| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-10 20:04:36 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
magic_cheats.pdb
|
| CompanyName | magiccheats |
| FileDescription | Magic Cheats |
| FileVersion | 0.3.0 |
| ProductName | Magic Cheats |
| ProductVersion | 0.3.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/70 (Scanned on 2026-08-12 10:57:36) | Trapmine: malicious.moderate.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-10 20:04:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x472400 |
| SizeOfInitializedData | 0x203600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000045DFF8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x67a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| ntdll.dll |
NtOpenFile
NtCreateNamedPipeFile NtReadFile RtlNtStatusToDosError NtWriteFile RtlGetVersion |
| kernel32.dll |
WideCharToMultiByte
ReleaseMutex WaitForSingleObject LoadLibraryExA MultiByteToWideChar HeapAlloc GetCurrentProcess SleepEx FormatMessageW ExitProcess CompareStringOrdinal GetSystemDirectoryW GetWindowsDirectoryW GetModuleFileNameW DuplicateHandle WaitForMultipleObjects GetExitCodeProcess SetWaitableTimer WaitForSingleObjectEx SetThreadStackGuarantee GetCurrentThread GetProcessHeap HeapFree HeapReAlloc RtlLookupFunctionEntry SetLastError SwitchToThread GetModuleHandleA Sleep TerminateProcess GetCurrentThreadId GetProcAddress GetModuleHandleW LoadLibraryW CloseHandle GetLastError GetUserDefaultUILanguage LCIDToLocaleName LocalFree GetSystemTimePreciseAsFileTime ReleaseSRWLockExclusive AcquireSRWLockExclusive GlobalLock GlobalSize FreeLibrary WakeAllConditionVariable OutputDebugStringA SleepConditionVariableSRW GlobalUnlock GetSystemTimeAsFileTime FindNextFileW GetTempPathW IsDebuggerPresent GetFileAttributesW GetFileInformationByHandleEx GetFileInformationByHandle FindFirstFileExW SetFileTime GetFullPathNameW WriteConsoleW GetConsoleOutputCP GetConsoleMode GetStdHandle FindClose SetFileInformationByHandle DeleteFileW GetFinalPathNameByHandleW CreateEventW GetCurrentProcessId OutputDebugStringW IsProcessorFeaturePresent LoadLibraryA lstrlenW LoadLibraryExW GetSystemInfo |
| user32.dll |
GetActiveWindow
SetCapture ScreenToClient GetKeyState GetAsyncKeyState SetCursor LoadCursorW UpdateWindow InvalidateRect SetCursorPos GetForegroundWindow FlashWindowEx IsWindowEnabled EnableWindow IsIconic IsWindowVisible ClipCursor GetClipCursor SendInput ShowWindow PostQuitMessage ShowCursor IsProcessDPIAware GetDC MonitorFromWindow GetTouchInputInfo SetForegroundWindow ClientToScreen GetCursorPos AppendMenuW InsertMenuW CheckMenuItem CreateAcceleratorTableW DestroyAcceleratorTable VkKeyScanW SetMenuItemInfoW EnableMenuItem DrawMenuBar CreatePopupMenu CreateMenu SetWindowLongW GetSystemMenu GetMonitorInfoW GetSystemMetrics SetMenu GetMenu GetWindowLongW GetClipboardData OpenClipboard KillTimer TrackMouseEvent SystemParametersInfoW IsWindow TrackPopupMenu CloseTouchInputHandle RegisterTouchWindow EnumChildWindows InvalidateRgn GetWindowPlacement DispatchMessageA GetMessageA SetWindowPos RegisterClassExW FindWindowExW TranslateAcceleratorW PostMessageW MsgWaitForMultipleObjectsEx SetWindowPlacement ChangeDisplaySettingsExW RegisterWindowMessageA SetWindowLongPtrW SetPropW MonitorFromRect ChangeWindowMessageFilterEx CreateWindowExW RegisterClassW GetMenuItemInfoW SendMessageW GetParent DispatchMessageW TranslateMessage GetMessageW DefWindowProcW MapVirtualKeyW GetUpdateRect PeekMessageW PostThreadMessageW ValidateRect SetParent GetRawInputData DestroyWindow GetWindowLongPtrW SetFocus SetWindowTextW RedrawWindow AdjustWindowRect EnumDisplayMonitors MonitorFromPoint GetWindowTextW GetWindowTextLengthW SetWindowDisplayAffinity GetWindow DestroyMenu CloseClipboard ReleaseCapture SetWindowRgn ToUnicodeEx GetKeyboardLayout MapVirtualKeyExW GetKeyboardState ReleaseDC SetTimer SystemParametersInfoA DestroyIcon CreateIcon AdjustWindowRectEx DrawTextW FillRect GetWindowDC OffsetRect GetWindowRect MapWindowPoints GetClientRect GetMenuBarInfo RemoveMenu DrawIconEx RegisterRawInputDevices |
