b411b444682179bf2f4270fbc22d9a86263b659152f9611712ec40101a8f3aee

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-17 18:58:14
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
CompanyName Real
FileDescription Real Setup
FileVersion 1.0.0.0
InternalName RealSetup
OriginalFilename RealSetup.exe
ProductName Real
ProductVersion 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentControlSet\Services
  • CurrentVersion\Run
Accesses the WMI:
  • ROOT\Security
  • root\Microsoft
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • Izenpe.com
  • animationData.fr
  • cv.iptc.org
  • dotnet.microsoft.com
  • example.com
  • github.com
  • githubusercontent.com
  • go.microsoft.com
  • http://cv.iptc.org
  • http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia
  • http://www.w3.org
  • http://www.w3.org/1999/xlink
  • http://www.w3.org/2000/svg
  • http://www.w3.org/XML/1998/namespace
  • https://1.1.1.1
  • https://1.1.1.1/dns-query
  • https://8.8.8.8
  • https://8.8.8.8/dns-query
  • https://9.9.9.9
  • https://9.9.9.9/dns-query
  • https://aka.ms
  • https://api.projectreal.live
  • https://api.projectreal.live/
  • https://api.projectreal.live/installer/report
  • https://api.projectreal.live/update/check
  • https://ca.trufo.ai
  • https://ca.trufo.ai/c2pa-ca.crt03
  • https://ca.trufo.ai/root-ca.crt0
  • https://curl.se
  • https://discord.gg
  • https://dl.projectreal.live
  • https://dl.projectreal.live/
  • https://dl.projectreal.live/verify
  • https://download.projectreal.live
  • https://download.projectreal.live/
  • https://download.projectreal.live/verify
  • https://github.com
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • https://go.microsoft.com/fwlink/p/?LinkId
  • https://ocsp.trufo.ai0
  • https://ocsp.trufo.ai0+
  • https://projectreal.gg
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/mozilla-firefox/firefox/refs/heads/release/security/nss/lib/ckfw/builtins/certdata.txt
  • https://trufo.ai
  • i.style.top
  • lottielab.com
  • microsoft.com
  • pool.ntp.org
  • raw.githubusercontent.com
  • style.top
  • this.animationData.fr
  • time.windows.com
  • windows.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to Blowfish
Uses known Diffie-Helman primes
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
  • RegGetValueW
  • RegEnumKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptDestroyHash
  • CryptDestroyKey
  • CryptSetHashParam
  • CryptGenRandom
  • CryptEnumProvidersW
  • CryptSignHashW
  • CryptDecrypt
  • CryptGetProvParam
  • CryptGetUserKey
  • CryptExportKey
  • CryptQueryObject
  • CryptMsgGetParam
  • CryptMsgClose
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Has Internet access capabilities:
  • WinHttpOpen
  • WinHttpSetOption
  • WinHttpCrackUrl
  • WinHttpSetStatusCallback
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpSetTimeouts
  • WinHttpCloseHandle
  • WinHttpQueryOption
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpConnect
  • InternetTimeToSystemTimeW
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceConfigW
  • QueryServiceStatusEx
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
  • OpenProcess
Changes object ACLs:
  • SetNamedSecurityInfoW
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Interacts with the certificate store:
  • CertOpenSystemStoreA
  • CertOpenSystemStoreW
  • CertOpenStore
Malicious The PE is possibly a dropper. Resource 101 detected as a PE Executable.
Malicious VirusTotal score: 44/68 (Scanned on 2026-09-11 15:46:42) ALYac: Generic.Dacic.21387.D686FB73
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Dropper/Win.MalwareX-gen.R786952
Antiy-AVL: RiskWare/Win64.GameTool
Arcabit: Generic.Dacic.21387.D686FB73
Avast: Win64:MalwareX-gen [Misc]
BitDefender: Generic.Dacic.21387.D686FB73
Bkav: W32.Malware.F2959B98
CAT-QuickHeal: Trojan.Agent
CTX: exe.trojan.posprefer
CrowdStrike: win/malicious_confidence_60% (D)
DeepInstinct: MALICIOUS
DrWeb: Trojan.Siggen33.39443
ESET-NOD32: Win64/GameTool_AGen.C potentially unsafe application
Elastic: malicious (high confidence)
Emsisoft: Generic.Dacic.21387.D686FB73 (B)
Fortinet: Adware/GameTool_AGen
GData: Generic.Dacic.21387.D686FB73
Google: Detected
Gridinsoft: Trojan.Win64.Kryptik.dd!n
K7AntiVirus: Unwanted-Program ( 006e231d1 )
K7GW: Unwanted-Program ( 006e231d1 )
Kaspersky: Trojan.Win32.Posprefer.e
Kingsoft: Win32.Trojan.Posprefer.e
Lionic: Trojan.Win32.Posprefer.tt8l
Malwarebytes: Trojan.Dropper
MaxSecure: Trojan.Malware.272153833.susgen
McAfeeD: Trojan:Win/Wacatac.ENR
MicroWorld-eScan: Generic.Dacic.21387.D686FB73
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Rising: Malware.Undefined!8.C (CLOUD)
Skyhigh: Artemis
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.11e65eba
TrellixENS: Artemis!D81C13E9063A
TrendMicro: Trojan.Win32.GAMETOOLAGEN.USBLHI26
TrendMicro-HouseCall: Trojan.Win32.GAMETOOLAGEN.USBLHI26
VBA32: Trojan.Posprefer
VIPRE: Generic.Dacic.21387.D686FB73
Varist: W64/ABTrojan.DARS-3588
Webroot: Win.Trojan.Gen
Yandex: Trojan.Posprefer!BQUrIzn9bRo

