MZ Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Sections

Data Directory

TLS

StringTable 040904b0

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Code Signing CA
serial: BD974BF9009DBC3184CB6C9FEA31A2E4

Certificates (5)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            bd:97:4b:f9:00:9d:bc:31:84:cb:6c:9f:ea:31:a2:e4
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Code Signing CA
        Validity
            Not Before: Jan 10 00:00:00 2019 GMT
            Not After : Jan 10 23:59:59 2020 GMT
        Subject: C=AU/postalCode=4212, ST=Queensland, L=Helensvale TC/street=PO Box 3852/postOfficeBox=3852, O=Velocidex Innovations, CN=Velocidex Innovations
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:ce:c9:88:9b:ee:71:1a:52:68:30:1c:b0:7d:f4:
                    a0:f7:33:d1:80:13:2f:78:88:1b:eb:95:76:97:fd:
                    be:c6:38:0b:64:f0:8b:01:7b:9e:7e:38:85:ba:ea:
                    fb:ac:1c:34:19:6e:43:ef:c8:21:2e:06:0b:54:f5:
                    40:0e:02:f2:f7:db:e9:b2:d7:3f:c6:8d:02:de:47:
                    79:65:74:7d:ef:b7:5f:a0:cf:7c:45:ec:0f:2d:6e:
                    6c:71:32:03:c3:4d:9e:02:8c:51:4e:e2:d4:a4:6f:
                    af:bf:03:25:67:de:0f:66:d3:67:d6:df:83:e3:44:
                    4a:7b:66:9d:e7:eb:e1:2a:92:8d:9a:3a:f7:26:b8:
                    c0:f6:33:8a:47:d6:3d:a7:c3:8f:7a:2b:e0:fc:c2:
                    50:77:86:cf:00:26:e5:f9:a3:cf:ff:fa:16:05:53:
                    16:51:28:88:4b:bd:ce:4e:65:93:5e:4b:0a:21:4e:
                    34:23:4c:f3:01:96:ff:4e:60:c1:78:68:cd:d9:c5:
                    c7:81:ae:89:6c:2a:78:6a:d2:64:de:25:5c:ae:a8:
                    23:2a:8f:c1:87:f4:eb:3a:24:45:1b:38:58:25:99:
                    8b:70:50:96:f1:ea:a6:b4:a4:48:8e:71:c4:ba:4a:
                    e1:bb:e4:53:3e:a1:1c:8b:19:cb:b4:7a:9f:03:4e:
                    c7:6f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:29:91:60:FF:8A:4D:FA:EB:F9:A6:6A:B8:CF:F9:E6:4B:BD:49:CE:12

            X509v3 Subject Key Identifier: 
                ED:DB:F1:2B:12:32:5E:7D:D5:5C:70:57:83:DF:B3:F0:53:05:A2:28
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: 
                Code Signing
            Netscape Cert Type: 
                Object Signing
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.6449.1.2.1.3.2
                  CPS: https://secure.comodo.net/CPS

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.comodoca.com/COMODORSACodeSigningCA.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.comodoca.com/COMODORSACodeSigningCA.crt
                OCSP - URI:http://ocsp.comodoca.com

            X509v3 Subject Alternative Name: 
                email:support@velocidex.com
    Signature Algorithm: sha256WithRSAEncryption
         a1:6b:93:f4:39:23:94:1d:39:1c:3b:f9:0a:1e:8c:c4:6c:0a:
         53:f8:f9:d5:fb:e3:99:d5:f8:13:b8:05:e2:86:09:65:85:25:
         d6:6d:4a:63:f9:0d:8c:78:cc:6e:f0:99:ee:95:38:3c:33:15:
         71:b6:8a:af:f0:e9:d0:83:cf:b8:bc:53:e8:ae:a5:8d:85:41:
         d0:28:91:96:e7:13:e4:89:88:9a:bc:c9:34:00:65:23:fb:d2:
         8c:a7:ec:3e:b9:79:7b:f2:8e:08:e7:f9:1e:5b:33:ae:b6:51:
         6a:9f:0b:7b:3e:d0:73:a4:de:a9:b3:7d:0a:17:f7:42:bb:14:
         1d:05:a2:92:d7:23:63:88:83:2b:70:cb:cb:1c:fd:59:46:03:
         a5:c2:6d:92:6d:0f:ad:f5:58:f2:ef:3e:f5:db:5a:46:c4:85:
         88:2a:e7:84:a4:62:c2:f1:89:b5:9d:77:da:f4:3b:6f:1e:9f:
         5e:b2:98:72:63:5d:62:f4:10:ee:71:7f:1a:4b:08:41:3f:b5:
         d7:29:2a:2e:47:0a:0f:a9:41:0f:35:e8:1b:1f:d5:dd:60:c5:
         21:58:1a:b4:fe:2b:0c:45:db:e6:36:9d:32:b5:fc:c7:d0:82:
         07:cd:0c:e1:38:53:f0:94:31:de:8b:2f:4f:e6:31:08:d7:be:
         0d:96:d6:55

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            2e:7c:87:cc:0e:93:4a:52:fe:94:fd:1c:b7:cd:34:af
        Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
        Validity
            Not Before: May  9 00:00:00 2013 GMT
            Not After : May  8 23:59:59 2028 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Code Signing CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a6:98:90:63:77:91:34:7f:8a:d1:dd:e9:67:31:
                    11:eb:cc:1e:fd:31:1d:b3:b9:62:57:3f:93:bc:5b:
                    e3:9f:1e:24:32:11:27:6b:bc:51:91:a7:cf:9e:9e:
                    25:b3:5f:81:a8:18:0f:1d:1e:20:30:0e:fb:61:7b:
                    86:09:b3:e3:fd:a2:68:9d:1c:2c:9d:bf:72:e3:e4:
                    75:a0:e5:35:23:8e:c9:8a:ee:1a:0c:64:c7:d8:42:
                    a1:7b:b5:52:03:4b:3a:b0:8e:23:4b:4b:63:e0:22:
                    94:37:7b:d5:79:90:0a:14:18:51:2c:e6:fe:c1:12:
                    f0:1c:3f:61:61:0a:8c:a2:dc:f6:c3:30:aa:cd:28:
                    18:75:48:c1:79:5a:08:cd:bb:8c:55:8c:f7:d4:76:
                    90:3a:33:46:50:73:98:5c:f4:85:4a:6b:0f:80:dd:
                    5e:d6:bd:fd:a9:2f:c0:25:f5:f9:78:d7:8d:5f:10:
                    c2:44:55:3c:90:3c:31:46:cb:70:ae:07:a9:0a:e3:
                    af:c1:01:6f:90:1a:23:e2:5f:38:db:c6:08:5d:47:
                    b3:83:41:f0:2e:00:37:14:b9:12:aa:79:92:52:cd:
                    87:0f:7b:d8:62:29:a4:7e:30:bd:1b:b5:8c:72:b4:
                    48:f2:e3:e8:21:f9:5e:4c:62:79:8b:02:06:9f:7f:
                    d5:0b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:BB:AF:7E:02:3D:FA:A6:F1:3C:84:8E:AD:EE:38:98:EC:D9:32:32:D4

            X509v3 Subject Key Identifier: 
                29:91:60:FF:8A:4D:FA:EB:F9:A6:6A:B8:CF:F9:E6:4B:BD:49:CE:12
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                Code Signing
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.comodoca.com/COMODORSACertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.comodoca.com/COMODORSAAddTrustCA.crt
                OCSP - URI:http://ocsp.comodoca.com

