comments powered byDisqus

MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Sections

Data Directory

TLS

StringTable 040904E4

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Code Signing CA
serial: 529E3F9FCF7D58D520D607AB74395002

Certificates (4)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            7e:93:eb:fb:7c:c6:4e:59:ea:4b:9a:77:d4:06:fc:3b
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
        Validity
            Not Before: Dec 21 00:00:00 2012 GMT
            Not After : Dec 30 23:59:59 2020 GMT
        Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b1:ac:b3:49:54:4b:97:1c:12:0a:d8:25:79:91:
                    22:57:2a:6f:dc:b8:26:c4:43:73:6b:c2:bf:2e:50:
                    5a:fb:14:c2:76:8e:43:01:25:43:b4:a1:e2:45:f4:
                    e8:b7:7b:c3:74:cc:22:d7:b4:94:00:02:f7:4d:ed:
                    bf:b4:b7:44:24:6b:cd:5f:45:3b:d1:44:ce:43:12:
                    73:17:82:8b:69:b4:2b:cb:99:1e:ac:72:1b:26:4d:
                    71:1f:b1:31:dd:fb:51:61:02:53:a6:aa:f5:49:2c:
                    05:78:45:a5:2f:89:ce:e7:99:e7:fe:8c:e2:57:3f:
                    3d:c6:92:dc:4a:f8:7b:33:e4:79:0a:fb:f0:75:88:
                    41:9c:ff:c5:03:51:99:aa:d7:6c:9f:93:69:87:65:
                    29:83:85:c2:60:14:c4:c8:c9:3b:14:da:c0:81:f0:
                    1f:0d:74:de:92:22:ab:ca:f7:fb:74:7c:27:e6:f7:
                    4a:1b:7f:a7:c3:9e:2d:ae:8a:ea:a6:e6:aa:27:16:
                    7d:61:f7:98:71:11:bc:e2:50:a1:4b:e5:5d:fa:e5:
                    0e:a7:2c:9f:aa:65:20:d3:d8:96:e8:c8:7c:a5:4e:
                    48:44:ff:19:e2:44:07:92:0b:d7:68:84:80:5d:6a:
                    78:64:45:cd:60:46:7e:54:c1:13:7c:c5:79:f1:c9:
                    c1:71
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD
            Authority Information Access: 
                OCSP - URI:http://ocsp.thawte.com

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.thawte.com/ThawteTimestampingCA.crl

            X509v3 Extended Key Usage: 
                Time Stamping
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Subject Alternative Name: 
                DirName:/CN=TimeStamp-2048-1
    Signature Algorithm: sha1WithRSAEncryption
         03:09:9b:8f:79:ef:7f:59:30:aa:ef:68:b5:fa:e3:09:1d:bb:
         4f:82:06:5d:37:5f:a6:52:9f:16:8d:ea:1c:92:09:44:6e:f5:
         6d:eb:58:7c:30:e8:f9:69:8d:23:73:0b:12:6f:47:a9:ae:39:
         11:f8:2a:b1:9b:b0:1a:c3:8e:eb:59:96:00:ad:ce:0c:4d:b2:
         d0:31:a6:08:5c:2a:7a:fc:e2:7a:1d:57:4c:a8:65:18:e9:79:
         40:62:25:96:6e:c7:c7:37:6a:83:21:08:8e:41:ea:dd:d9:57:
         3f:1d:77:49:87:2a:16:06:5e:a6:38:6a:22:12:a3:51:19:83:
         7e:b6

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0e:cf:f4:38:c8:fe:bf:35:6e:04:d8:6a:98:1b:1a:50
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2
        Validity
            Not Before: Oct 18 00:00:00 2012 GMT
            Not After : Dec 29 23:59:59 2020 GMT
        Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer - G4
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a2:63:0b:39:44:b8:bb:23:a7:44:49:bb:0e:ff:
                    a1:f0:61:0a:53:93:b0:98:db:ad:2c:0f:4a:c5:6e:
                    ff:86:3c:53:55:0f:15:ce:04:3f:2b:fd:a9:96:96:
                    d9:be:61:79:0b:5b:c9:4c:86:76:e5:e0:43:4b:22:
                    95:ee:c2:2b:43:c1:9f:d8:68:b4:8e:40:4f:ee:85:
                    38:b9:11:c5:23:f2:64:58:f0:15:32:6f:4e:57:a1:
                    ae:88:a4:02:d7:2a:1e:cd:4b:e1:dd:63:d5:17:89:
                    32:5b:b0:5e:99:5a:a8:9d:28:50:0e:17:ee:96:db:
                    61:3b:45:51:1d:cf:12:56:0b:92:47:fc:ab:ae:f6:
                    66:3d:47:ac:70:72:e7:92:e7:5f:cd:10:b9:c4:83:
                    64:94:19:bd:25:80:e1:e8:d2:22:a5:d0:ba:02:7a:
                    a1:77:93:5b:65:c3:ee:17:74:bc:41:86:2a:dc:08:
                    4c:8c:92:8c:91:2d:9e:77:44:1f:68:d6:a8:74:77:
                    db:0e:5b:32:8b:56:8b:33:bd:d9:63:c8:49:9d:3a:
                    c5:c5:ea:33:0b:d2:f1:a3:1b:f4:8b:be:d9:b3:57:
                    8b:3b:de:04:a7:7a:22:b2:24:ae:2e:c7:70:c5:be:
                    4e:83:26:08:fb:0b:bd:a9:4f:99:08:e1:10:28:72:
                    aa:cd
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: critical
                Time Stamping
            X509v3 Key Usage: critical
                Digital Signature
            Authority Information Access: 
                OCSP - URI:http://ts-ocsp.ws.symantec.com
                CA Issuers - URI:http://ts-aia.ws.symantec.com/tss-ca-g2.cer

