5eaeb550dad83988f283336c507092c1ff2df1373ffa7b288170f9be83794d31

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-16 22:11:38
Detected languages English - United States
Debug artifacts D:\Downloads\speed\speed perm and temp\speed perm and temp\permtemp\x64\Release\quantum.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious PEiD Signature: UPolyX V0.1 -> Delikon
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • %temp%
  • CurrentControlSet\Services
Accesses the WMI:
  • ROOT\CIMV2
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
  • exploit
  • virus
Contains domain names:
  • 2010-aia.verisign.com
  • 2010-crl.verisign.com
  • acutedotcomb.cn
  • aia.verisign.com
  • aia.ws.symantec.com
  • anbanggroup.com
  • apple.com
  • breveacutecomb.cn
  • brevegravecomb.cn
  • brevetildecomb.cn
  • certs.apple.com
  • circumflexacutecomb.cn
  • circumflexgravecomb.cn
  • circumflexhookcomb.cn
  • circumflextildecomb.cn
  • commaaccentright.cn
  • commaaccentrotate.cn
  • crl.apple.com
  • crl.microsoft.com
  • crl.sectigo.com
  • crl.thawte.com
  • crl.usertrust.com
  • crl.verisign.com
  • crl.ws.symantec.com
  • crt.sectigo.com
  • csc3-2010-aia.verisign.com
  • csc3-2010-crl.verisign.com
  • github.com
  • http://certs.apple.com
  • http://certs.apple.com/wwdrg3.der01
  • http://crl.apple.com
  • http://crl.apple.com/root.crl0
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • http://crl.sectigo.com
  • http://crl.sectigo.com/SectigoPublicTimeStampingCAR36.crl0z
  • http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://crl.usertrust.com
  • http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl05
  • http://crl.verisign.com
  • http://crl.verisign.com/pca3-g5.crl04
  • http://crt.sectigo.com
  • http://crt.sectigo.com/SectigoPublicTimeStampingCAR36.crt0#
  • http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0#
  • http://csc3-2010-aia.verisign.com
  • http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
  • http://csc3-2010-crl.verisign.com
  • http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
  • http://logo.verisign.com
  • http://logo.verisign.com/vslogo.gif04
  • http://ocsp.apple.com
  • http://ocsp.apple.com/ocsp03-applerootca0.
  • http://ocsp.apple.com/ocsp03-wwdrg3010
  • http://ocsp.sectigo.com0
  • http://ocsp.thawte.com0
  • http://ocsp.usertrust.com0
  • http://ocsp.verisign.com0
  • http://scripts.sil.org
  • http://scripts.sil.org/OFLInterMediumInterMediumOpen
  • http://scripts.sil.org/OFLhttp
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • https://discord.gg
  • https://fontawesome.comVersion
  • https://github.com
  • https://rsms.me
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://sectigo.com
  • https://www.apple.com
  • https://www.apple.com/certificateauthority/0
  • https://www.lexend.comBonnie
  • https://www.verisign.com
  • https://www.verisign.com/cps0
  • https://www.verisign.com/rpa
  • https://www.verisign.com/rpa0
  • koronisaccentleft.cn
  • logo.verisign.com
  • macrondieresiscomb.cn
  • microsoft.com
  • ocsp.apple.com
  • scripts.sil.org
  • sectigo.com
  • symantec.com
  • thawte.com
  • tildecross.cn
  • tildemacroncomb.cn
  • tonos.top
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • uni02E5.cn
  • uni02E6.cn
  • uni02E7.cn
  • uni02E8.cn
  • uni02E9.cn
  • uni1DC4.cn
  • uni1DC6.cn
  • usertrust.com
  • verisign.com
  • ws.symantec.com
  • www.anbanggroup.com
  • www.apple.com
  • www.verisign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Can create temporary files:
  • GetTempPathW
  • CreateFileA
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 28/70 (Scanned on 2026-08-16 22:14:00) ALYac: Gen:Variant.Application.Lazy.458736
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
Arcabit: Trojan.Application.Lazy.D6FFF0
Avast: Win64:MalwareX-gen [Misc]
BitDefender: Gen:Variant.Application.Lazy.458736
Bkav: W32.Malware.ABD19AEB
CTX: exe.unknown.lazy
ClamAV: Win.Tool.Zusy-10033075-0
CrowdStrike: win/malicious_confidence_70% (D)
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
DrWeb: Tool.VulnDriver.22
ESET-NOD32: Win64/Agent_AGen.GTT trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Application.Lazy.458736 (B)
GData: Gen:Variant.Application.Lazy.458736
Google: Detected
K7AntiVirus: Trojan ( 005ce2011 )
K7GW: Trojan ( 005ce2011 )
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: Trojan:Win/Driverloader.EAA
MicroWorld-eScan: Gen:Variant.Application.Lazy.458736
Microsoft: Trojan:Win32/Wacatac.B!ml
SentinelOne: Static AI - Suspicious PE
Symantec: ML.Attribute.HighConfidence
VIPRE: Gen:Variant.Application.Lazy.458736
huorong: TrojanDropper/Agent.arb

