| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Dec-13 08:38:47 |
| Detected languages |
English - United Kingdom
English - United States |
| Debug artifacts |
D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb
|
| CompanyName | YoYo Games Ltd |
| FileDescription | Can you survive Five Nights at Frickbear's 3? |
| FileVersion | 1.0.0.0 |
| LegalCopyright | |
| PrivateBuild | 01.00.00.00 |
| ProductName | Created with GameMaker Studio 2 |
| ProductVersion | 1.0.0.0 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: minATL
Unusual section name found: .mydata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 191200 bytes of data starting at offset 0xbc1f20. |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-03-28 07:27:28) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x138 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2023-Dec-13 08:38:47 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8d3c00 |
| SizeOfInitializedData | 0x31ca00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000082D540 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe5a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xbc2417 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| RPCRT4.dll |
UuidToStringW
UuidCreate |
|---|---|
| WININET.dll |
HttpEndRequestW
InternetWriteFile InternetCloseHandle HttpSendRequestA InternetCrackUrlA InternetCanonicalizeUrlA HttpOpenRequestA HttpQueryInfoA InternetOpenA InternetConnectA InternetReadFile InternetGetConnectedState |
| d3d11.dll |
D3D11CreateDevice
|
| dbghelp.dll |
MiniDumpWriteDump
SymInitialize SymFromAddr |
| WINMM.dll |
joyGetPos
mciSendStringA timeGetTime timeGetDevCaps timeEndPeriod timeBeginPeriod joyGetPosEx |
| WS2_32.dll |
WSAStartup
WSAAddressToStringA inet_pton socket connect gethostname recvfrom recv getsockopt freeaddrinfo sendto ioctlsocket setsockopt WSAGetLastError getpeername inet_ntop getnameinfo __WSAFDIsSet select ntohl ntohs htonl htons getaddrinfo listen closesocket bind accept WSACleanup getsockname send |
| gdiplus.dll |
GdiplusStartup
GdiplusShutdown |
| COMCTL32.dll |
InitCommonControlsEx
|
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
| MFPlat.DLL |
MFStartup
MFCreateSourceResolver MFCreateMediaType MFShutdown |
| MF.dll |
MFCreateAudioRendererActivate
MFCreateTopologyNode MFCreateMediaSession MFCreateSampleGrabberSinkActivate MFGetService MFCreateTopology |
| IPHLPAPI.DLL |
GetAdaptersAddresses
NotifyIpInterfaceChange CancelMibChangeNotify2 |
| KERNEL32.dll |
SetConsoleCtrlHandler
GetCurrentThread WriteFile GetStdHandle FreeLibraryAndExitThread ExitThread PeekNamedPipe GetFileType GetFileInformationByHandle GetDriveTypeW FileTimeToSystemTime SystemTimeToTzSpecificLocalTime FindFirstFileExW MoveFileExW SetFileAttributesW GetFileAttributesExW GetModuleHandleExW HeapWalk HeapValidate RtlUnwind LoadLibraryExW InterlockedFlushSList InterlockedPushEntrySList RtlPcToFileHeader RtlUnwindEx GetTempPathW GetProcessHeap HeapFree HeapAlloc InitializeSListHead RaiseException GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent GetConsoleMode GetFileSizeEx TerminateProcess UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry SetFilePointerEx ReadConsoleW SetStdHandle GetTimeZoneInformation HeapReAlloc IsValidLocale IsValidCodePage GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW GetDateFormatW GetTimeFormatW CompareStringW VirtualQuery Sleep LoadLibraryW GetProcAddress MultiByteToWideChar WideCharToMultiByte GetLastError LoadLibraryA OutputDebugStringA SetWaitableTimer CreateWaitableTimerW CloseHandle GetConsoleWindow SetLastError GetFullPathNameW GetExitCodeThread FormatMessageW DeleteFileW CreateThread GetCurrentDirectoryW SetCurrentDirectoryW LocalFree GetModuleHandleW ReadFile SetFilePointer CreateFileW GetFileAttributesW GetCurrentDirectoryA SetCurrentDirectoryA SetEnvironmentVariableW FreeLibrary FormatMessageA CreateDirectoryW