fbb4aa12410e26a8aeb3f9437de565edd83121567d0fd709969f06257fb59341

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Nov-10 13:35:14
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentControlSet\Services
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • apple.com
  • cacerts.digicert.com
  • crl.microsoft.com
  • crl3.digicert.com
  • crl4.digicert.com
  • digicert.com
  • github.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
  • http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
  • http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://crl3.digicert.com/sha2-assured-ts.crl02
  • http://crl4.digicert.com
  • http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
  • http://crl4.digicert.com/sha2-assured-ts.crl0
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.digicert.com0O
  • http://ocsp.digicert.com0\
  • http://www.apple.com
  • http://www.apple.com/
  • http://www.digicert.com
  • http://www.digicert.com/CPS0
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0
  • https://github.com
  • https://www.digicert.com
  • https://www.digicert.com/CPS0
  • https://www.microsoft.com
  • https://www.microsoft.com/en-us/windows
  • microsoft.com
  • www.apple.com
  • www.digicert.com
  • www.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegQueryValueExW
  • RegEnumValueW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegSetKeySecurity
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegCloseKey
  • RegGetKeySecurity
Possibly launches other programs:
  • CreateProcessAsUserW
  • CreateProcessW
  • ShellExecuteW
  • system
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • WinHttpConnect
  • WinHttpReceiveResponse
  • WinHttpOpen
  • WinHttpReadData
  • WinHttpQueryDataAvailable
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpCloseHandle
Functions related to the privilege level:
  • DuplicateTokenEx
  • OpenProcessToken
  • AdjustTokenPrivileges
Interacts with services:
  • QueryServiceStatusEx
  • OpenServiceW
  • OpenSCManagerW
Manipulates other processes:
  • WriteProcessMemory
  • OpenProcess
  • Process32NextW
  • Process32FirstW
  • ReadProcessMemory
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 43/70 (Scanned on 2026-09-06 00:54:43) ALYac: Gen:Variant.Application.Tedy.16270
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Trojan/Win.Generic.R763470
Alibaba: Trojan:Win64/GenKryptik.aa29b408
Antiy-AVL: Trojan/Win64.GenKryptik
Arcabit: Trojan.Application.Tedy.D3F8E
Avast: Win64:MalwareX-gen [Misc]
BitDefender: Gen:Variant.Application.Tedy.16270
Bkav: W32.Malware.8C2FED60
CTX: exe.trojan.genkryptik
ClamAV: Win.Malware.Redcap-10058771-0
CrowdStrike: win/malicious_confidence_90% (W)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GenKryptik_AGen.AES trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Application.Tedy.16270 (B)
Fortinet: W64/GenKryptik_AGen.AES!tr
GData: Gen:Variant.Application.Tedy.16270
Google: Detected
Ikarus: Trojan.Win64.Krypt
K7AntiVirus: Trojan ( 005cef171 )
K7GW: Trojan ( 005cef171 )
Lionic: Trojan.Win32.Generic.4!c
MaxSecure: Trojan.Malware.338148470.susgen
McAfeeD: Trojan:Win/Suschil.EAA
MicroWorld-eScan: Gen:Variant.Application.Tedy.16270
Microsoft: Trojan:Win32/Phonzy.A!ml
Paloalto: generic.ml
Rising: Trojan.Kryptik!8.8 (TFE:5:3N94mBEc0pB)
SentinelOne: Static AI - Suspicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.14a28bf2
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!D2C946FCB4CA
TrendMicro: Trojan.Win64.WACATAC.TL0101H526ZT
TrendMicro-HouseCall: Trojan.Win64.WACATAC.TL0101H526ZT
VBA32: Trojan.Wacatac
VIPRE: Gen:Variant.Application.Tedy.16270
Varist: W64/ABTrojan.PQHT-1132
ViRobot: Trojan.Win.C.Agent.3314688.A
Zillya: Trojan.GenKryptikAGen.Win64.8748
alibabacloud: RiskWare:Win/HackTool.Akgpp_DArY

Hashes

MD5 d2c946fcb4ca0f23c80c2990eb4f0ed2 🔍
SHA1 1ce469f7677254b1eb3d79a28dfce25ea7465305 🔍
SHA256 fbb4aa12410e26a8aeb3f9437de565edd83121567d0fd709969f06257fb59341 🔍
SHA3 a3abf22aa7a719c2287057fc7a3e5f8d99c2bd543045e51792c7922b455cc3d2 🔍
SSDeep 49152:W3BTI8hNHtLEbhOpIf2r3nL31cugq1NTxoPCdIA1sITLl3oKJ6mEO2l0MLUox6:W3+hOqMXxoj2 🔍
Imports Hash 6b327f993662a02f9935efcef2fc650b 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Nov-10 13:35:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x124400
SizeOfInitializedData 0x207600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000117048 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x331000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 60abcf7876793e3edb78f2ded48b5819 🔍
SHA1 b0ff7a79e103735a405c42724acd5128ef883ad0 🔍
SHA256 2ab8846c0a96597b658ade5920e0ae0b4f04d2b9201fdbd409144ca63dd1212d 🔍
SHA3 7e65a1b8ce8561aee9414a165d7ad077a2b5ef9d444931225e17e5eb16ad2fcb 🔍
VirtualSize 0x1242f3
VirtualAddress 0x1000
SizeOfRawData 0x124400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50863

