aca4124fab00d398993eacac459f568ff9f614163f09469b878002facb70ada4

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2071-Nov-21 11:02:20
Detected languages English - United States
Debug artifacts BootstrapPackagedGame-Win64-Shipping.pdb
FileVersion ++UE5+Release-5.7-CL-51494982
CompanyName Epic Games, Inc.
LegalCopyright Fill out your copyright notice in the Description page of Project Settings.
ProductName BootstrapPackagedGame
ProductVersion ++UE5+Release-5.7-CL-51494982
FileDescription BootstrapPackagedGame
InternalName UnrealEngine
OriginalFilename BootstrapPackagedGame-Win64-Shipping.exe

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Can access the registry:
  • RegOpenKeyExW
  • RegCloseKey
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
Suspicious The file contains overlay data. 213576 bytes of data starting at offset 0x2adb8.
The overlay data has an entropy of 7.34619 and is possibly compressed or encrypted.
Safe VirusTotal score: 0/72 (Scanned on 2026-03-14 13:39:48) All the AVs think this file is safe.

Hashes

MD5 0f595aa141cd89e661400c7ff8ef5e94
SHA1 cde2b946f6cb8248ec37dec49f6ce06b1db29437
SHA256 aca4124fab00d398993eacac459f568ff9f614163f09469b878002facb70ada4
SHA3 b6d4fea44705191c0281afd2975bd46cc6599350bd135a83d1c7634d1fca2727
SSDeep 6144:c6zY5lfd6nQtC67xdhdLfWNpaSNpIR4T4QsScR4Nzekd9BCwygHT/szUZHahULh:vzadWQC675gNpaSjIBQsSNz3kIjs4la
Imports Hash a8ff415d7b5164307cdba18944ae4f5d

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2071-Nov-21 11:02:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x13c00
SizeOfInitializedData 0x4b000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000023D8 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x64000
SizeOfHeaders 0x400
Checksum 0x315d6
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0xb71b00
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f79533e951aa1e3c696c64ef576222c8
SHA1 5a5aa07e16aba3c3fbcb51abdd5fdffddd341298
SHA256 14fd5fb1fcf5af80fa9c4e0b16cf68af2ca83c5b1838c31ae0ae2088ba913f89
SHA3 92f5ce0eafe99577a3e477f253838fcd868bdd3121ad751832a69cc9c49bb443
VirtualSize 0x13a80
VirtualAddress 0x1000
SizeOfRawData 0x13c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4785

.rdata

MD5 7d2b0b06015290e650fe61078a05e042
SHA1 cf6298025feaa98338e74eeed3ffdbc0d7e783f9
SHA256 ceb2caf654707e59375b5c46e9bb6ebc490998a63bc9479d873eb99f9054e147
SHA3 cd25880b60be68f1cabc01d87cc9a3aff4327996b852a44f5e2e15097023caea
VirtualSize 0xb1ee
VirtualAddress 0x15000
SizeOfRawData 0xb200
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.93249

.data

MD5 51cdcf2b319b148356517a71d2a15734
SHA1 3c029708daad7f3d34b9e96ee4a72f870a534ab2
SHA256 4f3a34df17de6cc2cab519b027509a62f72af4ae9e10495ca4b72494d12e85b6
SHA3 8cb3d1edf87c0bfe1cf229622d93b7e0b37a421291aa0c9b8b0eba3d26eabdc2
VirtualSize 0x1dd0
VirtualAddress 0x21000
SizeOfRawData 0xc00
PointerToRawData 0x1f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.07541

.pdata

MD5 630b56fae76a1d70bb6c75e772c43ba4
SHA1 2e1d22fa35017b5f0b71b8b9af034280455a7181
SHA256 5939dd3502bee923d80c4da24106e7e8fb02775b66e5edf3a297d7441d0c0f38
SHA3 cc2688000aec0fac3b8d62b465199564757d2c2dd9482af5cfe755e2dc3bbd40
VirtualSize 0x1248
VirtualAddress 0x23000
SizeOfRawData 0x1400
PointerToRawData 0x1fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67216

.rsrc

MD5 455313a8a559f4ea612f8bf90af53f5a
SHA1 ad881402cc00fcba84a76ebc89fd6f400e1231a6
SHA256 513bf67e26d038f036afb4c5c2f8c284d0c280cf6b645b2729c73a0d715f791e
SHA3 92f6eb6fbad8ef491d3d50c35b54b13a9eb88b77ae9344ecd858f7505164cf40
VirtualSize 0x3d4d0
VirtualAddress 0x25000
SizeOfRawData 0x3d600
PointerToRawData 0x21200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.23614

