| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-17 11:00:07 |
| TLS Callbacks | 3 callback(s) detected. |
| Debug artifacts |
Embedded COFF debugging symbols
|
| Suspicious | PEiD Signature: |
UPolyX V0.1 -> Delikon
HQR data file |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to RC5 or RC6 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 6335413 bytes of data starting at offset 0x1509c00. |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-07 07:47:24) | All the AVs think this file is safe. |
| MD5 | af281c8796141e6389680d197877558d 🔍 |
|---|---|
| SHA1 | 4a8af734a6fb6c391bfd0504020266984d706975 🔍 |
| SHA256 | 006a4607e297b33a3cb4f0d32125d69e1aff7edec9365e0bb885eba0a69a375f 🔍 |
| SHA3 | 48821e1e96d859dc277779d41bc70f08f5ed0298a01ac4f7882c0b2e84d281b0 🔍 |
| SSDeep | 196608:Dm9k3uNaBs4VHHM1Aug3VzfB1xtzlbdb8M6p+HizsjH4xZTva:Sm+NEJzJHVHb81FzsjH4xZTva 🔍 |
| Imports Hash | 7707ca55e47b7a84a3e10a7921d7b92e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 2026-May-17 11:00:07 |
| PointerToSymbolTable | 0x1509c00 |
| NumberOfSymbols | 70783 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xce7200 |
| SizeOfInitializedData | 0x822600 |
| SizeOfUninitializedData | 0x600 |
| AddressOfEntryPoint | 0x0000000000001420 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1510000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1b22c6c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 3cc221ca5dd60c802c448889014a09a1 🔍 |
|---|---|
| SHA1 | 78cb0ef820d1957e128f8a46d6ab7fb57aa040ce 🔍 |
| SHA256 | 8d04870ad6fafcffb664d7f1b3cf87f2ef4a283221ae822b85d52c722c4a9485 🔍 |
| SHA3 | efac455ff5994ed97edd4dd92b9de385ddf3af1c9e1282a4ecb02d589d6b9635 🔍 |
| VirtualSize | 0xce70a0 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xce7200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.42646 |
| MD5 | d262d19ab8c2e7cf64589e59ad2967bb 🔍 |
|---|---|
| SHA1 | 3156b9bd321e44e53f3826e691942309f43b4711 🔍 |
| SHA256 | 760693e7805637774d8a3e3b4c4d78cc691eab13c63ea43a3588cb59810d8de3 🔍 |
| SHA3 | bcc8054f973ac0e63d0efbdc966965a8083e003fe6e085c4e6f346bfae52efed 🔍 |
| VirtualSize | 0x3d70 |
| VirtualAddress | 0xce9000 |
| SizeOfRawData | 0x3e00 |
| PointerToRawData | 0xce7600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.60685 |
| MD5 | 4f29926728e7315ba08fd77ade0c47a4 🔍 |
|---|---|
| SHA1 | 62e31f62fdb08797dd5570f3bc8475c97b856783 🔍 |
| SHA256 | 40ec0abb079a65ca1fa96d4c5a8ef021b1618f1bc8c0734856eb3b9506e10173 🔍 |
| SHA3 | b49e39f9d16746f4e0cf9133e4d915ba1d577a5642ca585d2ffeaacf7b56ff45 🔍 |
| VirtualSize | 0x6fd920 |
| VirtualAddress | 0xced000 |
| SizeOfRawData | 0x6fda00 |
| PointerToRawData | 0xceb400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.29589 |
| MD5 | 6f9178cc115e551495786b0d88614fab 🔍 |
|---|---|
| SHA1 | 540c907ca25789fa614ff02aef674a95dc1d772d 🔍 |
| SHA256 | fe80ce929ff5c1feac482b849af09e143565846182da2c9461e0c7bd2d878a7b 🔍 |
| SHA3 | 1328e678723dccaecdbf0681ccd2d5b9fcf6655b7c21ec45c58ae1e3e2999b1a 🔍 |
| VirtualSize | 0x49518 |
| VirtualAddress | 0x13eb000 |
| SizeOfRawData | 0x49600 |
| PointerToRawData | 0x13e8e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.74717 |
| MD5 | 7bfce6d8652bb5043a9bd2425ce44345 🔍 |
|---|---|
| SHA1 | 2c293887379b9a5b9f724b3ac2c4c4f2acfa12a1 🔍 |
| SHA256 | 5bf378292615c7cc1475f24197d7f8263de2b2875a5b2ebd33ef193860271725 🔍 |
| SHA3 | eec0f1bdb145b0b16472676a10e13abd771133c29041e6e57e5fe5535b014cb0 🔍 |
| VirtualSize | 0xc16d4 |
| VirtualAddress | 0x1435000 |
| SizeOfRawData | 0xc1800 |
| PointerToRawData | 0x1432400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.67997 |
