| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-21 22:53:07 |
| Detected languages |
English - United States
Japanese - Japan |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
C:\CoopGame\ECStest\NewFrameWork\x64\Release\Application.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .msvcjmc |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/72 (Scanned on 2026-04-24 03:38:12) | Rising: Trojan.Kryptik@AI.80 (RDML:uyd52RIQqzaJ2D+N8z8iCg) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Apr-21 22:53:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x83c400 |
| SizeOfInitializedData | 0x8c3200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000007EB304 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1104000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WS2_32.dll |
gethostname
ioctlsocket sendto recvfrom freeaddrinfo getaddrinfo listen htonl select __WSAFDIsSet WSAIoctl WSASetLastError setsockopt recv getsockname getpeername connect bind accept WSACleanup WSAStartup ntohs socket htons WSAGetLastError closesocket WSAEventSelect WSAEnumNetworkEvents WSACreateEvent WSACloseEvent send getsockopt |
|---|---|
| CRYPT32.dll |
CertOpenStore
CertCloseStore CertEnumCertificatesInStore CryptStringToBinaryA CertFreeCertificateContext PFXImportCertStore CryptDecodeObjectEx CertFindCertificateInStore CertAddCertificateContextToStore CertFreeCertificateChain CertGetCertificateChain CertFreeCertificateChainEngine CertCreateCertificateChainEngine CryptQueryObject CertGetNameStringA CertFindExtension |
| Secur32.dll |
InitSecurityInterfaceA
|
| KERNEL32.dll |
ReleaseSRWLockShared
GetLocaleInfoEx FormatMessageA AcquireSRWLockShared RtlCaptureContext RtlLookupFunctionEntry TryAcquireSRWLockExclusive LeaveCriticalSection EnterCriticalSection InitializeCriticalSection DeleteCriticalSection GetModuleFileNameW SetDllDirectoryW GetModuleFileNameA GetLastError WaitForSingleObject CloseHandle MultiByteToWideChar GetModuleHandleW GlobalLock WideCharToMultiByte GlobalUnlock GlobalAlloc GlobalFree GetLocaleInfoA QueryPerformanceFrequency QueryPerformanceCounter LoadLibraryA GetProcAddress GetModuleHandleA VerSetConditionMask GetFileAttributesW CreateFileW ReadFile SleepConditionVariableSRW SetFilePointerEx GetFileInformationByHandleEx SetFilePointer InitOnceExecuteOnce SetEvent WaitForMultipleObjectsEx CreateEventExW WaitForSingleObjectEx RaiseException GetCurrentThread IsDebuggerPresent CreateSemaphoreA ReleaseSemaphore ReleaseSRWLockExclusive AcquireSRWLockExclusive SetLastError InitializeCriticalSectionEx SleepEx FormatMessageW GetTickCount Sleep GetFullPathNameW MoveFileExA CreateThread GetEnvironmentVariableA GetStdHandle GetFileType PeekNamedPipe WaitForMultipleObjects VerifyVersionInfoW CreateFileA GetFileSizeEx LocalFree GetSystemTimeAsFileTime RtlVirtualUnwind AreFileApisANSI TryAcquireSRWLockShared GetCurrentThreadId WakeAllConditionVariable UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetStartupInfoW GetFinalPathNameByHandleW GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose CreateDirectoryW GetCurrentDirectoryW SetCurrentDirectoryW LoadLibraryExA InitializeSListHead VirtualQuery VirtualProtect FreeLibrary GetSystemInfo GetCurrentProcessId |
| USER32.dll |
IsWindowUnicode
ReleaseCapture SetCapture GetCapture TrackMouseEvent GetMessageExtraInfo GetKeyState SetCursor GetKeyboardLayout SetClipboardData EmptyClipboard CloseClipboard GetClipboardData OpenClipboard GetWindowRect PostQuitMessage RemovePropW DefWindowProcW SetPropW GetPropW DispatchMessageW TranslateMessage PeekMessageW DestroyWindow GetAsyncKeyState UpdateWindow ShowWindow CreateWindowExW RegisterClassExW MessageBoxA MoveWindow LoadCursorW LoadIconW ShowCursor ScreenToClient GetForegroundWindow SetCursorPos ClientToScreen GetClientRect GetCursorPos SetWindowTextA |
