| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-27 17:36:03 |
| Detected languages |
English - United States
|
| CompanyName | Capcom Co., Ltd. |
| FileDescription | Resident Evil: Requiem - Community Trainer |
| FileVersion | 1.0.4.2026 |
| InternalName | RERequiemTrainer |
| LegalCopyright | Щ 2026 Capcom Co., Ltd. All rights reserved. |
| OriginalFilename | RERequiemTrainer.exe |
| ProductName | Resident Evil: Requiem |
| ProductVersion | 1.0.4 |
| Comments | Community trainer for Resident Evil: Requiem. Provides enhanced gameplay features and cheats. |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 Uses constants related to AES |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 101 detected as a PE Executable. |
| Info | The PE is digitally signed. |
Signer: Capcom Co. Ltd.
Issuer: Capcom Co. Ltd. |
| Malicious | VirusTotal score: 5/72 (Scanned on 2026-02-27 18:33:56) |
Elastic:
malicious (moderate confidence)
Kaspersky: UDS:Trojan.Win32.Agent Microsoft: Trojan:Win32/Bearfoos.B!ml Trapmine: malicious.moderate.ml.score VBA32: suspected of Trojan.Notifier.gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Feb-27 17:36:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2b800 |
| SizeOfInitializedData | 0xa4c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000ED9A (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd4000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xdce67 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WINHTTP.dll |
WinHttpSetTimeouts
WinHttpSendRequest WinHttpCloseHandle WinHttpSetOption WinHttpOpenRequest WinHttpAddRequestHeaders WinHttpOpen WinHttpConnect WinHttpReceiveResponse WinHttpQueryHeaders WinHttpReadData WinHttpQueryDataAvailable |
|---|---|
| WS2_32.dll |
inet_ntoa
gethostbyname gethostname |
| SHELL32.dll |
ShellExecuteExA
|
| ADVAPI32.dll |
RegQueryValueExA
AllocateAndInitializeSid GetUserNameA FreeSid CheckTokenMembership RegOpenKeyExA RegCloseKey |
| ole32.dll |
CoInitializeEx
CoCreateGuid CoUninitialize |
| KERNEL32.dll |
GetEnvironmentStringsW
GetCommandLineW GetCommandLineA GetOEMCP GetACP IsValidCodePage FindNextFileW FreeEnvironmentStringsW HeapReAlloc ReadConsoleW ReadFile EnumSystemLocalesW GetUserDefaultLCID SetStdHandle GetProcessHeap CreateFileW HeapSize WriteConsoleW FindFirstFileExW MultiByteToWideChar IsValidLocale GetLocaleInfoW LCMapStringW SizeofResource FindFirstFileA WriteFile WaitForMultipleObjects GetUserDefaultLocaleName FindResourceA FindClose CreateMutexA WaitForSingleObject Sleep GetTempPathA GetTimeZoneInformation GetTickCount64 GetLastError GetFileAttributesA CreateFileA LockResource DeleteFileA CloseHandle CreateThread LoadResource GlobalMemoryStatusEx WideCharToMultiByte CreateProcessA CreateDirectoryA GetTickCount GetComputerNameA GetExitCodeProcess FindNextFileA SetFileAttributesA RemoveDirectoryA EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer SetEndOfFile LCMapStringEx GetStringTypeW GetCPInfo IsProcessorFeaturePresent QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW RtlUnwind RaiseException SetLastError FlsAlloc FlsGetValue FlsSetValue FlsFree GetStdHandle GetModuleFileNameW GetCurrentProcess ExitProcess TerminateProcess FreeLibrary GetModuleHandleExW GetProcAddress IsDebuggerPresent UnhandledExceptionFilter GetFileSizeEx SetFilePointerEx GetFileType HeapAlloc FlushFileBuffers GetConsoleOutputCP GetConsoleMode HeapFree VirtualProtect LoadLibraryExW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.4.2026 |
| ProductVersion | 1.0.4.2026 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Capcom Co., Ltd. |
| FileDescription | Resident Evil: Requiem - Community Trainer |
| FileVersion (#2) | 1.0.4.2026 |
| InternalName | RERequiemTrainer |
| LegalCopyright | Щ 2026 Capcom Co., Ltd. All rights reserved. |
| OriginalFilename | RERequiemTrainer.exe |
| ProductName | Resident Evil: Requiem |
| ProductVersion (#2) | 1.0.4 |
| Comments | Community trainer for Resident Evil: Requiem. Provides enhanced gameplay features and cheats. |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-27 17:36:03 |
| Version | 0.0 |
| SizeofData | 852 |
| AddressOfRawData | 0x3873c |
| PointerToRawData | 0x3733c |
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x43b080 |
| SEHandlerTable | 0x4385d0 |
| SEHandlerCount | 47 |
| XOR Key | 0x527e030c |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 12 |
| C++ objects (33145) | 173 |
| C objects (33145) | 22 |
| ASM objects (35403) | 21 |
| C objects (35403) | 17 |
| C++ objects (35403) | 76 |
| Imports (33145) | 15 |
| Total imports | 144 |
| C++ objects (LTCG) (35724) | 3 |
| Resource objects (35724) | 1 |
| Linker (35724) | 1 |
No comments yet.