48e43339a3da662b6444d6ebfcb0129bfa77a9e7feb6a9660167cdaa0e149318

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-24 16:25:21
Detected languages English - United States
Debug artifacts C:\Users\Seven\Desktop\Desktop\Bureau\PERM X\Shadow_Master_Loader\bin\Release\MysticProject.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
May have dropper capabilities:
  • %TEMP%
  • CurrentControlSet\Services
  • Programs\Startup
Contains domain names:
  • example.com
  • https://curl.se
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Can access the registry:
  • RegDeleteKeyA
  • RegEnumKeyExA
  • RegQueryValueExW
  • RegEnumValueW
  • RegDeleteValueA
  • RegDeleteValueW
  • RegEnumValueA
  • RegOpenKeyExW
  • RegOpenKeyExA
  • RegSetValueExA
  • RegEnumKeyExW
  • RegCreateKeyExA
  • RegQueryValueExA
  • RegCloseKey
  • RegEnumKeyA
Possibly launches other programs:
  • ShellExecuteW
  • ShellExecuteA
  • CreateProcessW
  • CreateProcessA
  • system
Uses Microsoft's cryptographic API:
  • CryptImportKey
  • CryptDestroyKey
  • CryptEncrypt
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptGetHashParam
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptDecodeObjectEx
  • CryptStringToBinaryW
  • CryptQueryObject
Can create temporary files:
  • CreateFileW
  • GetTempPathA
  • CreateFileA
  • GetTempPathW
Has Internet access capabilities:
  • WinHttpCrackUrl
  • WinHttpSendRequest
  • WinHttpCloseHandle
  • WinHttpSetOption
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpConnect
  • WinHttpQueryDataAvailable
  • URLDownloadToFileA
Leverages the raw socket API to access the Internet:
  • getsockname
  • WSASetLastError
  • getsockopt
  • getpeername
  • gethostname
  • ioctlsocket
  • sendto
  • recvfrom
  • freeaddrinfo
  • getaddrinfo
  • listen
  • htonl
  • accept
  • select
  • __WSAFDIsSet
  • WSAIoctl
  • connect
  • send
  • recv
  • WSACloseEvent
  • WSACreateEvent
  • WSAEnumNetworkEvents
  • WSAEventSelect
  • bind
  • WSAResetEvent
  • WSAWaitForMultipleEvents
  • closesocket
  • setsockopt
  • WSAGetLastError
  • socket
  • inet_pton
  • ntohs
  • WSACleanup
  • WSAStartup
  • inet_ntop
  • htons
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • ControlService
  • DeleteService
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeA
  • GetVolumeInformationA
  • GetLogicalDriveStringsW
  • GetDriveTypeW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Changes object ACLs:
  • SetSecurityInfo
Can take screenshots:
  • FindWindowA
  • CreateCompatibleDC
  • BitBlt
Interacts with the certificate store:
  • CertOpenStore
  • CertAddCertificateContextToStore
Malicious The PE's digital signature is invalid. Signer: Epic Games Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
The file was modified after it was signed.
Malicious VirusTotal score: 22/70 (Scanned on 2026-07-26 10:09:23) ALYac: Gen:Variant.Tedy.988609
Arcabit: Trojan.Tedy.DF15C1
BitDefender: Gen:Variant.Tedy.988609
Bkav: W32.Malware.909008F9
CTX: exe.unknown.tedy
CrowdStrike: win/malicious_confidence_70% (D)
ESET-NOD32: Win64/GenKryptik_AGen.AZE trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Tedy.988609 (B)
GData: Gen:Variant.Tedy.988609
Google: Detected
Ikarus: Trojan.Win64.Krypt
Malwarebytes: Malware.AI.2835673422
McAfeeD: Trojan:Win/GenericY.FJJ
MicroWorld-eScan: Gen:Variant.Tedy.988609
Microsoft: Trojan:Win64/Lazy.ETL!MTB
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
Tencent: Trojan.Win64.Kryptik.16002199
Trapmine: suspicious.low.ml.score
VIPRE: Gen:Variant.Tedy.988609
huorong: Backdoor/W64.Agent.g

