| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Sep-03 23:46:30 |
| Detected languages |
English - United States
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to SHA512 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 21/70 (Scanned on 2026-09-04 20:31:23) |
APEX:
Malicious
AVG: FileRepMalware [Misc] Avast: FileRepMalware [Misc] ClamAV: Win.Malware.Lazy-10033364-0 CrowdStrike: win/malicious_confidence_90% (W) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: Win64/Riskware.GameHack.BO application Elastic: malicious (high confidence) GData: Win64.Trojan.Agent.1KW164 Google: Detected Malwarebytes: Malware.AI.2583404916 McAfeeD: ti!4B1AF6F9668A Microsoft: Trojan:Win32/Sabsik.EN.A!ml Paloalto: generic.ml Rising: Trojan.Kryptik@AI.90 (RDML:37H17pC6fR6q3T8eijkZYw) SentinelOne: Static AI - Suspicious PE Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!FA26BA12D6D0 Varist: W64/ABTrojan.MYHA-6886 huorong: Trojan/Agent.cfs |
| MD5 | fa26ba12d6d06c3144ae608d41221ae0 🔍 |
|---|---|
| SHA1 | 0f4bcd18546512fbee374ec8a35e500e954a2830 🔍 |
| SHA256 | 4b1af6f9668acb1f62b26f0254e059f510251320a763e60c4ee2740a6ec89378 🔍 |
| SHA3 | 3c528eb36c2056e982f28495de1199d9c3da36f86ddaf3df47cb4f206782fea4 🔍 |
| SSDeep | 98304:wFUD4VwdVOoSsUkfUS+DlrpvavA2Tf7Sl:TV7hTUS+DlrpvavIl 🔍 |
| Imports Hash | c5af04328bade5f54f71027bd5810182 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Sep-03 23:46:30 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x264c00 |
| SizeOfInitializedData | 0x235e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000245C00 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x49e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 2ac10241065323f3039d1bd2ee196216 🔍 |
|---|---|
| SHA1 | 878bbfde17a1ecce74bb9c5a07f3ae682b6dc73b 🔍 |
| SHA256 | d4d2f193443f612f69ae5b4a20984b60aabb8d7845fbd94733be620806c04e6f 🔍 |
| SHA3 | cfe77cc1e92bba7a1cc80e301ffbec12e0c28914a8156e1165d50650ac708201 🔍 |
| VirtualSize | 0x264b88 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x264c00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50241 |
| MD5 | bf9e922c2233c2e08405f15e672ad6b2 🔍 |
|---|---|
| SHA1 | adadb47c8600ce14e38afdf4da304b2207333314 🔍 |
| SHA256 | 047c1b1a52854293323028c62c0ade82eb77c609164934395de4f29cc812ee01 🔍 |
| SHA3 | 568df9e3e47da6523d37d62397acf08406dfc82c8e70c1413da585636bf4f0ac 🔍 |
| VirtualSize | 0x13964e |
| VirtualAddress | 0x266000 |
| SizeOfRawData | 0x139800 |
| PointerToRawData | 0x265000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.87735 |
| MD5 | 3231e198646b9697864caad57c69acf4 🔍 |
|---|---|
| SHA1 | fecd2d04b32a0f7d7b918e5b958e6668ec4c4965 🔍 |
| SHA256 | bc44e5cc89ae2ede3bc6813f1f804435a28a846a2ef58ec9ed67da1e1a953bef 🔍 |
| SHA3 | 8bc2ba07257b17fd7aec4b11d9b460f643b82345291a85af097e7b3118b061d1 🔍 |
| VirtualSize | 0xe2ff8 |
| VirtualAddress | 0x3a0000 |
| SizeOfRawData | 0xa1c00 |
| PointerToRawData | 0x39e800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 6.73466 |
| MD5 | b5c0b2af5aecf030b911416aa15922e7 🔍 |
|---|---|
| SHA1 | e0e97d2db824a9e7e7d0ed907cb2423273ff3a52 🔍 |
| SHA256 | 8dccbf4591e8b24b491d03c0bcab74833cf7b83d73fb106f089af57ad6bd7e4d 🔍 |
| SHA3 | b77236b78211b5e1bac92a71e74ae67b28978a7a8ecc48452474955b5a619b7a 🔍 |
| VirtualSize | 0x16ecc |
| VirtualAddress | 0x483000 |
| SizeOfRawData | 0x17000 |
| PointerToRawData | 0x440400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.31123 |
| MD5 | a64d0ab84c36f15999853a31d7e5caaa 🔍 |
|---|---|
| SHA1 | 515344d2864e1976d7d7d162cc5daa198a3b903a 🔍 |
| SHA256 | 83d680bf75a3d5cbfca35fa84de05cd5e0765538e1557b83d1a38ecca23ff3bb 🔍 |
| SHA3 | 6684ba3eba4c750ca2fd6b7261f23d0e2c02a0a71f7a604f0505ea46f23c8252 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x49a000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x457400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71134 |
