| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date |
2071-Nov-21 11:02:20
|
| Detected languages |
English - United States
|
| Debug artifacts |
BootstrapPackagedGame-Win64-Shipping.pdb
|
| FileVersion |
++UE5+Release-5.7-CL-51494982
|
| CompanyName |
Epic Games, Inc.
|
| LegalCopyright |
Fill out your copyright notice in the Description page of Project Settings.
|
| ProductName |
BootstrapPackagedGame
|
| ProductVersion |
++UE5+Release-5.7-CL-51494982
|
| FileDescription |
BootstrapPackagedGame
|
| InternalName |
UnrealEngine
|
| OriginalFilename |
BootstrapPackagedGame-Win64-Shipping.exe
|
| Info |
The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
- GetProcAddress
- LoadLibraryW
- LoadLibraryExW
Can access the registry:
- RegOpenKeyExW
- RegCloseKey
- RegQueryValueExW
Possibly launches other programs:
|
| Suspicious |
The file contains overlay data. |
213576 bytes of data starting at offset 0x2adb8.
The overlay data has an entropy of 7.34619 and is possibly compressed or encrypted.
|
| Safe |
VirusTotal score: 0/72 (Scanned on 2026-03-14 13:39:48) |
All the AVs think this file is safe.
|
| MD5 |
0f595aa141cd89e661400c7ff8ef5e94
|
| SHA1 |
cde2b946f6cb8248ec37dec49f6ce06b1db29437
|
| SHA256 |
aca4124fab00d398993eacac459f568ff9f614163f09469b878002facb70ada4
|
| SHA3 |
b6d4fea44705191c0281afd2975bd46cc6599350bd135a83d1c7634d1fca2727
|
| SSDeep |
6144:c6zY5lfd6nQtC67xdhdLfWNpaSNpIR4T4QsScR4Nzekd9BCwygHT/szUZHahULh:vzadWQC675gNpaSjIBQsSNz3kIjs4la
|
| Imports Hash |
a8ff415d7b5164307cdba18944ae4f5d
|
| e_magic |
MZ
|
| e_cblp |
0x90
|
| e_cp |
0x3
|
| e_crlc |
0
|
| e_cparhdr |
0x4
|
| e_minalloc |
0
|
| e_maxalloc |
0xffff
|
| e_ss |
0
|
| e_sp |
0xb8
|
| e_csum |
0
|
| e_ip |
0
|
| e_cs |
0
|
| e_ovno |
0
|
| e_oemid |
0
|
| e_oeminfo |
0
|
| e_lfanew |
0x100
|
| Signature |
PE
|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections |
6
|
| TimeDateStamp |
2071-Nov-21 11:02:20
|
| PointerToSymbolTable |
0
|
| NumberOfSymbols |
0
|
| SizeOfOptionalHeader |
0xf0
|
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic |
PE32+
|
| LinkerVersion |
14.0
|
| SizeOfCode |
0x13c00
|
| SizeOfInitializedData |
0x4b000
|
| SizeOfUninitializedData |
0
|
| AddressOfEntryPoint |
0x00000000000023D8 (Section: .text)
|
| BaseOfCode |
0x1000
|
| ImageBase |
0x140000000
|
| SectionAlignment |
0x1000
|
| FileAlignment |
0x200
|
| OperatingSystemVersion |
6.0
|
| ImageVersion |
0.0
|
| SubsystemVersion |
6.0
|
| Win32VersionValue |
0
|
| SizeOfImage |
0x64000
|
| SizeOfHeaders |
0x400
|
| Checksum |
0x315d6
|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve |
0xb71b00
|
| SizeofStackCommit |
0x1000
|
| SizeofHeapReserve |
0x100000
|
| SizeofHeapCommit |
0x1000
|
| LoaderFlags |
0
|
| NumberOfRvaAndSizes |
16
|
| MD5 |
f79533e951aa1e3c696c64ef576222c8
|
| SHA1 |
5a5aa07e16aba3c3fbcb51abdd5fdffddd341298
|
| SHA256 |
14fd5fb1fcf5af80fa9c4e0b16cf68af2ca83c5b1838c31ae0ae2088ba913f89
|
| SHA3 |
92f5ce0eafe99577a3e477f253838fcd868bdd3121ad751832a69cc9c49bb443
|
| VirtualSize |
0x13a80
|
| VirtualAddress |
0x1000
|
| SizeOfRawData |
0x13c00
|
| PointerToRawData |
0x400
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy |
6.4785
|
| MD5 |
7d2b0b06015290e650fe61078a05e042
|
| SHA1 |
cf6298025feaa98338e74eeed3ffdbc0d7e783f9
|
| SHA256 |
ceb2caf654707e59375b5c46e9bb6ebc490998a63bc9479d873eb99f9054e147
|
| SHA3 |
cd25880b60be68f1cabc01d87cc9a3aff4327996b852a44f5e2e15097023caea
|
| VirtualSize |
0xb1ee
|
| VirtualAddress |
0x15000
|
| SizeOfRawData |
0xb200
|
| PointerToRawData |
0x14000
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.93249
|
| MD5 |
51cdcf2b319b148356517a71d2a15734
|
| SHA1 |
3c029708daad7f3d34b9e96ee4a72f870a534ab2
|
| SHA256 |
4f3a34df17de6cc2cab519b027509a62f72af4ae9e10495ca4b72494d12e85b6
|
| SHA3 |
8cb3d1edf87c0bfe1cf229622d93b7e0b37a421291aa0c9b8b0eba3d26eabdc2
|
| VirtualSize |
0x1dd0
|
| VirtualAddress |
0x21000
|
| SizeOfRawData |
0xc00
|
| PointerToRawData |
0x1f200
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy |
2.07541
|
| MD5 |
630b56fae76a1d70bb6c75e772c43ba4
|
| SHA1 |
2e1d22fa35017b5f0b71b8b9af034280455a7181
|
| SHA256 |
5939dd3502bee923d80c4da24106e7e8fb02775b66e5edf3a297d7441d0c0f38
|
| SHA3 |
cc2688000aec0fac3b8d62b465199564757d2c2dd9482af5cfe755e2dc3bbd40
|
| VirtualSize |
0x1248
|
| VirtualAddress |
0x23000
|
| SizeOfRawData |
0x1400
|
| PointerToRawData |
0x1fe00
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
4.67216
|
| MD5 |
455313a8a559f4ea612f8bf90af53f5a
|
| SHA1 |
ad881402cc00fcba84a76ebc89fd6f400e1231a6
|
| SHA256 |
513bf67e26d038f036afb4c5c2f8c284d0c280cf6b645b2729c73a0d715f791e
|
| SHA3 |
92f6eb6fbad8ef491d3d50c35b54b13a9eb88b77ae9344ecd858f7505164cf40
|
| VirtualSize |
0x3d4d0
|
| VirtualAddress |
0x25000
|
| SizeOfRawData |
0x3d600
|
| PointerToRawData |
0x21200
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy |
7.23614
|
| MD5 |
a857e5bacb1711debcc69ee1d3a70f0b
|
| SHA1 |
8790b607728f777db830e07d263c065043dfcdd3
|
| SHA256 |
34230426a93e28a8a56e6ac4a285d4a64731fa2f607628e5562cdfa07abfb5b5
|
| SHA3 |
d1a48aa1e7809cc7a54cc5d8ad91692e5e5ce4a4edf92ce461b0c730e5886cec
|
| VirtualSize |
0x694
|
| VirtualAddress |
0x63000
|
| SizeOfRawData |
0x800
|
| PointerToRawData |
0x5e800
|
| PointerToRelocations |
0
|
| PointerToLineNumbers |
0
|
| NumberOfLineNumbers |
0
|
| NumberOfRelocations |
0
|
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy |
4.95434
|
| KERNEL32.dll |
WaitForSingleObject
GetCurrentProcess
GetExitCodeProcess
CreateProcessW
FreeLibrary
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
GetLastError
LockResource
SizeofResource
FindResourceW
LoadLibraryW
WriteConsoleW
CreateFileW
CloseHandle
GetFileAttributesW
LoadResource
GetEnvironmentVariableW
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
HeapReAlloc
HeapSize
SetFilePointerEx
GetProcessHeap
LCMapStringW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
HeapFree
HeapAlloc
GetFileType
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
|
| USER32.dll |
MessageBoxW
wsprintfW
|
| ADVAPI32.dll |
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
|
| SHELL32.dll |
ShellExecuteExW
|
| SHLWAPI.dll |
PathCanonicalizeW
PathRemoveFileSpecW
PathCombineW
|
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x468
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.23456
|
| MD5 |