Hashes

MD5 7bf05747b52371e8b032ca6064153e9f
SHA1 7efb5aecb2ef8f4ddd4a1b5a7d5de99f01af81f6
SHA256 48e43339a3da662b6444d6ebfcb0129bfa77a9e7feb6a9660167cdaa0e149318
SHA3 0e12b1eab7c8a5a3dbd280f7c18e6d4abbcffb9b156804493ef1bf7339f27573
SSDeep 49152:V9OubDzFwjkr3bfpb83NPYlcABu+d1TrrZoOHY:BTF6v3NPYlcABu+d1TR0
Imports Hash 112419928c71c51f3afaadb5f5015c67

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-24 16:25:21
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x13c000
SizeOfInitializedData 0x65a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000134DDC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1a6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 45731ae055507b18d4831939abb43597
SHA1 bd956fc3e43590ba9ed328fa2dd54123729ba421
SHA256 afbfcfb6b9d440d175af5cd490965f74f0a4186f51555a9285cb4aa02798b6e9
SHA3 a2f9f5b7605802ab5907acf765a32043b28362024c209e9266ae354bf6b2e034
VirtualSize 0x13bf7c
VirtualAddress 0x1000
SizeOfRawData 0x13c000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51866

.rdata

MD5 69e645ec501abcd365c3464d2095ee98
SHA1 08883c3f0dea044096b16bf7ebc326317881fabe
SHA256 532b32e0d6433e21b980a183a80d0adf32d5829fd5f6ca6af5c86b5108d62aca
SHA3 5c4f0352b7b6ffb8109aabb604348c41e4ad9184fa2692bbeedc53b04cdfc958
VirtualSize 0x4840a
VirtualAddress 0x13d000
SizeOfRawData 0x48600
PointerToRawData 0x13c400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.25398

.data

MD5 e5be29cea86a98a924a10c74356f196e
SHA1 397de9d60903fe4ef1a3a472bfda5a6a2d3cfe16
SHA256 48fe884e5f2430170337902f1de477923530b498bceea60b837cef59cb6e65a8
SHA3 0af0b13661e5bdf6e41a84d0423928434c48a48e232b5d0bedfb94bb48f4170d
VirtualSize 0x3af0
VirtualAddress 0x186000
SizeOfRawData 0x2000
PointerToRawData 0x184a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.97935

.pdata

MD5 6f24777644d18c82190a6b2092dfc07e
SHA1 b7eb3c9269dd9a7c277068c24ae1db8be329e7f1
SHA256 b668a3104492f361a445848dff7edec264d154717cdb3807ec01a6b97a1beb19
SHA3 f1dc3d5484374ca427f6521a6562d19f4e262173836603f06682585a9023d5e3
VirtualSize 0x97ec
VirtualAddress 0x18a000
SizeOfRawData 0x9800
PointerToRawData 0x186a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.10026

.rsrc

MD5 015f5701c4e84e0f2d42e877dac31451
SHA1 d2f82112a8495ba8246afa9ed57c8d6db6bb151f
SHA256 30f2aadf26d3d3d4a00cfc031688fcbb6c00ee4de0c949d13ae42872dde082a3
SHA3 55f948bfa0662be53d5ebc50a4dc31ea06d3b3ba3b8628991d1be8073cd3b3ba
VirtualSize 0x10cf0
VirtualAddress 0x194000
SizeOfRawData 0x10e00
PointerToRawData 0x190200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72035

.reloc

MD5 67fccb93ae918495adf8c58dc52d755d
SHA1 eefe3e95c0597f1aa69071feabd73cba728988e7
SHA256 68341f942e587df18ef0df5345bf65d5c88491415c0b351dc6d81bbc58714c51
SHA3 2147a7b1e15a34a1cc0da1371f87642f9a55a2d893bdeec96a80a00dd78213fd
VirtualSize 0xc6c
VirtualAddress 0x1a5000
SizeOfRawData 0xe00
PointerToRawData 0x1a1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.16341

