| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-23 02:52:41 |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
C:\Users\ducph\source\repos\TSONLINE_BOT\PIMBOT_TSN\Pimbot\V10\PimBotV10\bin\Release\net10.0-windows\win-x64\native\PimBot.pdb
|
| Comments | Phần má»m chÆ¡i game tá»± Äá»ng (BOT) TSONLINE MOBILE |
| CompanyName | MP |
| FileDescription | PimBot |
| FileVersion | 3.1.2.3 |
| InternalName | PimBot.dll |
| LegalCopyright | Copyright © 2019 by MP |
| LegalTrademarks | |
| OriginalFilename | PimBot.dll |
| ProductName | PimBot |
| ProductVersion | 3.1.2.3 |
| Assembly Version | 3.1.2.3 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Apr-23 02:52:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xa16000 |
| SizeOfInitializedData | 0x1339000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000009FBAC4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1d53000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x180000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
AdjustTokenPrivileges
DeregisterEventSource GetTokenInformation ImpersonateLoggedOnUser LookupPrivilegeValueW OpenProcessToken OpenThreadToken RegCloseKey RegCreateKeyExW RegEnumKeyExW RegEnumValueW RegNotifyChangeKeyValue RegOpenKeyExW RegQueryValueExW RegSetValueExW RegisterEventSourceW ReportEventW RevertToSelf |
|---|---|
| bcrypt.dll |
BCryptCreateHash
BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptEncrypt BCryptHashData BCryptFinishHash BCryptGenRandom BCryptOpenAlgorithmProvider BCryptGetProperty BCryptDecrypt BCryptSetProperty BCryptImportKeyPair BCryptImportKey BCryptDestroyKey BCryptExportKey |
| CRYPT32.dll |
CertFreeCertificateContext
CertFreeCertificateChainEngine CertFreeCertificateChain CertEnumCertificatesInStore CertGetCertificateChain CertDuplicateCertificateContext CryptImportPublicKeyInfoEx2 CryptFormatObject CryptFindOIDInfo CryptDecodeObject CertVerifyCertificateChainPolicy CertOpenStore CertCreateCertificateChainEngine CertNameToStrW CertGetNameStringW CertGetCertificateContextProperty CertAddCertificateContextToStore CertAddCertificateLinkToStore CertCloseStore CertControlStore |
| IPHLPAPI.DLL |
ConvertInterfaceNameToLuidW
GetAdaptersAddresses GetNetworkParams GetPerAdapterInfo ConvertInterfaceLuidToIndex |
| KERNEL32.dll |
IsDebuggerPresent
HeapCreate HeapDestroy HeapFree GetProcessHeap InitializeSListHead SetUnhandledExceptionFilter RtlUnwindEx RtlPcToFileHeader FlsFree EncodePointer InitializeCriticalSectionEx HeapAlloc CancelIoEx CancelSynchronousIo CancelThreadpoolIo CloseHandle CloseThreadpoolIo CloseThreadpoolWait CloseThreadpoolWork CompareStringEx CompareStringOrdinal CreateDirectoryW CreateEventExW CreateFileW CreatePipe CreateProcessW CreateThread CreateThreadpoolIo CreateThreadpoolTimer CreateThreadpoolWait CreateThreadpoolWork DeleteCriticalSection DeleteFileW DeviceIoControl DuplicateHandle EnterCriticalSection EnumCalendarInfoExEx EnumTimeFormatsEx ExitProcess ExpandEnvironmentStringsW FileTimeToSystemTime FindClose FindFirstFileExW FindNLSStringEx FindStringOrdinal FlushFileBuffers FormatMessageW FreeLibrary GetCPInfo GetCPInfoExW GetCalendarInfoEx GetConsoleCP GetConsoleOutputCP GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentProcessorNumberEx GetCurrentThread GetCurrentThreadId GetDynamicTimeZoneInformation GetEnvironmentVariableW GetExitCodeProcess GetExitCodeThread GetFileAttributesExW GetFileInformationByHandleEx GetFileType GetFullPathNameW GetLastError GetLocaleInfoEx GetLogicalDrives GetLongPathNameW GetModuleFileNameW GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessId GetShortPathNameW GetStartupInfoW GetStdHandle GetSystemDefaultLCID GetSystemDirectoryW GetSystemTime GetThreadLocale GetThreadPriority GetTickCount64 GetTimeZoneInformation GetUserPreferredUILanguages GetVolumeInformationW GlobalAlloc