f11120b0a7b7045305cfdf4ed29100db3d550934029d40fff0aeeb6642dea439

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-22 16:33:42
Detected languages English - United States
Debug artifacts C:\Users\Daniel\Desktop\loader\x64\Release\artSpoofer.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious PEiD Signature: UPolyX V0.1 -> Delikon
Suspicious Strings found in the binary may indicate undesirable behavior: Accesses the WMI:
  • ROOT\Microsoft
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • virus
Contains domain names:
  • 2010-aia.verisign.com
  • 2010-crl.verisign.com
  • Calligraphr.com
  • aia.verisign.com
  • aia.ws.symantec.com
  • crl.microsoft.com
  • crl.thawte.com
  • crl.verisign.com
  • crl.ws.symantec.com
  • csc3-2010-aia.verisign.com
  • csc3-2010-crl.verisign.com
  • github.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • http://crl.thawte.com
  • http://crl.thawte.com/ThawteTimestampingCA.crl0
  • http://crl.verisign.com
  • http://crl.verisign.com/pca3-g5.crl04
  • http://csc3-2010-aia.verisign.com
  • http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
  • http://csc3-2010-crl.verisign.com
  • http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
  • http://logo.verisign.com
  • http://logo.verisign.com/vslogo.gif04
  • http://ocsp.thawte.com0
  • http://ocsp.verisign.com0
  • http://ts-aia.ws.symantec.com
  • http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
  • http://ts-crl.ws.symantec.com
  • http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
  • http://ts-ocsp.ws.symantec.com07
  • https://github.com
  • https://indiantypefoundry.comNinad
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://www.lexend.comBonnie
  • https://www.verisign.com
  • https://www.verisign.com/cps0
  • https://www.verisign.com/rpa
  • https://www.verisign.com/rpa0
  • logo.verisign.com
  • microsoft.com
  • scripts.sil.org
  • symantec.com
  • thawte.com
  • ts-aia.ws.symantec.com
  • ts-crl.ws.symantec.com
  • verisign.com
  • ws.symantec.com
  • www.verisign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • CheckRemoteDebuggerPresent
  • FindWindowA
  • FindWindowW
  • NtQuerySystemInformation
Code injection capabilities:
  • VirtualAlloc
  • CreateRemoteThreadEx
  • WriteProcessMemory
  • OpenProcess
  • VirtualAllocEx
  • CreateRemoteThread
Code injection capabilities (PowerLoader):
  • FindWindowA
  • FindWindowW
  • GetWindowLongW
Code injection capabilities (mapping injection):
  • CreateRemoteThreadEx
  • CreateRemoteThread
  • CreateFileMappingA
  • MapViewOfFile
Can access the registry:
  • RegDeleteValueW
  • RegQueryValueExW
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
  • RegOpenKeyW
  • RegCreateKeyW
  • RegSetKeyValueW
  • RegOpenKeyExW
Possibly launches other programs:
  • ShellExecuteA
Uses Microsoft's cryptographic API:
  • CryptProtectData
  • CryptUnprotectData
  • CryptDestroyHash
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptHashData
  • CryptCreateHash
  • CryptAcquireContextA
Can create temporary files:
  • GetTempPathW
  • CreateFileA
  • CreateFileW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
  • VirtualProtectEx
  • VirtualAllocEx
Has Internet access capabilities:
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpConnect
  • WinHttpReadData
  • WinHttpGetDefaultProxyConfiguration
  • WinHttpGetIEProxyConfigForCurrentUser
  • WinHttpQueryDataAvailable
Leverages the raw socket API to access the Internet:
  • htons
  • setsockopt
  • WSAGetLastError
  • recv
  • htonl
  • connect
  • getsockopt
  • closesocket
  • shutdown
  • WSAStartup
  • inet_ntop
  • send
  • socket
Functions related to the privilege level:
  • OpenProcessToken
Interacts with services:
  • QueryServiceStatus
  • OpenSCManagerA
  • ControlService
  • OpenServiceA
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • WriteProcessMemory
  • OpenProcess
  • ReadProcessMemory
  • Process32NextW
  • Process32FirstW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 e09ce7a9a0f80bc9d5096bf7f8cbc281
SHA1 fa255431c660dcb956219976110a83348a4ac293
SHA256 f11120b0a7b7045305cfdf4ed29100db3d550934029d40fff0aeeb6642dea439
SHA3 27ff84a15e80c39ce0d875ddb41d32b59138939d8615dcfff9bfafc4910c73ce
SSDeep 49152:p7pKG401cZ0fY3dtS/SbGOmnMUMkT8+HEOT8+HEQT8+HEQT8+HEQT8+HEQT8+HE:L4rDjvbanR5f
Imports Hash 58701e4b54835ceeb9e71bb8f1296476

