Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Feb-29 21:56:49 |
Detected languages |
English - United Kingdom
English - United States |
Debug artifacts |
D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb
|
CompanyName | YoYo Games Ltd |
FileDescription | A GameMaker Game |
FileVersion | 1.0.0.0 |
LegalCopyright | |
PrivateBuild | 01.00.00.00 |
ProductName | Created with GameMaker |
ProductVersion | 1.0.0.0 |
Info | Matching compiler(s): | MASM/TASM - sig2(h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. |
Unusual section name found: minATL
Unusual section name found: .mydata |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 1/72 (Scanned on 2024-05-30 14:35:12) | Sangfor: Worm.Win32.Save.a |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2024-Feb-29 21:56:49 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x8e1000 |
SizeOfInitializedData | 0x2f6600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000083A298 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xe41000 |
SizeOfHeaders | 0x400 |
Checksum | 0xbe2b60 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
RPCRT4.dll |
UuidToStringW
UuidCreate |
---|---|
WININET.dll |
HttpEndRequestW
InternetWriteFile InternetCloseHandle HttpSendRequestA InternetConnectA InternetCrackUrlA InternetCanonicalizeUrlA HttpOpenRequestA HttpQueryInfoA InternetOpenA InternetReadFile InternetGetConnectedState |
d3d11.dll |
D3D11CreateDevice
|
dbghelp.dll |
MiniDumpWriteDump
SymInitialize SymFromAddr |
WINMM.dll |
joyGetPosEx
mciSendStringA timeGetTime timeGetDevCaps timeEndPeriod timeBeginPeriod joyGetPos |
WS2_32.dll |
getaddrinfo
WSAStartup listen send socket connect gethostname recvfrom recv getsockopt freeaddrinfo sendto ioctlsocket setsockopt WSAGetLastError getpeername inet_ntop getnameinfo __WSAFDIsSet select ntohl ntohs htonl htons inet_pton closesocket bind accept WSACleanup getsockname WSAAddressToStringA |
gdiplus.dll |
GdiplusShutdown
GdiplusStartup |
COMCTL32.dll |
InitCommonControlsEx
|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
MFPlat.DLL |
MFStartup
MFCreateSourceResolver MFCreateMediaType MFShutdown |
MF.dll |
MFCreateAudioRendererActivate
MFCreateTopologyNode MFCreateMediaSession MFCreateSampleGrabberSinkActivate MFGetService MFCreateTopology |
IPHLPAPI.DLL |
GetAdaptersAddresses
NotifyIpInterfaceChange CancelMibChangeNotify2 |
KERNEL32.dll |
SetConsoleCtrlHandler
GetCurrentThread WriteFile GetStdHandle FreeLibraryAndExitThread ExitThread PeekNamedPipe GetFileType GetFileInformationByHandle GetDriveTypeW FileTimeToSystemTime SystemTimeToTzSpecificLocalTime FindFirstFileExW MoveFileExW SetFileAttributesW GetFileAttributesExW GetModuleHandleExW HeapWalk HeapValidate TlsFree TlsSetValue TlsGetValue TlsAlloc RtlUnwind LoadLibraryExW GetTempPathW InterlockedPushEntrySList RtlPcToFileHeader RtlUnwindEx VirtualQuery GetProcessHeap HeapFree HeapAlloc InitializeSListHead GetConsoleMode GetFileSizeEx RaiseException GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent SetFilePointerEx ReadConsoleW SetStdHandle GetTimeZoneInformation HeapReAlloc IsValidLocale IsValidCodePage GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW GetDateFormatW GetTimeFormatW CompareStringW InterlockedFlushSList Sleep LoadLibraryW GetProcAddress MultiByteToWideChar WideCharToMultiByte GetLastError LoadLibraryA OutputDebugStringA SetWaitableTimer CreateWaitableTimerW CloseHandle GetConsoleWindow SetLastError GetFullPathNameW GetExitCodeThread FormatMessageW DeleteFileW CreateThread GetCurrentDirectoryW SetCurrentDirectoryW LocalFree GetModuleHandleW ReadFile SetFilePointer CreateFileW GetFileAttributesW GetCurrentDirectoryA SetCurrentDirectoryA SetEnvironmentVariableW FreeLibrary FormatMessageA CreateDirectoryW FindFirstFileW FindNextFileW RemoveDirectoryW GetModuleFileNameW GetUserDefaultLCID ResumeThread GetTempPathA CreateProcessW CreateDirectoryA WaitForSingleObject GetTickCount64 QueryPerformanceFrequency QueryPerformanceCounter GetCurrentProcess K32GetProcessMemoryInfo GlobalAlloc GlobalLock GlobalUnlock GetLocaleInfoW GetVersionExW GetSystemInfo GlobalMemoryStatusEx VerSetConditionMask VerifyVersionInfoW GlobalFree GetCurrentProcessId DebugBreak GetEnvironmentVariableA ExitProcess lstrlenA GetVersion SetEnvironmentVariableA CreateFileMappingW MapViewOfFile MoveFileA GetCommandLineW ExpandEnvironmentStringsW GetFinalPathNameByHandleW SetErrorMode GetCurrentThreadId SetUnhandledExceptionFilter WaitForSingleObjectEx CreateEventExA OutputDebugStringW TerminateProcess UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext CreateEventW ResetEvent SetEvent GetStringTypeW GetLocaleInfoEx GetCPInfo CompareStringEx LCMapStringEx DecodePointer EncodePointer CreateSymbolicLinkW GetFileInformationByHandleEx CloseThreadpoolWait SetThreadpoolWait CreateThreadpoolWait CloseThreadpoolTimer WaitForThreadpoolTimerCallbacks SetThreadpoolTimer CreateThreadpoolTimer CloseThreadpoolWork SubmitThreadpoolWork CreateThreadpoolWork FreeLibraryWhenCallbackReturns GetSystemTimeAsFileTime GetCurrentProcessorNumber FlushProcessWriteBuffers CreateSemaphoreExW CreateEventExW InitOnceExecuteOnce FlsFree FlsSetValue FlsGetValue FlsAlloc SetFileInformationByHandle GetNativeSystemInfo SwitchToThread SetEndOfFile SleepConditionVariableSRW SleepConditionVariableCS WakeAllConditionVariable WakeConditionVariable InitializeConditionVariable TryEnterCriticalSection InitializeCriticalSectionEx AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock SetThreadPriority DeleteCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount EnterCriticalSection RtlCaptureStackBackTrace LCMapStringW EnumSystemLocalesW FlushFileBuffers FindClose GetConsoleOutputCP HeapSize GetFileSize WriteConsoleW |
USER32.dll |
MsgWaitForMultipleObjectsEx
EnumDisplaySettingsA TranslateMessage SetProcessDPIAware SetDlgItemTextA MessageBoxA GetFocus PeekMessageW CloseClipboard EmptyClipboard GetClipboardData SetClipboardData IsClipboardFormatAvailable keybd_event GetAsyncKeyState IsWindowVisible IsDialogMessageW OpenClipboard DispatchMessageW GetCursorPos SetCursorPos UpdateWindow EnumDisplaySettingsW GetMonitorInfoW ShowWindow GetSystemMetrics SendMessageW SetWindowLongPtrW MonitorFromWindow GetWindowLongPtrW GetLayeredWindowAttributes IntersectRect GetWindowLongW GetWindowPlacement SetWindowPos GetWindowRect wsprintfW GetActiveWindow ClientToScreen MoveWindow CreateDialogParamW GetDC EndDialog SetWindowTextW SetDlgItemTextW GetDlgItemTextW GetDlgItem DrawTextW DialogBoxParamW ReleaseDC DefWindowProcW GetKeyState DestroyWindow CreateWindowExW ScreenToClient CallNextHookEx RegisterClassExW FindWindowExA MapWindowPoints SetWindowPlacement UnhookWindowsHookEx EnumWindows SetFocus BringWindowToTop EnumDisplayDevicesW LoadCursorW SendMessageA SetParent SetCapture SetWindowsHookExW SetCursor GetClientRect PostThreadMessageW FindWindowA ReleaseCapture SetForegroundWindow LoadImageW MessageBoxW GetRawInputDeviceInfoA GetRawInputDeviceList AdjustWindowRectEx PostMessageW |
GDI32.dll |
SelectObject
DeleteObject CombineRgn GetRgnBox CreateRectRgnIndirect GetDeviceCaps GetStockObject |
COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
ADVAPI32.dll |
RegOpenKeyExW
RegCloseKey CryptGenRandom CryptReleaseContext RegQueryValueExW CryptAcquireContextA |
SHELL32.dll |
ShellExecuteW
SHGetFolderPathW |
ole32.dll |
CoCreateInstance
CoCreateFreeThreadedMarshaler CoTaskMemFree CoInitialize PropVariantClear |
dwmapi.dll |
DwmGetWindowAttribute
DwmSetWindowAttribute DwmGetCompositionTimingInfo |
IMM32.dll |
ImmGetContext
ImmSetCompositionWindow ImmReleaseContext ImmSetCandidateWindow |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United Kingdom |
CompanyName | YoYo Games Ltd |
FileDescription | A GameMaker Game |
FileVersion (#2) | 1.0.0.0 |
LegalCopyright | |
PrivateBuild | 01.00.00.00 |
ProductName | Created with GameMaker |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United Kingdom |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Feb-29 21:56:49 |
Version | 0.0 |
SizeofData | 104 |
AddressOfRawData | 0xa357a0 |
PointerToRawData | 0xa34ba0 |
Referenced File | D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Feb-29 21:56:49 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0xa35808 |
PointerToRawData | 0xa34c08 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Feb-29 21:56:49 |
Version | 0.0 |
SizeofData | 1156 |
AddressOfRawData | 0xa3581c |
PointerToRawData | 0xa34c1c |
StartAddressOfRawData | 0x140a35cd0 |
---|---|
EndAddressOfRawData | 0x140a35cd8 |
AddressOfIndex | 0x140b67a74 |
AddressOfCallbacks | 0x1408e3180 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x138 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140af98e8 |
XOR Key | 0x10d94a5e |
---|---|
Unmarked objects | 0 |
ASM objects (30795) | 35 |
253 (28518) | 8 |
C objects (30034) | 20 |
ASM objects (30034) | 12 |
C++ objects (30034) | 93 |
C++ objects (30154) | 40 |
C++ objects (30795) | 223 |
C objects (30795) | 61 |
C objects (30154) | 40 |
Imports (30795) | 43 |
Total imports | 384 |
C++ objects (LTCG) (30154) | 463 |
Resource objects (30154) | 1 |
151 | 1 |
Linker (30154) | 1 |