60b66f613357fc8fdb5fcfb7583879a0d028e9eef9f0e37402f83cfaffcee3fc

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-20 11:17:39
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts C:\Users\QSTAR\Downloads\toast\toast\x64\Release\Toast Mods.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VMWare presence:
  • VMware
Contains domain names:
  • Calligraphr.com
  • api.github.com
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • cdn.discordapp.com
  • discord.com
  • discordapp.com
  • genretrucklooksValueFrame.net
  • github.com
  • githubusercontent.com
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://api.github.com
  • https://api.github.com/repos/hsnendheje-cmd/reimagined-octo-lamp/contents/eacbypass
  • https://api.github.com/repos/hsnendheje-cmd/reimagined-octo-lamp/contents/token
  • https://cdn.discordapp.com
  • https://cdn.discordapp.com/avatars/
  • https://curl.se
  • https://discord.com
  • https://github.com
  • https://pastebin.com
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/hsnendheje-cmd/reimagined-octo-lamp/main/
  • https://www.World
  • https://www.recent
  • pastebin.com
  • raw.githubusercontent.com
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to Twofish
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CheckRemoteDebuggerPresent
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Uses Windows's Native API:
  • NtClose
  • NtMapViewOfSection
  • NtUnmapViewOfSection
  • NtCreateSection
  • ntohs
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptEncrypt
  • CryptImportKey
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptDestroyKey
  • CryptCreateHash
  • CryptHashData
  • CryptDestroyHash
  • CryptQueryObject
  • CryptDecodeObjectEx
  • CryptStringToBinaryW
  • CryptCATAdminReleaseCatalogContext
  • CryptCATAdminReleaseContext
  • CryptCATCatalogInfoFromContext
  • CryptCATAdminAcquireContext
  • CryptCATAdminEnumCatalogFromHash
  • CryptCATAdminCalcHashFromFileHandle
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Has Internet access capabilities:
  • URLDownloadToFileA
  • WinHttpReadData
  • WinHttpQueryDataAvailable
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpSendRequest
  • WinHttpCloseHandle
  • WinHttpReceiveResponse
  • WinHttpOpen
  • WinHttpSetOption
  • WinHttpQueryHeaders
  • WinHttpAddRequestHeaders
  • WinHttpOpenRequest
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Interacts with services:
  • OpenSCManagerW
  • QueryServiceStatus
  • OpenServiceW
Manipulates other processes:
  • OpenProcess
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 2602d451d994a3e7e969bba4ac69b538 🔍
SHA1 099548c6d506b9733f1ae27746fd5d96ebefd2fb 🔍
SHA256 60b66f613357fc8fdb5fcfb7583879a0d028e9eef9f0e37402f83cfaffcee3fc 🔍
SHA3 b93371a0da33e83a17992d209c78ee94da73e208727cc17b9da715fdcfa3408a 🔍
SSDeep 49152:uWU3oZfu7UQ0EfKmGOGz2kuYQPbA3GY+ZfOWMSJq3d0gPLmUMHcLhhwckO0cSNf:u49ZQPbtYWflqHLmfHcLhhwcxqfAuIH 🔍
Imports Hash f0dfda2deb51a43f46f69f2f830c1ccf 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-20 11:17:39
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x164e00
SizeOfInitializedData 0x107000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000010EE0C (Section: .text)
BaseOfCode 0x10000
ImageBase 0x140000000
SectionAlignment 0x10000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2b0000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 ddd2fd439925aa8a136fee79a350eb18 🔍
SHA1 81694ca9858696731178549571200248f8a25828 🔍
SHA256 9c58739066ecef1c31dc9acbba64b39c20d7d9e36c9510ff3eabe05f940b1f28 🔍
SHA3 38bbf9849581cb7c19b00b0ea6c539e406464cd1aac8af8124b3e2982463c679 🔍
VirtualSize 0x164dc3
VirtualAddress 0x10000
SizeOfRawData 0x164e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.43229

