cf74afc6637db7343fa18661c971e4747e222f1746b5be8d556989a1d0b01692

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-17 19:13:01
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts audio_bridge_app.pdb
CompanyName vlads
FileDescription NektoMeme
FileVersion 3.0.0
ProductName NektoMeme
ProductVersion 3.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • http://dummy.testC
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://app.nektome.me
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://docs.rs
  • https://github.com
  • https://nektome.me
  • https://www.World
  • https://www.recent
  • microsoft.com
  • openssl.org
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowW
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
  • RegGetValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtOpenFile
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtWriteFile
  • NtReadFile
  • NtCreateFile
  • NtCancelIoFileEx
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • MapVirtualKeyW
  • GetForegroundWindow
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Can take screenshots:
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Interacts with the certificate store:
  • CertAddEncodedCertificateToStore
  • CertOpenStore
Suspicious VirusTotal score: 2/70 (Scanned on 2026-08-18 14:59:18) Kaspersky: UDS:Trojan.Win64.SBadur.gen
Trapmine: suspicious.low.ml.score

Hashes

MD5 c9ab16b48b2177d0c1796f7b5351f128 🔍
SHA1 ad9340cce666cfaf2f9b6aa324ce44350d30d76d 🔍
SHA256 cf74afc6637db7343fa18661c971e4747e222f1746b5be8d556989a1d0b01692 🔍
SHA3 b0ead097d70c0cbd3f982857f347792eb13fb7560284819338bdc6306a7f5a49 🔍
SSDeep 196608:Sweg18FTje4ldV/eMHPI9pgvfxrH4VrUHO:SwF18FTje4ldV/eMH4gvCVrUHO 🔍
Imports Hash 6f5852698d35bce934e8904c355d2557 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-17 19:13:01
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x8eea00
SizeOfInitializedData 0x396c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000008C3908 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xc88000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c680c4f6b9907f19797c5cf289e0f1ec 🔍
SHA1 1ed8829badb02a799a3111b1ca95ab76f233623e 🔍
SHA256 50185ed67dd4f427a63fc204da39352db8e61260b27199dab1cb459337d8f5b7 🔍
SHA3 e776a17e31a88c5c30f011aa5f12b570ebf3e38afc4fecd8ee04c2a7c2f524a0 🔍
VirtualSize 0x8ee950
VirtualAddress 0x1000
SizeOfRawData 0x8eea00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.19858

.rdata

MD5 14cf5e7dcdcb9c76d693b21efa1ee7a7 🔍
SHA1 9d44bfb1a0cdb833b04ddffaf163f510b58826be 🔍
SHA256 1a5633e7b7f54c1ecced95cb4435f87e14e080e32d7bc722ef8fac4de64bb08f 🔍
SHA3 fb515b48782432f96373c0e3513bd490bbb0d198470aa282b9d79629d435307a 🔍
VirtualSize 0x30baf8
VirtualAddress 0x8f0000
SizeOfRawData 0x30bc00
PointerToRawData 0x8eee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.89667

.data

MD5 3577f89c7acc2ee4e16347f47938ff1f 🔍
SHA1 81df63a8db8fd2d1c6c2c2f9c459ad106984f053 🔍
SHA256 5bcc915015ba0ec3b09003e8a0051dd61cdc6c0dfd90c5e748bb40961cd84384 🔍
SHA3 ed7270767e3e080039a36cb4bc3c867ae57e3f31cbc716dfd26762b079d7412b 🔍
VirtualSize 0x3e20
VirtualAddress 0xbfc000
SizeOfRawData 0x1400
PointerToRawData 0xbfaa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.16303

