7f67be0efc8dd21391269db9e79cb265667cf7734a5a0a92bafaf3d656181f8c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-27 18:10:12
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts loader.pdb
CompanyName morphine
FileDescription MORPHINE
FileVersion 1.0.0
ProductName MORPHINE
ProductVersion 1.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • GoDaddy.com
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://docs.rs
  • https://github.com
  • https://mrdill-nfa.mr-dill.com
  • https://mrdill-nfa.mr-dill.com/
  • https://www.World
  • https://www.recent
  • microsoft.com
  • mr-dill.com
  • mrdill-nfa.mr-dill.com
  • nfa.mr-dill.com
  • openssl.org
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegGetValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCancelIoFileEx
  • NtCreateFile
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtOpenFile
  • NtReadFile
  • NtWriteFile
Uses Microsoft's cryptographic API:
  • CryptProtectData
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyW
Leverages the raw socket API to access the Internet:
  • WSACleanup
  • WSAGetLastError
  • WSAIoctl
  • WSASend
  • WSASocketW
  • WSAStartup
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • getsockopt
  • ioctlsocket
  • recv
  • send
  • setsockopt
  • shutdown
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 a9f32e5ae696badbb104ca3d0f2d95e5
SHA1 41e08ecb320e973369e6df9b5f521f6a54a27d85
SHA256 7f67be0efc8dd21391269db9e79cb265667cf7734a5a0a92bafaf3d656181f8c
SHA3 5b1f973500f8b77161e430693f4e5bf42ec6dbea87414871e91a0831f1e2711d
SSDeep 98304:SKej7WltmDLYKpChirPHbMA4/VgDnzJEhi8detuNSzPN5yEIj6z+YLSP5we:L2fPyCD6j6zMy
Imports Hash d48ce5ea6f6219761512a7111359a9c4

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2026-Jul-27 18:10:12
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x58e800
SizeOfInitializedData 0x287c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000575E84 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x81e000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f78fa86ac307a6b2a70ce72350c3956f
SHA1 22b9d0d7e134a54b29e9a1ddfcfd3cc7d673254f
SHA256 95d7d2973a8ca4c7d40d2630ec54ef3bb60aa8aec6efca3a5a2817eabde40601
SHA3 92cbfdca94fccc5dcff4eb6ccc666f15dcc9e9701666851c5841deec3ca51028
VirtualSize 0x58e616
VirtualAddress 0x1000
SizeOfRawData 0x58e800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.24851

.rdata

MD5 735065d035d8ad015cdc450150176104
SHA1 a5242f8a561b400a6a41f0e5eaac5752d0aced39
SHA256 130c2ebfa74f7fc5d2d40396e56fb6b0c66f3ddb7da31b81d082e7c535e843fa
SHA3 85e3fdff30f780ec5e91b61e2211a2519690c6ba533cef4f207fc3151bedf739
VirtualSize 0x22fdc4
VirtualAddress 0x590000
SizeOfRawData 0x22fe00
PointerToRawData 0x58ec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.25578

.data

MD5 7b861b10019c4f0b7783521a33ef980a
SHA1 fb118623168ba6abce952fbf8e46e0bf34178f03
SHA256 edb123d0f813ffb4ddcb0b0d1cd79c32ebf893df3c07beda31cd8ee3146f7c79
SHA3 067b49e4b60430ae44e3c7c5eead4339c5f5571a0c5678897930e6cb78a8cf4e
VirtualSize 0x3418
VirtualAddress 0x7c0000
SizeOfRawData 0xc00
PointerToRawData 0x7bea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.4906

.pdata

MD5 205798ecd22e8fb453b5978834c5bca3
SHA1 961c3cc8e2d120c718af3a7b50b912c2e7c6a983
SHA256 4390850fbaed0a51d4fbaa4cddd79b66c5317d854f2060bb57292e4a47dbe330
SHA3 c6051a3a918556657939492d688102dd6ed93b03a09a3b56d4edfb8890e86097
VirtualSize 0x4d9d0
VirtualAddress 0x7c4000
SizeOfRawData 0x4da00
PointerToRawData 0x7bf600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.6315

.00cfg

MD5 f306700b80aa89cc3c50f806e3cfc5bb
SHA1 e7f8399f083e4af88b192cfe5c2303db1eebecc8
SHA256 14eb6996397496c673aa28c06ea4ad969fd8fd1d0da1fc4614f76c8da2acff3b
SHA3 ffba3983587461a07114260fc9a560e062f62393f0786dc3eb2cd53c18244854
VirtualSize 0x38
VirtualAddress 0x812000
SizeOfRawData 0x200
PointerToRawData 0x80d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.487903

