c4c0b8e1593bc5481521cecfce00b953e3ee6d7323b98e7ddf2e8c90a78ce545

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-May-20 18:40:00
Debug artifacts D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName VelocityLite
FileDescription VelocityLite
FileVersion 1.0.0.0
InternalName VelocityLite.dll
LegalCopyright
OriginalFilename VelocityLite.dll
ProductName VelocityLite
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • https://aka.ms
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegGetValueW
Possibly launches other programs:
  • ShellExecuteW
Malicious VirusTotal score: 4/70 (Scanned on 2026-08-12 16:12:16) Gridinsoft: Risk.Win64.Gen.bot
Kingsoft: Win32.Troj.Unknown.a
Malwarebytes: RiskWare.DllInjector
TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101FU26ZB

Hashes

MD5 e4df8ee6e755c3da3088701eb1c05b76 🔍
SHA1 c52dbc1190b84555e27649b9b54746b958e5f3cb 🔍
SHA256 c4c0b8e1593bc5481521cecfce00b953e3ee6d7323b98e7ddf2e8c90a78ce545 🔍
SHA3 c49178c4906f869297c30ec779ad7695a5704837637521f407b89cc4c437d957 🔍
SSDeep 3072:IlDJk88wN1QI7sxrYL1peQ3lOY9SkHNwG7NzaAT56Q7BQz:UAIwxrI14Q3kYBTM5QNQ 🔍
Imports Hash 53e4e12437621212a425d294842d0a96 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-May-20 18:40:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18400
SizeOfInitializedData 0x22a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000013BA0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e3d9860a10466315d5199d2470b85579 🔍
SHA1 e8ac8218dabaeca43d0fabfdfc249be0dab5a047 🔍
SHA256 7c0ed9342a9ceca678261941d15fd5215422194c2346cab0bf13bb27a4559b98 🔍
SHA3 eda39d9c0c31318ac5bf83fd2149aaaacce0452ae7d6539fc7683faafb58bf76 🔍
VirtualSize 0x183bc
VirtualAddress 0x1000
SizeOfRawData 0x18400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36553

.rdata

MD5 8893304650884f47691446e5e2d399d3 🔍
SHA1 015e518e0d41633355949ee5a54bd1b0f2ff4366 🔍
SHA256 297e4a3c8af82511438379611d5484c3e69117c15e58e37326921a38aee7ac43 🔍
SHA3 0adc7fcbef3ba199241171c7ff1445882dbb66a2e57725097908410d80def8d5 🔍
VirtualSize 0xc5fe
VirtualAddress 0x1a000
SizeOfRawData 0xc600
PointerToRawData 0x18800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84789

.data

MD5 b70d68dc5da6c85192fb3f5ed9e662b0 🔍
SHA1 7d5195109e2b7a181f67c91567acbe78faaee2f7 🔍
SHA256 a6244ced9c5b12bbb6483e6260e06e896aeff07dba5f696e953b13cba7dbf0d7 🔍
SHA3 c4b92e44c474497510664e6bfff5aa5a260dd108e6c63a46c4fe42735288144c 🔍
VirtualSize 0x1a40
VirtualAddress 0x27000
SizeOfRawData 0xc00
PointerToRawData 0x24e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.23137

.pdata

MD5 24165f8dfccb28f7da4cf026f3968201 🔍
SHA1 4c13384f8be4365f23e7cf1c8572599e9d2e2fcf 🔍
SHA256 46ccf92b7ee0d9686b75fda66946fcb333a0db8a3537cdfa6b4a06f2d5c931aa 🔍
SHA3 3b6e5f48f316f873f1ba655459440c348f39549325278e1772984e38c9279573 🔍
VirtualSize 0x14c4
VirtualAddress 0x29000
SizeOfRawData 0x1600
PointerToRawData 0x25a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.9072

