ab20c3f7e4fc3e639a2892ce79b58b2241ec107f3f3bdb047e33575aca46446b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-28 15:30:52
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • %temp%
  • CurrentControlSet\Services
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • exploit
Contains domain names:
  • 2010-aia.verisign.com
  • 2010-crl.verisign.com
  • aia.verisign.com
  • aia.ws.symantec.com
  • auctionr.org
  • crl.microsoft.com
  • crl.thawte.com
  • crl.verisign.com
  • crl.ws.symantec.com
  • csc3-2010-aia.verisign.com
  • csc3-2010-crl.verisign.com
  • github.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://crl.verisign.com
  • http://crl.verisign.com/pca3-g5.crl04
  • http://csc3-2010-aia.verisign.com
  • http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
  • http://csc3-2010-crl.verisign.com
  • http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
  • http://logo.verisign.com
  • http://logo.verisign.com/vslogo.gif04
  • http://ocsp.thawte.com0
  • http://ocsp.verisign.com0
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • https://auctionr.org
  • https://discord.gg
  • https://github.com
  • https://www.verisign.com
  • https://www.verisign.com/cps0
  • https://www.verisign.com/rpa
  • https://www.verisign.com/rpa0
  • logo.verisign.com
  • microsoft.com
  • symantec.com
  • thawte.com
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • verisign.com
  • ws.symantec.com
  • www.verisign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
  • FindWindowA
  • NtQuerySystemInformation
Can access the registry:
  • RegisterHotKey
  • RegCreateKeyW
  • RegSetKeyValueW
  • RegCloseKey
  • RegOpenKeyW
Possibly launches other programs:
  • ShellExecuteW
  • system
Uses Windows's Native API:
  • NtQuerySystemInformation
  • NtUnloadDriver
  • NtLoadDriver
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Manipulates other processes:
  • Process32First
  • OpenProcess
  • Process32Next
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The PE is possibly a dropper. Resources amount for 76.2932% of the executable.
Malicious VirusTotal score: 20/71 (Scanned on 2026-09-28 17:58:20) APEX: Malicious
AVG: FileRepMalware [Misc]
Avast: FileRepMalware [Misc]
Bkav: W32.Malware.3DF3742D
ClamAV: Win.Tool.Zusy-10033075-0
CrowdStrike: win/malicious_confidence_100% (D)
DeepInstinct: MALICIOUS
DrWeb: Tool.VulnDriver.22
ESET-NOD32: Win64/HackTool.GameHack.Q trojan
Elastic: malicious (high confidence)
Fortinet: W64/GameHack.Q!tr
Google: Detected
Ikarus: Trojan.Win64.Krypt
Kingsoft: malware.kb.a.804
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: ti!AB20C3F7E4FC
Microsoft: Trojan:Win32/Wacatac.C!ml
SentinelOne: Static AI - Malicious PE
Symantec: ML.Attribute.HighConfidence
huorong: Exploit/Vulndriver.c!crit

Hashes

MD5 19fb19d4b1fe857643513e3afd8ed043 🔍
SHA1 4807e6800371ff9bb009a23664ba11902a5178b1 🔍
SHA256 ab20c3f7e4fc3e639a2892ce79b58b2241ec107f3f3bdb047e33575aca46446b 🔍
SHA3 15396683aea95a700f5ea7a0347cb96c3e802b7d4c4d1c896f0e5f1df1df3b7b 🔍
SSDeep 98304:20+AuSNxNQIUUj0gWStTEdS1KgQqHqYVWiIwRBLG1:7RuLbgVwSogBqsIS0 🔍
Imports Hash 4392df4e161a0b9bf240c47fc10650d8 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Sep-28 15:30:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x99400
SizeOfInitializedData 0x2df800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000097374 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x37c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1beab6d996be69d52ab0be1b9fc05e79 🔍
SHA1 7b0c85950f3891f0ebd28c71deb97adb73518b39 🔍
SHA256 ab733549a628c088e7a5328af23cf0bba2a0d98f544d8810e3d54164c59a6745 🔍
SHA3 6296373a01e975cc38779008c1468c626157fe1a49cfee42644051e0c53e4f2e 🔍
VirtualSize 0x993c3
VirtualAddress 0x1000
SizeOfRawData 0x99400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.5337