| MD5 | 26e1355b9bcbf32b4128cd859b9c545b 🔍 |
|---|---|
| SHA1 | 54c5a01cd1cdb641ab0cc0c8e03cc4ee48025284 🔍 |
| SHA256 | 9613ebc666d4e9819ee206ed52b92d1e47ae0427f766e6908fbf7310b70a7839 🔍 |
| SHA3 | fc07b79bc3f40fa87f36607a3a78758e0a42654e23b55fc73c32f72bce970561 🔍 |
| VirtualSize | 0x22e0 |
| VirtualAddress | 0x49b000 |
| SizeOfRawData | 0x2400 |
| PointerToRawData | 0x457600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.40228 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| WINHTTP.dll |
WinHttpQueryHeaders
WinHttpOpen WinHttpSendRequest WinHttpQueryDataAvailable WinHttpReadData WinHttpReceiveResponse WinHttpCloseHandle WinHttpConnect WinHttpSetTimeouts WinHttpOpenRequest |
| WININET.dll |
InternetOpenUrlA
InternetReadFile InternetCloseHandle InternetOpenA |
| D3DCOMPILER_47.dll |
D3DCompile
|
| api-ms-win-core-libraryloader-l1-2-0.dll |
GetProcAddress
GetModuleFileNameA GetModuleHandleA GetModuleHandleW FreeLibrary LoadLibraryExW |
| api-ms-win-core-localization-l1-2-0.dll |
FormatMessageW
GetLocaleInfoA GetLocaleInfoEx FormatMessageA |
| api-ms-win-core-string-l1-1-0.dll |
WideCharToMultiByte
MultiByteToWideChar |
| api-ms-win-core-libraryloader-l1-2-1.dll |
LoadLibraryW
LoadLibraryA |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
QueryPerformanceFrequency |
| api-ms-win-core-sysinfo-l1-2-0.dll |
GetSystemTimePreciseAsFileTime
VerSetConditionMask |
| api-ms-win-core-heap-l2-1-0.dll |
GlobalFree
LocalFree GlobalAlloc |
| api-ms-win-core-heap-obsolete-l1-1-0.dll |
GlobalLock
GlobalUnlock |
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemDirectoryW
GetSystemInfo GetTickCount GetTickCount64 GetSystemTimeAsFileTime |
| api-ms-win-mm-time-l1-1-0.dll |
timeGetTime
timeEndPeriod timeBeginPeriod |
| api-ms-win-core-processthreads-l1-1-1.dll |
FlushInstructionCache
IsProcessorFeaturePresent OpenProcess |
| api-ms-win-core-synch-l1-2-0.dll |
WakeAllConditionVariable
InitOnceBeginInitialize InitOnceComplete Sleep SleepConditionVariableSRW |
| api-ms-win-core-psapi-ansi-l1-1-0.dll |
QueryFullProcessImageNameA
K32GetModuleFileNameExA |
| api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
DuplicateHandle |
| api-ms-win-ntuser-sysparams-l1-1-0.dll |
GetSystemMetrics
|
| api-ms-win-core-console-l3-2-0.dll |
GetConsoleWindow
|
| api-ms-win-core-memory-l1-1-0.dll |
VirtualAllocEx
VirtualQuery VirtualProtect WriteProcessMemory VirtualProtectEx VirtualQueryEx VirtualFreeEx ReadProcessMemory |
| api-ms-win-core-kernel32-legacy-l1-1-2.dll |
Process32Next
Process32First |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetCurrentProcess
GetProcessId OpenProcessToken GetCurrentProcessId GetExitCodeProcess GetCurrentThreadId SetThreadPriority GetCurrentThread TerminateProcess ExitProcess |
| api-ms-win-core-processenvironment-l1-1-0.dll |
GetEnvironmentVariableA
GetStdHandle GetCommandLineA |
| api-ms-win-core-console-l1-1-0.dll |
GetConsoleMode
SetConsoleMode |
| api-ms-win-core-file-l1-2-2.dll |
AreFileApisANSI
GetVolumeInformationA |
| api-ms-win-core-toolhelp-l1-1-0.dll |
CreateToolhelp32Snapshot
Process32NextW Process32FirstW |
| api-ms-win-core-debug-l1-1-0.dll |
IsDebuggerPresent
OutputDebugStringW |
| api-ms-win-core-debug-l1-1-1.dll |
CheckRemoteDebuggerPresent
|
| api-ms-win-core-registry-l1-1-0.dll |
RegCloseKey
RegQueryValueExA RegOpenKeyExA |
| api-ms-win-core-processtopology-obsolete-l1-1-0.dll |
SetThreadAffinityMask
|
| api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter GetLastError SetLastError |
| api-ms-win-core-psapi-l1-1-0.dll |
K32GetModuleBaseNameW
|
| api-ms-win-core-com-l1-1-0.dll |
CoCreateInstance
CoInitializeEx CoUninitialize CoCreateFreeThreadedMarshaler |
| api-ms-win-security-lsalookup-ansi-l2-1-0.dll |
LookupPrivilegeValueA
|
| api-ms-win-security-base-l1-1-0.dll |
AdjustTokenPrivileges
|
| KERNEL32.dll |
CreateFileMappingA
