d3cffee567457dbbafc05c331c0bedf077a1ce289c4c8d06c80f96fa421fff06

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-29 23:03:55
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts seekandpicture2_desktop.pdb
CompanyName FramePoison
FileDescription SeekAndPicture 2 — The Irony of Debt
FileVersion 0.10.175
LegalCopyright Copyright © 2026 FramePoison
ProductName SeekAndPicture 2 — The Irony of Debt
ProductVersion 0.10.175

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • developer.microsoft.com
  • genretrucklooksValueFrame.net
  • github.com
  • http://dummy.testC
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/microsoft-edge/webview2
  • https://github.com
  • https://www.World
  • https://www.recent
  • microsoft.com
  • thing.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to RC5 or RC6
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegGetValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtCreateNamedPipeFile
  • NtWriteFile
  • NtReadFile
  • NtOpenFile
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
  • MapVirtualKeyW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Suspicious VirusTotal score: 1/69 (Scanned on 2026-08-31 14:27:09) Trapmine: malicious.high.ml.score

Hashes

MD5 9e46964763a48a968f643e45a7b78104 🔍
SHA1 bb7bd5323cddeed19262d8dc7e02ea72383f09a5 🔍
SHA256 d3cffee567457dbbafc05c331c0bedf077a1ce289c4c8d06c80f96fa421fff06 🔍
SHA3 88d0bb947e4dcd9c5ed45a28be12cffdd32989885728bb65f808a3aa8ea6e9b3 🔍
SSDeep 98304:Hr+jSm5jNKiFSGxYBILV7xlSuYvPptxmPy9P4R7Xucs:L+D5jNKiFSGxYBILV7xlSuY3nIs 🔍
Imports Hash 0f666a7dee3ffc284a62096ce3074217 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-29 23:03:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x5f6800
SizeOfInitializedData 0x2a7400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000005D4BE0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x8a1000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 66883b4088dccddde0a1ebe3723793cd 🔍
SHA1 1bd19a70ba32118e430a154429d0ee00d93c1a27 🔍
SHA256 ebbffde4f44a7437f8e1fa76ae950c70c3067d28e70deb89d9eb01401914976e 🔍
SHA3 ff1864588f8a5cd18b99eaff2e32116713f1071b1c6688023437cf137feb8d2a 🔍
VirtualSize 0x5f67f0
VirtualAddress 0x1000
SizeOfRawData 0x5f6800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.18003

.rdata

MD5 3cf33ed57a6a6dd27dd5c69edd440563 🔍
SHA1 bf8329c026694688ebe397171f1cdc091d243d2f 🔍
SHA256 24594ce5166948068693599768d3b4d1f58ee26de95d8fb396f4d9f7f03b49cd 🔍
SHA3 b63315311af5e5a5f17933ab6348b942d869767c493529d5c2b04598828e6d9e 🔍
VirtualSize 0x22ba36
VirtualAddress 0x5f8000
SizeOfRawData 0x22bc00
PointerToRawData 0x5f6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.66337

.data

MD5 7d831905a9665f4071ca93e00096f483 🔍
SHA1 a5951e6dc3d200e141d697a39476148a4fac888d 🔍
SHA256 27fe7fa6fa4a3e3f5797e678752f22cfa3c90f1fd48684599897deb3f99cfd0d 🔍
SHA3 aa4dca6f76bf2696663ae091cdbbbe1abe1570a4cfba40b8811006fdaa220c21 🔍
VirtualSize 0x36a8
VirtualAddress 0x824000
SizeOfRawData 0xc00
PointerToRawData 0x822800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.08325

.pdata

MD5 7e292ef81ee9f6777fb02149cc9c0489 🔍
SHA1 7058ef4370f55804046260be4e9e6de402f0d4a9 🔍
SHA256 d9e1d023e1efcb1e0d5a4888d8ce12d0d8655ee44d273ee3f0ba8b67b457033b 🔍
SHA3 7c428469e7974b7889708714d6beeb14ddcdca6e4c890d5cfde841c9438021f0 🔍
VirtualSize 0x5571c
VirtualAddress 0x828000
SizeOfRawData 0x55800
PointerToRawData 0x823400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.52162

.rsrc

MD5 8ff0d1461a65c2fae4649c5662ce5617 🔍
SHA1 d2293bd6ae3369828f87c3dd6d4071505b963ee5 🔍
SHA256 0453199a5ae861fa978da93b31f1dfe2de504be7e1746737b0a496d5751123cb 🔍
SHA3 058c222a6f80fcc009ae32463ffa50db87304a3c701da1b19cda4763f2117ac5 🔍
VirtualSize 0x1ca40
VirtualAddress 0x87e000
SizeOfRawData 0x1cc00
PointerToRawData 0x878c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.97371

