d495844c87de83bb04a727ed0e989bee1e790611654697be64d3e64b981653ed

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-19 15:50:39
Detected languages English - United States
Debug artifacts dzpm_compat.pdb
CompanyName EgoLand Development Team
FileDescription EgoLand Project Manager & Build Harness
FileVersion 0.4.547
InternalName dz-project-manager.exe
LegalCopyright Copyright (c) 2026 EgoLand Team. All rights reserved.
OriginalFilename dz-project-manager.exe
ProductName dz-project-manager
ProductVersion 0.4.547

Plugin Output

Suspicious PEiD Signature: HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • sc.exe
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • GoDaddy.com
  • a.akamaihd.net
  • akamaihd.net
  • api.openai.com
  • fontello.com
  • github.com
  • googleapis.com
  • http://127.0.0.1
  • http://fontello.com
  • http://ns.adobe
  • http://www.w3.or3.org
  • http://www.w3.or3.org/1999/xlink
  • http://www.w3.org
  • http://www.w3.org/1999/xlinkxmlns
  • http://www.w3.org/2000/svg
  • http://www.w3.org/2000/svguse
  • http://www.w3.org/TR/SVG11/feature#BasicCliphttp
  • http://www.w3.org/TR/SVG11/feature#BasicFilterhttp
  • http://www.w3.org/TR/SVG11/feature#BasicGraphicsAttributehttp
  • http://www.w3.org/TR/SVG11/feature#BasicPaintAttributehttp
  • http://www.w3.org/TR/SVG11/feature#BasicStructurehttp
  • http://www.w3.org/TR/SVG11/feature#BasicTexthttp
  • http://www.w3.org/TR/SVG11/feature#Cliphttp
  • http://www.w3.org/TR/SVG11/feature#ConditionalProcessinghttp
  • http://www.w3.org/TR/SVG11/feature#ContainerAttributehttp
  • http://www.w3.org/TR/SVG11/feature#CoreAttributehttp
  • http://www.w3.org/TR/SVG11/feature#Filterhttp
  • http://www.w3.org/TR/SVG11/feature#Gradienthttp
  • http://www.w3.org/TR/SVG11/feature#GraphicsAttributehttp
  • http://www.w3.org/TR/SVG11/feature#Imagehttp
  • http://www.w3.org/TR/SVG11/feature#Markerhttp
  • http://www.w3.org/TR/SVG11/feature#Maskhttp
  • http://www.w3.org/TR/SVG11/feature#OpacityAttributehttp
  • http://www.w3.org/TR/SVG11/feature#PaintAttributehttp
  • http://www.w3.org/TR/SVG11/feature#Patternhttp
  • http://www.w3.org/TR/SVG11/feature#SVG-statichttp
  • http://www.w3.org/TR/SVG11/feature#SVGDOM-statichttp
  • http://www.w3.org/TR/SVG11/feature#Shapehttp
  • http://www.w3.org/TR/SVG11/feature#Structurehttp
  • http://www.w3.org/TR/SVG11/feature#Stylehttp
  • http://www.w3.org/TR/SVG11/feature#Texthttp
  • http://www.w3.org/TR/SVG11/feature#XlinkAttribute
  • http://www.w3.org/XML/1998/namespace
  • http://www.w3.org/XML/1998/namespacexml
  • https://api.anthropic.comclaude-sonnet-4-6ANTHROPIC_API_KEYu8src
  • https://api.anthropic.comclaude-sonnet-4-6ANTHROPIC_API_KEYu8src\pbo\derap.rs
  • https://api.openai.com
  • https://api.openai.com/v1OPENAI_API_KEYhttps
  • https://docs.rs
  • https://github.com
  • https://registry.khronos.org
  • https://registry.khronos.org/vulkan/specs/1.3-extensions/html/vkspec.html#devsandqueues-lost-device
  • https://steamcdn-a.akamaihd.net
  • https://steamcdn-a.akamaihd.net/client/installer/steamcmd.zipextract
  • https://steamcommunity.com
  • https://translate.googleapis.com
  • https://translate.googleapis.com/translate_a/singlegtxsltldtq
  • khronos.org
  • openai.com
  • openssl.org
  • registry.khronos.org
  • steamcdn-a.akamaihd.net
  • steamcommunity.com
  • translate.googleapis.com
  • w3.or3.org
  • www.w3.or3.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
Can access the registry:
  • RegGetValueW
  • RegCloseKey
  • RegOpenKeyExW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
Uses Windows's Native API:
  • NtCancelIoFileEx
  • NtCreateFile
  • NtReadFile
  • NtWriteFile
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtOpenFile
Uses Microsoft's cryptographic API:
  • CryptStringToBinaryA
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • MapVirtualKeyW
  • GetForegroundWindow
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Info The PE is digitally signed. Signer: EgoLand Development Team
Issuer: EgoLand Development Team
Suspicious VirusTotal score: 1/70 (Scanned on 2026-09-19 15:53:09) Gridinsoft: Trojan.Heur!.00014023

