| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
1970-Jan-01 00:00:00
|
| Detected languages |
Chinese - Taiwan
|
| TLS Callbacks |
2 callback(s) detected.
|
| InternalName |
PingTargetModeToggle.exe
|
| ProductVersion |
10.4.2141.796
|
| FileDescription |
Synchronizes ping target mode toggle between applications on the same PC
|
| LegalCopyright |
(c) 2026 Riverstone Creek Digital. All rights reserved.
|
| OriginalFilename |
PingTargetModeToggle.exe
|
| Suspicious |
PEiD Signature: |
XWD graphics format
HQR data file
|
| Info |
Interesting strings found in the binary: |
Contains domain names:
|
| Info |
Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
|
| Suspicious |
The PE is possibly packed. |
Unusual section name found: .xdata
|
| Suspicious |
The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
- GetProcAddress
- LoadLibraryA
- LoadLibraryExW
Functions which can be used for anti-debugging purposes:
Memory manipulation functions often used by packers:
- VirtualAlloc
- VirtualProtect
|
| Info |
The PE is digitally signed. |
Signer: Ping Target Mode Toggle
Issuer: Ping Target Mode Toggle
|
| Malicious |
VirusTotal score: 8/70 (Scanned on 2026-06-11 09:14:56) |
Bkav:
W32.Malware.954012CF
Elastic:
malicious (moderate confidence)
Kaspersky:
VHO:Trojan.Win64.DLLhijack.gen
Kingsoft:
Win64.Trojan.DLLhijack.gen
Malwarebytes:
Trojan.MalPack
Microsoft:
Trojan:Win32/Wacatac.B!ml
Trapmine:
malicious.high.ml.score
huorong:
Trojan/FakeDll.aj
|
| MD5 |
e024a6851f24ec6fd2853c528a7d9004
|
| SHA1 |
da7cb5459812f22db53874a3d2de278d90c5c6e5
|
| SHA256 |
51b9eb394d5b1a36bc2bf3264077cc400bafab7a3a88097e68bf4015b0655014
|
| SHA3 |
775f11d7381c0c02870c4b5a091acb24147d474d980f38bcf44c8d4f29116c2f
|
| SSDeep |
98304:6d9fMsgnf0wj3QmpE7LKnBnkYGri/KdvXAhhcdI7:6H+f0K3S5lriydEc
|
| Imports Hash |
f604c1c3e882e6a725b213d7fdcb6bc5
|
| e_magic |
MZ
|
| e_cblp |
0x90
|
| e_cp |
0x3
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x80
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections |
12
|
| TimeDateStamp |
1970-Jan-01 00:00:00
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xf0
|
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic |
PE32+
|
| LinkerVersion |
2.0
|
| SizeOfCode |
0xe1000
|
| SizeOfInitializedData |
0x5b4e00
|
| SizeOfUninitializedData |
0x204ae00
|
| AddressOfEntryPoint |
0x00000000000012EF (Section: .text)
|
| BaseOfCode |
0x1000
|
| ImageBase |
0x2d8aa0000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
6.1
|
| ImageVersion |
0.0
|
| SubsystemVersion |
6.1
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x26e8000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0x6a0025
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve |
0x200000
|
| SizeofStackCommit |
0x1000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
b25677366850b8834a4dc567a2079dab
|
| SHA1 |
d7dc6e13cfd78634107c7b9fa23ec056455fafe3
|
| SHA256 |
fc336153f88a0fbfb8c03ce73cf494a7dc951fc036594e420c373d797ba6387a
|
| SHA3 |
22064838c37f51670fcf2114d48670fd82a5f6ca58b035bb7baeacf17741b8bb
|
| VirtualSize |
0xe0e30
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0xe1000
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.30446
|
| MD5 |
855e01865a25fb34913c2e4f01cad232
|
| SHA1 |
4c727a9495580a4178fa1a4562791aaca418eec2
|
| SHA256 |
10becd8638359a8c93344849c6afd931082573d8f726c4b1031b134099086d35
|
| SHA3 |
e16aab8efdf38cc1632fe2ccdd84a4ffa066c0d829927c8479cdad099ec258fb
|
| VirtualSize |
0x481670
|
| VirtualAddress |
0xe2000
|
| SizeOfRawData |
0x481800
|
| PointerToRawData |
0xe1400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
7.99233
|
| MD5 |
af593df884ebc992214d70c89f371c92
|
| SHA1 |
cbf451c70b1a32221bd1624a64f5df1aa69e29d8
|
| SHA256 |
