1596e5b0cc74f2cf623303907ac09956a8b8adb2244873fbe67adf65d88caf03

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-18 00:00:50
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • github.com
  • http://127.0.0.1
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://curl.se
  • https://github.com
  • https://imtheo.lol
  • https://indiantypefoundry.comNinad
  • https://lrclib.net
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • lrclib.net
  • rbxcdn.com
  • roblox.com
  • scripts.sil.org
  • thumbnails.roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
  • CheckRemoteDebuggerPresent
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegCloseKey
  • RegQueryValueExA
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryW
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptHashData
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualProtectEx
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpQueryHeaders
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpSetTimeouts
  • WinHttpQueryDataAvailable
  • WinHttpConnect
  • InternetOpenA
  • InternetOpenUrlA
  • InternetCloseHandle
  • InternetReadFile
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • Process32First
  • Process32Next
  • OpenProcess
  • Process32NextW
  • Process32FirstW
  • ReadProcessMemory
  • WriteProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 11/71 (Scanned on 2026-08-18 00:53:28) APEX: Malicious
CrowdStrike: win/malicious_confidence_90% (D)
ESET-NOD32: Win64/Riskware.GameHack.BO application
Elastic: malicious (high confidence)
Google: Detected
Ikarus: Trojan.Win64.Krypt
Microsoft: Trojan:Win32/Phonzy.B!ml
Rising: Trojan.Kryptik@AI.86 (RDML:+dS/R+m1U17YB4CzpLwkfw)
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
huorong: Trojan/Agent.cfs

Hashes

MD5 d10c2abfa8e967505ad076e845ebd294 🔍
SHA1 ba93caff66b97f836129157c346067d7bb2ca9a1 🔍
SHA256 1596e5b0cc74f2cf623303907ac09956a8b8adb2244873fbe67adf65d88caf03 🔍
SHA3 0ea74ff67d96f275e0366fb64364adf6ab4c03ff76632516b8b89e208b0197d3 🔍
SSDeep 98304:5WB223mEC+ts8TvWS6k0pLM5KgJy7SlG:WmYTvWS6k0pLM5f9l 🔍
Imports Hash c419a4df1525bdfccabce328c6f45906 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-18 00:00:50
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x242e00
SizeOfInitializedData 0x1ac200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000224AA0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3f4000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9d145a026380e40423fd0ab342e8ad17 🔍
SHA1 7da621e233c11669dd59b82303de103d72968746 🔍
SHA256 7544d7bd586cb09feeccb8b28d74706908f013e12a046e10985819a2e732f282 🔍
SHA3 573a1557b2334e4f543a114c4ff3e0319cecfbff2cb78a062a26cf4ac91d7330 🔍
VirtualSize 0x242de8
VirtualAddress 0x1000
SizeOfRawData 0x242e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50587

.rdata

MD5 4085b125b9637301339e8228eff3db7c 🔍
SHA1 2d4ad1ca3c75e130d731ec2c83fc4a454e3615a2 🔍
SHA256 23396c09d2739cdeb496f421862b8031f5caed4d3d68d7ed72056a41c4115d9d 🔍
SHA3 3ab12c5ce97e69cfabf7a4c5b642bce55ebe4d71aedea8c5b61234f0d1e5b6b0 🔍
VirtualSize 0x1232e8
VirtualAddress 0x244000
SizeOfRawData 0x123400
PointerToRawData 0x243200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.84287

.data

MD5 31cfc696af013c2afe88bf4b65d68868 🔍
SHA1 00375ba9a464eac1e1e30f18c82dc02848ce769b 🔍
SHA256 fa1156c31c41a4bfb47e0ab6927476cd102748e08b2557699ed47b3c63512d00 🔍
SHA3 0216c056d3139cef108ef598c19f2d5bd570f75c2fc4fc706ef4041f74656769 🔍
VirtualSize 0x70200
VirtualAddress 0x368000
SizeOfRawData 0x2f200
PointerToRawData 0x366600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.55805

