MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

TLS

StringTable 040904b0

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Code Signing PCA 2010
serial: 33000004FA70208D01F14FEC1E0000000004FA

Certificates (2)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            33:00:00:04:fa:70:20:8d:01:f1:4f:ec:1e:00:00:00:00:04:fa
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA 2010
        Validity
            Not Before: Feb 16 20:11:03 2023 GMT
            Not After : Jan 31 20:11:03 2024 GMT
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:d0:fa:f2:1a:ac:0c:ea:bf:e6:70:7b:ce:d6:d4:
                    79:3e:29:0d:bd:c9:a8:44:70:6f:05:38:9a:f8:5e:
                    26:cf:50:b8:56:23:b8:7b:da:3a:d4:1f:ec:5a:7e:
                    a0:12:4d:fd:ee:ed:50:67:76:3b:5b:62:74:04:4d:
                    e2:b4:a4:f3:04:be:08:78:8a:13:59:f7:4d:18:41:
                    87:c5:9f:a2:0a:8e:f5:8c:dd:53:e5:d3:89:87:a0:
                    c1:ce:c5:b5:14:30:8a:5c:b3:9c:d4:80:c0:ab:0f:
                    63:43:c5:f2:6c:08:8e:08:b9:bc:5d:5b:98:eb:b6:
                    ee:e0:55:34:41:fe:dc:a7:16:54:d4:2c:5e:3a:71:
                    53:b4:47:df:92:d2:dd:88:14:cf:80:53:a1:ee:6a:
                    b8:83:a0:11:24:bd:b7:8f:3a:71:9e:b2:d6:72:09:
                    9f:84:ed:e0:5b:84:44:be:d6:2a:c3:f8:c4:e4:3d:
                    8c:ff:b6:49:61:b2:be:02:70:c4:f8:f9:7c:14:42:
                    0c:66:16:e2:a5:60:b8:7e:0c:cf:21:e0:a1:a1:34:
                    bf:d0:75:d3:31:ed:d3:61:a9:21:00:90:55:ab:fd:
                    79:ec:6f:50:1e:98:d5:8a:4d:40:be:21:78:c5:01:
                    98:c4:83:02:38:dd:5b:01:f2:d6:24:d1:08:a5:f1:
                    87:db
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Extended Key Usage: 
                1.3.6.1.4.1.311.10.3.21, Code Signing
            X509v3 Subject Key Identifier: 
                C1:31:FD:28:72:C7:4A:0D:48:B9:7C:59:96:99:1B:5A:7F:64:78:0B
            X509v3 Subject Alternative Name: 
                DirName:/OU=Microsoft Corporation/serialNumber=229861\+500171
            X509v3 Authority Key Identifier: 
                E6:FC:5F:7B:BB:22:00:58:E4:72:4E:B5:F4:21:74:23:32:E6:EF:AC
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
            Authority Information Access: 
                CA Issuers - URI:http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt
            X509v3 Basic Constraints: critical
                CA:FALSE
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        11:d7:ba:11:e1:a8:1c:be:8c:dd:df:2e:db:26:f0:32:e4:39:
        1d:13:38:34:16:1f:94:b7:04:f6:cc:4b:b6:84:44:82:41:0e:
        ce:03:d4:a5:64:7b:8e:93:c5:56:42:a7:a7:d3:16:e4:ed:e5:
        25:c9:5c:b0:0e:17:e2:c5:8a:cb:80:f6:f4:3a:1e:7a:46:0b:
        8f:94:10:1a:41:36:e6:ad:9f:43:ca:1a:d6:18:f7:bd:4f:20:
        c6:c2:51:eb:4e:96:a8:21:35:11:8b:72:fb:af:f2:20:03:e2:
        1f:9d:8c:17:e5:18:d7:3d:27:b3:67:0d:31:39:72:12:e7:7a:
        15:4e:ff:85:22:a3:f7:03:6c:4f:2f:ba:c6:a9:4d:fc:6a:33:
        01:49:c0:11:60:a6:5b:5c:87:5f:74:e3:39:79:d4:2c:72:0e:
        3b:6f:30:3b:f0:2d:b2:47:40:73:da:8b:68:e9:b9:f2:d3:07:
        49:7f:fa:ed:b1:a9:8c:ee:aa:7e:ed:50:df:4e:ae:22:e3:84:
        61:47:5d:c9:74:87:30:a1:a1:e3:ab:f3:b1:5b:22:de:61:62:
        9d:5a:1c:d7:33:48:22:2d:dd:96:3c:04:68:2d:8a:a8:c8:2b:
        1b:51:a7:9f:6e:14:22:25:ee:74:8a:e9:cb:77:6c:0c:1d:03:
        9d:05:95:da

