Edit tour

Windows Analysis Report
netscan.exe

Overview

General Information

Sample Name:netscan.exe
Analysis ID:1281785
MD5:5db121b74aede2736366690c74b4a197
SHA1:0f57df99a37b8c80b3fdf691a9fc50697c3ea26d
SHA256:6321c3bdb6e8311c5e62da960a5289fe95604023883c0eb2167865a8ddb44bfa

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sample file is different than original file name gathered from version info
PE file contains executable resources (Code or Archives)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • netscan.exe (PID: 5548 cmdline: C:\Users\user\Desktop\netscan.exe MD5: 5DB121B74AEDE2736366690C74B4A197)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: netscan.exe, 00000000.00000002.658173530.000000010081E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: -----BEGIN RSA PUBLIC KEY-----
Source: netscan.exeString found in binary or memory: http://nossl.softperfect.com/download/support/oui.txt
Source: netscan.exeString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
Source: netscan.exeString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/09/transfer/Get
Source: netscan.exeString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/04/discovery/Probe
Source: netscan.exeString found in binary or memory: http://v4.softperfect.com/scripts/netscanner/getinfo.php
Source: netscan.exeString found in binary or memory: http://v6.softperfect.com/scripts/netscanner/getinfo.php
Source: netscan.exe, 00000000.00000002.659160200.0000000100CCB000.00000008.00000001.01000000.00000003.sdmp, netscan.exe, 00000000.00000000.376653064.0000000100CC7000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: http://www.gnu.org/licenses/.
Source: netscan.exeString found in binary or memory: http://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Source: netscan.exeString found in binary or memory: http://www.softperfect.com/products/networkscanner/version.txt
Source: netscan.exeString found in binary or memory: https://nmap.org
Source: netscan.exeString found in binary or memory: https://www.softperfect.com
Source: netscan.exeString found in binary or memory: https://www.softperfect.com/order/?sns
Source: netscan.exeString found in binary or memory: https://www.softperfect.com/order/?sns&upgrade
Source: netscan.exeString found in binary or memory: https://www.softperfect.com/products/networkscanner/?from=nver
Source: netscan.exeString found in binary or memory: https://www.softperfect.com/products/networkscanner/manual/
Source: netscan.exeString found in binary or memory: https://www.softperfect.com/support/
Source: netscan.exe, 00000000.00000002.659160200.0000000100CCB000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameD vs netscan.exe
Source: netscan.exe, 00000000.00000000.376653064.0000000100CC7000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameD vs netscan.exe
Source: netscan.exeStatic PE information: Resource name: RT_RCDATA type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
Source: C:\Users\user\Desktop\netscan.exeFile read: C:\Users\user\Desktop\netscan.exeJump to behavior
Source: netscan.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\netscan.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: netscan.exeString found in binary or memory: IN-ADDR.ARPA
Source: netscan.exeString found in binary or memory: -oX - --script-help=all
Source: netscan.exeString found in binary or memory: <soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:lms="http://schemas.microsoft.com/windows/lms/2007/08" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing">
Source: netscan.exeString found in binary or memory: <wsa:Address>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:Address>
Source: netscan.exeString found in binary or memory: Z<wsa:Address>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:Address>
Source: netscan.exeString found in binary or memory: <soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:wsd="http://schemas.xmlsoap.org/ws/2005/04/discovery" xmlns:wsdp="http://schemas.xmlsoap.org/ws/2006/02/devprof">
Source: netscan.exeString found in binary or memory: ip-address
Source: netscan.exeString found in binary or memory: mac-address
Source: netscan.exeString found in binary or memory: <!--StartFragment-->
Source: classification engineClassification label: clean0.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\netscan.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4657278A-411B-11d2-839A-00C04FD918D0}\InProcServer32Jump to behavior
Source: netscan.exe, 00000000.00000002.658173530.000000010081E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: netscan.exe, 00000000.00000002.658173530.000000010081E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: C:\Users\user\Desktop\netscan.exeAutomated click: OK
Source: C:\Users\user\Desktop\netscan.exeAutomated click: Continue
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: netscan.exeStatic file information: File size 16358912 > 1048576
Source: netscan.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: netscan.exeStatic PE information: Image base 0x100000000 > 0x60000000
Source: netscan.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x76a000
Source: netscan.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x40a000
Source: netscan.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x2f2800
Source: netscan.exeStatic PE information: More than 200 imports for user32.dll
Source: C:\Users\user\Desktop\netscan.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\netscan.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: netscan.exe, 00000000.00000002.642306860.000000000619F000.00000004.00000020.00020000.00000000.sdmp, netscan.exe, 00000000.00000003.381194566.0000000006199000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll](u
Source: netscan.exe, 00000000.00000002.658173530.000000010081E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: Shell_TrayWnd
Source: netscan.exe, 00000000.00000002.658173530.000000010081E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: ToolbarWindow32Shell_TrayWnd
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts2
Command and Scripting Interpreter
Path Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
Security Software Discovery
Remote Services1
Archive Collected Data
Exfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1281785 Sample: netscan.exe Startdate: 28/07/2023 Architecture: WINDOWS Score: 0 4 netscan.exe 2 2->4         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
netscan.exe2%ReversingLabs
netscan.exe0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://www.softperfect.com/support/netscan.exefalse
    high
    http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymousnetscan.exefalse
      high
      http://v4.softperfect.com/scripts/netscanner/getinfo.phpnetscan.exefalse
        high
        http://www.softperfect.com/products/networkscanner/version.txtnetscan.exefalse
          high
          https://nmap.orgnetscan.exefalse
            high
            https://www.softperfect.com/products/networkscanner/manual/netscan.exefalse
              high
              http://schemas.xmlsoap.org/ws/2005/04/discovery/Probenetscan.exefalse
                high
                https://www.softperfect.com/order/?sns&upgradenetscan.exefalse
                  high
                  http://v6.softperfect.com/scripts/netscanner/getinfo.phpnetscan.exefalse
                    high
                    https://www.softperfect.com/order/?snsnetscan.exefalse
                      high
                      http://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csvnetscan.exefalse
                        high
                        http://www.gnu.org/licenses/.netscan.exe, 00000000.00000002.659160200.0000000100CCB000.00000008.00000001.01000000.00000003.sdmp, netscan.exe, 00000000.00000000.376653064.0000000100CC7000.00000008.00000001.01000000.00000003.sdmpfalse
                          high
                          http://schemas.xmlsoap.org/ws/2004/09/transfer/Getnetscan.exefalse
                            high
                            https://www.softperfect.com/products/networkscanner/?from=nvernetscan.exefalse
                              high
                              http://nossl.softperfect.com/download/support/oui.txtnetscan.exefalse
                                high
                                https://www.softperfect.comnetscan.exefalse
                                  high
                                  No contacted IP infos
                                  Joe Sandbox Version:38.0.0 Beryl
                                  Analysis ID:1281785
                                  Start date and time:2023-07-28 13:22:20 +02:00
                                  Joe Sandbox Product:CloudBasic
                                  Overall analysis duration:0h 7m 22s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                  Number of analysed new started processes analysed:4
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • HDC enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample file name:netscan.exe
                                  Detection:CLEAN
                                  Classification:clean0.winEXE@1/0@0/0
                                  EGA Information:Failed
                                  HDC Information:Failed
                                  HCA Information:
                                  • Successful, ratio: 100%
                                  • Number of executed functions: 0
                                  • Number of non-executed functions: 0
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe
                                  • Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  No simulations
                                  No context
                                  No context
                                  No context
                                  No context
                                  No context
                                  No created / dropped files found
                                  File type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
                                  Entropy (8bit):6.375845914075556
                                  TrID:
                                  • Visual Basic Script (13500/0) 45.69%
                                  • Win64 Executable (generic) (12005/4) 40.63%
                                  • Generic Win/DOS Executable (2004/3) 6.78%
                                  • DOS Executable Generic (2002/1) 6.78%
                                  • VXD Driver (31/22) 0.10%
                                  File name:netscan.exe
                                  File size:16'358'912 bytes
                                  MD5:5db121b74aede2736366690c74b4a197
                                  SHA1:0f57df99a37b8c80b3fdf691a9fc50697c3ea26d
                                  SHA256:6321c3bdb6e8311c5e62da960a5289fe95604023883c0eb2167865a8ddb44bfa
                                  SHA512:d1d6007ef788057292a3a1b8970262c0160545156a08e18d8f56259f83d1ca600d1b8264949fae2d39b61ae626457d42d516b3ad7340a089a1024b1e81c14d20
                                  SSDEEP:196608:txFbq99F4Z+OEhvXFGr8D8elzqHuBs+g:HFbq934YOEhvXFSk8I2Hw
                                  TLSH:D8F65BBBB532CA98C0CBC6F4148287A2DB317D1419B5134622C93F0F6E72F545E6E99E
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................./.....0.v.$/...@..@=.....................................................................................
