9ad7758093a356fe5bd9d49911aaacf766dbb9289b6f3662a8ed3242230f46b2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Oct-15 03:29:49
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName Bloxstrap
FileDescription Bloxstrap
FileVersion 2.11.4
InternalName Bloxstrap.dll
LegalCopyright
OriginalFilename Bloxstrap.dll
ProductName Bloxstrap
ProductVersion 2.11.4
Assembly Version 2.11.4.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Looks for VMWare presence:
  • VMWARE
Looks for VirtualPC presence:
  • 0f 3f 07 0b
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
  • virus
Contains domain names:
  • .bloxstraplabs.com
  • Bloxstrap.Resources.Strings.de
  • Bloxstrap.Resources.Strings.es
  • Bloxstrap.Resources.Strings.fr
  • Bloxstrap.Resources.Strings.it
  • Bloxstrap.Resources.Strings.nl
  • Bloxstrap.Resources.Strings.ru
  • Bloxstrap.Resources.Strings.uk
  • Brickfilms.com
  • Resources.Strings.de
  • Resources.Strings.es
  • Resources.Strings.fr
  • Resources.Strings.it
  • Resources.Strings.nl
  • Resources.Strings.ru
  • Resources.Strings.uk
  • Strings.de
  • Strings.es
  • Strings.fr
  • Strings.it
  • Strings.nl
  • Strings.ru
  • Strings.uk
  • ak.rbxcdn.com
  • amazonaws.com
  • api.github.com
  • aws.rbxcdn.com
  • bloxstraplabs.com
  • cacerts.digicert.com
  • cachefly.net
  • cdn.discordapp.com
  • clientsettings.roblox.com
  • clientsettingscdn.roblox.com
  • crl.microsoft.com
  • crl3.digicert.com
  • crl4.digicert.com
  • crowdin.com
  • devblogs.microsoft.com
  • devforum.roblox.com
  • digicert.com
  • discordapp.com
  • docs.microsoft.com
  • example.com
  • fontello.com
  • games.roblox.com
  • github.com
  • githubusercontent.com
  • go.microsoft.com
  • google.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
  • http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E
  • http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt0_
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0
  • http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
  • http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0
  • http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl0
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E
  • http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F
  • http://crl3.digicert.com/sha2-assured-ts.crl02
  • http://crl4.digicert.com
  • http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L
  • http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0
  • http://crl4.digicert.com/sha2-assured-ts.crl0
  • http://example.com
  • http://fontello.com
  • http://icsharpcode.net
  • http://james.newtonking.com
  • http://james.newtonking.com/projects/json
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.digicert.com0K
  • http://ocsp.digicert.com0N
  • http://ocsp.digicert.com0O
  • http://schemas.lepo.co
  • http://schemas.lepo.co/wpfui/2022/xaml
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://schemas.microsoft.com/SMI/2016/WindowsSettings
  • http://schemas.microsoft.com/expression/blend/2008
  • http://schemas.microsoft.com/winfx/2006/xaml
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/markup-compatibility/2006
  • http://scripts.sil.org
  • http://scripts.sil.org/OFL
  • http://scripts.sil.org/OFLSans
  • http://scripts.sil.org/OFLhttp
  • http://www.digicert.com
  • http://www.digicert.com/CPS0
  • http://www.google.com
  • http://www.google.com/get/noto/Designed
  • http://www.microsoft.com
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/docs/primarycps.htm0
  • http://www.microsoft.com0
  • http://www.monotype.com
  • http://www.monotype.com/studiohttp
  • http://www.roblox.com
  • http://www.roblox.com/
  • http://www.roblox.com/.
  • http://www.roblox.com/F
  • http://www.roblox.com/asset/?id
  • http://www.w3.org
  • http://www.w3.org/2000/xmlns/