.reloc

MD5 013117ac819f8cbe20d402f784ee2731 🔍
SHA1 2f089ff04f134328ae06b14119155796239226aa 🔍
SHA256 f6bfd84f8de960552694e3ba178d8b40ea4a0ea893f4dfe14706415288487e4a 🔍
SHA3 a31b80535fd6738c1909a024a81da7b26e3dcca70b1f62a8a3c9ef72b219e1c9 🔍
VirtualSize 0x33c
VirtualAddress 0x2b000
SizeOfRawData 0x400
PointerToRawData 0x27000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80647

.rsrc

MD5 383dad2233c9a6406e4106a3c938f2e4 🔍
SHA1 4cf41f144f9ec2213544c97cd69781772d1cffac 🔍
SHA256 81ecaf4500f4c5ca4ba1ff4d52cf3893a4611bec14c9b9f4e4c269a4921111d3 🔍
SHA3 b9a8c2c4c116c29667dc5ead6f332e616588a406f52c42e147e9a55303a8a473 🔍
VirtualSize 0x12d78
VirtualAddress 0x2c000
SizeOfRawData 0x12e00
PointerToRawData 0x27400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.63393

Imports

SHELL32.dll ShellExecuteW
ADVAPI32.dll RegCloseKey
ReportEventW
RegisterEventSourceW
RegOpenKeyExW
RegGetValueW
DeregisterEventSource
KERNEL32.dll TlsFree
CreateActCtxW
ActivateActCtx
GetLastError
FindResourceW
GetWindowsDirectoryW
GetProcAddress
GetModuleHandleW
FreeLibrary
LoadLibraryExW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetStdHandle
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
FindClose
GetFileAttributesW
MultiByteToWideChar
GetConsoleMode
GetFileAttributesExW
LoadLibraryA
WriteConsoleW
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
OutputDebugStringW
GetCurrentProcessId
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
api-ms-win-crt-runtime-l1-1-0.dll terminate
_register_thread_local_exe_atexit_callback
_c_exit
__p___wargv
__p___argc
_exit
exit
_initterm_e
_errno
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
abort
_invoke_watson
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
malloc
_callnewh
free
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64_s
wcsftime
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfwprintf
__p__commode
fputwc
__acrt_iob_func
__stdio_common_vswprintf
_set_fmode
_wfsopen
fflush
setvbuf
__stdio_common_vsnwprintf_s
api-ms-win-crt-locale-l1-1-0.dll _create_locale
___mb_cur_max_func
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_configthreadlocale
setlocale
_lock_locales
_free_locale
_unlock_locales
api-ms-win-crt-string-l1-1-0.dll strlen
strcmp
wcsncmp
toupper
strcpy_s
_wcsdup
wcsnlen
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.73059
MD5 cf51ca75f0350685c0fc141130e94030 🔍
SHA1 d9e01451feb73ae91a664237058da517918bad77 🔍
SHA256 1ad5386a6f3dd7fc14feccdd591aeca6b5b85b0f452af74d195748be860acf22 🔍
SHA3 cbcc570ecdd7c09104c8a5780d95af7bb1bc9bfa665bc758955992bb615d0026 🔍

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.49334
MD5 c7faaedcd02c03e9daedca5aefca6c43 🔍
SHA1 b05628be4bd990c3b7751b9a0a6bdf8e6ed26251 🔍
SHA256 2376fec9ceeb94ee42e3ac3f0e048ac3f256d5bd2c6207d23b9496ec791249da 🔍
SHA3 dc41d7526a43285343e8d3ca3800363ff486a7a092cbd528e207e6f92f328d0b 🔍

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.38583
MD5 6fbe2e4c7680bdeac5435efe537895d4 🔍
SHA1 79915c3f8d19c433d58e3bdf8a18821fe5aace25 🔍
SHA256 2e8b6932a88a22493a4ee86ca84c9bcf6e4c519f18780989157bee7fd75c7b6a 🔍
SHA3 1c3de94e3eb1b8b1ee850a14775133a0a30b3eec956f63a60355a3c61b57450f 🔍

