| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-01 19:58:31 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 3/71 (Scanned on 2026-09-01 19:59:49) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_60% (D) Microsoft: Trojan:Win32/Wacatac.B!ml |
| MD5 | c12377ed5dca7263da2ef34e7b685421 🔍 |
|---|---|
| SHA1 | 30cdff04290473d304892710f6b7c9612665c636 🔍 |
| SHA256 | 01b97b36ae5b2f25e6042dbd6895bc87e22596f6ede3f9610a31d139bcb3ad82 🔍 |
| SHA3 | f1c420c6784840b44e555956775a23247a369807c11898f5e44e7520a9ede504 🔍 |
| SSDeep | 12288:z53Nonypn4mv9EEPZH+7yckcYZvC33Exd1t:BNQKnpEExH+FMdi3EVt 🔍 |
| Imports Hash | 85420ab9d637dcc4b4bd92cf6da0fa77 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Sep-01 19:58:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x74c00 |
| SizeOfInitializedData | 0x84200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000071A70 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xfe000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 32b55d4b7dcfebca026a16d4c106d926 🔍 |
|---|---|
| SHA1 | c6d35e302157c656d4c35698107c4b80e65a9594 🔍 |
| SHA256 | 0f2c054abd169742c33fa70d23f17bd89e640e434295a834bd5b1ce38fe4bc6b 🔍 |
| SHA3 | afc8842eded4e9b7a2be0d482a596b8008792acd15139122c94ebf94161be06d 🔍 |
| VirtualSize | 0x74b71 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x74c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.49979 |
| MD5 | d53915f5c2ca5fe42fe2660c7de36048 🔍 |
|---|---|
| SHA1 | 31aad486478128d24e32d9abe8d504d73247021c 🔍 |
| SHA256 | 10b81f3bbcbc4e98fb7bacb6972ccac8f834e9a98c66817239aa731dbcc5ee22 🔍 |
| SHA3 | 6d738f251cd2f24405aaa7c6cc5cdb1e1f356e7d4ad69cebb60babb9cbf7ae83 🔍 |
| VirtualSize | 0x213de |
| VirtualAddress | 0x76000 |
| SizeOfRawData | 0x21400 |
| PointerToRawData | 0x75000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.88685 |
| MD5 | 68372460d3c26a759d6bbf48364937e1 🔍 |
|---|---|
| SHA1 | ef3fcca71efa6370e9c7ea2fcd6e9bb63032bf86 🔍 |
| SHA256 | abd0789f6fd86a06b88f18e07dc8e7c56a77593f3d619a354e4b2900b9d6ac4f 🔍 |
| SHA3 | 746568f7cb5c8912fea1ca1bb785194200c7d4cf374ad1f4d985f3213ca0724c 🔍 |
| VirtualSize | 0x5d160 |
| VirtualAddress | 0x98000 |
| SizeOfRawData | 0x5200 |
| PointerToRawData | 0x96400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.55134 |
| MD5 | e3d3dcadc43145d323b488ac770d093a 🔍 |
|---|---|
| SHA1 | f28c3e1d5ac7bb05f9943b5d71eb1aaab42e8867 🔍 |
| SHA256 | 976aeb324c1dac862c050187d3c3a86faa50aef3d95512897b062c7db87e1fc9 🔍 |
| SHA3 | 7ebc70339925ce32d10d6f9b01c159a0b552345b6277d009ae975a6a18af3a31 🔍 |
| VirtualSize | 0x53a0 |
| VirtualAddress | 0xf6000 |
| SizeOfRawData | 0x5400 |
| PointerToRawData | 0x9b600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.87485 |
| MD5 | 8364d32e12dd30ea59c819e967848c4a 🔍 |
|---|---|
| SHA1 | 112cc77d6bb41f6ec4b5e8d0a5007ded977afd26 🔍 |
| SHA256 | c504dafb10d85f054192c8136641fa251fe07ee20c6c893863e48ecd38b2624e 🔍 |
| SHA3 | 0fdf4872e373846db182f428560d3485fdc65a967506bb1dac61487581204116 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0xfc000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xa0a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71768 |
| MD5 | f06d618d00712091ea9781c3d8c1056d 🔍 |
|---|---|
| SHA1 | ee044ca0e1bf1df1e1850794d5d3308522f80966 🔍 |
| SHA256 | e170733c51e88988b61db9cffadde3102d9e00c032ca831fd2ec52dae0f4c6ff 🔍 |
| SHA3 | f656fb4ff8c1f23a74435d6818dcc5f83032815caae40da978c60fab3fe95546 🔍 |
| VirtualSize | 0x460 |
| VirtualAddress | 0xfd000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0xa0c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.39283 |
| WINHTTP.dll |
WinHttpQueryHeaders
WinHttpReceiveResponse WinHttpOpenRequest WinHttpSetOption WinHttpQueryDataAvailable WinHttpReadData WinHttpConnect WinHttpCloseHandle WinHttpSendRequest WinHttpOpen |
