5a2d35077c1cbe3a2537a089f65e26ad004aed7c5610bc41d6383948c65f0365

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-20 15:28:04
Detected languages English - United States
Debug artifacts C:\Users\User\Downloads\1777127053283-night\output\build\night.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://github.com
  • roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAlloc
Possibly launches other programs:
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Manipulates other processes:
  • Process32Next
  • WriteProcessMemory
  • OpenProcess
  • ReadProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 97d898bb1246f9bab346d5ad6a715037 🔍
SHA1 2062479c4226065b14a858cdf4ae40b51db1c95c 🔍
SHA256 5a2d35077c1cbe3a2537a089f65e26ad004aed7c5610bc41d6383948c65f0365 🔍
SHA3 85c26f82dec5d21e236e3007b928cd2dd0a5257a75a61d56a7f13bcaf4662102 🔍
SSDeep 49152:vGrja5LW6XJqtHgX/Ai5aUbMpPUfSjVRyjIY8eo:TBAuapTTV 🔍
Imports Hash 3240a5bd018c7dff35ced417dde97128 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-20 15:28:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x12be00
SizeOfInitializedData 0xf4e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000123620 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x225000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6055f02794f70648200ec43847885d77 🔍
SHA1 1c65dbda94bd0ffb43dc13f155bbd70c65687a8b 🔍
SHA256 48f32aa2d2b02fe6ed0e38f4a7e9a0bd9a0329f87c87dac50e5f305e4fc80468 🔍
SHA3 179a96355a6012882ae8c95b6c955ff75d8c9be180a7ed177463afa922debdbe 🔍
VirtualSize 0x12bc71
VirtualAddress 0x1000
SizeOfRawData 0x12be00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4935

.rdata

MD5 b9583e02783435a6621c06c3893d721c 🔍
SHA1 6c81c3022a9d953dd73f9b483407113f504eeec9 🔍
SHA256 ed53f5e8794980b17874cdf0243be034f716f209793b4044c13c1328f367ba98 🔍
SHA3 8ea0b32b25d04c40a9112b4e1fa67e6f4d2d0d735d27c88d2cb26b5693c3cb44 🔍
VirtualSize 0x49280
VirtualAddress 0x12d000
SizeOfRawData 0x49400
PointerToRawData 0x12c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.253

.data

MD5 4abc42d722afa6830fda5721919b9112 🔍
SHA1 d8b702d26d4bfed9ca21b771b97cbf38730ce889 🔍
SHA256 620979804d876eb6f7f02479957cb904a55499cd085ed8479904b6b38673aee8 🔍
SHA3 01f23fcb7660b8d283c65565787a0f01535b5f5a2d991405bb459d19b37cd2ea 🔍
VirtualSize 0x9cb10
VirtualAddress 0x177000
SizeOfRawData 0x9b000
PointerToRawData 0x175600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.98956

.pdata

MD5 b352c04a6343403cd64ed5a1766a8f14 🔍
SHA1 c499327c3884011510b4a807eda2ce17758d2a39 🔍
SHA256 0d3c9a06d6353bd6516436737242ca5aa5b767135c0a13f0b56f6d7ca178dce8 🔍
SHA3 e75615324a4c95c14d1fc1215bec61f109f007db14cc197a5427b5c4f182dea3 🔍
VirtualSize 0xd824
VirtualAddress 0x214000
SizeOfRawData 0xda00
PointerToRawData 0x210600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.14513

.rsrc

MD5 63c6ef1d7c5f5132ab7c56cb9bca1742 🔍
SHA1 168bb833727d0f6c683a8e3efc215354888d9f34 🔍
SHA256 150b80cd9881a62595d8067a4693442d7e25b947848ad58a6e798f22dbc3336b 🔍
SHA3 32b98ff6bfb12927152ee4f07c0d2bf42eb6c34428f149fa6c767893eaf58c8b 🔍
VirtualSize 0x1e0
VirtualAddress 0x222000
SizeOfRawData 0x200
PointerToRawData 0x21e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.69898

.reloc

MD5 714494741a9dbeb6d3a9d8be37eb1e52 🔍
SHA1 fa913ff6d30a84d6e86a387e1234bfcf6daf3cce 🔍
SHA256 79aefd06182dde4043699e0c8d7a6711e455848a97b6945b91ac68e765e0bb45 🔍
SHA3 0eb8d583376516feb72d2394aef88ab5305b41d4da3a1407060b26292bca01c1 🔍
VirtualSize 0x11bc
VirtualAddress 0x223000
SizeOfRawData 0x1200
PointerToRawData 0x21e200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42169

