1dd5c8789ec7f68ebcf19c93faed3baa9a937e07ca0334ee05605c24124818ec

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Aug-19 04:39:28
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName Loader
FileDescription Loader
FileVersion 1.0.0.0
InternalName Loader.dll
LegalCopyright
OriginalFilename Loader.dll
ProductName Loader
ProductVersion 1.0.0+48419c348e8295db624caeef4e44f6bc0c051390
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 22fccdbb512bfcf542f4a918031c71f1
SHA1 8614c4b252679498cfc68e304b4a98fc0447b0da
SHA256 1dd5c8789ec7f68ebcf19c93faed3baa9a937e07ca0334ee05605c24124818ec
SHA3 775876db66b67a7d4a5e0908a5edff67f09329fc68a8e9d3265374e239d83471
SSDeep 3072:iqvmgiYSo4k8uIPzlSRwa/dB26dQIg+xpe4ZebKCm3N0O7uWgFhKu8DPnXxgo4a:i6ok83LlMvDEIgmqKdNFshxeyo4
Imports Hash bb3ac2c21e02c68abcad237dc3fa6d00

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Aug-19 04:39:28
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x16400
SizeOfInitializedData 0x27600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000011AB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x42000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3ed5512b293aa5ccb14a2730a5a29785
SHA1 df85598271374ab44b618dd3406484df92cd74ce
SHA256 b55ea7f36007bb04f989c752a29e245bead9bdfc3913702e9f05cc1b26272d3e
SHA3 eac0d6142726512bc274619ea3ba58da9a701cbd4d73d4a2d5ed47b15533630a
VirtualSize 0x1627c
VirtualAddress 0x1000
SizeOfRawData 0x16400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.34417

.rdata

MD5 5fea80c7facfecc8cbcdca53b92a2c86
SHA1 48a5957ac4ae6dcfd7d72f8d0cf29cf0d97d0db2
SHA256 d5aa72239282b7d3e8e2ff9aad874ffda3e0e2fcb4975f24b080e4cc20801300
SHA3 03b8ae92cb4dd19bc1ff5066a14dc925cf7c0afdfac90293ffb33c239ff17473
VirtualSize 0xbd1e
VirtualAddress 0x18000
SizeOfRawData 0xbe00
PointerToRawData 0x16800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.83263

.data

MD5 dd99907ff175b57ef1cf305faf5f6778
SHA1 3f8906caeeb26b6d18bf817a176275c5a25f31b4
SHA256 34374ae003003f4b01e83cefb46e638785b0ae1abef8d9da90eae7b688b963a0
SHA3 1cf0acd2cacd8b2a97bb5d607fab0beefb96da537f5ff214a9b125d022b3083d
VirtualSize 0x1838
VirtualAddress 0x24000
SizeOfRawData 0xa00
PointerToRawData 0x22600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.36662

.pdata

MD5 c20628de244b4ad26d738fc5023ef5c1
SHA1 c4b6e73956dda9cc2bfc4b9f53d3cc6e8b6181be
SHA256 26d28ab08308ebbe19dea4673b4bd8cd46120a4826971710fa82c36ef53f389e
SHA3 d76843777bf9942d2219f35c7159ac599bcae19ec5b1fe5d9dc464b35914811a
VirtualSize 0x141c
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x23000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84522

.reloc

MD5 37812f81534460a128d06d0d29b2cb00
SHA1 8dcae4bb04c6e5e5d5a68d9e1d0bdc85c923ad95
SHA256 7d1932eae9901ec74760eb2c44a2df4a20f3a8bfb1a595db5dd20e43af7c73cf
SHA3 fa934fd7324404a9d4dd0c78dee6a4cbae71cf80f9cf2820ab6a74fe3716a019
VirtualSize 0x338
VirtualAddress 0x28000
SizeOfRawData 0x400
PointerToRawData 0x24600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80573

.rsrc

MD5 22783faf14594a29974b733fb0af33f0
SHA1 20db84d6089848b674a2730607ac3dc2e675a2a6
SHA256 7ec9f60eb2a7b3cab59a2edca15baf6490a605ea2076b4bb6b265bc3a5f9f7af
SHA3 85337a0599fad9f8ca3cfe6b74116ca905f50645062b2dc27639c545ad6931f2
VirtualSize 0x182b8
VirtualAddress 0x29000
SizeOfRawData 0x18400
PointerToRawData 0x24a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.98332