.rdata

MD5 53f92fab423d19fd5c2d546fc9fedf87 🔍
SHA1 2430b2ca617de21203ed0736f0255e0bf63242de 🔍
SHA256 013f19338445578edf4eb6d74507a47085c36d48df741465ffc55a5ec602c62b 🔍
SHA3 2ac8008aeb693526b618618624b1ab0a66dd948513ec58983270973bcd388a84 🔍
VirtualSize 0x78e8c
VirtualAddress 0x180000
SizeOfRawData 0x79000
PointerToRawData 0x165200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.34425

.data

MD5 e9baeb6df869eeba4332a76da484296c 🔍
SHA1 9a196a3fc98502296441eb33fb177bb8d9fe44be 🔍
SHA256 2619ce6d64d8acfaf59900d365b8730ffb13f2117eb024ad85eb43c0eb0ef21e 🔍
SHA3 a691920a257fc2dab9dc3e29e0b101624e3ef1280e88f480becfad9af355941b 🔍
VirtualSize 0x55d98
VirtualAddress 0x200000
SizeOfRawData 0x55000
PointerToRawData 0x1de200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.95365

.pdata

MD5 073f39c373be9b08b98e0c38406067e2 🔍
SHA1 bc948b7bf63da3f2d744c362074caa427ae346b6 🔍
SHA256 63baade33012ee885c6777a7e3a0a8468bd89241f3ed05d8fcc230e77a7d1425 🔍
SHA3 2645b8e538a914c4fd34fd98124605d5382f12a22c68159260e8d2fb4d93e52c 🔍
VirtualSize 0xffcc
VirtualAddress 0x260000
SizeOfRawData 0x10000
PointerToRawData 0x233200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.24969

.rsrc

MD5 3466f2795414a7794b59a7315ed53c94 🔍
SHA1 0d0248d51284a8e34f1ea9d5d1152e536e21f2a6 🔍
SHA256 aafe7da829a03b1f41192a75dfd653dafd44f221d0e500a1fdc3378d8ac75c54 🔍
SHA3 160b6aca5a2d781607181f4f4b7da01ece7069c2cd26de8e0d96cc6d73814dba 🔍
VirtualSize 0x268a8
VirtualAddress 0x270000
SizeOfRawData 0x26a00
PointerToRawData 0x243200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.95859

.reloc

MD5 55e7cc91e8d4c2b03d359797f0601d43 🔍
SHA1 c6d7b9558942edfa8c77d8a383e99d18e634c332 🔍
SHA256 f4d61e6d53243543f9a65b1cf0f7f3717287470b2d5fad74ccea74d3d70d936c 🔍
SHA3 2de8df62974de4c9574ef51ac17c0f26bf5c5cf00c7e2a7fd05660833ac5fe8d 🔍
VirtualSize 0x1798
VirtualAddress 0x2a0000
SizeOfRawData 0x1800
PointerToRawData 0x269c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.39292

