| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-26 02:58:46 |
| Detected languages |
English - United States
|
| TLS Callbacks | 8 callback(s) detected. |
| Debug artifacts |
Z:\_SOURCE_CODE\ClientModLauncher\Launcher\Release\CMLauncher.pdb
|
| LegalCopyright | ClientMod (C) 2025 |
| ProductName | ClientMod Launcher |
| ProductVersion | 1.5.9 |
| FileVersion | 1.5.9 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to Whirlpool Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .msec
Unusual section name found: .cdata Unusual section name found: .XxT Unusual section name found: .X4& Unusual section name found: .>'] |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ClientModGame
Issuer: ClientModGame |
| Malicious | VirusTotal score: 4/71 (Scanned on 2026-03-29 12:24:38) |
Bkav:
W32.AIDetectMalware
Malwarebytes: Malware.Heuristic.2108 Trapmine: malicious.moderate.ml.score VBA32: Malware-Cryptor.Inject.gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x1a8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 10 |
| TimeDateStamp | 2025-Dec-26 02:58:46 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x922000 |
| SizeOfInitializedData | 0x496200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x01BF9522 (Section: .>']) |
| BaseOfCode | 0x10000 |
| BaseOfData | 0x940000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x10000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x21c0000 |
| SizeOfHeaders | 0x600 |
| Checksum | 0x1819db8 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| SHELL32.dll |
SHGetKnownFolderPath
|
|---|---|
| imagehlp.dll |
StackWalk64
|
| ntdll.dll |
VerSetConditionMask
RtlNtStatusToDosError RtlCaptureContext RtlUnwind |
| IMM32.dll |
ImmReleaseContext
ImmSetCandidateWindow ImmGetContext ImmSetCompositionWindow |
| WINMM.dll |
timeBeginPeriod
|
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueA GetFileVersionInfoSizeW |
| WS2_32.dll |
inet_ntoa
WSASendTo gethostbyaddr shutdown WSARecvFrom freeaddrinfo getaddrinfo WSAAddressToStringW WSASocketW WSASend WSARecv WSAStringToAddressW inet_addr listen recv getpeername accept inet_ntop inet_pton WSAWaitForMultipleEvents WSAResetEvent WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent getsockopt WSAIoctl getservbyport WSAGetLastError WSASetLastError setsockopt send ioctlsocket connect bind getservbyname gethostname WSAStartup socket closesocket WSACleanup htonl select __WSAFDIsSet gethostbyname ntohl getsockname recvfrom sendto htons ntohs |
| USER32.dll |
TranslateMessage
PeekMessageA GetDesktopWindow EnumDisplaySettingsA MessageBoxW GetUserObjectInformationW IsWindowVisible SetClipboardData GetClipboardData EmptyClipboard GetWindowThreadProcessId FindWindowExA EnumDisplayDevicesA GetWindowLongW AdjustWindowRectEx GetKeyState CloseClipboard OpenClipboard GetCursorPos ReleaseDC SetCursorPos IsIconic SetForegroundWindow ReleaseCapture RegisterClassExA IsWindowUnicode SetProcessDPIAware UnregisterClassA GetClientRect SetWindowLongW LoadCursorA DestroyWindow GetDC SetWindowPos MonitorFromWindow EnumDisplayMonitors LoadIconA SetCursor SetCapture SendMessageA ScreenToClient LoadStringA RegisterClassA EnumWindows GetClassNameA FindWindowA MsgWaitForMultipleObjects DispatchMessageA BringWindowToTop SetFocus SetLayeredWindowAttributes CreateWindowExA DefWindowProcA GetForegroundWindow GetMonitorInfoA TrackMouseEvent IsChild ClientToScreen SetWindowLongA GetCapture ShowWindow WindowFromPoint SetWindowTextW GetProcessWindowStation |
| KERNEL32.dll |
GetStringTypeW
GetFileInformationByHandleEx GetFinalPathNameByHandleW FindFirstFileExW GetLocaleInfoEx GetModuleHandleExW CloseThreadpoolWork SubmitThreadpoolWork CreateThreadpoolWork FreeLibraryWhenCallbackReturns InitOnceComplete InitOnceBeginInitialize GetExitCodeThread TryAcquireSRWLockExclusive AcquireSRWLockShared ReleaseSRWLockShared InitializeSListHead GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter EncodePointer DecodePointer LCMapStringEx CompareStringEx GetCPInfo CreateSemaphoreA MultiByteToWideChar GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetModuleHandleA LoadLibraryA QueryPerformanceFrequency