85a31c4a88912da0b50e9460d4199d9e8c63f947bb5ebe3dab214a36c0703373

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-28 18:34:50
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts kiten_tensei.pdb
CompanyName scryde
FileDescription Scryde
FileVersion 0.4.62
ProductName Scryde
ProductVersion 0.4.62

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • .scrydecdn.com
  • 6881dht.libtorrent.org
  • backend.scrydep.com
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • cloudflare.com
  • cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • clubessence.gametwcstorage.ru
  • comdarvix.netl2.clubessence.gametwcstorage.ru
  • comscrydecdn.xyzscryde.xyzscryde.cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • developer.microsoft.com
  • dht.transmissionbt.com
  • eu.scrydecdn.com
  • facebook.com
  • frontend-static-eu.scrydecdn.com
  • gamescrydecdn.comscrydecdn.xyzscryde.xyzscryde.cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • gametwcstorage.ru
  • genretrucklooksValueFrame.net
  • github.com
  • google.com
  • gstatic.com
  • http://dummy.testcargo
  • http://schemas.xmlsoap.org
  • http://schemas.xmlsoap.org/soap/encoding/
  • http://schemas.xmlsoap.org/soap/envelope/
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.orexpand
  • http://www.w3.org
  • http://www.w3.org/2000/xmlns/'unknown
  • http://www.w3.org/2000/xmlns/Borrowed
  • http://www.w3.org/XML/1998/namespace''
  • http://www.w3.org/XML/1998/namespacehttp
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://a.scrd.to
  • https://a.scrd.to/welcome-to-scrydehttps
  • https://backend.scryde.game
  • https://backend.scryde.game/cabinethttps
  • https://backend.scryde.gamehttps
  • https://backend.scrydep.com
  • https://backend.scrydep.com/cabinethttps
  • https://backend.scrydep.comhttps
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://discord.gg
  • https://docs.rs
  • https://essence.game
  • https://files.scryde.cloud
  • https://files.scryde.cloud/clients_and_patches/Scryde-Client.torrenthttps
  • https://files.scryde.xyzhttps
  • https://frontend-static-eu.scrydecdn.com
  • https://game.scrd.to
  • https://game.scrd.to/scrydeforumDiscorddiscordhttps
  • https://game.scrd.to/scrydeforumhttps
  • https://github.com
  • https://launcher.scryde.cloud
  • https://launcher.scryde.cloud/media/hf_screen.webmhttps
  • https://launcher.scryde.cloud/media/hf_screen.webphttps
  • https://launcher.scryde.cloud/media/rog_screen.webmhttps
  • https://launcher.scryde.cloud/media/rog_screen.webphttps
  • https://launcher.scryde.cloudhttps
  • https://launcher.scryde.xyz
  • https://launcher.scryde.xyz/media/hf_screen.webmhttps
  • https://launcher.scryde.xyz/media/hf_screen.webphttps
  • https://launcher.scryde.xyz/media/rog_screen.webmhttps
  • https://launcher.scryde.xyz/media/rog_screen.webphttps
  • https://launcher.scryde.xyzhttps
  • https://launcher.scrydecdn.xyz
  • https://launcher.scrydecdn.xyz/media/hf_screen.webmhttps
  • https://launcher.scrydecdn.xyz/media/hf_screen.webphttps
  • https://launcher.scrydecdn.xyz/media/rog_screen.webmhttps
  • https://launcher.scrydecdn.xyz/media/rog_screen.webphttps
  • https://launcher.scrydecdn.xyzhttps
  • https://media.scrydecdn.com
  • https://media.scrydecdn.com/static/4VqV9JlrqWPK5xmy731u8x0f8JvpvWLZM42EFyLy.webp?v
  • https://media.scrydecdn.com/static/PqUKwj2ak3QHf2fFYekuF0z3q4M2hTBUEkHhrRcN.webm?v
  • https://ru.scryde.game6LeGcyUUAAAAAJbomIwJvRS-gA_Omis3zBD7ndsLysc1_LOYgareFkmctmtqhUWu7bzOWujWNJtgeBxSa7bwxe59971af
  • https://scryde.gamehttps
  • https://smartcaptcha.yandexcloud.net
  • https://smartcaptcha.yandexcloud.nethttp
  • https://static-eu.scrydecdn.com
  • https://telegram.me
  • https://twlaun.scryde.cloud
  • https://twlaun.scryde.cloud/launcher/Scryde-Client.torrentsitehttps
