fc5bbfcad8c7fc6e957a7e129dd7d380f04913ff57797959faa3ac0fd35c608a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-23 20:39:25
Detected languages English - United States

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • a.pvp.net
  • ac.pvp.net
  • ap.a.pvp.net
  • ap.vg.ac.pvp.net
  • auth.riotgames.com
  • br.vg.ac.pvp.net
  • cheatglobal.com
  • entitlements.auth.riotgames.com
  • eu.a.pvp.net
  • eu.vg.ac.pvp.net
  • google.com
  • https://cheatglobal.com
  • kr.a.pvp.net
  • kr.vg.ac.pvp.net
  • latam.vg.ac.pvp.net
  • na.a.pvp.net
  • na.vg.ac.pvp.net
  • pd.ap.a.pvp.net
  • pd.eu.a.pvp.net
  • pd.kr.a.pvp.net
  • pd.na.a.pvp.net
  • pool.ntp.org
  • riotgames.com
  • s.a.pvp.net
  • time.google.com
  • time.windows.com
  • valorant-api.com
  • vg.ac.pvp.net
  • windows.com
Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Possibly launches other programs:
  • CreateProcessW
  • CreateProcessA
  • CreateProcessWithTokenW
  • ShellExecuteW
  • ShellExecuteA
Uses Microsoft's cryptographic API:
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptCreateHash
  • CryptHashData
  • CryptDecodeObjectEx
  • CryptStringToBinaryA
  • CryptBinaryToStringA
  • CryptImportPublicKeyInfoEx2
Has Internet access capabilities:
  • InternetConnectA
  • InternetQueryOptionA
  • InternetSetOptionA
  • InternetReadFile
  • InternetOpenA
  • InternetCloseHandle
  • WinHttpSetOption
  • WinHttpQueryDataAvailable
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpSendRequest
  • WinHttpReceiveResponse
  • WinHttpOpen
  • WinHttpQueryHeaders
  • WinHttpReadData
  • WinHttpOpenRequest
  • WinHttpCloseHandle
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • DuplicateTokenEx
  • CheckTokenMembership
  • OpenProcessToken
  • AdjustTokenPrivileges
Interacts with services:
  • OpenServiceW
  • QueryServiceStatus
  • OpenSCManagerW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
  • OpenProcess
Interacts with the certificate store:
  • CertOpenStore
Malicious VirusTotal score: 22/70 (Scanned on 2026-08-24 02:33:13) APEX: Malicious
AVG: Win64:MalwareX-gen [Pws]
Avast: Win64:MalwareX-gen [Pws]
Avira: TR/W64.MalwareX
CrowdStrike: win/malicious_confidence_100% (D)
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
Elastic: malicious (high confidence)
F-Secure: Trojan.TR/W64.MalwareX
Google: Detected
Gridinsoft: Trojan.Heur!.02016023
Kaspersky: UDS:Trojan.Win32.GenericML.xnet
Kingsoft: malware.kb.a.770
Malwarebytes: Malware.AI.3977602356
McAfeeD: ti!FC5BBFCAD8C7
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!8055F7206A1E
alibabacloud: Trojan:Win/Wacatac.B9nj

Hashes

MD5 8055f7206a1ef2006ef744b09df10c6d 🔍
SHA1 ab91cb74eaad11715fe43679844c2085f966f8db 🔍
SHA256 fc5bbfcad8c7fc6e957a7e129dd7d380f04913ff57797959faa3ac0fd35c608a 🔍
SHA3 ed5404e3b746b1151c69c310a8e3c69930caef918799607fd92d81392cc9dae1 🔍
SSDeep 24576:4vZT0AivewuREIF2zIWZKMjMKJRhBMkayZww1m+gwy:4vZTQmwuREIF2zdoMjMK7L1md 🔍
Imports Hash 98184f3df3fc0152b01a76800210a593 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Aug-23 20:39:25
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9a400
SizeOfInitializedData 0x4d600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000065754 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xed000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a3dfb6bb288c8f5371cf8af0ac01c2df 🔍
SHA1 39185826a9244344044dcf5d20c9a64626ff0023 🔍
SHA256 e842511179edf68e5be098b573e796038ab4c2ed6769ace98cf1fc4c30268837 🔍
SHA3 feafff84b01ffb7e8cd865e305781335d35aafc816b695401146bc0ea6889357 🔍
VirtualSize 0x9a260
VirtualAddress 0x1000
SizeOfRawData 0x9a400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41714

