902584a04274d0cfbb766ace6f0b52d90d4b43bd0c6bda89ca5a6547662f02b2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jun-16 16:52:54
Detected languages English - United States
Debug artifacts C:\Users\vexx\Documents\Sources\Secureloader\Genesis\x64\Release\bypass.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • procexp.exe
  • procmon.exe
  • wireshark.exe
Contains references to debugging or reversing tools:
  • lordpe.exe
  • ollydbg.exe
Looks for VMWare presence:
  • VMware
  • vmmouse
Looks for Sandboxie presence:
  • sbiedll.dll
Looks for VirtualBox presence:
  • SOFTWARE\Oracle\VirtualBox Guest Additions
  • VBoxGuest
Contains domain names:
  • 9I68HV.au
  • attribution.com
  • discord.com
  • http://ns.attribution.com
  • http://ns.attribution.com/ads/1.0/'
  • http://purl.org
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#'
  • https://discord.com
  • https://discord.gg
  • https://i.imgur.com
  • https://i.imgur.com/4BGmIgH.png
  • https://i.imgur.com/8Crta8P.png
  • https://i.imgur.com/8WOEZa8.png
  • https://i.imgur.com/AFniYwh.png
  • https://i.imgur.com/DtVSPHN.png
  • https://i.imgur.com/FaSWh0V.png
  • https://i.imgur.com/nQmzZh9.png
  • https://i.imgur.com/uYFgjPO.png
  • https://i.imgur.com/vcBXkXp.png
  • https://vexor.wtf
  • i.imgur.com
  • imgur.com
  • ns.attribution.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
Can access the registry:
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
  • ShellExecuteA
Uses Microsoft's cryptographic API:
  • CryptDestroyHash
  • CryptGenRandom
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptProtectData
  • CryptStringToBinaryA
  • CryptUnprotectData
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • GetTempPathA
  • CreateFileA
Has Internet access capabilities:
  • InternetOpenUrlA
  • InternetOpenA
  • InternetReadFile
  • InternetCloseHandle
  • WinHttpAddRequestHeaders
  • WinHttpQueryHeaders
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSetOption
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpQueryDataAvailable
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpConnect
Enumerates local disk drives:
  • GetVolumeInformationW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 46/70 (Scanned on 2026-08-02 12:33:18) ALYac: Gen:Variant.Yogi.10608
APEX: Malicious
AVG: Win64:MalwareX-gen [Misc]
AhnLab-V3: Trojan/Win.Generic.C5899308
Alibaba: Trojan:Win32/Khalesi.e8996d21
Antiy-AVL: Trojan/Win64.GenKryptik
Arcabit: Trojan.Yogi.D2970
Avast: Win64:MalwareX-gen [Misc]
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Yogi.10608
Bkav: W32.Malware.DD312770
CTX: exe.unknown.yogi
CrowdStrike: win/malicious_confidence_70% (W)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/GenKryptik_AGen.DSY trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.10608 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W64/GenKryptik_AGen.DSY!tr
GData: Gen:Variant.Yogi.10608
Google: Detected
Kaspersky: Trojan.Win32.Khalesi.rhxl
Kingsoft: Win32.Troj.Unknown.a
Lionic: Trojan.Win32.Khalesi.4!c
Malwarebytes: Trojan.Crypt
MaxSecure: Trojan.Malware.345033516.susgen
McAfeeD: ti!902584A04274
MicroWorld-eScan: Gen:Variant.Yogi.10608
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Rising: Trojan.Kryptik!8.8 (TFE:5:ydpm8HRMw0K)
SentinelOne: Static AI - Malicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.14afe7a5
TrellixENS: Artemis!468D4BE3B71E
TrendMicro: Trojan.Win32.ZYX.USBLFI26
TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLFI26
VBA32: Trojan.Khalesi
VIPRE: Gen:Variant.Yogi.10608
Varist: W64/ABTrojan.KNEY-1980
ViRobot: Trojan.Win.Z.Khalesi.2506752
alibabacloud: Trojan:Win/GenKryptik_AGen.DBT
huorong: TrojanDropper/Agent.arb

