5653bc7b0e2701561464ef36602ff6171c96bffe96e4c3597359cd7addcba88a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 1981-Jan-19 07:15:57
Detected languages English - United States
Debug artifacts D3DCompiler_47.pdb
CompanyName Microsoft Corporation
FileDescription Direct3D HLSL Compiler for Redistribution
FileVersion 10.0.20348.1 (WinBuild.160101.0800)
InternalName d3dcompiler_47.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename d3dcompiler_47.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.20348.1

Plugin Output

Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Microsoft's Cryptography API
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegQueryValueExA
  • RegEnumKeyExA
  • RegOpenKeyExA
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Uses Microsoft's cryptographic API:
  • CryptDestroyHash
  • CryptAcquireContextW
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptReleaseContext
Enumerates local disk drives:
  • GetDriveTypeW
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010
Safe VirusTotal score: 0/68 (Scanned on 2026-08-10 18:24:13) All the AVs think this file is safe.

Hashes

MD5 cb9807f6cf55ad799e920b7e0f97df99
SHA1 bb76012ded5acd103adad49436612d073d159b29
SHA256 5653bc7b0e2701561464ef36602ff6171c96bffe96e4c3597359cd7addcba88a
SHA3 f9511dd0e6940e2d40d3f8117e910dec83e24eb112fe42f17c76399ca4bf89ae
SSDeep 49152:IuhjwXkKcimPVqB4faGCMhGNYYpQVTxx6k/ftO4w6FXKpOD21pLeXvZCoFwI8cc:oy904wYbZCoOI85oyI
Imports Hash dc71769f237c0a3ba38879380c54a4e6

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 1981-Jan-19 07:15:57
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x389000
SizeOfInitializedData 0x128000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000028F360 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4b2000
SizeOfHeaders 0x1000
Checksum 0x4acd32
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f26e5a699d56a105d86862cc8a9f4a2e
SHA1 a13527babd0bd850d4a5c9d8aeee5f8a26f87692
SHA256 93fe3e1f297e6e2a885c2d016f1a13d824af2ce1cd9faa60a3af9bf3b57a7c3c
SHA3 c3e173f318332fa9b5425f8ae647fa51532c8fffe5246dd7a3e66d8dc251688c
VirtualSize 0x38880e
VirtualAddress 0x1000
SizeOfRawData 0x389000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39795

.rdata

MD5 cb6b9f9acf7936bef3db24b5bf4c0297
SHA1 b70300424fbf1aa0cecb9eeebfe10bb5b781bef3
SHA256 5e5433c93e7e791a30e01a713b5b194965bd03f5a284cdbef87e1cbe67634c7e
SHA3 0fc6054981ea704816a4ff53608f109f9d0455c83d790378329970d42237b034
VirtualSize 0xe3d84
VirtualAddress 0x38a000
SizeOfRawData 0xe4000
PointerToRawData 0x38a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.35999

.data

MD5 1122e8e8b23db33b6edc6a3a893362dc
SHA1 d68a184cd90412461fb34644ff77d7baed936b06
SHA256 760e8711f0f54c81aa3525385ecfc33b20a782f8687ff05b9b48f294f36769b3
SHA3 441964c3015a5d0982b1cd4440117b22d77f1ec205cfd25f12530556b35a7648
VirtualSize 0x19240
VirtualAddress 0x46e000
SizeOfRawData 0x10000
PointerToRawData 0x46e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.9852

.pdata

MD5 b1e4ba89becfa0c0c8634840ae6ddcfa
SHA1 2d91c1440ee252ebe412a8372c2090eb1b20818a
SHA256 2017e0c2b17111bc57075687f8453a639bb20eec5646258fa1f540e74d8d5abe
SHA3 6d720071be7877ee054e09a22ec085b2e514498b1b23f9961ff13e6df17ea455
VirtualSize 0x1fef0
VirtualAddress 0x488000
SizeOfRawData 0x20000
PointerToRawData 0x47e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.36352