Hashes

MD5 d81c13e9063abe4687060d633ff1f701 🔍
SHA1 bb5bc882d52a5c342ab214df7de170e7d2f4769a 🔍
SHA256 b411b444682179bf2f4270fbc22d9a86263b659152f9611712ec40101a8f3aee 🔍
SHA3 e344e6609aed4abbc03d64a5d2d81fac89de89c9e3a2010183cb015655d02284 🔍
SSDeep 393216:8OtYCUkjbi+D014Buf8uKzYYlAbf4EOUYNOUY:NWqgQEY 🔍
Imports Hash 7a26bbfc78957f705f8159430e068dce 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Aug-17 18:58:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x490600
SizeOfInitializedData 0xbf4600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000454460 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1089000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ebf9fb7f8e05fe422089b2da1c19698b 🔍
SHA1 123556736f45f770e2ef1355fad987512825a860 🔍
SHA256 424ee783504bb6343ecbea50e4e2ad62c66c7102d0ac1d45b9f274de507be6b0 🔍
SHA3 36e0f6f9192ba64aca969c6b53d46566961dd0985945559d18019843f5b25448 🔍
VirtualSize 0x49047c
VirtualAddress 0x1000
SizeOfRawData 0x490600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.68047

.rdata

MD5 22f140a7a93524fe9cac45bc8269e113 🔍
SHA1 bbed2c287028ee872b9d62690c9d0f6a861e162d 🔍
SHA256 34c526869151ade90463748278fa7f0aaf56fbe3f83e47e51d07104622a83344 🔍
SHA3 628147eaa96d9191636a0c9e046e8cd9f0a8c2d4f6b75fd46adce405f71855b2 🔍
VirtualSize 0x1b0ed6
VirtualAddress 0x492000
SizeOfRawData 0x1b1000
PointerToRawData 0x490a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.90343

.data

MD5 df49c734dc954276c27f324f4cdd1469 🔍
SHA1 ac4cb3fc645f981a4dca2f53161b111a4b2065be 🔍
SHA256 4a4f23c9c8ab394712557e9d30bd3c2e1c5c8a6ed681eebf6d3666436ef3b67f 🔍
SHA3 72f4ecc3335eaa5b8040ba517f68ea3b8ac932e4f0188ee42cbaf9d6bbcf568b 🔍
VirtualSize 0xf1f4
VirtualAddress 0x643000
SizeOfRawData 0xae00
PointerToRawData 0x641a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.12617

.pdata

MD5 0af6e60ee74791e22bceb88ee4f2205e 🔍
SHA1 70f7b86566db24e45db9a06d961e083675c387c5 🔍
SHA256 2b15435a74964d599c166bd5466da580f9d73d671d2dddc6050aafea70e7e0d0 🔍
SHA3 49afb636619bf7a723b92e32a8b2098568d6bc71f6af8685e9f6e0067a2f4ab9 🔍
VirtualSize 0x34a58
VirtualAddress 0x653000
SizeOfRawData 0x34c00
PointerToRawData 0x64c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.38237

