3ed410db724e5219738e764c3c9a7a575f6f8ba1ee357c2d3f2bf546187f0352

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Dec-17 09:36:36
Detected languages English - United States
Debug artifacts C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb
CompanyName Proton Technologies AG
FileDescription ProtonVPN Installer
FileVersion 1.13.4
InternalName ProtonVPN_win_v1.13.4-139b12d9
LegalCopyright Copyright (C) 2020 Proton Technologies AG
OriginalFileName ProtonVPN_win_v1.13.4-139b12d9.exe
ProductName ProtonVPN
ProductVersion 1.13.4

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Looks for Qemu presence:
  • QeMu
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • download.microsoft.com
  • example.com
  • google.com
  • http://www.example.com
  • http://www.google.com
  • http://www.yahoo.com
  • https://download.microsoft.com
  • https://download.microsoft.com/download/2/D/7/2D78D0DD-2802-41F5-88D6-DC1D559F206D/Windows6.1-KB2533623-x86.msu
  • https://download.microsoft.com/download/3/7/4/37473F39-5728-4153-9A25-64C09DE9ED52/Windows6.1-KB3033929-x86.msu
  • https://download.microsoft.com/download/6/E/4/6E48E8AB-DC00-419E-9704-06DD46E5F81D/NDP472-KB4054530-x86-x64-AllOS-ENU.exe
  • https://download.microsoft.com/download/C/8/7/C87AE67E-A228-48FB-8F02-B2A9A1238099/Windows6.1-KB3033929-x64.msu
  • https://download.microsoft.com/download/E/C/5/EC5D4973-A233-4F48-A555-65DF1E6DDA99/Windows6.1-KB2992611-x64.msu
  • https://download.microsoft.com/download/F/1/0/F106E158-89A1-41E3-A9B5-32FEB2A99A0B/Windows6.1-KB2533623-x64.msu
  • https://download.microsoft.com/download/F/1/9/F19ED8C4-B547-49C3-B3EA-759D3613FD75/Windows6.1-KB2992611-x86.msu
  • microsoft.com
  • www.example.com
  • www.google.com
  • www.yahoo.com
  • yahoo.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA256
Uses constants related to AES
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryExA
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Enumerates local disk drives:
  • GetDriveTypeW
  • GetLogicalDriveStringsW
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
Info The PE is digitally signed. Signer: ProtonVPN AG
Issuer: GlobalSign CodeSigning CA - SHA256 - G3
Safe VirusTotal score: 0/69 (Scanned on 2020-03-29 08:16:44) All the AVs think this file is safe.

Hashes

MD5 eccbd5505efc372a2cda508c75804a08
SHA1 f9011ea1ef6e386c0f8c4557dbea1217726f6203
SHA256 3ed410db724e5219738e764c3c9a7a575f6f8ba1ee357c2d3f2bf546187f0352
SHA3 9e299b9fe2fb8253e4eeffe3e69bb2d88988d6d8a230fd98f6e60ff0979f998a
SSDeep 393216:OZy2e2Z1i+JnN9K/S193bSjD1DL8p7h36w0b:XSzZQ/S1hS6JI1
Imports Hash f44a5ad542f78dd233e94f7d1ec99d53

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2019-Dec-17 09:36:36
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x16ca00
SizeOfInitializedData 0x92000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0011952F (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x16e000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x204000
SizeOfHeaders 0x400
Checksum 0xdcaf94
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 646d51ad551e4d6eaba2e29b75493a25
SHA1 6fc7023e44c9e5c6bfedcb0ee222e06933dc4743
SHA256 6e111e81eda139e87d2eab68960aefab91d116168ac0ddc12f27e2541bd1eb38
SHA3 4d8893b5472a10471fb8940e8c91377114d99d976ce416c9e9ed35330d40df4e
VirtualSize 0x16c84f
VirtualAddress 0x1000
SizeOfRawData 0x16ca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45811

.rdata

MD5 2641b9d7e54cf6c5f3c7048b3a48bf15
SHA1 e5505d6bd19bc266b47d10cbdefc5e0716cf698f
SHA256 c9eab412cad29556790880212181944b6990915170e0d232aecf46b6524d79fc
SHA3 666085d310b8dcd6429b37a2c0972dab32ac3b813603f52824eee0e57ba7389b
VirtualSize 0x5e254
VirtualAddress 0x16e000
SizeOfRawData 0x5e400
PointerToRawData 0x16ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.59891

.data

MD5 0911c526897682337a2dc9dece8fccc8
SHA1 d34eee66f8ed34bb5e0f355ec573c1b13c522e60
SHA256 5ddec09549d58882c992d39e99690cf4b699a48089812b4e754054e23a3c3802
SHA3 394c0cf17ebb73a8cd31940d94a041191a9fa885754237ab02e9c51422cec138
VirtualSize 0x6d78
VirtualAddress 0x1cd000
SizeOfRawData 0x5400
PointerToRawData 0x1cb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.04023

