7f3f3bf916ce7eeb5bc13d703d7f2a7fc98212a7da031403d696f8a68b4e5dd8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-28 07:43:45
Detected languages English - United States
Debug artifacts C:\Users\cathy\Documents\imgui\New folder\1h32pzt\x64\Release\PopstarRoblox.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • virus
Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • avatar.roblox.com
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • https://www.roblox.com
  • https://www.roblox.com/
  • meshCenter.xyz
  • meshScale.xyz
  • rbxcdn.com
  • roblox.com
  • thumbnails.roblox.com
  • tonos.top
  • uni02E5.cn
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
  • FindWindowW
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Possibly launches other programs:
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • WinHttpAddRequestHeaders
  • WinHttpQueryHeaders
  • WinHttpReadData
  • WinHttpOpen
  • WinHttpSetOption
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpConnect
  • WinHttpQueryDataAvailable
  • WinHttpReceiveResponse
  • WinHttpOpenRequest
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
Can take screenshots:
  • GetDC
  • FindWindowW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 d700bd0246e091380f19933aa65c05af
SHA1 38d76ac755e232c78a4bc79cd9bcc6baee525771
SHA256 7f3f3bf916ce7eeb5bc13d703d7f2a7fc98212a7da031403d696f8a68b4e5dd8
SHA3 cab241543c44ecacd89b8653ebde7e65331c49dd73195a12faa71d6ee2a48e18
SSDeep 49152:JEAbLPy09kr1++1Oerb5q6Y5HSjGmpZc:JEMY1++13Z4YGmp
Imports Hash 3f44fd846250bea2266761569c9a6ef2

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-28 07:43:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xb0c00
SizeOfInitializedData 0x131400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000AE5A4 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1e6000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b92af58bb2e7010937c8529094dde939
SHA1 d05bead20db6d5bbf1b88a86fef90af774e18960
SHA256 c69a1f495e005fa291d621c243b756bb76d6cd2eee2d759ef69328aa96840a12
SHA3 9d65f2d96f06a6575f4ccd28d07b148ea32320082ca8230746065445ba521222
VirtualSize 0xb0bfc
VirtualAddress 0x1000
SizeOfRawData 0xb0c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52982

.rdata

MD5 d47346e82f5e580e545b50a8105855f4
SHA1 db28cfa9a5c26776e0f1650cd937bfa2049cd642
SHA256 746ebec7effdfcb1970516ee4231f0ba2e76bbfc87d3ac70af9c4066060a6744
SHA3 0e0407b8d8837a6e204369eedac5a67c3cb25eeaf65eb2f3ade3ecd7bc3078e6
VirtualSize 0x123180
VirtualAddress 0xb2000
SizeOfRawData 0x123200
PointerToRawData 0xb1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.00169

.data

MD5 b49c7c1ea76059a8b3ff986aabeea185
SHA1 45dad4be60dc40d69a2dc6e77549559b223cccfe
SHA256 d06c904ec4ac02354ec6fef660e50df3580eb688f0ada89418f7d26be253e230
SHA3 4f0070e3ce1506b35efa9f160938a1398132ba6b6e8ff461e864a54908242926
VirtualSize 0x5f08
VirtualAddress 0x1d6000
SizeOfRawData 0xa00
PointerToRawData 0x1d4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.59929

.pdata

MD5 a3191107a338a2e12733baec410160c3
SHA1 aaed2040b595919e52f4a099499f38742b825f69
SHA256 3924242c3bf9d70cb7312f4c8f6c55005a867ea75e6b9f51f382382c5111a231
SHA3 dfd428918face544e694469b9ddc05d8805bfbedfff4c1adc135b0bf74060445
VirtualSize 0x786c
VirtualAddress 0x1dc000
SizeOfRawData 0x7a00
PointerToRawData 0x1d4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.00312

.rsrc

MD5 7c548659a336cb9544a3f3e0648f4ca9
SHA1 6bac26f8ad32a2de21ce02403af520fba8583096
SHA256 3bbef63dd89f64e259ca6c83f47d17eef19d0047eb0ed68fc5641fd252b6d22d
SHA3 8a3f9885e6f420cb19c87eb9125320ea28b50da7a4fa97f7e12bf0895ec10d56
VirtualSize 0x1e0
VirtualAddress 0x1e4000
SizeOfRawData 0x200
PointerToRawData 0x1dc600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71768

.reloc

MD5 ee94a6c1a74d5e2e4c584c064704cd0d
SHA1 587c970681e4724acb5e5ec7de750a50b208e2f4
SHA256 9000655ff547c454b40a09ee4a925649693242fdf0b4805b4dd60518f28159e1
SHA3 2d0775ed8acf9c710a5cd7e1e21181d6a0e38890de0d11578839501793f71cef
VirtualSize 0x4e8
VirtualAddress 0x1e5000
SizeOfRawData 0x600
PointerToRawData 0x1dc800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.81034

