4ccfed7eacfa610f81038b1074048028425c885d6c477e54a50fba9f721b42a1

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Feb-16 15:26:55
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
FileVersion 0.6.6.0
ProductVersion 0.6.6.0
CompanyName Leo Peyre-Costa
ProductName Castle Mania Demo Alpha Playtest
FileDescription Castle Mania - Build playtest interne
LegalCopyright 2026 Leo Peyre-Costa

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .xdata
Info The PE contains common functions which appear in legitimate applications. Possibly launches other programs:
  • CreateProcessW
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 825ece584bc35f12fe8a56c5558317ba
SHA1 8fca346e962216c8f5f309901ac87387b1085219
SHA256 4ccfed7eacfa610f81038b1074048028425c885d6c477e54a50fba9f721b42a1
SHA3 50e4472e1e0efcba77150c2ba3ea400105cd79838191287c33982322ed9e02b2
SSDeep 1536:ybJnGpKPvUBQ7CrnXG2zjMNqrnbgdMiBfu6YazDmi0j3LYABEQss:ybJnG0PfUG2nM0rncpFu6JFEEQ
Imports Hash 31a86b0315f954965c026f3f94dcdf07

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2026-Feb-16 15:26:55
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x7c00
SizeOfInitializedData 0x12400
SizeOfUninitializedData 0xc00
AddressOfEntryPoint 0x0000000000001400 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x21000
SizeOfHeaders 0x400
Checksum 0x31e01
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x800000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 15ae774cd8c2d46ef651129fc329e537
SHA1 4deeeb31d13260284d227f954249363a49be7b79
SHA256 918ff676928e72a6f7af858d5e1ed3d1359b9dda835a1aae2ec0ddd38227d8a1
SHA3 1244a05320103a39829d710fd3a57f3688f5e480867151f2964d878e3ccf72f2
VirtualSize 0x7b90
VirtualAddress 0x1000
SizeOfRawData 0x7c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.22048

.data

MD5 63a476ce529a4b27b64cd87d4b8fe3ab
SHA1 9277f2f52a78de8ddfab6c8e07d9f455137b9ec5
SHA256 d84ea3ee0aa1e1acaf9817750ae21ecb0f150bcfc2d52ac76b25ce814fff1a82
SHA3 b33e782a1b9ae42d31297c35a85ca0fa11c23df3cd9efcbe428550e87d743368
VirtualSize 0x100
VirtualAddress 0x9000
SizeOfRawData 0x200
PointerToRawData 0x8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.08083

.rdata

MD5 0e8f91eaf6f33779cdf7b08b070791fd
SHA1 df8a093316de284d7886fc4965bb4f03034fc67a
SHA256 70d3abf9a5fbf0d04610cc5ca098f85b2002588e111c0a89a6a7d80c56001768
SHA3 8e577838ec632c4c947c15e77020fe76ae12cf24ef12b0ac7a21649bc01104db
VirtualSize 0x1848
VirtualAddress 0xa000
SizeOfRawData 0x1a00
PointerToRawData 0x8200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.6439

.pdata

MD5 86a1c9bd409e9bbca35e2df7b22153c8
SHA1 6baf8694acd6dfff648ad5a72e814a8616296376
SHA256 7302b9d0b2a98f2691a402dbd6d6b1602f17ad53d97ed047d87629d3a895564b
SHA3 fda4f3f159b0eabddd043ddec090f555eed626ab94072b68aa9b83dca291f06e
VirtualSize 0x450
VirtualAddress 0xc000
SizeOfRawData 0x600
PointerToRawData 0x9c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.23049

.xdata

MD5 2cc4b2d769b91f3bcf7667e5ccba864e
SHA1 62ade50cce603317ecc8f68fe707b57d994609b1
SHA256 98eb57ca8967e22e8498fd7aff1c8f396870b2453af1d08e721cfb78fe992088
SHA3 88d2b0280a2327ce861eac81858b2d4f594ca9d1a09f8f49345f40eb25132ee9
VirtualSize 0x3e8
VirtualAddress 0xd000
SizeOfRawData 0x400
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.14595

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xb80
VirtualAddress 0xe000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 5911da6f1409975870ac6b0040bdf347
SHA1 4908dcfe3f820f9f9bf2b43d1b28874468d9e1ca
SHA256 c60586a0ca8e590d43564de2249ee00d93782726c8f221bbb0545e9ebcc008a8
SHA3 944990a295599284a97e8ae7dd0968b26973d066ba0ccc1b47fcc9fbfdffa1d5
VirtualSize 0xaa8
VirtualAddress 0xf000
SizeOfRawData 0xc00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.7621

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x10000
SizeOfRawData 0x200
PointerToRawData 0xb200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 871b133ae81cac5e1b70c31762a35692
SHA1 dfbc17107ace283a98922d691973e6f5c1020444
SHA256 0bd3c9a9ac4acd2c3a818abc76000df6e2cbc5eed78de3aa15f5653891b08c88
SHA3 3540a6516724500e5a8e70a8aa14c34ddc12cb6e03796de5111c1eceb791f53d
VirtualSize 0xede4
VirtualAddress 0x11000
SizeOfRawData 0xee00
PointerToRawData 0xb400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.95445

.reloc

MD5 347dc17e4ba1de2b5ed154cecd744925
SHA1 b831296637fc68eb924dac1788a71e77c39c9ae6
SHA256 f29a6e67f8097d75f06aee571bacde0ecbf25b3fb5c49ae54433d6143cbe6f6d
SHA3 699c92385accd29e47f4ed7f87ab5757f82d4e70aa989a5064d03feadabc2399
VirtualSize 0x84
VirtualAddress 0x20000
SizeOfRawData 0x200
PointerToRawData 0x1a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.63621

