de0ea31558536ca7e3164c3cd4578bf5

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Feb-22 16:35:43
Detected languages English - United States
Debug artifacts C:\JobRelease\win\Release\stubs\x86\Updater.pdb
CompanyName Caphyon
ProductVersion 18.0
FileVersion 18.0
ProductName Advanced Installer 18.0
LegalCopyright Copyright (C) 2021 Caphyon
InternalName updater
OriginalFileName updater.exe
FileDescription updater 18.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • InternetCrackUrlW
  • InternetCreateUrlW
  • InternetCloseHandle
  • InternetSetStatusCallbackW
  • InternetSetOptionW
  • InternetOpenW
  • InternetGetLastResponseInfoW
  • InternetReadFile
  • InternetQueryDataAvailable
  • InternetQueryOptionW
  • InternetConnectW
  • InternetErrorDlg
Manipulates other processes:
  • Process32FirstW
  • OpenProcess
  • Process32NextW
Info The PE is digitally signed. Signer: Caphyon SRL
Issuer: thawte SHA256 Code Signing CA
Suspicious VirusTotal score: 1/71 (Scanned on 2025-02-04 07:17:47) MaxSecure: Trojan.Malware.218443187.susgen

Hashes

MD5 de0ea31558536ca7e3164c3cd4578bf5
SHA1 5cc890c3ade653bb1ed1e53dabb0410602ee52df
SHA256 6e599490e164505af796569dce30e18218b179b2b791fe69764892b3ed3e7478
SHA3 22bbca620ccfab6a40abda00e7f7e41ea52c7d5269c95f1578f40e4daf289118
SSDeep 24576:eZwu3kI1OqRsSLJG+tr4mr08m5GV1eFSxdRMfJs:w/3DUqRLJGLQwGVQSxdRMfJs
Imports Hash 627503773504977b8ac33b059b09283b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Feb-22 16:35:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0xaa400
SizeOfInitializedData 0x4c800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00076B92 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xac000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xfb000
SizeOfHeaders 0x400
Checksum 0xfe570
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ec4a0dd59268d64b2a32d82ffa2deb08
SHA1 eca4709034af9ceb15a8100c312dcfc5164d8be9
SHA256 dd4a953d2a123633d439e70c99a8a7fc8b7704b12341f28823e3b1ce589ae83d
SHA3 46fb46cdfe7bf32de6b010d2cdb5824b7b523ebda18a11547397656c8d38819f
VirtualSize 0xaa26f
VirtualAddress 0x1000
SizeOfRawData 0xaa400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51276

.rdata

MD5 33da09e16e1ba5d8272177321bf75daa
SHA1 1b531c347b72881ca2b5c9a2b130437afaf2b8c4
SHA256 881a737e664fd141df3db3a9b200bdf20dec1b6fd5d89930c349ab4b6336ee8b
SHA3 30f3f229b9e745a10b0268e910039f3f2b35f3515d777918edc4a4c801406ccf
VirtualSize 0x2d7b0
VirtualAddress 0xac000
SizeOfRawData 0x2d800
PointerToRawData 0xaa800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.83648

.data

MD5 4decb4e823b65b9d9b33c0823d63e755
SHA1 b0fc5ba124e62956124c0bb0ecbf5b1e7bdce981
SHA256 e196c75296ab97f3ef34539924317d202b576a10f5f80279883e6ea578eea94f
SHA3 576e1e7009f2ec6990d7c5cec0a4dbf0f244af3d5ea821939038ca180a99a5fa
VirtualSize 0x297c
VirtualAddress 0xda000
SizeOfRawData 0x1400
PointerToRawData 0xd8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.79071

.rsrc

MD5 cb929afb99804606ba6cdf304d295bd3
SHA1 cdec052cbc24537a8e5b6a3bfc3d23b92e95e876
SHA256 7e6dda618d6767e9c54e47dcc91679b661ff7673584d38f678cf0054a4f2064c
SHA3 29940ae46b93aba3a17fcfd1823baff29641c694bced878b1780a88ce066dbef
VirtualSize 0x13ddc
VirtualAddress 0xdd000
SizeOfRawData 0x13e00
PointerToRawData 0xd9400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.57725

