| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Dec-12 16:26:45 |
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
D:\a\_work\1\s\src\runtime\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
|
| CompanyName | ctiacademy |
| FileDescription | ctiacademy |
| FileVersion | 1.0.0.0 |
| InternalName | ctiacademy.dll |
| LegalCopyright | |
| OriginalFilename | ctiacademy.dll |
| ProductName | ctiacademy |
| ProductVersion | 1.0.0 |
| Assembly Version | 1.0.0.0 |
| Info | Matching compiler(s): |
Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .CLR_UEF
Unusual section name found: Section |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER detected as a PE Executable. |
| Suspicious | The file contains overlay data. | 4940231 bytes of data starting at offset 0x981c00. |
| Malicious | VirusTotal score: 6/60 (Scanned on 2026-07-06 05:21:48) |
Alibaba:
TrojanDownloader:Win64/Alien.864443c9
Fortinet: W32/PossibleThreat Kingsoft: Win64.Trojan-Downloader.Alien.dvf Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!8A73D2073096 |
| MD5 | 8a73d2073096bc207c5d7b16f85b4745 🔍 |
|---|---|
| SHA1 | 426d61a4ffa67252c52a5b658a6c8dc96cc7f577 🔍 |
| SHA256 | 13a43300caac9be345b1fadd590d707dc3d405097e3f1576a8cf6dc2a00b22ae 🔍 |
| SHA3 | 9321861afe39c7aeb6d83587a6497e22c8bc04c6760c5ae7c15dd72ea110f0f0 🔍 |
| SSDeep | 196608:8pKHmucHBDaDhjzclm9jDT4xRqqqqptxGeBbl3JBB1KZVlRmY5ETX/v/Q:8UHhO+t6IDTY0eBbl3La3lRmjX4 🔍 |
| Imports Hash | 4e36540356b63e346f910d7b2fa9f7bc 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2025-Dec-12 16:26:45 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x664000 |
| SizeOfInitializedData | 0x331600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000005C5FA0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x99b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x180000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | a33ea17632604b6107791cad01e34a8f 🔍 |
|---|---|
| SHA1 | 151858bd3f095370085817eed1e4bbc8c00a448c 🔍 |
| SHA256 | 94e5e5391de69df46d21d2111143bb5eea50cb48ee09ef94215f2124e25687e9 🔍 |
| SHA3 | 08cbfc526ea50f20cfb0b11a7196e940cf60159825a9c7bc1a354c88d16447ff 🔍 |
| VirtualSize | 0x663c4c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x663e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.46294 |
| MD5 | 02bed18704928b562756cf8d50806784 🔍 |
|---|---|
| SHA1 | fea4d76cc009097d5c55d6981e1b39ed7b1b7685 🔍 |
| SHA256 | 04e7ca1febf249e998fa05ecf9c4c86df38e58ac1946ddb87009c43b5568368f 🔍 |
| SHA3 | 52b97a2ae388a3ba75400d3ffed14bbec8524b8247b4a790e3b2984f5107c351 🔍 |
| VirtualSize | 0xd7 |
| VirtualAddress | 0x665000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x664200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.09179 |
| MD5 | 6da2d492ed492954a7c88d8d0167c742 🔍 |
|---|---|
| SHA1 | e34b01a0e738625b762d802b0d5296a38739b3b4 🔍 |
| SHA256 | 2999356e3ec2a8584678923597358b27ed7de375bbf2c37c16b152117eaaad0a 🔍 |
| SHA3 | 6701913f5600cd79fd8ac3305c8ff72d9cd032b1ca5ee8e74a29dd640ac81c01 🔍 |
| VirtualSize | 0x18cd96 |
| VirtualAddress | 0x666000 |
| SizeOfRawData | 0x18ce00 |
