b52ba968ed6d340119067709d08ed28051e91580f7d7586142e84269a9d812fa

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Mar-12 14:56:52
Detected languages English - United States
Polish - Poland
CompanyName GOG Sp. z o.o.
FileDescription GWENT: The Witcher Card Game
FileVersion 2.0.0.2
InternalName GOG Galaxy - Gwent Installer.exe
LegalCopyright (C) GOG Sp. z o.o. 2020
InternalName (#2) GOG Galaxy - Gwent Installer.exe
ProductName GWENT: The Witcher Card Game
ProductVersion 2.0.0.2

Plugin Output

Suspicious PEiD Signature: UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net
UPX Protector v1.0x (2)
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
The PE only has 9 import(s).
The PE's resources are bigger than it is.
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegCloseKey
Has Internet access capabilities:
  • URLDownloadToFileW
Suspicious The PE is possibly a dropper. Resource 133 is possibly compressed or encrypted.
Resource 134 is possibly compressed or encrypted.
Resource 135 is possibly compressed or encrypted.
Resource 136 is possibly compressed or encrypted.
Resource 137 is possibly compressed or encrypted.
Resource 138 is possibly compressed or encrypted.
Resource 139 is possibly compressed or encrypted.
Resource 140 is possibly compressed or encrypted.
Resource 141 is possibly compressed or encrypted.
Resource 142 is possibly compressed or encrypted.
Resource 143 is possibly compressed or encrypted.
Resource 144 is possibly compressed or encrypted.
Resource 145 is possibly compressed or encrypted.
Resources amount for 108.226% of the executable.
Info The PE is digitally signed. Signer: GOG Sp. z o.o.
Issuer: DigiCert SHA2 Assured ID Code Signing CA
Malicious VirusTotal score: 5/71 (Scanned on 2026-10-02 16:52:01) Antiy-AVL: GrayWare/Win32.Wacapew
Bkav: W32.Malware.CC18CA38
Jiangmin: Trojan.Generic.gwsjx
Rising: Trojan.Ymacco!8.11BE1 (RDMK:cmRtazqIIgWgCsT2CU+7fQHb0PnN)
VBA32: Trojan.Wacatac

Hashes

MD5 1477ba22877c49b5bb88d1a6d2790e5d 🔍
SHA1 a6a1402745413734885552785e19ea9f43fb409a 🔍
SHA256 b52ba968ed6d340119067709d08ed28051e91580f7d7586142e84269a9d812fa 🔍
SHA3 46e9c0392e03471a414b2f949a06e49925b7bd3d9e18c51c1f3ff75ef2b58433 🔍
SSDeep 12288:IPzVZu2r23JTLKgZOlTdytzWIWcW98rriAHl2HX00WfQvWm5Ac/iCbrfjI/9w4R:QR2RHqcmsiAgfWyWsAYLbrfM/tmq 🔍
Imports Hash 0b5d23895837448a329cb1b4dc10916a 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2020-Mar-12 14:56:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x93000
SizeOfInitializedData 0x84000
SizeOfUninitializedData 0x14b000
AddressOfEntryPoint 0x001DE410 (Section: UPX1)
BaseOfCode 0x14c000
BaseOfData 0x1df000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x263000
SizeOfHeaders 0x1000
Checksum 0x1184c2
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x14b000
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

UPX1

MD5 daea568462b3c1bd5f62cd5e0e88a3f4 🔍
SHA1 786073b864efa9a2014a044d2949b2d45e5208a2 🔍
SHA256 f842c1298eb53783f758ac119cef33c5cdb4e6da106022cdcf56b6e0d2b94c55 🔍
SHA3 393add067d243a0f9b9b9561cd9d4f08a25d5f7238402bd6b9ef7af6273bd4ea 🔍
VirtualSize 0x93000
VirtualAddress 0x14c000
SizeOfRawData 0x92800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.90766

.rsrc

MD5 7710ee01b9e90a2c0dffb206ff3aa6e0 🔍
SHA1 40f560e97e48c99e336a3070ba276d16998dfc55 🔍
SHA256 0ae227b9a7308113c7168fa06278ab70869fab108f96e33ac793908a56259c5e 🔍
SHA3 5761b7c7cdf5a636b7b59ac11ce69283e68edda2f898c2dd4e87e3ffb83c3c0a 🔍
VirtualSize 0x84000
VirtualAddress 0x1df000
SizeOfRawData 0x83600
PointerToRawData 0x92c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.36262

