filename | sample.ex_ | |
---|---|---|
size | 1280064 (0x138840) | |
md5 | 55d5eda6cd2551eec0bb800df11a638b | |
type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x2000 | 0xc3884 | 0xc4000 | R-X CODE | |
.rsrc | 0xc6000 | 0x70880 | 0x71000 | R-- IDATA | |
.reloc | 0x138000 | 0xc | 0x1000 | R-- IDATA DISCARDABLE |
Data Directory
type | name | size | cp | |
---|---|---|---|---|
ICON | #2 | 270376 | 0 | |
ICON | #3 | 67624 | 0 | |
ICON | #4 | 38056 | 0 | |
ICON | #5 | 26600 | 0 | |
ICON | #6 | 21640 | 0 | |
ICON | #7 | 16936 | 0 | |
ICON | #8 | 9640 | 0 | |
ICON | #9 | 4264 | 0 | |
ICON | #10 | 2440 | 0 | |
ICON | #11 | 1128 | 0 | |
GROUP_ICON | #32512 | 146 | 0 | |
VERSION | #1 | 836 | 0 | |
MANIFEST | #1 | 490 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
mscoree.dll | _CorExeMain |
StringTable 000004b0
Comments | The Witcher 3 |
CompanyName | CD Projekt Red |
FileDescription | The Witcher 3 |
FileVersion | 3.0.0 |
InternalName | pdffff.exe |
LegalCopyright | Copyright © 2012 CD Projekt Red. |
OriginalFilename | pdffff.exe |
ProductName | The Witcher 3 |
ProductVersion | 3.0.0 |
Assembly Version | 3.0.0.0 |
VS_FIXEDFILEINFO
FileVersion | 3.0.0.0 |
ProductVersion | 3.0.0.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
Signers (1)
issuer: /C=US/ST=Arizona/L=Scottsdale/O=Starfield Technologies, Inc./OU=http://certificates.starfieldtech.com/repository/CN=Starfield Secure Certification Authority/serialNumber=10688435
serial: 04430E53296BF1
Certificates (4)
Certificate: Data: Version: 3 (0x2) Serial Number: 7e:93:eb:fb:7c:c6:4e:59:ea:4b:9a:77:d4:06:fc:3b Signature Algorithm: sha1WithRSAEncryption Issuer: C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA Validity Not Before: Dec 21 00:00:00 2012 GMT Not After : Dec 30 23:59:59 2020 GMT Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:b1:ac:b3:49:54:4b:97:1c:12:0a:d8:25:79:91: 22:57:2a:6f:dc:b8:26:c4:43:73:6b:c2:bf:2e:50: 5a:fb:14:c2:76:8e:43:01:25:43:b4:a1:e2:45:f4: e8:b7:7b:c3:74:cc:22:d7:b4:94:00:02:f7:4d:ed: bf:b4:b7:44:24:6b:cd:5f:45:3b:d1:44:ce:43:12: 73:17:82:8b:69:b4:2b:cb:99:1e:ac:72:1b:26:4d: 71:1f:b1:31:dd:fb:51:61:02:53:a6:aa:f5:49:2c: 05:78:45:a5:2f:89:ce:e7:99:e7:fe:8c:e2:57:3f: 3d:c6:92:dc:4a:f8:7b:33:e4:79:0a:fb:f0:75:88: 41:9c:ff:c5:03:51:99:aa:d7:6c:9f:93:69:87:65: 29:83:85:c2:60:14:c4:c8:c9:3b:14:da:c0:81:f0: 1f:0d:74:de:92:22:ab:ca:f7:fb:74:7c:27:e6:f7: 4a:1b:7f:a7:c3:9e:2d:ae:8a:ea:a6:e6:aa:27:16: 7d:61:f7:98:71:11:bc:e2:50:a1:4b:e5:5d:fa:e5: 0e:a7:2c:9f:aa:65:20:d3:d8:96:e8:c8:7c:a5:4e: 48:44:ff:19:e2:44:07:92:0b:d7:68:84:80:5d:6a: 78:64:45:cd:60:46:7e:54:c1:13:7c:c5:79:f1:c9: c1:71 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD Authority Information Access: OCSP - URI:http://ocsp.thawte.com X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 CRL Distribution Points: Full Name: URI:http://crl.thawte.com/ThawteTimestampingCA.crl X509v3 Extended Key Usage: Time Stamping X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Subject Alternative Name: DirName:/CN=TimeStamp-2048-1 Signature Algorithm: sha1WithRSAEncryption 03:09:9b:8f:79:ef:7f:59:30:aa:ef:68:b5:fa:e3:09:1d:bb: 4f:82:06:5d:37:5f:a6:52:9f:16:8d:ea:1c:92:09:44:6e:f5: 6d:eb:58:7c:30:e8:f9:69:8d:23:73:0b:12:6f:47:a9:ae:39: 11:f8:2a:b1:9b:b0:1a:c3:8e:eb:59:96:00:ad:ce:0c:4d:b2: d0:31:a6:08:5c:2a:7a:fc:e2:7a:1d:57:4c:a8:65:18:e9:79: 40:62:25:96:6e:c7:c7:37:6a:83:21:08:8e:41:ea:dd:d9:57: 3f:1d:77:49:87:2a:16:06:5e:a6:38:6a:22:12:a3:51:19:83: 7e:b6
