f2150d91c01d8dcaa5f8cfd29ec421c16584a1440fa7817dd01152e701ff3e1e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-18 22:20:58
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • github.com
  • http://127.0.0.1
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://curl.se
  • https://github.com
  • https://imtheo.lol
  • https://indiantypefoundry.comNinad
  • https://lrclib.net
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • lrclib.net
  • rbxcdn.com
  • roblox.com
  • scripts.sil.org
  • thumbnails.roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
  • CheckRemoteDebuggerPresent
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegCloseKey
  • RegQueryValueExA
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryW
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptHashData
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualProtectEx
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpQueryHeaders
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpSetTimeouts
  • WinHttpQueryDataAvailable
  • WinHttpConnect
  • InternetOpenA
  • InternetOpenUrlA
  • InternetCloseHandle
  • InternetReadFile
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • Process32First
  • Process32Next
  • OpenProcess
  • Process32NextW
  • Process32FirstW
  • ReadProcessMemory
  • WriteProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 9/69 (Scanned on 2026-08-19 02:27:20) APEX: Malicious
CrowdStrike: win/malicious_confidence_90% (D)
ESET-NOD32: Win64/Riskware.GameHack.BO application
Elastic: malicious (high confidence)
Microsoft: Trojan:Win32/Sabsik.EN.A!ml
Rising: Trojan.Kryptik@AI.86 (RDML:oATlBXDic/T/ya6nSgS6vg)
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
huorong: Trojan/Agent.cfs

Hashes

MD5 a00f1111a4d9e96b5bf8412985d090b2 🔍
SHA1 4b29aea7f9495edd350c1f32f964ccda771e0698 🔍
SHA256 f2150d91c01d8dcaa5f8cfd29ec421c16584a1440fa7817dd01152e701ff3e1e 🔍
SHA3 db2623c7f0e3f29ad7e2e1e432b3f9062709667e347df01c6a80716a409add0d 🔍
SSDeep 98304:xaZcty3qDEtbx5/WCql0wqs0gwr7SlI33:o3Ff/WCql0wqs0MlI 🔍
Imports Hash 67c2238497862f113c6fcd900bbd70ae 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-18 22:20:58
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x23dc00
SizeOfInitializedData 0x1ab600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000021FAB0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3ee000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e147586d7fe91f1249aeb9107d8dbe2d 🔍
SHA1 75e9289525d27e89a55a9ac60463a37b2a8024f2 🔍
SHA256 4221dcf09038efd10634798f53b90dc9d33330ed928a2b8c043a259d6561527b 🔍
SHA3 5ef36576c1b80c2a16eaeb32273dff0cc7b535e15e2ca0681d48b9158b002efd 🔍
VirtualSize 0x23dbc8
VirtualAddress 0x1000
SizeOfRawData 0x23dc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50612

.rdata

MD5 b06e084055cb05591d6fcde31d78f5bb 🔍
SHA1 c611ea3105542036ae91a472416b9af9840ee653 🔍
SHA256 c0b6ffd31e73f4ee9059cd0c6255dda040a0bf9d8d34f975db2f47ce7b773eef 🔍
SHA3 c3cdd15071a144a5aedb2f64c9e3262d85749b2117b90acdaec6463b1e275d59 🔍
VirtualSize 0x122852
VirtualAddress 0x23f000
SizeOfRawData 0x122a00
PointerToRawData 0x23e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.84871

.data

MD5 83631bbf512782064965535682ea924b 🔍
SHA1 3ad0d9daf5f867a223301f685e32852b1910266e 🔍
SHA256 36fab2be550cc7ddf13d6fff006de3079c9d6478b06b8ea599cc59952f83c28e 🔍
SHA3 c124506a3065047efbd22ce9a7c211be0d7f9ee9164116575ac1e896c07ae4b6 🔍
VirtualSize 0x70060
VirtualAddress 0x362000
SizeOfRawData 0x2f000
PointerToRawData 0x360a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.56346