.pdata

MD5 cb72b33f37c5ac7c28a5dd64ce0ea4fc 🔍
SHA1 c9aa69809288539874fd3597c5ab40ec25c0a7c9 🔍
SHA256 b2aa81ab5cd7d27bc889162b872f965320ecd66885f814faa2c6ed4a06404014 🔍
SHA3 47c1952f3182cc603a946740cd93dba4201a4d2eb5a3e4bf95015d3309a94a1d 🔍
VirtualSize 0x1668c
VirtualAddress 0x3d9000
SizeOfRawData 0x16800
PointerToRawData 0x395800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.27059

.rsrc

MD5 3a264634321ff905c43ec34d1643bdd3 🔍
SHA1 a765cb547706a846486396e3809f336ef1d8d271 🔍
SHA256 8f910d3f60597280ee420be6f6af8744467ca116301058f497425159a7b4c23f 🔍
SHA3 78aa879379be4c9054cdd149c9b4fa8671b9250e4c1486c3ca7bfc8bc805282a 🔍
VirtualSize 0x1e0
VirtualAddress 0x3f0000
SizeOfRawData 0x200
PointerToRawData 0x3ac000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.69612

.reloc

MD5 7eb3c02afa28d7030511cc4cede470f4 🔍
SHA1 b7b1bc290f9b1538e59f569bdb4e389f01dddcd6 🔍
SHA256 75ea6f1d2d378198e10ac62685498a864c338d1c9bdff9e05381030ca1aecb19 🔍
SHA3 d435003d9d42052e550a9d6ee8e6fd33ebaabf3e1ca7714d2ef539ff7ad1acb0 🔍
VirtualSize 0x2124
VirtualAddress 0x3f1000
SizeOfRawData 0x2200
PointerToRawData 0x3ac200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4233