Hashes

MD5 516cb10959633639566964da7abbcc90 🔍
SHA1 95ed2a45302dc934a0de2cef110dbb6f20c6678e 🔍
SHA256 5eaeb550dad83988f283336c507092c1ff2df1373ffa7b288170f9be83794d31 🔍
SHA3 395f90f09d2225075dd3653deaa809d241135ac1ade97d4c474445f92cf71f2c 🔍
SSDeep 49152:y0tGMAV61WqNIcxnuL5KXoOfEdxR7HFVhWJkGwEycJM344:yL6kqUKYOfEfhlV58M3 🔍
Imports Hash e6602ecc06bf24b7d1a0564cbfe092dd 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-16 22:11:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xad000
SizeOfInitializedData 0x22e800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000ABD80 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2df000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3c2ab06e067bd23b0a88b49c9d681564 🔍
SHA1 7be7db1202806329496dddcd9e06a8cf2600805c 🔍
SHA256 666c64e9a07b201c8610e3ba2f5d1ed3c19cd631ac9263b041c8cdb313ee57bc 🔍
SHA3 e6942449b595dba3c0460aaa6b0199e1ed4d7764615846b4fb14ac8d223f68b0 🔍
VirtualSize 0xacf21
VirtualAddress 0x1000
SizeOfRawData 0xad000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51979

.rdata

MD5 840f35663f4acf041496ebb20f7ea278 🔍
SHA1 1d1ea65b96900dd3497e61ab73b199e7c1ea9c73 🔍
SHA256 bd62dadceced6d3ebf3eb70038df08a0d5d2c76a0839596fec5dd76df80e8b4e 🔍
SHA3 81695e509c6366f47db986a89987d677e9978801280c1af326c31d0d552f8633 🔍
VirtualSize 0x35a90
VirtualAddress 0xae000
SizeOfRawData 0x35c00
PointerToRawData 0xad400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28392

.data

MD5 2cf74b3af63511ff7bf556fc4387128c 🔍
SHA1 01bf73b2d786da708e7e167eb1c3e891910c00f9 🔍
SHA256 7393153e9561e4dc7291711c3b42b5f58d201be4374151707dd8d61a87f0010d 🔍
SHA3 98b23a810a28d1632d812027af4c38505bb817cd31e1e0ff388b19b9fb93d140 🔍
VirtualSize 0x1ef4d8
VirtualAddress 0xe4000
SizeOfRawData 0x1ef000
PointerToRawData 0xe3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.26405

.pdata

MD5 74386fbc4e6275e139f2fe5b1bc6470d 🔍
SHA1 96d816c5298057e4cfa64e41cf72e636d535d4dd 🔍
SHA256 44c829912534a23a249fb5886d646fe44e6ef980143c8f855a7165885c59a79f 🔍
SHA3 54fc5352171802c64e9d5f92d867d18d8b2367cb66351cee416fe0e912ef6699 🔍
VirtualSize 0x84d8
VirtualAddress 0x2d4000
SizeOfRawData 0x8600
PointerToRawData 0x2d2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.01437

.rsrc

MD5 bd7725d1375a619de8a1264ff43e4513 🔍
SHA1 eb362652761c4900354d0754fb8c7aeaa066271b 🔍
SHA256 6955075783419e861ab5b3368766c5789c0d6bf37bec585411732b65fafa8d1c 🔍
SHA3 b8bac19e1c48dd134103753f9dbb59b2d778bd3ffce7df7888ac2e40d1b91168 🔍
VirtualSize 0x1e8
VirtualAddress 0x2dd000
SizeOfRawData 0x200
PointerToRawData 0x2da600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.76442

.reloc

MD5 27bf008ceacdb0d52e7a735470e8dcb8 🔍
SHA1 62cc7b47f2c88085a2f59b87684e5ef4b3ba5cd6 🔍
SHA256 ea08fca2ba49e86c998d70250af8a377a64cb7fe9703f87539851693ef7e5b18 🔍
SHA3 8132ae6b8e6db7609476677aedfa9d6acad076e3a6279bbbe663c569368ad319 🔍
VirtualSize 0xdc0
VirtualAddress 0x2de000
SizeOfRawData 0xe00
PointerToRawData 0x2da800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.39927

