250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1970-Jan-01 00:00:00
TLS Callbacks 2 callback(s) detected.
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • schtask
May have dropper capabilities:
  • CurrentVersion\Run
Accesses the WMI:
  • root\cimv2
Miscellaneous malware strings:
  • VIRUS
  • exploit
Contains domain names:
  • .eq.golang.org
  • .hash.net
  • GonefilereadopensyncpipeStat.com
  • api.deepseek.com
  • deepseek.com
  • eq.golang.org
  • generativelanguage.googleapis.com
  • golang.org
  • googleapis.com
  • https://api.deepseek.com
  • https://api.deepseek.com/v1/chat/completions\Microsoft\Edge\User
  • https://api.mistral.ai
  • https://api.mistral.ai/v1/chat/completionslooking
  • https://generativelanguage.googleapis.com
  • https://generativelanguage.googleapis.com/v1beta/models/gemini-2.0-flash-exp
  • https://go.dev
  • https://openrouter.ai
  • textproto.nl
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: /4
Unusual section name found: /19
Unusual section name found: /31
Unusual section name found: /45
Unusual section name found: /57
Unusual section name found: /70
Unusual section name found: /81
Unusual section name found: /92
Unusual section name found: /106
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Suspicious The file contains overlay data. 572752 bytes of data starting at offset 0xf1c600.
Malicious VirusTotal score: 39/71 (Scanned on 2026-09-27 13:15:51) AVG: Win64:Malware-gen
AhnLab-V3: Trojan/Win.Agent.C5948636
Antiy-AVL: Trojan/Win32.Agentb
Arcabit: Trojan.ClosedQuorum.1
Avast: Win64:Malware-gen
Avira: TR/W64.Malware
BitDefender: Trojan.ClosedQuorum.1
Bkav: W32.Malware.341705BD
CTX: exe.trojan.closedquorum
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: WinGo/Quorum.B trojan
Emsisoft: Trojan.ClosedQuorum.1 (B)
F-Secure: Trojan.TR/W64.Malware
Fortinet: W32/PossibleThreat
GData: Trojan.ClosedQuorum.1
Google: Detected
Ikarus: Trojan.WinGo.Quorum
Kaspersky: HEUR:Trojan.Win32.Agentb.gen
Kingsoft: Win32.Trojan.Agentb.gen
Lionic: Trojan.Win32.ClosedQuorum.4!c
MaxSecure: Trojan.Malware.722084050.susgen
McAfeeD: Trojan:Win/Goshell.AA
MicroWorld-eScan: Trojan.ClosedQuorum.1
Microsoft: Trojan:Win32/Yomal!rfn
Paloalto: generic.ml
Panda: Trj/PhxBzA.A
Rising: Trojan.Quorum!8.1E1F7 (CLOUD)
Sangfor: Trojan.Win64.Closedquorum.Vwt9
Sophos: Mal/Generic-S
Symantec: Trojan.Gen.MBT
Tencent: Win32.Trojan.Agent.Hdhl
TrellixENS: WinGo/Quorum!6478400A4D00
TrendMicro: Trojan.Win32.YOMAL.USBLIM26
TrendMicro-HouseCall: Trojan.Win32.YOMAL.USBLIM26
VIPRE: Trojan.ClosedQuorum.1
Varist: W64/ABTrojan.RHBT-6163
VirIT: Trojan.Win64.GenPsw.KGH
alibabacloud: Trojan:Multi/Quorum.B

Hashes

MD5 6478400a4d00a8f755df453b47009212 🔍
SHA1 5e5ca8cda7f4640adc125225f4ec19c7ae75c89c 🔍
SHA256 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 🔍
SHA3 9a9517c47de40ff5a51553a1161e8bf81508bff3b78e72e42d2db37f78768d3a 🔍
SSDeep 98304:Q0NtUx3dYibFMGK1E3u6IQIkOI+5mTvEDgbczwnkzv0neYw4epNijyig+iZRBwHn:QAUDYibBKGyWm5mbE0bmAT 🔍
Imports Hash 3e7f59ce70274b512cf1583b61a8e97c 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 20
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0xf1c600
NumberOfSymbols 12619
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x2bf200
SizeOfInitializedData 0x606800
SizeOfUninitializedData 0x56600
AddressOfEntryPoint 0x00000000000014F0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xf7e000
SizeOfHeaders 0x600
Checksum 0xfa83c4
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 65a3fb4a280ca8d1f573c6aa25269d83 🔍
SHA1 5f17b0e17fe28669977bae67a21116bcb641edd6 🔍
SHA256 83f4c59e7771a75581402d2d5fda794d92cf4369b11294fe8d6703004df9ee7a 🔍
SHA3 657422b719922ebae808601f7222e1a603f00bc30eef36990425d4a63a376df4 🔍
VirtualSize 0x2bf160
VirtualAddress 0x1000
SizeOfRawData 0x2bf200
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.21338