|---|---|
| USER32.dll |
wsprintfA
GetMonitorInfoA MonitorFromPoint SetWindowLongW GetWindowLongW SetLayeredWindowAttributes GetDpiForWindow LoadCursorA SetCursor ReleaseCapture SetCapture GetCapture GetClipboardData ReleaseDC LoadCursorW AdjustWindowRect KillTimer SetTimer SetWindowPos ShowWindow DestroyWindow CreateWindowExW RegisterClassExW UnregisterClassW DefWindowProcW PeekMessageW MessageBoxW DispatchMessageW GetCursorInfo GetWindow GetWindowThreadProcessId EnumWindows ClipCursor ScreenToClient ClientToScreen GetCursorPos GetClientRect GetSystemMetrics SendInput GetAsyncKeyState EmptyClipboard SetClipboardData CloseClipboard OpenClipboard IsWindowVisible SetWindowDisplayAffinity GetWindowDisplayAffinity IsWindow PostMessageW GetWindowLongPtrW SetWindowLongPtrW GetDC TrackMouseEvent TranslateMessage |
| GDI32.dll |
GetGlyphIndicesW
RemoveFontResourceExA CreateCompatibleDC SwapBuffers SetPixelFormat ChoosePixelFormat GetTextMetricsA SelectObject AddFontResourceExA GetGlyphOutlineW DeleteObject DeleteDC CreateFontA |
| ole32.dll |
CoInitializeEx
CoCreateInstance CoUninitialize CoTaskMemFree CoCreateFreeThreadedMarshaler |
| WindowsCodecs.dll |
WICConvertBitmapSource
|
| d2d1.dll |
#1
|
| DWrite.dll |
DWriteCreateFactory
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
DwmSetWindowAttribute |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod |
| api-ms-win-core-processenvironment-l1-1-0.dll |
GetEnvironmentStringsW
ExpandEnvironmentStringsA GetEnvironmentVariableA FreeEnvironmentStringsW GetCurrentDirectoryA |
| api-ms-win-core-file-l1-1-0.dll |
DeleteFileA
GetFileAttributesA CreateFileW WriteFile ReadFile DeleteFileW GetTempFileNameW FindNextFileA FindFirstFileA CreateDirectoryA GetFileSize CreateFileA FindClose |
| api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
|
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceFrequency
QueryPerformanceCounter |
| api-ms-win-core-synch-l1-2-0.dll |
SleepConditionVariableSRW
Sleep WakeAllConditionVariable |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetStartupInfoW
GetCurrentThreadId GetExitCodeProcess GetCurrentProcessId |
| api-ms-win-core-processthreads-l1-1-1.dll |
OpenProcess
FlushInstructionCache |
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemInfo
GetSystemTimeAsFileTime GetTickCount |
| api-ms-win-core-memory-l1-1-0.dll |
VirtualQueryEx
VirtualAllocEx VirtualFreeEx VirtualProtectEx ReadProcessMemory WriteProcessMemory |
| api-ms-win-core-libraryloader-l1-2-0.dll |
LoadLibraryExW
FreeLibrary GetProcAddress GetModuleHandleW GetModuleFileNameA GetModuleHandleA |
| api-ms-win-core-libraryloader-l1-2-1.dll |
LoadLibraryA
|
| api-ms-win-core-heap-l2-1-0.dll |
GlobalAlloc
GlobalFree |
| api-ms-win-core-heap-obsolete-l1-1-0.dll |
GlobalLock
GlobalUnlock |
| api-ms-win-core-psapi-ansi-l1-1-0.dll |
QueryFullProcessImageNameA
|
| api-ms-win-core-toolhelp-l1-1-0.dll |
Process32NextW
CreateToolhelp32Snapshot Process32FirstW |
| api-ms-win-core-string-l1-1-0.dll |
MultiByteToWideChar
WideCharToMultiByte |
| d3d11.dll |
D3D11CreateDevice
|
| api-ms-win-core-file-l1-2-0.dll |
GetTempPathW
|
| api-ms-win-core-debug-l1-1-0.dll |
OutputDebugStringA
|
| api-ms-win-core-namedpipe-l1-1-0.dll |
PeekNamedPipe
SetNamedPipeHandleState |
| WS2_32.dll |
WSAStartup
|
| api-ms-win-core-synch-l1-1-0.dll |
SetEvent
AcquireSRWLockExclusive CreateEventA ReleaseSRWLockExclusive CreateEventW WaitForSingleObject |
| d3d12.dll |
D3D12SerializeRootSignature
#101 |
| dxgi.dll |
CreateDXGIFactory1
|
| D3DCOMPILER_47.dll |
D3DCompile
|
| SHELL32.dll |
ShellExecuteA
SHGetFolderPathA |
| OPENGL32.dll |
glPixelStorei
