4417754bc3e9d22129090a5a5fa0b6c9787a6c6bcbc2dfd93a2bf4970735d0ac

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2013-Mar-13 22:11:48
Detected languages English - United States
FileVersion 1.1.09.04
ProductVersion 1.1.09.04

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++
Microsoft Visual C++ v6.0
Info Interesting strings found in the binary: Contains domain names:
  • .exe.bat.com
  • ArcadeControls.com
  • arcadecontrols.com
  • autohotkey.com
  • exe.bat.com
  • forum.arcadecontrols.com
  • gmail.com
  • http://forum.arcadecontrols.com
  • http://forum.arcadecontrols.com/index.php/topic,137497.0.html
  • http://www.autohotkey.com
  • www.autohotkey.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegisterHotKey
  • RegDeleteKeyW
  • RegSetValueExW
  • RegCreateKeyExW
  • RegQueryValueExW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegQueryInfoKeyW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetAsyncKeyState
  • AttachThreadInput
  • CallNextHookEx
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAllocEx
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
Enumerates local disk drives:
  • GetDriveTypeW
  • GetVolumeInformationW
Manipulates other processes:
  • WriteProcessMemory
  • ReadProcessMemory
  • OpenProcess
Can take screenshots:
  • FindWindowW
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious VirusTotal score: 1/61 (Scanned on 2020-10-26 05:02:53) VBA32: Trojan.Downloader

Hashes

MD5 fbe8929d8d0da7590558ba2feba7985c
SHA1 a7c690415fced11b3e85347dc0758035de179ac5
SHA256 4417754bc3e9d22129090a5a5fa0b6c9787a6c6bcbc2dfd93a2bf4970735d0ac
SHA3 b1f0fcd368c02c7e833dfab9a5aa4d3f6e2b5a752fb5ab361d2a0f1b2de062fe
SSDeep 12288:2biQhEpJm4NNfKdXmGkicPwUfML/A3g2mhgftPnDf:2biQCpzNNSdXxcPwsM03g2mCtPnDf
Imports Hash ddb5907fa1ea63fe386562bd29085604

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2013-Mar-13 22:11:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0x98a00
SizeOfInitializedData 0x8d800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0008BDB3 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x9a000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x130000
SizeOfHeaders 0x400
Checksum 0xd72bf
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x400000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d564707d8dbb50e2c85c9f4d21a09acb
SHA1 8e51379374606f414d1bf9f6b2bacb7762916f8b
SHA256 af6eba0b4218678a8d098419444eb5f2064dc929f9a84b6a8687385568acb607
SHA3 de36116877e256720ea752c56356ec8f83cfee21d6f02dfe9f20c9b216b491d7
VirtualSize 0x98831
VirtualAddress 0x1000
SizeOfRawData 0x98a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.62351

.rdata

MD5 95c10215d3fbcff1d431e22943c04aab
SHA1 ba3d9f47c026c6b5086e9a2a17cb239805234d46
SHA256 0fb2ce35eade268cb67fcca8e1585a84b7cafe88f438b9c35216b1c4a256a426
SHA3 d60063a3874671a71dd2d44726f996071446c57e8855c632b2f8097c3e6d1b4c
VirtualSize 0x22414
VirtualAddress 0x9a000
SizeOfRawData 0x22600
PointerToRawData 0x98e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.82675

.data

MD5 5ab60128d914a2da3e2f2d04c0ce835b
SHA1 8664239e7cf92db0aebf7b7e09c71de405204d43
SHA256 54d5bd5b8a9921f5820cdb3d0573936175fc3ae60fd94dc6f5999a59e06669c4
SHA3 a03a7bd898450892e509cef9a18e10baee2b13fde254caea9278c528a3abecb9
VirtualSize 0x9b58
VirtualAddress 0xbd000
SizeOfRawData 0x2c00
PointerToRawData 0xbb400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.70405

.rsrc

MD5 a6b59d8662523b679b5825b90818bb02
SHA1 e22eabf9662d95c114fb53a2f759f258912c8d5f
SHA256 41a304352fbaba7812f9673a1d20120a26f02ecf11c673872f3be74f85efaa97
SHA3 ad50a872b718c75815953799bcdb62f952564d7ea0d874aab1a80a0a2442d539
VirtualSize 0x6853c
VirtualAddress 0xc7000
SizeOfRawData 0x68600
PointerToRawData 0xbe000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.20762

