1093aa76adc012d3d491668a635cbf6ad6198d88779b92693a4576ccca20350b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-30 17:45:49
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • dpaste.com
  • github.com
  • http://127.0.0.1
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://curl.se
  • https://dpaste.com
  • https://github.com
  • https://imtheo.lol
  • https://indiantypefoundry.comNinad
  • https://lrclib.net
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • lrclib.net
  • rbxcdn.com
  • roblox.com
  • scripts.sil.org
  • thumbnails.roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegQueryValueExA
  • RegCloseKey
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryW
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptAcquireContextW
  • CryptDestroyHash
  • CryptHashData
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Has Internet access capabilities:
  • WinHttpQueryHeaders
  • WinHttpOpen
  • WinHttpSendRequest
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpOpenRequest
  • InternetReadFile
  • InternetCloseHandle
  • InternetOpenA
  • InternetOpenUrlA
  • InternetConnectA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • WriteProcessMemory
  • ReadProcessMemory
  • Process32Next
  • Process32First
  • Process32NextW
  • Process32FirstW
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 10/44 (Scanned on 2026-08-30 23:49:30) APEX: Malicious
ClamAV: Win.Malware.Lazy-10033364-0
CrowdStrike: win/malicious_confidence_70% (D)
Elastic: malicious (high confidence)
Google: Detected
McAfeeD: ti!1093AA76ADC0
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
huorong: Trojan/Agent.cfs

Hashes

MD5 f159df8125675a316c43fef7e483976c 🔍
SHA1 860d572b6ab041eb667f9dbfe67cd1bcdec229dd 🔍
SHA256 1093aa76adc012d3d491668a635cbf6ad6198d88779b92693a4576ccca20350b 🔍
SHA3 b17469c70f59058377433045a54d79982f526f1d77ea25c3fa59566a821548c3 🔍
SSDeep 98304:VFLKRODIEOBxX2b7wMWB4Sqi1DYE6607SlE:vUEA3MWB4Sqi1DYfAlE 🔍
Imports Hash be21c44f126e33d4cbaa100f038af5d4 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-30 17:45:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x264800
SizeOfInitializedData 0x236400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000244E20 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x49f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 013b41b1c21899194d82bd068733eb89 🔍
SHA1 4bb65fdb320d2eb51f57773a26a93f8dbb0d2a7c 🔍
SHA256 38a5616ac80904fe01e26c7f77e20d16fda836843cf6ba289c41398901b61d62 🔍
SHA3 49570e7c36992ed9423e81cccea2c056d2b183665375159eb449efce9eb10196 🔍
VirtualSize 0x264718
VirtualAddress 0x1000
SizeOfRawData 0x264800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49971

.rdata

MD5 f37835c986f84fdb439caf7d674aec75 🔍
SHA1 76e3bc86913fd33bee866561731d00ec6b5244bb 🔍
SHA256 a10c8a9a085eda58d07ae6e759b794a26b6cc8fe612bd1d38b20de915b87c635 🔍
SHA3 f49faa0d4c078711681ffd0ee007e0868844b908608a3cb09b5d65cb464debb3 🔍
VirtualSize 0x139aec
VirtualAddress 0x266000
SizeOfRawData 0x139c00
PointerToRawData 0x264c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.87631

.data

MD5 64bc048a084f470aa49fa8c1f4ca048e 🔍
SHA1 aaa9aa672a60106b4304ec8100dc36b8a1ca3272 🔍
SHA256 3da831796b5d02221771d11fc473e7b660b4d17e15523ea56f34abda7971da7a 🔍
SHA3 a8ba62b13f1a55c94e8cca239d36278a69f482f81e9031777e8c1b651140bd19 🔍
VirtualSize 0xe3190
VirtualAddress 0x3a0000
SizeOfRawData 0xa1a00
PointerToRawData 0x39e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.73609

