MZ Header

DOS stub

00000000: 0e 1f 66 ba 0e 00 b4 09  cd 21 b4 00 cd 21 54 68  |..f......!...!Th|
00000010: 69 73 20 69 73 20 61 20  57 69 6e 64 6f 77 73 20  |is is a Windows |
00000020: 70 72 6f 67 72 61 6d 2c  20 79 6f 75 20 63 61 6e  |program, you can|
00000030: 6e 6f 74 20 72 75 6e 20  69 74 20 69 6e 20 44 4f  |not run it in DO|
00000040: 53 2e 5c 72 5c 6e 24 51  6c 66 90 51 6c 66 90 51  |S.\r\n$Qlf.Qlf.Q|

PE Header

Packer / Compiler

Sections

Data Directory

TLS

StringTable 040904b0

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 Code Signing 2010 CA
serial: 4C40DBA5F988FAE57A57D6457495F98B

Certificates (3)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            16:88:f0:39:25:5e:63:8e:69:14:39:07:e6:33:0b
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
        Validity
            Not Before: Dec 31 00:00:00 2015 GMT
            Not After : Jul  9 18:40:36 2019 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO SHA-1 Time Stamping Signer
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e9:e9:3d:df:d7:37:08:c9:1e:38:b2:52:53:42:
                    6d:22:f1:b1:c4:06:04:6b:9e:fd:82:74:50:43:7d:
                    c6:a0:bb:1f:4e:f9:02:71:26:b1:ef:43:d8:83:8c:
                    48:fc:e7:0f:97:7a:9a:eb:9c:de:a6:a3:0e:3b:1c:
                    44:18:75:8e:78:a5:17:69:fe:49:18:a4:e2:bb:5c:
                    4e:fe:8e:2a:54:7a:50:f0:d5:f6:cc:91:e7:99:79:
                    d7:de:79:94:d7:96:33:fe:0e:83:be:22:bf:63:16:
                    2c:a3:dd:28:1b:af:3d:ab:ea:97:d2:f1:bf:04:10:
                    e7:3d:48:45:fd:1f:68:65:c1:7f:59:99:69:c0:22:
                    31:0c:62:6e:a7:5c:65:01:21:b0:63:c4:22:18:27:
                    ee:e6:fc:d2:00:3d:47:2e:a8:b8:86:56:5d:04:dc:
                    13:17:25:6e:1c:df:44:0f:15:cd:b7:db:a5:57:76:
                    42:6f:00:68:82:99:d2:e3:c1:de:f0:8b:94:57:4c:
                    ec:08:90:22:21:ce:22:2b:98:0c:42:e6:42:93:94:
                    98:93:ef:fd:06:d9:3f:bc:5b:9b:54:3c:20:b1:ee:
                    6a:d6:47:7a:c5:ab:80:e9:30:9a:de:f1:a4:3f:55:
                    4d:0a:09:34:8a:75:29:d2:69:ad:97:0f:50:bf:f8:
                    ca:09
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:DA:ED:64:74:14:9C:14:3C:AB:DD:99:A9:BD:5B:28:4D:8B:3C:C9:D8

            X509v3 Subject Key Identifier: 
                8E:6B:2D:33:6B:F4:33:A7:93:B3:13:9A:A5:E0:0A:F7:12:35:6A:88
            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: critical
                Time Stamping
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/UTN-USERFirst-Object.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: sha1WithRSAEncryption
         ba:33:24:40:40:8c:7c:db:58:9f:b3:60:98:b2:f5:c0:31:fe:
         eb:1f:6e:50:f6:0a:e0:e4:e6:81:ad:26:87:a2:df:fd:b3:da:
         f4:73:f3:00:fb:29:1b:89:1b:15:3e:db:6b:52:93:2b:c4:ac:
         39:81:d7:3c:67:57:9a:39:36:e0:28:08:9a:e3:39:4f:9b:89:
         09:7f:7b:c5:61:7f:59:89:32:25:0a:6a:ae:1a:3e:f0:a2:27:
         a8:b6:c3:b8:87:f7:16:04:48:41:3d:5c:d8:ec:9f:4d:20:31:
         04:d9:65:a1:ed:cd:69:07:53:16:3d:dd:36:02:0a:88:eb:40:
         e5:06:30:0b:b8:16:4b:dc:ef:bc:55:09:ff:c6:3e:12:2e:76:
         b3:dc:ce:42:ef:f9:76:57:e1:b7:0a:05:40:98:58:9a:5d:71:
         16:93:71:8c:65:81:ea:6f:f3:89:f7:fb:73:ad:b4:e7:bf:d9:
         8e:6f:aa:0b:4f:25:f3:b8:e1:d5:dd:75:98:68:81:f8:aa:c0:
         d1:80:c2:c4:c4:39:89:c1:f6:c9:9e:6c:d7:74:f9:d9:97:f8:
         4f:c2:9a:0a:cd:5e:8f:f8:19:e9:e0:a5:9f:c4:f0:92:21:e6:
         2d:79:25:c9:22:f9:c3:f0:3a:84:57:ad:3a:16:f4:63:94:10:
         1d:5d:d0:c6

