MZ Header

DOS stub

00000000: 0e 1f 66 ba 0e 00 b4 09  cd 21 b4 00 cd 21 54 68  |..f......!...!Th|
00000010: 69 73 20 69 73 20 61 20  57 69 6e 64 6f 77 73 20  |is is a Windows |
00000020: 70 72 6f 67 72 61 6d 2c  20 79 6f 75 20 63 61 6e  |program, you can|
00000030: 6e 6f 74 20 72 75 6e 20  69 74 20 69 6e 20 44 4f  |not run it in DO|
00000040: 53 2e 5c 72 5c 6e 24 d8  4c 8f a5 d8 4c 8f a5 d8  |S.\r\n$.L...L...|

PE Header

Packer / Compiler

Sections

Data Directory

TLS

StringTable 040904b0

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 Code Signing 2010 CA
serial: 26279F0F2F11970DCCF63EBA88F2D4C4

Certificates (4)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            04:00:00:00:00:01:2f:4e:e1:52:d7
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
        Validity
            Not Before: Apr 13 10:00:00 2011 GMT
            Not After : Jan 28 12:00:00 2028 GMT
        Subject: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Timestamping CA - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:94:ef:65:f8:b5:57:9f:a0:53:0d:34:06:eb:09:
                    1f:b7:47:18:6a:cb:f0:5b:e4:ff:27:a5:34:d1:f7:
                    89:1a:bf:9e:b1:cd:12:41:6e:66:d4:81:a0:85:8b:
                    64:5a:46:2f:99:a0:8d:77:b1:e2:bc:5c:dd:22:d7:
                    6a:67:d0:bb:e8:ca:74:de:8b:4f:0d:b0:52:e5:90:
                    5b:eb:47:0e:f1:e7:9f:9c:0b:90:65:3e:17:96:30:
                    45:72:6d:39:a1:17:36:ca:b9:a0:8c:1b:4f:08:19:
                    f6:81:31:ad:61:16:a4:62:e6:b4:40:9e:c3:fc:fb:
                    95:f6:fb:b5:2e:95:81:98:e0:ef:c5:eb:d8:02:59:
                    78:77:f7:aa:e3:52:6b:50:91:29:c5:fc:f7:cd:93:
                    65:d2:60:61:22:f2:06:fb:32:dd:16:51:fa:0e:fd:
                    8a:30:f0:17:09:a7:bb:f3:04:ae:ab:90:e7:6c:df:
                    7a:a9:f4:ef:c4:62:27:5f:6f:99:6d:38:74:aa:11:
                    8b:da:df:c7:14:4c:e9:85:b2:ec:c2:7d:4a:26:8f:
                    e7:56:ba:a6:e0:cf:92:53:80:74:f4:03:ec:68:b2:
                    60:bc:84:20:00:83:1b:a1:ee:b4:74:05:c1:29:8e:
                    62:d0:47:b1:fa:f0:53:cc:18:f9:2e:3b:f9:70:7e:
                    b4:25
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Subject Key Identifier: 
                46:D8:3E:FF:DC:E3:BE:FF:83:E6:F4:85:9B:B0:DD:6A:D6:14:A9:C1
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.globalsign.com/repository/

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.globalsign.net/root.crl

            X509v3 Authority Key Identifier: 
                keyid:60:7B:66:1A:45:0D:97:CA:89:50:2F:7D:04:CD:34:A8:FF:FC:FD:4B