.rsrc

MD5 f84f1010f58ec4c84bcef0915e321095
SHA1 e50c17a9623315688d88c07137b97bcd3d228b8d
SHA256 7abed84e526389448f1e14487eee0bba35184a63151b782b155f22251c301388
SHA3 1aa1e8cbe6929fe358a122c1b20f368b06a8679fa5229eb60f7cdae3126cd0e9
VirtualSize 0x153f4
VirtualAddress 0x1d4000
SizeOfRawData 0x15400
PointerToRawData 0x1d0600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.79515

.reloc

MD5 58558d5f3adf94c939b1e8efc6fd63ea
SHA1 c00a14d524f3b9ac3fbdb42564f44b23e76f9cc5
SHA256 c94dd2bbf8c59a0604dfba1cad1256a46317bce3f8d704a5b92bd70a8d223ec7
SHA3 87bea9646c3508a74c8b3a66b107a185cf808cb3b281c75dd4ba263381bc59bd
VirtualSize 0x19240
VirtualAddress 0x1ea000
SizeOfRawData 0x19400
PointerToRawData 0x1e5a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.55545

Imports

KERNEL32.dll GetModuleFileNameW
FormatMessageW
OutputDebugStringW
CreateFileW
CloseHandle
WriteFile
DeleteFileW
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
RemoveDirectoryW
GetTempPathW
GetTempFileNameW
CreateDirectoryW
MoveFileW
GetLastError
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
GetCurrentThreadId
RaiseException
SetLastError
GlobalUnlock
GlobalLock
GlobalAlloc
MulDiv
lstrcmpW
CreateEventW
SetEvent
InitializeCriticalSection
lstrcpynW
WaitForSingleObject
CreateThread
GetProcAddress
LoadLibraryExW
DecodePointer
Sleep
GetDiskFreeSpaceExW
GetExitCodeThread
GetCurrentProcessId
FreeLibrary
GetSystemDirectoryW
lstrlenW
VerifyVersionInfoW
VerSetConditionMask
lstrcmpiW
GetModuleHandleW
LoadLibraryW
GetDriveTypeW
CompareStringW
FindFirstFileW
FindNextFileW
GetLogicalDriveStringsW
GetFileSize
GetFileAttributesW
SetFileAttributesW
GetFileTime
CopyFileW
ReadFile
SetFilePointer
FindClose
MultiByteToWideChar
WideCharToMultiByte
GetCurrentProcess
GetSystemInfo
WaitForMultipleObjects
ReadConsoleW
VirtualProtect
VirtualQuery
LoadLibraryExA
GetStringTypeW
GetShortPathNameW
SetUnhandledExceptionFilter
GetEnvironmentVariableW
GetEnvironmentStringsW
LocalFree
LoadLibraryA
GetModuleFileNameA
GetFullPathNameW
GetCurrentThread
FlushFileBuffers
SetConsoleTextAttribute
GetStdHandle
GetConsoleScreenBufferInfo
CreateProcessW
GetExitCodeProcess
GetTickCount
GetCommandLineW
SetCurrentDirectoryW
SetEndOfFile
EnumResourceLanguagesW
GetLocaleInfoW
GetSystemDefaultLangID
GetUserDefaultLangID
GetWindowsDirectoryW
GetSystemTime
SystemTimeToFileTime
FileTimeToSystemTime
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
ResetEvent
GlobalFree
GetPrivateProfileStringW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
GetLocalTime
CreateNamedPipeW
ConnectNamedPipe
TerminateThread
LocalAlloc
CompareFileTime
CopyFileExW
OpenEventW
PeekNamedPipe
IsProcessorFeaturePresent
WaitForSingleObjectEx
UnhandledExceptionFilter
TerminateProcess
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
EncodePointer
InterlockedPopEntrySList
InterlockedPushEntrySList
FlushInstructionCache
VirtualAlloc
VirtualFree
QueryPerformanceFrequency
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetCPInfo
LCMapStringW
RtlUnwind
ExitProcess
GetModuleHandleExW
GetFileType
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetConsoleCP
GetConsoleMode
IsValidCodePage
GetACP
GetOEMCP
FindFirstFileExW
GetCommandLineA
FreeEnvironmentStringsW
SetStdHandle
GetFileSizeEx
SetFilePointerEx
WriteConsoleW
msi.dll (delay-loaded) #6
#7
#62
#54
#58
#147
#140
#221
#94
#51
#169
#80
#224
#19
#8
#96
#281
#137
#115
#166
#52
#150
#78
#141
#90
#204
#113
#16
#116
#67
#114
#120
#47
#26
#34
#145
#103
#74
#118
#20
#160
#159
#32
#186
#171
#48
#24
#70
#195
#205
#121
#158
#49
#125
#17
#92
#139