9b32f4c94e7e4eda48db1e20a535ef01e794c96d01bc0a57c40f9745f17d3e86
|
| SHA3 |
f74ee51105608f416c41332bf732b394e845f7a060b307278ce89ec31a4c163b
|
| VirtualSize |
0x111600
|
| VirtualAddress |
0x564000
|
| SizeOfRawData |
0x111600
|
| PointerToRawData |
0x562c00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
5.52044
|
| MD5 |
bf619eac0cdf3f68d496ea9344137e8b
|
| SHA1 |
5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
|
| SHA256 |
076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
|
| SHA3 |
622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
|
| VirtualSize |
0x4
|
| VirtualAddress |
0x676000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x674200
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0
|
| MD5 |
5dd0522bba139bf891c3244bbba2b09c
|
| SHA1 |
a2a039242759a7044813fdbbf4fcf92766e42891
|
| SHA256 |
c718783f11f2356168a1a11b99a9332e03469de9edd9f522642718b073d00027
|
| SHA3 |
28fa30d848237dedf1883dcf6df763a8771a67abe785c6a7c1c8b3bf7d5c7bd6
|
| VirtualSize |
0x6240
|
| VirtualAddress |
0x677000
|
| SizeOfRawData |
0x6400
|
| PointerToRawData |
0x674400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
5.33371
|
| MD5 |
82e958f1db33d67d1ef887b4d7a330e6
|
| SHA1 |
862665290983925cebb6f5b78083b1b51762771c
|
| SHA256 |
5fa5aefc60599ebf274a7bb655072eae93aa36fd2be30bb4914f621f8dcc8291
|
| SHA3 |
75c855af66e102f83a5714c93a2c93895c14a173cbf43b649e276426e6cc1158
|
| VirtualSize |
0x364
|
| VirtualAddress |
0x67e000
|
| SizeOfRawData |
0x400
|
| PointerToRawData |
0x67a800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
3.51521
|
| MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
| SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
| SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
| SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
| VirtualSize |
0x204add0
|
| VirtualAddress |
0x67f000
|
| SizeOfRawData |
0
|
| PointerToRawData |
0
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 |
9b4f23bce613374502eb6eedf6b47a25
|
| SHA1 |
1eb77801e28a277875b813a0683dae384efa906d
|
| SHA256 |
a1cd9b9384d83454f1ce4c115fe206f37a9d72199ccb59e30dad46e22a154fdd
|
| SHA3 |
e5cabfe716b83b6cce0c84adebe785e587fa8827c2f0da61a26c678ba656a9eb
|
| VirtualSize |
0xfa
|
| VirtualAddress |
0x26ca000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x67ac00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
2.9197
|
| MD5 |
3ab39eb740f3311754f08774e8122078
|
| SHA1 |
0b2fed9c76b35efe4345ad2ce11182b89066be85
|
| SHA256 |
3b406838ec71412a07eb501d24335939c55a9e0cc8ae99dec598448729a11565
|
| SHA3 |
8f00638ea58a455bfc5d31945cce283951ab8aa7a41bab797c0a857d91f70fec
|
| VirtualSize |
0xd48
|
| VirtualAddress |
0x26cb000
|
| SizeOfRawData |
0xe00
|
| PointerToRawData |
0x67ae00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.57428
|
| MD5 |
bf619eac0cdf3f68d496ea9344137e8b
|
| SHA1 |
5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
|
| SHA256 |
076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
|
| SHA3 |
622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
|
| VirtualSize |
0x10
|
| VirtualAddress |
0x26cc000
|
| SizeOfRawData |
0x200
|
| PointerToRawData |
0x67bc00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
0
|
| MD5 |
af6a60a4b18b16f7b6ef6a74bdb93ea4
|
| SHA1 |
43577619f5386c9bd9c38c1cfec487704e3c71d1
|
| SHA256 |
b20d8150ff6e8880d3e8b94ad60b5b55cf96ec42bcbf1ff6711717c00f288af3
|
| SHA3 |
c61bb9bb3a1b629cc6e27ec724c0ff902361354fe073eb486a0afda5e42e73eb
|
| VirtualSize |
0x4ac4
|
| VirtualAddress |
0x26cd000
|
| SizeOfRawData |
0x4c00
|
| PointerToRawData |
0x67be00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy |
5.42129
|
| MD5 |
f40e9f8d3e32bbae83ec8c6cbd2d3469
|
| SHA1 |
f409fe023d315131613db4accf69d82f7a4b9a5c
