0a18261b8895811c731cfa42437ef965ff9ae0490723634d77e6173a48c120f1

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-24 20:55:12
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • adobe.com
  • http://ns.adobe.com
  • http://ns.adobe.com/tiff/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://purl.org
  • http://www.gimp.org
  • http://www.gimp.org/xmp/
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • ns.adobe.com
  • www.gimp.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Possibly launches other programs:
  • ShellExecuteW
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • MapVirtualKeyA
  • GetAsyncKeyState
Manipulates other processes:
  • Process32First
  • OpenProcess
  • Process32Next
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 38/71 (Scanned on 2026-10-05 05:55:18) ALYac: Application.Generic.37088007
APEX: Malicious
AVG: FileRepMalware [Misc]
Alibaba: RiskWare:Win64/Krypt.0dcccd42
Antiy-AVL: GrayWare/Win32.Wacapew
Arcabit: Application.Generic.D235EB07
Avast: FileRepMalware [Misc]
BitDefender: Application.Generic.37088007
Bkav: W32.Malware.2291DE08
CTX: exe.trojan.generic
CrowdStrike: win/malicious_confidence_60% (D)
Cylance: Unsafe
ESET-NOD32: Win64/Riskware.GameHack.BO application
Elastic: malicious (high confidence)
Emsisoft: Application.Generic.37088007 (B)
Fortinet: Riskware/GameHack
GData: Application.Generic.37088007
Google: Detected
Ikarus: Trojan.Win64.Krypt
K7AntiVirus: Riskware ( 006dcf651 )
K7GW: Riskware ( 006dcf651 )
Lionic: Trojan.Win32.Generic.4!c
Malwarebytes: Malware.AI.4019116178
MaxSecure: Trojan.Malware.345033516.susgen
McAfeeD: ti!0A18261B8895
MicroWorld-eScan: Application.Generic.37088007
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Panda: Trj/CI.A
Rising: Trojan.Kryptik@AI.96 (RDML:hVj5STtsnbNAhyqizhnsfQ)
SentinelOne: Static AI - Suspicious PE
Sophos: Generic Reputation PUA (PUA)
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!D7C8ADE7A209
TrendMicro: Trojan.Win64.KEPAVLL.USBLIR26
TrendMicro-HouseCall: Trojan.Win64.KEPAVLL.USBLIR26
VIPRE: Application.Generic.37088007
Varist: W64/ABTrojan.EIEI-0967

Hashes

MD5 d7c8ade7a209fbbddf4c8d82e298de74 🔍
SHA1 248d816c8f61a691156f12fa91004a1f306989de 🔍
SHA256 0a18261b8895811c731cfa42437ef965ff9ae0490723634d77e6173a48c120f1 🔍
SHA3 ae623ae92be7b223d16b5eb706d9c7ac1f3ceee0d03e44a690f59815b76eedea 🔍
SSDeep 49152:J4G0HVKSbVpWT+iLr2vUwjZoALnUWhsIX4J:WGgnjdXA 🔍
Imports Hash 3dc186e26a0416613974cb5499a20496 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-24 20:55:12
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x10b000
SizeOfInitializedData 0xdca00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000102130 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1eb000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9a32dd4cf92c3fcac02347dc7910b4fe 🔍
SHA1 9827299b886ace939f1d94d582e779613b2809b1 🔍
SHA256 71f8566c040c30088b56eb4c08df7f44d37b3eb225d45501433c620bfbeae1f3 🔍
SHA3 d9cdad3d8920caa7f092f07016ea3ff945a60925b5db840f1e01e32c6255f5dd 🔍
VirtualSize 0x10aec1
VirtualAddress 0x1000
SizeOfRawData 0x10b000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49854

.rdata

MD5 f6a6b8fdee7fb9823e54e45a2ad891c3 🔍
SHA1 7de1621644988d2b6af0b04ba5e76a5edf8f1c08 🔍
SHA256 6131fafcdbb109a1167f47fda33fa57b945971eccdbf0f2cdcb0b1e7c5e47833 🔍
SHA3 aaef1c8328d05191c12b1309d275a8484b3b924d483e99f71357317628cd410d 🔍
VirtualSize 0x65de2
VirtualAddress 0x10c000
SizeOfRawData 0x65e00
PointerToRawData 0x10b400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.65008