.pdata

MD5 df44cd9bad269f50d258b5002c8e5252 🔍
SHA1 d8752c209cfd7d5eb4683866d3f43d39a11871f0 🔍
SHA256 28f6b3362fa0225794f64eb613af6ae740817a06153d53d63d679a3048e04872 🔍
SHA3 744a57ca9e036236511a56fd99b2de6c849ae9ad8156f5c15ad4aab235b4aeeb 🔍
VirtualSize 0x7d868
VirtualAddress 0xc00000
SizeOfRawData 0x7da00
PointerToRawData 0xbfbe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.57377

.rsrc

MD5 db526275e400e6da45148f0f0cad3537 🔍
SHA1 e24115529e3c7fd27d22281f99868f70013303e5 🔍
SHA256 f68d051fdb3d0ad765d6863281599dcba7feb096d292428a5d2306e0cd5a2080 🔍
SHA3 69bc4d28ec954224c4b1052079318d8c1b9a21d7d9191dadd43c66a2d79be838 🔍
VirtualSize 0x2ee0
VirtualAddress 0xc7e000
SizeOfRawData 0x3000
PointerToRawData 0xc79800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.38913

.reloc

MD5 07c6fce4b578494faeb82b8b16d76344 🔍
SHA1 8864cfd3f23c4c428c8134a1fe061a3b5530cf40 🔍
SHA256 f95ffcb0f165c283088c2c152526cc6dfc9c12dd7671d14bf7ea0111f71a568e 🔍
SHA3 408fd34003b1fca9fce63d879c08cecf44cf72d3f004a1a1a8ecb8ae54c44fe7 🔍
VirtualSize 0x6540
VirtualAddress 0xc81000
SizeOfRawData 0x6600
PointerToRawData 0xc7c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45577

