13a43300caac9be345b1fadd590d707dc3d405097e3f1576a8cf6dc2a00b22ae

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2025-Dec-12 16:26:45
TLS Callbacks 2 callback(s) detected.
Debug artifacts D:\a\_work\1\s\src\runtime\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
CompanyName ctiacademy
FileDescription ctiacademy
FileVersion 1.0.0.0
InternalName ctiacademy.dll
LegalCopyright
OriginalFilename ctiacademy.dll
ProductName ctiacademy
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains strings related to LLMs.:
  • <System>
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • crl.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • go.microsoft.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://go.microsoft.com
  • http://go.microsoft.com/fwlink/?LinkId
  • http://manifests.microsoft.com
  • http://manifests.microsoft.com/win/2004/08/windows/events
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/win/2004/08/events
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegroup
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/role
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclaim
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegroup
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthority
  • http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclaim
  • http://schemas.xmlsoap.org
  • http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid
  • http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crt0
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crl0w
  • http://www.microsoft.com0
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/2001/XMLSchema
  • http://www.w3.org/2001/XMLSchema#boolean
  • http://www.w3.org/2001/XMLSchema#integer64
  • http://www.w3.org/2001/XMLSchema#string
  • http://www.w3.org/2001/XMLSchema#uinteger64
  • http://www.w3.org/2001/XMLSchema-instance
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://aka.ms
  • https://github.com
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?LinkID
  • https://go.microsoft.com/fwlink/?linkid
  • https://steamcommunity.com
  • https://www.World
  • https://www.recent
  • manifests.microsoft.com
  • microsoft.com
  • schemas.microsoft.com
  • schemas.xmlsoap.org
  • steamcommunity.com
  • thing.org
  • www.microsoft.com
  • www.w3.org
  • xmlsoap.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to RC5 or RC6
Suspicious The PE is possibly packed. Unusual section name found: .CLR_UEF
Unusual section name found: Section
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegGetValueW
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Changes object ACLs:
  • SetKernelObjectSecurity
Malicious The PE is possibly a dropper. Resource MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER detected as a PE Executable.
Suspicious The file contains overlay data. 4940231 bytes of data starting at offset 0x981c00.
Malicious VirusTotal score: 6/60 (Scanned on 2026-07-06 05:21:48) Alibaba: TrojanDownloader:Win64/Alien.864443c9
Fortinet: W32/PossibleThreat
Kingsoft: Win64.Trojan-Downloader.Alien.dvf
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!8A73D2073096

Hashes

MD5 8a73d2073096bc207c5d7b16f85b4745 🔍
SHA1 426d61a4ffa67252c52a5b658a6c8dc96cc7f577 🔍
SHA256 13a43300caac9be345b1fadd590d707dc3d405097e3f1576a8cf6dc2a00b22ae 🔍
SHA3 9321861afe39c7aeb6d83587a6497e22c8bc04c6760c5ae7c15dd72ea110f0f0 🔍
SSDeep 196608:8pKHmucHBDaDhjzclm9jDT4xRqqqqptxGeBbl3JBB1KZVlRmY5ETX/v/Q:8UHhO+t6IDTY0eBbl3La3lRmjX4 🔍
Imports Hash 4e36540356b63e346f910d7b2fa9f7bc 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2025-Dec-12 16:26:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x664000
SizeOfInitializedData 0x331600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000005C5FA0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x99b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a33ea17632604b6107791cad01e34a8f 🔍
SHA1 151858bd3f095370085817eed1e4bbc8c00a448c 🔍
SHA256 94e5e5391de69df46d21d2111143bb5eea50cb48ee09ef94215f2124e25687e9 🔍
SHA3 08cbfc526ea50f20cfb0b11a7196e940cf60159825a9c7bc1a354c88d16447ff 🔍
VirtualSize 0x663c4c
VirtualAddress 0x1000
SizeOfRawData 0x663e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46294