  • https://twlaun.scryde.cloud/media/hf_screen.webmhttps
  • https://twlaun.scryde.cloud/media/hf_screen.webphttps
  • https://twlaun.scryde.cloud/media/rog_screen.webmhttps
  • https://twlaun.scryde.cloud/media/rog_screen.webphttps
  • https://update.darvix.nethttps
  • https://update1.l2.clubKITEN_CONFIGkiten.config.jsonhttps
  • https://www.World
  • https://www.cloudflare.com
  • https://www.cloudflare.com/cdn-cgi/tracehttps
  • https://www.facebook.com
  • https://www.facebook.com/scrydenet/project_r_launcherScryde/Awesomium.dllScryde/libcef.dllScryde/WebView2Loader.dllhttps
  • https://www.google.com
  • https://www.gstatic.com
  • https://www.instagram.com
  • https://www.instagram.com/scrydenetFacebookfacebookhttps
  • https://www.instagram.com/scryderuhttps
  • https://www.recent
  • instagram.com
  • launcher.scryde.xyz
  • launcher.scrydecdn.xyz
  • libtorrent.org
  • media.scrydecdn.com
  • microsoft.com
  • netl2.clubessence.gametwcstorage.ru
  • netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • openssl.org
  • schemas.xmlsoap.org
  • scryde.gamescrydecdn.comscrydecdn.xyzscryde.xyzscryde.cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • scryde.xyz
  • scrydecdn.com
  • scrydecdn.xyz
  • scrydep.com
  • smartcaptcha.yandexcloud.net
  • static-eu.scrydecdn.com
  • thing.org
  • transmissionbt.com
  • www.cloudflare.com
  • www.facebook.com
  • www.google.com
  • www.gstatic.com
  • www.instagram.com
  • www.w3.org
  • xmlsoap.org
  • xyzscryde.cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • xyzscryde.xyzscryde.cloudscryde.netscrydep.comdarvix.netl2.clubessence.gametwcstorage.ru
  • yandexcloud.net
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
  • NtQueryInformationProcess
  • FindWindowW
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegQueryValueExW
  • RegSetValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteValueW
  • RegGetValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCreateFile
  • NtCancelIoFileEx
  • NtWriteFile
  • NtQueryInformationProcess
  • NtCreateNamedPipeFile
  • NtReadFile
  • NtDeviceIoControlFile
  • NtOpenFile
Uses Microsoft's cryptographic API:
  • CryptDestroyHash
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptCreateHash
  • CryptHashData
  • CryptGetHashParam
  • CryptUnprotectData
  • CryptMsgClose
  • CryptProtectData
  • CryptMsgGetParam
  • CryptQueryObject
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • MapVirtualKeyW
  • GetForegroundWindow
Leverages the raw socket API to access the Internet:
  • sendto
  • recvfrom
  • getsockopt
  • listen
  • WSAStartup
  • connect
  • getaddrinfo
  • freeaddrinfo
  • setsockopt
  • shutdown
  • recv
  • send
  • WSASend
  • bind
  • WSACleanup
  • getsockname
  • WSAGetLastError
  • getpeername
  • closesocket
  • WSAIoctl
  • ioctlsocket
  • WSASocketW
  • accept
Functions related to the privilege level:
  • OpenProcessToken
Manipulates other processes:
  • Process32FirstW
  • OpenProcess
  • Process32NextW
  • ReadProcessMemory
Can take screenshots:
  • FindWindowW
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Interacts with the certificate store:
  • CertAddEncodedCertificateToStore
  • CertAddCertificateContextToStore
  • CertOpenStore
Info The PE is digitally signed. Signer: SCRYDE TECH DMCC
Issuer: GlobalSign GCC R45 CodeSigning CA 2020
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 ef31158f4e19670f716da70808a8ebea
SHA1 603c609be3edd7f31fed728216fb4dc10825bd1c
SHA256 85a31c4a88912da0b50e9460d4199d9e8c63f947bb5ebe3dab214a36c0703373
SHA3 4bf43f2c9da0d167d4d22b24b2b4566455f2f523f99edc2b36c37b69d7993661
SSDeep 98304:CLw15s0UHTrcSz1s7NDlbQ1lsKBZEJRwCNaaY+7p1j:ywVU0ND4lsOmJRwX/WP
Imports Hash bbbbbc8fd3b65e8b63c7580b670e7ea7

