2d05971f80
SHA1 31678be92f1ba5d6e36f125b1dc1d36a72631e15
SHA256 e148622b944b3c1c314e5a15fa119039502d1e8ca5c6075f94d09a43c10c1adf
SHA3 edec86c3579c9f830c4b07244ac531099e59bb7c40d8c27fc00d53108744ce02

42

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.52902
MD5 1be98f8856d824209266f55495b9bdf8
SHA1 7d3bf673126cb5894c0d81f3eae6a8cf5e37dc00
SHA256 83d3349db39d5a47e7eee8a6158edf6d5ce62d7df9a1c75dd436cf38b39ad5ff
SHA3 e79ed09db8ab542cc393e0ab29a6fed1c0951a1103fc419f7fde6d4e00157bdc

43

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x410c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96748
Detected Filetype PNG graphic file
MD5 541d5d9e26c75b88257d2deedccbc388
SHA1 1ee36c090ac5e72c0102906fe494e550ca9c6426
SHA256 0e22260d9252fb28f7cd156b153eaf2fcfd258a06861aaf66c8b220ac31d1ec6
SHA3 29403400389214056c8608c4ead1c631c8c2ace334ac4e4d11f615ab06efeb3e

44

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59827
MD5 788d85a1630b86956257754c722bfa4c
SHA1 9da46f122284c5e2243df3be5e59064c84a4a5f2
SHA256 1d8dec4464be17c6333deafd54b0930df61ba8000b79714feac4f02f0136dcd6
SHA3 5250691982c0d03a685759c7b6b06efc47772d06ecee5f2492a9c7addc7c84a4

45

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.9026
MD5 d88d6ab98ae6197c002c625020fb4a7b
SHA1 03a00e885e1e4414bc6f88cfa76790df60e34782
SHA256 ab61243f5f6efe52b45b813eeb0016bed26b83f0080955bb28e1a08ec71bba35
SHA3 2043f942d3ebf8afb6b73312714e7d0a4bddd2634041b5fda44a89e93c73fe18

46

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.07787
MD5 9a45153ac95ae061e4a1612894449a24
SHA1 d311cbfddeeb851cadbfb9b30ede5528e1322b62
SHA256 0f37a684463d65dd8220087a69cac3a056e43589d1709be89e7fa61e7d73582b
SHA3 01ae5ae51d4f96f95b3f1c9053831005fa02b2c5c0a1706d3345ed72bfe646c4

47

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.41296
MD5 73c7fe306dd3f5cbda2bba555daa7e87
SHA1 47b002599bb3198c1d16678c85da22c6b938a2dd
SHA256 3f791d498f9f07e65d523891da0113a58a269081a995ed50040a2ac3cac7ded9
SHA3 37c85f6423f5bb0a4496d2de89dc39cc72de9851eaaee3b7bb3868c70bdc02cf

48

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00444
MD5 b3b8896e4c8bf8a4f0ff6b59f1d019c1
SHA1 178cd1c1217aae4bd849de3d8a73c97a5dd768bf
SHA256 65c2efad51a23cb4696104a211481344814586c99d8c77005e07964f0cc9fff0
SHA3 868a09843b2cb4d53689e9823961f8faa8e515f97a138e9e99e55a5567dc52ed

49

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xf4a3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88295
Detected Filetype PNG graphic file
MD5 e45c2f582a047b4fb513281ec35febd0
SHA1 61e78c7f319666af5f19167f321a13cbcb5d2646
SHA256 a017e8318eb9ef86a56d681856c4ecd05aa055ca4fc9d82adfa6a3c82385d2cb
SHA3 ba060104ef2a26318d0156aaac1ab1f12ab530759e78172e668f3f6f4cd08b12

50

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3464
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67159
Detected Filetype PNG graphic file
MD5 1a85d1c62af43b01ae16359d3d937875
SHA1 061b454ccabd4cab3745a78912a80891f8c49b7d
SHA256 cad662cabee2d1e8ea8e7764cfab53c49eb44cdf1b2041530450f7d17930bc60
SHA3 30646cca25fd4e0558a3c1858e7815ce548059f61e310723e75d2085ed806c5d

