fdb2a3ad1d350758ced5996a6aa847e516e0c41586d3c27cd8997572a7f345eb

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-24 18:39:29
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
CompanyName Real
FileDescription Real Setup
FileVersion 1.0.0.0
InternalName RealSetup
OriginalFilename RealSetup.exe
ProductName Real
ProductVersion 1.0.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • schtask
Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentControlSet\Services
  • CurrentVersion\Run
Accesses the WMI:
  • ROOT\Security
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • Izenpe.com
  • animationData.fr
  • api.github.com
  • cv.iptc.org
  • dotnet.microsoft.com
  • example.com
  • github.com
  • githubusercontent.com
  • go.microsoft.com
  • http://cv.iptc.org
  • http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia
  • http://www.w3.org
  • http://www.w3.org/1999/xlink
  • http://www.w3.org/2000/svg
  • http://www.w3.org/XML/1998/namespace
  • https://1.1.1.1
  • https://1.1.1.1/dns-query
  • https://8.8.8.8
  • https://8.8.8.8/dns-query
  • https://9.9.9.9
  • https://9.9.9.9/dns-query
  • https://aka.ms
  • https://api.github.com
  • https://api.github.com/repos/JohnnyMorganz/luau-lsp/releases/latest
  • https://api.projectreal.live
  • https://api.projectreal.live/
  • https://api.projectreal.live/installer/report
  • https://api.projectreal.live/update/check
  • https://api.projectreal.live/verify
  • https://ca.trufo.ai
  • https://ca.trufo.ai/c2pa-ca.crt03
  • https://ca.trufo.ai/root-ca.crt0
  • https://curl.se
  • https://discord.gg
  • https://dl.projectreal.live
  • https://dl.projectreal.live/
  • https://download.projectreal.live
  • https://download.projectreal.live/
  • https://download.projectreal.live/health.txt
  • https://download.projectreal.live/verify
  • https://github.com
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • https://go.microsoft.com/fwlink/p/?LinkId
  • https://ocsp.trufo.ai0
  • https://ocsp.trufo.ai0+
  • https://projectreal.gg
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/mozilla-firefox/firefox/refs/heads/release/security/nss/lib/ckfw/builtins/certdata.txt
  • https://trufo.ai
  • i.style.top
  • lottielab.com
  • microsoft.com
  • pool.ntp.org
  • raw.githubusercontent.com
  • style.top
  • this.animationData.fr
  • time.windows.com
  • windows.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses constants related to Blowfish
Uses known Diffie-Helman primes
Microsoft's Cryptography API
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegGetValueW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptDestroyHash
  • CryptDestroyKey
  • CryptGenRandom
  • CryptSetHashParam
  • CryptEnumProvidersW
  • CryptSignHashW
  • CryptDecrypt
  • CryptGetProvParam
  • CryptGetUserKey
  • CryptExportKey
  • CryptQueryObject
  • CryptBinaryToStringA
  • CryptMsgGetParam
  • CryptMsgClose
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Has Internet access capabilities:
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpOpenRequest
  • WinHttpSetTimeouts
  • WinHttpSetOption
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpCrackUrl
  • WinHttpCloseHandle
  • WinHttpQueryHeaders
  • WinHttpSetStatusCallback
  • WinHttpOpen
  • WinHttpConnect
Leverages the raw socket API to access the Internet:
  • recv
  • WSAWaitForMultipleEvents
  • WSAGetLastError
  • ntohs
  • WSAStartup
  • WSACleanup
  • accept
  • bind
  • closesocket
  • getpeername
  • getsockname
  • WSAResetEvent
  • WSAEventSelect
  • WSAEnumNetworkEvents
  • WSACreateEvent
  • WSACloseEvent
  • send
  • getsockopt
  • GetNameInfoW
  • ioctlsocket
  • htonl
  • freeaddrinfo
  • setsockopt
  • htons
  • connect
  • getaddrinfo
  • select
  • listen
  • WSASocketA
  • recvfrom
  • sendto
  • inet_addr
  • inet_ntoa
  • gethostbyaddr
  • gethostbyname
  • getservbyport
  • getservbyname
  • shutdown
  • __WSAFDIsSet
  • WSAIoctl
  • WSASetLastError
  • socket
Functions related to the privilege level:
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceConfigW
  • QueryServiceStatusEx
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Changes object ACLs:
  • SetNamedSecurityInfoW
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Interacts with the certificate store:
  • CertOpenSystemStoreA
  • CertOpenSystemStoreW
  • CertOpenStore
Malicious The PE is possibly a dropper. Resource 101 detected as a PE Executable.
Malicious VirusTotal score: 45/69 (Scanned on 2026-07-26 18:39:00) ALYac: Gen:Variant.Cerbu.278886
AVG: Win64:MalwareX-gen [Trj]
AhnLab-V3: Dropper/Win.MalwareX-gen.R782436
Antiy-AVL: Trojan/Win32.Sdum
Arcabit: Trojan.Cerbu.D44166
Avast: Win64:MalwareX-gen [Trj]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Cerbu.278886
Bkav: W32.Malware.70A35EC7
CAT-QuickHeal: Trojan.Sdum
CTX: exe.trojan.sdum
CrowdStrike: win/malicious_confidence_100% (W)
DrWeb: Trojan.Siggen33.3064
ESET-NOD32: Win64/GameTool_AGen.C potentially unsafe application
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Cerbu.278886 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: Adware/GameTool_AGen
GData: Gen:Variant.Cerbu.278886
Google: Detected
Gridinsoft: Trojan.Win64.Kryptik.dd!n
Ikarus: Trojan.W64.MalwareX
K7AntiVirus: Unwanted-Program ( 006e231d1 )
K7GW: Unwanted-Program ( 006e231d1 )
Kaspersky: HEUR:Trojan.Win32.Sdum.gen
Kingsoft: Win32.Trojan.Sdum.gen
Lionic: Trojan.Win32.Sdum.4!c
Malwarebytes: Trojan.Dropper
McAfeeD: Trojan:Win/Wacatac.ENR
MicroWorld-eScan: Gen:Variant.Cerbu.278886
Microsoft: Trojan:Win32/Egairtigado!rfn
Paloalto: generic.ml
Rising: Malware.Undefined!8.C (TFE:5:FtKAVutKhBM)
Skyhigh: Artemis
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.11e60d9a
TrellixENS: Artemis!78425792AD72
TrendMicro: Trojan.Win32.SDUM.USBLGO26
TrendMicro-HouseCall: Trojan.Win32.SDUM.USBLGO26
VBA32: Trojan.Sdum
VIPRE: Gen:Variant.Cerbu.278886
Varist: W64/ABTrojan.RURD-5069
Webroot: Win.Trojan.Gen
Yandex: Backdoor.Agent!X516lEh0cw8