Imports

KERNEL32.dll FreeLibrary
LoadLibraryExW
OutputDebugStringW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
GetModuleHandleW
MultiByteToWideChar
GetFileAttributesExW
LoadLibraryA
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetProcAddress
GetWindowsDirectoryW
FindResourceW
GetLastError
ActivateActCtx
FindClose
CreateActCtxW
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
__p___argc
_exit
exit
_initterm_e
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_errno
_initialize_onexit_table
abort
_c_exit
_register_thread_local_exe_atexit_callback
terminate
__p___wargv
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
_set_fmode
fputwc
__p__commode
fputws
_wfsopen
fflush
__stdio_common_vfwprintf
__stdio_common_vsnwprintf_s
__stdio_common_vswprintf
setvbuf
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
free
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll wcsncmp
toupper
strcmp
strlen
_wcsdup
wcsnlen
strcpy_s
api-ms-win-crt-convert-l1-1-0.dll wcstoul
_wtoi
api-ms-win-crt-time-l1-1-0.dll wcsftime
_gmtime64_s
_time64
api-ms-win-crt-locale-l1-1-0.dll ___mb_cur_max_func
_configthreadlocale
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_lock_locales
setlocale
_unlock_locales
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x17c65
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99465
Detected Filetype PNG graphic file
MD5 680d5608598f4812554ca6d5302e3555
SHA1 ec38f7ea30e777228b6dc44578d8528619380f1e
SHA256 1046a9a0d4dd64bd04993b745ffd24c775d42d079216945b5e96d1bbb65072e1
SHA3 bf73c28a702013372bd6835122b6be6e3301475454e72f00d393772f6b753f6a

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.59047
Detected Filetype Icon file
MD5 fd21531a75af0ec6d21ad72302f705f8
SHA1 677a8a876b57630c9d25365fcbaf669d6863ef8a
SHA256 fbe1192f24389070b4c42a8c8a6d06cf66dcd1f26ab525380afb2f1e8f31bf5a
SHA3 2f92c9930d89266f5140e05c43b6da173c13a092978f4b95e0f970c1cc6a3aba

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28185
MD5 2f20b22fca23ad1b08a4474f7e364462
SHA1 b45d193b99f20e27ebdbe001f3bd0a5dc84e1953
SHA256 8c17d6bd082043c6a284cb10426e76fce6316f5c245723101227e6d6b1f58b39
SHA3 469448c686586be982548b5d1605bc6d7b5189b38b14514ca04ee8362752cbe2

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x20b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.07094
MD5 1086c1f08ac7ea2009322c8d0a48b93c
SHA1 a808cd801b2e15c9d647345b6ab4154fe6130a52
SHA256 815aa8c08c8c764dc60314f5763179c3b6959cdf24633fec548a730371137462
SHA3 df8a14568b785fbc18b61de9610eef8991ae5d6f7b630ffc2f336e9b4c50b9ac

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Loader
FileDescription Loader
FileVersion (#2) 1.0.0.0
InternalName Loader.dll
LegalCopyright
OriginalFilename Loader.dll
ProductName Loader
ProductVersion (#2) 1.0.0+48419c348e8295db624caeef4e44f6bc0c051390
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Aug-19 22:21:14
Version 0.0
SizeofData 109
AddressOfRawData 0x2079c
PointerToRawData 0x1ef9c
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Aug-19 22:21:14
Version 0.0
SizeofData 20
AddressOfRawData 0x2080c
PointerToRawData 0x1f00c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Aug-19 22:21:14
Version 0.0
SizeofData 988
AddressOfRawData 0x20820
PointerToRawData 0x1f020

TLS Callbacks

StartAddressOfRawData 0x140020c48
EndAddressOfRawData 0x140020c58
AddressOfIndex 0x140025820
AddressOfCallbacks 0x1400184f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024080
GuardCFCheckFunctionPointer 5368808480
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x55c562a4
Unmarked objects 0
ASM objects (35207) 10
C objects (35207) 12
C++ objects (35207) 87
Imports (VS2008 SP1 build 30729) 16
Imports (33140) 9
Total imports 204
C++ objects (LTCG) (35209) 10
Linker (35209) 1

Errors

Leave a comment

No comments yet.