e1107da892eebe597f349324e82f2fff7049b4514cac1b3df6c90427928bf0bb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Oct-04 05:00:00
Detected languages English - United States
TLS Callbacks 3 callback(s) detected.
Debug artifacts nw.exe.pdb
CompanyName The NW.js Community
FileDescription nwjs
FileVersion 0.49.2
InternalName nw_exe
LegalCopyright Copyright 2020, The NW.js community and The Chromium Authors. All rights reserved.
OriginalFilename nw.exe
ProductName nwjs
ProductVersion 0.49.2
CompanyShortName nwjs.io
ProductShortName nwjs
LastChange 62f83a7521ae1f32e563795732dff0c9da1b660d-refs/heads/master@{#812354}

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • blink.net
  • chromium.org
  • crashpad.chromium.org
  • https://crashpad.chromium.org
  • https://crashpad.chromium.org/
  • https://crashpad.chromium.org/bug/new
  • openssl.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Suspicious The PE is possibly packed. Unusual section name found: .retplne
Unusual section name found: CPADinfo
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryW
Code injection capabilities:
  • CreateRemoteThread
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Code injection capabilities (mapping injection):
  • CreateFileMappingW
  • CreateRemoteThread
  • MapViewOfFile
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessW
  • CreateProcessAsUserW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Functions related to the privilege level:
  • DuplicateToken
  • DuplicateTokenEx
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
Changes object ACLs:
  • SetKernelObjectSecurity
  • SetSecurityInfo
Safe VirusTotal score: 0/70 (Scanned on 2026-07-20 14:21:38) All the AVs think this file is safe.

Hashes

MD5 7956bd80ab334bd015799b72c45d65c7
SHA1 eb6c079f6bcf29c517dcf8fbd7ca9ab0a634f746
SHA256 e1107da892eebe597f349324e82f2fff7049b4514cac1b3df6c90427928bf0bb
SHA3 1d8ef700bf53fd04b6ef9ddc1ce9643e947453db9e752b2f5376a7cea4720b6e
SSDeep 49152:w2VT6BQp3FaN5VXN2RdY05gIQyTAn+F7gTS:G+6QAnO
Imports Hash 1534e57ecc0751ee75e95c393ccc4ed8

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2020-Oct-04 05:00:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x162600
SizeOfInitializedData 0xace00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000001339F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x21d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x800000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b8080e022527ea9a6a7171b2124772bc
SHA1 1a8a4c1c6fd5580d848a364df336553e76a4e169
SHA256 2e130a32e3c063c6f8ce1114461adebce3505342fd5d9ae420ccf5ec68a18e69
SHA3 21891e9d3c55cb47e3d655c0f8bf570272ad85b04901767fcb37dae94c3c3274
VirtualSize 0x162449
VirtualAddress 0x1000
SizeOfRawData 0x162600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.5584

.rdata

MD5 7922801254aa4e2177449dbe7797c8d3
SHA1 e761e8db6148779d1cea0e07f4e4f5684a251797
SHA256 a2d319260c3846987e72c6f7d8606b94a8440e77cc508d1fae48944b300c76de
SHA3 e7ce38be9129d0cd104430d7df57fc1a8be209f4f126d06dedf1aca612d5c7be
VirtualSize 0x4aeac
VirtualAddress 0x164000
SizeOfRawData 0x4b000
PointerToRawData 0x162a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.60825

.data

MD5 c1ee7a1e04270f6e56d67d147f834d86
SHA1 bf2a7b7d23c6d5e052a385a77ba5ed75c1868291
SHA256 30973d1257e8e6452f43b2a4887684d8a9b485e2ae046f35474fbf546774264c
SHA3 93dc47521d186182a091d48b56a42ab790365ccb6d0b66a9afbfd76aef83ab84
VirtualSize 0x94f8
VirtualAddress 0x1af000
SizeOfRawData 0x3a00
PointerToRawData 0x1ada00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.31245

.pdata

MD5 86b782914f34cb4ebd07ef60933d8a77
SHA1 19229ed6830591b1c070267570d05fe6d7c0b73a
SHA256 a1e8e9be07aef521543681360ee971d3a02361372fd2b4ad80606552403c9376
SHA3 851fac018366498bcbc5af17c8fae35b73513989ecf0fff68a2c88c14496838b
VirtualSize 0xd518
VirtualAddress 0x1b9000
SizeOfRawData 0xd600
PointerToRawData 0x1b1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.99214