  • http://www.w3.org/2001/XMLSchema
  • https://aka.ms
  • https://api.github.com
  • https://api.github.com/repos/bloxstraplabs/bloxstrap/releases/latest
  • https://bloxstraplabs.com
  • https://clientsettings.roblox.com
  • https://clientsettingscdn.roblox.com
  • https://crowdin.com
  • https://devblogs.microsoft.com
  • https://devblogs.microsoft.com/directx/demystifying-full-screen-optimizations/
  • https://devforum.roblox.com
  • https://devforum.roblox.com/t/allowlist-for-local-client-configuration-via-fast-flags/3966569
  • https://discord.gg
  • https://docs.microsoft.com
  • https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation
  • https://games.roblox.com
  • https://games.roblox.com/v1/games?universeIds
  • https://github.com
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • https://ipinfo.io
  • https://music.yandex.ru
  • https://music.yandex.ru/iframe/#track/
  • https://ok.ru
  • https://player.vimeo.com
  • https://player.vimeo.com/video/
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/bloxstraplabs/config/main/assets/
  • https://raw.githubusercontent.com/bloxstraplabs/config/main/supporters.json
  • https://roblox-setup.cachefly.net
  • https://roblox.com
  • https://s3.amazonaws.com
  • https://s3.amazonaws.com/setup.roblox.com
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLRubik-LightVersion
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttp
  • https://setup-ak.rbxcdn.com
  • https://setup-aws.rbxcdn.com
  • https://setup.rbxcdn.com
  • https://status.roblox.com
  • https://support.microsoft.com
  • https://support.microsoft.com/en-us/topic/media-feature-pack-list-for-windows-n-editions-c1c6fffa-d052-8338-7a79-a4bb980a700a
  • https://thumbnails.roblox.com
  • https://thumbnails.roblox.com/v1/batch
  • https://thumbnails.roblox.com/v1/games/icons?universeIds
  • https://thumbnails.roblox.com/v1/users/avatar-headshot?userIds
  • https://tonsky.meThis
  • https://tonsky.mehttps
  • https://users.roblox.com
  • https://users.roblox.com/v1/users/
  • https://www.digicert.com
  • https://www.digicert.com/CPS0
  • https://www.newtonsoft.com
  • https://www.newtonsoft.com/json
  • https://www.newtonsoft.com/jsonschema
  • https://www.nuget.org
  • https://www.nuget.org/packages/Newtonsoft.Json.Bson
  • https://www.roblox.com
  • https://www.roblox.com//a$
  • https://www.roblox.com/communities/32380007/Bloxstrap
  • https://www.roblox.com/games/
  • https://www.roblox.com/users/129425241/profile
  • https://www.roblox.com/users/158082266/profile
  • https://www.roblox.com/users/2485612194/profile
  • https://www.roblox.com/users/923416649/profile
  • https://www.youtube.com
  • https://www.youtube.com/embed/
  • icsharpcode.net
  • james.newtonking.com
  • microsoft.com
  • monotype.com
  • music.yandex.ru
  • newtonking.com
  • newtonsoft.com
  • nuget.org
  • openxmlformats.org
  • paint.net
  • player.vimeo.com
  • raw.githubusercontent.com
  • rbxcdn.com
  • roblox-setup.cachefly.net
  • roblox.com
  • s3.amazonaws.com
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • scripts.sil.org
  • services.bloxstraplabs.com
  • setup-ak.rbxcdn.com
  • setup-aws.rbxcdn.com
  • setup.cachefly.net
  • setup.rbxcdn.com
  • setup.roblox.com
  • status.roblox.com
  • support.microsoft.com
  • thumbnails.roblox.com
  • users.roblox.com
  • vimeo.com
  • www.digicert.com
  • www.google.com
  • www.microsoft.com
  • www.monotype.com
  • www.newtonsoft.com
  • www.nuget.org
  • www.roblox.com
  • www.w3.org
  • www.youtube.com
  • yandex.ru
  • youtube.com
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Info The PE is digitally signed. Signer: SignPath Foundation
Issuer: GlobalSign GCC R45 CodeSigning CA 2020
Safe VirusTotal score: 0/67 (Scanned on 2026-08-19 09:52:28) All the AVs think this file is safe.