Imports

WINHTTP.dll WinHttpCrackUrl
WinHttpSendRequest
WinHttpCloseHandle
WinHttpSetOption
WinHttpOpenRequest
WinHttpReadData
WinHttpOpen
WinHttpReceiveResponse
WinHttpConnect
WinHttpQueryDataAvailable
ADVAPI32.dll OpenSCManagerW
CryptImportKey
CopySid
SetSecurityInfo
RegDeleteKeyA
IsValidSid
CryptDestroyKey
InitializeAcl
GetLengthSid
AddAccessAllowedAce
GetTokenInformation
RegEnumKeyExA
RegQueryValueExW
RegEnumValueW
RegDeleteValueA
OpenServiceW
RegDeleteValueW
RegEnumValueA
RegOpenKeyExW
RegOpenKeyExA
OpenProcessToken
RegSetValueExA
RegDeleteTreeW
RegEnumKeyExW
ControlService
DeleteService
RegCreateKeyExA
LookupPrivilegeValueA
CryptEncrypt
RegQueryValueExA
CloseServiceHandle
RegCloseKey
AdjustTokenPrivileges
RegEnumKeyA
SystemFunction036
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptReleaseContext
CryptAcquireContextW
ConvertSidToStringSidA
SHELL32.dll ShellExecuteW
ShellExecuteExA
ShellExecuteA
SHGetFolderPathW
IPHLPAPI.DLL GetAdaptersAddresses
CreateIpNetEntry
DeleteIpNetEntry
GetAdaptersInfo
GetIpNetTable
VirtDisk.dll CreateVirtualDisk
OpenVirtualDisk
DetachVirtualDisk
gdiplus.dll GdiplusStartup
GdiplusShutdown
GdipAddPathLine
GdipCreateStringFormat
GdipDeleteFontFamily
GdipResetClip
GdipCreateFontFamilyFromName
GdipSetStringFormatAlign
GdipSetClipRect
GdipSetPenStartCap
GdipDeleteBrush
GdipAlloc
GdipDeletePath
GdipSetSmoothingMode
GdipCreateLineBrush
GdipCreatePath
GdipSaveGraphics
GdipCreateFont
GdipCreateSolidFill
GdipSetStringFormatTrimming
GdipFillPath
GdipDrawLine
GdipDrawRectangle
GdipFillRectangle
GdipSetClipRectI
GdipClosePathFigure
GdipFree
GdipDrawPath
GdipDrawString
GdipCreateFromHDC
GdipFillEllipse
GdipSetPenEndCap
GdipSetTextRenderingHint
GdipDrawEllipse
GdipRestoreGraphics
GdipCloneBrush
GdipFillRectangleI
GdipAddPathArc
GdipDeleteGraphics
GdipDrawArc
GdipDeleteStringFormat
GdipDeleteFont
GdipDeletePen
GdipCreatePen1
GdipSetStringFormatLineAlign
dwmapi.dll DwmSetWindowAttribute
COMCTL32.dll #345
SETUPAPI.dll SetupDiGetDeviceRegistryPropertyA
SetupDiEnumDeviceInfo
SetupDiDestroyDeviceInfoList
SetupDiGetClassDevsA
SetupDiGetDeviceInstanceIdA
KERNEL32.dll InitializeSListHead
UnhandledExceptionFilter
OutputDebugStringW
GetSystemTimeAsFileTime
SetUnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
IsDebuggerPresent
WakeAllConditionVariable
GetCurrentThreadId
ReadFile
GetModuleFileNameA
GetVolumeInformationW
GetLogicalDrives
FindFirstFileW
GetFileSizeEx
FindFirstFileA
VirtualProtect
GetConsoleScreenBufferInfo
SetConsoleTitleA
FindNextFileW
GetCurrentProcess
GetStdHandle
WriteFile
ExpandEnvironmentStringsW
SetConsoleMode
DeviceIoControl
TerminateProcess
RemoveDirectoryW
GetDriveTypeA
GetCurrentDirectoryW
Thread32Next
ExpandEnvironmentStringsA
SetFilePointer
SetEndOfFile
Thread32First
FindClose
GetVolumeInformationA
WaitForSingleObject
CreateFileW
GetFileAttributesW
GetSystemDirectoryW
ResumeThread
GetModuleHandleA
SetFileAttributesW
GetLogicalDriveStringsW
CreateToolhelp32Snapshot
MultiByteToWideChar
Sleep
GetConsoleMode
GetTempPathA
GetTickCount64