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x688000
SizeOfRawData 0x200
PointerToRawData 0x681400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 39440dfaa11680955daf38c0f03e43a3 🔍
SHA1 a6b3d02c1e1a8671694ff5b898ca7f0dc0cc4a00 🔍
SHA256 acae468210a4aaa3870b8de67e6642b0bfdc30e521ce0362af6f1e94726dd119 🔍
SHA3 ecf9d779c72cbe097a15ca323d68f3bfaceb41e3eb2d09b9893280808dbf1256 🔍
VirtualSize 0x9f0d80
VirtualAddress 0x689000
SizeOfRawData 0x9f0e00
PointerToRawData 0x681600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.2982

.reloc

MD5 2b8e3c22af31b688e2d29a413e6822f4 🔍
SHA1 88e99b1e9398562e4962a915e4910375c78bdb99 🔍
SHA256 146d851f074a12c6d8414bdfe99cf9e6b6720f0c004bc37d7e1dcd2c976f6061 🔍
SHA3 28f23bddbd1928507135d7995d560ba69c080389627835d5b027d5905d19d92b 🔍
VirtualSize 0xe6fc
VirtualAddress 0x107a000
SizeOfRawData 0xe800
PointerToRawData 0x1072400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44408

Imports

ADVAPI32.dll OpenProcessToken
GetTokenInformation
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegDeleteTreeW
RegGetValueW
SetEntriesInAclW
SetNamedSecurityInfoW
RegEnumKeyExW
RegEnumValueW
CloseServiceHandle
OpenSCManagerW
OpenServiceW
QueryServiceConfigW
QueryServiceStatusEx
CryptAcquireContextW
CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptHashData
CryptDestroyHash
ConvertSidToStringSidW
EventRegister
EventSetInformation
EventWriteTransfer
EventUnregister
CryptDestroyKey
CryptSetHashParam
CryptGenRandom
ReportEventW
CryptEnumProvidersW
CryptSignHashW
CryptDecrypt
RegisterEventSourceW
DeregisterEventSource
CryptGetProvParam
CryptGetUserKey
CryptExportKey
bcrypt.dll BCryptGetProperty
BCryptDestroyHash
BCryptFinishHash
BCryptHashData
BCryptCreateHash
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
CRYPT32.dll CertGetNameStringW
CryptQueryObject
CertGetCertificateChain
CertFreeCertificateChain
CertVerifyCertificateChainPolicy
CertFreeCertificateContext
CertGetEnhancedKeyUsage
CertGetIntendedKeyUsage
CertOpenSystemStoreA
CryptMsgGetParam
CryptMsgClose
CertFindCertificateInStore
CertEnumCertificatesInStore
CertOpenSystemStoreW
CertOpenStore
CertDuplicateCertificateContext
CertCloseStore
CertGetCertificateContextProperty
IPHLPAPI.DLL GetAdaptersAddresses
if_nametoindex
ncrypt.dll NCryptCreatePersistedKey
NCryptFinalizeKey
NCryptFreeObject
NCryptDeleteKey
NCryptOpenStorageProvider
WINTRUST.dll WinVerifyTrust
COMCTL32.dll InitCommonControlsEx
SHELL32.dll SHGetFolderPathW
SHBrowseForFolderW
ShellExecuteW
ShellExecuteExW
SHGetPathFromIDListW
ole32.dll CoCreateInstance
CoInitializeEx
CoUninitialize
CoTaskMemAlloc
CoTaskMemFree
CoInitialize
CreateStreamOnHGlobal
StringFromGUID2
CoCreateGuid
CoSetProxyBlanket
PropVariantClear
OLEAUT32.dll SafeArrayGetElement
VariantClear
SysAllocString
SysFreeString
SafeArrayGetUBound
VariantInit
SafeArrayGetLBound
gdiplus.dll GdipSetPenEndCap
GdipSetPenStartCap
GdipDeletePen
GdipCreatePen1
GdipCreateLineBrushI
GdipCreateSolidFill
GdipDeleteBrush
GdipCloneBrush
GdipDeleteRegion
GdipCreateRegionPath
GdipScaleMatrix
GdipTranslateMatrix
GdipDeleteMatrix
GdipCreateMatrix
GdipTransformPath
GdipAddPathRectangle
GdipAddPathBezier
GdipCloneImage
GdipAddPathLine
GdipClosePathFigure
GdipStartPathFigure
GdipDeletePath
GdipCreatePath
GdiplusShutdown
GdiplusStartup
GdipFree
GdipAlloc
GdipSetSmoothingMode
GdipSetPixelOffsetMode
GdipSetTextRenderingHint
GdipSetInterpolationMode
GdipDrawLine
GdipDrawEllipse
GdipDrawPath
GdipFillEllipse
