fb8746e50fb74dd200bfd88ae2b4af807c21910727d13b70b596e3caa3773a02

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-05 10:53:01
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts open_video_downloader.pdb
CompanyName jelleglebbeek
FileDescription Open Video Downloader
FileVersion 3.2.1
ProductName Open Video Downloader
ProductVersion 3.2.1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • -encryption.org
  • age-encryption.org
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • encryption.org
  • genretrucklooksValueFrame.net
  • github.com
  • headerage-encryption.org
  • http://asset.localhost
  • http://dummy.testC
  • http://ipc.localhost
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://docs.rs
  • https://github.com
  • https://jely2002.github.io
  • https://jely2002.github.io/youtube-dl-gui/manifest/manifest.json
  • https://jely2002.github.io/youtube-dl-gui/manifest/manifest.sigae7988a00d92349e55ff560369e7ec6afdb4b22a7e1dbe62a6769e1f347fa073,invalid
  • https://www.World
  • https://www.recent
  • ingest.us
  • microsoft.com
  • o762792.ingest.us
  • openssl.org
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowW
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegDeleteValueW
  • RegSetValueExW
  • RegQueryValueExW
  • RegCloseKey
  • RegGetValueW
  • RegOpenKeyExW
  • RegisterHotKey
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCancelIoFileEx
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtCreateFile
  • NtWriteFile
  • NtOpenFile
  • NtReadFile
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Manipulates other processes:
  • EnumProcessModules
Can take screenshots:
  • FindWindowW
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertOpenStore
  • CertAddEncodedCertificateToStore
  • CertAddCertificateContextToStore
Suspicious VirusTotal score: 1/71 (Scanned on 2026-09-24 04:31:38) Trapmine: malicious.moderate.ml.score

Hashes

MD5 2d05a76bfa83af0d237ffc041105fabf 🔍
SHA1 a943ddbf417497670150a232b6f2c51d650c82ea 🔍
SHA256 fb8746e50fb74dd200bfd88ae2b4af807c21910727d13b70b596e3caa3773a02 🔍
SHA3 ed2f686f7db1910b6b9bd62e816d32eb45bb6e3897b7ecabaa054bda98ed8aa3 🔍
SSDeep 98304:IrVsxvcIDVLdyfrje0knFmTyBMiQTrZ28MRiBFkzEm9YFbOH6TsL+ZEn+SAul:ukPyfAFAAwBFkom9YQ6TuwK9 🔍
Imports Hash c2d60d1da86776436e9207f1905f9c9d 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-05 10:53:01
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x78fa00
SizeOfInitializedData 0x346800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000760CE0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xada000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6a31e43af4a8fd22a16ffbd700be461a 🔍
SHA1 9e5342a9db6d3a964c96f8a2f4aab702215cdd05 🔍
SHA256 5660c2bf1970bc41711958281f27ead696f6b72c7323d2e352866181c0a484f2 🔍
SHA3 996f3486ced679312da3268f021bbe26cf99d094d8543e18b9940126b911a134 🔍
VirtualSize 0x78f9e0
VirtualAddress 0x1000
SizeOfRawData 0x78fa00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.34682

.rdata

MD5 d2f7e744555d06e7ddae590efe8c0757 🔍
SHA1 9fb52659766503e3eb265bab5ee99b0562b53107 🔍
SHA256 844cdd094e778cff38ff6ac462928e695f3ef9929d608f7fb96f85c53258ccd9 🔍
SHA3 876248e768546157eafbb8439c382d73df96219e07ba8b3633ec0cbfae8ac83e 🔍
VirtualSize 0x2f9090
VirtualAddress 0x791000
SizeOfRawData 0x2f9200
PointerToRawData 0x78fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.88638