Hashes

MD5 f408c18edc86d2dc33385c2f11a57fb7 🔍
SHA1 84d9e3ef605d7ef184e8e24d6f8c0ec5670fa98a 🔍
SHA256 9ad7758093a356fe5bd9d49911aaacf766dbb9289b6f3662a8ed3242230f46b2 🔍
SHA3 14450c616dcbb2462710a054a54d63ac0dcc07fa479abaf13fd11c1237480baf 🔍
SSDeep 98304:CGiOBTscod5DkasbM11f1uD3P9uOYoHwfLk3vSmaR0+Mc4AN0edaAHDfysrTlz:CGiascgsbM1HAUObAbN08 🔍
Imports Hash a8308de57fce070f4cb88c7f43bf4b27 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Oct-15 03:29:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18600
SizeOfInitializedData 0x2d800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000014050 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4c000
SizeOfHeaders 0x400
Checksum 0xc0787d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8ba40b8040bd058914989c2acf2b0d09 🔍
SHA1 852478d9c389d77f5a6642d63f1ecbcaf3bfaefe 🔍
SHA256 334a1e4af4cf8c73fd0b14a6a8d1586fcb26ec6d839a63bbb1b8ff7ede6c5b5a 🔍
SHA3 cf32528ffa67521fd364c68e5668c7a6040107071c54cc6bf33df996aea4e6e9 🔍
VirtualSize 0x185fc
VirtualAddress 0x1000
SizeOfRawData 0x18600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.33502

.rdata

MD5 e005670478d4c826513df696f62e58dc 🔍
SHA1 3d8681478f95f2f585f161210dd5ae74ea848817 🔍
SHA256 df2877eb7c4beef8f6cb27148820de1e3765022640e2e0905c1b0be3d9b093fb 🔍
SHA3 41be8e1657481e217ae40b469d8ac2252c6953530ebaec135a65e6851374b7d3 🔍
VirtualSize 0x9700
VirtualAddress 0x1a000
SizeOfRawData 0x9800
PointerToRawData 0x18a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.55599

.data

MD5 505c9241840240eeb21d036fd9c4118e 🔍
SHA1 2ce26d35a9640b8e3e4b0b97d3d8361f7d79d3d1 🔍
SHA256 a050469bf62094c8b0543aa676f12605ee9a93eefc61cf715eba48b87ce3aebf 🔍
SHA3 55262cd901a433b4e43680e768e6cf95b1bb0fa0c4894af6844e97f7cce5e345 🔍
VirtualSize 0x1958
VirtualAddress 0x24000
SizeOfRawData 0xa00
PointerToRawData 0x22200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.47518

.pdata

MD5 299fd63f421a366c6705b013f85f6947 🔍
SHA1 7c39ae61df0499cc4344a8ed1cb01c2ec603a990 🔍
SHA256 81bb6182b016a9241a6ea1c657cf4ef418fd239fb94f4c0ca5d38fbd4e686ff0 🔍
SHA3 0df180cfea37055b9945ccdd0a6f004729ef3560d0818c8d97c71518f2a6810e 🔍
VirtualSize 0x144c
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x22c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.90097

_RDATA

MD5 41ea609ed0ec71f23235d9e9b18cc429 🔍
SHA1 03240ae8bb1c12991e04fcbe7b76a977afb2f971 🔍
SHA256 35d18ff27b98e33e48179da2ddc32a049ef929849d56206accc174d8742a98ab 🔍
SHA3 24afc7045d58391176b7ce1b5412861f0537f9682cb458bc10c610a3aa44dc0f 🔍
VirtualSize 0xf4
VirtualAddress 0x28000
SizeOfRawData 0x200
PointerToRawData 0x24200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.44277