Imports

WSOCK32.dll WSACleanup
inet_addr
gethostbyname
gethostname
WSAStartup
WINMM.dll mixerSetControlDetails
waveOutGetVolume
joyGetPosEx
mixerGetControlDetailsW
mixerOpen
mixerGetDevCapsW
mixerGetLineControlsW
waveOutSetVolume
mixerClose
mciSendStringW
joyGetDevCapsW
mixerGetLineInfoW
VERSION.dll VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
COMCTL32.dll ImageList_Create
CreateStatusWindowW
ImageList_ReplaceIcon
#17
ImageList_GetIconSize
ImageList_Destroy
ImageList_AddMasked
PSAPI.DLL GetModuleBaseNameW
GetModuleFileNameExW
KERNEL32.dll FindNextFileW
FindClose
FileTimeToLocalFileTime
SetEnvironmentVariableW
Beep
MoveFileW
OutputDebugStringW
CreateProcessW
GetFileAttributesW
WideCharToMultiByte
MultiByteToWideChar
GetExitCodeProcess
WriteProcessMemory
ReadProcessMemory
GetCurrentProcessId
OpenProcess
TerminateProcess
SetPriorityClass
SetLastError
GetEnvironmentVariableW
GetLocalTime
GetDateFormatW
GetTimeFormatW
SetErrorMode
GetDiskFreeSpaceW
SetVolumeLabelW
CreateFileW
DeviceIoControl
GetDriveTypeW
GetVolumeInformationW
CreateDirectoryW
ReadFile
WriteFile
GlobalSize
DeleteFileW
SetFileAttributesW
LocalFileTimeToFileTime
SetFileTime
GetSystemTime
GetComputerNameW
GetWindowsDirectoryW
GetTempPathW
GetFullPathNameW
GetShortPathNameW
FindFirstFileW
FreeLibrary
EnterCriticalSection
LeaveCriticalSection
VirtualProtect
QueryDosDeviceW
CompareStringW
RemoveDirectoryW
CopyFileW
GetCurrentProcess
FormatMessageW
GetPrivateProfileStringW
GetPrivateProfileSectionW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
WritePrivateProfileSectionW
SetEndOfFile
GetACP
GetFileType
SetFilePointerEx
GetFileSizeEx
SystemTimeToFileTime
FileTimeToSystemTime
GetFileSize
VirtualAllocEx
VirtualFreeEx
EnumResourceNamesW
LoadLibraryExW
IsValidCodePage
GetOEMCP
InterlockedDecrement
InterlockedIncrement
GetStartupInfoW
HeapSetInformation
GetCommandLineW
HeapQueryInformation
HeapSize
HeapFree
HeapReAlloc
ExitProcess
HeapAlloc
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStdHandle
HeapCreate
InitializeCriticalSectionAndSpinCount
LockResource
LoadResource
SizeofResource
FindResourceW
GetSystemTimeAsFileTime
MulDiv
GetModuleFileNameW
DeleteCriticalSection
GetCPInfo
GetVersionExW
GetLastError
CreateMutexW
CloseHandle
GetExitCodeThread
SetThreadPriority
CreateThread
lstrcmpiW
GetCurrentThreadId
GlobalUnlock
GlobalFree
GlobalAlloc
GlobalLock
GetModuleHandleW
GetProcAddress
GetCurrentDirectoryW
InitializeCriticalSection
SetCurrentDirectoryW
Sleep
GetTickCount
TlsAlloc
TlsGetValue
TlsSetValue
SetHandleCount
IsProcessorFeaturePresent
GetStringTypeW
LCMapStringW
RaiseException
RtlUnwind
GetConsoleCP
GetConsoleMode
FreeEnvironmentStringsW
GetEnvironmentStringsW
TlsFree
QueryPerformanceCounter
SetFilePointer
FlushFileBuffers
WriteConsoleW
SetStdHandle
GetProcessHeap
LoadLibraryW
VirtualQuery
USER32.dll GetMenuStringW
IsWindowEnabled
ExitWindowsEx
SetMenu
FlashWindow
MapWindowPoints
RedrawWindow
SetParent
UpdateWindow
GetMessagePos
GetClassLongW
DefDlgProcW
CallWindowProcW
CheckRadioButton
IntersectRect
PtInRect
CreateAcceleratorTableW
DestroyAcceleratorTable
AppendMenuW
SetMenuDefaultItem
RemoveMenu
SetMenuItemInfoW
IsMenu
CreateMenu
CreatePopupMenu
SetMenuInfo
DestroyMenu
TrackPopupMenuEx
CreateIconIndirect
GetDesktopWindow
CopyImage
LookupIconIdFromDirectoryEx