GetProcAddress GetProcessId GetCurrentProcessId FormatMessageW LocalFree FormatMessageA QueryPerformanceCounter CloseHandle GetModuleFileNameA SetThreadPriority GetCurrentThread OpenProcess Sleep GetExitCodeProcess GetProcessDEPPolicy SetProcessDEPPolicy SetLastError GetLastError VirtualProtect GetPrivateProfileStringA WritePrivateProfileStringA GetSystemInfo SetThreadAffinityMask GetCurrentProcess SetProcessAffinityMask GetProcessAffinityMask DuplicateHandle SystemTimeToFileTime GetSystemTime CreateToolhelp32Snapshot Thread32First OpenThread ResumeThread Thread32Next GetCurrentThreadId CreateFileA InitializeCriticalSectionEx VerifyVersionInfoW EnterCriticalSection WaitForMultipleObjects LeaveCriticalSection ResetEvent SetEvent WaitForSingleObject SleepEx CreateEventW QueueUserAPC TerminateThread DeleteCriticalSection InitializeCriticalSectionAndSpinCount ReleaseMutex CreateMutexA SetSearchPathMode GetLocalTime CreateWaitableTimerExW SetWaitableTimerEx GetUserDefaultUILanguage GetLocaleInfoA FreeLibrary CreateEventA GetTimeZoneInformation FileTimeToSystemTime GetSystemTimeAsFileTime GetTimeFormatW SetEnvironmentVariableW GetEnvironmentVariableW GetEnvironmentVariableA LoadLibraryW OutputDebugStringA SetPriorityClass GetPriorityClass ReadConsoleA GetLogicalProcessorInformation GlobalMemoryStatusEx GetProcessTimes AreFileApisANSI ReadFile TryEnterCriticalSection HeapCreate HeapFree GetFullPathNameW WriteFile GetDiskFreeSpaceW LockFile InitializeCriticalSection SetFilePointer GetFullPathNameA SetEndOfFile UnlockFileEx GetTempPathW CreateMutexW CreateFileW GetFileAttributesW GetVersionExW UnmapViewOfFile HeapValidate HeapSize GetTempPathA GetDiskFreeSpaceA GetFileAttributesA GetFileAttributesExW OutputDebugStringW FlushViewOfFile WaitForSingleObjectEx GetVersionExA DeleteFileA DeleteFileW HeapReAlloc RaiseException HeapAlloc HeapCompact HeapDestroy UnlockFile CreateFileMappingA LockFileEx GetFileSize GetProcessHeap CreateFileMappingW MapViewOfFile GetTickCount FlushFileBuffers GetStdHandle GetModuleHandleW Process32First K32GetProcessImageFileNameA TerminateProcess Process32Next TlsFree TlsSetValue TlsGetValue TlsAlloc VirtualFree VirtualAlloc VirtualQuery SuspendThread GetThreadContext FlushInstructionCache SetThreadContext SetFileAttributesW SetFileAttributesA GetCommandLineA CreateProcessA K32EmptyWorkingSet LCMapStringA GetUserDefaultLCID GetStringTypeExA LoadLibraryExA SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW GetDiskFreeSpaceExW GetFileInformationByHandle GetFileTime RemoveDirectoryW SetFilePointerEx DeviceIoControl CreateDirectoryExW CopyFileExW MoveFileExW ReleaseSemaphore WaitForMultipleObjectsEx OpenEventA SetWaitableTimer CreateWaitableTimerA InitializeConditionVariable WakeConditionVariable CompareStringW SleepConditionVariableCS CreateThread RegisterWaitForSingleObject UnregisterWait ExpandEnvironmentStringsA CreateIoCompletionPort GetQueuedCompletionStatusEx PostQueuedCompletionStatus SetFileCompletionNotificationModes ReleaseSRWLockExclusive AcquireSRWLockExclusive GetSystemDirectoryA MoveFileExA GetFileType PeekNamedPipe FindClose FindFirstFileW FindNextFileW InitializeSRWLock SleepConditionVariableSRW SwitchToThread lstrcmpA GetQueuedCompletionStatus GetDriveTypeW CancelIoEx CopyFileW CreateHardLinkW GetFileSizeEx GetOverlappedResult GetACP CancelIo FindFirstFileA FindNextFileA LCMapStringW ReadConsoleW LoadLibraryExW GetConsoleMode GetThreadPriority ExitThread GetLocaleInfoW IsValidLocale EnumSystemLocalesW FreeLibraryAndExitThread SystemTimeToTzSpecificLocalTime SetConsoleCtrlHandler ExitProcess SetStdHandle IsValidCodePage GetOEMCP GetCommandLineW SetConsoleMode WriteConsoleW GetConsoleOutputCP K32GetProcessMemoryInfo GetDateFormatW GetEnvironmentStringsW FreeEnvironmentStringsW GetModuleFileNameW WakeAllConditionVariable |
| GDI32.dll |
GetDeviceCaps
|
| MSWSOCK.dll |
GetAcceptExSockaddrs
AcceptEx |
| ADVAPI32.dll |
RegOpenKeyExW
GetSecurityInfo CryptGenRandom CryptAcquireContextW ReportEventW RegisterEventSourceW DeregisterEventSource RegNotifyChangeKeyValue SystemFunction036 GetTokenInformation OpenProcessToken RegCloseKey RegQueryValueExA RegOpenKeyExA RegGetValueA RegEnumKeyExA CryptAcquireContextA CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash |
| dbghelp.dll |
MiniDumpWriteDump
SymFromAddr |
| ole32.dll |
CoInitializeSecurity
CoTaskMemFree CoCreateGuid CoInitializeEx CoCreateInstance CoSetProxyBlanket CoUninitialize |
| OLEAUT32.dll |
SafeArrayGetElement
SysAllocStringLen SafeArrayGetUBound SafeArrayGetLBound VariantChangeType VariantClear VariantInit SysFreeString SysAllocString |
| WININET.dll |
InternetGetConnectedState
InternetCanonicalizeUrlA |
| bcrypt.dll |
BCryptCloseAlgorithmProvider
BCryptSetProperty BCryptGetProperty BCryptGenerateSymmetricKey BCryptGenRandom BCryptDestroyKey BCryptCreateHash BCryptHashData BCryptOpenAlgorithmProvider BCryptFinishHash BCryptDestroyHash BCryptDeriveKeyPBKDF2 BCryptEncrypt |
| CRYPT32.dll |
CertFindCertificateInStore
CertOpenSystemStoreW CertOpenSystemStoreA CertCloseStore CertEnumCertificatesInStore CertFreeCertificateContext |
| IPHLPAPI.DLL |
CancelMibChangeNotify2
if_indextoname NotifyIpInterfaceChange GetUnicastIpAddressTable FreeMibTable GetAdaptersAddresses GetBestRoute2 if_nametoindex NotifyUnicastIpAddressChange |
| WLDAP32.dll |
#301
#200 #30 #79 #143 #217 #46 #211 #60 #50 #41 #22 #26 #27 #32 #33 #35 |
| d3d9.dll (delay-loaded) |
Direct3DCreate9
Direct3DCreate9Ex |
| Attributes | 0x1 |
|---|---|
| Name | d3d9.dll |
| ModuleHandle | 0xd43840 |
| DelayImportAddressTable | 0xd43758 |
| DelayImportNameTable | 0x1b8c2b4 |
| BoundDelayImportTable | 0xcd4cb0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0xd4372c |
| Ordinal | 2 |
|---|---|
| Address | 0xcf5b48 |
| Ordinal | 3 |
|---|---|
| Address | 0xd43730 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.5.9.0 |
| ProductVersion | 1.5.9.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| LegalCopyright | ClientMod (C) 2025 |
| ProductName | ClientMod Launcher |
| ProductVersion (#2) | 1.5.9 |
| FileVersion (#2) | 1.5.9 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-26 02:58:46 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x2192a00 |
| PointerToRawData | 0x17f0400 |
| Referenced File | Z:\_SOURCE_CODE\ClientModLauncher\Launcher\Release\CMLauncher.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-26 02:58:46 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x2192a60 |
| PointerToRawData | 0x17f0460 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-26 02:58:46 |
| Version | 0.0 |
| SizeofData | 1776 |
| AddressOfRawData | 0x2192a80 |
| PointerToRawData | 0x17f0480 |
| StartAddressOfRawData | 0x18b07d8 |
|---|---|
| EndAddressOfRawData | 0x18b3048 |
| AddressOfIndex | 0x115bdb0 |
| AddressOfCallbacks | 0x21344e4 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_32BYTES
|
| Callbacks |
0x0235C230
0x00BD07C0 0x004732F0 0x00850167 0x00C5F280 0x0085021A 0x00C97100 0x00BD3400 |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10f2a00 |
| SEHandlerTable | 0x25931d0 |
| SEHandlerCount | 4293 |
| XOR Key | 0x91c009 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 31 |
| C++ objects (30795) | 212 |
| Unmarked objects (#2) | 22 |
| Imports (VS2015 UPD3.1 build 24215) | 2 |
| C objects (30795) | 39 |
| 253 (35207) | 10 |
| ASM objects (35207) | 37 |
| C objects (35207) | 23 |
| C objects (VS2019 Update 5 (16.5.2-3) compiler 28612) | 72 |
| C++ objects (33523) | 115 |
| C++ objects (VS2019 Update 10 (16.10.2) compiler 30038) | 1 |
| C++ objects (34441) | 6 |
| C objects (VS2022 Update 8 (17.8.0-2) compiler 33130) | 736 |
| C++ objects (VS2019 Update 8 (16.8.5-6) compiler 29337) | 3 |
| C objects (VS2019 Update 10 (16.10.2) compiler 30038) | 27 |
| C objects (34440) | 1 |
| C++ objects (34440) | 99 |
| C objects (34123) | 77 |
| C objects (VS2022 Update 5 (17.5.4) compiler 32217) | 39 |
| C++ objects (VS2019 Update 11 (16.11.19) compiler 30147) | 120 |
| C objects (34435) | 278 |
| C++ objects (33519) | 10 |
| C++ objects (35207) | 107 |
| C objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 43 |
| Total imports | 670 |
| C++ objects (POGO O) (35222) | 197 |
| Exports (35222) | 1 |
| Resource objects (35222) | 1 |
| 151 | 1 |
| Linker (35222) | 1 |
No comments yet.