| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-16 16:52:54 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\vexx\Documents\Sources\Secureloader\Genesis\x64\Release\bypass.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 46/70 (Scanned on 2026-08-02 12:33:18) |
ALYac:
Gen:Variant.Yogi.10608
APEX: Malicious AVG: Win64:MalwareX-gen [Misc] AhnLab-V3: Trojan/Win.Generic.C5899308 Alibaba: Trojan:Win32/Khalesi.e8996d21 Antiy-AVL: Trojan/Win64.GenKryptik Arcabit: Trojan.Yogi.D2970 Avast: Win64:MalwareX-gen [Misc] Avira: TR/W64.Agent BitDefender: Gen:Variant.Yogi.10608 Bkav: W32.Malware.DD312770 CTX: exe.unknown.yogi CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe Cynet: Malicious (score: 99) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GenKryptik_AGen.DSY trojan Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Yogi.10608 (B) F-Secure: Trojan.TR/W64.Agent Fortinet: W64/GenKryptik_AGen.DSY!tr GData: Gen:Variant.Yogi.10608 Google: Detected Kaspersky: Trojan.Win32.Khalesi.rhxl Kingsoft: Win32.Troj.Unknown.a Lionic: Trojan.Win32.Khalesi.4!c Malwarebytes: Trojan.Crypt MaxSecure: Trojan.Malware.345033516.susgen McAfeeD: ti!902584A04274 MicroWorld-eScan: Gen:Variant.Yogi.10608 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Rising: Trojan.Kryptik!8.8 (TFE:5:ydpm8HRMw0K) SentinelOne: Static AI - Malicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Tencent: Malware.Win32.Gencirc.14afe7a5 TrellixENS: Artemis!468D4BE3B71E TrendMicro: Trojan.Win32.ZYX.USBLFI26 TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLFI26 VBA32: Trojan.Khalesi VIPRE: Gen:Variant.Yogi.10608 Varist: W64/ABTrojan.KNEY-1980 ViRobot: Trojan.Win.Z.Khalesi.2506752 alibabacloud: Trojan:Win/GenKryptik_AGen.DBT huorong: TrojanDropper/Agent.arb |
| MD5 | 468d4be3b71eea444c233ea682ea2f29 🔍 |
|---|---|
| SHA1 | 21559b0d04719811d35d2482c0b455b8540e581e 🔍 |
| SHA256 | 902584a04274d0cfbb766ace6f0b52d90d4b43bd0c6bda89ca5a6547662f02b2 🔍 |
| SHA3 | 912ef605d1dab71bb62fe81904528f61829884de6c86aa59168a610ed72e527b 🔍 |
| SSDeep | 49152:HoaFRu674+P2Jn2fpJ+79akz2UsnE73nowWx2mk9GDBWASp:nDJU9Tsnzc14Dm 🔍 |
| Imports Hash | c858de1c52870f326958ecff2d32dfef 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-16 16:52:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x126e00 |
| SizeOfInitializedData | 0x13ee00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000121844 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x269000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0687a36ad916bb7b22b355fcda80306a 🔍 |
|---|---|
| SHA1 | afa52409982f2642f5773efdf619d8a010294d53 🔍 |
| SHA256 | f8f76ad54b2adc2e1910d3c3b19c1dacd184499776ee8820a6297388040509d4 🔍 |
| SHA3 | 89061bd3fed04d7c15ef795cf9437a01828d294cf29c44b3b5d7aacaa1ec58b0 🔍 |
| VirtualSize | 0x126d27 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x126e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.43841 |
| MD5 | 50c4a7c4b98615a02574d3b85c0e427e 🔍 |
|---|---|
| SHA1 | de032f956c198f48a585324ff78b63e31c2aaeeb 🔍 |
| SHA256 | 7be96b72c30dae0da842f855ff555f4ff43d755cd50bb23b820904e62c529425 🔍 |
| SHA3 | 63cf8d9c52c94de5e7e1d4d8eeb28117da7c6e705afb31a8390e0adc349a28fe 🔍 |
| VirtualSize | 0x901b2 |
| VirtualAddress | 0x128000 |
| SizeOfRawData | 0x90200 |
| PointerToRawData | 0x127200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.86927 |
| MD5 | 59f073bcc8607e8cc9259ae385cfc02d 🔍 |
|---|---|
| SHA1 | 49b993666b081ed5359679270bf1d207494c23d8 🔍 |
| SHA256 | 7281271769b358abeb7de6aacf94419f5401581b8dece6b40cf2e505cc7ff778 🔍 |
