2d1880299228a2b294bbf4b8ac7a1c5a96f7fddb2b824484a66d7c3813a1211c

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-27 23:52:57
Detected languages English - United States
Debug artifacts C:\Users\rayan\Downloads\Zen\ext_momentum\build\release.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • assetdelivery.roblox.com
  • github.com
  • githubusercontent.com
  • http://www.microsoft.com
  • http://www.microsoft.com/typography/fonts/
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://exo-api.tf
  • https://github.com
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/
  • https://thumbnails.roblox.com/v1/users/avatar-headshot?userIds
  • https://thumbnails.roblox.com/v1/users/avatar?userIds
  • https://tr.rbxcdn.com
  • https://tr.rbxcdn.com/
  • https://tr.rbxcdn.com/30DAY-Avatar-6B832677CF30D1735A665B7B2ED1FDBF-Png/720/720/Avatar/Webp/noFilter
  • microsoft.com
  • raw.githubusercontent.com
  • rbxcdn.com
  • roblox.com
  • thumbnails.roblox.com
  • tr.rbxcdn.com
  • www.microsoft.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Possibly launches other programs:
  • ShellExecuteW
  • system
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualProtectEx
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpConnect
  • WinHttpSendRequest
  • WinHttpReadData
  • WinHttpSetOption
  • WinHttpQueryDataAvailable
  • URLOpenBlockingStreamA
  • URLDownloadToCacheFileW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
  • OpenProcess
  • ReadProcessMemory
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 19f0da29f221354f49f0035d42accba9 🔍
SHA1 9e94263b7177ba8456c2d73e50cc98f06e0c0338 🔍
SHA256 2d1880299228a2b294bbf4b8ac7a1c5a96f7fddb2b824484a66d7c3813a1211c 🔍
SHA3 7c72980e314a36622a9ce8a7316bf1b07e5a96943babfb6bf19776114caa50b7 🔍
SSDeep 24576:zN0qxvS4NKXNxQv37ySWXQ84I8kmwnmS0zsCj3ELsWiG6zI9I93rf:k4mNxg73LI8kZzbi3WSG6zIa 🔍
Imports Hash a75cb9e97fe1bd2ae62b01c2bbb6c0e0 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-27 23:52:57
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x115400
SizeOfInitializedData 0x93000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000010B560 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1ac000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 5b836853ae855f780e85ad13e4010f36 🔍
SHA1 058648ee99574dae5494d454f0fe497e89f82cd2 🔍
SHA256 9e3f24bbc9a1151962edd87af704a7d9d9418efd458c3861e3196845f55190ad 🔍
SHA3 72077f1a60ce6f715622bdf6931926e8757e7dca0b7a04a59dcafa900e6558c0 🔍
VirtualSize 0x115321
VirtualAddress 0x1000
SizeOfRawData 0x115400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48757

.rdata

MD5 a6f0c4f2b7f47703c0103aefef6034d9 🔍
SHA1 0539fecfa55f67ccfc27849049fac601b051bff1 🔍
SHA256 98d345564c042d4f73fc4078aa9b36ddf7f35f3e5949490c3abbcf1cf9914c1a 🔍
SHA3 041a84851064c360f313f7900422cb044edd00078e107a77258dce85aa0e68e4 🔍
VirtualSize 0x78b4e
VirtualAddress 0x117000
SizeOfRawData 0x78c00
PointerToRawData 0x115800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.70847

.data

MD5 0d6b2b2949c9aff33fe2bd6ca4a3c1bb 🔍
SHA1 9b11ae0b8b02d3ce1322ffefe6244c63f0b72bed 🔍
SHA256 567439f1c8c3e811a4315fab30d6b7d0b3cf924ac80bb78b1a6050aea37d463f 🔍
SHA3 713ac15dd1163d1668a7ad5ec2d9cb3c5bdbe67c24be760139c245b5e25c801d 🔍
VirtualSize 0xf508
VirtualAddress 0x190000
SizeOfRawData 0xbc00
PointerToRawData 0x18e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.10802

.pdata

MD5 42374100a5e677d221d9b18a1566568b 🔍
SHA1 d091389a80ddb680815cd7fb44ddbb59f19581bd 🔍
SHA256 ef2ff63943da97cf6f560fc1f6e5737a15d524fb0c18079238cd71376b60824a 🔍
SHA3 6fa55075c5ab5aa9645852b74fd8d589f8f019e9d572831fc85824eabffd9c60 🔍
VirtualSize 0x9ffc
VirtualAddress 0x1a0000
SizeOfRawData 0xa000
PointerToRawData 0x19a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.12945