.tls

MD5 bf42b0702885d7da063f21d4257781a9
SHA1 52b87d40ff133e8742ae0a23ba045f6a3350c891
SHA256 00d4ae9a6f88fe490256d31aba7ea03283bed810ab27715316d672799cdb93dd
SHA3 290b88cea5ee099676a02c4f873ffc57302594a9228d46c0f1ad439e2877f8bc
VirtualSize 0x1ad
VirtualAddress 0x813000
SizeOfRawData 0x200
PointerToRawData 0x80d200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0776332

.rsrc

MD5 8e21c4cabb7becaf9ebccdc3f77c8813
SHA1 624238a00093bc53ffa02ff5e7b1b8f2b2d62596
SHA256 a3d197e5585ee00fa588986f82fbda92ff6e540f4d7cf6ef1b16c4d92c26569b
SHA3 aedb069c5536149c40c4d3f1bc30aa3f88f50338b51a85fde86c5f1c7d7322fa
VirtualSize 0x4cf0
VirtualAddress 0x814000
SizeOfRawData 0x4e00
PointerToRawData 0x80d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.69461

.reloc

MD5 0398f5f39242ebc8602fac4c4ec4c41b
SHA1 f0af9b2abf1fa0aa83f3fc96fba5ab8b39d7ccbb
SHA256 664bf72f7f4ecd01e189cb753a3b796fe377c32e00d7c455f68a8b8f5e82fd64
SHA3 594dfb2afddf4d278e6d326f01d0e8a440da6fdd9b659afaefd68761581bce49
VirtualSize 0x45e4
VirtualAddress 0x819000
SizeOfRawData 0x4600
PointerToRawData 0x812200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4613