| SHA3 | 125ed293461d20b7a1e38cb7ba735453c9ef6376792479a8d7fc7ecbd200a289 🔍 |
| VirtualSize | 0x2e60 |
| VirtualAddress | 0x1b9000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x1b7400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.46994 |
| MD5 | 9cedfc7e28f56d7b3185477e61242073 🔍 |
|---|---|
| SHA1 | 2583b83718f89e7e0daeb973a982e1c666ee122f 🔍 |
| SHA256 | 3784a55be1da1be4b84cbb63826d33d138065dca97b9120797b6a801a6743999 🔍 |
| SHA3 | 1c30c4b1ae6bee73fde0835cab5b88a8dacc4baee86565689b24f429a4d3acc6 🔍 |
| VirtualSize | 0xa5d8 |
| VirtualAddress | 0x1bc000 |
| SizeOfRawData | 0xa600 |
| PointerToRawData | 0x1b8400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.16892 |
| MD5 | f7302ba176d2c661301324c5797d34b2 🔍 |
|---|---|
| SHA1 | a4b2667a7f639f80c6eeef8d601122202b62b620 🔍 |
| SHA256 | 84ec4a357e3769af5fc7c7f1ebe666db9d52ecb3e76c4da76881dae7647bf19f 🔍 |
| SHA3 | 7109d2478766d074c56d097550182a41504b8763a83e75e1bec0b0eb0d53d851 🔍 |
| VirtualSize | 0xa0538 |
| VirtualAddress | 0x1c7000 |
| SizeOfRawData | 0xa0600 |
| PointerToRawData | 0x1c2a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.96092 |
| MD5 | a9f956e992669c0c0f8e703ed2a880c6 🔍 |
|---|---|
| SHA1 | 40152a10cb4e877e11098d12ecffcb93802c95f6 🔍 |
| SHA256 | bb81d920ba6638a003a3ae7611fe61ab0e93808467db26071ddbf8f48ff3b462 🔍 |
| SHA3 | 4bdd4366e2c0301360a4c4742ca891deac6b667c22029746c0d067ca0de364df 🔍 |
| VirtualSize | 0xefc |
| VirtualAddress | 0x268000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x263000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.31033 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| WININET.dll |
InternetOpenUrlA
InternetOpenA InternetReadFile InternetCloseHandle |
| KERNEL32.dll |
LoadResource
WriteFile GetTempPathW CreateFileW GetCurrentThreadId GetTickCount64 GetLastError DeleteFileW CloseHandle GetCurrentProcessId CreateProcessW FlushFileBuffers CreateDirectoryW ReadFile GetVolumeInformationW Sleep GetComputerNameW HeapFree HeapAlloc GetProcessHeap GetEnvironmentVariableW GetFileAttributesW MoveFileExW GetFileSizeEx LocalFree SetLastError GetTempPathA OutputDebugStringA FindResourceA CreateToolhelp32Snapshot Process32NextW GetCurrentThread Process32FirstW K32GetModuleBaseNameA GetThreadContext K32EnumProcessModules IsDebuggerPresent CheckRemoteDebuggerPresent CreateFileA MapViewOfFile UnmapViewOfFile CreateFileMappingA GetTickCount RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter IsProcessorFeaturePresent GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead InitOnceComplete InitOnceBeginInitialize LockResource SizeofResource GetModuleFileNameA SetUnhandledExceptionFilter TerminateProcess GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GlobalAlloc QueryPerformanceCounter FreeLibrary GetProcAddress QueryPerformanceFrequency LoadLibraryA MultiByteToWideChar GetLocaleInfoA SleepConditionVariableSRW GetModuleHandleW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive GetCurrentProcess |
| USER32.dll |
SetCursorPos
IsWindowVisible EnumWindows GetWindowTextW DefWindowProcW DispatchMessageA GetWindowRect DestroyWindow MessageBoxW SetWindowRgn CreateWindowExW GetSystemMetrics UnregisterClassW RegisterClassExW ShowWindow MoveWindow TranslateMessage LoadIconA PeekMessageA PostQuitMessage UpdateWindow OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetKeyState SetCursor GetMessageExtraInfo LoadCursorA ScreenToClient ReleaseCapture IsWindowUnicode GetClientRect SetCapture GetForegroundWindow GetKeyboardLayout TrackMouseEvent ClientToScreen GetCapture GetCursorPos |