Delayed Imports

Attributes 0x1
Name msi.dll
ModuleHandle 0x1d22f8
DelayImportAddressTable 0x1d21cc
DelayImportNameTable 0x1c9218
BoundDelayImportTable 0x1caca4
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

221

Type IMAGE_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.25163
MD5 acd4cb4d2fec6d3a9d84ec0604cf6395
SHA1 ab50880af341a7e9c14b1a3dbade53fbb1457e48
SHA256 20895f5708984178014cd6bf23aceb4c926eeb8343641ec3c4b308e6fa5caded
SHA3 29e31e66854952190509557a2e5ff9a7262e02fa9c261bf443d76ef74e773ef9

222

Type IMAGE_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.25163
MD5 acd4cb4d2fec6d3a9d84ec0604cf6395
SHA1 ab50880af341a7e9c14b1a3dbade53fbb1457e48
SHA256 20895f5708984178014cd6bf23aceb4c926eeb8343641ec3c4b308e6fa5caded
SHA3 29e31e66854952190509557a2e5ff9a7262e02fa9c261bf443d76ef74e773ef9

210

Type RTF_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.80026
Detected Filetype RTF Document
MD5 140cef8568455018c9707c29186f66af
SHA1 33a40abf8c36c21d9a792da2dc37ece8f2339d2d
SHA256 2e35a88a738e5852baf8b0feb0c9ef4ac9ba931baeb30450772ea5ffca674828
SHA3 4999db068a3e3009734408a0ef73d333d387fc7bb468a48e9911c81a9ee3a22a

219

Type RTF_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0xa1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95447
Detected Filetype RTF Document
MD5 4608b9e7ddf0a829ad4dd98c2e718f84
SHA1 92a010a8dce3a2696e24a5b2d4527d81f9d6eac8
SHA256 1b3e7d6b884fb63d6a551237845821bc9c66c177757a863cebe379c2e7742abc
SHA3 ad9a298b36fa6bb7d671a1cc36470a73d86af7f51d3b5c2e9629e959c2251c0c

249

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x13e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.68257
MD5 b89c53234608d5520e4d31473d295903
SHA1 eb0793d7eb2f6e963a670facdbc9eb0005882350
SHA256 32673976ffb81636486cd895a3e78e45d812109fdc5c773bcd551316d0b35182
SHA3 babff1eae44a15d43d7d370045bcc0ad9ffe1db664c6acb086248acd1c31cdb0
Preview

255

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.675615
MD5 2487cd4b69093c5f2b5daae9a97b6b0d
SHA1 bd685319d12d18941e76c6c65e6a9eeb8b56ba40
SHA256 43175f041004354a75b7cc148dc6192777411006df824d83587098ae0e87959c
SHA3 5f6abbd150f4ae75ceea15f8b7e0271b64ae7a55866213bcfc7f86641b37793c
Preview

10106

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x48a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.91386
MD5 feb4796a8797e048f5309d841b9e680d
SHA1 2bd88e01b58b033fc830623f6d3f3bea30c16b10
SHA256 6e1084a05b9b8a00d2f8572cb70133f10d9ccbb1c6d6dcbbd9c4ae8a655add8a
SHA3 9b52aa7127a27d71df724bf20d4619005546e24be0d4faa1db0229424501c480
Preview

10107

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0xa6a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.79553
MD5 e907975955dd2be6b62fd46628cfedce
SHA1 b4694d36c14d72ba6eec14f70d02197019499ca8
SHA256 1bd86eecad0a5db654c729a450c8feeb821c41a06d4bca338d2121b7a010c603
SHA3 e788a5bc64147359c6343cec773fc54ea0bf9174bc37850d4708e3e5ba276527
Preview

10124

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x152
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49051
MD5 ff7110580b8339ae5c3177248cd86f28
SHA1 c86171d538549724740ed7d5bdd784edfbe282e7
SHA256 faf9686e3bcbf27686fa92a97fee9c72db32240fef4295aad14403935c9bab8f
SHA3 8cd6ba7864898ce057585c51629c03dc57c71ef1c8511faf0bcc8224a8e8c476
Preview

10125

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.67246
MD5 9eb7f2c8f73508a28a7c701e35a9072f
SHA1 b01786342e84083bda8c94534c2ef2441f3ecb6d
SHA256 6ea607ae2e99a0d4d663d8f7d778228be0fcfc96f2f61b5e37641dc1512915bd
SHA3 10e1ccf1b01c53355dd05e1b1230116fda59dfcccb7e296383563cbb2fd69e9c
Preview