.rdata

MD5 5cc639ed8802d339acd9355c7d6b37f2 🔍
SHA1 68153086a31cbc6e254a11337e91b8f7200899f9 🔍
SHA256 4d34c1d8b93231e523378e5c7cdd3edd96693e66c67cad16fabaad0cad584b29 🔍
SHA3 c99b5a933da2f526dce45139948706d532b4f480fbcdcb8555db74f86dcd4beb 🔍
VirtualSize 0x2b170
VirtualAddress 0x9c000
SizeOfRawData 0x2b200
PointerToRawData 0x9a800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.69556

.data

MD5 e9b471c29ad98efb421a908d1d9b70ce 🔍
SHA1 8bc77b1aafb1cbdbdddafcd89fe92b5eb1fde05a 🔍
SHA256 77c326ef15087668114371bfecac022c72cac6003ce09f40c28cfeda6dd49bef 🔍
SHA3 d9554b6c215c5cbe97adf27eb8069231e21563c3d0ee58a6d541b23eeb2b50af 🔍
VirtualSize 0x4de4
VirtualAddress 0xc8000
SizeOfRawData 0x2a00
PointerToRawData 0xc5a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.98063

.pdata

MD5 a48c9526e14bf760b48ab94ae78fc56c 🔍
SHA1 153ec6060c487d50825d0933daff2ff1be004f93 🔍
SHA256 03a10ba78b7c724dd60b4fbb21281d12b1d73abb8513f604e259e60cb6113c21 🔍
SHA3 8dff1cc1909d0dac891ae228435ba0d57fe9b47cfb048bc87afab35fbf5aacce 🔍
VirtualSize 0x6144
VirtualAddress 0xcd000
SizeOfRawData 0x6200
PointerToRawData 0xc8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8927

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0xd4000
SizeOfRawData 0x200
PointerToRawData 0xce600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 07b629e595e22ea83954343a5a455e9d 🔍
SHA1 65c98f15a23afe42f72a99671d8ec66efa64de11 🔍
SHA256 f50a45d6fef161cda3c739fe47f6b6d258f4f990118d77d73d5c93ce03d3a3b2 🔍
SHA3 ed4e66547148de3a79f97b1cccea0b456471dfdca17eb803471838948b828293 🔍
VirtualSize 0x16280
VirtualAddress 0xd5000
SizeOfRawData 0x16400
PointerToRawData 0xce800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.98221

.reloc

MD5 43cdde087b1352a63cc87aa129ea3038 🔍
SHA1 56d1e4355f1f93fbc5b1043c2022f0ab83563197 🔍
SHA256 0fd20356e16f5ab99e776f5df44c74ceab7a254cfa31ccead73ef5fb6588dc3b 🔍
SHA3 85058dd2304a3ca28289c0f4c5ab92396dfaac056f02f73332a6d3164649b16e 🔍
VirtualSize 0xd88
VirtualAddress 0xec000
SizeOfRawData 0xe00
PointerToRawData 0xe4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38132