GlobalFree InitializeConditionVariable InitializeCriticalSection K32EnumProcesses LCIDToLocaleName LCMapStringEx LeaveCriticalSection LoadLibraryExW LocalAlloc LocalFree LocaleNameToLCID MultiByteToWideChar OpenProcess OpenThread QueryPerformanceCounter QueryPerformanceFrequency QueryUnbiasedInterruptTime RaiseFailFastException ReadDirectoryChangesW ReadFile ResetEvent ResolveLocaleName ResumeThread SetConsoleCtrlHandler SetEvent SetFileInformationByHandle SetFilePointerEx SetLastError SetThreadErrorMode SetThreadPriority SetThreadpoolTimer SetThreadpoolWait Sleep SleepConditionVariableCS StartThreadpoolIo SubmitThreadpoolWork SystemTimeToFileTime TzSpecificLocalTimeToSystemTime VirtualAlloc VirtualFree WaitForMultipleObjectsEx WaitForSingleObject WaitForThreadpoolWaitCallbacks WakeConditionVariable WideCharToMultiByte WriteFile RaiseException AddVectoredExceptionHandler RtlVirtualUnwind RtlCaptureContext RtlRestoreContext VerSetConditionMask FlsAlloc FlsGetValue FlsSetValue WaitForSingleObjectEx CreateEventW SwitchToThread SuspendThread FlushProcessWriteBuffers GetThreadContext SetThreadContext FlushInstructionCache GetSystemTimeAsFileTime VirtualProtect CreateMemoryResourceNotification QueryInformationJobObject GetModuleHandleExW GetProcessAffinityMask VerifyVersionInfoW InitializeContext GetEnabledXStateFeatures LocateXStateFeature SetXStateFeaturesMask VirtualQuery DebugBreak SleepEx GlobalMemoryStatusEx GetSystemInfo GetLogicalProcessorInformation GetLogicalProcessorInformationEx GetLargePageMinimum VirtualUnlock VirtualAllocExNuma IsProcessInJob GetNumaHighestNodeNumber GetProcessGroupAffinity K32GetProcessMemoryInfo |
| ncrypt.dll |
NCryptFreeObject
NCryptGetProperty NCryptImportKey NCryptOpenKey NCryptOpenStorageProvider NCryptSetProperty NCryptDeleteKey |
| ole32.dll |
CoCreateGuid
CoCreateInstance CoGetApartmentType CoGetContextToken CoInitializeEx CoTaskMemAlloc CoTaskMemFree CoUninitialize PropVariantClear CoWaitForMultipleHandles |
| OLEAUT32.dll |
SafeArrayDestroy
SafeArrayGetElement SafeArrayGetVartype SafeArrayPutElement OleCreatePictureIndirect SafeArrayCreate SysAllocStringLen SysFreeString LoadRegTypeLib |
| USER32.dll |
LoadStringW
|
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeExW GetFileVersionInfoExW |
| WS2_32.dll |
GetAddrInfoExW
listen ioctlsocket getsockopt recv FreeAddrInfoW getpeername closesocket bind select send WSACleanup setsockopt shutdown GetAddrInfoW GetNameInfoW WSAConnect WSAEventSelect WSAGetOverlappedResult WSAIoctl WSARecv WSASend WSASocketW WSAStartup getsockname FreeAddrInfoExW accept |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_aligned_malloc calloc _set_new_mode _callnewh realloc malloc _aligned_free |
| api-ms-win-crt-math-l1-1-0.dll |
modf
modff pow powf sin sinf sinhf tan tanf logf log2f __setusermatherr acosf acoshf asinf asinhf atan atan2f atanf atanhf tanhf cbrtf ceil ceilf cos cosf coshf expf floor floorf fmaf fmod fmodf log10f log |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
strlen strcmp strcpy strncpy_s _stricmp |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoull
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vfprintf
__stdio_common_vsprintf_s __stdio_common_vsnprintf_s __acrt_iob_func __stdio_common_vsscanf _set_fmode __p__commode |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
_exit _initterm_e _initterm _get_initial_wide_environment terminate _crt_atexit _register_onexit_function _initialize_onexit_table _initialize_wide_environment _configure_wide_argv _set_app_type _seh_filter_exe _cexit _register_thread_local_exe_atexit_callback _c_exit __p___wargv exit abort |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Ordinal | 1 |
|---|---|
| Address | 0x9e86c0 |
| Ordinal | 2 |
|---|---|
| Address | 0x9e87d0 |
| Ordinal | 3 |
|---|---|
| Address | 0x9e8880 |