CreateIconFromResourceEx
GetWindow
BringWindowToTop
GetTopWindow
SetRect
GetIconInfo
SetWindowTextW
IsWindowVisible
CheckMenuItem
MessageBoxW
SetClipboardViewer
LoadAcceleratorsW
ReleaseDC
GetSubMenu
EnableMenuItem
GetMenu
RegisterClassExW
LoadCursorW
LoadImageW
ChangeClipboardChain
DestroyIcon
DestroyWindow
IsCharAlphaW
MapVirtualKeyW
DefWindowProcW
GetWindowTextW
mouse_event
WindowFromPoint
GetSystemMetrics
keybd_event
SetKeyboardState
GetKeyboardState
GetCursorPos
GetAsyncKeyState
AttachThreadInput
SendInput
UnregisterHotKey
RegisterHotKey
PostQuitMessage
SendMessageTimeoutW
UnhookWindowsHookEx
SetWindowsHookExW
PostThreadMessageW
IsCharUpperW
IsCharLowerW
IsCharAlphaNumericW
ToUnicodeEx
GetKeyboardLayout
CallNextHookEx
CharLowerW
OpenClipboard
GetClipboardData
GetClipboardFormatNameW
CloseClipboard
SetClipboardData
EmptyClipboard
PostMessageW
FindWindowW
EndDialog
IsWindow
GetMenuItemID
GetMenuItemCount
GetCursor
ClientToScreen
GetCaretPos
EnumClipboardFormats
MessageBeep
SetDlgItemTextW
GetDlgItem
SendDlgItemMessageW
DialogBoxParamW
GetDC
SetForegroundWindow
DispatchMessageW
TranslateMessage
ShowWindow
CountClipboardFormats
SetWindowLongW
ScreenToClient
IsDialogMessageW
SendMessageW
GetWindowLongW
GetKeyState
FillRect
DrawIconEx
GetSysColorBrush
GetSysColor
RegisterWindowMessageW
IsIconic
IsZoomed
EnumWindows
GetWindowTextLengthW
EnableWindow
InvalidateRect
SetWindowPos
SetWindowRgn
SetFocus
SetActiveWindow
EnumChildWindows
MoveWindow
GetQueueStatus
GetWindowRect
GetClientRect
SystemParametersInfoW
TranslateAcceleratorW
KillTimer
PeekMessageW
GetFocus
GetClassNameW
GetWindowThreadProcessId
GetForegroundWindow
GetMessageW
SetTimer
GetParent
GetDlgCtrlID
CharUpperW
IsClipboardFormatAvailable
AdjustWindowRectEx
VkKeyScanExW
DrawTextW
CreateWindowExW
GDI32.dll FillRgn
GetClipBox
SetBkMode
EnumFontFamiliesExW
CreateDIBSection
GdiFlush
ExcludeClipRect
SetTextColor
SetBkColor
GetPixel
BitBlt
CreateCompatibleBitmap
GetSystemPaletteEntries
GetDIBits
CreateCompatibleDC
CreatePolygonRgn
CreateRectRgn
CreateRoundRectRgn
CreateEllipticRgn
DeleteDC
GetObjectW
GetTextMetricsW
GetTextFaceW
SelectObject
GetStockObject
CreateDCW
CreateSolidBrush
GetDeviceCaps
GetClipRgn
DeleteObject
CreateFontW
COMDLG32.dll GetOpenFileNameW
CommDlgExtendedError
GetSaveFileNameW
ADVAPI32.dll RegDeleteKeyW
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
CloseServiceHandle
UnlockServiceDatabase
LockServiceDatabase
OpenSCManagerW
GetUserNameW
RegEnumKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegCloseKey
RegConnectRegistryW
RegDeleteValueW
SHELL32.dll DragQueryPoint
SHFileOperationW
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetDesktopFolder
SHGetMalloc
SHGetFolderPathW
ShellExecuteExW
Shell_NotifyIconW
DragFinish
DragQueryFileW
ExtractIconW
ole32.dll OleInitialize
OleUninitialize
CoInitialize
CoCreateInstance
CoUninitialize
CLSIDFromString
CoGetObject
StringFromGUID2
CreateStreamOnHGlobal
OLEAUT32.dll SafeArrayGetDim
GetActiveObject
OleLoadPicture
SafeArrayUnaccessData
SafeArrayAccessData
SafeArrayUnlock
VariantCopy
SafeArrayGetElemsize
SafeArrayPtrOfIndex
SafeArrayLock
SafeArrayDestroy
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayCopy
SysAllocString
VariantChangeType
VariantClear
SafeArrayCreate
SysFreeString
SysStringLen