.reloc

MD5 4485ab456468b23ee3fa81d8d442fb4e
SHA1 eca351680f789c1b7307ef4e9dd4369f5f52f7e9
SHA256 fd2eabcd8852d7bd30fa804464a141a667c9ec863220d4a99bc76fc7f1d5b457
SHA3 9804f94c4d026f46ae81946f50f65896046423839f107db9905989c2d73b5a1d
VirtualSize 0x9db4
VirtualAddress 0xf1000
SizeOfRawData 0x9e00
PointerToRawData 0xed200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.56594

Imports

VERSION.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
WININET.dll HttpSendRequestW
InternetCrackUrlW
InternetCreateUrlW
InternetCloseHandle
InternetSetStatusCallbackW
InternetSetOptionW
InternetOpenW
InternetGetLastResponseInfoW
InternetReadFile
InternetQueryDataAvailable
FtpGetFileSize
InternetQueryOptionW
HttpQueryInfoW
InternetConnectW
HttpOpenRequestW
InternetErrorDlg
FtpCommandW
FtpOpenFileW
msi.dll #224
#173
CRYPT32.dll CertNameToStrW
CertFreeCertificateContext
MPR.dll WNetAddConnection2W
KERNEL32.dll GetConsoleMode
GetConsoleOutputCP
GetFileType
SetFilePointerEx
GetFileSizeEx
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
CopyFileExW
GetLastError
FileTimeToSystemTime
SystemTimeToFileTime
CompareFileTime
DeleteFileW
MoveFileW
CopyFileW
CreateFileW
CloseHandle
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
ReadFile
SizeofResource
LockResource
LoadResource
FindResourceExW
FindResourceW
WideCharToMultiByte
FindClose
GetSystemTime
FindFirstFileW
RemoveDirectoryW
FindNextFileW
GetFileSize
CreateDirectoryW
SetFileAttributesW
GetFileTime
WriteFile
SetFilePointer
SetFileTime
LoadLibraryW
GetProcAddress
GetTempPathW
GetTempFileNameW
GetSystemDirectoryW
LoadLibraryExW
CreateToolhelp32Snapshot
Process32FirstW
OpenProcess
Process32NextW
GetCurrentProcess
GetCurrentProcessId
GetExitCodeProcess
WaitForSingleObject
FreeLibrary
FindFirstFileExW
GetModuleHandleW
Sleep
RaiseException
LocalFree
GetTickCount
LocalAlloc
GetUserDefaultUILanguage
FileTimeToLocalFileTime
GetDateFormatW
GetTimeFormatW
GetLocaleInfoW
CreateProcessW
MultiByteToWideChar
FormatMessageW
SetLastError
GetEnvironmentVariableW
GetModuleFileNameW
DeleteCriticalSection
InitializeCriticalSectionEx
lstrcmpiW
VerifyVersionInfoW
VerSetConditionMask
lstrlenW
CompareStringW
GetExitCodeThread
TerminateThread
CreateThread
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
EnterCriticalSection
InitializeCriticalSection
LeaveCriticalSection
OutputDebugStringW
GetCurrentThreadId
GetLocalTime
FlushFileBuffers
GetStringTypeW
ResetEvent
CreateEventW
SetEvent
GlobalFree
MulDiv
QueryPerformanceFrequency
QueryPerformanceCounter
GetSystemDefaultLangID
GetPrivateProfileStringW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
UnmapViewOfFile
ReleaseMutex
CreateFileMappingW
MapViewOfFile
CreateMutexW
OpenFileMappingW
OpenEventW
lstrcpynW
DecodePointer
GetACP
QueryFullProcessImageNameW
IsValidCodePage
VirtualAlloc
IsProcessorFeaturePresent
FlushInstructionCache
InterlockedPushEntrySList
InterlockedPopEntrySList
InitializeSListHead
EncodePointer
IsDebuggerPresent
LoadLibraryExA
VirtualQuery
VirtualProtect
GetSystemInfo
GetOEMCP
GetCPInfo
InitializeCriticalSectionAndSpinCount
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
ReadConsoleW
WriteConsoleW
