| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-May-04 16:38:11 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\mobil\Downloads\FiveM External Base_[unknowncheats.me]_\FiveM External Base\x64\Release\CFramework.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 31/69 (Scanned on 2026-06-06 02:33:39) |
ALYac:
Application.Generic.5061333
APEX: Malicious Antiy-AVL: Trojan/Win32.Agent Arcabit: Application.Generic.D4D3AD5 BitDefender: Application.Generic.5061333 Bkav: W32.Malware.E2A26148 CTX: exe.trojan.generic CrowdStrike: win/malicious_confidence_70% (W) Cylance: Unsafe DeepInstinct: MALICIOUS ESET-NOD32: Win64/GameHack.KE potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Application.Generic.5061333 (B) Fortinet: Adware/GameHack GData: Application.Generic.5061333 Google: Detected Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.4264098717 MaxSecure: Trojan.Malware.324995110.susgen McAfeeD: ti!D4DD8EBB3085 MicroWorld-eScan: Application.Generic.5061333 Microsoft: Trojan:Win32/Kepavll!rfn Paloalto: generic.ml Rising: Trojan.Kryptik@AI.95 (RDML:777lVBfsaE65Co4FQvw0GQ) SentinelOne: Static AI - Suspicious PE Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence TrellixENS: Artemis!31D95CD864BB TrendMicro-HouseCall: Trojan.Win64.Gen.TL0101E926ZU VIPRE: Application.Generic.5061333 Varist: W64/ABTrojan.YMHE-2166 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-May-04 16:38:11 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x61400 |
| SizeOfInitializedData | 0x18200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000610C4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x7d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetLocaleInfoA
LoadLibraryA QueryPerformanceFrequency GetProcAddress VerSetConditionMask FreeLibrary QueryPerformanceCounter CreateToolhelp32Snapshot CloseHandle Module32Next OpenProcess AcquireSRWLockExclusive WakeAllConditionVariable MultiByteToWideChar GlobalUnlock RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetModuleHandleW GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead K32GetModuleBaseNameA ReadProcessMemory GetModuleHandleA WideCharToMultiByte GlobalLock GlobalFree RtlCaptureContext GlobalAlloc Sleep SleepConditionVariableSRW WriteProcessMemory ReleaseSRWLockExclusive |
|---|---|
| USER32.dll |
SetLayeredWindowAttributes
CreateWindowExA DefWindowProcA RegisterClassExA SetWindowDisplayAffinity GetWindowLongA SetWindowLongA ShowWindow SetWindowPos TranslateMessage DestroyWindow DispatchMessageA GetWindowThreadProcessId GetAsyncKeyState PeekMessageA UpdateWindow SetForegroundWindow GetKeyState GetMessageExtraInfo GetWindowDisplayAffinity UnregisterClassA PostQuitMessage FindWindowA LoadCursorA ScreenToClient GetCapture ClientToScreen TrackMouseEvent MessageBoxA GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect SetProcessDPIAware IsWindowUnicode SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard GetCursorPos SetCursorPos ReleaseCapture |
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
?_Throw_Cpp_error@std@@YAXH@Z _Cnd_do_broadcast_at_thread_exit _Thrd_detach |
| IMM32.dll |
ImmSetCompositionWindow
ImmReleaseContext ImmGetContext ImmSetCandidateWindow |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__C_specific_handler
_CxxThrowException memset memcpy memcmp __current_exception_context strstr __std_terminate __std_exception_copy __std_exception_destroy memmove memchr __current_exception |
| api-ms-win-crt-runtime-l1-1-0.dll |
_get_narrow_winmain_command_line
_initterm _initterm_e exit _exit _configure_narrow_argv _c_exit _register_thread_local_exe_atexit_callback _seh_filter_exe _cexit _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _invoke_watson _beginthreadex _crt_atexit _set_app_type terminate |
| api-ms-win-crt-stdio-l1-1-0.dll |
ftell
__stdio_common_vsprintf_s __stdio_common_vfprintf fflush fseek __stdio_common_vsprintf _wfopen fwrite __acrt_iob_func __p__commode _set_fmode fclose fread __stdio_common_vsscanf |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-string-l1-1-0.dll |
strncpy
strcmp strncmp |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_callnewh _set_new_mode malloc |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
|
| api-ms-win-crt-math-l1-1-0.dll |
sinf
sqrtf powf acosf atan2f logf ceilf fmodf cosf __setusermatherr |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-04 16:38:11 |
| Version | 0.0 |
| SizeofData | 136 |
| AddressOfRawData | 0x6db28 |
| PointerToRawData | 0x6c328 |
| Referenced File | C:\Users\mobil\Downloads\FiveM External Base_[unknowncheats.me]_\FiveM External Base\x64\Release\CFramework.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-04 16:38:11 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x6dbb0 |
| PointerToRawData | 0x6c3b0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-04 16:38:11 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0x6dbc4 |
| PointerToRawData | 0x6c3c4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-04 16:38:11 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14006df60 |
|---|---|
| EndAddressOfRawData | 0x14006df68 |
| AddressOfIndex | 0x140076898 |
| AddressOfCallbacks | 0x140063628 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140076040 |
| XOR Key | 0xe8358d7 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 30 |
| Imports (35207) | 6 |
| Imports (33145) | 15 |
| Total imports | 183 |
| C++ objects (LTCG) (35226) | 18 |
| Resource objects (35226) | 1 |
| Linker (35226) | 1 |
No comments yet.