8f3b300c9d80cfb02441b5f67b79b3d4bcc92e9ae1bf69d849170b2c4d3cf1d8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2017-Feb-24 08:09:28
TLS Callbacks 2 callback(s) detected.

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .xdata
Safe VirusTotal score: 0/72 (Scanned on 2025-08-07 21:33:56) All the AVs think this file is safe.

Hashes

MD5 fb149123f8ded79287807596f2f26cff
SHA1 177a55b37c75da79ef70b0658896def0a6691819
SHA256 8f3b300c9d80cfb02441b5f67b79b3d4bcc92e9ae1bf69d849170b2c4d3cf1d8
SHA3 81d573677bfdffda444bd5b017e514f89f91dd170facedc3abc0b26876be3f73
SSDeep 768:HiD9rlJvXGoD2FobvPLP8vjj6VSdFCmIHRSlx:CD9rfvXzDLbvPLErMSJIHRS
Imports Hash 9ae3f2eeb92954acf84d656bb9ad0601

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 11
TimeDateStamp 2017-Feb-24 08:09:28
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 2.0
SizeOfCode 0x6200
SizeOfInitializedData 0x3600
SizeOfUninitializedData 0x2200
AddressOfEntryPoint 0x0000000000001400 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x3b400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x14000
SizeOfHeaders 0x400
Checksum 0x1148c
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bb211013a1018d90a0c43cf26ff3da62
SHA1 97c121d0be636fb64a94616bb5611f18c6783574
SHA256 ac7271d92b2526120cfa52270240e226624c0066ed34e14819d985b545ce9e86
SHA3 e4fc23cb30aba3da3efda1ad832120b4f6146ddcd48f37dda7bc8db099a655f8
VirtualSize 0x6200
VirtualAddress 0x1000
SizeOfRawData 0x6200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.07196

.data

MD5 b79e925d7f5350304182110b8e1e8212
SHA1 de4170d87ff0359fe265e86e158f31fb2f88d392
SHA256 9dda2a763ee710b2e1785f5d7df67855525327949bbe2de331671d89575e8747
SHA3 0b369a67c4294e11914dad3b430b824426541450db8657b4966c750fbfb0f1bd
VirtualSize 0xa0
VirtualAddress 0x8000
SizeOfRawData 0x200
PointerToRawData 0x6600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.10313

.rdata

MD5 293d75b8c251b4ba407d36f2dfd54236
SHA1 9cc2312024e320c8397dda123171d427462a8cc2
SHA256 a45849a5955a0618cd1f1a4361586aebbe51c80c3d0f541239976f37936c1128
SHA3 75cd1263b964a094aaf904dd971e2a280e028c1723ebfdb4f3886bfa969196e0
VirtualSize 0x240
VirtualAddress 0x9000
SizeOfRawData 0x400
PointerToRawData 0x6800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.65906

.pdata

MD5 766823f61b128412fd16368f430cffcb
SHA1 7aa5785c4168b04af70739ffbdb0d3d2627fd843
SHA256 5e53ef077a8774125b120910db7e5303107d6b028dd1113d1e725d0f5a209ce0
SHA3 08068ed09cd18dafff6569128651edd8717ea2b6ce4f54b969f8b6f1ca356f20
VirtualSize 0xe40
VirtualAddress 0xa000
SizeOfRawData 0x1000
PointerToRawData 0x6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.84325

.xdata

MD5 6966310bb418751222a7fe11a6fc5df4
SHA1 4efcd391056ffcea51feec835199ae13de9664c2
SHA256 cbd1bbb834b7d872a05049ff85e303cb31bab496df8e7b73ff02c1ffe9b77452
SHA3 3c14cc38ddce0632f4ff81e47e275ee1cefe812cfb61d437cdd9d521eef625cd
VirtualSize 0x654
VirtualAddress 0xb000
SizeOfRawData 0x800
PointerToRawData 0x7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.14239

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x20f0
VirtualAddress 0xc000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.edata

MD5 1476cf058657bef9ada7055d57b6568a
SHA1 8bd0aa7302e56f82ab0d4ad394c8743875f1559e
SHA256 9a955cb3123c75b24bf1d7237d4f169b1a614516b5a2e6106b8693027b6e9020
SHA3 3ffd7c7d6bb6a7b8dc3230328c33621c11f70c1731b763113bbf26ed4f273767
VirtualSize 0x756
VirtualAddress 0xf000
SizeOfRawData 0x800
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84545