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            61:0c:52:4c:00:00:00:00:00:03
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
        Validity
            Not Before: Jul  6 20:40:17 2010 GMT
            Not After : Jul  6 20:50:17 2025 GMT
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA 2010
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e9:0e:64:50:79:67:b5:c4:e3:fd:09:00:4c:9e:
                    94:ac:f7:56:68:ea:44:d8:cf:c5:58:4f:a9:a5:76:
                    7c:6d:45:ba:d3:39:92:b4:a4:1e:f9:f9:65:82:e4:
                    17:d2:8f:fd:44:9c:08:e8:65:93:ce:2c:55:84:bf:
                    7d:08:e3:2e:2b:a8:41:2b:18:b7:a2:4b:6e:49:4c:
                    6b:15:07:de:d1:d2:c2:89:1e:71:94:cd:b5:7f:4b:
                    b4:af:08:d8:cc:88:d6:6b:17:94:3a:93:ce:26:3f:
                    ec:e6:fe:34:98:57:d5:1d:5d:49:f6:b2:2a:2e:d5:
                    85:bb:59:3f:f8:90:b4:2b:83:74:ca:2b:b3:3b:46:
                    e3:f0:46:49:c1:17:66:54:c9:1c:bd:1d:c4:55:62:
                    57:72:f8:67:b9:25:20:34:de:5d:a6:a5:95:5e:ab:
                    28:80:cd:d5:b2:9e:e5:03:b5:63:d3:b2:14:c8:c1:
                    c8:8a:26:0a:59:7f:07:ec:ff:0e:ed:80:12:35:4c:
                    12:a6:be:52:5b:f5:a6:da:e0:8b:0b:48:77:d6:85:
                    47:d5:10:b9:c6:e8:aa:ee:8b:6a:2d:05:5c:60:c6:
                    b4:2a:5b:9c:23:1c:5f:45:e3:1a:14:1e:6f:37:cb:
                    19:33:80:6a:89:4d:a3:6a:66:63:78:93:d5:30:cf:
                    95:1f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            1.3.6.1.4.1.311.21.1: 
                ...
            X509v3 Subject Key Identifier: 
                E6:FC:5F:7B:BB:22:00:58:E4:72:4E:B5:F4:21:74:23:32:E6:EF:AC
            1.3.6.1.4.1.311.20.2: 
                .
.S.u.b.C.A
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Authority Key Identifier: 
                D5:F6:56:CB:8F:E8:A2:5C:62:68:D1:3D:94:90:5B:D7:CE:9A:18:C4
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
            Authority Information Access: 
                CA Issuers - URI:http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.311.46.3
                  CPS: http://www.microsoft.com/PKI/docs/CPS/default.htm
                  User Notice:
                    Explicit Text:  
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        1a:74:ef:57:4f:29:7b:c4:16:85:78:b8:50:d3:22:fc:09:9d:
        ac:82:97:f8:34:ff:2a:2c:97:95:12:e5:e4:bf:cf:bf:93:c8:
        e3:34:a9:db:81:b8:dc:1e:00:be:d2:35:6f:af:e5:7f:79:95:
        77:e5:02:d4:f1:eb:d8:cd:4e:1e:1b:61:a2:c2:5a:23:1a:f0:
        8c:a8:62:51:45:67:08:e3:3f:3c:1e:93:f8:30:85:17:c8:39:
        40:a6:d7:0e:b3:21:29:e5:a5:a1:69:8c:22:93:cc:74:98:e7:
        a1:47:43:f2:53:ac:c0:0f:30:69:7f:fe:d2:25:20:6d:6f:61:
        d3:df:07:d5:d9:72:00:2c:69:86:76:3d:51:db:a6:39:48:c9:
        37:61:6d:07:dd:53:19:cb:a7:d6:61:c2:bf:e2:83:ab:0f:e0:
        6b:9b:95:d6:7d:28:51:b0:89:4a:51:a4:9a:6c:c8:b7:1f:4a:
        1a:0e:69:a9:d7:dc:c1:7e:d1:49:70:aa:b6:ad:bb:72:47:63:
        17:fa:a6:d6:a2:a6:86:ec:a8:10:44:9b:63:b6:b2:69:89:06:
        c7:46:86:7a:18:3f:e8:c5:1d:21:d5:7b:f9:02:23:2d:c5:41:
        cb:bf:1d:4c:c8:16:ef:b1:9c:7f:fc:22:4b:49:8a:6e:15:e3:
        a6:7f:76:5b:d1:53:79:91:85:9d:d5:d2:db:3d:73:35:f3:3c:
        ae:54:b2:52:47:6a:c0:aa:13:95:d2:8e:11:da:99:67:5e:32:
        8c:fb:37:85:d1:dc:75:85:9c:87:c6:5a:57:85:c2:bf:dd:0d:
        8f:8c:9b:2d:eb:b4:ee:cf:27:d3:b5:5e:69:fa:a4:16:04:01:
        a7:24:67:73:cf:4d:4f:b6:de:05:56:97:7a:f7:e9:52:4d:f4:
        77:05:4f:85:c6:d8:0b:f1:8e:ed:42:09:d1:0d:76:e3:23:56:
        78:22:26:36:be:ca:b1:8c:6e:aa:1d:e4:85:da:47:33:62:8f:
        a4:c9:91:33:5f:71:1e:40:af:98:65:c9:22:e8:42:21:25:8a:
        1c:2d:60:d9:37:89:41:89:2a:16:0f:d7:61:3c:94:68:60:52:
        ef:d6:47:99:a0:80:40:ee:15:81:77:3e:9c:e0:53:18:1a:50:
        1d:38:95:9b:1e:66:33:13:27:39:17:78:87:36:ce:4e:c3:5f:
        b2:f5:3d:47:53:b6:e0:e5:db:0b:61:3d:2a:d7:92:2c:ce:37:
        5a:3e:40:42:31:a4:1f:10:08:c2:56:9c:bf:24:5d:51:02:9d:
        6a:79:d2:17:d3:da:c1:94:8e:07:7b:25:71:44:ab:06:6a:e6:
        d4:c6:df:23:9a:96:75:c5

