| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-20 01:20:25 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\kazim\Desktop\GG Emu\build\loader.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to AES
Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 30/70 (Scanned on 2026-08-20 16:50:15) |
ALYac:
Generic.Dacic.21894.03467B04
APEX: Malicious AVG: FileRepMalware [Misc] Arcabit: Generic.Dacic.21894.03467B04 Avast: FileRepMalware [Misc] BitDefender: Generic.Dacic.21894.03467B04 Bkav: W32.Malware.187B31E1 CTX: exe.trojan.dacic CrowdStrike: win/malicious_confidence_90% (D) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: Win64/GameHack.AAO potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Generic.Dacic.21894.03467B04 (B) GData: Generic.Dacic.21894.03467B04 Google: Detected K7GW: Unwanted-Program ( 006e45b61 ) Lionic: Trojan.Win32.Dacic.4!c Malwarebytes: Generic.Malware/Suspicious McAfeeD: ti!902F12D9DEEA MicroWorld-eScan: Generic.Dacic.21894.03467B04 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml SentinelOne: Static AI - Malicious PE Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!649F422C2D92 TrendMicro-HouseCall: TROJ_GEN.R002H09HK26 VIPRE: Generic.Dacic.21894.03467B04 Varist: W64/ABApplication.FQVK-1318 |
| MD5 | 649f422c2d9234aa4e2695669651cd25 🔍 |
|---|---|
| SHA1 | 5e46e8835f0e522624e47d344b0d9165b578a6a3 🔍 |
| SHA256 | 902f12d9deea71d6e11b770bac772c2e66d1f9791b6ce0fbd8dbc3ee2f521103 🔍 |
| SHA3 | e90fb7af42f14ca585fde157b92c4759c480628df69fe5ed959752e009938ec9 🔍 |
| SSDeep | 12288:QK8W6uGSz7PfXEWshqc2DbwMt3S6weB5ImwS/Ui+n8EK:QK8Wue7PfI92QMt31w65lwS/Ui+nXK 🔍 |
| Imports Hash | a26d736d50167e35d1442a8425440361 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-20 01:20:25 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x82800 |
| SizeOfInitializedData | 0x2b400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000007D7D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | fee54865701e49b4d8a3b69e6ec34cf0 🔍 |
|---|---|
| SHA1 | e0a2f9b5c798356ea7e6bc23778b6a4b127d3e5d 🔍 |
| SHA256 | 08b51496392c1782ba594258b8c939bc6069ad3d6f497ece2daa3f038f753314 🔍 |
| SHA3 | 8a47d92bccec227402743c63c6a16deaac1ef90f5372b2fb0fbd1916f3f5242c 🔍 |
| VirtualSize | 0x82703 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x82800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.48154 |
| MD5 | 0c0dee607df9d6b448f9d58c5f096a12 🔍 |
|---|---|
| SHA1 | c371a345a5114f029fd55a0a5f581c7db315238e 🔍 |
| SHA256 | cee08f55a6e084bac9d59ef153b7e39c36bf985f07605f876f06920b604668dd 🔍 |
| SHA3 | 6e5fab6bef8bf2a9f56d52cc22f8f0c127af112783499575b65d7592a29c606a 🔍 |
| VirtualSize | 0x2162a |
| VirtualAddress | 0x84000 |
| SizeOfRawData | 0x21800 |
| PointerToRawData | 0x82c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.02689 |
| MD5 | e3c569a0c7972d4ded9a79bf5b69a0f1 🔍 |
|---|---|
| SHA1 | 5bef35e4533b42075b77e9b18e4612d274028e78 🔍 |
| SHA256 | 284cf90e50f77c87b9175d929be8be835a51161e844a984c517e0d3e23fd8ae5 🔍 |
| SHA3 | c548aeef3114eea12e9fb7a5b37f0703321f9c76fd433b2371f0e5c2b96a951c 🔍 |
| VirtualSize | 0x2988 |
| VirtualAddress | 0xa6000 |
| SizeOfRawData | 0x1800 |
| PointerToRawData | 0xa4400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.2166 |
| MD5 | 0aee504f388bb94f1abc4f00ff564c0e 🔍 |
|---|---|
| SHA1 | c29ee69533143a3e7c2c038ff9099702aba7f036 🔍 |
| SHA256 | 66257963bf8464f66cb6cc322e34347c3d1256a585a9fb0fba4d426cb97abdc4 🔍 |
| SHA3 | 97efc410f4d8ad6563c47521def0d665c6e92d81f5cb09651f53b6985d0defe1 🔍 |
| VirtualSize | 0x5a00 |
| VirtualAddress | 0xa9000 |
| SizeOfRawData | 0x5a00 |
| PointerToRawData | 0xa5c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.94143 |
| MD5 | 44411dbe48a5a8b23e29748dfe0f9a24 🔍 |
|---|---|
| SHA1 | e3b9a52c4f21fd809df6e5c08da55127d7d2d4c3 🔍 |
| SHA256 | ed1f69eb65bca072f43639d2930f51eefec03b7f00dbf346c9a989586aa924a7 🔍 |
| SHA3 | 4a9e826f06d057536b45fdda7179fd50a80d3f75f642ec62782836b80657a714 🔍 |
| VirtualSize | 0x1190 |
| VirtualAddress | 0xaf000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0xab600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.33156 |
| MD5 | 50adc15ecb1bed6256c0ebbe2e69e38c 🔍 |
|---|---|