.idata

MD5 b1befbbf7c776da440d8fd1564f980c9
SHA1 2def0fbcaf12ea6396a7874feaf056c800803837
SHA256 c4f747512f37002cb4b990b12f52b1c718dcaa76aef1269cc26974586d250a3e
SHA3 33f375e253f347ec48d7b1f5da1ad2a7877d3aacf1759c13ea9cbf84eaadce20
VirtualSize 0x9d0
VirtualAddress 0x10000
SizeOfRawData 0xa00
PointerToRawData 0x8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.14625

.CRT

MD5 994f1f5543eee4ed3466833fccf100bb
SHA1 71f9f57d23ef8fae01350198f33172ff64643f78
SHA256 a7215629a0178a30a4e8082b16489d3ce68a70fbe36af0785cd8092f81af644e
SHA3 6108df9702d003ae289968d1e2c478b3e75d327c3818e0247bf0a39972ce8af1
VirtualSize 0x58
VirtualAddress 0x11000
SizeOfRawData 0x200
PointerToRawData 0x9600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.201539

.tls

MD5 0e5d9d70a70bde5d0fdc082ed74a48d0
SHA1 b32e394262a5b78e4946d3f64c565466fc323d7c
SHA256 afafcd5b19310930a08c75f6aea926281c4866838bd3152922a05e475ff87beb
SHA3 91ccd63affd0da2d1cb8a79302e62b8e1e0f5a87d6c475cfedc856911e3cab4d
VirtualSize 0x50
VirtualAddress 0x12000
SizeOfRawData 0x200
PointerToRawData 0x9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_2048BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_8BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.292898

.reloc

MD5 695856cb96b5eb8df59e1e0405016e16
SHA1 b2c4ab2a8f850c5ddbfdabcb2a47506691359fb9
SHA256 61fd33070dc028ed47a3d248238aeaa551c2092b5727e27865a078859e1d9341
SHA3 f669464438b4924aa457b589779efe0df5f59db645cc1d2ba88ad0a32e912dbe
VirtualSize 0x34
VirtualAddress 0x13000
SizeOfRawData 0x200
PointerToRawData 0x9a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_ALIGN_1024BYTES
IMAGE_SCN_ALIGN_16BYTES
IMAGE_SCN_ALIGN_1BYTES
IMAGE_SCN_ALIGN_256BYTES
IMAGE_SCN_ALIGN_2BYTES
IMAGE_SCN_ALIGN_32BYTES
IMAGE_SCN_ALIGN_4096BYTES
IMAGE_SCN_ALIGN_4BYTES
IMAGE_SCN_ALIGN_512BYTES
IMAGE_SCN_ALIGN_64BYTES
IMAGE_SCN_ALIGN_8192BYTES
IMAGE_SCN_ALIGN_MASK
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.541651

Imports

KERNEL32.dll CloseHandle
CreateDirectoryA
CreateFileA
DeleteCriticalSection
DeleteFileA
EnterCriticalSection
FindClose
FindFirstFileA
FindNextFileA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetFileSize
GetFileTime
GetLastError
GetModuleHandleA
GetPrivateProfileStringA
GetProcessHeap
GetSystemTimeAsFileTime
GetTickCount
HeapAlloc
HeapFree
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryExA
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
Sleep
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualProtect
VirtualQuery
WriteFile
lstrcatA
lstrcmpA
lstrcpyA
lstrlenA
msvcrt.dll __dllonexit
__iob_func
_amsg_exit
_atoi64
_initterm
_lock
_onexit
_unlock
abort
atoi
calloc
free
fwrite
malloc
memcpy
signal
strlen
strncmp
vfprintf
SHELL32.dll SHGetFolderPathA
USER32.dll wsprintfA