Imports

bcryptprimitives.dll ProcessPrng
advapi32.dll RegOpenKeyExW
RegQueryValueExW
RegCloseKey
RegGetValueW
ntdll.dll NtOpenFile
NtCreateNamedPipeFile
NtDeviceIoControlFile
NtWriteFile
RtlNtStatusToDosError
NtReadFile
RtlGetVersion
NtCreateFile
NtCancelIoFileEx
kernel32.dll RaiseException
RtlPcToFileHeader
TlsFree
LoadLibraryW
FindNextFileW
GetTempPathW
InitializeSListHead
SetWaitableTimer
CreateWaitableTimerExW
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
SetEnvironmentVariableW
DeleteFileW
DeviceIoControl
CreateSymbolicLinkW
GetFinalPathNameByHandleW
CreateMutexA
UnhandledExceptionFilter
WaitForSingleObjectEx
WideCharToMultiByte
SwitchToThread
GetSystemInfo
ExitProcess
FindClose
FindFirstFileExW
EncodePointer
GetCurrentThreadId
TlsAlloc
GetCommandLineW
GetCurrentDirectoryW
GetCurrentThread
SetThreadStackGuarantee
AddVectoredExceptionHandler
SetFilePointerEx
CreateDirectoryW
LoadLibraryA
TlsSetValue
CreateProcessW
GetWindowsDirectoryW
GetSystemDirectoryW
GetEnvironmentStringsW
GetFileInformationByHandleEx
GetSystemTimePreciseAsFileTime
RtlLookupFunctionEntry
RtlCaptureContext
DuplicateHandle
GetCurrentProcess
ReadFileEx
GetCurrentProcessId
CreateThread
lstrlenW
IsProcessorFeaturePresent
QueryPerformanceCounter
QueryPerformanceFrequency
SetHandleInformation
HeapReAlloc
SetFileCompletionNotificationModes
SetFileTime
GetFileAttributesW
OutputDebugStringA
OutputDebugStringW
GetModuleFileNameW
GetProcessHeap
HeapFree
LoadLibraryExW
GetModuleHandleW
SetUnhandledExceptionFilter
ReleaseMutex
FreeLibrary
SetFileInformationByHandle
SetLastError
SleepEx
RtlUnwindEx
GetUserDefaultUILanguage
WriteFileEx
WaitForSingleObject
FreeEnvironmentStringsW
CompareStringOrdinal
GetEnvironmentVariableW
RtlVirtualUnwind
TerminateProcess
LCIDToLocaleName
TlsGetValue
GetModuleHandleA
Sleep
GetProcAddress
LoadLibraryExA
GetLastError
HeapAlloc
CloseHandle
DeleteCriticalSection
FormatMessageW
GetFullPathNameW
CreateMutexW
InitializeCriticalSectionAndSpinCount
CreateFileW
SetNamedPipeHandleState
IsDebuggerPresent
GetSystemTimeAsFileTime
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetStdHandle
GetConsoleMode
GetFileInformationByHandle
GetQueuedCompletionStatusEx
CreateIoCompletionPort
CancelIoEx
WriteFile
ReadFile
PostQueuedCompletionStatus
GetOverlappedResult
user32.dll SendMessageW
PostMessageW
VkKeyScanW
DrawTextW
GetWindowDC
OffsetRect
PostThreadMessageW
GetMenuBarInfo
DestroyMenu
DrawIconEx
CheckMenuItem
GetMenuItemInfoW
RemoveMenu
CreatePopupMenu
CreateMenu
SetMenu
DrawMenuBar
ClientToScreen
SetMenuItemInfoW
AppendMenuW
InsertMenuW
TrackPopupMenu
PostQuitMessage
CreateAcceleratorTableW
DestroyAcceleratorTable
CreateIcon
GetAsyncKeyState
GetKeyboardState
MapVirtualKeyExW
ToUnicodeEx
GetKeyState
GetMenu
IsWindowVisible
AdjustWindowRect
MonitorFromPoint
SetWindowTextW
GetWindowTextW
CreateWindowExW
PeekMessageW
GetWindowTextLengthW
SendInput
SetForegroundWindow
DestroyIcon
GetRawInputData
GetKeyboardLayout
SetWindowDisplayAffinity
SystemParametersInfoA
SetPropW
SetWindowLongW
EnableMenuItem
SetWindowPlacement
GetWindowPlacement
ClipCursor
GetClipCursor
ShowCursor
GetMessageW
GetSystemMenu
ReleaseCapture
SetCapture
MsgWaitForMultipleObjectsEx
RegisterWindowMessageA
SetParent
MapWindowPoints
InvalidateRgn
LoadCursorW
GetWindow
MapVirtualKeyW
SetCursor
RedrawWindow
SetFocus
ShowWindow
RegisterClassExW
SetCursorPos
ReleaseDC
GetWindowRect
GetParent
FindWindowExW
SetWindowRgn
EnableWindow
IsWindowEnabled
IsProcessDPIAware
GetDC
DispatchMessageW
SetWindowPos
FindWindowW
DefWindowProcW
GetMessageA
IsIconic
TranslateAcceleratorW
EnumChildWindows
TranslateMessage
EnumDisplayMonitors
SetWindowLongPtrW
GetWindowLongPtrW
GetUpdateRect
ValidateRect
CloseTouchInputHandle
GetTouchInputInfo
TrackMouseEvent
SystemParametersInfoW
FillRect
GetMonitorInfoW
MonitorFromRect
MonitorFromWindow
GetCursorPos
GetClientRect
GetWindowLongW
ScreenToClient
DestroyWindow
DispatchMessageA
GetForegroundWindow
ChangeDisplaySettingsExW
RegisterRawInputDevices
RegisterTouchWindow
GetSystemMetrics
IsWindow
AdjustWindowRectEx
FlashWindowEx
GetActiveWindow
UpdateWindow
InvalidateRect
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WakeByAddressSingle
WaitOnAddress
comctl32.dll DefSubclassProc
TaskDialogIndirect
RemoveWindowSubclass
SetWindowSubclass
ole32.dll OleInitialize
RevokeDragDrop
CoInitialize
CoUninitialize
CoTaskMemFree
CoCreateInstance
RegisterDragDrop
CoTaskMemAlloc
CoInitializeEx
CoCreateFreeThreadedMarshaler
gdi32.dll CreateSolidBrush
SetBkMode
SetTextColor
CreateCompatibleDC
DeleteDC
SelectObject
GetDeviceCaps
CreateDIBSection
DeleteObject
CreateRectRgn
BitBlt
CombineRgn
dwmapi.dll DwmSetWindowAttribute
DwmGetWindowAttribute
DwmEnableBlurBehindWindow
shlwapi.dll SHCreateMemStream
shell32.dll SHGetKnownFolderPath
ShellExecuteW
DragQueryFileW
ILCreateFromPathW
ILFree
SHCreateItemFromParsingName
DragFinish
ShellExecuteExW
SHOpenFolderAndSelectItems
SHAppBarMessage
oleaut32.dll SetErrorInfo
GetErrorInfo
SysStringLen
SysFreeString
ws2_32.dll WSACleanup
WSASocketW
WSAStartup
freeaddrinfo
bind
getaddrinfo
WSAIoctl
shutdown
getpeername
getsockopt
WSAGetLastError
getsockname
recv
WSASend
send
setsockopt
ioctlsocket
connect
closesocket
crypt32.dll CertGetCertificateChain
CertVerifyCertificateChainPolicy
CertSetCertificateContextProperty
CertAddEncodedCertificateToStore
CertCloseStore
CertFreeCertificateContext
CertFreeCertificateChainEngine
CertFreeCertificateChain
CertCreateCertificateChainEngine
CertOpenStore
bcrypt.dll BCryptGenRandom
ADVAPI32.dll EventSetInformation
SystemFunction036
EventWriteTransfer
EventUnregister
EventRegister
api-ms-win-crt-string-l1-1-0.dll wcsncmp
strcpy_s
wcscmp
wcslen
_wcsicmp
strlen
api-ms-win-crt-math-l1-1-0.dll roundf
floor
pow
round
__setusermatherr
trunc
api-ms-win-crt-convert-l1-1-0.dll wcstol
_ultow_s
_wtoi
api-ms-win-crt-runtime-l1-1-0.dll _initterm
_configure_narrow_argv
_set_app_type
_initialize_onexit_table
_seh_filter_exe
__p___argc
_get_initial_narrow_environment
_register_onexit_function
_crt_atexit
_register_thread_local_exe_atexit_callback
terminate
_c_exit
_exit
abort
_cexit
__p___argv
_initialize_narrow_environment
_initterm_e
exit
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll malloc
free
_set_new_mode
_callnewh
calloc

