filename | SFrame.exe | |
---|---|---|
size | 4172944 (0x3fac90) | |
md5 | cd6d41bedeb178a3407a8fb117dcf7ac | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 2 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0x380c6cf4 |
reserved3 | 0x47cfcccf |
reserved4 | 0 |
reserved5 | 0x82085c9b |
reserved6 | 0x4052ec19 |
lfanew | 0x148 |
Rich Header
lib id | version | times used |
---|---|---|
0 | 0 | 30 |
126 | 50327 | 10 |
125 | 50727 | 71 |
11 | 8168 | 9 |
93 | 3077 | 2 |
96 | 3077 | 1 |
109 | 50727 | 272 |
114 | 50727 | 1 |
4 | 8447 | 14 |
25 | 9210 | 2 |
95 | 3077 | 36 |
95 | 4035 | 19 |
15 | 4035 | 6 |
96 | 4035 | 146 |
93 | 4035 | 37 |
1 | 0 | 549 |
110 | 50727 | 680 |
124 | 50727 | 1 |
120 | 50727 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0xd80000 | 0xd8053c | 0xd4b1a4 | 0xaad3e8 | 0 | 0 |
id | lang | string |
---|---|---|
103 | 1042 | 2004-07-15 PD Version - Second Build |
109 | 1042 | SFRAME |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetProcAddress | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
d3d9.dll | Direct3DCreate9 | ||
psapi.dll | GetProcessMemoryInfo | ||
ws2_32.dll | 20 | ||
imm32.dll | ImmGetVirtualKey | ||
version.dll | GetFileVersionInfoA | ||
audiere.dll | _AdrGetSampleSize@4 | ||
devil.dll | ilSetInteger | ||
ilu.dll | iluErrorString | ||
libgobject-2.0-0.dll | g_object_ref | ||
libcairo-2.dll | cairo_image_surface_get_data | ||
libpango-1.0-0.dll | pango_font_map_create_context | ||
libpangocairo-1.0-0.dll | pango_cairo_update_context | ||
mss32.dll | _AIL_release_sample_handle@4 | ||
user32.dll | EmptyClipboard | ||
gdi32.dll | GetObjectA | ||
comdlg32.dll | GetOpenFileNameA | ||
advapi32.dll | RegDeleteValueA | ||
shell32.dll | ShellExecuteA | ||
ole32.dll | CoCreateInstance | ||
oleaut32.dll | 9 | ||
winmm.dll | timeGetTime | ||
iphlpapi.dll | GetAdaptersInfo | ||
dbghelp.dll | SymInitialize | ||
wininet.dll | HttpQueryInfoA | ||
oleaut32.dll | VariantChangeTypeEx |
Signers (1)
issuer: /C=US/O=Thawte, Inc./CN=Thawte Code Signing CA - G2
serial: 0DF9EE3CFBC6D8DEE0777F9263CE06DF
Certificates (4)
Certificate: Data: Version: 3 (0x2) Serial Number: 79:a2:a5:85:f9:d1:15:42:13:d9:b8:3e:f6:b6:8d:ed Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA Validity Not Before: May 1 00:00:00 2012 GMT Not After : Dec 31 23:59:59 2012 GMT Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer - G3 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (1024 bit) Modulus: 00:a9:59:66:74:da:3d:8a:7d:7a:d8:fc:f5:80:44: 7b:fe:47:6a:14:55:4e:50:47:0b:ec:d3:ed:ce:f6: 38:f7:4f:69:b9:b1:f0:b6:78:82:0a:8c:76:16:67: e2:02:ad:b7:0d:a5:8a:f6:03:fc:66:d3:fc:08:2d: cc:b5:73:59:7b:89:dc:33:6e:66:5a:5e:52:37:b4: 62:d1:92:59:35:14:8b:45:ac:59:b2:4d:24:a2:98: 94:68:42:72:9f:3a:68:e2:6b:8b:9e:22:2d:f4:98: 4e:9a:c6:af:b3:e4:a0:ab:3c:28:bf:23:e1:d7:72: a4:f2:10:53:67:ae:77:af:51 