.CLR_UEF

MD5 02bed18704928b562756cf8d50806784 🔍
SHA1 fea4d76cc009097d5c55d6981e1b39ed7b1b7685 🔍
SHA256 04e7ca1febf249e998fa05ecf9c4c86df38e58ac1946ddb87009c43b5568368f 🔍
SHA3 52b97a2ae388a3ba75400d3ffed14bbec8524b8247b4a790e3b2984f5107c351 🔍
VirtualSize 0xd7
VirtualAddress 0x665000
SizeOfRawData 0x200
PointerToRawData 0x664200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 3.09179

.rdata

MD5 6da2d492ed492954a7c88d8d0167c742 🔍
SHA1 e34b01a0e738625b762d802b0d5296a38739b3b4 🔍
SHA256 2999356e3ec2a8584678923597358b27ed7de375bbf2c37c16b152117eaaad0a 🔍
SHA3 6701913f5600cd79fd8ac3305c8ff72d9cd032b1ca5ee8e74a29dd640ac81c01 🔍
VirtualSize 0x18cd96
VirtualAddress 0x666000
SizeOfRawData 0x18ce00
PointerToRawData 0x664400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.70516

.data

MD5 cf1bc7baadf9e4be5ffbe2d0167cf0f5 🔍
SHA1 f3d1ca3b5335c28d6e1c834f57b2f3efa2087987 🔍
SHA256 dfdde300cec5fd0bb707e457ba2ea9bd0860d4a1f2085d030660690b5e94a0f7 🔍
SHA3 22ff3d427d6d99f59bd9cc47fde1bb9966e8380c209dbce7faa9c9445deb1ae0 🔍
VirtualSize 0x18e18
VirtualAddress 0x7f3000
SizeOfRawData 0x5200
PointerToRawData 0x7f1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.6757

.pdata

MD5 9c525745f60de7a48e56e29623959e9d 🔍
SHA1 e6829cf0b16d243f3698bf435566a924de4bbecd 🔍
SHA256 72cfea5e4f9f258d5c7d630780f1b366b085bfb7e574bc1c8c5db3b8ea37bd31 🔍
SHA3 87558d478a3ffd99ef71af2472576a27048b9651dce85a73d97dc7524317f1c6 🔍
VirtualSize 0x390b4
VirtualAddress 0x80c000
SizeOfRawData 0x39200
PointerToRawData 0x7f6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.47492

.didat

MD5 768c7507806da58900fb75fbaccdb621 🔍
SHA1 97558e9de38535ea9cc4af1912f8894bd5483040 🔍
SHA256 edc6a3c693b4bddfa27d8bff87e3d11b3821b42a9f218da271f2ae923956e8c9 🔍
SHA3 528213802bfd66d2fbce2b6253ebe1f9e96e9bf5ff5649e4e1464abf75fe1a94 🔍
VirtualSize 0x38
VirtualAddress 0x846000
SizeOfRawData 0x200
PointerToRawData 0x82f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.42693

Section

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x8
VirtualAddress 0x847000
SizeOfRawData 0x200
PointerToRawData 0x82f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 b515bfcab6d54b3073012719d387aaa6 🔍
SHA1 02e18e9e792979ad7c27553e09786c2c34027325 🔍
SHA256 b6c7ea62b2a031d3d042100dcd85932780a305ed23bbd5e412105e15b7f0ead4 🔍
SHA3 b0b12e0e2c2f069836059cda82b49ea075ab1785e2be566e84e8714a29745dc4 🔍
VirtualSize 0x14a668
VirtualAddress 0x848000
SizeOfRawData 0x14a800
PointerToRawData 0x82fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.37538

.reloc

MD5 1d5c75ea8655cdb787974bd4351fed12 🔍
SHA1 592fedd3820bcb266a23893c9e211e81d7922ceb 🔍
SHA256 651910e7c7ac87fe322ac5efa6e9e6e7d0aac2194d324d5714c2778b82550ba3 🔍
SHA3 16ac119dba4f3f6b30fb12b0541f1919049cd08dda97da0174b73a79154348ab 🔍
VirtualSize 0x78f8
VirtualAddress 0x993000
SizeOfRawData 0x7a00
PointerToRawData 0x97a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44768

