| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-24 16:25:21 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Seven\Desktop\Desktop\Bureau\PERM X\Shadow_Master_Loader\bin\Release\MysticProject.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE's digital signature is invalid. |
Signer: Epic Games Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 The file was modified after it was signed. |
| Malicious | VirusTotal score: 22/70 (Scanned on 2026-07-26 10:09:23) |
ALYac:
Gen:Variant.Tedy.988609
Arcabit: Trojan.Tedy.DF15C1 BitDefender: Gen:Variant.Tedy.988609 Bkav: W32.Malware.909008F9 CTX: exe.unknown.tedy CrowdStrike: win/malicious_confidence_70% (D) ESET-NOD32: Win64/GenKryptik_AGen.AZE trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Tedy.988609 (B) GData: Gen:Variant.Tedy.988609 Google: Detected Ikarus: Trojan.Win64.Krypt Malwarebytes: Malware.AI.2835673422 McAfeeD: Trojan:Win/GenericY.FJJ MicroWorld-eScan: Gen:Variant.Tedy.988609 Microsoft: Trojan:Win64/Lazy.ETL!MTB SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence Tencent: Trojan.Win64.Kryptik.16002199 Trapmine: suspicious.low.ml.score VIPRE: Gen:Variant.Tedy.988609 huorong: Backdoor/W64.Agent.g |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-24 16:25:21 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x13c000 |
| SizeOfInitializedData | 0x65a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000134DDC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WINHTTP.dll |
WinHttpCrackUrl
WinHttpSendRequest WinHttpCloseHandle WinHttpSetOption WinHttpOpenRequest WinHttpReadData WinHttpOpen WinHttpReceiveResponse WinHttpConnect WinHttpQueryDataAvailable |
|---|---|
| ADVAPI32.dll |
OpenSCManagerW
CryptImportKey CopySid SetSecurityInfo RegDeleteKeyA IsValidSid CryptDestroyKey InitializeAcl GetLengthSid AddAccessAllowedAce GetTokenInformation RegEnumKeyExA RegQueryValueExW RegEnumValueW RegDeleteValueA OpenServiceW RegDeleteValueW RegEnumValueA RegOpenKeyExW RegOpenKeyExA OpenProcessToken RegSetValueExA RegDeleteTreeW RegEnumKeyExW ControlService DeleteService RegCreateKeyExA LookupPrivilegeValueA CryptEncrypt RegQueryValueExA CloseServiceHandle RegCloseKey AdjustTokenPrivileges RegEnumKeyA SystemFunction036 CryptDestroyHash CryptHashData CryptCreateHash CryptGetHashParam CryptReleaseContext CryptAcquireContextW ConvertSidToStringSidA |
| SHELL32.dll |
ShellExecuteW
ShellExecuteExA ShellExecuteA SHGetFolderPathW |
| IPHLPAPI.DLL |
GetAdaptersAddresses
CreateIpNetEntry DeleteIpNetEntry GetAdaptersInfo GetIpNetTable |
| VirtDisk.dll |
CreateVirtualDisk
OpenVirtualDisk DetachVirtualDisk |
| gdiplus.dll |
GdiplusStartup
GdiplusShutdown GdipAddPathLine GdipCreateStringFormat GdipDeleteFontFamily GdipResetClip GdipCreateFontFamilyFromName GdipSetStringFormatAlign GdipSetClipRect GdipSetPenStartCap GdipDeleteBrush GdipAlloc GdipDeletePath GdipSetSmoothingMode GdipCreateLineBrush GdipCreatePath GdipSaveGraphics GdipCreateFont GdipCreateSolidFill GdipSetStringFormatTrimming GdipFillPath GdipDrawLine GdipDrawRectangle GdipFillRectangle GdipSetClipRectI GdipClosePathFigure GdipFree GdipDrawPath GdipDrawString GdipCreateFromHDC GdipFillEllipse GdipSetPenEndCap GdipSetTextRenderingHint GdipDrawEllipse GdipRestoreGraphics GdipCloneBrush GdipFillRectangleI GdipAddPathArc GdipDeleteGraphics GdipDrawArc GdipDeleteStringFormat GdipDeleteFont GdipDeletePen GdipCreatePen1 GdipSetStringFormatLineAlign |
| dwmapi.dll |
DwmSetWindowAttribute
|
| COMCTL32.dll |
#345
|
| SETUPAPI.dll |
SetupDiGetDeviceRegistryPropertyA
SetupDiEnumDeviceInfo SetupDiDestroyDeviceInfoList SetupDiGetClassDevsA SetupDiGetDeviceInstanceIdA |
| KERNEL32.dll |
InitializeSListHead