    Signature Algorithm: sha1WithRSAEncryption
         4e:5e:56:90:1e:46:b4:d9:49:31:f3:bb:17:39:28:1b:c2:16:
         dd:fd:41:dc:09:05:04:9b:6f:b2:a2:9a:d6:99:2e:40:99:00:
         55:b5:ea:3f:a5:20:76:d3:86:34:d4:17:cc:55:3a:c7:82:ee:
         ef:a8:ba:bc:d8:06:9f:15:50:df:cd:16:7b:52:3a:02:d7:19:
         1a:fd:af:f0:78:5c:e0:4b:c5:18:df:3a:24:1e:da:ac:b8:a9:
         58:04:02:07:30:db:b0:12:5e:fe:31:be:f0:04:48:f4:f0:70:
         f8:3a:5e:56:83:cf:3d:fb:0d:bc:f4:c5:ed:97:9d:b9:d4:db:
         a5:27:84:e3:38:9b:8b:a7:35:86:44:20:a4:3b:6d:a4:6a:0b:
         a1:83:fd:28:eb:da:ef:28:f6:cc:88:5d:fb:0a:3b:00:ab:e0:
         21:eb:e2:2f:35:6c:0f:8e:34:45:97:eb:a2:f7:99:33:35:7e:
         cb:9a:8a:bb:45:4d:e7:3f:9f:c2:d9:8a:fa:65:b2:6e:c7:7e:
         65:ff:e8:92:e1:2c:31:a2:f7:b0:27:36:48:8f:26:6f:3b:ee:
         4d:76:1f:79:c3:e5:7f:96:35:bc:2d:0e:cc:01:b0:8e:7f:ff:
         51:80:80:a7:92:d4:b3:44:46:64:8c:87:4f:16:63:07:31:4b:
         63:b0:df:f3

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            11:21:d6:99:a7:64:97:3e:f1:f8:42:7e:e9:19:cc:53:41:14
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Timestamping CA - G2
        Validity
            Not Before: May 24 00:00:00 2016 GMT
            Not After : Jun 24 00:00:00 2027 GMT
        Subject: C=SG, O=GMO GlobalSign Pte Ltd, CN=GlobalSign TSA for MS Authenticode - G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:b0:17:ae:a2:d3:b6:04:30:56:1e:58:0f:b1:ed:
                    55:a4:d6:54:cb:d8:f6:73:3a:ec:5d:5e:ab:25:fd:
                    36:a5:fa:84:c3:61:40:c5:46:b5:59:52:3b:42:a2:
                    2e:5f:13:62:10:a9:5b:e6:73:d6:92:25:b1:7d:23:
                    e3:06:b3:87:3a:0e:43:f0:d7:00:89:53:a2:11:31:
                    52:28:6e:5d:40:72:3c:f2:09:77:a7:49:92:97:d4:
                    6c:90:a0:76:a7:fd:b8:dc:b3:9d:f2:07:60:2c:4f:
                    58:98:00:6b:d3:15:54:e0:fa:dd:ff:80:2c:5f:18:
                    a6:98:ff:d4:ab:ec:a1:45:59:b2:2e:6f:62:5d:e0:
                    d9:19:ac:8b:57:9c:a8:26:2b:d9:17:a5:10:d2:47:
                    08:1a:70:2c:33:8b:7f:68:80:2a:b5:a1:5d:6b:dd:
                    8d:02:02:29:03:aa:7c:37:bb:bb:29:4e:3d:53:93:
                    b3:a6:fa:8f:d2:58:93:15:4c:b9:2d:ab:80:a3:a3:
                    25:fb:af:f7:08:64:b0:7a:44:0f:5c:10:d7:5f:61:
                    37:aa:4e:6b:d3:d2:53:25:9d:82:73:fa:2c:f9:72:
                    b0:a9:19:39:2a:50:fa:a9:d0:3c:3a:ca:e8:5b:ef:
                    f5:5f:51:f4:f9:0a:d9:97:35:de:6a:85:e6:23:04:
                    42:af
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.4146.1.30
                  CPS: https://www.globalsign.com/repository/

            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Extended Key Usage: critical
                Time Stamping
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.globalsign.com/gs/gstimestampingg2.crl

            Authority Information Access: 
                CA Issuers - URI:http://secure.globalsign.com/cacert/gstimestampingg2.crt