.rsrc

MD5 33b1739ef973e5c0733b5cf3872ef5cb 🔍
SHA1 9f801b3675590f53cceeb58e9a147fc1fe54f54e 🔍
SHA256 dc5cc20063bb30c69b29513b10016f048683443a64fbfa3e3c1a462917143f72 🔍
SHA3 7b9cf8480693fb9db866945d2b16dcfb796fa14d6e79f1fbaff392c8eff571dd 🔍
VirtualSize 0x218dc
VirtualAddress 0x29000
SizeOfRawData 0x21a00
PointerToRawData 0x24400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.20084

.reloc

MD5 3e4cd569c82075913d2243fb9e045f32 🔍
SHA1 b1461a5a441e1cccdc67c8cf02b28898c68373d9 🔍
SHA256 b2ca338412fb88ed9470a29bbbb30f214bc857ea5acf030b6de65d75e144c5eb 🔍
SHA3 40db256150f5391679bf72b9a7e999ca88af95b9da1f090d8de3d39bdd7152c3 🔍
VirtualSize 0x318
VirtualAddress 0x4b000
SizeOfRawData 0x400
PointerToRawData 0x45e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.70426

Imports

KERNEL32.dll FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
FindClose
MultiByteToWideChar
GetLastError
GetFileAttributesExW
GetFullPathNameW
GetProcAddress
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
LoadLibraryExW
FreeLibrary
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
EnterCriticalSection
FindFirstFileExW
OutputDebugStringW
LoadLibraryA
GetModuleHandleW
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___wargv
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_errno
_configure_wide_argv
_invalid_parameter_noinfo_noreturn
_set_app_type
_seh_filter_exe
_c_exit
exit
_cexit
_register_thread_local_exe_atexit_callback
_crt_atexit
_exit
_initterm_e
abort
_register_onexit_function
_initialize_onexit_table
terminate
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
__stdio_common_vsprintf_s
setvbuf
_wfopen
_set_fmode
__stdio_common_vswprintf
__acrt_iob_func
fputwc
fputws
__stdio_common_vfwprintf
fflush
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
free
malloc
calloc
api-ms-win-crt-string-l1-1-0.dll wcsnlen
strcpy_s
_wcsdup
strcspn
wcsncmp
toupper
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-locale-l1-1-0.dll __pctype_func
_unlock_locales
localeconv
_lock_locales
___lc_codepage_func
___mb_cur_max_func
_configthreadlocale
setlocale
___lc_locale_name_func
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
frexp
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
wcsftime
_time64

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.31144
MD5 bab3f3e26e7702cfea8a6caf29a499e8 🔍
SHA1 d17389ec05234face5c4fff7c865e6a14de9336f 🔍
SHA256 fdcbe585c7779894f9772495e74ced2e5553b7032d50a07523fa1c9440a4b6c2 🔍
SHA3 0c4d9219192eab7949ca7e4b10ede7c569910e1d58088ae32ad6266e131ab263 🔍

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.16353
MD5 0e74432caab984672e83dafbcc404c4b 🔍
SHA1 1ffd1ceb4f4484a811ba61734d4e10018f10aa8c 🔍
SHA256 cefad2ee93891cff9c3000d98b586843a068297fa7603405bc719dd676aa9b4c 🔍
SHA3 fb95ccb27fe88778427ec184add6757c490f8f212b6f1cb73ad99208e77e7936 🔍

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.02024
MD5 ddb032cf9a5c29d50cfa7ebf5b7dba08 🔍
SHA1 836b63d0a10b9e495005ab4895253c0894a08ab0 🔍
SHA256 1c442502cdb5ee238ce671269ef5bab0dfa39cec93ceecd0eafac28a96b50a80 🔍
SHA3 ec812e6dd0b613143732a5567af84e3139b25a77f96d6bd31eb4b0a509a6c30c 🔍

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6097
MD5 1808f10c454d825a0f95b82c37672e46 🔍
SHA1 120da705c324c9ad33e5219e63b97d673f73a668 🔍
SHA256 1b6e738b9fcfbc4277ca988bebe53ad56b5b6b46834e4403232a6a7fb5b77a14 🔍
SHA3 d8153f4925eed89ac7989ae0fa381d87b2a20201380223575c5063dcb1af2002 🔍