    Signature Algorithm: sha384WithRSAEncryption
         02:3f:02:39:c3:ee:f8:ca:3b:89:de:0c:6d:4d:b1:f1:4e:92:
         4f:af:c2:38:2c:04:cc:c5:63:11:ab:09:63:af:ab:a2:d7:02:
         3f:cc:6f:19:c3:3d:d6:1a:08:94:ff:25:d8:a9:88:a7:2b:10:
         1a:e0:9b:b1:07:22:1a:51:1c:3a:d4:e1:e9:09:bf:e6:24:74:
         af:1e:7b:16:31:6e:23:ef:54:51:2d:52:02:e2:75:08:05:4c:
         f1:b7:51:e1:51:00:c6:87:f6:6c:ee:10:44:76:57:6a:f1:df:
         58:6b:21:aa:49:d4:7c:37:4e:bd:ff:b6:75:54:40:18:36:57:
         67:11:cd:4f:02:e4:fe:f3:da:fc:75:17:db:ec:b7:f7:65:09:
         23:49:1f:43:57:83:ea:7e:20:77:61:c8:4d:f2:bb:65:4d:a8:
         f7:85:45:07:af:7a:69:27:65:90:29:40:8b:df:7b:3a:51:39:
         8c:a8:1f:70:79:ad:6d:42:20:a2:cf:0c:6c:03:8c:4c:cd:73:
         07:94:e7:5a:8e:3a:04:ba:a2:a1:7c:1f:cb:63:3a:15:a7:d4:
         15:1b:a7:52:47:32:a9:f4:bf:64:47:d1:aa:1f:53:4e:32:30:
         73:c2:6f:b7:78:82:9d:5c:ff:46:bb:6b:22:1d:88:0b:f8:1b:
         aa:34:a6:fc:8c:f5:dd:7f:65:8c:8c:31:57:31:d0:36:ec:47:
         a1:cf:cb:8b:a8:ef:1c:18:58:c5:06:77:ca:4b:9b:51:af:4c:
         08:4a:7a:8f:e2:a3:52:e2:8e:8e:cc:26:e4:b2:d8:e5:38:c2:
         a8:ed:c6:81:9c:35:6b:a9:58:61:4a:0a:97:b4:4b:42:b6:55:
         9d:be:99:e7:70:6d:59:f8:6d:2a:0c:7f:19:60:5f:0c:9a:88:
         6c:30:ac:52:09:90:16:1b:ff:2b:9d:db:d0:20:ca:89:ea:28:
         7e:32:8e:19:df:7b:48:33:1e:d7:65:f8:ae:c9:f8:83:14:93:
         76:7d:64:d0:8e:ce:be:35:7d:ff:72:31:4d:9f:9e:bd:1e:6c:
         2f:a8:8f:0c:06:50:fb:8c:27:b3:76:c9:f4:e6:d7:c3:34:e2:
         8c:87:21:86:61:fe:bf:55:74:e1:21:77:03:0a:68:6c:bb:e4:
         c9:a9:e6:cf:59:25:eb:7c:ec:45:0e:79:66:68:e8:22:cd:b8:
         ef:98:85:4d:96:11:3c:09:8a:d0:7f:bc:28:28:13:fb:6a:ca:
         54:8d:92:5c:cd:c2:65:98:06:9e:ce:48:5b:d4:b5:37:93:46:
         41:7c:07:dd:cf:fa:43:ef:ba:67:61:ff:7d:49:e0:bb:30:7d:
         5c:80:e3:e6:16:39:4b:a7

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            4c:aa:f9:ca:db:63:6f:e0:1f:f7:4e:d8:5b:03:86:9d
        Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
        Validity
            Not Before: Jan 19 00:00:00 2010 GMT
            Not After : Jan 18 23:59:59 2038 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:91:e8:54:92:d2:0a:56:b1:ac:0d:24:dd:c5:cf:
                    44:67:74:99:2b:37:a3:7d:23:70:00:71:bc:53:df:
                    c4:fa:2a:12:8f:4b:7f:10:56:bd:9f:70:72:b7:61:
                    7f:c9:4b:0f:17:a7:3d:e3:b0:04:61:ee:ff:11:97:
                    c7:f4:86:3e:0a:fa:3e:5c:f9:93:e6:34:7a:d9:14:
                    6b:e7:9c:b3:85:a0:82:7a:76:af:71:90:d7:ec:fd:
                    0d:fa:9c:6c:fa:df:b0:82:f4:14:7e:f9:be:c4:a6:
                    2f:4f:7f:99:7f:b5:fc:67:43:72:bd:0c:00:d6:89:
                    eb:6b:2c:d3:ed:8f:98:1c:14:ab:7e:e5:e3:6e:fc:
                    d8:a8:e4:92:24:da:43:6b:62:b8:55:fd:ea:c1:bc:
                    6c:b6:8b:f3:0e:8d:9a:e4:9b:6c:69:99:f8:78:48:
                    30:45:d5:ad:e1:0d:3c:45:60:fc:32:96:51:27:bc:
                    67:c3:ca:2e:b6:6b:ea:46:c7:c7:20:a0:b1:1f:65:
                    de:48:08:ba:a4:4e:a9:f2:83:46:37:84:eb:e8:cc:
                    81:48:43:67:4e:72:2a:9b:5c:bd:4c:1b:28:8a:5c:
                    22:7b:b4:ab:98:d9:ee:e0:51:83:c3:09:46:4e:6d:
                    3e:99:fa:95:17:da:7c:33:57:41:3c:8d:51:ed:0b:
                    b6:5c:af:2c:63:1a:df:57:c8:3f:bc:e9:5d:c4:9b:
                    af:45:99:e2:a3:5a:24:b4:ba:a9:56:3d:cf:6f:aa:
                    ff:49:58:be:f0:a8:ff:f4:b8:ad:e9:37:fb:ba:b8:
                    f4:0b:3a:f9:e8:43:42:1e:89:d8:84:cb:13:f1:d9:
                    bb:e1:89:60:b8:8c:28:56:ac:14:1d:9c:0a:e7:71:
                    eb:cf:0e:dd:3d:a9:96:a1:48:bd:3c:f7:af:b5:0d:
                    22:4c:c0:11:81:ec:56:3b:f6:d3:a2:e2:5b:b7:b2:
                    04:22:52:95:80:93:69:e8:8e:4c:65:f1:91:03:2d:
                    70:74:02:ea:8b:67:15:29:69:52:02:bb:d7:df:50:
                    6a:55:46:bf:a0:a3:28:61:7f:70:d0:c3:a2:aa:2c:
                    21:aa:47:ce:28:9c:06:45:76:bf:82:18:27:b4:d5:
                    ae:b4:cb:50:e6:6b:f4:4c:86:71:30:e9:a6:df:16:
                    86:e0:d8:ff:40:dd:fb:d0:42:88:7f:a3:33:3a:2e:
                    5c:1e:41:11:81:63:ce:18:71:6b:2b:ec:a6:8a:b7:
                    31:5c:3a:6a:47:e0:c3:79:59:d6:20:1a:af:f2:6a:
                    98:aa:72:bc:57:4a:d2:4b:9d:bb:10:fc:b0:4c:41:
                    e5:ed:1d:3d:5e:28:9d:9c:cc:bf:b3:51:da:a7:47:
                    e5:84:53
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                BB:AF:7E:02:3D:FA:A6:F1:3C:84:8E:AD:EE:38:98:EC:D9:32:32:D4
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
    Signature Algorithm: sha384WithRSAEncryption
         0a:f1:d5:46:84:b7:ae:51:bb:6c:b2:4d:41:14:00:93:4c:9c:
         cb:e5:c0:54:cf:a0:25:8e:02:f9:fd:b0:a2:0d:f5:20:98:3c:
         13:2d:ac:56:a2:b0:d6:7e:11:92:e9:2e:ba:9e:2e:9a:72:b1:
         bd:19:44:6c:61:35:a2:9a:b4:16:12:69:5a:8c:e1:d7:3e:a4:
         1a:e8:2f:03:f4:ae:61:1d:10:1b:2a:a4:8b:7a:c5:fe:05:a6:
         e1:c0:d6:c8:fe:9e:ae:8f:2b:ba:3d:99:f8:d8:73:09:58:46:
         6e:a6:9c:f4:d7:27:d3:95:da:37:83:72:1c:d3:73:e0:a2:47:
         99:03:38:5d:d5:49:79:00:29:1c:c7:ec:9b:20:1c:07:24:69:
         57:78:b2:39:fc:3a:84:a0:b5:9c:7c:8d:bf:2e:93:62:27:b7:
         39:da:17:18:ae:bd:3c:09:68:ff:84:9b:3c:d5:d6:0b:03:e3:
         57:9e:14:f7:d1:eb:4f:c8:bd:87:23:b7:b6:49:43:79:85:5c:
         ba:eb:92:0b:a1:c6:e8:68:a8:4c:16:b1:1a:99:0a:e8:53:2c:
         92:bb:a1:09:18:75:0c:65:a8:7b:cb:23:b7:1a:c2:28:85:c3:
         1b:ff:d0:2b:62:ef:a4:7b:09:91:98:67:8c:14:01:cd:68:06:
         6a:63:21:75:03:80:88:8a:6e:81:c6:85:f2:a9:a4:2d:e7:f4:
         a5:24:10:47:83:ca:cd:f4:8d:79:58:b1:06:9b:e7:1a:2a:d9:
         9d:01:d7:94:7d:ed:03:4a:ca:f0:db:e8:a9:01:3e:f5:56:99:
         c9:1e:8e:49:3d:bb:e5:09:b9:e0:4f:49:92:3d:16:82:40:cc:
         cc:59:c6:e6:3a:ed:12:2e:69:3c:6c:95:b1:fd:aa:1d:7b:7f:
         86:be:1e:0e:32:46:fb:fb:13:8f:75:7f:4c:8b:4b:46:63:fe:
         00:34:40:70:c1:c3:b9:a1:dd:a6:70:e2:04:b3:41:bc:e9:80:
         91:ea:64:9c:7a:e1:22:03:a9:9c:6e:6f:0e:65:4f:6c:87:87:
         5e:f3:6e:a0:f9:75:a5:9b:40:e8:53:b2:27:9d:4a:b9:c0:77:
         21:8d:ff:87:f2:de:bc:8c:ef:17:df:b7:49:0b:d1:f2:6e:30:
         0b:1a:0e:4e:76:ed:11:fc:f5:e9:56:b2:7d:bf:c7:6d:0a:93:
         8c:a5:d0:c0:b6:1d:be:3a:4e:94:a2:d7:6e:6c:0b:c2:8a:7c:
         fa:20:f3:c4:e4:e5:cd:0d:a8:cb:91:92:b1:7c:85:ec:b5:14:
         69:66:0e:82:e7:cd:ce:c8:2d:a6:51:7f:21:c1:35:53:85:06:
         4a:5d:9f:ad:bb:1b:5f:74

