db9683178efe755f8be5633a170b3976970dec44d971ee522c2d3ffbc1ebc9a0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Nov-12 16:50:07
Detected languages English - United States
FileVersion 1.0.0.0
ProductVersion 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • adobe.com
  • http://ns.adobe.com
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://purl.org
  • http://www.iec.ch
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • ns.adobe.com
  • www.iec.ch
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Unusual section name found: .debug
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowW
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegUnLoadKeyW
  • RegSetValueExW
  • RegSaveKeyW
  • RegRestoreKeyW
  • RegReplaceKeyW
  • RegQueryInfoKeyW
  • RegLoadKeyW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
Possibly launches other programs:
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • CallNextHookEx
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetLogicalDriveStringsW
  • GetDriveTypeW
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Queries user information on remote machines:
  • NetWkstaGetInfo
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC-3 timezone.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 da66f820aa5dbfc5859962a461644b02
SHA1 7bd1fd97fa94f717372590155607222f99db7e22
SHA256 db9683178efe755f8be5633a170b3976970dec44d971ee522c2d3ffbc1ebc9a0
SHA3 c63a90403e1f299b7f06a5ef7532ee17434414dca842aa3e5334009af9053a9f
SSDeep 98304:LoHIEd8ExP71B1msH/PBh6bGQnpDYMeO+ucwalZLCwpokCFCxJD9LKe:Qj8WtmsfmPDWVh
Imports Hash a87a0a0677b596c5ae8f02d394e10d23

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 12
TimeDateStamp 2018-Nov-12 16:50:07
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x213a00
SizeOfInitializedData 0x980a27
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00215680 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x216000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0xba2000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 69e6cfc9e2d4f8c20c3b19075dafb25e
SHA1 e6385db42c39acbb960720bf5e812e89c724ea6a
SHA256 06491cc5cbc8477ac65ad555ae0fd6501cfb82ec67200aecf4c08b6446bc2397
SHA3 eb0f6da766eb8fb0dba4044d0c5c7f7e399f1d44db9a31e2742a0ebff6f14cd7
VirtualSize 0x212144
VirtualAddress 0x1000
SizeOfRawData 0x212200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49127

.itext

MD5 23d9540cc94e62b261ccd4031cfdab46
SHA1 83beb734f4a93bac3883dde21431aae8ac3fb003
SHA256 05090b20a7f8bf13410998abb156db7da17c566a3fd7a4c3ee5e060cf59a7aaa
SHA3 c5b0c9223f5206a49815b82db50ee380e40eda3f2748c5903939fe8a7fc6e33b
VirtualSize 0x17b4
VirtualAddress 0x214000
SizeOfRawData 0x1800
PointerToRawData 0x212600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.26947

.data

MD5 a7c8f66186b378289d675a946ab83752
SHA1 717be2e4817407dc514ae499f362d3ab6edaa940
SHA256 1a6ed4b7ad533460d82393f95b6e9538e3bab49d0c50a4e67c118ec48b4d032c
SHA3 5b96c10494045802eebad714be97861275fbc3121e3adef358647cdfa19b57db
VirtualSize 0x92c0
VirtualAddress 0x216000
SizeOfRawData 0x9400
PointerToRawData 0x213e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.1501

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x5838
VirtualAddress 0x220000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 16b1991ba2e63d7ae939d8ae92f87c1c
SHA1 433d564ce3b50fca18863cd8d3854a308be1232d
SHA256 c2a3305b3b3a6488d28a58597e6975d4fdca16462e0caf3f6cd3022d3abaddbf
SHA3 602148d074b61532ff3d19408ad0f4443b4e94d000a708724bc2de2c43546295
VirtualSize 0x3a1a
VirtualAddress 0x226000
SizeOfRawData 0x3c00
PointerToRawData 0x21d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.10032

.didata

MD5 c2b2e66d73a43057c71b306eb6fe58f5
SHA1 f461d9a8d517ee985fa9c945af9acc728eb40ea7
SHA256 1a0cba17b813b5698b90f3ad8b97b8c3fc09af34667c08e666269ad26f24607b
SHA3 ec35b7008beb5d6ec0dc4b487bf5ee6a8461343ec4fd4214b9907f02c18d1204
VirtualSize 0xa9c
VirtualAddress 0x22a000
SizeOfRawData 0xc00
PointerToRawData 0x220e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.9268

