996b38fce4d37d6f27f5649b92b30ce27079835cc2260d237699adb14d5d0277

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-07 04:04:07
Detected languages English - United States
Debug artifacts C:\Users\Oveja\OneDrive\Desktop\awd\x64\Debug\hasbi.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Looks for Qemu presence:
  • QeMU
May have dropper capabilities:
  • CurrentControlSet\Services
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • aia.ws.symantec.com
  • cacerts.digicert.com
  • crl.microsoft.com
  • crl.thawte.com
  • crl.ws.symantec.com
  • crl3.digicert.com
  • crl4.digicert.com
  • digicert.com
  • fontello.com
  • gmail.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
  • http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
  • http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://crl3.digicert.com/sha2-assured-ts.crl02
  • http://crl4.digicert.com
  • http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
  • http://crl4.digicert.com/sha2-assured-ts.crl0
  • http://fontello.com
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.digicert.com0O
  • http://ocsp.digicert.com0\
  • http://ocsp.thawte.com0
  • http://scripts.sil.org
  • http://scripts.sil.org/OFL
  • http://scripts.sil.org/OFLPT
  • http://t1.symcb.com
  • http://t1.symcb.com/ThawtePCA.crl0
  • http://t2.symcb.com0
  • http://tl.symcb.com
  • http://tl.symcb.com/tl.crl0
  • http://tl.symcb.com/tl.crt0
  • http://tl.symcd.com0
  • http://tl.symcd.com0&
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • http://www.digicert.com
  • http://www.digicert.com/CPS0
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0
  • http://www.paratype.com
  • http://www.paratype.com/help/designershttp
  • http://www.paratype.comhttp
  • https://detect.ac
  • https://files.catbox.moe
  • https://files.catbox.moe/wfm4ed.pfx
  • https://ico.org.uk
  • https://ico.org.uk/.
  • https://msdl.microsoft.com
  • https://msdl.microsoft.com/download/symbols/
  • https://www.digicert.com
  • https://www.digicert.com/CPS0
  • https://www.microsoft.com
  • https://www.microsoft.com/en-us/windows
  • https://www.thawte.com
  • https://www.thawte.com/cps0/
  • https://www.thawte.com/repository0W
  • ico.org.uk
  • microsoft.com
  • msdl.microsoft.com
  • paratype.com
  • scripts.sil.org
  • symantec.com
  • symcb.com
  • t1.symcb.com
  • thawte.com
  • tl.symcb.com
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • ws.symantec.com
  • www.digicert.com
  • www.microsoft.com
  • www.paratype.com
  • www.thawte.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Suspicious The PE is possibly packed. Section .textbss is both writable and executable.
Unusual section name found: .msvcjmc
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • NtQuerySystemInformation
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • OpenProcess
  • WriteProcessMemory
  • VirtualAlloc
Can access the registry:
  • RegCloseKey
  • RegDeleteValueW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegGetKeySecurity
  • RegOpenKeyExW
  • RegQueryInfoKeyW
  • RegSetKeySecurity
  • RegCreateKeyA
  • RegDeleteKeyA
  • RegOpenKeyA
  • RegSetValueExA
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessA
  • CreateProcessW
  • CreateProcessAsUserW
Uses Windows's Native API:
  • ZwWriteVirtualMemory
  • ZwReadVirtualMemory
  • NtQuerySystemInformation
  • NtUnloadDriver
  • NtLoadDriver
Uses Microsoft's cryptographic API:
  • CryptUnprotectData
  • CryptProtectData
Can create temporary files:
  • CreateFileA
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Has Internet access capabilities:
  • WinHttpConnect
  • WinHttpReadData
  • WinHttpQueryDataAvailable
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpOpen
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • URLDownloadToFileA
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
  • DuplicateTokenEx
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceStatusEx
Enumerates local disk drives:
  • GetVolumeInformationW
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
  • Process32FirstW
  • Process32NextW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 7b8bb59d0e2e02a76f1c2c9d36196f83
SHA1 7ccdcf90d5819913d214bf708f042d58149d2c5a
SHA256 996b38fce4d37d6f27f5649b92b30ce27079835cc2260d237699adb14d5d0277
SHA3 9b7ed47e1ba67a2a3d043a56826ce3596210d3b14beb40a977fa58537969ba5f
SSDeep 49152:pGeVRMhwc4S8xQaqPCQ8TJVe0azFLuywncugq1NTxoPCdIA1sITLl3oKJ6mEO2l:Yc9XxoP1YEOOalS0sTs
Imports Hash 5588651abf36901c5e82c88b4b696dfb