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 CRL Distribution Points: Full Name: URI:http://crl.verisign.com/tss-ca.crl X509v3 Extended Key Usage: critical Time Stamping Authority Information Access: OCSP - URI:http://ocsp.verisign.com X509v3 Key Usage: critical Digital Signature X509v3 Subject Alternative Name: DirName:/CN=TSA1-3 X509v3 Subject Key Identifier: B4:B7:F1:89:49:26:60:E7:65:EA:73:AE:DC:D3:38:CD:BF:57:92:6F Signature Algorithm: sha1WithRSAEncryption 1e:98:aa:27:b7:78:b5:08:b5:c9:72:6d:b7:df:c0:0e:98:a6: 35:c4:88:c9:d2:f6:6d:f1:4b:1a:fb:d5:f9:2d:99:00:9e:d1: e7:9b:8b:e1:3f:bd:39:80:0c:66:cd:07:bc:5c:98:54:a6:94: ba:10:d1:4e:8b:ab:f5:6f:65:cc:67:09:a2:80:7c:52:e8:0e: 03:d6:6b:7a:c6:05:18:ec:c8:ac:42:7c:07:2c:a7:3d:08:66: dc:00:ed:fd:94:1d:73:f2:72:98:93:b1:11:d6:8f:ef:8e:ea: ac:f4:96:51:0c:d0:8d:df:31:52:4f:5e:af:7d:a7:4a:75:e6: 4e:ce:2b:9f:29:2b:e7:cf:5d:9f:03:7e:6e:27:7b:23:ad:62: 29:66:af:92:e8:2c:ce:bd:9c:7f:dc:cd:17:3c:43:c2:09:3f: 75:45:c7:9e:e4:d7:60:7f:97:c6:e4:aa:c7:69:f5:fc:cd:74: ac:2c:b0:48:c1:50:4e:70:56:1e:b5:35:d3:8e:be:b1:ed:ac: bd:fe:0c:ec:85:7d:d5:bb:85:66:44:19:5d:9f:93:eb:82:ba: 63:9e:d3:7c:61:ff:c8:1b:d9:23:58:7f:30:a3:66:a1:39:26: 5e:92:c3:3c:cb:37:32:fa:f5:a3:8d:dc:d5:b0:a3:e9:25:36: 55:d7:81:fa
Certificate: Data: Version: 3 (0x2) Serial Number: 47:bf:19:95:df:8d:52:46:43:f7:db:6d:48:0d:31:a4 Signature Algorithm: sha1WithRSAEncryption Issuer: C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA Validity Not Before: Dec 4 00:00:00 2003 GMT Not After : Dec 3 23:59:59 2013 GMT Subject: C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:a9:ca:b2:a4:cc:cd:20:af:0a:7d:89:ac:87:75: f0:b4:4e:f1:df:c1:0f:bf:67:61:bd:a3:64:1c:da: bb:f9:ca:33:ab:84:30:89:58:7e:8c:db:6b:dd:36: 9e:0f:bf:d1:ec:78:f2:77:a6:7e:6f:3c:bf:93:af: 0d:ba:68:f4:6c:94:ca:bd:52:2d:ab:48:3d:f5:b6: d5:5d:5f:1b:02:9f:fa:2f:6b:1e:a4:f7:a3:9a:a6: 1a:c8:02:e1:7f:4c:52:e3:0e:60:ec:40:1c:7e:b9: 0d:de:3f:c7:b4:df:87:bd:5f:7a:6a:31:2e:03:99: 81:13:a8:47:20:ce:31:73:0d:57:2d:cd:78:34:33: 95:12:99:12:b9:de:68:2f:aa:e6:e3:c2:8a:8c:2a: c3:8b:21:87:66:bd:83:58:57:6f:75:bf:3c:aa:26: 87:5d:ca:10:15:3c:9f:84:ea:54:c1:0a:6e:c4:fe: c5:4a:dd:b9:07:11:97:22:7c:db:3e:27:d1:1e:78: ec:9f:31:c9:f1:e6:22:19:db:c4:b3:47:43:9a:1a: 5f:a0:1e:90:e4:5e:f5:ee:7c:f1:7d:ab:62:01:8f: f5:4d:0b:de:d0:22:56:a8:95:cd:ae:88:76:ae:ee: ba:0d:f3:e4:4d:d9:a0:fb:68:a0:ae:14:3b:b3:87: c1:bb Exponent: 65537 (0x10001) X509v3 extensions: Authority Information Access: OCSP - URI:http://ocsp.verisign.com X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 CRL Distribution Points: Full Name: URI:http://crl.verisign.com/ThawteTimestampingCA.crl X509v3 Extended Key Usage: Time Stamping X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Subject Alternative Name: DirName:/CN=TSA2048-1-53 Signature Algorithm: sha1WithRSAEncryption 4a:6b:f9:ea:58:c2:44:1c:31:89:79:99:2b:96:bf:82:ac:01: d6:1c:4c:cd:b0:8a:58:6e:df:08:29:a3:5e:c8:ca:93:13:e7: 04:52:0d:ef:47:27:2f:00:38:b0:e4:c9:93:4e:9a:d4:22:62: 15:f7:3f:37:21:4f:70:31:80:f1:8b:38:87:b3:e8:e8:97:00: fe:cf:55:96:4e:24:d2:a9:27:4e:7a:ae:b7:61:41:f3:2a:ce: e7:c9:d9:5e:dd:bb:2b:85:3e:b5:9d:b5:d9:e1:57:ff:be:b4: c5:7e:f5:cf:0c:9e:f0:97:fe:2b:d3:3b:52:1b:1b:38:27:f7: 3f:4a