51

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x177b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.84236
Detected Filetype PNG graphic file
MD5 1348dec9fbecaf9bfcf5b3971513c3bd
SHA1 75cd490eaf467416c86986317bf6797282711a71
SHA256 e70e76bb574299ad5ed6ae029a5b0cc0b69b1f39f6a26dd3a2f242cb5210ef57
SHA3 981ce043dc4b8ea7397419b25c014a92a09a284569efec44acd2792e529b2407

52

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6779
MD5 efe3be67bb01df853f9d8ae3d8c0005e
SHA1 be09ec8ff1f2e9a30b2293bec3a6c3ec79fabfd8
SHA256 9503d50afd464c0d236f150d5b033112baf89ba97713c3db4b766cde136b12ac
SHA3 82e3fe2c0320b7a1eb6675304e4de53b08528785898d09c57abd7658d3f6bf80

53

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83135
MD5 8b0cb01e187cbfe0862da2aa6b5c1da6
SHA1 3dfb3f68a3cfb15b851a8b815b980d7d12322bb4
SHA256 89aed24c6421388f20ef16f866bad402f93ca3ff2cf12f5ceecab718aa6c8223
SHA3 6aa89526e9317580c4c93469e3df389deb69f502ab81efddbc857d03495b10e1

54

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99596
MD5 cf2c5f1901109c1cb3c5f86e707474ca
SHA1 eea97ce6f648ebfd977882550523031f5b91040d
SHA256 905a6e0a39bcb546ddcd665ba979b544b151a24ae94deea0c1b17f0ebf2d6763
SHA3 70a9118e8655f6a91fa35bb99ef6759f69b42efc14ba9243fdc0517ced142761

55

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15321
MD5 145e48c2ed399c717ebefa22706f2628
SHA1 f2da8ceb52ff8979aeec8857a2ba9ad4f86364aa
SHA256 349a51ad8ee0d6c7afbf9c36ed4dbbbf34de0afa6466fe15bdc22ae506926c5c
SHA3 a997b1b2c5c802b10398672ed5b0960e6a1c665dee0b61639d672ad71821b0c9

56

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.45271
MD5 6ff0d00921e29821bcc004ef07c56c0e
SHA1 4f9d96094612da18ec85715921ed531b789ea929
SHA256 e3535e5a6efb2e0c5d0c8482a79c1e5a52fd80a19e181f22fb8ecbc9bb20718c
SHA3 dd82a321d8f1bca9359c39a54325ba3e2f697c183cc7122c3347608c7619167c

57

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.6426
MD5 4d9d177343b3b80fa824643e94f7a73e
SHA1 fbd190acd896dd1b6b15376118e0ae41f7be5cc8
SHA256 f4d3f885dbe412a8262cc7f9e8bdacd93bd01641b013f13c7e0ca3528b5ed739
SHA3 7f5ab07b63c28fa54faac03db1c7045f15208b17025306ae23010525438213ee

58

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.77182
MD5 b65ec1cf2f7ceaaa079127354cda50db
SHA1 ef8ddd3a6d26113ea80b42e0487cb466da4c8238
SHA256 798c8643f7ff6c06a4f58af60c5fd6aa71c4475418e7c794bf66d44f8ecbc402
SHA3 acd03f33f1f86b347784027a8c1fbabb014e7c872df1f09eb26c1edca1318906

59

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.1405
MD5 5fba79ae881cab226609c641ef12e8d0
SHA1 ed05146fc3e1ca6ba59e40ff19f05853b0e688e1
SHA256 f1b413c7bf9b870012c8602c75c9928cbe69137071d9460c7a17a5ac433bc36a
SHA3 c023150e2e95ee06180eb0d5a93231e7525c1450b2bab8ced71768ae7f1179c1