.edata

MD5 a2acc788418f746a2cbc0e16fa467681
SHA1 dd7cc57916bc4b035124da28f8e5743549753e88
SHA256 c582a5830e6f5ab4fc84e3e0ecfae65934a20ca55e6b01c9084d0480eca991e6
SHA3 2ea0bbfd2ddca6516bc3546613b1698f1a364eb0867d03699e2641f6073bd3ea
VirtualSize 0x7b
VirtualAddress 0x22b000
SizeOfRawData 0x200
PointerToRawData 0x221a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.48563

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x40
VirtualAddress 0x22c000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 7636983c4ab052066f7a0d31935029ae
SHA1 d1f324681e3bc85844e8eb1a243709a31147d51c
SHA256 2f004c266fddd31cce32e2b197ff3bf7c70a98e0c238006ccb42a6baf563f84c
SHA3 f36378979b0fe1193a5745bde8d8f4c3cbc40663be53b59c49fa981e95af8218
VirtualSize 0x5d
VirtualAddress 0x22d000
SizeOfRawData 0x200
PointerToRawData 0x221c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.36679

.reloc

MD5 e88a1de5465a8c606822062afbd29fa3
SHA1 4fb9639dfd0a05038bb6e280f8c1a8eb1f121248
SHA256 7e7569865cde6dc0bb03c6dee2195b1e13ce9994b56b56d617a7385221895983
SHA3 556c0a5e7be246a7f983d5e1c477e07095f27226d1814018133f01da460189ae
VirtualSize 0x2e64c
VirtualAddress 0x22e000
SizeOfRawData 0x2e800
PointerToRawData 0x221e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.72275

.rsrc

MD5 f48ff724aa2a5558e6048bc40eebd7d1
SHA1 edb4bc386b448b93168c9481cabe10c989037995
SHA256 e5aabbe5b7ad7d12f1ecab17309950dfac626dcfad5b7c1333627532d153fe40
SHA3 3e03850f73fcf83ed1f9357823f61f6048b64cd81781f23242544b099d1d7165
VirtualSize 0x3fe00
VirtualAddress 0x25d000
SizeOfRawData 0x3fe00
PointerToRawData 0x250600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.37561

.debug

MD5 cc30e7bd451e4ea36ed7c8be684c5e09
SHA1 93f40e71168c41a422f43bfc90f4b3c9d35bb647
SHA256 a42c62dfa9e0d4f10c8cf6e8c3ceff3f469397f4620835a5c91d023593050813
SHA3 52759f2850ac86a6762119fe7d2c30d6e256eb8018c18dbe5879df86cb803ec9
VirtualSize 0x904427
VirtualAddress 0x29d000
SizeOfRawData 0x904427
PointerToRawData 0x290400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.29558

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll CharNextW
LoadStringW
kernel32.dll Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle
kernel32.dll (#2) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle
kernel32.dll (#3) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle
borlndmm.dll @Borlndmm@SysGetMem$qqri
user32.dll (#2) CharNextW
LoadStringW
gdi32.dll UnrealizeObject
StretchDIBits
StretchBlt
StartPage
StartDocW
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetRectRgn
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SetAbortProc
SelectPalette
SelectObject
SaveDC
RoundRect
RestoreDC
Rectangle
RectVisible
RealizePalette
Polyline
Polygon
PolyBezierTo
PolyBezier
PlayEnhMetaFile
Pie
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsW
GetTextExtentPointW
GetTextExtentPoint32W
GetSystemPaletteEntries
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectW
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileDescriptionW
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
GdiFlush
FrameRgn
ExtTextOutW
ExtFloodFill
ExcludeClipRect
EnumFontsW
EnumFontFamiliesExW
EndPage
EndDoc
Ellipse
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateICW
CreateHalftonePalette
CreateFontIndirectW
CreateDIBitmap
CreateDIBSection
CreateDCW
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileW
Chord
BitBlt
ArcTo
Arc
AngleArc
AbortDoc
version.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
kernel32.dll (#4) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
kernel32.dll (#5) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle
netapi32.dll NetWkstaGetInfo
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CoUninitialize
CoInitialize
IsEqualGUID
comctl32.dll InitializeFlatSB
FlatSB_SetScrollProp
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_GetScrollPos
FlatSB_GetScrollInfo
_TrackMouseEvent
ImageList_GetImageInfo
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Copy
ImageList_LoadImageW
ImageList_GetIcon
ImageList_Remove
ImageList_DrawEx
ImageList_Replace
ImageList_Draw
ImageList_SetOverlayImage
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_SetImageCount
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
user32.dll (#3) CharNextW
LoadStringW
msvcrt.dll memset
memcpy
shell32.dll ShellExecuteW
Shell_NotifyIconW
winspool.drv OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
winspool.drv (#2) OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
kernel32.dll (delay-loaded) Sleep
VirtualFree
VirtualAlloc
lstrlenW
VirtualQuery
QueryPerformanceCounter
GetTickCount
GetSystemInfo
GetVersion
CompareStringW
IsValidLocale
SetThreadLocale
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GetLocaleInfoW
WideCharToMultiByte
MultiByteToWideChar
GetACP
LoadLibraryExW
GetStartupInfoW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetCommandLineW
FreeLibrary
GetLastError
UnhandledExceptionFilter
RtlUnwind
RaiseException
ExitProcess
ExitThread
SwitchToThread
GetCurrentThreadId
CreateThread
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
FindFirstFileW
FindClose
WriteFile
GetStdHandle
CloseHandle