.data

MD5 7b16e3f1e0ead27013bca54db2531d52 🔍
SHA1 94e5d5780e995f1bb4ddb12feecb1a69aa777515 🔍
SHA256 58d0f5fc92173b7162811894ec36e65f6bf51d2cc4c6cdcab9e86a80a18415b7 🔍
SHA3 45a3a2b08064221a84082b88fe1be838afd0c2ab92017b2c70f31aed042e8837 🔍
VirtualSize 0x69dd8
VirtualAddress 0x172000
SizeOfRawData 0x66800
PointerToRawData 0x171200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.61909

.pdata

MD5 1b0aae1e7d34ab2af4c84245b71840eb 🔍
SHA1 35ea4157620abaf9de596c3813fb1a7d3231771d 🔍
SHA256 5d7259c77e98f12c82881264ee869eca51a8a0e521407b2c734ac88cbeb86c14 🔍
SHA3 037393ac651b2f00c4a56cfa1e33782c10729f27f7ce51aa4f04dcf176514247 🔍
VirtualSize 0x990c
VirtualAddress 0x1dc000
SizeOfRawData 0x9a00
PointerToRawData 0x1d7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.09781

_RDATA

MD5 a40195987236fe85a29643934a2b6e66 🔍
SHA1 21443eb394dce4347bf75252569d548f83580a73 🔍
SHA256 01684f5e191844c307a49bdba7555f08f9862c9085f8d7d090b96e19542df3b1 🔍
SHA3 e0b0042020a0cbf47f16c42cd00f2b1641a42057d69ebf3e5e74a959aad3152e 🔍
VirtualSize 0x2208
VirtualAddress 0x1e6000
SizeOfRawData 0x2400
PointerToRawData 0x1e1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.04224

.rsrc

MD5 408fba0c66994d4728fb15e6620d6e89 🔍
SHA1 3a1be62eadcbb090cb8102f6e3344a89112def7e 🔍
SHA256 f72726e9eb044dcf4099ad2aa654b837bb75eb704a3940a0c2a47715af6fdb90 🔍
SHA3 859baa33bc5061b9114dcc88a4349e132215f23facf7f55e193bba7db16f5969 🔍
VirtualSize 0x1e8
VirtualAddress 0x1e9000
SizeOfRawData 0x200
PointerToRawData 0x1e3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 7bd6ddf99f7818f38536f8346a985479 🔍
SHA1 f566a75a59b6881adf2d59751304f18b6b7ca54e 🔍
SHA256 ead5d235fd7078037db7fb6e383acf88b536bf96c65e53a1e7189b7100df9d80 🔍
SHA3 59fa4734bc074012601ec16a7cc60f8875bd1f9a998e8fdd392ec77921b67823 🔍
VirtualSize 0xd04
VirtualAddress 0x1ea000
SizeOfRawData 0xe00
PointerToRawData 0x1e3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.32439

