2a7afe1452827ab49abd05974f73a2c769dc4646d83a620af108993d50602944

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-03 05:48:47
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts C:\Users\rukia\Downloads\37f17kx\gameseks\..\bin\nexoriabeta.pdb

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • acutedotcomb.cn
  • breveacutecomb.cn
  • brevegravecomb.cn
  • brevehookcomb.cn
  • brevetildecomb.cn
  • carondotcomb.cn
  • circumflexacutecomb.cn
  • circumflexgravecomb.cn
  • circumflexhookcomb.cn
  • circumflextildecomb.cn
  • commaaccentright.cn
  • commaaccentrotate.cn
  • cyrillictail.cn
  • cyrillictic.cn
  • demon.nl
  • dieresisacutecomb.cn
  • dieresiscaroncomb.cn
  • dieresisgravecomb.cn
  • dieresismacroncomb.cn
  • dotmacroncomb.cn
  • github.com
  • google.com
  • http://www.google.com
  • http://www.google.com/get/noto/Monotype
  • http://www.josbuivenga.demon.nl
  • http://www.josbuivenga.demon.nlMuseo
  • http://www.monotype.com
  • http://www.monotype.com/studiohttp
  • http://www.sansoxygen.comVernon
  • http://www.w3.org
  • http://www.w3.org/2000/svg
  • https://github.com
  • https://msdl.microsoft.com
  • https://msdl.microsoft.com/download/symbols
  • https://openfontlicense.orgThis
  • https://openfontlicense.orghttp
  • https://openfontlicense.orghttps
  • https://rsms.me
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttp
  • https://scripts.sil.org/OFLhttps
  • josbuivenga.demon.nl
  • macrondieresiscomb.cn
  • microsoft.com
  • monotype.com
  • msdl.microsoft.com
  • ringacute.cn
  • scripts.sil.org
  • tildecross.cn
  • tildedieresiscomb.cn
  • tildemacroncomb.cn
  • tonos.top
  • uni02E5.cn
  • uni02E6.cn
  • uni02E7.cn
  • uni02E8.cn
  • uni02E9.cn
  • uni1DC4.cn
  • uni1DC6.cn
  • www.google.com
  • www.josbuivenga.demon.nl
  • www.monotype.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses known Mersenne Twister constants
Suspicious The PE is possibly packed. Unusual section name found: _addr
Unusual section name found: _guard_c
Unusual section name found: _guard_d
Unusual section name found: memcmp_
Unusual section name found: memcpy_
Unusual section name found: memset_
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowA
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyA
  • MapVirtualKeyW
Manipulates other processes:
  • ReadProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 12/71 (Scanned on 2026-09-03 13:56:37) ALYac: Gen:Variant.Application.Lazy.8054
Arcabit: Trojan.Application.Lazy.D1F76
BitDefender: Gen:Variant.Application.Lazy.8054
CTX: dll.unknown.lazy
Cynet: Malicious (score: 100)
ESET-NOD32: Win64/GameHack.ND potentially unsafe application
Emsisoft: Gen:Variant.Application.Lazy.8054 (B)
GData: Gen:Variant.Application.Lazy.8054
Google: Detected
Ikarus: Trojan.Win64.Krypt
MicroWorld-eScan: Gen:Variant.Application.Lazy.8054
VIPRE: Gen:Variant.Application.Lazy.8054

Hashes

MD5 e7ab688d7115529debaa3649b39fb183 🔍
SHA1 aabf77f96fa4f509a728c8fbaf80bc853e87e43e 🔍
SHA256 2a7afe1452827ab49abd05974f73a2c769dc4646d83a620af108993d50602944 🔍
SHA3 9f1f650e7e605348fcdf79d29b18a932779a6e2f2d9abeb2369e9d00ec9b369b 🔍
SSDeep 98304:spI6gcUcKaSeruvfxdMIr5uBX+GlTE7d83j/z:EU9IIrm++3z/z 🔍
Imports Hash a4ff5e9b4c121782e6d728acc2ecb08e 🔍

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 15
TimeDateStamp 2026-Sep-03 05:48:47
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x476400
SizeOfInitializedData 0x48a400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000001A5EA0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x929000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6e1644ac8fd84aa01ae3e587f5da8184 🔍
SHA1 331e1f6d803d577ed3c6c693f6d2faeb9f5551de 🔍
SHA256 b55d3d2f93563d1715d8727897e18f3e733ae2490423744aad36836d7d059ca9 🔍
SHA3 c0f04204561001eca32bb38cdc6b6d7cd467b586a4dbf20799c7e911acf6597d 🔍
VirtualSize 0x4763f6
VirtualAddress 0x1000
SizeOfRawData 0x476400
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49072

