9ae85b85e755395303950b95cff8154a86b9e649f8c6cf441b3361461129a9be

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-10 20:04:36
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts magic_cheats.pdb
CompanyName magiccheats
FileDescription Magic Cheats
FileVersion 0.3.0
ProductName Magic Cheats
ProductVersion 0.3.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://github.com
  • https://www.World
  • https://www.recent
  • microsoft.com
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to RC5 or RC6
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegGetValueW
  • RegSetValueExW
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Uses Windows's Native API:
  • NtOpenFile
  • NtCreateNamedPipeFile
  • NtReadFile
  • NtWriteFile
Uses Microsoft's cryptographic API:
  • CryptProtectData
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious VirusTotal score: 1/70 (Scanned on 2026-08-12 10:57:36) Trapmine: malicious.moderate.ml.score

Hashes

MD5 76e2a587950351c50068fa4ae78c6267
SHA1 bc9f1cd949c962da350e3b767505c3fa382ae342
SHA256 9ae85b85e755395303950b95cff8154a86b9e649f8c6cf441b3361461129a9be
SHA3 7e1fb5aeac5f8ca238632b19ec3b54f21c521b612d81b7d5c402da51d873f4e8
SSDeep 98304:tysixqK+5qq2dtI/D/6Aupy9RXXDNLFvUoBeDEhcxOY1cWCTYkVP:kqedl3
Imports Hash a71aa198f7b8abea744af6f6fe197222

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-10 20:04:36
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x472400
SizeOfInitializedData 0x203600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000045DFF8 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x67a000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1eff4d379f37e470591645ec96e02a28
SHA1 e5426a865b8c485c9fe82e85d5a0a29af86e1742
SHA256 068c0ab11823efd73d889c8f5a0ba312c58fe006433ad61ae97aaa472adbaa28
SHA3 605bb720f6d000093caabea6c0b843ab789c62966fb4e6da13749be5e4540f82
VirtualSize 0x4722cf
VirtualAddress 0x1000
SizeOfRawData 0x472400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.20393

.rdata

MD5 ca6357deec2f9f5bcf4b04222ff431d6
SHA1 f2d6980fc68e56196f62438bbc31fc1efaf2378e
SHA256 017ab3163b065b33feb3f769b047f4734433b1e84466d361010ab0f3235e6b2a
SHA3 fae102b783c7fe85640038ec6a4a3515ff3220a536ea3ac74362680a6e930060
VirtualSize 0x1b4672
VirtualAddress 0x474000
SizeOfRawData 0x1b4800
PointerToRawData 0x472800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.10715

.data

MD5 cf9073e2515697f1f473face4fe48bab
SHA1 fb6448ea12a96e3811ae1f41553e34ef71858e3d
SHA256 24ef25ca62433e9b9ce1185ae816e2dce2ad2eb9a1642a0f8097070ca4bfd917
SHA3 665b1ba848934d5a051bb4316d3c410d0f36d8e501eeda2aae1416caa2d96446
VirtualSize 0x3408
VirtualAddress 0x629000
SizeOfRawData 0xa00
PointerToRawData 0x627000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.7273

.pdata

MD5 0a51f98de5f7cc80511380a7e5b81677
SHA1 bf315d0a745bcdae5b682d2083aa1a9fdca263ff
SHA256 eb594a2520bebf63436fb8b89cc859e9747f9df7c6d555c453cfd162635b1b12
SHA3 95c1971f65be995e6e449ca8f31f02c503a61d224eae67f208183aec72c4fe98
VirtualSize 0x3dd4c
VirtualAddress 0x62d000
SizeOfRawData 0x3de00
PointerToRawData 0x627a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.61559

.rsrc

MD5 11d8fb2ad7ae33e341fdac942b4279a8
SHA1 a6ad41aa1f4b88c294dd526e8f9138752edf296e
SHA256 3212cac63e1a259a873f0b319fec41b360b1cea6e068ba94c079660bf905681d
SHA3 464eff21aaa86446ee4ce3761c06019449c77e5ffb20ca00e0b73ad22956278f
VirtualSize 0xa6d8
VirtualAddress 0x66b000
SizeOfRawData 0xa800
PointerToRawData 0x665800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.91412