Certificate: Data: Version: 3 (0x2) Serial Number: 0e:cf:f4:38:c8:fe:bf:35:6e:04:d8:6a:98:1b:1a:50 Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2 Validity Not Before: Oct 18 00:00:00 2012 GMT Not After : Dec 29 23:59:59 2020 GMT Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer - G4 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:a2:63:0b:39:44:b8:bb:23:a7:44:49:bb:0e:ff: a1:f0:61:0a:53:93:b0:98:db:ad:2c:0f:4a:c5:6e: ff:86:3c:53:55:0f:15:ce:04:3f:2b:fd:a9:96:96: d9:be:61:79:0b:5b:c9:4c:86:76:e5:e0:43:4b:22: 95:ee:c2:2b:43:c1:9f:d8:68:b4:8e:40:4f:ee:85: 38:b9:11:c5:23:f2:64:58:f0:15:32:6f:4e:57:a1: ae:88:a4:02:d7:2a:1e:cd:4b:e1:dd:63:d5:17:89: 32:5b:b0:5e:99:5a:a8:9d:28:50:0e:17:ee:96:db: 61:3b:45:51:1d:cf:12:56:0b:92:47:fc:ab:ae:f6: 66:3d:47:ac:70:72:e7:92:e7:5f:cd:10:b9:c4:83: 64:94:19:bd:25:80:e1:e8:d2:22:a5:d0:ba:02:7a: a1:77:93:5b:65:c3:ee:17:74:bc:41:86:2a:dc:08: 4c:8c:92:8c:91:2d:9e:77:44:1f:68:d6:a8:74:77: db:0e:5b:32:8b:56:8b:33:bd:d9:63:c8:49:9d:3a: c5:c5:ea:33:0b:d2:f1:a3:1b:f4:8b:be:d9:b3:57: 8b:3b:de:04:a7:7a:22:b2:24:ae:2e:c7:70:c5:be: 4e:83:26:08:fb:0b:bd:a9:4f:99:08:e1:10:28:72: aa:cd Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: critical Time Stamping X509v3 Key Usage: critical Digital Signature Authority Information Access: OCSP - URI:http://ts-ocsp.ws.symantec.com CA Issuers - URI:http://ts-aia.ws.symantec.com/tss-ca-g2.cer X509v3 CRL Distribution Points: Full Name: URI:http://ts-crl.ws.symantec.com/tss-ca-g2.crl X509v3 Subject Alternative Name: DirName:/CN=TimeStamp-2048-2 X509v3 Subject Key Identifier: 46:C6:69:A3:0E:4A:14:1E:D5:4C:DA:52:63:17:3F:5E:36:BC:0D:E6 X509v3 Authority Key Identifier: keyid:5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD Signature Algorithm: sha1WithRSAEncryption 78:3b:b4:91:2a:00:4c:f0:8f:62:30:37:78:a3:84:27:07:6f: 18:b2:de:25:dc:a0:d4:94:03:aa:86:4e:25:9f:9a:40:03:1c: dd:ce:e3:79:cb:21:68:06:da:b6:32:b4:6d:bf:f4:2c:26:63: 33:e4:49:64:6d:0d:e6:c3:67:0e:f7:05:a4:35:6c:7c:89:16: c6:e9:b2:df:b2:e9:dd:20:c6:71:0f:cd:95:74:dc:b6:5c:de: bd:37:1f:43:78:e6:78:b5:cd:28:04:20:a3:aa:f1:4b:c4:88: 29:91:0e:80:d1:11:fc:dd:5c:76:6e:4f:5e:0e:45:46:41:6e: 0d:b0:ea:38:9a:b1:3a:da:09:71:10:fc:1c:79:b4:80:7b:ac: 69:f4:fd:9c:b6:0c:16:2b:f1:7f:5b:09:3d:9b:5b:e2:16:ca: 13:81:6d:00:2e:38:0d:a8:29:8f:2c:e1:b2:f4:5a:a9:01:af: 15:9c:2c:2f:49:1b:db:22:bb:c3:fe:78:94:51:c3:86:b1:82: 88:5d:f0:3d:b4:51:a1:79:33:2b:2e:7b:b9:dc:20:09:13:71: eb:6a:19:5b:cf:e8:a5:30:57:2c:89:49:3f:b9:cf:7f:c9:bf: 3e:22:68:63:53:9a:bd:69:74:ac:c5:1d:3c:7f:92:e0:c3:bc: 1c:d8:04:75
Certificate: Data: Version: 3 (0x2) Serial Number: 513 (0x201) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority Validity Not Before: Nov 16 01:15:40 2006 GMT Not After : Nov 16 01:15:40 2026 GMT Subject: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository, CN=Starfield Secure Certification Authority/serialNumber=10688435 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:e2:a7:5d:a3:ed:66:ef:6a:2f:2b:36:1f:dd:8d: d3:05:02:a0:ca:0f:5e:19:ae:38:72:cf:16:da:54: 4a:cb:48:0a:f4:a1:73:11:65:85:43:c9:5b:17:0c: 9a:2b:be:0f:98:51:7a:60:29:0d:6c:de:e2:e8:e5: 15:4d:56:ff:90:d1:a7:a6:04:3f:60:07:4a:ca:6f: a5:10:e7:b3:f8:5c:b1:bc:2b:2a:dc:01:79:f5:1d: 