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 2026-Aug-07 04:04:07
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x327800
SizeOfInitializedData 0x44a000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000185B51 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x8f7000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.textbss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x180aa5
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.text

MD5 526dd9b2ea5c7c5ca4b332e46f63c6db
SHA1 480505c744611e59f900fd904aef5fe2d65622e5
SHA256 b0869a418324ec33673b85eaa2bc6d2aedd31c782bd2d90777f666d802373ac5
SHA3 66edda0f295d9c8598db83d63cf2ab074750840707c29ee9dd02fe9a0be579b7
VirtualSize 0x3277ce
VirtualAddress 0x182000
SizeOfRawData 0x327800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.1957

.rdata

MD5 58b07095520778762e9ed367294526f1
SHA1 5a59ec4cc02f8b08f6f661c8fbbea2966bb131f1
SHA256 be6604f7f75c50788d78e7c914f62cffbc5be6fe2c7da4ef4e474566becd2061
SHA3 1b432b3a7908ce0f8a4eac5bcfd09f924e3e84d75d7cab9aeef32c8932b0c258
VirtualSize 0xc8ce1
VirtualAddress 0x4aa000
SizeOfRawData 0xc8e00
PointerToRawData 0x327c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.79394

.data

MD5 d9b13bc7c0799436f5a6a4c70d61030a
SHA1 b6bf7e4b6d573662dc5287cd49445496e9677f69
SHA256 32df72232b7413a20eed8b6481e2cba270dcc8052e795766d9e6a36a21b18fb2
SHA3 8ccc3806a53c15024570cfff6b3d95378262e80160bdce89fea0df8e0758391f
VirtualSize 0x33ff50
VirtualAddress 0x573000
SizeOfRawData 0x336800
PointerToRawData 0x3f0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.81485

.pdata

MD5 5ff3b63e75dfb2d51ae1b13fbe5b6320
SHA1 b395cd61a47b63a54f559cd606a3a4e877ddbaea
SHA256 b8f98b719cea0a1211876ec0bf353a7addcdb364bff8bc5fdd4b65f3cf33b068
SHA3 68edf89bb4fa4f5a7056a3a3be1161386986fc89e94a776cdc2bd7eace9c4ee8
VirtualSize 0x2beb4
VirtualAddress 0x8b3000
SizeOfRawData 0x2c000
PointerToRawData 0x727200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.75375

.idata

MD5 82264262490a8d0d18a259e74bad5dd1
SHA1 1727a56b13d35fbe43982ee9d5f9fab467e17f01
SHA256 3958a8cbbd6253b045e90206c86b96abf0937cc028a99fcbbdc0b0f8efc7fbce
SHA3 0a462e63773cfda27a64fd96c127cbac955d4a74c30695524684c5c5593b275d
VirtualSize 0x721b
VirtualAddress 0x8df000
SizeOfRawData 0x7400
PointerToRawData 0x753200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.27259

.msvcjmc

MD5 c2a56e5264c135266dd11a9926f20c76
SHA1 e8a43fe5fdd6fc568a1db8346875ff3a6498064c
SHA256 51fefe341b39ae7689a945c5ab643d68e69c3be01141be97ed86d1e0487733de
SHA3 a6bcb0a5df7c29b209aaffb1bafd8acd9ff63c837ec46db0273066da4120159c
VirtualSize 0x2ce4
VirtualAddress 0x8e7000
SizeOfRawData 0x2e00
PointerToRawData 0x75a600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.731471

.tls

MD5 e44747f9a38bbdc738f2e0094dfbbd85
SHA1 f15aa2f4cb8a9af9c45adecc0ff41695dfbaf7be
SHA256 60c28020380763487d368bca16a98ffc0433d59f9925d47e5bf52689976fa117
SHA3 4f3bc1f22a4c3acc1e6cca49c57cf8411913a2f3595ef6c5e58233730c933725
VirtualSize 0x1aae
VirtualAddress 0x8ea000
SizeOfRawData 0x1c00
PointerToRawData 0x75d400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.001988