Hashes

MD5 ef1f36c6c15cf4265f2bd0544bc23f72 🔍
SHA1 52a8297f0e775a110381b9cbd679e60affa17c7e 🔍
SHA256 d495844c87de83bb04a727ed0e989bee1e790611654697be64d3e64b981653ed 🔍
SHA3 940d88a7ac978e285b1170d44ffd42c5afb440995dc538e629b90d70542ca7ae 🔍
SSDeep 196608:NhWPWKJa6ih/kOnipR4JjrJQRHDcyEvl9A:3GeJkqJjIEvl9A 🔍
Imports Hash 763c53fed20d3dd629320bba4cdbb655 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-19 15:50:39
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x10fc000
SizeOfInitializedData 0x3b5000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000109362C (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x14b6000
SizeOfHeaders 0x400
Checksum 0x14b7329
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0b9e43a781d3cd7ffbf4616de364abf0 🔍
SHA1 5034a044fbab075fbe2f23c7ec0e99774bc00d7e 🔍
SHA256 f50c6219e0b6af08356406f9b982c4564284c850cd44b7073d6b4ef6f226d9fd 🔍
SHA3 0963bfb6137cd61eeea2dacd6efa54545e1947945632dfac3fa48b56d046c802 🔍
VirtualSize 0x10fbe50
VirtualAddress 0x1000
SizeOfRawData 0x10fc000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.20496

.rdata

MD5 b400c1a1dc0b760af7a99c8b3ea267d0 🔍
SHA1 4c948b737d87da05f606f767bb2a4553a6d6c1d4 🔍
SHA256 0d5576f1c7d727495109f1dc2d7bf42770e9237a0c6d46a8665ec6b99b9460e7 🔍
SHA3 8c9d3e2a0edb041c13ce6c0d62565b239e444dc0f8997723b84f6d71b963e454 🔍
VirtualSize 0x3485cc
VirtualAddress 0x10fd000
SizeOfRawData 0x348600
PointerToRawData 0x10fc400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.00961

.data

MD5 5041c500d0d9c002b14ab989a4172480 🔍
SHA1 c8a60b0a2966e2ba459bf3162498fef699461718 🔍
SHA256 9d90611fdf00d3f596cea28d65f1e42e1faaedce0888d116fe6dbdcd70044a99 🔍
SHA3 bcec30ff2fc78841c7a5aec580eaf7637058bface56f45a2caaaec72f290bea4 🔍
VirtualSize 0x7248
VirtualAddress 0x1446000
SizeOfRawData 0x6400
PointerToRawData 0x1444a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.1561

.pdata

MD5 be6421b8d5c8801274e7eb34101e5314 🔍
SHA1 198ecc4b08142cb938ac7b6a76c9f4f3f1ca90bf 🔍
SHA256 f74428eab8807367a20d5a7fc2e8c8eae13fdf207a88e8513868313057feb9c0 🔍
SHA3 0265d9ccd95a81125f610efee57fc05eeb33a14fd0063cfaf37a3111395d5e2f 🔍
VirtualSize 0x34398
VirtualAddress 0x144e000
SizeOfRawData 0x34400
PointerToRawData 0x144ae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.51636