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
KERNEL32.dll CheckRemoteDebuggerPresent
OpenProcess
VirtualProtect
OpenThread
GetThreadContext
CreateToolhelp32Snapshot
ResumeThread
SuspendThread
Thread32First
Thread32Next
AddVectoredExceptionHandler
GetCurrentThread
GetStdHandle
SetConsoleTextAttribute
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
Process32NextW
Process32FirstW
K32GetModuleInformation
IsBadReadPtr
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetFileInformationByHandleEx
MoveFileExW
VirtualFree
AreFileApisANSI
SetFileInformationByHandle
GetFullPathNameW
GetFileAttributesExW
FindFirstFileW
FindClose
CreateFileW
CreateDirectoryW
GetLocaleInfoEx
FormatMessageA
LocalFree
CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
GetThreadId
SetLastError
FormatMessageW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
GetSystemDirectoryW
SleepEx
GetTickCount
WaitForSingleObjectEx
GetFileType
PeekNamedPipe
WaitForMultipleObjects
VerifyVersionInfoW
VirtualAlloc
GetSystemInfo
VirtualQuery
QueryFullProcessImageNameW
QueryPerformanceCounter
VerSetConditionMask
QueryPerformanceFrequency
LoadLibraryA
GetLocaleInfoA
GetModuleHandleA
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
CreateDirectoryA
CreateProcessA
GetCurrentProcessId
SetFileAttributesA
CloseHandle
DeleteFileA
CreateFileA
GetFileAttributesA
GetLastError
GetExitCodeThread
CopyFileA
GetTickCount64
GetCurrentDirectoryA
WaitForSingleObject
GetEnvironmentVariableA
WriteFile
MoveFileA
GetModuleFileNameA
GetModuleHandleW
Sleep
MultiByteToWideChar
FreeLibrary
GetProcAddress
LoadLibraryW
USER32.dll DispatchMessageW
DefWindowProcW
GetWindowLongW
SetClipboardData
SetWindowLongA
GetClipboardData
PeekMessageW
EmptyClipboard
LoadCursorW
SetCapture
SetCursor
CreateWindowExW
SetLayeredWindowAttributes
GetClientRect
TranslateMessage
PostQuitMessage
UpdateWindow
GetWindowRect
GetSystemMetrics
UnregisterClassW
ShowWindow
GetForegroundWindow
IsWindowUnicode
GetKeyboardLayout
TrackMouseEvent
CloseClipboard
RegisterClassExW
ClientToScreen
DestroyWindow
OpenClipboard
GetCapture
MessageBoxA
GetKeyState
GetCursorPos
GetMessageExtraInfo
SetCursorPos
ScreenToClient
MoveWindow
ReleaseCapture
ADVAPI32.dll RegOpenKeyExA
RegQueryValueExA
OpenSCManagerW
CloseServiceHandle
QueryServiceStatus
ReportEventW
RegisterEventSourceW
DeregisterEventSource
RegCloseKey
CryptAcquireContextW
OpenServiceW
CryptEncrypt
CryptImportKey
CryptReleaseContext
CryptGetHashParam
CryptDestroyKey
CryptCreateHash
CryptHashData
CryptDestroyHash
SHELL32.dll SHGetKnownFolderPath
ShellExecuteA
ole32.dll CoTaskMemFree
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
MSVCP140.dll ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??7ios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Xbad_alloc@std@@YAXXZ
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?_Xbad_function_call@std@@YAXXZ
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_lock
_Cnd_do_broadcast_at_thread_exit
_Thrd_detach
??0_Locinfo@std@@QEAA@HPEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getname@_Locinfo@std@@QEBAPEBDXZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z
??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
?_New_Locimp@_Locimp@locale@std@@CAPEAV123@_N@Z
?_Makeloc@_Locimp@locale@std@@CAPEAV123@AEBV_Locinfo@3@HPEAV123@PEBV23@@Z
_Mtx_unlock
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Xruntime_error@std@@YAXPEBD@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z
?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z
?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ
??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?good@ios_base@std@@QEBA_NXZ
?fail@ios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
_Thrd_join
_Xtime_get_ticks
_Query_perf_counter
_Thrd_id
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exception@std@@YA_NXZ
_Query_perf_frequency
?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
ntdll.dll NtClose
NtMapViewOfSection
NtUnmapViewOfSection
NtCreateSection
RtlGetVersion
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
RtlImageNtHeader
WS2_32.dll getsockopt
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSACleanup
accept
bind
closesocket
shutdown
listen
WSAStartup
send
socket
connect
recv
htonl
htons
gethostname
WSAEventSelect
WSAGetLastError
inet_pton
ntohs
sendto
recvfrom
WSASetLastError
inet_ntop
getpeername
ioctlsocket
getsockname
WSAIoctl
freeaddrinfo
getaddrinfo
select
setsockopt
__WSAFDIsSet
CRYPT32.dll CertFindCertificateInStore
CertGetNameStringW
CryptQueryObject
CertFreeCertificateChain
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CertFindExtension
CertAddCertificateContextToStore
CryptDecodeObjectEx
PFXImportCertStore
CryptStringToBinaryW
CertEnumCertificatesInStore
CertCloseStore
CertFreeCertificateContext
CertOpenStore
WINTRUST.dll CryptCATAdminReleaseCatalogContext
CryptCATAdminReleaseContext
CryptCATCatalogInfoFromContext
CryptCATAdminAcquireContext
CryptCATAdminEnumCatalogFromHash
WinVerifyTrust
CryptCATAdminCalcHashFromFileHandle
urlmon.dll URLDownloadToFileA
WINHTTP.dll WinHttpReadData
WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSetTimeouts
WinHttpSendRequest
WinHttpCloseHandle
WinHttpReceiveResponse
WinHttpOpen
WinHttpSetOption
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpOpenRequest
bcrypt.dll BCryptGenRandom
BCryptOpenAlgorithmProvider
BCryptCloseAlgorithmProvider
BCryptHash
IMM32.dll ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
ImmSetCompositionWindow
dwmapi.dll DwmExtendFrameIntoClientArea
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_copy
__std_terminate
__std_exception_destroy
strchr
strstr
strrchr
longjmp
memcpy
memmove
memset
memchr
memcmp
__C_specific_handler
__current_exception
__current_exception_context
__intrinsic_setjmp
_CxxThrowException
wcsrchr
wcschr
api-ms-win-crt-runtime-l1-1-0.dll _invoke_watson
exit
_beginthreadex
terminate
abort
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
__sys_nerr
__sys_errlist
_cexit
_seh_filter_exe
_set_app_type
_get_narrow_winmain_command_line
_initterm
_initterm_e
_exit
_c_exit
_register_thread_local_exe_atexit_callback
_errno
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
malloc
_callnewh
calloc
realloc
free
api-ms-win-crt-stdio-l1-1-0.dll _close
_fileno
_write
ungetwc
_read
__p__commode
__stdio_common_vfwprintf
fgetwc
_set_fmode
__stdio_common_vswprintf
fputwc
fputc
fflush
fclose
_lseeki64
fputs
feof
fgetc
__stdio_common_vfprintf
fwrite
fopen_s
_wopen
fgets
__stdio_common_vsprintf
fgetpos
__stdio_common_vsscanf
_wfopen
setvbuf
fseek
__acrt_iob_func
ftell
_get_stream_buffer_pointers
_fseeki64
fread
fsetpos
ungetc
api-ms-win-crt-string-l1-1-0.dll strncpy
strncmp
strcmp
wcsncpy
wcsncmp
_strnicmp
strpbrk
strspn
wcspbrk
tolower
strcspn
toupper
_strdup
_stricmp
strnlen
towlower
isalnum
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
_fstat64
_fullpath
_unlink
_wstat64
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-convert-l1-1-0.dll strtol
strtoll
wcstombs
strtoul
atoi
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
_configthreadlocale
api-ms-win-crt-math-l1-1-0.dll acosf
__setusermatherr
_fdopen
sqrtf
cosf
ceilf
sinf
fmodf
api-ms-win-crt-time-l1-1-0.dll _time64
_localtime64_s
wcsftime
_gmtime64
strftime
_localtime64