Hashes

MD5 468d4be3b71eea444c233ea682ea2f29 🔍
SHA1 21559b0d04719811d35d2482c0b455b8540e581e 🔍
SHA256 902584a04274d0cfbb766ace6f0b52d90d4b43bd0c6bda89ca5a6547662f02b2 🔍
SHA3 912ef605d1dab71bb62fe81904528f61829884de6c86aa59168a610ed72e527b 🔍
SSDeep 49152:HoaFRu674+P2Jn2fpJ+79akz2UsnE73nowWx2mk9GDBWASp:nDJU9Tsnzc14Dm 🔍
Imports Hash c858de1c52870f326958ecff2d32dfef 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jun-16 16:52:54
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x126e00
SizeOfInitializedData 0x13ee00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000121844 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x269000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0687a36ad916bb7b22b355fcda80306a 🔍
SHA1 afa52409982f2642f5773efdf619d8a010294d53 🔍
SHA256 f8f76ad54b2adc2e1910d3c3b19c1dacd184499776ee8820a6297388040509d4 🔍
SHA3 89061bd3fed04d7c15ef795cf9437a01828d294cf29c44b3b5d7aacaa1ec58b0 🔍
VirtualSize 0x126d27
VirtualAddress 0x1000
SizeOfRawData 0x126e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.43841

.rdata

MD5 50c4a7c4b98615a02574d3b85c0e427e 🔍
SHA1 de032f956c198f48a585324ff78b63e31c2aaeeb 🔍
SHA256 7be96b72c30dae0da842f855ff555f4ff43d755cd50bb23b820904e62c529425 🔍
SHA3 63cf8d9c52c94de5e7e1d4d8eeb28117da7c6e705afb31a8390e0adc349a28fe 🔍
VirtualSize 0x901b2
VirtualAddress 0x128000
SizeOfRawData 0x90200
PointerToRawData 0x127200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.86927

.data

MD5 59f073bcc8607e8cc9259ae385cfc02d 🔍
SHA1 49b993666b081ed5359679270bf1d207494c23d8 🔍
SHA256 7281271769b358abeb7de6aacf94419f5401581b8dece6b40cf2e505cc7ff778 🔍
SHA3 125ed293461d20b7a1e38cb7ba735453c9ef6376792479a8d7fc7ecbd200a289 🔍
VirtualSize 0x2e60
VirtualAddress 0x1b9000
SizeOfRawData 0x1000
PointerToRawData 0x1b7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.46994

.pdata

MD5 9cedfc7e28f56d7b3185477e61242073 🔍
SHA1 2583b83718f89e7e0daeb973a982e1c666ee122f 🔍
SHA256 3784a55be1da1be4b84cbb63826d33d138065dca97b9120797b6a801a6743999 🔍
SHA3 1c30c4b1ae6bee73fde0835cab5b88a8dacc4baee86565689b24f429a4d3acc6 🔍
VirtualSize 0xa5d8
VirtualAddress 0x1bc000
SizeOfRawData 0xa600
PointerToRawData 0x1b8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.16892

.rsrc

MD5 f7302ba176d2c661301324c5797d34b2 🔍
SHA1 a4b2667a7f639f80c6eeef8d601122202b62b620 🔍
SHA256 84ec4a357e3769af5fc7c7f1ebe666db9d52ecb3e76c4da76881dae7647bf19f 🔍
SHA3 7109d2478766d074c56d097550182a41504b8763a83e75e1bec0b0eb0d53d851 🔍
VirtualSize 0xa0538
VirtualAddress 0x1c7000
SizeOfRawData 0xa0600
PointerToRawData 0x1c2a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.96092

.reloc

MD5 a9f956e992669c0c0f8e703ed2a880c6 🔍
SHA1 40152a10cb4e877e11098d12ecffcb93802c95f6 🔍
SHA256 bb81d920ba6638a003a3ae7611fe61ab0e93808467db26071ddbf8f48ff3b462 🔍
SHA3 4bdd4366e2c0301360a4c4742ca891deac6b667c22029746c0d067ca0de364df 🔍
VirtualSize 0xefc
VirtualAddress 0x268000
SizeOfRawData 0x1000
PointerToRawData 0x263000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.31033