CopyFileA
GetLastError
GetFileAttributesA
Process32NextW
SetFileInformationByHandle
CreateFileA
GetCurrentThread
GetSystemDirectoryA
AreFileApisANSI
CreateDirectoryW
DeleteFileW
Process32FirstW
CloseHandle
K32GetModuleInformation
SetFileAttributesA
GetLocalTime
GetThreadContext
GetProcAddress
RemoveDirectoryA
ExitProcess
SetConsoleCP
GetCurrentProcessId
GetProcessHeap
CreateProcessW
GetModuleHandleW
FreeLibrary
WideCharToMultiByte
GetConsoleWindow
SetComputerNameExA
CreateProcessA
SetConsoleOutputCP
GetDiskFreeSpaceExA
CreateDirectoryA
SetConsoleCursorPosition
GetTickCount
AllocConsole
GetDriveTypeW
OpenThread
LoadLibraryExW
FlushFileBuffers
GetExitCodeProcess
SetHandleInformation
GetModuleFileNameW
CreatePipe
GetTempPathW
IsProcessorFeaturePresent
CopyFileW
AddVectoredExceptionHandler
HeapDestroy
HeapAlloc
HeapReAlloc
HeapFree
HeapSize
InitializeCriticalSectionEx
DeleteCriticalSection
CreateThread
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
QueryFullProcessImageNameW
SetLastError
FormatMessageW
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
LocalFree
QueryPerformanceFrequency
LoadLibraryW
SleepEx
GetSystemInfo
QueryPerformanceCounter
MoveFileExW
WaitForSingleObjectEx
GetEnvironmentVariableA
GetFileType
PeekNamedPipe
WaitForMultipleObjects
VerSetConditionMask
VerifyVersionInfoW
FindFirstFileExW
GetFileAttributesExW
GetFileInformationByHandle
GetFinalPathNameByHandleW
DeleteFileA
GetFullPathNameW
GetFileInformationByHandleEx
FormatMessageA
GetLocaleInfoEx
LoadLibraryA
SleepConditionVariableSRW
FindNextFileA
USER32.dll PostMessageW
EnumDisplayDevicesA
GetWindowRect
SetWindowPos
MessageBoxW
SetWindowRgn
CreateWindowExW
RegisterClassExW
SetTimer
DefWindowProcW
SetCapture
GetClientRect
KillTimer
ReleaseCapture
MessageBoxA
DestroyWindow
PostQuitMessage
FindWindowA
RegisterClassExA
UpdateWindow
GetCursorPos
SendMessageW
GetSystemMetrics
ShowWindow
DispatchMessageW
GetWindowTextA
SetWindowTextA
CreateWindowExA
SetLayeredWindowAttributes
TranslateMessage
EndPaint
InvalidateRect
GetMessageW
LoadCursorW
EnumDisplaySettingsA
UnregisterClassA
BeginPaint
GDI32.dll SetTextColor
GetStockObject
CreateFontA
DeleteObject
DeleteDC
CreateRoundRectRgn
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
SetBkMode
CreateSolidBrush
MSVCP140.dll ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?id@?$ctype@D@std@@2V0locale@2@A
?_Random_device@std@@YAIXZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??Bid@locale@std@@QEAA_KXZ
_Query_perf_frequency
_Query_perf_counter
_Xtime_get_ticks
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?_Xbad_function_call@std@@YAXXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z
?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?uncaught_exception@std@@YA_NXZ
?_Xbad_alloc@std@@YAXXZ
?id@?$ctype@_W@std@@2V0locale@2@A
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Thrd_detach
_Thrd_join
_Mtx_unlock
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ
??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
?widen@?$ctype@_W@std@@QEBA_WD@Z