.data

MD5 ed9f47714774f26b0b9e755e5d6d6249 🔍
SHA1 982ec530afd98cd77891d16e9af5eb06215869d5 🔍
SHA256 a45d53edd881ec2f78cca1c2b50036f17e278328a4555975244bfcfe070710d1 🔍
SHA3 89e78b8d9d7a1e04903e016ff88e596d1bb502f39fdb7694fa6d3793153626c8 🔍
VirtualSize 0x54980
VirtualAddress 0x2c1000
SizeOfRawData 0x54a00
PointerToRawData 0x2bf800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.89335

.rdata

MD5 7cf3b69c070bb5735caadcadfaab59f4 🔍
SHA1 2a6cc55296864dfa10be6107e5ff1c2e933ab18b 🔍
SHA256 f2d3b452d9ee9b0e35434c07a5bd33a751e21510f1497ab7a70e1717a2f6b459 🔍
SHA3 ef739ebda5a0df71a125164626e219426534e61f5660f6204111e17037f3e408 🔍
VirtualSize 0x2d34c0
VirtualAddress 0x316000
SizeOfRawData 0x2d3600
PointerToRawData 0x314200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.6101

.pdata

MD5 9a6e913adeda6cdeb006fc6fe096be8f 🔍
SHA1 cf2f5cdca8c4266ab7c17a31a572a808c95a6d20 🔍
SHA256 16184bad0524c81311b41f44d1ce490bc9077ef65326d82b47c8c6350aed1d8a 🔍
SHA3 cb0704e7f4cd11314a5bd400b05a714d6bb6be299d063ba18688bcd24f0db759 🔍
VirtualSize 0x101dc
VirtualAddress 0x5ea000
SizeOfRawData 0x10200
PointerToRawData 0x5e7800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.62569

.xdata

MD5 cda2e5f0511d4ca7140de71289b7fbd8 🔍
SHA1 afc0b09bacdc53fbcd90e1d0ae99552d4fd4aab7 🔍
SHA256 33fbba16b2bfa7262b2de9decc6f1d948371da0adbee9c6e42821d46a35a7d9d 🔍
SHA3 6344f3f0032294161c175088d7bca7d17e5334506e11de2de489346090d4178e 🔍
VirtualSize 0x57c
VirtualAddress 0x5fb000
SizeOfRawData 0x600
PointerToRawData 0x5f7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.14518

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x565f0
VirtualAddress 0x5fc000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.edata

MD5 bcfebd4680b5e725fac2f0862857cf27 🔍
SHA1 611520aee79a9806520b6daad4d2bd61984f1dd1 🔍
SHA256 2a83725a91a5f4a8c402c1ff7cc30fd1c33709e45219629e973ae877b3ce310c 🔍
SHA3 2f56a54158cef16d8549f059313556582807f5960e76904343d20a0042dac78c 🔍
VirtualSize 0x4e
VirtualAddress 0x653000
SizeOfRawData 0x200
PointerToRawData 0x5f8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.818927

.idata

MD5 ad1f089a358bcdd1057a168d930a5a22 🔍
SHA1 30b533a9d9133b6295165b9e9c971480cca16377 🔍
SHA256 db06fb8ef85b26a14f534fc7842c40569a3b56530f952625d0b2fb85d1631647 🔍
SHA3 36b67748190da2c8d3dee902dfe8899b8f0bf83ad9374942e0d8f409dbc7345c 🔍
VirtualSize 0xe70
VirtualAddress 0x654000
SizeOfRawData 0x1000
PointerToRawData 0x5f8200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.08307

.CRT

MD5 14183398bfa0b1240b2afcffb8df255a 🔍
SHA1 5eb1d810a12324592a83080776caba4103ef3286 🔍
SHA256 66d63e0b92c7ea815222a5c11a22749cbb8ea2528641bfc92eb6607419e84238 🔍
SHA3 64849bdf73799ab95ef50ea78f3039441375a0e222b11984903b1fd7f6c58804 🔍
VirtualSize 0x68
VirtualAddress 0x655000
SizeOfRawData 0x200
PointerToRawData 0x5f9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.39218

