b1bc13bafb557cbc27c42d8beb29176ce5fd62a65078ae17204fac9a0191e03b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Feb-12 01:57:20
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName F9 Inject
FileDescription F9 Inject
FileVersion 1.0.0.0
InternalName F9 Inject.dll
LegalCopyright
OriginalFilename F9 Inject.dll
ProductName F9 Inject
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Safe VirusTotal score: 0/71 (Scanned on 2026-01-13 02:20:09) All the AVs think this file is safe.

Hashes

MD5 f37073fe3ee764b33edf823d8ea01b00 🔍
SHA1 2ec342d8092e8cccb9dbcd060222da5a53fae46e 🔍
SHA256 b1bc13bafb557cbc27c42d8beb29176ce5fd62a65078ae17204fac9a0191e03b 🔍
SHA3 92662da537b0402094113ba64fd18c7739ca3d50d6651743a190ecdcc4e3b9bb 🔍
SSDeep 6144:N+f4nKvaQhcF7qIBxuZjwpBNZfDtf2QGRZhWaLN:NvhqQ2QG8ax 🔍
Imports Hash 6a91eb82bfd19d2706c7d43c46f7064e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Feb-12 01:57:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x15a00
SizeOfInitializedData 0x2c800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000011230 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x46000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 fdd4e2c3207e23dcc5ba58de438638b1 🔍
SHA1 57c35f3df45693124331fc3330a05f6b8b994372 🔍
SHA256 2b549fccb4439cb1b8f86d91ad6e6730fe9bc08edc3a29bf473f7e5b1d11eefd 🔍
SHA3 f598be4bcd373f0294fef4f91eab21cb333e778390aa2f502c874698ee14f02f 🔍
VirtualSize 0x1595c
VirtualAddress 0x1000
SizeOfRawData 0x15a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.33834

.rdata

MD5 9791e105fbf4d3988ba9aa21e4478e81 🔍
SHA1 365cd27295f2508b44855186c6ef251515471618 🔍
SHA256 f3d2744c032923bf798272060d4764df2b22ef3ea8fa1b7ce9ac91ef93df21ae 🔍
SHA3 b715128599f1cbd2fc95bbc385ce751f1761a4701e590bb02f328640f0754257 🔍
VirtualSize 0x968e
VirtualAddress 0x17000
SizeOfRawData 0x9800
PointerToRawData 0x15e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.45055

.data

MD5 b72f229183f8ace9bfaa927c6f1f302d 🔍
SHA1 058e57a7b550267d0b4e63aeed5d6a7bc1219978 🔍
SHA256 fdb9e6df8c5da5f8c2b7116a392a00946c8e4d79472fcaebf8ed704e784f3c83 🔍
SHA3 ae2641bc3a2f8b19fd0fab5eec1b4d28a39d2a6347f87fc2dd82ebc64cc9c5a0 🔍
VirtualSize 0x1898
VirtualAddress 0x21000
SizeOfRawData 0xa00
PointerToRawData 0x1f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.38021

.pdata

MD5 0e56c807892d815c0455bf816b22a5a2 🔍
SHA1 050637fa133f076222ef8a9109f871667e41e950 🔍
SHA256 f698a0ff3dd1bb2885f9f93a7a10da1e808ac1ff8bac7abdb0ada6cc81af3682 🔍
SHA3 5d2994d8a6ce5a4326ad396e2590a2b88da5c1335bb147e8fe0f256de7122303 🔍
VirtualSize 0x135c
VirtualAddress 0x23000
SizeOfRawData 0x1400
PointerToRawData 0x20000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.8809

.reloc

MD5 e0c6f48aac658908f5733951e5bee8fb 🔍
SHA1 54b1ab211e30c5ba812c67957851589c69173229 🔍
SHA256 e175eb0f4bde8765d7c2c28ee00c029ebd94213ad54985b1c28bcfd2d3e87d94 🔍
SHA3 e72c7a5166d197056d79982a41fccfc095ec06b5814f0548935a17680285e999 🔍
VirtualSize 0x328
VirtualAddress 0x25000
SizeOfRawData 0x400
PointerToRawData 0x21400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.76543

.rsrc

MD5 77925d63e8da47e17957bbfab87033c4 🔍
SHA1 feca972b7216499f79ef4f4f1eae75b1471cd5eb 🔍
SHA256 ab42ca6448e4c2b3a1fd63722fa85438cb4e7b80c0cb5e361610b12be5ae115b 🔍
SHA3 fae6d56c9656f40c290ff41d872480e7b496a2b04522bf70effbd62ae241adeb 🔍
VirtualSize 0x1fcc4
VirtualAddress 0x26000
SizeOfRawData 0x1fe00
PointerToRawData 0x21800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.93156