.pdata

MD5 0c5b228e43c63aa053213d095f67636b 🔍
SHA1 54d344d54585626fec017b76f377cc759297ce02 🔍
SHA256 c2944bde79a6184517c50ec380e0ace904b874808930ce97e8383f7b2e9c073a 🔍
SHA3 32584b6fa5d9ccd18c5a5dbb5e5abe7a3dcb5a4f5ae384d89d953f03cdb3e6cd 🔍
VirtualSize 0x16ea8
VirtualAddress 0x484000
SizeOfRawData 0x17000
PointerToRawData 0x440200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.31398

.rsrc

MD5 3045cdfc08ac3854f02a11b921ea9bf1 🔍
SHA1 098df2f5b6ff6e28a0f111c0454de0d2ab75a903 🔍
SHA256 3e28048a687a821dbf82280c44547eb22f3308e515af849dc8de5af1241e7ae6 🔍
SHA3 ba3c41f91dc73d30795631d371d21a8872cc0cfd88b626350cff5caa1ef24dfc 🔍
VirtualSize 0x1e0
VirtualAddress 0x49b000
SizeOfRawData 0x200
PointerToRawData 0x457200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71134

.reloc

MD5 f1c20f5a06172ed1dc26df371398db3b 🔍
SHA1 412472b03357d3d361c7f1740cc797340956dd8d 🔍
SHA256 8d818eaac551fd77f9af534c45d749a0ddea24637a84ba48c46a992822d33f42 🔍
SHA3 7f97f9e957f694be1fc4f99ea05b5cb45d2e142d072ee4680a4473b2056bc933 🔍
VirtualSize 0x22d4
VirtualAddress 0x49c000
SizeOfRawData 0x2400
PointerToRawData 0x457400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40222