.rdata

MD5 bbcca8809dfb277ea5115297e381f7d7 🔍
SHA1 a0aa5dd2d53609ea93a9077d8772addb87d6f9f2 🔍
SHA256 e457f590e26a9503708a1241b5826cc9efb23d1d45bd61b7df70110a47ea5df1 🔍
SHA3 5f11762db29630817f9737ffa1dd45a56e142f272b92f436bbce8cf97a192453 🔍
VirtualSize 0x1a297c
VirtualAddress 0x478000
SizeOfRawData 0x1a2a00
PointerToRawData 0x476a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.81276

.data

MD5 1a5d755e4a17ee7132a0a63e4b3c2d40 🔍
SHA1 282c01ac76f01711e37338dd1c0d0e9f32df851f 🔍
SHA256 2ec77ab8f56e6f398b92a84da940e5267efdfe772411243414d66d0647058513 🔍
SHA3 17997dfec75c8c1c50a8f37ee1f892a1c6099b2f0e4b6174ea0c70660d8409fb 🔍
VirtualSize 0x2b7440
VirtualAddress 0x61b000
SizeOfRawData 0x29aa00
PointerToRawData 0x619400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.57987

.pdata

MD5 394bbd5bcb7df58bd91e0efa35bc3b03 🔍
SHA1 054afc36387f69a27c456bb002e77810ded08c51 🔍
SHA256 294436f7511e7f7d964842340e194ac08392a85bed9042f262540961962de0ef 🔍
SHA3 a31845c8983c52aea98864a5cc24ac359c165b2ef4b7877b9ca5c468e2fcba91 🔍
VirtualSize 0x42bc4
VirtualAddress 0x8d3000
SizeOfRawData 0x42c00
PointerToRawData 0x8b3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.46116

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x916000
SizeOfRawData 0x200
PointerToRawData 0x8f6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.tls

MD5 468437133d0378d84a0530a55da4e00a 🔍
SHA1 8ad7e6cad0400dd752af3885b1aec8063b268948 🔍
SHA256 9c984d649e4d86d69775992c9d31f0e74248a260f72f2a272a8d01c4fe913a2c 🔍
SHA3 ccea60e25a0f87648fb8a114ef1266117a182f41170dfbfa95a7cd8e14a7fda7 🔍
VirtualSize 0x44c1
VirtualAddress 0x917000
SizeOfRawData 0x4600
PointerToRawData 0x8f6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.00510214

_RDATA

MD5 5a3bcaf70939d6583b38cf275d1e588e 🔍
SHA1 659c5a9e865f4c6e091231f332e1098b73b97207 🔍
SHA256 782fc3f1e2723a221ef090275f2fcb6161867c0e2233f656d4f16ad283034bff 🔍
SHA3 74f9b68d441eaa3cf085b32e97f998d76b51512c9772a0c516a2368ed150be86 🔍
VirtualSize 0x444
VirtualAddress 0x91c000
SizeOfRawData 0x600
PointerToRawData 0x8fb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.96669

_addr

MD5 aa0ffaf3ce1858bb7b756da8b9b51a8f 🔍
SHA1 5329d30a158a6af0c4664cb58e06e28c5c561f03 🔍
SHA256 c674346890ffb9fb366eee6199da66a26fcbb543b685cc45f74c5253e084ddda 🔍
SHA3 ade61596f2f3bdb4dbe6e467c5c83f99f1380633358bc9400b9a8df29da0f0de 🔍
VirtualSize 0xa90
VirtualAddress 0x91d000
SizeOfRawData 0xc00
PointerToRawData 0x8fb800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.91671

_guard_c

MD5 1ccfae942894f2bf0489a83efa9a0403 🔍
SHA1 e24397c1329031bf57be2b1fa45411665e887903 🔍
SHA256 77bd5b0f085ff603da1fbcb4163dd36f8043e9c3c3abb2878a7431c44c0c3be2 🔍
SHA3 9f9e3fcb0300c1e74fe24e5e93e624ea5b95fcc20e267f702f4e5f9099195d15 🔍
VirtualSize 0x24
VirtualAddress 0x91e000
SizeOfRawData 0x200
PointerToRawData 0x8fc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 0.221676