.00cfg

MD5 7bbaf74a9c27ea01e0206847ee2916a5
SHA1 a0fb55815b688fd75d8586c5c644c4f2acadc65b
SHA256 40e8ec2490bf3d7f88640460df621527dc70964413b9c7133250abcd52c34fd5
SHA3 521f48de0903acb80cce873ee13834ff92c3f4cf4dc57c731c7702ec9fd24ead
VirtualSize 0x10
VirtualAddress 0x1c7000
SizeOfRawData 0x200
PointerToRawData 0x1bea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.195869

.retplne

MD5 bcdee87f658a7bf4080188f07db97ca9
SHA1 b39e6a63392c43a2a2310b05f34539a40d08ab89
SHA256 cd7e321e97c97e7868f84d576463927c198cae07e3a7bfef1e7946eeae0a2de4
SHA3 84c1a226c0a000aaafed916616a5fee7cc655286427c324e2f74ac12ddd2eaf5
VirtualSize 0xc
VirtualAddress 0x1c8000
SizeOfRawData 0x200
PointerToRawData 0x1bec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 0.220113

.tls

MD5 9aa06f145d2598570c21005b86668587
SHA1 e7cc2f443a1d646aa3f4dd09d86959829da6bf8f
SHA256 242e9d6b75f9ac087844f012a8eed9e25d594be3d89be03d78eb28da270cf8a2
SHA3 0f93ba53c83470880a1b31ba203111368429f9a9fbad807c09541351f8206ce6
VirtualSize 0x131
VirtualAddress 0x1c9000
SizeOfRawData 0x200
PointerToRawData 0x1bee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.136464

CPADinfo

MD5 60d3ea61d541c9be2e845d2787fb9574
SHA1 a314e912df98dd680cdb9679390177a970ee9ac8
SHA256 911d1a12eca8935990172cfcd6768f9c6351ed94b700833b2cf0cf457a1d752d
SHA3 44f366ded1e40e29d2543686d5e4f2fc6daf379b056e4f94af32c16e9f6b2205
VirtualSize 0x38
VirtualAddress 0x1ca000
SizeOfRawData 0x200
PointerToRawData 0x1bf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.122276

.rsrc

MD5 9853493babef06d9f32deddf237aba03
SHA1 f6e0e2f7035031a17089ceb555c2f6ea9380768c
SHA256 3285333adef7e91e1bad6c82ff746b2c8f7318cda5aac35ae35ec191c6958a1f
SHA3 ded8ed119ee9a7c25169cada8f686654f1430a333ceaef62841ad2a08c79d91d
VirtualSize 0x4e2b0
VirtualAddress 0x1cb000
SizeOfRawData 0x4e400
PointerToRawData 0x1bf200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.17366

.reloc

MD5 011b3b334d48e0893c8db10fe095108a
SHA1 06873b68db631a20b38cfb2ebe9a627a2173cd60
SHA256 0415b11652fb0aad955baf6965b33dbbdd245ced044c0df057fc1656fb14eb44
SHA3 b3154e216674b6648283eb739c1d74647512c0fd144b3a35abfb843968e4b5b5
VirtualSize 0x229c
VirtualAddress 0x21a000
SizeOfRawData 0x2400
PointerToRawData 0x20d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38853