SetEndOfFile
VirtualFree
GetModuleHandleExW
ExitProcess
RtlUnwind
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
WaitForSingleObjectEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
GetStartupInfoW
GetStdHandle
USER32.dll GetSubMenu
LoadMenuW
ModifyMenuW
GetMessagePos
SetCursorPos
RemovePropW
SetPropW
GetWindowDC
DrawEdge
GetActiveWindow
LookupIconIdFromDirectoryEx
CreateIconFromResourceEx
DialogBoxParamW
MoveWindow
GetSystemMenu
DrawMenuBar
RegisterWindowMessageW
PostQuitMessage
SetMenuDefaultItem
GetMenuItemID
GetPropW
MonitorFromPoint
GetWindow
ShowWindow
IsWindowVisible
SetForegroundWindow
MessageBoxW
GetDlgCtrlID
FillRect
TrackMouseEvent
DestroyWindow
EndPaint
BeginPaint
SetCursor
RegisterClassExW
TrackPopupMenu
KillTimer
SetTimer
GetDesktopWindow
PostThreadMessageW
GetDlgItem
EndDialog
MonitorFromWindow
GetMonitorInfoW
GetWindowRect
EnableMenuItem
SetFocus
ReleaseCapture
GetCapture
PtInRect
ScreenToClient
GetCursorPos
UpdateWindow
InvalidateRect
CharNextW
OffsetRect
ReleaseDC
IsWindow
SetRectEmpty
GetWindowTextW
GetWindowTextLengthW
CreateWindowExW
SystemParametersInfoW
LoadCursorW
GetClassNameW
GetClientRect
DrawFocusRect
GetFocus
DrawTextW
GetSysColor
IsWindowEnabled
RedrawWindow
MapWindowPoints
DestroyMenu
LockWindowUpdate
CreateDialogParamW
GetMessageW
PostMessageW
GetClassInfoExW
SetWindowPos
UnregisterClassW
CallWindowProcW
DefWindowProcW
SetWindowLongW
GetSystemMetrics
LoadImageW
DispatchMessageW
EnableWindow
SetCapture
PeekMessageW
SetWindowTextW
LoadStringW
GetParent
SendMessageW
GetDC
GetWindowLongW
GetWindowThreadProcessId
EnumWindows
GetForegroundWindow
TranslateMessage
GDI32.dll GetObjectW
PatBlt
CreateBitmap
DeleteObject
CreateFontIndirectW
DeleteDC
SelectObject
SetTextColor
GetStockObject
SetBkMode
GetDeviceCaps
CreatePatternBrush
SHELL32.dll Shell_NotifyIconW
ShellExecuteW
SHBrowseForFolderW
SHGetMalloc
SHGetPathFromIDListW
SHGetSpecialFolderLocation
SHGetFolderPathW
ShellExecuteExW
ole32.dll CoInitializeEx
CoTaskMemAlloc
CoUninitialize
CoCreateInstance
CoTaskMemFree
CoRevokeClassObject
CoRegisterClassObject
CoAddRefServerProcess
CoReleaseServerProcess
CLSIDFromString
CoResumeClassObjects
CoCreateGuid
CoTaskMemRealloc
OLEAUT32.dll RevokeActiveObject
DispGetIDsOfNames
SysAllocString
LoadTypeLib
VarUI4FromStr
SysFreeString
DispInvoke
SHLWAPI.dll PathIsUNCW
PathFileExistsW
PathAppendW
COMCTL32.dll CreatePropertySheetPageW
DestroyPropertySheetPage
InitCommonControlsEx
PropertySheetW
UxTheme.dll IsAppThemed
EnableThemeDialogTexture
WINTRUST.dll (delay-loaded) WinVerifyTrust

Delayed Imports

Attributes 0x1
Name WINTRUST.dll
ModuleHandle 0xdb368
DelayImportAddressTable 0xdb35c
DelayImportNameTable 0xd7514
BoundDelayImportTable 0xd7888
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type TYPELIB
Language English - United States
Codepage Latin 1 / Western European
Size 0x1910
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.81475
MD5 c097ceb7d3a4c595c4b6aeef69c31b28
SHA1 4ce6fc9826bcbe3bac5fb125a52493be7b7e96b6
SHA256 427193b3b7f13acb47e79af9a4f8847b8b8e1e6e875f00d22c91cc9e9de4854a
SHA3 ad87df2ffbe652666b1d6d7e882726261aa4bac2c985ca005b339b0f4c8651af

