912940e7fa6f4289c1dbb51a0e782bbaf0136d794404ce7d69761cd9587b27a6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-16 00:28:20
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts C:\Users\pc\Downloads\40drspq (1)\fragment\build\passive.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • crl.globalsign.com
  • github.com
  • globalsign.com
  • http://crl.globalsign.com
  • http://crl.globalsign.com/ca/gstsacasha384g4.crl0
  • http://crl.globalsign.com/codesigningrootr45.crl0U
  • http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
  • http://crl.globalsign.com/root-r3.crl0G
  • http://crl.globalsign.com/root-r6.crl0G
  • http://crl.globalsign.com/root.crl0G
  • http://ocsp.globalsign.com
  • http://ocsp.globalsign.com/ca/gstsacasha384g40C
  • http://ocsp.globalsign.com/codesigningrootr450F
  • http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
  • http://ocsp.globalsign.com/rootr103
  • http://ocsp.globalsign.com/rootr30
  • http://ocsp2.globalsign.com
  • http://ocsp2.globalsign.com/rootr606
  • http://secure.globalsign.com
  • http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
  • http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
  • http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
  • http://secure.globalsign.com/cacert/root-r3.crt06
  • http://www.microsoft.com
  • http://www.microsoft.com/typography/fonts/
  • http://www.styleseven.comFreeware
  • http://www.styleseven.comSmallest
  • http://www.styleseven.comThin
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://github.com
  • https://offsets.imtheo.lol
  • https://www.globalsign.com
  • https://www.globalsign.com/repository/0
  • microsoft.com
  • ocsp.globalsign.com
  • ocsp2.globalsign.com
  • rbxcdn.com
  • roblox.com
  • secure.globalsign.com
  • thumbnails.roblox.com
  • www.globalsign.com
  • www.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities:
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
Possibly launches other programs:
  • ShellExecuteW
Can create temporary files:
  • GetTempPathW
  • CreateFileA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • WinHttpAddRequestHeaders
  • WinHttpReadData
  • WinHttpOpenRequest
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpSetTimeouts
  • WinHttpConnect
  • WinHttpQueryDataAvailable
  • WinHttpSetOption
  • URLDownloadToFileA
Manipulates other processes:
  • WriteProcessMemory
  • Process32First
  • OpenProcess
  • Process32Next
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 9/71 (Scanned on 2026-08-16 01:41:04) Bkav: W32.Malware.C17345BB
ESET-NOD32: Win64/GenKryptik_AGen.BVS trojan
Elastic: malicious (high confidence)
Google: Detected
Ikarus: Trojan.Win64.Krypt
Malwarebytes: Malware.AI.3410555604
McAfeeD: ti!912940E7FA6F
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence

Hashes

MD5 2aa8777e951259e85fe48d78a116230e 🔍
SHA1 29c3070bfa85d8e00a96fdafbffcd51f817ed957 🔍
SHA256 912940e7fa6f4289c1dbb51a0e782bbaf0136d794404ce7d69761cd9587b27a6 🔍
SHA3 02e549665bc422022b3184af5acf62a9f1be4ae46af1a1ce2981d79331833247 🔍
SSDeep 49152:CE0dkGYDSQKvwLqIgrUYGu8gPNiY/zFJMexSNBM0AGtq96O6WrLCM2sH+gCYUG2:UdkGY6oLzD06Arh8FuOM1zYij 🔍
Imports Hash f1c5455b9e5a4f7b3509815aabfadbf7 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-16 00:28:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x217c00
SizeOfInitializedData 0xa83e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000208040 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xca0000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 dfe1f5b2f63c2c1b5d6ea076b12334c3 🔍
SHA1 56f3365327dc950fd58bc744ccc5ff84b0e4f507 🔍
SHA256 f05226a551055a4f52b0040659f424c8e0bf55f3bebb0a1c5387627d99dcbff2 🔍
SHA3 c03120e4f4646835ee6dd374fd451a397eef8e7caba6323336a06cd4b8915205 🔍
VirtualSize 0x217a61
VirtualAddress 0x1000
SizeOfRawData 0x217c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51329

.rdata

MD5 0c15fa7d32acbbc7e439fad267d7f9ab 🔍
SHA1 27b9730693dfc2eb5b40c6705734bf8111be389e 🔍
SHA256 74786de5236eae76df51f283ddff3d10e1bfe1a70727191d6967b2182c7073c1 🔍
SHA3 b0777acbc07b0f7b0afb2c91c7a5620a61c932a59445d49634ea8e02886396fc 🔍
VirtualSize 0xa5637c
VirtualAddress 0x219000
SizeOfRawData 0xa56400
PointerToRawData 0x218000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.35076

