f3ab25c044aefd002f77f1cd1135548a2f0749d0a74624dcdd57c6cb9721015f

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2011-Apr-19 06:26:53
Detected languages English - United Kingdom
English - United States
CompanyName Simon Tatham
ProductName PuTTY suite
FileDescription SSH, Telnet and Rlogin client
InternalName PuTTY
OriginalFilename PuTTY
FileVersion Release 0.61
ProductVersion Release 0.61
LegalCopyright Copyright © 1997-2011 Simon Tatham.

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0
Info Interesting strings found in the binary: Contains domain names:
  • chiark.greenend.org.uk
  • greenend.org.uk
  • http://www.chiark.greenend.org.uk
  • http://www.chiark.greenend.org.uk/
  • lysator.liu.se
  • openssh.com
  • projects.tartarus.org
  • putty.projects.tartarus.org
  • tartarus.org
  • www.chiark.greenend.org.uk
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to AES
Uses constants related to Blowfish
Uses known Diffie-Helman primes
Suspicious The PE is possibly packed. Unusual section name found: lmtC
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongA
Can access the registry:
  • RegCloseKey
  • RegQueryValueExA
  • RegOpenKeyA
  • RegCreateKeyA
  • RegSetValueExA
  • RegDeleteKeyA
  • RegEnumKeyA
  • RegDeleteValueA
  • RegCreateKeyExA
Possibly launches other programs:
  • ShellExecuteA
  • CreateProcessA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • CreateCompatibleDC
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 50/62 (Scanned on 2026-03-27 06:14:21) APEX: Malicious
AhnLab-V3: Trojan/Win32.Patched.R275304
Alibaba: Trojan:Win32/Leivion.c8762659
Arcabit: Win32.Swrot.A
Avira: TR/Crypt.XPACK.Gen
BitDefender: Win32.Swrot.A
Bkav: W32.AIDetectMalware
CTX: exe.trojan.swrort
ClamAV: Win.Trojan.MSF_Shellcode-1
CrowdStrike: win/malicious_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
DrWeb: Trojan.Swrort.1
ESET-NOD32: Generik.ICWDZIK trojan
Elastic: malicious (high confidence)
Emsisoft: Win32.Swrot.A (B)
F-Secure: Trojan.TR/Crypt.XPACK.Gen
Fortinet: W32/Rozena.D!tr
GData: Win32.Swrot.A
Google: Detected
Ikarus: Trojan.Win32.Swrort
Jiangmin: Win32/PatchFile.ip
K7AntiVirus: Trojan ( 004786151 )
K7GW: Trojan ( 004786151 )
Kaspersky: Trojan.Win32.Patched.qa
Kingsoft: Win32.Infected.AutoInfector.a
Lionic: Trojan.Win32.Swrort.4!c
Malwarebytes: Malware.Heuristic.2108
MicroWorld-eScan: Win32.Swrot.A
Microsoft: VirTool:Win32/CobaltStrike.A
NANO-Antivirus: Virus.Win32.Gen-Crypt.ccnc
Paloalto: generic.ml
Panda: Generic Suspicious
Rising: HackTool.Swrort!1.6477 (CLASSIC)
Sangfor: Hacktool.Win32.Patched.Vzus
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win32.Infected.gh
Sophos: Mal/Swrort-D
Symantec: ML.Attribute.HighConfidence
Tencent: Win32.Trojan.Patched.Lcnw
VIPRE: Win32.Swrot.A
Varist: W32/Swrort.C
VirIT: Win32.Swrot.A
Xcitium: TrojWare.Win32.Rozena.A@4jwdqr
Yandex: Win32.Swrort.Gen.2
ZoneAlarm: Mal/Swrort-D
Zoner: Probably Heur.ExeHeaderL
alibabacloud: Backdoor:Win/metasploit.shellcode
huorong: HVM:Trojan/Swrort.gen!A

Hashes

MD5 d6e12a5bfff9d8c92b06cdc57b872169
SHA1 c93520c820634150efd374b9932b948e6eb8c484
SHA256 f3ab25c044aefd002f77f1cd1135548a2f0749d0a74624dcdd57c6cb9721015f
SHA3 a42122f1e15856af892ebbfa7ecf1f40b621c33f3a51f9aa7b3e7b4bdef953fc
SSDeep 12288:V576yiuL3gBYsCLrwCIBr0H1l5p19Yj0q692:rOyi0wJgIBr0H1LpEb68
Imports Hash f21a9f3053f9056b922fce95824077d7