| SHA1 | 51beab33bcabb997e6199b837ad5ae8ade13953d 🔍 |
| SHA256 | c9cb89173105064184402787b4c47c9e1994f4eff5dac337c5cfb6e83f566f3e 🔍 |
| SHA3 | 5e4f05d8fa019c8b7789c88d10c3771b63cc3409dbe05bd930f48e503ac67448 🔍 |
| VirtualSize | 0x5d8 |
| VirtualAddress | 0xb1000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0xac800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.34334 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| KERNEL32.dll |
Process32FirstW
CloseHandle LoadResource FindResourceW FillConsoleOutputAttribute Beep GetProcAddress SetFilePointerEx CreateFileMappingA LocalFree GetCurrentProcessId GetModuleHandleW FreeLibrary GetConsoleWindow CreateProcessA GetSystemTimeAsFileTime SetConsoleCursorPosition QueryPerformanceCounter GetTickCount SetConsoleTitleW ConnectNamedPipe FlushFileBuffers GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte QueryPerformanceFrequency GetLocaleInfoA OpenProcess CreateFileA GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose GetLocaleInfoEx FormatMessageA AreFileApisANSI GetFileInformationByHandleEx Process32NextW GetLastError DeleteFileW LockResource LoadLibraryA GlobalUnlock FileTimeToSystemTime InitOnceComplete InitOnceBeginInitialize ReleaseSRWLockExclusive GetModuleHandleA DuplicateHandle CreateFileW AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry GetTickCount64 Sleep MultiByteToWideChar WaitForSingleObject CreateMutexA GetEnvironmentVariableA GetTempPathW SetSystemTime CreateNamedPipeW TerminateProcess OutputDebugStringA WriteFile GetStdHandle GetCurrentProcess SetConsoleTextAttribute GetConsoleScreenBufferInfo GetFileSizeEx SetConsoleCtrlHandler SizeofResource FillConsoleOutputCharacterA ReadFile CreateToolhelp32Snapshot RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetCurrentThreadId InitializeSListHead SetFileInformationByHandle |
| USER32.dll |
ScreenToClient
GetCapture ClientToScreen GetMessageExtraInfo PeekMessageW DispatchMessageW RegisterClassExW UnregisterClassW GetKeyState SetWindowPos DestroyWindow GetWindowRect PostMessageW DefWindowProcW SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard SetCursorPos ReleaseCapture IsWindowUnicode GetClientRect SetCursor SetCapture LoadCursorW GetForegroundWindow GetKeyboardLayout TrackMouseEvent TranslateMessage PostQuitMessage UpdateWindow IsIconic GetCursorPos ShowWindow GetAsyncKeyState CreateWindowExW |
| ADVAPI32.dll |
CryptCreateHash
LookupPrivilegeValueW AdjustTokenPrivileges CryptAcquireContextW QueryServiceStatus CloseServiceHandle OpenSCManagerW ControlService CryptReleaseContext CryptHashData CryptDestroyHash OpenProcessToken OpenServiceW CryptGetHashParam QueryServiceStatusEx |
| SHELL32.dll |
ShellExecuteA
ShellExecuteExW |
| bcrypt.dll |
BCryptEncrypt
BCryptDestroyKey BCryptGetProperty BCryptFinalizeKeyPair BCryptDecrypt BCryptGenerateSymmetricKey BCryptCreateHash BCryptSetProperty BCryptHashData BCryptImportKeyPair BCryptDestroyHash BCryptCloseAlgorithmProvider BCryptFinishHash BCryptExportKey BCryptGenRandom BCryptOpenAlgorithmProvider BCryptGenerateKeyPair |
| CRYPT32.dll |
CryptDecodeObjectEx
CryptStringToBinaryA CryptBinaryToStringA CryptImportPublicKeyInfoEx2 |
| MSVCP140.dll |
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??Bios_base@std@@QEBA_NXZ ??7ios_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ??1facet@locale@std@@MEAA@XZ ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?_Incref@facet@locale@std@@UEAAXXZ ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z _Cnd_broadcast ??0facet@locale@std@@IEAA@_K@Z ?tolower@?$ctype@D@std@@QEBADD@Z _Strxfrm _Query_perf_frequency ??1_Lockit@std@@QEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Throw_Cpp_error@std@@YAXH@Z ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Xbad_alloc@std@@YAXXZ ?_Id_cnt@id@locale@std@@0HA ?_Xout_of_range@std@@YAXPEBD@Z ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?_Winerror_map@std@@YAHH@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ?id@?$ctype@D@std@@2V0locale@2@A ?_Xlength_error@std@@YAXPEBD@Z ?id@?$collate@D@std@@2V0locale@2@A ?_Syserror_map@std@@YAPEBDH@Z _Mtx_lock _Strcoll _Cnd_do_broadcast_at_thread_exit _Cnd_wait _Thrd_id _Query_perf_counter _Thrd_detach _Xtime_get_ticks _Thrd_join _Mtx_unlock ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@PEBD3@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@V?$fpos@U_Mbstatet@@@2@@Z |