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x528
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.6426
Detected Filetype PNG graphic file
MD5 8b9e7d6e4a2a1f3a3221e035d6e2fcfb 🔍
SHA1 cb497a0a16e9d14d5590f5f8a60039353c8ef1ea 🔍
SHA256 98bf24df096f08fbf981bab736a0f81cbd40aa35fda1e853c5d56fb7cc183349 🔍
SHA3 0bee9849405c6c4e053ee63db1f1b02ff034612ef82e2d173a127ed2b1093f79 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2a9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.48296
Detected Filetype PNG graphic file
MD5 d7bf7df7466f4e5de8019c20a124e96c 🔍
SHA1 8593f603c23c0cdfb006c133672b56b8b2f067cc 🔍
SHA256 e5d1c4e2c356fc03bdb9708ca3bf785fcdc823d7ce56e6f255ff5b4db1088279 🔍
SHA3 7bc32c46b409c0ac41ebc481a47b7119a49e05e2b52cfe6d10c888632e0a2c33 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4b1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74543
Detected Filetype PNG graphic file
MD5 7af84a58fe74438980e0bcc05ba80fe8 🔍
SHA1 0689862acd601b817949c20c4a4c07eb1d726cc9 🔍
SHA256 8085e6260ec5a48b39c8442cb8c2b87cb5aea4f826c4e303339a8086ed368235 🔍
SHA3 f0a4bd110c2575b772c5803ce4393bb2074b54c5feaeac4bfdfc7b431b346d4b 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x779
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63583
Detected Filetype PNG graphic file
MD5 9f3751abf3db44ab64930582ab395162 🔍
SHA1 a244bca5f01801ffd648d6d0e5acb1fa78e23c6c 🔍
SHA256 0a9d832a8b2293552a1b0758292163f25dbcaa146d113d96161c6417a9aa7b37 🔍
SHA3 57b88b47f797665de26d8c59b2add459c0ac156abc007c5fc61e39056fe7fa8d 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x916
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.58658
Detected Filetype PNG graphic file
MD5 505acb1cf0185dcf3573f5f7a89a7625 🔍
SHA1 bc8f0cc5d39a70b2c69832eb5042bc27df5c6b99 🔍
SHA256 f8ba7fa40c1cd09bb077317f9e12e2b8a906087bdb10ac3998b3f563a9f1ed15 🔍
SHA3 6b667dc09e7c30aafd46274dbd4f3f7211ecb749146d42b1452abc53d484556c 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xc0f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.4977
Detected Filetype PNG graphic file
MD5 59e8ae8ae2883afc8b904e06fe4d93f0 🔍
SHA1 6a3ac39283dad4100bb0a33bcf758f6cc0ab1c25 🔍
SHA256 b6964b5b1f926d7303e07e7460b39fdd424e9acde23b4d9ac61c62cbca56cb28 🔍
SHA3 79f4d4c9e3465b7fb05b8cf4f0157f46782ce6bb29b14b003438b298c9529290 🔍