Imports

ADVAPI32.dll RegCloseKey
KERNEL32.DLL LoadLibraryA
ExitProcess
GetProcAddress
VirtualProtect
SHELL32.dll ShellExecuteExW
SHLWAPI.dll PathFileExistsW
urlmon.dll URLDownloadToFileW
USER32.dll MessageBoxW

Delayed Imports

1

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27283
MD5 cc0722107b053065140bba616dcc7032 🔍
SHA1 7fb098b51ef0c6f28e7baf6f301b8ada6b4029b3 🔍
SHA256 884bbc144c5920d6b732af5d416e46a71a193df0a720d769594803d7aefc5c0e 🔍
SHA3 6f09e096e6b42d4b51e5f905889994ffa9cc00e757919b383b4aa00931e85c42 🔍

2

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.48179
MD5 9ddb39b09a3413dbad3f1ab6ad152917 🔍
SHA1 158f8b9c07f957344f8738c358cf51cc5f725e25 🔍
SHA256 4880142af92f7e5b249a715e8523f7523f104223bc1e2973aaf7184767fbfe64 🔍
SHA3 2156d20e3d2669d7ae87cd75d72465695c2f2c23903e25ec8283bf3690e6a857 🔍

3

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.63495
MD5 658beb37884ad692c78f82b92b87d987 🔍
SHA1 b09c2e3c110899976b71ad6dc9d74e8d4b6426a7 🔍
SHA256 9c5bef0d24227a9c28ac628a4f25ecc4b8e586f7f2620218be0174a49a916643 🔍
SHA3 bd1f9b20dd4d4720256bdbe8114bffa22664edbf81d46abb0162d2c958c463f8 🔍

4

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0xcd8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.67298
MD5 9f29450c19b1e4935d8275d6a80501fd 🔍
SHA1 856a4536ff46bc624bc8de2a57e8d469a4035647 🔍
SHA256 436db1945f4fa6c7613f999521dca2c47a3780bf2b0d7d4b9e5f98179aa8a3f8 🔍
SHA3 435b465622e0074075b299d55476d8e48dbb73326498400d8d83d3c98c076f55 🔍

5

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.01619
MD5 db35688208938606e60fd4a543fca3f4 🔍
SHA1 71a0ed9507de36eec3fc5809f47773a9a4794104 🔍
SHA256 8053c407a4abe4beb0204349828b3b93d0121be30b7e5cefdd583a457a9da813 🔍
SHA3 32e42a0f917e44069e67d0e230139d7e027fc3eaa95667624d848a703b7b0186 🔍

6

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.851
MD5 ca3c95b308d575dff3be604b137f2679 🔍
SHA1 fff91dd5714601625aab23b0d962ecc3d6d9059b 🔍
SHA256 c91d6d122781c289d96dcc6d3ffa1484675c8abbbc4449992f8bdcc3797be147 🔍
SHA3 b7f291f97f9c6416170ae49335f324503bd595838a6b23d1b17308c3f6e2bf82 🔍

7

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.73175
MD5 68835e46e6f3d7845aed74d1cae54a99 🔍
SHA1 f7edf525e7973dfd112d2f233a7b99f6a9d08063 🔍
SHA256 abeb7d04765a91df5af2165b44df1147d2f46b2118d64d4ea056bfc0e9675a83 🔍
SHA3 a3a7d7a681070b960705536cf22bb4bf941bd5dc13ea3587f832ef991793964c 🔍

8

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x32e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91127
MD5 a4e1ea06ae7cc6df5ea209d5881c1cd0 🔍
SHA1 b6c82477f76d30e6b9f70eb55182a6f8a6520f73 🔍
SHA256 914c3f3d98b95d097f87ea3bc5891495176f62e6037d9e9bb031c81cb3607097 🔍
SHA3 3d5a33c2f833c2623e5e233914603d342198c9319bc797b27181f1e43a6dc9e5 🔍

9

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.68541
MD5 831d538666e09258ca5f0d3d0ae9a0af 🔍
SHA1 2fa34a1abfb5b02eb0f36e3031c12b4402783d3f 🔍
SHA256 1ef05da398a2592fe5a766400581c4b5aaa86b7b1f08ed02eff0508d7577dccc 🔍
SHA3 6d7b5b6c21d10b425f59773a1d6351dc6d0dddaf7fd03d3d3bbec76396ee66ce 🔍

