| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2013-Oct-18 14:25:02 |
| Detected languages |
English - United States
|
| CompanyName | *!ReLOADeD!* |
| FileDescription | Steam API |
| FileVersion | 2,1,0,0 |
| InternalName | steam_api |
| LegalCopyright | *!ReLOADeD!* |
| OriginalFilename | steam_api |
| ProductName | Steam API |
| ProductVersion | 2,1,0,0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | MoleBox v2.0 |
| Info | Cryptographic algorithms detected in the binary: |
Uses known Mersenne Twister constants
Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .RLD0
Unusual section name found: .RLD1 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
516 bytes of data starting at offset 0xa0000.
The overlay data has an entropy of 7.60977 and is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 45/71 (Scanned on 2026-03-22 13:35:23) |
ALYac:
Application.Generic.3997786
AVG: Other:PUP-gen [PUP] Antiy-AVL: HackTool/Win32.Crack Arcabit: Application.Generic.D3D005A Avast: Other:PUP-gen [PUP] BitDefender: Application.Generic.3997786 Bkav: W32.AIDetectMalware CAT-QuickHeal: PUA.HackTool.S398420 ClamAV: Win.Tool.Gamehack-9886010-0 CrowdStrike: win/grayware_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/HackTool.Crack.CS potentially unsafe application Elastic: malicious (high confidence) Emsisoft: Application.GameHack (A) Fortinet: Riskware/Crack.BL!tr GData: Application.Generic.3997786 Google: Detected Gridinsoft: Crack.Win32.GameHack.dd!n Ikarus: PUA.HackTool.Steam Lionic: Hacktool.Win32.Crack.3!c Malwarebytes: Crack.Trojan.HackTool.DDS MaxSecure: Trojan.Malware.1380195.susgen MicroWorld-eScan: Application.Generic.3997786 Microsoft: HackTool:Win32/Keygen!MSR Paloalto: generic.ml Rising: Trojan.Wacatac!8.10C01 (CLOUD) Sangfor: PUP.Win32.Crack.V10s SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win32.Dropper.jc Sophos: Steam (PUA) TACHYON: Trojan/W32.Agent.655876.B Trapmine: malicious.high.ml.score TrellixENS: GenericRXWF-WL!879545746BCA TrendMicro: TROJ_GEN.R014C0CGG23 TrendMicro-HouseCall: TROJ_GEN.R014C0CGG23 VBA32: Trojan.Wacatac VIPRE: Application.Generic.3997786 Varist: W32/S-7034927e!Eldorado VirIT: HackTool.Win32.X-Gen.AHDO Webroot: Riskware.Gamehack.Gen Xcitium: Malware@#3fbavqdl0rfm3 Yandex: Trojan.Dynamer!cbZ3xcw3O+Y alibabacloud: HackTool:Win/Crack.CB |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2013-Oct-18 14:25:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 11.0 |
| SizeOfCode | 0x25200 |
| SizeOfInitializedData | 0x36000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0001B33A (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x27000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa6000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetModuleHandleA
LoadLibraryA GetProcessTimes GetCurrentProcess GetSystemTimeAsFileTime GetTickCount GetSystemPowerStatus GetLastError FindFirstFileA FindNextFileA GetDiskFreeSpaceExA GetFileTime ReadFile WriteConsoleW SetStdHandle SetFileAttributesA DeleteFileA GetFileAttributesA CreateDirectoryA TryEnterCriticalSection LeaveCriticalSection EnterCriticalSection GetCurrentThreadId InitializeCriticalSection GetModuleFileNameA FindClose VirtualFree GetConsoleMode GetConsoleCP CreateFileA SetEndOfFile SetFilePointerEx WriteFile GetFileSizeEx VirtualAlloc CloseHandle HeapAlloc HeapFree GetProcessHeap HeapDestroy HeapCreate RaiseException WideCharToMultiByte MultiByteToWideChar QueryPerformanceCounter WritePrivateProfileStructA GetPrivateProfileStringA WritePrivateProfileStringA GetPrivateProfileStructA EncodePointer DecodePointer RtlUnwind GetCommandLineA GetStdHandle GetModuleFileNameW IsProcessorFeaturePresent InterlockedDecrement ExitProcess GetModuleHandleExW GetProcAddress HeapSize Sleep IsDebuggerPresent SetLastError InterlockedIncrement GetFileType InitializeCriticalSectionAndSpinCount DeleteCriticalSection GetStartupInfoW GetCurrentProcessId GetEnvironmentStringsW FreeEnvironmentStringsW UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleW OutputDebugStringW LoadLibraryExW LoadLibraryW LCMapStringW IsValidCodePage GetACP GetOEMCP GetCPInfo HeapReAlloc GetStringTypeW FlushFileBuffers CreateFileW |