1 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.79188
MD5 471d3cbf51811ff153428abc6d45883f
SHA1 f6a9d8692ce7a69668bd874c5ebb9b91cfa712d3
SHA256 8deff789fffc5ef1353e38f604b11f255c60b0f7cca8257e847bd7ef61ad7eaa
SHA3 c04ba6c614a3d937cbc765aa1c979396156bc49c532b55aef0fba82be56cc3d7

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21778
MD5 6c9209f24fc3a371fcda596335c75ec8
SHA1 41c9f3891f8e415d370800579e9dd50494f6d325
SHA256 ddf39b41c9da124fe47f9d6cf6ea54f36d59c254e7a50005fdd07d397810bf8b
SHA3 12e92146e6f97a1a7e15c6e0f30c0350625f990acb928fae517e42e659ddfb86

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21317
MD5 fa4672cabb14bd2c97c6f0e29182e534
SHA1 03d2b5d02ed197a8518e3d7d3c7b90ee8e61b07e
SHA256 a368d179116bb0aeb05e33fcf6573ac25482f72d3f48d39e4dc5f110455f470a
SHA3 3e16584c43002665cc8542cbc9baeab141e51393692ed149634f42981eba2205

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.14991
MD5 8f1daedd5d6dbd5f691c45c67e5be069
SHA1 47462f69aa5b6b1532eeddc95fd20c8bbd82d266
SHA256 90649ba8b75ecef7455a8ebd17dedeb1f4aabf0e02db6b530928f8a7aef5ebb4
SHA3 fc34f1ffa3c9d7e69fb6dc2cbc16d531e3e1a3cb81d9de74df57b9ede9027c24

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.67396
MD5 4682040de707a4ddd9c8049fefbbe47b
SHA1 71e2eda643cc1a07625b69b089d3a50c757d0f6c
SHA256 e83237a2575c95f6559f7628edd17c3514996f3c725df925012b3375cd3334c6
SHA3 3a6ad868274065c9dc0f78c2dffcc792374ac490cebd31a219904325ef67d85d

111

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.53288
MD5 6f46acfbc6ab74cb22682b0bcb66b0f3
SHA1 e7fe0939b2834489fb2bf841444b5be7674ebc21
SHA256 fcabcb25bee5d1bb1e40a2f7b2dd1457dda96d3660e931b23ecc5075fa5542de
SHA3 618cd5c0986b3d2ba2fe5ae695caa7b81545e76bf46f25ee678a42bce4836f53

191

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80203
MD5 4a8e5bf474ca6b0a761f4f12096a79c6
SHA1 2992563adff26e6a6f942a760d88908b40e5949b
SHA256 1f396c552a7dfcf9dd9a752e4f2a3f36e6ac472b4225ac089a6c6ed1c40bb725
SHA3 cf70f0e6ffd3ea7caadd63485ec27e4fb7a237a5f699a7354538dd0653adea3f

103

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15891
MD5 35548381e1024ce0a5b2e564a216cdef
SHA1 4e8da389a8bc3936f3aa3397ff957c788f7dd5be
SHA256 4dd76d5a9fe17df6938e8559590b7558d8526f556aee19df5ae00a8c5cdeed55
SHA3 f52c207e22d765c56b6bf86194120658ddf54f2bff3fd208a7276d7d0d2ea56a

105

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3812
MD5 fe9c74ad051a1d57ba769c7815b43540
SHA1 25a6fbc9e08744ba27278bdbff489ff5544e0ae1
SHA256 8b525537d6ca1287790804142189dd44e62a8547cd9cde19d8c1b54aafd23831
SHA3 02c8c8c286275a3ad40d6eeb19febaa705e1b3a36a1750d355f33f2eb26c897f