.reloc

MD5 a857e5bacb1711debcc69ee1d3a70f0b
SHA1 8790b607728f777db830e07d263c065043dfcdd3
SHA256 34230426a93e28a8a56e6ac4a285d4a64731fa2f607628e5562cdfa07abfb5b5
SHA3 d1a48aa1e7809cc7a54cc5d8ad91692e5e5ce4a4edf92ce461b0c730e5886cec
VirtualSize 0x694
VirtualAddress 0x63000
SizeOfRawData 0x800
PointerToRawData 0x5e800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.95434

Imports

KERNEL32.dll WaitForSingleObject
GetCurrentProcess
GetExitCodeProcess
CreateProcessW
FreeLibrary
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
GetLastError
LockResource
SizeofResource
FindResourceW
LoadLibraryW
WriteConsoleW
CreateFileW
CloseHandle
GetFileAttributesW
LoadResource
GetEnvironmentVariableW
GetConsoleMode
GetConsoleOutputCP
FlushFileBuffers
HeapReAlloc
HeapSize
SetFilePointerEx
GetProcessHeap
LCMapStringW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
HeapFree
HeapAlloc
GetFileType
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
USER32.dll MessageBoxW
wsprintfW
ADVAPI32.dll RegOpenKeyExW
RegCloseKey
RegQueryValueExW
SHELL32.dll ShellExecuteExW
SHLWAPI.dll PathCanonicalizeW
PathRemoveFileSpecW
PathCombineW
VERSION.dll GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.23456
MD5 951c683f4ed3faca416726ccc1916f07
SHA1 765cdde467ac4c14bc094d1020d2bba05a5e291e
SHA256 e5aef79bceb756570add31dcdd29f295a842631a36d68ec077697e0e5940c59c
SHA3 69fd119c39a03cc735dd61247cebbe073702875a384a89b03abe73e933832ce7

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.40508
MD5 78ec9225d728fdff244f0d7dffcef35b
SHA1 65c46ce6a1e3aebcd826490b9bab39e7905a247c
SHA256 cb53aa7adde0003894f8191358845ebd79264b99b6452a39e453456a1c8773cf
SHA3 32c624d5a3d032f013fa1e959ccbf4137ff2bc09a9748491ce3a9ad46713dfcf

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.48739
MD5 20dbcf6d05b2e416ee51929261870a99
SHA1 a69e97634e9b801d3aa36f9d1a0b9050df979ed7
SHA256 9fa349ecd42a8126faa05b915c4f526004a43621c45b928e6d7b00a08d2df14e
SHA3 dfe44a2bde1a8c531fb42f4f39f528ce4c3aa9529934951d1db6e5dc600b8f7a

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.51123
MD5 4c19fe147d23a3bd8f24773c0af22a21
SHA1 cc1d8896eca8d552751fab09bbac3277a36169d1
SHA256 8305ecc08e2c7e4f9abbd7b93634fce89f1a7a830f8e8b9ae65149a438721e2d
SHA3 adf67af149835ac6f3d833601f94def7f728bb352b057e4cd272fbfb11504246

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.54911
MD5 6300bcddcb9a3af32a14dade06a147e9
SHA1 a1ad70eb4916d40e2778beab075df6e52069b888
SHA256 580c3c76cc9397c8239c11a61626e4ca5fbe7cd6d7f8a525986f6236d5e37d01
SHA3 3de3ebc4e59248ce7a0347d9d20987a7177741e250984767780bbd2855f5d72b

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.54419
MD5 a9eedbaaa5e18d027ab28e9cfeac1dda
SHA1 705e80992bb8080b3db1fae491c0491de91b159e
SHA256 5d634b50cea8fb9c512b42645d167ec295426cd957e3b94ba806e06ade48136a
SHA3 d08699ea0ddc89fefdf0058d8e35f25356a11aa1d2fcd374a0a259fe196b8c83

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.57312
MD5 ffb9c35d4e1a930881089b78b579299a
SHA1 e1fedfa25d13b5052790b3b482ad675684a4abd2
SHA256 ac009a206e68f8d20711fa4b42a8d5a0d14628d2555e142fee2b30466f28a8d7
SHA3 712a3561970085dd5112b4250b6648254503fcee77579dbf94d4fa9489b2d6d5

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.57776
MD5 828bd9caa3402c5990095df8c5da195d
SHA1 54152a4ea1a30b3e866fa726821953dc072a673f
SHA256 fbb8123a193732a3b3a22ae6a10fd8706c4ac5615893d72a5f319a0c1f13edeb
SHA3 b69af0d42cc7ead94dff0fa64f28f52f0276c03ffec283641f7ed83682a77649

