| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-18 00:00:50 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 11/71 (Scanned on 2026-08-18 00:53:28) |
APEX:
Malicious
CrowdStrike: win/malicious_confidence_90% (D) ESET-NOD32: Win64/Riskware.GameHack.BO application Elastic: malicious (high confidence) Google: Detected Ikarus: Trojan.Win64.Krypt Microsoft: Trojan:Win32/Phonzy.B!ml Rising: Trojan.Kryptik@AI.86 (RDML:+dS/R+m1U17YB4CzpLwkfw) SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence huorong: Trojan/Agent.cfs |
| MD5 | d10c2abfa8e967505ad076e845ebd294 🔍 |
|---|---|
| SHA1 | ba93caff66b97f836129157c346067d7bb2ca9a1 🔍 |
| SHA256 | 1596e5b0cc74f2cf623303907ac09956a8b8adb2244873fbe67adf65d88caf03 🔍 |
| SHA3 | 0ea74ff67d96f275e0366fb64364adf6ab4c03ff76632516b8b89e208b0197d3 🔍 |
| SSDeep | 98304:5WB223mEC+ts8TvWS6k0pLM5KgJy7SlG:WmYTvWS6k0pLM5f9l 🔍 |
| Imports Hash | c419a4df1525bdfccabce328c6f45906 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-18 00:00:50 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x242e00 |
| SizeOfInitializedData | 0x1ac200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000224AA0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3f4000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 9d145a026380e40423fd0ab342e8ad17 🔍 |
|---|---|
| SHA1 | 7da621e233c11669dd59b82303de103d72968746 🔍 |
| SHA256 | 7544d7bd586cb09feeccb8b28d74706908f013e12a046e10985819a2e732f282 🔍 |
| SHA3 | 573a1557b2334e4f543a114c4ff3e0319cecfbff2cb78a062a26cf4ac91d7330 🔍 |
| VirtualSize | 0x242de8 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x242e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50587 |
| MD5 | 4085b125b9637301339e8228eff3db7c 🔍 |
|---|---|
| SHA1 | 2d4ad1ca3c75e130d731ec2c83fc4a454e3615a2 🔍 |
| SHA256 | 23396c09d2739cdeb496f421862b8031f5caed4d3d68d7ed72056a41c4115d9d 🔍 |
| SHA3 | 3ab12c5ce97e69cfabf7a4c5b642bce55ebe4d71aedea8c5b61234f0d1e5b6b0 🔍 |
| VirtualSize | 0x1232e8 |
| VirtualAddress | 0x244000 |
| SizeOfRawData | 0x123400 |
| PointerToRawData | 0x243200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.84287 |
| MD5 | 31cfc696af013c2afe88bf4b65d68868 🔍 |
|---|---|
| SHA1 | 00375ba9a464eac1e1e30f18c82dc02848ce769b 🔍 |
| SHA256 | fa1156c31c41a4bfb47e0ab6927476cd102748e08b2557699ed47b3c63512d00 🔍 |
| SHA3 | 0216c056d3139cef108ef598c19f2d5bd570f75c2fc4fc706ef4041f74656769 🔍 |
| VirtualSize | 0x70200 |
| VirtualAddress | 0x368000 |
| SizeOfRawData | 0x2f200 |
| PointerToRawData | 0x366600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.55805 |
| MD5 | cb72b33f37c5ac7c28a5dd64ce0ea4fc 🔍 |
|---|---|
| SHA1 | c9aa69809288539874fd3597c5ab40ec25c0a7c9 🔍 |
| SHA256 | b2aa81ab5cd7d27bc889162b872f965320ecd66885f814faa2c6ed4a06404014 🔍 |
| SHA3 | 47c1952f3182cc603a946740cd93dba4201a4d2eb5a3e4bf95015d3309a94a1d 🔍 |
| VirtualSize | 0x1668c |
| VirtualAddress | 0x3d9000 |
| SizeOfRawData | 0x16800 |
| PointerToRawData | 0x395800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.27059 |
| MD5 | 3a264634321ff905c43ec34d1643bdd3 🔍 |
|---|---|
| SHA1 | a765cb547706a846486396e3809f336ef1d8d271 🔍 |
| SHA256 | 8f910d3f60597280ee420be6f6af8744467ca116301058f497425159a7b4c23f 🔍 |
| SHA3 | 78aa879379be4c9054cdd149c9b4fa8671b9250e4c1486c3ca7bfc8bc805282a 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x3f0000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x3ac000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.69612 |
| MD5 | 7eb3c02afa28d7030511cc4cede470f4 🔍 |
|---|---|
| SHA1 | b7b1bc290f9b1538e59f569bdb4e389f01dddcd6 🔍 |
| SHA256 | 75ea6f1d2d378198e10ac62685498a864c338d1c9bdff9e05381030ca1aecb19 🔍 |
| SHA3 | d435003d9d42052e550a9d6ee8e6fd33ebaabf3e1ca7714d2ef539ff7ad1acb0 🔍 |
| VirtualSize | 0x2124 |
| VirtualAddress | 0x3f1000 |
