2d0d17caf74f6dab699f824b7924011bdd993178cec500f45a77e4271ea17509

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-14 09:21:15
Detected languages English - United States
Debug artifacts C:\Users\Oveja\OneDrive\Desktop\Neptune Spoofer\examples\example_win32_directx11\Release\Source.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • %temp%
  • CurrentControlSet\Services
  • currentcontrolset\services
Contains domain names:
  • Battle.net
  • curl.haxx.se
  • example.com
  • github.com
  • https://curl.haxx.se
  • https://curl.haxx.se/docs/http-cookies.html
  • https://github.com
  • https://indiantypefoundry.comNinad
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • scripts.sil.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAlloc
  • WriteProcessMemory
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongA
Can access the registry:
  • RegOpenKeyExA
  • RegSetValueExA
  • RegCloseKey
Possibly launches other programs:
  • system
  • ShellExecuteA
Uses Windows's Native API:
  • NtRaiseHardError
  • ntohs
  • ntohl
Uses Microsoft's cryptographic API:
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptGenRandom
  • CryptGetHashParam
  • CryptAcquireContextA
  • CryptReleaseContext
  • CryptQueryObject
  • CryptStringToBinaryA
  • CryptDecodeObjectEx
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualProtectEx
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Manipulates other processes:
  • Process32Next
  • OpenProcess
  • WriteProcessMemory
  • Process32First
Changes object ACLs:
  • SetSecurityInfo
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 31/71 (Scanned on 2026-08-14 09:22:18) ALYac: Gen:Variant.Application.Tedy.22861
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
Acronis: suspicious
AhnLab-V3: Trojan/Win.Generic.R727495
Arcabit: Trojan.Application.Tedy.D594D
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Application.Tedy.22861
Bkav: W32.Malware.A4125AB4
CTX: exe.unknown.tedy
CrowdStrike: win/malicious_confidence_100% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/Agent_AGen.BDV trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Application.Tedy.22861 (B)
F-Secure: Trojan.TR/W64.Agent
GData: Gen:Variant.Application.Tedy.22861
Google: Detected
Ikarus: Trojan.Win64.Krypt
Malwarebytes: Malware.AI.2985711581
McAfeeD: ti!2D0D17CAF74F
MicroWorld-eScan: Gen:Variant.Application.Tedy.22861
Microsoft: Trojan:Win32/Wacatac.B!ml
Rising: Malware.Undefined!8.C (TFE:5:rVEDCBAbesP)
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
VIPRE: Gen:Variant.Application.Tedy.22861
Varist: W64/Agent.IIK.gen!Eldorado

Hashes

MD5 0061eb6d8124cb20c93df737a132bb59 🔍
SHA1 4a4d872be08c38d8ef624a4490b84319613e188c 🔍
SHA256 2d0d17caf74f6dab699f824b7924011bdd993178cec500f45a77e4271ea17509 🔍
SHA3 59538251367eff8b9253fa69b716fbb687c1d99d1e309eb9d2a461f0d31afb49 🔍
SSDeep 24576:JMRr/0GKU7RXZxZUOgjlRaAFUlO8FB20ZcGtoQCJCizyF3fEMMn3LQF0m:VmB2E6LJD2EDn 🔍
Imports Hash 904eb090b1f0c15c0ff3014cb7f544ce 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x138

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-14 09:21:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xdd400
SizeOfInitializedData 0x9dc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000DB988 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x180000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 baf58d33301923134ab700ccf7d401d2 🔍
SHA1 20de97aa068089341f8b53a94686f34199fc7ae5 🔍
SHA256 ee7915794a4347d7ca73788e2b85cf30f4f72ade0f7da8f114b6ba14be3bc4ee 🔍
SHA3 03bb0a8a9397aaf4f7eb9c72388c077c2a09fa379fc294ee726a84ff23ab22ea 🔍
VirtualSize 0xdd274
VirtualAddress 0x1000
SizeOfRawData 0xdd400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37823

.rdata

MD5 e0b258e517ccf31b9128da32d7ea8ccc 🔍
SHA1 afdd3a27cfa350ecc7aaeea03a43a8782bbc8647 🔍
SHA256 c1eeaf1dc3957d4f9c5824f0dfefcb3ba38c4d44254dc984fea6d1a8f4902d4a 🔍
SHA3 7edb056216c946224155abb3a28a76c7b0bb4e0402693e5a670a8a226ed13fa3 🔍
VirtualSize 0x46240
VirtualAddress 0xdf000
SizeOfRawData 0x46400
PointerToRawData 0xdd800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.99732

.data

MD5 3a113b5a6a9efe9413fd5a559db3037a 🔍
SHA1 1597c291342dd9eb623954a328eb1df2e91fbf92 🔍
SHA256 e9d1e4271cc970c90135d85486d4030f2fc6a0a78272a2598d056d541c945dd3 🔍
SHA3 3fb4737e122d4e9faa7382895b784388c9749544dd87390c30a69fbe4bf11ed3 🔍
VirtualSize 0x4f600
VirtualAddress 0x126000
SizeOfRawData 0x4dc00
PointerToRawData 0x123c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.74826