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-28 18:34:50
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x693e00
SizeOfInitializedData 0x299e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000665500 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x931000
SizeOfHeaders 0x400
Checksum 0x93a101
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 28b62174e76d7f79e736c3e480fcd36c
SHA1 1080bba9f404afb6f322d6409714e57d3c600a1b
SHA256 8247540d6a9f545d4683485866ca5de85f6b28add3b7f16f97c650ba1d5fb12a
SHA3 c551f6e9a747539b8c074cce1ae7bc6e0c98b92578bde7b9c2b579b9da48d8cd
VirtualSize 0x693d00
VirtualAddress 0x1000
SizeOfRawData 0x693e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32078

.rdata

MD5 3b600928f967d141a17d6722bc05bd04
SHA1 ef47272b56598c12d03d04de7f7cf6432f7cfd90
SHA256 6b12523920d46c0ae655b3cda73512c487def9c50a805fd89040e2a1ee20db92
SHA3 3d645fe674ce88275f2ea889b3c8423a7c2feb703f92c25700feacfdeb682952
VirtualSize 0x25457c
VirtualAddress 0x695000
SizeOfRawData 0x254600
PointerToRawData 0x694200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.81876

.data

MD5 7a36cd0c3a8a9da9d7fdf01c01df8904
SHA1 81625edc5da6c0309d8157cc90aa1d1ec3c85ac2
SHA256 c12c7250f7c85f2a883745dc0b54ad10a46ccee414574cfaaff3016898d89eab
SHA3 d1083239133668bcdff2ccacad165e5b8b696040962142843951e14feb8df1ae
VirtualSize 0x6130
VirtualAddress 0x8ea000
SizeOfRawData 0xc00
PointerToRawData 0x8e8800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.69559

.pdata

MD5 f3b369cab7ff970f27ae05b464a07347
SHA1 6924202862019d06a65d8b2e9378b53bfdb31e67
SHA256 0e4a3a5de14ed98d78c8d27803fe8241f269fd95bdd37f528e85d939dc674e92
SHA3 a645b5e529b8b49258bf7f318a84b0f0b7078b64e5f1585048d473d9bb08d0d8
VirtualSize 0x25ce0
VirtualAddress 0x8f1000
SizeOfRawData 0x25e00
PointerToRawData 0x8e9400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.32729

.rsrc

MD5 a0201fce992d72178f477045754231ca
SHA1 0ef1e33c43568e0892eeafff2ec6d300de1cf056
SHA256 be748b0e4db733fa190a4e8bd1b5cf2a87a30b0d203efc4dfa1af50aead0e784
SHA3 cbeeb2e883fbb697b01d21e5c7e029bcac02969b16d8c0aca7e28a87a31f03d1
VirtualSize 0xd700
VirtualAddress 0x917000
SizeOfRawData 0xd800
PointerToRawData 0x90f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.91422

.reloc

MD5 c7d46a967f132248f97952158a3ea450
SHA1 4c2381c4efa8368409bf9c0ba81dee34921fd30b
SHA256 333fc7d89e8ced591dc4e905f2c7194b4e9096df09d3247d7f617be34148ffa3
SHA3 a636e6d9b9d6f6269ba5b62be2ae9409955a3695d06af327197af08c403ef1f9
VirtualSize 0xc000
VirtualAddress 0x925000
SizeOfRawData 0xc000
PointerToRawData 0x91ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4734