.rdata

MD5 efdd19b240fdfd6914f2bbda7437ce1a 🔍
SHA1 3a167d284de7dd3af443c68f326a19cecd5aa0fe 🔍
SHA256 11a9125438b0223e0cb62d1b0d3736975ad440a866a422ce61eaf7983cfc1656 🔍
SHA3 e1c6bab6742fd19e781de77ae1ddd52b169fea5bc9108b90503667b6d8cea470 🔍
VirtualSize 0x2e522
VirtualAddress 0x9b000
SizeOfRawData 0x2e600
PointerToRawData 0x99800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.1555

.data

MD5 37688a12db1ddfef52044228164880ee 🔍
SHA1 1fb6a20c15c4ff6cd67786d388852bf6b2167ba5 🔍
SHA256 848f367b75f45e076632226dccb516b0b4e0d4d361682f29dc407d0a16b11dee 🔍
SHA3 3abd6f02195bb46988cab3295b1280248fa3e468cf2119721841c83963f2020b 🔍
VirtualSize 0xc9c8
VirtualAddress 0xca000
SizeOfRawData 0x1c00
PointerToRawData 0xc7e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.40584

.pdata

MD5 91005b275c31683547db59b665093d3e 🔍
SHA1 156d67f44405dbc9722dfa9bd65dffb13f154d7c 🔍
SHA256 ef3fc6aba06432c1318a6606bea780dc1f0f4cec9966df8444f08a2164af536e 🔍
SHA3 aed37fe36d239c5739dd504683811cc647d137905308a1fdccfdb1069caf4fe0 🔍
VirtualSize 0x5f88
VirtualAddress 0xd7000
SizeOfRawData 0x6000
PointerToRawData 0xc9a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.0113

.rsrc

MD5 700158116b6883b1447e463ba1f6423c 🔍
SHA1 464ba5d84cdb071e91d92af4be7800e8e6a3b4c2 🔍
SHA256 a42f340bc488a93212a04da736cdd79d6adfa73a1c83de032d30018b5fec33a4 🔍
SHA3 2020302282c54731f6ec32d6150cd2789a50d6d19351d39ffd2e4b9802f3e8bd 🔍
VirtualSize 0x29dfd8
VirtualAddress 0xdd000
SizeOfRawData 0x29e000
PointerToRawData 0xcfa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99869

.reloc

MD5 7159f506a6234f29a12cfaa2f0491e5a 🔍
SHA1 dc5c3a0f188f13cb368a1c424b346bb49efe9f83 🔍
SHA256 572f40502170ab5b637d8ee7947ac4d3a742db824619ad523cfba6cc3d12b210 🔍
SHA3 235234744b2f2b0e11da1db14d74084b77878117c3cd2f201d918be67fa1905f 🔍
VirtualSize 0x6a8
VirtualAddress 0x37b000
SizeOfRawData 0x800
PointerToRawData 0x36da00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.98623