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2011-Apr-19 06:26:53
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 7.0
SizeOfCode 0x55000
SizeOfInitializedData 0x28000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0007D000 (Section: lmtC)
BaseOfCode 0x1000
BaseOfData 0x55000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x7e000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0b77fec486a547e316b95ee87c45c419
SHA1 6b95b823b1d4d7929ef501d92167a45b09cc863f
SHA256 35f91d644afbd4ad844246c8236b417a1d481d7b0b30ea1b16fd55154a910d70
SHA3 53185e18f70017d260685ccc859aec997a7c5254c4ec27ac92c2cc0ce398f5a8
VirtualSize 0x532b1
VirtualAddress 0x1000
SizeOfRawData 0x54000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.63855

.rdata

MD5 7f880f3d2c37e3e25035be1179b1c708
SHA1 b5dd496364ba1fa468d6a8aa16c7243752497ba7
SHA256 f79c37da67cbeaf1f2a088887d3d54c38597296593020d8ad448eddda14c02aa
SHA3 a100c5e50de079a3e2883a053177a5718b27d1fd6cd2d086d0b63f434977a92e
VirtualSize 0x1b0ee
VirtualAddress 0x55000
SizeOfRawData 0x1c000
PointerToRawData 0x55000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.05418

.data

MD5 20944e03b97746c14a1e0d4038bde569
SHA1 b1500faec7b0c316dbcfc4603064e53b46ec3f54
SHA256 442f36408e8fd2df13b0a850230f5ae6ba319ee558e57e43e41e8a0cd9bdfd0e
SHA3 ae218995f45e68db98d71f839655dfc3222ebeee5db53dde6f4ef3e519f85cfb
VirtualSize 0x7e04
VirtualAddress 0x71000
SizeOfRawData 0x1000
PointerToRawData 0x71000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.03816

.rsrc

MD5 c6992180f3a4c61ec4747806ce56ec4c
SHA1 0ea90aabde7ab0830c0a8dd59545c28e67b74f04
SHA256 96be5dda43754a1d9b699b7f3d54da322aa742e529da80a89abb4b327cac3bc9
SHA3 b2e7d23cbe59632a0ae8bcb33d4c162ebe53dc5b0f3017bb28c3ae176194946f
VirtualSize 0x3b90
VirtualAddress 0x79000
SizeOfRawData 0x4000
PointerToRawData 0x72000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.87226

lmtC

MD5 4a13a77292c1ca16666a9692987cd9b4
SHA1 40736e0587ce26079507e4a5dd896aa57782978a
SHA256 e79495edada4bdd6ddacd3eec73c3cf4aaf4d5be07c5672f0fd4fce3943f8169
SHA3 aa7ecb0582402ccb8e08e835b2e0132959eec72c7a916d279da7aa95e4907a48
VirtualSize 0
VirtualAddress 0x7d000
SizeOfRawData 0x1000
PointerToRawData 0x76000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 1.95352