UnmapViewOfFile MapViewOfFile GetProcessHeap HeapFree HeapAlloc ReadFile GetFileSizeEx CreateFileA Module32First Module32Next K32EnumProcessModulesEx |
| USER32.dll |
keybd_event
MapVirtualKeyA SendInput SetWindowTextA GetWindowThreadProcessId GetWindowTextLengthW DefWindowProcW DispatchMessageA GetWindowRect DestroyWindow IsWindowVisible CreateWindowExW UnregisterClassW GetClassNameA RegisterClassExW ShowWindow IsWindow SetWindowLongA SetWindowDisplayAffinity MoveWindow EnumWindows SetLayeredWindowAttributes TranslateMessage LoadIconA PeekMessageA PostQuitMessage FindWindowA ShowCursor IsIconic GetWindowTextW GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetKeyState GetMessageExtraInfo LoadCursorA GetDC ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos UpdateWindow GetDesktopWindow |
| GDI32.dll |
GetDeviceCaps
CreateSolidBrush |
| SHELL32.dll |
ShellExecuteA
SHGetFolderPathA |
| MSVCP140.dll |
?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z ?__ExceptionPtrDestroy@@YAXPEAX@Z ?__ExceptionPtrToBool@@YA_NPEBX@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z ?__ExceptionPtrCreate@@YAXPEAX@Z _Cnd_unregister_at_thread_exit ??0task_continuation_context@Concurrency@@AEAA@XZ ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z ?_ReportUnobservedException@details@Concurrency@@YAXXZ ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z _Cnd_register_at_thread_exit ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ _Cnd_broadcast _Thrd_join _Thrd_id ?always_noconv@codecvt_base@std@@QEBA_NXZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z _Cnd_wait _Cnd_signal _Thrd_hardware_concurrency ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z _Thrd_detach _Cnd_do_broadcast_at_thread_exit ?_Random_device@std@@YAIXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Xbad_function_call@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A _Mtx_unlock _Query_perf_counter _Mtx_lock ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z ?_Throw_Cpp_error@std@@YAXH@Z _Query_perf_frequency ??1_Facet_base@std@@UEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ??1_Locinfo@std@@QEAA@XZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ??0facet@locale@std@@IEAA@_K@Z ??1facet@locale@std@@MEAA@XZ ?tolower@?$ctype@D@std@@QEBADD@Z ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z _Strcoll ??_7facet@locale@std@@6B@ ?id@?$collate@D@std@@2V0locale@2@A ?id@?$ctype@D@std@@2V0locale@2@A ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?_Id_cnt@id@locale@std@@0HA ?_Xbad_alloc@std@@YAXXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Strxfrm ??_7_Facet_base@std@@6B@ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?uncaught_exceptions@std@@YAHXZ |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmSetCompositionWindow ImmGetContext |
| WINMM.dll |
PlaySoundA
|
| CRYPT32.dll |
CertFreeCertificateChain
CryptStringToBinaryW PFXImportCertStore CryptDecodeObjectEx CertAddCertificateContextToStore CertFindExtension CertOpenStore CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertGetNameStringW CertFreeCertificateContext CertGetCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject |
| WS2_32.dll |
bind
inet_ntop WSASetLastError htonl inet_pton WSAGetLastError closesocket connect WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt listen getaddrinfo getpeername getsockname htons freeaddrinfo recvfrom recv setsockopt socket WSAIoctl __WSAFDIsSet select sendto ioctlsocket accept gethostname ntohs |
| bcrypt.dll |
BCryptGenRandom
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memcmp
memchr memset memmove memcpy longjmp wcschr __C_specific_handler strchr strstr __std_exception_copy __std_exception_destroy __intrinsic_setjmp strrchr _CxxThrowException _purecall __current_exception __current_exception_context |
| api-ms-win-crt-runtime-l1-1-0.dll |