Imports

nw_elf.dll GetInstallDetailsPayload
SignalChromeElf
KERNEL32.dll AcquireSRWLockExclusive
AssignProcessToJobObject
CloseHandle
CompareStringW
ConnectNamedPipe
CreateDirectoryW
CreateEventW
CreateFileMappingW
CreateFileW
CreateIoCompletionPort
CreateJobObjectW
CreateMutexW
CreateNamedPipeW
CreateProcessW
CreateRemoteThread
CreateSemaphoreW
CreateThread
DebugBreak
DeleteCriticalSection
DeleteFileW
DeleteProcThreadAttributeList
DisconnectNamedPipe
DuplicateHandle
EncodePointer
EnterCriticalSection
EnumSystemLocalesEx
EnumSystemLocalesW
ExitProcess
ExpandEnvironmentStringsW
FileTimeToSystemTime
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FlushViewOfFile
FormatMessageA
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentProcessorNumber
GetCurrentThread
GetCurrentThreadId
GetDateFormatW
GetDriveTypeW
GetEnvironmentStringsW
GetExitCodeProcess
GetFileAttributesW
GetFileInformationByHandle
GetFileInformationByHandleEx
GetFileSizeEx
GetFileTime
GetFileType
GetFullPathNameW
GetLastError
GetLocalTime
GetLocaleInfoW
GetLongPathNameW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetNativeSystemInfo
GetOEMCP
GetProcAddress
GetProcessHandleCount
GetProcessHeap
GetProcessHeaps
GetProcessId
GetProcessTimes
GetProductInfo
GetQueuedCompletionStatus
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemDefaultLCID
GetSystemDirectoryW
GetSystemInfo
GetSystemTimeAsFileTime
GetTempPathW
GetThreadContext
GetThreadId
GetThreadLocale
GetThreadPriority
GetTickCount
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultLangID
GetUserDefaultLocaleName
GetVersion
GetVersionExW
GetWindowsDirectoryW
HeapAlloc
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
InitOnceExecuteOnce
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InitializeProcThreadAttributeList
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
IsWow64Process
K32GetPerformanceInfo
K32GetProcessMemoryInfo
K32QueryWorkingSetEx
LCMapStringW
LeaveCriticalSection
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LocalFree
LockFileEx
MapViewOfFile
MoveFileW
MultiByteToWideChar
OpenProcess
OutputDebugStringA
PeekNamedPipe
PostQueuedCompletionStatus
ProcessIdToSessionId
QueryDosDeviceW
QueryInformationJobObject
QueryPerformanceCounter
QueryPerformanceFrequency
QueryThreadCycleTime
RaiseException
ReadConsoleW
ReadFile
ReadProcessMemory
RegisterWaitForSingleObject
ReleaseSRWLockExclusive
ReleaseSemaphore
RemoveDirectoryW
ReplaceFileW
ResetEvent
ResumeThread
RtlCaptureContext
RtlCaptureStackBackTrace
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
SearchPathW
SetConsoleCtrlHandler
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFileAttributesW
SetFilePointerEx
SetHandleInformation
SetInformationJobObject
SetLastError
SetNamedPipeHandleState
SetProcessShutdownParameters
SetStdHandle
SetThreadAffinityMask
SetThreadPriority
SetUnhandledExceptionFilter
SignalObjectAndWait
Sleep
SleepConditionVariableSRW
SleepEx
SuspendThread
SystemTimeToTzSpecificLocalTime
TerminateJobObject
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TransactNamedPipe
TryAcquireSRWLockExclusive
UnhandledExceptionFilter
UnlockFileEx
UnmapViewOfFile
UnregisterWait
UnregisterWaitEx
UpdateProcThreadAttribute
VirtualAllocEx
VirtualFree
VirtualFreeEx
VirtualProtect
VirtualProtectEx
VirtualQuery
VirtualQueryEx
WaitForMultipleObjects
WaitForSingleObject
WaitForSingleObjectEx
WaitNamedPipeW
WakeAllConditionVariable
WideCharToMultiByte
Wow64GetThreadContext
WriteConsoleW
WriteFile
WriteProcessMemory
lstrcmpiA
lstrlenW
VERSION.dll GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
ADVAPI32.dll (delay-loaded) AccessCheck
BuildExplicitAccessWithNameW
BuildSecurityDescriptorW
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidW
CopySid
CreateProcessAsUserW
CreateRestrictedToken
CreateWellKnownSid
DuplicateToken
DuplicateTokenEx
EqualSid
EventRegister
EventUnregister
EventWrite
FreeSid
GetAce
GetKernelObjectSecurity
GetLengthSid
GetNamedSecurityInfoW
GetSecurityDescriptorSacl
GetSecurityInfo
GetSidSubAuthority
GetTokenInformation
ImpersonateLoggedOnUser
ImpersonateNamedPipeClient
InitializeSid
IsValidSid
LookupPrivilegeValueW
MapGenericMask
OpenProcessToken
RegCloseKey
RegCreateKeyExW
RegDeleteValueW
RegDisablePredefinedCache
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RevertToSelf
SetEntriesInAclW
SetKernelObjectSecurity
SetSecurityInfo
SetThreadToken
SetTokenInformation
SystemFunction036

