| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2015-May-27 06:15:25 |
| Detected languages |
English - United States
Japanese - Japan |
| Debug artifacts |
D:\bhr2\svn\jenkins\BHR2\buildout\MasterRelease_NEXTWin32\rerev2.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to AES Uses constants related to Blowfish Uses constants related to DES |
| Suspicious | The PE is possibly packed. | Unusual section name found: .bind |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: CAPCOM Co.
Issuer: Symantec Class 3 SHA256 Code Signing CA |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-29 22:44:55) | All the AVs think this file is safe. |
| MD5 | cc4ef5ef37d7d7cea58e784cff3d5369 🔍 |
|---|---|
| SHA1 | 4e709709887bfa3c402212e7ce49c5007a277e5b 🔍 |
| SHA256 | 97651c493d41a21614478aecbd2f58cd340f183f82a793170c3dac169e4decce 🔍 |
| SHA3 | 172931486a6fa977f74e3d8f2ff2996b7564a32f6e81cd7be6f1dd713aee13cd 🔍 |
| SSDeep | 393216:ETM2ekecFq9nUy+aN3I5ReaArCnY6gAWt1LTZ75JvHO:ETTvFGqw3IZArCbgAWt1BC 🔍 |
| Imports Hash | 3620d71e0fdad3a590c07786a126b71a 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x158 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2015-May-27 06:15:25 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 11.0 |
| SizeOfCode | 0xe3c400 |
| SizeOfInitializedData | 0x3aa800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x011EA2F0 (Section: .bind) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xe3e000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x124d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x11bd509 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 2d6e3b2f0f4b672b155b4fb4869a69c5 🔍 |
|---|---|
| SHA1 | 502f8759eb322622e8ff6341a59229a28c89dc0f 🔍 |
| SHA256 | 4f7b959f5982486e8b8e4e55310894774017cae933499da1582285fb04a4c662 🔍 |
| SHA3 | 587be7e809ad01f80a44c34c4c2a28c7de42790c5b0a05845e460d6564a33c13 🔍 |
| VirtualSize | 0xe3c2eb |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xe3c400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 7.99999 |
| MD5 | 4964f8737db682b4fa2d16de422c0c9d 🔍 |
|---|---|
| SHA1 | 4a6c6048e02c194334933c04d9a1384700dcb16e 🔍 |
| SHA256 | 246664f3a80ab237da7365b95b328cac8e206914355028ca87e6e217028a1f9a 🔍 |
| SHA3 | 134b1c11699b8662729a9411d6a8eadad50f208114eaff15fee234e37a4e9c70 🔍 |
| VirtualSize | 0x21daec |
| VirtualAddress | 0xe3e000 |
| SizeOfRawData | 0x21dc00 |
| PointerToRawData | 0xe3c800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.1553 |
| MD5 | 79188f361242dbaa275192bfa1ecd33f 🔍 |
|---|---|
| SHA1 | 71f7340cc9fd17e50b3712d711a11a567016bbc7 🔍 |
| SHA256 | e1164d3bea2d2bb996ca9796f19929a88340b950fd63a692367ef48d90178f79 🔍 |
| SHA3 | 2e7c2f2af69b69ce422197e492c2fa02d5ceb87e2ebd48f18cc764eca3aca4d6 🔍 |
| VirtualSize | 0x18b6f8 |
| VirtualAddress | 0x105c000 |
| SizeOfRawData | 0xf4600 |
| PointerToRawData | 0x105a400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.56019 |
| MD5 | 3e90f7cf96668529c94ee9b75c456847 🔍 |
|---|---|
| SHA1 | e43587a39bef7faefea44862ec7b83cb41374194 🔍 |
| SHA256 | 1aeb963dc704c0f27f7e9f74eedd64894c42c218e1cbbbe4e89f26ec91e066f0 🔍 |
| SHA3 | 510be2cbce8c9513fb42a2dec994faded37304e3b2c8bc2b5d458c55df24a1fe 🔍 |
| VirtualSize | 0x1330 |
| VirtualAddress | 0x11e8000 |
| SizeOfRawData | 0x1400 |