.rsrc

MD5 5406c9ec4a4fe40c746c48adb8a649f9 🔍
SHA1 aef6773b0470bad178dd1b565708b48e156ffe65 🔍
SHA256 b1bd12fd2b22ecb8cb359ae77b6a375cd5eade10ceea9708befec14079981374 🔍
SHA3 33695ba4f4c177204829644e6802e2b7f19089ba25a0a1b32ab07bbfacbc43e8 🔍
VirtualSize 0x1e8
VirtualAddress 0x1aa000
SizeOfRawData 0x200
PointerToRawData 0x1a4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 938a913ba2064198b101ffc4894b93e2 🔍
SHA1 97f05a9e569343ac7a00c119f5b331dfdb737d03 🔍
SHA256 a7c31baa55ea5533c2ca8394ad4f45118a6831435791ca0e6b0f8f377f375c81 🔍
SHA3 26ae98c2aed5e3d9ce3257a0ffea80604ef028f2fd6e3bb58bf24a817dbb5ac8 🔍
VirtualSize 0xa8c
VirtualAddress 0x1ab000
SizeOfRawData 0xc00
PointerToRawData 0x1a4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.05585

Imports

freetype.dll FT_Get_Char_Index
FT_Done_Size
FT_Done_Library
FT_Done_Face
FT_GlyphSlot_Embolden
FT_Render_Glyph
FT_New_Library
FT_New_Size
FT_Select_Charmap
FT_GlyphSlot_Oblique
FT_New_Memory_Face
FT_Load_Glyph
FT_Add_Default_Modules
FT_Activate_Size
FT_Request_Size
dbghelp.dll MiniDumpWriteDump
WINHTTP.dll WinHttpOpenRequest
WinHttpCloseHandle
WinHttpOpen
WinHttpReceiveResponse
WinHttpConnect
WinHttpSendRequest
WinHttpReadData
WinHttpSetOption
WinHttpQueryDataAvailable
KERNEL32.dll FindClose
GetLocaleInfoEx
FormatMessageA
FindFirstFileExW
CreateFile2
AreFileApisANSI
FindFirstFileW
FindNextFileW
LocalFree
GetFileInformationByHandleEx
ReleaseSRWLockExclusive
CreateDirectoryW
SetConsoleCtrlHandler
SetConsoleTextAttribute
SetConsoleTitleA
GetStdHandle
WriteConsoleA
WriteFile
GetEnvironmentVariableW
CreateMutexW
CreateFileW
GetCurrentThreadId
CreateToolhelp32Snapshot
Sleep
GetLastError
GetFileAttributesExW
Process32NextW
Process32FirstW
CloseHandle
MoveFileExW
ExitProcess
GetModuleHandleW
GetConsoleWindow
SetConsoleOutputCP
IsDebuggerPresent
SetUnhandledExceptionFilter
GetModuleHandleA
GetProcAddress
SetLastError
OutputDebugStringA
K32GetModuleFileNameExW
K32EnumProcessModulesEx
LoadLibraryA
GetSystemInfo
VirtualProtectEx
VirtualAllocEx
FlushInstructionCache
VirtualFreeEx
VirtualQueryEx
GetModuleFileNameA
SetThreadPriority
GetFileAttributesA
GetCurrentThread
QueryPerformanceFrequency
QueryPerformanceCounter
ReadFile
MultiByteToWideChar
GetFileSize
OpenProcess
QueryFullProcessImageNameA
GetCurrentProcess
GetCurrentProcessId
GetSystemTimeAsFileTime
GetProcessTimes
K32EnumProcessModules
ReadProcessMemory
lstrcmpiW
GetExitCodeProcess
GetLocaleInfoA
VerSetConditionMask
FreeLibrary
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
InitOnceBeginInitialize
AcquireSRWLockExclusive
SleepConditionVariableSRW
WakeAllConditionVariable
InitializeSListHead
SetFileInformationByHandle
FlushFileBuffers
InitOnceComplete
USER32.dll RegisterClassW
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
GetCapture
TrackMouseEvent
GetKeyboardLayout
SetCapture
SetCursor
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
GetWindowRect
DestroyWindow
SetWindowPos
MessageBoxA
GetSystemMetrics
UnregisterClassW
RegisterClassExW
SetWindowDisplayAffinity
GetForegroundWindow
MoveWindow
SetLayeredWindowAttributes
SetFocus
LoadIconW
LoadCursorW
SetWindowLongW
PostQuitMessage
SetForegroundWindow
GetWindowThreadProcessId
keybd_event
GetClassNameA
GetWindowTextA
EnumWindows
GetClientRect
SendInput
ClientToScreen
SetCursorPos
ScreenToClient
GetAsyncKeyState
FindWindowA
PeekMessageW
DispatchMessageW
ShowWindow
GetCursorPos
DefWindowProcW
CreateWindowExW
TranslateMessage
GDI32.dll CreateSolidBrush
SHELL32.dll ShellExecuteW
SHGetFolderPathA
SHGetKnownFolderPath
ole32.dll CoInitialize
CoInitializeEx
CoUninitialize
CoTaskMemFree
CoCreateInstance
MSVCP140.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
??7ios_base@std@@QEBA_NXZ