10

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.76709
MD5 a697511d8b2bd4c55efab1e06493145f 🔍
SHA1 5a30361b95ee1134009b6388476e0ebda2f2dd7b 🔍
SHA256 e310bf27f329bdef1b082aa6bcb95ced73d9dcb7251a8935878846a34745e6cc 🔍
SHA3 e36a68cea298b491cfbf039d760ff2571f1d7b8827d59ec6492ccc551c77fe28 🔍

11

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x67e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72671
MD5 93ffbfcd6a3a64acd22803653f086b4b 🔍
SHA1 91d5aec9fde7df5dae56012e4101b6bab64d2d26 🔍
SHA256 97e016c05347e6d1e90d5615b7083dd1674483485d7b45fdb9ff3c3ce55a1d8a 🔍
SHA3 ab49fbe36b138ae35110075488db96852f6b16d0347e089f9cbc6f93e8e1206f 🔍

12

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.65438
MD5 d695835d2c82d614e29e40e6b6089cf5 🔍
SHA1 1cf90a5d17a3c81d9a32df38de16a194378bb25f 🔍
SHA256 3d459aaa36fc897d38e7a4c06ae83eaee252be946c60a639e57e366995f12dd1 🔍
SHA3 ceb4352d397c49236dd6433590c7c9cd716f42e69882e8128074fb535e6d153f 🔍

13

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0xcb28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56946
MD5 2a727a3ee7022c024e1f3f9f756d886e 🔍
SHA1 925e2b0ef23bf26ee948163bdbc060b6800f178b 🔍
SHA256 238f4672c105a57640ffa4c229f4acfbe3fc4c71ef2c3953e65e03a75dfc9512 🔍
SHA3 60b09b6b1aed4e26058eabc694847eb16c007531cba50887a43e805a623c8612 🔍

14

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.46888
MD5 406ec55a507bcc4fe727f0f745b71abc 🔍
SHA1 659a478a23227534e828117a0d4fa21c7ea23181 🔍
SHA256 c142e290bb0e592ef0c1e546edfdf3ea080642f67fdff986188bcc08b8f71c44 🔍
SHA3 107286af2722a53b5a899cd660a85d5c510f09a6c1eb12ae021b387e24356431 🔍

15

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x14f68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.57152
MD5 b2c418b7a37271ebecd6f1454f3ae687 🔍
SHA1 bb656b128b2e35bd21ccd790bcf14ed43246080f 🔍
SHA256 383520200181174cd665ab9dabed148e34e6307fd1f418dfb4b8ab6b56c4f571 🔍
SHA3 4fde0fb02232474a8302f33b802b4b171185a2d28de0565832a96dbdb04219c6 🔍

16

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x19ca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.60034
MD5 776e4a04cbe14c89b0d17c5366431095 🔍
SHA1 a586abebfc61142f8d312192927af85386eafdac 🔍
SHA256 c46ac64a0eb37edb744cf99796d241c538468ed0d4d392c5370e9d46ee5b7f8a 🔍
SHA3 9825a2d910d04eefb1fd607b1ec2ff0a3997e9f46fec8be649be7b0f90c68f2d 🔍

17

Type RT_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x129e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98988
Detected Filetype PNG graphic file
MD5 9a7f63789f2a90041f6a88d31d1b27ee 🔍
SHA1 b777c156e68c68842b2d7a6e3364ded5d9da7366 🔍
SHA256 a4fb137cc88a4094b0bae3eee7345e67106e3f4537f714dd0a4302a7685fe77e 🔍
SHA3 fee51e79e1d85a01f28d6bd9c6e9c18fd935365ed64e8700127370ac362d8f1f 🔍

109

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍

IDD_ABOUTBOX

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x168
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍

7 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x74
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍

109 (#2)

Type RT_ACCELERATOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍

129

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x97c48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍

133

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x6694
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.83728
MD5 cdad98606a447a37823fea3ccddaf54d 🔍
SHA1 9ed59c567b96139633037bbdb5ef134fb9c0c4da 🔍
SHA256 8cafaafc874e297d7d708c0d2a7389bfeeb483d74ea9884b41253debf2baa11c 🔍
SHA3 66dc90b232070173cb77604da576e67238ae0620c50fa656b7a9bfea627c2631 🔍