Imports

ADVAPI32.dll RegCloseKey
RegQueryValueExA
RegOpenKeyA
GetUserNameA
CopySid
GetLengthSid
RegCreateKeyA
RegSetValueExA
RegDeleteKeyA
RegEnumKeyA
RegDeleteValueA
RegCreateKeyExA
COMCTL32.dll #14
#15
#17
#13
comdlg32.dll ChooseColorA
ChooseFontA
GetOpenFileNameA
GetSaveFileNameA
GDI32.dll CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
SelectPalette
CreatePalette
ExtTextOutA
GetCharacterPlacementW
SetBkMode
GetBkMode
ExtTextOutW
GetCharABCWidthsFloatA
GetPixel
SetTextAlign
CreateCompatibleBitmap
TranslateCharsetInfo
GetObjectA
LineTo
MoveToEx
CreatePen
SetPixel
Polyline
GetCharWidthW
GetCharWidth32W
GetCharWidthA
GetCharWidth32A
SetPaletteEntries
UnrealizeObject
IMM32.dll ImmReleaseContext
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
ole32.dll CoUninitialize
CoInitialize
CoCreateInstance
SHELL32.dll ShellExecuteA
USER32.dll SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
GetForegroundWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
MessageBoxIndirectA
WinHelpA
UpdateWindow
DefWindowProcA
InvalidateRect
SetWindowPos
EndPaint
GetWindowTextA
GetWindowTextLengthA
GetClientRect
BeginPaint
SetWindowTextA
PeekMessageA
MsgWaitForMultipleObjects
IsWindow
CreateCaret
ShowCaret
HideCaret
DestroyCaret
TranslateMessage
EnableMenuItem
GetCursorPos
TrackPopupMenu
ScreenToClient
GetKeyboardLayout
SetKeyboardState
ToAsciiEx
SetScrollInfo
GetMessageTime
PostMessageA
CheckMenuItem
IsZoomed
FlashWindow
GetClipboardData
RegisterClipboardFormatA
OpenClipboard
SetClipboardData
CloseClipboard
SetCaretPos
KillTimer
SetTimer
GetKeyboardState
SetClassLongA
SetCursor
ShowCursor
CreatePopupMenu
InsertMenuA
DeleteMenu
AppendMenuA
IsIconic
GetSystemMetrics
GetCapture
ReleaseCapture
LoadIconA
GetDesktopWindow
MoveWindow
DefDlgProcA
LoadCursorA
CreateDialogParamA
GetMessageA
GetWindowLongA
IsDialogMessageA
DispatchMessageA
PostQuitMessage
EnableWindow
DialogBoxParamA
EndDialog
GetParent
SetActiveWindow
GetWindowPlacement
SetWindowPlacement
RegisterWindowMessageA
DrawEdge
SetCapture
MessageBoxA
SetFocus
GetDlgItem
GetDlgItemTextA
SetDlgItemTextA
CheckDlgButton
IsDlgButtonChecked
CheckRadioButton
SetWindowLongA
MessageBeep
SendDlgItemMessageA
GetDC
ReleaseDC
SendMessageA
MapDialogRect
GetCaretBlinkTime
DestroyWindow
RegisterClassA
GetSysColor
SystemParametersInfoA
GetWindowRect
CreateWindowExA
ShowWindow
EmptyClipboard
WINMM.dll PlaySoundA
WINSPOOL.DRV OpenPrinterA
StartDocPrinterA
StartPagePrinter
EndDocPrinter
ClosePrinter
EnumPrintersA
WritePrinter
EndPagePrinter
KERNEL32.dll SetEnvironmentVariableA
CompareStringW
CompareStringA
HeapSize
SetEndOfFile
InterlockedExchange
RtlUnwind
SetFilePointer
SetStdHandle
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
UnhandledExceptionFilter
VirtualFree
HeapCreate
HeapDestroy
GetFileType
GetStdHandle
SetHandleCount
LCMapStringW
LCMapStringA
VirtualQuery
GetSystemInfo
VirtualAlloc
VirtualProtect
GetTimeZoneInformation
FlushFileBuffers
GetStringTypeW
GetStringTypeA
GetCommandLineA
GetStartupInfoA
GetSystemTimeAsFileTime
DeleteFileA
TerminateProcess
ExitProcess
HeapFree
HeapReAlloc
HeapAlloc
GetDateFormatA
GetTimeFormatA
GetCurrentDirectoryA
SetCurrentDirectoryA
GetACP
GetLocalTime
GetEnvironmentVariableA
SetCommBreak
CreateFileA
GetCommState
SetCommState
SetCommTimeouts
ClearCommBreak
CreatePipe
SetHandleInformation
GetCurrentThreadId
OpenProcess
LocalAlloc
LocalFree
GetWindowsDirectoryA
FindFirstFileA
FindNextFileA
FindClose
GetCurrentProcessId
QueryPerformanceCounter
GlobalMemoryStatus
GetCurrentThread
GetThreadTimes
GetCurrentProcess
GetProcessTimes
GetSystemTime
GetSystemTimeAdjustment
GetSystemDirectoryA
WriteFile
CreateEventA
ReadFile
GetLastError
WaitForSingleObject
GetOverlappedResult
SetEvent
LoadLibraryA
FreeLibrary
CreateFileMappingA
MapViewOfFile
UnmapViewOfFile
GetModuleFileNameA
CreateProcessA
CloseHandle
Beep
CreateThread
WideCharToMultiByte
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalFree
IsDBCSLeadByteEx
MultiByteToWideChar
GetLocaleInfoA
GetOEMCP
GetCPInfo
lstrcpynA
GetModuleHandleA
GetProcAddress
GetVersionExA
MulDiv
GetTickCount

