be411b31ee80babb7b1d1577d553ee2150f3451036bf8d31ed8bcb0ef179e1e9

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-25 21:57:46
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegEnumKeyW
  • RegQueryValueExW
  • RegSetValueExW
  • RegCloseKey
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Netmarble Corporation
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/72 (Scanned on 2025-03-10 05:57:47) All the AVs think this file is safe.

Hashes

MD5 0757ef5978ec51bf1d0cd6ad2dba8cb3
SHA1 10fc96f1984885384ec5c536db32b39b18011cda
SHA256 be411b31ee80babb7b1d1577d553ee2150f3451036bf8d31ed8bcb0ef179e1e9
SHA3 75e5869981ba196702b889a699672e44f792d5608cc1a6650f2c1884266d5d6a
SSDeep 3072:/bG7N2kDTHUpouA/9aXCvLIaSQmjWAKpjnvR53oRPdWlr2tvhOEA1RJCir86SrSe:/bE/HU4FaXCTp8IzjGFe2t0EyL+Tx3
Imports Hash 56a78d55f3f7af51443e58e0ce2fb5f6

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Sep-25 21:57:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6a00
SizeOfInitializedData 0x2da00
SizeOfUninitializedData 0x800
AddressOfEntryPoint 0x0000352D (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x77000
SizeOfHeaders 0x400
Checksum 0x4851e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ce9df19df15aa7bfbc0a8d0af0b841d0
SHA1 6cba022a30ad3c84a5343e05a15e49562c18aba0
SHA256 c902047f3976f37a722b89e3e2401d690d77b3e70ebaf7a32e9ac5ce6ff34a5e
SHA3 a80cef7bf78b6d8cf31176f4f7b837d46a7ec1b2d2dd9ab44d791ec0b29f199c
VirtualSize 0x6897
VirtualAddress 0x1000
SizeOfRawData 0x6a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4584

.rdata

MD5 a118375c929d970903c1204233b7583d
SHA1 73c2bec231377068f99d5c55ff5c975960280e6c
SHA256 322668435dbcf8d7246f9f554db08e811dd251f45ad883764e7af6b723e51e0a
SHA3 712081c7df3abf95c9a3dacb7e21700d783b1ca8d1105fe9df0f6df834b73c24
VirtualSize 0x14a6
VirtualAddress 0x8000
SizeOfRawData 0x1600
PointerToRawData 0x6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.02411

.data

MD5 82a10c59a8679bb952fc8316070b8a6c
SHA1 7e347dcff055b97091b833896e1097b7ed374fdd
SHA256 05429ca22a1221b4c12a26881799b71b769633a366bccd17b0114acd29ac162f
SHA3 e2e59928a622a7543320d477ef40fed9784205f20846697c8936055ee1f94925
VirtualSize 0x2b018
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.15458

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x23000
VirtualAddress 0x36000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 6fba73d845045b508c40ebd66638b9b4
SHA1 88536866292214ddcff23aa47a48f0faa5306fb5
SHA256 f12c228b8fbb6fd481a6ca6e9a03b66fef06dfcea0b4d0e78b6509173608d251
SHA3 b7867e7ed1f11b4383319592aa00af52b532919deef022c46a8b5eb38719efd8
VirtualSize 0x1de88
VirtualAddress 0x59000
SizeOfRawData 0x1e000
PointerToRawData 0x8a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.41027