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x399
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70542
Detected Filetype PNG graphic file
MD5 9b011d6a9d98ae5154f4259614f8973c 🔍
SHA1 8d894da1d7ed67d1350aa8abcac647ff2486a5c2 🔍
SHA256 401288378c106d351a953699565577daaa0abbf8bf8a826c7de12d5379f00877 🔍
SHA3 92d16add1515ae6c1f12265869649b15b308e50ae2cdb2f0f60be9740cf1c369 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6f3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8382
Detected Filetype PNG graphic file
MD5 264f30529f63a2d92978a195ddaf8413 🔍
SHA1 f0b8db241f589cac809116b904e17c61f4176d81 🔍
SHA256 97cdcc49c13e330c2a0368dc96197fb7c809d7e5c51710cfc3944270820e1268 🔍
SHA3 6c8ed2918a6ff3e2ce85a2b9364f25e1daae30d6401781776c49a6a504c2337c 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb44
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89481
Detected Filetype PNG graphic file
MD5 f26f562bb73b15fa57d3d5eb39a76e36 🔍
SHA1 d87dedfc69d1e259d0ca53297f07f837c25ab4e1 🔍
SHA256 cd466104f37aba4933800040eda29879754d4cd84a46822f625120ef70757f07 🔍
SHA3 9bf008cb0a333d05ca0f638b26deaf2bde20cf0147b551f910f5ca1e2300aaa4 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x16dd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94493
Detected Filetype PNG graphic file
MD5 713e67dde98f3e3f9ee1450a264fa46a 🔍
SHA1 496cfd990a20fd49d748b836477c0c4a00804d0e 🔍
SHA256 c86fe11166563f1ac4e2cf85b36706a7d0c8aaa60fc39cb0a244cff9269f1c38 🔍
SHA3 1f47584be0508904fee55acd08cb03ec82731e527b6505c1823abe1f29ecd84c 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25d6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96682
Detected Filetype PNG graphic file
MD5 4b02d4035e9e993afebef2558c0dee5d 🔍
SHA1 0ad3962a282f042567b7a74bca36e305cf3b7090 🔍
SHA256 43eaa26ddbdcad6d0af7b487bb79bb59d27ef1587a545ee995d0267aeb025f62 🔍
SHA3 022549aa8eaf69d41db8f0249d349c74a68bbe0e349a7a868660eeafe6a7de5d 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x7c2d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9703
Detected Filetype PNG graphic file
MD5 df80e46c786429f9487203d64d97d52e 🔍
SHA1 2fbc2f7708737132a0081f680620a3952f23eefe 🔍
SHA256 47a638025c3d41c3cbf1b1a74412b618abbd5b7cae041572785acfd1e244d889 🔍
SHA3 9a8952a564b008a542c510d65d0b317d5f6b19ad94c91a294bf4d98344644849 🔍