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0x22a1c0
DelayImportAddressTable 0x22a1f8
DelayImportNameTable 0x22a2fc
BoundDelayImportTable 0x22a400
UnloadDelayImportTable 0x22a4d0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0x222c5c

TMethodImplementationIntercept

Ordinal 2
Address 0x62e00

1

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 4.33809
MD5 30c1d94734f11d32ba542634cbf99807
SHA1 9222223aa440bb066d6240f92bfe1dd457d52c4f
SHA256 c1525d8d971f44089980f97c93c76e886b026717ca7aa1c32b4182cab7931b9d
SHA3 7cc004d3023de26f7790ed833bb278788b00c6561a3ab9a32c21f1f1c87b8176

4073

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x114
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.06419
MD5 ce44804a25ed6817c4403321d788d270
SHA1 85bf042fae4ab0bcccc5a6a402d5042729c42a6b
SHA256 e77a07b44beff0dd0e6b572dfb648db5d960e5ebf37b43d845651113a7171212
SHA3 db35c8c60be0a2421a51ae78d20c2127d155ab2f90b1cea4252858b929046b94

4074

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x42c
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.25021
MD5 f5a0b4f71f73e7716137fc6f64f1e4b8
SHA1 18f256452c8d7ea020fb166353642fdc10f78e23
SHA256 9d10b0941dc659ad4e63432a08414528ebd470cf67a71b6e453e188f485fed92
SHA3 ad0e39ff03ce891a0deeabfc4db3375d555e623eab6dc7fabd18e2665c9a1880

4075

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x358
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.38031
MD5 f6aafcdbdefe7ca2a941b4d8381c8aff
SHA1 778935e765a9b9c62dd5b892bb34150aaf545764
SHA256 b61babb88319e9bc8f8c8f528b2ef5f4a0d192b07495508fa46c32d4c68f0d94
SHA3 b046cb1b165f479e015b9acdb335a057578cec884bbd2b462f36ca0f8de4c82b

4076

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2cc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.31038
MD5 c21ca2faa430b64f724cc9f5a03989a5
SHA1 edb15e353ff385871c1074493e0b79b9f191018c
SHA256 6bc1811f2d91d0769ea72588bc162b21e21ace2e4a781fd2ad0be00a57c14e5f
SHA3 5b350c9a4c13f44372478b4c037cdceba6618e1dd8991bd42c39429fee5ce1b6

4077

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xbc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.48379
MD5 f3d34521fcb7b6517853412f01fdaf1b
SHA1 906364b239f9dc8e320a7c872dee6a483adcec97
SHA256 45b2c7a2c3f36ebc21ebf6dcd3424722970f3f183b704cf0e1adf00a0ce8f3ee
SHA3 6ed1011ceadd13b01574e1975f3f2fb7708a951519a61e8c2e8667b7753cf156

4078

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xfc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.48702
MD5 f09129856bc06350c3cf136d50722917
SHA1 f92347b17397b121cbeaacca9fada741f43d5853
SHA256 46d3fd0ce3ada4ff2b73c35fbe472dadc5f53b2d6c66121f82bfee9e93bd12a6
SHA3 2edcb0cf28fb3af248d1832f00bafa006d62214c9839bd3d161f008d17115378