Imports

kernel32.dll CreateProcessW
GetFileAttributesW
GetTempPathW
DeleteFileW
GetFinalPathNameByHandleW
MoveFileExW
CreateWaitableTimerExW
SetWaitableTimer
GetFileInformationByHandleEx
GetFileInformationByHandle
SetFilePointerEx
FindNextFileW
CreateToolhelp32Snapshot
Process32FirstW
OpenProcess
GetProcessTimes
Process32NextW
GetSystemTimes
GetProcessIoCounters
FindFirstFileExW
SetFileTime
CreateThread
SetHandleInformation
WriteFileEx
SleepEx
ReadFileEx
ReadProcessMemory
HeapAlloc
VirtualQueryEx
MultiByteToWideChar
WideCharToMultiByte
CreateMutexA
WaitForSingleObjectEx
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
CreateFileW
QueryPerformanceCounter
SetLastError
CancelIoEx
WriteFile
SetFileCompletionNotificationModes
GetWindowsDirectoryW
GetOverlappedResult
ReadFile
PostQueuedCompletionStatus
GetQueuedCompletionStatusEx
UnmapViewOfFile
DuplicateHandle
GetCurrentProcess
MapViewOfFile
GetCommandLineW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetEnvironmentVariableW
GetCurrentDirectoryW
SetEnvironmentVariableW
FlushViewOfFile
VirtualProtect
TlsSetValue
TlsGetValue
TlsAlloc
InitOnceExecuteOnce
AcquireSRWLockShared
AcquireSRWLockExclusive
ReleaseSRWLockShared
ReleaseSRWLockExclusive
CreateFileMappingW
SetFileInformationByHandle
InitializeSRWLock
WriteConsoleW
RemoveDirectoryW
GetConsoleOutputCP
GetConsoleMode
GetStdHandle
QueryPerformanceFrequency
GetSystemDirectoryW
CompareStringOrdinal
ExitProcess
FlushFileBuffers
GetExitCodeProcess
WaitForSingleObject
GetCurrentThreadId
GetCurrentProcessId
GetDiskFreeSpaceW
GetVolumePathNameW
CreateIoCompletionPort
SetNamedPipeHandleState
LocalFree
FindClose
LCIDToLocaleName
GetProcAddress
LoadLibraryExA
AddVectoredExceptionHandler
GetUserDefaultUILanguage
GetModuleHandleA
WakeAllConditionVariable
GetModuleHandleW
DeviceIoControl
SleepConditionVariableSRW
GetSystemTimeAsFileTime
GetFullPathNameW
InitializeSListHead
SetUnhandledExceptionFilter
RtlUnwindEx
CreateMutexW
RtlPcToFileHeader
ReleaseMutex
RaiseException
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
EncodePointer
SwitchToThread
CloseHandle
lstrlenW
InitializeCriticalSectionEx
Sleep
GetSystemInfo
CreateDirectoryW
GetLastError
FreeLibrary
GetSystemTimePreciseAsFileTime
HeapReAlloc
LoadLibraryExW
OutputDebugStringW
LoadLibraryA
OutputDebugStringA
HeapFree
GetProcessHeap
LoadLibraryW
GetCurrentThread
GetModuleFileNameW
SetThreadStackGuarantee
FormatMessageW
DeleteCriticalSection
advapi32.dll EventUnregister
EventWriteTransfer
EventSetInformation
OpenProcessToken
GetTokenInformation
IsValidSid
RegQueryValueExW
RegSetValueExW
RegOpenKeyExW
EventRegister
RegCloseKey
CryptDestroyHash
CryptReleaseContext
GetLengthSid
CopySid
RegDeleteValueW
CryptAcquireContextW
RegGetValueW
CryptCreateHash
CryptHashData
CryptGetHashParam
SystemFunction036
shell32.dll CommandLineToArgvW
SHCreateItemFromParsingName
ShellExecuteExW
DragQueryFileW
Shell_NotifyIconGetRect
DragFinish
ILFree
SHOpenFolderAndSelectItems
ShellExecuteW
SHAppBarMessage
ILCreateFromPathW
SHGetKnownFolderPath
Shell_NotifyIconW
combase.dll CoTaskMemFree
CoCreateFreeThreadedMarshaler
CoTaskMemAlloc
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WakeByAddressSingle
WaitOnAddress
ws2_32.dll sendto
recvfrom
getsockopt
listen
WSAStartup
connect
getaddrinfo
freeaddrinfo
setsockopt
shutdown
recv
send
WSASend
bind
WSACleanup
getsockname
WSAGetLastError
getpeername
closesocket
WSAIoctl
ioctlsocket
WSASocketW
accept
ntdll.dll NtCreateFile
RtlGetVersion
RtlNtStatusToDosError
NtCancelIoFileEx
NtWriteFile
NtQueryInformationProcess
NtCreateNamedPipeFile
NtReadFile
NtDeviceIoControlFile
NtOpenFile
user32.dll SetCapture
GetTouchInputInfo
CloseTouchInputHandle
EnumDisplayMonitors
MonitorFromPoint
RegisterClassExW
RedrawWindow
GetRawInputData
ScreenToClient
GetKeyState
DestroyWindow
ValidateRect
GetUpdateRect
GetAsyncKeyState
SetParent
GetWindow
UpdateWindow
MapVirtualKeyW
InvalidateRect
ChangeDisplaySettingsExW
GetMenuItemInfoW
RegisterClassW
SetMenuItemInfoW
SetTimer
KillTimer
FindWindowW
SendMessageW
CreateWindowExW
SetWindowLongPtrW
GetParent
RegisterTouchWindow
SetCursorPos
SetCursor
VkKeyScanW
GetWindowLongPtrW