Delayed Imports

CreateInterface

Ordinal 1
Address 0x5be0

SteamAPI_GetHSteamPipe

Ordinal 2
Address 0x5b30

SteamAPI_GetHSteamUser

Ordinal 3
Address 0x5b20

SteamAPI_GetSteamInstallPath

Ordinal 4
Address 0x5ad0

SteamAPI_Init

Ordinal 5
Address 0x4700

SteamAPI_InitSafe

Ordinal 6
Address 0x57c0

SteamAPI_IsSteamRunning

Ordinal 7
Address 0x57e0

SteamAPI_RegisterCallResult

Ordinal 8
Address 0x5960

SteamAPI_RegisterCallback

Ordinal 9
Address 0x5890

SteamAPI_ReleaseCurrentThreadMemory

Ordinal 10
Address 0x5bb0

SteamAPI_RestartAppIfNecessary

Ordinal 11
Address 0x57a0

SteamAPI_RunCallbacks

Ordinal 12
Address 0x58a0

SteamAPI_SetBreakpadAppID

Ordinal 13
Address 0x5b50

SteamAPI_SetMiniDumpComment

Ordinal 14
Address 0x5930

SteamAPI_SetTryCatchCallbacks

Ordinal 15
Address 0x5af0

SteamAPI_Shutdown

Ordinal 16
Address 0x57b0

SteamAPI_UnregisterCallResult

Ordinal 17
Address 0x5950

SteamAPI_UnregisterCallback

Ordinal 18
Address 0x5880

SteamAPI_UseBreakpadCrashHandler

Ordinal 19
Address 0x5b80

SteamAPI_WriteMiniDump

Ordinal 20
Address 0x5940

SteamAppList

Ordinal 21
Address 0x5a90

SteamApps

Ordinal 22
Address 0x57f0

SteamClient

Ordinal 23
Address 0x5840

SteamController

Ordinal 24
Address 0x5a80

SteamFriends

Ordinal 25
Address 0x5830

SteamGameServer

Ordinal 26
Address 0x59c0

SteamGameServerNetworking

Ordinal 27
Address 0x59e0

SteamGameServerStats

Ordinal 28
Address 0x59f0

SteamGameServerUtils

Ordinal 29
Address 0x5a00

SteamGameServer_BSecure

Ordinal 30
Address 0x59d0

SteamGameServer_GetHSteamPipe

Ordinal 31
Address 0x5b00

SteamGameServer_GetHSteamUser

Ordinal 32
Address 0x5b70

SteamGameServer_GetSteamID

Ordinal 33
Address 0x5a30

SteamGameServer_Init

Ordinal 34
Address 0x59b0

SteamGameServer_InitSafe

Ordinal 35
Address 0x5b60

SteamGameServer_RunCallbacks

Ordinal 36
Address 0x5a20

SteamGameServer_Shutdown

Ordinal 37
Address 0x5a10

SteamHTTP

Ordinal 38
Address 0x5a40

SteamInternal_CreateInterface

Ordinal 39
Address 0x5bd0

SteamInternal_GameServer_Init

Ordinal 40
Address 0x5bc0

SteamMatchmaking

Ordinal 41
Address 0x5860

SteamMatchmakingServers

Ordinal 42
Address 0x59a0

SteamMusic

Ordinal 43
Address 0x5aa0

SteamMusicRemote

Ordinal 44
Address 0x5ab0

SteamNetworking

Ordinal 45
Address 0x5850

SteamRemoteStorage

Ordinal 46
Address 0x5800

SteamScreenshots

Ordinal 47
Address 0x5a50

SteamUGC

Ordinal 48
Address 0x5a60

SteamUnifiedMessages

Ordinal 49
Address 0x5a70

SteamUser

Ordinal 50
Address 0x5810

SteamUserStats

Ordinal 51
Address 0x5870

SteamUtils

Ordinal 52
Address 0x5820

Steam_GetHSteamUserCurrent

Ordinal 53
Address 0x5ac0

Steam_RegisterInterfaceFuncs

Ordinal 54
Address 0x5ae0

Steam_RunCallbacks

Ordinal 55
Address 0x5b40

VR_Init

Ordinal 56
Address 0x5ba0

VR_Shutdown

Ordinal 57
Address 0x5b90

g_pSteamClientGameServer

Ordinal 58
Address 0x5b10

Version Info

TLS Callbacks

StartAddressOfRawData 0x3b412040
EndAddressOfRawData 0x3b412048
AddressOfIndex 0x3b40d7cc
AddressOfCallbacks 0x3b411030
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks 0x000000003B405CF0
0x000000003B405CC0

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0!
Leave a comment

No comments yet.