.pdata

MD5 6a794bfffe9cdbe58bab21a33008b6ab 🔍
SHA1 859a6647ca3560d19e09215054fa434cef70a6e1 🔍
SHA256 cb1b78665beef5a795a9929d7d34c0f6a148d47e3113e4df726143d4719221ef 🔍
SHA3 691f9d9d50823adc061c56a019b39f080b0552417a0f19e7df4d4af935646134 🔍
VirtualSize 0x16488
VirtualAddress 0x3d3000
SizeOfRawData 0x16600
PointerToRawData 0x38fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.31166

.rsrc

MD5 025a1616745743798094f778fc8d1f98 🔍
SHA1 cb1ec80a914b6d1b38db991c98504d261039ff5e 🔍
SHA256 90f9264bf4f35125ced39c111a62114fdf413b6ddd23a5468d405e50a3195213 🔍
SHA3 bf422ed69588f7105a563447205a46e51c44597e7f9c56707388012101ef4a3b 🔍
VirtualSize 0x1e0
VirtualAddress 0x3ea000
SizeOfRawData 0x200
PointerToRawData 0x3a6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70824

.reloc

MD5 73d89e03d411b6f9b40b2d13ad230829 🔍
SHA1 e8aab64cbad68bc94fcdc9dd6e3e24723b3c4e45 🔍
SHA256 0d56d7d0d2f27fdd959ada70cb55a64b9e92e561b62c6a05464dfa85a01952cc 🔍
SHA3 f1609e674a4e9645039a6549113bb6b69d42617f25f65bc54ec8f9913553865c 🔍
VirtualSize 0x2100
VirtualAddress 0x3eb000
SizeOfRawData 0x2200
PointerToRawData 0x3a6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40472