Imports

KERNEL32.dll AssignProcessToJobObject
CloseHandle
CreateIoCompletionPort
CreateJobObjectW
CreateProcessW
DeleteCriticalSection
EnterCriticalSection
GetCommandLineW
GetConsoleMode
GetExitCodeProcess
GetFileAttributesW
GetLastError
GetModuleFileNameW
GetQueuedCompletionStatus
GetStdHandle
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
MultiByteToWideChar
ResumeThread
SetConsoleMode
SetConsoleTitleW
SetInformationJobObject
SetUnhandledExceptionFilter
Sleep
TlsGetValue
VirtualProtect
VirtualQuery
__C_specific_handler
msvcrt.dll ___lc_codepage_func
___mb_cur_max_func
__getmainargs
__initenv
__iob_func
fwprintf
__set_app_type
__setusermatherr
_amsg_exit
_cexit
_commode
_errno
_fmode
_initterm
_lock
_snwprintf_s
_unlock
abort
atexit
calloc
exit
fprintf
fputwc
free
localeconv
malloc
memcpy
memset
signal
strerror
strlen
strncmp
vfprintf
wcslen
SHELL32.dll StrRStrIW
SHLWAPI.dll PathGetArgsW
VERSION.dll GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.50992
Detected Filetype PNG graphic file
MD5 78d1c71abce7200afd52a50d985b374e
SHA1 ed1fc95575d706123c1711da89b334a5cdd467a6
SHA256 1b710c729eee928047f3562b7432ca9054b409033936f84f244a096ebdaa6a68
SHA3 8de6597437916dcec3e846df2d29378b875883234f2eec430da0c71d75191ccd

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5dd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.82853
Detected Filetype PNG graphic file
MD5 eb94c8013252a4c2da9885991d276324
SHA1 d15a424a17d9b5ab5d2096cf9d6a0b4d3517216a
SHA256 2103f006e98d9e598cf2423a94195c258ad067a27e0ff9875eecdb24c6ed3317
SHA3 16a87634fd66c9e0aadd7bf6e52ffb1fd7c13a0b5640b33486c7bd9be3e8f3b9

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xad8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91236
Detected Filetype PNG graphic file
MD5 a876fa3f6a2349de6a2cae7bea5d4866
SHA1 cf451e8dcca4a600cd6e16545068c8b0e414674e
SHA256 7e27e47567010e9ee5a5980681bf8a2c687ebfb47ba56316b88fb93bdd08f703
SHA3 0c4a71b1d309e490f965c0e2510a475e635bfe1dcae5a8695ef4064cffc9b7e7

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10b9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94041
Detected Filetype PNG graphic file
MD5 0ca39cd4da98a52dd33f4e749d4d27b3
SHA1 df7a198b09689a3fff4a87451b2fbcc5b6030fe4
SHA256 b15bfc112e26eb202880ad44b96d23df8d0ba207aa2deab153cc463f3112dbab
SHA3 2c022bfe18bbe71ae782587f59883758256121a067476f3a8020fe4e7a027325

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1adc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94653
Detected Filetype PNG graphic file
MD5 56de2b19113ffabaf7122df54481fbed
SHA1 23a6340bc6c78818fc31fbd4613bb39db7c72157
SHA256 ae87afccbc1e2d9fa995d6e5cfd3329f70c281314315b78a46aef59f771ed3c5
SHA3 1d15c8318af67703f5976baa0628cc0b83bcf387ae5acd11ce10561056d87478

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa7ca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98316
Detected Filetype PNG graphic file
MD5 8439692b68070d3594568f290bf42a40
SHA1 2d2c3e2605f7ddf92976d8969ee2eb649b42f65d
SHA256 f9350438fc6a8bde104a3633213164b99dc336785dcb4e98b6ba342d927aee4e
SHA3 e014d5076f63fde9e023d781755c3c4af274e4d9a9b4e88619ad008817b07a89

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3328
MD5 255649c0ab337594f0dd4b1b02c17493
SHA1 1936b3260105f5d2d655638529c96a17982af347
SHA256 86c10fc98b458683904d6c6bdd246000b8a298d47e85642366911c6b2f76b72f
SHA3 8a09de3ddd4e76beec7c0c1d5bbe3eba64c1c3f67e68a76bc9a0f367bdc30672

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.23802
MD5 c2a4ebfcf1b81b3adbf9313280889552
SHA1 70e5734a23a38fb0645438a701ba99fd1b1aef7c
SHA256 d2b9e890a61ceb226405957f7a9b123ea14e9341b6811427fb05149e8bd34752
SHA3 b45ed300382cdc7466df39911c2b631f92f4dce1bb4a3bba9d81368a6573a5a5

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.6.6.0
ProductVersion 0.6.6.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileVersion (#2) 0.6.6.0
ProductVersion (#2) 0.6.6.0
CompanyName Leo Peyre-Costa
ProductName Castle Mania Demo Alpha Playtest
FileDescription Castle Mania - Build playtest interne
LegalCopyright 2026 Leo Peyre-Costa
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x140010000
EndAddressOfRawData 0x140010008
AddressOfIndex 0x14000e07c
AddressOfCallbacks 0x14000b820
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x0000000140001580
0x0000000140001560

Load Configuration

RICH Header

Errors

[!] Error: Could not read an IMAGE_RESOURCE_DIRECTORY_ENTRY's name. [*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.