??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?width@ios_base@std@@QEAA_J_J@Z
?width@ios_base@std@@QEBA_JXZ
?good@ios_base@std@@QEBA_NXZ
??7ios_base@std@@QEBA_NXZ
??Bios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
WS2_32.dll getsockname
WSASetLastError
getsockopt
getpeername
gethostname
ioctlsocket
sendto
recvfrom
freeaddrinfo
getaddrinfo
listen
htonl
accept
select
__WSAFDIsSet
WSAIoctl
connect
send
recv
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAEventSelect
bind
WSAResetEvent
WSAWaitForMultipleEvents
closesocket
setsockopt
WSAGetLastError
socket
inet_pton
ntohs
WSACleanup
WSAStartup
inet_ntop
htons
urlmon.dll URLDownloadToFileA
SHLWAPI.dll PathFindFileNameW
USERENV.dll UnloadUserProfile
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll wcsstr
strstr
strrchr
__current_exception_context
__current_exception
__C_specific_handler
wcschr
strchr
memset
memmove
memcpy
memcmp
memchr
_CxxThrowException
__std_exception_destroy
__std_exception_copy
__std_terminate
api-ms-win-crt-runtime-l1-1-0.dll __sys_errlist
__sys_nerr
_register_onexit_function
_errno
_initialize_onexit_table
abort
_invalid_parameter_noinfo
terminate
_resetstkoflw
_invalid_parameter_noinfo_noreturn
_beginthreadex
_invoke_watson
_register_thread_local_exe_atexit_callback
_c_exit
_cexit
__p___argv
__p___argc
_exit
_initterm_e
_initterm
exit
_get_initial_narrow_environment
_crt_atexit
_initialize_narrow_environment
_configure_narrow_argv
_set_app_type
system
_seh_filter_exe
api-ms-win-crt-stdio-l1-1-0.dll _lseeki64
fgetc
fgetwc
fputc
_wfopen
_wopen
fwrite
_set_fmode
__stdio_common_vsscanf
__stdio_common_vsprintf
fgetpos
feof
__stdio_common_vswprintf_s
fputs
setvbuf
__p__commode
ungetwc
ungetc
fsetpos
__acrt_iob_func
fread
_popen
_pclose
_fseeki64
_read
_write
fgets
_get_stream_buffer_pointers
_fileno
_close
fclose
fputwc
ftell
fflush
_wfopen_s
fseek
__stdio_common_vsprintf_s
api-ms-win-crt-heap-l1-1-0.dll free
calloc
_set_new_mode
_callnewh
realloc
malloc
api-ms-win-crt-utility-l1-1-0.dll rand
srand
qsort
api-ms-win-crt-string-l1-1-0.dll strnlen
isdigit
_strdup
_wcsicmp
_wcsdup
towlower
strcspn
_stricmp
strncmp
wcspbrk
strspn
strcmp
wcsncmp
strpbrk
wcsncpy
tolower
wcscat_s
api-ms-win-crt-conio-l1-1-0.dll _getch
api-ms-win-crt-convert-l1-1-0.dll strtoul
strtoll
atoi
strtod
strtol
strtoull
wcstombs
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_fstat64
_lock_file
_unlink
_wstat64
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64
_localtime64
strftime
api-ms-win-crt-math-l1-1-0.dll _dsign
__setusermatherr
cosf
sinf
_fdopen
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
___lc_codepage_func
localeconv
CRYPT32.dll CertGetNameStringW
CertOpenStore
CertFindExtension
CertGetCertificateChain
CertFreeCertificateChain
CertAddCertificateContextToStore
CryptDecodeObjectEx
PFXImportCertStore
CryptStringToBinaryW
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertFreeCertificateContext
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
PSAPI.DLL GetModuleInformation