35:f5:7a:28:83:f2:93:73:82:89:ac:60:6d:cb:c2: 48:c2:1d:d4:06:44:17:3c:ac:01:47:ab:3e:70:84: 09:0b:b8:20:08:40:20:87:a1:63:1a:ca:3e:83:d2: 37:b3:98:8d:32:3f:37:bf:a1:b7:5b:5f:de:5c:33: 92:cf:3e:07:ce:b9:48:4b:e2:f0:55:50:2f:f8:70: 42:89:d1:93:96:8a:63:d9:66:0d:e6:58:6e:b9:6d: 90:bd:ca:dc:84:66:f2:39:8e:5b:a6:58:55:73:cb: 62:6c:1b:d7:20:16:3b:2c:59:f5:cb:c8:56:32:4a: 50:27:ba:55:d3:a8:01:cb:72:a9:74:8b:0c:ad:3a: e5:15:b6:2a:df:65:f8:de:8a:f5:ef:84:3b:f9:e7: 54:65:0b:80:bd:47:45:a5:f0:44:d8:53:3b:be:80: f1:2f Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 49:4B:52:27:D1:1B:BC:F2:A1:21:6A:62:7B:51:42:7A:8A:D7:D5:56 X509v3 Authority Key Identifier: keyid:BF:5F:B7:D1:CE:DD:1F:86:F4:5B:55:AC:DC:D7:10:C2:0E:A9:88:E7 X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 Authority Information Access: OCSP - URI:http://ocsp.starfieldtech.com X509v3 CRL Distribution Points: Full Name: URI:http://certificates.starfieldtech.com/repository/sfroot.crl X509v3 Certificate Policies: Policy: X509v3 Any Policy CPS: http://certificates.starfieldtech.com/repository X509v3 Key Usage: critical Certificate Sign, CRL Sign Signature Algorithm: sha1WithRSAEncryption 86:52:ba:b3:1f:a6:5e:6b:90:a6:64:2a:fc:45:b2:ae:9f:3e: b3:62:af:db:1f:67:c4:bd:ca:a1:2f:c7:9c:0d:21:57:d0:f8: 36:21:ce:3a:25:3e:78:76:b3:d9:dd:bc:de:fb:6c:84:5f:0c: a3:0d:12:eb:11:3b:71:5f:80:1e:f1:1f:6d:0e:5f:c1:ec:d4: a5:f7:65:bb:1f:4c:95:01:13:b2:6a:9c:0b:eb:1f:9d:b1:e7: ed:19:0d:bc:85:7c:f3:17:bd:59:63:ae:a7:1a:05:cd:47:e3: 2d:96:62:51:32:0a:08:68:4b:22:77:5f:f7:45:dc:61:de:f4: cb:2b:22:29:44:25:d2:9f:0b:77:7a:a1:26:7c:4a:d7:0f:c2: d1:3c:ba:0e:a7:95:9a:5b:05:0a:10:f9:55:5f:c1:97:8b:74: cc:5e:28:69:13:7e:d0:0a:8d:9d:0f:60:54:7a:c4:8c:1b:35: 0f:74:7a:70:b2:82:cf:1d:b5:e2:8a:db:2a:c6:b2:51:69:bf: 12:17:92:60:17:aa:3d:5b:09:f8:87:65:1d:a7:a4:28:e5:22: 02:03:82:44:9a:34:63:9e:fb:28:cf:e8:cd:2e:0e:52:20:ed: 4a:cb:38:7c:9d:ae:6e:79:d7:95:2c:a8:91:f3:86:01:21:91: 4b:b5:40:a4
Certificate: Data: Version: 3 (0x2) Serial Number: 1199628710669297 (0x4430e53296bf1) Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository, CN=Starfield Secure Certification Authority/serialNumber=10688435 Validity Not Before: May 3 07:56:10 2013 GMT Not After : May 3 20:33:52 2016 GMT Subject: C=US, ST=CA, L=Fremont, O=Foxit Corporation, CN=Foxit Corporation Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:b0:4d:62:15:13:e4:06:4f:47:8f:c3:3d:b2:40: b6:3b:e1:71:ec:3a:44:8a:29:54:ad:c8:1d:92:6f: 8c:26:58:28:11:b3:7a:13:1a:f0:8c:87:12:6b:f4: 49:4d:d3:e3:e9:5f:02:d7:3d:9c:5f:12:fc:d9:9b: d1:6e:e5:69:f7:6a:0b:02:b6:37:94:c9:0a:3c:16: e7:cf:1c:5d:68:58:36:ba:e6:77:32:d7:09:c2:f2: 7b:85:87:19:55:99:c8:fc:eb:5a:79:25:9d:f1:52: 9f:bd:ff:79:d2:14:5c:39:03:f1:c1:b5:18:47:89: 48:ad:f3:db:24:af:8e:60:49:9d:b3:3b:64:41:7a: 7f:f8:3a:f6:0c:d1:c4:e4:ad:78:ff:df:3b:f5:69: f6:c6:a6:a6:3c:79:96:cc:07:43:1e:b1:b5:0c:ff: 8a:83:eb:8e:54:28:e0:69:59:4e:4b:c6:02:76:a8: 35:05:e2:15:04:c5:52:0e:6d:f9:e6:0a:b0:3a:a6: 0c:71:a0:e2:b7:fc:53:c3:1c:20:68:75:71:55:82: 78:2d:dc:ac:c4:1a:c6:c9:b6:5b:42:cb:97:93:53: 8d:32:49:a9:87:5b:02:a8:ba:54:82:1f:3d:b4:44: bf:69:28:1b:7e:9d:8f:73:bb:c6:c6:a4:b1:07:a5: bc:e3 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: Code Signing X509v3 Key Usage: critical Digital Signature X509v3 CRL Distribution Points: Full Name: URI:http://crl.starfieldtech.com/sfs5-16.crl X509v3 Certificate Policies: Policy: 2.16.840.1.114414.1.7.23.2 CPS: http://certificates.starfieldtech.com/repository/ Authority Information Access: OCSP - URI:http://ocsp.starfieldtech.com/ CA Issuers - URI:http://certificates.starfieldtech.com/repository/sf_intermediate.crt X509v3 Authority Key Identifier: keyid:49:4B:52:27:D1:1B:BC:F2:A1:21:6A:62:7B:51:42:7A:8A:D7:D5:56 X509v3 Subject Key Identifier: 79:25:0D:FC:D3:6E:CD:74:F6:87:2D:8B:DA:CA:7D:73:05:75:8C:F2 Signature Algorithm: sha1WithRSAEncryption 10:17:c0:72:55:68:96:80:aa:59:87:88:bc:b9:c6:ca:21:b3: ec:d2:0c:da:86:c7:80:21:e8:dd:e5:57:22:a7:d1:27:c5:78: 3c:7f:9a:a1:2e:8d:43:b0:38:81:fb:f1:6d:e0:e8:ca:b5:f0: cd:70:04:d8:82:10:af:86:95:09:b7:33:a9:a5:12:c1:6d:ae: 75:70:91:a7:e6:e9:6a:f2:3a:64:e3:a8:2f:dd:92:03:ab:42: a8:81:07:8c:59:37:e8:4f:e7:43:2a:9c:43:3d:fd:6f:3f:24: d6:a1:2e:0d:cc:87:fb:cb:1b:3a:64:47:7a:c7:1d:db:c4:66: d7:e7:aa:ca:4b:65:bc:a1:4d:74:a7:a8:38:09:e6:60:6b:a2: ec:c9:a0:4b:e8:71:02:2a:26:fb:ce:c9:1c:d7:9a:00:93:ae: 17:83:cc:ee:27:73:d1:02:2d:4e:89:0f:b4:c3:e2:eb:50:47: a6:66:b8:44:b5:08:f0:d0:d2:9f:b6:80:bd:d6:0d:9d:d2:c3: 46:cf:4d:14:ec:25:12:56:a4:b3:b8:6b:36:64:13:02:1a:d6: 43:f5:4a:c2:25:72:42:03:7a:90:9c:d6:6c:1e:98:e2:dd:b2: a5:66:0d:35:9f:66:d0:97:8f:1d:45:d0:00:db:3d:e5:fb:0c: 13:53:4d:8e
pkcs7-signedData
- 1
- SHA1: nil
- 1.3.6.1.4.1.311.2.1.4
- #0
- 1.3.6.1.4.1.311.2.1.15
- :
00 3c 00 3c 00 3c 00 4f 00 62 00 73 00 6f 00 6c |.<.<.<.O.b.s.o.l| 00 65 00 74 00 65 00 3e 00 3e 00 3e |.e.t.e.>.>.> |
- :
- SHA1
01 3a b9 b9 18 aa 3a 90 81 5d 5d 9e 17 c9 55 57 |.:....:..]]...UW| 43 78 d5 3c |Cx.< |
- 1.3.6.1.4.1.311.2.1.15
- #0
- Certificates
- Certificate #0
- 2
- 7E:93:EB:FB:7C:C6:4E:59:EA:4B:9A:77:D4:06:FC:3B
- RSA-SHA1: nil
- Issuer
- C: ZA
- ST: Western Cape
- L: Durbanville
- O: Thawte
- OU: Thawte Certification
- CN: Thawte Timestamping CA
- 2012-12-21 00:00:00 UTC: 2020-12-30 23:59:59 UTC
- Subject
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- #5
- rsaEncryption: nil
- B1:AC:B3:49:54:4B:97:1C:12:0A:D8:25:79:91:22:57:
2A:6F:DC:B8:26:C4:43:73:6B:C2:BF:2E:50:5A:FB:14:
C2:76:8E:43:01:25:43:B4:A1:E2:45:F4:E8:B7:7B:C3:
74:CC:22:D7:B4:94:00:02:F7:4D:ED:BF:B4:B7:44:24:
6B:CD:5F:45:3B:D1:44:CE:43:12:73:17:82:8B:69:B4:
2B:CB:99:1E:AC:72:1B:26:4D:71:1F:B1:31:DD:FB:51:
61:02:53:A6:AA:F5:49:2C:05:78:45:A5:2F:89:CE:E7:
99:E7:FE:8C:E2:57:3F:3D:C6:92:DC:4A:F8:7B:33:E4:
79:0A:FB:F0:75:88:41:9C:FF:C5:03:51:99:AA:D7:6C:
9F:93:69:87:65:29:83:85:C2:60:14:C4:C8:C9:3B:14:
DA:C0:81:F0:1F:0D:74:DE:92:22:AB:CA:F7:FB:74:7C:
27:E6:F7:4A:1B:7F:A7:C3:9E:2D:AE:8A:EA:A6:E6:AA:
27:16:7D:61:F7:98:71:11:BC:E2:50:A1:4B:E5:5D:FA:
E5:0E:A7:2C:9F:AA:65:20:D3:D8:96:E8:C8:7C:A5:4E:
48:44:FF:19:E2:44:07:92:0B:D7:68:84:80:5D:6A:78:
64:45:CD:60:46:7E:54:C1:13:7C:C5:79:F1:C9:C1:71: 0x010001
- #6
- subjectKeyIdentifier:
5f 9a f5 6e 5c cc cc 74 9a d4 dd 7d ef 3f db ec |_..n\..t...}.?..| 4c 80 2e dd |L... |
- authorityInfoAccess
- OCSP: http://ocsp.thawte.com
- basicConstraints
- true
- true: 0
- crlDistributionPoints: http://crl.thawte.com/ThawteTimestampingCA.crl
- extendedKeyUsage: timeStamping
- keyUsage: true, 6
- subjectAltName
- CN: TimeStamp-2048-1
- subjectKeyIdentifier:
- RSA-SHA1:
03 09 9b 8f 79 ef 7f 59 30 aa ef 68 b5 fa e3 09 |....y..Y0..h....| 1d bb 4f 82 06 5d 37 5f a6 52 9f 16 8d ea 1c 92 |..O..]7_.R......| 09 44 6e f5 6d eb 58 7c 30 e8 f9 69 8d 23 73 0b |.Dn.m.X|0..i.#s.| 12 6f 47 a9 ae 39 11 f8 2a b1 9b b0 1a c3 8e eb |.oG..9..*.......| 59 96 00 ad ce 0c 4d b2 d0 31 a6 08 5c 2a 7a fc |Y.....M..1..\*z.| e2 7a 1d 57 4c a8 65 18 e9 79 40 62 25 96 6e c7 |.z.WL.e..y@b%.n.| c7 37 6a 83 21 08 8e 41 ea dd d9 57 3f 1d 77 49 |.7j.!..A...W?.wI| 87 2a 16 06 5e a6 38 6a 22 12 a3 51 19 83 7e b6 |.*..^.8j"..Q..~.|
- 2
- Certificate #1
- 2
- 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
- RSA-SHA1: nil
- Issuer
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- 2012-10-18 00:00:00 UTC: 2020-12-29 23:59:59 UTC
- Subject
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services Signer - G4
- #5
- rsaEncryption: nil
- A2:63:0B:39:44:B8:BB:23:A7:44:49:BB:0E:FF:A1:F0:
61:0A:53:93:B0:98:DB:AD:2C:0F:4A:C5:6E:FF:86:3C:
53:55:0F:15:CE:04:3F:2B:FD:A9:96:96:D9:BE:61:79:
0B:5B:C9:4C:86:76:E5:E0:43:4B:22:95:EE:C2:2B:43:
C1:9F:D8:68:B4:8E:40:4F:EE:85:38:B9:11:C5:23:F2:
64:58:F0:15:32:6F:4E:57:A1:AE:88:A4:02:D7:2A:1E:
CD:4B:E1:DD:63:D5:17:89:32:5B:B0:5E:99:5A:A8:9D:
28:50:0E:17:EE:96:DB:61:3B:45:51:1D:CF:12:56:0B:
92:47:FC:AB:AE:F6:66:3D:47:AC:70:72:E7:92:E7:5F:
CD:10:B9:C4:83:64:94:19:BD:25:80:E1:E8:D2:22:A5:
D0:BA:02:7A:A1:77:93:5B:65:C3:EE:17:74:BC:41:86:
2A:DC:08:4C:8C:92:8C:91:2D:9E:77:44:1F:68:D6:A8:
74:77:DB:0E:5B:32:8B:56:8B:33:BD:D9:63:C8:49:9D:
3A:C5:C5:EA:33:0B:D2:F1:A3:1B:F4:8B:BE:D9:B3:57:
8B:3B:DE:04:A7:7A:22:B2:24:AE:2E:C7:70:C5:BE:4E:
83:26:08:FB:0B:BD:A9:4F:99:08:E1:10:28:72:AA:CD: 0x010001
- X509v3 extensions
- basicConstraints
- true
- nil
- extendedKeyUsage: true, timeStamping
- keyUsage: true, 0x80
- authorityInfoAccess
- #0
- OCSP: http://ts-ocsp.ws.symantec.com
- caIssuers: http://ts-aia.ws.symantec.com/tss-ca-g2.cer
- #0
- crlDistributionPoints: http://ts-crl.ws.symantec.com/tss-ca-g2.crl
- subjectAltName
- CN: TimeStamp-2048-2
- subjectKeyIdentifier:
46 c6 69 a3 0e 4a 14 1e d5 4c da 52 63 17 3f 5e |F.i..J...L.Rc.?^| 36 bc 0d e6 |6... |
- authorityKeyIdentifier:
5f 9a f5 6e 5c cc cc 74 9a d4 dd 7d ef 3f db ec |_..n\..t...}.?..| 4c 80 2e dd |L... |
- basicConstraints
- RSA-SHA1:
78 3b b4 91 2a 00 4c f0 8f 62 30 37 78 a3 84 27 |x;..*.L..b07x..'| 07 6f 18 b2 de 25 dc a0 d4 94 03 aa 86 4e 25 9f |.o...%.......N%.| 9a 40 03 1c dd ce e3 79 cb 21 68 06 da b6 32 b4 |.@.....y.!h...2.| 6d bf f4 2c 26 63 33 e4 49 64 6d 0d e6 c3 67 0e |m..,&c3.Idm...g.| f7 05 a4 35 6c 7c 89 16 c6 e9 b2 df b2 e9 dd 20 |...5l|......... | c6 71 0f cd 95 74 dc b6 5c de bd 37 1f 43 78 e6 |.q...t..\..7.Cx.| 78 b5 cd 28 04 20 a3 aa f1 4b c4 88 29 91 0e 80 |x..(. ...K..)...| d1 11 fc dd 5c 76 6e 4f 5e 0e 45 46 41 6e 0d b0 |....\vnO^.EFAn..| ea 38 9a b1 3a da 09 71 10 fc 1c 79 b4 80 7b ac |.8..:..q...y..{.| 69 f4 fd 9c b6 0c 16 2b f1 7f 5b 09 3d 9b 5b e2 |i......+..[.=.[.| 16 ca 13 81 6d 00 2e 38 0d a8 29 8f 2c e1 b2 f4 |....m..8..).,...| 5a a9 01 af 15 9c 2c 2f 49 1b db 22 bb c3 fe 78 |Z.....,/I.."...x| 94 51 c3 86 b1 82 88 5d f0 3d b4 51 a1 79 33 2b |.Q.....].=.Q.y3+| 2e 7b b9 dc 20 09 13 71 eb 6a 19 5b cf e8 a5 30 |.{.. ..q.j.[...0| 57 2c 89 49 3f b9 cf 7f c9 bf 3e 22 68 63 53 9a |W,.I?.....>"hcS.| bd 69 74 ac c5 1d 3c 7f 92 e0 c3 bc 1c d8 04 75 |.it...<........u|
- 2
- Certificate #2
- 2
- 0x0201
- RSA-SHA1: nil
- Issuer
- C: US
- O: Starfield Technologies, Inc.
