4b1af6f9668acb1f62b26f0254e059f510251320a763e60c4ee2740a6ec89378

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Sep-03 23:46:30
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • github.com
  • http://127.0.0.1
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://curl.se
  • https://github.com
  • https://imtheo.lol
  • https://indiantypefoundry.comNinad
  • https://lrclib.net
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • lrclib.net
  • rbxcdn.com
  • roblox.com
  • scripts.sil.org
  • thumbnails.roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegCloseKey
  • RegQueryValueExA
  • RegOpenKeyExA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryW
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptAcquireContextW
  • CryptDestroyHash
  • CryptHashData
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Has Internet access capabilities:
  • WinHttpQueryHeaders
  • WinHttpOpen
  • WinHttpSendRequest
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpOpenRequest
  • InternetOpenUrlA
  • InternetReadFile
  • InternetCloseHandle
  • InternetOpenA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • WriteProcessMemory
  • ReadProcessMemory
  • Process32Next
  • Process32First
  • Process32NextW
  • Process32FirstW
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 21/70 (Scanned on 2026-09-04 20:31:23) APEX: Malicious
AVG: FileRepMalware [Misc]
Avast: FileRepMalware [Misc]
ClamAV: Win.Malware.Lazy-10033364-0
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/Riskware.GameHack.BO application
Elastic: malicious (high confidence)
GData: Win64.Trojan.Agent.1KW164
Google: Detected
Malwarebytes: Malware.AI.2583404916
McAfeeD: ti!4B1AF6F9668A
Microsoft: Trojan:Win32/Sabsik.EN.A!ml
Paloalto: generic.ml
Rising: Trojan.Kryptik@AI.90 (RDML:37H17pC6fR6q3T8eijkZYw)
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
TrellixENS: Artemis!FA26BA12D6D0
Varist: W64/ABTrojan.MYHA-6886
huorong: Trojan/Agent.cfs

Hashes

MD5 fa26ba12d6d06c3144ae608d41221ae0 🔍
SHA1 0f4bcd18546512fbee374ec8a35e500e954a2830 🔍
SHA256 4b1af6f9668acb1f62b26f0254e059f510251320a763e60c4ee2740a6ec89378 🔍
SHA3 3c528eb36c2056e982f28495de1199d9c3da36f86ddaf3df47cb4f206782fea4 🔍
SSDeep 98304:wFUD4VwdVOoSsUkfUS+DlrpvavA2Tf7Sl:TV7hTUS+DlrpvavIl 🔍
Imports Hash c5af04328bade5f54f71027bd5810182 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Sep-03 23:46:30
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x264c00
SizeOfInitializedData 0x235e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000245C00 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x49e000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2ac10241065323f3039d1bd2ee196216 🔍
SHA1 878bbfde17a1ecce74bb9c5a07f3ae682b6dc73b 🔍
SHA256 d4d2f193443f612f69ae5b4a20984b60aabb8d7845fbd94733be620806c04e6f 🔍
SHA3 cfe77cc1e92bba7a1cc80e301ffbec12e0c28914a8156e1165d50650ac708201 🔍
VirtualSize 0x264b88
VirtualAddress 0x1000
SizeOfRawData 0x264c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50241

.rdata

MD5 bf9e922c2233c2e08405f15e672ad6b2 🔍
SHA1 adadb47c8600ce14e38afdf4da304b2207333314 🔍
SHA256 047c1b1a52854293323028c62c0ade82eb77c609164934395de4f29cc812ee01 🔍
SHA3 568df9e3e47da6523d37d62397acf08406dfc82c8e70c1413da585636bf4f0ac 🔍
VirtualSize 0x13964e
VirtualAddress 0x266000
SizeOfRawData 0x139800
PointerToRawData 0x265000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.87735

.data

MD5 3231e198646b9697864caad57c69acf4 🔍
SHA1 fecd2d04b32a0f7d7b918e5b958e6668ec4c4965 🔍
SHA256 bc44e5cc89ae2ede3bc6813f1f804435a28a846a2ef58ec9ed67da1e1a953bef 🔍
SHA3 8bc2ba07257b17fd7aec4b11d9b460f643b82345291a85af097e7b3118b061d1 🔍
VirtualSize 0xe2ff8
VirtualAddress 0x3a0000
SizeOfRawData 0xa1c00
PointerToRawData 0x39e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.73466

