| Architecture |
IMAGE_FILE_MACHINE_I386
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
1992-Jun-19 22:22:17
|
| Detected languages |
English - United States
|
| Comments |
This installation was built with Inno Setup.
|
| CompanyName |
|
| FileDescription |
Specair Setup
|
| FileVersion |
|
| LegalCopyright |
|
| ProductName |
Specair
|
| ProductVersion |
3.0
|
| Malicious |
The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
- LoadLibraryA
- GetProcAddress
Can access the registry:
- RegQueryValueExA
- RegOpenKeyExA
- RegCloseKey
Possibly launches other programs:
Memory manipulation functions often used by packers:
- VirtualAlloc
- VirtualProtect
Functions related to the privilege level:
- OpenProcessToken
- AdjustTokenPrivileges
Can shut the system down or lock the screen:
|
| Suspicious |
The file contains overlay data. |
5205335 bytes of data starting at offset 0x1b400.
The overlay data has an entropy of 7.99997 and is possibly compressed or encrypted.
Overlay data amounts for 97.9008% of the executable.
|
| Safe |
VirusTotal score: 0/74 (Scanned on 2024-07-03 12:36:43) |
All the AVs think this file is safe.
|
| MD5 |
3d7cc791032611cb60a8ff655ef584e1
|
| SHA1 |
d75945fb6dc7da38d9075d34d582d3ceb74c0de6
|
| SHA256 |
6e63a4b605cb64bd068baf49e206ab5ae76840c04db5f1632a758388efb76e3c
|
| SHA3 |
7bc1400ac7e05d46c339fc2b838d479f7ce7ae60d7e536aafd92f6c74f87cf0d
|
| SSDeep |
98304:wM4IgLlCJyU4DJ9Yk9K1SNXAreHY1+eBM74tarMSUMD17s1THJ6Vz86flY+r:2I9J4rY+NfO+oq4t+MS317kTHJzEY+r
|
| Imports Hash |
4fb639b17a439bf0efa713bd4c6e715b
|
| e_magic |
MZ
|
| e_cblp |
0x50
|
| e_cp |
0x2
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0xf
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0x1a
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x100
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections |
8
|
| TimeDateStamp |
1992-Jun-19 22:22:17
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xe0
|
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic |
PE32
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0x9400
|
| SizeOfInitializedData |
0x11c00
|
| SizeOfUninitializedData |
0
|
| AddressOfEntryPoint |
0x00009C40 (Section: CODE)
|
| BaseOfCode |
0x1000
|
| BaseOfData |
0xb000
|
| ImageBase |
0x400000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
1.0
|
| ImageVersion |
6.0
|
| SubsystemVersion |
4.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x22000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve |
0x100000
|
| SizeofStackCommit |
0x4000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
0d7ac17dafcd52a9b3ea353c32256c1d
|
| SHA1 |
110175bfa6f09a21b5d185101b44af9027df5f69
|
| SHA256 |
ff523a52cbb5921c66593bd77e964b697cc2d5295030ddba0fbe7c0c964f5f0e
|
| SHA3 |
822ac75a1622fada7c5b454563815abf425be1847aab4d8cad3b33bd618a3402
|
| VirtualSize |
0x9364
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x9400
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.56223
|
| MD5 |
e8f82382eefca31b62f6a8c8a52ff421
|
| SHA1 |
fd8679cc636fa7a085e0d3d3d7d9428e56264902
|
| SHA256 |
38bb1f54de5eba80f167a0b06fb80f1d1904bd6aacc97588cf108e858785c862
|
| SHA3 |
e0ec98d1f8f43f12fab9589b941d274c7781009c7cb7f7a6b227bc1d65435190
|
| VirtualSize |
0x24c
|
| VirtualAddress |
0xb000
|
| SizeOfRawData |
0x400
|
| PointerToRawData |
0x9800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
2.75348
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0xe4c
|
| VirtualAddress |
0xc000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0x9c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
bb5485bf968b970e5ea81292af2acdba
|
| SHA1 |
40a39d9e8c8cecd5356ab96745d82d2ebfe17cfb
|
| SHA256 |
d9ea6e80cc1edfdffa8d534a8c61448b19b74d683845b94ad6d9a543e5ceb8cf
|
| SHA3 |
09274dc071547ce3dc33528de99c9ad5a9eb119600e5a61b3127f74cde6dcfbf
|
| VirtualSize |