            X509v3 Subject Key Identifier: 
                D4:A2:84:4A:38:5A:18:7F:BA:4F:30:50:BD:9D:D5:7A:87:D6:09:F7
            X509v3 Authority Key Identifier: 
                keyid:46:D8:3E:FF:DC:E3:BE:FF:83:E6:F4:85:9B:B0:DD:6A:D6:14:A9:C1

    Signature Algorithm: sha1WithRSAEncryption
         8f:a9:1a:91:6d:04:a6:37:20:0e:83:96:de:23:d3:6b:6e:1f:
         6e:dd:64:3d:68:21:22:b5:f8:47:36:69:8e:e1:a5:45:c7:24:
         a2:22:b7:29:09:cc:54:5a:ae:c6:bc:cd:63:8e:b3:3d:50:48:
         e5:b4:cc:ae:cd:92:8d:9e:28:8b:13:4a:11:aa:bd:a3:ef:d3:
         b2:36:fc:b4:a1:72:bf:6d:97:63:79:8c:44:bc:70:2f:7e:f3:
         bc:dd:82:53:ab:1a:f6:eb:fa:1c:97:bc:b6:37:9c:a4:1c:30:
         bc:ab:bc:2d:47:36:df:92:20:03:e8:71:c6:58:f6:75:05:9a:
         34:f0:0b:59:5a:82:44:34:aa:80:e4:2f:84:f6:47:5d:96:c9:
         b6:ca:ca:9d:b7:a6:ba:e4:50:d3:d4:37:b8:ba:20:0e:d0:d3:
         92:2a:5b:c4:59:bb:a1:6d:db:3c:ce:44:9d:c1:38:2a:ad:e3:
         8d:bd:cd:09:77:1a:10:be:67:0a:02:36:64:88:b9:b3:1b:26:
         ee:e7:9e:60:c4:46:a8:bc:61:33:6c:cf:4e:b9:9c:b9:6a:f0:
         9f:37:fe:b5:3d:4f:9a:d3:4d:ff:de:20:8e:4e:97:a6:fd:9f:
         09:bc:4d:ca:18:76:c9:b0:4d:85:50:f2:80:d2:1d:06:f5:58:
         04:07:b1:18

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            26:27:9f:0f:2f:11:97:0d:cc:f6:3e:ba:88:f2:d4:c4
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
        Validity
            Not Before: Jan  6 00:00:00 2016 GMT
            Not After : Mar 28 23:59:59 2019 GMT
        Subject: C=CN, ST=Beijing, L=Beijing, O=Qihoo 360 Software (Beijing) Company Limited, OU=Tech. Dev. Dept., CN=Qihoo 360 Software (Beijing) Company Limited
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c9:64:aa:cb:52:20:b5:8f:d7:ed:87:87:ef:fc:
                    63:b4:19:8a:28:49:7e:c7:89:82:b6:09:4a:1f:0d:
                    4f:9c:b5:69:0b:d5:18:b7:60:17:2c:25:ae:31:03:
                    ca:0c:08:0d:46:a4:97:8e:9c:83:5b:5a:83:57:5e:
                    0a:83:8f:d2:69:ab:b4:28:7b:ae:03:30:5e:96:f1:
                    47:67:39:80:d6:2b:51:e4:93:c4:23:df:35:85:a2:
                    ec:8f:b6:f1:52:c0:08:d0:53:8b:de:67:ba:04:ee:
                    7f:dd:f1:4e:40:53:6f:1d:34:8c:78:dd:fe:60:a8:
                    cc:15:b9:7a:89:62:f4:8a:67:19:a5:c4:4c:cc:ae:
                    7b:44:72:a8:5e:25:86:3d:11:0b:f5:d7:d8:e5:d5:
                    0a:59:03:17:be:c6:13:e5:94:9d:b2:ac:e3:eb:2f:
                    62:45:2f:16:d9:cd:ee:6c:80:8a:6c:e9:9c:c4:7c:
                    de:b0:14:62:8c:2d:2e:75:aa:c5:98:4c:45:31:9e:
                    13:0b:a1:44:55:e8:e4:ab:96:18:2d:df:2d:90:73:
                    dc:b1:00:81:d9:04:ff:81:08:85:c4:87:37:53:cf:
                    26:57:c8:48:a8:a2:44:bd:df:bd:cb:6b:84:0e:1b:
                    22:21:e7:02:2c:b3:f7:38:cf:41:8b:45:a3:84:0c:
                    70:b3
                Exponent: 3 (0x3)
        X509v3 extensions:
            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://sf.symcb.com/sf.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: https://d.symcb.com/cps
                  User Notice:
                    Explicit Text: https://d.symcb.com/rpa