LoadCursorW
GetForegroundWindow
GetDC
IsWindowEnabled
IsWindow
IsIconic
SetPropW
SystemParametersInfoW
ReleaseDC
ClipCursor
GetSystemMetrics
EnableWindow
GetClipCursor
ShowCursor
SetWindowTextW
SetWindowDisplayAffinity
DrawIconEx
GetActiveWindow
GetWindowPlacement
SetWindowPlacement
AdjustWindowRectEx
GetMenu
GetWindowLongW
SetWindowLongW
GetSystemMenu
RegisterWindowMessageA
MapWindowPoints
OffsetRect
GetWindowDC
FillRect
DrawTextW
MonitorFromRect
SendInput
DefWindowProcW
RegisterRawInputDevices
ClientToScreen
AdjustWindowRect
PostMessageW
SetFocus
ReleaseCapture
ToUnicodeEx
MonitorFromWindow
SetWindowRgn
IsProcessDPIAware
TrackPopupMenu
SetForegroundWindow
GetCursorPos
GetWindowRect
GetClientRect
GetMenuBarInfo
ShowWindow
PostQuitMessage
SystemParametersInfoA
SetMenu
CreateIcon
RemoveMenu
CheckMenuItem
EnableMenuItem
DrawMenuBar
CreatePopupMenu
CreateMenu
AppendMenuW
InsertMenuW
CreateAcceleratorTableW
DestroyAcceleratorTable
DestroyIcon
DestroyMenu
GetKeyboardLayout
SetWindowPos
GetMessageA
MapVirtualKeyExW
TranslateMessage
DispatchMessageA
EnumChildWindows
GetKeyboardState
TranslateAcceleratorW
InvalidateRgn
MessageBoxW
GetWindowTextW
GetWindowTextLengthW
GetWindowThreadProcessId
IsWindowVisible
EnumWindows
ChangeWindowMessageFilterEx
FlashWindowEx
MsgWaitForMultipleObjectsEx
DispatchMessageW
GetMessageW
PeekMessageW
PostThreadMessageW
TrackMouseEvent
FindWindowExW
GetMonitorInfoW
ole32.dll CoCreateInstance
CoInitialize
CoUninitialize
CoInitializeEx
RevokeDragDrop
RegisterDragDrop
OleInitialize
oleaut32.dll GetErrorInfo
SysStringLen
SetErrorInfo
SysFreeString
comctl32.dll DefSubclassProc
RemoveWindowSubclass
SetWindowSubclass
TaskDialogIndirect
shlwapi.dll SHCreateMemStream
iphlpapi.dll ConvertInterfaceLuidToIndex
ConvertLengthToIpv4Mask
GetAdaptersAddresses
secur32.dll AcceptSecurityContext
QueryContextAttributesW
DeleteSecurityContext
ApplyControlToken
DecryptMessage
FreeCredentialsHandle
EncryptMessage
FreeContextBuffer
InitializeSecurityContextW
AcquireCredentialsHandleA
psapi.dll GetProcessMemoryInfo
GetModuleFileNameExW
powrprof.dll CallNtPowerInformation
pdh.dll PdhRemoveCounter
PdhCloseQuery
bcryptprimitives.dll ProcessPrng
dwmapi.dll DwmSetWindowAttribute
DwmEnableBlurBehindWindow
DwmGetWindowAttribute
gdi32.dll SelectObject
DeleteObject
CreateRectRgn
CreateSolidBrush
DeleteDC
SetBkMode
SetTextColor
CreateCompatibleDC
GetDeviceCaps
BitBlt
CombineRgn
CreateDIBSection
crypt32.dll CertFreeCertificateChainEngine
CertAddEncodedCertificateToStore
CertGetCertificateChain
CertDuplicateCertificateContext
CertDuplicateStore
CertCreateCertificateChainEngine
CertSetCertificateContextProperty
CryptUnprotectData
CertFreeCertificateContext
CertCloseStore
CryptMsgClose
CertGetCertificateContextProperty
CertDuplicateCertificateChain
CertFindCertificateInStore
CertAddCertificateContextToStore
CertOpenStore
CryptProtectData
CryptMsgGetParam
CryptQueryObject
CertEnumCertificatesInStore
CertFreeCertificateChain
CertVerifyCertificateChainPolicy
rstrtmgr.dll RmGetList
RmStartSession
RmRegisterResources
RmEndSession
wintrust.dll WinVerifyTrust
bcrypt.dll BCryptGenRandom
api-ms-win-crt-string-l1-1-0.dll wcslen
wcscmp
_wcsicmp
strlen
strcmp
strcpy_s
api-ms-win-crt-math-l1-1-0.dll pow
roundf
round
floor
trunc
__setusermatherr
api-ms-win-crt-heap-l1-1-0.dll malloc
calloc
_callnewh
_set_new_mode
realloc
free
api-ms-win-crt-utility-l1-1-0.dll _rotl64
bsearch
api-ms-win-crt-convert-l1-1-0.dll _wtoi
strtol
wcstol
_ultow_s
api-ms-win-crt-runtime-l1-1-0.dll __p___argv
_c_exit
_initterm
__p___argc
abort
_seh_filter_exe
_set_app_type
_initterm_e
_configure_narrow_argv
_register_thread_local_exe_atexit_callback
_initialize_narrow_environment
_errno
terminate
_crt_atexit
_get_initial_narrow_environment
exit
_register_onexit_function
_initialize_onexit_table
_exit
_wassert
_cexit
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-stdio-l1-1-0.dll _setmode
fwrite
ftell
fseek
fflush
_fileno
__p__commode
fopen
fgets
__stdio_common_vsprintf
ferror
feof
_set_fmode
fclose
__stdio_common_vfprintf
__stdio_common_vsscanf
__acrt_iob_func
fread
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