.00cfg

MD5 36d93d41fbae2b6164e6277e335de548
SHA1 5e958f8518634230814bcaf71b86d8ea071fbc74
SHA256 7be58a9315ab147d30976201dfc654c4290c909dca7d5b4b73f26f1152db8925
SHA3 11c4a5aba9dfe11e57d8624c01bf1d7ff8a0942bbb4293c261332b45586381f0
VirtualSize 0x175
VirtualAddress 0x8ec000
SizeOfRawData 0x200
PointerToRawData 0x75f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.502848

.rsrc

MD5 ca4ea189bcc7661f4d4d0766df264800
SHA1 3e8513a9fcbac8b39ead970c57d57be66f8c349d
SHA256 96fde776c2f484f393cd2bc8be11ddf76bb122074a4066c36dff1c19c402df32
SHA3 3537ab5c5c7af2d0101d8ec77a09d76492356f950a2df3fde753d8e94c02f863
VirtualSize 0x446
VirtualAddress 0x8ed000
SizeOfRawData 0x600
PointerToRawData 0x75f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.17424

.reloc

MD5 935ec23f233fa89875c85056253cb850
SHA1 22cb87db00058638e52010020a0185d5a4e8ab28
SHA256 8464ec13ba67f3a543db57ad1fda0a9fbddd8f3422e8fb163bb5bb89847016e9
SHA3 9d82364995edc24ca02b26e177514262f69d3c3ddf217e9a07023d858e20b692
VirtualSize 0x8a02
VirtualAddress 0x8ee000
SizeOfRawData 0x8c00
PointerToRawData 0x75f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.20142

