8a72c285b697f82b79d9e641604e38c0b7c34066f66121c75fda3b53594cacf5

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-27 01:14:40
Detected languages English - United States

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .rbxcdn.com
  • assetdelivery.roblox.com
  • dpaste.com
  • dthumbnails.roblox.com
  • github.com
  • http://127.0.0.1
  • http://www.roblox.com
  • http://www.roblox.com/asset/?id
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://curl.se
  • https://dpaste.com
  • https://github.com
  • https://indiantypefoundry.comNinad
  • https://lrclib.net
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/users/avatar-3d?userId
  • lrclib.net
  • rbxcdn.com
  • roblox.com
  • scripts.sil.org
  • thumbnails.roblox.com
  • www.roblox.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
  • FindWindowA
Code injection capabilities:
  • OpenProcess
  • VirtualAllocEx
  • WriteProcessMemory
Can access the registry:
  • RegOpenKeyExA
  • RegCloseKey
  • RegQueryValueExA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryW
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptAcquireContextW
  • CryptDestroyHash
  • CryptHashData
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetAsyncKeyState
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualProtectEx
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpQueryHeaders
  • WinHttpOpen
  • WinHttpSendRequest
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpSetTimeouts
  • WinHttpOpenRequest
  • InternetReadFile
  • InternetCloseHandle
  • InternetOpenA
  • InternetOpenUrlA
  • InternetConnectA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
  • Process32Next
  • Process32First
  • Process32NextW
  • Process32FirstW
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 736b60fc2437a9f2fa58f867b2479eb7 🔍
SHA1 b7930d729ae27842307b1ea9628901840f24ae4f 🔍
SHA256 8a72c285b697f82b79d9e641604e38c0b7c34066f66121c75fda3b53594cacf5 🔍
SHA3 973eccc7bf97272a8f1d593e7cbb20f87ce15629c8c0e9a0b4104bb629667edf 🔍
SSDeep 98304:8bhZTMwF5RH0Pn7LjMgpWFE+Ugnmwh67Slp:8br5RwjMgpWFE+UgnrFl 🔍
Imports Hash 0c76382b6ac724c953d8a64de53f0956 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-27 01:14:40
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x235e00
SizeOfInitializedData 0x1a6000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000218DE0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3e0000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4442c0cf9ea2bf8cb180c0c61896195a 🔍
SHA1 bdb21268ae97fcbe5a9dfdf213185688a282d35a 🔍
SHA256 c5e3a212fcf51bde29592bf076aac0fa3d93aed7de25c7f6bd326ae046acc5d4 🔍
SHA3 23cb362a7c99f7571349bf20c3c59eebe8c27fc06c3e169346b757834f9fd1ad 🔍
VirtualSize 0x235cc8
VirtualAddress 0x1000
SizeOfRawData 0x235e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50385

.rdata

MD5 71a9487a03337505aba4d82727bfd59f 🔍
SHA1 6b82c3c954c74f6121d7a87189577011d8c0bad2 🔍
SHA256 4cbc7a9ed8318494c5034b7b6d76ffcd4f7b1ba7decd87e71643758f98c752ef 🔍
SHA3 b0d6a6acd4f3b6220a7d1207631227f08ec364fb5dc34a3ca5357f721c0d0cf2 🔍
VirtualSize 0x11e50e
VirtualAddress 0x237000
SizeOfRawData 0x11e600
PointerToRawData 0x236200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.85594

.data

MD5 c66442344f708bbddd2b8fc0c2537f85 🔍
SHA1 b3535f4be3083868aedab1e66988e99426b98cfd 🔍
SHA256 6ad480f5f4864bf5c8ab11120da507d2de7966580318df7babeb635d62d4af59 🔍
SHA3 d8a5574d1ff2961c8060367248775c1d2187e895d3b73fb7b7171dd7afe30fbe 🔍
VirtualSize 0x6f590
VirtualAddress 0x356000
SizeOfRawData 0x2e400
PointerToRawData 0x354800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.60133

.pdata

MD5 41da294c485bec127dccee6021d1aeb3 🔍
SHA1 2fbd7e198ce64b213543bacf023d908cf79994b8 🔍
SHA256 7958dae8555c974c1336345c7b1980ed7ee8798a408c0fffdb75a45a84d44533 🔍
SHA3 ae028568c76582b5fe15459cfc898c0bcb3c9f1a7a1e6a8a92ea4db659b755b1 🔍
VirtualSize 0x15f18
VirtualAddress 0x3c6000
SizeOfRawData 0x16000
PointerToRawData 0x382c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.27811