Hashes

MD5 78425792ad729ddb3de8bca9e041cae1
SHA1 2d68c4f3d07ef419d3ea757a5e21d06df255915f
SHA256 fdb2a3ad1d350758ced5996a6aa847e516e0c41586d3c27cd8997572a7f345eb
SHA3 c2a680bcc5ab1f7025663d04e3e7e5987c25c26ad5260872b4f68329ed293a3b
SSDeep 393216:zeuglhZR8XZOkNBN5BWH8YexcpjwAhcI/OUYFOUY:68BNyvMI/o
Imports Hash c327fce46ae26ece63da230a41919e85

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Jul-24 18:39:29
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x478e00
SizeOfInitializedData 0xbd4600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000043F1E0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1053000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 cc24a3fa0a7a13305bd3e9d2d85018d4
SHA1 01e1426db4f751db568e6918108048f2783614e4
SHA256 e31255845f99a33cbd748a9badcabd64f67cd28c51e7b61feca1866d4a13f68a
SHA3 44e2002c6196631c17677b2dccaf51ec8410df28f1522dedbef73fdd5da03715
VirtualSize 0x478cfc
VirtualAddress 0x1000
SizeOfRawData 0x478e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.68425

.rdata

MD5 4d4b0ef781ee7a8ee79984ed203e215b
SHA1 adbb5f9cfdd1049927dc2b3f9efd7d25137e99e4
SHA256 66f7b52753542cfaa971f5f68c94e0f904c37e1605acd672e085229e2fffbea3
SHA3 9231fcf5bb8cf65a04046f285627808bde66e004fdbc3601407d0ebd40b116d0
VirtualSize 0x1ab022
VirtualAddress 0x47a000
SizeOfRawData 0x1ab200
PointerToRawData 0x479200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.92494

.data

MD5 7672699552cf9775545074270c12d745
SHA1 7dbdc22135f8999752c18c51a0605b71a9755901
SHA256 1e580c1ae42586b2203bdcd4edae9b5b67a241d4cc185c8710fd2a40e24d244d
SHA3 4e168fb5570a8dccb8edcbbf2473c154c44758b6e7060aa569d88c30f53bd4da
VirtualSize 0xf054
VirtualAddress 0x626000
SizeOfRawData 0xae00
PointerToRawData 0x624400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.15514

.pdata

MD5 0a06801d0222cf2ed300e2ca99c6e529
SHA1 66f4b7fca464ec497f48e1cdae3f3d87b143eed1
SHA256 69f1253d81059097f2e12705ba8fe2289bb88a570930c205dd1aed95763098b5
SHA3 a1e64f2271222c037fed213092560eb3ae8d0fbbb6febec0ba7ec0804a75d03e
VirtualSize 0x34218
VirtualAddress 0x636000
SizeOfRawData 0x34400
PointerToRawData 0x62f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.37908

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x66b000
SizeOfRawData 0x200
PointerToRawData 0x663600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 ac48becaccc9c22026735b6a11f25c6b
SHA1 50dd268a83a2b6113dde9f5daa0fcc42a6dbe94d
SHA256 d0a071e1b58ed7f1c7d95690dd27f0dedc4e02fc6615a677ac7ef4b89c6f2bc2
SHA3 52aa590d0ec3d9509773ab0a5eda000eb9b397138ecd0b026071cb892b065ef1
VirtualSize 0x9d7380
VirtualAddress 0x66c000
SizeOfRawData 0x9d7400
PointerToRawData 0x663800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.30465

.reloc

MD5 23a8c85d302a9fabafb90cc435e36e73
SHA1 3de057b44fb908d66c70d00e839e26791fbb6218
SHA256 b4478b89800e111451ae17ae69d9bbb52d74ac436c130067d5577609596b9976
SHA3 701630f9d7df24a82edb8214014af177d8ef20c83eff9303625ac4c27965d0af
VirtualSize 0xe6e8
VirtualAddress 0x1044000
SizeOfRawData 0xe800
PointerToRawData 0x103ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44016