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.2477
MD5 8bf989b89f7d4b0477c3a5cc3caab1ba
SHA1 0359cbb8594405b760c4cfe8f10ecba464331e3f
SHA256 d43e7265013451cb43572ff5a601f6c9e481e723cb17df8f586b6b40546621d4
SHA3 dfbc56035df3dca3aaada754f1db93b2fdff3d775950e5de7e89e701412ab5f6

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x418
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.31562
MD5 0e856c58f50712b278e8f59eadf1d8d4
SHA1 b4d9fd45ad3be1af521c7c88aa53f662fba83d50
SHA256 dea78197cc4268733b3bd9765b9a2d6d4d11ac421c3b5815c90318aced904895
SHA3 1c99296a2991340fa3a5096c0f60f894543f64434324f27c54ff136d1abb1e65

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3cc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.2742
MD5 e3c38309101e1b6f6f4a77b384355292
SHA1 bffbcc1d151dfe0a18ea320b10507ff24de1a9d0
SHA256 689dcc03067643987ba7b0a1a454b29709bff3c7fb0bcc02ae1e3ab054735086
SHA3 38553c5246eed90f659d383631d3aba22ca1ba4bf6e6be77c115c89e69c71504

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4e0
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.23872
MD5 3442c6e6f5f1ffdd75ba3019962f7a77
SHA1 58c78f7cba6f4e7d1499c3561b91f56879f949ec
SHA256 41170c389dd569c9c716cc2c53dd9f0e50cf1ebaf6cfdebea6963e89dfdec1ed
SHA3 da96df7b1a0dc9d003307df22f0fa8cde37afc1c40f2297d345a2f0ebaee9f0e

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x200
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.31139
MD5 fd81117ffb04e0747dcdddf9e796260a
SHA1 1831a67d7249029a22dab6d575b24178aa539e0f
SHA256 2e0d9ea2f26b1f0545f98efa29dc0a4ab76815ab0c73e4d9057442f72ad5523b
SHA3 593f1436c28864d47a4ddbdbe1183aa49bff46fc07af5d9ba557f799c035dbed

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x44c
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.42182
MD5 c50a709aa835f1476a740908b601b14c
SHA1 463069c83341560604e7c7c92292cc16098af051
SHA256 d288589c6ac2c9b13148abb4371f1d1ffc4af2ab92cf66f16781607a01d3eb36
SHA3 56d31f92f87fd5dea92b00255798cf65d02893b66b47cbb3bc4dda0ba7955992

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4a8
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.31433
MD5 31c14ad9955a06c05c3f07f2be629795
SHA1 e090787ac5e860d18cd527239da95e522d2544a6
SHA256 64f48cd636265aa0b27d11edc2d37e3325de8a02fa96153b3642188c8c7bcb55
SHA3 3bff26b56ea2d6a95d8a4fbb824334307c78b5aca7f864e773b5f80e6a5fde94

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x534
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.22167
MD5 0124a97a450d0aca2550e26542b6e850
SHA1 adc24fa768b7a7d3faec49a433f5e2a19aec46fe
SHA256 c6ba2e8913455b6c752653d6b320c8ef050c9390215578dcaa8c5cd50191cb05
SHA3 66d31a04dd95ceef2b65e2701f11bb80aaa48d73908b62edd909aed70a53cf2c

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x380
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.21674
MD5 6c75728845a1c40b25049359949f0218
SHA1 bc64f92cae2f03d3cb785d88d050f64e80dc12ed
SHA256 3c56c5e05f2ba7ded1f3745fa098c1f615ef9d62235d5fb7ada75f5ee7c7ccaf
SHA3 bc0987dad3c601addba50acc41b77b8cba01b79ba6595772531547d6b90789ca

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x398
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.32043
MD5 01920569645d7ae24a886afb8a1ae324
SHA1 abf85d5ec58d609d40b4408abd65129965a2a505
SHA256 748e84fbc114dd11acfa704518f9fb2ea6cf7927642345c0980a37b33b2a61cc
SHA3 427a2ac080c1ff26a1b82bfbf0b3edded089848e6562ce5d7fabb124363e43b1

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x450
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.33016
MD5 1b066e5c0c9e3988591394c48d5c7812
SHA1 1b8384cd62aed4bd3eb01dc433a003318caa7e28
SHA256 4aaeadb8aac2f950f466c8ef2a220aaeac83dd7e509545b860be4b207a086b0d
SHA3 6be354d90b146fceaf1a8803efa2540d002b78cf28558b3d0591c4a4822218b9