.rsrc

MD5 56cf0ffdec8535708df838f1db62b78e 🔍
SHA1 b87c501cbd01735bd472437093cfe3a3eab0aaca 🔍
SHA256 346201479cf6e29b4832606af83689fb6286e5552255124e3ef66bdb059e62df 🔍
SHA3 089ef92a2869c97c64be3d0a66ab3f04f0f7c6525faae8cb4b9882d7580169f9 🔍
VirtualSize 0x1e0
VirtualAddress 0x3dc000
SizeOfRawData 0x200
PointerToRawData 0x398c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70883

.reloc

MD5 98bf7df66296b941071256c856a22f83 🔍
SHA1 cd6a6ee3a8ca1e1cab164f7b065c0faa48b2f287 🔍
SHA256 fc3efb6644cd602b6e051eaa2ab71abafb358972b72a706ca2d5eb8e930b5b37 🔍
SHA3 80aef3f294b031f7cbcc3e3790b6dcf1aa14466814d6bd3bf51ab2d4a19fd141 🔍
VirtualSize 0x20f8
VirtualAddress 0x3dd000
SizeOfRawData 0x2200
PointerToRawData 0x398e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38992

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
WINHTTP.dll WinHttpQueryHeaders
WinHttpOpen
WinHttpSendRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpCloseHandle
WinHttpConnect
WinHttpSetTimeouts
WinHttpOpenRequest
WININET.dll HttpOpenRequestA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetOpenUrlA
HttpSendRequestA
InternetConnectA
D3DCOMPILER_47.dll D3DCompile
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleA
GetModuleHandleW
GetModuleFileNameA
GetProcAddress
FreeLibrary
LoadLibraryExW
api-ms-win-core-localization-l1-2-0.dll GetLocaleInfoA
GetLocaleInfoEx
FormatMessageA
FormatMessageW
api-ms-win-core-string-l1-1-0.dll MultiByteToWideChar
WideCharToMultiByte
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
LoadLibraryA
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceFrequency
QueryPerformanceCounter
api-ms-win-core-sysinfo-l1-2-0.dll GetSystemTimePreciseAsFileTime
VerSetConditionMask
api-ms-win-core-heap-l2-1-0.dll GlobalAlloc
LocalFree
GlobalFree
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalLock
GlobalUnlock
api-ms-win-core-sysinfo-l1-1-0.dll GetSystemDirectoryW
GetTickCount
GetTickCount64
GetSystemInfo
GetSystemTimeAsFileTime
api-ms-win-mm-time-l1-1-0.dll timeGetTime
timeBeginPeriod
timeEndPeriod
api-ms-win-core-processthreads-l1-1-1.dll OpenProcess
FlushInstructionCache
IsProcessorFeaturePresent
api-ms-win-core-synch-l1-2-0.dll InitOnceComplete
SleepConditionVariableSRW
Sleep
InitOnceBeginInitialize
WakeAllConditionVariable
api-ms-win-core-psapi-ansi-l1-1-0.dll K32GetModuleFileNameExA
QueryFullProcessImageNameA
api-ms-win-core-handle-l1-1-0.dll DuplicateHandle
CloseHandle
api-ms-win-ntuser-sysparams-l1-1-0.dll GetSystemMetrics
api-ms-win-core-console-l3-2-0.dll GetConsoleWindow
api-ms-win-core-memory-l1-1-0.dll VirtualProtect
VirtualQuery
VirtualQueryEx
VirtualFreeEx
ReadProcessMemory
VirtualProtectEx
VirtualAllocEx
WriteProcessMemory
api-ms-win-core-kernel32-legacy-l1-1-2.dll Process32Next
Process32First
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentProcess
GetCurrentProcessId
SetThreadPriority
GetProcessId
GetExitCodeProcess
ExitProcess
GetCurrentThread
GetCurrentThreadId
TerminateProcess
OpenProcessToken
SwitchToThread
api-ms-win-core-processenvironment-l1-1-0.dll GetCommandLineA
GetStdHandle
GetEnvironmentVariableA
api-ms-win-core-console-l1-1-0.dll SetConsoleMode
GetConsoleMode
api-ms-win-core-file-l1-2-2.dll AreFileApisANSI
GetVolumeInformationA
api-ms-win-core-toolhelp-l1-1-0.dll Process32NextW
CreateToolhelp32Snapshot
Process32FirstW
api-ms-win-core-debug-l1-1-0.dll IsDebuggerPresent
OutputDebugStringW
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
api-ms-win-core-registry-l1-1-0.dll RegOpenKeyExA
RegCloseKey
RegQueryValueExA
api-ms-win-core-processtopology-obsolete-l1-1-0.dll SetThreadAffinityMask