| PointerToRawData | 0x664400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.70516 |
| MD5 | cf1bc7baadf9e4be5ffbe2d0167cf0f5 🔍 |
|---|---|
| SHA1 | f3d1ca3b5335c28d6e1c834f57b2f3efa2087987 🔍 |
| SHA256 | dfdde300cec5fd0bb707e457ba2ea9bd0860d4a1f2085d030660690b5e94a0f7 🔍 |
| SHA3 | 22ff3d427d6d99f59bd9cc47fde1bb9966e8380c209dbce7faa9c9445deb1ae0 🔍 |
| VirtualSize | 0x18e18 |
| VirtualAddress | 0x7f3000 |
| SizeOfRawData | 0x5200 |
| PointerToRawData | 0x7f1200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.6757 |
| MD5 | 9c525745f60de7a48e56e29623959e9d 🔍 |
|---|---|
| SHA1 | e6829cf0b16d243f3698bf435566a924de4bbecd 🔍 |
| SHA256 | 72cfea5e4f9f258d5c7d630780f1b366b085bfb7e574bc1c8c5db3b8ea37bd31 🔍 |
| SHA3 | 87558d478a3ffd99ef71af2472576a27048b9651dce85a73d97dc7524317f1c6 🔍 |
| VirtualSize | 0x390b4 |
| VirtualAddress | 0x80c000 |
| SizeOfRawData | 0x39200 |
| PointerToRawData | 0x7f6400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.47492 |
| MD5 | 768c7507806da58900fb75fbaccdb621 🔍 |
|---|---|
| SHA1 | 97558e9de38535ea9cc4af1912f8894bd5483040 🔍 |
| SHA256 | edc6a3c693b4bddfa27d8bff87e3d11b3821b42a9f218da271f2ae923956e8c9 🔍 |
| SHA3 | 528213802bfd66d2fbce2b6253ebe1f9e96e9bf5ff5649e4e1464abf75fe1a94 🔍 |
| VirtualSize | 0x38 |
| VirtualAddress | 0x846000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x82f600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.42693 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x8 |
| VirtualAddress | 0x847000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x82f800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | b515bfcab6d54b3073012719d387aaa6 🔍 |
|---|---|
| SHA1 | 02e18e9e792979ad7c27553e09786c2c34027325 🔍 |
| SHA256 | b6c7ea62b2a031d3d042100dcd85932780a305ed23bbd5e412105e15b7f0ead4 🔍 |
| SHA3 | b0b12e0e2c2f069836059cda82b49ea075ab1785e2be566e84e8714a29745dc4 🔍 |
| VirtualSize | 0x14a668 |
| VirtualAddress | 0x848000 |
| SizeOfRawData | 0x14a800 |
| PointerToRawData | 0x82fa00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.37538 |
| MD5 | 1d5c75ea8655cdb787974bd4351fed12 🔍 |
|---|---|
| SHA1 | 592fedd3820bcb266a23893c9e211e81d7922ceb 🔍 |
| SHA256 | 651910e7c7ac87fe322ac5efa6e9e6e7d0aac2194d324d5714c2778b82550ba3 🔍 |
| SHA3 | 16ac119dba4f3f6b30fb12b0541f1919049cd08dda97da0174b73a79154348ab 🔍 |
| VirtualSize | 0x78f8 |
| VirtualAddress | 0x993000 |
| SizeOfRawData | 0x7a00 |
| PointerToRawData | 0x97a200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.44768 |
| KERNEL32.dll |
ActivateActCtx
FindResourceW GetWindowsDirectoryW GetModuleHandleW LoadLibraryExW LoadLibraryExA RtlCaptureContext WideCharToMultiByte GetConsoleOutputCP MapViewOfFileEx SetLastError SetThreadErrorMode RaiseException SetConsoleCtrlHandler DebugBreak FlsAlloc FlsSetValue FlsGetValue GetLocaleInfoEx GetUserDefaultLocaleName FlushProcessWriteBuffers ReadFile CreateNamedPipeA GetCurrentProcess WriteFile WaitForMultipleObjects WaitForSingleObject DuplicateHandle DisconnectNamedPipe CreateEventW CreateFileA CancelIoEx GetOverlappedResult ConnectNamedPipe FlushFileBuffers SetEvent ResetEvent WaitForSingleObjectEx VirtualAlloc VirtualFree VirtualQuery