                                  Icon Hash:196566667ccc4d17
                                  Entrypoint:0x100003d40
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x100000000
                                  Subsystem:windows gui
                                  Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED
                                  DLL Characteristics:
                                  Time Stamp:0x0 [Thu Jan 1 00:00:00 1970 UTC]
                                  TLS Callbacks:0x3cc0, 0x1
                                  CLR (.Net) Version:
                                  OS Version Major:4
                                  OS Version Minor:0
                                  File Version Major:4
                                  File Version Minor:0
                                  Subsystem Version Major:4
                                  Subsystem Version Minor:0
                                  Import Hash:88349e111bd650ce90bc4f6c23f6aca3
                                  Instruction
                                  dec eax
                                  lea esp, dword ptr [esp-28h]
                                  mov byte ptr [00768574h], 00000000h
                                  dec esp
                                  lea eax, dword ptr [00CC22ADh]
                                  dec eax
                                  lea edx, dword ptr [00CC22AEh]
                                  dec eax
                                  lea ecx, dword ptr [0076730Fh]
                                  call 00007F8A24CDB88Fh
                                  call 00007F8A24CDB89Ah
                                  dec eax
                                  lea ecx, dword ptr [0076729Eh]
                                  call 00007F8A24CF11AEh
                                  nop
                                  dec eax
                                  lea esp, dword ptr [esp+28h]
                                  ret
                                  add byte ptr [eax], al
                                  push ebp
                                  dec eax
                                  mov ebp, ecx
                                  dec eax
                                  lea esp, dword ptr [esp-20h]
                                  dec eax
                                  lea edx, dword ptr [0083F168h]
                                  dec eax
                                  lea ecx, dword ptr [ebp-50h]
                                  call 00007F8A24CE74ECh
                                  dec eax
                                  lea ecx, dword ptr [ebp-48h]
                                  call 00007F8A24CE2133h
                                  dec eax
                                  lea ecx, dword ptr [ebp-40h]
                                  call 00007F8A24CE212Ah
                                  dec eax
                                  lea ecx, dword ptr [ebp-08h]
                                  call 00007F8A24CE2121h
                                  nop
                                  dec eax
                                  lea esp, dword ptr [esp+20h]
                                  pop ebp
                                  ret
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  push ebp
                                  dec eax
                                  mov ebp, esp
                                  dec eax
                                  lea esp, dword ptr [esp-80h]
                                  dec eax
                                  mov dword ptr [ebp-58h], ebx
                                  call 00007F8A24CEAE33h
                                  dec eax
                                  mov dword ptr [ebp-50h], 00000000h
                                  dec eax
                                  mov dword ptr [ebp-48h], 00000000h
                                  dec eax
                                  mov dword ptr [ebp-40h], 00000000h
                                  dec eax
                                  mov dword ptr [ebp-08h], 00000000h
                                  nop
                                  dec eax
                                  mov eax, dword ptr [00CA0DA6h]
                                  cmp byte ptr [eax+08h], 00000000h
                                  je 00007F8A24CDB9EEh
                                  dec eax
                                  lea eax, dword ptr [00000065h]
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0xcc70000x21c.idata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0xcce0000x2f265c.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0xc280000x78fa8.pdata
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x76b0700x28.data
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0xcc8bdc0x19c0.idata
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x10000x769f300x76a000unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .data0x76b0000xb2f240xb3000False0.5266713403456704DOS executable (block device driver)6.3957588377157135IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .rdata0x81e0000x409e580x40a000unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .pdata0xc280000x78fa80x79000False0.5050482631714877data6.512143931698007IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .bss0xca10000x240e00x0False0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .CRT0xcc60000x180x200False0.03515625data0.06116285224115448IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .idata0xcc70000x6e740x7000False0.25118582589285715data4.473242732391984IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .rsrc0xcce0000x2f265c0x2f2800unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                  TYPELIB0xcd3cf00x2264data0.3421172194457065
                                  RT_CURSOR0xcd5f540x134data0.12012987012987013
                                  RT_CURSOR0xcd60880x134data0.2305194805194805
                                  RT_CURSOR0xcd61bc0x134data0.4935064935064935
                                  RT_CURSOR0xcd62f00x334data0.24634146341463414
                                  RT_CURSOR0xcd66240x434data0.24814126394052044
                                  RT_CURSOR0xcd6a580x134Targa image data - Map - RLE 64 x 65536 x 1 +32 "\001"0.5
                                  RT_CURSOR0xcd6b8c0x334data0.24634146341463414
                                  RT_CURSOR0xcd6ec00x434Targa image data 128 x 65536 x 1 +64 "\001"0.24349442379182157
                                  RT_CURSOR0xcd72f40x134data0.36688311688311687
                                  RT_CURSOR0xcd74280x334data0.2146341463414634
                                  RT_CURSOR0xcd775c0x434data0.18680297397769516
                                  RT_CURSOR0xcd7b900x134Targa image data 64 x 65536 x 1 +32 "\001"0.36688311688311687
                                  RT_CURSOR0xcd7cc40x334Targa image data - RLE 96 x 65536 x 1 +48 "\001"0.20609756097560974
                                  RT_CURSOR0xcd7ff80x434Targa image data - Color 128 x 65536 x 1 +64 "\001"0.17657992565055763
                                  RT_CURSOR0xcd842c0x134data0.5844155844155844
                                  RT_CURSOR0xcd85600x334data0.3
                                  RT_CURSOR0xcd88940x434data0.2983271375464684
                                  RT_CURSOR0xcd8cc80x134Targa image data - Map - RLE 64 x 65536 x 1 +32 "\001"0.42857142857142855
                                  RT_CURSOR0xcd8dfc0x334data0.2280487804878049
                                  RT_CURSOR0xcd91300x434Targa image data 128 x 65536 x 1 +64 "\001"0.23513011152416358
                                  RT_CURSOR0xcd95640x134Targa image data - Map - RLE 64 x 65536 x 1 +32 "\001"0.5
                                  RT_CURSOR0xcd96980x334data0.24634146341463414
                                  RT_CURSOR0xcd99cc0x434Targa image data 128 x 65536 x 1 +64 "\001"0.24349442379182157
                                  RT_CURSOR0xcd9e000x134data0.2662337662337662
                                  RT_CURSOR0xcd9f340x134Targa image data - Map 64 x 65536 x 1 +32 "\001"0.38311688311688313
                                  RT_CURSOR0xcda0680x134data0.3538961038961039
                                  RT_CURSOR0xcda19c0x134AmigaOS bitmap font "(", fc_YSize 4294967064, 3584 elements, 2nd "\377\270w\377\377\370\177\377\377\370\177\377\377\370\177\377\377\370\177\377\377\370\177\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rd0.3181818181818182
                                  RT_CURSOR0xcda2d00x134Targa image data 64 x 65536 x 1 +32 "\001"0.5194805194805194
                                  RT_CURSOR0xcda4040x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.1858288770053476
                                  RT_CURSOR0xcda6f00x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.21256684491978609