| PointerToRawData | 0x114ea00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.68223 |
| MD5 | 3bdc78e18d209289297e4af08e4b6755 🔍 |
|---|---|
| SHA1 | 12c11d20bcc76291ce1ade7c220a197881797d01 🔍 |
| SHA256 | e116f78e5d0db25649c1f2140c1b2bd964efaf3b5271ee2bb361406c9fcd8a16 🔍 |
| SHA3 | 12af81b65e92714f50eeb407a927511deecc1bf467090dd6dbcc2da3ef9f869f 🔍 |
| VirtualSize | 0x62c10 |
| VirtualAddress | 0x11ea000 |
| SizeOfRawData | 0x62c10 |
| PointerToRawData | 0x114fe00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 7.99885 |
| KERNEL32.dll |
FindClose
SetEnvironmentVariableA CreateFileW WriteConsoleW GetStringTypeW LCMapStringW DeleteFileA GetCurrentThreadId CompareStringW OutputDebugStringW GetConsoleCP FlushFileBuffers SetStdHandle MoveFileExW DeleteFileW VirtualQuery LoadLibraryExW GetModuleHandleW TlsFree WriteFile TlsGetValue TlsAlloc SetUnhandledExceptionFilter ReadFile FreeEnvironmentStringsW GetEnvironmentStringsW QueryPerformanceCounter GetTimeZoneInformation SetLastError CreateEventA GetOEMCP GetACP IsValidCodePage HeapSize GetModuleFileNameW GetStartupInfoW InitializeCriticalSectionAndSpinCount GetFileType SetFilePointerEx ReadConsoleW GetConsoleMode IsDebuggerPresent HeapReAlloc RtlUnwind AreFileApisANSI GetModuleHandleExW GetSystemTimeAsFileTime DecodePointer EncodePointer IsProcessorFeaturePresent GetProcessHeap GetLastError TlsSetValue GetOverlappedResult HeapAlloc HeapFree FindFirstFileA CreateFileA CreateDirectoryA GetExitCodeThread CreateThread WaitForSingleObject CloseHandle InterlockedIncrement InterlockedDecrement WideCharToMultiByte GlobalFree GetModuleHandleA CreateProcessA TerminateProcess GetCurrentProcess GetStdHandle LoadLibraryW GetProcAddress FreeLibrary MultiByteToWideChar InterlockedExchange ResetEvent SetEvent SearchPathA GetUserDefaultLangID GetCPInfo DeleteCriticalSection InitializeCriticalSection LeaveCriticalSection UnhandledExceptionFilter EnterCriticalSection VirtualAlloc VirtualFree Sleep SetCurrentDirectoryA FileTimeToLocalFileTime FindNextFileA GetDiskFreeSpaceA GetFileAttributesA GetFileSize ReadFileEx RemoveDirectoryA SetEndOfFile SetFilePointer SleepEx GetModuleFileNameA CopyFileA MoveFileA FileTimeToSystemTime SetThreadPriority ResumeThread SetThreadIdealProcessor GlobalAlloc GlobalLock GlobalUnlock InterlockedExchangeAdd InterlockedCompareExchange GetCurrentDirectoryA GetPrivateProfileStringA WritePrivateProfileStringA VerSetConditionMask VerifyVersionInfoA RaiseException ReleaseSemaphore GetCurrentProcessId ExitProcess GetSystemInfo WaitForMultipleObjects CreateSemaphoreA ReleaseMutex CreateMutexA DebugBreak TryEnterCriticalSection GetCommandLineA QueryPerformanceFrequency |
|---|---|
| USER32.dll |
MessageBoxA
GetWindowThreadProcessId SetWindowTextW GetForegroundWindow LoadIconA IsIconic SendMessageA GetPropA DefWindowProcA SetWindowLongA GetSystemMetrics SetWindowPos LoadIconW LoadCursorA FindWindowW SetCursor ShowCursor AdjustWindowRect GetWindowRect RemovePropA SetPropA EndPaint BeginPaint UpdateWindow DeleteMenu EnableMenuItem GetSystemMenu LoadAcceleratorsA ShowWindow DestroyWindow CreateWindowExW CreateWindowExA RegisterClassExW RegisterClassExA PostQuitMessage DefWindowProcW SendMessageW PeekMessageA DispatchMessageW TranslateMessage ScreenToClient ClientToScreen ClipCursor GetCursorPos GetClientRect SystemParametersInfoA CloseClipboard SetClipboardData EmptyClipboard RegisterHotKey UnregisterHotKey GetAsyncKeyState |