951c683f4ed3faca416726ccc1916f07
|
| SHA1 |
765cdde467ac4c14bc094d1020d2bba05a5e291e
|
| SHA256 |
e5aef79bceb756570add31dcdd29f295a842631a36d68ec077697e0e5940c59c
|
| SHA3 |
69fd119c39a03cc735dd61247cebbe073702875a384a89b03abe73e933832ce7
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x988
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.40508
|
| MD5 |
78ec9225d728fdff244f0d7dffcef35b
|
| SHA1 |
65c46ce6a1e3aebcd826490b9bab39e7905a247c
|
| SHA256 |
cb53aa7adde0003894f8191358845ebd79264b99b6452a39e453456a1c8773cf
|
| SHA3 |
32c624d5a3d032f013fa1e959ccbf4137ff2bc09a9748491ce3a9ad46713dfcf
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x10a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.48739
|
| MD5 |
20dbcf6d05b2e416ee51929261870a99
|
| SHA1 |
a69e97634e9b801d3aa36f9d1a0b9050df979ed7
|
| SHA256 |
9fa349ecd42a8126faa05b915c4f526004a43621c45b928e6d7b00a08d2df14e
|
| SHA3 |
dfe44a2bde1a8c531fb42f4f39f528ce4c3aa9529934951d1db6e5dc600b8f7a
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x25a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.51123
|
| MD5 |
4c19fe147d23a3bd8f24773c0af22a21
|
| SHA1 |
cc1d8896eca8d552751fab09bbac3277a36169d1
|
| SHA256 |
8305ecc08e2c7e4f9abbd7b93634fce89f1a7a830f8e8b9ae65149a438721e2d
|
| SHA3 |
adf67af149835ac6f3d833601f94def7f728bb352b057e4cd272fbfb11504246
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4228
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.54911
|
| MD5 |
6300bcddcb9a3af32a14dade06a147e9
|
| SHA1 |
a1ad70eb4916d40e2778beab075df6e52069b888
|
| SHA256 |
580c3c76cc9397c8239c11a61626e4ca5fbe7cd6d7f8a525986f6236d5e37d01
|
| SHA3 |
3de3ebc4e59248ce7a0347d9d20987a7177741e250984767780bbd2855f5d72b
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x5488
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.54419
|
| MD5 |
a9eedbaaa5e18d027ab28e9cfeac1dda
|
| SHA1 |
705e80992bb8080b3db1fae491c0491de91b159e
|
| SHA256 |
5d634b50cea8fb9c512b42645d167ec295426cd957e3b94ba806e06ade48136a
|
| SHA3 |
d08699ea0ddc89fefdf0058d8e35f25356a11aa1d2fcd374a0a259fe196b8c83
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x94a8
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.57312
|
| MD5 |
ffb9c35d4e1a930881089b78b579299a
|
| SHA1 |
e1fedfa25d13b5052790b3b482ad675684a4abd2
|
| SHA256 |
ac009a206e68f8d20711fa4b42a8d5a0d14628d2555e142fee2b30466f28a8d7
|
| SHA3 |
712a3561970085dd5112b4250b6648254503fcee77579dbf94d4fa9489b2d6d5
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x10828
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
6.57776
|
| MD5 |
828bd9caa3402c5990095df8c5da195d
|
| SHA1 |
54152a4ea1a30b3e866fa726821953dc072a673f
|
| SHA256 |
fbb8123a193732a3b3a22ae6a10fd8706c4ac5615893d72a5f319a0c1f13edeb
|
| SHA3 |
b69af0d42cc7ead94dff0fa64f28f52f0276c03ffec283641f7ed83682a77649
|
| Type |
RT_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x14f4c
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
7.993
|
| Detected Filetype |
PNG graphic file
|
| MD5 |
bb0d16956cb142e25992392f53e52ee3
|
| SHA1 |
ce5e09638785fe5725958ec55f4612f9e2a5648f
|
| SHA256 |
b0570082a29dc3afa55adb92fda497119d3736036ba7b10b82865bb03c0305e8
|
| SHA3 |
5c43fef18542b35d7717fe1bb74997df37a92097187918d336705979c3ae55aa
|
| Type |
RT_RCDATA
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4a
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.88445
|
| MD5 |
4b308a7c4abd769b67087ded934dd8a8
|
| SHA1 |
2d1866cb8270f0857040688f8adc494d15b8d040
|
| SHA256 |
a8d26819da588ae4a1723d3b3a02bf3a3482c87b6f3594e0ae80c45d2f558263
|
| SHA3 |
31d3f824afba1cceb6ee239ee27615caf614f841152fd095013c81e2c6058613
|
| Type |
RT_RCDATA
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x64
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.97566
|
| MD5 |
986258b6567134bc4d8df22620ca4b71
|
| SHA1 |
5f14c2002126cbd5df3d8f652180d3c7b11c8705
|
| SHA256 |
d335bb1f88f7d43ee64f3756d6216d924c962da15274ff579265d85a6151e3c1
|
| SHA3 |
a06bb2fdb652d7846303bcfe7431cc3b1a6412b8a576e1b7c508a921fbf89a59
|
| Type |
RT_RCDATA
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x2
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
0
|
| MD5 |
c4103f122d27677c9db144cae1394a66
|
| SHA1 |
1489f923c4dca729178b3e3233458550d8dddf29
|
| SHA256 |
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
|
| SHA3 |
762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce
|
| Type |
RT_GROUP_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x84
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.05309
|
| Detected Filetype |
Icon file
|
| MD5 |
3b26ee7b0874a1a59bf34a5a058c2c04
|
| SHA1 |
2d6b2718d2ee21c181030275c0ec3baed8cbcfee
|
| SHA256 |
de9d316b1b949384c424c76a34c84edaf12f16c43af15a81e03bbf010ddd0b72
|
| SHA3 |
20af6d80f6f21198abff08dd9bd05563767636d4115a6c901e99b5af141a090b
|
| Type |
RT_GROUP_ICON
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x68
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
2.93324
|
| Detected Filetype |
Icon file
|
| MD5 |
26e4bbdda9f8e58b060feaa53c3083e2
|
| SHA1 |
bd724469fc43a9a58679a7016c303a5693fe9f94
|
| SHA256 |
74c73b469e08909c1b539a80c66cb442d04b3c29cd03e8a533a3c349c5cc84c4
|
| SHA3 |
49df4b8afdcf81a2097c2608740540f7e25ce3aa86c892702db1183998142c1b
|
| Type |
RT_VERSION
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x3f0
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
3.52269
|
| MD5 |
e6bb02f30122d2be744fbc720ebae68f
|
| SHA1 |
96bad17b8c318e5bcd7c80f1757fdecebac20984
|
| SHA256 |
981c6000d1378b0b2cd6c1a81b6af49b424383ffc5e93445e3eaf8daf1c2473c
|
| SHA3 |
b229e2f62a3b2c39fe56b36a2981605d7559d32b7c3af604f2eff60b7432c89f
|
| Type |
RT_MANIFEST
|
| Language |
English - United States
|
| Codepage |
Latin 1 / Western European
|
| Size |
0x4ab
|
| TimeDateStamp |
1980-Jan-01 00:00:00
|
| Entropy |
5.17111
|
| MD5 |
95c2c9489bd148da2aa8a81ad0ed51fd
|
| SHA1 |
f0183299607f193ce5ea333a13d0da18c5855e25
|
| SHA256 |
e2acd718de40a9dba7f7f7c596987e9b6c96ad3b447e28d2565e467b4f294593
|
| SHA3 |
4b305a1395c563907fca1139de6d7109ade1e8bca0df9227287e06625a88ba1f
|
| Signature |
0xfeef04bd
|
| StructVersion |
0x10000
|
| FileVersion |
5.7.4.0
|
| ProductVersion |
5.7.4.0
|
| FileFlags |
(EMPTY)
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language |
English - United States
|
| FileVersion (#2) |
++UE5+Release-5.7-CL-51494982
|
| CompanyName |
Epic Games, Inc.