Certificate: Data: Version: 3 (0x2) Serial Number: 0d:f9:ee:3c:fb:c6:d8:de:e0:77:7f:92:63:ce:06:df Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Thawte, Inc., CN=Thawte Code Signing CA - G2 Validity Not Before: Aug 23 00:00:00 2012 GMT Not After : Aug 23 23:59:59 2014 GMT Subject: C=KR, ST=Seoul, L=Gangnam-gu, O=Gala Lab Corp., OU=Tech Support Headquarters, CN=Gala Lab Corp. Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:a0:31:3c:56:1a:48:a0:de:80:f8:bd:71:40:76: 33:ff:f8:8d:8e:97:c2:b6:3b:e4:2b:35:a6:28:f9: cf:bb:43:14:b5:c2:bf:02:c5:0e:6d:ed:f4:46:ba: bd:e1:b4:0b:85:f7:32:b9:e8:b4:8e:72:ce:86:83: a2:14:97:b7:37:9d:29:1d:4a:f8:41:01:ca:71:57: 35:96:4d:60:8c:44:91:d3:7d:30:97:3f:d1:6c:68: f5:ed:1d:a5:25:ad:8a:ba:90:be:19:a8:f8:51:e2: 59:ae:55:b1:76:27:89:da:41:9b:c5:91:57:d1:df: 03:3c:3c:f7:31:85:bc:52:3a:06:b8:00:a0:54:cf: 93:23:79:00:a1:76:48:f4:48:a5:cc:2d:4d:a5:c3: f1:5d:9f:63:52:ff:1f:6c:8b:13:0a:a1:09:14:01: 5d:38:4b:02:0e:eb:1a:cf:52:6a:3d:47:31:6a:66: 66:b2:d8:14:66:9c:08:35:fe:8b:01:52:c4:a5:e5: 58:1b:c2:51:e8:24:3b:ff:01:6b:4e:84:c6:f9:85: 8e:3a:44:cc:78:df:f8:71:b1:08:49:1c:3b:8a:0e: c9:f5:63:a5:24:1d:8d:aa:f1:4c:a1:83:15:2b:d2: a4:28:67:07:2f:73:ae:f3:60:5e:ef:01:01:c8:0c: 5e:15 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 CRL Distribution Points: Full Name: URI:http://cs-g2-crl.thawte.com/ThawteCSG2.crl X509v3 Extended Key Usage: Code Signing, Microsoft Commercial Code Signing 2.5.29.4: 0.0.0.. +.....7....... Authority Information Access: OCSP - URI:http://ocsp.thawte.com Netscape Cert Type: Object Signing Signature Algorithm: sha1WithRSAEncryption 45:fe:af:60:2d:a8:4e:91:98:31:48:0c:43:1c:a2:55:d3:23: 17:c8:e9:c0:19:62:b4:2d:b9:f0:29:c1:b8:a1:26:91:b1:bb: 5c:a4:0a:6a:8a:0d:9f:2d:0f:8b:3e:f4:e5:12:3d:c2:23:25: 76:50:64:69:06:dd:db:e9:bb:64:ab:72:6c:70:7a:78:a2:a0: 02:75:58:2f:e4:e4:56:45:68:3a:ac:2b:e8:d4:30:2f:f3:d0: 40:e6:59:1b:c0:39:22:92:79:1a:9b:f9:0f:ba:85:49:25:25: 0d:9b:a0:21:a1:d5:c0:1c:90:ea:0b:50:f4:34:14:be:11:c2: 5e:93:55:f9:f0:7d:38:b6:c7:88:70:9a:c7:a9:72:a0:af:8f: 75:7e:d9:be:7f:91:1f:a0:dd:33:8b:24:15:fa:01:47:7f:f8: 34:64:86:be:fa:56:f4:bf:e6:65:d6:e5:49:57:20:6b:2d:07: 08:4e:3b:db:a6:ff:90:93:91:fb:69:64:d8:07:10:60:7a:d5: c2:52:dc:44:6e:bc:28:5a:e7:51:df:85:8d:ee:5f:42:a4:6f: a0:2b:ed:67:08:a1:49:6a:bd:9a:e3:dd:7e:50:d6:63:3b:20: 97:9b:65:ae:56:01:ac:ab:5f:93:57:ff:f2:cb:bb:c1:eb:28: 26:ec:6c:d9