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0e:cf:f4:38:c8:fe:bf:35:6e:04:d8:6a:98:1b:1a:50
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2
        Validity
            Not Before: Oct 18 00:00:00 2012 GMT
            Not After : Dec 29 23:59:59 2020 GMT
        Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer - G4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:a2:63:0b:39:44:b8:bb:23:a7:44:49:bb:0e:ff:
                    a1:f0:61:0a:53:93:b0:98:db:ad:2c:0f:4a:c5:6e:
                    ff:86:3c:53:55:0f:15:ce:04:3f:2b:fd:a9:96:96:
                    d9:be:61:79:0b:5b:c9:4c:86:76:e5:e0:43:4b:22:
                    95:ee:c2:2b:43:c1:9f:d8:68:b4:8e:40:4f:ee:85:
                    38:b9:11:c5:23:f2:64:58:f0:15:32:6f:4e:57:a1:
                    ae:88:a4:02:d7:2a:1e:cd:4b:e1:dd:63:d5:17:89:
                    32:5b:b0:5e:99:5a:a8:9d:28:50:0e:17:ee:96:db:
                    61:3b:45:51:1d:cf:12:56:0b:92:47:fc:ab:ae:f6:
                    66:3d:47:ac:70:72:e7:92:e7:5f:cd:10:b9:c4:83:
                    64:94:19:bd:25:80:e1:e8:d2:22:a5:d0:ba:02:7a:
                    a1:77:93:5b:65:c3:ee:17:74:bc:41:86:2a:dc:08:
                    4c:8c:92:8c:91:2d:9e:77:44:1f:68:d6:a8:74:77:
                    db:0e:5b:32:8b:56:8b:33:bd:d9:63:c8:49:9d:3a:
                    c5:c5:ea:33:0b:d2:f1:a3:1b:f4:8b:be:d9:b3:57:
                    8b:3b:de:04:a7:7a:22:b2:24:ae:2e:c7:70:c5:be:
                    4e:83:26:08:fb:0b:bd:a9:4f:99:08:e1:10:28:72:
                    aa:cd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: critical
                Time Stamping
            X509v3 Key Usage: critical
                Digital Signature
            Authority Information Access: 
                OCSP - URI:http://ts-ocsp.ws.symantec.com
                CA Issuers - URI:http://ts-aia.ws.symantec.com/tss-ca-g2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://ts-crl.ws.symantec.com/tss-ca-g2.crl

            X509v3 Subject Alternative Name: 
                DirName:/CN=TimeStamp-2048-2
            X509v3 Subject Key Identifier: 
                46:C6:69:A3:0E:4A:14:1E:D5:4C:DA:52:63:17:3F:5E:36:BC:0D:E6
            X509v3 Authority Key Identifier: 
                keyid:5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD

    Signature Algorithm: sha1WithRSAEncryption
         78:3b:b4:91:2a:00:4c:f0:8f:62:30:37:78:a3:84:27:07:6f:
         18:b2:de:25:dc:a0:d4:94:03:aa:86:4e:25:9f:9a:40:03:1c:
         dd:ce:e3:79:cb:21:68:06:da:b6:32:b4:6d:bf:f4:2c:26:63:
         33:e4:49:64:6d:0d:e6:c3:67:0e:f7:05:a4:35:6c:7c:89:16:
         c6:e9:b2:df:b2:e9:dd:20:c6:71:0f:cd:95:74:dc:b6:5c:de:
         bd:37:1f:43:78:e6:78:b5:cd:28:04:20:a3:aa:f1:4b:c4:88:
         29:91:0e:80:d1:11:fc:dd:5c:76:6e:4f:5e:0e:45:46:41:6e:
         0d:b0:ea:38:9a:b1:3a:da:09:71:10:fc:1c:79:b4:80:7b:ac:
         69:f4:fd:9c:b6:0c:16:2b:f1:7f:5b:09:3d:9b:5b:e2:16:ca:
         13:81:6d:00:2e:38:0d:a8:29:8f:2c:e1:b2:f4:5a:a9:01:af:
         15:9c:2c:2f:49:1b:db:22:bb:c3:fe:78:94:51:c3:86:b1:82:
         88:5d:f0:3d:b4:51:a1:79:33:2b:2e:7b:b9:dc:20:09:13:71:
         eb:6a:19:5b:cf:e8:a5:30:57:2c:89:49:3f:b9:cf:7f:c9:bf:
         3e:22:68:63:53:9a:bd:69:74:ac:c5:1d:3c:7f:92:e0:c3:bc:
         1c:d8:04:75