| shell32.dll |
Shell_NotifyIconGetRect
Shell_NotifyIconW SHAppBarMessage SHGetKnownFolderPath ShellExecuteW DragQueryFileW DragFinish |
| ole32.dll |
CoIncrementMTAUsage
RegisterDragDrop CoTaskMemAlloc CoCreateFreeThreadedMarshaler RevokeDragDrop CoUninitialize OleInitialize CoInitializeEx CoCreateInstance CoTaskMemFree |
| comctl32.dll |
TaskDialogIndirect
DefSubclassProc SetWindowSubclass RemoveWindowSubclass |
| oleaut32.dll |
SysStringLen
GetErrorInfo SysFreeString SetErrorInfo |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WakeByAddressAll WaitOnAddress |
| advapi32.dll |
EventRegister
EventSetInformation EventWriteTransfer EventUnregister RegGetValueW RegSetValueExW RegCloseKey RegQueryValueExW RegOpenKeyExW |
| dwmapi.dll |
DwmSetWindowAttribute
DwmEnableBlurBehindWindow DwmGetWindowAttribute |
| shlwapi.dll |
SHCreateMemStream
|
| gdi32.dll |
BitBlt
CreateSolidBrush CombineRgn GetDeviceCaps DeleteObject CreateCompatibleDC SelectObject SetBkMode DeleteDC CreateRectRgn SetTextColor CreateDIBSection |
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| KERNEL32.dll |
SetUnhandledExceptionFilter
UnhandledExceptionFilter InitializeSListHead CreateWaitableTimerExW CreateProcessW FreeEnvironmentStringsW GetEnvironmentStringsW ReadFile GetOverlappedResult AddVectoredExceptionHandler SetEnvironmentVariableW GetCommandLineW RtlCaptureContext RtlVirtualUnwind GetCurrentDirectoryW CreateMutexA GetEnvironmentVariableW ReadFileEx WriteFileEx QueryPerformanceFrequency QueryPerformanceCounter CreateThread CreateFileW CreateDirectoryW CancelIo |
| crypt32.dll |
CryptProtectData
|
| VCRUNTIME140.dll |
__current_exception_context
__current_exception __C_specific_handler _purecall __std_exception_copy memcmp wcsrchr _CxxThrowException __std_exception_destroy memset memcpy __CxxFrameHandler3 memmove |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
trunc floor roundf round pow fmod |
| api-ms-win-crt-string-l1-1-0.dll |
wcslen
_wcsicmp wcscmp |
| api-ms-win-crt-convert-l1-1-0.dll |
_ultow_s
wcstol _wtoi |
| api-ms-win-crt-runtime-l1-1-0.dll |
_exit
_seh_filter_exe __p___argc __p___argv _cexit _initterm_e _register_thread_local_exe_atexit_callback _initterm _get_initial_narrow_environment exit _initialize_onexit_table _register_onexit_function _crt_atexit terminate _initialize_narrow_environment _configure_narrow_argv _set_app_type _c_exit |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free malloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.3.0.0 |
| ProductVersion | 0.3.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | magiccheats |
| FileDescription | Magic Cheats |
| FileVersion (#2) | 0.3.0 |
| ProductName | Magic Cheats |
| ProductVersion (#2) | 0.3.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-10 20:04:36 |
| Version | 0.0 |
| SizeofData | 41 |
| AddressOfRawData | 0x526854 |
| PointerToRawData | 0x525054 |
| Referenced File | magic_cheats.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-10 20:04:36 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x526880 |
| PointerToRawData | 0x525080 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-10 20:04:36 |
| Version | 0.0 |
| SizeofData | 1008 |
| AddressOfRawData | 0x526894 |
| PointerToRawData | 0x525094 |
| StartAddressOfRawData | 0x140526ca8 |
|---|---|
| EndAddressOfRawData | 0x140526e54 |
| AddressOfIndex | 0x14062bdf4 |
| AddressOfCallbacks | 0x140474bf8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014039A1E0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1406298c0 |
| XOR Key | 0xe50bbc51 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| Imports (34321) | 4 |
| ASM objects (34321) | 4 |
| C objects (34321) | 10 |
| C++ objects (34321) | 30 |
| Imports (30795) | 3 |
| Total imports | 346 |
| Unmarked objects (#2) | 52 |
| Resource objects (34435) | 1 |
| Linker (34435) | 1 |
No comments yet.