Imports

KERNEL32.dll GetTickCount
SetUnhandledExceptionFilter
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
CloseHandle
Module32FirstW
Module32NextW
OpenProcess
WaitForSingleObject
CreateThread
GetTickCount64
GetModuleHandleW
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
SwitchToThread
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
SetConsoleTitleA
FreeLibrary
QueryPerformanceCounter
AcquireSRWLockExclusive
SleepConditionVariableSRW
GetCurrentThreadId
WakeAllConditionVariable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetProcessDEPPolicy
GetCurrentThread
Sleep
SetThreadPriority
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
SetPriorityClass
VirtualAllocEx
ReleaseSRWLockExclusive
GetCurrentProcess
ReadProcessMemory
GetProcAddress
WriteProcessMemory
USER32.dll GetWindowThreadProcessId
GetWindowLongW
SetClipboardData
GetClipboardData
CloseClipboard
GetKeyState
GetMessageExtraInfo
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
IsWindowUnicode
ReleaseCapture
SetCursorPos
OpenClipboard
DefWindowProcW
GetWindowRect
DestroyWindow
GetAsyncKeyState
TranslateMessage
PeekMessageW
DispatchMessageW
mouse_event
SendInput
GetCursorPos
ReleaseDC
GetDC
GetWindowTextW
PostQuitMessage
GetClientRect
IsWindowVisible
SetWindowPos
CreateWindowExW
UnregisterClassW
RegisterClassExW
ShowWindow
IsWindow
EnumWindows
SetLayeredWindowAttributes
FindWindowW
SetWindowLongW
EmptyClipboard
GDI32.dll GetDeviceCaps
SHELL32.dll ShellExecuteA
MSVCP140.dll ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?_Xbad_function_call@std@@YAXXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
??Bios_base@std@@QEBA_NXZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Xlength_error@std@@YAXPEBD@Z
_Query_perf_frequency
?_Xbad_alloc@std@@YAXXZ
_Query_perf_counter
?_Throw_Cpp_error@std@@YAXH@Z
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
_Mtx_lock
_Mtx_unlock
_Cnd_signal
_Cnd_broadcast
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
D3DCOMPILER_47.dll D3DCompile
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpQueryHeaders
WinHttpReadData
WinHttpOpen
WinHttpSetOption
WinHttpCloseHandle
WinHttpSendRequest
WinHttpConnect
WinHttpQueryDataAvailable
WinHttpReceiveResponse
WinHttpOpenRequest
d3d11.dll D3D11CreateDeviceAndSwapChain
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
__std_exception_copy
__std_terminate
__C_specific_handler
wcsstr
strstr
memchr
memcmp
memcpy
memset
__current_exception
__current_exception_context
_CxxThrowException
memmove
api-ms-win-crt-runtime-l1-1-0.dll _cexit
terminate
_seh_filter_exe
_set_app_type
_crt_atexit
_get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
_errno
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_register_onexit_function
_initialize_onexit_table
_configure_narrow_argv
_invoke_watson
_initialize_narrow_environment
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
_callnewh
free
malloc
api-ms-win-crt-stdio-l1-1-0.dll fread
fseek
_wfopen
__stdio_common_vfprintf
fclose
__p__commode
_set_fmode
fflush
__stdio_common_vsprintf
__stdio_common_vsprintf_s
ftell
__stdio_common_vsscanf
setvbuf
fwrite
__acrt_iob_func
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
isdigit
strncmp
tolower
isspace
_stricmp
strncpy
strncpy_s
strcmp
api-ms-win-crt-convert-l1-1-0.dll strtoul
strtol
strtoull
atof
strtof
api-ms-win-crt-math-l1-1-0.dll atan2f
acosf
_fdclass
cosf
expf
floorf
fmodf
powf
nearbyint
ceilf
sqrtf
sinf
logf
round
__setusermatherr
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
strftime
_time64
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-28 07:43:45
Version 0.0
SizeofData 104
AddressOfRawData 0x1c5220
PointerToRawData 0x1c4220
Referenced File C:\Users\cathy\Documents\imgui\New folder\1h32pzt\x64\Release\PopstarRoblox.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-28 07:43:45
Version 0.0
SizeofData 20
AddressOfRawData 0x1c5288
PointerToRawData 0x1c4288

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-28 07:43:45
Version 0.0
SizeofData 892
AddressOfRawData 0x1c529c
PointerToRawData 0x1c429c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-28 07:43:45
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1401c5638
EndAddressOfRawData 0x1401c5640
AddressOfIndex 0x1401d6f1c
AddressOfCallbacks 0x1400b29d0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401d6040

RICH Header

XOR Key 0x8ef8bedf
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 39
Imports (35207) 6
Imports (33145) 19
Total imports 277
C++ objects (LTCG) (35228) 45
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.