.data

MD5 ed92a7692f832cc770f54f73a14b6b85 🔍
SHA1 300c31a6d42d826a6ee03deb7567338d1903644a 🔍
SHA256 9b47f8cb2978e1f1df35dd6d0b674358fd2f750de90da737caff88f99980fd5e 🔍
SHA3 e489a808df8037f8553d77faf80f8d4d5e48739150a0113916fa82f7bf005b73 🔍
VirtualSize 0x157f4
VirtualAddress 0xc70000
SizeOfRawData 0xdc00
PointerToRawData 0xc6e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.69313

.pdata

MD5 226ff853f19848c81ef1f521aa1bcf6d 🔍
SHA1 2b5b817e9f7e59e232a0d1815beccd8db76e08ad 🔍
SHA256 a725585f4fd3339d0780b022423483152b95b7ea6c46108d70942964c7de1163 🔍
SHA3 152fa80ccb20546ba8f573ac108fa121d1a4571d52302999ff1bc4b4af2b1ad8 🔍
VirtualSize 0x1611c
VirtualAddress 0xc86000
SizeOfRawData 0x16200
PointerToRawData 0xc7c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28678

.rsrc

MD5 db2dd09ca07a86954b0d033f5a69acb8 🔍
SHA1 e2d82bf99d012df6a486d3ad8fa2059d2ad6109d 🔍
SHA256 5ae6a53ae1a32f83fb42f659555e4e3230a6a83a849693edc4d22d09ae4ccbcb 🔍
SHA3 3f374f24c5c1f72e98557bc369b6700dc0c58b2e45cb718ac730b879c2063c81 🔍
VirtualSize 0x1e0
VirtualAddress 0xc9d000
SizeOfRawData 0x200
PointerToRawData 0xc92200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 f064524a6cddff4ff00c2b31ee5c8bb1 🔍
SHA1 3476881237297204a21e762ba0b4d1c52e42ea80 🔍
SHA256 eb54f00b93f4caed4c89b85a4bfbe343bf3fe2ee46db08b7d3498119d5f0ef44 🔍
SHA3 928aad0a422d7214b13966d11e495e796e89556ce488a96316293770d823868a 🔍
VirtualSize 0x1c88
VirtualAddress 0xc9e000
SizeOfRawData 0x1e00
PointerToRawData 0xc92400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38529

