| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jun-15 02:01:54 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\uid\Desktop\past\mixcodes\x64\Release\Fivem-External.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jun-15 02:01:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xb9e00 |
| SizeOfInitializedData | 0x567800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000B2A40 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x625000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
|---|---|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| ADVAPI32.dll |
GetTokenInformation
RevertToSelf PrivilegeCheck SetTokenInformation OpenProcessToken SetThreadToken CreateProcessAsUserW RegQueryValueExW LookupPrivilegeValueW DuplicateTokenEx |
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| WINHTTP.dll |
WinHttpCloseHandle
WinHttpOpenRequest WinHttpReadData WinHttpOpen WinHttpReceiveResponse WinHttpSendRequest WinHttpConnect WinHttpQueryDataAvailable |
| KERNEL32.dll |
AcquireSRWLockExclusive
SetUnhandledExceptionFilter InitializeSListHead WakeAllConditionVariable SleepConditionVariableSRW GetCurrentProcessId GetCurrentThreadId ReleaseSRWLockExclusive Sleep GetTickCount64 WaitForSingleObject CloseHandle VirtualAllocEx CreateRemoteThread VirtualFreeEx CompareFileTime K32GetMappedFileNameA Thread32Next Thread32First ResumeThread GetModuleHandleA OpenProcess CreateToolhelp32Snapshot GetProcAddress LocalFree GetThreadTimes OpenThread VirtualQueryEx Process32NextW Process32FirstW Module32FirstW ReadProcessMemory Module32NextW GlobalLock WideCharToMultiByte GlobalUnlock GetStartupInfoW GetCommandLineW GetCurrentProcess GetLastError ExitProcess MultiByteToWideChar GlobalAlloc GlobalFree GetLocaleInfoA LoadLibraryA QueryPerformanceFrequency FreeLibrary QueryPerformanceCounter GetModuleHandleW WriteProcessMemory K32GetModuleInformation GetSystemTimeAsFileTime SuspendThread |
| USER32.dll |
TranslateMessage
OpenClipboard DefWindowProcW PostMessageW PeekMessageW CallNextHookEx GetMonitorInfoW MapWindowPoints MoveWindow SetWindowsHookExW SetWindowLongW SetForegroundWindow GetMessageExtraInfo MonitorFromWindow ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow LoadCursorW SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos GetCursorPos EmptyClipboard SetClipboardData GetKeyState DispatchMessageW CloseClipboard GetClipboardData GetAsyncKeyState |
| SHELL32.dll |
ShellExecuteA
|
| ole32.dll |
CoInitializeEx
|
| MSVCP140.dll |
?_Xinvalid_argument@std@@YAXPEBD@Z
_Mtx_unlock _Mtx_lock ?good@ios_base@std@@QEBA_NXZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z _Query_perf_frequency ?_Throw_Cpp_error@std@@YAXH@Z ?_Xlength_error@std@@YAXPEBD@Z _Cnd_do_broadcast_at_thread_exit _Query_perf_counter _Thrd_detach ?uncaught_exceptions@std@@YAHXZ ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A ?_Xout_of_range@std@@YAXPEBD@Z ?_Xbad_function_call@std@@YAXXZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z |
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| D3DCOMPILER_43.dll |
D3DCompile
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
memset
_CxxThrowException __current_exception memmove memcpy memcmp memchr __current_exception_context __C_specific_handler __std_exception_destroy __std_exception_copy __std_terminate strchr strstr |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
free _set_new_mode malloc |
| api-ms-win-crt-runtime-l1-1-0.dll |
_errno
terminate _beginthreadex _register_thread_local_exe_atexit_callback _c_exit _exit exit _initterm_e _initterm _get_wide_winmain_command_line _initialize_wide_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _configure_wide_argv |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__stdio_common_vsscanf fflush fclose _set_fmode _wfopen fwrite __p__commode ftell __stdio_common_vfprintf fread fseek __stdio_common_vsprintf |
| api-ms-win-crt-math-l1-1-0.dll |
ceilf
atan2f sqrtf sqrt floorf sinf __setusermatherr fmodf roundf log logf powf cosf pow acosf |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoull
strtol strtoul atof atoi strtoll strtod |
| api-ms-win-crt-locale-l1-1-0.dll |
localeconv
_configthreadlocale |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
rand |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
_wcsicmp tolower towlower strcmp strlen strncmp strncpy wcslen strncpy_s |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-15 02:01:54 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x52a770 |
| PointerToRawData | 0x529970 |
| Referenced File | C:\Users\uid\Desktop\past\mixcodes\x64\Release\Fivem-External.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-15 02:01:54 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x52a7cc |
| PointerToRawData | 0x5299cc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-15 02:01:54 |
| Version | 0.0 |
| SizeofData | 912 |
| AddressOfRawData | 0x52a7e0 |
| PointerToRawData | 0x5299e0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jun-15 02:01:54 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14052ab90 |
|---|---|
| EndAddressOfRawData | 0x14052ab98 |
| AddressOfIndex | 0x14061af84 |
| AddressOfCallbacks | 0x1400bb970 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14053a040 |
| XOR Key | 0x9b3f0e93 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| Imports (35721) | 6 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 34 |
| Imports (21202) | 6 |
| Imports (33145) | 21 |
| Total imports | 334 |
| C++ objects (LTCG) (36247) | 45 |
| Resource objects (36247) | 1 |
| Linker (36247) | 1 |
No comments yet.