| GDI32.dll |
GetStockObject
|
| COMDLG32.dll |
GetSaveFileNameA
GetOpenFileNameA |
| ADVAPI32.dll |
CryptGetHashParam
CryptEncrypt CryptImportKey CryptDestroyKey CryptDestroyHash CryptHashData CryptAcquireContextA CryptReleaseContext CryptCreateHash |
| ole32.dll |
CoCreateInstance
CoInitializeEx CoUninitialize PropVariantClear |
| WINMM.dll |
timeGetTime
timeBeginPeriod |
| MSVCP140.dll |
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?peek@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Random_device@std@@YAIXZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?_Xbad_alloc@std@@YAXXZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z _Mtx_trylock _Thrd_yield _Cnd_signal _Cnd_broadcast _Cnd_wait ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Xlength_error@std@@YAXPEBD@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Incref@facet@locale@std@@UEAAXXZ ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??1_Locinfo@std@@QEAA@XZ ??1_Lockit@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ??0_Lockit@std@@QEAA@H@Z ??1facet@locale@std@@MEAA@XZ ??0facet@locale@std@@IEAA@_K@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?id@?$ctype@D@std@@2V0locale@2@A ?_Id_cnt@id@locale@std@@0HA ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?good@ios_base@std@@QEBA_NXZ ?uncaught_exceptions@std@@YAHXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?tolower@?$ctype@D@std@@QEBADD@Z _Strxfrm ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ _Strcoll ?id@?$collate@D@std@@2V0locale@2@A ?_Xout_of_range@std@@YAXPEBD@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ?_Xbad_function_call@std@@YAXXZ _Xtime_get_ticks _Query_perf_counter _Query_perf_frequency ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z _Thrd_hardware_concurrency ??7ios_base@std@@QEBA_NXZ ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z _Thrd_id _Mtx_unlock ?_Throw_Cpp_error@std@@YAXH@Z _Mtx_lock ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z _Thrd_join _Cnd_do_broadcast_at_thread_exit ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ??Bios_base@std@@QEBA_NXZ ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?always_noconv@codecvt_base@std@@QEBA_NXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z |
| MSVCP140_ATOMIC_WAIT.dll |
__std_atomic_wait_get_remaining_timeout
__std_atomic_wait_direct __std_atomic_notify_all_direct __std_atomic_notify_one_direct __std_atomic_wait_get_deadline |
| d3d11.dll |
D3D11CreateDevice
|
| dxgi.dll |
CreateDXGIFactory1
|
| RPCRT4.dll |
UuidToStringA
UuidCreate UuidFromStringA |
| XINPUT1_4.dll |
#2
|
| IMM32.dll |
ImmSetCompositionWindow
ImmSetCandidateWindow ImmReleaseContext ImmGetContext |
| D3DCOMPILER_47.dll |
D3DReflect
D3DCompile D3DPreprocess |
| bcrypt.dll |
BCryptGenRandom
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception_context
__RTDynamicCast strchr __current_exception memchr strrchr __std_terminate __std_exception_copy __std_exception_destroy _purecall __std_type_info_compare __std_type_info_hash __std_type_info_name _CxxThrowException __C_specific_handler strstr memcpy memset memcmp memmove |
| api-ms-win-crt-runtime-l1-1-0.dll |