|
| SHA256 |
132be69513d6efa14677e03634dc137ab07c1499c2dde8bf0de030a6142537ec
|
| SHA3 |
d2c3859c6e8639f328c45628cfcc738f584850785288bd7a68c9eec745b964c5
|
| VirtualSize |
0x15699
|
| VirtualAddress |
0x26d2000
|
| SizeOfRawData |
0x15800
|
| PointerToRawData |
0x680a00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
7.90649
|
| KERNEL32.dll |
AddVectoredContinueHandler
AddVectoredExceptionHandler
CloseHandle
CreateEventA
CreateIoCompletionPort
CreateThread
CreateWaitableTimerExW
DeleteCriticalSection
DisableThreadLibraryCalls
DuplicateHandle
EnterCriticalSection
ExitProcess
FreeEnvironmentStringsW
FreeLibrary
GetConsoleMode
GetCurrentThreadId
GetEnvironmentStringsW
GetErrorMode
GetLastError
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetProcessAffinityMask
GetQueuedCompletionStatusEx
GetStdHandle
GetSystemDirectoryA
GetSystemInfo
GetThreadContext
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
PostQueuedCompletionStatus
QueryPerformanceCounter
RaiseFailFastException
ResumeThread
RtlLookupFunctionEntry
RtlVirtualUnwind
SetConsoleCtrlHandler
SetErrorMode
SetEvent
SetProcessPriorityBoost
SetThreadContext
SetWaitableTimer
Sleep
SuspendThread
SwitchToThread
TlsAlloc
TlsGetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WerGetFlags
WerSetFlags
WriteConsoleW
WriteFile
|
| api-ms-win-crt-heap-l1-1-0.dll |
calloc
free
malloc
|
| api-ms-win-crt-private-l1-1-0.dll |
memcpy
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_execute_onexit_table
_exit
_initialize_onexit_table
_initterm
_initterm_e
_register_onexit_function
abort
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__stdio_common_vfprintf
fwrite
|
| api-ms-win-crt-string-l1-1-0.dll |
_stricmp
strcmp
strlen
strncmp
|
| Ordinal |
1
|
| Address |
0xdfca0
|
| Ordinal |
2
|
| Address |
0xe01e0
|
| Ordinal |
3
|
| Address |
0xe0210
|
| Ordinal |
4
|
| Address |
0xe00b0
|
| Ordinal |
5
|
| Address |
0xe0190
|
| Ordinal |
6
|
| Address |
0xe0120
|
| Ordinal |
7
|
| Address |
0xe0240
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0xd10a
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.98827
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
04b8d88547799b89f9cb22653b1bd010
|
| SHA1 |
36a09e83acf0f9f7ddae1ec813318650ffd4624b
|
| SHA256 |
3abe52e4cfd9778e9773f96ac48dcacc4a552c2e3f506206b3be1fd9440e01ff
|
| SHA3 |
25290000c9f36164664e9e2f8f2b2f5877d1350e7565868cd1a91779a16555f7
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x410b
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.97922
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
811c3efb84657968089407cf49afec0f
|
| SHA1 |
54c0a8bfa49995a0f588991a81f29a5e8a99d783
|
| SHA256 |
a6bee39de2380cdae3d5fa94228d4f4c341474c40f0ce52f56b07adbb62fd5ff
|
| SHA3 |
1f143f21ece8222f0fc8bd204861e2a23eb23b0dc8f537b69ce51c2900c07da1
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x151b
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.95104
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
582e7084f71e0724261088557e0d8c7a
|
| SHA1 |
b4f8fb5122d16fd1b03b9de1d162e2c9fc17439d
|
| SHA256 |
320d7ab34a18c114950d4eee57cd36b193112f71bd83fea2f3b1b1eafd05c444
|
| SHA3 |
a9f0d2497f7d0393b4126ee80f899fc2c37c3c1e0aa83b3f096ed93fce5fa1cb
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0xe07
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.92971
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
0f64657d39a245a7b08ac59f5e9b8ae8
|
| SHA1 |
dd3644fd9eba394d290c87c6c735e44cdd8613ac
|
| SHA256 |
afefea07d43b46e45958c1c440567a982438ea5f9c56be15bd5d6d3c562cd7f2
|
| SHA3 |
a97eb2dc25ce8e80a41240a5226f9e3965e34a19b3c9e39752ecc7d58aeeee91
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x759
