f06e8684052fe924c9d289f3d6f0e86f0dcbb7f8548a3b270e341ac06b3186ff

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-20 23:02:14
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts pluto.pdb
CompanyName vrad
FileDescription pluto
FileVersion 0.1.0
ProductName pluto
ProductVersion 0.1.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • GoDaddy.com
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • githubusercontent.com
  • http://dummy.testC
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://docs.rs
  • https://github.com
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/plutoguy/plutov2/main/Injector.exeInjector.exehttps
  • https://raw.githubusercontent.com/plutoguy/plutov2/main/Pluto.dllPluto.dllhttps
  • https://raw.githubusercontent.com/plutoguy/plutov2/main/appversion.txtappversion.txtsrc\lib.rs
  • https://tauri.localhost
  • https://www.World
  • https://www.recent
  • microsoft.com
  • openssl.org
  • raw.githubusercontent.com
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryW
  • LoadLibraryExW
  • LoadLibraryExA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
  • RegGetValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCancelIoFileEx
  • NtDeviceIoControlFile
  • NtReadFile
  • NtOpenFile
  • NtWriteFile
  • NtCreateNamedPipeFile
  • NtCreateFile
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • MapVirtualKeyW
  • GetForegroundWindow
Leverages the raw socket API to access the Internet:
  • freeaddrinfo
  • WSAStartup
  • WSACleanup
  • getaddrinfo
  • closesocket
  • getpeername
  • getsockopt
  • WSAGetLastError
  • getsockname
  • recv
  • WSASend
  • send
  • setsockopt
  • ioctlsocket
  • connect
  • shutdown
  • bind
  • WSASocketW
  • WSAIoctl
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Malicious VirusTotal score: 3/70 (Scanned on 2026-07-21 08:39:14) AVG: MalwareX-gen [Drp]
Avast: MalwareX-gen [Drp]
Avira: DR/W64.MalwareX

Hashes

MD5 d538861e64c56b5652f5b18a3e253af5
SHA1 ef451e8c0d9c89f85c6664d6449b747b5db3858c
SHA256 f06e8684052fe924c9d289f3d6f0e86f0dcbb7f8548a3b270e341ac06b3186ff
SHA3 75fd7b855ca91d1a80e94858b32c0551313e8cb4305fa9aba1378f7f4d20c019
SSDeep 196608:WS/U8dfbwwpRvfvWn+T2mYxrxr07BZOlJGJIGj:RdfBRHW+jYxdYBZgJb+
Imports Hash c0bd0891ba338a0c6886946797ab6290

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-20 23:02:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x7e5000
SizeOfInitializedData 0x7da800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000007BD7FC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xfc3000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 38754fbcb97b7a8c3dcf1d74b0032c5e
SHA1 299a1f87a0d1106f1ea4c1cdc1a67df08d2feb71
SHA256 00b426e250a9f0c0b9e4dc82bf81d96b8dcd6975c985c7a4996167590766eaee
SHA3 a2df5fdd87081cd97690ac13e1d552d243d337712f8059185faeab0b69e032a7
VirtualSize 0x7e4e50
VirtualAddress 0x1000
SizeOfRawData 0x7e5000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.18228

.rdata

MD5 061d1a2d42a8f7f75f2d67183bf54cdb
SHA1 16cd13372e514eb01a359db8778fb0477760e1ea
SHA256 6d5bba4495ca9440e9cc9542bd62d5b56b622a1311bd73202fa8aa66fd6cc5f0
SHA3 d6f3542b0f559f3d14b487cfc4dfdf476b1ab0b561bd7c9a7f0d27576bf2952f
VirtualSize 0x74bfa0
VirtualAddress 0x7e6000
SizeOfRawData 0x74c000
PointerToRawData 0x7e5400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.46583

.data

MD5 861589a621e12de37f2c33658d09d9e6
SHA1 95280d4b1250467ca0cc2bce107bc047ab31a9ec
SHA256 7c5f5815fc6ba14080120e37320ceb32b0f8f46af160a2fc8f58c555d36655ac
SHA3 80090c27cf5dbe674abd7c93cc55c3810d450109835f6d66e9636a1b88eaf6ea
VirtualSize 0x3788
VirtualAddress 0xf32000
SizeOfRawData 0x1200
PointerToRawData 0xf31400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.33587