106

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x19a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34744
MD5 6ed77081e193a7dab41446bf91bfcb2e
SHA1 b9b295c6d47475666b27411a1437fb3fb00bd1ac
SHA256 2128cdda7d4a883d2aa0b60e7a6b9abfa6475d0f19a11fb8289b0b1e495a6df9
SHA3 9913b2ca3a554520f7241ccfd136cd2a619b0f26fcb50e8062105b4e49b8f2cf

110

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xf6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11435
MD5 7fd0ba8089f47c1cceb610ee8a463cd5
SHA1 5a4402de6548d917ad294610516daa837e2ad515
SHA256 eddcdf57682d66a7653b5a7898ae1dc8cfcd654634c3e951520360fcdf7f2805
SHA3 a87af8ce0a6a2aa0b6aa4c5594f59786070de265213d54bff330efc5034a4e52

190

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10494
MD5 0ab3adaf818180a97120568e26693754
SHA1 31d82f873a7618ff771517f69f22e5e86a158036
SHA256 eeeadeb290c8931b71769a1ccae30035b086c12bd664c85f0dadd2aa44093c8e
SHA3 75ba1224755cbf4cf0f46806d84270bf276027ced002a62f099086eb1ae5dc41

194

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34467
MD5 e0848b5e536bd917cd1ef3f91e7a7740
SHA1 e8ef2403791996375ee195bad70ad26c338e031c
SHA256 0856c4137bcde03836941b6db05b1abfeafdf6846d80f2b45b3cf91934559dce
SHA3 581d005f7535ade75de38ff7bb97e184bb7fbf45563ac0396ba145902c02e9a4

195

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97879
MD5 6a7611ec6d355b427b15e4f61aa0801a
SHA1 ad8dd1a792f6e99481e2ebcb85d687840e3195e9
SHA256 2468159e6866a700905993fe6e04a0b8f7890070b8e008b8d97829cda20b2ad6
SHA3 2b46cf7d587dc149f223d2690137a6cb9050c4a0cc8894a6d8a3f4ac920c3401

196

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x6c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79401
MD5 18304531386c6e4177afd82d2d5d63c2
SHA1 c08ff3f339b010603534e98ef8e01dcde4df1b47
SHA256 233d38d590d1e3e348d6e5faf5514cd39e94430c87b173b09e8fd2f361bb3559
SHA3 3990cd74f2dcbb743c77582b82e78c8b289cbcac2f9a585cce9f36d6a4b30001

1080

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x7c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83711
MD5 83dcf4bc6de667cc786686bdbe622a3a
SHA1 3485f3ed167b93db572fa1e9fe7d504b114fbff3
SHA256 d36a6a83139cbd12c9a4336da18de356f1e95791c9368b4639acd55199ecf8cf
SHA3 f4e11d2982eb39de7212eebafe71a4d54c6d52e425a262317f92dfaf54185a10

8

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30772
MD5 03cfe94d33f6e8e4544bb77aee4ab06b
SHA1 9c0501f8418acbc5ad4374da5085f0a5af3fe2eb
SHA256 5957e32228c97c9b6071cb30562230e236aa5792c9fd8a6f20b6255d37c16d85
SHA3 634849480717b3ad8f26fb9e4bda2dc92f05a43c832ac231d04587f5624d78fa

9

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x186
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.45738
MD5 b1191580f931e989855dab5ea5598e28
SHA1 8355a1890bafe601a0df2e0f1c21445562922cb6
SHA256 7788aec7ae0fa141c191c434a0c4fe3530fe33f6db45f355856269f8951686c2
SHA3 3d550e2938f4a4982e6d6a05a74a587da87acd57a6d627f58c89e946e6ac7bf2

10

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29537
MD5 85bd687793b2c8fd9be68e1f8ffdc876
SHA1 749dab0c69e281971b4157c10007befc713358f2
SHA256 c6a96d2392648e4ed8411e299539104daa806b045b1511e5f765f81ee9b1c617
SHA3 1d34186b23f2b819d47b34dc3c54c275adda9bae27287edb96408120f4723e70