            X509v3 Extended Key Usage: 
                Code Signing
            Authority Information Access: 
                OCSP - URI:http://sf.symcd.com
                CA Issuers - URI:http://sf.symcb.com/sf.crt

            X509v3 Authority Key Identifier: 
                keyid:CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D

            X509v3 Subject Key Identifier: 
                2D:FC:FD:93:C4:EB:22:A6:50:B8:25:51:57:42:1C:3C:00:32:C4:CC
    Signature Algorithm: sha1WithRSAEncryption
         14:de:ff:13:d8:88:b6:8e:8f:e5:1f:e7:61:e9:4a:08:cc:7e:
         92:23:86:1f:3c:f6:1f:51:f8:62:9f:c2:01:1a:e3:a3:b5:af:
         2e:fa:ea:51:20:a9:2b:16:a2:e3:da:99:18:1c:e1:a7:41:fb:
         2c:fb:8d:cd:78:c8:69:ad:25:91:14:76:c9:e2:bc:b2:81:59:
         a9:16:18:51:e3:e4:6c:28:28:ca:7f:89:bd:36:b4:54:e4:9e:
         f2:8a:6d:87:56:3b:ce:d3:27:77:10:e9:14:7e:c8:17:ef:d7:
         13:01:e8:68:15:8e:2c:9d:7a:63:10:f1:12:13:40:54:62:90:
         47:fe:86:37:cf:4f:e1:c2:1a:0a:d2:9b:38:8f:00:31:a1:e1:
         3e:4f:9b:06:dc:81:35:1d:8d:e4:bf:8f:c9:ad:f7:48:10:53:
         15:d0:f6:7c:9c:4e:39:1f:42:ab:db:51:87:73:47:68:5b:c0:
         72:e3:bb:64:98:99:bb:8b:46:97:f6:d4:82:69:a5:35:76:fa:
         82:f3:e0:a9:55:2c:03:b6:45:c0:7f:83:2d:df:35:45:87:7a:
         c6:4f:86:10:d8:61:d5:4e:3e:c1:c0:9f:35:86:f1:b7:85:64:
         a6:18:e3:c7:61:40:9a:c9:c8:4d:0a:9c:8c:ba:ba:46:d7:b1:
         1c:ba:1d:fb