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            7e:93:eb:fb:7c:c6:4e:59:ea:4b:9a:77:d4:06:fc:3b
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
        Validity
            Not Before: Dec 21 00:00:00 2012 GMT
            Not After : Dec 30 23:59:59 2020 GMT
        Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b1:ac:b3:49:54:4b:97:1c:12:0a:d8:25:79:91:
                    22:57:2a:6f:dc:b8:26:c4:43:73:6b:c2:bf:2e:50:
                    5a:fb:14:c2:76:8e:43:01:25:43:b4:a1:e2:45:f4:
                    e8:b7:7b:c3:74:cc:22:d7:b4:94:00:02:f7:4d:ed:
                    bf:b4:b7:44:24:6b:cd:5f:45:3b:d1:44:ce:43:12:
                    73:17:82:8b:69:b4:2b:cb:99:1e:ac:72:1b:26:4d:
                    71:1f:b1:31:dd:fb:51:61:02:53:a6:aa:f5:49:2c:
                    05:78:45:a5:2f:89:ce:e7:99:e7:fe:8c:e2:57:3f:
                    3d:c6:92:dc:4a:f8:7b:33:e4:79:0a:fb:f0:75:88:
                    41:9c:ff:c5:03:51:99:aa:d7:6c:9f:93:69:87:65:
                    29:83:85:c2:60:14:c4:c8:c9:3b:14:da:c0:81:f0:
                    1f:0d:74:de:92:22:ab:ca:f7:fb:74:7c:27:e6:f7:
                    4a:1b:7f:a7:c3:9e:2d:ae:8a:ea:a6:e6:aa:27:16:
                    7d:61:f7:98:71:11:bc:e2:50:a1:4b:e5:5d:fa:e5:
                    0e:a7:2c:9f:aa:65:20:d3:d8:96:e8:c8:7c:a5:4e:
                    48:44:ff:19:e2:44:07:92:0b:d7:68:84:80:5d:6a:
                    78:64:45:cd:60:46:7e:54:c1:13:7c:c5:79:f1:c9:
                    c1:71
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD
            Authority Information Access: 
                OCSP - URI:http://ocsp.thawte.com

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.thawte.com/ThawteTimestampingCA.crl