Delayed Imports

123

Type GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11665
Detected Filetype Icon file
MD5 43072efc112e4438492cc95bec4eefb5
SHA1 22f6be1fb470064e76c41caeb399b5edf6c1cdcc
SHA256 d74a8df948b03e06ae775bbde3cef92330c26604428627e991c576b50a22cb88
SHA3 4e2409987532c7e46c92d2459c48580ec65607a1e54459323213d7fd8c0a4ae2

1

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66021
MD5 c601b60afd3317ff5b5dc586058630dc
SHA1 cc954b65619e07dec1b416e0c10ddce9bce66575
SHA256 b807981d9a07957e24e3de8931a81feb60abafc37bf2c69572c6b56fbdeb9fac
SHA3 a5a6c47afca7a48020cc49e2062a78b46259bbe50abd0d0717a9e90e72316db2

2

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63427
MD5 ea374dda5b84cacde5120306d69bfaa9
SHA1 1c283c1e1da559b00b36b0310863055fc3e75b04
SHA256 7fac61317bb44c2bcdc708181e5b03c7cc11cc7d8f2c044bb98ed3a60b4d0d0c
SHA3 bb7132163b4a1eee044275e38afc4f21d6b544f429605638ba841637637ef665

3

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.87259
MD5 995951209c9e285cf0e0332d25b9b312
SHA1 0c72c014593ef3900f5cd3131b366ca14b3a3289
SHA256 7e2c8ebee2247331d06d97fdff7c41bce9fff1111bd1868a753454ecf1766ebe
SHA3 5c750388878191472034389f201c413234dff6b32594ca0dc6f55f9b251cc5c0

4

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.59789
MD5 620b6f8e941e1c2d7ec5934d6d319f22
SHA1 81df05fdf81d09affd2c2f797d15d77c7fc98a77
SHA256 e5f707776c15b07b8264752be89b2ef99d33e1a668b848ab03827a115ad43799
SHA3 27c4f895d64e13946e39b8b202c87b8458e823dba8f6d8b5bb6c9739ead3e00b

5

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98127
MD5 7d5125c1700741cdbbc05496cf7234c0
SHA1 1c58e68f2c65f3eba4e0cafea3fa39ab8bf29444
SHA256 cb4187a9a9cc7d7f920eed34041740e01928b1ae567d98c213ffec79e8426e37
SHA3 37153415bf5209658db4dab0d4b9e340701fd2b3230f8ef894e3b0670e640ce4

6

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x35e2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91128
Detected Filetype PNG graphic file
MD5 46c1e16e876119e4e626ecc309f31c51
SHA1 29099b92d351f02a34625a6a43420d92d2d5efd9
SHA256 7c137572bb0108e087eff43948017c63eb81be4e18fdf93a62be12b752b5e3b9
SHA3 79029f8f80e8e3932e56b2b94df053bb30e92d7d9ecd1a8590ddaec2c741b447

7

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.60646
MD5 b44e8d7588364ee607955b088747bed6
SHA1 12a734d64439bacc39fd5f7d0c3e40c85b244a78
SHA256 b1b0b9a6a2d05dbaa4d3f22653129bdbbaf32a3a264359c1f9ea130887f9216d
SHA3 de8deba5b8515dac6bb3b0ec8147f240e7512c861d30f0e31f5ca4f2fadd0d91

8

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81183
MD5 a96a94ad1a1e33f64ff2d3e167fb9467
SHA1 7be974d14bca3433713b90ba87db02ff862619aa
SHA256 3a1c250c88638fef5d53dbc57a8df419c332c8886ad16b763a1b53e813c41bf8
SHA3 d2f4381e229466bf641c617ca51c59fbfd6d4c826d4259cb472bc177893fa326

9

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76409
MD5 12606923495bc5c6fd46405ad90824d7
SHA1 a8f9f2f6757671d95356e692685a73a14f5ec55b
SHA256 a8f8ac614cf89bc2aa75f9ee7ac3fe61b21d04a80fdaacc3d00777ebdf81698a
SHA3 24d0ede201dc5d1ed1f99d56a44b2cd8d63dd711054b63602e1110652fa99e70