                                  RT_CURSOR0xcda9dc0x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.1858288770053476
                                  RT_CURSOR0xcdacc80x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.1925133689839572
                                  RT_CURSOR0xcdafb40x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.20588235294117646
                                  RT_CURSOR0xcdb2a00x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.18850267379679145
                                  RT_CURSOR0xcdb58c0x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.18181818181818182
                                  RT_CURSOR0xcdb8780x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.18449197860962566
                                  RT_CURSOR0xcdbb640x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.19117647058823528
                                  RT_CURSOR0xcdbe500x2ecTarga image data 64 x 65536 x 1 +32 "\004"0.18983957219251338
                                  RT_CURSOR0xcdc13c0x134data0.3538961038961039
                                  RT_ICON0xcdc2700xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.6881663113006397
                                  RT_ICON0xcdd1180x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.7847472924187726
                                  RT_ICON0xcdd9c00x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 00.7321428571428571
                                  RT_ICON0xcde0880x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.5036127167630058
                                  RT_ICON0xcde5f00x69b7PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9944943280493663
                                  RT_ICON0xce4fa80x10828Device independent bitmap graphic, 128 x 256 x 32, image size 00.17091565124807762
                                  RT_ICON0xcf57d00x4228Device independent bitmap graphic, 64 x 128 x 32, image size 00.33354983467170524
                                  RT_ICON0xcf99f80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.35560165975103736
                                  RT_ICON0xcfbfa00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.4652908067542214
                                  RT_ICON0xcfd0480x988Device independent bitmap graphic, 24 x 48 x 32, image size 00.5483606557377049
                                  RT_ICON0xcfd9d00x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.6090425531914894
                                  RT_DIALOG0xcfde380x32data0.76
                                  RT_RCDATA0xcfde6c0x111PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0
                                  RT_RCDATA0xcfdf800x11fPNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced0.9930313588850174
                                  RT_RCDATA0xcfe0a00x139PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced0.9904153354632588
                                  RT_RCDATA0xcfe1dc0x163PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0225352112676056
                                  RT_RCDATA0xcfe3400x1dcPNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.023109243697479
                                  RT_RCDATA0xcfe51c0x274PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.017515923566879
                                  RT_RCDATA0xcfe7900x1efPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0222222222222221
                                  RT_RCDATA0xcfe9800x2eaPNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0147453083109919
                                  RT_RCDATA0xcfec6c0x377PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.012401352874859
                                  RT_RCDATA0xcfefe40x175PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0
                                  RT_RCDATA0xcff15c0x173PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0080862533692723
                                  RT_RCDATA0xcff2d00x1f2PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0140562248995983
                                  RT_RCDATA0xcff4c40x194PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0222772277227723
                                  RT_RCDATA0xcff6580x1d4PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0235042735042734
                                  RT_RCDATA0xcff82c0x22cPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0197841726618706
                                  RT_RCDATA0xcffa580x2c8PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0154494382022472
                                  RT_RCDATA0xcffd200x41ePNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0104364326375712
                                  RT_RCDATA0xd001400x528PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0083333333333333
                                  RT_RCDATA0xd006680x178PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0132978723404256
                                  RT_RCDATA0xd007e00x200PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.021484375
                                  RT_RCDATA0xd009e00x248PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.018835616438356
                                  RT_RCDATA0xd00c280x279PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0173775671406002
                                  RT_RCDATA0xd00ea40x346PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0131264916467781
                                  RT_RCDATA0xd011ec0x36cPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0125570776255708
                                  RT_RCDATA0xd015580x1e9PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0224948875255624
                                  RT_RCDATA0xd017440x243PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0189982728842832
                                  RT_RCDATA0xd019880x315PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0139416983523448
                                  RT_RCDATA0xd01ca00x178PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0132978723404256
                                  RT_RCDATA0xd01e180x200PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.021484375
                                  RT_RCDATA0xd020180x248PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.018835616438356
                                  RT_RCDATA0xd022600x226PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.02
                                  RT_RCDATA0xd024880x2e9PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.014765100671141
                                  RT_RCDATA0xd027740x39dPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.011891891891892
                                  RT_RCDATA0xd02b140x2daPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.015068493150685
                                  RT_RCDATA0xd02df00x441PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0101010101010102
                                  RT_RCDATA0xd032340x599PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0076762037683182
                                  RT_RCDATA0xd037d00x264PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0179738562091503
                                  RT_RCDATA0xd03a340x361PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0127167630057803
                                  RT_RCDATA0xd03d980x4b2PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0091514143094842
                                  RT_RCDATA0xd0424c0x26cPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.017741935483871
                                  RT_RCDATA0xd044b80x3c0PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0114583333333333
                                  RT_RCDATA0xd048780x52fPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.008289374529013
                                  RT_RCDATA0xd04da80x1cdPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.017353579175705
                                  RT_RCDATA0xd04f780x2acPNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0160818713450293
                                  RT_RCDATA0xd052240x324PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.013681592039801
                                  RT_RCDATA0xd055480x37dPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0123180291153415
                                  RT_RCDATA0xd058c80x554PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0080645161290323
                                  RT_RCDATA0xd05e1c0x632PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0069356872635562
                                  RT_RCDATA0xd064500x1cdPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.017353579175705
                                  RT_RCDATA0xd066200x2acPNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0160818713450293
                                  RT_RCDATA0xd068cc0x324PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.013681592039801