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
WINHTTP.dll WinHttpOpenRequest
WinHttpReadData
WinHttpOpen
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpCloseHandle
WinHttpSendRequest
WinHttpSetTimeouts
WinHttpQueryDataAvailable
WinHttpConnect
WININET.dll InternetOpenA
InternetOpenUrlA
InternetCloseHandle
InternetReadFile
D3DCOMPILER_47.dll D3DCompile
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleA
GetModuleFileNameA
GetProcAddress
GetModuleHandleW
LoadLibraryExW
FreeLibrary
api-ms-win-core-localization-l1-2-0.dll FormatMessageA
GetLocaleInfoEx
FormatMessageW
GetLocaleInfoA
api-ms-win-core-string-l1-1-0.dll WideCharToMultiByte
MultiByteToWideChar
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
LoadLibraryA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-sysinfo-l1-2-0.dll VerSetConditionMask
GetSystemTimePreciseAsFileTime
api-ms-win-core-heap-l2-1-0.dll GlobalFree
GlobalAlloc
LocalFree
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalLock
GlobalUnlock
api-ms-win-core-sysinfo-l1-1-0.dll GetTickCount
GetTickCount64
GetSystemTimeAsFileTime
GetSystemInfo
GetSystemDirectoryW
api-ms-win-core-kernel32-legacy-l1-1-2.dll Process32First
Process32Next
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
OpenProcess
FlushInstructionCache
api-ms-win-core-toolhelp-l1-1-0.dll CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
api-ms-win-core-synch-l1-2-0.dll SleepConditionVariableSRW
InitOnceComplete
Sleep
InitOnceBeginInitialize
WakeAllConditionVariable
api-ms-win-core-psapi-ansi-l1-1-0.dll QueryFullProcessImageNameA
K32GetModuleFileNameExA
api-ms-win-core-handle-l1-1-0.dll DuplicateHandle
CloseHandle
api-ms-win-ntuser-sysparams-l1-1-0.dll GetSystemMetrics
api-ms-win-core-console-l3-2-0.dll GetConsoleWindow
api-ms-win-core-memory-l1-1-0.dll VirtualProtect
VirtualProtectEx
VirtualAllocEx
ReadProcessMemory
VirtualFreeEx
VirtualQueryEx
WriteProcessMemory
VirtualQuery
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
SwitchToThread
SetThreadPriority
GetProcessId
GetCurrentThreadId
OpenProcessToken
TerminateProcess
GetCurrentThread
GetCurrentProcessId
ExitProcess
api-ms-win-core-processenvironment-l1-1-0.dll GetEnvironmentVariableA
GetStdHandle
GetCommandLineA
api-ms-win-core-console-l1-1-0.dll SetConsoleMode
GetConsoleMode
api-ms-win-core-file-l1-2-2.dll AreFileApisANSI
GetVolumeInformationA
api-ms-win-core-debug-l1-1-0.dll IsDebuggerPresent
OutputDebugStringW
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
RegQueryValueExA
RegOpenKeyExA
api-ms-win-core-processtopology-obsolete-l1-1-0.dll SetThreadAffinityMask
api-ms-win-mm-time-l1-1-0.dll timeGetTime
timeBeginPeriod
api-ms-win-core-errorhandling-l1-1-0.dll GetLastError
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
api-ms-win-core-com-l1-1-0.dll CoInitializeEx
CoUninitialize
CoCreateFreeThreadedMarshaler
CoCreateInstance
api-ms-win-security-lsalookup-ansi-l2-1-0.dll LookupPrivilegeValueA
api-ms-win-security-base-l1-1-0.dll AdjustTokenPrivileges
KERNEL32.dll CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
GetProcessHeap
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
Module32First
Module32Next
K32EnumProcessModulesEx
USER32.dll GetDesktopWindow
ShowCursor
keybd_event
MapVirtualKeyA
SendInput
SetWindowTextA
GetWindowThreadProcessId
GetWindowTextLengthW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
CreateWindowExW
UnregisterClassW
GetClassNameA
RegisterClassExW
ShowWindow
IsWindow
SetWindowLongA
SetWindowDisplayAffinity
GetMonitorInfoA
MoveWindow
EnumWindows
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
FindWindowA
UpdateWindow
IsIconic
GetWindowTextW
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
MonitorFromWindow
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
PostQuitMessage
GDI32.dll GetDeviceCaps
CreateSolidBrush
SHELL32.dll SHGetFolderPathA
ShellExecuteA
MSVCP140.dll ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
_Thrd_hardware_concurrency
_Cnd_signal
_Cnd_wait
_Cnd_register_at_thread_exit
?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Cnd_broadcast
_Thrd_join
_Thrd_id
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?uncaught_exceptions@std@@YAHXZ
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Random_device@std@@YAIXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_function_call@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
_Mtx_unlock
_Query_perf_counter
_Mtx_lock
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
??1_Facet_base@std@@UEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
??0facet@locale@std@@IEAA@_K@Z
??1facet@locale@std@@MEAA@XZ