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x1483000
SizeOfRawData 0x200
PointerToRawData 0x147f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 25eb47aef25d54e6649dc1e52eb55149 🔍
SHA1 800d202713d8aaaf058a768b2ecd5307098053cf 🔍
SHA256 12d8b8b090dd49a420087a379df2dcede0d2fce05979eb6d7e6e7c6101e09e94 🔍
SHA3 782826355347f447d27bb842ffb0ad092b51123d9356ee55eab13abc591e8868 🔍
VirtualSize 0x1cb10
VirtualAddress 0x1484000
SizeOfRawData 0x1cc00
PointerToRawData 0x147f400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.98

.reloc

MD5 63b05c1a27e6a8042132206ae6a10504 🔍
SHA1 9c77bc9c73f0680cad0830fcab59fc7a0a89f36b 🔍
SHA256 645b2aa87d0dba9d7910dfb9f0c107cceefcef3e92441e9b4c9ee781439000f4 🔍
SHA3 a9fdcae9be1b2b6af466f964897bfef306c58f18182ba6a7b2868db06d265ec6 🔍
VirtualSize 0x14348
VirtualAddress 0x14a1000
SizeOfRawData 0x14400
PointerToRawData 0x149c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.4978

Imports

KERNEL32.dll CreateNamedPipeW
CloseHandle
OpenProcess
GetExitCodeProcess
CreateFileW
CreateProcessW
WaitForSingleObject
GetLogicalDrives
GetDriveTypeW
GetStdHandle
AttachConsole
SetConsoleCtrlHandler
QueryFullProcessImageNameW
VirtualLock
VirtualUnlock
GetCurrentThreadId
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
AssignProcessToJobObject
GetCurrentProcess
SetCurrentDirectoryW
LoadLibraryW
FreeLibrary
GetProcAddress
CreateJobObjectW
SetInformationJobObject
HeapSize
LCMapStringW
CompareStringW
GetStringTypeW
SetStdHandle
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
UnhandledExceptionFilter
IsProcessorFeaturePresent
GetCommandLineA
RtlPcToFileHeader
DeleteCriticalSection
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
RaiseException
EncodePointer
FlsGetValue
RtlUnwindEx
SetUnhandledExceptionFilter
InitializeSListHead
bcryptprimitives.dll ProcessPrng
kernel32.dll WriteConsoleW
ReadConsoleW
SetEnvironmentVariableW
GetEnvironmentVariableW
DeviceIoControl
CreateSymbolicLinkW
ReleaseMutex
CreateMutexA
WaitForSingleObjectEx
FindFirstFileExW
RemoveDirectoryW
GetWindowsDirectoryW
GetFileInformationByHandleEx
GetFileInformationByHandle
SetFileTime
CancelIo
RtlLookupFunctionEntry
RtlCaptureContext
WriteFileEx
SleepEx
ReadFileEx
HeapReAlloc
GetCurrentThread
CopyFileExW
SetFileInformationByHandle
MoveFileExW
GetFullPathNameW
CompareStringOrdinal
GetConsoleOutputCP
GlobalSize
SetWaitableTimer
CreateWaitableTimerExW
GetCurrentProcessId
LoadLibraryA
VirtualProtect
CreateFileMappingW
MapViewOfFile
DuplicateHandle
FlushFileBuffers
GetSystemDirectoryW
AddVectoredExceptionHandler
GetModuleHandleW
RemoveVectoredExceptionHandler
FindNextFileW
GetProcessHeap
HeapFree
LoadLibraryExA
FlsFree
HeapAlloc
CreateEventW
SetThreadStackGuarantee
GetConsoleScreenBufferInfo
GetConsoleMode
SetConsoleMode
SetConsoleTextAttribute
CreateEventA
GetFileAttributesW
GetUserPreferredUILanguages
CreateDirectoryW
SwitchToThread
GetStartupInfoW
GetSystemInfo
GetBinaryTypeW
LocalFree
GetTempPathW
ExitProcess
DeleteFileW
ReadFile
WriteFile
SetFilePointerEx
UnmapViewOfFile
GlobalFree
FindClose
GetTimeZoneInformationForYear
CreatePipe
CreatePseudoConsole
InitializeProcThreadAttributeList
UpdateProcThreadAttribute
GetProcessId
TerminateProcess
ClosePseudoConsole
DeleteProcThreadAttributeList
PeekNamedPipe
RegisterWaitForSingleObject
UnregisterWaitEx
GetSystemTimePreciseAsFileTime
FlsAlloc
FlsSetValue
IsThreadAFiber
GetFileType
GetSystemTimeAsFileTime
WaitForMultipleObjects
