4ab7bf0ed2498da51e14dfac96af13376320d338364b0e5336d897ea1bc2b8fc

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-May-30 03:14:55
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts C:\Users\Matt\source\repos\FPV KD\x64\Release\FPV KD.pdb
CompanyName Tsuda Kageyu
FileDescription MinHook - The Minimalistic API Hook Library for x64/x86
FileVersion 1.3.4.0
InternalName MinHookD
LegalCopyright Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
LegalTrademarks Tsuda Kageyu
ProductName MinHook DLL
ProductVersion 1.3.4.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • MapVirtualKeyA
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 3/69 (Scanned on 2026-07-24 19:37:59) Bkav: W32.Malware.E07ABABA
Cynet: Malicious (score: 100)
Google: Detected

Hashes

MD5 8710e66dcea7da47056ae63e0f9d6920 🔍
SHA1 8091c2d4a186807593cc54f00e2b07cfb40814a6 🔍
SHA256 4ab7bf0ed2498da51e14dfac96af13376320d338364b0e5336d897ea1bc2b8fc 🔍
SHA3 85f74cb32c2f687650e9a4d3cd603502497140565269e3b9423798afeb1aff76 🔍
SSDeep 12288:myTP9xqWhMC2vtloQgx1Qg9p3l3QzjmoapuZB7XEnSGEYn:pTOW4BgPlz3l3+jmaEnSGv 🔍
Imports Hash 966491408d87a84b766059a6cc66fbc6 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-May-30 03:14:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x88200
SizeOfInitializedData 0x23200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000876CC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xb0000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4bb537b22dae89f267b3b41f5ea3a6ca 🔍
SHA1 e8cfca9b98ab410c6aa6b32cd20ae4385072a5f9 🔍
SHA256 3bf4323f360dee760f9dcca1faeb5b57fc011befd78ff7db86944d8c30a37e11 🔍
SHA3 fd3fbe52486ec1fefc5c3210058c814f5448a30da2ed431e6e1445c053a19860 🔍
VirtualSize 0x88081
VirtualAddress 0x1000
SizeOfRawData 0x88200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50351

.rdata

MD5 b0afd61d11e89ce0f91a1e50ccfec9b8 🔍
SHA1 a95dd99469d8f9cf07f2dac54dff61fd8220d6dc 🔍
SHA256 62d395a7c968fe4cd83b1160c837eff9226ee2564b283a3d008ebbf7cf3d0b76 🔍
SHA3 1633cb1ff9c20d1f14c0c357b51a757b4804d8fa8ddb5375c9956ae19a1ebf02 🔍
VirtualSize 0x18c58
VirtualAddress 0x8a000
SizeOfRawData 0x18e00
PointerToRawData 0x88600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.86407

.data

MD5 22fff2c4aa94426635b4b5abfea9bc4a 🔍
SHA1 f3cb1e2c054d5e0592aad5b263a0ae66d413d54b 🔍
SHA256 b261b77f7cf9ddb91e3aeaf94ba0da42b37f472d4f2400c0c10701daecf33af1 🔍
SHA3 1e3198f20ea590ec1ad4f913634c1b069c9a7965e154e745a3ec82d2b77223c2 🔍
VirtualSize 0x4628
VirtualAddress 0xa3000
SizeOfRawData 0xe00
PointerToRawData 0xa1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.44177

.pdata

MD5 eff656453d4ebf41d2cce785b42284c5 🔍
SHA1 51f1262f091f357671279cf0e1d32d9c879f4b02 🔍
SHA256 4ced8ec45d0a4bdf800eb22eff699413d5409b908d132020fa6184588ed9e87e 🔍
SHA3 94b4ab798f04ea20b4154157b995274acaf4b831df54c941957a4e4dd539dc8d 🔍
VirtualSize 0x519c
VirtualAddress 0xa8000
SizeOfRawData 0x5200
PointerToRawData 0xa2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.90853

.rsrc

MD5 71e1f34f9660abfdb7ae5e4134eb0dcc 🔍
SHA1 6cb30e25293a8745969d5f904437b5365410851a 🔍
SHA256 54a53d19b96d7f78ddc5554d665a2703bf7732663392f15be085d44518b14cb5 🔍
SHA3 a44fe9872c9dde4bdeb289ae15988c340824efc4c3f4268733b537fc65388d98 🔍
VirtualSize 0x498
VirtualAddress 0xae000
SizeOfRawData 0x600
PointerToRawData 0xa7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.06916

.reloc

MD5 622bc6ddce279747476fa0352ed246f3 🔍
SHA1 8ee1d8ae49b45487e681384912275b6ce0d9c18d 🔍
SHA256 e02893f1f7ed0ed30184bcc1d7ffdbc735bc189f6e37008d89189017e0e2942c 🔍
SHA3 0d1e81d4a829401b7b77fbe1a8b77eef33fa22d95b85ca0e0d1eb09a09886cfb 🔍
VirtualSize 0x370
VirtualAddress 0xaf000
SizeOfRawData 0x400
PointerToRawData 0xa7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.85292