Imports

KERNEL32.dll ActivateActCtx
FindResourceW
GetWindowsDirectoryW
GetModuleHandleW
LoadLibraryExW
LoadLibraryExA
RtlCaptureContext
WideCharToMultiByte
GetConsoleOutputCP
MapViewOfFileEx
SetLastError
SetThreadErrorMode
RaiseException
SetConsoleCtrlHandler
DebugBreak
FlsAlloc
FlsSetValue
FlsGetValue
GetLocaleInfoEx
GetUserDefaultLocaleName
FlushProcessWriteBuffers
ReadFile
CreateNamedPipeA
GetCurrentProcess
WriteFile
WaitForMultipleObjects
WaitForSingleObject
DuplicateHandle
DisconnectNamedPipe
CreateEventW
CreateFileA
CancelIoEx
GetOverlappedResult
ConnectNamedPipe
FlushFileBuffers
SetEvent
ResetEvent
WaitForSingleObjectEx
VirtualAlloc
VirtualFree
VirtualQuery
VirtualProtect
SleepEx
SwitchToThread
MultiByteToWideChar
SuspendThread
ResumeThread
LCMapStringEx
FormatMessageW
LocalFree
GetModuleFileNameW
GetEnvironmentVariableW
CreateFileW
GetFullPathNameW
HeapAlloc
HeapFree
CreateFileMappingW
HeapCreate
GetProcessHeap
HeapDestroy
VerSetConditionMask
VerifyVersionInfoW
QueueUserAPC
SetThreadPriority
GetThreadPriority
TlsSetValue
TlsAlloc
WaitForMultipleObjectsEx
SignalObjectAndWait
RtlLookupFunctionEntry
SetThreadStackGuarantee
LocateXStateFeature
SetErrorMode
RaiseFailFastException
GetExitCodeProcess
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
AddVectoredExceptionHandler
GetThreadContext
SetThreadContext
GetEnabledXStateFeatures
InitializeContext
RtlRestoreContext
SetXStateFeaturesMask
CopyContext
GetModuleHandleExW
GetCommandLineW
CreateProcessW
GetCPInfo
ExitProcess
OutputDebugStringW
RtlInstallFunctionTableCallback
GetLogicalProcessorInformationEx
SetThreadGroupAffinity
UnmapViewOfFile
GetProcessGroupAffinity
GetProcessAffinityMask
QueryInformationJobObject
FlushInstructionCache
RtlDeleteFunctionTable
CreateMemoryResourceNotification
WerRegisterRuntimeExceptionModule
RtlUnwind
CloseThreadpoolTimer
CreateThreadpoolTimer
SetThreadpoolTimer
OpenEventW
ExitThread
HeapReAlloc
TlsGetValue
GetFileSize
RtlAddFunctionTable
CreateSemaphoreExW
ReleaseSemaphore
GetSystemDefaultLCID
GetUserDefaultLCID
OutputDebugStringA
QueryThreadCycleTime
SetFilePointer
MapViewOfFile
FindClose
Sleep
RemoveDirectoryW
CreateDirectoryW
GetEnvironmentStringsW
GetSystemTime
GetSystemTimeAsFileTime
FreeLibrary
GetCurrentProcessId
GetProcAddress
CreateThread
GetSystemInfo
CloseHandle
GetActiveProcessorGroupCount
GetCurrentThread
GetLastError
FreeEnvironmentStringsW
GetCurrentThreadId
CreateActCtxW
GetTempPathW
InitializeCriticalSection
LeaveCriticalSection
GetStdHandle
FindNextFileW
EnterCriticalSection
FindFirstFileExW
GetFileSizeEx
GetConsoleMode
GetFileAttributesExW
LoadLibraryA
GetCurrentDirectoryW
WriteConsoleW
DeleteCriticalSection
CreateFileMappingA
GetTickCount64
QueryPerformanceFrequency
QueryPerformanceCounter
IsDebuggerPresent
GetNumaHighestNodeNumber
SetThreadAffinityMask
GetFileAttributesW
SetThreadIdealProcessorEx
GetThreadIdealProcessorEx
VirtualAllocExNuma
GetNumaProcessorNodeEx
VirtualUnlock
GetLargePageMinimum
IsProcessInJob
K32GetProcessMemoryInfo
GetLogicalProcessorInformation
GlobalMemoryStatusEx
RtlVirtualUnwind
IsProcessorFeaturePresent
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsFree
TryAcquireSRWLockExclusive
GetExitCodeThread
GetStringTypeW
InitializeCriticalSectionEx
DecodePointer
SetEnvironmentVariableW
GetThreadGroupAffinity