60

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.16424
MD5 7634fe8af3db2bfdcaf2559f579e743b
SHA1 2ec4eeee24146c1401d6d62411a544d48d61b59d
SHA256 c3f4f2a39be9f107f04c65ff8aa22bfb10806c494514a3aa2ec2275f7cafdf09
SHA3 9b21ce36244d2a87c120a294fb73c29974365ca5ac45a8e4879e825dbf88d067

61

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.14398
MD5 efc58dc58b5e5f155657fa62bfa6a470
SHA1 4ffe1c6926282ccd355fdfc226a612d7d8af2432
SHA256 e87f562fc9d25218f4193ef742099d7149ed07c8786671ab30fff062d7b9fd48
SHA3 4308173c06cbe7b1d4011be49638db7602d837c39adfed1f09c34ed2698c4cc1

62

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.016
MD5 c5be74be87610326912d798479f59684
SHA1 91d088ed27a6dbbd64e0a4747b553e1f1f988a14
SHA256 bb419cc8aee5f2d505dec565453f129cc4d7d92e2965c341191c1d45adce6a13
SHA3 c096f71b6ce35b5cda7089507de4af4225fee8b94c79c76be1bcc8635f27982d

63

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59949
MD5 6d66e5cf438a4d4e820be6439f25947d
SHA1 f996cb822186f5a2fadd65f9c7a4101acee4d0d3
SHA256 e495fb44bae9b66ea49ddb1c304ee13105002d145f9e6924d930b81541b82a1d
SHA3 297dbfa40775870d591fc0ed7af158554ab11c6974fe3d57aad66fb9eb303156

64

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75118
MD5 b12ffbbf891de5d55149efc169a2b1f3
SHA1 735375beefac489dff5be591a6371ec4d010d000
SHA256 a55168adbe19c650077411b03250c89428a2e01c4af48d17c9116b502ca141e7
SHA3 9db510a7b1e57366be1b0f28606f7300fa9c09ff7c3d8d44feb538fef0937d53

65

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x35f3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95053
Detected Filetype PNG graphic file
MD5 e916f9aecba3fbfb9568fd28380b96b4
SHA1 399c8f5a0a3c7e7a7a7d9e56d3cd0086f77f3311
SHA256 d091fe82ab0ec97a1fd0a181155f50020604848c2d3b52bdcd9566fe8944fe41
SHA3 540d39e6338978b84d4855d46ed8a3ecead5ae2fbf09e68251908c33a08ebbf8

66

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01567
MD5 85e6c5d95c2466e57e100d11dca779be
SHA1 57d0045d8c5a402e584086b2ab30f77b1f809054
SHA256 7a934a60034c9bd9f6457fae7cad6cd22480fefaed14456aa96fc1084526ae1d
SHA3 18018b8cc6fb8872775f2274a0ccf9d9b86f10c44bdf15df7099b243ad1706c0

67

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36418
MD5 13a2e6216131f0a7bd40e9ebfa3abd96
SHA1 59ba8df56c03fe32f76ea1b6ca58e2105b2c522f
SHA256 4094ac613b1d049248292d471eb91d8c5015a5a0a23f579e5859e005f31211e3
SHA3 3261192903c705fd5e67362e71a65482dd6f91f7847220ca5b198a71280e7b26

68

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59647
MD5 31913ed75fefd2a7388c17fbe7a86466
SHA1 fd83fc4c5533912c85d50e993a97dc88ef802d7d
SHA256 7cf1ac9e40c3297f812ed81f91e50ec31473c98c6168d9c3602a267db41e7ac5
SHA3 6b257dc3278500add659e03b705a42b71ed127101e2179ac94c075274854c99a

69

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.90982
MD5 5b6a69a3cae6a325b74c6d43cc54d9b6
SHA1 5a99fd371967b93e70c4e1c6dcdfa8fbcb6d8fc9
SHA256 f521178c68cad559d7ee90e6df38bd864e8cb40b61f3733b2148022f61240086
SHA3 8df84f2089af838cdd5feeeb8effa3107039f6dff27bdb4f68b48bef187e1dde

