| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Apr-24 02:13:56 |
| Detected languages |
English - United States
Process Default Language |
| Debug artifacts |
D:\jenkins_home\workspace\plat-launcher-gitlab-release\.build\win.x64\output\Release\bin\launcher.pdb
|
| CompanyName | Cognosphere |
| ProductName | HoYoPlay |
| ProductVersion | 1.7.3.261 |
| FileVersion | 1.7.3.261 |
| FileDescription | HoYoPlay |
| LegalCopyright | Copyright © COGNOSPHERE. All Rights Reserved. |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | The PE is possibly packed. | Unusual section name found: memcpy_ |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: COGNOSPHERE PTE. LTD.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/72 (Scanned on 2025-06-09 02:24:16) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2025-Apr-24 02:13:56 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x5ee00 |
| SizeOfInitializedData | 0x86e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000004070 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xec000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xec7f1 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetEnvironmentVariableW
DecodePointer CloseHandle GetLastError HeapDestroy HeapAlloc HeapReAlloc HeapFree HeapSize GetProcessHeap InitializeCriticalSectionEx DeleteCriticalSection CreateProcessW FindResourceExW GetModuleFileNameW LoadResource LockResource SizeofResource FindResourceW LocalFree FormatMessageW WriteConsoleW CreateFileW ReadConsoleW ReadFile GetConsoleMode GetConsoleOutputCP FlushFileBuffers SetFilePointerEx GetFileSizeEx GetStringTypeW SetStdHandle SetConsoleCtrlHandler EnumSystemLocalesW IsDebuggerPresent OutputDebugStringW RaiseException EnterCriticalSection LeaveCriticalSection ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlPcToFileHeader RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList SetLastError EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree FreeLibrary GetProcAddress LoadLibraryExW GetCurrentProcess TerminateProcess ExitProcess GetModuleHandleExW GetStdHandle WriteFile GetCurrentThread GetFileType FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW GetTempPathW FlsAlloc FlsGetValue FlsSetValue FlsFree GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID RtlUnwind |
|---|---|
| USER32.dll |
MessageBoxW
UnregisterClassW |
| SHELL32.dll |
ShellExecuteExW
|
| SHLWAPI.dll |
PathRemoveFileSpecW
PathAppendW |
| VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.7.3.261 |
| ProductVersion | 1.7.3.261 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Cognosphere |
| ProductName | HoYoPlay |
| ProductVersion (#2) | 1.7.3.261 |
| FileVersion (#2) | 1.7.3.261 |
| FileDescription | HoYoPlay |
| LegalCopyright | Copyright © COGNOSPHERE. All Rights Reserved. |
| Resource LangID | Process Default Language |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-24 02:13:56 |
| Version | 0.0 |
| SizeofData | 126 |
| AddressOfRawData | 0x6c2e8 |
| PointerToRawData | 0x6b4e8 |
| Referenced File | D:\jenkins_home\workspace\plat-launcher-gitlab-release\.build\win.x64\output\Release\bin\launcher.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-24 02:13:56 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x6c368 |
| PointerToRawData | 0x6b568 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-24 02:13:56 |
| Version | 0.0 |
| SizeofData | 1184 |
| AddressOfRawData | 0x6c37c |
| PointerToRawData | 0x6b57c |
| StartAddressOfRawData | 0x14006c868 |
|---|---|
| EndAddressOfRawData | 0x14006c870 |
| AddressOfIndex | 0x140074f60 |
| AddressOfCallbacks | 0x140060468 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400740c0 |
| XOR Key | 0x45dd4d |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 5 |
| C++ objects (30795) | 140 |
| C objects (30795) | 10 |
| Unmarked objects (#2) | 1 |
| C objects (VS 2015-2022 runtime 33030) | 16 |
| ASM objects (VS 2015-2022 runtime 33030) | 17 |
| C++ objects (VS 2015-2022 runtime 33030) | 44 |
| Imports (30795) | 11 |
| Total imports | 112 |
| C++ objects (33134) | 1 |
| Resource objects (33134) | 1 |
| 151 | 1 |
| Linker (33134) | 1 |
No comments yet.