VirtualProtect SleepEx SwitchToThread MultiByteToWideChar SuspendThread ResumeThread LCMapStringEx FormatMessageW LocalFree GetModuleFileNameW GetEnvironmentVariableW CreateFileW GetFullPathNameW HeapAlloc HeapFree CreateFileMappingW HeapCreate GetProcessHeap HeapDestroy VerSetConditionMask VerifyVersionInfoW QueueUserAPC SetThreadPriority GetThreadPriority TlsSetValue TlsAlloc WaitForMultipleObjectsEx SignalObjectAndWait RtlLookupFunctionEntry SetThreadStackGuarantee LocateXStateFeature SetErrorMode RaiseFailFastException GetExitCodeProcess TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter AddVectoredExceptionHandler GetThreadContext SetThreadContext GetEnabledXStateFeatures InitializeContext RtlRestoreContext SetXStateFeaturesMask CopyContext GetModuleHandleExW GetCommandLineW CreateProcessW GetCPInfo ExitProcess OutputDebugStringW RtlInstallFunctionTableCallback GetLogicalProcessorInformationEx SetThreadGroupAffinity UnmapViewOfFile GetProcessGroupAffinity GetProcessAffinityMask QueryInformationJobObject FlushInstructionCache RtlDeleteFunctionTable CreateMemoryResourceNotification WerRegisterRuntimeExceptionModule RtlUnwind CloseThreadpoolTimer CreateThreadpoolTimer SetThreadpoolTimer OpenEventW ExitThread HeapReAlloc TlsGetValue GetFileSize RtlAddFunctionTable CreateSemaphoreExW ReleaseSemaphore GetSystemDefaultLCID GetUserDefaultLCID OutputDebugStringA QueryThreadCycleTime SetFilePointer MapViewOfFile FindClose Sleep RemoveDirectoryW CreateDirectoryW GetEnvironmentStringsW GetSystemTime GetSystemTimeAsFileTime FreeLibrary GetCurrentProcessId GetProcAddress CreateThread GetSystemInfo CloseHandle GetActiveProcessorGroupCount GetCurrentThread GetLastError FreeEnvironmentStringsW GetCurrentThreadId CreateActCtxW GetTempPathW InitializeCriticalSection LeaveCriticalSection GetStdHandle FindNextFileW EnterCriticalSection FindFirstFileExW GetFileSizeEx GetConsoleMode GetFileAttributesExW LoadLibraryA GetCurrentDirectoryW WriteConsoleW DeleteCriticalSection CreateFileMappingA GetTickCount64 QueryPerformanceFrequency QueryPerformanceCounter IsDebuggerPresent GetNumaHighestNodeNumber SetThreadAffinityMask GetFileAttributesW SetThreadIdealProcessorEx GetThreadIdealProcessorEx VirtualAllocExNuma GetNumaProcessorNodeEx VirtualUnlock GetLargePageMinimum IsProcessInJob K32GetProcessMemoryInfo GetLogicalProcessorInformation GlobalMemoryStatusEx RtlVirtualUnwind IsProcessorFeaturePresent ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW InitializeSListHead RtlUnwindEx RtlPcToFileHeader EncodePointer InitializeCriticalSectionAndSpinCount TlsFree TryAcquireSRWLockExclusive GetExitCodeThread GetStringTypeW InitializeCriticalSectionEx DecodePointer SetEnvironmentVariableW GetThreadGroupAffinity GetCurrentProcessorNumberEx |
|---|---|
| ADVAPI32.dll |
LookupPrivilegeValueW
RegGetValueW SetKernelObjectSecurity RegQueryValueExW RegOpenKeyExW GetSidSubAuthorityCount GetSidSubAuthority GetTokenInformation OpenProcessToken RegCloseKey SetThreadToken RevertToSelf OpenThreadToken EventWrite EventRegister EventWriteTransfer DeregisterEventSource RegisterEventSourceW ReportEventW AdjustTokenPrivileges |