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.27545
MD5 f38a9d05b740487b4a568413c47589b8 🔍
SHA1 bc4740b1f63134b7ace57a1d8536bd3a294565ef 🔍
SHA256 9d6b084aaa50d631ff0d424e19ffa822901a4575b17c5b6d47468e7ade6e3cc5 🔍
SHA3 6a0c80d106886be2516d4dac660e6cc86376852b5d695fcfd8b99eb37422fa69 🔍

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.14327
MD5 4da99ef046ee054ff0c0a3ae49234000 🔍
SHA1 ecf5756f2faa22dfb83f308a61fecfd069a2372b 🔍
SHA256 be07e90f388873eb81f68df923af44590656d4a0d6063ac2ccc88868e2a7acb0 🔍
SHA3 5ea41777aa4a1c7d114f16cd742463fda912a49b22cf3552fbe38d53284faf85 🔍

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.07171
MD5 6885f227e4e9533b0184672dc627fe50 🔍
SHA1 1b40d738e836fbc154686ffeed31cc7cfd84819a 🔍
SHA256 10222591225c22600358d60cd500bd89b19f8cb0719b0a8db23f7817816488a8 🔍
SHA3 22d872b3150e2ac5a9575f571ff47832a3d777eaa3d0ddc73954c22bd33069aa 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89637
Detected Filetype Icon file
MD5 411a13e25c0d01a3175db08c339b0d9d 🔍
SHA1 1efb96c4bebc53de89f20ceedd9869bcecba130a 🔍
SHA256 c988e91ba6c972da0a1d2b7e0c0cbe44be9a6452459d580330c95b159967c31a 🔍
SHA3 9d102fcb41d6db24963b1d2862b249f9b03567ba819d7dc647ad8e7ae6ee8ab4 🔍

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19757
MD5 020d33c682e4c3af16dbea8ef27c509a 🔍
SHA1 a9eae295b09471bc979f56f0f26ad530ebc2a9d3 🔍
SHA256 c332a840f28cc8e2ed795dc853f6d8882309782be6d821ea869888460bfb7292 🔍
SHA3 7af084c174e7a060a9f8139c1ac315211a172380133bf18927b588ee1207f005 🔍

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd04
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.97388
MD5 84f2d5b0bd4eae2b5ee20c5f83ae7062 🔍
SHA1 0bda84d89f39fe47f2da37903fe580aa50e883ec 🔍
SHA256 eea373d990a6ef10b83a8602e46d7d97ca9c47feb8ebe4b07a509209c0e93ffb 🔍
SHA3 c9d0ca96f246b4b1b047409e6594457c704e508c6a30061bb3bd3ba94485ed3a 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName VelocityLite
FileDescription VelocityLite
FileVersion (#2) 1.0.0.0
InternalName VelocityLite.dll
LegalCopyright
OriginalFilename VelocityLite.dll
ProductName VelocityLite
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-May-20 19:23:14
Version 0.0
SizeofData 121
AddressOfRawData 0x22e2c
PointerToRawData 0x2162c
Referenced File D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-May-20 19:23:14
Version 0.0
SizeofData 20
AddressOfRawData 0x22ea8
PointerToRawData 0x216a8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-May-20 19:23:14
Version 0.0
SizeofData 988
AddressOfRawData 0x22ebc
PointerToRawData 0x216bc

UNKNOWN

Characteristics 0
TimeDateStamp 2026-May-20 19:23:14
Version 0.0
SizeofData 4
AddressOfRawData 0x232c0
PointerToRawData 0x21ac0

TLS Callbacks

StartAddressOfRawData 0x1400232e8
EndAddressOfRawData 0x1400232f8
AddressOfIndex 0x140028a28
AddressOfCallbacks 0x14001a518
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x1400270c0
GuardCFCheckFunctionPointer 5368816712
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x2c9dd37e
Unmarked objects 0
ASM objects (35207) 10
C objects (35207) 13
C++ objects (35207) 86
Imports (VS2008 SP1 build 30729) 16
Imports (33145) 9
Total imports 212
C++ objects (LTCG) (35223) 10
Linker (35223) 1

Errors

Leave a comment

No comments yet.