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74321
MD5 84660bec1eeebe3ad61960f5b6785077
SHA1 38a40c423383d9e79664115cf1bfea6369e82dad
SHA256 89101ef80cb32eccdb988e8ea35f93fe4c04923023ad5c9d09d6dbaadd238073
SHA3 c423144290bb9d9273fb83be08980440a3c2cbb0dca4e170f8a7db81b2bedbfb

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98271
MD5 7d4cff360d2871fed319ecef64aa7d3d
SHA1 d7b7f55cbc2db4fad3018b6f068f1d56b1b2f88b
SHA256 8130832a780a7c334abfaaf3fce44fd99b2b8cff2e6d652764f4180472aeba74
SHA3 74045787c0b1a9cd244e4915f8121f761c4f3bd3afadaf720da5cef4eb4be380

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67905
MD5 401c9b96e28a617d87b18f017e47e714
SHA1 15e92225acb8fb97731c2bf55b7ae535d1a04043
SHA256 fcab313f71a454c02f47579f088001b972056019c2077da20c54473def350549
SHA3 d464f12be5ff5584404967fabd1c380a396908062b4823eb99e7e122dbc236d7

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.38964
MD5 1899fdd1a312061843a64f2dc3fb9bd2
SHA1 5c81855117b20af2a5b7405a3a875564b7601d33
SHA256 549e2b61d82d10da12bc640ff22dbe352087d641c391fe382f7665847066c31a
SHA3 3909e0f0041a56a52ec3a2094d2fb33cd7389b68f551ce4b94300f66e5427bac

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48609
MD5 ff8720e524b5fd54f831d5051e37017a
SHA1 eb680d020357a6a7aea93e8c617205a9bd673b58
SHA256 14528797e8c9c18854e9e5340c0453f608f83f63de0961e25c0528583c9fe781
SHA3 90860f98bb96b9bc2d537ab29e9063690a553019ceb55d6f2721edb5d06a9a7f

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62978
MD5 cec32b23e7b9942c91b7d943369d82d3
SHA1 cc936495e775e943954d3e0209ec87c715abe110
SHA256 90ce310a4f670171b69ba82f780064dccd25c92ff92cfeebb41f69b19008111a
SHA3 6450647b46175493d84ba14b12f84928309b81f4618d95a94df980c75acd565a

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16607
MD5 24fa9e5d440f1eb2741c3ff69bcf0066
SHA1 176a233a5af1f19b578f4ff28b30abb5b35703fa
SHA256 ca6932144ee553c7df83805a932ca120d4a6458fda707ad92b758ade870bbff5
SHA3 7d89863c42b1bfcef049d2b1f9f3e295d8ad4d08d4d0b8f91ccdc89b8f2fd684

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.57192
MD5 88ae047b639324c0c2532300cce7761e
SHA1 db8418aeb902e55c805617aaca62b5148f25f385
SHA256 40d176e64a8772483202fa25b4d7ef89341ddfb3b0c168d762fc1f86c35abae7
SHA3 aff6159d87a79321c53dfba65f1fa7d25cf1cd9fbc98c136cef94bf0b69ef0f4

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24629
MD5 d814ed55a8ec423c506a097ed5452e1c
SHA1 3199ef73669357b3176967cf729689ffdf506b12
SHA256 a8085f0bf68db8adc5aab891081cb87d3089a4dff05d3359047c503f17510559
SHA3 547ea078849cd72726d9b23aa04f61023fa4e6ae2796cacb09a42449f51eec44

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59447
MD5 1bcd2ac1427e73b3a2616488fcb926e9
SHA1 41f1b135dba51510b2eb89108500a54d624107b9
SHA256 0fee484eb60dac53c69ca37b3d0fe76d75a1c927f5adc1db82949a3fd63c116c
SHA3 a94d7c044505574da9e6396e020e037b4ec017ea42434110be12eeba60cc7773

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.131
MD5 000e79a9829ed30a66c9e9f46b630867
SHA1 bb080b9a8f1c3e44cfc93651bc84841615278c5a
SHA256 09aeee834e20c34531786e0db7a69eb388d3365b1f06d2e9bfea30c6fe2a49e5
SHA3 d19f1f5d1aa0c4262c651cf72b30b46493c9f0e8451e57e795cb476c9e03a3c1

12

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12285
MD5 6d9fd0eb34bb2598e10c2885d4c4a74e
SHA1 70a4473f857c959408dafba7a616c9baaf4626b7
SHA256 a0ac1114637fa796329b357fda4dcb1d6986ee0c8735b6072439322e86eb1a21
SHA3 a1d3545ab5b2416703e70ff48f8ecbca04edee92410cd2513444b4d7aded867d