Imports

KERNEL32.dll FreeLibrary
LoadLibraryExW
OutputDebugStringW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
GetModuleHandleW
MultiByteToWideChar
GetFileAttributesExW
LoadLibraryA
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
GetProcAddress
GetWindowsDirectoryW
FindResourceW
GetLastError
ActivateActCtx
FindClose
CreateActCtxW
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetCurrentProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll _invalid_parameter_noinfo_noreturn
_exit
exit
_initterm_e
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_errno
abort
__p___wargv
_c_exit
_register_thread_local_exe_atexit_callback
terminate
__p___argc
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
fputwc
__p__commode
_set_fmode
fputws
_wfsopen
fflush
__stdio_common_vfwprintf
__stdio_common_vsnwprintf_s
__stdio_common_vswprintf
setvbuf
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
free
_callnewh
malloc
api-ms-win-crt-string-l1-1-0.dll toupper
_wcsdup
wcsncmp
wcsnlen
strcpy_s
api-ms-win-crt-convert-l1-1-0.dll wcstoul
_wtoi
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
_time64
wcsftime
api-ms-win-crt-locale-l1-1-0.dll setlocale
___mb_cur_max_func
_configthreadlocale
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_lock_locales
_unlock_locales
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1f19a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94929
Detected Filetype PNG graphic file
MD5 2b628f8a83ac203324d1df2aec7b23ab 🔍
SHA1 6710b23788fa147d0369dd2c81904bb42d726cd1 🔍
SHA256 1836c339bd45f14e5781a6c49499b0cc825b266214708321c86924cd5e3c65fa 🔍
SHA3 2d9cf14f6a03aee6bda1ab3cc5689cb3894d406b00c669d62e31b9a4eeb75fb0 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.59047
Detected Filetype Icon file
MD5 e7e5e6c28e544badc6dd18e16e671079 🔍
SHA1 42cb5e0750a9e87edd57faec55d5ca3f66d9a64c 🔍
SHA256 f0bec1bbfa2043127ff453bdd24123a622252c7cfbd4a6d5714dd160c213974a 🔍
SHA3 dc684b7af182f9263a384c4882031c236c933f15c319b33e8fd5782797eae76a 🔍

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26048
MD5 3b4427a673c9a3843025fcf580544e2c 🔍
SHA1 ebdfc33110453395735540a7efdf189b23315a67 🔍
SHA256 fdac155a66ecf2d33790cffd07afd1f3178146cc1236dd85d5b6e9b3829b9e1d 🔍
SHA3 526f05650b6a4187b82e5fa1f603eac5a8623d158644cbc8171b75520570cfc6 🔍

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x721
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.40367
MD5 56dfde86ff963601849e6f1d2a3c0bc5 🔍
SHA1 caea7165157e5da4df350312cb5f17d83484d06d 🔍
SHA256 1de7dfc0132c37cda6c66cad2506c1d9e0ba91ad7d75bba82023ad6fe8c1f65e 🔍
SHA3 4b3a9d3441df5730dab87b26654cfbcfb1029427b841797e478d5a20d248bb2e 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName F9 Inject
FileDescription F9 Inject
FileVersion (#2) 1.0.0.0
InternalName F9 Inject.dll
LegalCopyright
OriginalFilename F9 Inject.dll
ProductName F9 Inject
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Feb-12 04:50:41
Version 0.0
SizeofData 109
AddressOfRawData 0x1d220
PointerToRawData 0x1c020
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Feb-12 04:50:41
Version 0.0
SizeofData 20
AddressOfRawData 0x1d290
PointerToRawData 0x1c090

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Feb-12 04:50:41
Version 0.0
SizeofData 988
AddressOfRawData 0x1d2a4
PointerToRawData 0x1c0a4

TLS Callbacks

StartAddressOfRawData 0x14001d6c8
EndAddressOfRawData 0x14001d6d8
AddressOfIndex 0x140022880
AddressOfCallbacks 0x1400174e0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140021080
GuardCFCheckFunctionPointer 5368804368
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x8c740897
Unmarked objects 0
ASM objects (34321) 10
C objects (34321) 12
C++ objects (34321) 87
Imports (VS2008 SP1 build 30729) 16
Imports (33138) 9
Total imports 201
C++ objects (LTCG) (34435) 10
Linker (34435) 1

Errors

Leave a comment

No comments yet.