Imports

KERNEL32.dll GetModuleFileNameA
GetFileAttributesW
SetFileAttributesW
GetModuleFileNameW
GetTempPathW
LoadLibraryW
GetTickCount64
WriteProcessMemory
GetModuleHandleW
OutputDebugStringA
GetWindowsDirectoryA
GetConsoleWindow
Process32First
Module32Next
GetProcessId
Module32First
OpenProcess
CreateToolhelp32Snapshot
GetLastError
Process32Next
CloseHandle
VirtualAllocEx
GetExitCodeProcess
SetConsoleScreenBufferSize
GetStdHandle
SetCurrentConsoleFontEx
SetConsoleWindowInfo
GetConsoleScreenBufferInfo
SetConsoleTextAttribute
GetLocalTime
CreateFileA
GetFileSizeEx
ReadFile
HeapAlloc
HeapFree
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
GlobalUnlock
WideCharToMultiByte
InitOnceComplete
GetLocaleInfoEx
FormatMessageA
LocalFree
Sleep
AcquireSRWLockShared
ReleaseSRWLockShared
GetFileInformationByHandleEx
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFileAttributesExW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
CreateDirectoryW
GetCurrentDirectoryW
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
SetUnhandledExceptionFilter
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GlobalLock
GlobalFree
GlobalAlloc
QueryPerformanceCounter
FreeLibrary
VerSetConditionMask
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
MultiByteToWideChar
GetLocaleInfoA
InitOnceBeginInitialize
GetModuleHandleA
USER32.dll IsWindowUnicode
SetProcessDPIAware
GetClientRect
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
GetWindow
IsWindowVisible
EnumWindows
PostMessageA
DefWindowProcW
MonitorFromPoint
DispatchMessageA
DestroyWindow
SetWindowPos
GetSystemMetrics
SetWindowLongA
SetWindowDisplayAffinity
CreateWindowExA
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
UnregisterClassA
PostQuitMessage
FindWindowA
RegisterClassExA
UpdateWindow
ShowWindow
GetWindowThreadProcessId
SetCursor
SetCapture
GetForegroundWindow
GetKeyboardLayout
IsWindow
SendInput
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetClassNameA
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GDI32.dll CreateSolidBrush
GetDeviceCaps
COMDLG32.dll GetOpenFileNameW
SHELL32.dll ShellExecuteW
ole32.dll CoInitializeEx
CoCreateInstance
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
MSVCP140.dll ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAI@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
_Cnd_broadcast
_Cnd_wait
_Cnd_register_at_thread_exit
?__ExceptionPtrRethrow@@YAXPEBX@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
??7ios_base@std@@QEBA_NXZ
__crtLCMapStringA
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?_Xlength_error@std@@YAXPEBD@Z
_Strxfrm
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?id@?$ctype@D@std@@2V0locale@2@A
?id@?$collate@D@std@@2V0locale@2@A
_Strcoll
_Xtime_get_ticks
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?tolower@?$ctype@D@std@@QEBADD@Z
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
?id@?$numpunct@D@std@@2V0locale@2@A
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Query_perf_counter
_Thrd_join
_Mtx_unlock
?_Gettrue@_Locinfo@std@@QEBAPEBDXZ
?_Getfalse@_Locinfo@std@@QEBAPEBDXZ
?_Getlconv@_Locinfo@std@@QEBAPEBUlconv@@XZ
?_Winerror_map@std@@YAHH@Z
?_Syserror_map@std@@YAPEBDH@Z
_Thrd_detach
?uncaught_exceptions@std@@YAHXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
?good@ios_base@std@@QEBA_NXZ
??Bios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?_Random_device@std@@YAIXZ
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_Xbad_function_call@std@@YAXXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
MSVCP140_ATOMIC_WAIT.dll __std_atomic_notify_all_direct
__std_atomic_wait_direct
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpReadData
WinHttpOpenRequest
WinHttpOpen
WinHttpReceiveResponse
WinHttpCloseHandle
WinHttpSendRequest
WinHttpSetTimeouts
WinHttpConnect
WinHttpQueryDataAvailable
WinHttpSetOption
urlmon.dll URLDownloadToFileA
d3d11.dll D3D11CreateDeviceAndSwapChain
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
__RTDynamicCast
__intrinsic_setjmp
__current_exception_context
__current_exception
memcmp
memchr
memset
memmove
memcpy
longjmp
strrchr
__C_specific_handler
__RTtypeid
__std_type_info_compare
__std_exception_copy
__std_exception_destroy
strchr
_purecall
strstr
__std_terminate
api-ms-win-crt-stdio-l1-1-0.dll fsetpos
fgetc
_set_fmode
__p__commode
ungetc
_fwrite_nolock
_wfopen_s
_get_stream_buffer_pointers
__stdio_common_vsscanf
fread
_fseeki64
__stdio_common_vsprintf
_wfopen
fwrite
fgetpos
__stdio_common_vfprintf
fseek
fclose
fflush
__acrt_iob_func
ftell
setvbuf
fputc
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-heap-l1-1-0.dll realloc
free
_set_new_mode
_callnewh
calloc
malloc
api-ms-win-crt-convert-l1-1-0.dll atof
strtof
atoi
strtol
strtoull
strtoll
strtod
api-ms-win-crt-string-l1-1-0.dll strncpy_s
strlen
isxdigit
isdigit
_stricmp
wcscpy_s
strncpy
strcmp
strncmp
isblank
tolower
isspace
toupper
isalnum
wcslen
api-ms-win-crt-math-l1-1-0.dll roundf
powf
llround
atan2f
logf
nearbyint
atanf
ceilf
sqrtf
_fdsign
_ldsign
lroundf
round
cosf
sinf
expf
__setusermatherr
acosf
floorf
fmodf
_dsign
tanf
api-ms-win-crt-runtime-l1-1-0.dll __p___argv
_errno
__p___argc
_configure_narrow_argv
_register_thread_local_exe_atexit_callback
abort
exit
_initterm_e
_initterm
_get_initial_narrow_environment
_set_app_type
_exit
_initialize_narrow_environment
_seh_filter_exe
_cexit
_beginthreadex
terminate
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_c_exit
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
api-ms-win-crt-locale-l1-1-0.dll localeconv
___lc_codepage_func
___lc_collate_cp_func
_configthreadlocale
___lc_locale_name_func

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-16 00:28:20
Version 0.0
SizeofData 85
AddressOfRawData 0xc436d4
PointerToRawData 0xc426d4
Referenced File C:\Users\pc\Downloads\40drspq (1)\fragment\build\passive.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-16 00:28:20
Version 0.0
SizeofData 20
AddressOfRawData 0xc4372c
PointerToRawData 0xc4272c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-16 00:28:20
Version 0.0
SizeofData 992
AddressOfRawData 0xc43740
PointerToRawData 0xc42740

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-16 00:28:20
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140c43b40
EndAddressOfRawData 0x140c43cc4
AddressOfIndex 0x140c7db70
AddressOfCallbacks 0x14021a580
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x0000000140207950
0x00000001402079C0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140c70040

RICH Header

XOR Key 0x6768fb56
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
Imports (35721) 8
253 (35721) 1
ASM objects (35721) 6
C objects (35721) 10
C++ objects (35721) 47
C objects (35222) 1
Imports (35222) 25
Total imports 473
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
C++ objects (LTCG) (36256) 65
ASM objects (36256) 1
Resource objects (36256) 1
Linker (36256) 1

Errors

Leave a comment

No comments yet.