| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2026-Mar-03 14:46:47 |
| Detected languages |
English - United States
|
| Debug artifacts |
denuvo-anti-cheat.pdb
|
| Comments | Denuvo Anti-Cheat Driver v6.13 |
| CompanyName | Denuvo GmbH |
| FileDescription | Denuvo Anti-Cheat Driver |
| FileVersion | 6.13.2.9798 |
| InternalName | Denuvo Anti-Cheat Driver |
| LegalCopyright | © Denuvo GmbH. All rights reserved. |
| OriginalFilename | denuvo-anti-cheat.sys |
| ProductName | Denuvo Anti-Cheat Driver |
| ProductVersion | 6.13.2.9798 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to AES |
| Suspicious | The PE is possibly packed. |
Unusual section name found: PAGE
Unusual section name found: Unusual section name found: Unusual section name found: Unusual section name found: |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Windows Hardware Compatibility Publisher
Issuer: Microsoft Windows Third Party Component CA 2014 |
| Safe | VirusTotal score: 0/69 (Scanned on 2026-06-16 17:27:51) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 16 |
| TimeDateStamp | 2026-Mar-03 14:46:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x4f5a00 |
| SizeOfInitializedData | 0xc000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001184 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | A.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x507000 |
| SizeOfHeaders | 0x600 |
| Checksum | 0x4ae21d |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WDFLDR.SYS |
WdfVersionBindClass
WdfVersionUnbindClass WdfVersionBind WdfVersionUnbind |
|---|---|
| ntoskrnl.exe |
KdRefreshDebuggerNotPresent
ZwOpenProcess RtlConvertSidToUnicodeString ZwOpenProcessTokenEx ZwQueryInformationToken KdDebuggerEnabled KeInitializeMutex KeReleaseMutex KeAcquireSpinLockRaiseToDpc KeReleaseSpinLock ExAcquireFastMutex ExReleaseFastMutex ExUuidCreate RtlRandomEx RtlInitUnicodeString RtlQueryRegistryValues RtlWriteRegistryValue RtlCreateRegistryKey ZwCreateFile ZwWriteFile ZwFlushBuffersFile towlower RtlGUIDFromString IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice IoDeleteSymbolicLink PsGetCurrentProcessId RtlDowncaseUnicodeChar RtlUnicodeToUTF8N KeDeregisterBugCheckReasonCallback KeRegisterBugCheckReasonCallback ExCreateCallback ExRegisterCallback ExUnregisterCallback MmIsAddressValid IoGetStackLimits ObOpenObjectByPointer DbgPrintEx KeBugCheckEx memchr RtlInitAnsiString PsGetProcessCreateTimeQuadPart RtlFreeUnicodeString KeDelayExecutionThread MmMapIoSpace MmUnmapIoSpace KeQueryActiveProcessorCountEx ZwOpenFile ZwQueryInformationFile ZwReadFile MmGetPhysicalAddress KeStackAttachProcess KeUnstackDetachProcess PsGetProcessSectionBaseAddress RtlPcToFileHeader KeEnterCriticalRegion KeLeaveCriticalRegion ExAcquireResourceSharedLite ExReleaseResourceLite MmLockPagableDataSection MmUnlockPagableImageSection PsGetProcessId PsGetThreadProcessId PsGetThreadProcess PsProcessType PsThreadType ExInitializeResourceLite ExAcquireResourceExclusiveLite ExDeleteResourceLite SeLocateProcessImageName IoFileObjectType ExAcquireSpinLockExclusive ExReleaseSpinLockExclusive IoFreeIrp ObRegisterCallbacks ObUnRegisterCallbacks PsSetCreateProcessNotifyRoutineEx PsSetLoadImageNotifyRoutine PsRemoveLoadImageNotifyRoutine IoGetInitialStack PsGetCurrentThreadTeb ZwQueryVirtualMemory ZwDeviceIoControlFile IoAllocateIrp IoReuseIrp MmBuildMdlForNonPagedPool IoAllocateMdl IoFreeMdl RtlCopyUnicodeString ZwQuerySystemInformation ObfDereferenceObject RtlTimeToTimeFields KeGetCurrentProcessorNumberEx KeSetSystemAffinityThreadEx KeRevertToUserAffinityThreadEx KfRaiseIrql KeLowerIrql RtlCheckRegistryKey KeSetEvent KeInitializeEvent ZwClose ObReferenceObjectByHandle PsTerminateSystemThread PsCreateSystemThread KeWaitForSingleObject KeSetPriorityThread ExFreePoolWithTag ExAllocatePoolWithTag IoGetCurrentProcess RtlGetEnabledExtendedFeatures KeRestoreExtendedProcessorState KeSaveExtendedProcessorState __C_specific_handler __chkstk RtlGetVersion MmGetSystemRoutineAddress _purecall PsLookupProcessByProcessId RtlAnsiStringToUnicodeString RtlUnicodeToMultiByteN RtlAnsiCharToUnicodeChar PsGetVersion ExAllocatePoolWithQuotaTag |
| HAL.dll |
KeQueryPerformanceCounter
|
| NETIO.SYS |
WskRegister
WskCaptureProviderNPI WskDeregister WskReleaseProviderNPI |
| cng.sys |
BCryptVerifySignature
BCryptDestroyKey BCryptImportKeyPair BCryptDestroyHash BCryptFinishHash BCryptHashData BCryptCreateHash BCryptGetProperty BCryptCloseAlgorithmProvider BCryptSetProperty BCryptOpenAlgorithmProvider BCryptGenRandom |
| FLTMGR.SYS |
FltCreateFile
FltGetFileNameInformation FltReleaseFileNameInformation FltClose FltReadFile FltStartFiltering FltUnregisterFilter FltRegisterFilter FltQueryInformationFile |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.13.2.9798 |
| ProductVersion | 6.13.2.9798 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | Denuvo Anti-Cheat Driver v6.13 |
| CompanyName | Denuvo GmbH |
| FileDescription | Denuvo Anti-Cheat Driver |
| FileVersion (#2) | 6.13.2.9798 |
| InternalName | Denuvo Anti-Cheat Driver |
| LegalCopyright | © Denuvo GmbH. All rights reserved. |
| OriginalFilename | denuvo-anti-cheat.sys |
| ProductName | Denuvo Anti-Cheat Driver |
| ProductVersion (#2) | 6.13.2.9798 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-03 14:46:47 |
| Version | 0.0 |
| SizeofData | 142 |
| AddressOfRawData | 0x4f9050 |
| PointerToRawData | 0x494050 |
| Referenced File | denuvo-anti-cheat.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-03 14:46:47 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xeecac |
| PointerToRawData | 0xedeac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-03 14:46:47 |
| Version | 0.0 |
| SizeofData | 584 |
| AddressOfRawData | 0xeecc0 |
| PointerToRawData | 0xedec0 |
| Size | 0x118 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400f7410 |
No comments yet.