b5df92eddc1f49912315e19cfb7be1ecc6a470c390eaf36c75dd7a9a7c9b8594

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Mar-16 06:03:05
Detected languages English - United States
FileVersion 1.1.37.02
ProductVersion 1.1.37.02

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .exe.bat.com
  • autohotkey.com
  • exe.bat.com
  • https://autohotkey.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. Unusual section name found: data
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowW
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegisterHotKey
  • RegDeleteKeyW
  • RegSetValueExW
  • RegCreateKeyExW
  • RegQueryValueExW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegQueryInfoKeyW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetAsyncKeyState
  • AttachThreadInput
  • CallNextHookEx
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAllocEx
Has Internet access capabilities:
  • InternetOpenW
  • InternetOpenUrlW
  • InternetCloseHandle
  • InternetReadFileExA
  • InternetReadFile
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
Enumerates local disk drives:
  • GetDriveTypeW
  • GetVolumeInformationW
Manipulates other processes:
  • WriteProcessMemory
  • ReadProcessMemory
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Can take screenshots:
  • GetDC
  • FindWindowW
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious VirusTotal score: 3/68 (Scanned on 2026-09-18 06:12:01) Fortinet: PossibleThreat.PALLAS.H
Skyhigh: BehavesLike.Win64.Dropper.th
TrellixENS: Artemis!0E66C8492D9E

Hashes

MD5 0e66c8492d9e0502a08010a07195e0e0 🔍
SHA1 88ef2afb0435940c5643878bab17acfbee98e622 🔍
SHA256 b5df92eddc1f49912315e19cfb7be1ecc6a470c390eaf36c75dd7a9a7c9b8594 🔍
SHA3 bfc30b6ce8c529657c0318945969c3be742e023eaba8359fa3fe41ab478da9ba 🔍
SSDeep 24576:wUNxvqF6FGYJf6yjNQpNONZNlTX5PlGPgquLEIWxUc7N11QaSYx7Gqg3:wUNxvC6FGYJf6yjNQpNONZnTX5PlGPgb 🔍
Imports Hash a649e6750bcf2911044dec744c57f40f 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Mar-16 06:03:05
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 10.0
SizeOfCode 0xde400
SizeOfInitializedData 0x4d800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000CDB30 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x138000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x400000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1b1d6dd14717b7a4a86bc608450d2229 🔍
SHA1 5827c9234d741237645543f25effbd5418b38c2a 🔍
SHA256 caaebf9c1ae3831629d8b46695b799c234a6a194a6e472167cb1b71814800f15 🔍
SHA3 93b15cc0b1586e2b81d6c9cc2f6b0837ae21c37d27d45f8040e972ca315a3c08 🔍
VirtualSize 0xde3e6
VirtualAddress 0x1000
SizeOfRawData 0xde400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54753

.rdata

MD5 09069cfe30350895756a1046ae0bd101 🔍
SHA1 cc036f39e775c0a46e16baa95fd0968f0368d3c6 🔍
SHA256 17214ccf9a2d65e142b5e2b6a368249caf02a18119e442e66eb8f0276dda7895 🔍
SHA3 c9bd465b283bc197c1a33bf7fe4aca3925a0743deb24e036fd4a2c51b53af0e5 🔍
VirtualSize 0x312fe
VirtualAddress 0xe0000
SizeOfRawData 0x31400
PointerToRawData 0xde800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.96889

.data

MD5 969162fa5a35d1af3366239c5d31d147 🔍
SHA1 6bedf43879cb2d748e7529dcb756e753adae6e22 🔍
SHA256 89a002c9e5401d6961f751a930cccaaa8ae4aff79767e6e118a57333cb6abfc6 🔍
SHA3 6ba1d722211ef8c7a89c9c9c44bb872e3d75c57bd19d5a84b33312c8e242e3d8 🔍
VirtualSize 0xc3b8
VirtualAddress 0x112000
SizeOfRawData 0x5000
PointerToRawData 0x10fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.31157