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
WINHTTP.dll WinHttpOpenRequest
WinHttpReadData
WinHttpOpen
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpCloseHandle
WinHttpSendRequest
WinHttpSetTimeouts
WinHttpQueryDataAvailable
WinHttpConnect
WININET.dll InternetOpenA
InternetOpenUrlA
InternetCloseHandle
InternetReadFile
D3DCOMPILER_47.dll D3DCompile
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleA
GetModuleFileNameA
GetProcAddress
GetModuleHandleW
LoadLibraryExW
FreeLibrary
api-ms-win-core-localization-l1-2-0.dll FormatMessageA
GetLocaleInfoEx
FormatMessageW
GetLocaleInfoA
api-ms-win-core-string-l1-1-0.dll WideCharToMultiByte
MultiByteToWideChar
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
LoadLibraryA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-sysinfo-l1-2-0.dll VerSetConditionMask
GetSystemTimePreciseAsFileTime
api-ms-win-core-heap-l2-1-0.dll GlobalFree
GlobalAlloc
LocalFree
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalLock
GlobalUnlock
api-ms-win-core-sysinfo-l1-1-0.dll GetTickCount
GetTickCount64
GetSystemTimeAsFileTime
GetSystemInfo
GetSystemDirectoryW
api-ms-win-core-kernel32-legacy-l1-1-2.dll Process32First
Process32Next
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
OpenProcess
FlushInstructionCache
api-ms-win-core-toolhelp-l1-1-0.dll CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
api-ms-win-core-synch-l1-2-0.dll SleepConditionVariableSRW
InitOnceComplete
Sleep
InitOnceBeginInitialize
WakeAllConditionVariable
api-ms-win-core-psapi-ansi-l1-1-0.dll QueryFullProcessImageNameA
K32GetModuleFileNameExA
api-ms-win-core-handle-l1-1-0.dll DuplicateHandle
CloseHandle
api-ms-win-ntuser-sysparams-l1-1-0.dll GetSystemMetrics
api-ms-win-core-console-l3-2-0.dll GetConsoleWindow
api-ms-win-core-memory-l1-1-0.dll VirtualProtect
VirtualProtectEx
VirtualAllocEx
ReadProcessMemory
VirtualFreeEx
VirtualQueryEx
WriteProcessMemory
VirtualQuery
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
SwitchToThread
SetThreadPriority
GetProcessId
GetCurrentThreadId
OpenProcessToken
TerminateProcess
GetCurrentThread
GetCurrentProcessId
ExitProcess
api-ms-win-core-processenvironment-l1-1-0.dll GetEnvironmentVariableA
GetStdHandle
GetCommandLineA
api-ms-win-core-console-l1-1-0.dll SetConsoleMode
GetConsoleMode
api-ms-win-core-file-l1-2-2.dll AreFileApisANSI
GetVolumeInformationA
api-ms-win-core-debug-l1-1-0.dll IsDebuggerPresent
OutputDebugStringW
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
RegQueryValueExA
RegOpenKeyExA
api-ms-win-core-processtopology-obsolete-l1-1-0.dll SetThreadAffinityMask
api-ms-win-mm-time-l1-1-0.dll timeGetTime
timeBeginPeriod
api-ms-win-core-errorhandling-l1-1-0.dll GetLastError
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
api-ms-win-core-com-l1-1-0.dll CoInitializeEx
CoUninitialize
CoCreateFreeThreadedMarshaler
CoCreateInstance
api-ms-win-security-lsalookup-ansi-l2-1-0.dll LookupPrivilegeValueA
api-ms-win-security-base-l1-1-0.dll AdjustTokenPrivileges
KERNEL32.dll CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
GetProcessHeap
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
Module32First
Module32Next
K32EnumProcessModulesEx
USER32.dll GetDesktopWindow
ShowCursor
mouse_event
keybd_event
MapVirtualKeyA
SendInput
SetWindowTextA
GetWindowThreadProcessId
GetWindowTextLengthW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
CreateWindowExW
UnregisterClassW
GetClassNameA
RegisterClassExW
ShowWindow
IsWindow
SetWindowLongA
SetWindowDisplayAffinity
GetMonitorInfoA
MoveWindow
EnumWindows
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
FindWindowA
UpdateWindow
IsIconic
GetWindowTextW
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
MonitorFromWindow
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
PostQuitMessage
GDI32.dll GetDeviceCaps
CreateSolidBrush
SHELL32.dll SHGetFolderPathA
ShellExecuteA
MSVCP140.dll ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
_Thrd_hardware_concurrency
_Cnd_signal
_Cnd_wait
_Cnd_register_at_thread_exit
?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Cnd_broadcast
_Thrd_join
_Thrd_id
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Random_device@std@@YAIXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_function_call@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
_Mtx_unlock
_Query_perf_counter
_Mtx_lock
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
??1_Facet_base@std@@UEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
??0facet@locale@std@@IEAA@_K@Z
??1facet@locale@std@@MEAA@XZ
?tolower@?$ctype@D@std@@QEBADD@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
_Strcoll
??_7facet@locale@std@@6B@