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
WINHTTP.dll WinHttpQueryHeaders
WinHttpOpen
WinHttpSendRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpCloseHandle
WinHttpConnect
WinHttpSetTimeouts
WinHttpOpenRequest
WININET.dll HttpOpenRequestA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetOpenUrlA
HttpSendRequestA
InternetConnectA
D3DCOMPILER_47.dll D3DCompile
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleW
GetModuleFileNameA
FreeLibrary
GetModuleHandleA
LoadLibraryExW
GetProcAddress
api-ms-win-core-localization-l1-2-0.dll GetLocaleInfoA
FormatMessageA
GetLocaleInfoEx
FormatMessageW
api-ms-win-core-string-l1-1-0.dll MultiByteToWideChar
WideCharToMultiByte
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
LoadLibraryA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-sysinfo-l1-2-0.dll VerSetConditionMask
GetSystemTimePreciseAsFileTime
api-ms-win-core-heap-l2-1-0.dll GlobalAlloc
LocalFree
GlobalFree
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalUnlock
GlobalLock
api-ms-win-core-sysinfo-l1-1-0.dll GetTickCount64
GetSystemTimeAsFileTime
GetSystemInfo
GetSystemDirectoryW
GetTickCount
api-ms-win-mm-time-l1-1-0.dll timeGetTime
timeEndPeriod
timeBeginPeriod
api-ms-win-core-processthreads-l1-1-1.dll FlushInstructionCache
IsProcessorFeaturePresent
OpenProcess
api-ms-win-core-synch-l1-2-0.dll InitOnceBeginInitialize
InitOnceComplete
SleepConditionVariableSRW
WakeAllConditionVariable
Sleep
api-ms-win-core-psapi-ansi-l1-1-0.dll K32GetModuleFileNameExA
QueryFullProcessImageNameA
api-ms-win-core-handle-l1-1-0.dll CloseHandle
DuplicateHandle
api-ms-win-ntuser-sysparams-l1-1-0.dll GetSystemMetrics
api-ms-win-core-console-l3-2-0.dll GetConsoleWindow
api-ms-win-core-memory-l1-1-0.dll VirtualAllocEx
VirtualQuery
VirtualProtect
WriteProcessMemory
VirtualProtectEx
VirtualQueryEx
VirtualFreeEx
ReadProcessMemory
api-ms-win-core-kernel32-legacy-l1-1-2.dll Process32Next
Process32First
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
GetProcessId
OpenProcessToken
GetExitCodeProcess
GetCurrentThreadId
SetThreadPriority
GetCurrentProcessId
GetCurrentThread
TerminateProcess
ExitProcess
api-ms-win-core-processenvironment-l1-1-0.dll GetEnvironmentVariableA
GetStdHandle
GetCommandLineA
api-ms-win-core-console-l1-1-0.dll SetConsoleMode
GetConsoleMode
api-ms-win-core-file-l1-2-2.dll AreFileApisANSI
GetVolumeInformationA
api-ms-win-core-toolhelp-l1-1-0.dll Process32NextW
CreateToolhelp32Snapshot
Process32FirstW
api-ms-win-core-debug-l1-1-0.dll OutputDebugStringW
IsDebuggerPresent
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
api-ms-win-core-registry-l1-1-0.dll RegQueryValueExA
RegCloseKey
RegOpenKeyExA
api-ms-win-core-processtopology-obsolete-l1-1-0.dll SetThreadAffinityMask
api-ms-win-core-errorhandling-l1-1-0.dll UnhandledExceptionFilter
SetLastError
GetLastError
SetUnhandledExceptionFilter
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
api-ms-win-core-com-l1-1-0.dll CoCreateInstance
CoInitializeEx
CoUninitialize
CoCreateFreeThreadedMarshaler
api-ms-win-security-lsalookup-ansi-l2-1-0.dll LookupPrivilegeValueA
api-ms-win-security-base-l1-1-0.dll AdjustTokenPrivileges
KERNEL32.dll CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
GetProcessHeap
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
Module32First
Module32Next
K32EnumProcessModulesEx
USER32.dll keybd_event
MapVirtualKeyA
SendInput
SetWindowTextA
GetWindowThreadProcessId
GetWindowTextLengthW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
CreateWindowExW
UnregisterClassW
GetClassNameA
RegisterClassExW
ShowWindow
IsWindow
SetWindowLongA
SetWindowDisplayAffinity
MoveWindow
EnumWindows
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
PostQuitMessage
FindWindowA
ShowCursor
IsIconic
GetWindowTextW
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
UpdateWindow
GetDesktopWindow
GDI32.dll GetDeviceCaps
CreateSolidBrush
SHELL32.dll ShellExecuteA
SHGetFolderPathA
MSVCP140.dll ?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
_Cnd_register_at_thread_exit
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Cnd_broadcast
_Thrd_join
_Thrd_id
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
_Cnd_wait
_Cnd_signal
_Thrd_hardware_concurrency
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Random_device@std@@YAIXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_function_call@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
_Mtx_unlock
_Query_perf_counter
_Mtx_lock
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
??1_Facet_base@std@@UEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
??0facet@locale@std@@IEAA@_K@Z
??1facet@locale@std@@MEAA@XZ
?tolower@?$ctype@D@std@@QEBADD@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