.pdata

MD5 ee1089d1b53300da83162d138f4a39cc 🔍
SHA1 59879bcae9eb45d60dac472a365c6717c684a670 🔍
SHA256 75c876ac2f97602355d09206d1313d253d95be58e6967d9dc5d1dbe83be16ff3 🔍
SHA3 a38e01f6092c8a36994f4cfe6b296379722a60d5e34c554f1849f3275e59f961 🔍
VirtualSize 0x7a58
VirtualAddress 0x11f000
SizeOfRawData 0x7c00
PointerToRawData 0x114c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.988

text

MD5 6cae918481287a7ff0aaef42fc0b95ee 🔍
SHA1 4402918cf33a8ff7a015fc911cd0186e2d7ca1f0 🔍
SHA256 29d2b10c7f1a9b1f8eaf1fa09d2c202d5b8bdd6def63889f5cfa6edee3fef39c 🔍
SHA3 cc19666dc0d92fda1e19c13f273f6b0d19dd8a71c1ef7f8903a418ad616d6943 🔍
VirtualSize 0x258d
VirtualAddress 0x127000
SizeOfRawData 0x2600
PointerToRawData 0x11c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
Entropy 5.77432

data

MD5 8f4275b626558a8640120f611553e570 🔍
SHA1 353e3345d0a3058c1fee970144c22844ac1d4560 🔍
SHA256 f1ee9c61cd936b223504365c8f4ff63ca0b67a72ecfbb6480562140739308433 🔍
SHA3 127cdb09b38e90d67b8dd08ee4cee51745e7ddfe4ff0e4df5d977ada62a6ca02 🔍
VirtualSize 0x6ec0
VirtualAddress 0x12a000
SizeOfRawData 0x7000
PointerToRawData 0x11ee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.45736

.rsrc

MD5 7db042cfdd4c8d24fe696c3c705fe0dc 🔍
SHA1 1b6928ea173534daf84326d4262fd58194221ff3 🔍
SHA256 cf2a1e011b5073e5ca301053aca45233c050bf5073c5dfceeb00d0539472c3bb 🔍
SHA3 ec4b041dc6732b58b598b1dce14c92f583ac8a6f4d06942f8864e96c2988c1d2 🔍
VirtualSize 0x6144
VirtualAddress 0x131000
SizeOfRawData 0x6200
PointerToRawData 0x125e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.9978