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44042
MD5 18ad5d6ccee9a7e99808b51f1a5b2163
SHA1 357283f0ce4b7483d7379d06af9bfa84cec9c60a
SHA256 4c4796ad176cc1beb4df922fa8e7acb4d8aa0d011b300e77648803c375026d02
SHA3 afc7cbe3635f7a87ea4e2baa9550205651dc23e65d617de7091ba35608c09df6

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2982
MD5 c85748ba3364ade0d7f0eb665a78afa1
SHA1 44cbe43791d41642f41e33a5434236aa269a59b3
SHA256 0e22fc5f33b299a47d037a0c413bd0105bcedae294bde0c68ead32449a5d5a6a
SHA3 d06d25990f879b96d7b60bf13562c748a226029b7c9eca7043dff9a79d0873cf

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19797
MD5 6ffb97fe18897587ce91cba6e3f674aa
SHA1 e58a677a2d5685a1a233f85ab22044370f51b013
SHA256 fffed36c7194636d989790460686a17c77f297b988b481b7c747bffd9226a7b3
SHA3 89c3936b4c71572223012ec22e03736ba1643278008d00c2da83709992f599fa

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93168
MD5 17d5a143e1eb4f28b07657e045b209c3
SHA1 c1487f113a4472531da08c2e421d19fd7d142d72
SHA256 a477213c028fcda31d2d2b9d6893f3265cb4b9b31692d7fbb0a50967d91b53d5
SHA3 e676933c9f34d0574c22cc619fcd4a99d02aededa2f3f465c183e71d7dd9e08e

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42de
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96069
Detected Filetype PNG graphic file
MD5 72b8ffabd9ddbcc76ac8ecf74c1d9711
SHA1 82ed1b8566a8cbf46b79a3a15b9227a73a15f974
SHA256 4bc28cf5777495e50c4a3cc1c1cbdcbc594131acdeb305b146e9a0499ae64431
SHA3 a0efd33a5344e137f353a64710aeeafe59ebb9103456a941c473dbf11c913896

213

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x5c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00642
MD5 abfffe4e3820ef1e6be1e3edbb928850
SHA1 62d1b7774375c47f1632cf5480ad314642a252fa
SHA256 3e47269c9d1e169a319f9149f3edcdf81c071134124d0d00a0f86ceab4107a1d
SHA3 15967e8ac79649521f57cb14973344ccece724deaa60d1f5790d23ea86cad023

214

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.46729
MD5 2de7f9dea9df0162fb0829e4c918afb9
SHA1 5ccdd5f933a3b7a48886c58280d863377afa21a9
SHA256 49289cf8f62077d89ba6e8ac99f52b68d6471a1ea17e373c6042aacd07399b0e
SHA3 c51e51fea0d3c1a44327fcd4ff8b0d920438c8f86e51421753f8a83e7052bb63

201

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97566
MD5 b9b65d5665b18db6184ce81b485aa7a4
SHA1 a0927bb2b99bdefa1134023c23a5931fd6889a8e
SHA256 fd13c023359af19820646f58138d7cba69a82b5a55ce2f42d7dfdb34098ebdf7
SHA3 4eca1f6d50a21935c56a6a8965301a805ff1c91b079927c15838b0471f2afc6e

202

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41539
MD5 eb0e145cf85121d86fd50d9d8c907a10
SHA1 97b5961b46ff4366de4d0f01db92d72da12245a0
SHA256 ad1d4b5d0ccfc7e23f7e4120e57a840f4e60eaad2817a6d348064da78189115e
SHA3 7404649e829e2e189e8a09c0c2f010eb0e207468a1cba42591c8aca0c04ca1ed

203

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37343
MD5 b363180143ad11331e36957c97adf1d8
SHA1 8aeb68fc1d7997c14eb14cc74697e4f716b23293
SHA256 8995344377adca3633e297ef55e1e2ef45e973152d27860e6a732ff3807fc178
SHA3 1a26e31ff8a8ea45eb87cdfb318cb50c5e2dd6bcab572a6354b68adbf34906cf

206

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07552
MD5 22033b9a0e3bd4f361e5a92e01dde47e
SHA1 7abfabc5b58e4d95e97a7c35408f79deade739e9
SHA256 3addcedd607a71eec21678478de4a532aef743d19aba72e9f0e7dc4a9cf35536
SHA3 9df51edb3635b5054b22e7c25187ff17ba9d9b4e168aac0bcb8429f46b71bb3a

211

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x204
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40149
MD5 90b400d106635a3a5b671956fbceed8c
SHA1 0e541d3848dd6e009671ffc25d59b2dfee00de8e
SHA256 f94cbc8bd64f4e2fb6ff64b19a63707ed6848569e68172c927ee77e31568aabb
SHA3 fe88d8bdef7f0ce53856d49cda64f1a128eb1267c5e4c683c964b697b188867f