GetCurrentProcessorNumberEx
ADVAPI32.dll LookupPrivilegeValueW
RegGetValueW
SetKernelObjectSecurity
RegQueryValueExW
RegOpenKeyExW
GetSidSubAuthorityCount
GetSidSubAuthority
GetTokenInformation
OpenProcessToken
RegCloseKey
SetThreadToken
RevertToSelf
OpenThreadToken
EventWrite
EventRegister
EventWriteTransfer
DeregisterEventSource
RegisterEventSourceW
ReportEventW
AdjustTokenPrivileges
ole32.dll CLSIDFromProgID
CoCreateGuid
CoTaskMemAlloc
CoUnmarshalInterface
CoMarshalInterface
CoGetMarshalSizeMax
CoCreateFreeThreadedMarshaler
CoGetClassObject
CoGetContextToken
CoGetObjectContext
CoReleaseMarshalData
CoInitializeEx
CoRegisterInitializeSpy
CoWaitForMultipleHandles
CoUninitialize
CoRevokeInitializeSpy
CoTaskMemFree
OLEAUT32.dll SetErrorInfo
GetErrorInfo
SysFreeString
SysStringLen
CreateErrorInfo
QueryPathOfRegTypeLib
SafeArrayGetVartype
VariantChangeType
SysAllocString
LoadRegTypeLib
SysAllocStringLen
VariantClear
VariantInit
VarCyFromDec
SafeArrayDestroy
SafeArrayAllocDescriptorEx
GetRecordInfoFromTypeInfo
SafeArraySetRecordInfo
SafeArrayAllocData
SafeArrayGetElemsize
SysStringByteLen
SysAllocStringByteLen
SafeArrayCreateVector
SafeArrayPutElement
SafeArrayGetDim
SafeArrayGetLBound
LoadTypeLibEx
USER32.dll LoadStringW
MessageBoxW
SHELL32.dll ShellExecuteW
api-ms-win-crt-string-l1-1-0.dll iswspace
strncpy
iswascii
iswupper
wcsncpy_s
isalpha
strncmp
strncpy_s
towlower
wcscat_s
_wcsdup
wcscpy_s
isdigit
strnlen
wcsnlen
strncat_s
towupper
strcmp
strcpy_s
_stricmp
strcat_s
isspace
tolower
wcsncmp
_strdup
strtok_s
wcsncat_s
strlen
_wcsnicmp
_wcsicmp
_strnicmp
api-ms-win-crt-heap-l1-1-0.dll _aligned_malloc
malloc
_callnewh
realloc
free
_set_new_mode
_aligned_free
calloc
api-ms-win-crt-convert-l1-1-0.dll atoi
_wcstoui64
_wtoi
strtoull
strtol
wcstoul
_ltow_s
_atoi64
atol
strtoul
api-ms-win-crt-stdio-l1-1-0.dll fputwc
__stdio_common_vsprintf_s
__stdio_common_vfprintf
__acrt_iob_func
_set_fmode
__stdio_common_vsprintf
ftell
fseek
_wfsopen
__stdio_common_vfwprintf
fclose
setvbuf
_setmode
_dup
_fileno
fwrite
__p__commode
_flushall
__stdio_common_vswprintf
__stdio_common_vsnprintf_s
fopen
_write
_wfopen
__stdio_common_vsscanf
fgets
fflush
fputs
__stdio_common_vsnwprintf_s
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
_invalid_parameter_noinfo
_beginthreadex
terminate
_wcserror_s
_register_thread_local_exe_atexit_callback
_c_exit
__p___wargv
__p___argc
abort
_exit
exit
_initterm_e
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_errno
_controlfp_s
api-ms-win-crt-filesystem-l1-1-0.dll _wrename
_wremove
api-ms-win-crt-math-l1-1-0.dll truncf
atanf
trunc
ilogbf
ceil
atan2
copysign
ceilf
round
fmodf
asinh
cbrt
acosh
atanh
modf
acoshf
cbrtf
atanhf
tanhf
modff
asinhf
fmod
__setusermatherr
_fdopen
fmaf
fma
floorf
floor
acos
acosf
asin
asinf
log10
expf
exp
log10f
log
log2
coshf
cosh
log2f
cosf
logf
pow
cos
powf
roundf
atan2f
sin
sinf
sinh
sinhf
sqrt
sqrtf
tan
tanf
tanh
copysignf
atan
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
_time64
wcsftime
api-ms-win-crt-locale-l1-1-0.dll setlocale
__pctype_func
___lc_locale_name_func
___lc_codepage_func
_lock_locales
_free_locale
_configthreadlocale
_unlock_locales
___mb_cur_max_func
_create_locale
VERSION.dll (delay-loaded) VerQueryValueW
GetFileVersionInfoExW
GetFileVersionInfoSizeExW