.reloc

MD5 579b58c75ac78becbe4c12241daf7db1
SHA1 df53c115dac9485857670480ad3e283fcc4444a2
SHA256 60994a4774f423e27538c1fc17d4a5b30bd63df3ff62d4ff5f8aaaf4079a3aef
SHA3 fb34a7d270d591c97476d47628dae8882526bb3229b7975baa2cb1c7275229c3
VirtualSize 0x3114
VirtualAddress 0x676000
SizeOfRawData 0x3200
PointerToRawData 0x670000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44216

Imports

bcryptprimitives.dll ProcessPrng
ntdll.dll NtOpenFile
NtCreateNamedPipeFile
NtReadFile
RtlNtStatusToDosError
NtWriteFile
RtlGetVersion
kernel32.dll WideCharToMultiByte
ReleaseMutex
WaitForSingleObject
LoadLibraryExA
MultiByteToWideChar
HeapAlloc
GetCurrentProcess
SleepEx
FormatMessageW
ExitProcess
CompareStringOrdinal
GetSystemDirectoryW
GetWindowsDirectoryW
GetModuleFileNameW
DuplicateHandle
WaitForMultipleObjects
GetExitCodeProcess
SetWaitableTimer
WaitForSingleObjectEx
SetThreadStackGuarantee
GetCurrentThread
GetProcessHeap
HeapFree
HeapReAlloc
RtlLookupFunctionEntry
SetLastError
SwitchToThread
GetModuleHandleA
Sleep
TerminateProcess
GetCurrentThreadId
GetProcAddress
GetModuleHandleW
LoadLibraryW
CloseHandle
GetLastError
GetUserDefaultUILanguage
LCIDToLocaleName
LocalFree
GetSystemTimePreciseAsFileTime
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
GlobalLock
GlobalSize
FreeLibrary
WakeAllConditionVariable
OutputDebugStringA
SleepConditionVariableSRW
GlobalUnlock
GetSystemTimeAsFileTime
FindNextFileW
GetTempPathW
IsDebuggerPresent
GetFileAttributesW
GetFileInformationByHandleEx
GetFileInformationByHandle
FindFirstFileExW
SetFileTime
GetFullPathNameW
WriteConsoleW
GetConsoleOutputCP
GetConsoleMode
GetStdHandle
FindClose
SetFileInformationByHandle
DeleteFileW
GetFinalPathNameByHandleW
CreateEventW
GetCurrentProcessId
OutputDebugStringW
IsProcessorFeaturePresent
LoadLibraryA
lstrlenW
LoadLibraryExW
GetSystemInfo
user32.dll GetActiveWindow
SetCapture
ScreenToClient
GetKeyState
GetAsyncKeyState
SetCursor
LoadCursorW
UpdateWindow
InvalidateRect
SetCursorPos
GetForegroundWindow
FlashWindowEx
IsWindowEnabled
EnableWindow
IsIconic
IsWindowVisible
ClipCursor
GetClipCursor
SendInput
ShowWindow
PostQuitMessage
ShowCursor
IsProcessDPIAware
GetDC
MonitorFromWindow
GetTouchInputInfo
SetForegroundWindow
ClientToScreen
GetCursorPos
AppendMenuW
InsertMenuW
CheckMenuItem
CreateAcceleratorTableW
DestroyAcceleratorTable
VkKeyScanW
SetMenuItemInfoW
EnableMenuItem
DrawMenuBar
CreatePopupMenu
CreateMenu
SetWindowLongW
GetSystemMenu
GetMonitorInfoW
GetSystemMetrics
SetMenu
GetMenu
GetWindowLongW
GetClipboardData
OpenClipboard
KillTimer
TrackMouseEvent
SystemParametersInfoW
IsWindow
TrackPopupMenu
CloseTouchInputHandle
RegisterTouchWindow
EnumChildWindows
InvalidateRgn
GetWindowPlacement
DispatchMessageA
GetMessageA
SetWindowPos
RegisterClassExW
FindWindowExW
TranslateAcceleratorW
PostMessageW
MsgWaitForMultipleObjectsEx
SetWindowPlacement
ChangeDisplaySettingsExW
RegisterWindowMessageA
SetWindowLongPtrW
SetPropW
MonitorFromRect
ChangeWindowMessageFilterEx
CreateWindowExW
RegisterClassW
GetMenuItemInfoW
SendMessageW
GetParent
DispatchMessageW
TranslateMessage
GetMessageW
DefWindowProcW
MapVirtualKeyW
GetUpdateRect
PeekMessageW
PostThreadMessageW
ValidateRect
SetParent
GetRawInputData
DestroyWindow
GetWindowLongPtrW
SetFocus