.pdata

MD5 b5c0b2af5aecf030b911416aa15922e7 🔍
SHA1 e0e97d2db824a9e7e7d0ed907cb2423273ff3a52 🔍
SHA256 8dccbf4591e8b24b491d03c0bcab74833cf7b83d73fb106f089af57ad6bd7e4d 🔍
SHA3 b77236b78211b5e1bac92a71e74ae67b28978a7a8ecc48452474955b5a619b7a 🔍
VirtualSize 0x16ecc
VirtualAddress 0x483000
SizeOfRawData 0x17000
PointerToRawData 0x440400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.31123

.rsrc

MD5 a64d0ab84c36f15999853a31d7e5caaa 🔍
SHA1 515344d2864e1976d7d7d162cc5daa198a3b903a 🔍
SHA256 83d680bf75a3d5cbfca35fa84de05cd5e0765538e1557b83d1a38ecca23ff3bb 🔍
SHA3 6684ba3eba4c750ca2fd6b7261f23d0e2c02a0a71f7a604f0505ea46f23c8252 🔍
VirtualSize 0x1e0
VirtualAddress 0x49a000
SizeOfRawData 0x200
PointerToRawData 0x457400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71134

.reloc

MD5 26e1355b9bcbf32b4128cd859b9c545b 🔍
SHA1 54c5a01cd1cdb641ab0cc0c8e03cc4ee48025284 🔍
SHA256 9613ebc666d4e9819ee206ed52b92d1e47ae0427f766e6908fbf7310b70a7839 🔍
SHA3 fc07b79bc3f40fa87f36607a3a78758e0a42654e23b55fc73c32f72bce970561 🔍
VirtualSize 0x22e0
VirtualAddress 0x49b000
SizeOfRawData 0x2400
PointerToRawData 0x457600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40228