212

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x282
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34343
MD5 c094d1476a8b82860d976fb331ea1d6a
SHA1 f1f370efec5e41851bf4995cccb01a016c10bc21
SHA256 faa9574306006ba6a9be3d6d19ec334f94f0d35ab106fa3757cdfb91c0d1cceb
SHA3 9c34d169ba0d84bae90cfcd8f26755b3a944bd259a0514850613a344c469d5d4

216

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95251
MD5 3bef094dbf2ea14e852b5115dfc27c01
SHA1 e4543f8ee40821ff4bd5a159c6eac14740507600
SHA256 2d383bc8ee9892418d03cba3ba938ebc11483ceec2923a171aba8148e31a5d74
SHA3 9babb54cedea25fb8dee9c33d3cd6f98fd3c954e65d7a95e62807c4e21e23344

217

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02577
MD5 d2411f85ef7864376e51e9dde17be67f
SHA1 4660271ade07f24a20996964e2f82d697ba996dc
SHA256 7cfcbb32df3d4275599d0b293feed4ab24ceb065aa62eafebd109c03533a9531
SHA3 c88ac3822c822980bf676786b4b2ebd2f35e7a25de8b4a425312129196d886a8

218

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x226
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32165
MD5 b3cd660f4cf22085690d7e577416848c
SHA1 c41cd85fae30918284b544b1a260e2e6858531b6
SHA256 e85bd20dae0d64bd3f751c16133cbf3d75ecb771d756ececb430c9aa6ec910a9
SHA3 5a5513b94c5bf664ecedaa1ec6048a30c5de86c67bf7b16dbe024d0805422111

223

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x388
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35341
MD5 d1f000af3b5ee3f81773b8427e216c71
SHA1 eb391879ecc051b3c1d695318eedcb1b35be1430
SHA256 25a1b1f3952e5c00c460cfe5ec036b3ab42b6d5fab4e9c5d5b549875dfd7156e
SHA3 c9cfee0e040b78dd1e11ba3ecdec7dc82164bc331722b2af28ffc626bdc2a3d1

225

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11595
MD5 d586b4c2b2b822483a616c0131f3987a
SHA1 b4ed46162c1f453fe0d0f138d5038df718093881
SHA256 ad6fda587ab7a3f8424d37499a31fe22a168ae4dc28a75d355515ca684918405
SHA3 b2f7570787e13a977a90fbfd93c01ca6a9d36eca98bd680e552217efe1175a75

2000

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x136
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10615
MD5 e956f800d346d4d9836e188482c383b6
SHA1 33c2d6be547d8f6c9281d5c4b8a4f438dcab8c57
SHA256 2fdf71fc373ceeb67cdba7abdb6181b0b0f1fc6394abde884def028c01df22e7
SHA3 7a546374030dc54ede31055b791738fb0d2f0ade37b521511d93502e273f2da4

10123

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65407
MD5 1908f46cac6eaed1a2e79513bb135f67
SHA1 3ce39d89c18bc4f425582dfe56429bb1a06cf9c6
SHA256 477c4e79c878015fb0f6d7fab9bb703bb9cc1a072fadb6bd2c8c73c91baf757e
SHA3 15c0545ad62484a2e7f7f6660afe409e6e19dc1a3125250176660006781c82c7

9

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x45c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37783
MD5 c7348aa264060f3ab4e201d5bdb88fe6
SHA1 494f800e8011fedaea99b22a8f9b07c9c053d658
SHA256 f9fcc2ef47b098b85a50e480c3cd78c2fa8c4545db342b39025393599351de57
SHA3 26a4a5d6ba962e0b1b1a9f2b1aff101e80253e629619b7190ffe9e373b0b627a

10

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x760
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35254
MD5 76540f73e4f44f5742f792679aad0e7e
SHA1 4d86dfb93069823df2d18f9acc2c97558841e9fd
SHA256 696500e68ea8a157ab57f0ce0046a8cfe69317a897032b1f4a5f7cda05d5af18
SHA3 906be7ed66a8af5005f49c0a1996c87f4eda2b0724af5dd9c7a8e9625117f5ce

11

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31743
MD5 29c8d9bfecdd111a60d028c6ded13548
SHA1 23055010ab79d42caa2df439cd430f1bbe541fb2
SHA256 dd1e05c4ba3d0764e0621a426bfe69ca3792b0da3f80ada3af9df40449e7790b
SHA3 947d738729615bc2c4439833736b5fbbaf24e9184aa3a7c21d5fd19edfb38ecc