aws_lc_0_42_0_jent_entropy_collector_alloc

Ordinal 1
Address 0x659a30

aws_lc_0_42_0_jent_entropy_collector_free

Ordinal 2
Address 0x659ab0

aws_lc_0_42_0_jent_entropy_init

Ordinal 3
Address 0x659b30

aws_lc_0_42_0_jent_entropy_init_ex

Ordinal 4
Address 0x659b70

aws_lc_0_42_0_jent_entropy_switch_notime_impl

Ordinal 5
Address 0x659c00

aws_lc_0_42_0_jent_read_entropy

Ordinal 6
Address 0x659570

aws_lc_0_42_0_jent_read_entropy_safe

Ordinal 7
Address 0x659720

aws_lc_0_42_0_jent_set_fips_failure_callback

Ordinal 8
Address 0x659bd0

aws_lc_0_42_0_jent_version

Ordinal 9
Address 0x659bf0

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x83f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.73337
Detected Filetype PNG graphic file
MD5 92c3694d50345bfae913efa809770f4b
SHA1 3baacbbcaf9c734751cefda8c565f0f554d1245c
SHA256 5abef034e746af364237af119dc5d29e80898a7b2fb5f15edd1125397081581f
SHA3 7c4081eef793c60ecba87dfd6c3e40821bea8ee6db2475d030ef6e7cfe70d71b

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x323
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.53321
Detected Filetype PNG graphic file
MD5 7fa47814c4f49e98c8e3914345ebcdc5
SHA1 d33ee85b4edfb6939edaefc641f9dc61d32eab72
SHA256 0d328d7e4bcb1088e957ab865105621e19af3632cd18ad3298c61ca83edfb216
SHA3 37e93242eaf121363da1b45b33a355b8816e784c4c50c7d7134bb0585b3bb769