.rdata

MD5 49ffe1184078e96e9738cb0b70e57fe0 🔍
SHA1 cd76c855a0da12186a694c7a5d8c10860f1ceb4e 🔍
SHA256 3e2273dafa462654fc7cba5ed15417b83d6c94da436a5f07d315a26c046a2d88 🔍
SHA3 ebe509bde2df56ae099beb9fb296b07d875c206b555eb4d36c79218e053f8ea7 🔍
VirtualSize 0x4d4a8
VirtualAddress 0x126000
SizeOfRawData 0x4d600
PointerToRawData 0x124800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.1469

.data

MD5 600ca85ff29ea2307a1b72b5a929c407 🔍
SHA1 3e2a24e9186e21f03d88527ef1675918aa38e4b3 🔍
SHA256 4ff770774383bbcd9f4cea94755a2d13068c253788b3ff96bf8ed12a600e724c 🔍
SHA3 16f246d4804a39fab8e037d21089d104e9f965c53b813bae8c1108fb36f3896d 🔍
VirtualSize 0x1ac640
VirtualAddress 0x174000
SizeOfRawData 0x1a9e00
PointerToRawData 0x171e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.00527

.pdata

MD5 c00a5c8ccedcde04bafc340448ba6533 🔍
SHA1 f2c206cbfbb69d38f9f7452f36bb99956721cdbd 🔍
SHA256 83bb916bb38c5009c1f2dd16810924f86035639bbe1ea26df4cba272773e6be1 🔍
SHA3 24d1be0f33e799376c14699da965f69dd38feab4ca9734362f8397cad1d8ab1f 🔍
VirtualSize 0xc3a8
VirtualAddress 0x321000
SizeOfRawData 0xc400
PointerToRawData 0x31bc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.16468

.rsrc

MD5 e4a32da2377f87b8a9b61ad8711cf257 🔍
SHA1 70a526c9226f648833f7be66a4b01a5ed7e09602 🔍
SHA256 e1c04d088d07ceeb54f79e0069287bde5860b19c080cf861f9b37f2964ac61e7 🔍
SHA3 e3c73f8c692e61615c3e469cfb05d33e3ddb7307e6ea84ad11f06afcedb997ba 🔍
VirtualSize 0x1e8
VirtualAddress 0x32e000
SizeOfRawData 0x200
PointerToRawData 0x328000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 8fea0b3d11b1fe6fad87dafff17aecd8 🔍
SHA1 efce6c8e1593ea224a7ba56f87eae02e09f22e81 🔍
SHA256 f20fdec5e26e22775fd489fc2bddb296da3f297c7af46301eefd2962d17fc587 🔍
SHA3 b7292b5583dec0e4f789f2eaa59d7b4d933caa9f4d9ccc37b10ea1a751dde692 🔍
VirtualSize 0x10fc
VirtualAddress 0x32f000
SizeOfRawData 0x1200
PointerToRawData 0x328200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.33485