Certificate: Data: Version: 3 (0x2) Serial Number: 47:97:4d:78:73:a5:bc:ab:0d:2f:b3:70:19:2f:ce:5e Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA Validity Not Before: Feb 8 00:00:00 2010 GMT Not After : Feb 7 23:59:59 2020 GMT Subject: C=US, O=Thawte, Inc., CN=Thawte Code Signing CA - G2 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:b7:8b:cf:75:5b:9f:25:da:7e:39:b0:93:db:38: d3:a9:23:d0:82:fa:e9:24:7e:5c:0b:8e:83:f8:e6: 7a:59:e6:a3:c5:98:a7:99:d2:44:ff:00:a6:a5:39: 04:8a:da:29:88:ea:db:a2:f3:1c:99:15:26:c2:b1: f4:fc:e1:0c:47:a9:09:11:06:0a:20:92:b9:c7:a0: 04:8c:5c:94:19:ab:5b:25:2c:1d:62:7e:70:0d:ce: 61:6c:dd:2b:82:c9:ce:5d:48:5f:f7:c2:be:bc:41: 23:1e:4f:29:5d:d7:4f:bc:f4:c5:2a:fc:63:e6:7c: 26:4e:99:a7:79:41:9e:10:4a:7a:79:c9:c6:86:f7: 86:95:d2:26:ce:3c:18:2a:d6:7c:ce:af:cd:ad:bb: f7:82:2c:70:26:37:45:e5:0f:47:22:c6:01:28:bd: 2e:83:5c:6a:a4:47:c1:e7:d0:d8:6b:81:46:3f:21: 17:f5:07:c5:43:5a:a6:67:2c:b8:7b:60:11:b5:83: ee:f5:74:0a:72:71:44:3d:58:fe:e8:1a:ab:38:c3: 59:db:7f:6e:38:7d:76:c7:72:69:98:36:96:57:d3: 66:1c:d2:54:91:04:2e:54:19:b0:dc:3d:b5:22:5e: 86:d5:2a:7e:20:df:5d:e6:7a:b1:65:fe:c5:02:4e: 31:2d Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 CRL Distribution Points: Full Name: URI:http://crl.thawte.com/ThawtePCA.crl X509v3 Key Usage: critical Certificate Sign, CRL Sign Authority Information Access: OCSP - URI:http://ocsp.thawte.com X509v3 Extended Key Usage: TLS Web Client Authentication, Code Signing X509v3 Subject Alternative Name: DirName:/CN=VeriSignMPKI-2-10 X509v3 Subject Key Identifier: D4:0D:65:3F:7A:BD:34:C6:FE:47:E7:4C:0D:C0:BD:F2:DE:15:AB:71 X509v3 Authority Key Identifier: keyid:7B:5B:45:CF:AF:CE:CB:7A:FD:31:92:1A:6A:B6:F3:46:EB:57:48:50 Signature Algorithm: sha1WithRSAEncryption 56:fe:53:5c:e1:c7:9e:bc:a7:ed:7e:53:6d:6a:14:4b:51:8c: 40:5e:80:5f:aa:a4:e8:2f:ef:38:c8:04:c9:ca:3e:cf:df:3a: 58:4e:b0:d4:b6:63:c5:29:57:fa:02:05:9a:45:4d:68:db:2a: 1b:d4:34:3d:9f:00:c3:5a:cb:95:49:a5:6e:e1:b0:c5:fc:41: 4d:41:4a:6f:d3:77:c8:d7:38:8d:e4:19:de:18:f3:1f:15:65: 83:6d:45:0c:53:f9:0a:9a:2e:a5:5d:bf:6f:32:81:18:92:19: 6a:55:00:ad:63:1c:52:06:7e:55:d9:29:68:ae:4a:7c:18:9a: 79:88:6b:23:23:d8:27:38:2a:29:87:76:ca:fb:c7:b6:62:23: 1f:ed:7a:56:4c:dd:9c:32:5b:f5:3d:0c:46:18:95:3b:2a:23: 68:83:64:41:d9:00:6d:0f:19:24:15:68:72:bd:c5:71:67:6e: ac:4c:db:90:eb:51:a5:1a:62:07:d0:be:6a:00:47:3c:72:2f: ec:4f:61:3e:73:85:ce:5a:0a:b7:ba:c0:1c:13:75:e3:22:39: 28:dd:6d:1d:09:46:9d:4f:ba:e8:40:81:91:c6:a4:ce:94:72: 1b:01:cf:2a:6e:15:67:95:89:ae:7d:b7:b7:cd:f9:0a:3d:75: b6:6b:3c:25
pkcs7-signedData
- 1
- SHA1: nil
- 1.3.6.1.4.1.311.2.1.4
- #0
- 1.3.6.1.4.1.311.2.1.15
- :
00 3c 00 3c 00 3c 00 4f 00 62 00 73 00 6f 00 6c |.<.<.<.O.b.s.o.l| 00 65 00 74 00 65 00 3e 00 3e 00 3e |.e.t.e.>.>.> |
- :
- SHA1
de 05 92 0f 45 b6 63 49 6d 18 ac a3 9e 91 d2 11 |....E.cIm.......| 66 c5 42 09 |f.B. |
- 1.3.6.1.4.1.311.2.1.15
- #0
- Certificates
- Certificate #0
- 2
- 79:A2:A5:85:F9:D1:15:42:13:D9:B8:3E:F6:B6:8D:ED
- RSA-SHA1: nil
- Issuer
- C: US
- O: VeriSign, Inc.