            X509v3 Extended Key Usage: 
                Time Stamping
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Subject Alternative Name: 
                DirName:/CN=TimeStamp-2048-1
    Signature Algorithm: sha1WithRSAEncryption
         03:09:9b:8f:79:ef:7f:59:30:aa:ef:68:b5:fa:e3:09:1d:bb:
         4f:82:06:5d:37:5f:a6:52:9f:16:8d:ea:1c:92:09:44:6e:f5:
         6d:eb:58:7c:30:e8:f9:69:8d:23:73:0b:12:6f:47:a9:ae:39:
         11:f8:2a:b1:9b:b0:1a:c3:8e:eb:59:96:00:ad:ce:0c:4d:b2:
         d0:31:a6:08:5c:2a:7a:fc:e2:7a:1d:57:4c:a8:65:18:e9:79:
         40:62:25:96:6e:c7:c7:37:6a:83:21:08:8e:41:ea:dd:d9:57:
         3f:1d:77:49:87:2a:16:06:5e:a6:38:6a:22:12:a3:51:19:83:
         7e:b6
pkcs7-signedData
  • 1
    • SHA256: nil
    • 1.3.6.1.4.1.311.2.1.4
      • #0
        • 1.3.6.1.4.1.311.2.1.15
          • :
            00 3c 00 3c 00 3c 00 4f  00 62 00 73 00 6f 00 6c  |.<.<.<.O.b.s.o.l|
            00 65 00 74 00 65 00 3e  00 3e 00 3e              |.e.t.e.>.>.>    |
        • SHA256
          • 25 7f 98 98 64 84 cc ad  a8 0d 4c dd 4c b6 50 c3  |%...d.....L.L.P.|
            67 38 d1 20 cb fb b7 d6  f9 b3 7a c5 af d5 2d da  |g8. ......z...-.|
    • Certificates
      • Certificate #0
        • 2
          • BD:97:4B:F9:00:9D:BC:31:84:CB:6C:9F:EA:31:A2:E4
          • RSA-SHA256: nil
          • Issuer
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO RSA Code Signing CA
          • 2019-01-10 00:00:00 UTC: 2020-01-10 23:59:59 UTC
          • Subject
            • C: AU
            • postalCode: 4212
            • ST: Queensland
            • L: Helensvale TC
            • street: PO Box 3852
            • postOfficeBox: 3852
            • O: Velocidex Innovations
            • CN: Velocidex Innovations
          • #5
            • rsaEncryption: nil
            • CE:C9:88:9B:EE:71:1A:52:68:30:1C:B0:7D:F4:A0:F7:
              33:D1:80:13:2F:78:88:1B:EB:95:76:97:FD:BE:C6:38:
              0B:64:F0:8B:01:7B:9E:7E:38:85:BA:EA:FB:AC:1C:34:
              19:6E:43:EF:C8:21:2E:06:0B:54:F5:40:0E:02:F2:F7:
              DB:E9:B2:D7:3F:C6:8D:02:DE:47:79:65:74:7D:EF:B7:
              5F:A0:CF:7C:45:EC:0F:2D:6E:6C:71:32:03:C3:4D:9E:
              02:8C:51:4E:E2:D4:A4:6F:AF:BF:03:25:67:DE:0F:66:
              D3:67:D6:DF:83:E3:44:4A:7B:66:9D:E7:EB:E1:2A:92:
              8D:9A:3A:F7:26:B8:C0:F6:33:8A:47:D6:3D:A7:C3:8F:
              7A:2B:E0:FC:C2:50:77:86:CF:00:26:E5:F9:A3:CF:FF:
              FA:16:05:53:16:51:28:88:4B:BD:CE:4E:65:93:5E:4B:
              0A:21:4E:34:23:4C:F3:01:96:FF:4E:60:C1:78:68:CD:
              D9:C5:C7:81:AE:89:6C:2A:78:6A:D2:64:DE:25:5C:AE:
              A8:23:2A:8F:C1:87:F4:EB:3A:24:45:1B:38:58:25:99:
              8B:70:50:96:F1:EA:A6:B4:A4:48:8E:71:C4:BA:4A:E1:
              BB:E4:53:3E:A1:1C:8B:19:CB:B4:7A:9F:03:4E:C7:6F
              : 0x010001
          • #6
            • authorityKeyIdentifier:
              29 91 60 ff 8a 4d fa eb  f9 a6 6a b8 cf f9 e6 4b  |).`..M....j....K|
              bd 49 ce 12                                       |.I..            |
            • subjectKeyIdentifier:
              ed db f1 2b 12 32 5e 7d  d5 5c 70 57 83 df b3 f0  |...+.2^}.\pW....|
              53 05 a2 28                                       |S..(            |
            • keyUsage: true, 0x80
            • basicConstraints
              • true
              • nil
            • extendedKeyUsage: codeSigning
            • nsCertType: 0x10
            • certificatePolicies
              • 1.3.6.1.4.1.6449.1.2.1.3.2
                • id-qt-cps: https://secure.comodo.net/CPS
            • crlDistributionPoints: http://crl.comodoca.com/COMODORSACodeSigningCA.crl
            • authorityInfoAccess
              • #0
                • caIssuers: http://crt.comodoca.com/COMODORSACodeSigningCA.crt
                • OCSP: http://ocsp.comodoca.com
            • subjectAltName: support@velocidex.com
        • RSA-SHA256:
          a1 6b 93 f4 39 23 94 1d  39 1c 3b f9 0a 1e 8c c4  |.k..9#..9.;.....|
          6c 0a 53 f8 f9 d5 fb e3  99 d5 f8 13 b8 05 e2 86  |l.S.............|
          09 65 85 25 d6 6d 4a 63  f9 0d 8c 78 cc 6e f0 99  |.e.%.mJc...x.n..|
          ee 95 38 3c 33 15 71 b6  8a af f0 e9 d0 83 cf b8  |..8<3.q.........|
          bc 53 e8 ae a5 8d 85 41  d0 28 91 96 e7 13 e4 89  |.S.....A.(......|
          88 9a bc c9 34 00 65 23  fb d2 8c a7 ec 3e b9 79  |....4.e#.....>.y|
          7b f2 8e 08 e7 f9 1e 5b  33 ae b6 51 6a 9f 0b 7b  |{......[3..Qj..{|
          3e d0 73 a4 de a9 b3 7d  0a 17 f7 42 bb 14 1d 05  |>.s....}...B....|
          a2 92 d7 23 63 88 83 2b  70 cb cb 1c fd 59 46 03  |...#c..+p....YF.|
          a5 c2 6d 92 6d 0f ad f5  58 f2 ef 3e f5 db 5a 46  |..m.m...X..>..ZF|
          c4 85 88 2a e7 84 a4 62  c2 f1 89 b5 9d 77 da f4  |...*...b.....w..|
          3b 6f 1e 9f 5e b2 98 72  63 5d 62 f4 10 ee 71 7f  |;o..^..rc]b...q.|
          1a 4b 08 41 3f b5 d7 29  2a 2e 47 0a 0f a9 41 0f  |.K.A?..)*.G...A.|
          35 e8 1b 1f d5 dd 60 c5  21 58 1a b4 fe 2b 0c 45  |5.....`.!X...+.E|
          db e6 36 9d 32 b5 fc c7  d0 82 07 cd 0c e1 38 53  |..6.2.........8S|
          f0 94 31 de 8b 2f 4f e6  31 08 d7 be 0d 96 d6 55  |..1../O.1......U|
      • Certificate #1
        • 2
          • 2E:7C:87:CC:0E:93:4A:52:FE:94:FD:1C:B7:CD:34:AF
          • RSA-SHA384: nil
          • Issuer
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO RSA Certification Authority
          • 2013-05-09 00:00:00 UTC: 2028-05-08 23:59:59 UTC
          • Subject
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO RSA Code Signing CA
          • #5
            • rsaEncryption: nil
            • A6:98:90:63:77:91:34:7F:8A:D1:DD:E9:67:31:11:EB:
              CC:1E:FD:31:1D:B3:B9:62:57:3F:93:BC:5B:E3:9F:1E:
              24:32:11:27:6B:BC:51:91:A7:CF:9E:9E:25:B3:5F:81:
              A8:18:0F:1D:1E:20:30:0E:FB:61:7B:86:09:B3:E3:FD:
              A2:68:9D:1C:2C:9D:BF:72:E3:E4:75:A0:E5:35:23:8E:
              C9:8A:EE:1A:0C:64:C7:D8:42:A1:7B:B5:52:03:4B:3A:
              B0:8E:23:4B:4B:63:E0:22:94:37:7B:D5:79:90:0A:14:
              18:51:2C:E6:FE:C1:12:F0:1C:3F:61:61:0A:8C:A2:DC:
              F6:C3:30:AA:CD:28:18:75:48:C1:79:5A:08:CD:BB:8C:
              55:8C:F7:D4:76:90:3A:33:46:50:73:98:5C:F4:85:4A:
              6B:0F:80:DD:5E:D6:BD:FD:A9:2F:C0:25:F5:F9:78:D7:
              8D:5F:10:C2:44:55:3C:90:3C:31:46:CB:70:AE:07:A9:
              0A:E3:AF:C1:01:6F:90:1A:23:E2:5F:38:DB:C6:08:5D:
              47:B3:83:41:F0:2E:00:37:14:B9:12:AA:79:92:52:CD:
              87:0F:7B:D8:62:29:A4:7E:30:BD:1B:B5:8C:72:B4:48:
              F2:E3:E8:21:F9:5E:4C:62:79:8B:02:06:9F:7F:D5:0B
              : 0x010001
          • #6
            • authorityKeyIdentifier:
              bb af 7e 02 3d fa a6 f1  3c 84 8e ad ee 38 98 ec  |..~.=...<....8..|
              d9 32 32 d4                                       |.22.            |
            • subjectKeyIdentifier:
              29 91 60 ff 8a 4d fa eb  f9 a6 6a b8 cf f9 e6 4b  |).`..M....j....K|
              bd 49 ce 12                                       |.I..            |
            • keyUsage: true, 0x86
            • basicConstraints
              • true
              • true: 0
            • extendedKeyUsage: codeSigning
            • certificatePolicies: anyPolicy
            • crlDistributionPoints: http://crl.comodoca.com/COMODORSACertificationAuthority.crl
            • authorityInfoAccess
              • #0
                • caIssuers: http://crt.comodoca.com/COMODORSAAddTrustCA.crt
                • OCSP: http://ocsp.comodoca.com
        • RSA-SHA384:
          02 3f 02 39 c3 ee f8 ca  3b 89 de 0c 6d 4d b1 f1  |.?.9....;...mM..|
          4e 92 4f af c2 38 2c 04  cc c5 63 11 ab 09 63 af  |N.O..8,...c...c.|
          ab a2 d7 02 3f cc 6f 19  c3 3d d6 1a 08 94 ff 25  |....?.o..=.....%|
          d8 a9 88 a7 2b 10 1a e0  9b b1 07 22 1a 51 1c 3a  |....+......".Q.:|
          d4 e1 e9 09 bf e6 24 74  af 1e 7b 16 31 6e 23 ef  |......$t..{.1n#.|
          54 51 2d 52 02 e2 75 08  05 4c f1 b7 51 e1 51 00  |TQ-R..u..L..Q.Q.|
          c6 87 f6 6c ee 10 44 76  57 6a f1 df 58 6b 21 aa  |...l..DvWj..Xk!.|
          49 d4 7c 37 4e bd ff b6  75 54 40 18 36 57 67 11  |I.|7N...uT@.6Wg.|
          cd 4f 02 e4 fe f3 da fc  75 17 db ec b7 f7 65 09  |.O......u.....e.|
          23 49 1f 43 57 83 ea 7e  20 77 61 c8 4d f2 bb 65  |#I.CW..~ wa.M..e|
          4d a8 f7 85 45 07 af 7a  69 27 65 90 29 40 8b df  |M...E..zi'e.)@..|
          7b 3a 51 39 8c a8 1f 70  79 ad 6d 42 20 a2 cf 0c  |{:Q9...py.mB ...|
          6c 03 8c 4c cd 73 07 94  e7 5a 8e 3a 04 ba a2 a1  |l..L.s...Z.:....|
          7c 1f cb 63 3a 15 a7 d4  15 1b a7 52 47 32 a9 f4  ||..c:......RG2..|
          bf 64 47 d1 aa 1f 53 4e  32 30 73 c2 6f b7 78 82  |.dG...SN20s.o.x.|
          9d 5c ff 46 bb 6b 22 1d  88 0b f8 1b aa 34 a6 fc  |.\.F.k"......4..|
          8c f5 dd 7f 65 8c 8c 31  57 31 d0 36 ec 47 a1 cf  |....e..1W1.6.G..|
          cb 8b a8 ef 1c 18 58 c5  06 77 ca 4b 9b 51 af 4c  |......X..w.K.Q.L|
          08 4a 7a 8f e2 a3 52 e2  8e 8e cc 26 e4 b2 d8 e5  |.Jz...R....&....|
          38 c2 a8 ed c6 81 9c 35  6b a9 58 61 4a 0a 97 b4  |8......5k.XaJ...|
          4b 42 b6 55 9d be 99 e7  70 6d 59 f8 6d 2a 0c 7f  |KB.U....pmY.m*..|
          19 60 5f 0c 9a 88 6c 30  ac 52 09 90 16 1b ff 2b  |.`_...l0.R.....+|
          9d db d0 20 ca 89 ea 28  7e 32 8e 19 df 7b 48 33  |... ...(~2...{H3|
          1e d7 65 f8 ae c9 f8 83  14 93 76 7d 64 d0 8e ce  |..e.......v}d...|
          be 35 7d ff 72 31 4d 9f  9e bd 1e 6c 2f a8 8f 0c  |.5}.r1M....l/...|
          06 50 fb 8c 27 b3 76 c9  f4 e6 d7 c3 34 e2 8c 87  |.P..'.v.....4...|
          21 86 61 fe bf 55 74 e1  21 77 03 0a 68 6c bb e4  |!.a..Ut.!w..hl..|
          c9 a9 e6 cf 59 25 eb 7c  ec 45 0e 79 66 68 e8 22  |....Y%.|.E.yfh."|
          cd b8 ef 98 85 4d 96 11  3c 09 8a d0 7f bc 28 28  |.....M..<.....((|
          13 fb 6a ca 54 8d 92 5c  cd c2 65 98 06 9e ce 48  |..j.T..\..e....H|
          5b d4 b5 37 93 46 41 7c  07 dd cf fa 43 ef ba 67  |[..7.FA|....C..g|
          61 ff 7d 49 e0 bb 30 7d  5c 80 e3 e6 16 39 4b a7  |a.}I..0}\....9K.|
      • Certificate #2
        • 2
          • 4C:AA:F9:CA:DB:63:6F:E0:1F:F7:4E:D8:5B:03:86:9D
          • RSA-SHA384: nil
          • Issuer
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO RSA Certification Authority
          • 2010-01-19 00:00:00 UTC: 2038-01-18 23:59:59 UTC
          • Subject
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO RSA Certification Authority
          • #5
            • rsaEncryption: nil
            • 91:E8:54:92:D2:0A:56:B1:AC:0D:24:DD:C5:CF:44:67:
              74:99:2B:37:A3:7D:23:70:00:71:BC:53:DF:C4:FA:2A:
              12:8F:4B:7F:10:56:BD:9F:70:72:B7:61:7F:C9:4B:0F:
              17:A7:3D:E3:B0:04:61:EE:FF:11:97:C7:F4:86:3E:0A:
              FA:3E:5C:F9:93:E6:34:7A:D9:14:6B:E7:9C:B3:85:A0:
              82:7A:76:AF:71:90:D7:EC:FD:0D:FA:9C:6C:FA:DF:B0:
              82:F4:14:7E:F9:BE:C4:A6:2F:4F:7F:99:7F:B5:FC:67:
              43:72:BD:0C:00:D6:89:EB:6B:2C:D3:ED:8F:98:1C:14:
              AB:7E:E5:E3:6E:FC:D8:A8:E4:92:24:DA:43:6B:62:B8:
              55:FD:EA:C1:BC:6C:B6:8B:F3:0E:8D:9A:E4:9B:6C:69:
              99:F8:78:48:30:45:D5:AD:E1:0D:3C:45:60:FC:32:96:
              51:27:BC:67:C3:CA:2E:B6:6B:EA:46:C7:C7:20:A0:B1:
              1F:65:DE:48:08:BA:A4:4E:A9:F2:83:46:37:84:EB:E8:
              CC:81:48:43:67:4E:72:2A:9B:5C:BD:4C:1B:28:8A:5C:
              22:7B:B4:AB:98:D9:EE:E0:51:83:C3:09:46:4E:6D:3E:
              99:FA:95:17:DA:7C:33:57:41:3C:8D:51:ED:0B:B6:5C:
              AF:2C:63:1A:DF:57:C8:3F:BC:E9:5D:C4:9B:AF:45:99:
              E2:A3:5A:24:B4:BA:A9:56:3D:CF:6F:AA:FF:49:58:BE:
              F0:A8:FF:F4:B8:AD:E9:37:FB:BA:B8:F4:0B:3A:F9:E8:
              43:42:1E:89:D8:84:CB:13:F1:D9:BB:E1:89:60:B8:8C:
              28:56:AC:14:1D:9C:0A:E7:71:EB:CF:0E:DD:3D:A9:96:
              A1:48:BD:3C:F7:AF:B5:0D:22:4C:C0:11:81:EC:56:3B:
              F6:D3:A2:E2:5B:B7:B2:04:22:52:95:80:93:69:E8:8E:
              4C:65:F1:91:03:2D:70:74:02:EA:8B:67:15:29:69:52:
              02:BB:D7:DF:50:6A:55:46:BF:A0:A3:28:61:7F:70:D0:
              C3:A2:AA:2C:21:AA:47:CE:28:9C:06:45:76:BF:82:18:
              27:B4:D5:AE:B4:CB:50:E6:6B:F4:4C:86:71:30:E9:A6:
              DF:16:86:E0:D8:FF:40:DD:FB:D0:42:88:7F:A3:33:3A:
              2E:5C:1E:41:11:81:63:CE:18:71:6B:2B:EC:A6:8A:B7:
              31:5C:3A:6A:47:E0:C3:79:59:D6:20:1A:AF:F2:6A:98:
              AA:72:BC:57:4A:D2:4B:9D:BB:10:FC:B0:4C:41:E5:ED:
              1D:3D:5E:28:9D:9C:CC:BF:B3:51:DA:A7:47:E5:84:53
              : 0x010001