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://ts-crl.ws.symantec.com/tss-ca-g2.crl

            X509v3 Subject Alternative Name: 
                DirName:/CN=TimeStamp-2048-2
            X509v3 Subject Key Identifier: 
                46:C6:69:A3:0E:4A:14:1E:D5:4C:DA:52:63:17:3F:5E:36:BC:0D:E6
            X509v3 Authority Key Identifier: 
                keyid:5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD

    Signature Algorithm: sha1WithRSAEncryption
         78:3b:b4:91:2a:00:4c:f0:8f:62:30:37:78:a3:84:27:07:6f:
         18:b2:de:25:dc:a0:d4:94:03:aa:86:4e:25:9f:9a:40:03:1c:
         dd:ce:e3:79:cb:21:68:06:da:b6:32:b4:6d:bf:f4:2c:26:63:
         33:e4:49:64:6d:0d:e6:c3:67:0e:f7:05:a4:35:6c:7c:89:16:
         c6:e9:b2:df:b2:e9:dd:20:c6:71:0f:cd:95:74:dc:b6:5c:de:
         bd:37:1f:43:78:e6:78:b5:cd:28:04:20:a3:aa:f1:4b:c4:88:
         29:91:0e:80:d1:11:fc:dd:5c:76:6e:4f:5e:0e:45:46:41:6e:
         0d:b0:ea:38:9a:b1:3a:da:09:71:10:fc:1c:79:b4:80:7b:ac:
         69:f4:fd:9c:b6:0c:16:2b:f1:7f:5b:09:3d:9b:5b:e2:16:ca:
         13:81:6d:00:2e:38:0d:a8:29:8f:2c:e1:b2:f4:5a:a9:01:af:
         15:9c:2c:2f:49:1b:db:22:bb:c3:fe:78:94:51:c3:86:b1:82:
         88:5d:f0:3d:b4:51:a1:79:33:2b:2e:7b:b9:dc:20:09:13:71:
         eb:6a:19:5b:cf:e8:a5:30:57:2c:89:49:3f:b9:cf:7f:c9:bf:
         3e:22:68:63:53:9a:bd:69:74:ac:c5:1d:3c:7f:92:e0:c3:bc:
         1c:d8:04:75

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            52:9e:3f:9f:cf:7d:58:d5:20:d6:07:ab:74:39:50:02
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Code Signing CA
        Validity
            Not Before: Jun  2 00:00:00 2017 GMT
            Not After : Jun  1 23:59:59 2020 GMT
        Subject: C=DE/postalCode=10117, ST=Berlin, L=Berlin/street=Marienstrasse 12, O=win.rar GmbH, CN=win.rar GmbH
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:da:6c:b4:9e:19:d5:67:74:56:09:42:7e:60:35:
                    9a:43:05:0d:1b:23:c8:e4:cb:ff:8b:36:70:92:08:
                    29:57:4b:99:81:a5:a9:04:d8:21:77:01:b9:be:66:
                    0a:c8:a2:d5:2e:bd:cc:22:23:0d:96:da:69:e6:1f:
                    f7:0f:9c:99:73:b1:e9:5f:bc:ba:ff:d6:3d:43:65:
                    92:57:a2:ac:a4:9c:46:c2:6d:53:56:a3:4c:c3:29:
                    f4:c7:59:a5:49:f3:0a:e2:13:41:88:46:51:d2:bc:
                    ea:2e:07:6c:f2:b9:34:5a:47:88:17:2b:1f:7f:d9:
                    5d:7f:1f:4b:78:ab:bc:ec:1c:97:9a:66:5b:c6:78:
                    a3:41:54:ef:2d:c2:2b:b0:6c:8e:c2:0b:06:22:01:
                    2c:74:be:92:c8:e1:93:f8:d8:cb:aa:57:5b:9a:6c:
                    e0:0e:d1:d6:a4:58:0f:1a:0e:4b:e5:a9:10:f7:06:
                    3e:4b:c1:11:c4:b7:a1:8e:8f:7b:bd:ca:e6:19:10:
                    ef:fa:5e:20:4f:34:69:34:df:65:57:1c:34:76:41:
                    e9:d9:86:c6:be:b1:8e:a2:d0:b7:c0:5a:01:7d:d4:
                    c4:0f:a3:cc:1e:58:11:8c:66:b7:cd:05:43:09:82:
                    04:39:95:b6:5a:ca:ee:f2:64:63:cb:87:b0:af:16:
                    c7:bb
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:29:91:60:FF:8A:4D:FA:EB:F9:A6:6A:B8:CF:F9:E6:4B:BD:49:CE:12