?tolower@?$ctype@D@std@@QEBADD@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
_Strcoll
??_7facet@locale@std@@6B@
?id@?$collate@D@std@@2V0locale@2@A
?id@?$ctype@D@std@@2V0locale@2@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Strxfrm
??_7_Facet_base@std@@6B@
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
CRYPT32.dll CertFreeCertificateChain
CryptStringToBinaryW
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertGetNameStringW
CertFreeCertificateContext
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
WS2_32.dll __WSAFDIsSet
WSAIoctl
socket
setsockopt
recv
htons
getsockname
getpeername
connect
sendto
inet_ntop
WSASetLastError
select
inet_pton
WSAGetLastError
closesocket
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
ioctlsocket
gethostname
accept
htonl
recvfrom
getaddrinfo
ntohs
freeaddrinfo
bind
listen
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __current_exception
wcschr
_CxxThrowException
memcmp
memchr
memset
memmove
__current_exception_context
longjmp
strrchr
_purecall
__C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
__intrinsic_setjmp
memcpy
api-ms-win-crt-runtime-l1-1-0.dll _invalid_parameter_noinfo_noreturn
_invalid_parameter_noinfo
abort
exit
terminate
_configure_narrow_argv
_beginthreadex
__sys_errlist
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
system
_errno
_get_initial_narrow_environment
_initterm
_invoke_watson
_initterm_e
_c_exit
__p___argv
__p___argc
__sys_nerr
_exit
api-ms-win-crt-math-l1-1-0.dll sinf
powf
__setusermatherr
pow
logf
_fdopen
roundf
fmodf
_dclass
_fdclass
acosf
asinf
ldexp
lroundf
atan2f
ceilf
sqrtf
sqrt
cosf
_dsign
floorf
api-ms-win-crt-string-l1-1-0.dll strcmp
strncmp
toupper
strcspn
wcspbrk
iswspace
isalnum
_stricmp
_wcsicmp
wcsncmp
strpbrk
wcsncpy
strcpy_s
tolower
strncpy
_strdup
strspn
api-ms-win-crt-convert-l1-1-0.dll strtol
strtof
strtoull
strtoll
strtod
atoi
wcstombs
atof
strtoul
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
fflush
fclose
ungetc
setvbuf
fgetpos
__p__commode
fgetc
_read
_write
_fileno
_close
fseek
_set_fmode
__stdio_common_vfprintf
fputc
__stdio_common_vsprintf_s
fsetpos
_lseeki64
_fseeki64
_get_stream_buffer_pointers
__stdio_common_vsscanf
_wopen
fwrite
fread
fputs
__stdio_common_vsprintf
_wfopen
ftell
feof
fgets
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
malloc
_callnewh
free
calloc
realloc
api-ms-win-crt-time-l1-1-0.dll _gmtime64
strftime
_time64
_localtime64
api-ms-win-crt-filesystem-l1-1-0.dll _wstat64
_unlock_file
_fstat64
remove
_unlink
_lock_file
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
_configthreadlocale
localeconv
api-ms-win-core-file-l1-1-0.dll GetFileType
FindNextFileW
FindClose
FindFirstFileExW
CreateFileW
GetFileAttributesExW
SetFileInformationByHandle
FindFirstFileW
CreateDirectoryW
api-ms-win-core-synch-l1-1-0.dll DeleteCriticalSection
AcquireSRWLockShared
WaitForSingleObjectEx
ReleaseSRWLockExclusive
WaitForSingleObject
EnterCriticalSection
SleepEx
CreateEventW
SetEvent
LeaveCriticalSection
InitializeCriticalSectionEx
AcquireSRWLockExclusive
ReleaseSRWLockShared
InitializeCriticalSection
api-ms-win-core-file-l2-1-0.dll GetFileInformationByHandleEx
MoveFileExW
api-ms-win-security-cryptoapi-l1-1-0.dll CryptReleaseContext
CryptAcquireContextW
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptGetHashParam
CryptDestroyHash
CryptHashData
api-ms-win-core-namedpipe-l1-1-0.dll PeekNamedPipe
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-core-kernel32-legacy-l1-1-1.dll VerifyVersionInfoW
api-ms-win-security-systemfunctions-l1-1-0.dll SystemFunction036
api-ms-win-core-rtlsupport-l1-1-0.dll RtlLookupFunctionEntry
RtlVirtualUnwind
RtlCaptureContext
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
InterlockedPushEntrySList
OLEAUT32.dll SetErrorInfo
SysFreeString
SysStringLen
GetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-18 22:20:58
Version 0.0
SizeofData 912
AddressOfRawData 0x32ac40
PointerToRawData 0x329c40

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-18 22:20:58
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14032aff0
EndAddressOfRawData 0x14032b0c0
AddressOfIndex 0x1403916d0
AddressOfCallbacks 0x140240788
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140362f40

RICH Header

XOR Key 0xaa01c3dc
Unmarked objects 0
253 (35207) 8
C objects (35207) 10
C++ objects (35207) 42
ASM objects (35207) 6
Imports (35207) 8
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 123
C++ objects (34436) 5
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (VS2008 SP1 build 30729) 136
Imports (33145) 32
Imports (21202) 3
Total imports 706
C++ objects (LTCG) (35228) 81
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.