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x564
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.69269
Detected Filetype PNG graphic file
MD5 ecc15ed02513823d867cf1d005d12af5
SHA1 386dc857b2285b942846e607507b494b0557e5f3
SHA256 6bae9cba5d79475eb250bc6ccede96fe7af54eea9470c51d368bc8d79053c75a
SHA3 fd362cdde12d2bafddd58c97705e95b3cb23c78f7ee449d20f1907a1eed7a9ab

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xedd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.73659
Detected Filetype PNG graphic file
MD5 4ce650828ab5b45bb73e63c0b4b8ca66
SHA1 cfd0b1bb576d95b2cbe853dc768972754e7315f2
SHA256 40bee934abf1e4280eb07a049403e85517e4df8703bb508ed0790fbdbab6808f
SHA3 bbd4be21873948727f812c3952b0c4060b306a9261fbf84d5b55cdfc35b35b7b

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1682
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.73669
Detected Filetype PNG graphic file
MD5 f6497bae49f6a97b4b184cc86ad3b205
SHA1 7800833726a3ab80a60af82e53a4b7eb1ae4459a
SHA256 36798cedc2ff75303053108708d07026287082a4f3b4df2627cb471e5dc0b0b2
SHA3 6d036aad8939e21f243f2105b2fe97b79de5c08b9fbacfc8a81c6de9a4d39ca6

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x96cf
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98241
Detected Filetype PNG graphic file
MD5 f055ca7f2c1e181145432db84589549c
SHA1 4b978aa83825561017d6824a29c99610d250cd62
SHA256 14eba5d768fa86abab7186b4ccb2ae635781c6793c81b6d766f6e56cde4af463
SHA3 78a34ec83958643ad9d8cce621b408db6f458e3a4c18fa751576f7b9a714ce59

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82432
Detected Filetype Icon file
MD5 9f51440c4ababff1fb58b7898c09f6bc
SHA1 0e991e0c66a1e5ff2af471ababc8e5f3073539f9
SHA256 dd54789c1facb77bf0951c512dd3f1d0c371483164de8796d9ae2d7a79f0c453
SHA3 63c03dd2c583bfe2279cf148dc5122ec019d5d0c6834268ec8d6553b6628c6a7

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1d8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10037
MD5 a33d234584af893a91d5e57fcb469cb7
SHA1 78e39f09d333d29c60bdc95e8557c6608eb9facc
SHA256 10fb04449bf965c7952e0cebe6c284378628f3d85981d66dcbbf634a1083d212
SHA3 121a4e7f3ee1bf58447e06ff0ce3266a4c6db8a80b00cd7029f5cb0575142fdc

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x5a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28304
MD5 d0ab7a7bbe12bb5b489320e4ec19e9f0
SHA1 30c4f53c1a08417c7131bc7373ae0180da0067a0
SHA256 dfcc1c9042597a7dda72b21f8eb1b2dbd6cc3d5bde005e87369c2a98f170095a
SHA3 9fd96a7d0fb2b8191c534d6460cc7a4b43991b5b0dbd3e7d6c6f2816867d9557

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.4.62.0
ProductVersion 0.4.62.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName scryde
FileDescription Scryde
FileVersion (#2) 0.4.62
ProductName Scryde
ProductVersion (#2) 0.4.62
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-28 18:34:50
Version 0.0
SizeofData 41
AddressOfRawData 0x8d56cc
PointerToRawData 0x8d48cc
Referenced File kiten_tensei.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-28 18:34:50
Version 0.0
SizeofData 20
AddressOfRawData 0x8d56f8
PointerToRawData 0x8d48f8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-28 18:34:50
Version 0.0
SizeofData 1084
AddressOfRawData 0x8d570c
PointerToRawData 0x8d490c

TLS Callbacks

StartAddressOfRawData 0x1408d5b90
EndAddressOfRawData 0x1408d5d74
AddressOfIndex 0x1408effbc
AddressOfCallbacks 0x1406960b8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014050DEE0
0x00000001406541B0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1408ea940

RICH Header

XOR Key 0x6fbefda
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 19
ASM objects (35721) 10
C objects (35721) 14
C++ objects (35721) 46
Total imports 504
C objects (36248) 75
Unmarked objects (#2) 104
Exports (36248) 1
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.