glIsEnabled glGetIntegerv glGenTextures glEnable glTexParameteri glDeleteTextures wglDeleteContext glViewport glClearColor glClear wglMakeCurrent glTexSubImage2D glTexImage2D glDisable glBindTexture wglGetProcAddress wglCreateContext |
| KERNEL32.dll |
Module32FirstW
lstrcpynA Module32NextW |
| MSVCP140.dll |
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??7ios_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0_Lockit@std@@QEAA@H@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ??1_Lockit@std@@QEAA@XZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Throw_Cpp_error@std@@YAXH@Z _Cnd_do_broadcast_at_thread_exit _Mtx_unlock _Mtx_lock _Thrd_detach _Query_perf_frequency _Query_perf_counter ?uncaught_exceptions@std@@YAHXZ ?_Xout_of_range@std@@YAXPEBD@Z ?always_noconv@codecvt_base@std@@QEBA_NXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xbad_function_call@std@@YAXXZ ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z ?id@?$ctype@D@std@@2V0locale@2@A ??Bios_base@std@@QEBA_NXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAI@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEA_K@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Xinvalid_argument@std@@YAXPEBD@Z _Thrd_id _Thrd_join ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z ?_Xbad_alloc@std@@YAXXZ |
| VCRUNTIME140.dll |
__std_exception_destroy
__std_terminate __std_exception_copy memcpy _CxxThrowException __current_exception_context __current_exception __C_specific_handler memset memmove strstr memcmp |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-string-l1-1-0.dll |
strncpy_s
wcslen _strnicmp iswspace strncmp strlen strcmp strnlen _stricmp strncat_s _wcsicmp strpbrk |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free malloc |
| api-ms-win-crt-convert-l1-1-0.dll |
strtod
atoi _strtoui64 atof |
| api-ms-win-crt-stdio-l1-1-0.dll |
fopen_s
__stdio_common_vsprintf_s fflush __p__commode fgetc fgetpos fputc _get_stream_buffer_pointers __stdio_common_vsprintf __stdio_common_vfprintf fputs fread ungetc setvbuf _set_fmode fwrite _fseeki64 fclose fsetpos |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| api-ms-win-crt-runtime-l1-1-0.dll |
terminate
_beginthreadex _c_exit _seh_filter_exe _cexit _register_thread_local_exe_atexit_callback _get_narrow_winmain_command_line _crt_atexit _initterm _initterm_e exit _exit _invalid_parameter_noinfo _errno abort _register_onexit_function _initialize_onexit_table _set_app_type _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-math-l1-1-0.dll |
sqrtf
cosf __setusermatherr powf sinf ceilf expf fmod |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-core-errorhandling-l1-1-0.dll |
SetUnhandledExceptionFilter
GetLastError |
| api-ms-win-core-interlocked-l1-1-0.dll |
InterlockedPushEntrySList
InitializeSListHead |
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
| OLEAUT32.dll |
SysStringLen
GetErrorInfo SetErrorInfo SysFreeString |
| api-ms-win-core-heap-l1-1-0.dll |
HeapAlloc
GetProcessHeap HeapFree |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-01 19:58:31 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x89a0c |
| PointerToRawData | 0x88a0c |
| StartAddressOfRawData | 0x140089dc0 |
|---|---|
| EndAddressOfRawData | 0x140089dc8 |
| AddressOfIndex | 0x1400f5130 |
| AddressOfCallbacks | 0x140077068 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14009ac80 |
| XOR Key | 0x8c3b9ccc |
|---|---|
| Unmarked objects | 0 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 36 |
| Imports (35721) | 6 |
| Imports (VS2008 SP1 build 30729) | 80 |
| C objects (33145) | 1 |
| Imports (33145) | 25 |
| Total imports | 406 |
| C++ objects (36256) | 37 |
| Resource objects (36256) | 1 |
| Linker (36256) | 1 |
No comments yet.