| GDI32.dll |
CreateRoundRectRgn
|
| ADVAPI32.dll |
CryptDestroyHash
CryptGenRandom CredWriteW CredReadW CredFree CredDeleteW CryptReleaseContext RegCloseKey CryptAcquireContextW RegQueryValueExW CryptGetHashParam RegOpenKeyExW CryptCreateHash CryptHashData |
| SHELL32.dll |
ShellExecuteW
SHGetFolderPathW ShellExecuteA |
| ole32.dll |
CoCreateInstance
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| MSVCP140.dll |
_Thrd_detach
_Query_perf_counter _Cnd_do_broadcast_at_thread_exit _Mtx_lock ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?_Throw_Cpp_error@std@@YAXH@Z _Strxfrm ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?id@?$ctype@D@std@@2V0locale@2@A ?id@?$collate@D@std@@2V0locale@2@A _Strcoll ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z ?tolower@?$ctype@D@std@@QEBADD@Z ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z _Thrd_id _Thrd_join _Query_perf_frequency ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Xbad_function_call@std@@YAXXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ _Mtx_unlock ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?_Xbad_alloc@std@@YAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Random_device@std@@YAIXZ ?__ExceptionPtrCreate@@YAXPEAX@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?uncaught_exceptions@std@@YAHXZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?__ExceptionPtrToBool@@YA_NPEBX@Z ?__ExceptionPtrDestroy@@YAXPEAX@Z ?__ExceptionPtrCurrentException@@YAXPEAX@Z ?__ExceptionPtrRethrow@@YAXPEBX@Z ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| WINHTTP.dll |
WinHttpAddRequestHeaders
WinHttpQueryHeaders WinHttpReadData WinHttpReceiveResponse WinHttpSetOption WinHttpCloseHandle WinHttpSendRequest WinHttpQueryDataAvailable WinHttpOpen WinHttpOpenRequest WinHttpConnect |
| bcrypt.dll |
BCryptGetProperty
BCryptGenerateSymmetricKey BCryptSetProperty BCryptDecrypt BCryptDestroyKey BCryptCreateHash BCryptHashData BCryptDestroyHash BCryptCloseAlgorithmProvider BCryptFinishHash BCryptOpenAlgorithmProvider |
| RPCRT4.dll |
RpcStringFreeA
UuidToStringA UuidCreate |
| CRYPT32.dll |
CryptProtectData
CryptStringToBinaryA CryptUnprotectData |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_exception_destroy
__std_exception_copy strstr strchr __current_exception_context __current_exception strrchr longjmp memchr memcpy wcsstr __intrinsic_setjmp _CxxThrowException memmove memset __std_terminate __C_specific_handler memcmp |
| api-ms-win-crt-stdio-l1-1-0.dll |
fwrite
fread __stdio_common_vsscanf __p__commode __stdio_common_vfprintf fseek fclose fflush fputc __acrt_iob_func __stdio_common_vswprintf_s ftell _get_stream_buffer_pointers _fseeki64 __stdio_common_vsprintf fsetpos ungetc fgetc setvbuf _set_fmode fgetpos __stdio_common_vsprintf_s _wfopen |
| api-ms-win-crt-heap-l1-1-0.dll |
realloc
free _set_new_mode malloc _callnewh |
| api-ms-win-crt-runtime-l1-1-0.dll |
_Exit
_c_exit _exit _initterm _get_narrow_winmain_command_line _set_app_type _seh_filter_exe exit _cexit _crt_atexit _beginthreadex terminate _invoke_watson set_terminate _register_onexit_function _initialize_onexit_table abort _initterm_e _initialize_narrow_environment _configure_narrow_argv _register_thread_local_exe_atexit_callback |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
towlower
strcmp strncpy strncpy_s strcpy_s wcscpy_s isxdigit tolower strncmp isdigit |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
strtoull atoi |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