                                  RT_RCDATA0xd06bf00x3a9SVG Scalable Vector Graphics imageEnglishAustralia0.48772678762006405
                                  RT_RCDATA0xd06f9c0x560SVG Scalable Vector Graphics imageEnglishAustralia0.4113372093023256
                                  RT_RCDATA0xd074fc0x6bePNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0063731170336037
                                  RT_RCDATA0xd07bbc0xb7bPNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0037427696495407
                                  RT_RCDATA0xd087380xf46PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0028132992327365
                                  RT_RCDATA0xd096800x523PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0083650190114068
                                  RT_RCDATA0xd09ba40x80cPNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0053398058252427
                                  RT_RCDATA0xd0a3b00xb0bPNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0038910505836576
                                  RT_RCDATA0xd0aebc0x5cdPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0074074074074073
                                  RT_RCDATA0xd0b48c0x997PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0044806517311609
                                  RT_RCDATA0xd0be240xca6PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.003397158739963
                                  RT_RCDATA0xd0cacc0x53cPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0082089552238807
                                  RT_RCDATA0xd0d0080x7a4PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0056237218813906
                                  RT_RCDATA0xd0d7ac0xa58PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0041540785498488
                                  RT_RCDATA0xd0e2040x342PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.013189448441247
                                  RT_RCDATA0xd0e5480x45dPNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0098478066248882
                                  RT_RCDATA0xd0e9a80x607PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0071289695398573
                                  RT_RCDATA0xd0efb00xfdb89Unicode text, UTF-8 (with BOM) text, with very long lines (453), with CRLF line terminatorsEnglishUnited States0.3159998498904489
                                  RT_RCDATA0xe0cb3c0x878PNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0050738007380073
                                  RT_RCDATA0xe0d3b40xd32PNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced0.9863824748371818
                                  RT_RCDATA0xe0e0e80xfd5PNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9518874907475944
                                  RT_RCDATA0xe0f0c00x7c8PNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0055220883534137
                                  RT_RCDATA0xe0f8880xbb4PNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced0.992656875834446
                                  RT_RCDATA0xe1043c0xeabPNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9691078561917443
                                  RT_RCDATA0xe112e80x5b9PNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0075085324232083
                                  RT_RCDATA0xe118a40x8c5PNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced0.9973273942093541
                                  RT_RCDATA0xe1216c0xb9dPNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9606458123107972
                                  RT_RCDATA0xe12d0c0x1c3PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.024390243902439
                                  RT_RCDATA0xe12ed00x29aPNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0165165165165164
                                  RT_RCDATA0xe1316c0x32ePNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0135135135135136
                                  RT_RCDATA0xe1349c0x196PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.022167487684729
                                  RT_RCDATA0xe136340x287PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.017001545595054
                                  RT_RCDATA0xe138bc0x29bPNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0059970014992503
                                  RT_RCDATA0xe13b580x1a0PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0216346153846154
                                  RT_RCDATA0xe13cf80x232PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.019572953736655
                                  RT_RCDATA0xe13f2c0x277PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.01743264659271
                                  RT_RCDATA0xe141a40x84dPNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0051764705882353
                                  RT_RCDATA0xe149f40xccdPNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced0.9874885566066525
                                  RT_RCDATA0xe156c40xf14PNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9546632124352331
                                  RT_RCDATA0xe165d80x78fPNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0056847545219638
                                  RT_RCDATA0xe16d680xb37PNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced0.9923371647509579
                                  RT_RCDATA0xe178a00xde3PNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9673699015471168
                                  RT_RCDATA0xe186840x539PNG image data, 144 x 16, 8-bit/color RGBA, non-interlaced1.0082273747195214
                                  RT_RCDATA0xe18bc00x891PNG image data, 216 x 24, 8-bit/color RGBA, non-interlaced1.005015959872321
                                  RT_RCDATA0xe194540xa3ePNG image data, 288 x 32, 8-bit/color RGBA, non-interlaced1.0041952707856598
                                  RT_RCDATA0xe19e940xfeePNG image data, 400 x 16, 8-bit/color RGBA, non-interlaced1.0026974006866112
                                  RT_RCDATA0xe1ae840x128PNG image data, 9 x 9, 8-bit/color RGBA, non-interlaced1.0
                                  RT_RCDATA0xe1afac0x1c0PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced1.0245535714285714
                                  RT_RCDATA0xe1b16c0x19ePNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced1.0217391304347827
                                  RT_RCDATA0xe1b30c0x14dPNG image data, 9 x 9, 8-bit/color RGBA, non-interlaced1.012012012012012
                                  RT_RCDATA0xe1b45c0x1eePNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced1.0222672064777327
                                  RT_RCDATA0xe1b64c0x1c7PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced1.024175824175824
                                  RT_RCDATA0xe1b8140x1b93PNG image data, 600 x 24, 8-bit/color RGBA, non-interlaced1.0007083156254426
                                  RT_RCDATA0xe1d3a80x1fb3PNG image data, 800 x 32, 8-bit/color RGBA, non-interlaced0.9930991990141713
                                  RT_RCDATA0xe1f35c0x9600PE32 executable (console) Intel 80386 (stripped to external PDB), for MS WindowsEnglishAustralia0.471796875
                                  RT_RCDATA0xe2895c0x964Unicode text, UTF-8 (with BOM) text, with very long lines (578), with CRLF line terminatorsEnglishUnited States0.5016638935108153
                                  RT_RCDATA0xe292c00x2f6SVG Scalable Vector Graphics imageEnglishAustralia0.45118733509234826
                                  RT_RCDATA0xe295b80x423SVG Scalable Vector Graphics imageEnglishAustralia0.35694050991501414
                                  RT_RCDATA0xe299dc0x16fPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0190735694822888
                                  RT_RCDATA0xe29b4c0x194PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0198019801980198
                                  RT_RCDATA0xe29ce00x243PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0189982728842832
                                  RT_RCDATA0xe29f240x108PNG image data, 8 x 8, 8-bit/color RGBA, non-interlaced1.0
                                  RT_RCDATA0xe2a02c0x162PNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced1.0141242937853108
                                  RT_RCDATA0xe2a1900x17dPNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.020997375328084
                                  RT_RCDATA0xe2a3100x1b1PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0184757505773672
                                  RT_RCDATA0xe2a4c40x23fPNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0191304347826087
                                  RT_RCDATA0xe2a7040x12dPNG image data, 8 x 8, 8-bit/color RGBA, non-interlaced1.0066445182724253
                                  RT_RCDATA0xe2a8340x15dPNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced1.0143266475644699
                                  RT_RCDATA0xe2a9940x1cdDelphi compiled form 'TCalendarPopupForm'0.6355748373101953