Imports

ADVAPI32.dll OpenProcessToken
GetTokenInformation
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegDeleteTreeW
SetEntriesInAclW
SetNamedSecurityInfoW
RegEnumKeyExW
RegEnumValueW
RegGetValueW
CloseServiceHandle
OpenSCManagerW
OpenServiceW
QueryServiceConfigW
QueryServiceStatusEx
CryptAcquireContextW
CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptHashData
CryptDestroyHash
EventRegister
EventSetInformation
EventWriteTransfer
EventUnregister
CryptDestroyKey
CryptGenRandom
CryptSetHashParam
ReportEventW
CryptEnumProvidersW
CryptSignHashW
CryptDecrypt
RegisterEventSourceW
DeregisterEventSource
CryptGetProvParam
CryptGetUserKey
CryptExportKey
bcrypt.dll BCryptDestroyHash
BCryptFinishHash
BCryptHashData
BCryptCreateHash
BCryptCloseAlgorithmProvider
BCryptGetProperty
BCryptOpenAlgorithmProvider
CRYPT32.dll CertGetNameStringW
CryptQueryObject
CertGetCertificateChain
CertFreeCertificateChain
CertVerifyCertificateChainPolicy
CryptBinaryToStringA
CertFreeCertificateContext
CertGetEnhancedKeyUsage
CertGetIntendedKeyUsage
CertOpenSystemStoreA
CryptMsgGetParam
CryptMsgClose
CertFindCertificateInStore
CertOpenSystemStoreW
CertEnumCertificatesInStore
CertOpenStore
CertGetCertificateContextProperty
CertCloseStore
CertDuplicateCertificateContext
IPHLPAPI.DLL GetAdaptersAddresses
if_nametoindex
ncrypt.dll NCryptFinalizeKey
NCryptCreatePersistedKey
NCryptOpenStorageProvider
NCryptDeleteKey
NCryptFreeObject
WINTRUST.dll WinVerifyTrust
COMCTL32.dll InitCommonControlsEx
SHELL32.dll SHGetFolderPathW
ShellExecuteExW
ShellExecuteW
SHGetPathFromIDListW
SHBrowseForFolderW
ole32.dll CoCreateInstance
PropVariantClear
CoInitializeEx
CoTaskMemFree
CoInitialize
CreateStreamOnHGlobal
StringFromGUID2
CoUninitialize
CoCreateGuid
CoSetProxyBlanket
CoTaskMemAlloc
gdiplus.dll GdipGetImageWidth
GdipDisposeImage
GdipCloneImage
GdipSetPenLineJoin
GdipSetPenEndCap
GdipSetPenStartCap
GdipDeletePen
GdipCreatePen1
GdipCreateLineBrushI
GdipCreateSolidFill
GdipDeleteBrush
GdipCloneBrush
GdipDeleteRegion
GdipCreateRegionPath
GdipScaleMatrix
GdipGetImageHeight
GdipDeleteMatrix
GdipCreateMatrix
GdipTransformPath
GdipAddPathRectangle
GdipAddPathBezier
GdipAddPathArc
GdipAddPathLine
GdipClosePathFigure
GdipStartPathFigure
GdipDeletePath
GdipCreatePath
GdiplusShutdown
GdiplusStartup
GdipFree
GdipAlloc
GdipCreateImageAttributes
GdipCreateBitmapFromStream
GdipDisposeImageAttributes
GdipSetImageAttributesColorMatrix
GdipCreateFromHDC
GdipDeleteGraphics
GdipSetSmoothingMode
GdipSetPixelOffsetMode
GdipSetTextRenderingHint
GdipTranslateMatrix
GdipSetInterpolationMode
GdipDrawLine
GdipDrawEllipse
GdipDrawPath
GdipFillRectangleI
GdipFillEllipse
GdipFillPath
GdipDrawImageRectRect
GdipSetClipRegion
GdipResetClip
dwmapi.dll DwmSetWindowAttribute
WS2_32.dll recv
WSAWaitForMultipleEvents
WSAGetLastError
ntohs
WSAStartup
WSACleanup
accept
bind
closesocket
getpeername
getsockname
WSAResetEvent
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
GetNameInfoW
ioctlsocket
htonl
freeaddrinfo
setsockopt
htons
connect
getaddrinfo
select
listen
WSASocketA
recvfrom
sendto
inet_addr
inet_ntoa
gethostbyaddr
gethostbyname
getservbyport
getservbyname
shutdown
__WSAFDIsSet
WSAIoctl
WSASetLastError
socket
Secur32.dll InitSecurityInterfaceW
KERNEL32.dll IsDebuggerPresent
SetConsoleCtrlHandler
SetStdHandle
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
PeekNamedPipe
GetFileInformationByHandle
GetDriveTypeW
FreeLibraryAndExitThread
ExitThread
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
RtlUnwindEx
RtlLookupFunctionEntry
RaiseException
RtlPcToFileHeader