| ole32.dll |
CLSIDFromProgID
CoCreateGuid CoTaskMemAlloc CoUnmarshalInterface CoMarshalInterface CoGetMarshalSizeMax CoCreateFreeThreadedMarshaler CoGetClassObject CoGetContextToken CoGetObjectContext CoReleaseMarshalData CoInitializeEx CoRegisterInitializeSpy CoWaitForMultipleHandles CoUninitialize CoRevokeInitializeSpy CoTaskMemFree |
| OLEAUT32.dll |
SetErrorInfo
GetErrorInfo SysFreeString SysStringLen CreateErrorInfo QueryPathOfRegTypeLib SafeArrayGetVartype VariantChangeType SysAllocString LoadRegTypeLib SysAllocStringLen VariantClear VariantInit VarCyFromDec SafeArrayDestroy SafeArrayAllocDescriptorEx GetRecordInfoFromTypeInfo SafeArraySetRecordInfo SafeArrayAllocData SafeArrayGetElemsize SysStringByteLen SysAllocStringByteLen SafeArrayCreateVector SafeArrayPutElement SafeArrayGetDim SafeArrayGetLBound LoadTypeLibEx |
| USER32.dll |
LoadStringW
MessageBoxW |
| SHELL32.dll |
ShellExecuteW
|
| api-ms-win-crt-string-l1-1-0.dll |
iswspace
strncpy iswascii iswupper wcsncpy_s isalpha strncmp strncpy_s towlower wcscat_s _wcsdup wcscpy_s isdigit strnlen wcsnlen strncat_s towupper strcmp strcpy_s _stricmp strcat_s isspace tolower wcsncmp _strdup strtok_s wcsncat_s strlen _wcsnicmp _wcsicmp _strnicmp |
| api-ms-win-crt-heap-l1-1-0.dll |
_aligned_malloc
malloc _callnewh realloc free _set_new_mode _aligned_free calloc |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
_wcstoui64 _wtoi strtoull strtol wcstoul _ltow_s _atoi64 atol strtoul |
| api-ms-win-crt-stdio-l1-1-0.dll |
fputwc
__stdio_common_vsprintf_s __stdio_common_vfprintf __acrt_iob_func _set_fmode __stdio_common_vsprintf ftell fseek _wfsopen __stdio_common_vfwprintf fclose setvbuf _setmode _dup _fileno fwrite __p__commode _flushall __stdio_common_vswprintf __stdio_common_vsnprintf_s fopen _write _wfopen __stdio_common_vsscanf fgets fflush fputs __stdio_common_vsnwprintf_s |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_invoke_watson
_invalid_parameter_noinfo _beginthreadex terminate _wcserror_s _register_thread_local_exe_atexit_callback _c_exit __p___wargv __p___argc abort _exit exit _initterm_e _initterm _get_initial_wide_environment _initialize_wide_environment _configure_wide_argv _set_app_type _seh_filter_exe _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _errno _controlfp_s |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_wrename
_wremove |
| api-ms-win-crt-math-l1-1-0.dll |
truncf
atanf trunc ilogbf ceil atan2 copysign ceilf round fmodf asinh cbrt acosh atanh modf acoshf cbrtf atanhf tanhf modff asinhf fmod __setusermatherr _fdopen fmaf fma floorf floor acos acosf asin asinf log10 expf exp log10f log log2 coshf cosh log2f cosf logf pow cos powf roundf atan2f sin sinf sinh sinhf sqrt sqrtf tan tanf tanh copysignf atan |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64_s
_time64 wcsftime |
| api-ms-win-crt-locale-l1-1-0.dll |
setlocale
__pctype_func ___lc_locale_name_func ___lc_codepage_func _lock_locales _free_locale _configthreadlocale _unlock_locales ___mb_cur_max_func _create_locale |
| VERSION.dll (delay-loaded) |
VerQueryValueW