134

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.68211
MD5 2371019c3192a83782c5ffd6ad3679ae 🔍
SHA1 dea2e5272ea6a7def2e467bac5d5e279d84b72d9 🔍
SHA256 2a8c836bc0bb345a6a8f6795f2cdcdbdd7c7278522878561db9367bd249dbf53 🔍
SHA3 2f7f428cf1a7b02cab0a5f2b83edb4178fb3f54359bb61af68ebbbdc7a694ff1 🔍

135

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67576
MD5 21dce31b78a0e93fc4419b70f50cef9b 🔍
SHA1 0505ed3972df28a8f0489b21af133f781c09a4f0 🔍
SHA256 12e9c5f3ed4cdd320f24c3ec1a39ab281338faabd39493841df7621af7efd74c 🔍
SHA3 66618b6feada453491044d8b6321ac0e01914c0e81d7ff4ecd998fdda92540c6 🔍

136

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67699
MD5 2d38a39555518613e69ff30d5118b921 🔍
SHA1 7858eb42004c5fb39339a250b29a11c14e3480e0 🔍
SHA256 4adac5fcec7f80b6b498e62807efcebe9e2b622a103db16093ccc3de751a3cbc 🔍
SHA3 5b76b898cbc09a1bda3191f53ab675506899a9f4e4585b8f4aff5c2cfda4c965 🔍

137

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.68559
MD5 1bcc08fc28e66d980df1feecf53e250b 🔍
SHA1 f0e152b572654c87e5e0efb586471f54f024a9ad 🔍
SHA256 42a27384b6c66d45cf71e1ab3c8573ba83ff478d18efa988e36b0f3aabca28dc 🔍
SHA3 07d7795645483e1652f21aee492118cf8461ff6b5df201e6e7df0aece92311d4 🔍

138

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67995
MD5 22aba791080ddd1b610d044215dd220e 🔍
SHA1 a66a855e90d0a13887c85b04196c02b5085de136 🔍
SHA256 157cbe7583f6657e53b81818bb5c29ccefe0b0abd2955cd1872357ecb1db8a5f 🔍
SHA3 21e3fa136f047b594fca113b15fcfad3aee6ade68d74afdc9ca91fb6c30a79e0 🔍

139

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67293
MD5 0e0a030e34fc9fce070c9ef3748370ee 🔍
SHA1 a5c667bd623260efa985793ae6666dd25c422998 🔍
SHA256 c51d210c2d893fef64915d5e0319e1f31ab7597f6c72627b38c1c139dde7d82c 🔍
SHA3 ded4fbe6fe6791bf44788c481ab542a15c3f2cd26d50394a69878335cbe24df0 🔍

140

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.69619
MD5 c6e64c2011c5ef626b382a8ead299cff 🔍
SHA1 d3f944bdbbeb589fd8113a80f893d5a7746f2571 🔍
SHA256 b3c5e2e4756a437ea346bff9cc65945f60499e21179457c2b89324c4f34965c4 🔍
SHA3 83b0d409e12e1e24c2f9a2749d559d0bdcfd979b4307312e747aef1395e87bdf 🔍

141

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.68439
MD5 48b727ca7e3a10d103b4ffe159c69ac8 🔍
SHA1 bc0f381b069101c991c1253c7a87a482259b31e6 🔍
SHA256 09c8cb36d3b715d4a1e9c98c60e7f0a25794e7dd9e30245d0ea5b0a7f34eded8 🔍
SHA3 74d3b97b02a59f35c8a48c2d1334bbe14ec87098281ee6fbcffb4b1d6a324385 🔍

142

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.6921
MD5 c02d3d708b6f2453dcc95b6000ea26a8 🔍
SHA1 5a08927a17c00c2df15bd3276599dac5e709b272 🔍
SHA256 64ec4d4670b7647c2c837d61cef48d39a2ebaa512429040f27ecad3a758d9b51 🔍
SHA3 fda12fe6cc984136c055412686ea44813a5e69f82252b6c9bac8a2ca8e0f79a7 🔍