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyExA RegCloseKey |
| PSAPI.DLL |
GetModuleFileNameExA
|
| d3dx9_43.dll |
D3DXSaveTextureToFileInMemory
D3DXGetShaderConstantTableEx D3DXGetShaderOutputSemantics |
| d3d9.dll |
Direct3DCreate9
D3DPERF_GetStatus D3DPERF_SetOptions |
| DINPUT8.dll |
DirectInput8Create
|
| XINPUT1_3.dll |
#5
#4 #3 #2 |
| steam_api.dll |
SteamAPI_IsSteamRunning
SteamMatchmaking SteamAPI_UnregisterCallback SteamAPI_RegisterCallResult SteamAPI_UnregisterCallResult SteamNetworking SteamFriends SteamUtils SteamApps SteamUser SteamRemoteStorage SteamUserStats SteamAPI_RegisterCallback SteamAPI_Shutdown SteamAPI_Init SteamAPI_RunCallbacks SteamHTTP |
| WS2_32.dll |
send
select setsockopt listen htons htonl socket WSAStartup WSACleanup ioctlsocket recv closesocket bind WSAGetLastError sendto recvfrom getsockopt connect __WSAFDIsSet accept getsockname |
| IPHLPAPI.DLL |
GetIfEntry
GetAdaptersAddresses |
| MSVFW32.dll |
ICCompressorFree
ICCompressorChoose |
| AVIFIL32.dll |
AVIStreamRelease
AVIStreamSetFormat AVIFileOpenA AVIFileRelease AVIFileExit AVIFileInit AVIStreamWrite AVIMakeCompressedStream AVIFileCreateStreamA |
| WINMM.dll |
timeGetTime
timeEndPeriod timeBeginPeriod |
| WMVCore.DLL |
WMCreateSyncReader
WMCreateProfileManager WMCreateWriter |
| gdiplus.dll |
GdipAlloc
GdipGetImageEncoders GdipGetImageEncodersSize GdipSaveImageToFile GdipDisposeImage GdipCloneImage GdipLoadImageFromFile GdiplusShutdown GdiplusStartup GdipFree |
| IMM32.dll |
ImmGetDefaultIMEWnd
ImmDisableIME ImmGetContext ImmReleaseContext ImmGetCompositionStringA |
| GDI32.dll |
GetStockObject
|
| SHELL32.dll |
SHGetFolderPathA
DragAcceptFiles |
| ole32.dll |
CoTaskMemFree
CoInitialize CoUninitialize CoCreateInstance CoSetProxyBlanket CoTaskMemAlloc |
| OLEAUT32.dll |
SysAllocString
SysFreeString |
| Type |
RT_ICON
|
|---|---|
| Language | Japanese - Japan |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.69113 |
| MD5 | 17005aa91c3cc3dea3925a7f616895f0 🔍 |
| SHA1 | 0d125353a42cee0c4f2861654c18a3ae51c5ba98 🔍 |
| SHA256 | 174251c2d8e9aa5d492280a6846f456f008df4592cd636d5e9fcd54bf4514ed2 🔍 |
| SHA3 | 2433f6eb206bb6b167bc5537328394c22c1064aace81c033f0d4a7226d5c6cac 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | Japanese - Japan |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.7815 |
| Detected Filetype | Icon file |
| MD5 | 3c68f77c35c26ff079a1c410ee44fa62 🔍 |
| SHA1 | 0b40150c95fc2c6414c90d44ee78b8d8814b3393 🔍 |
| SHA256 | a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0 🔍 |
| SHA3 | 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2015-May-27 06:15:25 |
| Version | 0.0 |
| SizeofData | 93 |
| AddressOfRawData | 0x1059730 |
| PointerToRawData | 0x1057f30 |
| Referenced File | D:\bhr2\svn\jenkins\BHR2\buildout\MasterRelease_NEXTWin32\rerev2.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2015-May-27 06:15:25 |
| Version | 0.0 |
| SizeofData | 16 |
| AddressOfRawData | 0x1059790 |
| PointerToRawData | 0x1057f90 |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x154f118 |
| SEHandlerTable | 0x1459aa0 |
| SEHandlerCount | 4 |
No comments yet.