.data

MD5 a390687f3bca9fdc6c426a15954ebd74 🔍
SHA1 649607ba4121cc65856c35faad5ab09c5a65260c 🔍
SHA256 cd02fcfa107b39bc97507587b8398ff4fd1c0ae131cab629417d9d760856cd4d 🔍
SHA3 5d94df5c29f0430773e3a9a0f96eab79f889b6cf50efe98e77d8b8b88cfd2c1c 🔍
VirtualSize 0x8f90
VirtualAddress 0xa8b000
SizeOfRawData 0x3800
PointerToRawData 0xa89000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.9163

.pdata

MD5 d0399d5c0475a47a3bf0588b96057380 🔍
SHA1 f6eb8dddc018904b7d1693863cdc9d17adb07067 🔍
SHA256 294e8ac5886d50b58b9cdbccbe3b9bd5df776b0f82955c9a6da7b2d74a1c1ece 🔍
SHA3 af64233972fb3283bfee7f69e1f504841e04cfc3f4fa5733d6dec9e4f10bae90 🔍
VirtualSize 0x28830
VirtualAddress 0xa94000
SizeOfRawData 0x28a00
PointerToRawData 0xa8c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.33438

.rsrc

MD5 9eb0570dd6263ab927ca674a5005faf2 🔍
SHA1 cfbbf8aebcfa191fcacb6445bcad955884268248 🔍
SHA256 83f6176115804440b5e9b79dc15a950975d538954e4366c298fcc8895ef7cd18 🔍
SHA3 215997f37daf749886227a1d6e42b3c161a82efe851f8d1b1508fcd5c75a538b 🔍
VirtualSize 0xd570
VirtualAddress 0xabd000
SizeOfRawData 0xd600
PointerToRawData 0xab5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.93723

.reloc

MD5 4d23d3be136f563657b5b83929c685e7 🔍
SHA1 f013358babd8f78138c4726d881b791895256fe6 🔍
SHA256 da26bd3faee3488e45feb4f2119af19c03892161cfa6f55849abc117796157af 🔍
SHA3 1bc81797babc923068da6c0552f846ca5962afbd91cef1f63d27239d64e44349 🔍
VirtualSize 0xe44c
VirtualAddress 0xacb000
SizeOfRawData 0xe600
PointerToRawData 0xac2800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45944