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60927
MD5 e721224030833969127209aab1d61dc4
SHA1 2cc97d55f9340d69dcb082f34533e6f8d0cef7dd
SHA256 cb1f3e5a2c29d6929a85d212cf89067ecdfd43833efcdcffe9705d6ee1cbfdd9
SHA3 a6f007f705ffb45318b8d7a92c2cbdb0931e1d90f2a9b90d17053a7a9815931d

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12497
MD5 8675d1b5ea4c9c8f1116ebff5312ceb5
SHA1 8e164fee08da64eddeb3098d105b4165495ba337
SHA256 541c58f9305e5b06649fd44eb5d7f17c4bf21f1c49fb4cac3ec3c8c2f0def361
SHA3 44da55b5e06920fdfaae1dc604efb42c598197082775d1e40c3e8dbafc063d09

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90297
MD5 772b5f0a32be10cc43614cf0c2054a54
SHA1 b92ea702b2fd29094a5ffb6aa2f7baea9ada1836
SHA256 32ebcfbb0cc1bc2add9e0d6273ac6c7cb66cbf9d98474b32e2f07967423e6cd3
SHA3 5d375777d739a7c54a86e413b33058b32e135d4c323e65f33cc9c5eb0906e581

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.84157
MD5 1c93a14c5a485c11350ef568f5e423c1
SHA1 bead6553859c4ec6e647551a19b224dc2357fc5f
SHA256 ae6b56a4aabbeb5d22f508ed6d1522ba6e5b668d1ffb05e4d9cee348a14197cd
SHA3 5719b4dc9bcc5a323c95d760317d4a5b737343f709eee16eddf819e8054ee6dd

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3349
MD5 266626c8655c67b9530c361ca939f01d
SHA1 4f799d89f7255ef58628605cc0f37a3420925a3d
SHA256 1bfebd87e8f7129fe598c91a87ff03e7962b95af723ea024faf9549e6442aa84
SHA3 85b69f2f4e1bfa507c52634afc60ad29f41321a0a4526654693b1dd7a6f516d9

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46964
MD5 fbbd1dfd9481f55d0e9ebc890ce09c3c
SHA1 cbfd96b3e1c556af63424b3a153def765077b8fb
SHA256 5ef6e7b16676575434a274b3654dcc6c4934adcb5c86ee31939720568578d2c0
SHA3 108eb4ba2bc3e913cec2e0d5cd215901fb0f4ebffc7fbd7679673ea2c735a609

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60719
MD5 7a7fd531976bf5d5962ce6bd512ec4f9
SHA1 5d6dc5099fdac2d02ef7e225e392710810518a79
SHA256 028ea5589efb612bc2129a09b3e3ce73ab811de0344e9ef58a4b85af5fb3ca40
SHA3 2ffc02d1ad8fc89d9a4deb38df4ca7ccc6b486507f0a66967ead0547c292ae75

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60406
MD5 71ba081b94218e8364dd2e4e8b804c51
SHA1 63096c0a4dff3b067b6e619e5e6a38c5ed5cc943
SHA256 8a5ac6abb43180226052148a21c3b919701cfdf797b43b39ba2611d5230d3e80
SHA3 7908406b9e7ea05d6a597e10b9801003dab62e73a24157dae82aea95d9362170

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72735
MD5 4452d334b20a4a74f1c614d62c75d35c
SHA1 1c8aed9c27ab287ba8687bdd973c1bdc1fab02fc
SHA256 2c1bb9b12fb5684a5c1b89aca9e3870e658e12fc1c0e5bca453b18c93518862c
SHA3 5462052da40668ec7849fabe1a011a1287b06dc0eba1e12194c8ec554337b2d9

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.19142
MD5 83f6a1c8b60d451f6851d741522a4501
SHA1 5b237fb5cac5086ed9c4bf904c5afbdbb9f094f9
SHA256 4b7f70d81e67bec9132a9d008a81be3717e430f6422c07cc5e5edf6e10783cba
SHA3 d20d8555d489a977a0cc43274a2b8e386f8430f57685db0b093d4853585ff366