| WINHTTP.dll |
WinHttpOpen
WinHttpQueryHeaders WinHttpReadData WinHttpReceiveResponse WinHttpSetOption WinHttpCloseHandle WinHttpConnect WinHttpQueryDataAvailable WinHttpSendRequest WinHttpOpenRequest WinHttpSetTimeouts |
| WININET.dll |
HttpSendRequestA
InternetConnectA InternetCloseHandle InternetOpenA HttpQueryInfoA InternetQueryOptionA InternetReadFile HttpOpenRequestA InternetSetOptionA HttpAddRequestHeadersA |
| WS2_32.dll |
htons
recv connect socket send WSAStartup inet_pton closesocket setsockopt |
| Secur32.dll |
DecryptMessage
FreeCredentialsHandle QueryContextAttributesW EncryptMessage AcquireCredentialsHandleW InitializeSecurityContextW DeleteSecurityContext FreeContextBuffer |
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memset
_CxxThrowException memcpy memchr memcmp strstr strchr __std_terminate __std_exception_copy memmove __std_exception_destroy __current_exception_context __C_specific_handler __current_exception |
| api-ms-win-crt-runtime-l1-1-0.dll |
_invoke_watson
__p___argv abort __p___argc _exit exit _c_exit _initterm_e _beginthreadex system _initterm _get_initial_narrow_environment terminate _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _register_thread_local_exe_atexit_callback |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vswprintf_s
__acrt_iob_func __stdio_common_vsscanf _wfopen _set_fmode fflush fseek ftell fclose __p__commode _fseeki64 __stdio_common_vsprintf_s fgetc __stdio_common_vfprintf fwrite __stdio_common_vsprintf _get_stream_buffer_pointers fgetpos fread fsetpos ungetc setvbuf fputc |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc realloc _set_new_mode free |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
_wcsicmp _stricmp strcmp |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
|
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| api-ms-win-crt-convert-l1-1-0.dll |
atoi
|
| api-ms-win-crt-math-l1-1-0.dll |
sinf
acosf cosf fmodf ceilf sqrtf __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xb2 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.38467 |
| MD5 | 6651c7406d46d245125b2223c11e3cd5 🔍 |
| SHA1 | b054c1a0ecbad483bcd6a67c72f910611f37c1ec 🔍 |
| SHA256 | bf07c955bc792bc9ed9e669a24ae8591dcc85559c676d22558464ea94116c5e9 🔍 |
| SHA3 | 236c5b2f3fa0a1493ed454f9d74273fea90b69fe99d01a70ed5659c633c2ec07 🔍 |
| Type |
RT_RCDATA
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xe88 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.24092 |
| MD5 | ffb5ba2f59ba1036b67a5a8586efaf90 🔍 |
| SHA1 | 24ce311c1f9b0f1301f79a87807735452fea3c3e 🔍 |
| SHA256 | ea644d162f38bddf473c8e80c1a2cc70ea53d71cfd9f163aa1a6bb4c2d7389df 🔍 |
| SHA3 | 502e05f2b3a1f0dc5792f0d294d0e0937fca19476944b9e8c3bb8114d9e94ee5 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 01:20:25 |
| Version | 0.0 |
| SizeofData | 71 |
| AddressOfRawData | 0x96270 |
| PointerToRawData | 0x94e70 |
| Referenced File | C:\Users\kazim\Desktop\GG Emu\build\loader.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 01:20:25 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x962b8 |
| PointerToRawData | 0x94eb8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 01:20:25 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x962cc |
| PointerToRawData | 0x94ecc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-20 01:20:25 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140096680 |
|---|---|
| EndAddressOfRawData | 0x140096688 |
| AddressOfIndex | 0x1400a7c80 |
| AddressOfCallbacks | 0x140084ed0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400a6040 |
| XOR Key | 0xe1798b17 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| C objects (35207) | 10 |
| C objects (33145) | 1 |
| C++ objects (35207) | 43 |
| ASM objects (35207) | 6 |
| Imports (35207) | 6 |
| Imports (33145) | 35 |
| Total imports | 495 |
| C++ objects (LTCG) (35228) | 16 |
| Resource objects (35228) | 1 |
| 151 | 1 |
| Linker (35228) | 1 |
No comments yet.