__sys_nerr
_invalid_parameter_noinfo_noreturn _beginthreadex _invalid_parameter_noinfo abort _errno _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _get_initial_narrow_environment exit _initterm terminate _initterm_e _invoke_watson _exit _register_thread_local_exe_atexit_callback _c_exit __p___argv __p___argc system __sys_errlist |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
sqrt pow logf acosf sin _fdclass log powf _fdopen _dsign roundf _dclass ldexp asinf lroundf floorf atan2f ceilf cosf sqrtf expf exp fmodf sinf tanf |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
wcspbrk strspn wcsncmp strpbrk iswspace wcsncpy strcspn strcpy_s _wcsicmp tolower _strdup isalnum _stricmp toupper strncmp strncpy |
| api-ms-win-crt-convert-l1-1-0.dll |
strtod
strtoll strtoul atoi strtol strtoull wcstombs strtof atof |
| api-ms-win-crt-stdio-l1-1-0.dll |
fflush
_set_fmode __p__commode fputc __stdio_common_vsprintf_s _get_stream_buffer_pointers _fseeki64 _read _write _fileno _close feof ftell fsetpos ungetc setvbuf fgetpos fclose _lseeki64 __stdio_common_vsscanf fread _wopen fgetc fputs __stdio_common_vsprintf __stdio_common_vfprintf _wfopen fgets fwrite __acrt_iob_func fseek |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
qsort |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode malloc calloc realloc _callnewh |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64
_time64 strftime _localtime64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_fstat64 remove _unlink _unlock_file _wstat64 |
| api-ms-win-crt-locale-l1-1-0.dll |
localeconv
___lc_codepage_func _configthreadlocale |
| api-ms-win-core-file-l1-1-0.dll |
CreateDirectoryW
CreateFileW FindClose FindFirstFileW SetFileInformationByHandle FindFirstFileExW FindNextFileW GetFileType GetFileAttributesExW |
| api-ms-win-core-synch-l1-1-0.dll |
DeleteCriticalSection
LeaveCriticalSection AcquireSRWLockExclusive WaitForSingleObjectEx InitializeCriticalSection EnterCriticalSection WaitForSingleObject ReleaseSRWLockShared AcquireSRWLockShared SleepEx SetEvent CreateEventW ReleaseSRWLockExclusive InitializeCriticalSectionEx |
| api-ms-win-core-file-l2-1-0.dll |
MoveFileExW
GetFileInformationByHandleEx |
| api-ms-win-security-cryptoapi-l1-1-0.dll |
CryptReleaseContext
CryptGetHashParam CryptCreateHash CryptEncrypt CryptImportKey CryptDestroyKey CryptAcquireContextW CryptDestroyHash CryptHashData |
| api-ms-win-core-namedpipe-l1-1-0.dll |
PeekNamedPipe
|
| api-ms-win-core-synch-l1-2-1.dll |
WaitForMultipleObjects
|
| api-ms-win-core-kernel32-legacy-l1-1-1.dll |
VerifyVersionInfoW
|
| api-ms-win-security-systemfunctions-l1-1-0.dll |
SystemFunction036
|
| api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlVirtualUnwind
RtlCaptureContext RtlLookupFunctionEntry |
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
InterlockedPushEntrySList |
| OLEAUT32.dll |
SetErrorInfo
SysStringLen SysFreeString GetErrorInfo |
| api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-03 23:46:30 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x366ee8 |
| PointerToRawData | 0x365ee8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Sep-03 23:46:30 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1403672a0 |
|---|---|
| EndAddressOfRawData | 0x140367370 |
| AddressOfIndex | 0x140442260 |
| AddressOfCallbacks | 0x1402677e8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1403a0f40 |
| XOR Key | 0xcd4a6766 |
|---|---|
| Unmarked objects | 0 |
| 253 (35207) | 8 |
| C objects (35207) | 10 |
| C++ objects (35207) | 42 |
| ASM objects (35207) | 6 |
| Imports (35207) | 8 |
| C objects (33523) | 43 |
| C objects (VS2022 Update 6 (17.6.4) compiler 32535) | 123 |
| C++ objects (34436) | 5 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (VS2008 SP1 build 30729) | 136 |
| Imports (33145) | 34 |
| Imports (21202) | 3 |
| Total imports | 720 |
| C++ objects (LTCG) (35228) | 85 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.