12

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x598
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23118
MD5 066e47920e63c033ef6fa01c4d9bda61
SHA1 6bee24a095cd99b626f0f401ed86f16ef6f3fd8b
SHA256 b9b343517562cbafe4a944cc8d12189cb7cf5a68fdc4a6520788890caf432db3
SHA3 e5341016a9d5ca4932f674a49ea82fc7c8a573b558e9261cea96dbdb819a212a

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x334
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35766
MD5 b2b3e06fe95ebb4236eb9a3686f9487a
SHA1 b8ba027f645425e4e3c4b1c1b5bd1bb85eff99db
SHA256 f56d3df6a367f3c4072fa0493a8994874970a1e362a97c39b3de1eb88ce8e222
SHA3 bf72a8e403ae6e0f6a3be80d0cb7512dd11f316a16870182b2e2cb19258ab47f

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16649
MD5 3be9a36a7f74b04a62a9523892acea11
SHA1 ce0c6f8120fd39bb9b4eb73b24372a8690a0adcb
SHA256 bbd9734f361616c3046606bab309ebcf80e2d330ce2b2d4c7be67bacdd4b1b60
SHA3 58681a73e0dc3d13fcaf01ff77e413f76b481e0ffdf509de3b4ca1f001371744

15

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x274
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16338
MD5 f16d63ceb9574f1cf089b7c135555554
SHA1 e8680a65d21de78604f7e077fc9918d8bc992e93
SHA256 63e35ada4a3b2149f713a72687104a4777914f2e7092869aa450531fb87eba5b
SHA3 0efefb9076c6ec19f978b3952f99dcc925767737444df05f8f958aa5b9f5f7eb

16

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x164
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04011
MD5 c1e0a4e1a928fc2e80c61135a4520e67
SHA1 064d477f7e1a96b07fdd2a5841f5d3db035c4f38
SHA256 90a773af7f8a0fb902848e606d94fdd1f0d0970d872892617788acc1b06e444b
SHA3 1da1c8a65ea4149c95a8777c4cce8821c038a06282db5fcb22bb653b230fa709

17

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x520
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3657
MD5 f6d684601b6a329541b4d36003ad4e32
SHA1 9ae927f8cfc7d7cc9be5a74281d0cc2a698a0628
SHA256 79f41692abf816b5679673adb4746996ff01f4255b59061256e98c49da8332e7
SHA3 e28046989e54dd3853b87c54212d3ec1f9b0597863e58030fe0df60303ff57bc

18

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20151
MD5 dc0e178588fce9302d14064c390cf22d
SHA1 9546f46d3a79fd3c5a2da8fdca4654f0aa74d3d2
SHA256 472888fd1541a96cdf7cfd6b29b4610d32b85821d0316138dc49b21be65ec351
SHA3 4898046a334fc1b7a141d5dd621aacdc03c199e966f629527b310cf730669e06

634

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0751
MD5 7e73112de5acaa97c7213fc14d96ccc0
SHA1 bd5d869ed232c978594a3bd6d3df96d28502338b
SHA256 4d6ee08852cf885069655460144391767a8153c29cfb97cb5f67f2bd87413e05
SHA3 1807415824e80407ed8b84b3f89d24c637f24978808843c0dbfe4f586f75d850

4063

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x216
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35239
MD5 37d36ef637c1eedcbc9f55c93ca696f5
SHA1 52fde54dff5438759b55653e3847110153f582ee
SHA256 783d14215f20390eed1996c78ed95e304b7d66bbd1bdd1f343eb9b9be9e5e2c1
SHA3 ac12c5a4cf75a44feb5ceefdd56d1f0ba50112c165663682bdd7de83e53e5263

4064

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x574
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43466
MD5 7649cdfb71bacb86a9761c8c2bfa837b
SHA1 db0c9a91df3f6cd6d7c0801850fdf89e08520a63
SHA256 2a9b06c5a4e3455772dff524ce1986fecb18b699408cb0efa54e580453f69721
SHA3 c395b6cfbe183e4dd1d4172e80cbdfd58fe73101a969a444b3eec87690817831

4065

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x660
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44025
MD5 73f6cadef66fe41cd99e1f2dce0b273f
SHA1 7ebf195fca72736b475fbda3cc5a369157a8cbc5
SHA256 3224f6542bed9e3e7bc42c754f4864fabfc03e531bf18f76f0f5a35cf2fdb193
SHA3 cce6002143a84b79ce11029c3f9275dd0e9bc4bdeb73ab36285c6ccbf16bda71

4066

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90658
MD5 70dc3e3ea81ae31e077223f0c0544c9b
SHA1 b42b274b0aa0505bac290d22f45d7198463f40ec
SHA256 16664781c6daa6c0bbbb4177f38a69dda7e202f6f976734cbd906346f5e1441d
SHA3 e038315f2b387965823e3f1c0d7da3251cffe0878a98bd43d0e6f28c52f3548b