undefined method `first' for #

offsetsizetypecomment
15c115HTM#
15d0315416BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 321000 bytes (314 KiB)


--
Type = PE
Physical Size = 321000
CPU = x64
64-bit = +
Characteristics = Executable LargeAddress
Created = 2023-06-08 12:50:49
Headers Size = 4096
Checksum = 326070
Name = AM_Delta_Patch_1.391.851.0.exe
Image Size = 319488
Section Alignment = 4096
File Alignment = 4096
Code Size = 184320
Initialized Data Size = 122880
Uninitialized Data Size = 0
Linker Version = 14.29
OS Version = 10.0
Image Version = 10.0
Subsystem Version = 6.0
Subsystem = Windows GUI
DLL Characteristics = Relocated NX-Compatible TerminalServerAware 0x4020
Stack Reserve = 524288
Stack Commit = 8192
Heap Reserve = 1048576
Heap Commit = 4096
Image Base = 5368709120
Comment = FileVersion: 1.391.860.0
ProductVersion: 1.391.860.0
CompanyName: Microsoft Corporation
FileDescription: Microsoft Antimalware WU Stub
InternalName: AM_Delta_Patch_1.391.851.0.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: AM_Delta_Patch_1.391.851.0.exe
ProductName: Microsoft Malware Protection
StubName: WuStubFinal
StubVersion: 1.1.18500.10
----
Path = .rsrc/0/CABINET/UPDATEPAYLOAD
Size = 41070
Packed Size = 41070
--
Path = .rsrc/0/CABINET/UPDATEPAYLOAD
Type = Cab
Physical Size = 41070
Method = None
Blocks = 1
Volumes = 1
Volume Index = 0
ID = 6187

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2023-06-08 12:50:36 ....A         3634               1.391.851.0_to_1.391.860.0_mpasdlta.vdm._p
2023-06-08 12:50:34 ....A        37258               1.391.851.0_to_1.391.860.0_mpavdlta.vdm._p
------------------- ----- ------------ ------------  ------------------------
2023-06-08 12:50:36              40892       321000  2 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0x3e0e8