| MD5 | d41d8cd98f00b204e9800998ecf8427e 🔍 |
|---|---|
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍 |
| SHA3 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍 |
| VirtualSize | 0x460 |
| VirtualAddress | 0x14f7000 |
| SizeOfRawData | 0 |
| PointerToRawData | 0 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| MD5 | 85bfd2ae49b876b0a8212cbd715f43ad 🔍 |
|---|---|
| SHA1 | 9e5009158890be9481cc2e2381ee9dd50d5915c8 🔍 |
| SHA256 | e587e03fae3de359e8a6f7186bf59a782e80e6feb3c86a4e40d854d6a9c983ac 🔍 |
| SHA3 | d1d1f65c09762568bc9c33f28176a4abed352ab5aa3d680a2ceaac8ddbb39f75 🔍 |
| VirtualSize | 0x4198 |
| VirtualAddress | 0x14f8000 |
| SizeOfRawData | 0x4200 |
| PointerToRawData | 0x14f3c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.97775 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x10 |
| VirtualAddress | 0x14fd000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x14f7e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 8812c64f4e91a3e7838172ff6dc70f09 🔍 |
|---|---|
| SHA1 | c05bbad543cf40e24eaa27fceb9c71cd499aa1af 🔍 |
| SHA256 | 42111168c79afda5283cac435a598f0003bbae5e9fd954ecf514044622c64443 🔍 |
| SHA3 | d0bc2364ccdc8cf8a104d89df43ec09e33648c0b32e47cc8926305dedd9c2d30 🔍 |
| VirtualSize | 0x11a0c |
| VirtualAddress | 0x14fe000 |
| SizeOfRawData | 0x11c00 |
| PointerToRawData | 0x14f8000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.49187 |
| advapi32.dll |
ImpersonateAnonymousToken
RevertToSelf |
|---|---|
| gdi32.dll |
ChoosePixelFormat
DescribePixelFormat SetPixelFormat SwapBuffers |
| imm32.dll |
ImmAssociateContextEx
ImmGetCompositionStringW ImmGetContext ImmReleaseContext ImmSetCandidateWindow ImmSetCompositionWindow |
| kernel32.dll |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| ntdll.dll |
NtCreateFile
NtOpenFile NtReadFile NtWriteFile RtlNtStatusToDosError |
| ole32.dll |
OleInitialize
RegisterDragDrop RevokeDragDrop |
| opengl32.dll |
wglCreateContext
wglDeleteContext wglGetCurrentContext wglGetCurrentDC wglGetProcAddress wglMakeCurrent wglShareLists |
| user32.dll |
CloseClipboard
CloseTouchInputHandle CountClipboardFormats EmptyClipboard EnumClipboardFormats GetActiveWindow GetAsyncKeyState GetClipboardData GetClipboardFormatNameW GetKeyState GetKeyboardLayout GetKeyboardState GetRawInputData GetRawInputDeviceInfoW GetTouchInputInfo MapVirtualKeyExW MapVirtualKeyW OpenClipboard RegisterClipboardFormatW RegisterRawInputDevices RegisterTouchWindow ReleaseCapture SendInput SetCapture SetClipboardData ToUnicode ToUnicodeEx TrackMouseEvent VkKeyScanW |
| userenv.dll |
GetUserProfileDirectoryW
|
| uxtheme.dll |
SetWindowTheme
|
| ws2_32.dll |
GetHostNameW
WSACleanup WSADuplicateSocketW WSAGetLastError WSARecv WSASend WSASocketW WSAStartup accept bind closesocket connect freeaddrinfo getaddrinfo getpeername getsockname getsockopt ioctlsocket listen recv recvfrom select send sendto setsockopt shutdown |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| bcryptprimitives.dll |
ProcessPrng
|
| kernel32.dll (#2) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| kernel32.dll (#3) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| kernel32.dll (#4) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmGetColorizationColor DwmSetWindowAttribute |
| dwrite.dll |
DWriteCreateFactory
|
| gdi32.dll (#2) |
ChoosePixelFormat
DescribePixelFormat SetPixelFormat SwapBuffers |
| kernel32.dll (#5) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| user32.dll (#2) |
CloseClipboard