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-22 16:33:42
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xeb800
SizeOfInitializedData 0x47bc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000E8980 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x56b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2cb8c6854c85c4a35b0f23889bbe6345
SHA1 e3ef5b2592da5104901b31cc8293e3bf0e9ff7c2
SHA256 16e8837b04843a2bef10c65193b59424c9cf98c3d4af471b5dd3b3f1b2996cc5
SHA3 6e60572bc60787dcb0f3f68a30983847bd561f1e714a2c4ddc415f1426fb83cb
VirtualSize 0xeb761
VirtualAddress 0x1000
SizeOfRawData 0xeb800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55849

.rdata

MD5 afe2a8286d1d480c2a62ee715c6fa56d
SHA1 fd1feeb520a36d8ebddcc521164879228a43df29
SHA256 6afbf6d1ea11577bec65698d74418f145aa719f681972059d68b98d4d9279e9b
SHA3 cb8c9dd875e25117f3e1f91354f6884af4586e10ed33b7c2ee13b170a9ee4a21
VirtualSize 0x3e5560
VirtualAddress 0xed000
SizeOfRawData 0x3e5600
PointerToRawData 0xebc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.02009

.data

MD5 d086587d7a25cdbb7f5d29b7aa20a6ad
SHA1 a670aa3ad0c4a0ebb007c29e45963c4392cb7620
SHA256 87d709a128cfd4ea3b26e5b21665ae69c6e1da4ecdeec53ebca465ececc127d2
SHA3 13ec7a9c48b89c1d9fa6eee788e4b779457ee63c30a1f861e78eed424168e819
VirtualSize 0x8aa88
VirtualAddress 0x4d3000
SizeOfRawData 0x8a200
PointerToRawData 0x4d1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.28243

.pdata

MD5 c9ab2b89d22388080935347e7683b0c8
SHA1 3ecd7b4e57c534121a9cc2b6af00bb8346affb8f
SHA256 f561d5d29fde0afda570ee90f0842549656ebf0173fe47dd65a49fdf76d5d2e9
SHA3 1a97e05dc0d464c7c38e14bec7592b6c9c0d046e4c870cd220ab6eb481789004
VirtualSize 0xa65c
VirtualAddress 0x55e000
SizeOfRawData 0xa800
PointerToRawData 0x55b400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.08278

.rsrc

MD5 ebc4e7c701e32ac1423ffa0429c487cc
SHA1 e5469eaa5212bfa730a2a309f7d178c80f38f642
SHA256 137f93b0f9957b8bdcc83d608f59c50a73ce488207a5e3bb647b6bac7b4f1b76
SHA3 affd12c797a1c528c11f8981f5cb9bc931d4e5ad14c347fbd97e7ebfd40dfc8b
VirtualSize 0x1e8
VirtualAddress 0x569000
SizeOfRawData 0x200
PointerToRawData 0x565c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.76813

.reloc

MD5 a87a9282b865eeb7fb85b6d02c9d4151
SHA1 bce5247a7f29240ee7ce7558757a1286c9122945
SHA256 68dfac178d4cb76f39b01b6d23cc1ed3f6db3d466ddf4b1e6ced740771c46f46
SHA3 f53d931d00decba06b31b6f03d7f004dcb602c056214f3534859a471b43776a0
VirtualSize 0xe24
VirtualAddress 0x56a000
SizeOfRawData 0x1000
PointerToRawData 0x565e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.15359