Imports

d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
KERNEL32.dll GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
FreeLibrary
QueryPerformanceCounter
Sleep
CloseHandle
CreateProcessA
GetModuleHandleW
InitializeSListHead
GetCurrentProcessId
GetStartupInfoW
SetUnhandledExceptionFilter
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetLastError
AreFileApisANSI
CreateFile2
GetTempPathW
GetFileAttributesW
GetLocaleInfoEx
FormatMessageA
LocalFree
CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
HeapFree
HeapAlloc
ReadFile
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
MultiByteToWideChar
GetCurrentThreadId
GetFileSizeEx
CreateFileA
GetSystemTimeAsFileTime
GlobalUnlock
USER32.dll ShowWindow
RegisterClassExW
UnregisterClassW
GetSystemMetrics
DispatchMessageW
MoveWindow
GetWindowRect
DestroyWindow
DefWindowProcW
GetWindowLongW
SetWindowLongA
CreateWindowExW
SetLayeredWindowAttributes
TranslateMessage
PostQuitMessage
UpdateWindow
MessageBoxA
BlockInput
GetKeyState
GetMessageExtraInfo
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
SetCursorPos
ReleaseCapture
IsWindowUnicode
SetCapture
GetClientRect
SetCursor
PeekMessageW
SHELL32.dll ShellExecuteA
ole32.dll CoSetProxyBlanket
CoCreateInstance
CoUninitialize
CoInitializeSecurity
CoInitializeEx
OLEAUT32.dll SysFreeString
SysAllocString
VariantClear
MSVCP140.dll ?always_noconv@codecvt_base@std@@QEBA_NXZ
??Bios_base@std@@QEBA_NXZ
??7ios_base@std@@QEBA_NXZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Xlength_error@std@@YAXPEBD@Z
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Xbad_alloc@std@@YAXXZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Syserror_map@std@@YAPEBDH@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
dwmapi.dll DwmExtendFrameIntoClientArea
d3d9.dll Direct3DCreate9
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll longjmp
__std_exception_destroy
memmove
strstr
__std_terminate
strrchr
memcpy
_CxxThrowException
__intrinsic_setjmp
__current_exception_context
__current_exception
__std_exception_copy
__C_specific_handler
memset
memcmp
memchr
api-ms-win-crt-math-l1-1-0.dll fmodf
sqrtf
cosf
roundf
ceilf
sinf
powf
acosf
__setusermatherr
api-ms-win-crt-string-l1-1-0.dll strcmp
strncmp
strlen
strncpy
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-stdio-l1-1-0.dll ftell
__acrt_iob_func
fflush
__p__commode
_set_fmode
fclose
fseek
__stdio_common_vfprintf
_get_stream_buffer_pointers
_fseeki64
fsetpos
ungetc
setvbuf
fgetpos
fgetc
fputc
fwrite
__stdio_common_vsscanf
fread
__stdio_common_vsprintf
_wfopen
api-ms-win-crt-heap-l1-1-0.dll free
_set_new_mode
_callnewh
malloc
api-ms-win-crt-convert-l1-1-0.dll strtol
api-ms-win-crt-runtime-l1-1-0.dll _cexit
_initialize_onexit_table
_initialize_narrow_environment
_crt_atexit
_configure_narrow_argv
abort
terminate
_seh_filter_exe
exit
_register_thread_local_exe_atexit_callback
_c_exit
_set_app_type
_exit
_initterm_e
_initterm
_register_onexit_function
_get_narrow_winmain_command_line
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
___lc_codepage_func

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-16 22:11:38
Version 0.0
SizeofData 116
AddressOfRawData 0xd5214
PointerToRawData 0xd4614
Referenced File D:\Downloads\speed\speed perm and temp\speed perm and temp\permtemp\x64\Release\quantum.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-16 22:11:38
Version 0.0
SizeofData 20
AddressOfRawData 0xd5288
PointerToRawData 0xd4688

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-16 22:11:38
Version 0.0
SizeofData 912
AddressOfRawData 0xd529c
PointerToRawData 0xd469c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-16 22:11:38
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400d5650
EndAddressOfRawData 0x1400d5658
AddressOfIndex 0x1402d3030
AddressOfCallbacks 0x1400ae938
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400e4040

RICH Header

XOR Key 0x80a922e7
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
C objects (33145) 1
253 (35721) 1
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 42
Imports (35721) 6
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (33145) 24
Imports (21202) 3
Total imports 289
C++ objects (LTCG) (36252) 19
Resource objects (36252) 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.