Imports

KERNEL32.dll GetLastError
Process32NextW
CreateFileA
FileTimeToSystemTime
LoadLibraryA
QueryPerformanceFrequency
DeleteFileA
Process32FirstW
CloseHandle
GetLocalTime
FillConsoleOutputAttribute
Beep
GetProcAddress
SetFilePointerEx
CreateFileMappingA
LocalFree
ExitProcess
GetCurrentProcessId
CreateProcessW
FreeLibrary
CreateProcessA
GetSystemTimeAsFileTime
GetSystemTime
SetConsoleCursorPosition
QueryPerformanceCounter
GetTickCount
SetConsoleTitleW
ConnectNamedPipe
GetTickCount64
GetExitCodeProcess
SetEndOfFile
WriteConsoleW
HeapSize
SetStdHandle
GetProcessHeap
Sleep
MultiByteToWideChar
CreateToolhelp32Snapshot
OpenProcess
DisconnectNamedPipe
ReleaseMutex
GetFileAttributesW
CreateFileW
WaitForSingleObject
CreateMutexA
FindClose
GetEnvironmentVariableA
CreateMutexW
SetSystemTime
CreateNamedPipeW
GetModuleFileNameW
TerminateProcess
DeviceIoControl
OutputDebugStringA
ExpandEnvironmentStringsW
WriteFile
GetStdHandle
GetCurrentProcess
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetOEMCP
GetACP
IsValidCodePage
ReadConsoleW
HeapReAlloc
GetConsoleMode
GetConsoleOutputCP
GetTimeZoneInformation
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
VirtualProtect
FlsFree
FindNextFileW
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
GetFileSizeEx
FindFirstFileW
SetConsoleCtrlHandler
FillConsoleOutputCharacterA
GetModuleFileNameA
ReadFile
FlushFileBuffers
CreateDirectoryW
FlsSetValue
FlsGetValue
FlsAlloc
HeapFree
HeapAlloc
GetFileType
GetCommandLineW
GetCommandLineA
GetModuleHandleExW
FreeLibraryAndExitThread
ExitThread
CreateThread
LoadLibraryExW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RtlUnwind
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SleepConditionVariableSRW
WakeAllConditionVariable
GetCPInfo
CompareStringEx
DecodePointer
EncodePointer
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
FormatMessageA
GetLocaleInfoEx
FindFirstFileExW
GetFileAttributesExW
SetFileInformationByHandle
AreFileApisANSI
GetModuleHandleW
MoveFileExW
GetFileInformationByHandleEx
WideCharToMultiByte
InitOnceComplete
InitOnceBeginInitialize
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
GetCurrentThreadId
WaitForSingleObjectEx
GetExitCodeThread
LCMapStringEx
InitializeCriticalSectionEx
USER32.dll GetWindowThreadProcessId
MessageBoxW
GetShellWindow
GetAsyncKeyState
ADVAPI32.dll CloseServiceHandle
DuplicateTokenEx
CryptGetHashParam
ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenServiceW
CheckTokenMembership
FreeSid
OpenProcessToken
CryptDestroyHash
LookupPrivilegeValueW
AdjustTokenPrivileges
CryptAcquireContextW
QueryServiceStatus
CryptReleaseContext
OpenSCManagerW
AllocateAndInitializeSid
CreateProcessWithTokenW
CryptCreateHash
CryptHashData
SHELL32.dll ShellExecuteExW
ShellExecuteW
ShellExecuteA
bcrypt.dll BCryptOpenAlgorithmProvider
BCryptGenerateKeyPair
BCryptDecrypt
BCryptFinalizeKeyPair
BCryptGetProperty
BCryptDestroyKey
BCryptEncrypt
BCryptExportKey
BCryptFinishHash
BCryptDestroyHash
BCryptImportKeyPair
BCryptHashData
BCryptSetProperty
BCryptCreateHash
BCryptGenerateSymmetricKey
BCryptGenRandom
BCryptCloseAlgorithmProvider
CRYPT32.dll CryptDecodeObjectEx
CertCreateSelfSignCertificate
CertFreeCertificateContext
CryptStringToBinaryA
CryptBinaryToStringA
PFXExportCertStore
CertCloseStore
CertStrToNameA
CryptImportPublicKeyInfoEx2
CertOpenStore
WININET.dll InternetConnectA
InternetQueryOptionA
HttpOpenRequestA
InternetSetOptionA
HttpAddRequestHeadersA
InternetReadFile
InternetOpenA
HttpSendRequestA
InternetCloseHandle
HttpQueryInfoA
WINHTTP.dll WinHttpSetOption
WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSetTimeouts
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpOpen
WinHttpQueryHeaders
WinHttpReadData
WinHttpOpenRequest
WinHttpCloseHandle
WS2_32.dll htons
setsockopt
htonl
recv
accept
bind
closesocket
listen
inet_pton
WSAStartup
send
WSAGetLastError
socket
connect
Secur32.dll DeleteSecurityContext
FreeCredentialsHandle
EncryptMessage
FreeContextBuffer
DecryptMessage
QueryContextAttributesW
AcquireCredentialsHandleW
InitializeSecurityContextW
AcceptSecurityContext