Imports

KERNEL32.dll VirtualProtect
HeapFree
GetCurrentProcess
Thread32Next
Thread32First
GetCurrentThreadId
SuspendThread
ResumeThread
CreateToolhelp32Snapshot
GetLastError
HeapReAlloc
CloseHandle
HeapAlloc
HeapDestroy
GetThreadContext
GetProcAddress
GetCurrentProcessId
FlushInstructionCache
SetThreadContext
OpenThread
GetModuleHandleA
WaitForSingleObject
GetModuleHandleExA
GetModuleFileNameA
GetSystemInfo
CreateThread
FindFirstFileA
FindNextFileA
GetEnvironmentVariableA
FindClose
DeleteFileA
CreateDirectoryA
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
LoadLibraryA
GetLocaleInfoA
QueryPerformanceFrequency
FreeLibrary
QueryPerformanceCounter
GetSystemTimeAsFileTime
DisableThreadLibraryCalls
GetTickCount64
HeapCreate
InitializeSListHead
VirtualAlloc
VirtualFree
VirtualQuery
GetFileAttributesA
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
GetModuleHandleW
FreeLibraryAndExitThread
CreateEventA
Sleep
ReleaseSRWLockExclusive
USER32.dll ClientToScreen
GetCapture
ScreenToClient
LoadCursorA
GetMessageExtraInfo
GetKeyState
GetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetKeyboardLayout
TrackMouseEvent
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
SetCursorPos
SetClipboardData
GetKeyNameTextA
MapVirtualKeyA
DestroyWindow
CreateWindowExA
ShowCursor
ClipCursor
ReleaseCapture
CallWindowProcW
GetRawInputData
SendInput
GetAsyncKeyState
GetClipboardData
SetWindowLongPtrW
SHELL32.dll ShellExecuteA
MSVCP140.dll ?_Xbad_function_call@std@@YAXXZ
_Mtx_unlock
_Mtx_lock
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Throw_Cpp_error@std@@YAXH@Z
d3d12.dll #101
dxgi.dll CreateDXGIFactory2
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_type_info_destroy_list
__C_specific_handler
__std_terminate
__std_exception_destroy
__std_exception_copy
strrchr
strstr
memchr
memcmp
memcpy
memmove
memset
_CxxThrowException
api-ms-win-crt-string-l1-1-0.dll strlen
wcslen
strncmp
tolower
towlower
strcmp
strncpy
api-ms-win-crt-heap-l1-1-0.dll _callnewh
malloc
free
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vsprintf
fclose
__stdio_common_vfprintf
fread
_wfopen
fwrite
fgets
fseek
fflush
__acrt_iob_func
ftell
__stdio_common_vsscanf
fopen_s
api-ms-win-crt-convert-l1-1-0.dll atof
atoi
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-runtime-l1-1-0.dll _cexit
_initterm
_initterm_e
_configure_narrow_argv
_crt_atexit
_initialize_narrow_environment
_execute_onexit_table
_initialize_onexit_table
_register_onexit_function
_seh_filter_dll
api-ms-win-crt-math-l1-1-0.dll cos
ceilf
cosf
floorf
atan2f
atan
asinf
acosf
_fdclass
pow
powf
sin
fmod
sinf
sqrtf
tanf
log
fmodf
logf

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51142
MD5 f8980a7eb607c0d9a99a7a8fe55c455c 🔍
SHA1 cb2c1b5e5aae5ac4161e164b94ebfaada3436b5b 🔍
SHA256 6d0f774f55eabd76cded8f4ea42d9e87a19b247b5bc0e181244b059598c8ccc4 🔍
SHA3 a6c125bdfb29cfdb94606d89dcca16d5faae95856000074a8be048803f5b517d 🔍

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x91
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8858
MD5 f7ad1eab748bc07570a57ec87787cf90 🔍
SHA1 0b1608da9fef218386e825db575c65616826d9f4 🔍
SHA256 d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04 🔍
SHA3 6c9541b36948c19ae507d74223621875b3af4064f7cd8200bdb97e15a047e96a 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.3.4.0
ProductVersion 1.3.4.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Tsuda Kageyu
FileDescription MinHook - The Minimalistic API Hook Library for x64/x86
FileVersion (#2) 1.3.4.0
InternalName MinHookD
LegalCopyright Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
LegalTrademarks Tsuda Kageyu
ProductName MinHook DLL
ProductVersion (#2) 1.3.4.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-May-30 03:14:55
Version 0.0
SizeofData 81
AddressOfRawData 0x9804c
PointerToRawData 0x9664c
Referenced File C:\Users\Matt\source\repos\FPV KD\x64\Release\FPV KD.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-May-30 03:14:55
Version 0.0
SizeofData 20
AddressOfRawData 0x980a0
PointerToRawData 0x966a0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-May-30 03:14:55
Version 0.0
SizeofData 932
AddressOfRawData 0x980b4
PointerToRawData 0x966b4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-May-30 03:14:55
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x180098480
EndAddressOfRawData 0x1800989d8
AddressOfIndex 0x1800a3d98
AddressOfCallbacks 0x18008a6d0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x000000018008720C
0x000000018008727C

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1800a3040

RICH Header

XOR Key 0x9a7c1738
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (35403) 3
C objects (35403) 8
C++ objects (35403) 25
Imports (35403) 6
Imports (33145) 19
Total imports 194
C++ objects (LTCG) (35730) 29
Resource objects (35730) 1
151 1
Linker (35730) 1

Errors

Leave a comment

No comments yet.