128

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64638
Detected Filetype Icon file
MD5 700ddb87b2cbcdfdfc79c4548af9c995
SHA1 683dda4091516af3ac1220c8c032911ae3d63d3e
SHA256 68b4673c3754bde1768e614a2d7711b98c0babd2298c2ef8d689b5dbdde0c746
SHA3 78688fdf41213507d6eda5503c47fd5c45c31c3b80032db82fd15f08113d20ae

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x35c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4481
MD5 8661f89eb2aee9eea633dfc54fa16406
SHA1 27f9167852d1d8bebfe9dbe3ebefa35f00e49a84
SHA256 3428bf6865a6ed7733b36fb6f5e6e16d071e953644cc48178ed0566ca57dffdf
SHA3 3efd8c0ca1a6e836bc60b53c5f67d96a60fe12cdcb5871004b88be2325f54ba2

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x775
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.18998
MD5 78e38259eebbf0c526aafc73463a9e6b
SHA1 9502aa310e7e47fa97367c084356db446c924b0c
SHA256 b43343091e7afcfc5d59698191d4071591bd8543f3f14a390ca50f18f030bc22
SHA3 f231e74e096a09dc8fcc5b5a4002d3cfdf1f95c046b17a44c1c3053ef90af345

String Table contents

Setup
This archive is corrupted.
This archive has an unsupported version.
Windows Installer could not be started.
An error occurred while reading the file.
An error occurred while extracting.
Select the download folder.
%s can not be installed on systems with Windows Installer version smaller than %s.
Error
This package requires Windows Installer version "%s". You have "%s".
Please upgrade your Windows Installer.
Checking integrity (MD5)...
Corrupt file (wrong MD5 signature). File removed.
%s Options
Extracting the main application files...
URL
Status
Command Line:
%s [options]
options:
/? or /help - displays this message
/extract:<directory> - extracts all files in <directory>
/listlangs - list languages supported by this setup
/exenoui - launches the EXE setup without UI
/exebasicui - launches the EXE setup with basic UI
/exelang <langId> - launches the EXE setup using the specified language
/username - username used by the proxy
/password - password used by the proxy
/exelog<path_to_log_file> - creates a log file at specified path
/exenoupdates - does not check for a newer version
<msiOptions> - options for msiexec.exe on running the MSI package
Name
Action
Skip
Download
Install
Installed
Not Found
Open Site
Installing %s
Press the Next button to download the prerequisites.
Press the Next button to install the prerequisites.
Press the Next button to open the prerequisites' web sites.
Press the Finish button to install the main application.
Pause
Resume
Required: any.
%s Setup
Required: %s or lower.
Required: %s or higher.
Required: between %s and %s.
Found: nothing.
Found: %s.
Version
This prerequisite is mandatory. It must be installed and can not be unchecked.
Name
Press the Finish button when you are done and ready to install %s.
Press the Next button to install the prerequisites.
Status
Pending
Installing...
Installed
Error: %s
Installing %s from: %s
Some prerequisites could not be installed. Press Back to return to the prerequisites list.
After launching all packages some required prerequisites are still missing. Press Back to return to the prerequisites list.
All prerequisites have been installed successfully. Press Finish to install the main application.
Welcome to the %s Prerequisites Wizard
Prerequisite
Some prerequisites could not be downloaded. You can try again or remove them from the prerequisites list.
Pending
Finished
Wrong size
%d.%d KB/s
Some required prerequisites are still missing. You can try again or remove them from the prerequisites list.
%d hr %d min at %s/sec
%d min %d sec at %s/sec
%d sec at %s/sec
Size
Paused
Progress: %d%% (%s of %s)
Downloading: %s %d%% (%s of %s)
Download Finished
Paused
Opening site of %s
Downloading %s
Extracting files from archive...
Extracting file to %s
The %s file can't be unpacked. Error message: %s
The Java Runtime Environment version 1.5 or later must be installed in order to unpack JAR files.
Another instance of setup is already running.
Found an acceptable version.
Error: %s
You must reboot your computer in order to continue the installation. Press Yes to restart now or press No to abort the installation and manually restart later.
Confirmation
Unpacking file:%s
There is not enough space in folder:%s
Please free some space and press Retry or press Cancel to abort the installation.
Preparing...
%s Languages
Searching for prerequisites...
Install Location
Product Name
Question
An upgrade of the selected instance will be performed. Do you want to continue?
Upgrade all installed instances.
This package allows you to install multiple instances of %s. Please select the option you want and press OK to continue:
Evaluating launch conditions...
%s cannot be installed on systems without %s
Connect to %s
The server %s at %s requires a username and password. Please enter them below.
Cannot access URL: %s
Failed
There is a newer version of %s (%s).
Would you like to download and install it?
Checking for a newer version...
Failed to download newer version (Error: %s). Would you like to retry or proceed and install current version?
Failed to read from file "%s". Error: %s
Failed to write in file "%s". Error: %s
Instance
Default
Version
Setup package was encrypted using AES 256 algorithm. To continue the setup process, you should provide the password needed to decrypt the package.
A reboot was initiated. Application will close automatically.
Deleting extracted files...
Unmatching digital signature between EXE bootstraper and MSI database
Back
Next
Finish
Cancel
Downloaded file does not have expected size
%s mandatory prerequisite was not correctly installed.
Searching for installed AppX package...
Installing AppX package...
Removing AppX package...
Invalid command line
Unable to init windows application
Internal error
This installation package is not supported by this processor type. Contact your product vendor.
Advanced Installer
Unexpected exception.
The application ran into a problem that it couldn't handle.
Sorry for the inconvenience.
Exception (at %2!ls!:%3!ld!) - %1!ls!
STD Exception (at %2!ls!:%3!ld!) - %1!hs!
A COM API returned error: [0x%1!lX!].
%1!ls! %3!ls!:%4!ld! %2!ls!
Could not allocate memory.
Parse error in file: "%1!ls!" at line: [%2!ld!] column: [%3!ld!] (code: %4!ls!).
Unsupported file encoding.
File "%1!ls!" could not be read.
File not found: "%1!ls!".
Error opening file: "%1!ls!".
File "%1!ls!" could not be written.
Unsupported command file format. The supported file formats are: ANSI, Unicode Big Endian and Unicode Little Endian. The first line of the file must begin with "%1!ls!".
Value is missing for the parameter %s.
Invalid "%s" parameter value: "%s".
Unknown parameter:
Maybe you should use instead:
A required argument is missing: %s.
One of the following parameters is required:
Null pointer exception.
Error parsing XML file: "%1!ls!".
Invalid XPath expression: "%1!ls!".
Command "%s" is unknown. Maybe you should use instead "%s"
Invalid XSL transform.
Invalid input filtered.
Your input has been filtered because it contained invalid characters for this field.
Your input has been filtered.
The port number needs to be in 0-65564 range.
Error calling MSI API: %1!ld! Method: %2!ls! Table: %3!ls!.
Error calling MSI API: %1!ld! Method: %2!ls! Table: %3!ls!. Extended Error: %4!ls!.
Provide a valid Offline Registry handle.
Invalid hexadecimal string "%s" in registry value "%s".
The version is invalid!
Underscore can be used after every digit, except for the last one.
Invalid version format, expected: major, major.minor, major.minor.build or major.minor.build.revision.
Invalid version format, expected: major or major.minor.
Invalid dot sequence.
The version is not allowed to start with the dot character.
The version is not allowed to end with the dot character.
Each part of the version number must be an integer between 0 and