Delayed Imports

Attributes 0x1
Name VERSION.dll
ModuleHandle 0x7f8200
DelayImportAddressTable 0x846000
DelayImportNameTable 0x7ef8a8
BoundDelayImportTable 0x7ef948
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

g_CLREngineMetrics

Ordinal 2
Address 0x7f3b30

CLRJitAttachState

Ordinal 3
Address 0x7fae7c

DotNetRuntimeInfo

Ordinal 4
Address 0x7f4890

g_dacTable

Ordinal 5
Address 0x71fdb0

BrotliDecoderAttachDictionary

Ordinal 6
Address 0x615a20

BrotliDecoderCreateInstance

Ordinal 7
Address 0x615b30

BrotliDecoderDecompress

Ordinal 8
Address 0x615be0

BrotliDecoderDecompressStream

Ordinal 9
Address 0x615cb0

BrotliDecoderDestroyInstance

Ordinal 10
Address 0x617290

BrotliDecoderErrorString

Ordinal 11
Address 0x6172e0

BrotliDecoderGetErrorCode

Ordinal 12
Address 0x617490

BrotliDecoderHasMoreOutput

Ordinal 13
Address 0x6174a0

BrotliDecoderIsFinished

Ordinal 14
Address 0x6174e0

BrotliDecoderIsUsed

Ordinal 15
Address 0x617520

BrotliDecoderSetMetadataCallbacks

Ordinal 16
Address 0x617540

BrotliDecoderSetParameter

Ordinal 17
Address 0x617560

BrotliDecoderTakeOutput

Ordinal 18
Address 0x6175b0

BrotliDecoderVersion

Ordinal 19
Address 0x5cb6b0

BrotliDefaultAllocFunc

Ordinal 20
Address 0x61cff0

BrotliDefaultFreeFunc

Ordinal 21
Address 0x61d000

BrotliEncoderAttachPreparedDictionary

Ordinal 22
Address 0x5ca1e0

BrotliEncoderCompress

Ordinal 23
Address 0x5ca3e0

BrotliEncoderCompressStream

Ordinal 24
Address 0x5ca990

BrotliEncoderCreateInstance

Ordinal 25
Address 0x5cb0e0

BrotliEncoderDestroyInstance

Ordinal 26
Address 0x5cb2a0

BrotliEncoderDestroyPreparedDictionary

Ordinal 27
Address 0x5cb410

BrotliEncoderHasMoreOutput

Ordinal 28
Address 0x5cb480

BrotliEncoderIsFinished

Ordinal 29
Address 0x5cb490

BrotliEncoderMaxCompressedSize

Ordinal 30
Address 0x5cb4b0

BrotliEncoderPrepareDictionary

Ordinal 31
Address 0x5cb4e0

BrotliEncoderSetParameter

Ordinal 32
Address 0x5cb560

BrotliEncoderTakeOutput

Ordinal 33
Address 0x5cb640

BrotliEncoderVersion

Ordinal 34
Address 0x5cb6b0

BrotliGetDictionary

Ordinal 35
Address 0x61d010

BrotliGetTransforms

Ordinal 36
Address 0x61d020

BrotliSetDictionaryData

Ordinal 37
Address 0x2ae50

BrotliSharedDictionaryAttach

Ordinal 38
Address 0x61d420

BrotliSharedDictionaryCreateInstance

Ordinal 39
Address 0x61d450

BrotliSharedDictionaryDestroyInstance

Ordinal 40
Address 0x61d530

BrotliTransformDictionaryWord

Ordinal 41
Address 0x61d030

DotNetRuntimeContractDescriptor

Ordinal 42
Address 0x7f4868

MetaDataGetDispenser

Ordinal 43
Address 0x5b38f0

_kBrotliContextLookupTable

Ordinal 44
Address 0x6c2340

_kBrotliPrefixCodeRanges

Ordinal 45
Address 0x6e0ea0

CLRDEBUGINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.33659
MD5 8c2a64759681cbfe4d44b575b8667496 🔍
SHA1 bd915862e4f5e34bba0aa6b4028517fc1977c791 🔍
SHA256 da0df2e6c75b2bc9dd5916cb671cd2e648f6b222370c022f2d3eef49387a8afc 🔍