_guard_d

MD5 779b48f52d3c8b209bd6de4376596dce 🔍
SHA1 2ea74ef4f8092da18eda3aa11947372fb1c083cd 🔍
SHA256 3f788b915978f05de7ed169977106cf6ec99842504a94952e478d4164d24f8e1 🔍
SHA3 808d5349a958eca88c797e8d02e9367d2c1340a7be4cf48aafc68597bc60f244 🔍
VirtualSize 0x24
VirtualAddress 0x91f000
SizeOfRawData 0x200
PointerToRawData 0x8fc600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 0.221676

memcmp_

MD5 38063e9123c21bf1615a8e8f4c8ccada 🔍
SHA1 81ac0d59f03e0267bb46113a598c87ee3e23627f 🔍
SHA256 a8b8e662dab974a4bf696134a86825878b2cf20274c6b0ba0ec028fc7e762814 🔍
SHA3 1ff18c107a1269338f527b5cf3299c41e4cb9dde63dbab14a914c3315d802094 🔍
VirtualSize 0x58
VirtualAddress 0x920000
SizeOfRawData 0x200
PointerToRawData 0x8fc800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 0.592317

memcpy_

MD5 f66e6db168267e4d42e95687f4dfb270 🔍
SHA1 f4464ac128142a897ab5132e3e0b51ecb094cffb 🔍
SHA256 6f05979c7b7c05ba87b02bcac17694b748d24fa9eaf94764bcf252c7a99bb4bd 🔍
SHA3 01f3b9d211c6fe87de0ca280dc8ec6f8038130a41ddf153842d224e53b19882c 🔍
VirtualSize 0x14c
VirtualAddress 0x921000
SizeOfRawData 0x200
PointerToRawData 0x8fca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 2.29738

memset_

MD5 4603e1b14a4c44aca892456ad69117d4 🔍
SHA1 ae70a44d9446170c2115de4cdb5aca2d8608d5dd 🔍
SHA256 63ce42da8f2157c78f6408c8d9ed8a499d0bf0a5fff0bbd38ce28df412547fec 🔍
SHA3 1606810775839d6242887afd9cefe189abd4352bec368d6969d1134801250a36 🔍
VirtualSize 0x78
VirtualAddress 0x922000
SizeOfRawData 0x200
PointerToRawData 0x8fcc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics (EMPTY)
Entropy 0.824548

.rsrc

MD5 082fd82fa02cb50a299679cb058e534b 🔍
SHA1 94f3f6885f337aae7b003f5a7b7be095a07b33a8 🔍
SHA256 42e41a1ffc409b15fd487b8419e8f75dc7ea7f325828dd685869ceec1539e144 🔍
SHA3 2e6abb64887f731fa5fd372aa2b0736d8fe33c3731556cc3747f124fdc5b2ec9 🔍
VirtualSize 0xe8
VirtualAddress 0x923000
SizeOfRawData 0x200
PointerToRawData 0x8fce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.34492

.reloc

MD5 b0c024a08a361c8aef454220df3e2c60 🔍
SHA1 75d039fc8a3a9b2920413c7b63cabd7b839518e7 🔍
SHA256 e47719716066f3165e95b6ec4f82b5381593f1e77d3ff3520a1d6903bd81ca30 🔍
SHA3 f80217c96092d0c1f50fc0649848a47b3fb82a8c6bb73820725e450430479243 🔍
VirtualSize 0x4654
VirtualAddress 0x924000
SizeOfRawData 0x4800
PointerToRawData 0x8fd000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.02193

