305d00b819cca664cab13ffe33add99057aa85a314cc837ffc14b579a44323a8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-May-14 18:58:32
TLS Callbacks 2 callback(s) detected.
Debug artifacts D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
CompanyName BasicHTTPServer
FileDescription BasicHTTPServer
FileVersion 1.0.0.0
InternalName BasicHTTPServer.dll
LegalCopyright
OriginalFilename BasicHTTPServer.dll
ProductName BasicHTTPServer
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • crl.microsoft.com
  • genretrucklooksValueFrame.net
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crt0
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Code%20Signing%20PCA%202024.crl0w
  • http://www.microsoft.com0
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://aka.ms
  • https://www.World
  • https://www.recent
  • microsoft.com
  • microsoft.net
  • thing.org
  • www.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to RC5 or RC6
Suspicious The PE is possibly packed. Unusual section name found: .CLR_UEF
Unusual section name found: Section
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • LoadLibraryW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegGetValueW
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • CreateFileW
  • CreateFileA
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetKernelObjectSecurity
Malicious The PE is possibly a dropper. Resource MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER detected as a PE Executable.
Suspicious The file contains overlay data. 1290113 bytes of data starting at offset 0x932c00.
The overlay data has an entropy of 7.99213 and is possibly compressed or encrypted.
Malicious VirusTotal score: 11/70 (Scanned on 2026-07-30 20:40:44) ALYac: Gen:Variant.Yogi.23804
APEX: Malicious
Arcabit: Trojan.Yogi.D5CFC
BitDefender: Gen:Variant.Yogi.23804
Bkav: W32.Malware.CDCEFC6C
CTX: exe.unknown.yogi
Emsisoft: Gen:Variant.Yogi.23804 (B)
GData: Gen:Variant.Yogi.23804
MicroWorld-eScan: Gen:Variant.Yogi.23804
Microsoft: Trojan:Win32/Wacatac.B!ml
VIPRE: Gen:Variant.Yogi.23804

Hashes

MD5 46eb166983ddb2d5a6dd6a0dfe48998f
SHA1 dce17140f374d068dd4e7024952ad9bf659fa555
SHA256 305d00b819cca664cab13ffe33add99057aa85a314cc837ffc14b579a44323a8
SHA3 af37eaf3ff0ed3565c083bf707eb732cc0680ae4134bfda492d76831ec089332
SSDeep 98304:FvklazdpMVoytnVua5NjIsZ0i9WybfKP+8NhvGGVWIghHQkCY6+7tBn5BER:p+azUtnV951h0XCfQbG2p6HQB+7tB5KR
Imports Hash 6a08817aa472d4d409353937485cdebc

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2026-May-14 18:58:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x60de00
SizeOfInitializedData 0x324a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000005C3030 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x94f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 107bf4b6c39d44039e302bbe076d66cd
SHA1 4d2e87644ace53b866595463ae7d1592e9f943ba
SHA256 e7a0c7a8c0b00e79df8cbb7324adcba168e2e077bd00c3bb1a6f29be991b8709
SHA3 3828429c701a5377ae63214e7aa7e7e7896e8bade0d5c11709234f6ce8655ef8
VirtualSize 0x60dbec
VirtualAddress 0x1000
SizeOfRawData 0x60dc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45188

.CLR_UEF

MD5 47115f298517ccf492f1037550bb860f
SHA1 0b74d3d511a9ff54a7b660aa298a66953752bc22
SHA256 0517f13f8fa00b6678372d0b2d267a04aa1baedc6de96a8edce24fd89a3ef61c
SHA3 feeb07f78ab23ee44846683cfdad918b944a1d857bb468ce159479e79d11ba97
VirtualSize 0xdd
VirtualAddress 0x60f000
SizeOfRawData 0x200
PointerToRawData 0x60e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 3.1038

.rdata

MD5 51a53b838b78c5cd9536caaba1029c32
SHA1 3eaff22e114d2a33ecaec2a63affeef795eb866d
SHA256 13143ef5f7567b92907968f4e417621133bc4a2e7359a4a8a019665ae22759a6
SHA3 3a0e4ae5c7ffdec68e585d246bfbc5558b3d6c6e169e2bd583cd6369a8298f49
VirtualSize 0x17eac4
VirtualAddress 0x610000
SizeOfRawData 0x17ec00
PointerToRawData 0x60e200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.67516