?id@?$collate@D@std@@2V0locale@2@A
?id@?$ctype@D@std@@2V0locale@2@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Strxfrm
??_7_Facet_base@std@@6B@
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?uncaught_exceptions@std@@YAHXZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
CRYPT32.dll CertFreeCertificateChain
CryptStringToBinaryW
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertGetNameStringW
CertFreeCertificateContext
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
WS2_32.dll __WSAFDIsSet
WSAIoctl
socket
setsockopt
recv
htons
getsockname
getpeername
connect
sendto
inet_ntop
WSASetLastError
select
inet_pton
WSAGetLastError
closesocket
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
ioctlsocket
gethostname
accept
htonl
recvfrom
getaddrinfo
ntohs
freeaddrinfo
bind
listen
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __current_exception
wcschr
_CxxThrowException
memcmp
memchr
memset
memmove
__current_exception_context
longjmp
strrchr
_purecall
__C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
__intrinsic_setjmp
memcpy
api-ms-win-crt-runtime-l1-1-0.dll _invalid_parameter_noinfo_noreturn
_invalid_parameter_noinfo
abort
exit
terminate
_configure_narrow_argv
_beginthreadex
__sys_errlist
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
system
_errno
_get_initial_narrow_environment
_initterm
_invoke_watson
_initterm_e
_c_exit
__p___argv
__p___argc
__sys_nerr
_exit
api-ms-win-crt-math-l1-1-0.dll sinf
powf
__setusermatherr
pow
logf
_fdopen
roundf
fmodf
_dclass
_fdclass
acosf
asinf
ldexp
lroundf
atan2f
ceilf
sqrtf
sqrt
cosf
_dsign
floorf
api-ms-win-crt-string-l1-1-0.dll strcmp
strncmp
toupper
strcspn
wcspbrk
iswspace
isalnum
_stricmp
_wcsicmp
wcsncmp
strpbrk
wcsncpy
strcpy_s
tolower
strncpy
_strdup
strspn
api-ms-win-crt-convert-l1-1-0.dll strtol
strtof
strtoull
strtoll
strtod
atoi
wcstombs
atof
strtoul
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
fflush
fclose
ungetc
setvbuf
fgetpos
__p__commode
fgetc
_read
_write
_fileno
_close
fseek
_set_fmode
__stdio_common_vfprintf
fputc
__stdio_common_vsprintf_s
fsetpos
_lseeki64
_fseeki64
_get_stream_buffer_pointers
__stdio_common_vsscanf
_wopen
fwrite
fread
fputs
__stdio_common_vsprintf
_wfopen
ftell
feof
fgets
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
malloc
_callnewh
free
calloc
realloc
api-ms-win-crt-time-l1-1-0.dll _gmtime64
strftime
_time64
_localtime64
api-ms-win-crt-filesystem-l1-1-0.dll _wstat64
_unlock_file
_fstat64
remove
_unlink
_lock_file
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
_configthreadlocale
localeconv
api-ms-win-core-file-l1-1-0.dll GetFileType
FindNextFileW
FindClose
FindFirstFileExW
CreateFileW
GetFileAttributesExW
SetFileInformationByHandle
FindFirstFileW
CreateDirectoryW
api-ms-win-core-synch-l1-1-0.dll DeleteCriticalSection
AcquireSRWLockShared
WaitForSingleObjectEx
ReleaseSRWLockExclusive
WaitForSingleObject
EnterCriticalSection
SleepEx
CreateEventW
SetEvent
LeaveCriticalSection
InitializeCriticalSectionEx
AcquireSRWLockExclusive
ReleaseSRWLockShared
InitializeCriticalSection
api-ms-win-core-file-l2-1-0.dll GetFileInformationByHandleEx
MoveFileExW
api-ms-win-security-cryptoapi-l1-1-0.dll CryptReleaseContext
CryptAcquireContextW
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptGetHashParam
CryptDestroyHash
CryptHashData
api-ms-win-core-namedpipe-l1-1-0.dll PeekNamedPipe
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-core-kernel32-legacy-l1-1-1.dll VerifyVersionInfoW
api-ms-win-security-systemfunctions-l1-1-0.dll SystemFunction036
api-ms-win-core-rtlsupport-l1-1-0.dll RtlLookupFunctionEntry
RtlVirtualUnwind
RtlCaptureContext
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
InterlockedPushEntrySList
OLEAUT32.dll SetErrorInfo
SysFreeString
SysStringLen
GetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-18 00:00:50
Version 0.0
SizeofData 912
AddressOfRawData 0x32ffb8
PointerToRawData 0x32f1b8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-18 00:00:50
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140330370
EndAddressOfRawData 0x140330440
AddressOfIndex 0x1403978e0
AddressOfCallbacks 0x140245798
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140368f40

RICH Header

XOR Key 0xaa05c3dc
Unmarked objects 0
253 (35207) 8
C objects (35207) 10
C++ objects (35207) 42
ASM objects (35207) 6
Imports (35207) 8
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 123
C++ objects (34436) 5
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (VS2008 SP1 build 30729) 136
Imports (33145) 32
Imports (21202) 3
Total imports 707
C++ objects (LTCG) (35228) 81
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.