            X509v3 Subject Key Identifier: 
                B7:B9:31:84:AF:37:A0:11:C8:7A:C3:9D:A7:F8:86:63:7C:6E:06:0D
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: 
                Code Signing
            Netscape Cert Type: 
                Object Signing
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.6449.1.2.1.3.2
                  CPS: https://secure.comodo.net/CPS

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.comodoca.com/COMODORSACodeSigningCA.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.comodoca.com/COMODORSACodeSigningCA.crt
                OCSP - URI:http://ocsp.comodoca.com

            X509v3 Subject Alternative Name: 
                email:info@win-rar.com
    Signature Algorithm: sha256WithRSAEncryption
         59:d3:91:0a:4e:a9:08:94:77:b9:95:0c:0f:4c:76:5a:b1:43:
         aa:d4:3f:70:e7:10:ce:84:44:61:e7:eb:86:76:b3:31:2e:c7:
         c6:79:04:85:9e:fe:e5:2d:db:ea:c9:54:a8:a8:f2:da:8b:23:
         ad:2c:d8:9f:b9:f4:a8:dc:49:0a:2c:e2:1d:a5:4f:42:75:ba:
         28:b8:e8:b1:40:65:98:4f:81:2a:fa:a9:04:2d:29:88:8f:c0:
         a7:f9:55:42:a2:cc:cc:f2:2b:95:a8:dd:59:6e:38:48:1c:06:
         b6:6f:8c:c8:02:f8:17:95:1e:ab:8d:7f:35:ab:e1:f0:6d:f6:
         81:75:5d:8b:8b:d3:15:a9:2b:21:fa:0b:37:39:42:58:f6:b8:
         fa:7e:c0:d3:6c:f3:ab:36:61:f5:bb:18:d0:d6:6f:e0:cf:b9:
         3d:0f:90:38:4d:07:7d:ca:be:aa:5a:d4:22:fe:2e:42:32:af:
         78:ee:26:39:ec:ca:f8:47:4b:c0:72:8e:03:4f:b3:45:a2:ee:
         58:07:b8:1b:ee:e7:ff:55:d2:f6:09:e3:7c:db:a4:ed:70:e0:
         4f:c1:12:0c:27:3b:86:2d:ed:96:ba:c1:01:78:b5:ee:99:e7:
         0e:f8:e3:14:1e:ea:3c:ae:5a:b6:f9:fd:60:d6:7a:c8:55:d4:
         97:59:70:9f

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            2e:7c:87:cc:0e:93:4a:52:fe:94:fd:1c:b7:cd:34:af
    Signature Algorithm: sha384WithRSAEncryption
        Issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
        Validity
            Not Before: May  9 00:00:00 2013 GMT
            Not After : May  8 23:59:59 2028 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Code Signing CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a6:98:90:63:77:91:34:7f:8a:d1:dd:e9:67:31:
                    11:eb:cc:1e:fd:31:1d:b3:b9:62:57:3f:93:bc:5b:
                    e3:9f:1e:24:32:11:27:6b:bc:51:91:a7:cf:9e:9e:
                    25:b3:5f:81:a8:18:0f:1d:1e:20:30:0e:fb:61:7b:
                    86:09:b3:e3:fd:a2:68:9d:1c:2c:9d:bf:72:e3:e4:
                    75:a0:e5:35:23:8e:c9:8a:ee:1a:0c:64:c7:d8:42:
                    a1:7b:b5:52:03:4b:3a:b0:8e:23:4b:4b:63:e0:22:
                    94:37:7b:d5:79:90:0a:14:18:51:2c:e6:fe:c1:12:
                    f0:1c:3f:61:61:0a:8c:a2:dc:f6:c3:30:aa:cd:28:
                    18:75:48:c1:79:5a:08:cd:bb:8c:55:8c:f7:d4:76:
                    90:3a:33:46:50:73:98:5c:f4:85:4a:6b:0f:80:dd:
                    5e:d6:bd:fd:a9:2f:c0:25:f5:f9:78:d7:8d:5f:10:
                    c2:44:55:3c:90:3c:31:46:cb:70:ae:07:a9:0a:e3:
                    af:c1:01:6f:90:1a:23:e2:5f:38:db:c6:08:5d:47:
                    b3:83:41:f0:2e:00:37:14:b9:12:aa:79:92:52:cd:
                    87:0f:7b:d8:62:29:a4:7e:30:bd:1b:b5:8c:72:b4:
                    48:f2:e3:e8:21:f9:5e:4c:62:79:8b:02:06:9f:7f:
                    d5:0b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:BB:AF:7E:02:3D:FA:A6:F1:3C:84:8E:AD:EE:38:98:EC:D9:32:32:D4