GetFileVersionInfoExW GetFileVersionInfoSizeExW |
| Attributes | 0x1 |
|---|---|
| Name | VERSION.dll |
| ModuleHandle | 0x7f8200 |
| DelayImportAddressTable | 0x846000 |
| DelayImportNameTable | 0x7ef8a8 |
| BoundDelayImportTable | 0x7ef948 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 2 |
|---|---|
| Address | 0x7f3b30 |
| Ordinal | 3 |
|---|---|
| Address | 0x7fae7c |
| Ordinal | 4 |
|---|---|
| Address | 0x7f4890 |
| Ordinal | 5 |
|---|---|
| Address | 0x71fdb0 |
| Ordinal | 6 |
|---|---|
| Address | 0x615a20 |
| Ordinal | 7 |
|---|---|
| Address | 0x615b30 |
| Ordinal | 8 |
|---|---|
| Address | 0x615be0 |
| Ordinal | 9 |
|---|---|
| Address | 0x615cb0 |
| Ordinal | 10 |
|---|---|
| Address | 0x617290 |
| Ordinal | 11 |
|---|---|
| Address | 0x6172e0 |
| Ordinal | 12 |
|---|---|
| Address | 0x617490 |
| Ordinal | 13 |
|---|---|
| Address | 0x6174a0 |
| Ordinal | 14 |
|---|---|
| Address | 0x6174e0 |
| Ordinal | 15 |
|---|---|
| Address | 0x617520 |
| Ordinal | 16 |
|---|---|
| Address | 0x617540 |
| Ordinal | 17 |
|---|---|
| Address | 0x617560 |
| Ordinal | 18 |
|---|---|
| Address | 0x6175b0 |
| Ordinal | 19 |
|---|---|
| Address | 0x5cb6b0 |
| Ordinal | 20 |
|---|---|
| Address | 0x61cff0 |
| Ordinal | 21 |
|---|---|
| Address | 0x61d000 |
| Ordinal | 22 |
|---|---|
| Address | 0x5ca1e0 |
| Ordinal | 23 |
|---|---|
| Address | 0x5ca3e0 |
| Ordinal | 24 |
|---|---|
| Address | 0x5ca990 |
| Ordinal | 25 |
|---|---|
| Address | 0x5cb0e0 |
| Ordinal | 26 |
|---|---|
| Address | 0x5cb2a0 |
| Ordinal | 27 |
|---|---|
| Address | 0x5cb410 |
| Ordinal | 28 |
|---|---|
| Address | 0x5cb480 |
| Ordinal | 29 |
|---|---|
| Address | 0x5cb490 |
| Ordinal | 30 |
|---|---|
| Address | 0x5cb4b0 |
| Ordinal | 31 |
|---|---|
| Address | 0x5cb4e0 |
| Ordinal | 32 |
|---|---|
| Address | 0x5cb560 |
| Ordinal | 33 |
|---|---|
| Address | 0x5cb640 |
| Ordinal | 34 |
|---|---|
| Address | 0x5cb6b0 |
| Ordinal | 35 |
|---|---|
| Address | 0x61d010 |
| Ordinal | 36 |
|---|---|
| Address | 0x61d020 |
| Ordinal | 37 |
|---|---|
| Address | 0x2ae50 |
| Ordinal | 38 |
|---|---|
| Address | 0x61d420 |
| Ordinal | 39 |
|---|---|
| Address | 0x61d450 |
| Ordinal | 40 |
|---|---|
| Address | 0x61d530 |
| Ordinal | 41 |
|---|---|
| Address | 0x61d030 |
| Ordinal | 42 |
|---|---|
| Address | 0x7f4868 |
| Ordinal | 43 |
|---|---|
| Address | 0x5b38f0 |
| Ordinal | 44 |
|---|---|
| Address | 0x6c2340 |
| Ordinal | 45 |
|---|---|
| Address | 0x6e0ea0 |
| Type |
RT_RCDATA
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x24 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.33659 |
| MD5 | 8c2a64759681cbfe4d44b575b8667496 🔍 |
| SHA1 | bd915862e4f5e34bba0aa6b4028517fc1977c791 🔍 |
| SHA256 | da0df2e6c75b2bc9dd5916cb671cd2e648f6b222370c022f2d3eef49387a8afc 🔍 |
| SHA3 | 9cbee1950cd51d8a5085eed3ef7cb770410c4f6acb0d283dcdea6feff8cfe222 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x24 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.33659 |
| MD5 | 8c2a64759681cbfe4d44b575b8667496 🔍 |
| SHA1 | bd915862e4f5e34bba0aa6b4028517fc1977c791 🔍 |
| SHA256 | da0df2e6c75b2bc9dd5916cb671cd2e648f6b222370c022f2d3eef49387a8afc 🔍 |