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.12002
MD5 c0990d426f48ebfd8f1e8483da3fd4ff
SHA1 3bb85ae8f1c21e190cd049958eea0d31334da620
SHA256 c549faca829178a841e8e9f4868c6ba8a967eb8f84441de53e54677efa70d0bc
SHA3 64e113d3ac40c5ba606afeb4b3970a8150f56c5b8d8e481293a79a7498ab8eac

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.1487
MD5 0daac2c090132999057977c8145efe0b
SHA1 21cebd7f2c3836976242714acd05ea13a4c4706d
SHA256 d2e72cf78e8c1ec70dfd35a1e3a5a870821feef9d76a674ba14cd047c4ec8bc6
SHA3 f0e1a1a616b34b88a0bebb2848815e8f409d94e55a0a8da8cc9d4b73c49920f2

13

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.67639
MD5 d71b7306acf232a20b51a1222ef1659f
SHA1 50e0c9ddabfb4415198cb3a8487d811e5fcb7637
SHA256 2bc02fc0c6b5c414ac2310c3ad9cb50e7d26ac1991973aa72b8750bcb018c847
SHA3 bc134de925cee2e92a3e2972ea01ab915f1cd8f1a488795fbd7412322b7cb20c

14

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75589
MD5 9e860c3ec8708c0e727f8069e3a5ff0c
SHA1 6ee56c59b4eeefa9359222d9c8b9fdd1c5fb03da
SHA256 ba45cb4d52913c9781cc12367dcdacc8fb281333043f864961e6cd90aeac8460
SHA3 7cc684b90dfc54b1d803f03997db7d2cc77594b254a4acd847c1bcb370dcacea

15

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.49005
MD5 fc7a29a5c1e0424c00ead6538eadf8fa
SHA1 d35d12b072431cb7e28b4ea4989a0c7371db87be
SHA256 0966e1d1b878f2dc95a65150c32060c7570e2cf44d9b44432182a101713b377f
SHA3 1e64514cc9f73f6fb90f6b9930c46fe9af75fb9a4b0f36d2197c5006239ccede

16

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.31553
MD5 48860b8f7f3dd3b8c0297aded5d9986e
SHA1 6c792f70c451cb89b961709c6bf0451912371eef
SHA256 7fdc3f2c683c181cd5dab900be37b4090947bf918646c42a53af8220ac9b6518
SHA3 a1bf334006283136d0ea1eb2559b77f2e3c7e4ce0c2e3e9807ae0c3d084291a3

211

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37124
MD5 2cfd05e0e8346abd1be8b6933d0684ad
SHA1 898c4f11bceec1fb399cc9e0f305e09b9a2df803
SHA256 c0306fb5f7462e74df09e5e0627c01a238f291bbdc89c24c0ea1f46e7341ab5a
SHA3 8f3778cee4660e3c85805aa4bce2602547080ca7cfc425029bce1441a5af9a1f

205

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82326
MD5 fec66af562e184a3acd4ada5b1603016
SHA1 fe5cd5d19cfc12992d23a18db8edaf1c06f610c2
SHA256 0b54b12fc56db7f7a5a366544081e75cfd312d6db7dd0b298b8088ad2f748908
SHA3 36780025f039a7044aac6d427f489314299b398567b3b737bb5f229278d74563

212

Type RT_ACCELERATOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96144
MD5 7fb94687aa0fe2b18873dba5ac59ab1d
SHA1 e19e8d6b0e33da063de27c83fa0bab4058513332
SHA256 86286a59831ad1d0d84eb411ae6fa236b21bca5d3ebfc93a59cf4b6bf1d466d0
SHA3 33011788d35d1127a1ee6fbdb975c0d4ef6b36d3896e0d27d3f75f0ff68e3aec

>AHK WITH ICON<

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7e4f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.30175
MD5 74c8aa9cc6b761db7fc1afa4ecb85a28
SHA1 10387f80dc108fb140344ab658c773c0e1a48982
SHA256 c2d62f9b8b501e66409ff9637c09f5ea4e1095b4ec5554bb8f27b1779729f0b0
SHA3 84060d87c036efb6aadabca3118245fc5e95d4dd51bb2e16a535c7f661989319

159

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.57561
Detected Filetype Icon file
MD5 260596c67b307accdc2c25cf9b9fa15b
SHA1 997a56efe4d43b65fd37fd82f409fb0d2a45a505
SHA256 438c70387ce8f05257770aaf392193c31a40085228928f20bd4813db6319111b
SHA3 4224faee2e6b9b640ae51e649280bfad44082c0cb0d3e8bd9e3305bb9dc3301c