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
WININET.dll InternetOpenUrlA
InternetOpenA
InternetReadFile
InternetCloseHandle
KERNEL32.dll LoadResource
WriteFile
GetTempPathW
CreateFileW
GetCurrentThreadId
GetTickCount64
GetLastError
DeleteFileW
CloseHandle
GetCurrentProcessId
CreateProcessW
FlushFileBuffers
CreateDirectoryW
ReadFile
GetVolumeInformationW
Sleep
GetComputerNameW
HeapFree
HeapAlloc
GetProcessHeap
GetEnvironmentVariableW
GetFileAttributesW
MoveFileExW
GetFileSizeEx
LocalFree
SetLastError
GetTempPathA
OutputDebugStringA
FindResourceA
CreateToolhelp32Snapshot
Process32NextW
GetCurrentThread
Process32FirstW
K32GetModuleBaseNameA
GetThreadContext
K32EnumProcessModules
IsDebuggerPresent
CheckRemoteDebuggerPresent
CreateFileA
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
GetTickCount
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
IsProcessorFeaturePresent
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
InitOnceComplete
InitOnceBeginInitialize
LockResource
SizeofResource
GetModuleFileNameA
SetUnhandledExceptionFilter
TerminateProcess
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
QueryPerformanceCounter
FreeLibrary
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
MultiByteToWideChar
GetLocaleInfoA
SleepConditionVariableSRW
GetModuleHandleW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetCurrentProcess
USER32.dll SetCursorPos
IsWindowVisible
EnumWindows
GetWindowTextW
DefWindowProcW
DispatchMessageA
GetWindowRect
DestroyWindow
MessageBoxW
SetWindowRgn
CreateWindowExW
GetSystemMetrics
UnregisterClassW
RegisterClassExW
ShowWindow
MoveWindow
TranslateMessage
LoadIconA
PeekMessageA
PostQuitMessage
UpdateWindow
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
SetCursor
GetMessageExtraInfo
LoadCursorA
ScreenToClient
ReleaseCapture
IsWindowUnicode
GetClientRect
SetCapture
GetForegroundWindow
GetKeyboardLayout
TrackMouseEvent
ClientToScreen
GetCapture
GetCursorPos
GDI32.dll CreateRoundRectRgn
ADVAPI32.dll CryptDestroyHash
CryptGenRandom
CredWriteW
CredReadW
CredFree
CredDeleteW
CryptReleaseContext
RegCloseKey
CryptAcquireContextW
RegQueryValueExW
CryptGetHashParam
RegOpenKeyExW
CryptCreateHash
CryptHashData
SHELL32.dll ShellExecuteW
SHGetFolderPathW
ShellExecuteA
ole32.dll CoCreateInstance
dwmapi.dll DwmExtendFrameIntoClientArea
MSVCP140.dll _Thrd_detach
_Query_perf_counter
_Cnd_do_broadcast_at_thread_exit
_Mtx_lock
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Strxfrm
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?id@?$ctype@D@std@@2V0locale@2@A
?id@?$collate@D@std@@2V0locale@2@A
_Strcoll
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?tolower@?$ctype@D@std@@QEBADD@Z
??1facet@locale@std@@MEAA@XZ
??0facet@locale@std@@IEAA@_K@Z
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?_Incref@facet@locale@std@@UEAAXXZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
??1_Locinfo@std@@QEAA@XZ
??0_Locinfo@std@@QEAA@PEBD@Z
_Thrd_id
_Thrd_join
_Query_perf_frequency
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Xbad_function_call@std@@YAXXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?good@ios_base@std@@QEBA_NXZ
_Mtx_unlock
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Random_device@std@@YAIXZ
?__ExceptionPtrCreate@@YAXPEAX@Z
?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?uncaught_exceptions@std@@YAHXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?__ExceptionPtrToBool@@YA_NPEBX@Z
?__ExceptionPtrDestroy@@YAXPEAX@Z
?__ExceptionPtrCurrentException@@YAXPEAX@Z
?__ExceptionPtrRethrow@@YAXPEBX@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
IMM32.dll ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
ImmSetCandidateWindow
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpQueryHeaders
WinHttpReadData
WinHttpReceiveResponse
WinHttpSetOption
WinHttpCloseHandle
WinHttpSendRequest
WinHttpQueryDataAvailable
WinHttpOpen
WinHttpOpenRequest
WinHttpConnect
bcrypt.dll BCryptGetProperty
BCryptGenerateSymmetricKey
BCryptSetProperty
BCryptDecrypt
BCryptDestroyKey
BCryptCreateHash
BCryptHashData
BCryptDestroyHash
BCryptCloseAlgorithmProvider
BCryptFinishHash
BCryptOpenAlgorithmProvider
RPCRT4.dll RpcStringFreeA
UuidToStringA
UuidCreate
CRYPT32.dll CryptProtectData
CryptStringToBinaryA
CryptUnprotectData
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
__std_exception_copy
strstr
strchr
__current_exception_context
__current_exception
strrchr
longjmp
memchr
memcpy
wcsstr
__intrinsic_setjmp
_CxxThrowException
memmove
memset
__std_terminate
__C_specific_handler
memcmp
api-ms-win-crt-stdio-l1-1-0.dll fwrite
fread
__stdio_common_vsscanf
__p__commode
__stdio_common_vfprintf
fseek
fclose
fflush
fputc
__acrt_iob_func
__stdio_common_vswprintf_s
ftell
_get_stream_buffer_pointers
_fseeki64
__stdio_common_vsprintf
fsetpos
ungetc
fgetc
setvbuf
_set_fmode
fgetpos
__stdio_common_vsprintf_s
_wfopen
api-ms-win-crt-heap-l1-1-0.dll realloc
free
_set_new_mode
malloc
_callnewh
api-ms-win-crt-runtime-l1-1-0.dll _Exit
_c_exit
_exit
_initterm
_get_narrow_winmain_command_line
_set_app_type
_seh_filter_exe
exit
_cexit
_crt_atexit
_beginthreadex
terminate
_invoke_watson
set_terminate
_register_onexit_function
_initialize_onexit_table
abort
_initterm_e
_initialize_narrow_environment
_configure_narrow_argv
_register_thread_local_exe_atexit_callback
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-string-l1-1-0.dll towlower
strcmp
strncpy
strncpy_s
strcpy_s
wcscpy_s
isxdigit
tolower
strncmp
isdigit
api-ms-win-crt-convert-l1-1-0.dll strtol
strtoull
atoi
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file
api-ms-win-crt-time-l1-1-0.dll _time64
_localtime64_s
api-ms-win-crt-math-l1-1-0.dll powf
fmodf
cosf
ceilf
sinf
acosf
sqrtf
__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