api-ms-win-core-errorhandling-l1-1-0.dll SetLastError
GetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-psapi-l1-1-0.dll K32GetModuleBaseNameW
api-ms-win-core-com-l1-1-0.dll CoInitializeEx
CoCreateInstance
CoUninitialize
CoCreateFreeThreadedMarshaler
api-ms-win-security-lsalookup-ansi-l2-1-0.dll LookupPrivilegeValueA
api-ms-win-security-base-l1-1-0.dll AdjustTokenPrivileges
KERNEL32.dll CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
GetProcessHeap
HeapFree
HeapAlloc
ReadFile
GetFileSizeEx
CreateFileA
Module32First
Module32Next
K32EnumProcessModulesEx
USER32.dll keybd_event
MapVirtualKeyA
SendInput
SetWindowTextA
GetWindowThreadProcessId
GetWindowTextLengthW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
IsWindowVisible
CreateWindowExW
UnregisterClassW
GetClassNameA
RegisterClassExW
ShowWindow
IsWindow
SetWindowLongA
SetWindowDisplayAffinity
GetMonitorInfoA
MoveWindow
EnumWindows
SetLayeredWindowAttributes
TranslateMessage
LoadIconA
PeekMessageA
PostQuitMessage
FindWindowA
UpdateWindow
IsIconic
ShowCursor
GetAsyncKeyState
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
MonitorFromWindow
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
SetProcessDPIAware
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
GetDesktopWindow
GetWindowTextW
GDI32.dll GetDeviceCaps
CreateSolidBrush
SHELL32.dll SHGetFolderPathA
ShellExecuteA
MSVCP140.dll ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
_Thrd_hardware_concurrency
_Cnd_signal
_Cnd_wait
_Cnd_register_at_thread_exit
?__ExceptionPtrRethrow@@YAXPEBX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
?__ExceptionPtrCreate@@YAXPEAX@Z
_Cnd_unregister_at_thread_exit
??0task_continuation_context@Concurrency@@AEAA@XZ
?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
?_ReportUnobservedException@details@Concurrency@@YAXXZ
?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
_Cnd_broadcast
_Thrd_join
_Thrd_id
?always_noconv@codecvt_base@std@@QEBA_NXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Random_device@std@@YAIXZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Xbad_function_call@std@@YAXXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
_Mtx_unlock
_Query_perf_counter
_Mtx_lock
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
_Xtime_get_ticks
?id@?$ctype@D@std@@2V0locale@2@A
?_Id_cnt@id@locale@std@@0HA
?_Xbad_alloc@std@@YAXXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exceptions@std@@YAHXZ
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmSetCompositionWindow
ImmGetContext
CRYPT32.dll CertFreeCertificateChain
CryptStringToBinaryW
PFXImportCertStore
CryptDecodeObjectEx
CertAddCertificateContextToStore
CertFindExtension
CertOpenStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertGetNameStringW
CertFreeCertificateContext
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
WS2_32.dll getpeername
connect
bind
inet_ntop
htonl
ntohs
inet_pton
WSAGetLastError
closesocket
getsockname
WSAEventSelect
WSAEnumNetworkEvents
WSACreateEvent
WSACloseEvent
send
getsockopt
listen
getaddrinfo
htons
recv
setsockopt
socket
freeaddrinfo
recvfrom
WSAIoctl
__WSAFDIsSet
select
accept
sendto
ioctlsocket
gethostname
WSASetLastError
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memcmp
memchr
memset
memmove
memcpy
longjmp
wcschr
__C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
__current_exception_context
strrchr
_CxxThrowException
_purecall
__current_exception
__intrinsic_setjmp
api-ms-win-crt-runtime-l1-1-0.dll __sys_nerr
_beginthreadex
_invalid_parameter_noinfo_noreturn