                                  RT_RCDATA0xe2ab640x165a31Delphi compiled form 'TDefaultDataModule'0.9504413604736328
                                  RT_RCDATA0xf905980x7bcDelphi compiled form 'TfmAbout'0.4626262626262626
                                  RT_RCDATA0xf90d540x172Delphi compiled form ''0.7351351351351352
                                  RT_RCDATA0xf90ec80x353Delphi compiled form 'TfmAuthInfo'0.5029377203290247
                                  RT_RCDATA0xf9121c0xfbDelphi compiled form 'TfmBackColorPopup'0.8087649402390438
                                  RT_RCDATA0xf913180x19aDelphi compiled form 'TfmBaseDialog'0.6609756097560976
                                  RT_RCDATA0xf914b40x1c1Delphi compiled form '\027TfmBaseDialogRemoteEdit\026fmBaseDialogRemoteEdit\007Caption\006'0.6057906458797327
                                  RT_RCDATA0xf916780x2c5Delphi compiled form '\025TfmBaseDialogShutdown\024fmBaseDialogShutdown\006Height\003\265\001\005Width\003\264\001\014ClientHeight\003\265\001\013ClientWidth\003\264\001\010OnCreate\007'0.5289139633286318
                                  RT_RCDATA0xf919400x897Delphi compiled form '\023TfmBaseQueryBuilder\022fmBaseQueryBuilder\004Left\003\303\002\006Height\003D\002\003Top\0037\001\005Width\003.\003\014ClientHeight\003D\002\013ClientWidth\003.\003\010OnCreate\007'0.4242837653478854
                                  RT_RCDATA0xf921d80x3a5Delphi compiled form '\017TfmBookmarkEdit\016fmBookmarkEdit\004Left\003K\004\006Height\003\305\001\003Top\003\013\002\005Width\003\251\002\007Caption\006\021Add/Edit IP Range\014ClientHeight\003\305\001\013ClientWidth\003\251\002\010OnC'0.5219721329046088
                                  RT_RCDATA0xf925800xa85Delphi compiled form 'TfmBookmarkList'0.39918306721128854
                                  RT_RCDATA0xf930080x8d2Delphi compiled form '\027TfmColumnDisplayOptions\026fmColumnDisplayOptions\006Height\003\324\001\007Caption\006\007Display\014ClientHeight\003\324\001'0.37156775907883083
                                  RT_RCDATA0xf938dc0xaf2Delphi compiled form 'TfmCompare'0.3886509635974304
                                  RT_RCDATA0xf943d00x9f5Delphi compiled form 'TfmCreateBatch'0.4123185562965869
                                  RT_RCDATA0xf94dc80x2b2Delphi compiled form '\013TfmCredEdit'0.4855072463768116
                                  RT_RCDATA0xf9507c0x595Delphi compiled form 'TfmCredManager'0.4268719384184745
                                  RT_RCDATA0xf956140x2ffDelphi compiled form '\025TfmDeleteDevicePrompt\024fmDeleteDevicePrompt\006Height\003\225'0.5397653194263363
                                  RT_RCDATA0xf959140x457Delphi compiled form '\013TfmDetectIP'0.5472547254725473
                                  RT_RCDATA0xf95d6c0x375Delphi compiled form 'TfmDHCPView'0.5694915254237288
                                  RT_RCDATA0xf960e40x682Delphi compiled form 'TfmDiscoveryView'0.4411764705882353
                                  RT_RCDATA0xf967680x52bDelphi compiled form 'TfmDuplicateIP'0.528344671201814
                                  RT_RCDATA0xf96c940x4b2Delphi compiled form ''0.4841930116472546
                                  RT_RCDATA0xf971480x6f0Delphi compiled form '\020TfmEmailSettings\017fmEmailSettings\006Height\003\200\001\005Width\003\264\001\007Caption\006\017E-mail settings\014ClientHeight\003\200\001\013ClientWidth\003\264\001\006OnShow\007\010FormShow'0.44876126126126126
                                  RT_RCDATA0xf978380x374Delphi compiled form '\017TfmFilterEditor\016fmFilterEditor\004Left\003@\003\006Height\003h\001\003Top\003\243\001\005Width\003X\002\007Caption\006\004Edit\014ClientHeight\003h\001\013ClientWidth\003X\002\010OnCreate\007'0.5113122171945701
                                  RT_RCDATA0xf97bac0x537Delphi compiled form '\023TfmFilterManagement\022fmFilterManagement\004Left\003\331\004\006Height\003\240\001\003Top\003\300\001\005Width\003\023\002'0.4756554307116105
                                  RT_RCDATA0xf980e40x244Delphi compiled form '\020TfmFreeFormInput\017fmFreeFormInput\006Height\003\254'0.5913793103448276
                                  RT_RCDATA0xf983280x2a1Delphi compiled form '\023TfmFriendlyNameEdit\022fmFriendlyNameEdit\006Height\003\315'0.5334323922734027
                                  RT_RCDATA0xf985cc0xad4Delphi compiled form 'TfmFriendlyNameList'0.398989898989899
                                  RT_RCDATA0xf990a00x373Delphi compiled form 'TfmHostProps'0.5775764439411099
                                  RT_RCDATA0xf994140x27aDelphi compiled form '\020TfmIgnoreAddress\017fmIgnoreAddress\004Left\003I\002\006Height\003\206\001\003Top\003.\001\005Width\003\364\001\007Caption\006\024Ignored IP Addresses\014ClientHeight\003\206\001\013ClientWidth\003\364'0.5977917981072555
                                  RT_RCDATA0xf996900x5e1Delphi compiled form ''0.4850498338870432
                                  RT_RCDATA0xf99c740x588Delphi compiled form 'TfmIPInput'0.3983050847457627
                                  RT_RCDATA0xf9a1fc0x75cDelphi compiled form '\023TfmJsonQueryBuilder\022fmJsonQueryBuilder'0.4140127388535032
                                  RT_RCDATA0xf9a9580x6d3Delphi compiled form '\017TfmKeyValEditor\016fmKeyValEditor\006Height\003p\001\005Width\003\344\001'0.4585002862049227
                                  RT_RCDATA0xf9b02c0x550Delphi compiled form '\013TfmLdapEdit'0.42205882352941176
                                  RT_RCDATA0xf9b57c0x336Delphi compiled form 'TfmLegend'0.597323600973236
                                  RT_RCDATA0xf9b8b40x1dfDelphi compiled form '\017TfmLicenseInput\016fmLicenseInput\006Height\003\344'0.5845511482254697
                                  RT_RCDATA0xf9ba940x372Delphi compiled form '\030TfmLiveDisplayFileOutput\027fmLiveDisplayFileOutput\006Height\003\305'0.5521541950113379
                                  RT_RCDATA0xf9be080x8a9Delphi compiled form 'TfmLiveDisplayLog'0.43346865133062695
                                  RT_RCDATA0xf9c6b40x829Delphi compiled form '\034TfmLiveDisplayNotifySettings\033fmLiveDisplayNotifySettings\006Height\003\016\002\005Width\003\261\001\007Caption\006\030Notification Preferences\014ClientHeight\003\016\002\013'0.38678793681187174
                                  RT_RCDATA0xf9cee00x612Delphi compiled form '\016TfmLoadOptions'0.3944658944658945
                                  RT_RCDATA0xf9d4f40x7dfeDelphi compiled form 'TfmMainView'0.2432876542444348
                                  RT_RCDATA0xfa52f40x1d3Delphi compiled form '\016TfmMapShortCut'0.6338329764453962
                                  RT_RCDATA0xfa54c80x4b8Delphi compiled form ''0.4991721854304636
                                  RT_RCDATA0xfa59800x397Delphi compiled form '\014TfmNavigator\013fmNavigator\004Left\003\303\002\006Height\003\213\001\003Top\0037\001\005Width\003\322\001'0.5397170837867247
                                  RT_RCDATA0xfa5d180x558Delphi compiled form '\022TfmNmapIntegration\021fmNmapIntegration\004Left\003\026\003\003Top\003\365'0.4656432748538012
                                  RT_RCDATA0xfa62700xe23Delphi compiled form '\026TfmNmapIntegrationEdit\025fmNmapIntegrationEdit\006Height\003!\002\005Width\003\360\001\014ClientHeight\003!\002\013ClientWidth\003\360\001\010OnCreate\007'0.40563691627521414
                                  RT_RCDATA0xfa70940x335Delphi compiled form '\017TfmNmapSettings\016fmNmapSettings\004Left\003\303\002\006Height\003\363'0.4701583434835566
                                  RT_RCDATA0xfa73cc0x31eDelphi compiled form 'TfmOfflineDialog'0.5338345864661654
                                  RT_RCDATA0xfa76ec0x56edDelphi compiled form 'TfmOptions'0.2870174807891071
                                  RT_RCDATA0xfacddc0x21eDelphi compiled form 'TfmPassFrame'0.6180811808118081
                                  RT_RCDATA0xfacffc0x342Delphi compiled form 'TfmPasteIP'0.4784172661870504
                                  RT_RCDATA0xfad3400x12dDelphi compiled form '\021TfmPortListEditor\020fmPortListEditor\007Caption\006\017TCP Port Groups'0.7475083056478405
                                  RT_RCDATA0xfad4700x4d4Delphi compiled form '\021TfmPoweroffParams\020fmPoweroffParams'0.5137540453074434
                                  RT_RCDATA0xfad9440x722Delphi compiled form 'TfmPublicIP'0.3729463307776561
                                  RT_RCDATA0xfae0680x269Delphi compiled form '\014TfmRearrange\013fmRearrange\007Caption\006\017Rearrange Items'0.5850891410048622
                                  RT_RCDATA0xfae2d40xa4aDelphi compiled form 'TfmRemoteCommon'0.3800303720577069
                                  RT_RCDATA0xfaed200x1e3Delphi compiled form ''0.6231884057971014
                                  RT_RCDATA0xfaef040x40dDelphi compiled form '\021TfmRemoteFileEdit\020fmRemoteFileEdit'0.5188042430086789