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
WINHTTP.dll WinHttpQueryHeaders
WinHttpOpen
WinHttpSendRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpCloseHandle
WinHttpConnect
WinHttpSetTimeouts
WinHttpOpenRequest
WININET.dll InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
D3DCOMPILER_47.dll D3DCompile
api-ms-win-core-libraryloader-l1-2-0.dll GetProcAddress
GetModuleFileNameA
GetModuleHandleA
GetModuleHandleW
FreeLibrary
LoadLibraryExW
api-ms-win-core-localization-l1-2-0.dll FormatMessageW
GetLocaleInfoA
GetLocaleInfoEx
FormatMessageA
api-ms-win-core-string-l1-1-0.dll WideCharToMultiByte
MultiByteToWideChar
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
LoadLibraryA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-sysinfo-l1-2-0.dll GetSystemTimePreciseAsFileTime
VerSetConditionMask
api-ms-win-core-heap-l2-1-0.dll GlobalFree
LocalFree
GlobalAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalLock
GlobalUnlock
api-ms-win-core-sysinfo-l1-1-0.dll GetSystemDirectoryW
GetSystemInfo
GetTickCount
GetTickCount64
GetSystemTimeAsFileTime
api-ms-win-mm-time-l1-1-0.dll timeGetTime
timeEndPeriod
timeBeginPeriod
api-ms-win-core-processthreads-l1-1-1.dll FlushInstructionCache
IsProcessorFeaturePresent
OpenProcess
api-ms-win-core-synch-l1-2-0.dll WakeAllConditionVariable
InitOnceBeginInitialize
InitOnceComplete
Sleep
SleepConditionVariableSRW
api-ms-win-core-psapi-ansi-l1-1-0.dll QueryFullProcessImageNameA
K32GetModuleFileNameExA
api-ms-win-core-handle-l1-1-0.dll CloseHandle
DuplicateHandle
api-ms-win-ntuser-sysparams-l1-1-0.dll GetSystemMetrics
api-ms-win-core-console-l3-2-0.dll GetConsoleWindow
api-ms-win-core-memory-l1-1-0.dll VirtualAllocEx
VirtualQuery
VirtualProtect
WriteProcessMemory
VirtualProtectEx
VirtualQueryEx
VirtualFreeEx
ReadProcessMemory
api-ms-win-core-kernel32-legacy-l1-1-2.dll Process32Next
Process32First
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
GetProcessId
OpenProcessToken
GetCurrentProcessId
GetExitCodeProcess
GetCurrentThreadId
SetThreadPriority
GetCurrentThread
TerminateProcess
ExitProcess
api-ms-win-core-processenvironment-l1-1-0.dll GetEnvironmentVariableA
GetStdHandle
GetCommandLineA
api-ms-win-core-console-l1-1-0.dll GetConsoleMode
SetConsoleMode
api-ms-win-core-file-l1-2-2.dll AreFileApisANSI
GetVolumeInformationA
api-ms-win-core-toolhelp-l1-1-0.dll CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
api-ms-win-core-debug-l1-1-0.dll IsDebuggerPresent
OutputDebugStringW
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
RegQueryValueExA
RegOpenKeyExA
api-ms-win-core-processtopology-obsolete-l1-1-0.dll SetThreadAffinityMask
api-ms-win-core-errorhandling-l1-1-0.dll UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
SetLastError
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
api-ms-win-core-com-l1-1-0.dll CoCreateInstance
CoInitializeEx
CoUninitialize
CoCreateFreeThreadedMarshaler
api-ms-win-security-lsalookup-ansi-l2-1-0.dll LookupPrivilegeValueA
api-ms-win-security-base-l1-1-0.dll AdjustTokenPrivileges
KERNEL32.dll CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
GetProcessHeap
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
Module32First
Module32Next
K32EnumProcessModulesEx
USER32.dll keybd_event
MapVirtualKeyA
SendInput
SetWindowTextA
GetWindowThreadProcessId
GetWindowTextLengthW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
CreateWindowExW
UnregisterClassW
GetClassNameA
RegisterClassExW
ShowWindow
IsWindow
SetWindowLongA
SetWindowDisplayAffinity
MoveWindow
EnumWindows
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
PostQuitMessage
FindWindowA
ShowCursor
IsIconic
GetWindowTextW
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
UpdateWindow
GetDesktopWindow
GDI32.dll GetDeviceCaps
CreateSolidBrush
SHELL32.dll ShellExecuteA
SHGetFolderPathA
MSVCP140.dll ?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
_Cnd_register_at_thread_exit
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Cnd_broadcast
_Thrd_join
_Thrd_id
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
_Cnd_wait
_Cnd_signal
_Thrd_hardware_concurrency
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Random_device@std@@YAIXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_function_call@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
_Mtx_unlock
_Query_perf_counter
_Mtx_lock
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
??1_Facet_base@std@@UEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
??0facet@locale@std@@IEAA@_K@Z
??1facet@locale@std@@MEAA@XZ
?tolower@?$ctype@D@std@@QEBADD@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
_Strcoll
??_7facet@locale@std@@6B@
