| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-08 22:41:55 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
C:\Users\Ivan\Downloads\bladeball\bin\Roblox_External.pdb
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Dec-08 22:41:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x53ac00 |
| SizeOfInitializedData | 0xabba00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000004D8318 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xffa000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_43.dll |
D3DCompile
|
| KERNEL32.dll |
Sleep
GetLastError K32GetModuleBaseNameW K32GetDeviceDriverBaseNameW GetCurrentThread FreeConsole CreateThread SetFileAttributesA LocalFree ExitProcess GetCurrentProcessId CreateProcessW SetThreadExecutionState GetModuleHandleW GetConsoleWindow QueryFullProcessImageNameW K32EnumProcessModules CreateDirectoryA AllocConsole CreateFileA GetFileSizeEx ReadFile HeapAlloc HeapFree MapViewOfFile UnmapViewOfFile CreateFileMappingA ReleaseSRWLockExclusive AcquireSRWLockExclusive EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection GetSystemDirectoryW GetVolumeInformationA SleepEx FormatMessageW MoveFileExW WaitForSingleObjectEx GetEnvironmentVariableA GetFileType PeekNamedPipe WaitForMultipleObjects VerifyVersionInfoW AreFileApisANSI CreateFile2 SetFileInformationByHandle GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose CreateDirectoryW GetLocaleInfoEx FormatMessageA GetFileInformationByHandleEx SleepConditionVariableSRW SetThreadPriority K32GetModuleFileNameExW GetModuleFileNameW TerminateProcess OutputDebugStringA GetCurrentProcess SetConsoleTitleA SetLastError VirtualProtect QueryDosDeviceW GetModuleFileNameA GetCurrentThreadId WakeAllConditionVariable SetUnhandledExceptionFilter GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead CreateFileW K32EnumDeviceDrivers Module32NextW Module32FirstW CloseHandle Process32FirstW Process32NextW CreateToolhelp32Snapshot OpenProcess GetProcessId GlobalUnlock WideCharToMultiByte GlobalLock GlobalFree GlobalAlloc QueryPerformanceCounter FreeLibrary VerSetConditionMask GetProcAddress QueryPerformanceFrequency LoadLibraryA MultiByteToWideChar GetLocaleInfoA GetModuleHandleA GetTickCount GetStdHandle SetConsoleTextAttribute LoadLibraryW |
| USER32.dll |
GetKeyState
SetClipboardData GetClipboardData ScreenToClient GetMessageExtraInfo ClientToScreen TrackMouseEvent GetKeyboardLayout EmptyClipboard GetForegroundWindow LoadCursorW CloseClipboard SetCapture SetCursor GetClientRect GetCapture SetProcessDPIAware GetWindowLongW GetWindowThreadProcessId DefWindowProcW IsWindowUnicode ReleaseCapture PostMessageW SetCursorPos OpenClipboard GetWindowTextW GetCursorPos GetAsyncKeyState DestroyWindow IsWindowVisible keybd_event CreateWindowExW SendMessageW GetSystemMetrics UnregisterClassW SendInput UpdateWindow FindWindowA GetParent PostQuitMessage SetWindowLongW mouse_event FindWindowW TranslateMessage SetLayeredWindowAttributes EnumWindows SetWindowDisplayAffinity PeekMessageW DispatchMessageW ShowWindow RegisterClassExW |
| ADVAPI32.dll |
CryptEncrypt
CryptImportKey CheckTokenMembership GetTokenInformation CryptDestroyKey CryptDestroyHash CryptHashData CryptCreateHash CryptGetHashParam CryptReleaseContext CryptAcquireContextW RegCloseKey GetCurrentHwProfileA ConvertSidToStringSidA RegQueryValueExA AllocateAndInitializeSid RegCreateKeyExA RegSetValueExA OpenProcessToken FreeSid RegOpenKeyExA |
| SHELL32.dll |
SHGetFolderPathA
ShellExecuteExW ShellExecuteA |
| MSVCP140.dll |
__crtLCMapStringA
??7ios_base@std@@QEBA_NXZ ?_Xbad_alloc@std@@YAXXZ ?_Winerror_map@std@@YAHH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Syserror_map@std@@YAPEBDH@Z ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?uncaught_exceptions@std@@YAHXZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xout_of_range@std@@YAXPEBD@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_N@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?good@ios_base@std@@QEBA_NXZ ??Bios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ _Query_perf_frequency ?_Xbad_function_call@std@@YAXXZ _Query_perf_counter _Xtime_get_ticks ?_Throw_Cpp_error@std@@YAXH@Z _Cnd_do_broadcast_at_thread_exit _Thrd_detach _Strxfrm ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?id@?$ctype@D@std@@2V0locale@2@A ?id@?$collate@D@std@@2V0locale@2@A _Strcoll ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?tolower@?$ctype@D@std@@QEBADD@Z ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z _Thrd_yield ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?_Random_device@std@@YAIXZ _Mtx_lock _Mtx_unlock ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ |
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| WINHTTP.dll |
WinHttpCloseHandle
WinHttpReadData WinHttpSetTimeouts WinHttpConnect WinHttpOpen WinHttpSendRequest WinHttpOpenRequest WinHttpReceiveResponse WinHttpQueryDataAvailable |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| bcrypt.dll |
BCryptDestroyKey
BCryptGenRandom BCryptGenerateSymmetricKey BCryptCreateHash BCryptSetProperty BCryptHashData BCryptDestroyHash BCryptCloseAlgorithmProvider BCryptFinishHash BCryptOpenAlgorithmProvider BCryptDecrypt BCryptGetProperty |
| WS2_32.dll |
WSAStartup
WSACleanup bind connect getpeername inet_ntop gethostname ioctlsocket sendto recvfrom WSACreateEvent getaddrinfo listen htonl accept select __WSAFDIsSet WSAIoctl socket setsockopt recv htons WSAEnumNetworkEvents WSAEventSelect WSAResetEvent WSAWaitForMultipleEvents WSACloseEvent closesocket WSAGetLastError inet_pton ntohs freeaddrinfo WSASetLastError getsockname getsockopt send |
| CRYPT32.dll |
CryptStringToBinaryW
CertFindExtension CertAddCertificateContextToStore CertFreeCertificateChain CertGetCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject CertOpenStore CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertFreeCertificateContext CryptDecodeObjectEx PFXImportCertStore CertGetNameStringW |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
_CxxThrowException
__intrinsic_setjmp __current_exception_context __current_exception wcschr memcmp memchr memset memmove memcpy longjmp strrchr wcsstr __C_specific_handler strstr __RTtypeid strchr __std_type_info_compare __std_terminate __std_exception_copy __std_exception_destroy |
| api-ms-win-crt-heap-l1-1-0.dll |
calloc
free _set_new_mode _callnewh malloc realloc |
| api-ms-win-crt-math-l1-1-0.dll |
asinf
acosf _fdopen _dsign _dclass cosf roundf ceilf __setusermatherr fmodf sqrtf log logf pow sinf powf sin cos |
| api-ms-win-crt-stdio-l1-1-0.dll |
fseek
__stdio_common_vsprintf_s _pclose fclose _lseeki64 fgetc fgets _set_fmode _popen freopen_s ftell __stdio_common_vsprintf __p__commode fflush setvbuf _read _write _wopen _fileno _close fgetpos fputs __stdio_common_vfprintf __acrt_iob_func _wfopen fwrite _get_stream_buffer_pointers _fseeki64 __stdio_common_vsscanf fread fsetpos ungetc feof fputc |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
remove _unlock_file _wstat64 _unlink _fstat64 |
| api-ms-win-crt-runtime-l1-1-0.dll |
_wassert
_configure_wide_argv _beginthreadex _errno terminate __sys_nerr _register_thread_local_exe_atexit_callback _c_exit _exit system _initterm_e _initterm _get_wide_winmain_command_line _initialize_wide_environment abort __sys_errlist exit _set_app_type _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
atoi strtoul strtoll atof wcstombs strtod strtoull |
| api-ms-win-crt-time-l1-1-0.dll |
strftime
_time64 _gmtime64 _localtime64_s |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_collate_cp_func
_configthreadlocale localeconv ___lc_codepage_func ___lc_locale_name_func |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
rand |
| api-ms-win-crt-string-l1-1-0.dll |
_strdup
wcsncpy strpbrk wcsncmp strspn wcspbrk strcspn _wcsdup strncmp strcmp strncpy isdigit isalnum tolower _wcsicmp _stricmp strlen wcslen |
| api-ms-win-crt-environment-l1-1-0.dll |
_dupenv_s
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-08 22:41:55 |
| Version | 0.0 |
| SizeofData | 82 |
| AddressOfRawData | 0xee8b3c |
| PointerToRawData | 0xee7b3c |
| Referenced File | C:\Users\Ivan\Downloads\bladeball\bin\Roblox_External.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-08 22:41:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xee8b90 |
| PointerToRawData | 0xee7b90 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-08 22:41:55 |
| Version | 0.0 |
| SizeofData | 992 |
| AddressOfRawData | 0xee8ba4 |
| PointerToRawData | 0xee7ba4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-08 22:41:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140ee8fb0 |
|---|---|
| EndAddressOfRawData | 0x140ee9104 |
| AddressOfIndex | 0x140f8a590 |
| AddressOfCallbacks | 0x14053d518 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001404D7C88
0x00000001404D7CF0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140f2f900 |
| XOR Key | 0x1e2ece9d |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| 253 (35403) | 8 |
| ASM objects (35403) | 4 |
| C objects (35403) | 10 |
| C++ objects (35403) | 43 |
| Imports (35403) | 6 |
| Imports (33145) | 26 |
| C objects (VS2022 Update 6 (17.6.4) compiler 32535) | 123 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (21202) | 7 |
| Total imports | 597 |
| ASM objects (35717) | 1 |
| C++ objects (LTCG) (35717) | 104 |
| Resource objects (35717) | 1 |
| 151 | 1 |
| Linker (35717) | 1 |