UnhandledExceptionFilter OutputDebugStringW GetSystemTimeAsFileTime SetUnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext IsDebuggerPresent WakeAllConditionVariable GetCurrentThreadId ReadFile GetModuleFileNameA GetVolumeInformationW GetLogicalDrives FindFirstFileW GetFileSizeEx FindFirstFileA VirtualProtect GetConsoleScreenBufferInfo SetConsoleTitleA FindNextFileW GetCurrentProcess GetStdHandle WriteFile ExpandEnvironmentStringsW SetConsoleMode DeviceIoControl TerminateProcess RemoveDirectoryW GetDriveTypeA GetCurrentDirectoryW Thread32Next ExpandEnvironmentStringsA SetFilePointer SetEndOfFile Thread32First FindClose GetVolumeInformationA WaitForSingleObject CreateFileW GetFileAttributesW GetSystemDirectoryW ResumeThread GetModuleHandleA SetFileAttributesW GetLogicalDriveStringsW CreateToolhelp32Snapshot MultiByteToWideChar Sleep GetConsoleMode GetTempPathA GetTickCount64 CopyFileA GetLastError GetFileAttributesA Process32NextW SetFileInformationByHandle CreateFileA GetCurrentThread GetSystemDirectoryA AreFileApisANSI CreateDirectoryW DeleteFileW Process32FirstW CloseHandle K32GetModuleInformation SetFileAttributesA GetLocalTime GetThreadContext GetProcAddress RemoveDirectoryA ExitProcess SetConsoleCP GetCurrentProcessId GetProcessHeap CreateProcessW GetModuleHandleW FreeLibrary WideCharToMultiByte GetConsoleWindow SetComputerNameExA CreateProcessA SetConsoleOutputCP GetDiskFreeSpaceExA CreateDirectoryA SetConsoleCursorPosition GetTickCount AllocConsole GetDriveTypeW OpenThread LoadLibraryExW FlushFileBuffers GetExitCodeProcess SetHandleInformation GetModuleFileNameW CreatePipe GetTempPathW IsProcessorFeaturePresent CopyFileW AddVectoredExceptionHandler HeapDestroy HeapAlloc HeapReAlloc HeapFree HeapSize InitializeCriticalSectionEx DeleteCriticalSection CreateThread CreateFileMappingW MapViewOfFile UnmapViewOfFile QueryFullProcessImageNameW SetLastError FormatMessageW ReleaseSRWLockExclusive AcquireSRWLockExclusive InitializeCriticalSection EnterCriticalSection LeaveCriticalSection LocalFree QueryPerformanceFrequency LoadLibraryW SleepEx GetSystemInfo QueryPerformanceCounter MoveFileExW WaitForSingleObjectEx GetEnvironmentVariableA GetFileType PeekNamedPipe WaitForMultipleObjects VerSetConditionMask VerifyVersionInfoW FindFirstFileExW GetFileAttributesExW GetFileInformationByHandle GetFinalPathNameByHandleW DeleteFileA GetFullPathNameW GetFileInformationByHandleEx FormatMessageA GetLocaleInfoEx LoadLibraryA SleepConditionVariableSRW FindNextFileA |
| USER32.dll |
PostMessageW
EnumDisplayDevicesA GetWindowRect SetWindowPos MessageBoxW SetWindowRgn CreateWindowExW RegisterClassExW SetTimer DefWindowProcW SetCapture GetClientRect KillTimer ReleaseCapture MessageBoxA DestroyWindow PostQuitMessage FindWindowA RegisterClassExA UpdateWindow GetCursorPos SendMessageW GetSystemMetrics ShowWindow DispatchMessageW GetWindowTextA SetWindowTextA CreateWindowExA SetLayeredWindowAttributes TranslateMessage EndPaint InvalidateRect GetMessageW LoadCursorW EnumDisplaySettingsA UnregisterClassA BeginPaint |
| GDI32.dll |
SetTextColor
GetStockObject CreateFontA DeleteObject DeleteDC CreateRoundRectRgn CreateCompatibleDC SelectObject CreateCompatibleBitmap BitBlt SetBkMode CreateSolidBrush |
| MSVCP140.dll |
??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?id@?$ctype@D@std@@2V0locale@2@A ?_Random_device@std@@YAIXZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??Bid@locale@std@@QEAA_KXZ _Query_perf_frequency _Query_perf_counter _Xtime_get_ticks ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?_Xbad_function_call@std@@YAXXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z ?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Throw_Cpp_error@std@@YAXH@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?uncaught_exception@std@@YA_NXZ ?_Xbad_alloc@std@@YAXXZ ?id@?$ctype@_W@std@@2V0locale@2@A ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xout_of_range@std@@YAXPEBD@Z ?_Winerror_map@std@@YAHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Xlength_error@std@@YAXPEBD@Z ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A ?_Syserror_map@std@@YAPEBDH@Z _Mtx_lock _Cnd_do_broadcast_at_thread_exit _Thrd_id _Thrd_detach _Thrd_join _Mtx_unlock ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z ?widen@?$ctype@_W@std@@QEBA_WD@Z ??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?width@ios_base@std@@QEAA_J_J@Z ?width@ios_base@std@@QEBA_JXZ ?good@ios_base@std@@QEBA_NXZ ??7ios_base@std@@QEBA_NXZ ??Bios_base@std@@QEBA_NXZ ?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z |
| WS2_32.dll |
getsockname