11

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x23c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31748
MD5 ace26e18c68ca78abe26f2c1f4ec32d9
SHA1 61a170caf98f9e2f24e9a099976a1dfc9e6a07a3
SHA256 3b6bb18a18302bbec018c5ea953c99cc7a3ab1a511c1baa0a0b50aa1891f5f06
SHA3 ed820f9f3894e21e4fd807de5af3754c14220c62ba7757986d4bd2796f4d271e

12

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3d2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21561
MD5 14045162122eea57f2e2db124aa4bc13
SHA1 1e2c5ee60669c1fe1cbc7e77f70db64ac7a3cd75
SHA256 1254b9f68048e59a9751b50050da28316eed5b4e2f2513cc9c2209a9cb4feb45
SHA3 3ba8b3175722bd6c232ecea9b245c468e6ede60b6befefee5f14bc32facee03f

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x350
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36861
MD5 c3ba24ff0d5287cc1bbccf81ac2982df
SHA1 4fb24431c0260d6f45a1daff48d1100781aac15e
SHA256 b74196d4aaf6850a452a1c71c667c95e7e2368aa1fb0ab7cdb17b943332cd98a
SHA3 a626e5910cfa5bdf6ab5f77514122c800b677cb4a3e4414e4f6209633a49f858

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x55e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29033
MD5 368dae6dfa95eb7e62aee98f333f442c
SHA1 bcbd37c9e1269b97641efb587d9331404f4279e2
SHA256 05c1d9e739daa181f9585c24c086a66a8b6f0b2e2d675f0359246235c9531fa4
SHA3 9c4d6fb728bf8ce6c1d7278a5809036035b5d47a4b8e3a90bbf9c49e4441bc55

15

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x660
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25075
MD5 d2bb756591555d845c5d2f487aab6bda
SHA1 cd2a4b7a70591212a8006fc48f2997d9454fdb29
SHA256 708e3d3cc8d4a8bfac32c5c5e6efa1584d3d7668573a7a5c0e7933bfa664fd79
SHA3 0d790abef60cf52e0e5525bfaf6eb66f1224c68440477d77e6b8f63a8448dad3

68

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02187
MD5 5922c50ad5c5c104a54492966709e986
SHA1 ad95fb3595871d45f0f5a13d1e1e0059b39dc603
SHA256 4636c7831cf4ca8219e9edc78cf8cf14a74327576263dc2f1c58636893cffc91
SHA3 e6988445d83626e3c25336e5050ee8779b246cbde8b85ed737dce0f57e0f3e8c

1 (#3)

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.918296
MD5 1718d57986110b6af2dd96b59d3db416
SHA1 d0d5f5f3d469570bf8d9559b0daabada2e4fadfc
SHA256 914204c25f3f144ddec3469c61a6faea695c87590ab78a5eb25b0f3904cf84e0
SHA3 c2074188de1c50b4c3a79d5421ea21fe9ab29ac4c7429a7390664cd1e58bb1f6

238

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ece
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21897
Detected Filetype Icon file
MD5 47af659aedd467f117d3803a0b1ff2e9
SHA1 e94d14d687e434b3cbde0eb9f746b6dbb59cc8a7
SHA256 810f815f13e22c8ba918e5e92d907327bbc7bdb7ea5efafaa09e337b29b88f34
SHA3 87464bf74912b80e1ad8738895bb76855916409a0498ab9a75e9e32632c4f234

239

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ece
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06162
Detected Filetype Icon file
MD5 a6721ab8f9bab67c77e9e08f1d806f03
SHA1 89d2228f3e77ae699766500efe82e8c40d0e6a11
SHA256 cbbcd1745a18faf4b6f59e5f963cc5024874e5ffb009673da61cb4d21dc855f8
SHA3 e3dea70b86102c26bfafcca41ff811fe08afce3cf66bd52b5f57425a0e6797be

240

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ece
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35413
Detected Filetype Icon file
MD5 18b0e100253b8a07a9ec3bd4ab714a1b
SHA1 eb15a70c59756575610a5bab9f9335c8fb587069
SHA256 d3e072317d015f1c9eea531e45c27d503c546319226131b7a5ad8afd0f8014d4
SHA3 38bc099b097c717a13238ae0d6159dd8193354c687a2a564768c0a454d627881