          • #6
            • subjectKeyIdentifier:
              bb af 7e 02 3d fa a6 f1  3c 84 8e ad ee 38 98 ec  |..~.=...<....8..|
              d9 32 32 d4                                       |.22.            |
            • keyUsage: true, 6
            • basicConstraints: true, true
        • RSA-SHA384:
          0a f1 d5 46 84 b7 ae 51  bb 6c b2 4d 41 14 00 93  |...F...Q.l.MA...|
          4c 9c cb e5 c0 54 cf a0  25 8e 02 f9 fd b0 a2 0d  |L....T..%.......|
          f5 20 98 3c 13 2d ac 56  a2 b0 d6 7e 11 92 e9 2e  |. .<.-.V...~....|
          ba 9e 2e 9a 72 b1 bd 19  44 6c 61 35 a2 9a b4 16  |....r...Dla5....|
          12 69 5a 8c e1 d7 3e a4  1a e8 2f 03 f4 ae 61 1d  |.iZ...>.../...a.|
          10 1b 2a a4 8b 7a c5 fe  05 a6 e1 c0 d6 c8 fe 9e  |..*..z..........|
          ae 8f 2b ba 3d 99 f8 d8  73 09 58 46 6e a6 9c f4  |..+.=...s.XFn...|
          d7 27 d3 95 da 37 83 72  1c d3 73 e0 a2 47 99 03  |.'...7.r..s..G..|
          38 5d d5 49 79 00 29 1c  c7 ec 9b 20 1c 07 24 69  |8].Iy.).... ..$i|
          57 78 b2 39 fc 3a 84 a0  b5 9c 7c 8d bf 2e 93 62  |Wx.9.:....|....b|
          27 b7 39 da 17 18 ae bd  3c 09 68 ff 84 9b 3c d5  |'.9.....<.h...<.|
          d6 0b 03 e3 57 9e 14 f7  d1 eb 4f c8 bd 87 23 b7  |....W.....O...#.|
          b6 49 43 79 85 5c ba eb  92 0b a1 c6 e8 68 a8 4c  |.ICy.\.......h.L|
          16 b1 1a 99 0a e8 53 2c  92 bb a1 09 18 75 0c 65  |......S,.....u.e|
          a8 7b cb 23 b7 1a c2 28  85 c3 1b ff d0 2b 62 ef  |.{.#...(.....+b.|
          a4 7b 09 91 98 67 8c 14  01 cd 68 06 6a 63 21 75  |.{...g....h.jc!u|
          03 80 88 8a 6e 81 c6 85  f2 a9 a4 2d e7 f4 a5 24  |....n......-...$|
          10 47 83 ca cd f4 8d 79  58 b1 06 9b e7 1a 2a d9  |.G.....yX.....*.|
          9d 01 d7 94 7d ed 03 4a  ca f0 db e8 a9 01 3e f5  |....}..J......>.|
          56 99 c9 1e 8e 49 3d bb  e5 09 b9 e0 4f 49 92 3d  |V....I=.....OI.=|
          16 82 40 cc cc 59 c6 e6  3a ed 12 2e 69 3c 6c 95  |..@..Y..:...i
      • Certificate #3
        • 2
          • 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
          • RSA-SHA1: nil
          • Issuer
            • C: US
            • O: Symantec Corporation
            • CN: Symantec Time Stamping Services CA - G2
          • 2012-10-18 00:00:00 UTC: 2020-12-29 23:59:59 UTC
          • Subject
            • C: US
            • O: Symantec Corporation
            • CN: Symantec Time Stamping Services Signer - G4
          • #5
            • rsaEncryption: nil
            • A2:63:0B:39:44:B8:BB:23:A7:44:49:BB:0E:FF:A1:F0:
              61:0A:53:93:B0:98:DB:AD:2C:0F:4A:C5:6E:FF:86:3C:
              53:55:0F:15:CE:04:3F:2B:FD:A9:96:96:D9:BE:61:79:
              0B:5B:C9:4C:86:76:E5:E0:43:4B:22:95:EE:C2:2B:43:
              C1:9F:D8:68:B4:8E:40:4F:EE:85:38:B9:11:C5:23:F2:
              64:58:F0:15:32:6F:4E:57:A1:AE:88:A4:02:D7:2A:1E:
              CD:4B:E1:DD:63:D5:17:89:32:5B:B0:5E:99:5A:A8:9D:
              28:50:0E:17:EE:96:DB:61:3B:45:51:1D:CF:12:56:0B:
              92:47:FC:AB:AE:F6:66:3D:47:AC:70:72:E7:92:E7:5F:
              CD:10:B9:C4:83:64:94:19:BD:25:80:E1:E8:D2:22:A5:
              D0:BA:02:7A:A1:77:93:5B:65:C3:EE:17:74:BC:41:86:
              2A:DC:08:4C:8C:92:8C:91:2D:9E:77:44:1F:68:D6:A8:
              74:77:DB:0E:5B:32:8B:56:8B:33:BD:D9:63:C8:49:9D:
              3A:C5:C5:EA:33:0B:D2:F1:A3:1B:F4:8B:BE:D9:B3:57:
              8B:3B:DE:04:A7:7A:22:B2:24:AE:2E:C7:70:C5:BE:4E:
              83:26:08:FB:0B:BD:A9:4F:99:08:E1:10:28:72:AA:CD
              : 0x010001
          • X509v3 extensions
            • basicConstraints
              • true
              • nil
            • extendedKeyUsage: true, timeStamping
            • keyUsage: true, 0x80
            • authorityInfoAccess
              • #0
                • OCSP: http://ts-ocsp.ws.symantec.com
                • caIssuers: http://ts-aia.ws.symantec.com/tss-ca-g2.cer
            • crlDistributionPoints: http://ts-crl.ws.symantec.com/tss-ca-g2.crl
            • subjectAltName
              • CN: TimeStamp-2048-2
            • subjectKeyIdentifier:
              46 c6 69 a3 0e 4a 14 1e  d5 4c da 52 63 17 3f 5e  |F.i..J...L.Rc.?^|
              36 bc 0d e6                                       |6...            |
            • authorityKeyIdentifier:
              5f 9a f5 6e 5c cc cc 74  9a d4 dd 7d ef 3f db ec  |_..n\..t...}.?..|
              4c 80 2e dd                                       |L...            |
        • RSA-SHA1:
          78 3b b4 91 2a 00 4c f0  8f 62 30 37 78 a3 84 27  |x;..*.L..b07x..'|
          07 6f 18 b2 de 25 dc a0  d4 94 03 aa 86 4e 25 9f  |.o...%.......N%.|
          9a 40 03 1c dd ce e3 79  cb 21 68 06 da b6 32 b4  |.@.....y.!h...2.|
          6d bf f4 2c 26 63 33 e4  49 64 6d 0d e6 c3 67 0e  |m..,&c3.Idm...g.|
          f7 05 a4 35 6c 7c 89 16  c6 e9 b2 df b2 e9 dd 20  |...5l|......... |
          c6 71 0f cd 95 74 dc b6  5c de bd 37 1f 43 78 e6  |.q...t..\..7.Cx.|
          78 b5 cd 28 04 20 a3 aa  f1 4b c4 88 29 91 0e 80  |x..(. ...K..)...|
          d1 11 fc dd 5c 76 6e 4f  5e 0e 45 46 41 6e 0d b0  |....\vnO^.EFAn..|
          ea 38 9a b1 3a da 09 71  10 fc 1c 79 b4 80 7b ac  |.8..:..q...y..{.|
          69 f4 fd 9c b6 0c 16 2b  f1 7f 5b 09 3d 9b 5b e2  |i......+..[.=.[.|
          16 ca 13 81 6d 00 2e 38  0d a8 29 8f 2c e1 b2 f4  |....m..8..).,...|
          5a a9 01 af 15 9c 2c 2f  49 1b db 22 bb c3 fe 78  |Z.....,/I.."...x|
          94 51 c3 86 b1 82 88 5d  f0 3d b4 51 a1 79 33 2b  |.Q.....].=.Q.y3+|
          2e 7b b9 dc 20 09 13 71  eb 6a 19 5b cf e8 a5 30  |.{.. ..q.j.[...0|
          57 2c 89 49 3f b9 cf 7f  c9 bf 3e 22 68 63 53 9a  |W,.I?.....>"hcS.|
          bd 69 74 ac c5 1d 3c 7f  92 e0 c3 bc 1c d8 04 75  |.it...<........u|
      • Certificate #4
        • 2
          • 7E:93:EB:FB:7C:C6:4E:59:EA:4B:9A:77:D4:06:FC:3B
          • RSA-SHA1: nil
          • Issuer
            • C: ZA
            • ST: Western Cape
            • L: Durbanville
            • O: Thawte
            • OU: Thawte Certification
            • CN: Thawte Timestamping CA
          • 2012-12-21 00:00:00 UTC: 2020-12-30 23:59:59 UTC
          • Subject
            • C: US
            • O: Symantec Corporation
            • CN: Symantec Time Stamping Services CA - G2
          • #5