.reloc

MD5 a8113a54c9ab487d70ac80a98f392171 🔍
SHA1 25e4a83d8eaf2c7dcfbfae74406824d295e710d1 🔍
SHA256 6b70d22c377b3bd13a6dfab53d4dc5b8c7943cadcb733419f5f694ec037b44f8 🔍
SHA3 cf2e8a99b0b74bcd567e9e606293daca19b3b16e0e554710289841b0ad71239e 🔍
VirtualSize 0x5b08
VirtualAddress 0x89b000
SizeOfRawData 0x5c00
PointerToRawData 0x895800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43377

Imports

bcryptprimitives.dll ProcessPrng
advapi32.dll RegCloseKey
RegOpenKeyExW
RegQueryValueExW
RegGetValueW
ntdll.dll NtCreateNamedPipeFile
NtWriteFile
NtReadFile
RtlGetVersion
RtlNtStatusToDosError
NtOpenFile
kernel32.dll RtlPcToFileHeader
lstrlenW
IsProcessorFeaturePresent
RaiseException
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InitializeSListHead
UnhandledExceptionFilter
SetUnhandledExceptionFilter
RtlUnwindEx
FindNextFileW
GetTempPathW
SetWaitableTimer
CreateWaitableTimerExW
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
SetEnvironmentVariableW
IsDebuggerPresent
LoadLibraryW
LoadLibraryA
GetFinalPathNameByHandleW
ReleaseMutex
CreateMutexA
WaitForSingleObjectEx
WideCharToMultiByte
SwitchToThread
GetSystemInfo
ExitProcess
FindClose
FindFirstFileExW
GetCommandLineW
GetCurrentDirectoryW
GetSystemTimeAsFileTime
GetUserDefaultUILanguage
AddVectoredExceptionHandler
SetFilePointerEx
CreateDirectoryW
GetStdHandle
GetEnvironmentStringsW
TerminateProcess
GetExitCodeProcess
CreateProcessW
GetWindowsDirectoryW
GetSystemDirectoryW
GetFileInformationByHandleEx
GetSystemTimePreciseAsFileTime
RtlVirtualUnwind
SleepConditionVariableSRW
WakeAllConditionVariable
RtlLookupFunctionEntry
RtlCaptureContext
DuplicateHandle
OutputDebugStringA
OutputDebugStringW
GetModuleFileNameW
GetLastError
GetProcessHeap
HeapFree
LoadLibraryExW
LCIDToLocaleName
FreeLibrary
GetCurrentProcess
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
ReadFileEx
GetCurrentProcessId
CreateThread
QueryPerformanceCounter
QueryPerformanceFrequency
HeapReAlloc
SetFileTime
SetFileInformationByHandle
GetFullPathNameW
SetLastError
SleepEx
WriteFileEx
WaitForSingleObject
FreeEnvironmentStringsW
CompareStringOrdinal
GetEnvironmentVariableW
GetCurrentThreadId
GetModuleHandleW
CreateFileW
GetModuleHandleA
GetCurrentThread
Sleep
GetProcAddress
CloseHandle
LoadLibraryExA
HeapAlloc
DeleteCriticalSection
FormatMessageW
SetThreadStackGuarantee
GetConsoleMode
GetFileAttributesW
GetFileInformationByHandle
InitializeCriticalSectionAndSpinCount
comctl32.dll TaskDialogIndirect
SetWindowSubclass
DefSubclassProc
RemoveWindowSubclass
user32.dll DrawTextW
GetWindowDC
GetCursorPos
OffsetRect
MonitorFromWindow
GetMenuBarInfo
DestroyMenu
TrackPopupMenu
PostQuitMessage
SetMenu
RemoveMenu
AppendMenuW
InsertMenuW
DrawIconEx
MonitorFromRect
GetMonitorInfoW
CheckMenuItem
GetSystemMetrics
SetMenuItemInfoW
CreateAcceleratorTableW
DestroyAcceleratorTable
DrawMenuBar
CreatePopupMenu
CreateMenu
GetMenuItemInfoW
