| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-24 16:04:09 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\erenk\Desktop\melwez\exeler\CraftRise.pdb
|
| CompanyName | CraftRise Launcher |
| FileDescription | CraftRise |
| FileVersion | 1.0.0.1 |
| InternalName | CraftRise Launcher |
| LegalCopyright | craftrise-copyright |
| OriginalFilename | CraftRise Launcher.exe |
| ProductName | CraftRise Launcher |
| ProductVersion | 1.0.0.1 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Mar-24 16:04:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x9ba00 |
| SizeOfInitializedData | 0xd6a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000948E0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x176000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ntdll.dll |
VerSetConditionMask
|
|---|---|
| ADVAPI32.dll |
GetUserNameA
|
| api-ms-win-shcore-scaling-l1-1-1.dll |
SetProcessDpiAwareness
|
| gdiplus.dll |
GdipSaveImageToFile
GdipFree GdipDisposeImage GdipCreateBitmapFromHBITMAP GdiplusStartup GdiplusShutdown GdipCloneImage GdipAlloc |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| KERNEL32.dll |
MultiByteToWideChar
GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock GetModuleHandleA LoadLibraryA QueryPerformanceFrequency GetProcAddress FreeLibrary QueryPerformanceCounter CreateMutexA Sleep GetLastError DeleteFileW CloseHandle WinExec GetComputerNameA Process32First WriteProcessMemory FindFirstFileA SetConsoleTextAttribute GetStdHandle Module32Next FindNextFileA FindClose Module32First OpenProcess CreateToolhelp32Snapshot GetTempPathA QueryFullProcessImageNameA DeleteFileA Process32Next FreeConsole Beep RemoveDirectoryA ExitProcess ReadProcessMemory GetCurrentProcessId GetCurrentThreadId ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW GetModuleHandleW GetSystemTimeAsFileTime InitializeSListHead GetFileInformationByHandleEx AreFileApisANSI CreateFile2 GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW GetLocaleInfoEx FormatMessageA LocalFree TryAcquireSRWLockExclusive GetSystemTimePreciseAsFileTime LCMapStringEx EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection EncodePointer DecodePointer CompareStringEx GetCPInfo |
| USER32.dll |
DispatchMessageA
SetProcessDpiAwarenessContext MonitorFromPoint GetWindowThreadProcessId ShowWindow DestroyWindow GetAsyncKeyState SetWindowLongA SetWindowDisplayAffinity DefWindowProcA CreateWindowExA SetWindowPos IsWindow RegisterClassExA UpdateWindow GetSystemMetrics SetLayeredWindowAttributes TranslateMessage mouse_event LoadIconA PeekMessageA UnregisterClassA PostQuitMessage FindWindowA GetKeyState LoadCursorA GetDC ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetForegroundWindow SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData |
| GDI32.dll |
GetDeviceCaps
DeleteDC CreateCompatibleDC SelectObject CreateCompatibleBitmap BitBlt DeleteObject |
| SHELL32.dll |
SHGetFolderPathA
|
| ole32.dll |
CLSIDFromString
|
| IMM32.dll |
ImmSetCompositionWindow
ImmGetContext ImmReleaseContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_terminate
_purecall __std_type_info_compare __uncaught_exceptions memmove memchr memcpy memcmp memset _CxxThrowException __C_specific_handler strchr __current_exception_context __current_exception __std_exception_copy __RTtypeid __std_exception_destroy strstr |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsscanf
fread _wfsopen __stdio_common_vsprintf __stdio_common_vsprintf_s fgetc ftell __acrt_iob_func fflush fclose fseek fgetpos setvbuf __stdio_common_vfprintf ungetc fwrite fsetpos _wfopen fputc _fseeki64 __p__commode _set_fmode _get_stream_buffer_pointers |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
qsort |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
realloc _callnewh calloc free malloc |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsdup
islower isupper strcmp strlen tolower strncmp strncpy __strncnt strcpy_s wcslen |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_exit
_c_exit _register_thread_local_exe_atexit_callback exit _initterm_e _initterm _get_narrow_winmain_command_line abort _set_app_type _cexit _crt_atexit _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _errno _configure_narrow_argv system _beginthreadex terminate _seh_filter_exe |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
strftime _time64 |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| api-ms-win-crt-locale-l1-1-0.dll |
setlocale
__pctype_func _lock_locales ___lc_collate_cp_func ___lc_locale_name_func _configthreadlocale ___lc_codepage_func _unlock_locales |
| api-ms-win-crt-math-l1-1-0.dll |
cosf
ceilf sqrtf sinf powf fmodf __setusermatherr acosf logf |
| api-ms-win-crt-environment-l1-1-0.dll |
getenv
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | CraftRise Launcher |
| FileDescription | CraftRise |
| FileVersion (#2) | 1.0.0.1 |
| InternalName | CraftRise Launcher |
| LegalCopyright | craftrise-copyright |
| OriginalFilename | CraftRise Launcher.exe |
| ProductName | CraftRise Launcher |
| ProductVersion (#2) | 1.0.0.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-24 16:04:09 |
| Version | 0.0 |
| SizeofData | 75 |
| AddressOfRawData | 0xad2b8 |
| PointerToRawData | 0xac0b8 |
| Referenced File | C:\Users\erenk\Desktop\melwez\exeler\CraftRise.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-24 16:04:09 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xad304 |
| PointerToRawData | 0xac104 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-24 16:04:09 |
| Version | 0.0 |
| SizeofData | 932 |
| AddressOfRawData | 0xad318 |
| PointerToRawData | 0xac118 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-24 16:04:09 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400ad6e0 |
|---|---|
| EndAddressOfRawData | 0x1400ad6e8 |
| AddressOfIndex | 0x14016c970 |
| AddressOfCallbacks | 0x14009dae8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400bb040 |
| XOR Key | 0xaa9e7cca |
|---|---|
| Unmarked objects | 0 |
| Imports (35403) | 4 |
| Imports (21202) | 2 |
| Imports (VS2008 SP1 build 30729) | 24 |
| ASM objects (35403) | 4 |
| C objects (35403) | 10 |
| C++ objects (35403) | 80 |
| Imports (33145) | 25 |
| Total imports | 377 |
| C++ objects (LTCG) (35727) | 14 |
| Resource objects (35727) | 1 |
| 151 | 1 |
| Linker (35727) | 1 |
No comments yet.