- CN: VeriSign Time Stamping Services CA
- 2012-05-01 00:00:00 UTC: 2012-12-31 23:59:59 UTC
- Subject
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services Signer - G3
- #5
- rsaEncryption: nil
- A9:59:66:74:DA:3D:8A:7D:7A:D8:FC:F5:80:44:7B:FE:
47:6A:14:55:4E:50:47:0B:EC:D3:ED:CE:F6:38:F7:4F:
69:B9:B1:F0:B6:78:82:0A:8C:76:16:67:E2:02:AD:B7:
0D:A5:8A:F6:03:FC:66:D3:FC:08:2D:CC:B5:73:59:7B:
89:DC:33:6E:66:5A:5E:52:37:B4:62:D1:92:59:35:14:
8B:45:AC:59:B2:4D:24:A2:98:94:68:42:72:9F:3A:68:
E2:6B:8B:9E:22:2D:F4:98:4E:9A:C6:AF:B3:E4:A0:AB:
3C:28:BF:23:E1:D7:72:A4:F2:10:53:67:AE:77:AF:51: 0x010001
- X509v3 extensions
- basicConstraints
- true
- nil
- crlDistributionPoints: http://crl.verisign.com/tss-ca.crl
- extendedKeyUsage: true, timeStamping
- authorityInfoAccess
- OCSP: http://ocsp.verisign.com
- keyUsage: true, 0x80
- subjectAltName
- CN: TSA1-3
- subjectKeyIdentifier:
b4 b7 f1 89 49 26 60 e7 65 ea 73 ae dc d3 38 cd |....I&`.e.s...8.| bf 57 92 6f |.W.o |
- basicConstraints
- RSA-SHA1:
1e 98 aa 27 b7 78 b5 08 b5 c9 72 6d b7 df c0 0e |...'.x....rm....| 98 a6 35 c4 88 c9 d2 f6 6d f1 4b 1a fb d5 f9 2d |..5.....m.K....-| 99 00 9e d1 e7 9b 8b e1 3f bd 39 80 0c 66 cd 07 |........?.9..f..| bc 5c 98 54 a6 94 ba 10 d1 4e 8b ab f5 6f 65 cc |.\.T.....N...oe.| 67 09 a2 80 7c 52 e8 0e 03 d6 6b 7a c6 05 18 ec |g...|R....kz....| c8 ac 42 7c 07 2c a7 3d 08 66 dc 00 ed fd 94 1d |..B|.,.=.f......| 73 f2 72 98 93 b1 11 d6 8f ef 8e ea ac f4 96 51 |s.r............Q| 0c d0 8d df 31 52 4f 5e af 7d a7 4a 75 e6 4e ce |....1RO^.}.Ju.N.| 2b 9f 29 2b e7 cf 5d 9f 03 7e 6e 27 7b 23 ad 62 |+.)+..]..~n'{#.b| 29 66 af 92 e8 2c ce bd 9c 7f dc cd 17 3c 43 c2 |)f...,.......
- 2
- Certificate #1
- 2
- 47:BF:19:95:DF:8D:52:46:43:F7:DB:6D:48:0D:31:A4
- RSA-SHA1: nil
- Issuer
- C: ZA
- ST: Western Cape
- L: Durbanville
- O: Thawte
- OU: Thawte Certification
- CN: Thawte Timestamping CA
- 2003-12-04 00:00:00 UTC: 2013-12-03 23:59:59 UTC
- Subject
- C: US
- O: VeriSign, Inc.
- CN: VeriSign Time Stamping Services CA
- #5
- rsaEncryption: nil
- A9:CA:B2:A4:CC:CD:20:AF:0A:7D:89:AC:87:75:F0:B4:
4E:F1:DF:C1:0F:BF:67:61:BD:A3:64:1C:DA:BB:F9:CA:
33:AB:84:30:89:58:7E:8C:DB:6B:DD:36:9E:0F:BF:D1:
EC:78:F2:77:A6:7E:6F:3C:BF:93:AF:0D:BA:68:F4:6C:
94:CA:BD:52:2D:AB:48:3D:F5:B6:D5:5D:5F:1B:02:9F:
FA:2F:6B:1E:A4:F7:A3:9A:A6:1A:C8:02:E1:7F:4C:52:
E3:0E:60:EC:40:1C:7E:B9:0D:DE:3F:C7:B4:DF:87:BD:
5F:7A:6A:31:2E:03:99:81:13:A8:47:20:CE:31:73:0D:
57:2D:CD:78:34:33:95:12:99:12:B9:DE:68:2F:AA:E6:
E3:C2:8A:8C:2A:C3:8B:21:87:66:BD:83:58:57:6F:75:
BF:3C:AA:26:87:5D:CA:10:15:3C:9F:84:EA:54:C1:0A:
6E:C4:FE:C5:4A:DD:B9:07:11:97:22:7C:DB:3E:27:D1:
1E:78:EC:9F:31:C9:F1:E6:22:19:DB:C4:B3:47:43:9A:
1A:5F:A0:1E:90:E4:5E:F5:EE:7C:F1:7D:AB:62:01:8F:
F5:4D:0B:DE:D0:22:56:A8:95:CD:AE:88:76:AE:EE:BA:
0D:F3:E4:4D:D9:A0:FB:68:A0:AE:14:3B:B3:87:C1:BB: 0x010001
- X509v3 extensions
- authorityInfoAccess
- OCSP: http://ocsp.verisign.com
- basicConstraints
- true
- true: 0
- crlDistributionPoints: http://crl.verisign.com/ThawteTimestampingCA.crl
- extendedKeyUsage: timeStamping
- keyUsage: true, 6
- subjectAltName
- CN: TSA2048-1-53
- authorityInfoAccess
- RSA-SHA1:
4a 6b f9 ea 58 c2 44 1c 31 89 79 99 2b 96 bf 82 |Jk..X.D.1.y.+...| ac 01 d6 1c 4c cd b0 8a 58 6e df 08 29 a3 5e c8 |....L...Xn..).^.| ca 93 13 e7 04 52 0d ef 47 27 2f 00 38 b0 e4 c9 |.....R..G'/.8...| 93 4e 9a d4 22 62 15 f7 3f 37 21 4f 70 31 80 f1 |.N.."b..?7!Op1..| 8b 38 87 b3 e8 e8 97 00 fe cf 55 96 4e 24 d2 a9 |.8........U.N$..| 27 4e 7a ae b7 61 41 f3 2a ce e7 c9 d9 5e dd bb |'Nz..aA.*....^..| 2b 85 3e b5 9d b5 d9 e1 57 ff be b4 c5 7e f5 cf |+.>.....W....~..| 0c 9e f0 97 fe 2b d3 3b 52 1b 1b 38 27 f7 3f 4a |.....+.;R..8'.?J|
- 2
- Certificate #2
- 2
- 0D:F9:EE:3C:FB:C6:D8:DE:E0:77:7F:92:63:CE:06:DF
- RSA-SHA1: nil
- Issuer
- C: US
- O: Thawte, Inc.