.data

MD5 7e5c660c4232a6fa7e8af575771babc5
SHA1 0f409c3181766dc239ab6cad45aa8524e5fef35b
SHA256 0b48c8f73fc496f4ab2d0dc7f757f5ecd0110609250f80939009645ff806cc40
SHA3 a7d238987a81f56f8e929c18ff077eaf761d437ffe996bf837d5b9357c0cdeac
VirtualSize 0x1ffb4
VirtualAddress 0x78f000
SizeOfRawData 0x9800
PointerToRawData 0x78ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.3326

.pdata

MD5 e44f79323accc990667227a1bf9b25bb
SHA1 def69d03f397d3ec4889e9ab5c32b198ed1bb0af
SHA256 08978df2cbe934334c2ec63ecd0f48f91d38e0fe1fc7e81fff21e1647c7278fd
SHA3 0f931dc5ea9fdb07195bb90908eb10ac079baf26a6b2d0b37eae333b34d15fba
VirtualSize 0x36048
VirtualAddress 0x7af000
SizeOfRawData 0x36200
PointerToRawData 0x796600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.47526

.didat

MD5 147852ffd0d368de4c559f6bf5d26f68
SHA1 383ce3fca625b529c3c4599d99fbf4b568de6824
SHA256 15e7cced55a0cfadf027c57b403f1d5fc6dd9763fdc288ca0b4ed9f8a7376396
SHA3 721e97fd37cbd225af9a7c6eee863be621694bedb7a2d7cc1db54f4db0fcd34f
VirtualSize 0x38
VirtualAddress 0x7e6000
SizeOfRawData 0x200
PointerToRawData 0x7cc800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.424498

Section

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x8
VirtualAddress 0x7e7000
SizeOfRawData 0x200
PointerToRawData 0x7cca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

_RDATA

MD5 617430a8cd708dda1865fee2910d8a1a
SHA1 b2d344e99eaf406f9d735221b7e4be4a00b5dc4c
SHA256 46fcf6f9bc3d68ed740f4c7a9ec00a525bf1567d1b3292ea60a0f225dec677f1
SHA3 4cb75c28b76b7e3356736ef0006976b6595b0fdd1d2e93a03ccae4ac27bb3445
VirtualSize 0x13208
VirtualAddress 0x7e8000
SizeOfRawData 0x13400
PointerToRawData 0x7ccc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.48272

.rsrc

MD5 f6afe98bfa5301b5cf718fc88528eaa4
SHA1 a004fbcbc1b6f5cf4054838a265d70acdb4f9141
SHA256 9292877b8e8ac5cc9552e7fffaff12d9c0de150706bf5c35923a9a9120950eff
SHA3 f7dd6cfccd8bbe3f865cab27bc6ac952b89124bd14a8e2aaf230b12074019d3d
VirtualSize 0x14abf0
VirtualAddress 0x7fc000
SizeOfRawData 0x14ac00
PointerToRawData 0x7e0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.35024

.reloc

MD5 c52f50a37afcf4ebec70a5bf38989669
SHA1 c18ae19de0957cd14ab70a862911b8e3c914be9d
SHA256 f3483fb26474a8e5be4ce47e0d357f9117bf8be62342e281fdc23d5c5251fa09
SHA3 ef33fe63d3b4ebfc5279f1b9e0662c474fcf4f1cf52c7939128eaa2ee84cbb7f
VirtualSize 0x7e44
VirtualAddress 0x947000
SizeOfRawData 0x8000
PointerToRawData 0x92ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44617