| SHA3 | 9cbee1950cd51d8a5085eed3ef7cb770410c4f6acb0d283dcdea6feff8cfe222 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x149f80 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.37666 |
| Detected Filetype | PE Executable |
| MD5 | f100711d7963554dc5708bd49024eccd 🔍 |
| SHA1 | 063d20e3e3f79205002ff7f30ceeeb29b59bde18 🔍 |
| SHA256 | ea9e08c32c81aa02bbcc07b9372dcb7ae403da116eb445c0319eb6340f6a5e83 🔍 |
| SHA3 | 4b09050368081957afae4c8bbe6ab2f7da66876304f1e0c0422dd77547457afc 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x2d4 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.19415 |
| MD5 | 1397dfc3dda3cc36bb970feec798b75b 🔍 |
| SHA1 | cb570c9eb31201ca86abf5ba39b2543d2e9a90be 🔍 |
| SHA256 | 8883cb3111f91abdd9331d9005aaf00c17aefe83694e79becb857f708c70905e 🔍 |
| SHA3 | a7fbb7e08a2dc117b5794171ddd0197105ec2abc973a36bf45567de1d8d447d1 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | UNKNOWN |
| Codepage | Latin 1 / Western European |
| Size | 0x1ea |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.00112 |
| MD5 | b7db84991f23a680df8e95af8946f9c9 🔍 |
| SHA1 | cac699787884fb993ced8d7dc47b7c522c7bc734 🔍 |
| SHA256 | 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a 🔍 |
| SHA3 | 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | ctiacademy |
| FileDescription | ctiacademy |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | ctiacademy.dll |
| LegalCopyright | |
| OriginalFilename | ctiacademy.dll |
| ProductName | ctiacademy |
| ProductVersion (#2) | 1.0.0 |
| Assembly Version | 1.0.0.0 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 16:26:45 |
| Version | 0.0 |
| SizeofData | 128 |
| AddressOfRawData | 0x772a34 |
| PointerToRawData | 0x770e34 |
| Referenced File | D:\a\_work\1\s\src\runtime\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 16:26:45 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x772ab4 |
| PointerToRawData | 0x770eb4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 16:26:45 |
| Version | 0.0 |
| SizeofData | 1316 |
| AddressOfRawData | 0x772ac8 |
| PointerToRawData | 0x770ec8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-12 16:26:45 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x773014 |
| PointerToRawData | 0x771414 |
| StartAddressOfRawData | 0x140773040 |
|---|---|
| EndAddressOfRawData | 0x140773309 |
| AddressOfIndex | 0x1407f8808 |
| AddressOfCallbacks | 0x140666f98 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001405C53A0
0x00000001405C5750 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0x800 |
| EditList | 0 |
| SecurityCookie | 0x1407f30c0 |
| GuardCFCheckFunctionPointer | 5375422000 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x4b0b1fd0 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| ASM objects (35207) | 11 |
| C objects (35207) | 19 |
| C objects (35217) | 68 |
| C++ objects (35207) | 101 |
| C objects (33140) | 8 |
| Imports (33140) | 13 |
| Total imports | 505 |
| ASM objects (35217) | 22 |
| C++ objects (LTCG) (35217) | 571 |
| Exports (35217) | 1 |
| Resource objects (35217) | 1 |
| Linker (35217) | 1 |
No comments yet.