10

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02681
MD5 0a3e9865544865f0be6a88c996708960
SHA1 6504f9acbec580dd551ba9e94fc2ba6028b20811
SHA256 43407b89e09806978c716ffe34f98a9f6923e603c3905e1c61ffbf9ded2502f8
SHA3 a46820209ce09dffde5169d14f1c095c555bd349d5c1937019cde180a8d40043

11

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52572
MD5 2cd4c617697adf4b60620e0fbdaa92c1
SHA1 bd6e34b7d9f1330a854d7afb6710db772201a8cd
SHA256 fff8374306e0916a17010d8246a70712df3556e37423dce7420c5fa556fd7262
SHA3 fa3db35b6754283b28a41a2dbcd9ddb8d3b24e06fb9f007900d4928fcf0efae5

12

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4258
MD5 f3b1004c9d3e9bf9b2226d162f9827a9
SHA1 15067eaf95d811d006911f7cdea6160d14c38421
SHA256 1d394661800e33bef5ad09bce87d117decb0229c86ac9af1ecd51a3547304021
SHA3 58656eda8a0515b80859b5883ace643a3bd6408a76ae71ea34c47e86e181d049

13

Type ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.8839
MD5 ff40094e77198173cf772bd64bee9d3d
SHA1 f28cbc687b6221a13dc02543b363e426fcdc41bb
SHA256 8e0d1736ef9794f341aa4c8607704cd26a5f151e7a78bd3a11f59b7bb4e0c805
SHA3 f8009623bfaed9d0d55ac31da8583cfac5333ee1f842e81cb844786227ff1893

1 (#2)

Type MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x417
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44473
MD5 262bab911e161cab80f8b026b95cd9e9
SHA1 2c60abcdb0f4bcc116b0c0a02e4e87cdae7722d3
SHA256 228b66dced54b3cd73b9e6eb2efbc5797b41959f06e025aec05864294a823b5f
SHA3 1aade489844d5953b1990ad589c5735013289f8038340618818453031b0cdb01

1 (#3)

Type VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x36c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46402
MD5 e3df4d5df0e03a2332ff87a16c325e13
SHA1 3a296b44d3b91692c71e7c2e563275e67c21cb82
SHA256 c635d7e79de8872c9fd176bb455cc1615e3ee6cb78bab3cd3f02524aad3f3b4d
SHA3 9d6cdcf6be161594fdbf465376bfe1993a5fef459fe4d295e291d1f125cb12d4

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06467
MD5 d875a3e09bd74a8f760449a19a351827
SHA1 870df3cd183e92816fb4f92427cafa686f946a33
SHA256 a148bb733a7a6233501d6e615bcd37bedb995c29670798088e6c9c325b4429c8
SHA3 782f36c3fdf8521b0f1ebd9c721ce82161d3bd77c965734f3fd2714a3113db23

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-24 16:25:21
Version 0.0
SizeofData 120
AddressOfRawData 0x16e72c
PointerToRawData 0x16db2c
Referenced File C:\Users\Seven\Desktop\Desktop\Bureau\PERM X\Shadow_Master_Loader\bin\Release\MysticProject.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-24 16:25:21
Version 0.0
SizeofData 20
AddressOfRawData 0x16e7a4
PointerToRawData 0x16dba4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-24 16:25:21
Version 0.0
SizeofData 912
AddressOfRawData 0x16e7b8
PointerToRawData 0x16dbb8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-24 16:25:21
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14016eb68
EndAddressOfRawData 0x14016eb70
AddressOfIndex 0x140188748
AddressOfCallbacks 0x14013e548
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140186f40

RICH Header

XOR Key 0xcc66d4c8
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 24
253 (35207) 7
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 40
Imports (35207) 6
C objects (33145) 1
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 129
C++ objects (34436) 5
Imports (33145) 41
Total imports 698
C++ objects (LTCG) (35226) 2
Resource objects (35226) 1
Linker (35226) 1

Errors

Leave a comment

No comments yet.