Imports

KERNEL32.dll RaiseException
FreeLibrary
SetErrorMode
RaiseFailFastException
GetExitCodeProcess
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
AddVectoredExceptionHandler
MultiByteToWideChar
GetTickCount
FlushInstructionCache
QueryPerformanceFrequency
QueryPerformanceCounter
RtlLookupFunctionEntry
LocateXStateFeature
RtlDeleteFunctionTable
InterlockedPushEntrySList
InterlockedFlushSList
InitializeSListHead
GetTickCount64
DuplicateHandle
QueueUserAPC
WaitForSingleObjectEx
SetThreadPriority
GetThreadPriority
GetCurrentThreadId
TlsAlloc
GetCurrentThread
GetCurrentProcessId
CreateThread
GetModuleHandleW
WaitForMultipleObjectsEx
SignalObjectAndWait
RtlCaptureContext
SetThreadStackGuarantee
VirtualQuery
WriteFile
GetStdHandle
GetConsoleOutputCP
MapViewOfFileEx
UnmapViewOfFile
GetStringTypeExW
InterlockedPopEntrySList
ExitProcess
Sleep
CreateMemoryResourceNotification
VirtualAlloc
VirtualFree
VirtualProtect
SleepEx
SwitchToThread
SuspendThread
ResumeThread
InitializeContext
SetXStateFeaturesMask
RtlRestoreContext
CloseThreadpoolTimer
CreateThreadpoolTimer
SetThreadpoolTimer
ReadFile
GetFileSize
GetEnvironmentVariableW
SetEnvironmentVariableW
CreateEventW
SetEvent
ResetEvent
GetThreadContext
SetThreadContext
GetEnabledXStateFeatures
CopyContext
WerRegisterRuntimeExceptionModule
RtlInstallFunctionTableCallback
GetSystemDefaultLCID
GetUserDefaultLCID
RtlUnwind
HeapAlloc
HeapFree
GetProcessHeap
HeapCreate
HeapDestroy
GetEnvironmentStringsW
FreeEnvironmentStringsW
FormatMessageW
CreateSemaphoreExW
ReleaseSemaphore
GetACP
LCMapStringEx
LocalFree
VerSetConditionMask
VerifyVersionInfoW
QueryThreadCycleTime
GetLogicalProcessorInformationEx
SetThreadGroupAffinity
GetThreadGroupAffinity
GetProcessGroupAffinity
GetCurrentProcessorNumberEx
GetProcessAffinityMask
QueryInformationJobObject
CloseHandle
GetSystemTimeAsFileTime
GetModuleFileNameW
CreateProcessW
GetCPInfo
LoadLibraryExW
CreateFileW
GetFileAttributesExW
GetFullPathNameW
LoadLibraryExA
OutputDebugStringA
OpenEventW
ReleaseMutex
ExitThread
CreateMutexW
HeapReAlloc
CreateNamedPipeA
WaitForMultipleObjects
DisconnectNamedPipe
CreateFileA
CancelIoEx
GetOverlappedResult
ConnectNamedPipe
FlushFileBuffers
SetFilePointer
MapViewOfFile
GetActiveProcessorGroupCount
GetSystemTime
SetConsoleCtrlHandler
GetLocaleInfoEx
GetUserDefaultLocaleName
RtlAddFunctionTable
LoadLibraryW
CreateDirectoryW
RemoveDirectoryW
CreateActCtxW
ActivateActCtx
FindResourceW
GetWindowsDirectoryW
GetFileSizeEx
FindFirstFileExW
FindNextFileW
GetTempPathW
FindClose
LoadLibraryA
GetCurrentDirectoryW
IsWow64Process
EncodePointer
DecodePointer
CreateFileMappingA
TlsSetValue
TlsGetValue
GetSystemInfo
GetCurrentProcess
OutputDebugStringW
IsDebuggerPresent
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSection
WideCharToMultiByte
GetCommandLineW
GetProcAddress
GetModuleHandleExW
SetThreadErrorMode
FlushProcessWriteBuffers
SetLastError
DebugBreak
WaitForSingleObject
GetNumaHighestNodeNumber
SetThreadAffinityMask
SetThreadIdealProcessorEx
GetThreadIdealProcessorEx
VirtualAllocExNuma
GetNumaProcessorNodeEx
VirtualUnlock
GetLargePageMinimum
IsProcessInJob
K32GetProcessMemoryInfo
GetLogicalProcessorInformation
GlobalMemoryStatusEx
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
RtlVirtualUnwind
IsProcessorFeaturePresent
RtlUnwindEx
InitializeCriticalSectionAndSpinCount
TlsFree
RtlPcToFileHeader
TryAcquireSRWLockExclusive
GetExitCodeThread
GetStringTypeW
InitializeCriticalSectionEx
GetLastError
CreateFileMappingW
ADVAPI32.dll ReportEventW
AdjustTokenPrivileges
RegGetValueW
SetKernelObjectSecurity