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.13.4.0
ProductVersion 1.13.4.0
FileFlags VS_FF_DEBUG
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Proton Technologies AG
FileDescription ProtonVPN Installer
FileVersion (#2) 1.13.4
InternalName ProtonVPN_win_v1.13.4-139b12d9
LegalCopyright Copyright (C) 2020 Proton Technologies AG
OriginalFileName ProtonVPN_win_v1.13.4-139b12d9.exe
ProductName ProtonVPN
ProductVersion (#2) 1.13.4
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-Dec-17 09:36:36
Version 0.0
SizeofData 75
AddressOfRawData 0x197584
PointerToRawData 0x196384
Referenced File C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2019-Dec-17 09:36:36
Version 0.0
SizeofData 20
AddressOfRawData 0x1975d0
PointerToRawData 0x1963d0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2019-Dec-17 09:36:36
Version 0.0
SizeofData 1072
AddressOfRawData 0x1975e4
PointerToRawData 0x1963e4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2019-Dec-17 09:36:36
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x597a24
EndAddressOfRawData 0x597a2c
AddressOfIndex 0x5d26b0
AddressOfCallbacks 0x56e3a8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xa4
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x5cd010
SEHandlerTable 0x595870
SEHandlerCount 1861

RICH Header

XOR Key 0x2d35e784
Unmarked objects 0
ASM objects (26213) 14
C++ objects (26213) 179
C objects (VS2019 Update 2 (16.2) compiler 27905) 19
ASM objects (VS2019 Update 2 (16.2) compiler 27905) 23
C++ objects (VS2019 Update 2 (16.2) compiler 27905) 99
C objects (26213) 26
Imports (26213) 3
263 (26213) 2
Total imports 667
265 (VS2019 Update 3 (16.3) compiler 28107) 289
Resource objects (VS2019 Update 3 (16.3) compiler 28107) 1
151 1
Linker (VS2019 Update 3 (16.3) compiler 28107) 1

Errors

Leave a comment

No comments yet.