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14f4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.993
Detected Filetype PNG graphic file
MD5 bb0d16956cb142e25992392f53e52ee3
SHA1 ce5e09638785fe5725958ec55f4612f9e2a5648f
SHA256 b0570082a29dc3afa55adb92fda497119d3736036ba7b10b82865bb03c0305e8
SHA3 5c43fef18542b35d7717fe1bb74997df37a92097187918d336705979c3ae55aa

201

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88445
MD5 4b308a7c4abd769b67087ded934dd8a8
SHA1 2d1866cb8270f0857040688f8adc494d15b8d040
SHA256 a8d26819da588ae4a1723d3b3a02bf3a3482c87b6f3594e0ae80c45d2f558263
SHA3 31d3f824afba1cceb6ee239ee27615caf614f841152fd095013c81e2c6058613

202

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x64
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97566
MD5 986258b6567134bc4d8df22620ca4b71
SHA1 5f14c2002126cbd5df3d8f652180d3c7b11c8705
SHA256 d335bb1f88f7d43ee64f3756d6216d924c962da15274ff579265d85a6151e3c1
SHA3 a06bb2fdb652d7846303bcfe7431cc3b1a6412b8a576e1b7c508a921fbf89a59

205

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 c4103f122d27677c9db144cae1394a66
SHA1 1489f923c4dca729178b3e3233458550d8dddf29
SHA256 96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
SHA3 762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce

101

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05309
Detected Filetype Icon file
MD5 3b26ee7b0874a1a59bf34a5a058c2c04
SHA1 2d6b2718d2ee21c181030275c0ec3baed8cbcfee
SHA256 de9d316b1b949384c424c76a34c84edaf12f16c43af15a81e03bbf010ddd0b72
SHA3 20af6d80f6f21198abff08dd9bd05563767636d4115a6c901e99b5af141a090b

123

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.93324
Detected Filetype Icon file
MD5 26e4bbdda9f8e58b060feaa53c3083e2
SHA1 bd724469fc43a9a58679a7016c303a5693fe9f94
SHA256 74c73b469e08909c1b539a80c66cb442d04b3c29cd03e8a533a3c349c5cc84c4
SHA3 49df4b8afdcf81a2097c2608740540f7e25ce3aa86c892702db1183998142c1b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x3f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52269
MD5 e6bb02f30122d2be744fbc720ebae68f
SHA1 96bad17b8c318e5bcd7c80f1757fdecebac20984
SHA256 981c6000d1378b0b2cd6c1a81b6af49b424383ffc5e93445e3eaf8daf1c2473c
SHA3 b229e2f62a3b2c39fe56b36a2981605d7559d32b7c3af604f2eff60b7432c89f

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x4ab
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17111
MD5 95c2c9489bd148da2aa8a81ad0ed51fd
SHA1 f0183299607f193ce5ea333a13d0da18c5855e25
SHA256 e2acd718de40a9dba7f7f7c596987e9b6c96ad3b447e28d2565e467b4f294593
SHA3 4b305a1395c563907fca1139de6d7109ade1e8bca0df9227287e06625a88ba1f

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 5.7.4.0
ProductVersion 5.7.4.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
FileVersion (#2) ++UE5+Release-5.7-CL-51494982
CompanyName Epic Games, Inc.
LegalCopyright Fill out your copyright notice in the Description page of Project Settings.
ProductName BootstrapPackagedGame
ProductVersion (#2) ++UE5+Release-5.7-CL-51494982
FileDescription BootstrapPackagedGame
InternalName UnrealEngine
OriginalFilename BootstrapPackagedGame-Win64-Shipping.exe
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2071-Nov-21 11:02:20
Version 0.0
SizeofData 65
AddressOfRawData 0x1e1e8
PointerToRawData 0x1d1e8
Referenced File BootstrapPackagedGame-Win64-Shipping.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2071-Nov-21 11:02:20
Version 0.0
SizeofData 20
AddressOfRawData 0x1e22c
PointerToRawData 0x1d22c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2071-Nov-21 11:02:20
Version 0.0
SizeofData 820
AddressOfRawData 0x1e240
PointerToRawData 0x1d240

UNKNOWN

Characteristics 0
TimeDateStamp 2071-Nov-21 11:02:20
Version 0.0
SizeofData 36
AddressOfRawData 0x1e59c
PointerToRawData 0x1d59c

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140021040

RICH Header

XOR Key 0x3fc0667d
Unmarked objects 0
ASM objects (30795) 7
C++ objects (30795) 139
C objects (30795) 10
ASM objects (35207) 9
C objects (35207) 16
C++ objects (35207) 45
Imports (30795) 13
Total imports 111
C++ objects (35223) 1
Resource objects (35223) 1
151 1
Linker (35223) 1

Errors

[*] Warning: The WIN_CERTIFICATE appears to be invalid.
Leave a comment

No comments yet.