| SizeOfRawData | 0x2200 |
| PointerToRawData | 0x3ac200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.4233 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| WINHTTP.dll |
WinHttpOpenRequest
WinHttpReadData WinHttpOpen WinHttpReceiveResponse WinHttpQueryHeaders WinHttpCloseHandle WinHttpSendRequest WinHttpSetTimeouts WinHttpQueryDataAvailable WinHttpConnect |
| WININET.dll |
InternetOpenA
InternetOpenUrlA InternetCloseHandle InternetReadFile |
| D3DCOMPILER_47.dll |
D3DCompile
|
| api-ms-win-core-libraryloader-l1-2-0.dll |
GetModuleHandleA
GetModuleFileNameA GetProcAddress GetModuleHandleW LoadLibraryExW FreeLibrary |
| api-ms-win-core-localization-l1-2-0.dll |
FormatMessageA
GetLocaleInfoEx FormatMessageW GetLocaleInfoA |
| api-ms-win-core-string-l1-1-0.dll |
WideCharToMultiByte
MultiByteToWideChar |
| api-ms-win-core-libraryloader-l1-2-1.dll |
LoadLibraryW
LoadLibraryA |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
QueryPerformanceFrequency |
| api-ms-win-core-sysinfo-l1-2-0.dll |
VerSetConditionMask
GetSystemTimePreciseAsFileTime |
| api-ms-win-core-heap-l2-1-0.dll |
GlobalFree
GlobalAlloc LocalFree |
| api-ms-win-core-heap-obsolete-l1-1-0.dll |
GlobalLock
GlobalUnlock |
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetTickCount
GetTickCount64 GetSystemTimeAsFileTime GetSystemInfo GetSystemDirectoryW |
| api-ms-win-core-kernel32-legacy-l1-1-2.dll |
Process32First
Process32Next |
| api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
OpenProcess FlushInstructionCache |
| api-ms-win-core-toolhelp-l1-1-0.dll |
CreateToolhelp32Snapshot
Process32NextW Process32FirstW |
| api-ms-win-core-synch-l1-2-0.dll |
SleepConditionVariableSRW
InitOnceComplete Sleep InitOnceBeginInitialize WakeAllConditionVariable |
| api-ms-win-core-psapi-ansi-l1-1-0.dll |
QueryFullProcessImageNameA
K32GetModuleFileNameExA |
| api-ms-win-core-handle-l1-1-0.dll |
DuplicateHandle
CloseHandle |
| api-ms-win-ntuser-sysparams-l1-1-0.dll |
GetSystemMetrics
|
| api-ms-win-core-console-l3-2-0.dll |
GetConsoleWindow
|
| api-ms-win-core-memory-l1-1-0.dll |
VirtualProtect
VirtualProtectEx VirtualAllocEx ReadProcessMemory VirtualFreeEx VirtualQueryEx WriteProcessMemory VirtualQuery |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetCurrentProcess
SwitchToThread SetThreadPriority GetProcessId GetCurrentThreadId OpenProcessToken TerminateProcess GetCurrentThread GetCurrentProcessId ExitProcess |
| api-ms-win-core-processenvironment-l1-1-0.dll |
GetEnvironmentVariableA
GetStdHandle GetCommandLineA |
| api-ms-win-core-console-l1-1-0.dll |
SetConsoleMode
GetConsoleMode |
| api-ms-win-core-file-l1-2-2.dll |
AreFileApisANSI
GetVolumeInformationA |
| api-ms-win-core-debug-l1-1-0.dll |
IsDebuggerPresent
OutputDebugStringW |
| api-ms-win-core-debug-l1-1-1.dll |
CheckRemoteDebuggerPresent
|
| api-ms-win-core-registry-l1-1-0.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyExA |
| api-ms-win-core-processtopology-obsolete-l1-1-0.dll |
SetThreadAffinityMask
|
| api-ms-win-mm-time-l1-1-0.dll |
timeGetTime
timeBeginPeriod |
| api-ms-win-core-errorhandling-l1-1-0.dll |
GetLastError
SetLastError UnhandledExceptionFilter SetUnhandledExceptionFilter |
| api-ms-win-core-psapi-l1-1-0.dll |
K32GetModuleBaseNameW
|
| api-ms-win-core-com-l1-1-0.dll |
CoInitializeEx
CoUninitialize CoCreateFreeThreadedMarshaler CoCreateInstance |
| api-ms-win-security-lsalookup-ansi-l2-1-0.dll |
LookupPrivilegeValueA
|
| api-ms-win-security-base-l1-1-0.dll |
AdjustTokenPrivileges
|
| KERNEL32.dll |
CreateFileMappingA
UnmapViewOfFile MapViewOfFile GetProcessHeap HeapFree HeapAlloc ReadFile GetFileSizeEx CreateFileA Module32First Module32Next K32EnumProcessModulesEx |
| USER32.dll |
GetDesktopWindow