|
| LegalCopyright |
Fill out your copyright notice in the Description page of Project Settings.
|
| ProductName |
BootstrapPackagedGame
|
| ProductVersion (#2) |
++UE5+Release-5.7-CL-51494982
|
| FileDescription |
BootstrapPackagedGame
|
| InternalName |
UnrealEngine
|
| OriginalFilename |
BootstrapPackagedGame-Win64-Shipping.exe
|
| Resource LangID |
English - United States
|
| Characteristics |
0
|
| TimeDateStamp |
2071-Nov-21 11:02:20
|
| Version |
0.0
|
| SizeofData |
65
|
| AddressOfRawData |
0x1e1e8
|
| PointerToRawData |
0x1d1e8
|
| Referenced File |
BootstrapPackagedGame-Win64-Shipping.pdb
|
| Characteristics |
0
|
| TimeDateStamp |
2071-Nov-21 11:02:20
|
| Version |
0.0
|
| SizeofData |
20
|
| AddressOfRawData |
0x1e22c
|
| PointerToRawData |
0x1d22c
|
| Characteristics |
0
|
| TimeDateStamp |
2071-Nov-21 11:02:20
|
| Version |
0.0
|
| SizeofData |
820
|
| AddressOfRawData |
0x1e240
|
| PointerToRawData |
0x1d240
|
| Characteristics |
0
|
| TimeDateStamp |
2071-Nov-21 11:02:20
|
| Version |
0.0
|
| SizeofData |
36
|
| AddressOfRawData |
0x1e59c
|
| PointerToRawData |
0x1d59c
|
| Size |
0x140
|
| TimeDateStamp |
1970-Jan-01 00:00:00
|
| Version |
0.0
|
| GlobalFlagsClear |
(EMPTY)
|
| GlobalFlagsSet |
(EMPTY)
|
| CriticalSectionDefaultTimeout |
0
|
| DeCommitFreeBlockThreshold |
0
|
| DeCommitTotalFreeThreshold |
0
|
| LockPrefixTable |
0
|
| MaximumAllocationSize |
0
|
| VirtualMemoryThreshold |
0
|
| ProcessAffinityMask |
0
|
| ProcessHeapFlags |
(EMPTY)
|
| CSDVersion |
0
|
| Reserved1 |
0
|
| EditList |
0
|
| SecurityCookie |
0x140021040
|
| XOR Key |
0x3fc0667d
|
| Unmarked objects |
0
|
| ASM objects (30795) |
7
|
| C++ objects (30795) |
139
|
| C objects (30795) |
10
|
| ASM objects (35207) |
9
|
| C objects (35207) |
16
|
| C++ objects (35207) |
45
|
| Imports (30795) |
13
|
| Total imports |
111
|
| C++ objects (35223) |
1
|
| Resource objects (35223) |
1
|
| 151 |
1
|
| Linker (35223) |
1
|
[*] Warning: The WIN_CERTIFICATE appears to be invalid.