.pdata

MD5 259750624127a6ae7f6e6f6013a50f97 🔍
SHA1 dd4b5a6a21228bc9754a2a6b9c3bb57c83f5122f 🔍
SHA256 595f343feeaf49bc0e8a6cc94c24a3a90ff161fc23bdc62683aee65da0d44ad7 🔍
SHA3 3258c10e995f05ca3579958d50931e6510047f8f6bdf3266f2a342427e885594 🔍
VirtualSize 0x7524
VirtualAddress 0x176000
SizeOfRawData 0x7600
PointerToRawData 0x171800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.07048

.rsrc

MD5 f9e4bfa8ef4d2b9dcf1bc7bbb05234b6 🔍
SHA1 9706724f795905b75d139eebf878905420ad1236 🔍
SHA256 f232e69d7e9900b99760799b46d0f1f8beecf99c0a2730cea0dcd2c2893d88cb 🔍
SHA3 4fbf6ed7350212a3b6e9b76a77e43949be68664cdf7c873f3ac003b5d800d6ae 🔍
VirtualSize 0x1e0
VirtualAddress 0x17e000
SizeOfRawData 0x200
PointerToRawData 0x178e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 a583f6eb169fde866cb71a7108e0875e 🔍
SHA1 56f087eb0e67bba26087bd4cdcd16dae55ee5ebc 🔍
SHA256 36b9df0f19e4faffa986d94e49f969cd95b776d8a9b3b3251d604c4df5410bb4 🔍
SHA3 bdfa093778b5654865a4e7808cdaf7f954e94718bb6c950d92772551c3e96a08 🔍
VirtualSize 0x808
VirtualAddress 0x17f000
SizeOfRawData 0xa00
PointerToRawData 0x179000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.796