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x10
VirtualAddress 0x656000
SizeOfRawData 0x200
PointerToRawData 0x5f9400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 ff6988e2c509a4a1da6ca9d686d21509 🔍
SHA1 d8cb3435c14e2898ee75a652a85c5dae81268ce7 🔍
SHA256 956953481de0eafeb8f14afcdebeabe1fdae88d4affd1bf1e34eafe943c31e35 🔍
SHA3 76131932858bf963d6c00e5e071f1ff4c6cb5f134a1efbc4b9fee44a433e5b46 🔍
VirtualSize 0xd7d8
VirtualAddress 0x657000
SizeOfRawData 0xd800
PointerToRawData 0x5f9600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43431

/4

MD5 86967755b93a71970fc6ad9c6a9dd30d 🔍
SHA1 504522ddbea6ca854f10235d33e7e4d22177f672 🔍
SHA256 7827dc103f39d34da831afc328bb1fdfd8d05a2e52c2e2872aa18c005b8ba346 🔍
SHA3 03a1f72c087ba1f99783cc095d63d98ef2b1e723468a650ec3e171f21774cbe8 🔍
VirtualSize 0x820
VirtualAddress 0x665000
SizeOfRawData 0xa00
PointerToRawData 0x606e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.7767

/19

MD5 660a30c6e307ca7fc9bde1d37920a7ca 🔍
SHA1 be99475b280b09b07ecf6f4f0fb55cda6c494c6c 🔍
SHA256 7a3cd9bcc4446bc73e1602641d69458958bf5f5afc2cc820fee98ccd96e0d193 🔍
SHA3 da5e9716c650a82e348a02a832042c65a85de715fc5ed8828333768b61aa7ba8 🔍
VirtualSize 0x32b2df
VirtualAddress 0x666000
SizeOfRawData 0x32b400
PointerToRawData 0x607800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.35698

/31

MD5 73db729cd6038fd690c6aaddb08d3f70 🔍
SHA1 2ad06b6a8fa0876f4dd5f45597c7f5c7b4cde4d8 🔍
SHA256 1b9f2ad10ed3023e5e2764b212fcea184fafd2c2655ebd7e2bedf3aea89cf84a 🔍
SHA3 f362de7ea52b5b613bc9278447f50a015ce434f332abec1e6efa391f47ed4092 🔍
VirtualSize 0x453d
VirtualAddress 0x992000
SizeOfRawData 0x4600
PointerToRawData 0x932c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.73311

/45

MD5 0a978f16b60435d58f060ca3e77ef089 🔍
SHA1 aaf5ad95a3cce48c6200d2071968abbc46cafda4 🔍
SHA256 a141b9e4fd4098a3ee2fc114d0d2800404591a167e81d9aed5d7a499a5367353 🔍
SHA3 ea781e69651c73020743a34ad1debab06f5e181d1f101ac790fd8ddc07309049 🔍
VirtualSize 0xfbe7e
VirtualAddress 0x997000
SizeOfRawData 0xfc000
PointerToRawData 0x937200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.01878

/57

MD5 23b9ac3432302e87ce2d0e58189df47b 🔍
SHA1 09480032a9e92bd7c65d074f4b6335faf82324e7 🔍
SHA256 592945c6f6925f3fd76aeddf5d5a23141df57dbeb72510699f4b1f5f58b12be5 🔍
SHA3 e79135155a48f6a3c5bd2fc32f7c6beead21fd3fff6326d78e9cdaabfd1ecee8 🔍
VirtualSize 0x51ff8
VirtualAddress 0xa93000
SizeOfRawData 0x52000
PointerToRawData 0xa33200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.30669

/70

MD5 72876d24a4a9f8bbe068de8928ad2d80 🔍
SHA1 b04b9c8f396da3edd9df98d0d232ac9e25c57432 🔍
SHA256 9c7618f983ca17b95ca6db07feed09395a82830acfe7e4a401940db64f6997d5 🔍
SHA3 9f27b363c459a2f553ddeb050e39726f531764b808bfa26db188e4eeeebaf1e9 🔍
VirtualSize 0xa24
VirtualAddress 0xae5000
SizeOfRawData 0xc00
PointerToRawData 0xa85200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.48209