|---|---|
| USER32.dll |
LoadBitmapA
|
| GDI32.dll |
DeleteObject
GetBitmapBits |
| ADVAPI32.dll |
CryptDestroyHash
CryptHashData CryptCreateHash CryptImportKey CryptDestroyKey CryptReleaseContext CryptAcquireContextA CryptVerifySignatureA |
| SHELL32.dll |
SHGetSpecialFolderPathA
|
| Ordinal | 1 |
|---|---|
| Address | 0x111d0 |
| Ordinal | 2 |
|---|---|
| Address | 0x112f0 |
| Ordinal | 3 |
|---|---|
| Address | 0x111d0 |
| Ordinal | 4 |
|---|---|
| Address | 0x112f0 |
| Ordinal | 5 |
|---|---|
| Address | 0x11010 |
| Ordinal | 6 |
|---|---|
| Address | 0x11020 |
| Ordinal | 7 |
|---|---|
| Address | 0x11020 |
| Ordinal | 8 |
|---|---|
| Address | 0x113c0 |
| Ordinal | 9 |
|---|---|
| Address | 0x11030 |
| Ordinal | 10 |
|---|---|
| Address | 0x11050 |
| Ordinal | 11 |
|---|---|
| Address | 0x11070 |
| Ordinal | 12 |
|---|---|
| Address | 0x11090 |
| Ordinal | 13 |
|---|---|
| Address | 0x11260 |
| Ordinal | 14 |
|---|---|
| Address | 0x11260 |
| Ordinal | 15 |
|---|---|
| Address | 0x110a0 |
| Ordinal | 16 |
|---|---|
| Address | 0x11260 |
| Ordinal | 17 |
|---|---|
| Address | 0x110c0 |
| Ordinal | 18 |
|---|---|
| Address | 0x110e0 |
| Ordinal | 19 |
|---|---|
| Address | 0x11260 |
| Ordinal | 20 |
|---|---|
| Address | 0x11260 |
| Ordinal | 21 |
|---|---|
| Address | 0x11160 |
| Ordinal | 22 |
|---|---|
| Address | 0x11100 |
| Ordinal | 23 |
|---|---|
| Address | 0x11110 |
| Ordinal | 24 |
|---|---|
| Address | 0x111a0 |
| Ordinal | 25 |
|---|---|
| Address | 0x11120 |
| Ordinal | 26 |
|---|---|
| Address | 0x11090 |
| Ordinal | 27 |
|---|---|
| Address | 0x11260 |
| Ordinal | 28 |
|---|---|
| Address | 0x11140 |
| Ordinal | 29 |
|---|---|
| Address | 0x11150 |
| Ordinal | 30 |
|---|---|
| Address | 0x11160 |
| Ordinal | 31 |
|---|---|
| Address | 0x11170 |
| Ordinal | 32 |
|---|---|
| Address | 0x11180 |
| Ordinal | 33 |
|---|---|
| Address | 0x11190 |
| Ordinal | 34 |
|---|---|
| Address | 0x111a0 |
| Ordinal | 35 |
|---|---|
| Address | 0x111b0 |
| Ordinal | 36 |
|---|---|
| Address | 0x111d0 |
| Ordinal | 37 |
|---|---|
| Address | 0x112f0 |
| Ordinal | 38 |
|---|---|
| Address | 0x18f30 |
| Ordinal | 39 |
|---|---|
| Address | 0x111f0 |
| Ordinal | 40 |
|---|---|
| Address | 0x11220 |
| Ordinal | 41 |
|---|---|
| Address | 0x11220 |
| Ordinal | 42 |
|---|---|
| Address | 0x11250 |
| Ordinal | 43 |
|---|---|
| Address | 0x11260 |
| Ordinal | 44 |
|---|---|
| Address | 0x11170 |
| Ordinal | 45 |
|---|---|
| Address | 0x11270 |
| Ordinal | 46 |
|---|---|
| Address | 0x11280 |
| Ordinal | 47 |
|---|---|
| Address | 0x11290 |
| Ordinal | 48 |
|---|---|
| Address | 0x11180 |
| Ordinal | 49 |
|---|---|
| Address | 0x112a0 |
| Ordinal | 50 |
|---|---|
| Address | 0x112b0 |
| Ordinal | 51 |
|---|---|
| Address | 0x112c0 |
| Ordinal | 52 |
|---|---|
| Address | 0x112d0 |
| Ordinal | 53 |
|---|---|
| Address | 0x112e0 |
| Ordinal | 54 |
|---|---|
| Address | 0x111a0 |
| Ordinal | 55 |
|---|---|
| Address | 0x112f0 |
| Ordinal | 56 |
|---|---|
| Address | 0x11260 |
| Ordinal | 57 |
|---|---|
| Address | 0x11310 |
| Ordinal | 58 |
|---|---|
| Address | 0x334a4 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.1.0.0 |
| ProductVersion | 2.1.0.0 |
| FileFlags |
VS_FF_PATCHED
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | *!ReLOADeD!* |
| FileDescription | Steam API |
| FileVersion (#2) | 2,1,0,0 |
| InternalName | steam_api |
| LegalCopyright | *!ReLOADeD!* |
| OriginalFilename | steam_api |
| ProductName | Steam API |
| ProductVersion (#2) | 2,1,0,0 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10032150 |
| SEHandlerTable | 0 |
| SEHandlerCount | 0 |
| XOR Key | 0xeb84f42d |
|---|---|
| Unmarked objects | 0 |
| ASM objects (50929) | 17 |
| C objects (50929) | 103 |
| C++ objects (50929) | 37 |
| 210 (VS2012 UPD3 build 60610) | 7 |
| Total imports | 121 |
| 185 (30716) | 11 |
| C++ objects (VS2012 UPD3 build 60610) | 133 |
| Exports (VS2012 UPD3 build 60610) | 1 |
| Resource objects (VS2012 UPD3 build 60610) | 1 |
| Linker (VS2012 UPD3 build 60610) | 1 |
No comments yet.