Imports

kernel32.dll GetNativeSystemInfo
GlobalFree
LoadLibraryExW
VirtualQuery
FreeLibrary
RaiseException
FindFirstFileExW
SetFileInformationByHandle
GetFileInformationByHandle
GetFileInformationByHandleEx
FlushFileBuffers
GetModuleFileNameW
GetTempPathW
SetHandleInformation
DeleteFileW
GetFinalPathNameByHandleW
SetFileAttributesW
MoveFileExW
CreateSymbolicLinkW
CompareStringOrdinal
SleepEx
SetWaitableTimer
ExitProcess
TerminateProcess
GetExitCodeProcess
GetSystemDirectoryW
GetWindowsDirectoryW
GetFileAttributesW
DuplicateHandle
WaitForMultipleObjects
FindNextFileW
VirtualAlloc
MultiByteToWideChar
FlsSetValue
GlobalUnlock
VirtualFree
SetThreadStackGuarantee
FlsFree
EncodePointer
LoadLibraryExA
FormatMessageW
GetLastError
FlsAlloc
HeapAlloc
HeapFree
GetProcessHeap
MapViewOfFile
UnmapViewOfFile
lstrlenW
WideCharToMultiByte
ReleaseMutex
GetCurrentProcess
GetProcAddress
LoadLibraryA
WaitForSingleObjectEx
GlobalSize
CreateProcessW
CloseHandle
CancelIo
CreateWaitableTimerExW
ReadFileEx
WriteFileEx
CreateThread
DeviceIoControl
CreateHardLinkW
GetModuleHandleA
CreateDirectoryW
WriteConsoleW
GetConsoleOutputCP
GetConsoleMode
GetStdHandle
Sleep
GetSystemTimeAsFileTime
SleepConditionVariableSRW
SetFilePointerEx
GetUserPreferredUILanguages
CreateFileMappingW
WaitForSingleObject
WakeAllConditionVariable
SetFileTime
SetNamedPipeHandleState
GetComputerNameExW
CreateFileW
SwitchToThread
GetProcessId
GetSystemTimePreciseAsFileTime
SetFileCompletionNotificationModes
FlsGetValue
GetCurrentThreadId
GetSystemInfo
LCIDToLocaleName
GetUserDefaultUILanguage
CreatePipe
CreateMutexW
TerminateJobObject
VirtualProtect
VirtualLock
VirtualUnlock
InitializeSRWLock
ReleaseSRWLockExclusive
ReleaseSRWLockShared
AcquireSRWLockExclusive
AcquireSRWLockShared
InitOnceExecuteOnce
TlsAlloc
TlsGetValue
TlsSetValue
OutputDebugStringA
OutputDebugStringW
AssignProcessToJobObject
RtlPcToFileHeader
SetInformationJobObject
CreateJobObjectW
GlobalLock
GetModuleHandleW
GlobalAlloc
CopyFileExW
FindClose
CreateEventW
LoadLibraryW
SetLastError
CreateMutexA
GetCurrentProcessId
CancelIoEx
HeapReAlloc
RtlVirtualUnwind
CreateIoCompletionPort
GetQueuedCompletionStatusEx
ReadFile
RtlLookupFunctionEntry
RtlCaptureContext
GetCurrentThread
GetFullPathNameW
GetOverlappedResult
WriteFile
PostQueuedCompletionStatus
advapi32.dll RegDeleteValueW
RegSetValueExW
RegQueryValueExW
RegCloseKey
RegGetValueW
ImpersonateAnonymousToken
RevertToSelf
SystemFunction036
CredReadW
CredFree
CredDeleteW
RegOpenKeyExW
CredWriteW
oleaut32.dll GetErrorInfo
SysStringLen
SetErrorInfo
SysFreeString
ntdll.dll NtCancelIoFileEx
NtCreateNamedPipeFile
NtDeviceIoControlFile
NtCreateFile
NtWriteFile
NtOpenFile
NtReadFile
RtlNtStatusToDosError
RtlGetVersion