- CN: Thawte Code Signing CA - G2
- 2012-08-23 00:00:00 UTC: 2014-08-23 23:59:59 UTC
- Subject
- C: KR
- ST: Seoul
- L: Gangnam-gu
- O: Gala Lab Corp.
- OU: Tech Support Headquarters
- CN: Gala Lab Corp.
- #5
- rsaEncryption: nil
- A0:31:3C:56:1A:48:A0:DE:80:F8:BD:71:40:76:33:FF:
F8:8D:8E:97:C2:B6:3B:E4:2B:35:A6:28:F9:CF:BB:43:
14:B5:C2:BF:02:C5:0E:6D:ED:F4:46:BA:BD:E1:B4:0B:
85:F7:32:B9:E8:B4:8E:72:CE:86:83:A2:14:97:B7:37:
9D:29:1D:4A:F8:41:01:CA:71:57:35:96:4D:60:8C:44:
91:D3:7D:30:97:3F:D1:6C:68:F5:ED:1D:A5:25:AD:8A:
BA:90:BE:19:A8:F8:51:E2:59:AE:55:B1:76:27:89:DA:
41:9B:C5:91:57:D1:DF:03:3C:3C:F7:31:85:BC:52:3A:
06:B8:00:A0:54:CF:93:23:79:00:A1:76:48:F4:48:A5:
CC:2D:4D:A5:C3:F1:5D:9F:63:52:FF:1F:6C:8B:13:0A:
A1:09:14:01:5D:38:4B:02:0E:EB:1A:CF:52:6A:3D:47:
31:6A:66:66:B2:D8:14:66:9C:08:35:FE:8B:01:52:C4:
A5:E5:58:1B:C2:51:E8:24:3B:FF:01:6B:4E:84:C6:F9:
85:8E:3A:44:CC:78:DF:F8:71:B1:08:49:1C:3B:8A:0E:
C9:F5:63:A5:24:1D:8D:AA:F1:4C:A1:83:15:2B:D2:A4:
28:67:07:2F:73:AE:F3:60:5E:EF:01:01:C8:0C:5E:15: 0x010001
- X509v3 extensions
- basicConstraints
- true
- nil
- crlDistributionPoints: http://cs-g2-crl.thawte.com/ThawteCSG2.crl
- extendedKeyUsage
- codeSigning: msCodeCom
- 2.5.29.4
- msCodeCom: 0x80
- authorityInfoAccess
- OCSP: http://ocsp.thawte.com
- nsCertType: 0x10
- basicConstraints
- RSA-SHA1:
45 fe af 60 2d a8 4e 91 98 31 48 0c 43 1c a2 55 |E..`-.N..1H.C..U| d3 23 17 c8 e9 c0 19 62 b4 2d b9 f0 29 c1 b8 a1 |.#.....b.-..)...| 26 91 b1 bb 5c a4 0a 6a 8a 0d 9f 2d 0f 8b 3e f4 |&...\..j...-..>.| e5 12 3d c2 23 25 76 50 64 69 06 dd db e9 bb 64 |..=.#%vPdi.....d| ab 72 6c 70 7a 78 a2 a0 02 75 58 2f e4 e4 56 45 |.rlpzx...uX/..VE| 68 3a ac 2b e8 d4 30 2f f3 d0 40 e6 59 1b c0 39 |h:.+..0/..@.Y..9| 22 92 79 1a 9b f9 0f ba 85 49 25 25 0d 9b a0 21 |".y......I%%...!| a1 d5 c0 1c 90 ea 0b 50 f4 34 14 be 11 c2 5e 93 |.......P.4....^.| 55 f9 f0 7d 38 b6 c7 88 70 9a c7 a9 72 a0 af 8f |U..}8...p...r...| 75 7e d9 be 7f 91 1f a0 dd 33 8b 24 15 fa 01 47 |u~.......3.$...G| 7f f8 34 64 86 be fa 56 f4 bf e6 65 d6 e5 49 57 |..4d...V...e..IW| 20 6b 2d 07 08 4e 3b db a6 ff 90 93 91 fb 69 64 | k-..N;.......id| d8 07 10 60 7a d5 c2 52 dc 44 6e bc 28 5a e7 51 |...`z..R.Dn.(Z.Q| df 85 8d ee 5f 42 a4 6f a0 2b ed 67 08 a1 49 6a |...._B.o.+.g..Ij| bd 9a e3 dd 7e 50 d6 63 3b 20 97 9b 65 ae 56 01 |....~P.c; ..e.V.| ac ab 5f 93 57 ff f2 cb bb c1 eb 28 26 ec 6c d9 |.._.W......(&.l.|
- 2
- Certificate #3
- 2
- 47:97:4D:78:73:A5:BC:AB:0D:2F:B3:70:19:2F:CE:5E
- RSA-SHA1: nil
- Issuer
- C: US
- O: thawte, Inc.
