| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-29 09:04:40 |
| Detected languages |
English - United States
|
| Debug artifacts |
D:\fa\Cheat\x64\Release\Cheat.pdb
|
| Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Apr-29 09:04:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2dc00 |
| SizeOfInitializedData | 0x31600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000162B4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x64000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| USER32.dll |
CallWindowProcW
GetCursorPos GetForegroundWindow GetAsyncKeyState FindWindowA SetWindowLongPtrW |
| KERNEL32.dll |
WriteConsoleW
FlsGetValue CreateFileW GetConsoleMode GetConsoleOutputCP WriteFile Sleep GetCurrentProcess CreateThread VirtualProtect GetModuleHandleA GetProcAddress GetTickCount64 VirtualQuery DisableThreadLibraryCalls FreeLibraryAndExitThread K32GetModuleInformation HeapCreate HeapFree Thread32Next Thread32First GetCurrentThreadId SuspendThread ResumeThread CreateToolhelp32Snapshot HeapReAlloc CloseHandle HeapAlloc HeapDestroy GetThreadContext GetCurrentProcessId GetModuleHandleW FlushInstructionCache SetThreadContext OpenThread VirtualFree VirtualAlloc GetSystemInfo ReleaseSRWLockExclusive AcquireSRWLockExclusive WakeAllConditionVariable SleepConditionVariableSRW SetUnhandledExceptionFilter GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead FlushFileBuffers RtlUnwindEx RtlPcToFileHeader RaiseException RtlLookupFunctionEntry InterlockedFlushSList GetLastError SetLastError FlsAlloc FlsSetValue FlsFree EncodePointer EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection ExitProcess TerminateProcess FreeLibrary GetModuleHandleExW GetModuleFileNameW IsProcessorFeaturePresent RtlCaptureContext RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter GetStdHandle GetFileType LoadLibraryExW LCMapStringW FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA GetCommandLineW MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW GetProcessHeap SetFilePointerEx GetStringTypeW SetStdHandle HeapSize |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-29 09:04:40 |
| Version | 0.0 |
| SizeofData | 58 |
| AddressOfRawData | 0x3b5bc |
| PointerToRawData | 0x3a5bc |
| Referenced File | D:\fa\Cheat\x64\Release\Cheat.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-29 09:04:40 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x3b5f8 |
| PointerToRawData | 0x3a5f8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-29 09:04:40 |
| Version | 0.0 |
| SizeofData | 952 |
| AddressOfRawData | 0x3b60c |
| PointerToRawData | 0x3a60c |
| StartAddressOfRawData | 0x18003ba10 |
|---|---|
| EndAddressOfRawData | 0x18003f4d0 |
| AddressOfIndex | 0x18005cf40 |
| AddressOfCallbacks | 0x18002f3f8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180044600 |
| XOR Key | 0xf16b2969 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 139 |
| C objects (33145) | 29 |
| ASM objects (33145) | 20 |
| ASM objects (35403) | 9 |
| C objects (35403) | 14 |
| Imports (33145) | 9 |
| Total imports | 121 |
| C++ objects (35403) | 38 |
| C objects (LTCG) (35729) | 4 |
| C++ objects (35729) | 7 |
| Resource objects (35729) | 1 |
| Linker (35729) | 1 |
No comments yet.