__sys_nerr
__sys_errlist _invalid_parameter_noinfo_noreturn abort terminate _errno _invalid_parameter_noinfo _register_thread_local_exe_atexit_callback _beginthreadex _c_exit _exit _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe exit _set_app_type _initterm_e _get_narrow_winmain_command_line _initterm _invoke_watson |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_aligned_free _aligned_malloc free realloc _callnewh calloc _set_new_mode |
| api-ms-win-crt-locale-l1-1-0.dll |
setlocale
___lc_codepage_func localeconv _configthreadlocale |
| api-ms-win-crt-stdio-l1-1-0.dll |
fopen
_set_fmode _open fgets ftell _wfopen __p__commode _wfopen_s fputs _fileno _close __stdio_common_vsprintf_s fflush fseek setvbuf _lseeki64 _write fsetpos __acrt_iob_func __stdio_common_vsscanf _fseeki64 _read fgetpos fwrite __stdio_common_vsprintf fclose _get_stream_buffer_pointers __stdio_common_vfprintf feof fputc ungetc fgetc fread |
| api-ms-win-crt-math-l1-1-0.dll |
log10f
sinf cosf sqrtf ceilf floorf roundf _fdclass _fdopen modff lroundf atan2f _dsign ldexp __setusermatherr pow round asinf acosf expf log _dclass logf fmodf tanf powf |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoll
strtoull mbstowcs strtod wcstombs atoi atof strtol |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_stat64
_unlink _lock_file _unlock_file _fstat64 _fullpath |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
qsort |
| api-ms-win-crt-string-l1-1-0.dll |
strncpy_s
strncmp toupper strlen tolower strcspn strcmp isalnum _strdup strcpy wcslen wcsncmp wcsncpy wcscpy strpbrk strncpy strcpy_s strspn |
| api-ms-win-crt-time-l1-1-0.dll |
_gmtime64
strftime _time64 |
| api-ms-win-crt-multibyte-l1-1-0.dll |
_mbschr
_mbsnbcpy _mbsnbcmp |
| assimp-vc142-mt.dll (delay-loaded) |
??1Importer@Assimp@@QEAA@XZ
aiGetMaterialFloatArray aiGetMaterialColor ?ReadFile@Importer@Assimp@@QEAAPEBUaiScene@@PEBDI@Z ??0Importer@Assimp@@QEAA@XZ aiGetMaterialString ?SetPropertyInteger@Importer@Assimp@@QEAA_NPEBDH@Z |
| Attributes | 0x1 |
|---|---|
| Name | assimp-vc142-mt.dll |
| ModuleHandle | 0xfecd90 |
| DelayImportAddressTable | 0xfecd48 |
| DelayImportNameTable | 0xb17180 |
| BoundDelayImportTable | 0xb172b0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Application |
| APPLICATION |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 22:53:07 |
| Version | 0.0 |
| SizeofData | 85 |
| AddressOfRawData | 0xaa751c |
| PointerToRawData | 0xaa5d1c |
| Referenced File | C:\CoopGame\ECStest\NewFrameWork\x64\Release\Application.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 22:53:07 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xaa7574 |
| PointerToRawData | 0xaa5d74 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 22:53:07 |
| Version | 0.0 |
| SizeofData | 1112 |
| AddressOfRawData | 0xaa7588 |
| PointerToRawData | 0xaa5d88 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 22:53:07 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140aa7a00 |
|---|---|
| EndAddressOfRawData | 0x140aa8de8 |
| AddressOfIndex | 0x140fed608 |
| AddressOfCallbacks | 0x140840a48 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x00000001407EAD94
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140b1d700 |
| XOR Key | 0x15d50f1f |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 22 |
| 253 (35207) | 6 |
| ASM objects (35207) | 5 |
| C objects (35207) | 11 |
| C++ objects (33145) | 1 |
| C++ objects (35214) | 71 |
| Imports (35207) | 10 |
| C++ objects (35207) | 50 |
| C objects (33145) | 2 |
| Imports (33145) | 39 |
| C objects (35217) | 136 |
| C++ objects (34809) | 14 |
| C++ objects (30154) | 23 |
| Total imports | 577 |
| C++ objects (LTCG) (35217) | 1119 |
| Resource objects (35217) | 1 |
| 151 | 1 |
| Linker (35217) | 1 |
No comments yet.