101

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x1aeaf
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96927
Detected Filetype PNG graphic file
MD5 168af5cbf53b6f2ded3afb5a6d147d0a 🔍
SHA1 6929121ac449d9891628cb7b108ae1929376d73f 🔍
SHA256 9528a0daae55524d0861ae861f6ed930effb185c756dcd8250730cbf35a8e17f 🔍
SHA3 c224c89bf4a4a7432b44fa44f92859c0783dd9808f1e6dda1ed7c6398eda25e1 🔍

102

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x4a1ae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97827
Detected Filetype Windows animated cursor
MD5 3824a3c807e6c6c36cc9585feec78ce8 🔍
SHA1 ecfe8d48a765c4a447b8efe2bbab867593b19857 🔍
SHA256 ac6912678122d13c8d17e5c3db2172feb3a89c67ceb0367410f5df82058abdf8 🔍
SHA3 d72bd22cc080f77af51c3f779ad84a4d3173b69fe20f4dae03d829dcf101ad63 🔍

103

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x4b11
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97516
Detected Filetype JPEG graphic file
MD5 2694b61052bdaaf75a4f7a5e530ba802 🔍
SHA1 b4dde4893d4ec88d747f9a9a03370d112204e01d 🔍
SHA256 225fd8a888365a970b2e06611f5b08e2fa25d00fd9a217780957d1a7bb2f9335 🔍
SHA3 091f76839cc7ca0c7b062474f2a706a848d0086ebe4e32c3d258b9e64bd873b9 🔍

104

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2d758
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88289
Detected Filetype PNG graphic file
MD5 d9459b1b0748c4b3611a8ba9b1599758 🔍
SHA1 1344f8d4403e98ffbdcf4d35f520e542e7cc2af2 🔍
SHA256 a112426c2a29cbd852add29baecccda232d99420c06bc19c2b85753c1f7b44bc 🔍
SHA3 7269524b9484bb0182d9bfcff64ddd849e9addbbb5c8a850f1d07889c43a1af1 🔍

105

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x8f82
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74761
Detected Filetype PNG graphic file
MD5 494607afce1422721e5a856f79e69cac 🔍
SHA1 c9fa8b96841ad3d669cb42d5615b431ca363bc75 🔍
SHA256 185cbd3f12fa2e88006d29bfbcec110f288b74a4abbb71df7ad22bed567f1503 🔍
SHA3 ba0a16fc89f68e52866fd1bf5a32ddcf2a09d4857c1d2f953cedbcbc7ba1d568 🔍

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jun-16 16:52:54
Version 0.0
SizeofData 100
AddressOfRawData 0x1a265c
PointerToRawData 0x1a185c
Referenced File C:\Users\vexx\Documents\Sources\Secureloader\Genesis\x64\Release\bypass.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jun-16 16:52:54
Version 0.0
SizeofData 20
AddressOfRawData 0x1a26c0
PointerToRawData 0x1a18c0

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jun-16 16:52:54
Version 0.0
SizeofData 912
AddressOfRawData 0x1a26d4
PointerToRawData 0x1a18d4

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jun-16 16:52:54
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1401a2a88
EndAddressOfRawData 0x1401a2b88
AddressOfIndex 0x1401ba528
AddressOfCallbacks 0x140128d60
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401b9040

RICH Header

XOR Key 0x49575f9
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
Imports (35207) 6
253 (35207) 1
ASM objects (35207) 6
C objects (35207) 10
C++ objects (35207) 34
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
C++ objects (33145) 1
Imports (33145) 31
Total imports 403
C++ objects (LTCG) (35225) 51
Resource objects (35225) 1
151 1
Linker (35225) 1

Errors

Leave a comment

No comments yet.