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            4c:40:db:a5:f9:88:fa:e5:7a:57:d6:45:74:95:f9:8b
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
        Validity
            Not Before: Dec 14 00:00:00 2015 GMT
            Not After : Dec 14 23:59:59 2016 GMT
        Subject: C=US, ST=California, L=Mountain View, O=Google Inc, CN=Google Inc
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b7:c1:1e:ca:21:1c:a1:dc:c5:53:6c:39:ce:3d:
                    97:73:7d:48:5f:f3:54:b6:1d:d3:ab:f0:85:ff:3d:
                    a9:c4:16:96:e8:7c:e2:03:fe:37:6a:ae:d1:eb:f8:
                    c6:cb:c2:8c:f1:9d:02:88:62:88:1b:a9:c6:21:9b:
                    28:de:ac:55:6d:01:80:1d:be:b6:70:be:9e:7e:9f:
                    2f:57:da:0c:45:fa:6e:4a:b9:2b:52:a4:bf:92:67:
                    0e:fe:02:8b:7f:56:d7:37:9c:f8:ba:e9:6a:33:c3:
                    29:f2:f7:2d:99:17:91:31:50:97:5b:72:99:9c:91:
                    a4:4a:41:6e:73:b6:de:40:4a:74:86:0d:ad:71:71:
                    c1:bb:4f:27:05:ed:4d:44:ad:a7:6e:98:27:a8:b1:
                    65:4f:4d:24:79:e1:c1:70:3a:df:a6:48:25:37:f3:
                    33:2a:5b:3f:05:03:eb:ba:b6:be:72:6a:a2:04:a8:
                    c0:c5:a4:5c:9a:3e:4b:1d:74:46:ff:16:69:83:0a:
                    a2:85:90:0d:84:bd:a6:1b:55:a9:54:11:2a:dd:a7:
                    b8:b3:08:4b:2f:8a:a3:0e:3e:b7:0e:cd:00:9a:dd:
                    7e:52:6c:82:ec:04:38:32:15:15:ef:13:61:4a:13:
                    bc:f8:73:32:94:9c:5a:3c:31:7b:a6:04:23:3c:32:
                    89:61
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                Code Signing
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: https://d.symcb.com/cps
                  User Notice:
                    Explicit Text: https://d.symcb.com/rpa

            X509v3 Authority Key Identifier: 
                keyid:CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://sf.symcb.com/sf.crl

            Authority Information Access: 
                OCSP - URI:http://sf.symcd.com
                CA Issuers - URI:http://sf.symcb.com/sf.crt

            Netscape Cert Type: 
                Object Signing
            1.3.6.1.4.1.311.2.1.27: 
                0.......
    Signature Algorithm: sha1WithRSAEncryption
         55:7a:27:95:56:9a:85:c6:3c:e4:c6:c9:79:8f:11:6a:58:98:
         66:c8:1b:da:6b:db:a1:97:e9:f6:a8:ad:ba:96:d2:28:e5:54:
         65:f6:38:fc:a5:ba:b0:40:f1:7b:4f:f0:cd:6b:9e:85:ca:98:
         8e:c3:82:f3:71:61:8d:98:6b:88:b4:00:b8:74:6a:30:77:cc:
         7f:6d:25:4d:2d:14:57:5e:21:15:a3:2a:9d:d1:36:d9:89:1d:
         c9:c0:f4:a1:db:c0:ad:08:34:87:fb:24:32:cb:54:a6:59:db:
         1d:61:1f:45:db:09:9d:6c:e1:2b:7b:73:26:21:c0:43:16:0f:
         12:15:e0:4b:48:92:87:49:05:e9:8a:3f:36:f2:d4:97:f7:c0:
         a8:39:2e:f9:d4:92:ae:93:57:7e:30:18:11:2c:bb:3b:ae:ed:
         99:28:8c:bb:50:d4:a0:d2:98:c0:6d:10:62:39:d7:04:4a:90:
         d8:b6:25:92:31:c0:af:0c:61:57:d3:be:7e:be:a8:13:b0:41:
         66:fc:2e:69:07:a4:06:3e:7b:3a:89:bd:be:15:f1:9e:7f:2b:
         a0:32:da:c1:5c:57:e1:6e:34:94:11:73:24:86:9d:fa:d0:7b:
         57:c7:0d:8e:ab:60:f1:c1:10:90:cd:d4:fd:7c:56:1b:68:87:
         a1:2b:b2:82