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
ole32.dll CoInitialize
CoUninitialize
CoCreateInstance
KERNEL32.dll AcquireSRWLockExclusive
SleepConditionVariableSRW
GetCurrentThreadId
WakeAllConditionVariable
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
VirtualFree
GetSystemInfo
CheckRemoteDebuggerPresent
IsDebuggerPresent
AllocConsole
GetTickCount
DebugBreak
GlobalFindAtomA
GetCurrentProcessId
GetThreadContext
VirtualProtectEx
CreateThread
LoadLibraryW
CloseHandle
Process32Next
GetCurrentThread
GetLastError
GlobalAddAtomA
Sleep
CreateToolhelp32Snapshot
OpenProcess
GetFileSizeEx
CreateFileA
WaitForMultipleObjects
PeekNamedPipe
ReadFile
GetFileType
GetStdHandle
GetEnvironmentVariableA
WaitForSingleObjectEx
MoveFileExA
VerifyVersionInfoA
GetSystemDirectoryA
SleepEx
LeaveCriticalSection
EnterCriticalSection
LocalFree
FormatMessageA
QueryFullProcessImageNameW
GetModuleHandleW
GetModuleFileNameA
UnmapViewOfFile
MapViewOfFile
CreateFileMappingW
CreateFileW
HeapDestroy
ReleaseMutex
WaitForSingleObject
TerminateProcess
VirtualAlloc
OutputDebugStringA
GetCurrentProcess
SetLastError
WriteProcessMemory
Process32First
QueryPerformanceCounter
FreeLibrary
VerSetConditionMask
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
GetModuleHandleA
HeapAlloc
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
MultiByteToWideChar
HeapFree
HeapSize
HeapReAlloc
ReleaseSRWLockExclusive
GetProcessHeap
InitializeCriticalSectionEx
DeleteCriticalSection
VirtualProtect
USER32.dll GetClientRect
SetCursor
GetCursorPos
OpenClipboard
GetForegroundWindow
TrackMouseEvent
EmptyClipboard
GetClipboardData
SetClipboardData
ReleaseCapture
IsWindowUnicode
CloseClipboard
ClientToScreen
ScreenToClient
SetCursorPos
SetCapture
LoadCursorA
GetKeyState
UpdateWindow
FindWindowA
PostQuitMessage
PeekMessageA
LoadIconA
TranslateMessage
SetLayeredWindowAttributes
DefWindowProcA
GetCapture
MoveWindow
MessageBoxA
SetWindowDisplayAffinity
GetWindowLongA
SetWindowLongA
GetAsyncKeyState
ShowWindow
GetActiveWindow
RegisterClassExW
UnregisterClassW
GetSystemMetrics
DispatchMessageA
GetWindowRect
DestroyWindow
SetWindowRgn
CreateWindowExW
GDI32.dll CreateRoundRectRgn
ADVAPI32.dll OpenProcessToken
GetLengthSid
GetTokenInformation
InitializeAcl
IsValidSid
GetUserNameA
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGenRandom
CryptGetHashParam
SetSecurityInfo
CopySid
ConvertSidToStringSidA
RegOpenKeyExA
RegSetValueExA
RegCloseKey
CryptAcquireContextA
CryptReleaseContext
AddAccessAllowedAce
VMProtectSDK64.dll VMProtectBeginUltra
VMProtectEnd
VMProtectIsDebuggerPresent
MSVCP140.dll ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?_Xbad_function_call@std@@YAXXZ
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exception@std@@YA_NXZ
?_Xout_of_range@std@@YAXPEBD@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
_Cnd_do_broadcast_at_thread_exit
_Query_perf_counter
_Thrd_detach
_Xtime_get_ticks
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?setf@ios_base@std@@QEAAHHH@Z
?good@ios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
IMM32.dll ImmSetCompositionWindow
ImmGetContext
ImmSetCandidateWindow
ImmReleaseContext
dwmapi.dll DwmExtendFrameIntoClientArea
ntdll.dll RtlLookupFunctionEntry
NtRaiseHardError
RtlAdjustPrivilege
RtlCaptureContext
RtlVirtualUnwind
Normaliz.dll IdnToAscii
WLDAP32.dll #143
#217
#46
#211
#60
#45
#50
#41
#22
#26
#27
#32
#33
#35
#79
#30
#200
#301
CRYPT32.dll CertGetNameStringA
CryptQueryObject
CertCreateCertificateChainEngine
CertFreeCertificateChainEngine
CertGetCertificateChain
CertFreeCertificateChain
CertAddCertificateContextToStore
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertFreeCertificateContext
CryptStringToBinaryA
CertFindExtension
PFXImportCertStore
CryptDecodeObjectEx
WS2_32.dll WSACleanup
closesocket
recv
send
WSAGetLastError
bind
connect
getpeername
getsockname
getsockopt
htons
ntohs
setsockopt
socket
WSASetLastError
WSAIoctl
WSAStartup
select
accept
ntohl
gethostname
sendto
recvfrom
freeaddrinfo
getaddrinfo
htonl
listen
__WSAFDIsSet
ioctlsocket
RPCRT4.dll UuidCreate
RpcStringFreeA
UuidToStringA
PSAPI.DLL GetModuleInformation
USERENV.dll UnloadUserProfile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
__std_exception_copy
__current_exception_context
__current_exception
strrchr
memset
memmove
memcpy
memchr
_CxxThrowException
wcsstr
__C_specific_handler
strchr
strstr
__std_terminate
memcmp
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
_lseeki64
__stdio_common_vsprintf
fflush
fread
__stdio_common_vsscanf
feof
__p__commode
fputs
fopen
_wfopen
__acrt_iob_func
__stdio_common_vfprintf
_read
_write
_close
_popen
_pclose
fgets
_open
fseek
fputc
ftell
fclose
fwrite
api-ms-win-crt-runtime-l1-1-0.dll _beginthreadex
terminate
_invalid_parameter_noinfo
_invalid_parameter_noinfo_noreturn
_errno
strerror
__sys_nerr
exit
_resetstkoflw
_wassert
_register_thread_local_exe_atexit_callback
_c_exit
_getpid
_exit
_initterm_e
_initterm
_get_narrow_winmain_command_line
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_invoke_watson
system
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-string-l1-1-0.dll _strdup
strncmp
isupper
tolower
strpbrk
strcmp
strcspn
strspn
strncpy
api-ms-win-crt-heap-l1-1-0.dll free
malloc
calloc
_callnewh
realloc
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll strtoull
strtoll
strtol
strtod
atoi
strtoul
api-ms-win-crt-multibyte-l1-1-0.dll _mbsicmp
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
api-ms-win-crt-math-l1-1-0.dll _dclass
__setusermatherr
acosf
ceilf
cosf
fmodf
powf
sinf
sqrtf
api-ms-win-crt-time-l1-1-0.dll _gmtime64
_time64
api-ms-win-crt-filesystem-l1-1-0.dll _access
_fstat64
_stat64
_unlink
SHELL32.dll ShellExecuteA

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-14 09:21:15
Version 0.0
SizeofData 124
AddressOfRawData 0x116934
PointerToRawData 0x115134
Referenced File C:\Users\Oveja\OneDrive\Desktop\Neptune Spoofer\examples\example_win32_directx11\Release\Source.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-14 09:21:15
Version 0.0
SizeofData 20
AddressOfRawData 0x1169b0
PointerToRawData 0x1151b0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-14 09:21:15
Version 0.0
SizeofData 912
AddressOfRawData 0x1169c4
PointerToRawData 0x1151c4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-14 09:21:15
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140116d78
EndAddressOfRawData 0x140116d80
AddressOfIndex 0x140173d50
AddressOfCallbacks 0x1400dfec0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140126080

RICH Header

XOR Key 0xe4d0c2ae
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 24
253 (35207) 8
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 39
Imports (35207) 6
Imports (VS2015 UPD3.1 build 24215) 2
C objects (VS2019 Update 6 (16.6.1-5) compiler 28806) 105
C objects (VS2022 Update 6 (17.6.3) compiler 32534) 2
C++ objects (VS2022 Update 6 (17.6.3) compiler 32534) 2
C objects (33145) 1
Imports (33145) 36
Imports (21202) 5
Total imports 487
C++ objects (LTCG) (35228) 13
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.