.pdata

MD5 6b28ae62eedf32dbb8194cb7693121e3
SHA1 bd665e63703cb3d509ab3cdb8531d3c3cf078aad
SHA256 d079a73d1409a1b364a760b65d308f4dda0d9b2bf30aa105540bcf609b804d9b
SHA3 0f059dbc8501f1fe81d5769790f225fa84fcf8cd68a7f9fc2f3dc9cf3d9fd9af
VirtualSize 0x6e448
VirtualAddress 0xf36000
SizeOfRawData 0x6e600
PointerToRawData 0xf32600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.5551

.rsrc

MD5 a2138c522280c9bb0fcd1c8e42707d28
SHA1 aa5044fed0ad1291ee21bf6864369738a48348f9
SHA256 068d4bdba843735a67a948336e89aed7e81497e67fd260c748ef42860c8ca98c
SHA3 46aac5b5370f28e6bf91996a5d798cf59a0b56b0e8e5b58a750fd5f08950a938
VirtualSize 0x15748
VirtualAddress 0xfa5000
SizeOfRawData 0x15800
PointerToRawData 0xfa0c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.59344

.reloc

MD5 84c6bd31f25ee7e295b198d7b4739a83
SHA1 16a99f31d05776d51fa05f95588e1b444d40c04d
SHA256 f4879a4d278834227659b786e852f27f1d33380a38f2db52cf316621521813dc
SHA3 a89ff8e85c2ac02f3f881ef103fe731f6e14dcdc6bc23d82ec4541fbfe3bda58
VirtualSize 0x7098
VirtualAddress 0xfbb000
SizeOfRawData 0x7200
PointerToRawData 0xfb6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45378