0x950
|
| VirtualAddress |
0xd000
|
| SizeOfRawData |
0xa00
|
| PointerToRawData |
0x9c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
4.43073
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x8
|
| VirtualAddress |
0xe000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0xa600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
9ba824905bf9c7922b6fc87a38b74366
|
| SHA1 |
f43ee83e6afa1c343ff6db68e13efde43471cbb6
|
| SHA256 |
ad44157821ba24c07dd44f66940dd75adee9d6919a0577c5a75aa502637dddaa
|
| SHA3 |
370eba5499bce03a18d462f5b9e6ee4598126f2a2243cc5fa1590c7c7245c5d7
|
| VirtualSize |
0x18
|
| VirtualAddress |
0xf000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0xa600
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| Entropy |
0.204488
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x8b4
|
| VirtualAddress |
0x10000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| MD5 |
f927b5d3c752529bcdc1f98b41372762
|
| SHA1 |
3dd79dc1024c94ef00765b79f6be1a8826c7a296
|
| SHA256 |
5c1f2eefb57b1d5c7865b6cf4e0d5bf4f5d5de95e0bc1758af06a2a5e620b928
|
| SHA3 |
8efef0be52c564f3fb3cc993383771f978be5dd9c900f5335990797d1b67a231
|
| VirtualSize |
0x10b04
|
| VirtualAddress |
0x11000
|
| SizeOfRawData |
0x10c00
|
| PointerToRawData |
0xa800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
|
| Entropy |
2.68797
|
| kernel32.dll |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
| user32.dll |
MessageBoxA
|
| oleaut32.dll |
VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
|
| advapi32.dll |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
| kernel32.dll (#2) |
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
|
| user32.dll (#2) |
MessageBoxA
|
| comctl32.dll |
InitCommonControls
|
| advapi32.dll (#2) |
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x128
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.3628
|
| MD5 |
d277a82ae86b8eb2ced9144ffe59463a
|
| SHA1 |
17115508c18203ad2788a70e21eaf2bf92e460d8
|
| SHA256 |
ca277162deb3f08ca3b14c176b97ef742bf31389976c9c98df72dab1a4785f38
|
| SHA3 |
d3315845c26e69f0afe72b5cd4191a90d9b794041a1ec069eba4fe101690c2d3
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x368
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
4.08255
|
| MD5 |
de768755d0d26dc5466067a5f114e797
|
| SHA1 |
0e060ca9517922de66ea362a17660f7b0125ba91
|
| SHA256 |
1ea10068ac68aa0f1ccbb15810964639c5d53a4905b24ece363699ab240bb2be
|
| SHA3 |
a54ca83e69923e957a8b4ec60278e3dd77612d378baa1286d9349ca0940da7ef
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x468
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
4.45685
|
| MD5 |
d70a76aafa08bd4ad6c9a312ddd1425b
|
| SHA1 |
8763f91c75358147a780f56e5f975c814097e8f6
|
| SHA256 |
6b919efa4bb3d341893a4a997c6ffdea29c1e5880d42135965383dcdc2b3a073
|
| SHA3 |
dcb07bf93454a79adcfba7deccd1a476cdd90b44fd3b6677b672b37ad48fb6f6
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2e8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.12705
|
| MD5 |
bb2ed69f8850851599dfee84d1e2f574
|
| SHA1 |
3a6b4563d44c5f007dd4d91db5ac2954a40e7696
|
| SHA256 |
64b00883231c9504e5de84e8b34e97ff7e5a1dd67450fc4bbd4be17a2e8ec651
|
| SHA3 |
4977bb726754b76b5b430389dfe6b13ded9d8020b8b2de89c2575b41aa078c6c
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xca8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.89157
|
| MD5 |
e7d1543aa1a69a190bcee0eee1aa4985
|
| SHA1 |
1da544f391ea61fd1bec38c8241f9afc59d59726
|
| SHA256 |
86683da2e2564722d465efa840927c9a63f1feccaa445919513a55e0304440a6
|
| SHA3 |
afc2423ec18a5a6c2ee991fc1fe63b04f8c53fd1817647695106cb8fb230d269
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x10a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.12959
|
| MD5 |
06c31feb5c701a8406c6ad8c8b280b51
|
| SHA1 |
787d9c7972bcf3f4607c45385bcb5aef30e94df6
|
| SHA256 |