Imports

dwmapi.dll DwmIsCompositionEnabled
DwmEnableBlurBehindWindow
DwmGetColorizationColor
DwmExtendFrameIntoClientArea
d3d9.dll Direct3DCreate9
d3dx9_43.dll D3DXCreateTextureFromFileInMemory
ntdll.dll VerSetConditionMask
ZwWriteVirtualMemory
ZwReadVirtualMemory
NtQuerySystemInformation
NtUnloadDriver
NtLoadDriver
RtlCaptureContext
RtlInitAnsiString
RtlAnsiStringToUnicodeString
RtlLookupFunctionEntry
RtlVirtualUnwind
WINHTTP.dll WinHttpConnect
WinHttpReadData
WinHttpQueryDataAvailable
WinHttpOpenRequest
WinHttpCloseHandle
WinHttpOpen
WinHttpReceiveResponse
WinHttpSendRequest
KERNEL32.dll OpenProcess
GetSystemInfo
GetTickCount
VirtualQueryEx
ReadProcessMemory
WriteProcessMemory
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
LocalAlloc
LocalFree
MoveFileW
MoveFileExW
MultiByteToWideChar
WideCharToMultiByte
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
VirtualAlloc
VirtualFree
GetCurrentDirectoryA
CreateDirectoryA
CreateFileA
GetFileAttributesExA
SetLastError
GetCurrentProcessId
HeapAlloc
HeapFree
GetProcessHeap
DeviceIoControl
GetCurrentThreadId
FreeLibrary
LoadLibraryA
CompareFileTime
OpenThread
SuspendThread
TerminateProcess
GetThreadTimes
GetTickCount64
GetModuleHandleA
Thread32First
Thread32Next
K32GetMappedFileNameA
K32EnumProcessModules
K32GetModuleBaseNameA
K32GetModuleInformation
GetStdHandle
ExitProcess
AllocConsole
SetConsoleTextAttribute
CreatePipe
SetConsoleTitleW
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
QueryPerformanceCounter
QueryPerformanceFrequency
CreateProcessA
GetCommandLineW
GetStartupInfoW
GetVolumeInformationW
GetComputerNameW
SetEndOfFile
GetDiskFreeSpaceExW
FindNextFileW
FindFirstFileExW
FindFirstFileW
FindClose
CreateDirectoryW
GetCurrentDirectoryW
SetCurrentDirectoryW
GetLocaleInfoEx
FormatMessageA
CreateProcessW
GetCurrentProcess
Sleep
SetFileAttributesW
WaitForSingleObject
GetLastError
CloseHandle
GetTempPathW
GetTempFileNameW
GetFileSize
GetFileAttributesW
DeleteFileW
CreateFileW
GetFileAttributesExW
GetFileInformationByHandle
GetFinalPathNameByHandleW
GetFullPathNameW
SetFileTime
AreFileApisANSI
CreateDirectoryExW
CopyFileW
CreateHardLinkW
GetFileInformationByHandleEx
CreateSymbolicLinkW
ReleaseSRWLockExclusive
ReleaseSRWLockShared
AcquireSRWLockExclusive
AcquireSRWLockShared
TryAcquireSRWLockExclusive
TryAcquireSRWLockShared
SleepConditionVariableSRW
WakeAllConditionVariable
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
WriteFile
SetFilePointer
SetConsoleTitleA
SetFileInformationByHandle
IsDebuggerPresent
RaiseException
GetSystemTimeAsFileTime
InitializeSListHead
ResumeThread
VirtualQuery
USER32.dll GetCapture
UnhookWindowsHookEx
GetWindowLongW
MapWindowPoints
GetWindowRect
SetWindowDisplayAffinity
MoveWindow
UpdateWindow
GetSystemMetrics
SetWindowPos
ShowWindow
EmptyClipboard
CreateWindowExW
RegisterClassExW
UnregisterClassW
PostQuitMessage
DefWindowProcW
SetWindowLongW
SetForegroundWindow
SetProcessDPIAware
MonitorFromWindow
LoadCursorW
ScreenToClient
ClientToScreen
GetCursorPos
SetCursor
SetCursorPos
TrackMouseEvent
DestroyWindow
GetDC
TranslateMessage
DispatchMessageW
PeekMessageW
GetAsyncKeyState
OpenClipboard
CloseClipboard
SetClipboardData
GetClipboardData
SetCapture
ReleaseCapture
GetForegroundWindow
GetClientRect
ReleaseDC
GetKeyState
GDI32.dll CreateRectRgn
DeleteObject
GetDeviceCaps
ADVAPI32.dll InitializeSecurityDescriptor
FreeSid
AllocateAndInitializeSid
AdjustTokenPrivileges
OpenProcessToken
SetSecurityDescriptorDacl
LookupPrivilegeValueW
RegCloseKey
RegDeleteValueW
RegEnumKeyExW
RegEnumValueW
RegGetKeySecurity
RegOpenKeyExW
RegQueryInfoKeyW
RegSetKeySecurity
CloseServiceHandle
OpenSCManagerW
OpenServiceW
QueryServiceStatusEx
SetEntriesInAclW
RegCreateKeyA
RegDeleteKeyA
RegOpenKeyA
RegSetValueExA
GetTokenInformation
GetUserNameA
RegQueryValueExW
CreateProcessAsUserW
SetThreadToken
DuplicateTokenEx
PrivilegeCheck
RevertToSelf
SetTokenInformation
SHELL32.dll SHGetFolderPathW
SHGetFolderPathA
ole32.dll StringFromGUID2
CoInitializeEx
MSVCP140D.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
_Thrd_detach
?_Xbad_function_call@std@@YAXXZ
_Mtx_lock
_Mtx_unlock
?setf@ios_base@std@@QEAAHH@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEBX@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?setf@ios_base@std@@QEAAHHH@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?get@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$istreambuf_iterator@DU?$char_traits@D@std@@@2@V32@0AEAVios_base@2@AEAHPEAUtm@@PEBD4@Z
?_Getcat@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?id@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@G@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?_Random_device@std@@YAIXZ
??7ios_base@std@@QEBA_NXZ
?_Throw_Cpp_error@std@@YAXH@Z
_Cnd_do_broadcast_at_thread_exit
_Thrd_id
_Thrd_join
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
_Strcoll
_Strxfrm
??0_Locinfo@std@@QEAA@PEBD@Z
??1_Locinfo@std@@QEAA@XZ
?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ
?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ
?_W_Getdays@_Locinfo@std@@QEBAPEBGXZ
?_W_Getmonths@_Locinfo@std@@QEBAPEBGXZ
?c_str@?$_Yarn@D@std@@QEBAPEBDXZ
??2_Crt_new_delete@std@@SAPEAX_K@Z
??3_Crt_new_delete@std@@SAXPEAX@Z
??0facet@locale@std@@IEAA@_K@Z
??1facet@locale@std@@MEAA@XZ
?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
?is@?$ctype@D@std@@QEBA_NFD@Z
?tolower@?$ctype@D@std@@QEBADD@Z
?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z
?_Incref@facet@locale@std@@UEAAXXZ
?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?_Id_cnt@id@locale@std@@0HA
?id@?$ctype@D@std@@2V0locale@2@A
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?id@?$collate@D@std@@2V0locale@2@A
?uncaught_exceptions@std@@YAHXZ
?good@ios_base@std@@QEBA_NXZ
?flags@ios_base@std@@QEBAHXZ
?width@ios_base@std@@QEBA_JXZ
?width@ios_base@std@@QEAA_J_J@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
_Query_perf_counter
_Query_perf_frequency
SHLWAPI.dll PathStripPathW
dbghelp.dll SymInitialize
SymCleanup
SymSetOptions
SymGetTypeInfo
SymLoadModuleEx
SymUnloadModule64
SymGetTypeFromName
SymFromName
urlmon.dll URLDownloadToFileA
CRYPT32.dll CryptUnprotectData
CryptProtectData
IMM32.dll ImmGetContext
ImmSetCompositionWindow
ImmSetCandidateWindow
ImmReleaseContext
VCRUNTIME140D.dll __vcrt_LoadLibraryExW
__vcrt_GetModuleHandleW
__vcrt_GetModuleFileNameW
memmove
memcmp
memcpy
__std_type_info_destroy_list
memset
strchr
__std_exception_copy
__std_exception_destroy
_CxxThrowException
__C_specific_handler_noexcept
memchr
strstr
_purecall
__current_exception
__current_exception_context
__C_specific_handler
VCRUNTIME140_1D.dll __CxxFrameHandler4
ucrtbased.dll getenv
__stdio_common_vsprintf
_errno
wcstombs_s
_dtest
strtod
strtoll
strtoull
localeconv
ceilf
sqrtf
pow
sqrt
_stricmp
strnlen
__acrt_iob_func
freopen_s
strcmp
strncpy
_wfopen
fseek
ftell
__stdio_common_vfprintf
__stdio_common_vsscanf
qsort
fabs
fmodf
toupper
acosf
cosf
sinf
strncmp
atof
log
atan2f
logf
powf
__stdio_common_vsprintf_s
strcpy_s
roundf
strcat
strcpy
fgets
freopen
_pclose
_popen
_mkgmtime64
_rotl
_free_dbg
_malloc_dbg
___lc_codepage_func
abort
_callnewh
_CrtDbgReportW
_seh_filter_dll
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_execute_onexit_table
_crt_atexit
_crt_at_quick_exit
_cexit
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_wide_argv
_initialize_wide_environment
_get_wide_winmain_command_line
_initterm
_initterm_e
_exit
_set_fmode
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
strcat_s
_wmakepath_s
_wsplitpath_s
_invoke_watson
_itoa_s
wcscmp
_wassert
_beginthreadex
terminate
exit
_time64
srand
_unlock_file
_lock_file
ungetc
setvbuf
fwrite
_fseeki64
fsetpos
fread
fputc
fgetpos
fgetc
fflush
fclose
_get_stream_buffer_pointers
__stdio_common_vswprintf_s
_CrtDbgReport
_calloc_dbg
rand
_wsystem
realloc
malloc
free
strlen
_wcsicmp
wcslen
wcscpy_s
tolower
towlower
_dsign

