| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-16 14:39:29 |
| Detected languages |
English - United States
|
| CompanyName | Original Experimental Division |
| FileDescription | HD2 Cheat Menu Injector |
| FileVersion | 1.0.0.2 |
| InternalName | HD2CheatMenuInjector |
| LegalCopyright | Zodiac |
| OriginalFilename | HD2CheatMenuInjector.exe |
| ProductName | HD2 Cheat Menu Injector |
| ProductVersion | 1.0.0.2 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 7/72 (Scanned on 2026-03-22 22:18:21) |
APEX:
Malicious
Bkav: W64.AIDetectMalware DeepInstinct: MALICIOUS Elastic: malicious (moderate confidence) Malwarebytes: Malware.Heuristic.2518 Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Mar-16 14:39:29 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2d600 |
| SizeOfInitializedData | 0x3d600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000001642C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x70000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetConsoleWindowInfo
SetConsoleScreenBufferSize Sleep CloseHandle GetCurrentProcess GetModuleFileNameW GetLastError CreateToolhelp32Snapshot Process32FirstW Process32NextW GetProcAddress GetModuleHandleW OpenProcess TerminateProcess VirtualAllocEx GetCurrentConsoleFontEx CreateRemoteThread WaitForSingleObject GetExitCodeThread VirtualFreeEx SetConsoleCP SetConsoleOutputCP SetConsoleTitleW WriteConsoleW CreateFileW HeapSize FlushFileBuffers SetStdHandle GetConsoleWindow GetStdHandle SetConsoleTextAttribute WriteProcessMemory MultiByteToWideChar GetProcessHeap SetEnvironmentVariableW FreeEnvironmentStringsW FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW CreateFile2 AreFileApisANSI GetFileInformationByHandleEx WideCharToMultiByte FormatMessageA LocalFree GetLocaleInfoEx EncodePointer DecodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection GetStringTypeW GetCPInfo ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlLookupFunctionEntry RtlUnwindEx RtlPcToFileHeader RaiseException SetLastError FlsAlloc FlsGetValue FlsSetValue FlsFree ExitProcess FreeLibrary GetModuleHandleExW IsProcessorFeaturePresent WriteFile GetCommandLineA GetCommandLineW RtlCaptureContext RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter HeapAlloc HeapFree VirtualProtect LoadLibraryExW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx HeapReAlloc IsValidCodePage GetACP GetOEMCP GetEnvironmentStringsW |
|---|---|
| USER32.dll |
SetWindowLongW
GetDesktopWindow GetClientRect GetWindowRect SetWindowPos GetWindowLongW |
| ADVAPI32.dll |
LookupPrivilegeValueW
GetTokenInformation OpenProcessToken AdjustTokenPrivileges |
| SHELL32.dll |
ShellExecuteW
ShellExecuteExW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.2 |
| ProductVersion | 1.0.0.2 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| CompanyName | Original Experimental Division |
| FileDescription | HD2 Cheat Menu Injector |
| FileVersion (#2) | 1.0.0.2 |
| InternalName | HD2CheatMenuInjector |
| LegalCopyright | Zodiac |
| OriginalFilename | HD2CheatMenuInjector.exe |
| ProductName | HD2 Cheat Menu Injector |
| ProductVersion (#2) | 1.0.0.2 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-16 14:39:29 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0x5e828 |
| PointerToRawData | 0x5d228 |
| StartAddressOfRawData | 0x14005ec90 |
|---|---|
| EndAddressOfRawData | 0x14005ec98 |
| AddressOfIndex | 0x1400645f4 |
| AddressOfCallbacks | 0x14002f4b0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140063040 |
| XOR Key | 0x99ad2d6 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 158 |
| C objects (33145) | 18 |
| ASM objects (33145) | 7 |
| ASM objects (35403) | 10 |
| C objects (35403) | 16 |
| C++ objects (35403) | 81 |
| Imports (33145) | 9 |
| Total imports | 150 |
| C++ objects (LTCG) (35726) | 2 |
| Resource objects (35726) | 1 |
| 151 | 1 |
| Linker (35726) | 1 |
No comments yet.