ShowCursor mouse_event keybd_event MapVirtualKeyA SendInput SetWindowTextA GetWindowThreadProcessId GetWindowTextLengthW DefWindowProcW DispatchMessageA GetWindowRect DestroyWindow IsWindowVisible CreateWindowExW UnregisterClassW GetClassNameA RegisterClassExW ShowWindow IsWindow SetWindowLongA SetWindowDisplayAffinity GetMonitorInfoA MoveWindow EnumWindows SetLayeredWindowAttributes TranslateMessage LoadIconA PeekMessageA FindWindowA UpdateWindow IsIconic GetWindowTextW GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetKeyState GetMessageExtraInfo LoadCursorA GetDC MonitorFromWindow ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos PostQuitMessage |
| GDI32.dll |
GetDeviceCaps
CreateSolidBrush |
| SHELL32.dll |
SHGetFolderPathA
ShellExecuteA |
| MSVCP140.dll |
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z _Thrd_hardware_concurrency _Cnd_signal _Cnd_wait _Cnd_register_at_thread_exit ?__ExceptionPtrRethrow@@YAXPEBX@Z ?__ExceptionPtrCurrentException@@YAXPEAX@Z ?__ExceptionPtrDestroy@@YAXPEAX@Z ?__ExceptionPtrToBool@@YA_NPEBX@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z ?__ExceptionPtrCreate@@YAXPEAX@Z _Cnd_unregister_at_thread_exit ??0task_continuation_context@Concurrency@@AEAA@XZ ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z ?_ReportUnobservedException@details@Concurrency@@YAXXZ ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ _Cnd_broadcast _Thrd_join _Thrd_id ?always_noconv@codecvt_base@std@@QEBA_NXZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z _Thrd_detach _Cnd_do_broadcast_at_thread_exit ?_Random_device@std@@YAIXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xbad_function_call@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A _Mtx_unlock _Query_perf_counter _Mtx_lock ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z ?_Throw_Cpp_error@std@@YAXH@Z _Query_perf_frequency ??1_Facet_base@std@@UEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ??1_Locinfo@std@@QEAA@XZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ??0facet@locale@std@@IEAA@_K@Z ??1facet@locale@std@@MEAA@XZ ?tolower@?$ctype@D@std@@QEBADD@Z ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z _Strcoll ??_7facet@locale@std@@6B@ ?id@?$collate@D@std@@2V0locale@2@A ?id@?$ctype@D@std@@2V0locale@2@A ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?_Id_cnt@id@locale@std@@0HA ?_Xbad_alloc@std@@YAXXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Strxfrm ??_7_Facet_base@std@@6B@ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmSetCompositionWindow ImmGetContext |
| CRYPT32.dll |
CertFreeCertificateChain
CryptStringToBinaryW PFXImportCertStore CryptDecodeObjectEx CertAddCertificateContextToStore CertFindExtension CertOpenStore CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertGetNameStringW CertFreeCertificateContext CertGetCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject |
| WS2_32.dll |
__WSAFDIsSet
WSAIoctl socket setsockopt recv htons getsockname getpeername connect sendto inet_ntop WSASetLastError select inet_pton WSAGetLastError closesocket WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt ioctlsocket gethostname accept htonl recvfrom getaddrinfo ntohs freeaddrinfo bind listen |
| bcrypt.dll |
BCryptGenRandom
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception
wcschr _CxxThrowException memcmp memchr memset memmove __current_exception_context longjmp strrchr _purecall __C_specific_handler strchr strstr __std_exception_copy __std_exception_destroy __intrinsic_setjmp memcpy |
| api-ms-win-crt-runtime-l1-1-0.dll |
_invalid_parameter_noinfo_noreturn
_invalid_parameter_noinfo abort exit terminate _configure_narrow_argv _beginthreadex __sys_errlist _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _register_thread_local_exe_atexit_callback system _errno _get_initial_narrow_environment _initterm _invoke_watson _initterm_e _c_exit __p___argv __p___argc __sys_nerr _exit |