- OU: Certification Services Division
- OU: (c) 2006 thawte, Inc. - For authorized use only
- CN: thawte Primary Root CA
- 2010-02-08 00:00:00 UTC: 2020-02-07 23:59:59 UTC
- Subject
- C: US
- O: Thawte, Inc.
- CN: Thawte Code Signing CA - G2
- #5
- rsaEncryption: nil
- B7:8B:CF:75:5B:9F:25:DA:7E:39:B0:93:DB:38:D3:A9:
23:D0:82:FA:E9:24:7E:5C:0B:8E:83:F8:E6:7A:59:E6:
A3:C5:98:A7:99:D2:44:FF:00:A6:A5:39:04:8A:DA:29:
88:EA:DB:A2:F3:1C:99:15:26:C2:B1:F4:FC:E1:0C:47:
A9:09:11:06:0A:20:92:B9:C7:A0:04:8C:5C:94:19:AB:
5B:25:2C:1D:62:7E:70:0D:CE:61:6C:DD:2B:82:C9:CE:
5D:48:5F:F7:C2:BE:BC:41:23:1E:4F:29:5D:D7:4F:BC:
F4:C5:2A:FC:63:E6:7C:26:4E:99:A7:79:41:9E:10:4A:
7A:79:C9:C6:86:F7:86:95:D2:26:CE:3C:18:2A:D6:7C:
CE:AF:CD:AD:BB:F7:82:2C:70:26:37:45:E5:0F:47:22:
C6:01:28:BD:2E:83:5C:6A:A4:47:C1:E7:D0:D8:6B:81:
46:3F:21:17:F5:07:C5:43:5A:A6:67:2C:B8:7B:60:11:
B5:83:EE:F5:74:0A:72:71:44:3D:58:FE:E8:1A:AB:38:
C3:59:DB:7F:6E:38:7D:76:C7:72:69:98:36:96:57:D3:
66:1C:D2:54:91:04:2E:54:19:B0:DC:3D:B5:22:5E:86:
D5:2A:7E:20:DF:5D:E6:7A:B1:65:FE:C5:02:4E:31:2D: 0x010001
- X509v3 extensions
- basicConstraints
- true
- true: 0
- crlDistributionPoints: http://crl.thawte.com/ThawtePCA.crl
- keyUsage: true, 6
- authorityInfoAccess
- OCSP: http://ocsp.thawte.com
- extendedKeyUsage
- clientAuth: codeSigning
- subjectAltName
- CN: VeriSignMPKI-2-10
- subjectKeyIdentifier:
d4 0d 65 3f 7a bd 34 c6 fe 47 e7 4c 0d c0 bd f2 |..e?z.4..G.L....| de 15 ab 71 |...q |
- authorityKeyIdentifier:
7b 5b 45 cf af ce cb 7a fd 31 92 1a 6a b6 f3 46 |{[E....z.1..j..F| eb 57 48 50 |.WHP |
- basicConstraints
- RSA-SHA1:
56 fe 53 5c e1 c7 9e bc a7 ed 7e 53 6d 6a 14 4b |V.S\......~Smj.K| 51 8c 40 5e 80 5f aa a4 e8 2f ef 38 c8 04 c9 ca |Q.@^._.../.8....| 3e cf df 3a 58 4e b0 d4 b6 63 c5 29 57 fa 02 05 |>..:XN...c.)W...| 9a 45 4d 68 db 2a 1b d4 34 3d 9f 00 c3 5a cb 95 |.EMh.*..4=...Z..| 49 a5 6e e1 b0 c5 fc 41 4d 41 4a 6f d3 77 c8 d7 |I.n....AMAJo.w..| 38 8d e4 19 de 18 f3 1f 15 65 83 6d 45 0c 53 f9 |8........e.mE.S.| 0a 9a 2e a5 5d bf 6f 32 81 18 92 19 6a 55 00 ad |....].o2....jU..| 63 1c 52 06 7e 55 d9 29 68 ae 4a 7c 18 9a 79 88 |c.R.~U.)h.J|..y.| 6b 23 23 d8 27 38 2a 29 87 76 ca fb c7 b6 62 23 |k##.'8*).v....b#| 1f ed 7a 56 4c dd 9c 32 5b f5 3d 0c 46 18 95 3b |..zVL..2[.=.F..;| 2a 23 68 83 64 41 d9 00 6d 0f 19 24 15 68 72 bd |*#h.dA..m..$.hr.| c5 71 67 6e ac 4c db 90 eb 51 a5 1a 62 07 d0 be |.qgn.L...Q..b...| 6a 00 47 3c 72 2f ec 4f 61 3e 73 85 ce 5a 0a b7 |j.G
s..Z..| ba c0 1c 13 75 e3 22 39 28 dd 6d 1d 09 46 9d 4f |....u."9(.m..F.O| ba e8 40 81 91 c6 a4 ce 94 72 1b 01 cf 2a 6e 15 |..@......r...*n.| 67 95 89 ae 7d b7 b7 cd f9 0a 3d 75 b6 6b 3c 25 |g...}.....=u.k<%|
- 2
- Certificate #0
- 1
- unnamed
- #0
- C: US
- O: Thawte, Inc.
