51b9eb394d5b1a36bc2bf3264077cc400bafab7a3a88097e68bf4015b0655014

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00
Detected languages Chinese - Taiwan
TLS Callbacks 2 callback(s) detected.
InternalName PingTargetModeToggle.exe
ProductVersion 10.4.2141.796
FileDescription Synchronizes ping target mode toggle between applications on the same PC
LegalCopyright (c) 2026 Riverstone Creek Digital. All rights reserved.
OriginalFilename PingTargetModeToggle.exe

Plugin Output

Suspicious PEiD Signature: XWD graphics format
HQR data file
Info Interesting strings found in the binary: Contains domain names:
  • golang.org
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Info The PE is digitally signed. Signer: Ping Target Mode Toggle
Issuer: Ping Target Mode Toggle
Malicious VirusTotal score: 8/70 (Scanned on 2026-06-11 09:14:56) Bkav: W32.Malware.954012CF
Elastic: malicious (moderate confidence)
Kaspersky: VHO:Trojan.Win64.DLLhijack.gen
Kingsoft: Win64.Trojan.DLLhijack.gen
Malwarebytes: Trojan.MalPack
Microsoft: Trojan:Win32/Wacatac.B!ml
Trapmine: malicious.high.ml.score
huorong: Trojan/FakeDll.aj

Hashes

MD5 e024a6851f24ec6fd2853c528a7d9004
SHA1 da7cb5459812f22db53874a3d2de278d90c5c6e5
SHA256 51b9eb394d5b1a36bc2bf3264077cc400bafab7a3a88097e68bf4015b0655014
SHA3 775f11d7381c0c02870c4b5a091acb24147d474d980f38bcf44c8d4f29116c2f
SSDeep 98304:6d9fMsgnf0wj3QmpE7LKnBnkYGri/KdvXAhhcdI7:6H+f0K3S5lriydEc
Imports Hash f604c1c3e882e6a725b213d7fdcb6bc5

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 12
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0xe1000
SizeOfInitializedData 0x5b4e00
SizeOfUninitializedData 0x204ae00
AddressOfEntryPoint 0x00000000000012EF (Section: .text)
BaseOfCode 0x1000
ImageBase 0x2d8aa0000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x26e8000
SizeOfHeaders 0x400
Checksum 0x6a0025
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b25677366850b8834a4dc567a2079dab
SHA1 d7dc6e13cfd78634107c7b9fa23ec056455fafe3
SHA256 fc336153f88a0fbfb8c03ce73cf494a7dc951fc036594e420c373d797ba6387a
SHA3 22064838c37f51670fcf2114d48670fd82a5f6ca58b035bb7baeacf17741b8bb
VirtualSize 0xe0e30
VirtualAddress 0x1000
SizeOfRawData 0xe1000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.30446

.data

MD5 855e01865a25fb34913c2e4f01cad232
SHA1 4c727a9495580a4178fa1a4562791aaca418eec2
SHA256 10becd8638359a8c93344849c6afd931082573d8f726c4b1031b134099086d35
SHA3 e16aab8efdf38cc1632fe2ccdd84a4ffa066c0d829927c8479cdad099ec258fb
VirtualSize 0x481670
VirtualAddress 0xe2000
SizeOfRawData 0x481800
PointerToRawData 0xe1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.99233

.rdata

MD5 af593df884ebc992214d70c89f371c92
SHA1 cbf451c70b1a32221bd1624a64f5df1aa69e29d8
SHA256 9b32f4c94e7e4eda48db1e20a535ef01e794c96d01bc0a57c40f9745f17d3e86
SHA3 f74ee51105608f416c41332bf732b394e845f7a060b307278ce89ec31a4c163b
VirtualSize 0x111600
VirtualAddress 0x564000
SizeOfRawData 0x111600
PointerToRawData 0x562c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.52044

.eh_fram

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x4
VirtualAddress 0x676000
SizeOfRawData 0x200
PointerToRawData 0x674200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.pdata

MD5 5dd0522bba139bf891c3244bbba2b09c
SHA1 a2a039242759a7044813fdbbf4fcf92766e42891
SHA256 c718783f11f2356168a1a11b99a9332e03469de9edd9f522642718b073d00027
SHA3 28fa30d848237dedf1883dcf6df763a8771a67abe785c6a7c1c8b3bf7d5c7bd6
VirtualSize 0x6240
VirtualAddress 0x677000
SizeOfRawData 0x6400
PointerToRawData 0x674400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.33371

.xdata

MD5 82e958f1db33d67d1ef887b4d7a330e6
SHA1 862665290983925cebb6f5b78083b1b51762771c
SHA256 5fa5aefc60599ebf274a7bb655072eae93aa36fd2be30bb4914f621f8dcc8291
SHA3 75c855af66e102f83a5714c93a2c93895c14a173cbf43b649e276426e6cc1158
VirtualSize 0x364
VirtualAddress 0x67e000
SizeOfRawData 0x400
PointerToRawData 0x67a800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.51521