Delayed Imports

Attributes 0x1
Name ADVAPI32.dll
ModuleHandle 0x1b2590
DelayImportAddressTable 0x1b25d8
DelayImportNameTable 0x1a2460
BoundDelayImportTable 0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

GetHandleVerifier

Ordinal 1
Address 0x65c50

IsSandboxedProcess

Ordinal 2
Address 0x558b0

1

Type GOOGLEUPDATEAPPLICATIONCOMMANDS
Language English - United States
Codepage UNKNOWN
Size 0x4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02794
MD5 a29215c2d08412d0a09089bece74a8d8
SHA1 7f427a32af62958ee729a48113126b0034f8338d
SHA256 cbef4b9a98a6118f2665822d7a2868b8a4645f36c517627e3f4fe361f128ee32
SHA3 598f9ada42b2c0ec13af2bb0acd86650df2f7bf0860cfbfb85931352f08f76e6

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.05163
MD5 1d631f6d8fa19398d2df5863be341a2c
SHA1 97243c848ad1a29da52855996d88fbdb092ef48f
SHA256 7abae35099733d994c7168b58edf433d9a87096ffacdbee04cacc5a05dd84909
SHA3 d6fbfd69d2f15297c09308bc2fc122cb08b379927f53cbf30c5974c6f62067a9

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.36687
MD5 f5a0e41bc60f9722f17d2eec66a72996
SHA1 db94b2c361fd617c8ef978dc1e4e5f71e0538d7c
SHA256 110d31262fc1d5c2a33c27059c94469b6fb4f7e4e16a91572c0492795c3f21b7
SHA3 2c2652334d23ef6e09283055ceb3997751854a44b3907deca030491f4fd46f59

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.32943
MD5 faaa6b184f0de776b3694d7333bb7dd3
SHA1 821091dda1f7b14e9d84a2114021773366aead18
SHA256 a8589c4aab8ed377a9602ef5bf3b6565e45a3357911efd6048f38a56b0a102c7
SHA3 3f0f8f6b4531727f1e8196654de4352ba230b90a335a6b5f621bbca551d72e9d

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x7c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.26175
Detected Filetype PNG graphic file
MD5 44ecf3fd91cf33cfb4535bb2ea59e27a
SHA1 3090f24b36ec71739d9820d550aa3f4eed8e52e9
SHA256 977990ecb2a3a7bf7ef2edea2c484b538b73476eb46722791fb8591d19bcda4a
SHA3 b339de91d44a8b0b0dddcc8b659a82533fc85134b67ad2e7a6c70e9a13577924

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.32779
MD5 d790cb9b9086f45ea53fec385891355d
SHA1 20e3548d16dbba68b8f322a1c4f7086e38110d10
SHA256 18621604c0b5f4229416994b569e2afda775a608e1759d5ba7082a31458e1169
SHA3 b14e2bb5e8953ae807c2ec3b726942eb2ead7890772fdf6a410a8c9a71e81915

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21995
MD5 7ab8c3240114b0f7ebc42c5c489060f6
SHA1 0de249b988a94d3374bbf9eb3585f00ace2e5499
SHA256 f5feb3ba96da36d90fb879e6f1af274a1c5f6fd4ba68332b1c25d97c6508d062
SHA3 def1c08500690c2ea7b272685c0a594f8ca5bf9865055bfb9c488d12a6955dfe

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.65783
MD5 d720ab3b897affd8516a5c73e9020b19
SHA1 36e5ac25f4b4f4b869d109c0072da7f6f1fd03c2
SHA256 f269848277f345c8fc62634f14c012bc8ee1afa4887e8819228e99c6915bbdf3
SHA3 c946f83fcb2547d27caf0a1adff84c375349fd416f64281d3fb2653a224affa0

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70621
MD5 7a8fd82c16489f1ed6e5cdc5dc38c815
SHA1 595b39dc0c92b6e3943ea918a213cec58503daf4
SHA256 9260d8b6f0fd7fc00e9a960db1b1283180efd59049be2c8867a4e660b1ff0123
SHA3 2eec2ac06df13fa72c5317fe2f7e049cddea95363b53620674c73c866a7f8d52

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1234
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.90997
MD5 11921cfff61b5877c53bb37c86b6d09c
SHA1 3800127e39a03ea9b2a9f79538d40227ef4d0c89
SHA256 c714566bd8b7f0be360e68950a5615a2fb365d53b14ea7c2812f23c458497799
SHA3 0e2df531413bcc400f2f42179d34b093d3229754f3ee9d7c982faacd2f766e18