                                  RT_RCDATA0xfaf3140x1d8Delphi compiled form '\017TfmRemoteGroups\016fmRemoteGroups\007Caption\006'0.6292372881355932
                                  RT_RCDATA0xfaf4ec0x5b0Delphi compiled form '\023TfmRemoteGroupsEdit\022fmRemoteGroupsEdit\006Height\003~\001\014ClientHeight\003~\001'0.48282967032967034
                                  RT_RCDATA0xfafa9c0x339Delphi compiled form ''0.5393939393939394
                                  RT_RCDATA0xfafdd80x36fDelphi compiled form '\021TfmRemoteHTTPEdit\020fmRemoteHTTPEdit\004Left\003\303\002\006Height\003i\001\003Top\0037\001\014ClientHeight\003i\001'0.48350398179749715
                                  RT_RCDATA0xfb01480x1b5Delphi compiled form ''0.6453089244851259
                                  RT_RCDATA0xfb03000x407Delphi compiled form '\021TfmRemoteJSONEdit\020fmRemoteJSONEdit\004Left\003\304\002\006Height\003\226\001\003Top\0038\001\014ClientHeight\003\226\001'0.49466537342386036
                                  RT_RCDATA0xfb07080x2c0Delphi compiled form '\021TfmRemotePerfEdit\020fmRemotePerfEdit'0.5198863636363636
                                  RT_RCDATA0xfb09c80x191Delphi compiled form '\024TfmRemotePerformance\023fmRemotePerformance\007Caption\006\022Remote Performance'0.6334164588528678
                                  RT_RCDATA0xfb0b5c0x4cbDelphi compiled form '\023TfmRemotePowerShell\022fmRemotePowerShell\004Left\003\256\001\003Top\003\322'0.5232273838630807
                                  RT_RCDATA0xfb10280x191Delphi compiled form '\027TfmRemotePowerShellEdit\026fmRemotePowerShellEdit'0.6134663341645885
                                  RT_RCDATA0xfb11bc0x1fcDelphi compiled form '\021TfmRemoteRegistry\020fmRemoteRegistry\007Caption\006\017Remote Registry\010OnCreate\007'0.5826771653543307
                                  RT_RCDATA0xfb13b80x444Delphi compiled form '\030TfmRemoteRegistryBrowser\027fmRemoteRegistryBrowser\006Height\003&\002\005Width\003 \003\007Caption\006\020Registry Browser\014ClientHeight\003&\002\013ClientWidth\003 \003\010O'0.4734432234432234
                                  RT_RCDATA0xfb17fc0x5a6Delphi compiled form '\025TfmRemoteRegistryEdit\024fmRemoteRegistryEdit\006Height\003e\001\005Width\003\255\001\014ClientHeight\003e\001\013ClientWidth\003\255\001'0.45643153526970953
                                  RT_RCDATA0xfb1da40x163Delphi compiled form '\022TfmRemoteScripting\021fmRemoteScripting\004Left\003\256\001\003Top\003\322'0.6873239436619718
                                  RT_RCDATA0xfb1f080x67fDelphi compiled form '\026TfmRemoteScriptingEdit\025fmRemoteScriptingEdit\006Height\003\201\002\005Width\003\243\002\013BorderStyle\007'0.46422128683102826
                                  RT_RCDATA0xfb25880x3abDelphi compiled form '\024TfmRemoteServiceEdit\023fmRemoteServiceEdit'0.503727369542066
                                  RT_RCDATA0xfb29340x1f7Delphi compiled form '\021TfmRemoteServices\020fmRemoteServices\004Left\003\260\001\003Top\003\355'0.6242544731610338
                                  RT_RCDATA0xfb2b2c0x1a3Delphi compiled form ''0.6897374701670644
                                  RT_RCDATA0xfb2cd00x87eDelphi compiled form '\021TfmRemoteSNMPEdit\020fmRemoteSNMPEdit\006Height\003\332\001\005Width\003\255\001\014ClientHeight\003\332\001\013ClientWidth\003\255\001\010OnCreate\007'0.43514259429622815
                                  RT_RCDATA0xfb35500x411Delphi compiled form '\014TfmRemoteSSH\013fmRemoteSSH\004Left\003\256\001\003Top\003\322'0.5504322766570605
                                  RT_RCDATA0xfb39640x19dDelphi compiled form '\020TfmRemoteSSHEdit\017fmRemoteSSHEdit'0.6174334140435835
                                  RT_RCDATA0xfb3b040x4c4Delphi compiled form '\014TfmRemoteWMI\013fmRemoteWMI\004Left\003\220\002\006Height\003\372\001\003Top\003\361'0.5377049180327869
                                  RT_RCDATA0xfb3fc80x638Delphi compiled form '\020TfmRemoteWMIEdit\017fmRemoteWMIEdit\006Height\003\371\001\005Width\003P\002\007Caption\006\021WMI Query Builder\014ClientHeight\003\371\001\013ClientWidth\003P\002\010OnCreate\007'0.47110552763819097
                                  RT_RCDATA0xfb46000x377Delphi compiled form '\014TfmRemoteXML\013fmRemoteXML\007Caption\006'0.5467869222096956
                                  RT_RCDATA0xfb49780x41bDelphi compiled form '\020TfmRemoteXMLEdit\017fmRemoteXMLEdit'0.5185537583254044
                                  RT_RCDATA0xfb4d940x32fDelphi compiled form '\016TfmScriptInput'0.5276073619631901
                                  RT_RCDATA0xfb50c40x41dDelphi compiled form '\021TfmShutdownParams\020fmShutdownParams\007Caption\006\013Shutdown %s'0.5223171889838556
                                  RT_RCDATA0xfb54e40x6d9Delphi compiled form 'TfmSNMPv3Params'0.3764974329720479
                                  RT_RCDATA0xfb5bc00x345Delphi compiled form '\017TfmSNMPv3String\016fmSNMPv3String\006Height\003\230\001\005Width\003\011\002\007Caption\006\006SNMPv3\014ClientHeight\003\230\001\013ClientWidth\003\011\002'0.43608124253285546
                                  RT_RCDATA0xfb5f080x34Delphi compiled form '\013TfmSSDPView'1.0
                                  RT_RCDATA0xfb5f3c0x292Delphi compiled form '\016TfmSSLCertInfo'0.5820668693009119
                                  RT_RCDATA0xfb61d00x278Delphi compiled form 'TfmStopScanDialog'0.625
                                  RT_RCDATA0xfb64480x2ffDelphi compiled form '\020TfmSubmitMessage\017fmSubmitMessage\006Height\003P\001\005Width\003\212\001'0.5397653194263363
                                  RT_RCDATA0xfb67480x5a2Delphi compiled form 'TfmTrialInfo'0.521497919556172
                                  RT_RCDATA0xfb6cec0x2f2Delphi compiled form ''0.5729442970822282
                                  RT_RCDATA0xfb6fe00x2c2Delphi compiled form '\017TfmUserSettings\016fmUserSettings\006Height\003\357'0.5736543909348442
                                  RT_RCDATA0xfb72a40x2e4aDelphi compiled form 'TfmVBScriptEditor'0.25468354430379747
                                  RT_RCDATA0xfba0f00x1a6Delphi compiled form '\021TfmVirtualColumns\020fmVirtualColumns\004Left\003\260\001\003Top\003\355'0.6184834123222749
                                  RT_RCDATA0xfba2980x36aDelphi compiled form '\025TfmVirtualColumnsEdit\024fmVirtualColumnsEdit\006Height\003e\001\005Width\003\256\001\014ClientHeight\003e\001\013ClientWidth\003\256\001'0.4290617848970252
                                  RT_RCDATA0xfba6040x1feDelphi compiled form '\021TfmVisibleColumns\020fmVisibleColumns\006Height\003Y\001\007Caption\006\017Visible Columns\014ClientHeight\003Y\001'0.5705882352941176
                                  RT_RCDATA0xfba8040x4ccDelphi compiled form '\023TfmVisibleColumnsEx\022fmVisibleColumnsEx\006Height\003\232\001\005Width\003X\002\007Caption\006\017Visible Columns\014ClientHeight\003\232\001\013ClientWidth\003X\002\010OnCreate\007'0.504885993485342
                                  RT_RCDATA0xfbacd00x38fDelphi compiled form '\011TfmWOLAdd\010fmWOLAdd\005Width\003D\001'0.5137211855104281
                                  RT_RCDATA0xfbb0600xb36Delphi compiled form 'TfmWOLManager'0.38571428571428573
                                  RT_RCDATA0xfbbb980x404Delphi compiled form '\016TfmWOLSettings'0.4795719844357977
                                  RT_RCDATA0xfbbf9c0x31Delphi compiled form ''0.9795918367346939
                                  RT_RCDATA0xfbbfd00x87fDelphi compiled form '\022TfmXmlQueryBuilder\021fmXmlQueryBuilder\006Height\003@\002\005Width\0035\003\007Caption\006\023XPath Query Builder\014ClientHeight\003@\002\013ClientWidth\0035\003\006OnShow\007\010Fo'0.37057471264367814
                                  RT_RCDATA0xfbc8500x164Delphi compiled form 'TModalControl'0.5926966292134831
                                  RT_RCDATA0xfbc9b40x866Delphi compiled form 'TTimePopupForm'0.4441860465116279
                                  RT_RCDATA0xfbd21c0x2a4Delphi compiled form 'TWaitForm'0.5636094674556213
                                  RT_RCDATA0xfbd4c00x72ASCII text, with CRLF line terminatorsEnglishUnited States0.9649122807017544
                                  RT_RCDATA0xfbd5340x15cASCII text, with CRLF line terminatorsEnglishUnited States0.6752873563218391
                                  RT_RCDATA0xfbd6900x4deASCII text, with CRLF line terminatorsEnglishUnited States0.5112359550561798
                                  RT_RCDATA0xfbdb700x2acASCII text, with CRLF line terminatorsEnglishUnited States0.5058479532163743
                                  RT_RCDATA0xfbde1c0x402ASCII text, with CRLF line terminatorsEnglishUnited States0.40253411306042886
                                  RT_RCDATA0xfbe2200x180ASCII text, with CRLF line terminatorsEnglishUnited States0.6875