SetWindowTextW
RedrawWindow
AdjustWindowRect
EnumDisplayMonitors
MonitorFromPoint
GetWindowTextW
GetWindowTextLengthW
SetWindowDisplayAffinity
GetWindow
DestroyMenu
CloseClipboard
ReleaseCapture
SetWindowRgn
ToUnicodeEx
GetKeyboardLayout
MapVirtualKeyExW
GetKeyboardState
ReleaseDC
SetTimer
SystemParametersInfoA
DestroyIcon
CreateIcon
AdjustWindowRectEx
DrawTextW
FillRect
GetWindowDC
OffsetRect
GetWindowRect
MapWindowPoints
GetClientRect
GetMenuBarInfo
RemoveMenu
DrawIconEx
RegisterRawInputDevices
shell32.dll Shell_NotifyIconGetRect
Shell_NotifyIconW
SHAppBarMessage
SHGetKnownFolderPath
ShellExecuteW
DragQueryFileW
DragFinish
ole32.dll CoIncrementMTAUsage
RegisterDragDrop
CoTaskMemAlloc
CoCreateFreeThreadedMarshaler
RevokeDragDrop
CoUninitialize
OleInitialize
CoInitializeEx
CoCreateInstance
CoTaskMemFree
comctl32.dll TaskDialogIndirect
DefSubclassProc
SetWindowSubclass
RemoveWindowSubclass
oleaut32.dll SysStringLen
GetErrorInfo
SysFreeString
SetErrorInfo
api-ms-win-core-synch-l1-2-0.dll WakeByAddressSingle
WakeByAddressAll
WaitOnAddress
advapi32.dll EventRegister
EventSetInformation
EventWriteTransfer
EventUnregister
RegGetValueW
RegSetValueExW
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
dwmapi.dll DwmSetWindowAttribute
DwmEnableBlurBehindWindow
DwmGetWindowAttribute
shlwapi.dll SHCreateMemStream
gdi32.dll BitBlt
CreateSolidBrush
CombineRgn
GetDeviceCaps
DeleteObject
CreateCompatibleDC
SelectObject
SetBkMode
DeleteDC
CreateRectRgn
SetTextColor
CreateDIBSection
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory
KERNEL32.dll SetUnhandledExceptionFilter
UnhandledExceptionFilter
InitializeSListHead
CreateWaitableTimerExW
CreateProcessW
FreeEnvironmentStringsW
GetEnvironmentStringsW
ReadFile
GetOverlappedResult
AddVectoredExceptionHandler
SetEnvironmentVariableW
GetCommandLineW
RtlCaptureContext
RtlVirtualUnwind
GetCurrentDirectoryW
CreateMutexA
GetEnvironmentVariableW
ReadFileEx
WriteFileEx
QueryPerformanceFrequency
QueryPerformanceCounter
CreateThread
CreateFileW
CreateDirectoryW
CancelIo
crypt32.dll CryptProtectData
VCRUNTIME140.dll __current_exception_context
__current_exception
__C_specific_handler
_purecall
__std_exception_copy
memcmp
wcsrchr
_CxxThrowException
__std_exception_destroy
memset
memcpy
__CxxFrameHandler3
memmove
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
trunc
floor
roundf
round
pow
fmod
api-ms-win-crt-string-l1-1-0.dll wcslen
_wcsicmp
wcscmp
api-ms-win-crt-convert-l1-1-0.dll _ultow_s
wcstol
_wtoi
api-ms-win-crt-runtime-l1-1-0.dll _exit
_seh_filter_exe
__p___argc
__p___argv
_cexit
_initterm_e
_register_thread_local_exe_atexit_callback
_initterm
_get_initial_narrow_environment
exit
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
_initialize_narrow_environment
_configure_narrow_argv
_set_app_type
_c_exit
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_set_fmode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
free
malloc

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.42008
Detected Filetype PNG graphic file
MD5 aa2b8d9dbeb1c2c78fa61de7709c7921
SHA1 615eb927eddb112e7b64c2bcacef5863e87eccdf
SHA256 896e5de322efe59fcb6641b4c40f98e81298659ebc7b2af48f4412acfee0758f
SHA3 fb3463cc41795ad5696040670ce210cccfda2da01708ef4fcf5d80bfc0ebce7c