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.86776
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
e2f26d8bc7eda9d4d98491ca97010ecc
|
| SHA1 |
ec48b6f7f2296443a697191b1845f9926675d5c1
|
| SHA256 |
6dcf2960293b164ddf6fc41f615cb08789c03a1fc846b39cd17337537597f863
|
| SHA3 |
898cfc66bb2eb4823d4591b0d33c4c0ad64cfa29f287039f3907510777adade0
|
| Type |
RT_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x2b2
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.58729
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
a6ffa96ce8b3831be969d8aa4aa83ed1
|
| SHA1 |
5d5b460774a306fc09bf903a62160d9661be5968
|
| SHA256 |
77c103104091265d70865d82781417f3b12769a3b3b5abd87b1cb8948f56e32b
|
| SHA3 |
1df7bd9673420d7b57c34928466257aeeb1f4b9b30c1eefda00c4bab73a8918b
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x22c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.2501
|
| MD5 |
e67673d6656e0c58f970c6dce6acd9a6
|
| SHA1 |
59f2f0c10772c89e9293228fcd2f10b11a193c92
|
| SHA256 |
2534e49f390357fa9e494397d2f0d623eeb24785d092776d746e9c22bd8ceae3
|
| SHA3 |
1d3d8117c835db2621788a30318b5dda404cb3e95743d01f2b5255e4e5adea76
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x84
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.76892
|
| MD5 |
5fd9e3aeaa789287b2cb867bce46230a
|
| SHA1 |
d2dcfc9d996745f4e77b06996db622c5df3cd987
|
| SHA256 |
fb9175e167b4bcdb19265ca866088918212d940a47fb69fa47accf131a7971ee
|
| SHA3 |
41950f3387510f74b0acc6b1f55823351b1c9b3596d399df42541869845f01d8
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x94
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.68065
|
| MD5 |
596085657bc47bc8d40b06fe5e43b33f
|
| SHA1 |
fd4574c0a9b11f6f3eab955607359f0c82b4a603
|
| SHA256 |
3a791bea50896efe69d41b5ff2f8c6e49a767a1c97ff50cc94d308c2623e64ef
|
| SHA3 |
d3bdaa1998fbe44c124df3824b449375fe14da487045cfe43b0bffbeb2e0f223
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x110
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.99599
|
| MD5 |
b207a7bdd550acd4ef728f5823d6bcd6
|
| SHA1 |
88e4b3da8a1b59a76ad33bfe50dabf06707fe32e
|
| SHA256 |
42e9ca12f2a0a7ce18c59cf198c480a88ad89e6e886e0b5d62635a827f45d09b
|
| SHA3 |
44606f5a9702ab6814ef47c711f4d4a0a20eca3e031c1001420829661b3ab8d8
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x15c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.22096
|
| MD5 |
85857f324ddad03537e475645ee5a614
|
| SHA1 |
2fc4194effd93f126a35d65ed3ac1ce520bbb91f
|
| SHA256 |
f4a4bf5b9868ec454b9ba0f1b9251b540b14a162d237ced4446ad95fec946058
|
| SHA3 |
cdef415be9d519222608f35cc211941df5d845b9915a4f20a44bad5c5346725f
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0xe4
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.98445
|
| MD5 |
57c0b0919f0610bdfecf35f3dddf2f99
|
| SHA1 |
82d941a96ce88d48c4d4eb5f1bd752368f3d21aa
|
| SHA256 |
b3a9b409e93afb1cfd74d1ca7eb97db28ea013c575907a4128e27e621d1d8510
|
| SHA3 |
97a59321c70a45edb577a3d5499cb09cc966e5e25a3863d4c461f148bf860372
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x144
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.10598
|
| MD5 |
b9d6b31ddc4a13c93f2d394a77f38845
|
| SHA1 |
862efd04286a96f7339ffe27f730087121732f19
|
| SHA256 |
9fad73205780162bb0724d7e72772593e4233061c03c43b21282b62bd1c5ff27
|
| SHA3 |
af63e22eefd8d0a2c97948d20bf6c3d614d461cfc4b5fe77e1a1bb0d8f0ab02e
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x88
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.71866
|
| MD5 |
ba6f6d88c91ba45f3eb102d18dbd68b5
|
| SHA1 |
f1dafa7670a2073be146c95a08f2f86c05d40a25
|
| SHA256 |
f85d3b59cde72b59d77d7a01c6b8f8d4a49cabaf302963cc7296ba3a9e667d22
|
| SHA3 |
6bb79af44cdee9233eb5a0ae45d065842cd5ec55bd4d73b5de1172afd925919b
|
| Type |
RT_STRING