| Ordinal | 4 |
|---|---|
| Address | 0x9e8950 |
| Ordinal | 5 |
|---|---|
| Address | 0x9e9e50 |
| Ordinal | 6 |
|---|---|
| Address | 0x9e9ea0 |
| Ordinal | 7 |
|---|---|
| Address | 0x9ea050 |
| Ordinal | 8 |
|---|---|
| Address | 0x9ea060 |
| Ordinal | 9 |
|---|---|
| Address | 0x9ea0a0 |
| Ordinal | 10 |
|---|---|
| Address | 0x9ea0e0 |
| Ordinal | 11 |
|---|---|
| Address | 0x9ea100 |
| Ordinal | 12 |
|---|---|
| Address | 0x9ea120 |
| Ordinal | 13 |
|---|---|
| Address | 0x9ea170 |
| Ordinal | 14 |
|---|---|
| Address | 0x99e3e0 |
| Ordinal | 15 |
|---|---|
| Address | 0xa0e400 |
| Ordinal | 16 |
|---|---|
| Address | 0xa0e410 |
| Ordinal | 17 |
|---|---|
| Address | 0x99cf10 |
| Ordinal | 18 |
|---|---|
| Address | 0x99d110 |
| Ordinal | 19 |
|---|---|
| Address | 0x99d6c0 |
| Ordinal | 20 |
|---|---|
| Address | 0x99de10 |
| Ordinal | 21 |
|---|---|
| Address | 0x99dfd0 |
| Ordinal | 22 |
|---|---|
| Address | 0x99e140 |
| Ordinal | 23 |
|---|---|
| Address | 0x99e1b0 |
| Ordinal | 24 |
|---|---|
| Address | 0x99e1c0 |
| Ordinal | 25 |
|---|---|
| Address | 0x99e1e0 |
| Ordinal | 26 |
|---|---|
| Address | 0x99e210 |
| Ordinal | 27 |
|---|---|
| Address | 0x99e290 |
| Ordinal | 28 |
|---|---|
| Address | 0x99e370 |
| Ordinal | 29 |
|---|---|
| Address | 0x99e3e0 |
| Ordinal | 30 |
|---|---|
| Address | 0xa0e420 |
| Ordinal | 31 |
|---|---|
| Address | 0xa0e430 |
| Ordinal | 32 |
|---|---|
| Address | 0x95d5c0 |
| Ordinal | 33 |
|---|---|
| Address | 0xa0e830 |
| Ordinal | 34 |
|---|---|
| Address | 0xa0e860 |
| Ordinal | 35 |
|---|---|
| Address | 0xa0e940 |
| Ordinal | 36 |
|---|---|
| Address | 0xa0e440 |
| Ordinal | 37 |
|---|---|
| Address | 0x1bc5760 |
| Ordinal | 38 |
|---|---|
| Address | 0x195f380 |
| Ordinal | 39 |
|---|---|
| Address | 0x197dee0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 3.1.2.3 |
| ProductVersion | 3.1.2.3 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Comments | Phần má»m chÆ¡i game tá»± Äá»ng (BOT) TSONLINE MOBILE |
| CompanyName | MP |
| FileDescription | PimBot |
| FileVersion (#2) | 3.1.2.3 |
| InternalName | PimBot.dll |
| LegalCopyright | Copyright © 2019 by MP |
| LegalTrademarks | |
| OriginalFilename | PimBot.dll |
| ProductName | PimBot |
| ProductVersion (#2) | 3.1.2.3 |
| Assembly Version | 3.1.2.3 |
| Resource LangID | UNKNOWN |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-23 02:52:41 |
| Version | 0.0 |
| SizeofData | 151 |
| AddressOfRawData | 0x197f45c |
| PointerToRawData | 0x197e85c |
| Referenced File | C:\Users\ducph\source\repos\TSONLINE_BOT\PIMBOT_TSN\Pimbot\V10\PimBotV10\bin\Release\net10.0-windows\win-x64\native\PimBot.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-23 02:52:41 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x197f4f4 |
| PointerToRawData | 0x197e8f4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-23 02:52:41 |
| Version | 0.0 |
| SizeofData | 1216 |
| AddressOfRawData | 0x197f508 |
| PointerToRawData | 0x197e908 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-23 02:52:41 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x197f9f0 |
| PointerToRawData | 0x197edf0 |
| StartAddressOfRawData | 0x14197fa20 |
|---|---|
| EndAddressOfRawData | 0x14197fb49 |
| AddressOfIndex | 0x141c02fe8 |
| AddressOfCallbacks | 0x140a17ce8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001409FBAD8
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x141bc6580 |
| XOR Key | 0xb9d9c127 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (35403) | 9 |
| C objects (35403) | 13 |
| C++ objects (35403) | 47 |
| Imports (VS2008 SP1 build 30729) | 14 |
| Imports (33145) | 23 |
| Total imports | 392 |
| ASM objects (35223) | 10 |
| C objects (35223) | 75 |
| Unmarked objects (#2) | 1 |
| C++ objects (35223) | 65 |
| Exports (35729) | 1 |
| Linker (35729) | 1 |
No comments yet.