                                  RT_RCDATA0xfbe3a00x657ASCII text, with CRLF line terminatorsEnglishUnited States0.41897720271102895
                                  RT_RCDATA0xfbe9f80x2bbASCII text, with CRLF line terminatorsEnglishUnited States0.5078683834048641
                                  RT_RCDATA0xfbecb40x33bASCII text, with CRLF line terminatorsEnglishUnited States0.5392986698911729
                                  RT_RCDATA0xfbeff00x355ASCII text, with CRLF line terminatorsEnglishUnited States0.5158264947245017
                                  RT_RCDATA0xfbf3480x344ASCII text, with CRLF line terminatorsEnglishUnited States0.4605263157894737
                                  RT_RCDATA0xfbf68c0x231ASCII text, with CRLF line terminatorsEnglishUnited States0.5846702317290553
                                  RT_GROUP_CURSOR0xfbf8c00x14Lotus unknown worksheet or configuration, revision 0x11.25
                                  RT_GROUP_CURSOR0xfbf8d40x14Lotus unknown worksheet or configuration, revision 0x11.25
                                  RT_GROUP_CURSOR0xfbf8e80x30Lotus unknown worksheet or configuration, revision 0x30.8958333333333334
                                  RT_GROUP_CURSOR0xfbf9180x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbf9480x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbf9780x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbf9a80x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbf9d80x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbfa080x30Lotus unknown worksheet or configuration, revision 0x30.9375
                                  RT_GROUP_CURSOR0xfbfa380x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfa4c0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfa600x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfa740x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfa880x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfa9c0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfab00x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfac40x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfad80x14Lotus unknown worksheet or configuration, revision 0x11.25
                                  RT_GROUP_CURSOR0xfbfaec0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb000x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb140x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb280x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb3c0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb500x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_CURSOR0xfbfb640x14Lotus unknown worksheet or configuration, revision 0x11.3
                                  RT_GROUP_ICON0xfbfb780xa0data0.65625
                                  RT_VERSION0xfbfc180x328data0.46534653465346537
                                  RT_MANIFEST0xfbff400x71bXML 1.0 document, ASCII text, with CRLF line terminators0.4167124793842771
                                  DLLImport
                                  kernel32.dllGetStdHandle, GetConsoleMode, TlsGetValue, GetLastError, SetLastError, RaiseException, GetTickCount, ExitProcess, GetStartupInfoA, GetCommandLineA, GetCurrentProcessId, GetCurrentThreadId, GetCurrentProcess, ReadProcessMemory, GetModuleFileNameA, GetModuleHandleA, WriteFile, ReadFile, CloseHandle, SetFilePointer, GetFileSize, SetEndOfFile, GetSystemInfo, LoadLibraryW, LoadLibraryA, GetProcAddress, FreeLibrary, FormatMessageW, DeleteFileW, MoveFileW, CreateFileW, GetFileAttributesW, CreateDirectoryW, RemoveDirectoryW, SetCurrentDirectoryW, GetCurrentDirectoryW, GetFullPathNameW, SetEnvironmentVariableW, GetConsoleOutputCP, GetOEMCP, GetProcessHeap, HeapAlloc, HeapFree, TlsAlloc, TlsSetValue, CreateThread, ExitThread, LocalAlloc, LocalFree, Sleep, SuspendThread, ResumeThread, TerminateThread, WaitForSingleObject, SetThreadPriority, GetThreadPriority, GetCurrentThread, OpenThread, IsDebuggerPresent, CreateEventA, ResetEvent, SetEvent, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, GetEnvironmentStringsW, FreeEnvironmentStringsW, MultiByteToWideChar, WideCharToMultiByte, GetACP, GetConsoleCP, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, RtlUnwindEx, EnumResourceTypesA, EnumResourceNamesA, EnumResourceLanguagesA, FindResourceA, FindResourceExA, LoadResource, SizeofResource, LockResource, FreeResource, AttachConsole, CancelSynchronousIo, GetEnvironmentStringsA, FreeEnvironmentStringsA, FormatMessageA, CreateFileMappingA, SetEnvironmentVariableA, GlobalAddAtomA, GetWindowsDirectoryA, CreateFileA, GetVolumeInformationA, GetVersionExA, CompareStringA, GetLocaleInfoA, GetDateFormatA, EnumCalendarInfoA, LoadLibraryExW, GetModuleFileNameW, GetCommandLineW, ExpandEnvironmentStringsW, GetSystemDirectoryW, GetFileAttributesExW, GetComputerNameW, CreateProcessW, FindFirstFileW, FindNextFileW, CompareStringW, GetLocaleInfoW, GetDateFormatW, FindFirstFileExW, GlobalAlloc, GlobalReAlloc, GlobalSize, GlobalLock, GlobalUnlock, GetProcessAffinityMask, GetExitCodeProcess, GetExitCodeThread, SetErrorMode, GlobalDeleteAtom, FlushFileBuffers, DeviceIoControl, FindClose, MulDiv, GetSystemTime, GetLocalTime, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, FileTimeToLocalFileTime, FileTimeToSystemTime, FileTimeToDosDateTime, CreatePipe, PeekNamedPipe, MapViewOfFile, UnmapViewOfFile, QueryPerformanceCounter, QueryPerformanceFrequency, GetCPInfo, GetThreadLocale, SetThreadLocale, GetSystemDefaultLCID, GetUserDefaultLCID, FreeConsole, GetDiskFreeSpaceExW, SetFileInformationByHandle, SetDllDirectoryW
                                  oleaut32.dllSysAllocStringLen, SysFreeString, SysReAllocStringLen, VariantChangeTypeEx, VariantClear, VariantCopy, VariantInit, SafeArrayAccessData, SafeArrayCreate, SafeArrayGetElement, SafeArrayGetLBound, SafeArrayGetUBound, SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayRedim, SafeArrayUnaccessData, LoadTypeLib, RegisterTypeLib, UnRegisterTypeLib
                                  user32.dllMessageBoxA, CharUpperBuffW, CharLowerBuffW, GetUserObjectInformationA, RegisterWindowMessageA, PeekMessageA, SendMessageA, PostMessageA, PostThreadMessageA, DefWindowProcA, CallWindowProcA, RegisterClassA, UnregisterClassA, GetClassInfoA, RegisterClassExA, CreateWindowExA, SendDlgItemMessageA, RegisterClipboardFormatA, GetClipboardFormatNameA, CharToOemA, CharUpperA, CharUpperBuffA, CharLowerA, CharLowerBuffA, GetMenuItemInfoA, SetPropA, GetPropA, RemovePropA, EnumPropsA, GetWindowLongA, GetClassLongA, GetWindowLongPtrA, SetWindowLongPtrA, SetClassLongPtrA, FindWindowA, GetClassNameA, LoadBitmapA, LoadCursorA, LoadIconA, LoadImageA, SystemParametersInfoA, DispatchMessageW, PeekMessageW, SendMessageW, PostMessageW, DefWindowProcW, CallWindowProcW, RegisterClassW, UnregisterClassW, GetClassInfoW, CreateWindowExW, InsertMenuItemW, GetMenuItemInfoW, SetMenuItemInfoW, DrawTextW, DrawStateW, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, MessageBoxW, GetWindowLongPtrW, SetWindowLongPtrW, LoadStringW, DefFrameProcW, DefMDIChildProcW, GetKeyboardLayout, GetProcessWindowStation, TranslateMessage, PostQuitMessage, GetDoubleClickTime, IsWindow, IsMenu, DestroyWindow, ShowWindow, ShowWindowAsync, ShowOwnedPopups, MoveWindow, SetWindowPos, GetWindowPlacement, SetWindowPlacement, BeginDeferWindowPos, DeferWindowPos, EndDeferWindowPos, IsWindowVisible, IsIconic, BringWindowToTop, IsZoomed, OpenClipboard, CloseClipboard, SetClipboardData, GetClipboardData, CountClipboardFormats, EnumClipboardFormats, EmptyClipboard, IsClipboardFormatAvailable, SetFocus, GetActiveWindow, GetFocus, GetKeyState, GetKeyboardState, ToAscii, GetCapture, SetCapture, ReleaseCapture, MsgWaitForMultipleObjects, SetTimer, KillTimer, EnableWindow, IsWindowEnabled, GetSystemMetrics, GetMenu, SetMenu, DrawMenuBar, GetSystemMenu, CreateMenu, CreatePopupMenu, DestroyMenu, EnableMenuItem, GetSubMenu, GetMenuItemCount, RemoveMenu, DeleteMenu, GetMenuItemRect, UpdateWindow, SetActiveWindow, GetForegroundWindow, SetForegroundWindow, WindowFromDC, GetDC, GetDCEx, GetWindowDC, ReleaseDC, BeginPaint, EndPaint, GetUpdateRect, SetWindowRgn, InvalidateRect, InvalidateRgn, RedrawWindow, LockWindowUpdate, ScrollWindow, ScrollDC, ScrollWindowEx, ShowScrollBar, EnableScrollBar, GetClientRect, GetWindowRect, AdjustWindowRectEx, MessageBeep, SetCursorPos, SetCursor, GetCursorPos, CreateCaret, GetCaretBlinkTime, DestroyCaret, HideCaret, ShowCaret, SetCaretPos, GetCaretPos, ClientToScreen, ScreenToClient, MapWindowPoints, WindowFromPoint, GetSysColor, GetSysColorBrush, SetSysColors, DrawFocusRect, FillRect, FrameRect, SetRect, InflateRect, IntersectRect, UnionRect, SubtractRect, OffsetRect, IsRectEmpty, PtInRect, GetDesktopWindow, GetParent, SetParent, EnumChildWindows, EnumThreadWindows, GetTopWindow, GetWindowThreadProcessId, GetLastActivePopup, GetWindow, CallNextHookEx, DestroyCursor, DestroyIcon, CopyImage, CreateIconIndirect, GetIconInfo, SetScrollInfo, GetScrollInfo, TranslateMDISysAccel, DrawEdge, DrawFrameControl, TrackPopupMenuEx, ChildWindowFromPointEx, DrawIconEx, FlashWindowEx, GetComboBoxInfo, SetMenuInfo