- CN: Thawte Code Signing CA - G2
- 0D:F9:EE:3C:FB:C6:D8:DE:E0:77:7F:92:63:CE:06:DF
- #0
- SHA1: nil
- #2
- contentType: 1.3.6.1.4.1.311.2.1.4
- 1.3.6.1.4.1.311.2.1.11: msCodeCom
- messageDigest:
cb b8 31 83 7c 48 9b 54 e2 fd 81 ba d0 92 4d c9 |..1.|H.T......M.| 0f 46 14 fe |.F.. |
- 1.3.6.1.4.1.311.2.1.12
00 52 00 61 00 70 00 70 00 65 00 6c 00 7a |.R.a.p.p.e.l.z |
: http://www.galalab.kr
- rsaEncryption:
97 de 9c 4b 3f ff 75 69 6d a7 ed 56 db e4 6e c2 |...K?.uim..V..n.| 4d 15 a5 d0 25 14 6a 3d 36 5e 13 30 c4 23 1e 20 |M...%.j=6^.0.#. | 9e 1c 00 f4 7d fb e2 d3 f8 c8 69 c5 23 df 77 fe |....}.....i.#.w.| e7 ec 73 08 0f 0f b7 fd 30 10 bb f2 14 22 63 7f |..s.....0...."c.| cb ca ad 13 1d 6c 31 11 5b 46 88 32 12 8f 16 1a |.....l1.[F.2....| 0c ff b4 e9 6c d3 39 52 38 f0 81 50 22 56 fa c4 |....l.9R8..P"V..| f6 84 f0 1d 97 a3 1d 16 da 42 df d0 ae 43 90 11 |.........B...C..| e7 cc 6f cc 2c 76 c7 79 6f 64 33 64 43 c9 a1 1d |..o.,v.yod3dC...| f4 a2 6b 49 83 2e 8e d2 b4 ce a1 7b 7a 26 5a 50 |..kI.......{z&ZP| 79 1d d3 7f 2e 78 62 33 d6 6b 7a cc 91 5f d8 1a |y....xb3.kz.._..| b2 32 1d 65 27 98 58 d9 21 1a af 50 bb 6e 8d 59 |.2.e'.X.!..P.n.Y| 45 57 98 9c 18 a8 db 6a db 20 12 69 eb e5 25 83 |EW.....j. .i..%.| 6b 1f a5 e4 6f 83 45 03 d4 c5 c8 c5 71 53 ea 90 |k...o.E.....qS..| f1 f5 b9 e4 43 af 91 e6 27 e6 be 4b a6 32 53 de |....C...'..K.2S.| de 44 97 49 10 10 bc 37 71 70 c3 65 07 10 1c 1a |.D.I...7qp.e....| 7c 1d ca a7 25 61 28 54 51 04 89 c1 07 ec 0b a1 ||...%a(TQ.......|
- countersignature
- 1
- unnamed
- #0
- C: US
- O: VeriSign, Inc.
- CN: VeriSign Time Stamping Services CA
- 79:A2:A5:85:F9:D1:15:42:13:D9:B8:3E:F6:B6:8D:ED
- #0
- SHA1: nil
- #2
- contentType: pkcs7-data
- signingTime: 2012-11-27 17:15:28 UTC
- messageDigest:
e2 6f a0 54 9f 62 95 1b 56 04 7c cc 43 95 22 bb |.o.T.b..V.|.C.".| 5d e8 48 60 |].H` |
- rsaEncryption:
2c 76 a6 dc 52 0e 93 64 b6 b7 67 9a a9 68 ed d2 |,v..R..d..g..h..| 20 8f c0 ce c0 90 de 61 2d 82 bd 7a df c8 ca 83 | ......a-..z....| f7 10 f8 51 d6 6e 9a ec 59 4b 86 2f c4 61 ab 0b |...Q.n..YK./.a..| a8 1b fd 2e 6c 24 10 b8 e5 82 44 30 85 4e 0a 25 |....l$....D0.N.%| 5d 68 47 10 b2 5e 21 88 7f 65 0d 56 0b 65 b6 7a |]hG..^!..e.V.e.z| cf 0a 20 b3 01 85 c0 d0 a0 5c 59 e8 6e cf 51 8e |.. ......\Y.n.Q.| 57 7f 84 f6 d6 fd f9 d9 7c de 9d bc 9f d3 be 09 |W.......|.......| fd 0a 83 92 af ad 78 d7 06 15 63 95 4e 79 33 23 |......x...c.Ny3#|
- unnamed
- 1
- unnamed
offset | size | type | comment | |
---|---|---|---|---|
0 | 4167680 | EXE | 11/27/2012 16:03:20 | # |
15c1 | 15 | HTM | # | |
3f9800 | 5264 | PKCS7 | Authenticode Signature | # |
![]() |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x94b1a4
[?] can't find file_offset of VA 0x0