user32.dll FlashWindowEx
RegisterClipboardFormatW
GetClipboardData
CloseClipboard
OpenClipboard
RegisterTouchWindow
IsWindow
IsWindowEnabled
IsIconic
IsWindowVisible
EnableWindow
SetPropW
GetKeyboardState
SetCursorPos
GetWindow
SetFocus
DefWindowProcW
GetAsyncKeyState
SetWindowTextW
SetParent
GetWindowTextLengthW
RegisterHotKey
SetWindowDisplayAffinity
InvalidateRect
MonitorFromRect
ToUnicodeEx
MapVirtualKeyExW
GetKeyboardLayout
ClipCursor
GetClipCursor
UpdateWindow
SystemParametersInfoW
GetKeyState
SetWindowLongW
SetCursor
GetMonitorInfoW
GetWindowPlacement
SetWindowPlacement
ChangeDisplaySettingsExW
RegisterRawInputDevices
AdjustWindowRectEx
GetMenu
GetWindowLongW
InvalidateRgn
ReleaseCapture
ScreenToClient
SetCapture
GetTouchInputInfo
RegisterWindowMessageA
GetSystemMetrics
FindWindowExW
CloseTouchInputHandle
GetForegroundWindow
IsClipboardFormatAvailable
UnregisterHotKey
FindWindowW
TranslateAcceleratorW
ChangeWindowMessageFilterEx
RegisterClassW
TrackMouseEvent
MsgWaitForMultipleObjectsEx
DispatchMessageW
MapVirtualKeyW
GetUpdateRect
PeekMessageW
PostThreadMessageW
ValidateRect
GetRawInputData
GetMessageW
SetWindowLongPtrW
DestroyWindow
GetSystemMenu
GetParent
LoadCursorW
EnumChildWindows
DispatchMessageA
TranslateMessage
GetMessageA
SetWindowPos
CreateWindowExW
RegisterClassExW
SetClipboardData
GetWindowLongPtrW
RedrawWindow
AdjustWindowRect
EnumDisplayMonitors
MonitorFromPoint
EmptyClipboard
SetWindowRgn
KillTimer
SetTimer
ShowCursor
GetWindowTextW
IsProcessDPIAware
MonitorFromWindow
TrackPopupMenu
SetForegroundWindow
ClientToScreen
GetCursorPos
EnableMenuItem
DrawIconEx
GetDC
VkKeyScanW
AppendMenuW
InsertMenuW
SendInput
CheckMenuItem
DrawTextW
ReleaseDC
FillRect
GetWindowDC
OffsetRect
GetWindowRect
MapWindowPoints
GetClientRect
GetMenuBarInfo
GetMenuItemInfoW
ShowWindow
SendMessageW
PostQuitMessage
SystemParametersInfoA
PostMessageW
GetActiveWindow
SetMenu
RemoveMenu
CreateIcon
SetMenuItemInfoW
DrawMenuBar
CreatePopupMenu
CreateMenu
CreateAcceleratorTableW
DestroyAcceleratorTable
DestroyIcon
DestroyMenu
gdi32.dll CombineRgn
BitBlt
CreateSolidBrush
GetDeviceCaps
DeleteDC
SelectObject
CreateRectRgn
CreateDIBSection
CreateCompatibleDC
SetBkMode
DeleteObject
SetTextColor
shell32.dll DragQueryFileW
ILFree
DragFinish
SHAppBarMessage
ShellExecuteExW
SHCreateItemFromParsingName
ShellExecuteW
SHGetKnownFolderPath
SHOpenFolderAndSelectItems
Shell_NotifyIconGetRect
Shell_NotifyIconW
ILCreateFromPathW
ole32.dll RegisterDragDrop
CoIncrementMTAUsage
RevokeDragDrop
CoTaskMemFree
CoCreateFreeThreadedMarshaler
CoTaskMemAlloc
CoInitializeEx
OleInitialize
CoInitialize
CoCreateInstance
CoUninitialize
api-ms-win-core-synch-l1-2-0.dll WakeByAddressSingle
WaitOnAddress
WakeByAddressAll