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            52:00:e5:aa:25:56:fc:1a:86:ed:96:c9:d4:4b:33:c7
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
        Validity
            Not Before: Feb  8 00:00:00 2010 GMT
            Not After : Feb  7 23:59:59 2020 GMT
        Subject: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:f5:23:4b:5e:a5:d7:8a:bb:32:e9:d4:57:f7:ef:
                    e4:c7:26:7e:ad:19:98:fe:a8:9d:7d:94:f6:36:6b:
                    10:d7:75:81:30:7f:04:68:7f:cb:2b:75:1e:cd:1d:
                    08:8c:df:69:94:a7:37:a3:9c:7b:80:e0:99:e1:ee:
                    37:4d:5f:ce:3b:14:ee:86:d4:d0:f5:27:35:bc:25:
                    0b:38:a7:8c:63:9d:17:a3:08:a5:ab:b0:fb:cd:6a:
                    62:82:4c:d5:21:da:1b:d9:f1:e3:84:3b:8a:2a:4f:
                    85:5b:90:01:4f:c9:a7:76:10:7f:27:03:7c:be:ae:
                    7e:7d:c1:dd:f9:05:bc:1b:48:9c:69:e7:c0:a4:3c:
                    3c:41:00:3e:df:96:e5:c5:e4:94:71:d6:55:01:c7:
                    00:26:4a:40:3c:b5:a1:26:a9:0c:a7:6d:80:8e:90:
                    25:7b:cf:bf:3f:1c:eb:2f:96:fa:e5:87:77:c6:b5:
                    56:b2:7a:3b:54:30:53:1b:df:62:34:ff:1e:d1:f4:
                    5a:93:28:85:e5:4c:17:4e:7e:5b:fd:a4:93:99:7f:
                    df:cd:ef:a4:75:ef:ef:15:f6:47:e7:f8:19:72:d8:
                    2e:34:1a:a6:b4:a7:4c:7e:bd:bb:4f:0c:3d:57:f1:
                    30:d6:a6:36:8e:d6:80:76:d7:19:2e:a5:cd:7e:34:
                    2d:89
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: https://www.verisign.com/cps
                  User Notice:
                    Explicit Text: https://www.verisign.com/rpa

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            1.3.6.1.5.5.7.1.12: 
                0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.verisign.com/pca3-g5.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.verisign.com

            X509v3 Extended Key Usage: 
                TLS Web Client Authentication, Code Signing
            X509v3 Subject Alternative Name: 
                DirName:/CN=VeriSignMPKI-2-8
            X509v3 Subject Key Identifier: 
                CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D
            X509v3 Authority Key Identifier: 
                keyid:7F:D3:65:A7:C2:DD:EC:BB:F0:30:09:F3:43:39:FA:02:AF:33:31:33

    Signature Algorithm: sha1WithRSAEncryption
         56:22:e6:34:a4:c4:61:cb:48:b9:01:ad:56:a8:64:0f:d9:8c:
         91:c4:bb:cc:0c:e5:ad:7a:a0:22:7f:df:47:38:4a:2d:6c:d1:
         7f:71:1a:7c:ec:70:a9:b1:f0:4f:e4:0f:0c:53:fa:15:5e:fe:
         74:98:49:24:85:81:26:1c:91:14:47:b0:4c:63:8c:bb:a1:34:
         d4:c6:45:e8:0d:85:26:73:03:d0:a9:8c:64:6d:dc:71:92:e6:
         45:05:60:15:59:51:39:fc:58:14:6b:fe:d4:a4:ed:79:6b:08:
         0c:41:72:e7:37:22:06:09:be:23:e9:3f:44:9a:1e:e9:61:9d:
         cc:b1:90:5c:fc:3d:d2:8d:ac:42:3d:65:36:d4:b4:3d:40:28:
         8f:9b:10:cf:23:26:cc:4b:20:cb:90:1f:5d:8c:4c:34:ca:3c:
         d8:e5:37:d6:6f:a5:20:bd:34:eb:26:d9:ae:0d:e7:c5:9a:f7:
         a1:b4:21:91:33:6f:86:e8:58:bb:25:7c:74:0e:58:fe:75:1b:
         63:3f:ce:31:7c:9b:8f:1b:96:9e:c5:53:76:84:5b:9c:ad:91:
         fa:ac:ed:93:ba:5d:c8:21:53:c2:82:53:63:af:12:0d:50:87:
         11:1b:3d:54:52:96:8a:2c:9c:3d:92:1a:08:9a:05:2e:c7:93:
         a5:48:91:d3

Cannot convert into OpenSSL::BN

offsetsizetypecomment
1c53680122HTM#
1c53ff0203HTM#
1c580d8155HTM#
1ccadbe66322HTM#
1ce4c3f16929HTM#
1d65287404HTM#
1e2a9789642HTM#
1e2ac047657GIF(0 x 18759)#
1f79a6f134HTM#
2083ad024935PNG(256 x 256)#
208f41020818PNG(256 x 256)#
20945621260342BINoverlay data past EOF#
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] ignoring invalid PEdump::BITMAPINFOHEADER

[?] can't find file_offset of VA 0x20a8dc0