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x138
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.24214
MD5 87f6bdf5289355184b37d9ed2ac0d5b8
SHA1 096890ce75d420e35a0137371c035ae9d5058012
SHA256 dba5efa8ee7a17709bd38074049a0b5217c2fcf9342ae7d4619ca283e55edbbc
SHA3 1a815626e80459b333f93bb37269b91ebb159e7d765d11b924e8af1113296059

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.34889
MD5 41e84c55d83e38e1b0ccab4f95866254
SHA1 450faac12f2e13711bfc14c90b000d3cf66d9e5c
SHA256 e04403c92735b3fc70823791da7ca19ed2a76b68328a76743f07290479c44652
SHA3 5ebd657deaf91b038845ad4b68ebcec97e3c47da836a637a570e0d27d0a48024

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1f8
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.3829
MD5 5822b5b23e5754e3b050b0eff0407eb3
SHA1 72f85448cf4fe6f7c0b41a9c931d91706eadbf82
SHA256 9e5f1faa606494330030f5c13e152ab8237f25949156dd69b04f8a1c0f11b330
SHA3 5f4ed303a2a73783d08f4e86f3c53ed50974ee54f79fea4b1306f316e6c6a884

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x40c
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.32044
MD5 f99c1adba81b46ddaea9a92461239d73
SHA1 aa89678f64327ecf1e9acc5d34debcebf8067c9b
SHA256 f9ed8263a2347eb12b140d3a1fc44a084e63b882d168e1a8ca77d33280ec2549
SHA3 c6857eeb8445b6222f495c6470f1bd8d066c48766484e4d7b2c0c180444bf8c4

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x384
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.32615
MD5 84466111b5f73a0bc891562c866018be
SHA1 0addd4c1953c3ce80a8b8200cf7e6e5f1539435b
SHA256 bdba9e6e967a308b2e7d27f009e36fc117e37da8eea35715e7033716cde61bb1
SHA3 a325bb8e3948f5dc93527d99a1140c6307100be613480dfee5c0fd7e775a9043

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x318
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.33405
MD5 0cce9b165b6494fb6ca6af28cf356fa8
SHA1 623aafe23d80141cd55f913fd059d56bfa5cc37c
SHA256 91a1a79d1c5d33e5840ae5847f3e4e9dda646078e189940237ba3840c2c899fb
SHA3 af4b6e56b3bfdc31ffd148c554a46c800b70824578fa7bd3bc28aaa7d11d24b6

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x31c
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3.23257
MD5 b7d943eaf113f1472e06777675f30a58
SHA1 e6f429dd8eb3563a1133b49753bbb4ba4ee6e37d
SHA256 4dba5636f99bf92601bfc496523154ee96c03f046da80edaaf2fdbd9242bb255
SHA3 6fd686d149ef19be41703a291ed5a6b6e7c3a38c24f3d7fb3a65b95370c2cb73

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x6cc
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 5.19156
MD5 af2dde5672db34f27bba13cc38db999c
SHA1 9f93d190fd4d15841dbefd72ac2e64639fa9c5ac
SHA256 b92ae8e4d25ba8a37e734355773074254af72af2e0d832b7410de4d420305708
SHA3 b466b0c93ef53e7f44a036428f8c2d0a6b042c76f3e178295de444c5f57dc4a3

PLATFORMTARGETS

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 1
MD5 25daad3d9e60b45043a70c4ab7d3b1c6
SHA1 0e356ba505631fbf715758bed27d503f8b260e3a
SHA256 47dc540c94ceb704a23875c11273e16bb0b8a87aed84de911f2133568115f254
SHA3 47b7fb6f259cfa242dc8e381efb31dad613f8bfe5a8a92f524d1a0a7058c56dc

TFRMVIAIMOB

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x38216
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 5.28229
MD5 3941ba09c0206930dea1e00dc1617c3a
SHA1 a1ecb7b9722aa5d34847ff6f3251a0280cc0b46d
SHA256 c683841a17475cddbd05c6a39fb1e84008e80f360ac7aec1a72ed5266d1987a2
SHA3 d22c62733396cf4fc7ac5fb5d50b70cb1a6fa379e44e3b238d64f945d61e78bd