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x184
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91862
MD5 3250787fdcd75aa2587529b89c7738b2
SHA1 622b5627941ecee9cfe6179c3017bbf7b43fffaa
SHA256 8b0de2e560d8476fb0013b44f1e10c2789ae71e0353866890dc5f9c57fb1f44a
SHA3 6bf4f0eaf6795c219d4d808caa895dcb53f7fe9c81e92ce03da1db7841bfcd3d

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-07 04:04:07
Version 0.0
SizeofData 80
AddressOfRawData 0x522d14
PointerToRawData 0x3a0914
Referenced File C:\Users\Oveja\OneDrive\Desktop\awd\x64\Debug\hasbi.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-07 04:04:07
Version 0.0
SizeofData 20
AddressOfRawData 0x522d64
PointerToRawData 0x3a0964

TLS Callbacks

StartAddressOfRawData 0x1408ea000
EndAddressOfRawData 0x1408eb9ad
AddressOfIndex 0x1408b282c
AddressOfCallbacks 0x1404aaa28
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1408a8240

RICH Header

XOR Key 0x9d476709
Unmarked objects 0
ASM objects (35207) 4
C objects (35207) 11
C++ objects (35207) 42
Imports (35207) 6
Imports (21202) 2
Imports (VS2012 build 50727 / VS2005 build 50727) 2
Imports (33145) 31
Total imports 508
C++ objects (35228) 32
Resource objects (35228) 1
Linker (35228) 1

Errors

[*] Warning: Section .textbss has a size of 0!
Leave a comment

No comments yet.