e29edc164645680c31d59a13679b76f48fb3685199eb9ff0d72648f105770bb8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-15 21:31:20
Detected languages English - United States
Debug artifacts c:\Users\sgzir\OneDrive\Documents\fortnaight\Fortnite Public - main (FN EXTERNAL)\thunderpublic\build\Fortnite External.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • 2-aia.verisign.com
  • 2-crl.verisign.com
  • 2009-2-aia.verisign.com
  • 2009-2-crl.verisign.com
  • aia.verisign.com
  • aia.ws.symantec.com
  • crl.microsoft.com
  • crl.thawte.com
  • crl.verisign.com
  • crl.ws.symantec.com
  • csc3-2009-2-aia.verisign.com
  • csc3-2009-2-crl.verisign.com
  • fontello.com
  • github.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://crl.verisign.com
  • http://crl.verisign.com/pca3.crl0
  • http://csc3-2009-2-aia.verisign.com
  • http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
  • http://csc3-2009-2-crl.verisign.com
  • http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
  • http://fontello.com
  • http://logo.verisign.com
  • http://logo.verisign.com/vslogo.gif0
  • http://ocsp.thawte.com0
  • http://ocsp.verisign.com0
  • http://ocsp.verisign.com01
  • http://ocsp.verisign.com0?
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • https://curl.se
  • https://github.com
  • https://keyauth.win
  • https://www.verisign.com
  • https://www.verisign.com/cps0
  • https://www.verisign.com/rpa
  • https://www.verisign.com/rpa0
  • logo.verisign.com
  • microsoft.com
  • symantec.com
  • thawte.com
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • verisign.com
  • ws.symantec.com
  • www.verisign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • NtQuerySystemInformation
  • CheckRemoteDebuggerPresent
  • CreateToolhelp32Snapshot
Can access the registry:
  • SHDeleteKeyW
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Windows's Native API:
  • NtLoadDriver
  • NtDeviceIoControlFile
  • NtUnloadDriver
  • NtQuerySystemInformation
  • NtCreateFile
  • NtClose
  • ntohs
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptGetHashParam
  • CryptReleaseContext
  • CryptEncrypt
  • CryptImportKey
  • CryptDestroyKey
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptStringToBinaryW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
  • OpenProcess
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertOpenStore
  • CertAddCertificateContextToStore
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 f9da188f8512585bdb182ef3d120c9b4 🔍
SHA1 9685392bf1472e780f16abc42fe94148fbf82ea9 🔍
SHA256 e29edc164645680c31d59a13679b76f48fb3685199eb9ff0d72648f105770bb8 🔍
SHA3 e981a214d3ab78bf305ca71e197661d305314a60d3e90dbca29846584a3f2f23 🔍
SSDeep 49152:OwDjOGGyIrPs7+pvclr4dYmsU8tSKsZ5UEvJ5ossgc1sB92UXy:BjOGGhs3ptSKsZ5UEvJ5os1B 🔍
Imports Hash 5799230bb8593bc6359d5d174f91e7c1 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x128

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-15 21:31:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x211400
SizeOfInitializedData 0xaf800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000020F360 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2c4000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2a56a600e1f9d987c96394af5ed162ea 🔍
SHA1 4ef91d638458054ac03859f07de0589668ecfb15 🔍
SHA256 5801aa00ec057db804a9d84869324c186921d36a6d152a75e9b17a3ddbf98ddf 🔍
SHA3 542e6ff8a8fe7d65b1ad7898561af943899db771ad0a4538bd1fb616f01d660f 🔍
VirtualSize 0x211350
VirtualAddress 0x1000
SizeOfRawData 0x211400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.02821

.rdata

MD5 72af6d07d565031dba162847ab567ab1 🔍
SHA1 d614978a5950f4b5391cb4e4f1ba8ae371da91f4 🔍
SHA256 b6d8a08150d0feae1aa55f9cf9e30d5a208226681058c1e89f802e099c9e64ab 🔍
SHA3 c9ef4ade38c7246a63506a3690e331bc68085548bd81f5e42ef7926ce9cf7e3f 🔍
VirtualSize 0x3fc16
VirtualAddress 0x213000
SizeOfRawData 0x3fe00
PointerToRawData 0x211800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.36215

.data

MD5 bf1214c5270f08a7595b5d92156d571a 🔍
SHA1 a66c144c8703c77ff9909dc4b85f91184a80ff38 🔍
SHA256 879c91102ff6430e09d41d7342fc4c6b12e64dfd2dd6a5145a3238cb736e41a0 🔍
SHA3 ad951a2a1b708fb9d1d69d272463299e5fcfa9700e6095c03502325568956f60 🔍
VirtualSize 0x63ee0
VirtualAddress 0x253000
SizeOfRawData 0x61e00
PointerToRawData 0x251600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.79494