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromStream
GdipCreateImageAttributes
GdipDisposeImageAttributes
GdipSetImageAttributesColorMatrix
GdipCreateFromHDC
GdipSetPenLineJoin
GdipAddPathArc
GdipDeleteGraphics
GdipFillPath
GdipDrawImageRectRect
GdipSetClipRegion
GdipResetClip
GdipFillRectangleI
dwmapi.dll DwmSetWindowAttribute
WS2_32.dll GetNameInfoW
getsockopt
send
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAEventSelect
WSAResetEvent
WSAWaitForMultipleEvents
WSAGetLastError
ntohs
WSACleanup
WSAStartup
ioctlsocket
htonl
freeaddrinfo
getaddrinfo
select
__WSAFDIsSet
accept
WSAIoctl
WSASetLastError
socket
setsockopt
recv
htons
getsockname
shutdown
bind
closesocket
connect
getpeername
listen
WSASocketA
recvfrom
sendto
inet_addr
inet_ntoa
gethostbyaddr
gethostbyname
getservbyport
getservbyname
Secur32.dll InitSecurityInterfaceW
KERNEL32.dll IsDebuggerPresent
SetConsoleCtrlHandler
SetStdHandle
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
PeekNamedPipe
GetDriveTypeW
FreeLibraryAndExitThread
ExitThread
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
RtlUnwindEx
RtlLookupFunctionEntry
RaiseException
RtlPcToFileHeader
InitializeSListHead
GetStartupInfoW
SetUnhandledExceptionFilter
GetCPInfo
LCMapStringEx
DecodePointer
EncodePointer
SleepConditionVariableSRW
WakeAllConditionVariable
GetStringTypeW
ExitProcess
GetFileInformationByHandleEx
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFinalPathNameByHandleW
GetFileInformationByHandle
FindFirstFileExW
GetCurrentDirectoryW
GetLocaleInfoEx
UnhandledExceptionFilter
HeapAlloc
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
HeapReAlloc
SetEndOfFile
GetConsoleOutputCP
IsProcessorFeaturePresent
RtlCaptureContext
IsValidCodePage
GetOEMCP
GetTimeZoneInformation
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
WriteConsoleW
HeapSize
SetFilePointerEx
RtlVirtualUnwind
ConvertThreadToFiberEx
ConvertFiberToThread
GetACP
CreateSemaphoreA
GetExitCodeThread
ReleaseSemaphore
InitializeCriticalSection
LoadLibraryA
GetSystemDirectoryA
GetModuleHandleExW
FindNextFileW
FindFirstFileW
FindClose
GetSystemTime
CreateFiberEx
DeleteFiber
SwitchToFiber
VirtualFree
VirtualProtect
GetCommandLineW
CreateFileW
GetFileSizeEx
ReadFile
WriteFile
GetTempPathW
CloseHandle
GetLastError
ReleaseMutex
WaitForSingleObject
CreateMutexW
Sleep
GetCurrentProcess
GetCurrentProcessId
TerminateProcess
GetExitCodeProcess
CreateProcessW
GetTickCount64
FreeLibrary
GetModuleFileNameW
GetProcAddress
LoadLibraryExW
LoadResource
LockResource
SizeofResource
FindResourceW
LocalFree
MoveFileExW
MultiByteToWideChar
SetEvent
CreateEventW
GetTickCount
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
MulDiv
GetSystemDirectoryW
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
CreateDirectoryW
DeleteFileW
GetFileAttributesExW
GetCurrentThreadId
GetLocalTime
GetModuleHandleW
MoveFileW
WideCharToMultiByte
GetDiskFreeSpaceExW
OpenProcess
QueryFullProcessImageNameW
GetEnvironmentVariableW
SystemTimeToFileTime
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
SetLastError
FormatMessageA
SleepEx
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
QueryPerformanceCounter
QueryPerformanceFrequency
InitializeConditionVariable
GetFullPathNameW
GetEnvironmentVariableA
CompareFileTime
GetSystemTimeAsFileTime
VerSetConditionMask
VerifyVersionInfoW
WakeConditionVariable
SleepConditionVariableCS
WaitForSingleObjectEx
CreateThread
GetFileAttributesW
OutputDebugStringA
OutputDebugStringW