InitializeSListHead
GetStartupInfoW
SetUnhandledExceptionFilter
GetCPInfo
LCMapStringEx
DecodePointer
EncodePointer
SleepConditionVariableSRW
WakeAllConditionVariable
ExitProcess
GetFileInformationByHandleEx
CopyFile2
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFinalPathNameByHandleW
GetFileAttributesExW
FindFirstFileExW
GetCurrentDirectoryW
GetLocaleInfoEx
UnhandledExceptionFilter
HeapAlloc
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
HeapReAlloc
SetEndOfFile
GetConsoleOutputCP
IsProcessorFeaturePresent
GetStringTypeW
RtlCaptureContext
IsValidCodePage
GetOEMCP
GetTimeZoneInformation
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
WriteConsoleW
HeapSize
SetFilePointerEx
RtlVirtualUnwind
ConvertThreadToFiberEx
ConvertFiberToThread
GetACP
CreateSemaphoreA
GetExitCodeThread
ReleaseSemaphore
InitializeCriticalSection
LoadLibraryA
GetSystemDirectoryA
GetModuleHandleExW
FindNextFileW
FindFirstFileW
GetCommandLineW
CreateFileW
GetFileSizeEx
ReadFile
WriteFile
CloseHandle
GetLastError
ReleaseMutex
WaitForSingleObject
CreateMutexW
Sleep
GetCurrentProcess
GetCurrentProcessId
TerminateProcess
GetExitCodeProcess
CreateProcessW
OpenProcess
GetTickCount64
FreeLibrary
GetModuleFileNameW
GetProcAddress
LoadLibraryExW
LoadResource
LockResource
SizeofResource
FindResourceW
LocalFree
QueryFullProcessImageNameW
MoveFileExW
MultiByteToWideChar
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
GetTickCount
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
MulDiv
GetSystemDirectoryW
GetTempPathW
CreateDirectoryW
DeleteFileW
GetLocalTime
GetModuleHandleW
WideCharToMultiByte
GetDiskFreeSpaceExW
GetEnvironmentVariableW
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
SetLastError
FormatMessageA
SleepEx
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
QueryPerformanceCounter
QueryPerformanceFrequency
InitializeConditionVariable
GetFullPathNameW
GetEnvironmentVariableA
CompareFileTime
GetSystemTimeAsFileTime
VerSetConditionMask
VerifyVersionInfoW
WakeConditionVariable
SleepConditionVariableCS
WaitForSingleObjectEx
CreateThread
GetFileAttributesW
OutputDebugStringA
OutputDebugStringW
GetProcessHeap
HeapFree
LoadLibraryW
GetFileType
GetStdHandle
GetConsoleMode
SetConsoleMode
ReadConsoleA
ReadConsoleW
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
GetCurrentThreadId
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
VirtualProtect
VirtualFree
SwitchToFiber
DeleteFiber
CreateFiberEx
GetSystemTime
SystemTimeToFileTime
FindClose
RtlUnwind
USER32.dll SetForegroundWindow
MessageBoxW
EnumWindows
GetClassNameW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
SendMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
BringWindowToTop
SetCapture
ReleaseCapture
SetTimer
KillTimer
GetSystemMetrics
DrawTextW
UpdateWindow
GetDC
ReleaseDC
BeginPaint
EndPaint
InvalidateRect
SetWindowTextW
GetClientRect
ScreenToClient
PtInRect
LoadCursorW
LoadIconW
GetWindowLongPtrW
SetWindowLongPtrW
EnumChildWindows
GetProcessWindowStation
GetUserObjectInformationW
PostMessageW
ShowWindow
IsWindowVisible
IsIconic
GDI32.dll SetBkMode
SetTextColor
SelectObject
EnumFontFamiliesExW
DeleteObject
DeleteDC
CreateSolidBrush
CreateFontW
CreateCompatibleDC
CreateCompatibleBitmap
GetDeviceCaps
BitBlt
OLEAUT32.dll SysFreeString
VariantInit
VariantClear
SysAllocString
WINHTTP.dll WinHttpReceiveResponse
WinHttpSendRequest
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpSetOption
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCrackUrl
WinHttpCloseHandle
WinHttpQueryHeaders
WinHttpSetStatusCallback
WinHttpOpen
WinHttpConnect