RtlVirtualUnwind
GlobalUnlock
GetFinalPathNameByHandleW
SetLastError
QueryPerformanceFrequency
GlobalAlloc
SetHandleInformation
QueryPerformanceCounter
GlobalLock
FreeEnvironmentStringsW
GetEnvironmentStringsW
WideCharToMultiByte
CreateIoCompletionPort
PostQueuedCompletionStatus
ConnectNamedPipe
GetQueuedCompletionStatusEx
MultiByteToWideChar
GetCurrentDirectoryW
SetFileCompletionNotificationModes
IsDebuggerPresent
GetCommandLineW
GetOverlappedResult
CancelIoEx
FormatMessageW
lstrlenW
GetModuleHandleA
Sleep
SetThreadErrorMode
GetModuleHandleExW
LoadLibraryExW
GetModuleFileNameW
GetLastError
CreateThread
secur32.dll EncryptMessage
FreeCredentialsHandle
InitializeSecurityContextW
AcquireCredentialsHandleA
AcceptSecurityContext
DecryptMessage
QueryContextAttributesW
DeleteSecurityContext
FreeContextBuffer
user32.dll GetRawInputData
SetWindowPlacement
GetAsyncKeyState
MapVirtualKeyW
ToUnicodeEx
RedrawWindow
ClientToScreen
IsWindowVisible
CloseTouchInputHandle
GetTouchInputInfo
GetForegroundWindow
SendInput
TrackMouseEvent
SetCapture
DefWindowProcA
RegisterClassExA
CreateWindowExA
IsIconic
MsgWaitForMultipleObjectsEx
IsProcessDPIAware
DestroyIcon
ReleaseCapture
CloseClipboard
RegisterClipboardFormatW
GetClipboardData
DispatchMessageW
TranslateMessage
GetKeyboardLayout
GetActiveWindow
RegisterTouchWindow
GetWindowLongPtrW
GetClientRect
PostMessageW
SetWindowPos
InvalidateRgn
GetKeyState
SetCursor
DestroyWindow
EmptyClipboard
RegisterRawInputDevices
DestroyCursor
RegisterWindowMessageA
ValidateRect
SetWindowDisplayAffinity
SystemParametersInfoA
MonitorFromPoint
ChangeDisplaySettingsExW
ShowCursor
ClipCursor
GetClipCursor
CreateIcon
AdjustWindowRectEx
GetWindowLongW
SetWindowLongW
PeekMessageW
SendMessageW
ShowWindow
SetWindowTextW
GetWindowPlacement
SetClipboardData
SetForegroundWindow
CreateWindowExW
RegisterClassExW
TrackPopupMenu
SetMenuDefaultItem
EnableMenuItem
GetSystemMenu
GetWindowRect
GetSystemMetrics
DefWindowProcW
SetWindowLongPtrW
MonitorFromRect
ScreenToClient
GetMenu
GetCursorPos
MonitorFromWindow
GetKeyboardState
GetMonitorInfoW
LoadCursorW
MapVirtualKeyExW
ReleaseDC
GetDC
OpenClipboard
FlashWindowEx
ws2_32.dll getsockname
getaddrinfo
WSAStartup
WSAGetLastError
WSAIoctl
setsockopt
closesocket
getpeername
shutdown
WSACleanup
bind
send
recv
getsockopt
connect
ioctlsocket
WSASend
freeaddrinfo
WSASocketW
advapi32.dll CredWriteW
CredDeleteW
RegGetValueW
OpenProcessToken
GetTokenInformation
RegCloseKey
SystemFunction036
CredReadW
CredFree
ImpersonateAnonymousToken
RegOpenKeyExW
RevertToSelf
RegQueryValueExW
api-ms-win-core-synch-l1-2-0.dll WakeByAddressSingle
WakeByAddressAll
WaitOnAddress
gdi32.dll ChoosePixelFormat
GetPixelFormat
SetPixelFormat
BitBlt
SwapBuffers
SelectObject
CreateDIBSection
CreateCompatibleDC
DeleteDC
DescribePixelFormat
DeleteObject
GetDeviceCaps
CreateRectRgn
crypt32.dll CertFreeCertificateChain
CertDuplicateCertificateContext
CertDuplicateCertificateChain
CertAddCertificateContextToStore
CertDuplicateStore
CertCreateCertificateContext
CertCloseStore
CryptStringToBinaryA
CertFreeCertificateContext
CertEnumCertificatesInStore
CertOpenStore
CertVerifyCertificateChainPolicy
CertGetCertificateChain
ole32.dll RevokeDragDrop
CoInitializeEx
RegisterDragDrop
CoUninitialize
CoCreateInstance
OleInitialize
combase.dll CoTaskMemFree
shell32.dll SHCreateItemFromParsingName
SHGetKnownFolderPath
DragFinish
DragQueryFileW
ShellExecuteExW