                                  ole32.dllCoCreateGuid, CoRegisterClassObject, CoTaskMemFree, IsEqualGUID, OleInitialize, OleUninitialize, RegisterDragDrop, RevokeDragDrop, DoDragDrop, OleSetClipboard, OleGetClipboard, ReleaseStgMedium, CreateStreamOnHGlobal, CoInitializeEx, CoUninitialize, CoCreateInstance, CLSIDFromProgID, CoInitialize, CoRevokeClassObject, CoDisconnectObject, CoLockObjectExternal, CoTaskMemAlloc, CreateDataAdviseHolder, MkParseDisplayName, CreateBindCtx, SetErrorInfo, GetErrorInfo, CreateErrorInfo
                                  dnsapi.dllDnsQuery_W, DnsRecordListFree
                                  iphlpapi.dllGetIpNetTable2, FreeMibTable, GetAdaptersAddresses, IcmpCreateFile, Icmp6CreateFile, IcmpCloseHandle, IcmpSendEcho, Icmp6SendEcho2, Icmp6ParseReplies, GetIfEntry, GetAdaptersInfo, SendARP
                                  netapi32.dllNetShareEnum, NetServerGetInfo, NetWkstaUserEnum, NetWkstaGetInfo, NetRemoteTOD, NetServerDiskEnum, NetStatisticsGet, NetUserEnum, NetApiBufferFree, NetLocalGroupEnum, NetGroupEnum, NetLocalGroupGetMembers, NetGroupGetUsers, NetUserGetLocalGroups, NetUserGetGroups, NetGetDCName
                                  wtsapi32.dllWTSOpenServerW, WTSEnumerateSessionsW, WTSEnumerateSessionsExW, WTSSendMessageW, WTSFreeMemoryExW, WTSFreeMemory, WTSCloseServer
                                  advapi32.dllConvertSidToStringSidW, RegCreateKeyExA, RegOpenKeyExA, RegQueryInfoKeyA, RegQueryValueExA, EnumServicesStatusA, OpenSCManagerA, OpenServiceA, QueryServiceConfigA, LookupAccountSidW, LookupAccountNameW, LookupPrivilegeValueW, GetUserNameW, RegSetValueExW, InitiateSystemShutdownW, RegQueryValueExW, RegConnectRegistryW, RegCreateKeyExW, RegDeleteKeyW, RegEnumKeyExW, RegEnumValueW, RegOpenKeyExW, CreateServiceW, OpenSCManagerW, StartServiceW, OpenProcessToken, AdjustTokenPrivileges, IsValidSid, EqualSid, AllocateAndInitializeSid, FreeSid, MapGenericMask, GetAclInformation, GetAce, IsValidSecurityDescriptor, RegCloseKey, RegFlushKey, CloseServiceHandle, QueryServiceStatus, GetNamedSecurityInfoW
                                  Ws2_32.dllGetNameInfoW
                                  pdh.dllPdhOpenQueryW, PdhAddCounterW, PdhCollectQueryData, PdhCloseQuery, PdhGetFormattedCounterValue, PdhBrowseCountersW, PdhExpandCounterPathW, PdhCloseLog, PdhBindInputDataSourceW
                                  version.dllGetFileVersionInfoSizeExW, GetFileVersionInfoExW, GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA, VerQueryValueW
                                  shell32.dllSHGetFolderLocation, DragQueryFileA, Shell_NotifyIconA, DragQueryFileW, ShellExecuteW, Shell_NotifyIconW, DragFinish, DragAcceptFiles, SHGetMalloc, SHGetDesktopFolder, SHGetPathFromIDListW, SHBrowseForFolderW, ILFree, ShellExecuteExW
                                  gdi32.dllCreateFontIndirectA, EnumFontFamiliesA, GetCharABCWidthsA, GetTextExtentPointA, GetTextMetricsA, GetObjectA, ExtTextOutA, CreateFontIndirectW, EnumFontFamiliesExW, GetCharABCWidthsW, GetTextExtentPointW, GetTextExtentPoint32W, GetTextExtentExPointW, GetObjectW, TextOutW, ExtTextOutW, GetRandomRgn, Arc, BitBlt, Chord, CombineRgn, CreateBitmap, CreateBrushIndirect, CreateCompatibleBitmap, CreateCompatibleDC, CreateDIBitmap, CreateEllipticRgn, CreatePen, CreatePenIndirect, CreatePatternBrush, CreateRectRgn, CreateRoundRectRgn, CreateSolidBrush, DeleteDC, DeleteObject, Ellipse, EqualRgn, ExcludeClipRect, ExtCreateRegion, ExtFloodFill, FillRgn, GetROP2, GetBkColor, GetBitmapBits, GetClipBox, GetClipRgn, GetCurrentObject, GetDeviceCaps, GetDIBits, GetMapMode, GetObjectType, GetPixel, GetRegionData, GetRgnBox, GetStockObject, GetTextAlign, GetTextColor, GetViewportExtEx, GetViewportOrgEx, GetWindowExtEx, GetWindowOrgEx, IntersectClipRect, LineTo, MaskBlt, OffsetRgn, PatBlt, Pie, PaintRgn, PtInRegion, RectInRegion, RectVisible, Rectangle, RestoreDC, RealizePalette, RoundRect, SaveDC, SelectClipRgn, ExtSelectClipRgn, SelectObject, SelectPalette, SetBkColor, SetBkMode, SetMapMode, SetPixel, SetPolyFillMode, StretchBlt, SetRectRgn, StretchDIBits, SetROP2, SetStretchBltMode, SetTextCharacterExtra, SetTextColor, SetTextAlign, CreateDIBSection, SetArcDirection, ExtCreatePen, MoveToEx, CreatePolygonRgn, DPtoLP, LPtoDP, Polygon, Polyline, PolyBezier, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, SetBrushOrgEx, GetDCOrgEx, GdiFlush
                                  mpr.dllWNetCancelConnection2A, WNetAddConnection2W, WNetCancelConnection2W, WNetConnectionDialog1W, WNetDisconnectDialog
                                  shlwapi.dllAssocQueryStringW, StrCmpLogicalW, PathIsNetworkPathW, PathMatchSpecW
                                  comctl32.dllInitCommonControls, ImageList_Create, ImageList_Destroy, ImageList_GetImageCount, ImageList_SetImageCount, ImageList_Add, ImageList_Replace, ImageList_AddMasked, ImageList_DrawEx, ImageList_DrawIndirect, ImageList_Remove, ImageList_Copy, ImageList_BeginDrag, ImageList_EndDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_DragMove, ImageList_DragShowNolock, _TrackMouseEvent, SetWindowSubclass, RemoveWindowSubclass, DefSubclassProc
                                  imm32.dllImmGetContext, ImmReleaseContext, ImmGetCompositionStringW, ImmNotifyIME
                                  comdlg32.dllChooseColorA, CommDlgExtendedError, GetOpenFileNameW, GetSaveFileNameW, ChooseFontW
                                  ws2_32.dllaccept, bind, closesocket, connect, ioctlsocket, getpeername, getsockopt, listen, recv, recvfrom, select, send, sendto, setsockopt, shutdown, socket, gethostbyaddr, gethostbyname, WSAStartup, WSACleanup, WSAGetLastError, __WSAFDIsSet, WSAIoctl, getaddrinfo, freeaddrinfo, getnameinfo, WSAPoll
                                  wsock32.dll__WSAFDIsSet, accept, bind, closesocket, connect, ioctlsocket, getsockopt, htons, inet_addr, listen, recv, select, send, setsockopt, shutdown, socket, gethostbyaddr, gethostbyname, gethostname, WSAStartup, WSACleanup, WSAGetLastError
                                  winmm.dllsndPlaySoundW, timeGetTime
                                  aclui.dllEditSecurity
                                  urlmon.dllURLOpenBlockingStreamA
                                  KERNEL32.dllAreFileApisANSI, CloseHandle, CreateFileA, CreateFileMappingA, CreateFileMappingW, CreateFileW, CreateMutexW, DeleteCriticalSection, DeleteFileA, DeleteFileW, EnterCriticalSection, FlushFileBuffers, FlushViewOfFile, FormatMessageA, FormatMessageW, FreeLibrary, GetCurrentProcessId, GetCurrentThreadId, GetDiskFreeSpaceA, GetDiskFreeSpaceW, GetFileAttributesA, GetFileAttributesExW, GetFileAttributesW, GetFileSize, GetFullPathNameA, GetFullPathNameW, GetLastError, GetProcAddress, GetProcessHeap, GetSystemInfo, GetSystemTime, GetSystemTimeAsFileTime, GetTempPathA, GetTempPathW, GetTickCount, GetVersionExA, GetVersionExW, HeapAlloc, HeapCompact, HeapCreate, HeapDestroy, HeapFree, HeapReAlloc, HeapSize, HeapValidate, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, LoadLibraryW, LocalFree, LockFile, LockFileEx, MapViewOfFile, MultiByteToWideChar, OutputDebugStringA, OutputDebugStringW, QueryPerformanceCounter, ReadFile, SetEndOfFile, SetFilePointer, Sleep, SystemTimeToFileTime, TryEnterCriticalSection, UnlockFile, UnlockFileEx, UnmapViewOfFile, WaitForSingleObject, WaitForSingleObjectEx, WideCharToMultiByte, WriteFile
                                  msvcrt.dll_beginthreadex, _endthreadex, _localtime64, free, malloc, memcmp, memcpy, memmove, memset, realloc, strcmp, strcspn, strncmp, strrchr
                                  Language of compilation systemCountry where language is spokenMap
                                  EnglishAustralia
                                  EnglishUnited States
                                  No network behavior found
                                  050100s020406080100

                                  Click to jump to process

                                  050100s0.0020406080MB

                                  Click to jump to process

                                  • File
                                  • Registry

                                  Click to dive into process behavior distribution

                                  Target ID:0
                                  Start time:13:23:11
                                  Start date:28/07/2023
                                  Path:C:\Users\user\Desktop\netscan.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Users\user\Desktop\netscan.exe
                                  Imagebase:0x100000000
                                  File size:16'358'912 bytes
                                  MD5 hash:5DB121B74AEDE2736366690C74B4A197
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:low

                                  No disassembly