a66e9f32b01d4c12ada4fdcf93ed3399c8768bed30108f83ecd1b5f7e4fcb82e
|
| SHA3 |
7d8a93c9a6fcba9750b39fa1c298bb9b16f5ea2d47e879b5161711de5d1998d3
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x668
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.35214
|
| MD5 |
675204435ea16f973155780a25d7a639
|
| SHA1 |
f5e5ba13c3808185208d230c94dc6682fa7f662d
|
| SHA256 |
a2bf32bc1ac9d048c913f75a13fcb78b6673050e0f1b58852d014fddfe88403d
|
| SHA3 |
e62b6781fa31b378ac14af8e1041a76a02016d14b67a76f7cf445e05ede6a28d
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x1ca8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
1.97038
|
| MD5 |
1dfa424c9575ce5e598343089e21eef3
|
| SHA1 |
b91f452834ba73a999d79a09076357ab0be140c3
|
| SHA256 |
be1b2f32d6b4cb33571e6bd010e1d6114bd05ce13d923c4405baf3601614ea73
|
| SHA3 |
dc35b3402da0a38acb1aebb84aa94234d68738e5a88e87104f3518504431edd4
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x25a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.08203
|
| MD5 |
cc54332b7932487429aff8240735ab46
|
| SHA1 |
be804c142d88d2e54c2198ed7a0f2707438deb24
|
| SHA256 |
e2704760b46a5a8f365294f50fc1fcaca44a6a5dc8a6cf33c3d2b2f717f6e6f1
|
| SHA3 |
10f9a8b72039ec10e586f6462732ee8cdcb4f2143db6c4867228a549471ef1a1
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xa68
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
1.91368
|
| MD5 |
e5b46b80fa0a75866f459d6d39146d99
|
| SHA1 |
688f2dba2a03d0bf8f5660dcd8e5752be6d1c9ab
|
| SHA256 |
aae894e13ac5c8c8cd341ff4ffb2d0358fa80524129dcd471c893882d1f6c313
|
| SHA3 |
cbdd645aac14b8b435ebfb3aa0aa9bec3263d541656c32bd0896e1edc984ab6a
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x3228
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
1.40214
|
| MD5 |
865670c57ba7a1d0d5d754bec91d2c81
|
| SHA1 |
a6b374a0b73e2ffb53a98aa625400d01db5374cb
|
| SHA256 |
95006945e93082fe5673b02de17d208e478978b6957a467c072068a2fac44659
|
| SHA3 |
ce814be2b1199359a1d71981059b2e8d69e58c156340e9a7722b4119099f4c88
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4228
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
1.44064
|
| MD5 |
6369e393aebb7ffe454df86239b7b399
|
| SHA1 |
9ab79e6c5d51677e0de4cd9e88781f65a9b4a0b6
|
| SHA256 |
25238dd3418edad6917339c5d6770e6193dec93917aead468dbc88c4630aa38a
|
| SHA3 |
74d771c5c18e027df3c8cd2d926b60906ba5ef533464a4dfe9f83b44f9603d11
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2f2
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.21823
|
| MD5 |
bbf4b644f9dd284b35eb31573d0df2f7
|
| SHA1 |
4f9885ae629e83464e313af5254ef86f01accd0b
|
| SHA256 |
2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
|
| SHA3 |
ebed2e4a929600c1460761d462143feb092840986b31c9748d3aeb8174d4205e
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x30c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.31515
|
| MD5 |
ac2a0551cb90f91d779ee8622682dfb1
|
| SHA1 |
ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
|
| SHA256 |
840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
|
| SHA3 |
58a85f5c53df73aa79e5f5a36aa151ca0d9da4d450ebc2975a3ee827b46342a5
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2ce
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.25024
|
| MD5 |
c99b474c52df3049dfb38b5308f2827d
|
| SHA1 |
7375e693629ce6bbd1a0419621d094bcd2c67bb7
|
| SHA256 |
26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
|
| SHA3 |
c6013febd14dd876e3b81111ec17dd2724dbf4147b0ad7be9d03259bcb59fef3
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x68
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.86149
|
| MD5 |
aec4e28ea9db1361160cde225d158108
|
| SHA1 |
249013a10cde021c713ba2dc8912f9e05be35735
|
| SHA256 |
d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
|
| SHA3 |
a067c4d88d719ed8d568951acb776bd798b691a8b153f8d94ba0574ede1fbf4c
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xb4