Imports

ADVAPI32.dll RegCreateKeyExW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegOpenKeyExW
RegEnumValueW
SHELL32.dll SHGetSpecialFolderLocation
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
IIDFromString
CoTaskMemFree
COMCTL32.dll #17
ImageList_Create
ImageList_Destroy
ImageList_AddMasked
USER32.dll GetClientRect
EndPaint
DrawTextW
IsWindowEnabled
DispatchMessageW
wsprintfA
CharNextA
CharPrevW
MessageBoxIndirectW
GetDlgItemTextW
SetDlgItemTextW
GetSystemMetrics
FillRect
AppendMenuW
TrackPopupMenu
OpenClipboard
SetClipboardData
CloseClipboard
IsWindowVisible
CallWindowProcW
GetMessagePos
CheckDlgButton
LoadCursorW
SetCursor
GetSysColor
SetWindowPos
GetWindowLongW
PeekMessageW
SetClassLongW
GetSystemMenu
EnableMenuItem
GetWindowRect
ScreenToClient
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
FindWindowExW
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
EmptyClipboard
CreatePopupMenu
GDI32.dll SetBkMode
SetBkColor
GetDeviceCaps
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
SetTextColor
SelectObject
KERNEL32.dll GetExitCodeProcess
WaitForSingleObject
GetModuleHandleA
GetProcAddress
GetSystemDirectoryW
lstrcatW
Sleep
lstrcpyA
WriteFile
GetTempFileNameW
CreateFileW
lstrcmpiA
RemoveDirectoryW
CreateProcessW
CreateDirectoryW
GetLastError
CreateThread
GlobalLock
GlobalUnlock
GetDiskFreeSpaceW
WideCharToMultiByte
lstrcpynW
lstrlenW
SetErrorMode
GetVersionExW
GetCommandLineW
GetTempPathW
GetWindowsDirectoryW
SetEnvironmentVariableW
CopyFileW
ExitProcess
GetCurrentProcess
GetModuleFileNameW
GetFileSize
GetTickCount
MulDiv
SetFileAttributesW
GetFileAttributesW
SetCurrentDirectoryW
MoveFileW
GetFullPathNameW
GetShortPathNameW
SearchPathW
CompareFileTime
SetFileTime
CloseHandle
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalFree
GlobalAlloc
GetModuleHandleW
LoadLibraryExW
MoveFileExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
lstrlenA
MultiByteToWideChar
ReadFile
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21109
MD5 1a69f6e26b50595f78632697966a812b
SHA1 00fd1f80d22b0706bc9fc3a8295c573aed8b2215
SHA256 e17fb83b2b2d0247731fabc33f7cca76470e89c1dc958c078f39eeff9a224566
SHA3 e392dcb888b85f5486663200f06ea94793a1759affe8bf40d7644977a7ed372c

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8c22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97486
Detected Filetype PNG graphic file
MD5 bf3794ec91842a80bd052e2147a19d43
SHA1 91563ff055a70e1b36cc40ff620042fced4a5834
SHA256 3487e7d23bf797bb06b15b625a08ca9b3e8898ca8481c8aacb6cd551562d8321
SHA3 f055fd4800ff39ad3407c10f945602d29b6c9375bc33093dcbf0a948cd0f0b8f

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2776
MD5 987499f3ef8180a6d8375dbfe5347ce7
SHA1 4651650405efea5a5952a570201dab2ebf529eb8
SHA256 eb17b13e9aeda231c38575130c430dbc1fad856f7ef31bdd52e9f31b9bc6c0d9
SHA3 f55ebe92e46d65565d46bc682a93b25f88d408ea9a894f30ca4f29159cad4e67

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.32115
MD5 4fbd91b1aba269af93db1d36b8da28a0
SHA1 df721056df97a5d182a695403ba5cd29e673a3b1
SHA256 397e216ebca435cd6d1b26cbe62c18680b78b6a1c59031d40fcee19d829d3a25
SHA3 a25dc4d220f157f47eab76cba7a6f442f708a3301b3fd517f88d177c447533b7

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45276
MD5 3e68059d081d603189be3e65537121fa
SHA1 fbf95318e26a549eac32c35ee71a233bc28124a2
SHA256 12cabfc97bb6540ca1a370d2f3c1456ddae0ca6bd2704f0489d9fbcc851b9bba
SHA3 a24188fd503968d38a4d625e820df8d832656925f673a9e34561de5ad31480ec

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47543
MD5 a9fe0eafe10f0440050838171a29f005
SHA1 4f86e2eb592a9191b939b9b2e37fe0498ad49fb0
SHA256 55891f3c1f7fd04effee3fce3af9e4d77e514ffc4c655cf076318e8d9dad2a6b
SHA3 2afd7177f5d7616e3e00df9e7e19d06e3c94d046ed8aa2d7e416232b3ecbdb05