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63272
Detected Filetype PNG graphic file
MD5 e20ad0dadfecd402f496f2721baebd5d 🔍
SHA1 e361b9ca0ec208fc881b54d6a7d01591168e716c 🔍
SHA256 e86855571de8788a8c2707469832bf014930f6fd93620a661bab21e85e145185 🔍
SHA3 fb944bb6a5338750bde12e3bfd4620b4208cdc283c2a2278a8d6f77264b22fdc 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3f5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.75183
Detected Filetype PNG graphic file
MD5 a93390c4ecc95e0894abe7f7daf52910 🔍
SHA1 2e23f22f0af194d42d34b3706fbeb5acd1746538 🔍
SHA256 16d6a1e2cccdfcd2adb1efc4b796af5def91aaadae60bb9f1c941b450a022666 🔍
SHA3 032a1f6b3da0c4087abc273546e9fc2b2e8b94918ce400f4ff490afb0061a3a0 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5c6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86292
Detected Filetype PNG graphic file
MD5 8cca48142310c3e1a351fecf52c4f438 🔍
SHA1 c26bd03bdcfd2a242c2001f10a9f095eae6f793a 🔍
SHA256 9441623227b8747e107bacfe0fb1fa3c805f0585e20340bb1fb0e680321a35ea 🔍
SHA3 3ed4bef083148ff8d8eea8a7a022465b7ab1e52dc3111cced27f1f4db823e1bd 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb25
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92682
Detected Filetype PNG graphic file
MD5 d2c47db09b80c37bf8f530daf749c4f8 🔍
SHA1 1091a8651ba44fec549a4ded0b8ee27c42c144cf 🔍
SHA256 1dbc8105d31eff9361dac6ebffd1e9afc22ab7f11fba0debe7dc4bbcd2526f21 🔍
SHA3 e26246731c5dbfd4a69ffc2a2a3cee82fdb559922eb2fb86092f3e30983e663d 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x11df
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95437
Detected Filetype PNG graphic file
MD5 f751d85563a1eedd2306c051289c14b4 🔍
SHA1 7a34e8be4e6269af2a15f3f08ee17d8799c82c6e 🔍
SHA256 46aac84df114cc089446aa9f4a1a100789595d34e917c26e440b3a9de5ea0343 🔍
SHA3 f07d77eec36f4bb5c03c75728937ae4ff35f9e478492b4232771eaafd20122db 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3f24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98238
Detected Filetype PNG graphic file
MD5 bd4d877282d1213727b42394b3de3043 🔍
SHA1 ad66195699fb2de283c450d11e6b906cbff5b4b6 🔍
SHA256 372e21bea27580699d091013b8a1638ed3164c2e5298ff592f758dcc335c3f17 🔍
SHA3 4d3104d984241cbd998ed913558f6373e0d5a7f5be6840052e4c252aeca31d7b 🔍

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xf632
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99273
Detected Filetype PNG graphic file
MD5 1290327f5990b01def46868a2ee0c787 🔍
SHA1 bbba1ebb4a3129b29e93f1ec9f517e528dfbe3ee 🔍
SHA256 1e229d8aa9f11fe28d828a33e2da3bf62e4e810230a0549bf7c9835a1c43fa3e 🔍
SHA3 5b2ff7937a2a9aa67df45474a944619f7418f1ab077647975a48d3aad1757940 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92127
Detected Filetype Icon file
MD5 cc2d373ab001d3a64967c16f1e54f7b3 🔍
SHA1 b9fbd87fb6c78c8e74165e8a35f0f50d1603ebc6 🔍
SHA256 623791f2c39f08d114f40a441a8322b165b4e995dff5accc74963ff23685ee74 🔍
SHA3 dafd01b7f6ad633876d41ec7374a7ab467cbf104fa3b4707a90b88a990812e85 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-23 20:39:25
Version 0.0
SizeofData 1052
AddressOfRawData 0xb7ca4
PointerToRawData 0xb64a4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-23 20:39:25
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400b8108
EndAddressOfRawData 0x1400b8110
AddressOfIndex 0x1400cb940
AddressOfCallbacks 0x14009ca30
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400c8180

RICH Header

XOR Key 0xf5d91a66
Unmarked objects 0
C++ objects (33145) 186
C objects (33145) 17
ASM objects (33145) 8
C objects (35207) 17
ASM objects (35207) 12
C++ objects (35207) 96
Imports (33145) 21
Total imports 288
C++ objects (LTCG) (35217) 1
Resource objects (35217) 1
151 1
Linker (35217) 1

Errors

Leave a comment

No comments yet.