| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Apr-30 00:22:32 |
| Detected languages |
Chinese - PRC
English - United States |
| CompanyName | 3DMGAME |
| FileDescription | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| FileVersion | 1.0.0.0 |
| InternalName | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| LegalCopyright | FLiNG Copyright (C) 2025 |
| OriginalFilename | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer.exe |
| ProductName | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| ProductVersion | 1.0.0.1 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource 117 is possibly compressed or encrypted.
Resource 250 detected as a PE Executable. Resource 101 is possibly compressed or encrypted. |
| Malicious | VirusTotal score: 22/72 (Scanned on 2025-12-24 09:56:24) |
APEX:
Malicious
Bkav: W64.AIDetectMalware CAT-QuickHeal: Trojan.Ghanarava.1760860594edc0c4 CTX: exe.hacktool.generic ClamAV: Win.Dropper.GameHack-9917263-0 CrowdStrike: win/grayware_confidence_90% (W) DeepInstinct: MALICIOUS ESET-NOD32: Win64/GameHack.BT potentially unsafe application Elastic: malicious (high confidence) Fortinet: Riskware/GameHack GData: Win64.Application.Agent.T1D7XI Ikarus: PUA.HackTool K7GW: Trojan ( baba064c1 ) Lionic: Trojan.Win32.GameHack.4!c Malwarebytes: GameHack.Riskware.Agent.DDS MaxSecure: Trojan.Malware.325188728.susgen McAfeeD: ti!B81D405C9EB8 Paloalto: generic.ml Rising: Malware.Undefined!8.C (TFE:5:WdurPrxgR4T) Sangfor: Trojan.Win64.Gamehack.Vmh0 Skyhigh: BehavesLike.Win64.Generic.th TrellixENS: Artemis!04398916398E |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Apr-30 00:22:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xa8c00 |
| SizeOfInitializedData | 0xd5600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000007C938 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x182000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
UnmapViewOfFile
CreateFileMappingW MapViewOfFile Sleep GetCurrentProcessId LoadLibraryW GetProcAddress GetModuleHandleA LoadLibraryA InitializeCriticalSectionEx DeleteCriticalSection GetModuleHandleW DecodePointer GetModuleFileNameW HeapAlloc HeapFree HeapReAlloc HeapSize GetProcessHeap GetTickCount GetTempPathW WaitNamedPipeW ReadFile GetPrivateProfileStringW WritePrivateProfileStringW FindResourceW LoadResource SizeofResource LockResource LoadLibraryExW GetFileAttributesW FreeLibrary MultiByteToWideChar GetProcessTimes GetSystemTimeAsFileTime IsWow64Process SetLastError ResumeThread WaitForSingleObject GetFileSizeEx LocalFree CreateDirectoryW SetEndOfFile WriteConsoleW SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW WriteFile CreateFileW GetLastError GetCurrentProcess CloseHandle GetCommandLineA GetOEMCP GetACP IsValidCodePage EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW VirtualProtect FlsFree FlsSetValue FlsGetValue FlsAlloc ReadConsoleW FormatMessageA GetLocaleInfoEx WideCharToMultiByte GetStringTypeW ReleaseSRWLockExclusive AcquireSRWLockExclusive TryAcquireSRWLockExclusive GetCurrentThreadId FindClose FindFirstFileW FindFirstFileExW FindNextFileW GetFileAttributesExW AreFileApisANSI GetFileInformationByHandleEx WaitForSingleObjectEx GetExitCodeThread EnterCriticalSection LeaveCriticalSection EncodePointer CompareStringEx GetCPInfo LCMapStringEx QueryPerformanceCounter WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead OutputDebugStringW RaiseException RtlUnwindEx RtlPcToFileHeader InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetStdHandle GetFileType SetFilePointerEx FlushFileBuffers GetConsoleOutputCP GetConsoleMode RtlUnwind |
|---|---|
| USER32.dll |
MessageBoxA
SetProcessDPIAware MessageBoxW |
| ADVAPI32.dll |
SetEntriesInAclW
ConvertStringSidToSidW GetNamedSecurityInfoW SetNamedSecurityInfoW |
| SHELL32.dll |
SHGetFolderPathW
|
| ole32.dll |
CoInitializeEx
CoUninitialize |
| OLEAUT32.dll |
SysFreeString
SysAllocString VariantInit SafeArrayUnaccessData SafeArrayAccessData SafeArrayCreate |
| mscoree.dll |
CorBindToRuntime
CLRCreateInstance |
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| WINMM.dll |
PlaySoundW
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | 3DMGAME |
| FileDescription | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| FileVersion (#2) | 1.0.0.0 |
| InternalName | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| LegalCopyright | FLiNG Copyright (C) 2025 |
| OriginalFilename | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer.exe |
| ProductName | Romancing SaGa 2 Revenge of the Seven v1.0-v20250416 Plus 20 Trainer |
| ProductVersion (#2) | 1.0.0.1 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-30 00:22:32 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0xd860c |
| PointerToRawData | 0xd760c |
| StartAddressOfRawData | 0x1400d8a70 |
|---|---|
| EndAddressOfRawData | 0x1400d8a78 |
| AddressOfIndex | 0x1400e820c |
| AddressOfCallbacks | 0x1400aa7a8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400e5100 |
| XOR Key | 0x80cbe270 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33140) | 181 |
| C objects (33140) | 18 |
| ASM objects (33140) | 6 |
| ASM objects (34321) | 10 |
| C objects (34321) | 16 |
| C++ objects (34321) | 98 |
| Imports (VS2008 build 21022) | 2 |
| Imports (33140) | 17 |
| Total imports | 199 |
| C++ objects (33523) | 30 |
| C++ objects (LTCG) (34809) | 18 |
| Resource objects (34809) | 1 |
| 151 | 1 |
| Linker (34809) | 1 |