/81

MD5 9a6dae77119f3fc29edd7281247b900c 🔍
SHA1 e2cd6192edd4fba86268b300a2e5fc56a147324d 🔍
SHA256 7f9afd1e538bc72f8670ad1f03b65f41b431659fa01a0c12825207d536315ac5 🔍
SHA3 36f761502eb256421f9d721e53ba2079c787eec67c57fde5410b6f1787b9e90a 🔍
VirtualSize 0x38afeb
VirtualAddress 0xae6000
SizeOfRawData 0x38b000
PointerToRawData 0xa85e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.95338

/92

MD5 cb01b1e6910f7ee3ee6161b702dd7a04 🔍
SHA1 8042dcf8333d782216377bef7557c0e8b691e638 🔍
SHA256 4fb3d783fc66eeb0f9e64c8ea4ac9e3adf42b04251dd79aa355e77be695239a9 🔍
SHA3 ae41144e3bd83709f30ba8a6f9402af655fbc2d05378188a540ca6705eac9dfe 🔍
VirtualSize 0x10b500
VirtualAddress 0xe71000
SizeOfRawData 0x10b600
PointerToRawData 0xe10e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.34983

/106

MD5 56d08c10aa9e5c0c3680f67f8992b3d4 🔍
SHA1 5c31bb8cb4724831186f4adf11b6a46cba1b7936 🔍
SHA256 3edf472b3815ca8cab6b3efd8773b22c8a567a0ec7f5ce7b1a9b30e2a22b0258 🔍
SHA3 0e65aaf1cebf5c5fcda0ebafc01834bf7378c916495ab10752a8a034209a6034 🔍
VirtualSize 0x2a
VirtualAddress 0xf7d000
SizeOfRawData 0x200
PointerToRawData 0xf1c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.73721

Imports

KERNEL32.dll AddVectoredContinueHandler
AddVectoredExceptionHandler
CloseHandle
CreateEventA
CreateIoCompletionPort
CreateThread
CreateWaitableTimerExW
DeleteCriticalSection
DuplicateHandle
EnterCriticalSection
ExitProcess
FreeEnvironmentStringsW
GetConsoleMode
GetCurrentThreadId
GetEnvironmentStringsW
GetErrorMode
GetLastError
GetProcAddress
GetProcessAffinityMask
GetQueuedCompletionStatusEx
GetStartupInfoA
GetStdHandle
GetSystemDirectoryA
GetSystemInfo
GetThreadContext
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
LoadLibraryExW
LoadLibraryW
MultiByteToWideChar
PostQueuedCompletionStatus
RaiseFailFastException
ResumeThread
SetConsoleCtrlHandler
SetErrorMode
SetEvent
SetProcessPriorityBoost
SetThreadContext
SetUnhandledExceptionFilter
SetWaitableTimer
Sleep
SuspendThread
SwitchToThread
TlsAlloc
TlsGetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WerGetFlags
WerSetFlags
WideCharToMultiByte
WriteConsoleW
WriteFile
__C_specific_handler
msvcrt.dll ___lc_codepage_func
___mb_cur_max_func
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_beginthread
_cexit
_commode
_errno
_fmode
_initterm
_lock
_onexit
_unlock
abort
calloc
exit
fprintf
fputc
free
fwrite
localeconv
malloc
memcpy
signal
strerror
strlen
strncmp
vfprintf
wcslen
ntdll.dll RtlLookupFunctionEntry
RtlVirtualUnwind

Delayed Imports

_cgo_dummy_export

Ordinal 1
Address 0x6519f0

Version Info

TLS Callbacks

StartAddressOfRawData 0x140656000
EndAddressOfRawData 0x140656008
AddressOfIndex 0x1406524ac
AddressOfCallbacks 0x140655040
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x00000001402BE9A0
0x00000001402BE970

Load Configuration

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /19! [*] Warning: Tried to read outside the COFF string table to get the name of section /31! [*] Warning: Tried to read outside the COFF string table to get the name of section /45! [*] Warning: Tried to read outside the COFF string table to get the name of section /57! [*] Warning: Tried to read outside the COFF string table to get the name of section /70! [*] Warning: Tried to read outside the COFF string table to get the name of section /81! [*] Warning: Tried to read outside the COFF string table to get the name of section /92! [*] Warning: Tried to read outside the COFF string table to get the name of section /106! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF String Table's reported size is bigger than the remaining bytes! [*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.