Imports

bcryptprimitives.dll ProcessPrng
advapi32.dll RegOpenKeyExW
RegQueryValueExW
RegCloseKey
RegGetValueW
ntdll.dll NtCancelIoFileEx
RtlGetVersion
NtDeviceIoControlFile
RtlNtStatusToDosError
NtReadFile
NtOpenFile
NtWriteFile
NtCreateNamedPipeFile
NtCreateFile
kernel32.dll GetSystemTimeAsFileTime
FlsGetValue
SleepConditionVariableSRW
WakeAllConditionVariable
lstrlenW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
FindNextFileW
RtlLookupFunctionEntry
LoadLibraryA
GetSystemInfo
QueryPerformanceCounter
GetSystemTimePreciseAsFileTime
WriteFileEx
CreateProcessW
GetWindowsDirectoryW
GetSystemDirectoryW
CompareStringOrdinal
FreeEnvironmentStringsW
CreateThread
SetWaitableTimer
CreateWaitableTimerExW
LoadLibraryW
FlsAlloc
GetConsoleOutputCP
GetStdHandle
WriteConsoleW
MultiByteToWideChar
QueryPerformanceFrequency
SleepEx
ReadFileEx
ExitProcess
GetTempPathW
SetEnvironmentVariableW
FlsSetValue
FindClose
FindFirstFileExW
RtlPcToFileHeader
DeleteFileW
SwitchToThread
GetFileInformationByHandleEx
DeviceIoControl
CreateDirectoryW
MoveFileExW
GetCommandLineW
GetEnvironmentStringsW
GetCurrentDirectoryW
SetLastError
GetCurrentThread
SetThreadStackGuarantee
AddVectoredExceptionHandler
WaitForSingleObject
DuplicateHandle
GetModuleHandleW
GetUserDefaultUILanguage
SetHandleInformation
SetFileCompletionNotificationModes
SetFileInformationByHandle
GetFileAttributesW
OutputDebugStringA
OutputDebugStringW
GetModuleFileNameW
GetLastError
GetProcessHeap
HeapFree
LoadLibraryExW
FlsFree
EncodePointer
InitializeSListHead
FreeLibrary
ReleaseMutex
CreateMutexA
GetCurrentProcessId
SetUnhandledExceptionFilter
WaitForSingleObjectEx
LCIDToLocaleName
GetFullPathNameW
WideCharToMultiByte
GetCurrentProcess
HeapReAlloc
GetEnvironmentVariableW
RtlVirtualUnwind
RtlUnwindEx
GetCurrentThreadId
RaiseException
GetModuleHandleA
LoadLibraryExA
Sleep
HeapAlloc
GetProcAddress
CloseHandle
InitializeCriticalSectionEx
FormatMessageW
GetFinalPathNameByHandleW
RtlCaptureContext
CreateFileW
SetNamedPipeHandleState
GetConsoleMode
GetFileInformationByHandle
GetQueuedCompletionStatusEx
CreateIoCompletionPort
CancelIoEx
WriteFile
ReadFile
PostQueuedCompletionStatus
GetOverlappedResult
DeleteCriticalSection
user32.dll GetTouchInputInfo
RedrawWindow
VkKeyScanW
DrawTextW
GetWindowDC
OffsetRect
GetMenuBarInfo
TrackMouseEvent
DestroyMenu
DrawIconEx
CheckMenuItem
GetMenuItemInfoW
RemoveMenu
CreatePopupMenu
CreateMenu
SetMenu
DrawMenuBar
SetMenuItemInfoW
SendMessageW
TranslateMessage
AppendMenuW
InsertMenuW
TrackPopupMenu
PostQuitMessage
CreateAcceleratorTableW
DestroyAcceleratorTable
CreateIcon
ToUnicodeEx
GetKeyState
SystemParametersInfoW
GetAsyncKeyState
GetKeyboardState
MapVirtualKeyExW
GetMenu
GetUpdateRect
FillRect
SetPropW
SetWindowLongW
EnableMenuItem
DispatchMessageW
LoadCursorW
PostMessageW
GetSystemMenu
ClipCursor
GetClipCursor
ShowCursor
MonitorFromRect
GetRawInputData
ClientToScreen
EnumDisplayMonitors
MonitorFromPoint
GetKeyboardLayout
SetWindowTextW
GetWindowTextW
GetWindowTextLengthW
SetWindowDisplayAffinity
SendInput
SetForegroundWindow
DestroyIcon
PeekMessageW
RegisterRawInputDevices
ReleaseCapture
SetCapture
MsgWaitForMultipleObjectsEx
GetSystemMetrics
CloseTouchInputHandle
RegisterWindowMessageA
SetParent
MapWindowPoints
GetWindow
SetFocus
ShowWindow
ReleaseDC
SetWindowPos
GetClientRect
IsProcessDPIAware
GetDC
GetWindowRect
SetWindowLongPtrW
GetParent
GetWindowLongPtrW
FindWindowExW
SetWindowRgn
EnableWindow
IsWindowEnabled
GetWindowLongW
SetCursor
GetCursorPos
PostThreadMessageW
ScreenToClient
ValidateRect
GetMonitorInfoW
IsWindowVisible
RegisterTouchWindow
IsWindow
AdjustWindowRectEx
GetWindowPlacement
SetWindowPlacement
ChangeDisplaySettingsExW
FlashWindowEx
DefWindowProcW
GetMessageW
MapVirtualKeyW
TranslateAcceleratorW
MonitorFromWindow
GetForegroundWindow
GetActiveWindow
UpdateWindow
InvalidateRect
SetCursorPos
InvalidateRgn
DestroyWindow
IsIconic
EnumChildWindows
DispatchMessageA
GetMessageA
CreateWindowExW
RegisterClassExW
SystemParametersInfoA
AdjustWindowRect
shell32.dll DragFinish
SHGetKnownFolderPath
ILFree
SHAppBarMessage
DragQueryFileW
SHOpenFolderAndSelectItems
ShellExecuteExW
ILCreateFromPathW
ShellExecuteW
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WakeByAddressSingle
WaitOnAddress
ole32.dll CoUninitialize
CoInitializeEx
RevokeDragDrop
CoInitialize
RegisterDragDrop
CoTaskMemAlloc
CoCreateInstance
OleInitialize
CoTaskMemFree
CoCreateFreeThreadedMarshaler
comctl32.dll TaskDialogIndirect
SetWindowSubclass
RemoveWindowSubclass
DefSubclassProc
gdi32.dll CreateRectRgn
SetBkMode
DeleteDC
SelectObject
CreateDIBSection
GetDeviceCaps
BitBlt
CreateCompatibleDC
CombineRgn
CreateSolidBrush
SetTextColor
DeleteObject
shlwapi.dll SHCreateMemStream
dwmapi.dll DwmGetWindowAttribute
DwmSetWindowAttribute
DwmEnableBlurBehindWindow
oleaut32.dll SetErrorInfo
SysStringLen
GetErrorInfo
SysFreeString
ws2_32.dll freeaddrinfo
WSAStartup
WSACleanup
getaddrinfo
closesocket
getpeername
getsockopt
WSAGetLastError
getsockname
recv
WSASend
send
setsockopt
ioctlsocket
connect
shutdown
bind
WSASocketW
WSAIoctl
bcrypt.dll BCryptGenRandom
ADVAPI32.dll EventSetInformation
SystemFunction036
EventWriteTransfer
EventUnregister
EventRegister
api-ms-win-crt-math-l1-1-0.dll trunc
round
roundf
pow
floor
__setusermatherr
api-ms-win-crt-string-l1-1-0.dll wcscmp
strcpy_s
wcslen
_wcsicmp
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstol
_ultow_s
api-ms-win-crt-runtime-l1-1-0.dll _initialize_narrow_environment
_cexit
_configure_narrow_argv
_c_exit
_register_thread_local_exe_atexit_callback
__p___argv
_initterm
abort
__p___argc
_exit
_initterm_e
exit
terminate
_seh_filter_exe
_set_app_type
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_get_initial_narrow_environment
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_set_fmode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
free
_callnewh
malloc