GetSidSubAuthorityCount
GetSidSubAuthority
GetTokenInformation
OpenProcessToken
DeregisterEventSource
RegisterEventSourceW
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
EventRegister
SetThreadToken
RevertToSelf
OpenThreadToken
EventWriteTransfer
EventWrite
LookupPrivilegeValueW
ole32.dll CoCreateFreeThreadedMarshaler
CreateStreamOnHGlobal
CoRevokeInitializeSpy
CoGetContextToken
CoGetObjectContext
CoUnmarshalInterface
CoMarshalInterface
CoGetMarshalSizeMax
CLSIDFromProgID
CoReleaseMarshalData
CoTaskMemFree
CoTaskMemAlloc
CoCreateGuid
CoInitializeEx
CoRegisterInitializeSpy
CoWaitForMultipleHandles
CoUninitialize
CoGetClassObject
OLEAUT32.dll CreateErrorInfo
SysFreeString
GetErrorInfo
SetErrorInfo
SysStringLen
SysAllocString
SysAllocStringLen
SafeArrayGetDim
SafeArrayGetLBound
SafeArrayDestroy
QueryPathOfRegTypeLib
LoadTypeLibEx
SafeArrayGetVartype
VariantChangeType
VariantChangeTypeEx
VariantClear
VariantInit
VarCyFromDec
SafeArrayAllocDescriptorEx
GetRecordInfoFromTypeInfo
SafeArraySetRecordInfo
SafeArrayAllocData
SafeArrayGetElemsize
SysStringByteLen
SysAllocStringByteLen
SafeArrayCreateVector
SafeArrayPutElement
LoadRegTypeLib
USER32.dll LoadStringW
MessageBoxW
SHELL32.dll ShellExecuteW
api-ms-win-crt-string-l1-1-0.dll strncat_s
wcsncat_s
_wcsicmp
wcsnlen
wcscat_s
towupper
iswascii
_strdup
strncpy
strnlen
wcstok_s
isdigit
isupper
isalpha
towlower
_wcsdup
iswspace
isspace
islower
strtok_s
strcmp
strcspn
__strncnt
_wcsnicmp
strlen
wcscpy_s
toupper
wcsncpy_s
strcpy_s
strcat_s
strncpy_s
_strnicmp
tolower
wcsncmp
iswupper
strncmp
_stricmp
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsscanf
fflush
__acrt_iob_func
__stdio_common_vfprintf
__stdio_common_vswprintf
__stdio_common_vfwprintf
fputws
fputwc
_get_stream_buffer_pointers
_fseeki64
fread
fsetpos
ungetc
fgetpos
fgets
fgetc
fputc
_wfsopen
_wfopen
__p__commode
_set_fmode
__stdio_common_vsnprintf_s
setvbuf
_setmode
_dup
_fileno
ftell
fseek
fputs
__stdio_common_vsnwprintf_s
__stdio_common_vsprintf_s
fwrite
_flushall
fopen
fclose
api-ms-win-crt-runtime-l1-1-0.dll _crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_register_onexit_function
_configure_wide_argv
_initialize_wide_environment
_get_initial_wide_environment
_initterm
_initterm_e
_exit
_invoke_watson
__p___argc
__p___wargv
_c_exit
_register_thread_local_exe_atexit_callback
_initialize_onexit_table
_beginthreadex
terminate
_controlfp_s
_wcserror_s
_invalid_parameter_noinfo
_errno
exit
abort
api-ms-win-crt-convert-l1-1-0.dll _atoi64
_ltow_s
_wtoi
strtoul
_wcstoui64
atol
_itow_s
strtoull
wcstoul
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
calloc
malloc
realloc
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-math-l1-1-0.dll asinhf
atanhf
cbrtf
acoshf
cosh
cbrt
coshf
exp
expf
acosh
atanh
floor
floorf
fma
fmaf
cosf
_fdopen
cos
ceilf
_copysignf
_isnanf
trunc
truncf
ilogb
ilogbf
tanhf
ceil
fmod
fmodf
atanf
frexp
atan2f
atan2
log
log10
log10f
atan
asinf
log2
log2f
logf
pow
powf
sin
sinf
asin
sinh
sinhf
sqrt
sqrtf
tan
tanf
tanh
acosf
_copysign
asinh
_isnan
_finite
modf
modff
_dclass
_ldclass
acos
__setusermatherr
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64_s
wcsftime
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-locale-l1-1-0.dll _unlock_locales
setlocale
__pctype_func
___lc_locale_name_func
_lock_locales
___lc_codepage_func
___mb_cur_max_func
_configthreadlocale
localeconv
api-ms-win-crt-filesystem-l1-1-0.dll _wrename
_unlock_file
_wremove
_lock_file
VERSION.dll (delay-loaded) VerQueryValueW
GetFileVersionInfoExW
GetFileVersionInfoSizeExW

