f4c5f1cb50a3cfc65e02d134581377d2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2056-Jun-02 02:19:42
Debug artifacts Dota2 Gachi.pdb
Comments
CompanyName
FileDescription Dota2 Gachi
FileVersion 1.0.0.0
InternalName Dota2 Gachi.exe
LegalCopyright Copyright © 2021
LegalTrademarks
OriginalFilename Dota2 Gachi.exe
ProductName Dota2 Gachi
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Suspicious The PE is possibly packed. Unusual section name found: .sdata
The PE only has 0 import(s).
Suspicious The file contains overlay data. 512 bytes of data starting at offset 0x23600.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 f4c5f1cb50a3cfc65e02d134581377d2
SHA1 fa646f138bf184c74f17e3e31fbbf964930b4a40
SHA256 e1f4ae3ed226bc4d5f3b12f2686f99cebc78c8323a63ae1d2eb2a86f3b55efb9
SHA3 92fb1e0f911c6b16e0538ed1f377074cdb97cbfb26769ec8d7a24df450ccc106
SSDeep 3072:ilDY72KPr6cPMvr2NwS/3NrZTkkgCHfbC8bB637Hqh6Jz:ilDY7tvMzEN/bXbB6LH5
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 3
TimeDateStamp 2056-Jun-02 02:19:42
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 6.0
SizeOfCode 0x1c800
SizeOfInitializedData 0x6c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000000000 (Section: ?)
BaseOfCode 0x2000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x2a000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 15

.text

MD5 884dde76feb7b7d660d6a85ed092f48d
SHA1 69ed39a25c4dd001b47998aa12deb07b5baca9e3
SHA256 4be68e9e5df08ccf65473b4bef8eb2aaad7efe13dfd83a5e3d6d1b3842acdbe0
SHA3 8575a4cfb20a9aa6fb93bade2d9c26b2f8a0949f528f83e47b1f94e7f3dafee5
VirtualSize 0x1c7b4
VirtualAddress 0x2000
SizeOfRawData 0x1c800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.76435

.sdata

MD5 c72c61ec89f2a4408ef215ad5f5ac754
SHA1 390260a3dc5968b2787871553a8c9e511a94f03c
SHA256 d0b639c6df03075aa8dea0329f2ade8f571a9a928f63d7d03a4feb1a55eecc6f
SHA3 94a043aa218068872a8955826d0ceb187f4755019569197f1f942e30471827d2
VirtualSize 0x1e8
VirtualAddress 0x20000
SizeOfRawData 0x200
PointerToRawData 0x1cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.62309

.rsrc

MD5 808d74bfe5f5b58c65dc219498950bde
SHA1 a6ac50680d5e5134fe50d36f22f39a54d4ede6fd
SHA256 5552dea4407d565c9c5aa255d2f5a798cf76559b5d7c6cfe0c7818c2d0f80321
SHA3 8478d1944bf24357e1aad83b78eb815697c44ea1002d1c1ed806f9232ce4c5e8
VirtualSize 0x66f4
VirtualAddress 0x22000
SizeOfRawData 0x6800
PointerToRawData 0x1ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.70848

Imports

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x515e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9195
Detected Filetype PNG graphic file
MD5 ea07194619ac2069573c842eb7e2cbe9
SHA1 572ebf84389bf7b00c582b81978b2a72a1842653
SHA256 67cb9b8bf37a19b7d09e57d2d64c92b739806af41754870bc66d53b9a2c52bb4
SHA3 9e5cf0c1ab22423713c15c839c69c4e8dfb598708ec916390c8f0af46e67bbd8

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.51664
Detected Filetype Icon file
MD5 7cd50ca410eb427b250c06ad22c1a0bc
SHA1 d329e974a6a819bc6eb3dd4e2ad8a90bf1882d28
SHA256 2eedc50dc9c61a1878e91b67592168cbbea2b4d15a71c0bd597bb0f9fe813252
SHA3 1a15a9e4d621efacbb964027f6737206c5d7811fa00af677f76405b850763cd1

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x32c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29633
MD5 a8e9e0786902ea0cc506ffc9b74e0537
SHA1 c59b3170841e012b4d4533a2cc071cb294ab1455
SHA256 793c7ab08019ede02d08898291ef3fb0a624a359deb3b33d6d4b71d4a33ef290
SHA3 13c6bdc7168f699b3e4da0289bf76bb449c76c8cc17951b55e9adf07b4eeab9e

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x1123
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45661
MD5 9932165f30849870e05b22d26904aaca
SHA1 0aecdae7bc9f87b57428b2a29bcfdb54d8fa1381
SHA256 c8fe26556f61b3547cfbc77bc906f44f23e81d8d1d36e041e4ec4c64fb104360
SHA3 a5dd46bbced332533dec3dc4f14f2dd1d5387c645dc9c4a2f255526a635ef611

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments
CompanyName
FileDescription Dota2 Gachi
FileVersion (#2) 1.0.0.0
InternalName Dota2 Gachi.exe
LegalCopyright Copyright © 2021
LegalTrademarks
OriginalFilename Dota2 Gachi.exe
ProductName Dota2 Gachi
ProductVersion (#2) 1.0.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
SizeofData 40
AddressOfRawData 0x1e735
PointerToRawData 0x1cb35
Referenced File Dota2 Gachi.pdb

TLS Callbacks

Load Configuration

RICH Header

Errors

<-- -->