adf1753f4f182e3c4287eeea19ceddb5b91f3386c73d1d17b8f0b8171a9c219f

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-24 19:49:05
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts W:\Depot\LoTRWarInTheNorth\Remaster\Day0_Cert_514686\trixie\bin\pc\SteamRelease\witn.pdb
CompanyName WB Games Inc.
FileDescription The Lord of the Rings: War in the North
FileVersion 1, 0, 0, 1
InternalName The Lord of the Rings: War in the North
LegalCopyright TM & © New Line. THE LORD OF THE RINGS: WAR IN THE NORTH and the names of the characters, items, events and places therein are trademarks or registered trademarks of SZC under license to WBIE. (S11)
LegalTrademarks TM & © New Line. THE LORD OF THE RINGS: WAR IN THE NORTH and the names of the characters, items, events and places therein are trademarks or registered trademarks of SZC under license to WBIE. (S11)
OriginalFilename The Lord of the Rings: War in the North
ProductName The Lord of the Rings: War in the North
ProductVersion 1, 0, 0, 1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
Contains domain names:
  • Havok.com
  • aspyr.com
  • ctep.aspyr.com
  • https://ctep.aspyr.com
  • https://ctep.aspyr.com/witn_pc
  • https://www.aspyr.com
  • https://www.aspyr.com/
  • lotr-matrix.wbgames.com
  • matrix.wbgames.com
  • wbgames.com
  • www.aspyr.com
  • www.lua.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .fptable
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryExA
Can access the registry:
  • RegOpenKeyA
Possibly launches other programs:
  • ShellExecuteA
Uses Windows's Native API:
  • ntohs
  • ntohl
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Leverages the raw socket API to access the Internet:
  • getaddrinfo
  • WSAGetLastError
  • WSACleanup
  • WSAStartup
  • socket
  • shutdown
  • setsockopt
  • sendto
  • select
  • WSAAsyncSelect
  • recv
  • ntohs
  • ntohl
  • listen
  • htons
  • gethostname
  • gethostbyname
  • send
  • __WSAFDIsSet
  • inet_ntoa
  • inet_addr
  • accept
  • bind
  • closesocket
  • connect
  • ioctlsocket
  • getsockname
  • getsockopt
  • htonl
  • freeaddrinfo
  • recvfrom
Interacts with services:
  • OpenSCManagerA
  • OpenServiceA
Safe VirusTotal score: 0/71 (Scanned on 2026-08-11 17:50:03) All the AVs think this file is safe.

Hashes

MD5 9cd0035f77ccd09486e7f2e549172561
SHA1 d3cc7bdd8a85c5839ebc41767e90af98860eb702
SHA256 adf1753f4f182e3c4287eeea19ceddb5b91f3386c73d1d17b8f0b8171a9c219f
SHA3 0c4a1bbf7d32d9bf90b7cfb7617a517876c23442f3b4f82ab6baa3a44d2d9285
SSDeep 196608:zkCyBQVeoxCqcq8tii5fa4/ug119v8w1/Qk:LFeoxCqcq8oUf1rJP
Imports Hash 0e23906187e543adc967a711ff44dda9

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x158

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2026-Jul-24 19:49:05
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9e4800
SizeOfInitializedData 0x1462200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000007CC2C0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1e4c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d22f1e744f9ca82ca4629e3ca880811f
SHA1 f055243bb97eabdfa23aaf08c431431b75b87e35
SHA256 65542567cf991c8985d70f4e4cf59ba941d5ee05565721bf599519d60352d436
SHA3 d2013e18b86121bb593f6ffa48b16ca5ad55ba487d26fc70781c696261f2d59f
VirtualSize 0x9e46af
VirtualAddress 0x1000
SizeOfRawData 0x9e4800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.47337

.rdata

MD5 e089f1557a36b0251f96d8fda92989ec
SHA1 4e297936a9eecaa701c9268d7ad760f447f9dd6c
SHA256 5a804d92d99ad0ecd3adcf712d176463286cf640df2bc0554cb4da42005268f2
SHA3 90ffe10fafc57ae8607bc2463e3e35cb7d4e5ba0e652f6c1d05e9abe3a3dc8e0
VirtualSize 0x18384c
VirtualAddress 0x9e6000
SizeOfRawData 0x183a00
PointerToRawData 0x9e4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.67729

.data

MD5 6cca7227b1c7c2e1386e70e0637532cd
SHA1 14a95be5fc21c67952c8998208722d4705779701
SHA256 f7c0b090eed702f68ca90b43e3a656c9e12841fca7055377bd235d66fc6bcecd
SHA3 ba881618db63b99012e607afc23a93242db8314af084ab9e4213d5da11e42c47
VirtualSize 0x11f30cc
VirtualAddress 0xb6a000
SizeOfRawData 0x24800
PointerToRawData 0xb68600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.4827

.pdata

MD5 bad19a54cd65e32c5a166601c7e2cc4b
SHA1 364cbba27ca08f0a04465f6f18de4f7db0c5cb00
SHA256 e546c6e6cd47d95ab36ee584b51211290cb4e157d4fd186d2f9bbbe6447734cb
SHA3 477bc404fdc57644dc0e0ab765bddf3d38648a6dc09feef08efe3db0c83a1733
VirtualSize 0x99c9c
VirtualAddress 0x1d5e000
SizeOfRawData 0x99e00
PointerToRawData 0xb8ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.58996

_RDATA

MD5 296aaab61fa8ee322c384fc0a57139f5
SHA1 83b10502a2ebb1aae19373842a174bcfe1c985db
SHA256 4df0a185df2d2cf4d7d64ddb6d495b5047b77fc58fd10322f5368ddcbed4da35
SHA3 cbbac6b5784cc949764ed6cb21b7458e91faaaab6c8b2e4335b58a8e68b72d90
VirtualSize 0x2308
VirtualAddress 0x1df8000
SizeOfRawData 0x2400
PointerToRawData 0xc26c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.15734

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x100
VirtualAddress 0x1dfb000
SizeOfRawData 0x200
PointerToRawData 0xc29000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 a31cfa20098dfbf7756396fa75cda3fe
SHA1 99bc809353c091c601d02f996936b363a631255f
SHA256 9db21b913b9bdb963268b8b961caf22d739cfc1b38470377d38995cd127933be
SHA3 ce55aada74f2df3362ef45db38b713cc8df1efba35c67c78c0e8afffc5ea7686
VirtualSize 0x38c78
VirtualAddress 0x1dfc000
SizeOfRawData 0x38e00
PointerToRawData 0xc29200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.89034

.reloc

MD5 7e8246aac305ee37dabe55a6a04f7527
SHA1 27380503a298d26b46b3c56f85d6239f1fe0ea2f
SHA256 41c334170ddf8bc2d23f2f2e12efefc0b8208c09ef0d136129d20bac6756c0c9
SHA3 ab5a41617d339b5bf6481a51c0e7b4b266d3cad8b6479758d9b38b5054823a71
VirtualSize 0x16334
VirtualAddress 0x1e35000
SizeOfRawData 0x16400
PointerToRawData 0xc62000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43889

Imports

dbghelp.dll MiniDumpWriteDump
steam_api64.dll SteamAPI_RegisterCallback
SteamAPI_UnregisterCallback
SteamAPI_Shutdown
SteamInternal_SteamAPI_Init
SteamAPI_RegisterCallResult
SteamAPI_UnregisterCallResult
SteamAPI_RunCallbacks
SteamInternal_CreateInterface
SteamInternal_FindOrCreateUserInterface
SteamInternal_ContextInit
SteamAPI_GetHSteamUser
SteamAPI_IsSteamRunning
KERNEL32.dll GetConsoleOutputCP
GetFileSizeEx
HeapReAlloc
HeapSize
HeapQueryInformation
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
ReadConsoleW
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
SetEndOfFile
WriteConsoleW
GetExitCodeThread
LoadLibraryA
GetOEMCP
GetConsoleMode
DeleteFileA
GetCurrentThreadId
GetCurrentProcessId
GetCurrentProcess
CloseHandle
CreateFileW
FindClose
GetTimeZoneInformation
GetFileType
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetLocaleInfoW
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
VirtualProtect
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetStdHandle
GetModuleHandleExW
ExitProcess
LoadLibraryExW
FreeLibrary
TlsFree
TlsSetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RtlUnwindEx
RtlPcToFileHeader
TerminateProcess
InitializeSListHead
IsProcessorFeaturePresent
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
SleepConditionVariableSRW
WakeAllConditionVariable
GetCPInfo
GetStringTypeW
TlsGetValue
CreateDirectoryA
FlushFileBuffers
GetFileAttributesA
GetFileAttributesExA
GetFileSize
ReadFile
ReadFileEx
SetFilePointer
WriteFile
WriteFileEx
GetLastError
GetOverlappedResult
CopyFileA
RaiseException
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
DeleteCriticalSection
InitializeConditionVariable
WakeConditionVariable
SleepConditionVariableCS
SetEvent
WaitForSingleObject
CreateEventA
Sleep
WaitForMultipleObjects
CreateThread
GetCurrentThread
SetThreadPriority
SuspendThread
ResumeThread
GetEnvironmentVariableA
SetCurrentDirectoryA
CompareFileTime
CreateFileA
RtlUnwind
FindFirstFileA
FindNextFileA
GetFileTime
QueryPerformanceCounter
QueryPerformanceFrequency
GetLocalTime
GetTickCount
SystemTimeToFileTime
OutputDebugStringA
ReleaseSemaphore
VirtualAlloc
GetModuleFileNameW
GetModuleHandleA
CreateSemaphoreA
GetProcAddress
LoadLibraryExA
GetUserDefaultLangID
GetFullPathNameW
MultiByteToWideChar
WideCharToMultiByte
GetSystemInfo
SetFilePointerEx
GetCurrentDirectoryA
GlobalAlloc
GlobalUnlock
GlobalLock
GlobalFree
HeapAlloc
HeapFree
GetProcessHeap
CreateEventW
CreateEventExW
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
GetSystemTimeAsFileTime
GetModuleHandleW
SHELL32.dll SHGetSpecialFolderPathA
ShellExecuteA
WS2_32.dll getaddrinfo
WSAGetLastError
WSACleanup
WSAStartup
socket
shutdown
setsockopt
sendto
select
WSAAsyncSelect
recv
ntohs
ntohl
listen
htons
gethostname
gethostbyname
send
__WSAFDIsSet
inet_ntoa
inet_addr
accept
bind
closesocket
connect
ioctlsocket
getsockname
getsockopt
htonl
freeaddrinfo
recvfrom
d3d12.dll #101
D3D12SerializeRootSignature
dxgi.dll CreateDXGIFactory2
dxcompiler.dll DxcCreateInstance
EOSSDK-Win64-Shipping.dll EOS_ByteArray_ToString
EOS_UI_HideFriends
EOS_UI_ShowFriends
EOS_LobbySearch_CopySearchResultByIndex
EOS_P2P_RemoveNotifyPeerConnectionClosed
EOS_LobbySearch_SetParameter
EOS_P2P_RemoveNotifyPeerConnectionRequest
EOS_P2P_AddNotifyPeerConnectionRequest
EOS_P2P_SendPacket
EOS_P2P_AddNotifyPeerConnectionClosed
EOS_P2P_AcceptConnection
EOS_P2P_CloseConnection
EOS_P2P_GetPacketQueueInfo
EOS_LobbySearch_GetSearchResultCount
EOS_Connect_CreateUser
EOS_LobbySearch_SetLobbyId
EOS_LobbySearch_Find
EOS_LobbyDetails_GetMemberByIndex
EOS_LobbyDetails_GetMemberCount
EOS_LobbyDetails_CopyAttributeByIndex
EOS_LobbyDetails_GetAttributeCount
EOS_LobbyDetails_CopyInfo
EOS_LobbyDetails_GetLobbyOwner
EOS_LobbyModification_AddAttribute
EOS_Lobby_RemoveNotifyLeaveLobbyRequested
EOS_Lobby_AddNotifyLeaveLobbyRequested
EOS_Lobby_CopyLobbyDetailsHandle
EOS_Lobby_CopyLobbyDetailsHandleByUiEventId
EOS_Lobby_CopyLobbyDetailsHandleByInviteId
EOS_Lobby_RemoveNotifyJoinLobbyAccepted
EOS_Lobby_AddNotifyJoinLobbyAccepted
EOS_Lobby_RemoveNotifyLobbyInviteAccepted
EOS_Lobby_AddNotifyLobbyInviteAccepted
EOS_Lobby_RemoveNotifyLobbyInviteReceived
EOS_Lobby_AddNotifyLobbyInviteReceived
EOS_Lobby_CreateLobbySearch
EOS_Lobby_RemoveNotifyLobbyMemberStatusReceived
EOS_Lobby_AddNotifyLobbyMemberStatusReceived
EOS_Lobby_RemoveNotifyLobbyMemberUpdateReceived
EOS_Lobby_AddNotifyLobbyMemberUpdateReceived
EOS_Lobby_RemoveNotifyLobbyUpdateReceived
EOS_EpicAccountId_IsValid
EOS_UserInfo_BestDisplayName_Release
EOS_Platform_GetUserInfoInterface
EOS_UserInfo_QueryUserInfo
EOS_UserInfo_CopyBestDisplayName
EOS_UserInfo_CopyBestDisplayNameWithPlatform
EOS_EResult_IsOperationComplete
EOS_ProductUserId_IsValid
EOS_ProductUserId_ToString
EOS_IntegratedPlatformOptionsContainer_Release
EOS_Initialize
EOS_Shutdown
EOS_Platform_Create
EOS_Platform_Release
EOS_Auth_Token_Release
EOS_Connect_Login
EOS_Lobby_UpdateLobby
EOS_Connect_AddNotifyAuthExpiration
EOS_Connect_RemoveNotifyAuthExpiration
EOS_Platform_Tick
EOS_Platform_GetAuthInterface
EOS_Platform_GetConnectInterface
EOS_Platform_GetP2PInterface
EOS_Auth_Login
EOS_Auth_Logout
EOS_Auth_LinkAccount
EOS_Auth_CopyUserAuthToken
EOS_Logging_SetCallback
EOS_Logging_SetLogLevel
EOS_P2P_GetNextReceivedPacketSize
EOS_P2P_ReceivePacket
EOS_ProductUserId_FromString
EOS_LobbyModification_Release
EOS_LobbyDetails_Release
EOS_LobbySearch_Release
EOS_LobbyDetails_Info_Release
EOS_Lobby_Attribute_Release
EOS_Platform_GetUIInterface
EOS_Platform_GetLobbyInterface
EOS_Lobby_CreateLobby
EOS_Lobby_DestroyLobby
EOS_Lobby_JoinLobby
EOS_Lobby_LeaveLobby
EOS_Lobby_UpdateLobbyModification
EOS_Lobby_AddNotifyLobbyUpdateReceived
XAudio2_9.dll #2
#6
XINPUT1_4.dll #3
#2
bink2w64.dll BinkNextFrame
BinkWait
BinkShouldSkip
BinkStartAsyncThread
BinkDoFrameAsyncMulti
BinkRequestStopAsyncThreadsMulti
BinkWaitStopAsyncThreadsMulti
BinkSetSoundSystem2
BinkSetVolume
BinkGetRealtime
BinkGetFrameBuffersInfo
BinkRegisterFrameBuffers
BinkUtilMalloc
BinkUtilFree
BinkGetTrackID
BinkDoFrameAsyncWait
BinkControlBackgroundIO
BinkPause
BinkClose
BinkOpen
BinkDoFrame
BinkSetIOSize
BinkSetMemory
BinkSetSoundTrack
BinkSetOSFileCallbacks
BinkOpenXAudio2
BinkSetSpeakerVolumes
BinkGetSummary
WTSAPI32.dll WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
USER32.dll AdjustWindowRectEx
GetWindowRect
CreateDialogIndirectParamA
SetWindowPos
GetClassInfoA
UnregisterClassA
PostMessageA
SetFocus
MessageBoxA
EnumDisplaySettingsA
LoadIconA
LockSetForegroundWindow
SetForegroundWindow
SetWindowLongPtrA
RegisterClassExA
PostQuitMessage
RegisterRawInputDevices
GetWindowInfo
SystemParametersInfoA
DestroyCursor
LoadCursorA
PtInRect
ClipCursor
MapWindowPoints
ScreenToClient
ClientToScreen
GetCursorPos
SetCursor
MessageBoxW
GetClientRect
SetWindowTextW
ToUnicode
GetKeyboardState
GetKeyState
ShowWindow
DestroyWindow
PeekMessageA
GetRawInputData
CreateWindowExA
DispatchMessageA
TranslateMessage
LoadStringW
DefWindowProcA
GDI32.dll GetStockObject
ADVAPI32.dll RegOpenKeyA
OpenSCManagerA
OpenServiceA
GetUserNameA
CloseServiceHandle
ole32.dll CoUninitialize
CoInitializeEx
RawInput.dll ?GetState@IGamepad@RawInput@@QEAA?BU_XINPUT_STATE@@XZ
?HasConnectedPads@GamepadsManager@RawInput@@SA_NXZ
?GetFreeGamepads@GamepadsManager@RawInput@@SAHPEAV?$shared_ptr@VIGamepad@RawInput@@@std@@I@Z
WndProcRawInput
SetFilter
?Assign@IGamepad@RawInput@@QEAAXPEAXP6AX0@Z@Z
?SetAxisDistributionValues@IGamepad@RawInput@@QEAAXHH@Z

Delayed Imports

12

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x10ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7628
MD5 1a1a1f62e0042be91d7124927396bb56
SHA1 52aaecf1e7486d2f6811a3e8339cc50ea1cb4718
SHA256 562db3587fea849f916a51d305eb51693302df20dba2e2ccf98db0d583b98627
SHA3 19a6444917892971a934269dc9325fbeedad1c82d7afd2823ae3052e39e9bd45

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.90173
MD5 1a3cccecbd5ef5385e5353fd701025f5
SHA1 bd7c4fa4b3d9d2865ab892321f568ecda923c1e8
SHA256 00c2c1b14e8cfbbf7c2ca86f7d20032ccb85d9da5d66d5ad75e9c4495e1f2ce1
SHA3 b3cf3cde46b81d3686809ec9cd61ef9ef196879cf4d3737fc6071d48a344e16c

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.6139
MD5 a8cba1962eb7a8d97da08a33958cbd5b
SHA1 6fc39fc6c785b0844d909de369cf5be7b62c89a6
SHA256 17b419111d0bd94e7a37fdb150883c900e0837ef2d64f8831bd52ba0f212d1c0
SHA3 be2bbabe2473705911ee8367624e3e601592cc7c112fcfb9bff3c2235818b668

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.22267
MD5 c3c49132268db853746297c24bfa53dc
SHA1 8359b864c8ca2528bbe22280766041d377af3f6e
SHA256 54e1208d58ec3c156c4cedda6dff82578450f84abc1ebc79176ad5424293c677
SHA3 e4e0d8c6acbdfe2fd4234305e1aa2a23a885f3976c0dc78a43db21ef9a6a9334