102

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03977
MD5 0a2c5ab8767275738e79922a882de64a
SHA1 31720966b798968da9f39f54de0ef3dd1ebc1f8a
SHA256 351948a69293ee808ea5d6189f242fc5789dd7dc7ecd64a4401c1d21bb35f16b
SHA3 826048c4e8bd66d10c2a5d9e048c341a3c7cc4f57e05b9ea0a727def01f9c4b1

110

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31878
MD5 1e765c553e8c1c3c6ec35855247b47a9
SHA1 10510dc04fc29b33943420c9399fcb8d9154ab59
SHA256 0d9e394d80fc7df4aa10f0e96cad4a477a035a250fcfb59a91cd16dbca8381a8
SHA3 5de7600840998959a30322eea3f0737518fea3a747285077fac90f372b4ce968

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x196
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55605
MD5 54b811c536ceb5026ead52b3e4e6d583
SHA1 c3c217fa6d64f38cbe237f1365ae0d05744061b6
SHA256 7f222406ffa97009b89a7345e6ebe4a4c390e0e6e330e388018f5571c9d8592a
SHA3 eda5ceec65a5318508a272050f108f98e41da96d0514667d480458cb0b65f2f4

113

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xcc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68828
MD5 daeb7916c61cb021637b5a474f33518f
SHA1 7961ea3fdba89ec39b6b9449ad5e069a1625f665
SHA256 9e2eb5d511db5fb2fb9c35fd8647ca1e2dd9986321830e128fa9b9d061441775
SHA3 5a5c70a1ddaeb04e03e90b01d20d5d7697176aefcb703c079c6b0a2fb054a428

200

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74417
Detected Filetype Icon file
MD5 d148c75e59377aa79c180396f45f355c
SHA1 b0b26cad3bc43856c4de4bcb92e54dce6bf1f6f7
SHA256 ef77555c4d1e769f6748372d39d8422b85e6af8f11c8a811c82ce78a87cc8c9d
SHA3 e87f2a758ae18abe7e030c83b7d0b1e53c08b6b448376f9e954b53967f547bf5

201

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92968
Detected Filetype Icon file
MD5 9e81388befd1d4f93e209377728cb884
SHA1 4f7f26481375e507ac0045c531d8080586cc00f4
SHA256 383ca4cb5b95add3073e2cd86e4c5d62477d81bc80e0066da0919a1005f5033c
SHA3 29e35edf9c489ed74f8ae22c4e8ffc50cf11c6ca7607012da0ddcae96c53ba71

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37747
MD5 a5e1807f0a2ed057e8f30fe4690b1763
SHA1 83f3992af6cec445980bd1966af0295c0242ce8a
SHA256 67d7a5d0315a7cf60115cc3f0c19a9a7638d64ce87892081d6cc027d50ede154
SHA3 66a655380706e13d57abc1535de7dcec189d2187173636edd382caa69837107b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x4d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84233
MD5 7df7508f04c81632429b9aebf67ef509
SHA1 d73a137b4efa090a3cc65f38a6796089f1434061
SHA256 67186526ccffa82ac4afd862a4c3f29985232c2b26c9e9387774caa592dbd118
SHA3 d49004c44246d22c24da5c3d7703a40d3138917ca02b9a5a6534d4ededb36730

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.61.0.0
ProductVersion 0.61.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United Kingdom
CompanyName Simon Tatham
ProductName PuTTY suite
FileDescription SSH, Telnet and Rlogin client
InternalName PuTTY
OriginalFilename PuTTY
FileVersion (#2) Release 0.61
ProductVersion (#2) Release 0.61
LegalCopyright Copyright © 1997-2011 Simon Tatham.
Resource LangID English - United States

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x471680
SEHandlerTable 0x46e710
SEHandlerCount 2

RICH Header

XOR Key 0x38f67e29
Unmarked objects 0
105 (2067) 2
C++ objects (VS2003 (.NET) build 3077) 2
ASM objects (VS2003 (.NET) build 3077) 27
Imports (2067) 2
Imports (9210) 4
Imports (2179) 17
Total imports 301
C objects (VS2003 (.NET) build 3077) 188
94 (VS2003 (.NET) build 3052) 1
Linker (VS2003 (.NET) build 3077) 1

Errors

Leave a comment

No comments yet.