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
KERNEL32.dll GetConsoleWindow
Module32Next
CreateToolhelp32Snapshot
Process32Next
CloseHandle
WriteProcessMemory
Sleep
SetConsoleTitleA
SetConsoleMode
SetCurrentConsoleFontEx
GetConsoleMode
GetLocaleInfoA
MultiByteToWideChar
LoadLibraryA
QueryPerformanceFrequency
FreeLibrary
QueryPerformanceCounter
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
CreateFileA
GetFileSizeEx
ReadFile
HeapAlloc
HeapFree
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
GetProcAddress
GetCurrentProcessId
SetUnhandledExceptionFilter
WakeAllConditionVariable
OpenProcess
GetFileInformationByHandleEx
GetModuleHandleW
GetLastError
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFileAttributesExW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
CreateDirectoryW
GetLocaleInfoEx
FormatMessageA
LocalFree
GetCurrentThreadId
SleepConditionVariableSRW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
InitOnceBeginInitialize
InitOnceComplete
ReadProcessMemory
GetModuleHandleA
VirtualAlloc
GetStdHandle
VirtualProtect
GetSystemTimeAsFileTime
InitializeSListHead
USER32.dll SendInput
ScreenToClient
FindWindowA
GetDC
GetAsyncKeyState
IsIconic
UpdateWindow
GetCursorPos
ReleaseDC
GetClipboardData
OpenClipboard
CloseClipboard
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
SetWindowPos
MonitorFromWindow
PostQuitMessage
PeekMessageA
TranslateMessage
SetLayeredWindowAttributes
CreateWindowExA
MoveWindow
GetForegroundWindow
GetMonitorInfoA
SetWindowDisplayAffinity
SetWindowLongA
ShowWindow
UnregisterClassW
RegisterClassExW
EmptyClipboard
GDI32.dll GetDeviceCaps
SHELL32.dll SHGetFolderPathA
ShellExecuteA
ole32.dll CoUninitialize
CoCreateInstance
CoInitializeEx
MSVCP140.dll _Xtime_get_ticks
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
??0task_continuation_context@Concurrency@@AEAA@XZ
_Cnd_unregister_at_thread_exit
?__ExceptionPtrCreate@@YAXPEAX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
?_Xbad_alloc@std@@YAXXZ
?_Xbad_function_call@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Syserror_map@std@@YAPEBDH@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
_Mtx_lock
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrRethrow@@YAXPEBX@Z
_Cnd_register_at_thread_exit
_Cnd_do_broadcast_at_thread_exit
_Cnd_wait
_Thrd_id
_Query_perf_counter
_Thrd_join
_Mtx_unlock
_Cnd_broadcast
_Thrd_detach
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?good@ios_base@std@@QEBA_NXZ
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
ImmSetCompositionWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
__std_exception_copy
_CxxThrowException
__intrinsic_setjmp
__current_exception_context
__current_exception
_purecall
__C_specific_handler
memcmp
memchr
memset
memmove
memcpy
longjmp
strrchr
strchr
strstr
__std_terminate
api-ms-win-crt-heap-l1-1-0.dll malloc
free
_set_new_mode
_callnewh
api-ms-win-crt-runtime-l1-1-0.dll __p___argv
__p___argc
_beginthreadex
terminate
exit
_initterm_e
_initterm
_register_thread_local_exe_atexit_callback
_get_initial_narrow_environment
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
_c_exit
abort
_exit
_errno
api-ms-win-crt-stdio-l1-1-0.dll fread
fsetpos
ungetc
setvbuf
fgetpos
__stdio_common_vsprintf
_get_stream_buffer_pointers
fwrite
ftell
_wfopen
__p__commode
fgetc
_set_fmode
fclose
fflush
fseek
fputc
__stdio_common_vsscanf
_fseeki64
__acrt_iob_func
__stdio_common_vfprintf
api-ms-win-crt-string-l1-1-0.dll tolower
strncpy_s
toupper
wcscpy_s
_stricmp
strncmp
strcmp
strncpy
strlen
wcslen
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
api-ms-win-crt-math-l1-1-0.dll logf
pow
log
cosf
fmodf
roundf
__setusermatherr
atan2f
_hypotf
acosf
sqrtf
sinf
sqrt
powf
_dsign
floorf
ceilf
api-ms-win-crt-convert-l1-1-0.dll strtoll
strtod
strtoull
strtol
atof
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
localeconv
_configthreadlocale
api-ms-win-crt-time-l1-1-0.dll _localtime64_s

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-20 15:28:04
Version 0.0
SizeofData 91
AddressOfRawData 0x15c120
PointerToRawData 0x15b320
Referenced File C:\Users\User\Downloads\1777127053283-night\output\build\night.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-20 15:28:04
Version 0.0
SizeofData 20
AddressOfRawData 0x15c17c
PointerToRawData 0x15b37c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-20 15:28:04
Version 0.0
SizeofData 912
AddressOfRawData 0x15c190
PointerToRawData 0x15b390

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-20 15:28:04
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14015c540
EndAddressOfRawData 0x14015c548
AddressOfIndex 0x140211ff0
AddressOfCallbacks 0x14012dbb0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140177040

RICH Header

XOR Key 0x544be9fa
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (35721) 1
C objects (35721) 10
C++ objects (35721) 40
ASM objects (35721) 6
Imports (35721) 6
C objects (35222) 1
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (35222) 19
Total imports 381
C++ objects (LTCG) (36256) 23
Resource objects (36256) 1
Linker (36256) 1

Errors

Leave a comment

No comments yet.