70

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.6065
MD5 f9b67b44b0c127e0d63eb8afa760f91b
SHA1 3e5ed2cccff860163a30502b4a41353a7ed7d711
SHA256 3646de04938362e03e446debf7ca9582fdac69ee129542ab36de482d5d34dd78
SHA3 fbeb6b8b9d6f4f38e7679d14b7cf281de4e3d440e9df198a0eee1e4d10b443b4

IDI_ICON1

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79908
Detected Filetype Icon file
MD5 e01ed32917e131d38582c82812a0d285
SHA1 5d4d9393888a4dcc250140de703563034db93cb6
SHA256 bdb68d700137c21703bcc1712eddb9ad5dd1889ef889f163ffcdee0423adfd57
SHA3 280c8b76b58a0f4a01170103d9d935edd5019216fd47fc618b8116ed47668376

IDI_ICON2

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
Detected Filetype Icon file
MD5 3aaf2a0e1b243db1e91656775ab299ac
SHA1 4c619462b2bce48ac40c0beeb9d8c757d79829fb
SHA256 10b02a071d18cc2f7210220bfcc24eb66ea3bcc823f7722301f333e340178683
SHA3 4a3e645a208a026f808a44679f9dcde31ff7d48b8357e428933eaaad43a0620c

IDI_ICON_ACTION

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84101
Detected Filetype Icon file
MD5 b42703cdb40e701aa476122c55c7afdf
SHA1 bd4905c18dcc004fbcc950447c772643cad89aee
SHA256 6b89ee52fae17381ce11ea3baea946c88c359c496d55fe777c6d1a327d8c6de0
SHA3 e6a30f33fa9b57d82d22b366391c96131e0b61f6bc2d85725a025617fab5a1e3

IDI_ICON_ANME

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86826
Detected Filetype Icon file
MD5 8f21ce1bba6522343d3187020f7b9cce
SHA1 77801eb498f393a2f4731e721c634b78a31ab5d2
SHA256 d43e1b6c628b860568b8b807be1d6e570b00dd7affb1909dbc910ef60baffcca
SHA3 6bdeb1ff70a27d9040421f91fd4c360146391312e1ce4f5631147c9c14124ce0

IDI_ICON_BRUSH

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86324
Detected Filetype Icon file
MD5 1176e799038d98dbaf21b59aaf5996f4
SHA1 c44f1536b491eafd19ad84ae6536dcc2f44ebe59
SHA256 8892591faed34de65246ebfb3ddbd4b9f1127c7c99403b919b1b06e29b587d9a
SHA3 67188749c73b73883170a76e2c880fb5c55bf86c2a6a4f9af61b1f133d5047e7

IDI_ICON_EXPORT

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89385
Detected Filetype Icon file
MD5 e2887ac675b5df700596b2f32ac77193
SHA1 35b4d76dd4c40dd7a6cc5a78982c9d8be7bf017b
SHA256 36801a570d781a68c21f7b163f2ae381e7a8e14dafe653da80498a43848a3be6
SHA3 d79917d42d9f58c504363989ce3ca615b19f86520c5776c9f1bc9a9e773df65a

IDI_ICON_MOHO

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77987
Detected Filetype Icon file
MD5 6f72e8a1e58ec10693d13d7bcc602342
SHA1 f0f9c1535576d73b30719f6c1f63be3f5ad09902
SHA256 1c0376d979bc31745cecd8f672333120dc7a64963c2f5c4922b23d59ec458478
SHA3 c5fd8e48ba6325a1402e0654bd1c17936953c0affa984f76a5515ce6ebd4c693

IDI_ICON_STYLE

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84352
Detected Filetype Icon file
MD5 13b77806e823a5ffe71eb84362e80c26
SHA1 48d5d0aefdd5a0d155be9a5736dd1f3cc26a6e4e
SHA256 e04b1d60ec8e275a3d5ce491d8fe0aa11b999745d3e6e4fbf3581821ca433a21
SHA3 170b6c0f37fd19733b57a5ecab7633af340ac4c197f4f22f004891c596669405