Imports

dwmapi.dll DwmExtendFrameIntoClientArea
KERNEL32.dll QueryPerformanceCounter
GetModuleFileNameA
SizeofResource
Process32First
FindFirstFileA
SetConsoleTitleA
GetCurrentProcess
DeviceIoControl
TerminateProcess
Module32Next
FindNextFileA
SetThreadPriority
FindClose
Module32First
CreateFileW
OpenProcess
CreateToolhelp32Snapshot
GetExitCodeThread
Sleep
GetTickCount64
GetLastError
GetCurrentThread
LockResource
DeleteFileA
Process32Next
CloseHandle
CreateThread
LoadResource
FindResourceW
FreeLibrary
GetModuleHandleW
CreateDirectoryA
GetTickCount
IsDebuggerPresent
VirtualQueryEx
CheckRemoteDebuggerPresent
VirtualFree
VirtualAlloc
GetCurrentThreadId
GetCurrentProcessId
GetTempPathW
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
GetSystemTimeAsFileTime
InitializeSListHead
GetProcAddress
IsDBCSLeadByte
QueryPerformanceFrequency
WideCharToMultiByte
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
ReleaseSRWLockExclusive
GlobalUnlock
OutputDebugStringA
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
LoadLibraryA
GetLocaleInfoA
GetModuleHandleA
GetLocalTime
USER32.dll OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
GetCursorPos
GetWindowThreadProcessId
UnregisterHotKey
DispatchMessageA
DestroyWindow
SetActiveWindow
PostMessageA
GetSystemMetrics
ShowWindow
IsWindow
GetAsyncKeyState
SetWindowDisplayAffinity
MessageBoxA
RegisterHotKey
DefWindowProcA
CreateWindowExA
SetLayeredWindowAttributes
SetFocus
TranslateMessage
mouse_event
PeekMessageA
GetWindowLongPtrA
UnregisterClassA
PostQuitMessage
SetWindowLongPtrA
FindWindowA
PtInRect
RegisterClassExA
UpdateWindow
SetForegroundWindow
DefWindowProcW
GetKeyState
GetMessageExtraInfo
LoadCursorA
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetClipboardData
SetCursorPos
ADVAPI32.dll RegCreateKeyW
LookupPrivilegeValueA
RegSetKeyValueW
RegCloseKey
RegDeleteTreeW
OpenProcessToken
RegOpenKeyW
AdjustTokenPrivileges
SHELL32.dll ShellExecuteW
ole32.dll CoInitializeEx
CoCreateInstance
CoUninitialize
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
D3DCOMPILER_47.dll D3DCompile
MSVCP140.dll ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z
?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?id@?$ctype@_W@std@@2V0locale@2@A
?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A
?always_noconv@codecvt_base@std@@QEBA_NXZ
??Bios_base@std@@QEBA_NXZ
?good@ios_base@std@@QEBA_NXZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@PEBX@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??7ios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@K@Z
?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z
?widen@?$ctype@_W@std@@QEBA_WD@Z
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@J@Z
_Query_perf_frequency
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?uncaught_exceptions@std@@YAHXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xbad_function_call@std@@YAXXZ
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Xlength_error@std@@YAXPEBD@Z
_Mtx_lock
_Query_perf_counter
_Mtx_unlock
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
d3d11.dll D3D11CreateDeviceAndSwapChain
ntdll.dll NtQuerySystemInformation
RtlVirtualUnwind
NtUnloadDriver
RtlCaptureContext
NtLoadDriver
RtlInitUnicodeString
RtlLookupFunctionEntry
RtlAdjustPrivilege
WINMM.dll timeEndPeriod
timeBeginPeriod
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll strchr
memcpy
memmove
memchr
memcmp
_CxxThrowException
memset
__C_specific_handler
__current_exception_context
__current_exception
wcsstr
__std_exception_copy
strstr
__std_terminate
__std_exception_destroy
api-ms-win-crt-stdio-l1-1-0.dll fseek
_get_stream_buffer_pointers
_fseeki64
fsetpos
__stdio_common_vsscanf
ungetc
__stdio_common_vfprintf
fread
setvbuf
fgetpos
fflush
fopen_s
fputc
_set_fmode
__stdio_common_vsprintf_s
fgetc
fclose
ftell
__stdio_common_vsprintf
_wfopen
__p__commode
fwrite
__acrt_iob_func
api-ms-win-crt-utility-l1-1-0.dll srand
rand
qsort
api-ms-win-crt-string-l1-1-0.dll strncmp
strncpy
strcmp
_stricmp
strncpy_s
api-ms-win-crt-heap-l1-1-0.dll _callnewh
free
malloc
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll atof
strtol
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
_register_thread_local_exe_atexit_callback
_c_exit
__p___argv
system
__p___argc
_exit
exit
_initterm_e
_initterm
_get_initial_narrow_environment
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
terminate
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
_wremove
api-ms-win-crt-time-l1-1-0.dll _time64
api-ms-win-crt-math-l1-1-0.dll cosf
pow
_fdclass
powf
sqrtf
ceilf
__setusermatherr
atan2f
acosf
logf
log
fmodf
expf
sinf
tanf
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x29ddaa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9987
Detected Filetype PNG graphic file
MD5 bb75f0798bd6fef3b43d757bad001890 🔍
SHA1 94e6bd62247c06e691b934b232e3a8f700a9dff7 🔍
SHA256 f05bb37ce8d59ee3e099554587808a7dd140e658bb62df20e20a556c679f3fcf 🔍
SHA3 fe66eb017c08c165ef63eb2e86bde865dbabcd2290def446d4a70a818160f929 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-28 15:30:52
Version 0.0
SizeofData 912
AddressOfRawData 0xbb9a4
PointerToRawData 0xba1a4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Sep-28 15:30:52
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400bbd58
EndAddressOfRawData 0x1400bbd60
AddressOfIndex 0x1400cc1b8
AddressOfCallbacks 0x14009bb58
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400ca040

RICH Header

XOR Key 0xeb5ae652
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
Imports (35207) 6
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 34
C objects (33145) 1
Imports (33145) 25
Total imports 365
C++ objects (LTCG) (35229) 14
Resource objects (35229) 1
151 1
Linker (35229) 1

Errors

Leave a comment

No comments yet.