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xe07b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98251
Detected Filetype PNG graphic file
MD5 87c479950e1aebf38f86b6a52378a294
SHA1 256011a178283a439a5d73071fc0601c058f9947
SHA256 2f4e0bba263f7989cf1cd04bd42075ad6ed352443cdffad241598dbc387d91b8
SHA3 abb5b9bc6b86ae8c5bd9b635bb2ef555b281199127804c4b1bc40f3e4bb2848e

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9933
MD5 19dbff845885ae526a94a46406fb8695
SHA1 af7d66dd5d168957bb5cc29ee6a3d1bcbe3b4bb8
SHA256 e1be7c9cb6ae9a3018e1aca4d793e77baa76a0ec0f481755dfd9439ac2c26842
SHA3 ef373136af32157f502432b56f5dc583c443007af3c62c98250725c106a949ff

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40695
MD5 600ac91e0a187b77df5382d4c5866df2
SHA1 e5435b9c736d2d50e954491625ce8d84c5ee8d2f
SHA256 28a12ef1e3343b61e7d22ca0b04fd2da2c63fe638f60afccbf64ef9f690064d8
SHA3 89c89108440a8645f43acab2177686d221305111c172162f728f92fb5e66695d

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22633
MD5 77f2e8232c56a194908d337ed5dca344
SHA1 767d92c1cabc792bd3590db3b74b2bec16a25712
SHA256 ed1c29cb026dd351529cd16f7d294f99979dd970d3c480feb22fa9cd87a58407
SHA3 dcf0134a648678a59799ecbd8920c522c6e3b0a17e2d689577be075a579dfdec

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07623
MD5 180b4fad5e4028e756b38d8622dc2c56
SHA1 19ad9bf2886c69036367843c63e486ef6d8e286f
SHA256 50ff793790bcf6260406df305dde11cff65c081f120bfe6dbd587f3984aee6f2
SHA3 f6dedd36dce0f7a27c378021e019125a79e78a72f65575d0e78777304b647c4e

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35334
MD5 b788c6e9f45ddc0ab3a1c7be30d586ac
SHA1 673a50dd538ada421378996c92ff1a95f8ff2547
SHA256 3106ccaa4e70b4b90b484f8a10ca4580f3bdf31d1b334d5e019c2fc7f0be2928
SHA3 e4f88610a614f782ea2b2ec951e8c835b7749f55cb1b13063bca7a09766aad45

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17001
MD5 a976fd637aba831c79b0aaaa8eb12435
SHA1 8b0dbf2ca42f695865d871cda97aa56b4a98953f
SHA256 099dbe25f21fde5a3f2510301fe1ca331404154af356cdc9c0b3b587881d3ada
SHA3 a9d25d923a3a57949a3fb299acc17c23dafa8cd0f8ebc1519c7a55f12e9aeff5

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29241
MD5 edb196db3227327fd759fe8e06e7629e
SHA1 ef589fc33e598750c252e582e8946c0a5f64514e
SHA256 85f1e5199b2a4d381d179e5078fd33966a8ced2dbdc3e89b70fd5906941f5931
SHA3 738220148315e680d01141c3d8ebb36e621fd14fba98445b5492325c9bd12de8

7 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x29c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.03282
MD5 b9da2e8945db60f84b8af0780b01ef4c
SHA1 ad39a2cd31ff14ac7a9ec9fc463bc1953c7ae3c4
SHA256 39f7b86bb47f463f54d54605a871b0467979eee349208ff9a125139501aeb55d
SHA3 c437a3743e1b34ffa5ff2f11b348ef16480a96a21d2084ff125bacf31d06aaf5

112

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21924
Detected Filetype Cursor file
MD5 874e41c97e9c38232490d3bea15ae8b3
SHA1 ae70b2c25c1566c2e13ac44e0057ef4f6daf8d91
SHA256 2c57fbd554735f2b8ff46f26b3d2d58a5a5e4152a02043e7fd6c552a43a3ceee
SHA3 b13a2c1efb8dad10ad85e8b4ce0067cbbea82053146cd5a81b0fecef2a15bf15
Preview

101

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05711
Detected Filetype Icon file
MD5 09c6f7b46b79503cdc5edc1b534f1b31
SHA1 4c8fbc286814b2903695ba9ab6506cc09fe88883
SHA256 1e0aa4b023e5e25e5403ba45b0d1885e717261cd8a1dc79b02bcebb3dc3114ed
SHA3 159b95958544ba9d23e5598563b17796fc6e9890cba2956c1d9ec0eaddbffbf3

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4296
MD5 c2a8008d6947d13f101a7057c1e3f98f
SHA1 eb9293bddf88cd83b1dabbc2aeecb4dd8b6a404c
SHA256 14aad36a166159105d2ca1ce2f1a24863f7bede0a147b16387d114c74b4939cc
SHA3 eb38bf214aa78e2c16743e8c5dd37d59df3b5bea19b0238f509c3f330f35dbec

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x242
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05061
MD5 3cd98ef72247ce15b8f79603bd3f233c
SHA1 94146f7062d29bc44c9da8b80601c901a11256fd
SHA256 86c556c57d39ff572bb390b5859de589f653595963e7308f810ceccbcc3f1126
SHA3 39506a8e18650d2376af48ff92dce75441f3b97be1b426ba2eaa38bdf934f04e

String Table contents

A game instance is already running.
Une instance de jeu est déjà en cours d'exécution.
Un'istanza del gioco è già in esecuzione.
Ein Spielvorgang läuft bereits.
Ya está funcionando una partida.
Uma instância do jogo já está sendo executada.
Игра уже запущена.
Gra jest już uruchomiona.
ゲームインスタンスが既に起動しています
게임 인스턴스가 이미 실행 중입니다.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.1
ProductVersion 1.0.0.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName WB Games Inc.
FileDescription The Lord of the Rings: War in the North
FileVersion (#2) 1, 0, 0, 1
InternalName The Lord of the Rings: War in the North
LegalCopyright TM & © New Line. THE LORD OF THE RINGS: WAR IN THE NORTH and the names of the characters, items, events and places therein are trademarks or registered trademarks of SZC under license to WBIE. (S11)
LegalTrademarks TM & © New Line. THE LORD OF THE RINGS: WAR IN THE NORTH and the names of the characters, items, events and places therein are trademarks or registered trademarks of SZC under license to WBIE. (S11)
OriginalFilename The Lord of the Rings: War in the North
ProductName The Lord of the Rings: War in the North
ProductVersion (#2) 1, 0, 0, 1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-24 19:49:05
Version 0.0
SizeofData 113
AddressOfRawData 0xaa0f1c
PointerToRawData 0xa9fb1c
Referenced File W:\Depot\LoTRWarInTheNorth\Remaster\Day0_Cert_514686\trixie\bin\pc\SteamRelease\witn.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-24 19:49:05
Version 0.0
SizeofData 20
AddressOfRawData 0xaa0f90
PointerToRawData 0xa9fb90

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-24 19:49:05
Version 0.0
SizeofData 1148
AddressOfRawData 0xaa0fa4
PointerToRawData 0xa9fba4

TLS Callbacks

StartAddressOfRawData 0x140aa1478
EndAddressOfRawData 0x140aa14d0
AddressOfIndex 0x141d4e288
AddressOfCallbacks 0x1409f2210
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001407CC2D4

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140b80e80

RICH Header

XOR Key 0x27475e43
Unmarked objects 0
C objects (33145) 61
ASM objects (33145) 37
253 (35207) 1
ASM objects (35207) 19
C objects (35207) 20
C++ objects (35207) 85
Imports (35223) 2
C objects (35223) 24
Imports (30148) 2
Imports (VS2008 SP1 build 30729) 2
C++ objects (33523) 27
C++ objects (33522) 656
C++ objects (33145) 194
Imports (30154) 2
Imports (34808) 2
Total imports 403
Imports (33145) 27
C++ objects (35223) 1581
Resource objects (35223) 1
151 1
Linker (35223) 1

Errors

Leave a comment

No comments yet.