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45268
MD5 4bfae152ee67e6be718aed4072112a1b
SHA1 84e573b959d79eb104246c09cb5ed2a687b1e14d
SHA256 d1aa9e398f222126ae42c775574faf92bb8733c388cd59f53211c33f6b863347
SHA3 b289639e2130fcb614bbc7aaa89be99190fc8ce672867061f5c8a6ca5f2120e9

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6607
MD5 dd7b27d1457ac076013193d34ce7a19f
SHA1 424ff40626cb46ccfffdf9f668ef3571ff2aa5db
SHA256 c91c2133fb3f66d0534db003db62ce5f76225bd3cb69d90f0482970e4b79a65d
SHA3 83d563defbec3fb23cf9a7d7f5ea315214371f6c64de75f7994585dec6119052

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51013
MD5 a37acd634599ef3ab285754b7da443d7
SHA1 016c4159d5f5adf896d4762f42e2d124ab43e026
SHA256 dd22cdae96a3923bfc5b51448591977602eee19f0696d3498c6469179306df24
SHA3 d15e0b58c14c82dd1c4cb006ef1a8b03283cb7285a24f952f3c61327a19cc961

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x140
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65437
MD5 4228c9750cea54344d97dc0d14e27b7d
SHA1 3ae70d80f8b0b05f531341e8a7895bf65ee881e1
SHA256 3f93052e0bfbde7657b7276577908c0bed1f5f98c145f30584de7822171d1b66
SHA3 27896014cc691fe18a51c468e0dcdcfe82104ee1e321c50e33537d2c808cc999

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x11c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88094
MD5 2d12c45dc2c029044aaff357141cb900
SHA1 083db861ab3c7db23c6257878296e73a89a74b8b
SHA256 69897c784f1491eb3024b0d52c2897196a2e245974497fda1915db5fefcf8729
SHA3 349b5d605c9c3efe5e0c4e2faa12dd21022fc5f9b053f2cbf4e2a6b8bc656442

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48825
MD5 6be4e1387d369cf86e68eacbdd0e81dd
SHA1 351970fe2681b9b35b5d59ad052011ed96a96e17
SHA256 85025c8556952f6a651c2468c8a0d58853b0ba482be9ad5cd3060f216540dfc0
SHA3 45e552e173141e06d113209b6cc915042ad0b4d5531464b8dbe5637029f489cb

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x12c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.57846
MD5 e36e7db32904c66ad0a2712479a4584f
SHA1 da628b4d31e10b6961882aee07610cf2025486f8
SHA256 2483994af176f2244aa19a35d3c447371d9e98462f20e7fe63987268d3c2fa78
SHA3 d53b961f386fa9bb78a6ac42bf0c0a17011c3fa09dd787c16d3ebfa29e3a92bd

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x108
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8423
MD5 fc90fe6661f0b16b8ce0c1aa99bea3e2
SHA1 c4d34ca437db74be364cb2180f6203f86db74b82
SHA256 b5543e3d38107be314a9e6fb087276eee2f1826badfa971457be444ea20d7746
SHA3 91c7abc04e6e765a507384c0c713ea1f642f317252c5b88c8228fa4b16e8345c

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.36476
MD5 2be3bcd55b1b72399df63e9c689d8f5f
SHA1 e57896fa1df9372b1c5a9e763d1da7a77af521ce
SHA256 564c895446fafa8f70c06d52141b03bb6bbab392ce362cae8c345a60c7519c99
SHA3 dfcd3b0ca5972684d1c4f55b1d0e316d3d32e3c9ee7ebacdd15b8caee47b2c05

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x138
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7234
MD5 5b885abb944381dba058f99a4161d086
SHA1 1d5b6fb8b6b733e1759405630763b87ee6115302
SHA256 7d33e45ad5a65363c1bde1d7d9b2fbc96091c0b45d8e04a2bc53b488cfac82f9
SHA3 1eaf2758f40e5aa758df990912db2f2fa3cb97cdc7b1f87577f19838d473af28