- OU: Starfield Class 2 Certification Authority
- 2006-11-16 01:15:40 UTC: 2026-11-16 01:15:40 UTC
- Subject
- C: US
- ST: Arizona
- L: Scottsdale
- O: Starfield Technologies, Inc.
- OU: http://certificates.starfieldtech.com/repository
- CN: Starfield Secure Certification Authority
- serialNumber: 10688435
- #5
- rsaEncryption: nil
- E2:A7:5D:A3:ED:66:EF:6A:2F:2B:36:1F:DD:8D:D3:05:
02:A0:CA:0F:5E:19:AE:38:72:CF:16:DA:54:4A:CB:48:
0A:F4:A1:73:11:65:85:43:C9:5B:17:0C:9A:2B:BE:0F:
98:51:7A:60:29:0D:6C:DE:E2:E8:E5:15:4D:56:FF:90:
D1:A7:A6:04:3F:60:07:4A:CA:6F:A5:10:E7:B3:F8:5C:
B1:BC:2B:2A:DC:01:79:F5:1D:35:F5:7A:28:83:F2:93:
73:82:89:AC:60:6D:CB:C2:48:C2:1D:D4:06:44:17:3C:
AC:01:47:AB:3E:70:84:09:0B:B8:20:08:40:20:87:A1:
63:1A:CA:3E:83:D2:37:B3:98:8D:32:3F:37:BF:A1:B7:
5B:5F:DE:5C:33:92:CF:3E:07:CE:B9:48:4B:E2:F0:55:
50:2F:F8:70:42:89:D1:93:96:8A:63:D9:66:0D:E6:58:
6E:B9:6D:90:BD:CA:DC:84:66:F2:39:8E:5B:A6:58:55:
73:CB:62:6C:1B:D7:20:16:3B:2C:59:F5:CB:C8:56:32:
4A:50:27:BA:55:D3:A8:01:CB:72:A9:74:8B:0C:AD:3A:
E5:15:B6:2A:DF:65:F8:DE:8A:F5:EF:84:3B:F9:E7:54:
65:0B:80:BD:47:45:A5:F0:44:D8:53:3B:BE:80:F1:2F: 0x010001
- #6
- subjectKeyIdentifier:
49 4b 52 27 d1 1b bc f2 a1 21 6a 62 7b 51 42 7a |IKR'.....!jb{QBz| 8a d7 d5 56 |...V |
- authorityKeyIdentifier:
bf 5f b7 d1 ce dd 1f 86 f4 5b 55 ac dc d7 10 c2 |._.......[U.....| 0e a9 88 e7 |.... |
- basicConstraints
- true
- true: 0
- authorityInfoAccess
- OCSP: http://ocsp.starfieldtech.com
- crlDistributionPoints: http://certificates.starfieldtech.com/repository/sfroot.crl
- certificatePolicies
- anyPolicy
- id-qt-cps: http://certificates.starfieldtech.com/repository
- anyPolicy
- keyUsage: true, 6
- subjectKeyIdentifier:
- RSA-SHA1:
86 52 ba b3 1f a6 5e 6b 90 a6 64 2a fc 45 b2 ae |.R....^k..d*.E..| 9f 3e b3 62 af db 1f 67 c4 bd ca a1 2f c7 9c 0d |.>.b...g..../...| 21 57 d0 f8 36 21 ce 3a 25 3e 78 76 b3 d9 dd bc |!W..6!.:%>xv....| de fb 6c 84 5f 0c a3 0d 12 eb 11 3b 71 5f 80 1e |..l._......;q_..| f1 1f 6d 0e 5f c1 ec d4 a5 f7 65 bb 1f 4c 95 01 |..m._.....e..L..| 13 b2 6a 9c 0b eb 1f 9d b1 e7 ed 19 0d bc 85 7c |..j............|| f3 17 bd 59 63 ae a7 1a 05 cd 47 e3 2d 96 62 51 |...Yc.....G.-.bQ| 32 0a 08 68 4b 22 77 5f f7 45 dc 61 de f4 cb 2b |2..hK"w_.E.a...+| 22 29 44 25 d2 9f 0b 77 7a a1 26 7c 4a d7 0f c2 |")D%...wz.&|J...| d1 3c ba 0e a7 95 9a 5b 05 0a 10 f9 55 5f c1 97 |.<.....[....U_..| 8b 74 cc 5e 28 69 13 7e d0 0a 8d 9d 0f 60 54 7a |.t.^(i.~.....`Tz| c4 8c 1b 35 0f 74 7a 70 b2 82 cf 1d b5 e2 8a db |...5.tzp........| 2a c6 b2 51 69 bf 12 17 92 60 17 aa 3d 5b 09 f8 |*..Qi....`..=[..| 87 65 1d a7 a4 28 e5 22 02 03 82 44 9a 34 63 9e |.e...(."...D.4c.| fb 28 cf e8 cd 2e 0e 52 20 ed 4a cb 38 7c 9d ae |.(.....R .J.8|..| 6e 79 d7 95 2c a8 91 f3 86 01 21 91 4b b5 40 a4 |ny..,.....!.K.@.|
- 2
- Certificate #3
- 2
- 04:43:0E:53:29:6B:F1
- RSA-SHA1: nil
- Issuer
- C: US
- ST: Arizona
- L: Scottsdale
- O: Starfield Technologies, Inc.