| api-ms-win-crt-math-l1-1-0.dll |
sinf
powf __setusermatherr pow logf _fdopen roundf fmodf _dclass _fdclass acosf asinf ldexp lroundf atan2f ceilf sqrtf sqrt cosf _dsign floorf |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
strncmp toupper strcspn wcspbrk iswspace isalnum _stricmp _wcsicmp wcsncmp strpbrk wcsncpy strcpy_s tolower strncpy _strdup strspn |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
strtof strtoull strtoll strtod atoi wcstombs atof strtoul |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
fflush fclose ungetc setvbuf fgetpos __p__commode fgetc _read _write _fileno _close fseek _set_fmode __stdio_common_vfprintf fputc __stdio_common_vsprintf_s fsetpos _lseeki64 _fseeki64 _get_stream_buffer_pointers __stdio_common_vsscanf _wopen fwrite fread fputs __stdio_common_vsprintf _wfopen ftell feof fgets |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
rand |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
malloc _callnewh free calloc realloc |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64
strftime _time64 _localtime64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_wstat64
_unlock_file _fstat64 remove _unlink _lock_file |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
_configthreadlocale localeconv |
| api-ms-win-core-file-l1-1-0.dll |
GetFileType
FindNextFileW FindClose FindFirstFileExW CreateFileW GetFileAttributesExW SetFileInformationByHandle FindFirstFileW CreateDirectoryW |
| api-ms-win-core-synch-l1-1-0.dll |
DeleteCriticalSection
AcquireSRWLockShared WaitForSingleObjectEx ReleaseSRWLockExclusive WaitForSingleObject EnterCriticalSection SleepEx CreateEventW SetEvent LeaveCriticalSection InitializeCriticalSectionEx AcquireSRWLockExclusive ReleaseSRWLockShared InitializeCriticalSection |
| api-ms-win-core-file-l2-1-0.dll |
GetFileInformationByHandleEx
MoveFileExW |
| api-ms-win-security-cryptoapi-l1-1-0.dll |
CryptReleaseContext
CryptAcquireContextW CryptCreateHash CryptEncrypt CryptImportKey CryptDestroyKey CryptGetHashParam CryptDestroyHash CryptHashData |
| api-ms-win-core-namedpipe-l1-1-0.dll |
PeekNamedPipe
|
| api-ms-win-core-synch-l1-2-1.dll |
WaitForMultipleObjects
|
| api-ms-win-core-kernel32-legacy-l1-1-1.dll |
VerifyVersionInfoW
|
| api-ms-win-security-systemfunctions-l1-1-0.dll |
SystemFunction036
|
| api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlLookupFunctionEntry
RtlVirtualUnwind RtlCaptureContext |
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
InterlockedPushEntrySList |
| OLEAUT32.dll |
SetErrorInfo
SysFreeString SysStringLen GetErrorInfo |
| api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-18 00:00:50 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x32ffb8 |
| PointerToRawData | 0x32f1b8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-18 00:00:50 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140330370 |
|---|---|
| EndAddressOfRawData | 0x140330440 |
| AddressOfIndex | 0x1403978e0 |
| AddressOfCallbacks | 0x140245798 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140368f40 |
| XOR Key | 0xaa05c3dc |
|---|---|
| Unmarked objects | 0 |
| 253 (35207) | 8 |
| C objects (35207) | 10 |
| C++ objects (35207) | 42 |
| ASM objects (35207) | 6 |
| Imports (35207) | 8 |
| C objects (33523) | 43 |
| C objects (VS2022 Update 6 (17.6.4) compiler 32535) | 123 |
| C++ objects (34436) | 5 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (VS2008 SP1 build 30729) | 136 |
| Imports (33145) | 32 |
| Imports (21202) | 3 |
| Total imports | 707 |
| C++ objects (LTCG) (35228) | 81 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.