133

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0xe6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21979
Detected Filetype Icon file
MD5 62c9e8fa3b41dd4477fe7bd586c953b3
SHA1 926e84ea8fdd2ad130a38da9d83a5d52b674422d
SHA256 0ef7e8858675e4c013af0eb69a7c6ae783c75cd0acb5d1cc67353b7886f08a49
SHA3 5604e06052d29f832b773fe85b46ddeb28a89758c19eb29d4df8296a44ff008c

134

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
Detected Filetype Icon file
MD5 bec478eabb51a48dc7d1c3ca0703fe47
SHA1 c8b0488613d21513780c2bf35ade4686097880e9
SHA256 58b22540b4aec26808f6628288e5667846c3252d3dc8b1d2e04aa43744c20f55
SHA3 025e39210899fbab59c6c8c3cdafafd3cad0f54d4478bafa27c979d92a7d9d77

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x274
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32634
MD5 0f2290e6a7836ff056b459a79a3d0a08
SHA1 0a3eacd8fb9adb13e15c155962f72748a77da223
SHA256 812bba2292950f1407e5b30fb87a6342803416613b64e8c6fc6e4b36122b66a7
SHA3 e3df8007e16a54d6d6c832753dd0ae09d9bb40e72fac4987c18d7e8d8dc3c0ea

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06467
MD5 d875a3e09bd74a8f760449a19a351827
SHA1 870df3cd183e92816fb4f92427cafa686f946a33
SHA256 a148bb733a7a6233501d6e615bcd37bedb995c29670798088e6c9c325b4429c8
SHA3 782f36c3fdf8521b0f1ebd9c721ce82161d3bd77c965734f3fd2714a3113db23

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 13.5.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs (EMPTY)
FileType VFT_UNKNOWN
Language English - United States
CompanyName Lost Marble LLC
LegalCopyright Copyright © 1999-2021 Lost Marble LLC. All Rights Reserved.
FileDescription Moho
FileVersion (#2) 13.5
ProductName Moho
ProductVersion (#2) 13.5
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Apr-23 03:28:44
Version 0.0
SizeofData 924
AddressOfRawData 0x13cbd20
PointerToRawData 0x6af120

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140a57028

RICH Header

XOR Key 0x8b35d01c
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 26
C++ objects (VS2017 v14.15 compiler 26715) 1
199 (41118) 3
C objects (VS 2015/2017/2019 runtime 29118) 10
ASM objects (VS 2015/2017/2019 runtime 29118) 4
C++ objects (VS 2015/2017/2019 runtime 29118) 35
Imports (VS 2015/2017/2019 runtime 29118) 6
253 (23601) 2
C objects (VS2017 v14.15 compiler 26715) 8
C objects (CVTCIL) (VS2017 v14.15 compiler 26715) 1
Imports (VS2017 v15.7.5 compiler 26433) 2
Imports (VS2017 v15.9.16-18 compiler 27034) 2
Imports (VS2010 SP1 build 40219) 2
Imports (VS2019 Update 8 (16.8.3) compiler 29335) 2
Imports (VS2008 build 21022) 2
Imports (VS2019 Update 7 (16.7.2-4) compiler 29112) 2
Imports (VS2017 v14.15 compiler 26715) 45
Total imports 1003
C++ objects (LTCG) (VS2019 Update 8 (16.8.3) compiler 29335) 580
Exports (VS2019 Update 8 (16.8.3) compiler 29335) 1
Resource objects (VS2019 Update 8 (16.8.3) compiler 29335) 1
151 1
Linker (VS2019 Update 8 (16.8.3) compiler 29335) 1

Errors

[!] Error: Could not reach the TLS callback table. [*] Warning: Section .text has a size of 0! [*] Warning: Section .rdata has a size of 0! [*] Warning: Section .data has a size of 0! [*] Warning: Section .pdata has a size of 0! [*] Warning: Section .vmp0 has a size of 0!
<-- -->