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
ole32.dll CoInitializeSecurity
CoSetProxyBlanket
CoCreateInstance
CoUninitialize
CoTaskMemFree
CoInitializeEx
WINHTTP.dll WinHttpOpen
WinHttpOpenRequest
WinHttpCloseHandle
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpConnect
WinHttpReadData
WinHttpGetDefaultProxyConfiguration
WinHttpGetIEProxyConfigForCurrentUser
WinHttpQueryDataAvailable
CRYPT32.dll CryptProtectData
CryptUnprotectData
KERNEL32.dll CloseHandle
LocalFree
Sleep
VirtualFree
DeviceIoControl
VirtualAlloc
GetCurrentThreadId
GetModuleHandleA
GetCurrentProcessId
GetTempPathW
GetSystemFirmwareTable
GetEnvironmentVariableW
MultiByteToWideChar
GlobalFree
CreateRemoteThreadEx
WriteProcessMemory
VirtualProtect
GetCurrentProcess
TerminateProcess
GetProcessId
DuplicateHandle
OpenProcess
GetTickCount64
K32GetModuleFileNameExA
LoadLibraryA
CreateThread
VirtualProtectEx
VirtualAllocEx
ExitProcess
ReadProcessMemory
GetModuleHandleW
CreateRemoteThread
GetTickCount
OpenThread
IsDebuggerPresent
WideCharToMultiByte
GetFileAttributesExW
QueryDosDeviceW
GetLogicalDrives
WaitForSingleObject
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
QueryFullProcessImageNameW
QueryPerformanceCounter
GetDriveTypeW
GlobalAlloc
GlobalLock
GlobalUnlock
GetLocaleInfoA
DeleteFileW
GlobalMemoryStatusEx
InitOnceComplete
SleepConditionVariableSRW
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
CreateFileMappingA
UnmapViewOfFile
MapViewOfFile
HeapFree
HeapAlloc
CreateFileA
GetFileInformationByHandleEx
FormatMessageA
GetLocaleInfoEx
WakeAllConditionVariable
SetUnhandledExceptionFilter
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
GetLastError
CreateFileW
WriteFile
GetFileSizeEx
ReadFile
FreeLibrary
GetProcAddress
InitOnceBeginInitialize
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFinalPathNameByHandleW
SetFileInformationByHandle
CreateFile2
QueryPerformanceFrequency
CreateDirectoryW
CheckRemoteDebuggerPresent
USER32.dll GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
LoadCursorW
SetCapture
SetCursor
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetCursorPos
OpenClipboard
RegisterClassExW
EmptyClipboard
GetMessageExtraInfo
GetKeyState
ScreenToClient
ShowWindow
DispatchMessageW
GetSystemMetrics
SetWindowRgn
SetWindowPos
EnumDisplayDevicesA
UpdateWindow
FindWindowA
GetWindowTextLengthA
PostQuitMessage
GetClientRect
FindWindowW
TranslateMessage
SetLayeredWindowAttributes
EnumWindows
SetWindowsHookW
GetClipboardData
SetClipboardData
MessageBoxA
GetWindowLongW
DefWindowProcW
CloseClipboard
DestroyWindow
IsWindowVisible
MessageBoxW
SetWindowLongA
CreateWindowExW
PeekMessageW
GetWindowTextA
UnregisterClassW
GDI32.dll CreateRoundRectRgn
ADVAPI32.dll CryptDestroyHash
RegDeleteValueW
RegQueryValueExW
QueryServiceStatus
CloseServiceHandle
OpenSCManagerA
ControlService
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegDeleteTreeW
RegSetKeyValueW
CryptReleaseContext
CryptGetHashParam
RegOpenKeyExW
CryptHashData
CryptCreateHash
CryptAcquireContextA
GetTokenInformation
OpenServiceA
OpenProcessToken
SHELL32.dll SHGetKnownFolderPath
ShellExecuteA
OLEAUT32.dll SysFreeString
VariantClear
SysAllocString
VariantInit
MSVCP140.dll ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??7ios_base@std@@QEBA_NXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z
_Query_perf_frequency
_Cnd_do_broadcast_at_thread_exit
_Query_perf_counter