comctl32.dll RemoveWindowSubclass
TaskDialogIndirect
SetWindowSubclass
DefSubclassProc
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory
shlwapi.dll SHCreateMemStream
dwmapi.dll DwmSetWindowAttribute
DwmGetWindowAttribute
DwmEnableBlurBehindWindow
bcryptprimitives.dll ProcessPrng
bcrypt.dll BCryptGenRandom
ws2_32.dll WSASend
shutdown
send
freeaddrinfo
getaddrinfo
WSACleanup
WSAStartup
setsockopt
bind
getsockname
connect
ioctlsocket
WSASocketW
recv
closesocket
getsockopt
WSAIoctl
getpeername
WSAGetLastError
crypt32.dll CertDuplicateCertificateContext
CertCloseStore
CertVerifyCertificateChainPolicy
CertDuplicateCertificateChain
CertDuplicateStore
CertCreateCertificateChainEngine
CertOpenStore
CertEnumCertificatesInStore
CertFreeCertificateContext
CertAddEncodedCertificateToStore
CertAddCertificateContextToStore
CertFreeCertificateChain
CertGetCertificateChain
CertSetCertificateContextProperty
CertFreeCertificateChainEngine
secur32.dll ApplyControlToken
DecryptMessage
FreeCredentialsHandle
QueryContextAttributesW
InitializeSecurityContextW
AcquireCredentialsHandleA
EncryptMessage
AcceptSecurityContext
FreeContextBuffer
DeleteSecurityContext
KERNEL32.dll LeaveCriticalSection
RtlUnwindEx
InitializeSListHead
AddVectoredExceptionHandler
InitializeCriticalSectionEx
GetCurrentDirectoryW
GetEnvironmentVariableW
GetCommandLineW
QueryPerformanceFrequency
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
InitializeCriticalSection
EnterCriticalSection
SetEnvironmentVariableW
SetUnhandledExceptionFilter
DeleteCriticalSection
ADVAPI32.dll EventSetInformation
EventRegister
EventWriteTransfer
EventUnregister
PSAPI.DLL GetModuleFileNameExW
GetModuleInformation
EnumProcessModules
api-ms-win-crt-runtime-l1-1-0.dll _wassert
strerror
_errno
terminate
abort
_crt_atexit
exit
_register_onexit_function
_initialize_onexit_table
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
_c_exit
_cexit
__p___argv
__p___argc
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_exit
_initterm_e
_initterm
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
wcscmp
strcmp
wcslen
strlen
strcpy_s
api-ms-win-crt-math-l1-1-0.dll ceil
floor
round
__setusermatherr
roundf
pow
fmod
trunc
api-ms-win-crt-heap-l1-1-0.dll calloc
realloc
_set_new_mode
free
malloc
_callnewh
api-ms-win-crt-convert-l1-1-0.dll strtol
_ultow_s
wcstol
_wtoi
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-stdio-l1-1-0.dll feof
_set_fmode
ferror
fgets
__acrt_iob_func
fopen
__stdio_common_vfprintf
__stdio_common_vsprintf
__p__commode
_fileno
fread
fseek
__stdio_common_vsscanf
ftell
fwrite
fflush
_setmode
fclose
api-ms-win-crt-utility-l1-1-0.dll _rotl64
bsearch
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