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.40602
MD5 771273a59da8e84a9adce8214f95cddb 🔍
SHA1 7735fd9b3753d5829b30e414413b543e4fbfbd64 🔍
SHA256 a8088d07e4f0adeb065eca2cc463fcdaef59efb99563723683a171bdcfc74f72 🔍
SHA3 1adfcc7f597b2ebc2ed175cd7d0f3fb918655d56240b7b29b48da92803c370c0 🔍

6

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98336
MD5 8f7a59dc5cf9651c4c21d876f83f273a 🔍
SHA1 19740e8c731fbd485248493d5a2d75ed7600c341 🔍
SHA256 2c75f1bca6705edac27866da02fb4334e1b93627941191d6fb5a8b79c70f5430 🔍
SHA3 592f686bb61a58b7985e725815b654aad39123e38cddebf539cd601b5957e284 🔍

7

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x77e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93373
Detected Filetype PNG graphic file
MD5 c523e822dc87d21f5228058fb29ea971 🔍
SHA1 f6c9edae7a5ca37c11a80e26c39a08239471f49b 🔍
SHA256 119d49741853a1ef16fb695ad864c92d64b8e038062bca6b3b2570d1f35d7ebe 🔍
SHA3 b24c2172865d3761c6605c08415a6448f833ab43c0746a0a965a2cdc51950add 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91902
Detected Filetype Icon file
MD5 0e3acf18cfc0c7355ad782801a81504e 🔍
SHA1 f56afeb798733762358cb327bd3947db5df6773b 🔍
SHA256 d7ce4b7d8559b8e0da3cfbdd072af752d4fa503c0e872bfb5779bef79475f635 🔍
SHA3 21a9d4ade7212b5715395ea81433b5e94e94eb0a5253babbc779a8f992842f63 🔍

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30862
MD5 1835440f34839a49f1758ef33b37bf5b 🔍
SHA1 42567995dde98c7109358c7b27a36d8998ee025c 🔍
SHA256 677dcfac5177371fa25ad1cbe9e4c91b88db21feb18bdef4175e270b8c2d8e4f 🔍
SHA3 b48c3369c216e6f033b5608d392be05ef9ad4defeb8a91e18cc908d473c14eec 🔍

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xce1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00175
MD5 73f60e86e7ab2b7a73a1f1a18e93b7ad 🔍
SHA1 549a55e09318ff6829abdfdf624955abb4cd6776 🔍
SHA256 742f6de330674fa9308385d4dfa408bac8f7498de822176671fc77804db6b75e 🔍
SHA3 7b08b0ba07bf513724d536c406b5f81453e57a52142dad8addabfad1914c50e6 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.11.4.0
ProductVersion 2.11.4.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Bloxstrap
FileDescription Bloxstrap
FileVersion (#2) 2.11.4
InternalName Bloxstrap.dll
LegalCopyright
OriginalFilename Bloxstrap.dll
ProductName Bloxstrap
ProductVersion (#2) 2.11.4
Assembly Version 2.11.4.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 109
AddressOfRawData 0x1ff78
PointerToRawData 0x1e978
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 20
AddressOfRawData 0x1ffe8
PointerToRawData 0x1e9e8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Oct-15 03:29:49
Version 0.0
SizeofData 964
AddressOfRawData 0x1fffc
PointerToRawData 0x1e9fc

TLS Callbacks

StartAddressOfRawData 0x1400203e0
EndAddressOfRawData 0x1400203f0
AddressOfIndex 0x140025940
AddressOfCallbacks 0x14001a4c8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024020
GuardCFCheckFunctionPointer 5368816648
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x4ad45e8d
Unmarked objects 0
C objects (30034) 12
ASM objects (30034) 10
C++ objects (30034) 83
Imports (VS2008 SP1 build 30729) 16
Imports (29395) 9
Total imports 205
C++ objects (LTCG) (30154) 10
Linker (30154) 1

Errors

Leave a comment

No comments yet.