.pdata

MD5 ba943f6c805c5890551400f6c0f4f65b 🔍
SHA1 07d5973b17c60cb0efd104e241764ce01dd3be42 🔍
SHA256 ac273c5634cf117c448e1285bb6b5b85111b68b4911b02c46d76e54574ca33d7 🔍
SHA3 005d2f2c0d075a5e28736a41de06ffb708e8dbd0b76d4c3bf86ec6a4aa3dd050 🔍
VirtualSize 0xa9f8
VirtualAddress 0x2b7000
SizeOfRawData 0xaa00
PointerToRawData 0x2b3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.10261

.rsrc

MD5 8a745227f98eb0c8c47ed2310d37a498 🔍
SHA1 592af9c77ddea5b4051b7599d3eaf058ed7495e0 🔍
SHA256 23e4d2cfea3ef005eb148214b4e655f8b8807881aabc3e8c55297ccdef5ecb9d 🔍
SHA3 ed81b635ab7637bb6065e4b38819f4f348de3d235d9e5082a3fe9a763057055a 🔍
VirtualSize 0x1e8
VirtualAddress 0x2c2000
SizeOfRawData 0x200
PointerToRawData 0x2bde00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.75872

.reloc

MD5 ece9021594185946479cc2c908264436 🔍
SHA1 9c2a92309f578aef78838a057f6174af97f4a012 🔍
SHA256 e316b9f07bb5c38d4eaaa84d25e8c2f1c94e8e10996e2e541e3e9012b2e0afc8 🔍
SHA3 c5fdc9935c24eae87d940378735c026cfc32d17b4bcc6535529db17dc25cd413 🔍
VirtualSize 0xdd4
VirtualAddress 0x2c3000
SizeOfRawData 0xe00
PointerToRawData 0x2be000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40883