SHA3 9cbee1950cd51d8a5085eed3ef7cb770410c4f6acb0d283dcdea6feff8cfe222 🔍

CLRDEBUGINFOWINDOWSAMD64

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.33659
MD5 8c2a64759681cbfe4d44b575b8667496 🔍
SHA1 bd915862e4f5e34bba0aa6b4028517fc1977c791 🔍
SHA256 da0df2e6c75b2bc9dd5916cb671cd2e648f6b222370c022f2d3eef49387a8afc 🔍
SHA3 9cbee1950cd51d8a5085eed3ef7cb770410c4f6acb0d283dcdea6feff8cfe222 🔍

MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x149f80
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.37666
Detected Filetype PE Executable
MD5 f100711d7963554dc5708bd49024eccd 🔍
SHA1 063d20e3e3f79205002ff7f30ceeeb29b59bde18 🔍
SHA256 ea9e08c32c81aa02bbcc07b9372dcb7ae403da116eb445c0319eb6340f6a5e83 🔍
SHA3 4b09050368081957afae4c8bbe6ab2f7da66876304f1e0c0422dd77547457afc 🔍

1

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19415
MD5 1397dfc3dda3cc36bb970feec798b75b 🔍
SHA1 cb570c9eb31201ca86abf5ba39b2543d2e9a90be 🔍
SHA256 8883cb3111f91abdd9331d9005aaf00c17aefe83694e79becb857f708c70905e 🔍
SHA3 a7fbb7e08a2dc117b5794171ddd0197105ec2abc973a36bf45567de1d8d447d1 🔍

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9 🔍
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734 🔍
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a 🔍
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName ctiacademy
FileDescription ctiacademy
FileVersion (#2) 1.0.0.0
InternalName ctiacademy.dll
LegalCopyright
OriginalFilename ctiacademy.dll
ProductName ctiacademy
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Dec-12 16:26:45
Version 0.0
SizeofData 128
AddressOfRawData 0x772a34
PointerToRawData 0x770e34
Referenced File D:\a\_work\1\s\src\runtime\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Dec-12 16:26:45
Version 0.0
SizeofData 20
AddressOfRawData 0x772ab4
PointerToRawData 0x770eb4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Dec-12 16:26:45
Version 0.0
SizeofData 1316
AddressOfRawData 0x772ac8
PointerToRawData 0x770ec8

UNKNOWN

Characteristics 0
TimeDateStamp 2025-Dec-12 16:26:45
Version 0.0
SizeofData 4
AddressOfRawData 0x773014
PointerToRawData 0x771414

TLS Callbacks

StartAddressOfRawData 0x140773040
EndAddressOfRawData 0x140773309
AddressOfIndex 0x1407f8808
AddressOfCallbacks 0x140666f98
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001405C53A0
0x00000001405C5750

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x1407f30c0
GuardCFCheckFunctionPointer 5375422000
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x4b0b1fd0
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
ASM objects (35207) 11
C objects (35207) 19
C objects (35217) 68
C++ objects (35207) 101
C objects (33140) 8
Imports (33140) 13
Total imports 505
ASM objects (35217) 22
C++ objects (LTCG) (35217) 571
Exports (35217) 1
Resource objects (35217) 1
Linker (35217) 1

Errors

Leave a comment

No comments yet.