_Xtime_get_ticks
_Strcoll
??_7facet@locale@std@@6B@
?id@?$collate@D@std@@2V0locale@2@A
?id@?$ctype@D@std@@2V0locale@2@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Strxfrm
??_7_Facet_base@std@@6B@
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exceptions@std@@YAHXZ
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
CRYPT32.dll CertFreeCertificateChain
CryptStringToBinaryW
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertGetNameStringW
CertFreeCertificateContext
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
WS2_32.dll getpeername
connect
bind
inet_ntop
htonl
ntohs
inet_pton
WSAGetLastError
closesocket
getsockname
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
listen
getaddrinfo
htons
recv
setsockopt
freeaddrinfo
recvfrom
socket
WSAIoctl
__WSAFDIsSet
select
accept
sendto
ioctlsocket
gethostname
WSASetLastError
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcmp
memchr
memset
memmove
memcpy
longjmp
wcschr
__C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
__current_exception_context
strrchr
_CxxThrowException
_purecall
__current_exception
__intrinsic_setjmp
api-ms-win-crt-runtime-l1-1-0.dll __sys_nerr
_beginthreadex
_invalid_parameter_noinfo_noreturn
_invalid_parameter_noinfo
system
_errno
abort
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_get_initial_narrow_environment
exit
_initterm
terminate
_initterm_e
_invoke_watson
_register_thread_local_exe_atexit_callback
_c_exit
__p___argv
__p___argc
_exit
__sys_errlist
api-ms-win-crt-math-l1-1-0.dll sqrt
sinf
powf
__setusermatherr
pow
logf
_fdclass
_fdopen
log
fmodf
roundf
_dclass
acosf
asinf
ldexp
lroundf
atan2f
ceilf
cosf
floorf
tanf
sqrtf
expf
_dsign
api-ms-win-crt-string-l1-1-0.dll strcmp
wcspbrk
strspn
wcsncmp
strpbrk
iswspace
wcsncpy
strcspn
strcpy_s
_wcsicmp
tolower
_strdup
isalnum
_stricmp
toupper
strncmp
strncpy
api-ms-win-crt-convert-l1-1-0.dll strtoll
strtol
strtoull
strtoul
strtod
atoi
strtof
atof
wcstombs
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
fflush
_set_fmode
fputc
__stdio_common_vsprintf_s
_get_stream_buffer_pointers
__p__commode
_fseeki64
_read
_write
_fileno
feof
_close
fseek
fsetpos
ungetc
setvbuf
fgetpos
_lseeki64
__stdio_common_vsscanf
__stdio_common_vfprintf
_wopen
fgetc
fputs
fread
__stdio_common_vsprintf
_wfopen
fgets
fwrite
ftell
fclose
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
realloc
malloc
calloc
_callnewh
api-ms-win-crt-time-l1-1-0.dll _gmtime64
_time64
strftime
_localtime64
api-ms-win-crt-filesystem-l1-1-0.dll _wstat64
_fstat64
remove
_unlink
_lock_file
_unlock_file
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
localeconv
_configthreadlocale
api-ms-win-core-file-l1-1-0.dll CreateDirectoryW
CreateFileW
FindClose
FindFirstFileW
SetFileInformationByHandle
FindFirstFileExW
FindNextFileW
GetFileType
GetFileAttributesExW
api-ms-win-core-synch-l1-1-0.dll WaitForSingleObjectEx
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
AcquireSRWLockExclusive
SleepEx
DeleteCriticalSection
ReleaseSRWLockExclusive
CreateEventW
WaitForSingleObject
SetEvent
ReleaseSRWLockShared
InitializeCriticalSectionEx
AcquireSRWLockShared
api-ms-win-core-file-l2-1-0.dll MoveFileExW
GetFileInformationByHandleEx
api-ms-win-security-cryptoapi-l1-1-0.dll CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptAcquireContextW
CryptDestroyHash
CryptHashData
api-ms-win-core-namedpipe-l1-1-0.dll PeekNamedPipe
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-core-kernel32-legacy-l1-1-1.dll VerifyVersionInfoW
api-ms-win-security-systemfunctions-l1-1-0.dll SystemFunction036
api-ms-win-core-rtlsupport-l1-1-0.dll RtlLookupFunctionEntry
RtlVirtualUnwind
RtlCaptureContext
api-ms-win-core-interlocked-l1-1-0.dll InterlockedPushEntrySList
InitializeSListHead
OLEAUT32.dll SetErrorInfo
SysStringLen
SysFreeString
GetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-30 17:45:49
Version 0.0
SizeofData 912
AddressOfRawData 0x367028
PointerToRawData 0x365c28

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-30 17:45:49
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1403673e0
EndAddressOfRawData 0x1403674b0
AddressOfIndex 0x140442190
AddressOfCallbacks 0x1402677f8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1403a0f40

RICH Header

XOR Key 0xa45e2fa
Unmarked objects 0
253 (35207) 8
C objects (35207) 10
C++ objects (35207) 42
ASM objects (35207) 6
Imports (35207) 8
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 123
C++ objects (34436) 5
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (VS2008 SP1 build 30729) 136
Imports (33145) 32
Imports (21202) 3
Total imports 718
C++ objects (LTCG) (35228) 85
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.