Imports

KERNEL32.dll AcquireSRWLockExclusive
AcquireSRWLockShared
AddVectoredExceptionHandler
AllocConsole
AreFileApisANSI
AttachConsole
CloseHandle
CompareStringEx
CompareStringW
CopyFile2
CreateDirectoryExW
CreateDirectoryW
CreateEventW
CreateFile2
CreateFileA
CreateFileMappingA
CreateFileW
CreateHardLinkW
CreateSymbolicLinkW
CreateThread
DecodePointer
DeleteCriticalSection
DeleteFileW
DeviceIoControl
DisableThreadLibraryCalls
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
ExitThread
FindClose
FindFirstFileExW
FindFirstFileW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FormatMessageA
FreeConsole
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryA
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatW
GetDiskFreeSpaceExW
GetEnvironmentStringsW
GetEnvironmentVariableA
GetEnvironmentVariableW
GetExitCodeThread
GetFileAttributesExW
GetFileAttributesW
GetFileInformationByHandle
GetFileInformationByHandleEx
GetFileSizeEx
GetFileType
GetFinalPathNameByHandleW
GetFullPathNameW
GetLastError
GetLocalTime
GetLocaleInfoA
GetLocaleInfoEx
GetLocaleInfoW
GetLogicalProcessorInformationEx
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessId
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetSystemTimePreciseAsFileTime
GetTempPathW
GetThreadContext
GetThreadId
GetTickCount64
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
GetVersionExA
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitOnceBeginInitialize
InitOnceComplete
InitializeCriticalSectionEx
InitializeSListHead
InterlockedFlushSList
InterlockedPushEntrySList
IsDebuggerPresent
IsProcessorFeaturePresent
IsThreadAFiber
IsValidCodePage
IsValidLocale
LCMapStringEx
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
LocalFree
MapViewOfFile
MoveFileExW
MultiByteToWideChar
OutputDebugStringA
OutputDebugStringW
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadConsoleW
ReadFile
ReadProcessMemory
ReleaseSRWLockExclusive
ReleaseSRWLockShared
RemoveVectoredExceptionHandler
ResetEvent
ResumeThread
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
SetConsoleCtrlHandler
SetConsoleTitleA
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFileAttributesW
SetFileInformationByHandle
SetFilePointerEx
SetFileTime
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
Sleep
SleepConditionVariableSRW
SuspendThread
SwitchToThread
TerminateProcess
TryAcquireSRWLockExclusive
TryAcquireSRWLockShared
UnhandledExceptionFilter
UnmapViewOfFile
VerSetConditionMask
VirtualProtect
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
WritePrivateProfileStringA
SHELL32.dll SHGetFolderPathW
USER32.dll ClientToScreen
CloseClipboard
CreateWindowExA
DefWindowProcA
DestroyWindow
EmptyClipboard
FindWindowA
FlashWindowEx
GetActiveWindow
GetAsyncKeyState
GetCapture
GetClientRect
GetClipboardData
GetCursorPos
GetDC
GetForegroundWindow
GetKeyState
GetKeyboardLayout
GetMessageExtraInfo
GetSystemMetrics
GetWindowLongPtrW
GetWindowTextA
GetWindowTextLengthA
IsWindowUnicode
LoadCursorW
MapVirtualKeyA
MapVirtualKeyW
MonitorFromWindow
OpenClipboard
RegisterClassExA
ReleaseCapture
ReleaseDC
ScreenToClient
SetCapture
SetClipboardData
SetCursor
SetCursorPos
SetProcessDPIAware
TrackMouseEvent
UnregisterClassA
ole32.dll CoCreateInstance
CoInitializeEx
CoUninitialize
CreateStreamOnHGlobal
PropVariantClear
GDI32.dll CreateRectRgn
DeleteObject
GetDeviceCaps
ADVAPI32.dll GetUserNameA
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
IMM32.dll ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
ImmSetCompositionWindow
dwmapi.dll DwmEnableBlurBehindWindow
DwmGetColorizationColor
DwmIsCompositionEnabled
VERSION.dll GetFileVersionInfoA
GetFileVersionInfoSizeA
VerQueryValueW

Delayed Imports

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x87
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.66463
MD5 d531bf1544c19ee7c3dc477d8fd9c302 🔍
SHA1 3120b5f05a48d41b42e8542d23725c98e1af83b9 🔍
SHA256 39abce8cd98964b342942a3770e2ce865cda054577ddc4b790ccc0ece897a371 🔍
SHA3 892e36cfcac6e08d443805d5b103b9b2be2f46665b35309eb4561d0f8bb18d88 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-03 05:48:47
Version 0.0
SizeofData 89
AddressOfRawData 0x589bd8
PointerToRawData 0x5885d8
Referenced File C:\Users\rukia\Downloads\37f17kx\gameseks\..\bin\nexoriabeta.pdb

TLS Callbacks

StartAddressOfRawData 0x180917000
EndAddressOfRawData 0x18091b4c0
AddressOfIndex 0x1808d0710
AddressOfCallbacks 0x180589ec8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001802F5220
0x00000001802F5370

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1808b2100

RICH Header

Errors

Leave a comment
💴 New Message from Coinbase. READ ⭐➤ graph.org/YOU-HAVE-A-NEW-BI 9 hours ago
💴 New Message from Coinbase. READ ⭐➤ graph.org/YOU-HAVE-A-NEW-BITCOIN-TRANSFER-FROM-COINBASE-08-27?hs=c03c24ab856326632bc6dafac6754e9a& #QA7732 💴