.rsrc

MD5 a0f1ab47d7a68f340463cb6e66040344
SHA1 9483ca99a4a09e228fb3c04bea9495cebdca20df
SHA256 8262305b6eb0a6893b9d8b452ddde13b75c1b20947a20b90ae91f3d1fd87cb6d
SHA3 a5c5bdd6e73bb1778dc0b4fa6153ec3041e74eb42628ab8eeba8d0962f6fa3b9
VirtualSize 0x440
VirtualAddress 0x4a8000
SizeOfRawData 0x1000
PointerToRawData 0x49e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.1379

.reloc

MD5 67b424abe2d7452184be8b5f30cd6866
SHA1 6616a5795ee432690be8fbf13d5e05a9480949c0
SHA256 794be91bbf42797d4173c0b2808de4a113b12a6c83ff7644c6bc78d5e55cb7d0
SHA3 98850c36c3a5849ce89faf5414a2a14449aaa74b95244b7dbeb2302d2f1fdddd
VirtualSize 0x89a4
VirtualAddress 0x4a9000
SizeOfRawData 0x9000
PointerToRawData 0x49f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.40257

Imports

KERNEL32.dll WriteFile
FreeLibrary
Sleep
TlsAlloc
TlsSetValue
HeapDestroy
TlsGetValue
TlsFree
GetFullPathNameW
GetFullPathNameA
GetEnvironmentVariableA
VirtualFree
VirtualAlloc
GetSystemInfo
GetProcAddress
LoadLibraryExW
SetLastError
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
GetCurrentThreadId
GetStdHandle
GetFileType
GetStartupInfoW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitializeCriticalSectionAndSpinCount
GetSystemTimeAsFileTime
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
ExitProcess
GetModuleHandleW
GetModuleHandleExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetFilePointerEx
GetStringTypeW
SetStdHandle
ReadFile
FreeEnvironmentStringsW
SetEnvironmentVariableW
RaiseException
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetModuleFileNameW
ReadConsoleW
HeapSize
HeapReAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
InitializeSListHead
RtlUnwindEx
InterlockedFlushSList
EncodePointer
InitializeCriticalSectionEx
RtlPcToFileHeader
LocalAlloc
LocalFree
GetFileSizeEx
GetLastError
CreateFileW
HeapFree
GetProcessHeap
UnmapViewOfFile
GetFileSize
CreateFileMappingW
MapViewOfFile
GetFileAttributesW
SetFileAttributesW
DeleteFileW
SetEndOfFile
DeviceIoControl
MapViewOfFileEx
CreateFileMappingA
ExpandEnvironmentStringsW
HeapAlloc
OutputDebugStringA
CloseHandle
LeaveCriticalSection
EnterCriticalSection
lstrcmpiA
HeapCreate
GetModuleFileNameA
CreateFileA
DeleteCriticalSection
InitializeCriticalSection
WideCharToMultiByte
FindClose
FindFirstFileExW
FindNextFileW
GetCommandLineA
GetCommandLineW
GetDriveTypeW
GetCurrentDirectoryW
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
MultiByteToWideChar
GetEnvironmentStringsW
DisableThreadLibraryCalls
ADVAPI32.dll CryptDestroyHash
CryptAcquireContextW
RegQueryValueExA
RegEnumKeyExA
RegOpenKeyExA
CryptGetHashParam
CryptCreateHash
CryptHashData
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
CryptReleaseContext
RPCRT4.dll UuidCreate