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.20731
|
| MD5 |
c76a8843204c0572bca24ada35abe8c7
|
| SHA1 |
066052030d0a32310da8cb5a51d0590960a65f32
|
| SHA256 |
00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
|
| SHA3 |
07523cf88b3803ea41acfeb3c9c0c4b5b4b9fb6f9a3232802491d8de1b6c9166
|
| Type |
RT_STRING
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xae
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.04592
|
| MD5 |
4bd4f3f6d918ba49d8800ad83d277a86
|
| SHA1 |
1f5e4c73965fea1d1f729efbe7568dcd081a2168
|
| SHA256 |
34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
|
| SHA3 |
2d01c56a5bf0b390addf4fb5b6ae02f9a64bd03ffd300d3763615bbb8ec911fe
|
| Type |
RT_RCDATA
|
| Language |
UNKNOWN
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
4.56808
|
| MD5 |
d8b0114d137f0c55d6f2695462d4eb2b
|
| SHA1 |
7c43312e4965184aed0d5296fbc941a662c54bed
|
| SHA256 |
7f0d3f59b3a17bd94c354ef3875c84b6a5f4578e7285dbed1fe32bdb184e5926
|
| SHA3 |
abd16058ded84c95ab9671b026a1ce4e3df44ea855c0a79fd2d7e51da0dba16f
|
| Type |
RT_GROUP_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0xae
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.93706
|
| Detected Filetype |
Icon file
|
| MD5 |
38864da26302591a3d5fe2ae85b94d9f
|
| SHA1 |
cc1e6e78d732a367c22288abd3ca692c3c59d448
|
| SHA256 |
6d0a1ee25d328a3304688b4dd595fa6d9b04ee582f7ce1396cf6c3367b355d68
|
| SHA3 |
6887578a54a5dd6892fbf49a2c8dd811bafe6e7b5aa6bad3c42d5e1e7ff715b1
|
| Type |
RT_VERSION
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4b8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.51519
|
| MD5 |
778bf7543d6c56e0ef7b562e58d8389c
|
| SHA1 |
4f0a1d2d6cbebb3c59bf3fc37f07501d506c136a
|
| SHA256 |
30b732c423764259cc7895ef7ef1a18ad175ec15ba5e1eed49f7db3b5433f013
|
| SHA3 |
b960d459b80bc6ec60af1601a03e3e0b0b1d1b2dde4f465ada2b93dac2c4a8d5
|
| Type |
RT_MANIFEST
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x560
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.05007
|
| MD5 |
8d7accca43bc3864983dbbb9af490005
|
| SHA1 |
07ae72350bcbfedb5015a78efd74fcfd3bab11ac
|
| SHA256 |
ec233469005d39f4f2673be991a0415318631a59c5976c35d4dd22db45226fd0
|
| SHA3 |
d340127cbdd815e5c2dd4b44e8755c28512ad5e969b757cfcec6612b00e9d186
|
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%s' is not a valid date |
| '%s' is not a valid time |
| '%s' is not a valid date and time |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Invalid filename |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Invalid variant type conversion |
| Invalid variant operation |
| Variant method calls not supported |
| Read |
| Write |
| Format result longer than 4096 characters |
| Format string too long |
| Error creating variant array |
| Variant is not an array |
| Variant array index out of bounds |
| External exception %x |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Signature |
0xfeef04bd
|
| StructVersion |
0x10000
|
| FileVersion |
0.0.0.0
|
| ProductVersion |
0.0.0.0
|
| FileFlags |
(EMPTY)
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language |
UNKNOWN
|
| Comments |
This installation was built with Inno Setup.
|
| CompanyName |
|
| FileDescription |
Specair Setup
|
| FileVersion (#2) |
|
| LegalCopyright |
|
| ProductName |
Specair
|
| ProductVersion (#2) |
3.0
|
| Resource LangID |
English - United States
|
| StartAddressOfRawData |
0x40e000
|
| EndAddressOfRawData |
0x40e008
|
| AddressOfIndex |
0x40c3d0
|
| AddressOfCallbacks |
0x40f010
|
| SizeOfZeroFill |
0
|
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
(EMPTY)
|
[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted!
[!] Error: Could not reach the requested directory (offset=0x0).
[*] Warning: Section BSS has a size of 0!
[*] Warning: Section .tls has a size of 0!
[*] Warning: Section .reloc has a size of 0!