CreateIcon
GetKeyboardLayout
FillRect
SystemParametersInfoW
ToUnicodeEx
SetWindowLongW
EnableMenuItem
GetSystemMenu
SendInput
SetForegroundWindow
GetMenu
ShowCursor
ClipCursor
GetClipCursor
IsWindowVisible
EnumDisplayMonitors
MonitorFromPoint
SetWindowTextW
GetWindowTextW
TranslateMessage
GetUpdateRect
PeekMessageW
DestroyIcon
SetWindowDisplayAffinity
MapVirtualKeyExW
GetKeyState
GetAsyncKeyState
GetKeyboardState
GetRawInputData
ClientToScreen
TrackMouseEvent
GetTouchInputInfo
SetPropW
ReleaseCapture
GetWindowTextLengthW
SetCapture
MsgWaitForMultipleObjectsEx
DispatchMessageW
CloseTouchInputHandle
LoadCursorW
PostThreadMessageW
RegisterRawInputDevices
SendMessageW
GetClientRect
RegisterWindowMessageA
GetWindow
SetParent
MapWindowPoints
SetFocus
ShowWindow
DestroyWindow
ReleaseDC
GetDC
IsProcessDPIAware
EnableWindow
IsWindowEnabled
GetWindowRect
SetWindowLongPtrW
GetParent
GetWindowLongPtrW
FindWindowExW
SetWindowRgn
RedrawWindow
VkKeyScanW
TranslateAcceleratorW
GetForegroundWindow
GetActiveWindow
UpdateWindow
InvalidateRect
SetCursorPos
SetCursor
FlashWindowEx
InvalidateRgn
GetWindowPlacement
SetWindowPlacement
ChangeDisplaySettingsExW
DefWindowProcW
MapVirtualKeyW
GetMessageW
ValidateRect
RegisterTouchWindow
IsWindow
AdjustWindowRectEx
IsIconic
AdjustWindowRect
EnumChildWindows
DispatchMessageA
GetMessageA
SetWindowPos
CreateWindowExW
RegisterClassExW
ScreenToClient
PostMessageW
SystemParametersInfoA
GetWindowLongW
ole32.dll RevokeDragDrop
RegisterDragDrop
CoInitializeEx
OleInitialize
CoCreateFreeThreadedMarshaler
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoTaskMemAlloc
gdi32.dll CombineRgn
DeleteDC
DeleteObject
CreateRectRgn
CreateSolidBrush
SetTextColor
SetBkMode
CreateDIBSection
BitBlt
GetDeviceCaps
SelectObject
CreateCompatibleDC
shlwapi.dll SHCreateMemStream
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WakeByAddressSingle
WaitOnAddress
dwmapi.dll DwmEnableBlurBehindWindow
DwmGetWindowAttribute
DwmSetWindowAttribute
shell32.dll SHGetKnownFolderPath
ShellExecuteW
DragQueryFileW
DragFinish
SHAppBarMessage
oleaut32.dll GetErrorInfo
SetErrorInfo
SysStringLen
SysFreeString
ADVAPI32.dll EventSetInformation
EventRegister
EventUnregister
EventWriteTransfer
api-ms-win-crt-math-l1-1-0.dll trunc
roundf
pow
round
__setusermatherr
floor
api-ms-win-crt-string-l1-1-0.dll wcsncmp
_wcsicmp
strcmp
strlen
wcscmp
wcslen
strcpy_s
api-ms-win-crt-convert-l1-1-0.dll _ultow_s
wcstol
_wtoi
api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_cexit
_get_initial_narrow_environment
_initialize_onexit_table
_initialize_narrow_environment
_register_onexit_function
_initterm
_configure_narrow_argv
_crt_atexit
_set_app_type
_initterm_e
exit
_exit
_register_thread_local_exe_atexit_callback
abort
__p___argc
__p___argv
_seh_filter_exe
terminate
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll calloc
_set_new_mode
_callnewh
free
malloc