Imports

bcryptprimitives.dll ProcessPrng
ntdll.dll NtCancelIoFileEx
NtCreateFile
NtCreateNamedPipeFile
NtDeviceIoControlFile
NtOpenFile
NtReadFile
NtWriteFile
RtlGetVersion
RtlNtStatusToDosError
kernel32.dll AcquireSRWLockExclusive
AddVectoredExceptionHandler
CancelIo
CancelIoEx
CloseHandle
CompareStringOrdinal
CreateDirectoryW
CreateEventW
CreateFileW
CreateIoCompletionPort
CreateMutexA
CreateProcessW
CreateThread
CreateWaitableTimerExW
DeleteFileW
DuplicateHandle
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetEnvironmentStringsW
GetEnvironmentVariableW
GetExitCodeProcess
GetFileAttributesW
GetFileInformationByHandle
GetFileInformationByHandleEx
GetFinalPathNameByHandleW
GetFullPathNameW
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOverlappedResult
GetProcAddress
GetProcessHeap
GetQueuedCompletionStatusEx
GetStdHandle
GetSystemDirectoryW
GetSystemInfo
GetSystemTimeAsFileTime
GetSystemTimePreciseAsFileTime
GetTempPathW
GetUserDefaultUILanguage
GetWindowsDirectoryW
GlobalLock
GlobalSize
GlobalUnlock
HeapAlloc
HeapFree
HeapReAlloc
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
LCIDToLocaleName
LoadLibraryA
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LocalFree
MultiByteToWideChar
OutputDebugStringA
OutputDebugStringW
PostQueuedCompletionStatus
QueryPerformanceCounter
QueryPerformanceFrequency
ReadFile
ReadFileEx
ReleaseMutex
ReleaseSRWLockExclusive
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetEnvironmentVariableW
SetFileCompletionNotificationModes
SetFileInformationByHandle
SetFileTime
SetHandleInformation
SetLastError
SetNamedPipeHandleState
SetThreadStackGuarantee
SetUnhandledExceptionFilter
SetWaitableTimer
Sleep
SleepConditionVariableSRW
SleepEx
SwitchToThread
TerminateProcess
UnhandledExceptionFilter
WaitForMultipleObjects
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
WriteFileEx
lstrlenW
user32.dll AdjustWindowRect
AdjustWindowRectEx
AppendMenuW
ChangeDisplaySettingsExW
ChangeWindowMessageFilterEx
CheckMenuItem
ClientToScreen
ClipCursor
CloseClipboard
CloseTouchInputHandle
CreateAcceleratorTableW
CreateIcon
CreateMenu
CreatePopupMenu
CreateWindowExW
DefWindowProcW
DestroyAcceleratorTable
DestroyIcon
DestroyMenu
DestroyWindow
DispatchMessageA
DispatchMessageW
DrawIconEx
DrawMenuBar
DrawTextW
EnableMenuItem
EnableWindow
EnumChildWindows
EnumDisplayMonitors
FillRect
FindWindowExW
FlashWindowEx
GetActiveWindow
GetAsyncKeyState
GetClientRect
GetClipCursor
GetClipboardData
GetCursorPos
GetDC
GetForegroundWindow
GetKeyState
GetKeyboardLayout
GetKeyboardState
GetMenu
GetMenuBarInfo
GetMenuItemInfoW
GetMessageA
GetMessageW
GetMonitorInfoW
GetParent
GetRawInputData
GetSystemMenu
GetSystemMetrics
GetTouchInputInfo
GetUpdateRect
GetWindow
GetWindowDC
GetWindowLongPtrW
GetWindowLongW
GetWindowPlacement
GetWindowRect
GetWindowTextLengthW
GetWindowTextW
InsertMenuW
InvalidateRect
InvalidateRgn
IsIconic
IsProcessDPIAware
IsWindow
IsWindowEnabled
IsWindowVisible
KillTimer
LoadCursorW
MapVirtualKeyExW
MapVirtualKeyW
MapWindowPoints
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
OffsetRect
OpenClipboard
PeekMessageW
PostMessageW
PostQuitMessage
PostThreadMessageW
RedrawWindow
RegisterClassExW
RegisterClassW
RegisterRawInputDevices
RegisterTouchWindow
RegisterWindowMessageA
ReleaseCapture
ReleaseDC
RemoveMenu
ScreenToClient
SendInput
SendMessageW
SetCapture
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetMenu
SetMenuItemInfoW
SetParent
SetPropW
SetTimer
SetWindowDisplayAffinity
SetWindowLongPtrW
SetWindowLongW
SetWindowPlacement
SetWindowPos
SetWindowRgn
SetWindowTextW
ShowCursor
ShowWindow
SystemParametersInfoA
SystemParametersInfoW
ToUnicodeEx
TrackMouseEvent
TrackPopupMenu
TranslateAcceleratorW
TranslateMessage
UpdateWindow
ValidateRect
VkKeyScanW
shell32.dll DragFinish
DragQueryFileW
SHAppBarMessage
SHGetKnownFolderPath
ShellExecuteW
Shell_NotifyIconGetRect
Shell_NotifyIconW
gdi32.dll BitBlt
CombineRgn
CreateCompatibleDC
CreateDIBSection
CreateRectRgn
CreateSolidBrush
DeleteDC
DeleteObject
GetDeviceCaps
SelectObject
SetBkMode
SetTextColor
ole32.dll CoCreateFreeThreadedMarshaler
CoCreateInstance
CoIncrementMTAUsage
CoInitializeEx
CoTaskMemAlloc
CoTaskMemFree
CoUninitialize
OleInitialize
RegisterDragDrop
RevokeDragDrop
comctl32.dll DefSubclassProc
RemoveWindowSubclass
SetWindowSubclass
TaskDialogIndirect
dwmapi.dll DwmEnableBlurBehindWindow
DwmGetWindowAttribute
DwmSetWindowAttribute
oleaut32.dll GetErrorInfo
SetErrorInfo
SysFreeString
SysStringLen
ADVAPI32.dll EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
RegCloseKey
RegGetValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SystemFunction036
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory
shlwapi.dll SHCreateMemStream
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
WakeByAddressAll
WakeByAddressSingle
ws2_32.dll WSACleanup
WSAGetLastError
WSAIoctl
WSASend
WSASocketW
WSAStartup
bind
closesocket
connect
freeaddrinfo
getaddrinfo
getpeername
getsockname
getsockopt
ioctlsocket
recv
send
setsockopt
shutdown
bcrypt.dll BCryptGenRandom
crypt32.dll CryptProtectData
VCRUNTIME140.dll _CxxThrowException
__C_specific_handler
__CxxFrameHandler3
__current_exception
__current_exception_context
__std_exception_copy
__std_exception_destroy
_purecall
memcmp
memcpy
memmove
memset
wcsrchr
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
_c_exit
_cexit
_configure_narrow_argv
_crt_atexit
_exit
_get_initial_narrow_environment
_initialize_narrow_environment
_initialize_onexit_table
_initterm
_initterm_e
_register_onexit_function
_register_thread_local_exe_atexit_callback
_seh_filter_exe
_set_app_type
exit
terminate
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_set_fmode
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
floor
fmod
pow
round
roundf
trunc
api-ms-win-crt-utility-l1-1-0.dll _byteswap_ulong
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
free
malloc
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-convert-l1-1-0.dll _ultow_s
_wtoi
wcstol
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
wcscmp
wcslen