            X509v3 Subject Key Identifier: 
                29:91:60:FF:8A:4D:FA:EB:F9:A6:6A:B8:CF:F9:E6:4B:BD:49:CE:12
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Extended Key Usage: 
                Code Signing
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.comodoca.com/COMODORSACertificationAuthority.crl

            Authority Information Access: 
                CA Issuers - URI:http://crt.comodoca.com/COMODORSAAddTrustCA.crt
                OCSP - URI:http://ocsp.comodoca.com

    Signature Algorithm: sha384WithRSAEncryption
         02:3f:02:39:c3:ee:f8:ca:3b:89:de:0c:6d:4d:b1:f1:4e:92:
         4f:af:c2:38:2c:04:cc:c5:63:11:ab:09:63:af:ab:a2:d7:02:
         3f:cc:6f:19:c3:3d:d6:1a:08:94:ff:25:d8:a9:88:a7:2b:10:
         1a:e0:9b:b1:07:22:1a:51:1c:3a:d4:e1:e9:09:bf:e6:24:74:
         af:1e:7b:16:31:6e:23:ef:54:51:2d:52:02:e2:75:08:05:4c:
         f1:b7:51:e1:51:00:c6:87:f6:6c:ee:10:44:76:57:6a:f1:df:
         58:6b:21:aa:49:d4:7c:37:4e:bd:ff:b6:75:54:40:18:36:57:
         67:11:cd:4f:02:e4:fe:f3:da:fc:75:17:db:ec:b7:f7:65:09:
         23:49:1f:43:57:83:ea:7e:20:77:61:c8:4d:f2:bb:65:4d:a8:
         f7:85:45:07:af:7a:69:27:65:90:29:40:8b:df:7b:3a:51:39:
         8c:a8:1f:70:79:ad:6d:42:20:a2:cf:0c:6c:03:8c:4c:cd:73:
         07:94:e7:5a:8e:3a:04:ba:a2:a1:7c:1f:cb:63:3a:15:a7:d4:
         15:1b:a7:52:47:32:a9:f4:bf:64:47:d1:aa:1f:53:4e:32:30:
         73:c2:6f:b7:78:82:9d:5c:ff:46:bb:6b:22:1d:88:0b:f8:1b:
         aa:34:a6:fc:8c:f5:dd:7f:65:8c:8c:31:57:31:d0:36:ec:47:
         a1:cf:cb:8b:a8:ef:1c:18:58:c5:06:77:ca:4b:9b:51:af:4c:
         08:4a:7a:8f:e2:a3:52:e2:8e:8e:cc:26:e4:b2:d8:e5:38:c2:
         a8:ed:c6:81:9c:35:6b:a9:58:61:4a:0a:97:b4:4b:42:b6:55:
         9d:be:99:e7:70:6d:59:f8:6d:2a:0c:7f:19:60:5f:0c:9a:88:
         6c:30:ac:52:09:90:16:1b:ff:2b:9d:db:d0:20:ca:89:ea:28:
         7e:32:8e:19:df:7b:48:33:1e:d7:65:f8:ae:c9:f8:83:14:93:
         76:7d:64:d0:8e:ce:be:35:7d:ff:72:31:4d:9f:9e:bd:1e:6c:
         2f:a8:8f:0c:06:50:fb:8c:27:b3:76:c9:f4:e6:d7:c3:34:e2:
         8c:87:21:86:61:fe:bf:55:74:e1:21:77:03:0a:68:6c:bb:e4:
         c9:a9:e6:cf:59:25:eb:7c:ec:45:0e:79:66:68:e8:22:cd:b8:
         ef:98:85:4d:96:11:3c:09:8a:d0:7f:bc:28:28:13:fb:6a:ca:
         54:8d:92:5c:cd:c2:65:98:06:9e:ce:48:5b:d4:b5:37:93:46:
         41:7c:07:dd:cf:fa:43:ef:ba:67:61:ff:7d:49:e0:bb:30:7d:
         5c:80:e3:e6:16:39:4b:a7

Cannot convert into OpenSSL::BN

offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0xa4950