143

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.71346
MD5 51ddd42bd2f1968c7990a113aa1f8943 🔍
SHA1 3ea3dd491308d5df6eff471f60d7ee8e54fd8f42 🔍
SHA256 9a2a7f2c8833bb79b8ec27945f522347538bd3bf1e1b9d44889216e6fd84e40a 🔍
SHA3 0ba0ddcf00260f59c00e97ff01edd4a3fd02dcb06a2c73ade3cd896eff96396c 🔍

144

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.68429
MD5 2bdf1bdbc3acde514f1e7f5d46706e3d 🔍
SHA1 804697feb0f27d4cc2830ec3918d9d8e1601d3e3 🔍
SHA256 29c0af0815059c237e22bce66189712d655dccaa4d56d2f4b56db24bc89d24ac 🔍
SHA3 7782f4e789d98881df8969234dcd69de04525526d6e4943e079645d04427f104 🔍

145

Type RT_RCDATA
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x1600
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.7004
MD5 cfa8c6f5859ba2986744fd94502f6073 🔍
SHA1 532cd22c86be87706eb9efd1dfe8c821f7db81fb 🔍
SHA256 d97bb00f2cef0bd84e3f26d01417815c01bda47044f35a86accea77b3d19a8c3 🔍
SHA3 54ea79f044de3368cab817b9048201e9f153d10573a2870fcfee35a59835e319 🔍

132

Type RT_GROUP_ICON
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0xf4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43771
Detected Filetype Icon file
MD5 43430e806b8ccf6974a412b882dbc9df 🔍
SHA1 5627e9dec2bb737621305140558f411f36527f98 🔍
SHA256 f0c3b526082adfc3101ea85f5efe38c31140ffbd517567ca310f2879d465e3c5 🔍
SHA3 6f532de077803fbdc163a04cd9dc956d6eccb16dec55a4db45e86233d4754338 🔍

1 (#2)

Type RT_VERSION
Language Polish - Poland
Codepage Latin 1 / Western European
Size 0x35c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38965
MD5 f29c1e3ce8301d6828c3529417cbb24d 🔍
SHA1 45aa3993da3592c4cb10f4fd98d5727a25209a30 🔍
SHA256 34edac48d8c42981def4f49c85ee1d662bd8c0bf58415f6c44d880616a6c185f 🔍
SHA3 e6f513ff5f520e3a764540fe5b34238fbc7925da2610ee881390cd4474e7824a 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x4ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.12886
MD5 262e2da31d4388bc67ba1eca106924a5 🔍
SHA1 59cc957866df0e70f62bfac2fcc0d577968f0105 🔍
SHA256 5b4b0be9c33743ff03ffc800ab2419a25590b29a93627eb407af751aa9f35b7c 🔍
SHA3 a85921b207cbf4d086a0d12a122952aa49bb49728a137a94c2b941b5dc3b6e7f 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.0.0.2
ProductVersion 2.0.0.2
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName GOG Sp. z o.o.
FileDescription GWENT: The Witcher Card Game
FileVersion (#2) 2.0.0.2
InternalName GOG Galaxy - Gwent Installer.exe
LegalCopyright (C) GOG Sp. z o.o. 2020
InternalName (#2) GOG Galaxy - Gwent Installer.exe
ProductName GWENT: The Witcher Card Game
ProductVersion (#2) 2.0.0.2
Resource LangID Polish - Poland

TLS Callbacks

Load Configuration

Size 0x5c
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x496b64
SEHandlerTable 0x48e4a0
SEHandlerCount 320

RICH Header

XOR Key 0xe26595f6
Unmarked objects 0
241 (40116) 18
243 (40116) 157
242 (40116) 31
ASM objects (VS2015 UPD3 build 24123) 24
C++ objects (VS2015 UPD3 build 24123) 118
C objects (VS2015 UPD3 build 24123) 37
Imports (VS2008 SP1 build 30729) 13
Total imports 162
C++ objects (24234) 3
Resource objects (24234) 1
151 1
Linker (24234) 1

Errors

[!] Error: Could not reach the TLS callback table. [*] Warning: Section UPX0 has a size of 0! [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [*] Warning: Resource is empty! [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [*] Warning: Resource IDD_ABOUTBOX is empty! [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [*] Warning: Resource is empty! [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [*] Warning: Resource is empty! [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource IDD_ABOUTBOX is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 7 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 109 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory. [!] Error: Resource 129 is bigger than the PE. Not trying to load it in memory.
Leave a comment

No comments yet.