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x53e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70307
Detected Filetype PNG graphic file
MD5 166df3ff7cb2a3c941e2e2c09cc6accd
SHA1 9b9f595c5c77fbf6534887bb54ef26e6201b3fcc
SHA256 079829f7378b892fa5a55120c26364acb054712f39350bcfaa78465ce347397d
SHA3 378d78ddaa6a676c51d8146b87219757147da38ed80ff8212ff0ca1e1ad6875d

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.56268
Detected Filetype PNG graphic file
MD5 7bd35cb407fc9a4288048790c7e6df9b
SHA1 07d823344fd72e1d7a1156408e979bb1b80ef304
SHA256 ea688627747d47f8fd302a6607936b861d158ca2eb5307b3e96b7846238de58b
SHA3 9b20423913e090347a2019d58be73934e15527b28bddd0bb5e5650b9e1c92cea

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62605
Detected Filetype PNG graphic file
MD5 6985e85a55aa5e345515d0a7d403582d
SHA1 bf61278c68bb84662b5e70be67a5d77c4fd31eac
SHA256 12c0f2d386dbb989024544bc55a5ef5cf0c9c7806bc5ccacb16fbb2008e5c367
SHA3 a435f709414c276bf8e8012d442b840ad1b3a3a93b0562d1838f1d937fce0628

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x727
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.7444
Detected Filetype PNG graphic file
MD5 280120be97286e441c88edc605a83af9
SHA1 d4c85467795b6653c2ee7024663f6bea1593798c
SHA256 4432a5b017468a158508089a89e2f86a4394b4e489e42d9a7fb22431ced24928
SHA3 c9a740c3348990adcb8bc15ef9643049e973a95a9c86c64622e3b0bbfbd34518

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa29
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74088
Detected Filetype PNG graphic file
MD5 b94bf096780224f145e0189ee86a3cbf
SHA1 854d16693d662cc200d10ced48e6457cd16fa8f1
SHA256 be9d5994690d96812e64f7a9a19b94389e21510837d344826d2c0130504d9859
SHA3 81c219271198e3da876518903d4b062e7a7c649b2e1d43c1f9f72274c9a370ba

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2a3b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88473
Detected Filetype PNG graphic file
MD5 ed9afdc009b872280f32848e01e24262
SHA1 63d871bfd67ed780fc00d6079e16b296d0efac10
SHA256 0fcdebe123c90da1e5580c6c8e51a465171f96fc48e6cc6ac6b591eff881c41e
SHA3 1407aa16a88c80539fe5f28018ed365a670e8de93484fd94b6dc0ad98a4c8e4a

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8021
Detected Filetype Icon file
MD5 7da124573e163f7c895aa44b8e51dc40
SHA1 95d73b29756e23d3a615baa0ab94b2ecebb6b8ef
SHA256 a252193d42d8f13e8785048e1b3f0a8bad9e0d1c9ecdab171d2fa4b4eb39b59d
SHA3 c010fa78b9239b3d3392cdcac8c209a809a91c7b004c6cf83366ca90083023cb

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15069
MD5 96ee803fb90d1fcfe101bad9dd770a9b
SHA1 41e96bfec04f18613e3346ac27ffd15dba6e69aa
SHA256 b2d43c584f56962f8d2f6e70af0837779d804caead9cd6b245ac5654a0a83528
SHA3 1083a6ffb0e0912226adec69b1d7179ac4071762c0b7365afcb2b22d294b3cb3

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName morphine
FileDescription MORPHINE
FileVersion (#2) 1.0.0
ProductName MORPHINE
ProductVersion (#2) 1.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-27 18:10:12
Version 0.0
SizeofData 35
AddressOfRawData 0x68d3d4
PointerToRawData 0x68bfd4
Referenced File loader.pdb

TLS Callbacks

StartAddressOfRawData 0x140813000
EndAddressOfRawData 0x1408131ac
AddressOfIndex 0x1407c2ddc
AddressOfCallbacks 0x14068d448
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014047AB40

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1407c0900

RICH Header

Errors

Leave a comment

No comments yet.