| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Aug-21 11:55:57 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\stan\RiderProjects\PG3DUnlock\x64\Release\PG3DUnlock.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 4/72 (Scanned on 2025-09-11 07:17:55) |
Cynet:
Malicious (score: 100)
MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!CF0B07BA95E1 Skyhigh: BehavesLike.Win64.Generic.gh |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2025-Aug-21 11:55:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x52800 |
| SizeOfInitializedData | 0x1d000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000051470 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x75000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SuspendThread
AllocConsole GetConsoleWindow GetModuleHandleW GetProcAddress InitializeSListHead GetSystemTimeAsFileTime GetCurrentProcessId IsDebuggerPresent IsProcessorFeaturePresent TerminateProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext WakeAllConditionVariable ResumeThread GetThreadContext SetThreadContext IsBadReadPtr VirtualAlloc GetModuleHandleA VirtualFree VirtualQuery SetLastError CloseHandle WaitForSingleObject CreateEventA LoadLibraryA QueryPerformanceCounter QueryPerformanceFrequency MultiByteToWideChar GetLocaleInfoA GlobalAlloc GlobalUnlock GlobalLock GlobalFree ReleaseSRWLockExclusive AcquireSRWLockExclusive GetCurrentThreadId WideCharToMultiByte GetCurrentThread FlushInstructionCache K32GetModuleInformation SleepConditionVariableSRW Sleep VirtualProtect GetLastError GetCurrentProcess |
|---|---|
| USER32.dll |
LoadCursorA
SetCursor SetCursorPos GetCursorPos GetForegroundWindow IsWindowUnicode ShowCursor PostQuitMessage ReleaseCapture SetCapture GetCapture GetKeyState GetMessageExtraInfo TrackMouseEvent GetKeyboardLayout ClientToScreen GetAsyncKeyState GetActiveWindow RegisterClassExW UnregisterClassW ScreenToClient CreateWindowExW SetWindowLongPtrW DestroyWindow MapVirtualKeyW CallWindowProcW DefWindowProcW ShowWindow EmptyClipboard OpenClipboard CloseClipboard GetClientRect SetClipboardData ClipCursor GetClipboardData |
| MSVCP140.dll |
?_Throw_Cpp_error@std@@YAXH@Z
?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A _Cnd_do_broadcast_at_thread_exit _Thrd_id _Query_perf_counter _Thrd_detach _Thrd_join ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?good@ios_base@std@@QEBA_NXZ _Mtx_lock _Mtx_unlock ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ?_Xbad_alloc@std@@YAXXZ _Query_perf_frequency ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??1_Lockit@std@@QEAA@XZ ?_Xlength_error@std@@YAXPEBD@Z ?id@?$ctype@D@std@@2V0locale@2@A ?_Xout_of_range@std@@YAXPEBD@Z ?_Id_cnt@id@locale@std@@0HA ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??0_Lockit@std@@QEAA@H@Z ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z |
| D3DCOMPILER_47.dll |
D3DCompile
|
| IMM32.dll |
ImmReleaseContext
ImmSetCandidateWindow ImmSetCompositionWindow ImmGetContext |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__std_terminate
__C_specific_handler memcpy memset __std_exception_copy __std_exception_destroy strstr memchr memmove memcmp _CxxThrowException __current_exception __current_exception_context __std_type_info_destroy_list |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_beginthreadex _crt_atexit _execute_onexit_table _register_onexit_function _initialize_onexit_table _initialize_narrow_environment _configure_narrow_argv _seh_filter_dll _errno terminate _initterm_e _invalid_parameter_noinfo_noreturn _cexit _invoke_watson |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
atof |
| api-ms-win-crt-stdio-l1-1-0.dll |
fread
fflush fclose _wfopen freopen_s fseek __stdio_common_vsprintf ftell __stdio_common_vsscanf __stdio_common_vfprintf fwrite __acrt_iob_func __stdio_common_vsprintf_s |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
calloc free malloc |
| api-ms-win-crt-string-l1-1-0.dll |
strncmp
strncpy strcmp |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-math-l1-1-0.dll |
sqrtf
fmodf log logf pow acosf cosf ceilf sinf powf |
| SHELL32.dll |
ShellExecuteA
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Aug-21 11:55:57 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x604cc |
| PointerToRawData | 0x5f0cc |
| Referenced File | C:\Users\stan\RiderProjects\PG3DUnlock\x64\Release\PG3DUnlock.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Aug-21 11:55:57 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x60528 |
| PointerToRawData | 0x5f128 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Aug-21 11:55:57 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x6053c |
| PointerToRawData | 0x5f13c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Aug-21 11:55:57 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1800608d8 |
|---|---|
| EndAddressOfRawData | 0x1800608e0 |
| AddressOfIndex | 0x1800696ac |
| AddressOfCallbacks | 0x1800547c0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1800690c0 |
| XOR Key | 0xdb758e6e |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 4 |
| C objects (35207) | 8 |
| C++ objects (35207) | 26 |
| Imports (35207) | 6 |
| C++ objects (34120) | 11 |
| Imports (33140) | 15 |
| Total imports | 244 |
| C++ objects (LTCG) (35214) | 9 |
| Resource objects (35214) | 1 |
| Linker (35214) | 1 |