160

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70265
Detected Filetype Icon file
MD5 ad692dfb9d3a017c6904883edaebe744
SHA1 b17ba1985021d40e61437d2f03cad0b432b3d969
SHA256 878e2e93a4e08a0e754bec870f4ea4012f977c7fd8922271ff740b770e570ed0
SHA3 9a337373ef41f4193d51c51887238deed35d4e913c1e028bec888873f72aa2d2

206

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.9815
Detected Filetype Icon file
MD5 40c1414025bcc34e7ba97fd22bc9f5a4
SHA1 b53a6a13513b5205cef6fc6d7556ad80d8b62173
SHA256 d6659139f55adad2497df8d1a11fcd68324a00ccdadbc133ddd49fb79e9ccc1c
SHA3 88c00f73975983695c16e34c6a1750573250999152f5399a198b799e76349720

207

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 9b2193af49fdb53892356f594e9f18b9
SHA1 448aa28721dd65475b37505de8140d88d5aa1501
SHA256 9b8ca9c6a330d0d17d1108ab5442d60ea574817a65caa860cceb24313cc4f0e4
SHA3 46527c3333b02958fd025cfdaa12d481f8505aa77c1cd0b5f15348e870530116

208

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 5f51cbb6145d3a4c36cffa3b028b0199
SHA1 b2bbd2afcfa1c44725bf90df8948792d3bc7fb97
SHA256 fbb52a958caa73dce023ce27649d69f8886e86b5706e767153c41dde7b5eebf9
SHA3 93f253b05e0e42147b5a9000d421c3e105df42f9fafae5147c4e9a09958e3f79

228

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.02322
Detected Filetype Icon file
MD5 cb6224423116bd21b2417c0c419f2a7b
SHA1 93f63a175f19235b1fdf8cdf724028b3099db026
SHA256 2ef8f3005787231e5b1b5baaa4e31980f4f0eb0eb40d74513cd03b5f684f2e8f
SHA3 3a502b5c5b58d819aecb6d5623cdf726f9dd0ddcb729ac03b2425a636b027f8a

229

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.02322
Detected Filetype Icon file
MD5 bf79d4a6fab4b2afb8fd89db4e6c11d2
SHA1 e788a77cf462ddfaaf8e36fe47b57514839d3396
SHA256 e03ca89042dd41574baa264f8b55be15286e9c1460a2c7e7b125c87c81e2fb65
SHA3 fe836edf70892eface97ba91a8d000758bd15ca5e99830f58b1bd1f7b319a585

230

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 d80241770c930920add7e76f0cefd2f9
SHA1 c354ef4aec39043879237b1bf3b63122556a6b29
SHA256 ba55be7ae64195441cf269f9c0105a859a748a524a732944b0e439e74580a506
SHA3 810b398f300491a2f2dfbf3567d286eec8dff11ddc8ad320e080d0644c2b3468

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x1fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2231
MD5 bacdc846a2a426750d572e23186f39ef
SHA1 befcbcd641f7d35c9fdbef82a32829b16bc478b2
SHA256 6ca9fdf3c76ac6e428fbfc3a6dbebd038e6d87e29a4ff7ff0d5db793f92921da
SHA3 b3f61b8336e9925523da96bfdeca87507ad51cac2364bcc1439e72a8c88391f5

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x292
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01079
MD5 edebbda6dc2d1a08464b0b2e606a1116
SHA1 0748fd88f79a084033c6717fc314c68fbec90e7e
SHA256 9477545692300e144053d82eb9714d554aa74c295f98792a398b0cb4aad63ba4
SHA3 d1d2e1630641f4d6a718a3f1a42d4b09b949502fbb65ff1b1543c57f019a9884

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.9.4
ProductVersion 1.1.9.4
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 1.1.09.04
ProductVersion (#2) 1.1.09.04
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x80c965d3
Unmarked objects 0
C++ objects (VS2010 SP1 build 40219) 51
C objects (VS2010 SP1 build 40219) 139
C objects (VS2008 SP1 build 30729) 7
Imports (VS2008 SP1 build 30729) 27
Total imports 428
ASM objects (VS2010 SP1 build 40219) 29
175 (VS2010 SP1 build 40219) 42
Resource objects (VS2010 SP1 build 40219) 1
Linker (VS2010 SP1 build 40219) 1

Errors

Leave a comment

No comments yet.