Imports

WSOCK32.dll gethostbyname
inet_addr
WSACleanup
gethostname
WSAStartup
WINMM.dll mixerGetLineInfoW
mixerGetDevCapsW
mixerOpen
mciSendStringW
joyGetPosEx
mixerGetLineControlsW
mixerGetControlDetailsW
mixerSetControlDetails
waveOutGetVolume
mixerClose
waveOutSetVolume
joyGetDevCapsW
VERSION.dll GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
COMCTL32.dll ImageList_Create
CreateStatusWindowW
ImageList_ReplaceIcon
ImageList_GetIconSize
ImageList_Destroy
ImageList_AddMasked
PSAPI.DLL GetProcessImageFileNameW
GetModuleBaseNameW
GetModuleFileNameExW
WININET.dll InternetOpenW
InternetOpenUrlW
InternetCloseHandle
InternetReadFileExA
InternetReadFile
KERNEL32.dll GetModuleFileNameW
GetSystemTimeAsFileTime
FindResourceW
SizeofResource
LoadResource
LockResource
GetFullPathNameW
GetShortPathNameW
FindFirstFileW
FindNextFileW
FindClose
FileTimeToLocalFileTime
SetEnvironmentVariableW
Beep
MoveFileW
OutputDebugStringW
CreateProcessW
GetFileAttributesW
WideCharToMultiByte
MultiByteToWideChar
GetExitCodeProcess
WriteProcessMemory
ReadProcessMemory
GetCurrentProcessId
OpenProcess
TerminateProcess
SetPriorityClass
SetLastError
GetEnvironmentVariableW
GetLocalTime
GetDateFormatW
GetTimeFormatW
GetDiskFreeSpaceExW
SetVolumeLabelW
CreateFileW
DeviceIoControl
GetDriveTypeW
GetVolumeInformationW
GetDiskFreeSpaceW
GetCurrentDirectoryW
CreateDirectoryW
ReadFile
WriteFile
DeleteFileW
SetFileAttributesW
LocalFileTimeToFileTime
SetFileTime
DeleteCriticalSection
GetSystemTime
GetSystemDefaultUILanguage
GetComputerNameW
GetSystemWindowsDirectoryW
GetTempPathW
EnterCriticalSection
LeaveCriticalSection
VirtualProtect
QueryDosDeviceW
CompareStringW
RemoveDirectoryW
CopyFileW
GetCurrentProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
FormatMessageW
GetPrivateProfileStringW
GetPrivateProfileSectionW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
WritePrivateProfileSectionW
SetEndOfFile
GetACP
GetFileType
GetStdHandle
SetFilePointerEx
SystemTimeToFileTime
FileTimeToSystemTime
GetFileSize
IsWow64Process
VirtualAllocEx
VirtualFreeEx
EnumResourceNamesW
LoadLibraryExW
GlobalSize
HeapReAlloc
EncodePointer
HeapFree
DecodePointer
ExitProcess
HeapAlloc
IsValidCodePage
FlsGetValue
FlsSetValue
FlsFree
FlsAlloc
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
InitializeCriticalSection
GetCPInfo
GetVersionExW
GetModuleHandleW
FreeLibrary
GetProcAddress
LoadLibraryW
GetLastError
CreateMutexW
CloseHandle
GetExitCodeThread
SetThreadPriority
CreateThread
GetStringTypeExW
lstrcmpiW
GetCurrentThreadId
GlobalUnlock
GlobalFree
GlobalAlloc
GlobalLock
SetErrorMode
SetCurrentDirectoryW
Sleep
GetTickCount
MulDiv
RtlCaptureContext
HeapSetInformation
GetVersion
HeapCreate
InitializeCriticalSectionAndSpinCount
HeapSize
HeapQueryInformation
GetCommandLineW
GetStartupInfoW
RtlUnwindEx
GetStringTypeW
RaiseException
RtlPcToFileHeader
LCMapStringW
GetConsoleCP
GetConsoleMode
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
QueryPerformanceCounter
GetOEMCP
SetFilePointer
WriteConsoleW
SetStdHandle
FlushFileBuffers
GetFileSizeEx
GetProcessHeap
USER32.dll GetDlgItem
SetDlgItemTextW
MessageBeep
GetCursorInfo
GetLastInputInfo
GetSystemMenu
GetMenuItemCount
GetMenuItemID
GetSubMenu
GetMenuStringW
ExitWindowsEx
SetMenu
FlashWindow
GetPropW
SetPropW
RemovePropW
MapWindowPoints
RedrawWindow
SetWindowLongPtrW
SetParent
GetClassInfoExW
DefDlgProcW
GetAncestor
UpdateWindow
GetMessagePos
GetClassLongPtrW
CallWindowProcW
CheckRadioButton
IntersectRect
GetUpdateRect
PtInRect
CreateDialogIndirectParamW
GetWindowLongPtrW
CreateAcceleratorTableW
DestroyAcceleratorTable
InsertMenuItemW
SetMenuDefaultItem