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.72497
MD5 0e559d7f5897727c98dfdd1e6c3631e7
SHA1 fcd9803592250e14d186e9c8fd0f094e7debfdf0
SHA256 6e6dd7cc3df380721e4678fb1825b982df22a4dc058091634e733c33f3543b1f
SHA3 54cc4d475eb6e3066dda379e7ce197dad0d994522cc58d68673a5707d4aa46cf

12

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x184b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91162
Detected Filetype PNG graphic file
MD5 e3e595605f7ba7a83a424e5698b342b4
SHA1 b7cf89a883818649ffeab77f323b07808b1b717e
SHA256 05de73b49e62f848770d877a92a4a920e2ef6812538b84ab3a3255ee89bf3666
SHA3 0a0834c7fc8c9270e4ef414eb9095219a154fefc631b38f811eb7639a46a3aec

IDR_MAINFRAME

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.67095
Detected Filetype Icon file
MD5 464cb94db3a2622922a9562865009ae8
SHA1 dbe17c767d942f219df59f9eae77b213c15eab70
SHA256 8affd1fa69a6c5a5b54e504d72d4e9a0eba9b7d702a445ea1399a5978794719a
SHA3 3e0e32110c6c0f3323eeeb5e4a6cbb7a8db52ab14e0f065384fb4eedac4fbcda

IDR_X001_APP_LIST

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70093
Detected Filetype Icon file
MD5 ebd01df5e0c227d025c744fd77d18949
SHA1 ea41a91bc08e43f974a395bd993654f707491c30
SHA256 d55b27d2272c74fda2acb571fbf89a7b7416798a5d992de502021440011b54bd
SHA3 9628813598141ed97d425f1e69c5bedcf64a7dc509ccf0e111fb9cdfd2daed83

IDR_X003_INCOGNITO

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7835
Detected Filetype Icon file
MD5 2b1a0aabe335e382aa150d72d082139f
SHA1 9ca0531e01d97b7f40fa2e4880ed08ed568598d4
SHA256 534a7ac5f2ef0bdb2a11ebaa0ed4f0af49ee8ed81baedfce70f4e548d677a045
SHA3 b84443d0dc73e05278a110f8a2746d8587c5c94099cf870c32ed820995704514

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50059
MD5 e069d7a616bd63eb63df8619b80d62e0
SHA1 546e7f8effbcaca5444beed9bd1688d0d3b31e15
SHA256 30ee54b85ad5d2f763c0422110c6fdd470564be891e7f09473e5114433640f1c
SHA3 52cc42560d9d9a2c6df193b34c3d0224539e4da4b5e87fb487bb5b73f144d7a3

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x42c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33361
MD5 fa140205692392be88038eaba9ca7910
SHA1 4ede0ea94437564dc9b1d1d989e3116e92a1a4dc
SHA256 1f4b3a5657ae0d8242461a11cb08b8adf8e46a21fb612336311fcba10faccb61
SHA3 c72a92379b693f109c695e4e9511e110aa78840b4f2d31bc63ef1a9ff674e88d

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.49.2.0
ProductVersion 0.49.2.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName The NW.js Community
FileDescription nwjs
FileVersion (#2) 0.49.2
InternalName nw_exe
LegalCopyright Copyright 2020, The NW.js community and The Chromium Authors. All rights reserved.
OriginalFilename nw.exe
ProductName nwjs
ProductVersion (#2) 0.49.2
CompanyShortName nwjs.io
ProductShortName nwjs
LastChange 62f83a7521ae1f32e563795732dff0c9da1b660d-refs/heads/master@{#812354}
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-Oct-04 05:00:00
Version 0.0
SizeofData 35
AddressOfRawData 0x1a0a00
PointerToRawData 0x19f400
Referenced File nw.exe.pdb

TLS Callbacks

StartAddressOfRawData 0x1401c9000
EndAddressOfRawData 0x1401c9130
AddressOfIndex 0x1401b4710
AddressOfCallbacks 0x1401a22c8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x0000000140098D70
0x0000000140074CB0
0x0000000140131D50

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401b1698
GuardCFCheckFunctionPointer 5370572800
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

Errors

[*] Warning: 1 invalid export(s) not shown.
Leave a comment

No comments yet.