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x204add0
VirtualAddress 0x67f000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.edata

MD5 9b4f23bce613374502eb6eedf6b47a25
SHA1 1eb77801e28a277875b813a0683dae384efa906d
SHA256 a1cd9b9384d83454f1ce4c115fe206f37a9d72199ccb59e30dad46e22a154fdd
SHA3 e5cabfe716b83b6cce0c84adebe785e587fa8827c2f0da61a26c678ba656a9eb
VirtualSize 0xfa
VirtualAddress 0x26ca000
SizeOfRawData 0x200
PointerToRawData 0x67ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.9197

.idata

MD5 3ab39eb740f3311754f08774e8122078
SHA1 0b2fed9c76b35efe4345ad2ce11182b89066be85
SHA256 3b406838ec71412a07eb501d24335939c55a9e0cc8ae99dec598448729a11565
SHA3 8f00638ea58a455bfc5d31945cce283951ab8aa7a41bab797c0a857d91f70fec
VirtualSize 0xd48
VirtualAddress 0x26cb000
SizeOfRawData 0xe00
PointerToRawData 0x67ae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.57428

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x26cc000
SizeOfRawData 0x200
PointerToRawData 0x67bc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 af6a60a4b18b16f7b6ef6a74bdb93ea4
SHA1 43577619f5386c9bd9c38c1cfec487704e3c71d1
SHA256 b20d8150ff6e8880d3e8b94ad60b5b55cf96ec42bcbf1ff6711717c00f288af3
SHA3 c61bb9bb3a1b629cc6e27ec724c0ff902361354fe073eb486a0afda5e42e73eb
VirtualSize 0x4ac4
VirtualAddress 0x26cd000
SizeOfRawData 0x4c00
PointerToRawData 0x67be00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42129

.rsrc

MD5 f40e9f8d3e32bbae83ec8c6cbd2d3469
SHA1 f409fe023d315131613db4accf69d82f7a4b9a5c
SHA256 132be69513d6efa14677e03634dc137ab07c1499c2dde8bf0de030a6142537ec
SHA3 d2c3859c6e8639f328c45628cfcc738f584850785288bd7a68c9eec745b964c5
VirtualSize 0x15699
VirtualAddress 0x26d2000
SizeOfRawData 0x15800
PointerToRawData 0x680a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.90649

Imports

KERNEL32.dll AddVectoredContinueHandler
AddVectoredExceptionHandler
CloseHandle
CreateEventA
CreateIoCompletionPort
CreateThread
CreateWaitableTimerExW
DeleteCriticalSection
DisableThreadLibraryCalls
DuplicateHandle
EnterCriticalSection
ExitProcess
FreeEnvironmentStringsW
FreeLibrary
GetConsoleMode
GetCurrentThreadId
GetEnvironmentStringsW
GetErrorMode
GetLastError
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetProcessAffinityMask
GetQueuedCompletionStatusEx
GetStdHandle
GetSystemDirectoryA
GetSystemInfo
GetThreadContext
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
PostQueuedCompletionStatus
QueryPerformanceCounter
RaiseFailFastException
ResumeThread
RtlLookupFunctionEntry
RtlVirtualUnwind
SetConsoleCtrlHandler
SetErrorMode
SetEvent
SetProcessPriorityBoost
SetThreadContext
SetWaitableTimer
Sleep
SuspendThread
SwitchToThread
TlsAlloc
TlsGetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WerGetFlags
WerSetFlags
WriteConsoleW
WriteFile
api-ms-win-crt-heap-l1-1-0.dll calloc
free
malloc
api-ms-win-crt-private-l1-1-0.dll memcpy
api-ms-win-crt-runtime-l1-1-0.dll _execute_onexit_table
_exit
_initialize_onexit_table
_initterm
_initterm_e
_register_onexit_function
abort
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__stdio_common_vfprintf
fwrite
api-ms-win-crt-string-l1-1-0.dll _stricmp
strcmp
strlen
strncmp

Delayed Imports

DllRegisterServer

Ordinal 1
Address 0xdfca0

curl_easy_cleanup

Ordinal 2
Address 0xe01e0

curl_easy_duphandle

Ordinal 3
Address 0xe0210

curl_easy_init

Ordinal 4
Address 0xe00b0

curl_easy_perform

Ordinal 5
Address 0xe0190

curl_easy_setopt

Ordinal 6
Address 0xe0120

curl_easy_strerror

Ordinal 7
Address 0xe0240

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0xd10a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98827
Detected Filetype PNG graphic file
MD5 04b8d88547799b89f9cb22653b1bd010
SHA1 36a09e83acf0f9f7ddae1ec813318650ffd4624b
SHA256 3abe52e4cfd9778e9773f96ac48dcacc4a552c2e3f506206b3be1fd9440e01ff
SHA3 25290000c9f36164664e9e2f8f2b2f5877d1350e7565868cd1a91779a16555f7