RemoveMenu
SetMenuItemInfoW
IsMenu
GetMenuItemInfoW
CreateMenu
CreatePopupMenu
SetMenuInfo
AppendMenuW
DestroyMenu
TrackPopupMenuEx
CopyImage
CreateIconIndirect
CreateIconFromResourceEx
EnumClipboardFormats
GetWindow
BringWindowToTop
MessageBoxW
GetTopWindow
GetQueueStatus
SendDlgItemMessageW
SetClipboardViewer
LoadAcceleratorsW
EnableMenuItem
GetMenu
CreateWindowExW
RegisterClassExW
LoadCursorW
DestroyWindow
EnableWindow
MapVirtualKeyW
VkKeyScanExW
MapVirtualKeyExW
GetKeyboardLayoutNameW
ActivateKeyboardLayout
GetGUIThreadInfo
GetWindowTextW
mouse_event
WindowFromPoint
GetSystemMetrics
keybd_event
SetKeyboardState
GetKeyboardState
GetCursorPos
GetAsyncKeyState
AttachThreadInput
SendInput
UnregisterHotKey
RegisterHotKey
SendMessageTimeoutW
UnhookWindowsHookEx
SetWindowsHookExW
PostThreadMessageW
IsCharAlphaNumericW
IsCharUpperW
IsCharLowerW
ToUnicodeEx
GetKeyboardLayout
CallNextHookEx
CharLowerW
ReleaseDC
GetDC
OpenClipboard
GetClipboardData
GetClipboardFormatNameW
CloseClipboard
SetClipboardData
EmptyClipboard
PostMessageW
FindWindowW
EndDialog
IsWindow
DispatchMessageW
TranslateMessage
ShowWindow
CountClipboardFormats
SetWindowLongW
ScreenToClient
IsDialogMessageW
DialogBoxParamW
SetForegroundWindow
DefWindowProcW
FillRect
DrawIconEx
GetSysColorBrush
GetSysColor
RegisterWindowMessageW
EnumDisplayMonitors
IsIconic
IsZoomed
EnumWindows
ChangeClipboardChain
GetWindowTextLengthW
SendMessageW
IsWindowEnabled
GetWindowLongW
GetKeyState
TranslateAcceleratorW
KillTimer
PeekMessageW
GetFocus
GetClassNameW
GetWindowThreadProcessId
GetForegroundWindow
InvalidateRect
SetLayeredWindowAttributes
SetWindowPos
SetWindowRgn
SetFocus
SetActiveWindow
ClientToScreen
EnumChildWindows
MoveWindow
GetWindowRect
GetMonitorInfoW
MonitorFromPoint
GetClientRect
SystemParametersInfoW
AdjustWindowRectEx
DrawTextW
SetRect
GetIconInfo
SetWindowTextW
IsWindowVisible
BlockInput
GetMessageW
SetTimer
GetParent
GetDlgCtrlID
CharUpperW
IsClipboardFormatAvailable
CheckMenuItem
PostQuitMessage
IsCharAlphaW
LoadImageW
DestroyIcon
GDI32.dll GetPixel
GetClipRgn
GetCharABCWidthsW
SetBkMode
CreatePatternBrush
SetBrushOrgEx
EnumFontFamiliesExW
CreateDIBSection
GdiFlush
SetBkColor
ExcludeClipRect
SetTextColor
GetClipBox
BitBlt
CreateCompatibleBitmap
GetSystemPaletteEntries
GetDIBits
CreateCompatibleDC
CreatePolygonRgn
CreateRectRgn
CreateRoundRectRgn
CreateEllipticRgn
DeleteDC
GetObjectW
GetTextMetricsW
GetTextFaceW
SelectObject
GetStockObject
CreateDCW
CreateSolidBrush
CreateFontW
FillRgn
GetDeviceCaps
DeleteObject
COMDLG32.dll CommDlgExtendedError
GetSaveFileNameW
GetOpenFileNameW
ADVAPI32.dll RegDeleteKeyW
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
CloseServiceHandle
UnlockServiceDatabase
LockServiceDatabase
OpenSCManagerW
GetUserNameW
RegEnumKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegCloseKey
RegConnectRegistryW
RegDeleteValueW
SHELL32.dll DragQueryPoint
SHEmptyRecycleBinW
SHFileOperationW
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetDesktopFolder
SHGetMalloc
SHGetFolderPathW
ShellExecuteExW
Shell_NotifyIconW
DragFinish
DragQueryFileW
ExtractIconW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
CoInitialize
CoUninitialize
CLSIDFromString
CLSIDFromProgID
CoGetObject
StringFromGUID2
CreateStreamOnHGlobal
OLEAUT32.dll SafeArrayGetLBound
GetActiveObject
SysStringLen
OleLoadPicture
SafeArrayUnaccessData
SafeArrayGetElemsize
SafeArrayAccessData
SafeArrayUnlock
SafeArrayPtrOfIndex
SafeArrayLock
SafeArrayGetDim
SafeArrayDestroy
SafeArrayGetUBound
VariantCopyInd
SafeArrayCopy
SysAllocString
VariantChangeType
VariantClear
SafeArrayCreate
SysFreeString