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
ntdll.dll NtLoadDriver
RtlAdjustPrivilege
NtDeviceIoControlFile
RtlGetFullPathName_UEx
RtlInitUnicodeString
RtlCreateRegistryKey
NtUnloadDriver
NtQuerySystemInformation
RtlWriteRegistryValue
NtCreateFile
NtClose
VerSetConditionMask
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
ADVAPI32.dll CryptAcquireContextW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptReleaseContext
CryptEncrypt
CryptImportKey
CryptDestroyKey
SystemFunction036
MSVCP140.dll ?_Xbad_alloc@std@@YAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
?uncaught_exceptions@std@@YAHXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??Bios_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
_Mtx_unlock
_Xtime_get_ticks
_Thrd_detach
_Query_perf_counter
_Cnd_do_broadcast_at_thread_exit
_Mtx_lock
?_Random_device@std@@YAIXZ
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Throw_Cpp_error@std@@YAXH@Z
_Query_perf_frequency
?good@ios_base@std@@QEBA_NXZ
?_Xlength_error@std@@YAXPEBD@Z
USER32.dll GetCursorPos
OpenClipboard
CloseClipboard
SetCursorPos
EmptyClipboard
SetCursor
LoadCursorW
GetForegroundWindow
GetKeyboardLayout
ClientToScreen
GetClipboardData
ScreenToClient
SetClipboardData
GetClientRect
GetSystemMetrics
GetKeyState
UpdateWindow
TranslateMessage
SetLayeredWindowAttributes
EnumWindows
BlockInput
PeekMessageW
FindWindowExA
DispatchMessageW
GetAsyncKeyState
ShowWindow
MessageBoxW
DestroyWindow
GetWindowThreadProcessId
KERNEL32.dll OutputDebugStringW
InitializeSListHead
GetSystemTimeAsFileTime
SetUnhandledExceptionFilter
WakeAllConditionVariable
GetCurrentThreadId
SleepConditionVariableSRW
AcquireSRWLockShared
ReleaseSRWLockShared
GetFileSizeEx
VerifyVersionInfoW
GetCurrentProcessId
WaitForMultipleObjects
PeekNamedPipe
ReadFile
GetFileType
GetEnvironmentVariableA
WaitForSingleObjectEx
MoveFileExW
GetTickCount
SleepEx
LoadLibraryW
GetSystemDirectoryW
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
FormatMessageW
GetModuleHandleW
DeleteCriticalSection
InitializeCriticalSectionEx
CheckRemoteDebuggerPresent
IsDebuggerPresent
SetConsoleOutputCP
SetConsoleCP
ExitProcess
CreateThread
RaiseException
CloseHandle
Process32FirstW
CreateFileA
Process32NextW
GetLastError
K32GetModuleFileNameExA
CreateToolhelp32Snapshot
OpenProcess
CreateFileW
TerminateProcess
WriteFile
GetStdHandle
SetConsoleTextAttribute
SetLastError
QueryPerformanceCounter
FreeLibrary
QueryPerformanceFrequency
LoadLibraryA
GetLocaleInfoA
GetModuleHandleA
GlobalUnlock
WideCharToMultiByte
GlobalLock
GlobalFree
GlobalAlloc
MultiByteToWideChar
LoadLibraryExW
GetProcAddress
K32GetModuleInformation
Sleep
VirtualAlloc
GetCurrentProcess
VirtualFree
SHELL32.dll ShellExecuteA
IMM32.dll ImmSetCandidateWindow
ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
D3DCOMPILER_43.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
SHLWAPI.dll SHDeleteKeyW
CRYPT32.dll CertOpenStore
PFXImportCertStore
CertCloseStore
CertEnumCertificatesInStore
CertFindCertificateInStore
CertFreeCertificateContext
CryptDecodeObjectEx
CertFreeCertificateChain
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
CertGetNameStringW
CertFindExtension
CertAddCertificateContextToStore
CryptStringToBinaryW
WS2_32.dll __WSAFDIsSet
select
accept
htonl
listen
getaddrinfo
recv
recvfrom
sendto
ioctlsocket
socket
WSAIoctl
WSACloseEvent
send
htons
getsockname
getpeername
connect
bind
getsockopt
gethostname
inet_ntop
WSASetLastError
ntohs
inet_pton
setsockopt
WSAGetLastError
closesocket
WSAEventSelect
WSAEnumNetworkEvents
freeaddrinfo
WSACreateEvent
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __C_specific_handler
strchr
strstr
__std_exception_copy
__std_exception_destroy
memcmp
memcpy
__std_terminate
memchr
memmove
memset
strrchr
wcschr
__current_exception
__current_exception_context
_CxxThrowException
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
realloc
malloc
calloc
free
api-ms-win-crt-math-l1-1-0.dll ceilf
_fdopen
pow
tanf
cosf
fmodf
powf
__setusermatherr
sqrtf
atan2f
roundf
atan2
asin
acosf
sinf
ldexp
sqrt
acos
api-ms-win-crt-string-l1-1-0.dll strlen
wcsncpy
strpbrk
_strdup
wcsncmp
strcspn
strcmp
strspn
_stricmp
wcscat_s
wcscpy_s
strncpy
wcspbrk
strncmp
wcslen
_wcsicmp
api-ms-win-crt-stdio-l1-1-0.dll fputs
__acrt_iob_func
__stdio_common_vfprintf
_close
_fileno
_wopen
ftell
fflush
_write
_read
__p__commode
_lseeki64
fclose
fseek
fgets
fwrite
feof
_fseeki64
_wfopen
fputc
__stdio_common_vsscanf
_set_fmode
fread
__stdio_common_vsprintf
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-convert-l1-1-0.dll strtoul
strtol
wcstombs
strtoll
atoi
atof
api-ms-win-crt-time-l1-1-0.dll _localtime64_s
_gmtime64
strftime
_time64
api-ms-win-crt-filesystem-l1-1-0.dll _wstat64
remove
_fstat64
_unlink
api-ms-win-crt-runtime-l1-1-0.dll _initialize_onexit_table
_crt_atexit
_initialize_narrow_environment
_invalid_parameter_noinfo_noreturn
_configure_narrow_argv
_errno
_cexit
exit
_seh_filter_exe
_set_app_type
_register_thread_local_exe_atexit_callback
terminate
_register_onexit_function
__p___argc
system
_get_initial_narrow_environment
_beginthreadex
_initterm
__sys_errlist
__sys_nerr
_initterm_e
_c_exit
abort
_exit
__p___argv
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-15 21:31:20
Version 0.0
SizeofData 148
AddressOfRawData 0x23fa88
PointerToRawData 0x23e288
Referenced File c:\Users\sgzir\OneDrive\Documents\fortnaight\Fortnite Public - main (FN EXTERNAL)\thunderpublic\build\Fortnite External.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-15 21:31:20
Version 0.0
SizeofData 20
AddressOfRawData 0x23fb1c
PointerToRawData 0x23e31c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-15 21:31:20
Version 0.0
SizeofData 912
AddressOfRawData 0x23fb30
PointerToRawData 0x23e330

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-15 21:31:20
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14023fee0
EndAddressOfRawData 0x14023ff10
AddressOfIndex 0x1402b4fa8
AddressOfCallbacks 0x140213dd0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140253f40

RICH Header

XOR Key 0xce5159a7
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
253 (35721) 7
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 39
Imports (35721) 6
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 129
C++ objects (34436) 5
Imports (33145) 30
Imports (21202) 7
Total imports 567
C++ objects (LTCG) (36256) 34
ASM objects (36256) 1
Resource objects (36256) 1
Linker (36256) 1

Errors

Leave a comment

No comments yet.