_localtime64_s |
| api-ms-win-crt-math-l1-1-0.dll |
powf
fmodf cosf ceilf sinf acosf sqrtf __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1aeaf |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.96927 |
| Detected Filetype | PNG graphic file |
| MD5 | 168af5cbf53b6f2ded3afb5a6d147d0a 🔍 |
| SHA1 | 6929121ac449d9891628cb7b108ae1929376d73f 🔍 |
| SHA256 | 9528a0daae55524d0861ae861f6ed930effb185c756dcd8250730cbf35a8e17f 🔍 |
| SHA3 | c224c89bf4a4a7432b44fa44f92859c0783dd9808f1e6dda1ed7c6398eda25e1 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4a1ae |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.97827 |
| Detected Filetype | Windows animated cursor |
| MD5 | 3824a3c807e6c6c36cc9585feec78ce8 🔍 |
| SHA1 | ecfe8d48a765c4a447b8efe2bbab867593b19857 🔍 |
| SHA256 | ac6912678122d13c8d17e5c3db2172feb3a89c67ceb0367410f5df82058abdf8 🔍 |
| SHA3 | d72bd22cc080f77af51c3f779ad84a4d3173b69fe20f4dae03d829dcf101ad63 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4b11 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.97516 |
| Detected Filetype | JPEG graphic file |
| MD5 | 2694b61052bdaaf75a4f7a5e530ba802 🔍 |
| SHA1 | b4dde4893d4ec88d747f9a9a03370d112204e01d 🔍 |
| SHA256 | 225fd8a888365a970b2e06611f5b08e2fa25d00fd9a217780957d1a7bb2f9335 🔍 |
| SHA3 | 091f76839cc7ca0c7b062474f2a706a848d0086ebe4e32c3d258b9e64bd873b9 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2d758 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.88289 |
| Detected Filetype | PNG graphic file |
| MD5 | d9459b1b0748c4b3611a8ba9b1599758 🔍 |
| SHA1 | 1344f8d4403e98ffbdcf4d35f520e542e7cc2af2 🔍 |
| SHA256 | a112426c2a29cbd852add29baecccda232d99420c06bc19c2b85753c1f7b44bc 🔍 |
| SHA3 | 7269524b9484bb0182d9bfcff64ddd849e9addbbb5c8a850f1d07889c43a1af1 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x8f82 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.74761 |
| Detected Filetype | PNG graphic file |
| MD5 | 494607afce1422721e5a856f79e69cac 🔍 |
| SHA1 | c9fa8b96841ad3d669cb42d5615b431ca363bc75 🔍 |
| SHA256 | 185cbd3f12fa2e88006d29bfbcec110f288b74a4abbb71df7ad22bed567f1503 🔍 |
| SHA3 | ba0a16fc89f68e52866fd1bf5a32ddcf2a09d4857c1d2f953cedbcbc7ba1d568 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-16 16:52:54 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0x1a265c |
| PointerToRawData | 0x1a185c |
| Referenced File | C:\Users\vexx\Documents\Sources\Secureloader\Genesis\x64\Release\bypass.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-16 16:52:54 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1a26c0 |
| PointerToRawData | 0x1a18c0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-16 16:52:54 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x1a26d4 |
| PointerToRawData | 0x1a18d4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-16 16:52:54 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1401a2a88 |
|---|---|
| EndAddressOfRawData | 0x1401a2b88 |
| AddressOfIndex | 0x1401ba528 |
| AddressOfCallbacks | 0x140128d60 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1401b9040 |
| XOR Key | 0x49575f9 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| Imports (35207) | 6 |
| 253 (35207) | 1 |
| ASM objects (35207) | 6 |
| C objects (35207) | 10 |
| C++ objects (35207) | 34 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| C++ objects (33145) | 1 |
| Imports (33145) | 31 |
| Total imports | 403 |
| C++ objects (LTCG) (35225) | 51 |
| Resource objects (35225) | 1 |
| 151 | 1 |
| Linker (35225) | 1 |
No comments yet.