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.86108
MD5 a39fb44bf8050f41f6d83455a14d1e66 🔍
SHA1 2dd0427450108b59ace3a04792f05415949ae7d5 🔍
SHA256 48371b314b0fe0d31d36b0b70b2360930b491b51a099b879d73045add236019c 🔍
SHA3 c76ad8953ad38b2d5017109fb4b34294921110d5e43bf4a8bda7b5d9b4b9784e 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37027
MD5 43e1dcd2406d58c8db6a5c02e7999c12 🔍
SHA1 83c5d441bd94ec88fb47ae6aa9359a44841b3f17 🔍
SHA256 438e452bb673b15eeb4cf0232a116703d211a586889d98d6927915a2fecfd4dc 🔍
SHA3 05fcd83f1be53d0b5bc947db45924361cffec22a2367bf3627dfccbceb0808cc 🔍

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.67639
MD5 d71b7306acf232a20b51a1222ef1659f 🔍
SHA1 50e0c9ddabfb4415198cb3a8487d811e5fcb7637 🔍
SHA256 2bc02fc0c6b5c414ac2310c3ad9cb50e7d26ac1991973aa72b8750bcb018c847 🔍
SHA3 bc134de925cee2e92a3e2972ea01ab915f1cd8f1a488795fbd7412322b7cb20c 🔍

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.84157
MD5 1c93a14c5a485c11350ef568f5e423c1 🔍
SHA1 bead6553859c4ec6e647551a19b224dc2357fc5f 🔍
SHA256 ae6b56a4aabbeb5d22f508ed6d1522ba6e5b668d1ffb05e4d9cee348a14197cd 🔍
SHA3 5719b4dc9bcc5a323c95d760317d4a5b737343f709eee16eddf819e8054ee6dd 🔍

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3349
MD5 266626c8655c67b9530c361ca939f01d 🔍
SHA1 4f799d89f7255ef58628605cc0f37a3420925a3d 🔍
SHA256 1bfebd87e8f7129fe598c91a87ff03e7962b95af723ea024faf9549e6442aa84 🔍
SHA3 85b69f2f4e1bfa507c52634afc60ad29f41321a0a4526654693b1dd7a6f516d9 🔍

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46964
MD5 fbbd1dfd9481f55d0e9ebc890ce09c3c 🔍
SHA1 cbfd96b3e1c556af63424b3a153def765077b8fb 🔍
SHA256 5ef6e7b16676575434a274b3654dcc6c4934adcb5c86ee31939720568578d2c0 🔍
SHA3 108eb4ba2bc3e913cec2e0d5cd215901fb0f4ebffc7fbd7679673ea2c735a609 🔍

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56056
MD5 9104d9f5acc220ac5a9a1c29a283e42d 🔍
SHA1 7e274a143071c4d7801c07669074cd8fa2972047 🔍
SHA256 e773c795d1dbb9bf8cd8f73f12c4f02c047f58dc516be4a629fe807610476917 🔍
SHA3 8cd4a3f7555bedc4ecddbcb83b34780f450c902a91ddda511b41f9b6f1c21103 🔍

211

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37124
MD5 2cfd05e0e8346abd1be8b6933d0684ad 🔍
SHA1 898c4f11bceec1fb399cc9e0f305e09b9a2df803 🔍
SHA256 c0306fb5f7462e74df09e5e0627c01a238f291bbdc89c24c0ea1f46e7341ab5a 🔍
SHA3 8f3778cee4660e3c85805aa4bce2602547080ca7cfc425029bce1441a5af9a1f 🔍

205

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82326
MD5 fec66af562e184a3acd4ada5b1603016 🔍
SHA1 fe5cd5d19cfc12992d23a18db8edaf1c06f610c2 🔍
SHA256 0b54b12fc56db7f7a5a366544081e75cfd312d6db7dd0b298b8088ad2f748908 🔍
SHA3 36780025f039a7044aac6d427f489314299b398567b3b737bb5f229278d74563 🔍

212

Type RT_ACCELERATOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96144
MD5 7fb94687aa0fe2b18873dba5ac59ab1d 🔍
SHA1 e19e8d6b0e33da063de27c83fa0bab4058513332 🔍
SHA256 86286a59831ad1d0d84eb411ae6fa236b21bca5d3ebfc93a59cf4b6bf1d466d0 🔍
SHA3 33011788d35d1127a1ee6fbdb975c0d4ef6b36d3896e0d27d3f75f0ff68e3aec 🔍