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.12876
MD5 d6f7e9921ea85f01cef44ced4a537444
SHA1 5fc1ea19549568116ebfc20d386ae05243effc7d
SHA256 29b693bc1a518cf5c2c0e6041b685bd2c1aaa38a18072a858dc9275e1e80130f
SHA3 e5dd96611e1a651a679d72c66531c52a7468e835ae8d73c85abd1472ec846cd8

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41449
MD5 fa337418e9bf59504f419bf5ee96d5a7
SHA1 846710efc3f5a866be3295c21ae8e5e19c95e120
SHA256 d0c5daa9b7df9bb4e45601080eb03df1bb7763e82b463689988017b114630674
SHA3 462d4cce01066d6d4fc343a0e6fe4e984e2e91d5564464d75b14bc9b584fe877

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.08611
MD5 e8b4468986841f67538f14800acc737c
SHA1 60bf3e202876b17857d8e67a7328b57470fdd0a1
SHA256 b9c644cc7f87b7d6b27d035bb4bf7e707758f1ebc0f5dddc7c7e93c5ff3f0efc
SHA3 af85fe45aacfe7f008117d21f34fd2d3d29a20a75799205952445c21cbed88d6

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x34f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95173
Detected Filetype PNG graphic file
MD5 6777ab7d8ead647e4d2bb84f58226cfa
SHA1 b32cc346c5bd7e9702763ea68bb43875833d1748
SHA256 b940f2834f50e8d53ec04dc5107b7256579b4078be5ab5a67f329641bb5b020b
SHA3 46d3e742bdeb0c1c61253a7a239741b365a162a7063cf244163ae136f63853c0

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.51652
Detected Filetype Icon file
MD5 ca045fcfa6205952b2b270075f8d50fb
SHA1 4a9539d6e30dfabfa75a1ce53b15736930783bb7
SHA256 d591a03fd1e36f66a14c35ef2b823e97a27346da1b1a35379336cbe2e176f9f7
SHA3 a99a6472e4288329649e74a4f152a9dea1370f348f9ab5b1c93de288da8defa8

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07841
MD5 de5347caf6577d825715ddaf4c12b21a
SHA1 3ef2c344abbf12c9c8acebd595a74640ac8d1059
SHA256 b5a88734764bf5440b2e6448adea28d84f5fd6605c57746e9788a7b0b514b136
SHA3 f354d79dba35b6afe31c09263a9e6a1beb788f1cb25301e8cd9ebc5479ff847f

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.1.0.0
ProductVersion 0.1.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName vrad
FileDescription pluto
FileVersion (#2) 0.1.0
ProductName pluto
ProductVersion (#2) 0.1.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-20 23:02:14
Version 0.0
SizeofData 34
AddressOfRawData 0xd737cc
PointerToRawData 0xd72bcc
Referenced File pluto.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-20 23:02:14
Version 0.0
SizeofData 20
AddressOfRawData 0xd737f0
PointerToRawData 0xd72bf0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-20 23:02:14
Version 0.0
SizeofData 1048
AddressOfRawData 0xd73804
PointerToRawData 0xd72c04

TLS Callbacks

StartAddressOfRawData 0x140d73c68
EndAddressOfRawData 0x140d73e6c
AddressOfIndex 0x140f35620
AddressOfCallbacks 0x1407e6c40
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014077A670

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140f33080

RICH Header

XOR Key 0xd62ef7f4
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (35403) 9
C objects (35403) 13
C++ objects (35403) 46
Imports (33145) 5
Total imports 427
C objects (35719) 12
Unmarked objects (#2) 669
Resource objects (35719) 1
Linker (35719) 1

Errors

Leave a comment

No comments yet.