241

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x276
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01834
MD5 d09401d4fc60dcaa4ecc3f27ef3bfa40
SHA1 3725b092265a00bb3c6b07a520e7bcdba4d3dc84
SHA256 7ce765f86f9bdaf20790fd27930f67068ffd371d4a3bca86e39236da3070b58b
SHA3 76885a47ba157052f5f3a38dbdab7fd482044cb3ebed0d7ed472344d4506cc0e

242

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x140
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.52151
MD5 bd4c2a8d1ccfa584e7580225a120e27f
SHA1 a0ed6522d7912c23c0bf9dc1442e1680b1b6a1b3
SHA256 0534101d059af0d17681c552949629b1ad0f8837899335f66a6689bea74741cd
SHA3 20562f3a3f85a22fd71d6f2e85dea24398d43a41557bb9912c0cce11726bbaf7

243

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x119
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.47659
MD5 5eae2314282d403bdc5cc4ef34c0ca2e
SHA1 7cdb648a200c4b714b3a8564a2565b60b0bb719e
SHA256 62bd98b3b30911085431e2276cdd4b18a7cca6b363cd321df5c2466be5b868f7
SHA3 3f9af37f791b9782892e2602a3dddbae813b274b4ba3a4d49898be412c4d356f

244

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x96
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.26464
MD5 0445f4a5285c0520c1dbe5247919ff90
SHA1 e2e0cb1d01edfcf08ab10b6efe4db10b5ceb56dc
SHA256 44ab58631042bd6e161097a139f7db35b7af781bc9212031e7676426b8280b75
SHA3 d5217107d7b351e8be10bf52b79bb0e9c24b791b0acdc505dfd07d4757763da2

245

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xbd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.38485
MD5 b3f9615732c3ec928e2e2070e0bd86db
SHA1 86510558473d306747171714395c22c7f9b29881
SHA256 29832315b6d9899060e6002ce858aa613f004f6555abc398267d6c4f9b7a7907
SHA3 2fad55b3327b056999e822616aec054fe7db4d3e0f5e547fff58fef43f77668a

128

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79808
Detected Filetype Icon file
MD5 aae6decb939a13d7048a1829b30157f2
SHA1 b927e97b6642fbb6121d0ece607a96d07b55ac7d
SHA256 672569335f397f199e8e5ffd52c221068b0082ae9607e73edb0418832db3e2ac
SHA3 1bbb1d06db6fbcfe5725b8156ce06ac465c4487a15c0bbd60aa75b4459527bad

1 (#4)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x2c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3492
MD5 9fec8309b6bf8ceeb6d39b8c99664f21
SHA1 c3fe0a670c6685b942664e0770810659a02b0981
SHA256 976710533d410b34e01485bb7021cfbff25e6c0529123d90a8f43d7659c9a433
SHA3 bf58790c22993059c98311e5a53d4f296914dfd547faf68fadd84c184d7e5022

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x77b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.221
MD5 fd833400305d14da9d63c549bdf66f53
SHA1 80c1bb6758e64bb6c2c9afddeea1ef05335279f1
SHA256 0dc28b15060678b8275c35c06d374529e57cd7707af05dfc6d2488ea840cefee
SHA3 6d3eed05e9e8998c5f330f0601670b55c752d2e217a969e557242fb76a955b28