oleaut32.dll GetErrorInfo
SysFreeString
SysStringLen
bcrypt.dll BCryptGenRandom
ntdll.dll NtCancelIoFileEx
NtCreateFile
RtlNtStatusToDosError
NtReadFile
NtWriteFile
NtCreateNamedPipeFile
NtDeviceIoControlFile
NtOpenFile
imm32.dll ImmGetContext
ImmAssociateContextEx
ImmGetCompositionStringW
ImmReleaseContext
dwmapi.dll DwmSetWindowAttribute
DwmEnableBlurBehindWindow
uxtheme.dll SetWindowTheme
opengl32.dll wglCreateContext
wglMakeCurrent
wglGetProcAddress
wglDeleteContext
wglGetCurrentContext
d3dcompiler_47.dll D3DCompile
api-ms-win-core-winrt-error-l1-1-0.dll RoOriginateErrorW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x381
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70068
Detected Filetype PNG graphic file
MD5 e23377d8dad872243c15949ad6c9944b 🔍
SHA1 2eab7c04ca7d891518e78817201507daeda4d804 🔍
SHA256 466ae08c9cff60163905ddb3bcb043bd26d137f727191aec9c48bd3ff86f8825 🔍
SHA3 1ed5c63c4e9c35f89d03d130f124ea11d2b23eb96697ed3c3ff38f18eca796cb 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91085
Detected Filetype PNG graphic file
MD5 3aeef74d75b334464553331a9b69c348 🔍
SHA1 36fe82b7c44d00deedee0ebdec06ec7d5397de9a 🔍
SHA256 594f7eff2a34b769076acb6eaecfa0c3b689bb27c7e2ffe1b8c660001c480b41 🔍
SHA3 fc3b3986e3b1e4b32a18a005e562197358585c57262d664e07865f47b2bdd523 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x12be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9549
Detected Filetype PNG graphic file
MD5 78a5c9f5cb8798e73154f247c5230ae8 🔍
SHA1 c5ca1cd8cef62448dcf28a4eb173385dc710a506 🔍
SHA256 4053f04e042c36ba6198859fd9ff0b226ffa3ec78e2eb904ee075a52aa87070c 🔍
SHA3 d4d974b987afa9791e7d5be1601dbab01f0f8bad60bb54b146ab92770389dfd9 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1d48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96713
Detected Filetype PNG graphic file
MD5 1e093c558dcb38c0e8a1b7f42322fb08 🔍
SHA1 805929c15b8ff3f14ee0da3ac0e3bf49cc7f5090 🔍
SHA256 ee595d372bf65c8710fbd696abadaa7747106499b09e55871cd5deb1c70cb60d 🔍
SHA3 d5cf3153f27253cce44e1d87a72cf4a6240cd29568e40198fd8e961b991279f9 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x58c2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.988
Detected Filetype PNG graphic file
MD5 c2e503d08acf1a8b4060a7740f6dcbd9 🔍
SHA1 66505d3a525ebe1cb72be195d4a7e91384da283b 🔍
SHA256 dc522387cdccd7d965988730b9e8eacbade57d94f1d5a9ac3a65857ae7ef64dd 🔍
SHA3 391c48b375eadc30183adc3cde7db20e55baab41599161e935656ffcd1a64d35 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x12a4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99504
Detected Filetype PNG graphic file
MD5 e751127583d4e8cec2f56ba8e65322d8 🔍
SHA1 d51e2ce6eeb511978bf1ee39c95359a180a304bc 🔍
SHA256 9d9993285d63603e738b920ec84491fa1f75cc443b92bfb524d54accf48ed67e 🔍
SHA3 cbb445db11e5b4fef72a446a021f243e4cbfa7d2f75e7f6447cc3cc828bbcda8 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84352
Detected Filetype Icon file
MD5 6b528bb6737e35cd4a4ee2019478dfa6 🔍
SHA1 0437d7fe4f8d7af8a087ab52e55bf05abeaf477c 🔍
SHA256 d4a7f7d399e29a9a7cf2923a8c1d951b38552c402d2628613a44d62c27bc3c22 🔍
SHA3 0e82597c4a3675834f0b1c1984f5b6e5ae009352671f493b93dbd6f1f28e2204 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43529
MD5 55a970699c4d3dd0d525a5819c5f45fc 🔍
SHA1 22788d4e3507f28140e79f6c29064fb0b433c99e 🔍
SHA256 90afdf8a6edcad0c4c1a914efd9e6f84632e74782c50176195befd6b344ea1d1 🔍
SHA3 48538dbc065dc54619d9c677150a80e90001c85415c567289dddae0a32f54ef1 🔍