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x81d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70358
Detected Filetype PNG graphic file
MD5 3d7ea167e30bcbdc2fa31d9dfaa13049
SHA1 ed834b4527f9233e7643af543021cd4af803a07f
SHA256 9b830c372e8b1bbc2b2e15041c8cc200a7d9badb669bd2b7996b20af13bd7195
SHA3 dcbdb8ea73e43ebc5b8d8eda5dfa021065fddba244c11cec70c4e3117084fe4e

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.54112
Detected Filetype PNG graphic file
MD5 9c420a570d51e2076a3ad3726488d94a
SHA1 f0c74cd41eb1afbac2a9f7c2ef7fb31b998fe7f6
SHA256 62debe35bb58d4d4acd6c913b835d238587f437177ad4386028687ea92397a1b
SHA3 33446f5829e3cab6437dbd9f3f308978801f440eeeba11981755431ca1a4590a

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x52f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.64947
Detected Filetype PNG graphic file
MD5 dce841f305927b16350c7cf4823b1b22
SHA1 d6b4dcecd74d2de7bfa7e65872b540d96bf73445
SHA256 ab5c4d82d348fd0b2961dcd1ea79f1411a8f024003d775d127bd8d21f49bdb23
SHA3 6b0e47bfee907d2b3017b274016e34302d8fc1be5dc9f862a0ab82e37c5f0fd4

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xe71
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76346
Detected Filetype PNG graphic file
MD5 3074bbbf8f58f2de9a2616c3e930addf
SHA1 519ad260f8f3664c75dfcf2272e1deeaf2d4cb0a
SHA256 610a0969e7b5f85442699fd00a8e632e1593b3756c7556768a0f8ad807d9d481
SHA3 21ee830769c6f6d255421953629ff0d4bc198f706c153ef9465420ef9a2e12df

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x153e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76112
Detected Filetype PNG graphic file
MD5 c80fded070d5cb7b7470bb187cfbcc86
SHA1 a8f72680f646bc8fc2565ba4531ca6d45001fd48
SHA256 09ea539a4c81663fe1c1f76f27e0581ca9f1bdfa67973de643256b1d5969d91b
SHA3 c990c9b049d0951f747c19f0cbbfece27b98ace11b6071708f205bc4461fbece

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4a0e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97502
Detected Filetype PNG graphic file
MD5 c2e3ab2a7d6be87870383a2e39321fa5
SHA1 fa98b9350372145af2e101a9e3a797814bf038aa
SHA256 b963e54c1bcf3ea5e37ab52002e68db4324640635a59e8a653047ffa8378cf2d
SHA3 a591c9ff387a0e31bda60013c6db8c22c87f68f57a39c481ffa51942e1437c73

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x810000
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.06792
Detected Filetype PE Executable
MD5 63bbb88e782a012f1ed7205763acf047
SHA1 f24402b5952b2d4a48640cb274dcd0d8241975b5
SHA256 45bddd53f8138278b93bb88731e5e2fbfbad4cc545578faea30b047b6bd639c5
SHA3 1699c747cd9ed65add0b57bf671735396da978fde47449491ecf3f23bdbe61c1

201

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x13d33
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95918
Detected Filetype PNG graphic file
MD5 f932874fef3e37d9157914f0b7670f8f
SHA1 f3b65aa52bd33b3260bef9b1112ee8ed891e52a3
SHA256 14ff2e916a88bc9e2beab7418df8f5f9e42f2a2d0283826d752eb5b1177efef1
SHA3 1259347e60650cb749f870b90dece0536a9e28c9991af2da749a194d78c6bfde