            • rsaEncryption: nil
            • B1:AC:B3:49:54:4B:97:1C:12:0A:D8:25:79:91:22:57:
              2A:6F:DC:B8:26:C4:43:73:6B:C2:BF:2E:50:5A:FB:14:
              C2:76:8E:43:01:25:43:B4:A1:E2:45:F4:E8:B7:7B:C3:
              74:CC:22:D7:B4:94:00:02:F7:4D:ED:BF:B4:B7:44:24:
              6B:CD:5F:45:3B:D1:44:CE:43:12:73:17:82:8B:69:B4:
              2B:CB:99:1E:AC:72:1B:26:4D:71:1F:B1:31:DD:FB:51:
              61:02:53:A6:AA:F5:49:2C:05:78:45:A5:2F:89:CE:E7:
              99:E7:FE:8C:E2:57:3F:3D:C6:92:DC:4A:F8:7B:33:E4:
              79:0A:FB:F0:75:88:41:9C:FF:C5:03:51:99:AA:D7:6C:
              9F:93:69:87:65:29:83:85:C2:60:14:C4:C8:C9:3B:14:
              DA:C0:81:F0:1F:0D:74:DE:92:22:AB:CA:F7:FB:74:7C:
              27:E6:F7:4A:1B:7F:A7:C3:9E:2D:AE:8A:EA:A6:E6:AA:
              27:16:7D:61:F7:98:71:11:BC:E2:50:A1:4B:E5:5D:FA:
              E5:0E:A7:2C:9F:AA:65:20:D3:D8:96:E8:C8:7C:A5:4E:
              48:44:FF:19:E2:44:07:92:0B:D7:68:84:80:5D:6A:78:
              64:45:CD:60:46:7E:54:C1:13:7C:C5:79:F1:C9:C1:71
              : 0x010001
          • #6
            • subjectKeyIdentifier:
              5f 9a f5 6e 5c cc cc 74  9a d4 dd 7d ef 3f db ec  |_..n\..t...}.?..|
              4c 80 2e dd                                       |L...            |
            • authorityInfoAccess
              • OCSP: http://ocsp.thawte.com
            • basicConstraints
              • true
              • true: 0
            • crlDistributionPoints: http://crl.thawte.com/ThawteTimestampingCA.crl
            • extendedKeyUsage: timeStamping
            • keyUsage: true, 6
            • subjectAltName
              • CN: TimeStamp-2048-1
        • RSA-SHA1:
          03 09 9b 8f 79 ef 7f 59  30 aa ef 68 b5 fa e3 09  |....y..Y0..h....|
          1d bb 4f 82 06 5d 37 5f  a6 52 9f 16 8d ea 1c 92  |..O..]7_.R......|
          09 44 6e f5 6d eb 58 7c  30 e8 f9 69 8d 23 73 0b  |.Dn.m.X|0..i.#s.|
          12 6f 47 a9 ae 39 11 f8  2a b1 9b b0 1a c3 8e eb  |.oG..9..*.......|
          59 96 00 ad ce 0c 4d b2  d0 31 a6 08 5c 2a 7a fc  |Y.....M..1..\*z.|
          e2 7a 1d 57 4c a8 65 18  e9 79 40 62 25 96 6e c7  |.z.WL.e..y@b%.n.|
          c7 37 6a 83 21 08 8e 41  ea dd d9 57 3f 1d 77 49  |.7j.!..A...W?.wI|
          87 2a 16 06 5e a6 38 6a  22 12 a3 51 19 83 7e b6  |.*..^.8j"..Q..~.|
    • Signer
      • 1
      • unnamed
        • #0
          • C: GB
          • ST: Greater Manchester
          • L: Salford
          • O: COMODO CA Limited
          • CN: COMODO RSA Code Signing CA
        • BD:97:4B:F9:00:9D:BC:31:84:CB:6C:9F:EA:31:A2:E4
      • SHA256: nil
      • #3
        • contentType: 1.3.6.1.4.1.311.2.1.4
        • signingTime: 2019-08-20 12:38:13 UTC
        • 1.3.6.1.4.1.311.2.1.11: msCodeInd
        • messageDigest:
          9d 89 9f e0 ff 44 89 85  52 2d 92 60 99 e1 f8 87  |.....D..R-.`....|
          46 de e3 c0 07 a3 f3 ae  84 01 57 c8 be fc 5f 66  |F.........W..._f|
        • 1.3.6.1.4.1.311.2.1.12
          • Velociraptor: https://docs.velociraptor.velocidex.com/blog/html/pages/overview.html
      • rsaEncryption:
        bc 3c b7 06 71 75 2c fd  13 aa 63 48 1f c5 3a 95  |.<..qu,...cH..:.|
        b4 9a 83 73 49 d8 76 e2  e1 3b 78 e6 2d 95 34 b5  |...sI.v..;x.-.4.|
        c7 0d 85 ee f3 ef b2 25  2e 0e aa 87 28 21 78 25  |.......%....(!x%|
        d1 19 20 a2 7f de 11 b4  8b 9c bf c5 2d 70 10 9f  |.. .........-p..|
        a3 65 3c 07 09 11 ef d5  83 8f 1c 26 51 24 6a 6d  |.e<........&Q$jm|
        eb 21 f8 11 b3 c1 bc 31  08 a6 a2 32 c7 27 eb 59  |.!.....1...2.'.Y|
        4b f1 d6 91 8f cb 55 74  22 5c 69 2d e1 af 06 0c  |K.....Ut"\i-....|
        d9 99 5e 6e 84 c3 92 88  e5 85 95 64 e6 d8 b2 a5  |..^n.......d....|
        b3 31 e5 96 88 ef cf 75  d6 fb 12 09 09 18 a2 54  |.1.....u.......T|
        c6 4a 79 9e b1 d8 06 b9  73 71 a1 7d 90 49 00 6c  |.Jy.....sq.}.I.l|
        de 68 65 9b 13 22 29 2c  f7 ac 0a 16 95 48 f4 0a  |.he.."),.....H..|
        ed 80 5f 84 a8 bc d3 44  46 92 e2 78 f5 f2 d1 77  |.._....DF..x...w|
        2e 53 53 c3 12 0a 3e 97  cc 36 ec b3 61 ee c1 22  |.SS...>..6..a.."|
        60 be d9 7a a6 fe cf 0d  a6 e2 4d 02 96 10 6b 9a  |`..z......M...k.|
        b6 8b 0d 53 7d 8e 3f e0  c6 34 11 93 b5 b1 50 b1  |...S}.?..4....P.|
        6d 71 4e 87 16 17 98 61  a2 5a a0 a0 d1 73 1d c9  |mqN....a.Z...s..|
      • countersignature
        • 1
          • unnamed
            • #0
              • C: US
              • O: Symantec Corporation
              • CN: Symantec Time Stamping Services CA - G2
            • 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
          • SHA1: nil
          • #2
            • contentType: pkcs7-data
            • signingTime: 2019-08-20 12:38:14 UTC
            • messageDigest:
              bf bd 90 07 cd 09 9f 86  0d b6 7d 1d 4c e7 98 6e  |..........}.L..n|
              5e 97 3a 80                                       |^.:.            |
          • rsaEncryption:
            8f 58 3c 12 1c 98 0c 23  ff 30 16 d4 a4 35 28 a2  |.X<....#.0...5(.|
            27 e4 5e f5 d5 99 a4 73  19 ec 05 39 1d ce 6c 19  |'.^....s...9..l.|
            b0 0d dd 91 af 26 ec d5  9e 47 ad 40 fb d6 50 a5  |.....&...G.@..P.|
            4a 5d 5f a1 d3 fe 91 91  9b 90 e6 1d 29 75 6e 69  |J]_.........)uni|
            05 a0 d1 44 a6 e8 99 4e  f3 fe bd f2 9f d9 a9 32  |...D...N.......2|
            02 7b 52 55 22 97 e5 41  27 d0 f5 7e ec c4 60 31  |.{RU"..A'..~..`1|
            ac 68 7f 3a aa a2 ca ad  9b 77 03 d6 c3 11 64 9b  |.h.:.....w....d.|
            8f bf c3 0b 48 64 84 04  d8 54 60 f4 be 97 3b 3a  |....Hd...T`...;:|
            65 33 ec 3d 21 7c e3 07  19 ba 8e a6 a7 50 68 ae  |e3.=!|.......Ph.|
            08 da 2b f8 2f 7c 90 43  a0 47 5f 49 6e 4d 7c 4f  |..+./|.C.G_InM|O|
            55 7c cb d0 cb a7 af 93  df d2 8d d1 c5 07 cc 1f  |U|..............|
            61 63 0c 6e 4e 9b e1 9b  e2 bf ff 70 dc 32 a0 d8  |ac.nN......p.2..|
            de 8e 28 13 3e bd 30 99  3c 8d 67 f5 98 55 48 47  |..(.>.0.<.g..UHG|
            3b 87 f6 e7 13 b9 4f 1f  e1 e2 25 84 39 9f b5 b4  |;.....O...%.9...|
            8c 52 9d c6 3c 6c 2e 7d  8e e3 39 3d 7a 35 71 d5  |.R..
offsetsizetypecomment
02541056EXE08/20/2019 12:37:25#
15c115HTM#
26c6008000PKCS7Authenticode Signature#
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0x26f9b0