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x114
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00455
MD5 0938523e64c2bbf7728bfa3c79b56100
SHA1 a2514ebd7061e1eebf09fdecc59a36a87bec5822
SHA256 282ab46ed5405f81d4a9b9ab8c2aac2345e7f12e146e2159169c2be9ce5d611a
SHA3 7625e64c4d3615c19b003b35a26509250d2d5ccbe7a30033132bea47eef68199

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x58
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76109
MD5 076eaa29cb0fd488dbf28132ba9053ce
SHA1 4ed7d9235080ca286344b50642c16cfe8bf1adda
SHA256 fb1541fab691418f4ba1d7881ee001103522cc5bc7e351b993c04cf0b4bc1385
SHA3 bfb755e23413508cb86824e402871098d7f3f998e137ff56be87aa36e045a57c

405

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65909
MD5 6d596300208d77a91782007c9962cd3b
SHA1 824e2f72e1e4f764f33430ab377a763a781e4121
SHA256 3585f53a5d0bc65be298313e075fced2dbf36938852c36b1e1a4cb846a9f0f04
SHA3 27bea26df6f289a89433bc327f23667b629f0779777cdb727ff891889c0eacac

406

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x10c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.93418
MD5 f3623d128301f09f43bb7f2bb05d131b
SHA1 f38f1369324051f74016a0ecb2c0d1f1c19e8ba4
SHA256 e574bca7fb2aa385186e38f5e75c3e07091046b36711ec94504003fc257dbe43
SHA3 51b239c161acdc69394cfa4d1abadccad161ccb40c485e0bd02e4a87ee8ba0e6

411

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x50
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63292
MD5 9fd86d0859f2cb45a303f2eccbb728ef
SHA1 e5ee9f452cb943e5c3b21783da7abf4a748d9ca2
SHA256 66c5a54fc613b3a72b0ce1651649944bfbef2d0c2068f2ecba821ed82188496c
SHA3 7fe952e87ecbbdf41b8934c0cd40f81161a5b312c4640e037bd47dca5b16717d

505

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x12c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.57179
MD5 897b37f0699127d64eb9d73ceb57db0f
SHA1 cab423db34759db649848e9bfb036f6590c1cc34
SHA256 85e837b1b7182187a0fc01bfd01074420d23ec97e970e185a70c6c13419544dd
SHA3 2cb6ced77fa6644b54b8826cce7c817c071a500ae64c61435720df4dd0c4a711

506

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x108
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84516
MD5 893d63dec1e2e03d34ed1b204441cf5d
SHA1 992a45ecfb666bb2161474bdb956bd27758f42d3
SHA256 22d4a1e9f8c4881abc6ffcceac4a8466ceef818a8ea296de8008a0a210950185
SHA3 a7025ceda45780109fd77344412d7dbae5515241a96127f9d1a67a077bba5dbf

511

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.36476
MD5 a6e82d7b05a5b3f5961b64f1642a06ee
SHA1 12b290ffc5492d4ee7fcb2398411f5cd8e2f63fd
SHA256 e9c101b10de7cb49faad8c6cbc66a8c98b63d107c92fbd6160bf711149450786
SHA3 aa6c8ba15c0f1fd950ab322991aff62e650279e97a3f3c6b885148ed427c7059

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00943
Detected Filetype Icon file
MD5 d7d74069885a469a8f5fed66db8f51f0
SHA1 ccb920b4aa4d06b0915c348b312908ae9e198cf5
SHA256 95732fdc7563da5e3fc44029e2b971b3c9a623d8b95937e6d2081bf715654bab
SHA3 d32184bdcdd697e5491f6922eea272d5972114b18b9b90969995ba6072509bec

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x349
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28747
MD5 39a5f7e944b19d4a6d666e5b22cb9189
SHA1 02ba880d90d9591390530245c9f79a8ff3e79aed
SHA256 64853bb3de406ea1dd1ca7b2acdf1e5f011236e25cf8271042b952be01e8f040
SHA3 d58d7ac1878dc0236f33fd60d22d0336f96582f4c1e4569f8d5bdadb4dc2e30c

Version Info

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
Leave a comment

No comments yet.