- OU: http://certificates.starfieldtech.com/repository
- CN: Starfield Secure Certification Authority
- serialNumber: 10688435
- 2013-05-03 07:56:10 UTC: 2016-05-03 20:33:52 UTC
- Subject
- C: US
- ST: CA
- L: Fremont
- O: Foxit Corporation
- CN: Foxit Corporation
- #5
- rsaEncryption: nil
- B0:4D:62:15:13:E4:06:4F:47:8F:C3:3D:B2:40:B6:3B:
E1:71:EC:3A:44:8A:29:54:AD:C8:1D:92:6F:8C:26:58:
28:11:B3:7A:13:1A:F0:8C:87:12:6B:F4:49:4D:D3:E3:
E9:5F:02:D7:3D:9C:5F:12:FC:D9:9B:D1:6E:E5:69:F7:
6A:0B:02:B6:37:94:C9:0A:3C:16:E7:CF:1C:5D:68:58:
36:BA:E6:77:32:D7:09:C2:F2:7B:85:87:19:55:99:C8:
FC:EB:5A:79:25:9D:F1:52:9F:BD:FF:79:D2:14:5C:39:
03:F1:C1:B5:18:47:89:48:AD:F3:DB:24:AF:8E:60:49:
9D:B3:3B:64:41:7A:7F:F8:3A:F6:0C:D1:C4:E4:AD:78:
FF:DF:3B:F5:69:F6:C6:A6:A6:3C:79:96:CC:07:43:1E:
B1:B5:0C:FF:8A:83:EB:8E:54:28:E0:69:59:4E:4B:C6:
02:76:A8:35:05:E2:15:04:C5:52:0E:6D:F9:E6:0A:B0:
3A:A6:0C:71:A0:E2:B7:FC:53:C3:1C:20:68:75:71:55:
82:78:2D:DC:AC:C4:1A:C6:C9:B6:5B:42:CB:97:93:53:
8D:32:49:A9:87:5B:02:A8:BA:54:82:1F:3D:B4:44:BF:
69:28:1B:7E:9D:8F:73:BB:C6:C6:A4:B1:07:A5:BC:E3: 0x010001
- X509v3 extensions
- basicConstraints: true, false
- extendedKeyUsage: codeSigning
- keyUsage: true, 0x80
- crlDistributionPoints: http://crl.starfieldtech.com/sfs5-16.crl
- certificatePolicies
- 2.16.840.1.114414.1.7.23.2
- id-qt-cps: http://certificates.starfieldtech.com/repository/
- 2.16.840.1.114414.1.7.23.2
- authorityInfoAccess
- #0
- OCSP: http://ocsp.starfieldtech.com/
- caIssuers: http://certificates.starfieldtech.com/repository/sf_intermediate.crt
- #0
- authorityKeyIdentifier:
49 4b 52 27 d1 1b bc f2 a1 21 6a 62 7b 51 42 7a |IKR'.....!jb{QBz| 8a d7 d5 56 |...V |
- subjectKeyIdentifier:
79 25 0d fc d3 6e cd 74 f6 87 2d 8b da ca 7d 73 |y%...n.t..-...}s| 05 75 8c f2 |.u.. |
- RSA-SHA1:
10 17 c0 72 55 68 96 80 aa 59 87 88 bc b9 c6 ca |...rUh...Y......| 21 b3 ec d2 0c da 86 c7 80 21 e8 dd e5 57 22 a7 |!........!...W".| d1 27 c5 78 3c 7f 9a a1 2e 8d 43 b0 38 81 fb f1 |.'.x<.....C.8...| 6d e0 e8 ca b5 f0 cd 70 04 d8 82 10 af 86 95 09 |m......p........| b7 33 a9 a5 12 c1 6d ae 75 70 91 a7 e6 e9 6a f2 |.3....m.up....j.| 3a 64 e3 a8 2f dd 92 03 ab 42 a8 81 07 8c 59 37 |:d../....B....Y7| e8 4f e7 43 2a 9c 43 3d fd 6f 3f 24 d6 a1 2e 0d |.O.C*.C=.o?$....| cc 87 fb cb 1b 3a 64 47 7a c7 1d db c4 66 d7 e7 |.....:dGz....f..| aa ca 4b 65 bc a1 4d 74 a7 a8 38 09 e6 60 6b a2 |..Ke..Mt..8..`k.| ec c9 a0 4b e8 71 02 2a 26 fb ce c9 1c d7 9a 00 |...K.q.*&.......| 93 ae 17 83 cc ee 27 73 d1 02 2d 4e 89 0f b4 c3 |......'s..-N....| e2 eb 50 47 a6 66 b8 44 b5 08 f0 d0 d2 9f b6 80 |..PG.f.D........| bd d6 0d 9d d2 c3 46 cf 4d 14 ec 25 12 56 a4 b3 |......F.M..%.V..| b8 6b 36 64 13 02 1a d6 43 f5 4a c2 25 72 42 03 |.k6d....C.J.%rB.| 7a 90 9c d6 6c 1e 98 e2 dd b2 a5 66 0d 35 9f 66 |z...l......f.5.f| d0 97 8f 1d 45 d0 00 db 3d e5 fb 0c 13 53 4d 8e |....E...=....SM.|
- 2
- Certificate #0
- Signer
- 1
- unnamed
- #0
- C: US
- ST: Arizona
- L: Scottsdale
- O: Starfield Technologies, Inc.