?id@?$collate@D@std@@2V0locale@2@A
?id@?$ctype@D@std@@2V0locale@2@A
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
_Strxfrm
??_7_Facet_base@std@@6B@
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exceptions@std@@YAHXZ
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
WINMM.dll PlaySoundA
CRYPT32.dll CertFreeCertificateChain
CryptStringToBinaryW
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertGetNameStringW
CertFreeCertificateContext
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
WS2_32.dll bind
inet_ntop
WSASetLastError
htonl
inet_pton
WSAGetLastError
closesocket
connect
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
listen
getaddrinfo
getpeername
getsockname
htons
freeaddrinfo
recvfrom
recv
setsockopt
socket
WSAIoctl
__WSAFDIsSet
select
sendto
ioctlsocket
accept
gethostname
ntohs
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcmp
memchr
memset
memmove
memcpy
longjmp
wcschr
__C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
__intrinsic_setjmp
strrchr
_CxxThrowException
_purecall
__current_exception
__current_exception_context
api-ms-win-crt-runtime-l1-1-0.dll __sys_nerr
_invalid_parameter_noinfo_noreturn
_beginthreadex
_invalid_parameter_noinfo
abort
_errno
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_get_initial_narrow_environment
exit
_initterm
terminate
_initterm_e
_invoke_watson
_exit
_register_thread_local_exe_atexit_callback
_c_exit
__p___argv
__p___argc
system
__sys_errlist
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
sqrt
pow
logf
acosf
sin
_fdclass
log
powf
_fdopen
_dsign
roundf
_dclass
ldexp
asinf
lroundf
floorf
atan2f
ceilf
cosf
sqrtf
expf
exp
fmodf
sinf
tanf
api-ms-win-crt-string-l1-1-0.dll strcmp
wcspbrk
strspn
wcsncmp
strpbrk
iswspace
wcsncpy
strcspn
strcpy_s
_wcsicmp
tolower
_strdup
isalnum
_stricmp
toupper
strncmp
strncpy
api-ms-win-crt-convert-l1-1-0.dll strtod
strtoll
strtoul
atoi
strtol
strtoull
wcstombs
strtof
atof
api-ms-win-crt-stdio-l1-1-0.dll fflush
_set_fmode
__p__commode
fputc
__stdio_common_vsprintf_s
_get_stream_buffer_pointers
_fseeki64
_read
_write
_fileno
_close
feof
ftell
fsetpos
ungetc
setvbuf
fgetpos
fclose
_lseeki64
__stdio_common_vsscanf
fread
_wopen
fgetc
fputs
__stdio_common_vsprintf
__stdio_common_vfprintf
_wfopen
fgets
fwrite
__acrt_iob_func
fseek
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
malloc
calloc
realloc
_callnewh
api-ms-win-crt-time-l1-1-0.dll _gmtime64
_time64
strftime
_localtime64
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_fstat64
remove
_unlink
_unlock_file
_wstat64
api-ms-win-crt-locale-l1-1-0.dll localeconv
___lc_codepage_func
_configthreadlocale
api-ms-win-core-file-l1-1-0.dll CreateDirectoryW
CreateFileW
FindClose
FindFirstFileW
SetFileInformationByHandle
FindFirstFileExW
FindNextFileW
GetFileType
GetFileAttributesExW
api-ms-win-core-synch-l1-1-0.dll DeleteCriticalSection
LeaveCriticalSection
AcquireSRWLockExclusive
WaitForSingleObjectEx
InitializeCriticalSection
EnterCriticalSection
WaitForSingleObject
ReleaseSRWLockShared
AcquireSRWLockShared
SleepEx
SetEvent
CreateEventW
ReleaseSRWLockExclusive
InitializeCriticalSectionEx
api-ms-win-core-file-l2-1-0.dll MoveFileExW
GetFileInformationByHandleEx
api-ms-win-security-cryptoapi-l1-1-0.dll CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptAcquireContextW
CryptDestroyHash
CryptHashData
api-ms-win-core-namedpipe-l1-1-0.dll PeekNamedPipe
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-core-kernel32-legacy-l1-1-1.dll VerifyVersionInfoW
api-ms-win-security-systemfunctions-l1-1-0.dll SystemFunction036
api-ms-win-core-rtlsupport-l1-1-0.dll RtlVirtualUnwind
RtlCaptureContext
RtlLookupFunctionEntry
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
InterlockedPushEntrySList
OLEAUT32.dll SetErrorInfo
SysStringLen
SysFreeString
GetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-03 23:46:30
Version 0.0
SizeofData 912
AddressOfRawData 0x366ee8
PointerToRawData 0x365ee8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Sep-03 23:46:30
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1403672a0
EndAddressOfRawData 0x140367370
AddressOfIndex 0x140442260
AddressOfCallbacks 0x1402677e8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1403a0f40

RICH Header

XOR Key 0xcd4a6766
Unmarked objects 0
253 (35207) 8
C objects (35207) 10
C++ objects (35207) 42
ASM objects (35207) 6
Imports (35207) 8
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 123
C++ objects (34436) 5
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (VS2008 SP1 build 30729) 136
Imports (33145) 34
Imports (21202) 3
Total imports 720
C++ objects (LTCG) (35228) 85
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.