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8021
Detected Filetype Icon file
MD5 f270a97f6f4e4277ae010a4444e01a3b 🔍
SHA1 1b6a780e465d970999eb9b1913e89ca79a8a8257 🔍
SHA256 d6f61d4fc17dcc2f1fadef748cf2ab8591a50411b49102814ef4b9a2f0340540 🔍
SHA3 b51061f1a9eb111a970b273df9d03920b51a2634c58cec4bfdbfdacd32eab2a3 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15396
MD5 f38c5c54afb2f966cb0a5da71b908aff 🔍
SHA1 27b83a3687633f5a00126b1a87f15b9809d0e482 🔍
SHA256 e466e21f221297f029982349029f99cf81aa9bb0ceb449eb991d7b77332d99e5 🔍
SHA3 5caee9d58ec55d4075c6d9ea4ffebb4ed0309f8fd95bdf768e0b3e755ee4407c 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7 🔍
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9 🔍
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8 🔍
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.0.0.0
ProductVersion 3.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName vlads
FileDescription NektoMeme
FileVersion (#2) 3.0.0
ProductName NektoMeme
ProductVersion (#2) 3.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-17 19:13:01
Version 0.0
SizeofData 45
AddressOfRawData 0xa036f4
PointerToRawData 0xa024f4
Referenced File audio_bridge_app.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-17 19:13:01
Version 0.0
SizeofData 20
AddressOfRawData 0xa03724
PointerToRawData 0xa02524

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-17 19:13:01
Version 0.0
SizeofData 1048
AddressOfRawData 0xa03738
PointerToRawData 0xa02538

TLS Callbacks

StartAddressOfRawData 0x140a03b98
EndAddressOfRawData 0x140a03dac
AddressOfIndex 0x140bff698
AddressOfCallbacks 0x1408f0cf0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001408997B0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140bfd0c0

RICH Header

XOR Key 0x140401e1
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (33731) 9
C objects (33731) 13
C++ objects (33731) 47
Imports (29395) 3
Total imports 446
C objects (33812) 12
Unmarked objects (#2) 715
Resource objects (33812) 1
Linker (33812) 1

Errors

Leave a comment

No comments yet.