String Table contents

Found Updates for %s
Updates for %s were detected.
Please select the next course of action.
Welcome to the Updates Wizard
Download and install now
Remind me tomorrow
Remind me in a week from today
Disable the automatic updates check
Configure
Updates
Next check: %s %s
Do not check for updates automatically
Check and prompt me to download and install updates
Check frequency:
days
Downloads folder:
Check Options
Download Options
Update Options
Choose Updates to Install
Update
Size
New Features
Action
Install
Download
Skip
Fixed Bugs
Enhancements
Checking for Updates
Pause
Resume
Downloading (%s of %s, %d%% complete)
(%u%%) %s for %s
The server %s at %s requires a username and password.
Canceling...
Download finished
Error: %s
Pending
%d%%
Finished
Error: Wrong file size
Error: Already downloaded
URL
Unable to expand path
Status
Downloading Updates
Paused
Automatically install updates after finishing downloads
Configuration file not found
Installed
Installing
Installing update %s.
Installing Updates
Some of the updates failed to install properly.
OK
Your software is up to date
Undefined configuration file format
Undefined file version
Unable to save file
Invalid command line
Invalid client configuration file
Action canceled
File not found
Unable to find update
Unknown exception
Update installation failed
Dependent update not installed
Invalid or missing updates configuration file. The first line of the .INI file should be ";aiu;". It is possible that the content on the server does not match the updates configuration file URL.
Missing
updates
Check and automatically download and install:
Critical
All
Error: Corrupt file (wrong %s signature). File removed.
Checking integrity (%s)...
The file was corrupt (wrong %s signature). Restart download?
You need a user name and password to access this resource.
User name:
Password:
User Authentication
Connect to %s
Remember my credentials
Invalid updates configuration file.
Update installation canceled.
Warning
The release date of one of the selected updates is outside of your license's maintenance plan. Do you still want to install it?
Canceled
The server understood the request, but is refusing to fulfill it.
The Certificate Issuer for this site is untrusted or unknown. Do you wish to proceed?
Security Alert
To access the update you need User Name/Password authentication
The connection with the server timed-out and the server does not support Resume. This error also occurs if the server reports a wrong HTTP "CONTENT LENGTH".
Internet request timeout.
%s for %s
Unable to find resource on server. Please check if the URL is correct.
Updates for %s are available
Back
Next
Finish
Cancel
Requires renewal of license maintenance plan.
This update requires renewal of license maintenance plan. Do you still want to install it?
Update size: %s
Download restarting...
Update Summary
Install Summary
The downloaded update size does not match the size specified in updates configuration file.
The support service has encountered an error.
Update installation was blocked, untrusted publisher. Please contact technical support.
Update installation was blocked, License Check script unknown return code. Please contact technical support.
Update installation was blocked, License Check script URL unreachable. Please contact technical support.
Update package file not found. Check your update download URL's.
Update installation was blocked, digital signature mismatch. Please contact technical support.
The notification format is invalid. Some mandatory fields are missing.
You have a custom proxy "%s". The error may be caused by a non working proxy.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 18.0.0.0
ProductVersion 18.0.0.0
FileFlags VS_FF_DEBUG
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Caphyon
ProductVersion (#2) 18.0
FileVersion (#2) 18.0
ProductName Advanced Installer 18.0
LegalCopyright Copyright (C) 2021 Caphyon
InternalName updater
OriginalFileName updater.exe
FileDescription updater 18.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2021-Feb-22 16:35:43
Version 0.0
SizeofData 72
AddressOfRawData 0xc3308
PointerToRawData 0xc1b08
Referenced File C:\JobRelease\win\Release\stubs\x86\Updater.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2021-Feb-22 16:35:43
Version 0.0
SizeofData 20
AddressOfRawData 0xc3350
PointerToRawData 0xc1b50

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Feb-22 16:35:43
Version 0.0
SizeofData 1072
AddressOfRawData 0xc3364
PointerToRawData 0xc1b64

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2021-Feb-22 16:35:43
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x4c37a4
EndAddressOfRawData 0x4c37ac
AddressOfIndex 0x4db9f4
AddressOfCallbacks 0x4ac5fc
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xbc
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4da064
SEHandlerTable 0x4c2800
SEHandlerCount 706

RICH Header

XOR Key 0x8df2b8d1
Unmarked objects 0
ASM objects (27412) 14
C++ objects (27412) 185
C objects (VS 2015/2017/2019 runtime 29118) 19
ASM objects (VS 2015/2017/2019 runtime 29118) 24
C++ objects (VS 2015/2017/2019 runtime 29118) 94
C objects (27412) 27
C objects (CVTCIL) (27412) 1
Imports (27412) 31
Total imports 440
C++ objects (LTCG) (VS2019 Update 8 (16.8.5-6) compiler 29337) 124
Resource objects (VS2019 Update 8 (16.8.5-6) compiler 29337) 1
Linker (VS2019 Update 8 (16.8.5-6) compiler 29337) 1

Errors

<-- -->