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x100
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.01671
|
| MD5 |
e78a308d8d54ffefddaf8b516b9e984e
|
| SHA1 |
f9376cbdc5e34fb16ad2bec512227ab174391875
|
| SHA256 |
a18143c8cc16a8adeef8f5866b2eb45d0fb3dd24d3b171c8ad1d0ff54f966090
|
| SHA3 |
5bbd3c8756720b460e0d043c6bf556daacc9c5e3bab7c0921d3818caeb93aec8
|
| Type |
RT_GROUP_ICON
|
| Language |
UNKNOWN
|
| Codepage |
UNKNOWN
|
| Size |
0x5a
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.82432
|
| Detected Filetype |
Icon file
|
| MD5 |
fca8f874093abf18f1efe141ce0eaef9
|
| SHA1 |
ad905ece10a123665734a5b5a310684ead3b8643
|
| SHA256 |
d70524299da21b31cf0d804dfcfeb49a4fccde5b9eecd337ab215b6e0742534b
|
| SHA3 |
e3b3dee8b219cbf015c38fdaa51c27114ef9a058a67d6ed8f91ce415f66838c0
|
| Type |
RT_VERSION
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x31c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.47251
|
| MD5 |
2da718aaaf9ec3af1aacd463ccce3b16
|
| SHA1 |
1a5c58b7e890c606c43c5fa453ed33e33c2a2dce
|
| SHA256 |
799bd7acdc6805d1717970aaf5c4214cbb3379c96c6ea7adfbc5dce40c11398f
|
| SHA3 |
84e42c85fc8ef02e1bfca16dfbe1281f0a32c530909799115462adb4556d207c
|
| Type |
RT_MANIFEST
|
| Language |
Chinese - Taiwan
|
| Codepage |
UNKNOWN
|
| Size |
0x68d
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.20866
|
| MD5 |
2a46b668208aa4434bdc3374636a502d
|
| SHA1 |
709523d6d2c7223b899b8d5e495b58c423ecc5f0
|
| SHA256 |
35f7dfb5e9b07d87cad07ea153a088b7a5e0dc6671002dde659af03c0c10077e
|
| SHA3 |
45ae833536584e7f56e5bcde90bd9c459d04994f77498aa6a0693b94ed06397a
|
| Ping Target Mode Toggle |
| Synchronizes ping target mode toggle between applications on the same PC |
| Riverstone Creek Digital |
| Version 10.4.2141.796 |
| (c) 2026 Riverstone Creek Digital. All rights reserved. |
| Ping Target Mode Toggle is a trademark of Riverstone Creek Digital. |
| Item 6359: pending. |
| Item 5290: pending. |
| Skip |
| Options |
| Your software is up to date. |
| Scheduled task created. |
| Accept |
| Unable to write to the specified location. |
| Test run: 128 passed, 0 failed. |
| The specified path is invalid. |
| Access is denied. |
| Item 1454: ready. |
| Garbage collection completed. |
| Item 5964: ready. |
| Backup completed. |
| Item 4947: ready. |
| Item 7269: ready. |
| Printer: HP LaserJet ready |
| Item 8555: ready. |
| Item 2076: ready. |
| Item 3506: ready. |
| Preparing... |
| Item 1403: ready. |
| Item 1243: ready. |
| Item 4289: ready. |
| Item 6011: updated. |
| Item 8831: updated. |
| Item 7295: updated. |
| Item 9701: updated. |
| Installing... |
| Installing update... |
| Item 620: updated. |
| Item 7286: updated. |
| Disconnected |
| USB device connected. |
| Packets sent: 8,412 |
| Account verified. |
| License activated. |
| License valid until December 31, 2026. |
| Session expired. Please sign in again. |
| Signature |
0xfeef04bd
|
| StructVersion |
0x10000
|
| FileVersion |
10.4.2141.796
|
| ProductVersion |
10.4.2141.796
|
| FileFlags |
(EMPTY)
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language |
Chinese - Taiwan
|
| InternalName |
PingTargetModeToggle.exe
|
| ProductVersion (#2) |
10.4.2141.796
|
| FileDescription |
Synchronizes ping target mode toggle between applications on the same PC
|
| LegalCopyright |
(c) 2026 Riverstone Creek Digital. All rights reserved.
|
| OriginalFilename |
PingTargetModeToggle.exe
|
| Resource LangID |
Chinese - Taiwan
|
| StartAddressOfRawData |
0x2db16c000
|
| EndAddressOfRawData |
0x2db16c008
|
| AddressOfIndex |
0x2db169d30
|
| AddressOfCallbacks |
0x2d91155d8
|
| SizeOfZeroFill |
0
|
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x00000002D8B80900
0x00000002D8B809B9
|
[*] Warning: Section .bss has a size of 0!