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xbab
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74881
Detected Filetype PNG graphic file
MD5 540f8a2ab12d55a7fd2dc18100577f72 🔍
SHA1 fe802dd48036281e3d2202abfe0d1b2e6892171e 🔍
SHA256 5bdac14f559459fdd027670a368fb1f73d96145720322dc1639b314a709ab3c7 🔍
SHA3 258cd1dc89d725495a2b2f14c29fb85e2ed9d7a1e492b42e250ca61b0e8514b4 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3f1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.53017
Detected Filetype PNG graphic file
MD5 81c0c6b010965cbb1b21a1afd3b2881e 🔍
SHA1 9683a377ae6598ca5640595184d0608dd391045b 🔍
SHA256 88897e51e728d0c4bc6d8a7e96f06f84752789c4f138780c67db64dd5117477b 🔍
SHA3 7683dc8f50e9ab5d2e2abd2b7fa66eacae2fc3b0a5464c5adfe7f195a8c5700c 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x779
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.65945
Detected Filetype PNG graphic file
MD5 e98ac739a8c135c6d9179634d4f598a1 🔍
SHA1 9eef2d656cf11170de3180c88f882a46fadadd7e 🔍
SHA256 07d971fd98533bd94eaa61cc1387e9d58439bdcedcaf6f1b4e13cc3b48dea230 🔍
SHA3 85afe017581164a3718f619c2f1a0d06de9a7209b89b96198407ca2e383d142d 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x15fd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85432
Detected Filetype PNG graphic file
MD5 d9b4c8acc7a45c3a447e689025012549 🔍
SHA1 a29c3abfb467755e598dff4121fcc27d69e4e2d8 🔍
SHA256 5540e4ef7ded9b068a39153c053a1302bc5ede8fb3f44f8b70d84bf86ca4b6ee 🔍
SHA3 3fce677986a57b260d9d61acf2eea6073b7b97c4e9246cfedba3e770fc48c119 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x22c7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89156
Detected Filetype PNG graphic file
MD5 8911d3b689b7c3166365905304c07eac 🔍
SHA1 19844eecab6af9751eb85fabbcfb354985a21c3f 🔍
SHA256 60348b776b06c5b996b8151a21eb4a5900eb7419a6c631d32ed65fc03324a221 🔍
SHA3 68514a20a03d9b97ff8883b8dce1782e5f65554cb8851747e4db36858ce39471 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x173be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99451
Detected Filetype PNG graphic file
MD5 85ef99e8a9f52c3e150fdf15b1d084a4 🔍
SHA1 83ab48757552ecd0c04f7b0659a5be4b512e22d5 🔍
SHA256 e138aacfd0e012895c39b70d6a3013936e1a6d940090595256c73c33731663e3 🔍
SHA3 ed90de05ed8a0d415cbc2e92b160a923c9e0f1aab8d6a6791750f5186e2be2c6 🔍

32512

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87413
Detected Filetype Icon file
MD5 3a0c94027b206e9b0e5c8a34688b2a44 🔍
SHA1 c1eaec270ac46a9c0a47ddd20d92357e79664361 🔍
SHA256 ff0738856dc528da97757f30c72282f9f1936b1190390c180d0a525d40fa4b54 🔍
SHA3 77db050ee8f496e5a45ff38301423a73ef4bec1c15405ba0d23df8b8b3568d6b 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39358
MD5 10ccfc9ef093751b100338ac845e33c3 🔍
SHA1 870d58038db9d24194a6e23446d13710683234af 🔍
SHA256 3ac56e97f39694956592cc3c3562d7383630056a7207bc979e3fc429c750bcda 🔍
SHA3 8e921b39a99274473af479acde075dcbc5128e40eb695334260f6cebb2279403 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96056
MD5 01e4c8c046a47771f13cd120b53303e7 🔍
SHA1 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9 🔍
SHA256 b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8 🔍
SHA3 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.10.175.0
ProductVersion 0.10.175.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName FramePoison
FileDescription SeekAndPicture 2 — The Irony of Debt
FileVersion (#2) 0.10.175
LegalCopyright Copyright © 2026 FramePoison
ProductName SeekAndPicture 2 — The Irony of Debt
ProductVersion (#2) 0.10.175
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-29 23:03:55
Version 0.0
SizeofData 52
AddressOfRawData 0x6bc874
PointerToRawData 0x6bb474
Referenced File seekandpicture2_desktop.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-29 23:03:55
Version 0.0
SizeofData 20
AddressOfRawData 0x6bc8a8
PointerToRawData 0x6bb4a8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-29 23:03:55
Version 0.0
SizeofData 1048
AddressOfRawData 0x6bc8bc
PointerToRawData 0x6bb4bc

TLS Callbacks

StartAddressOfRawData 0x1406bcd20
EndAddressOfRawData 0x1406bcecc
AddressOfIndex 0x140826f90
AddressOfCallbacks 0x1405f8b30
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001405BB140

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140824a40

RICH Header

XOR Key 0xd1691521
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 14
ASM objects (35207) 9
C objects (35207) 13
C++ objects (35207) 47
Imports (33145) 3
Total imports 425
Unmarked objects (#2) 411
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.