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
MFPlat.DLL MFCreateMediaType
MFCreateFile
MFShutdown
MFStartup
MFReadWrite.dll MFCreateSourceReaderFromByteStream
KERNEL32.dll GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
GetModuleHandleA
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
QueryPerformanceCounter
GetStdHandle
SetConsoleMode
GetConsoleMode
GlobalAlloc
FindNextFileW
LoadLibraryExA
FindClose
GetLastError
CreateDirectoryA
Sleep
SetConsoleTitleA
GetConsoleWindow
AllocConsole
Process32First
Module32Next
GetProcessId
Module32First
OpenProcess
CreateToolhelp32Snapshot
Process32Next
CloseHandle
GetExitCodeProcess
MultiByteToWideChar
FindFirstFileW
GetSystemTimeAsFileTime
GetCurrentProcessId
SetUnhandledExceptionFilter
WakeAllConditionVariable
GetLocaleInfoEx
FormatMessageA
LocalFree
GetCurrentThreadId
SleepConditionVariableSRW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetFileInformationByHandleEx
GetModuleHandleW
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFileAttributesExW
FindFirstFileExW
CreateDirectoryW
InitializeSListHead
GetModuleFileNameA
USER32.dll PostQuitMessage
PeekMessageA
TranslateMessage
DispatchMessageA
GetWindowRect
DestroyWindow
GetSystemMetrics
SetWindowDisplayAffinity
MessageBoxA
DefWindowProcA
CreateWindowExA
SetLayeredWindowAttributes
RegisterClassExA
UpdateWindow
ShowWindow
SetWindowLongA
SendInput
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetMessageExtraInfo
GetKeyState
GetForegroundWindow
MapVirtualKeyA
SetCapture
GetAsyncKeyState
SetCursor
GetClientRect
IsWindowUnicode
LoadCursorA
ReleaseCapture
GetKeyNameTextA
SetCursorPos
GetWindowThreadProcessId
IsWindow
EnumWindows
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
FindWindowA
GetCursorPos
SHELL32.dll ShellExecuteW
SHGetFolderPathA
SHGetKnownFolderPath
ShellExecuteA
ole32.dll CoUninitialize
CoTaskMemFree
CoInitializeEx
MSVCP140.dll ?_Random_device@std@@YAIXZ
??7ios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?always_noconv@codecvt_base@std@@QEBA_NXZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
_Cnd_wait
?_Xinvalid_argument@std@@YAXPEBD@Z
_Cnd_signal
_Thrd_detach
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ
?_Xbad_function_call@std@@YAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
_Query_perf_frequency
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Id_cnt@id@locale@std@@0HA
?id@?$numpunct@D@std@@2V0locale@2@A
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_lock
_Query_perf_counter
_Xtime_get_ticks
_Mtx_unlock
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??Bios_base@std@@QEBA_NXZ
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Gettrue@_Locinfo@std@@QEBAPEBDXZ
?_Getfalse@_Locinfo@std@@QEBAPEBDXZ
?_Getlconv@_Locinfo@std@@QEBAPEBUlconv@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
?uncaught_exceptions@std@@YAHXZ
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
?good@ios_base@std@@QEBA_NXZ
_Cnd_do_broadcast_at_thread_exit
IMM32.dll ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
ImmSetCompositionWindow
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcpy
__C_specific_handler
__std_exception_destroy
__std_exception_copy
__current_exception_context
__current_exception
__std_terminate
memset
memmove
strstr
strchr
_CxxThrowException
memcmp
memchr
api-ms-win-crt-heap-l1-1-0.dll realloc
free
_set_new_mode
calloc
_callnewh
malloc
api-ms-win-crt-math-l1-1-0.dll lroundf
nearbyint
log
logf
powf
acosf
roundf
_dsign
sin
sinf
round
fmodf
asinf
cos
__setusermatherr
_fdsign
pow
_ldsign
api-ms-win-crt-stdio-l1-1-0.dll fflush
fclose
freopen_s
ftell
fseek
fwrite
__acrt_iob_func
_set_fmode
_get_stream_buffer_pointers
_fseeki64
fsetpos
ungetc
setvbuf
fgetpos
fgetc
fputc
__p__commode
_fwrite_nolock
_wfopen
__stdio_common_vsprintf_s
__stdio_common_vsprintf
__stdio_common_vsscanf
fread
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-string-l1-1-0.dll towlower
tolower
_stricmp
isalpha
isalnum
strcpy_s
strncpy
strncmp
strlen
strcmp
wcslen
api-ms-win-crt-convert-l1-1-0.dll strtoll
atoi
strtoull
strtod
atof
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
strftime
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
api-ms-win-crt-runtime-l1-1-0.dll _beginthreadex
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_initterm_e
_initterm
terminate
_get_initial_narrow_environment
_exit
exit
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
abort
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_errno
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
___lc_codepage_func

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-24 20:55:12
Version 0.0
SizeofData 1008
AddressOfRawData 0x15b33c
PointerToRawData 0x15a73c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Sep-24 20:55:12
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14015b750
EndAddressOfRawData 0x14015b8c4
AddressOfIndex 0x1401d8800
AddressOfCallbacks 0x14010cbe0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x0000000140101D20
0x0000000140101D90

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140172040

RICH Header

XOR Key 0x1d01b668
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
ASM objects (35721) 9
C objects (35721) 10
C++ objects (35721) 45
Imports (35721) 6
C objects (CVTCIL) (33145) 1
C++ objects (33145) 1
Imports (33145) 23
Total imports 385
C++ objects (LTCG) (36257) 38
ASM objects (36257) 1
Resource objects (36257) 1
Linker (36257) 1

Errors

Leave a comment

No comments yet.