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x410b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97922
Detected Filetype PNG graphic file
MD5 811c3efb84657968089407cf49afec0f
SHA1 54c0a8bfa49995a0f588991a81f29a5e8a99d783
SHA256 a6bee39de2380cdae3d5fa94228d4f4c341474c40f0ce52f56b07adbb62fd5ff
SHA3 1f143f21ece8222f0fc8bd204861e2a23eb23b0dc8f537b69ce51c2900c07da1

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x151b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95104
Detected Filetype PNG graphic file
MD5 582e7084f71e0724261088557e0d8c7a
SHA1 b4f8fb5122d16fd1b03b9de1d162e2c9fc17439d
SHA256 320d7ab34a18c114950d4eee57cd36b193112f71bd83fea2f3b1b1eafd05c444
SHA3 a9f0d2497f7d0393b4126ee80f899fc2c37c3c1e0aa83b3f096ed93fce5fa1cb

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0xe07
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92971
Detected Filetype PNG graphic file
MD5 0f64657d39a245a7b08ac59f5e9b8ae8
SHA1 dd3644fd9eba394d290c87c6c735e44cdd8613ac
SHA256 afefea07d43b46e45958c1c440567a982438ea5f9c56be15bd5d6d3c562cd7f2
SHA3 a97eb2dc25ce8e80a41240a5226f9e3965e34a19b3c9e39752ecc7d58aeeee91

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x759
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86776
Detected Filetype PNG graphic file
MD5 e2f26d8bc7eda9d4d98491ca97010ecc
SHA1 ec48b6f7f2296443a697191b1845f9926675d5c1
SHA256 6dcf2960293b164ddf6fc41f615cb08789c03a1fc846b39cd17337537597f863
SHA3 898cfc66bb2eb4823d4591b0d33c4c0ad64cfa29f287039f3907510777adade0

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x2b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.58729
Detected Filetype PNG graphic file
MD5 a6ffa96ce8b3831be969d8aa4aa83ed1
SHA1 5d5b460774a306fc09bf903a62160d9661be5968
SHA256 77c103104091265d70865d82781417f3b12769a3b3b5abd87b1cb8948f56e32b
SHA3 1df7bd9673420d7b57c34928466257aeeb1f4b9b30c1eefda00c4bab73a8918b

63

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x22c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2501
MD5 e67673d6656e0c58f970c6dce6acd9a6
SHA1 59f2f0c10772c89e9293228fcd2f10b11a193c92
SHA256 2534e49f390357fa9e494397d2f0d623eeb24785d092776d746e9c22bd8ceae3
SHA3 1d3d8117c835db2621788a30318b5dda404cb3e95743d01f2b5255e4e5adea76

69

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76892
MD5 5fd9e3aeaa789287b2cb867bce46230a
SHA1 d2dcfc9d996745f4e77b06996db622c5df3cd987
SHA256 fb9175e167b4bcdb19265ca866088918212d940a47fb69fa47accf131a7971ee
SHA3 41950f3387510f74b0acc6b1f55823351b1c9b3596d399df42541869845f01d8

70

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x94
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68065
MD5 596085657bc47bc8d40b06fe5e43b33f
SHA1 fd4574c0a9b11f6f3eab955607359f0c82b4a603
SHA256 3a791bea50896efe69d41b5ff2f8c6e49a767a1c97ff50cc94d308c2623e64ef
SHA3 d3bdaa1998fbe44c124df3824b449375fe14da487045cfe43b0bffbeb2e0f223

126

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99599
MD5 b207a7bdd550acd4ef728f5823d6bcd6
SHA1 88e4b3da8a1b59a76ad33bfe50dabf06707fe32e
SHA256 42e9ca12f2a0a7ce18c59cf198c480a88ad89e6e886e0b5d62635a827f45d09b
SHA3 44606f5a9702ab6814ef47c711f4d4a0a20eca3e031c1001420829661b3ab8d8

188

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x15c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22096
MD5 85857f324ddad03537e475645ee5a614
SHA1 2fc4194effd93f126a35d65ed3ac1ce520bbb91f
SHA256 f4a4bf5b9868ec454b9ba0f1b9251b540b14a162d237ced4446ad95fec946058
SHA3 cdef415be9d519222608f35cc211941df5d845b9915a4f20a44bad5c5346725f