WSASetLastError getsockopt getpeername gethostname ioctlsocket sendto recvfrom freeaddrinfo getaddrinfo listen htonl accept select __WSAFDIsSet WSAIoctl connect send recv WSACloseEvent WSACreateEvent WSAEnumNetworkEvents WSAEventSelect bind WSAResetEvent WSAWaitForMultipleEvents closesocket setsockopt WSAGetLastError socket inet_pton ntohs WSACleanup WSAStartup inet_ntop htons |
| urlmon.dll |
URLDownloadToFileA
|
| SHLWAPI.dll |
PathFindFileNameW
|
| USERENV.dll |
UnloadUserProfile
|
| bcrypt.dll |
BCryptGenRandom
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
wcsstr
strstr strrchr __current_exception_context __current_exception __C_specific_handler wcschr strchr memset memmove memcpy memcmp memchr _CxxThrowException __std_exception_destroy __std_exception_copy __std_terminate |
| api-ms-win-crt-runtime-l1-1-0.dll |
__sys_errlist
__sys_nerr _register_onexit_function _errno _initialize_onexit_table abort _invalid_parameter_noinfo terminate _resetstkoflw _invalid_parameter_noinfo_noreturn _beginthreadex _invoke_watson _register_thread_local_exe_atexit_callback _c_exit _cexit __p___argv __p___argc _exit _initterm_e _initterm exit _get_initial_narrow_environment _crt_atexit _initialize_narrow_environment _configure_narrow_argv _set_app_type system _seh_filter_exe |
| api-ms-win-crt-stdio-l1-1-0.dll |
_lseeki64
fgetc fgetwc fputc _wfopen _wopen fwrite _set_fmode __stdio_common_vsscanf __stdio_common_vsprintf fgetpos feof __stdio_common_vswprintf_s fputs setvbuf __p__commode ungetwc ungetc fsetpos __acrt_iob_func fread _popen _pclose _fseeki64 _read _write fgets _get_stream_buffer_pointers _fileno _close fclose fputwc ftell fflush _wfopen_s fseek __stdio_common_vsprintf_s |
| api-ms-win-crt-heap-l1-1-0.dll |
free
calloc _set_new_mode _callnewh realloc malloc |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand qsort |
| api-ms-win-crt-string-l1-1-0.dll |
strnlen
isdigit _strdup _wcsicmp _wcsdup towlower strcspn _stricmp strncmp wcspbrk strspn strcmp wcsncmp strpbrk wcsncpy tolower wcscat_s |
| api-ms-win-crt-conio-l1-1-0.dll |
_getch
|
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
strtoll atoi strtod strtol strtoull wcstombs |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_fstat64 _lock_file _unlink _wstat64 |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
_gmtime64 _localtime64 strftime |
| api-ms-win-crt-math-l1-1-0.dll |
_dsign
__setusermatherr cosf sinf _fdopen |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func localeconv |
| CRYPT32.dll |
CertGetNameStringW
CertOpenStore CertFindExtension CertGetCertificateChain CertFreeCertificateChain CertAddCertificateContextToStore CryptDecodeObjectEx PFXImportCertStore CryptStringToBinaryW CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertFreeCertificateContext CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject |
| PSAPI.DLL |
GetModuleInformation
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-24 16:25:21 |
| Version | 0.0 |
| SizeofData | 120 |
| AddressOfRawData | 0x16e72c |
| PointerToRawData | 0x16db2c |
| Referenced File | C:\Users\Seven\Desktop\Desktop\Bureau\PERM X\Shadow_Master_Loader\bin\Release\MysticProject.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-24 16:25:21 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x16e7a4 |
| PointerToRawData | 0x16dba4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-24 16:25:21 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x16e7b8 |
| PointerToRawData | 0x16dbb8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-24 16:25:21 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14016eb68 |
|---|---|
| EndAddressOfRawData | 0x14016eb70 |
| AddressOfIndex | 0x140188748 |
| AddressOfCallbacks | 0x14013e548 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140186f40 |
| XOR Key | 0xcc66d4c8 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 24 |
| 253 (35207) | 7 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 40 |
| Imports (35207) | 6 |
| C objects (33145) | 1 |
| C objects (33523) | 43 |
| C objects (VS2022 Update 6 (17.6.4) compiler 32535) | 129 |
| C++ objects (34436) | 5 |
| Imports (33145) | 41 |
| Total imports | 698 |
| C++ objects (LTCG) (35226) | 2 |
| Resource objects (35226) | 1 |
| Linker (35226) | 1 |
No comments yet.