Delayed Imports

Attributes 0x1
Name VERSION.dll
ModuleHandle 0x798800
DelayImportAddressTable 0x7e6000
DelayImportNameTable 0x78b9e0
BoundDelayImportTable 0x78ba80
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

g_CLREngineMetrics

Ordinal 2
Address 0x790dd8

CLRJitAttachState

Ordinal 3
Address 0x7a4228

DotNetRuntimeInfo

Ordinal 4
Address 0x7915d0

MetaDataGetDispenser

Ordinal 5
Address 0x564ac0

g_dacTable

Ordinal 6
Address 0x639c10

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70214
MD5 e60e5c40fd35a8879d096f670dc84ba9
SHA1 ecefe6176abd578e1e6d0eccf7fc191c45fcdc60
SHA256 ad56a7bc1ea3161984baeaab2d729967f5ab97bddb4f6237881e254f4202394f
SHA3 9e3badaacd9bc1f6b93aa6d303b3e35ce41d4862cdf1bb531b38b754dc9872ca

CLRDEBUGINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21078
MD5 9f3276795f3f1f0e1a3b862e9255f8c4
SHA1 bbb093874065dfd54156394691e6b6aa5b9176d4
SHA256 b182c1f8a0c422a7c41439b38c040051cf16405d571ed77ceab563041abe850d
SHA3 27ceea02d4e3e355e3279306011b2e7763edd9315f1309ef074a56a8da5789b7

CLRDEBUGINFOWINDOWSAMD64

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21078
MD5 9f3276795f3f1f0e1a3b862e9255f8c4
SHA1 bbb093874065dfd54156394691e6b6aa5b9176d4
SHA256 b182c1f8a0c422a7c41439b38c040051cf16405d571ed77ceab563041abe850d
SHA3 27ceea02d4e3e355e3279306011b2e7763edd9315f1309ef074a56a8da5789b7

MINIDUMP_EMBEDDED_AUXILIARY_PROVIDER

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x149388
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.35643
Detected Filetype PE Executable
MD5 05137084b44734e559d71bef35659d36
SHA1 02c596fecf01ac8fb76404f0ff7ca25663f7d3e2
SHA256 6f7a3520fb5a30d1c747e7d232b219c1c97a2270429da7aa1f572ac2c60b28be
SHA3 98f0a3203604c86097721bf4505a2594e205d899d02675a0b3c674cc1530e6f0

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7815
Detected Filetype Icon file
MD5 e4125217b893e2bda912ed8a4b0acf62
SHA1 9d7d595b7900152e0ab579240a6152d0026d6702
SHA256 729aac5a6d455deac3b3ad87f36fc1c9f0f53c6fa74f9e58289f8840261bdc4b
SHA3 7e92b23c855c359cd18c6f25e3b14031ee01745b9982d95e20d77b31d6347f9d

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29015
MD5 6fe47b84de369516d3bed6828d027746
SHA1 30618efa37062d4e645dbaa2a17be0d5bdabaa3d
SHA256 ff618f4bebf4381bb5b78e1ede3611435bde9f986991cc4e2b245749875a2158
SHA3 ef173fedc6f81466dd8ecd563b1b7e30d7b2155da0e53ad98da12f54e0fbfa4e

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName BasicHTTPServer
FileDescription BasicHTTPServer
FileVersion (#2) 1.0.0.0
InternalName BasicHTTPServer.dll
LegalCopyright
OriginalFilename BasicHTTPServer.dll
ProductName BasicHTTPServer
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-May-14 18:58:32
Version 0.0
SizeofData 116
AddressOfRawData 0x712414
PointerToRawData 0x710614
Referenced File D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-May-14 18:58:32
Version 0.0
SizeofData 20
AddressOfRawData 0x712488
PointerToRawData 0x710688

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-May-14 18:58:32
Version 0.0
SizeofData 1332
AddressOfRawData 0x71249c
PointerToRawData 0x71069c

TLS Callbacks

StartAddressOfRawData 0x140712a20
EndAddressOfRawData 0x140712c0d
AddressOfIndex 0x140798850
AddressOfCallbacks 0x140611038
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001405C24B0
0x00000001405C2C70

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14078f040
GuardCFCheckFunctionPointer 5375069912
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xeae9ca0d
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
ASM objects (35207) 20
C objects (35207) 18
C++ objects (35207) 96
C objects (33145) 8
Imports (33145) 13
Total imports 521
ASM objects (35223) 21
C++ objects (LTCG) (35223) 653
Exports (35223) 1
Resource objects (35223) 1
Linker (35223) 1

Errors

Leave a comment

No comments yet.