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@V?$fpos@U_Mbstatet@@@2@@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
_Cnd_register_at_thread_exit
?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
_Cnd_unregister_at_thread_exit
_Query_perf_frequency
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Query_perf_counter
_Xtime_get_ticks
_Thrd_join
_Mtx_unlock
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?good@ios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
_Thrd_yield
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?_Random_device@std@@YAIXZ
?_Xbad_function_call@std@@YAXXZ
_Thrd_detach
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
_Cnd_broadcast
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??Bios_base@std@@QEBA_NXZ
_Cnd_wait
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
WINMM.dll timeBeginPeriod
mciSendStringW
d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
urlmon.dll URLOpenBlockingStreamA
URLDownloadToCacheFileW
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll _CxxThrowException
__current_exception_context
__current_exception
memset
memmove
memcpy
memchr
memcmp
_purecall
strchr
__std_exception_destroy
__std_exception_copy
__std_terminate
__C_specific_handler
wcsrchr
strstr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
_wfopen
fseek
ftell
__stdio_common_vswprintf_s
freopen
fputc
__p__commode
__acrt_iob_func
fflush
__stdio_common_vswprintf
__stdio_common_vsprintf_s
__stdio_common_vsscanf
fclose
_get_stream_buffer_pointers
_fseeki64
fread
fsetpos
ungetc
setvbuf
fgetpos
__stdio_common_vsprintf
fwrite
__stdio_common_vsnprintf_s
__stdio_common_vfprintf
fgetc
api-ms-win-crt-heap-l1-1-0.dll malloc
_set_new_mode
free
_callnewh
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
toupper
tolower
strncpy_s
strcmp
strlen
strncmp
strncpy
strcpy_s
wcslen
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
api-ms-win-crt-runtime-l1-1-0.dll _exit
_register_thread_local_exe_atexit_callback
_errno
__p___argc
_c_exit
abort
terminate
system
_beginthreadex
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__p___argv
_get_initial_narrow_environment
_initterm
_initterm_e
exit
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-math-l1-1-0.dll lroundf
floorf
asinf
powf
atan2f
sinf
expf
sqrtf
tanf
acosf
logf
ceilf
roundf
cosf
fmodf
nearbyint
_dsign
__setusermatherr
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-convert-l1-1-0.dll atof
strtoll
strtod
strtoull
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
___lc_codepage_func

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-27 23:52:57
Version 0.0
SizeofData 84
AddressOfRawData 0x17753c
PointerToRawData 0x175d3c
Referenced File C:\Users\rayan\Downloads\Zen\ext_momentum\build\release.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-27 23:52:57
Version 0.0
SizeofData 20
AddressOfRawData 0x177590
PointerToRawData 0x175d90

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-27 23:52:57
Version 0.0
SizeofData 912
AddressOfRawData 0x1775a4
PointerToRawData 0x175da4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-27 23:52:57
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x140177958
EndAddressOfRawData 0x140177960
AddressOfIndex 0x14019bc54
AddressOfCallbacks 0x140118218
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140190040

RICH Header

XOR Key 0xae21628c
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
C objects (35721) 10
C++ objects (35721) 42
ASM objects (35721) 6
Imports (35721) 6
C objects (33145) 1
C objects (CVTCIL) (33145) 1
Imports (33145) 26
Imports (36244) 5
Total imports 488
C++ objects (LTCG) (36244) 51
Resource objects (36244) 1
Linker (36244) 1

Errors

Leave a comment

No comments yet.