CloseTouchInputHandle CountClipboardFormats EmptyClipboard EnumClipboardFormats GetActiveWindow GetAsyncKeyState GetClipboardData GetClipboardFormatNameW GetKeyState GetKeyboardLayout GetKeyboardState GetRawInputData GetRawInputDeviceInfoW GetTouchInputInfo MapVirtualKeyExW MapVirtualKeyW OpenClipboard RegisterClipboardFormatW RegisterRawInputDevices RegisterTouchWindow ReleaseCapture SendInput SetCapture SetClipboardData ToUnicode ToUnicodeEx TrackMouseEvent VkKeyScanW |
| combase.dll |
CoCreateFreeThreadedMarshaler
CoTaskMemFree |
| kernel32.dll (#6) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| rpcrt4.dll |
UuidCreate
|
| api-ms-win-core-winrt-error-l1-1-0.dll |
RoOriginateErrorW
|
| kernel32.dll (#7) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| oleaut32.dll |
GetErrorInfo
SetErrorInfo |
| kernel32.dll (#8) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| oleaut32.dll (#2) |
GetErrorInfo
SetErrorInfo |
| comctl32.dll |
DefSubclassProc
RemoveWindowSubclass SetWindowSubclass |
| kernel32.dll (#9) |
AddVectoredExceptionHandler
CancelIo CompareStringOrdinal CopyFileExW CreateDirectoryW CreateEventW CreateFileMappingA CreateFileMappingW CreateFileW CreateHardLinkW CreatePipe CreateProcessW CreateSymbolicLinkW CreateThread CreateToolhelp32Snapshot CreateWaitableTimerExW DeleteFileW DeleteProcThreadAttributeList DeviceIoControl ExitProcess FindClose FindFirstFileExW FindNextFileW FlushViewOfFile FreeEnvironmentStringsW GetCommandLineW GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW GetEnvironmentVariableW GetExitCodeProcess GetFileAttributesW GetFileInformationByHandle GetFileInformationByHandleEx GetFileSizeEx GetFileType GetFinalPathNameByHandleW GetFullPathNameW GetModuleHandleW GetOverlappedResult GetProcessId GetStdHandle GetSystemDirectoryW GetSystemTimePreciseAsFileTime GetTempPathW GetWindowsDirectoryW GlobalAlloc GlobalLock GlobalSize GlobalUnlock HeapReAlloc InitOnceBeginInitialize InitOnceComplete InitializeProcThreadAttributeList LoadLibraryA LoadLibraryW LockFileEx MapViewOfFile Module32FirstW Module32NextW MoveFileExW QueryPerformanceCounter QueryPerformanceFrequency ReadConsoleW ReadFile ReadFileEx RemoveDirectoryW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind SetCurrentDirectoryW SetEnvironmentVariableW SetFileAttributesW SetFileInformationByHandle SetFilePointerEx SetFileTime SetHandleInformation SetLastError SetThreadStackGuarantee SetUnhandledExceptionFilter SetWaitableTimer SleepEx SwitchToThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TlsAlloc TlsFree TlsGetValue TlsSetValue UnlockFile UnmapViewOfFile UpdateProcThreadAttribute VirtualProtect WaitForMultipleObjects WaitForSingleObject WriteConsoleW WriteFileEx |
| ole32.dll (#2) |
OleInitialize
RegisterDragDrop RevokeDragDrop |
| shell32.dll |
DragFinish
DragQueryFileW SHCreateItemFromParsingName SHGetKnownFolderPath |
| shlwapi.dll |
AssocQueryStringW
|
| KERNEL32.dll |
DeleteCriticalSection
EnterCriticalSection InitializeCriticalSection LeaveCriticalSection RaiseException RtlUnwindEx VirtualQuery __C_specific_handler |
| msvcrt.dll |
__getmainargs
__initenv __iob_func __set_app_type __setusermatherr _amsg_exit _cexit _commode _errno _fmode _fpreset _hypot _initterm abort acos atexit calloc exit exp fprintf free frexp ldexp log10 malloc memcmp memcpy memmove memset signal strerror strlen strncmp tan vfprintf wcslen |
| ntdll.dll (#2) |
NtCreateFile
NtOpenFile NtReadFile NtWriteFile RtlNtStatusToDosError |
| StartAddressOfRawData | 0x1414fd000 |
|---|---|
| EndAddressOfRawData | 0x1414fd008 |
| AddressOfIndex | 0x1414f739c |
| AddressOfCallbacks | 0x1413ea8f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x0000000140C8E8F0
0x0000000140CE7010 0x0000000140CE6FF0 |
No comments yet.