189

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98445
MD5 57c0b0919f0610bdfecf35f3dddf2f99
SHA1 82d941a96ce88d48c4d4eb5f1bd752368f3d21aa
SHA256 b3a9b409e93afb1cfd74d1ca7eb97db28ea013c575907a4128e27e621d1d8510
SHA3 97a59321c70a45edb577a3d5499cb09cc966e5e25a3863d4c461f148bf860372

251

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10598
MD5 b9d6b31ddc4a13c93f2d394a77f38845
SHA1 862efd04286a96f7339ffe27f730087121732f19
SHA256 9fad73205780162bb0724d7e72772593e4233061c03c43b21282b62bd1c5ff27
SHA3 af63e22eefd8d0a2c97948d20bf6c3d614d461cfc4b5fe77e1a1bb0d8f0ab02e

313

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71866
MD5 ba6f6d88c91ba45f3eb102d18dbd68b5
SHA1 f1dafa7670a2073be146c95a08f2f86c05d40a25
SHA256 f85d3b59cde72b59d77d7a01c6b8f8d4a49cabaf302963cc7296ba3a9e667d22
SHA3 6bb79af44cdee9233eb5a0ae45d065842cd5ec55bd4d73b5de1172afd925919b

376

Type RT_STRING
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01671
MD5 e78a308d8d54ffefddaf8b516b9e984e
SHA1 f9376cbdc5e34fb16ad2bec512227ab174391875
SHA256 a18143c8cc16a8adeef8f5866b2eb45d0fb3dd24d3b171c8ad1d0ff54f966090
SHA3 5bbd3c8756720b460e0d043c6bf556daacc9c5e3bab7c0921d3818caeb93aec8

1 (#2)

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82432
Detected Filetype Icon file
MD5 fca8f874093abf18f1efe141ce0eaef9
SHA1 ad905ece10a123665734a5b5a310684ead3b8643
SHA256 d70524299da21b31cf0d804dfcfeb49a4fccde5b9eecd337ab215b6e0742534b
SHA3 e3b3dee8b219cbf015c38fdaa51c27114ef9a058a67d6ed8f91ce415f66838c0

1 (#3)

Type RT_VERSION
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x31c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47251
MD5 2da718aaaf9ec3af1aacd463ccce3b16
SHA1 1a5c58b7e890c606c43c5fa453ed33e33c2a2dce
SHA256 799bd7acdc6805d1717970aaf5c4214cbb3379c96c6ea7adfbc5dce40c11398f
SHA3 84e42c85fc8ef02e1bfca16dfbe1281f0a32c530909799115462adb4556d207c

1 (#4)

Type RT_MANIFEST
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x68d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20866
MD5 2a46b668208aa4434bdc3374636a502d
SHA1 709523d6d2c7223b899b8d5e495b58c423ecc5f0
SHA256 35f7dfb5e9b07d87cad07ea153a088b7a5e0dc6671002dde659af03c0c10077e
SHA3 45ae833536584e7f56e5bcde90bd9c459d04994f77498aa6a0693b94ed06397a

String Table contents

Ping Target Mode Toggle
Synchronizes ping target mode toggle between applications on the same PC
Riverstone Creek Digital
Version 10.4.2141.796
(c) 2026 Riverstone Creek Digital. All rights reserved.
Ping Target Mode Toggle is a trademark of Riverstone Creek Digital.
Item 6359: pending.
Item 5290: pending.
Skip
Options
Your software is up to date.
Scheduled task created.
Accept
Unable to write to the specified location.
Test run: 128 passed, 0 failed.
The specified path is invalid.
Access is denied.
Item 1454: ready.
Garbage collection completed.
Item 5964: ready.
Backup completed.
Item 4947: ready.
Item 7269: ready.
Printer: HP LaserJet ready
Item 8555: ready.
Item 2076: ready.
Item 3506: ready.
Preparing...
Item 1403: ready.
Item 1243: ready.
Item 4289: ready.
Item 6011: updated.
Item 8831: updated.
Item 7295: updated.
Item 9701: updated.
Installing...
Installing update...
Item 620: updated.
Item 7286: updated.
Disconnected
USB device connected.
Packets sent: 8,412
Account verified.
License activated.
License valid until December 31, 2026.
Session expired. Please sign in again.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.4.2141.796
ProductVersion 10.4.2141.796
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language Chinese - Taiwan
InternalName PingTargetModeToggle.exe
ProductVersion (#2) 10.4.2141.796
FileDescription Synchronizes ping target mode toggle between applications on the same PC
LegalCopyright (c) 2026 Riverstone Creek Digital. All rights reserved.
OriginalFilename PingTargetModeToggle.exe
Resource LangID Chinese - Taiwan

TLS Callbacks

StartAddressOfRawData 0x2db16c000
EndAddressOfRawData 0x2db16c008
AddressOfIndex 0x2db169d30
AddressOfCallbacks 0x2d91155d8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x00000002D8B80900
0x00000002D8B809B9

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.