- OU: http://certificates.starfieldtech.com/repository
- CN: Starfield Secure Certification Authority
- serialNumber: 10688435
- 04:43:0E:53:29:6B:F1
- #0
- SHA1: nil
- #3
- 1.3.6.1.4.1.311.2.1.12
- nil
- contentType: 1.3.6.1.4.1.311.2.1.4
- 1.3.6.1.4.1.311.2.1.11: msCodeInd
- messageDigest:
d6 9a 4d 8d 00 c5 66 fe 7c 45 87 e1 56 71 13 17 |..M...f.|E..Vq..| 00 c2 0b 40 |...@ |
- 1.3.6.1.4.1.311.2.1.12
- rsaEncryption:
1b bf eb 6d 47 c8 8b b6 23 c5 ca 5e 45 0a c1 8e |...mG...#..^E...| e8 79 a1 f6 bf 2d 87 f5 2c ec 01 d0 e3 0b c6 02 |.y...-..,.......| c4 0f 6f 7c 46 70 85 90 2b 59 4a ca 6b d6 23 f0 |..o|Fp..+YJ.k.#.| e8 c8 e1 aa fa 27 a7 c7 12 93 91 1f be fe af 01 |.....'..........| d9 90 c8 1d 07 0e 89 53 76 e4 02 82 36 52 34 43 |.......Sv...6R4C| a4 60 c8 dc 40 98 46 47 57 11 b8 52 2e eb 28 62 |.`..@.FGW..R..(b| 7f 79 c6 1a bb 22 fd 53 94 7a 7d 81 9e 0e 98 9b |.y...".S.z}.....| 5a 25 e5 ec f0 7f 1c af 19 a6 43 58 59 92 fd cf |Z%........CXY...| 97 ee 78 8e 55 9a 27 09 97 7b 12 10 87 c7 5d 39 |..x.U.'..{....]9| 5e 14 21 87 07 72 5c da 1c 94 97 f4 da ac 8c 54 |^.!..r\........T| 39 93 a1 5d 7a 3a 38 6a 76 3e f7 42 46 7d e7 fd |9..]z:8jv>.BF}..| 89 23 2b 2a d6 b6 70 86 e8 db 01 d5 cd 95 ef 71 |.#+*..p........q| f4 d5 be ed 42 ae e9 25 3f 52 1b 28 0a d4 e1 db |....B..%?R.(....| 08 75 8a d0 27 b3 fa 25 ec 98 c3 68 ca 02 ac 80 |.u..'..%...h....| 25 ce c2 6b eb ab 54 c0 cf 1e 4c b8 4b 9c 2a dd |%..k..T...L.K.*.| 8e 09 c6 51 da 9c ea 62 9b 57 97 73 90 32 f0 87 |...Q...b.W.s.2..|
- countersignature
- 1
- unnamed
- #0
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
- #0
- SHA1: nil
- #2
- contentType: pkcs7-data
- signingTime: 2014-04-14 10:06:42 UTC
- messageDigest:
c0 38 1e 1e fd 4a 1d c1 7b c0 da 49 a1 b5 f2 bd |.8...J..{..I....| 33 64 8b 13 |3d.. |
- rsaEncryption:
2c 31 e2 b3 eb a5 08 da 1a 15 2a 4f 0a 71 7a 4d |,1........*O.qzM| d5 95 24 fc b8 b2 2b 4e da 7b 94 62 9f e6 6c 7f |..$...+N.{.b..l.| 3c e7 d0 aa 38 e7 91 81 73 a0 6d bf e2 c8 b4 30 |<...8...s.m....0| 12 f7 59 37 b8 07 c5 0b d3 61 30 83 e1 4f b3 bf |..Y7.....a0..O..| 00 4e fc 41 09 43 ad 47 69 17 52 38 72 07 68 47 |.N.A.C.Gi.R8r.hG| 52 dc f9 f7 73 79 64 36 d3 5f ad 2a 84 b1 6b ed |R...syd6._.*..k.| 56 17 18 b8 09 a7 c3 a4 1c fd 40 cc d3 df 76 37 |V.........@...v7| 21 44 dc 2f 29 2b be b6 b4 b9 60 1d ea f2 65 4c |!D./)+....`...eL| a2 cf 2b bc 74 c0 ee 2b 45 13 b5 97 92 9f 6e 55 |..+.t..+E.....nU| 5a 26 95 cc bc 7a d9 23 5f 85 34 a5 4f 0f 2b eb |Z&...z.#_.4.O.+.| 15 df c9 40 76 e5 cc 21 d1 9c ba bc e2 63 32 1f |...@v..!.....c2.| de d3 be 86 47 33 32 8d 07 6f 5f d1 c9 b7 2e e7 |....G32..o_.....| 2c 4e 97 7b 25 38 2a 35 b8 74 bc 8e 64 76 35 0c |,N.{%8*5.t..dv5.| c8 45 de 73 4f d0 06 d1 c7 7c a4 fa 89 15 7a 0f |.E.sO....|....z.| 68 b0 88 40 1d 31 03 ad e7 25 09 e2 b5 a1 62 b9 |h..@.1...%....b.| 2d ab e4 62 3d 75 92 11 12 51 a0 c5 32 06 88 65 |-..b=u...Q..2..e|
- unnamed
- 1
offset | size | type | comment | |
---|---|---|---|---|
0 | 1273856 | EXE | 07/28/2016 22:01:03 | # |
15c1 | 15 | HTM | # | |
137000 | 6208 | PKCS7 | Authenticode Signature | # |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK