5d8096647545c1f50bd52d4971b7c895c8eef5ea9b0d774e8ceaeb59b0f5e5cb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-25 06:47:21
Detected languages English - United States
Debug artifacts E:\updated-kernel-script-main\ks-external\bin\Release\Division2External-FreeNotice.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 74faec8520f61a22c320ec3d32f8f1e3 🔍
SHA1 1377f2868a0cdebd1261cd768fc186b56cff6fb8 🔍
SHA256 5d8096647545c1f50bd52d4971b7c895c8eef5ea9b0d774e8ceaeb59b0f5e5cb 🔍
SHA3 a815bae31613912c633678672cdd15570cbc4e03028ca0c800c45f584b371e7f 🔍
SSDeep 12288:lgLvQzGaat9Wcg1AMGi79M3B1nampEunfs:lgL9ZWddV5MppEunfs 🔍
Imports Hash 2ea48db37b387f57edaaf45297cd5097 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Sep-25 06:47:21
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x81000
SizeOfInitializedData 0x20600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000080440 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 66e6c3fc9986ce3a0558ca94767c8dde 🔍
SHA1 9817a01c0c1f03cf0aa97e032c10c6ae31ea1129 🔍
SHA256 d4ddef4b62dafab52993bebd8dc188b693e08b6862d993e8cd5cd0c848daaa5b 🔍
SHA3 c9bc61f5aa0d0c45f97c50dda3aa950962f1bf7d6934266faf9809779a06c57e 🔍
VirtualSize 0x80f83
VirtualAddress 0x1000
SizeOfRawData 0x81000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48269

.rdata

MD5 70a45cf4b059f16da87c11224ece6a21 🔍
SHA1 9fd9c3c41d4501b3dfd4fc8cf826e4713981c390 🔍
SHA256 ab3f497ce5e0964653a72ea9e94c7a750d5f916f91b46e671a70834541f40b45 🔍
SHA3 65df93e8e385442a179e7d4fb97ba82b4628b4aab33f1f53130c4a859a48338e 🔍
VirtualSize 0x19584
VirtualAddress 0x82000
SizeOfRawData 0x19600
PointerToRawData 0x81400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.04569

.data

MD5 efcb1c99e6675b55185732650baebe0e 🔍
SHA1 c5da1e9616ef67c545328b6e2a251043ef362a6e 🔍
SHA256 5c14ee44af765740a2a3b36b714f9f557441ca8d71163ef4f58c4ca910d337f1 🔍
SHA3 e63049891a7014a1035849b1c13f5c0c9fb0b24bb58b5c5db9a4718e0a0bd438 🔍
VirtualSize 0xd30
VirtualAddress 0x9c000
SizeOfRawData 0x800
PointerToRawData 0x9aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.48282

.pdata

MD5 4001c871ea42ae26a810c180431860b5 🔍
SHA1 5fa687049efe95d9c0d2330b43dd5e771638337e 🔍
SHA256 d543308d1397d181d63cab7a4328e3d1ace6535f211467ebc0101ea50bcb13be 🔍
SHA3 d8ebf07ed8e958e921f7cce5868bd4a346698c6d6811da898216ba75c07c7c18 🔍
VirtualSize 0x5bf8
VirtualAddress 0x9d000
SizeOfRawData 0x5c00
PointerToRawData 0x9b200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.91211

.rsrc

MD5 839b67c112d21ec57c01dad31220d0fc 🔍
SHA1 c94d82a3b8d2ad9b147739cb58c045ab3474292e 🔍
SHA256 aed69eef7ad0b8152a7060696fb9d4745601203d68bbc6337a00b6c725042bdc 🔍
SHA3 f87e15d47ec09adc73627655a487d16be2fea77e46e60cc32df17e5fc4194758 🔍
VirtualSize 0x1e0
VirtualAddress 0xa3000
SizeOfRawData 0x200
PointerToRawData 0xa0e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.7019

.reloc

MD5 8eea6795c59c14b8b233c6bc35cb6254 🔍
SHA1 f114c9428f9c6eebc05de22d2cd37bd57e2b2c8f 🔍
SHA256 fb5bb1e2c5b363865801102376831882c72e583c4d941e805f56ba324014e8cf 🔍
SHA3 fec5fd6a7865b3a9de9bfa226800beb9bb553b9dbc43862b9af70d9de9e34439 🔍
VirtualSize 0x310
VirtualAddress 0xa4000
SizeOfRawData 0x400
PointerToRawData 0xa1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.5596

Imports

d3d11.dll D3D11CreateDevice
dcomp.dll DCompositionCreateDevice
dwmapi.dll DwmExtendFrameIntoClientArea
USER32.dll SetCursor
SetCursorPos
IsWindowUnicode
SetCapture
GetKeyState
GetMessageExtraInfo
TrackMouseEvent
GetKeyboardLayout
EmptyClipboard
GetClipboardData
SetClipboardData
CloseClipboard
OpenClipboard
GetCursorPos
GetWindow
GetWindowThreadProcessId
EnumWindows
SetWindowLongPtrW
GetWindowLongPtrW
ClipCursor
ClientToScreen
GetWindowRect
GetClientRect
SetForegroundWindow
GetForegroundWindow
GetSystemMetrics
MsgWaitForMultipleObjectsEx
ReleaseCapture
GetCapture
SendInput
ScreenToClient
LoadCursorW
DispatchMessageW
GetAsyncKeyState
GetFocus
SetFocus
IsIconic
IsWindowVisible
SetWindowPos
SetLayeredWindowAttributes
PeekMessageW
DefWindowProcW
PostQuitMessage
UnregisterClassW
RegisterClassExW
CreateWindowExW
DestroyWindow
ShowWindow
TranslateMessage
SetProcessDPIAware
MessageBoxW
KERNEL32.dll WakeAllConditionVariable
GetCurrentThreadId
Sleep
SleepConditionVariableSRW
RtlLookupFunctionEntry
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
TerminateProcess
IsProcessorFeaturePresent
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
QueryPerformanceCounter
IsDebuggerPresent
WideCharToMultiByte
MultiByteToWideChar
GlobalFree
GlobalLock
GlobalUnlock
GlobalAlloc
CreateEventW
SetEvent
Process32NextW
Process32FirstW
CreateToolhelp32Snapshot
CreateWaitableTimerExW
SetWaitableTimer
WaitForSingleObject
WaitNamedPipeW
GetLastError
CloseHandle
WriteFile
ReadFile
CreateFileW
GetCurrentThread
LoadLibraryExW
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
FreeLibrary
GetTickCount64
GetPriorityClass
SetPriorityClass
GetThreadPriority
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
GetCurrentProcess
GetCurrentProcessId
SetThreadPriority
MSVCP140.dll ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?imbue@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Id_cnt@id@locale@std@@0HA
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
_Mtx_lock
_Mtx_unlock
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@G@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Query_perf_counter
_Query_perf_frequency
?uncaught_exceptions@std@@YAHXZ
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
_Thrd_join
_Thrd_id
_Cnd_do_broadcast_at_thread_exit
?_Throw_Cpp_error@std@@YAXH@Z
?classic@locale@std@@SAAEBV12@XZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??7ios_base@std@@QEBA_NXZ
?good@ios_base@std@@QEBA_NXZ
?flags@ios_base@std@@QEBAHXZ
?setf@ios_base@std@@QEAAHHH@Z
?width@ios_base@std@@QEBA_JXZ
?width@ios_base@std@@QEAA_J_J@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
MSVCP140_ATOMIC_WAIT.dll __std_atomic_wait_direct
__std_atomic_notify_all_direct
IMM32.dll ImmGetContext
ImmSetCompositionWindow
ImmSetCandidateWindow
ImmReleaseContext
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140.dll __C_specific_handler
__current_exception
__current_exception_context
memchr
__std_terminate
__std_exception_copy
__std_exception_destroy
_CxxThrowException
strstr
memcpy
memmove
memset
memcmp
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
_initterm
_beginthreadex
_register_thread_local_exe_atexit_callback
_c_exit
_exit
exit
_initterm_e
terminate
abort
_get_wide_winmain_command_line
_initialize_wide_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_configure_wide_argv
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfprintf
_get_stream_buffer_pointers
__stdio_common_vsprintf
fclose
__acrt_iob_func
_wfopen
_set_fmode
fflush
fseek
fgetc
fgetpos
__p__commode
ftell
fputc
__stdio_common_vsscanf
ungetc
setvbuf
fread
fwrite
_fseeki64
fsetpos
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
api-ms-win-crt-heap-l1-1-0.dll malloc
free
_set_new_mode
_callnewh
api-ms-win-crt-string-l1-1-0.dll strcmp
strlen
wcslen
strncmp
strncpy
_stricmp
_wcsicmp
tolower
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
sqrtf
lroundf
logf
_dclass
_hypotf
_fdclass
log
atan2f
pow
sinf
acosf
fmodf
cosf
floorf
powf
ceilf
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-convert-l1-1-0.dll atof
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x9c004

NvOptimusEnablement

Ordinal 2
Address 0x9c000

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-25 06:47:21
Version 0.0
SizeofData 111
AddressOfRawData 0x8ef1c
PointerToRawData 0x8e31c
Referenced File E:\updated-kernel-script-main\ks-external\bin\Release\Division2External-FreeNotice.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-25 06:47:21
Version 0.0
SizeofData 20
AddressOfRawData 0x8ef8c
PointerToRawData 0x8e38c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-25 06:47:21
Version 0.0
SizeofData 908
AddressOfRawData 0x8efa0
PointerToRawData 0x8e3a0

TLS Callbacks

StartAddressOfRawData 0x14008f350
EndAddressOfRawData 0x14008f358
AddressOfIndex 0x14009c780
AddressOfCallbacks 0x140082a08
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14009c140

RICH Header

XOR Key 0x2bfbceb7
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 31
Imports (35207) 8
Imports (33145) 17
Total imports 311
C++ objects (35223) 10
Exports (35223) 1
Resource objects (35223) 1
Linker (35223) 1

Errors

Leave a comment

No comments yet.