GetProcessHeap
HeapFree
LoadLibraryW
GetFileType
GetStdHandle
GetConsoleMode
SetConsoleMode
ReadConsoleA
ReadConsoleW
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
RtlUnwind
USER32.dll LoadCursorW
GetUserObjectInformationW
PostMessageW
ShowWindow
IsWindowVisible
IsIconic
SetForegroundWindow
MessageBoxW
EnumWindows
GetClassNameW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
SendMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
BringWindowToTop
SetCapture
ReleaseCapture
SetTimer
KillTimer
GetSystemMetrics
DrawTextW
UpdateWindow
GetDC
ReleaseDC
BeginPaint
EndPaint
InvalidateRect
SetWindowTextW
GetClientRect
ScreenToClient
PtInRect
GetProcessWindowStation
LoadIconW
GetWindowLongPtrW
SetWindowLongPtrW
EnumChildWindows
GDI32.dll SetBkMode
SetTextColor
SelectObject
GetDeviceCaps
DeleteObject
DeleteDC
CreateSolidBrush
CreateFontW
CreateCompatibleDC
CreateCompatibleBitmap
EnumFontFamiliesExW
BitBlt
WINHTTP.dll WinHttpOpen
WinHttpSetOption
WinHttpCrackUrl
WinHttpSetStatusCallback
WinHttpQueryHeaders
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpCloseHandle
WinHttpQueryOption
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpConnect
WININET.dll InternetTimeToSystemTimeW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x81d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70358
Detected Filetype PNG graphic file
MD5 3d7ea167e30bcbdc2fa31d9dfaa13049 🔍
SHA1 ed834b4527f9233e7643af543021cd4af803a07f 🔍
SHA256 9b830c372e8b1bbc2b2e15041c8cc200a7d9badb669bd2b7996b20af13bd7195 🔍
SHA3 dcbdb8ea73e43ebc5b8d8eda5dfa021065fddba244c11cec70c4e3117084fe4e 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.54112
Detected Filetype PNG graphic file
MD5 9c420a570d51e2076a3ad3726488d94a 🔍
SHA1 f0c74cd41eb1afbac2a9f7c2ef7fb31b998fe7f6 🔍
SHA256 62debe35bb58d4d4acd6c913b835d238587f437177ad4386028687ea92397a1b 🔍
SHA3 33446f5829e3cab6437dbd9f3f308978801f440eeeba11981755431ca1a4590a 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x52f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.64947
Detected Filetype PNG graphic file
MD5 dce841f305927b16350c7cf4823b1b22 🔍
SHA1 d6b4dcecd74d2de7bfa7e65872b540d96bf73445 🔍
SHA256 ab5c4d82d348fd0b2961dcd1ea79f1411a8f024003d775d127bd8d21f49bdb23 🔍
SHA3 6b0e47bfee907d2b3017b274016e34302d8fc1be5dc9f862a0ab82e37c5f0fd4 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xe71
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76346
Detected Filetype PNG graphic file
MD5 3074bbbf8f58f2de9a2616c3e930addf 🔍
SHA1 519ad260f8f3664c75dfcf2272e1deeaf2d4cb0a 🔍
SHA256 610a0969e7b5f85442699fd00a8e632e1593b3756c7556768a0f8ad807d9d481 🔍
SHA3 21ee830769c6f6d255421953629ff0d4bc198f706c153ef9465420ef9a2e12df 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x153e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76112
Detected Filetype PNG graphic file
MD5 c80fded070d5cb7b7470bb187cfbcc86 🔍
SHA1 a8f72680f646bc8fc2565ba4531ca6d45001fd48 🔍
SHA256 09ea539a4c81663fe1c1f76f27e0581ca9f1bdfa67973de643256b1d5969d91b 🔍
SHA3 c990c9b049d0951f747c19f0cbbfece27b98ace11b6071708f205bc4461fbece 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4a0e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97502
Detected Filetype PNG graphic file
MD5 c2e3ab2a7d6be87870383a2e39321fa5 🔍
SHA1 fa98b9350372145af2e101a9e3a797814bf038aa 🔍
SHA256 b963e54c1bcf3ea5e37ab52002e68db4324640635a59e8a653047ffa8378cf2d 🔍
SHA3 a591c9ff387a0e31bda60013c6db8c22c87f68f57a39c481ffa51942e1437c73 🔍