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 1.7815
Detected Filetype Icon file
MD5 3c68f77c35c26ff079a1c410ee44fa62
SHA1 0b40150c95fc2c6414c90d44ee78b8d8814b3393
SHA256 a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0
SHA3 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x140
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 3
MD5 d7073783a22528cccc420b6e25c7431f
SHA1 f405884e4509147807ca9fc353c9a9037c258b7d
SHA256 bc7ff32be85eeaaf8ceb824d1bcf43498b8e02455430a89cc2805f791924ffa9
SHA3 f15c1f93a4cb7d50be0fe7f4714ba44247fb2dda790f775d8b8b7ff0e5995a04

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3af
TimeDateStamp 2018-Nov-12 13:50:08
Entropy 4.96472
MD5 96d52087b247d2d4c7834fc436530505
SHA1 b8e02771c29468901a7258bd32bc8b5aa55a0cec
SHA256 0b217924128c613eb9be2c9c71d6962b45704b442f82b79e35c64177929f723e
SHA3 f4f22c0c5dfce96b6e74c6195a1b22f9425469f586f34b4690ee556ed1a0ec10

String Table contents

Dispatch methods do not support more than 64 parameters
Cannot change the size of a JPEG image
JPEG error #%d
JPEG Image File
Style class '%s' already registered
Style '%s' not found
Style class '%s' not found
Invalid style handle
Invalid style format
Class '%s' is already registered for '%s'
Class '%s' is not registered for '%s'
%s parameter cannot be nil
Feature not supported by this style
Style '%s' is not registered
Cannot unregister the system style
Style not registered
Cannot call BeginInvoke on a control with no parent or window handle
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Length of value array must be >= length of prompt array
Prompt array must not be empty
&Username
&Password
&Domain
Login
Cannot remove shell notification icon
%s requires Windows Vista or later
Button%d
RadioButton%d
Caption cannot be empty
Unable to load style '%s'
Unable to load styles: %s
Style '%s' already registered
Down
Ins
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
All
Clipboard does not support Icons
Cannot open clipboard: %s
Operation not supported on selected printer
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
&All
N&o to All
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Enhanced Metafiles
Icons
Bitmaps
TIFF Images
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
Cannot drag a form
Metafiles
Text format flag '%s' not supported
Invalid image size
Invalid ImageList
Unable to Replace Image
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
Invalid time string: %s
Invalid time Offset string: %s
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid pixel format
Invalid image
Scan line index out of range
Cannot change the size of an icon
Cannot change the size of a WIC Image
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Error writing zip file
Invalid Zip Local Header signature
Invalid Zip Central Header signature
Support for compression method not registered: %s
File must be open
File must be open for writing
File must be open for reading
Zip file must be empty
File name must not be empty
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Observer is not available
Invalid date string: %s
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows 8
Windows 8.1
Windows 10
Error reading zip file
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Argument out of range
Argument must not be nil
Item not found
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Specified Login Credential Service not found
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
No help viewer that supports filters
Invalid argument
Index out of range (%d). Must be >= 0 and < %d
Length of Strings and Objects arrays must be equal
Class %s is not intended to be constructed
Invalid Timeout value: %s
SpinCount out of range. Must be between 0 and %d
Timespan too long
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue
Value cannot be NaN
Negating the minimum value of a Timespan is invalid
Invalid Timespan format
Timespan element too long
No context-sensitive help installed
No help found for context %d
Unable to open Index
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Cannot call CheckTerminated on an externally created thread
Cannot call SetReturnValue on an externally create thread
Parameter %s cannot be nil
Parameter %s cannot be a negative value
Input buffer exceeded for %s = %d, %s = %d
Invalid characters in path
Invalid characters in search pattern
The specified path is too long
The specified path was not found
The path format is not supported
The drive cannot be found
The specified file was not found
The specified file already exists
The given "%s" local time is invalid (situated within the missing period prior to DST).
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid stream format
'%s' is an invalid mask at (%d)
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
No mapping for the Unicode character exists in the target multi-byte code page
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Unable to create directory
Invalid source array
Invalid destination array
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
<unknown>
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
Too many open files
File access denied
Read beyond end of file
Disk full

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 1.0.0.0
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x62c000
EndAddressOfRawData 0x62c040
AddressOfIndex 0x616c10
AddressOfCallbacks 0x62d010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.