Delayed Imports

D3DAssemble

Ordinal 1
Address 0xe8b50

DebugSetMute

Ordinal 2
Address 0x11fca0

D3DCompile

Ordinal 3
Address 0xe8810

D3DCompile2

Ordinal 4
Address 0xe8890

D3DCompileFromFile

Ordinal 5
Address 0xe89a0

D3DCompressShaders

Ordinal 6
Address 0xeb720

D3DCreateBlob

Ordinal 7
Address 0x80a0

D3DCreateFunctionLinkingGraph

Ordinal 8
Address 0x8280

D3DCreateLinker

Ordinal 9
Address 0x80b0

D3DDecompressShaders

Ordinal 10
Address 0xeba90

D3DDisassemble

Ordinal 11
Address 0x7c20

D3DDisassemble10Effect

Ordinal 12
Address 0x17ff0

D3DDisassemble11Trace

Ordinal 13
Address 0x7cf0

D3DDisassembleRegion

Ordinal 14
Address 0x7c60

D3DGetBlobPart

Ordinal 15
Address 0xea3e0

D3DGetDebugInfo

Ordinal 16
Address 0xea9a0

D3DGetInputAndOutputSignatureBlob

Ordinal 17
Address 0xeaa30

D3DGetInputSignatureBlob

Ordinal 18
Address 0xea9d0

D3DGetOutputSignatureBlob

Ordinal 19
Address 0xeaa00

D3DGetTraceInstructionOffsets

Ordinal 20
Address 0x7cb0

D3DLoadModule

Ordinal 21
Address 0x8160

D3DPreprocess

Ordinal 22
Address 0xe9b10

D3DReadFileToBlob

Ordinal 23
Address 0xe6750

D3DReflect

Ordinal 24
Address 0x7d30

D3DReflectLibrary

Ordinal 25
Address 0x7ee0

D3DReturnFailure1

Ordinal 26
Address 0xebca0

D3DSetBlobPart

Ordinal 27
Address 0xea420

D3DStripShader

Ordinal 28
Address 0xeaa60

D3DWriteBlobToFile

Ordinal 29
Address 0xe69c0

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.45752
MD5 1e3f66f61895380f2716dca9e816b0ea
SHA1 9ea89b3b2481aab36fc429441574c5b963dcae44
SHA256 4e9e21a72e775da46083881e770353b2429e8a72f0bdece6ae9bc394717261cf
SHA3 3377ace79f46c21a35f297507ca1abf168c2c8e7ec4dce6428338d578803d700

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.20348.1
ProductVersion 10.0.20348.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription Direct3D HLSL Compiler for Redistribution
FileVersion (#2) 10.0.20348.1 (WinBuild.160101.0800)
InternalName d3dcompiler_47.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename d3dcompiler_47.dll
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.20348.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1981-Jan-19 07:15:57
Version 0.0
SizeofData 43
AddressOfRawData 0x447abc
PointerToRawData 0x447abc
Referenced File D3DCompiler_47.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 1981-Jan-19 07:15:57
Version 0.0
SizeofData 1068
AddressOfRawData 0x447ae8
PointerToRawData 0x447ae8

UNKNOWN

Characteristics 0
TimeDateStamp 1981-Jan-19 07:15:57
Version 0.0
SizeofData 36
AddressOfRawData 0x447f24
PointerToRawData 0x447f24

UNKNOWN (#2)

Characteristics 0
TimeDateStamp 1981-Jan-19 07:15:57
Version 0.0
SizeofData 4
AddressOfRawData 0x447f48
PointerToRawData 0x447f48

TLS Callbacks

StartAddressOfRawData 0x180447f70
EndAddressOfRawData 0x180447f78
AddressOfIndex 0x18047f7b0
AddressOfCallbacks 0x1803c0b90
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x18047d1c0
GuardCFCheckFunctionPointer 6446385112
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xa1a463be
Unmarked objects 0
Imports (28900) 2
Total imports 145
Imports (VS2008 SP1 build 30729) 5
C++ objects (27316) 60
C objects (27316) 1
ASM objects (28900) 30
C++ objects (28900) 220
C objects (28900) 55
Exports (28900) 1
C objects (LTCG) (28900) 136
Resource objects (28900) 1
Linker (28900) 1

Errors

Leave a comment

No comments yet.