Imports

dwmapi.dll DwmExtendFrameIntoClientArea
d3d11.dll D3D11CreateDeviceAndSwapChain
ADVAPI32.dll AllocateAndInitializeSid
SetTokenInformation
SetThreadToken
CreateProcessAsUserW
DuplicateTokenEx
RegQueryValueExW
GetTokenInformation
RevertToSelf
RegEnumValueW
QueryServiceStatusEx
OpenServiceW
RegDeleteValueW
RegOpenKeyExW
InitializeSecurityDescriptor
FreeSid
OpenProcessToken
RegSetKeySecurity
RegEnumKeyExW
SetEntriesInAclW
PrivilegeCheck
OpenSCManagerW
CloseServiceHandle
RegQueryInfoKeyW
RegCloseKey
RegGetKeySecurity
AdjustTokenPrivileges
SetSecurityDescriptorDacl
LookupPrivilegeValueW
ntdll.dll RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
WINHTTP.dll WinHttpConnect
WinHttpReceiveResponse
WinHttpOpen
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpSendRequest
WinHttpOpenRequest
WinHttpCloseHandle
KERNEL32.dll GetSystemTimeAsFileTime
IsDebuggerPresent
IsProcessorFeaturePresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetFileAttributesExW
InitializeSListHead
WriteProcessMemory
GetCurrentProcess
WriteFile
TerminateProcess
GetModuleFileNameW
CreatePipe
SetFilePointer
SetEndOfFile
GetTempPathW
WaitForSingleObject
LocalAlloc
CreateFileW
GetFileAttributesW
OpenProcess
SetFileAttributesW
CreateToolhelp32Snapshot
MultiByteToWideChar
Sleep
GetLastError
Process32NextW
GetLocaleInfoEx
DeleteFileW
Process32FirstW
CloseHandle
GetSystemInfo
GetProcAddress
LocalFree
MoveFileExW
GetFileSize
ReadProcessMemory
CreateProcessW
GetModuleHandleW
WideCharToMultiByte
FindNextFileW
GetTickCount
MoveFileW
VirtualQueryEx
GetCurrentProcessId
GetCurrentThreadId
LoadLibraryA
FreeLibrary
CompareFileTime
K32GetMappedFileNameA
Thread32Next
Thread32First
SuspendThread
ResumeThread
GetModuleHandleA
GetTickCount64
GetThreadTimes
OpenThread
SetConsoleTextAttribute
SetConsoleTitleA
GetStdHandle
ExitProcess
AllocConsole
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
GetLocaleInfoA
QueryPerformanceFrequency
QueryPerformanceCounter
GetStartupInfoW
GetCommandLineW
SleepConditionVariableSRW
FindFirstFileExW
FindFirstFileW
GetTempFileNameW
AreFileApisANSI
GetFileInformationByHandleEx
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
FindClose
FormatMessageA
SetFileInformationByHandle
USER32.dll GetWindowRect
MapWindowPoints
SetWindowDisplayAffinity
MoveWindow
DefWindowProcW
GetWindowLongW
SetWindowLongW
SetForegroundWindow
GetKeyState
GetMessageExtraInfo
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
GetClientRect
PeekMessageW
SetCursorPos
IsWindowUnicode
ReleaseCapture
DispatchMessageW
GetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetAsyncKeyState
TranslateMessage
SHELL32.dll ShellExecuteW
SHGetFolderPathW
ole32.dll CoInitializeEx
MSVCP140.dll ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?_Xinvalid_argument@std@@YAXPEBD@Z
_Mtx_unlock
_Mtx_lock
?_Xbad_function_call@std@@YAXXZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
_Xtime_get_ticks
_Thrd_detach
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
_Query_perf_counter
??_7_Facet_base@std@@6B@
_Strxfrm
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Xlength_error@std@@YAXPEBD@Z
?id@?$collate@D@std@@2V0locale@2@A
?_Syserror_map@std@@YAPEBDH@Z
??_7facet@locale@std@@6B@
_Strcoll
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?tolower@?$ctype@D@std@@QEBADD@Z
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Facet_base@std@@UEAA@XZ
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
_Query_perf_frequency
?_Throw_Cpp_error@std@@YAXH@Z
?_Random_device@std@@YAIXZ
_Cnd_do_broadcast_at_thread_exit
SHLWAPI.dll PathStripPathW
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
D3DCOMPILER_43.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_copy
_CxxThrowException
__intrinsic_setjmp
__C_specific_handler
__std_exception_destroy
__current_exception_context
strchr
strstr
strrchr
longjmp
memcpy
memmove
memset
memchr
memcmp
__current_exception
api-ms-win-crt-stdio-l1-1-0.dll fclose
__stdio_common_vsprintf
fgetc
__stdio_common_vsscanf
_wfopen
__stdio_common_vsprintf_s
fwrite
__stdio_common_vfprintf
fflush
ftell
freopen_s
__acrt_iob_func
_set_fmode
fgetpos
setvbuf
__stdio_common_vswprintf_s
fputc
__p__commode
ungetc
_get_stream_buffer_pointers
fsetpos
fseek
fread
_fseeki64
fopen
api-ms-win-crt-heap-l1-1-0.dll free
_callnewh
realloc
_set_new_mode
malloc
api-ms-win-crt-string-l1-1-0.dll strncmp
wcscpy_s
_wcsicmp
strcmp
strncpy
towlower
tolower
api-ms-win-crt-runtime-l1-1-0.dll _wsystem
_errno
_register_thread_local_exe_atexit_callback
_c_exit
_exit
system
_initterm_e
_initterm
_get_wide_winmain_command_line
_initialize_wide_environment
_configure_wide_argv
exit
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
terminate
abort
_beginthreadex
_invoke_watson
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
api-ms-win-crt-convert-l1-1-0.dll strtoull
strtoll
strtod
strtol
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
sqrt
cosf
ceilf
sinf
acosf
roundf
_dsign
_dclass
pow
fmodf
sqrtf
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
localeconv
_configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Nov-10 13:35:14
Version 0.0
SizeofData 912
AddressOfRawData 0x155f38
PointerToRawData 0x154738

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2025-Nov-10 13:35:14
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1401562e8
EndAddressOfRawData 0x1401562f0
AddressOfIndex 0x14031e2b0
AddressOfCallbacks 0x140126cd0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140174040

RICH Header

XOR Key 0xe8f10562
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (35207) 1
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 36
Imports (35207) 6
C objects (VS2022 Update 6 (17.6.4) compiler 32537) 24
Imports (21202) 4
Imports (33140) 29
Total imports 503
C++ objects (LTCG) (35209) 38
Resource objects (35209) 1
Linker (35209) 1

Errors

Leave a comment

No comments yet.