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4d7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.75986
Detected Filetype PNG graphic file
MD5 6536a798b6ba8d91263a0216f2c6e72b
SHA1 a854f413aa4754043bc54b12531040818eeffc92
SHA256 090be1d4b9b98eea731f82d56b9d5c7bdf104fb4db378d071f1351178f375f15
SHA3 06f535796ef366f809759b9e1d0ef8a0c9c4b162deebbea28205ac75fa4158cf

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x834
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.84618
Detected Filetype PNG graphic file
MD5 1c45b80192764a78888c589be2422fa6
SHA1 73e48435045c784ade01e78ef75d0213c05412ab
SHA256 1b556e8ffced3c7f2a5c4a347e329d73544cd5db51dedcef60c6925be785ff4a
SHA3 7070b36b76316d55934b92960d2828c87cf9e478e72e7888635058e0d65772b4

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xcbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89827
Detected Filetype PNG graphic file
MD5 d5da9c8052283f06b6145577bcb87dab
SHA1 259c71262cc55e77cb5072e4ba282881c75bdf2e
SHA256 8d139128b2c9269fe9bafdca74348caf606cfb4b657eb1535b8c9b76cc385329
SHA3 f30c6ba98457b320184bff2634184cc7946f07418cad48e0836ed065ef1b8e14

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95641
Detected Filetype PNG graphic file
MD5 b218b66b192a140c82d0174ba3e5845b
SHA1 c68a72405612d7fac0b00b8cde9b594a0fb8faaa
SHA256 1d1cc04b413989ef0ac979f0f1b3cd90acd1dfbc8b98393a8f34add5648ce2ce
SHA3 7abc8cbea42e3e4155d22266dfe6a83e3a1e94f830b54e3097acbc740974ae98

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x620f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97042
Detected Filetype PNG graphic file
MD5 9407e95b887842946e3391e7ce18d1d4
SHA1 f656ea200bedcc71a20fbdea36394fa3bead4a06
SHA256 1d09cb0d0096f762864ad87e82a3fefd33aa75b39a48337f93784ef21c52108f
SHA3 91a37ba0d3acd20d414d4ed1d96a50c4d046710bd37224a238ee2467350ffc4b

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74607
Detected Filetype Icon file
MD5 c4690b3271653ab6b5417d84e7cd1565
SHA1 5b645c26e5550d86c05c5f9eab845397ebedf376
SHA256 83ee1fc75828d31e4f5ae1d62caaa1b49d5eea178d7588312bdab4bee961140c
SHA3 77eb201897b7c9279a4f490978082d4ab321c5c6880e67a55454974b020da369

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18267
MD5 2ed952709696ccade0dffee353cfb050
SHA1 e9a65d04e2faa36a269508302da5da0c491fa5c5
SHA256 f6841c15f517f12424cd65f258cf8df19c3983793019092e15baa312f3b9c1c3
SHA3 3185e7ef0778e08faffeec314726230beb19d9176a52ed6bc7e8ef3e0151cdf3

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.3.0.0
ProductVersion 0.3.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName magiccheats
FileDescription Magic Cheats
FileVersion (#2) 0.3.0
ProductName Magic Cheats
ProductVersion (#2) 0.3.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-10 20:04:36
Version 0.0
SizeofData 41
AddressOfRawData 0x526854
PointerToRawData 0x525054
Referenced File magic_cheats.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-10 20:04:36
Version 0.0
SizeofData 20
AddressOfRawData 0x526880
PointerToRawData 0x525080

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-10 20:04:36
Version 0.0
SizeofData 1008
AddressOfRawData 0x526894
PointerToRawData 0x525094

TLS Callbacks

StartAddressOfRawData 0x140526ca8
EndAddressOfRawData 0x140526e54
AddressOfIndex 0x14062bdf4
AddressOfCallbacks 0x140474bf8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014039A1E0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1406298c0

RICH Header

XOR Key 0xe50bbc51
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
Imports (34321) 4
ASM objects (34321) 4
C objects (34321) 10
C++ objects (34321) 30
Imports (30795) 3
Total imports 346
Unmarked objects (#2) 52
Resource objects (34435) 1
Linker (34435) 1

Errors

Leave a comment

No comments yet.