| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Dec-06 19:46:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\bhaie\Documents\ABI ANITCHEAT DCO\x64\Release\ABI ANITCHEAT DCO.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-04-19 23:36:21) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Dec-06 19:46:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8400 |
| SizeOfInitializedData | 0x8400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000084A0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetConsoleMode
GetProcessId K32GetModuleFileNameExW Thread32Next Thread32First DuplicateHandle OpenProcess CreateToolhelp32Snapshot Sleep GetConsoleMode GetLastError Process32NextW K32GetModuleBaseNameW Process32FirstW CloseHandle GetStdHandle Beep GetProcAddress GetCurrentProcessId GetModuleHandleW GetConsoleWindow Module32NextW SetConsoleCursorPosition OpenThread SetUnhandledExceptionFilter InitializeSListHead GetSystemTimeAsFileTime QueryPerformanceCounter GetCurrentThreadId GetCurrentProcess SetConsoleTitleA SetConsoleTextAttribute Module32FirstW GetConsoleScreenBufferInfo |
|---|---|
| USER32.dll |
DeleteMenu
GetWindowLongW EnumWindows PostMessageW GetWindowThreadProcessId GetSystemMenu |
| ADVAPI32.dll |
AdjustTokenPrivileges
OpenProcessToken GetTokenInformation LookupPrivilegeValueW |
| MSVCP140.dll |
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?_Xbad_alloc@std@@YAXXZ ?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?_Id_cnt@id@locale@std@@0HA ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?wcerr@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A ?_Random_device@std@@YAIXZ ?_Xlength_error@std@@YAXPEBD@Z ?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z _Cnd_do_broadcast_at_thread_exit _Thrd_id _Query_perf_counter _Thrd_join ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?uncaught_exceptions@std@@YAHXZ ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z ?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@PEBX@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?good@ios_base@std@@QEBA_NXZ ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A ?_Throw_Cpp_error@std@@YAXH@Z ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ _Query_perf_frequency ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A |
| WINTRUST.dll |
WinVerifyTrust
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception_context
__std_exception_destroy __current_exception memset _CxxThrowException __C_specific_handler __std_terminate memmove memcpy memcmp __std_exception_copy |
| api-ms-win-crt-heap-l1-1-0.dll |
free
malloc realloc _set_new_mode _callnewh |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
strftime _localtime64_s |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argv
__p___argc _c_exit _register_thread_local_exe_atexit_callback _beginthreadex _exit exit _initialize_onexit_table _register_onexit_function _crt_atexit _initterm_e _initterm _get_initial_narrow_environment _configure_narrow_argv _set_app_type _seh_filter_exe system _cexit terminate _initialize_narrow_environment |
| api-ms-win-crt-conio-l1-1-0.dll |
_getch
|
| api-ms-win-crt-string-l1-1-0.dll |
tolower
strlen wcslen |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode __stdio_common_vsprintf |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 19:46:02 |
| Version | 0.0 |
| SizeofData | 101 |
| AddressOfRawData | 0xe774 |
| PointerToRawData | 0xcf74 |
| Referenced File | C:\Users\bhaie\Documents\ABI ANITCHEAT DCO\x64\Release\ABI ANITCHEAT DCO.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 19:46:02 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xe7dc |
| PointerToRawData | 0xcfdc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 19:46:02 |
| Version | 0.0 |
| SizeofData | 780 |
| AddressOfRawData | 0xe7f0 |
| PointerToRawData | 0xcff0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-06 19:46:02 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140012040 |
| XOR Key | 0x9c9333a0 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| ASM objects (35403) | 4 |
| C objects (35403) | 10 |
| C++ objects (35403) | 30 |
| Imports (35403) | 6 |
| Imports (33145) | 9 |
| Total imports | 203 |
| C++ objects (LTCG) (35719) | 1 |
| Resource objects (35719) | 1 |
| Linker (35719) | 1 |
No comments yet.