>AUTOHOTKEY SCRIPT<

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x84a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.34594
MD5 a55498688a254f02e4e7909782a74cd4 🔍
SHA1 e1e873da371ccccc62f807a8832e50f8b49d357c 🔍
SHA256 15a228e7e25699f281f4a0c40bd3c23fec7f4ebb1c03cab83580f8fc0bae5265 🔍
SHA3 d9eee9ae36860c842dfad9919dd114f5730c287a916e281f82aa6ecf9baf7924 🔍

159

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 dafef03caf7d734f3b3109544d379061 🔍
SHA1 38346ec865640b6f3fff23486d584ed75daf36b2 🔍
SHA256 3c56cd7df93d9db479214fe27416c1e6fb7def4aa7be334f5f191bcff395674c 🔍
SHA3 f33c3b7db100d2e8cd39d715a1ada8d8c7595baaab95d8a26658133740031c9c 🔍

160

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.02322
Detected Filetype Icon file
MD5 6a368971d47678239d334269be28300e 🔍
SHA1 9fcfe92b319b372d6d59c9096cf13e9662e8299f 🔍
SHA256 45de95e2bc9da2d99016c89cba3816940f7ddb7f044c6d34b5f5c168c3b638ff 🔍
SHA3 10b30bfdab83169af38b453132bc26884230b58321aab1e2ebd88135cfae8457 🔍

206

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.9815
Detected Filetype Icon file
MD5 40c1414025bcc34e7ba97fd22bc9f5a4 🔍
SHA1 b53a6a13513b5205cef6fc6d7556ad80d8b62173 🔍
SHA256 d6659139f55adad2497df8d1a11fcd68324a00ccdadbc133ddd49fb79e9ccc1c 🔍
SHA3 88c00f73975983695c16e34c6a1750573250999152f5399a198b799e76349720 🔍

207

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 9b2193af49fdb53892356f594e9f18b9 🔍
SHA1 448aa28721dd65475b37505de8140d88d5aa1501 🔍
SHA256 9b8ca9c6a330d0d17d1108ab5442d60ea574817a65caa860cceb24313cc4f0e4 🔍
SHA3 46527c3333b02958fd025cfdaa12d481f8505aa77c1cd0b5f15348e870530116 🔍

208

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 5f51cbb6145d3a4c36cffa3b028b0199 🔍
SHA1 b2bbd2afcfa1c44725bf90df8948792d3bc7fb97 🔍
SHA256 fbb52a958caa73dce023ce27649d69f8886e86b5706e767153c41dde7b5eebf9 🔍
SHA3 93f253b05e0e42147b5a9000d421c3e105df42f9fafae5147c4e9a09958e3f79 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x21c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27273
MD5 1a61de9a5f7811f42822e8a21ac2e298 🔍
SHA1 64a9ebceb0e83a5c30bf93e2c9ad411c527273d9 🔍
SHA256 488d89a43a389151f881f11f112c163af28788fd97dabf588bad18492f8307cf 🔍
SHA3 f8784d306b1b8d2e3eb0a18b0e2e8d44098afb71c9f7cc8838a7a9acb8159404 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x4f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.34908
MD5 fd97ad678377c9966ba3f8697c4e0aec 🔍
SHA1 a219c82a72b1a932c555f7b8ca0180f5b909d8ca 🔍
SHA256 0ca571f6485ac59097ce1d665a6c65086b8bc9f639715beb28666cb367f12f8a 🔍
SHA3 cf4561c34a35064efaa478d33745f6e1bb002dbf220524c3fe547d68cc0337ef 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.37.2
ProductVersion 1.1.37.2
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 1.1.37.02
ProductVersion (#2) 1.1.37.02
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xe9f3c943
Unmarked objects 0
C++ objects (VS2010 SP1 build 40219) 53
C objects (VS2010 SP1 build 40219) 143
C objects (VS2008 SP1 build 30729) 7
135 (VS2008 SP1 build 30729) 1
Imports (VS2008 SP1 build 30729) 29
Total imports 467
ASM objects (VS2010 SP1 build 40219) 23
175 (VS2010 SP1 build 40219) 43
Resource objects (VS2010 SP1 build 40219) 1
Linker (VS2010 SP1 build 40219) 1

Errors

Leave a comment

No comments yet.