aws_lc_0_41_0_jent_entropy_collector_alloc

Ordinal 1
Address 0x73f260

aws_lc_0_41_0_jent_entropy_collector_free

Ordinal 2
Address 0x73f2e0

aws_lc_0_41_0_jent_entropy_init

Ordinal 3
Address 0x73f360

aws_lc_0_41_0_jent_entropy_init_ex

Ordinal 4
Address 0x73f3a0

aws_lc_0_41_0_jent_entropy_switch_notime_impl

Ordinal 5
Address 0x73f430

aws_lc_0_41_0_jent_read_entropy

Ordinal 6
Address 0x73eda0

aws_lc_0_41_0_jent_read_entropy_safe

Ordinal 7
Address 0x73ef50

aws_lc_0_41_0_jent_set_fips_failure_callback

Ordinal 8
Address 0x73f400

aws_lc_0_41_0_jent_version

Ordinal 9
Address 0x73f420

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87168
Detected Filetype PNG graphic file
MD5 f3b90ca96ac5121174d64ccbd2938279 🔍
SHA1 a8e898906ab44b1bd1ef87318a46c304a925ad0a 🔍
SHA256 69dd387a2c1f186b2e377e9e93af40016d5abde757eb5d21113ed6cc3f00ecfb 🔍
SHA3 5b34242abccc8e584233bfb2fd9ccae67dfc3215ada2791b2e40065adf15a259 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2fb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67194
Detected Filetype PNG graphic file
MD5 89c01ce5218dc817ba9af410ec02e8b0 🔍
SHA1 9bfb0a35e5fa15d2c06ce7d3b6a70fa5dfe42b30 🔍
SHA256 8504a723782c4f8917497c8aabef542563815b033eda2092fac8847a29627466 🔍
SHA3 d650c7264d402643b8871fec9cb594665cd5dbfecfb1956d3303da2986610564 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5b5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.79417
Detected Filetype PNG graphic file
MD5 9fb203c0a1ea7a58640f9abf33c4b450 🔍
SHA1 98975d5df0426822ea1bb9105fa040830fcdef12 🔍
SHA256 0f118127376dae7651f857ad66d9e8b2129b391a931b6b1bf6d4f8603c1b3b3b 🔍
SHA3 4ff955838b9047ff3b4922f3322c9a0e82e5771d7d18a132e4e0a3bb59e81c9d 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1039
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90954
Detected Filetype PNG graphic file
MD5 513e018df5ed816084efc04ac7b8d8ca 🔍
SHA1 24c4d399201cf4080bec30e976eb928317c3df18 🔍
SHA256 a52c6b338bc3abc71172bfef892294ef93281cf20c58dc1dcc7660089fda6ba6 🔍
SHA3 ecdd106f887a60b442012b700f99f08557cd3984d1cfc34ed5747a2f9d1f4e30 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1763
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.841
Detected Filetype PNG graphic file
MD5 0c0bc93f165fa87108aecf097cece6dd 🔍
SHA1 9a9c8bb16fce8ab45f78c6280b69ccdf946d9501 🔍
SHA256 177cb8331c24cebbbfa9293eacac5e16353a70b20feebd703a14025a2419cda9 🔍
SHA3 f0e8341a6d6f986831d36ce60e8175f1c584ec72a8e21747ef241e2b9743164f 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x9641
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97869
Detected Filetype PNG graphic file
MD5 34a38487ddcf1ec6fa7b95680f6ed1c4 🔍
SHA1 bfbc2f208c8070c10290d1348a1154ab3906bcb2 🔍
SHA256 188992cbe106d0dd6e7b9c219020118a1246c3657c828f86e463617c3d6214cb 🔍
SHA3 45eab3adfb04edc917dae376cda5f3c87678a66f9bad676752f28fc5eb155d1b 🔍

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79371
Detected Filetype Icon file
MD5 4339523965ebd407e460bda96a6a18cc 🔍
SHA1 789f3e3104b98000596771bee5556231eb9f22fa 🔍
SHA256 87715bcc1151583ff493d35f3ef7751e71a1594fc4fc8bbd1c5800d5a61e82f2 🔍
SHA3 37795139853547a5e10970bb4443b331a254919e4aa3f8810ed5f7e5d6911b2a 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28404
MD5 a7af1cb3070299bc939d55de85ba64d0 🔍
SHA1 2c06453c4b098a9ffe666f291ef0edd24afecb24 🔍
SHA256 13e0d098ab6af6017fea467e59a9afef778639212817a27e539d701ccc009195 🔍
SHA3 c39626340b3870c47f41c8ae038247705fdf04e0374f3d3cd7f95d6289bebaa6 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7 🔍
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9 🔍
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8 🔍
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.2.1.0
ProductVersion 3.2.1.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName jelleglebbeek
FileDescription Open Video Downloader
FileVersion (#2) 3.2.1
ProductName Open Video Downloader
ProductVersion (#2) 3.2.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-05 10:53:01
Version 0.0
SizeofData 50
AddressOfRawData 0xa736b4
PointerToRawData 0xa724b4
Referenced File open_video_downloader.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-05 10:53:01
Version 0.0
SizeofData 20
AddressOfRawData 0xa736e8
PointerToRawData 0xa724e8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-05 10:53:01
Version 0.0
SizeofData 1084
AddressOfRawData 0xa736fc
PointerToRawData 0xa724fc

TLS Callbacks

StartAddressOfRawData 0x140a73b80
EndAddressOfRawData 0x140a73ec4
AddressOfIndex 0x140a93e1c
AddressOfCallbacks 0x140792098
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001405899F0
0x0000000140739A60

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140a8e680

RICH Header

XOR Key 0xd171395a
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35721) 10
C objects (35721) 14
C++ objects (35721) 46
Imports (33145) 7
C objects (36248) 87
C objects (35228) 39
Total imports 500
Unmarked objects (#2) 94
Exports (36248) 1
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.