210

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x179597
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99301
Detected Filetype PNG graphic file
MD5 57bba85f4d5541b89c650ddfc814728b
SHA1 271cce70524654d7fc5e675ec2210ce345414c1c
SHA256 2945a042fc053bcf273b0b044689cc98321f6152ba158ae89cb3a198367703d8
SHA3 49f8861d591dc99d0793f2aec8e9109579d8cbe07b3ba660876c34ed219852f1

211

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0xba0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.72683
Detected Filetype PNG graphic file
MD5 5cf1a8ef1a6472052e114f605884865a
SHA1 d88d054513aa1b0b55f19cf952b42a7e06007e77
SHA256 14d616e51104812e375cb84c84cd1fbe425704c2a6498f85a52e9c92da150322
SHA3 c123c6e12a2ec50bcd538efeafb55a29a4accbbff20757eb8281253866df7bc4

301

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x291ca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27096
MD5 2efa233002285699cd2c63f8f511686f
SHA1 8dc8aa8f569688220ed6dd08968721faee2f102d
SHA256 9588432bec30c8ef8200bac4a67d8aaad881047bc2a6c9fa624d90ec96402410
SHA3 4d04728414696d105efe69a556db8e713524f90d0715bf874aa0dcfcd71decfe

302

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x7da5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.03028
MD5 82645b4974986e3b6b5b0c5d7a66846e
SHA1 e77e47e24d2c7c704e02c99a6f5db62cac28709d
SHA256 3c9dbc3544bcc588170b9a137bdb2b84224b16dc49a3b0b9e9971489d209b675
SHA3 3aa34f8da2f06768920dbf75472c0df34eaa34d4ecb25347568074940bd85fe6

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8021
Detected Filetype Icon file
MD5 a81d7363c069ec33cdb1196402ed27bf
SHA1 55a2bb17984cbe6a5c7d4b040779aeb7cf38abb6
SHA256 17b4f6ef4e39cba391d21014b80dd7674f4ad95f83971b72273e715507bef262
SHA3 23ef4fc6b7d474983c13e6165ab2062280fc488555d0e6a291ff76a0553297f4

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17496
MD5 114b32209c9b656b95cd1be00bb6ec2f
SHA1 e52498ff9d52594403c5ea29270bef818378f18f
SHA256 e891f1260cd8cba10e9ede273f4c4e612d89d59e80bf8e99c137d57ed27add3f
SHA3 1a964acc6e387afc7ec9d7dc69f0764937f52abf28c215fbac0a042fe2710a00

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Real
FileDescription Real Setup
FileVersion (#2) 1.0.0.0
InternalName RealSetup
OriginalFilename RealSetup.exe
ProductName Real
ProductVersion (#2) 1.0.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-24 18:39:29
Version 0.0
SizeofData 1264
AddressOfRawData 0x5ebab4
PointerToRawData 0x5eacb4

TLS Callbacks

StartAddressOfRawData 0x1405ebff0
EndAddressOfRawData 0x1405ec198
AddressOfIndex 0x140633f28
AddressOfCallbacks 0x14047af90
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x000000014043EF00
0x000000014043EDD0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14062da00

RICH Header

XOR Key 0xf6c68c8f
Unmarked objects 0
C++ objects (33145) 197
ASM objects (33145) 16
ASM objects (35721) 10
C objects (35721) 19
C++ objects (35721) 101
C objects (33145) 25
C objects (CVTCIL) (33145) 1
Imports (33145) 37
Total imports 465
Unmarked objects (#2) 48
C objects (36307) 1054
C++ objects (36231) 14
C objects (36231) 2
Resource objects (36231) 1
151 1
Linker (36231) 1

Errors

Leave a comment

No comments yet.