_invalid_parameter_noinfo
system
_errno
abort
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
_get_initial_narrow_environment
exit
_initterm
terminate
_initterm_e
_invoke_watson
_c_exit
__p___argv
__p___argc
__sys_errlist
_exit
api-ms-win-crt-math-l1-1-0.dll ldexp
lroundf
__setusermatherr
_dsign
cosf
_fdopen
sqrt
expf
_dclass
roundf
floorf
fmodf
logf
pow
powf
sinf
_fdclass
acosf
asinf
atan2f
ceilf
sqrtf
api-ms-win-crt-string-l1-1-0.dll strcmp
wcspbrk
strspn
wcsncmp
strpbrk
iswspace
wcsncpy
strcspn
strcpy_s
_wcsicmp
tolower
_strdup
isalnum
_stricmp
toupper
strncmp
strncpy
api-ms-win-crt-convert-l1-1-0.dll strtof
atoi
atof
wcstombs
strtoull
strtod
strtoul
strtol
strtoll
api-ms-win-crt-stdio-l1-1-0.dll ftell
__acrt_iob_func
fflush
__stdio_common_vfprintf
__stdio_common_vsprintf_s
_get_stream_buffer_pointers
__p__commode
_fseeki64
_read
_write
_fileno
feof
_close
fsetpos
_set_fmode
ungetc
setvbuf
fgetpos
_lseeki64
__stdio_common_vsscanf
fputc
_wopen
fseek
fputs
fread
__stdio_common_vsprintf
_wfopen
fgets
fwrite
fclose
fgetc
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
realloc
_callnewh
malloc
free
api-ms-win-crt-time-l1-1-0.dll _gmtime64
_time64
strftime
_localtime64
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
remove
_unlink
_fstat64
_wstat64
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
___lc_codepage_func
api-ms-win-core-file-l1-1-0.dll CreateDirectoryW
FindFirstFileExW
FindClose
FindFirstFileW
FindNextFileW
GetFileAttributesExW
CreateFileW
SetFileInformationByHandle
GetFileType
api-ms-win-core-synch-l1-1-0.dll DeleteCriticalSection
EnterCriticalSection
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
CreateEventW
SleepEx
ReleaseSRWLockShared
WaitForSingleObjectEx
AcquireSRWLockShared
InitializeCriticalSectionEx
WaitForSingleObject
LeaveCriticalSection
InitializeCriticalSection
SetEvent
api-ms-win-core-file-l2-1-0.dll GetFileInformationByHandleEx
MoveFileExW
api-ms-win-security-cryptoapi-l1-1-0.dll CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptEncrypt
CryptImportKey
CryptDestroyKey
CryptAcquireContextW
CryptDestroyHash
CryptHashData
api-ms-win-core-namedpipe-l1-1-0.dll PeekNamedPipe
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-core-kernel32-legacy-l1-1-1.dll VerifyVersionInfoW
api-ms-win-security-systemfunctions-l1-1-0.dll SystemFunction036
api-ms-win-core-rtlsupport-l1-1-0.dll RtlVirtualUnwind
RtlCaptureContext
RtlLookupFunctionEntry
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
InterlockedPushEntrySList
OLEAUT32.dll SysFreeString
GetErrorInfo
SysStringLen
SetErrorInfo
api-ms-win-core-winrt-error-l1-1-1.dll RoOriginateLanguageException
api-ms-win-core-winrt-l1-1-0.dll RoGetActivationFactory

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-27 01:14:40
Version 0.0
SizeofData 912
AddressOfRawData 0x320518
PointerToRawData 0x31f718

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-27 01:14:40
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1403208d0
EndAddressOfRawData 0x1403209a0
AddressOfIndex 0x1403849e0
AddressOfCallbacks 0x140238758
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140356f40

RICH Header

XOR Key 0xb9fdc3dc
Unmarked objects 0
253 (35207) 8
C objects (35207) 10
C++ objects (35207) 42
ASM objects (35207) 6
Imports (35207) 8
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 123
C++ objects (34436) 5
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (VS2008 SP1 build 30729) 136
Imports (33145) 32
Imports (21202) 3
Total imports 716
C++ objects (LTCG) (35228) 81
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.