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x829a00
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.06249
Detected Filetype PE Executable
MD5 6da042cfa6cd298b107a3a566a4d7442 🔍
SHA1 4d80fe0351fd54c988ab1c7b5c2d155fbfa804d2 🔍
SHA256 b42d62f0e5275ed85cb8451973f6d3b953ab024c685cf9bb90bf10dbf48ad3b2 🔍
SHA3 71d90bce029080c65b3d3cff48129940bbe5c22a78701a352b62fb9128945ac4 🔍

201

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x13d33
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95918
Detected Filetype PNG graphic file
MD5 f932874fef3e37d9157914f0b7670f8f 🔍
SHA1 f3b65aa52bd33b3260bef9b1112ee8ed891e52a3 🔍
SHA256 14ff2e916a88bc9e2beab7418df8f5f9e42f2a2d0283826d752eb5b1177efef1 🔍
SHA3 1259347e60650cb749f870b90dece0536a9e28c9991af2da749a194d78c6bfde 🔍

210

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x179597
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99301
Detected Filetype PNG graphic file
MD5 57bba85f4d5541b89c650ddfc814728b 🔍
SHA1 271cce70524654d7fc5e675ec2210ce345414c1c 🔍
SHA256 2945a042fc053bcf273b0b044689cc98321f6152ba158ae89cb3a198367703d8 🔍
SHA3 49f8861d591dc99d0793f2aec8e9109579d8cbe07b3ba660876c34ed219852f1 🔍

211

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xba0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.72683
Detected Filetype PNG graphic file
MD5 5cf1a8ef1a6472052e114f605884865a 🔍
SHA1 d88d054513aa1b0b55f19cf952b42a7e06007e77 🔍
SHA256 14d616e51104812e375cb84c84cd1fbe425704c2a6498f85a52e9c92da150322 🔍
SHA3 c123c6e12a2ec50bcd538efeafb55a29a4accbbff20757eb8281253866df7bc4 🔍

301

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x291ca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27096
MD5 2efa233002285699cd2c63f8f511686f 🔍
SHA1 8dc8aa8f569688220ed6dd08968721faee2f102d 🔍
SHA256 9588432bec30c8ef8200bac4a67d8aaad881047bc2a6c9fa624d90ec96402410 🔍
SHA3 4d04728414696d105efe69a556db8e713524f90d0715bf874aa0dcfcd71decfe 🔍

302

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x7da5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.03028
MD5 82645b4974986e3b6b5b0c5d7a66846e 🔍
SHA1 e77e47e24d2c7c704e02c99a6f5db62cac28709d 🔍
SHA256 3c9dbc3544bcc588170b9a137bdb2b84224b16dc49a3b0b9e9971489d209b675 🔍
SHA3 3aa34f8da2f06768920dbf75472c0df34eaa34d4ecb25347568074940bd85fe6 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8021
Detected Filetype Icon file
MD5 a81d7363c069ec33cdb1196402ed27bf 🔍
SHA1 55a2bb17984cbe6a5c7d4b040779aeb7cf38abb6 🔍
SHA256 17b4f6ef4e39cba391d21014b80dd7674f4ad95f83971b72273e715507bef262 🔍
SHA3 23ef4fc6b7d474983c13e6165ab2062280fc488555d0e6a291ff76a0553297f4 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17496
MD5 114b32209c9b656b95cd1be00bb6ec2f 🔍
SHA1 e52498ff9d52594403c5ea29270bef818378f18f 🔍
SHA256 e891f1260cd8cba10e9ede273f4c4e612d89d59e80bf8e99c137d57ed27add3f 🔍
SHA3 1a964acc6e387afc7ec9d7dc69f0764937f52abf28c215fbac0a042fe2710a00 🔍

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Real
FileDescription Real Setup
FileVersion (#2) 1.0.0.0
InternalName RealSetup
OriginalFilename RealSetup.exe
ProductName Real
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-17 18:58:14
Version 0.0
SizeofData 1264
AddressOfRawData 0x60796c
PointerToRawData 0x60636c

TLS Callbacks

StartAddressOfRawData 0x140607eb0
EndAddressOfRawData 0x1406080e1
AddressOfIndex 0x1406510d8
AddressOfCallbacks 0x140492ff8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x0000000140454180
0x0000000140454050

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14064ac40

RICH Header

XOR Key 0xeb839c83
Unmarked objects 0
C++ objects (33145) 197
ASM objects (33145) 16
ASM objects (35721) 10
C objects (35721) 19
C++ objects (35721) 101
C objects (33145) 26
C objects (CVTCIL) (33145) 2
Imports (33145) 39
Total imports 473
Unmarked objects (#2) 48
C++ objects (36252) 15
C objects (36252) 1056
Resource objects (36252) 1
151 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.