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x195e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96053
Detected Filetype PNG graphic file
MD5 5afe7e8ce074b2a8aefb753482c01400 🔍
SHA1 08450c88e761a49496f19ecf53b268b85772bf32 🔍
SHA256 e6ea32bf930c410bd7f2960437d14cd58e514b5314f5d4160623dc58e1f7b373 🔍
SHA3 a3d9f5cf0eac84f02cc3dbafbd1a6f2a9b034d49df5fd3abcd7bcc61be5837ed 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.96474
Detected Filetype Icon file
MD5 32ac86492ed842ccb59a82a4986f7320 🔍
SHA1 4453e514ab0bd206bd04456acd7bf745c71701c3 🔍
SHA256 096e1aa9fe2a746e7b47aafb5996e2836fed6919eb069cc502c5cd907a37ec61 🔍
SHA3 ed3ee9a0851e9b7d2787cb7c9ee0292ce1a1a5d2e3dd143fe2d9f4041f2e3eac 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-20 11:17:39
Version 0.0
SizeofData 88
AddressOfRawData 0x1dcf94
PointerToRawData 0x1c2194
Referenced File C:\Users\QSTAR\Downloads\toast\toast\x64\Release\Toast Mods.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-20 11:17:39
Version 0.0
SizeofData 20
AddressOfRawData 0x1dcfec
PointerToRawData 0x1c21ec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-20 11:17:39
Version 0.0
SizeofData 932
AddressOfRawData 0x1dd000
PointerToRawData 0x1c2200

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-20 11:17:39
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1401dd3c8
EndAddressOfRawData 0x1401dd3d0
AddressOfIndex 0x140255528
AddressOfCallbacks 0x140181270
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks 0x0000000140092FF0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140200040

RICH Header

XOR Key 0xfb8e5f9f
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
C objects (34435) 135
253 (35207) 8
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 37
Imports (35207) 6
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
C objects (CVTCIL) (33145) 1
Imports (33145) 34
Imports (21202) 7
Total imports 640
C++ objects (LTCG) (35228) 35
Resource objects (35228) 1
151 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.