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            52:00:e5:aa:25:56:fc:1a:86:ed:96:c9:d4:4b:33:c7
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
        Validity
            Not Before: Feb  8 00:00:00 2010 GMT
            Not After : Feb  7 23:59:59 2020 GMT
        Subject: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:f5:23:4b:5e:a5:d7:8a:bb:32:e9:d4:57:f7:ef:
                    e4:c7:26:7e:ad:19:98:fe:a8:9d:7d:94:f6:36:6b:
                    10:d7:75:81:30:7f:04:68:7f:cb:2b:75:1e:cd:1d:
                    08:8c:df:69:94:a7:37:a3:9c:7b:80:e0:99:e1:ee:
                    37:4d:5f:ce:3b:14:ee:86:d4:d0:f5:27:35:bc:25:
                    0b:38:a7:8c:63:9d:17:a3:08:a5:ab:b0:fb:cd:6a:
                    62:82:4c:d5:21:da:1b:d9:f1:e3:84:3b:8a:2a:4f:
                    85:5b:90:01:4f:c9:a7:76:10:7f:27:03:7c:be:ae:
                    7e:7d:c1:dd:f9:05:bc:1b:48:9c:69:e7:c0:a4:3c:
                    3c:41:00:3e:df:96:e5:c5:e4:94:71:d6:55:01:c7:
                    00:26:4a:40:3c:b5:a1:26:a9:0c:a7:6d:80:8e:90:
                    25:7b:cf:bf:3f:1c:eb:2f:96:fa:e5:87:77:c6:b5:
                    56:b2:7a:3b:54:30:53:1b:df:62:34:ff:1e:d1:f4:
                    5a:93:28:85:e5:4c:17:4e:7e:5b:fd:a4:93:99:7f:
                    df:cd:ef:a4:75:ef:ef:15:f6:47:e7:f8:19:72:d8:
                    2e:34:1a:a6:b4:a7:4c:7e:bd:bb:4f:0c:3d:57:f1:
                    30:d6:a6:36:8e:d6:80:76:d7:19:2e:a5:cd:7e:34:
                    2d:89
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: https://www.verisign.com/cps
                  User Notice:
                    Explicit Text: https://www.verisign.com/rpa

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            1.3.6.1.5.5.7.1.12: 
                0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.verisign.com/pca3-g5.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.verisign.com

            X509v3 Extended Key Usage: 
                TLS Web Client Authentication, Code Signing
            X509v3 Subject Alternative Name: 
                DirName:/CN=VeriSignMPKI-2-8
            X509v3 Subject Key Identifier: 
                CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D
            X509v3 Authority Key Identifier: 
                keyid:7F:D3:65:A7:C2:DD:EC:BB:F0:30:09:F3:43:39:FA:02:AF:33:31:33

    Signature Algorithm: sha1WithRSAEncryption
         56:22:e6:34:a4:c4:61:cb:48:b9:01:ad:56:a8:64:0f:d9:8c:
         91:c4:bb:cc:0c:e5:ad:7a:a0:22:7f:df:47:38:4a:2d:6c:d1:
         7f:71:1a:7c:ec:70:a9:b1:f0:4f:e4:0f:0c:53:fa:15:5e:fe:
         74:98:49:24:85:81:26:1c:91:14:47:b0:4c:63:8c:bb:a1:34:
         d4:c6:45:e8:0d:85:26:73:03:d0:a9:8c:64:6d:dc:71:92:e6:
         45:05:60:15:59:51:39:fc:58:14:6b:fe:d4:a4:ed:79:6b:08:
         0c:41:72:e7:37:22:06:09:be:23:e9:3f:44:9a:1e:e9:61:9d:
         cc:b1:90:5c:fc:3d:d2:8d:ac:42:3d:65:36:d4:b4:3d:40:28:
         8f:9b:10:cf:23:26:cc:4b:20:cb:90:1f:5d:8c:4c:34:ca:3c:
         d8:e5:37:d6:6f:a5:20:bd:34:eb:26:d9:ae:0d:e7:c5:9a:f7:
         a1:b4:21:91:33:6f:86:e8:58:bb:25:7c:74:0e:58:fe:75:1b:
         63:3f:ce:31:7c:9b:8f:1b:96:9e:c5:53:76:84:5b:9c:ad:91:
         fa:ac:ed:93:ba:5d:c8:21:53:c2:82:53:63:af:12:0d:50:87:
         11:1b:3d:54:52:96:8a:2c:9c:3d:92:1a:08:9a:05:2e:c7:93:
         a5:48:91:d3

Cannot convert into OpenSSL::BN

offsetsizetypecomment
1e4b34835597GIF(0 x 18759)#
1e4e880380160HTM#
20283ef1148HTM#
205a5df84HTM#
2087f4c48363HTM#
2093c50683454HTM#
22af35024956PNG(256 x 256)#
22b54cc1335676BINoverlay data past EOF#
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] ignoring invalid PEdump::BITMAPINFOHEADER

[?] can't find file_offset of VA 0x23c18bc