_Thrd_detach
?_Winerror_map@std@@YAHH@Z
?_Random_device@std@@YAIXZ
?_Syserror_map@std@@YAPEBDH@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Throw_Cpp_error@std@@YAXH@Z
_Mtx_lock
_Mtx_unlock
?uncaught_exceptions@std@@YAHXZ
?_Xout_of_range@std@@YAXPEBD@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?good@ios_base@std@@QEBA_NXZ
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Id_cnt@id@locale@std@@0HA
ntdll.dll NtQuerySystemInformation
RtlInitUnicodeString
WS2_32.dll htons
setsockopt
WSAGetLastError
recv
htonl
connect
getsockopt
closesocket
shutdown
WSAStartup
inet_ntop
send
socket
WINMM.dll mciSendStringW
IMM32.dll ImmSetCandidateWindow
ImmSetCompositionWindow
ImmReleaseContext
ImmGetContext
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll strchr
strrchr
longjmp
memcpy
memmove
memset
memchr
strstr
_CxxThrowException
__C_specific_handler
__current_exception
__current_exception_context
__intrinsic_setjmp
wcsstr
memcmp
__std_exception_copy
__std_exception_destroy
__std_terminate
api-ms-win-crt-heap-l1-1-0.dll malloc
realloc
_set_new_mode
_callnewh
free
api-ms-win-crt-stdio-l1-1-0.dll fflush
fputc
fclose
fgetc
__p__commode
_set_fmode
fwrite
fgetpos
__stdio_common_vsscanf
__stdio_common_vsprintf
_wfopen
__stdio_common_vfprintf
fseek
__acrt_iob_func
ftell
ungetc
__stdio_common_vswprintf_s
_get_stream_buffer_pointers
_fseeki64
fread
fsetpos
setvbuf
api-ms-win-crt-utility-l1-1-0.dll qsort
rand
srand
api-ms-win-crt-filesystem-l1-1-0.dll _wremove
_lock_file
_unlock_file
api-ms-win-crt-string-l1-1-0.dll strncmp
strcmp
strncpy
_wcsnicmp
strncpy_s
_wcsicmp
towlower
isspace
isalnum
tolower
_stricmp
strlen
wcslen
api-ms-win-crt-time-l1-1-0.dll _time64
api-ms-win-crt-runtime-l1-1-0.dll _set_app_type
_cexit
_get_narrow_winmain_command_line
_initterm
_initterm_e
_exit
_crt_atexit
_c_exit
_register_thread_local_exe_atexit_callback
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
exit
_beginthreadex
_seh_filter_exe
terminate
abort
api-ms-win-crt-environment-l1-1-0.dll _dupenv_s
api-ms-win-crt-convert-l1-1-0.dll strtol
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll cosf
fmodf
sinf
ceilf
acosf
floorf
sqrtf
__setusermatherr

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-22 16:33:42
Version 0.0
SizeofData 82
AddressOfRawData 0x4bdb68
PointerToRawData 0x4bc768
Referenced File C:\Users\Daniel\Desktop\loader\x64\Release\artSpoofer.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-22 16:33:42
Version 0.0
SizeofData 20
AddressOfRawData 0x4bdbbc
PointerToRawData 0x4bc7bc

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-22 16:33:42
Version 0.0
SizeofData 912
AddressOfRawData 0x4bdbd0
PointerToRawData 0x4bc7d0

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-22 16:33:42
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1404bdf80
EndAddressOfRawData 0x1404bdf88
AddressOfIndex 0x14055d100
AddressOfCallbacks 0x1400ede80
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1404d3040

RICH Header

XOR Key 0x95e9328b
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
C objects (35222) 1
253 (35721) 1
C objects (35721) 10
C++ objects (35721) 44
ASM objects (35721) 6
Imports (35721) 6
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
C++ objects (35222) 1
Imports (35222) 35
Total imports 440
C++ objects (LTCG) (36248) 32
Resource objects (36248) 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.