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x445
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28914
MD5 95b373eb92a2c84ce976d9451e262aad 🔍
SHA1 c2cfd8c1eccabb3b23c3d004c29cbee0bca5f848 🔍
SHA256 db7695c3c8dcf2143c8cbb0916298bb59d468e7383db5bf820799fb88c7a7fa0 🔍
SHA3 151349b6f81321ad5fbe6a17f4a903f2d05124b92f74293c34b577a669429239 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.4.547.0
ProductVersion 0.4.547.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName EgoLand Development Team
FileDescription EgoLand Project Manager & Build Harness
FileVersion (#2) 0.4.547
InternalName dz-project-manager.exe
LegalCopyright Copyright (c) 2026 EgoLand Team. All rights reserved.
OriginalFilename dz-project-manager.exe
ProductName dz-project-manager
ProductVersion (#2) 0.4.547
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-19 15:50:39
Version 0.0
SizeofData 40
AddressOfRawData 0x142926c
PointerToRawData 0x142866c
Referenced File dzpm_compat.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-19 15:50:39
Version 0.0
SizeofData 20
AddressOfRawData 0x1429294
PointerToRawData 0x1428694

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-19 15:50:39
Version 0.0
SizeofData 1012
AddressOfRawData 0x14292a8
PointerToRawData 0x14286a8

TLS Callbacks

StartAddressOfRawData 0x1414296f8
EndAddressOfRawData 0x1414299c9
AddressOfIndex 0x14144c748
AddressOfCallbacks 0x1410fdcd0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14144b900

RICH Header

XOR Key 0xfc7cf096
Unmarked objects 0
C++ objects (33145) 145
C objects (33145) 55
ASM objects (33145) 27
ASM objects (35403) 9
C objects (35403) 16
C++ objects (35403) 40
C objects (35728) 12
Imports (33145) 3
Total imports 552
Unmarked objects (#2) 302
Resource objects (35728) 1
Linker (35728) 1

Errors

Leave a comment

No comments yet.