FindFirstFileW FindNextFileW RemoveDirectoryW GetModuleFileNameW GetUserDefaultLCID WaitForSingleObject ResumeThread GetTempPathA CreateProcessW CreateDirectoryA OpenThread GetTickCount64 QueryPerformanceFrequency QueryPerformanceCounter GetCurrentProcess K32GetProcessMemoryInfo GlobalAlloc GlobalLock GlobalUnlock GetLocaleInfoW GetVersionExW GetSystemInfo GlobalMemoryStatusEx VerSetConditionMask VerifyVersionInfoW GlobalFree GetCurrentProcessId DebugBreak GetEnvironmentVariableA ExitProcess lstrlenA GetVersion SetEnvironmentVariableA CreateFileMappingW MapViewOfFile MoveFileA GetCommandLineW ExpandEnvironmentStringsW GetFinalPathNameByHandleW SetErrorMode GetCurrentThreadId SetUnhandledExceptionFilter WaitForSingleObjectEx CreateEventExA OutputDebugStringW RtlCaptureContext CreateEventW ResetEvent SetEvent GetStringTypeW GetLocaleInfoEx GetCPInfo CompareStringEx LCMapStringEx DecodePointer EncodePointer CreateSymbolicLinkW GetFileInformationByHandleEx CloseThreadpoolWait SetThreadpoolWait CreateThreadpoolWait CloseThreadpoolTimer WaitForThreadpoolTimerCallbacks SetThreadpoolTimer CreateThreadpoolTimer CloseThreadpoolWork SubmitThreadpoolWork CreateThreadpoolWork FreeLibraryWhenCallbackReturns GetSystemTimeAsFileTime GetCurrentProcessorNumber FlushProcessWriteBuffers CreateSemaphoreExW CreateEventExW InitOnceExecuteOnce FlsFree FlsSetValue FlsGetValue FlsAlloc SetFileInformationByHandle GetNativeSystemInfo SwitchToThread SleepConditionVariableSRW SleepConditionVariableCS SetEndOfFile WakeAllConditionVariable WakeConditionVariable InitializeConditionVariable TryEnterCriticalSection InitializeCriticalSectionEx AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock TlsFree TlsGetValue TlsAlloc SetThreadPriority TlsSetValue DeleteCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount EnterCriticalSection RtlCaptureStackBackTrace LCMapStringW EnumSystemLocalesW FlushFileBuffers FindClose GetConsoleOutputCP HeapSize GetFileSize WriteConsoleW |
| USER32.dll |
MsgWaitForMultipleObjectsEx
EnumDisplaySettingsA TranslateMessage SetProcessDPIAware SetDlgItemTextA MessageBoxA PeekMessageW OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData IsClipboardFormatAvailable keybd_event IsDialogMessageW DispatchMessageW GetFocus GetRawInputDeviceList GetCursorPos SetCursorPos UpdateWindow EnumDisplaySettingsW GetMonitorInfoW ShowWindow GetSystemMetrics SendMessageW GetAsyncKeyState IsWindowVisible GetWindowLongPtrW GetLayeredWindowAttributes IntersectRect SetWindowLongPtrW MonitorFromWindow wsprintfW GetActiveWindow ClientToScreen MoveWindow CreateDialogParamW GetDC EndDialog SetWindowTextW SetDlgItemTextW GetDlgItemTextW GetDlgItem DrawTextW DialogBoxParamW ReleaseDC GetWindowLongW DefWindowProcW GetKeyState PostMessageW CreateWindowExW ScreenToClient CallNextHookEx RegisterClassExW FindWindowExA MapWindowPoints UnhookWindowsHookEx EnumWindows SetFocus BringWindowToTop EnumDisplayDevicesW LoadCursorW SendMessageA SetParent SetCapture SetWindowsHookExW SetCursor GetClientRect PostThreadMessageW FindWindowA ReleaseCapture SetForegroundWindow LoadImageW MessageBoxW GetRawInputDeviceInfoA DestroyWindow AdjustWindowRectEx GetWindowRect SetWindowPos |
| GDI32.dll |
SelectObject
DeleteObject CombineRgn GetRgnBox CreateRectRgnIndirect GetDeviceCaps GetStockObject |
| COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
| ADVAPI32.dll |
RegOpenKeyExW
RegCloseKey CryptGenRandom CryptReleaseContext RegQueryValueExW CryptAcquireContextA |
| SHELL32.dll |
ShellExecuteW
SHGetFolderPathW |
| ole32.dll |
CoInitialize
CoTaskMemFree CoCreateInstance CoCreateFreeThreadedMarshaler PropVariantClear |
| dwmapi.dll |
DwmGetWindowAttribute
DwmGetCompositionTimingInfo |
| IMM32.dll |
ImmGetContext
ImmSetCompositionWindow ImmReleaseContext ImmSetCandidateWindow |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United Kingdom |
| CompanyName | YoYo Games Ltd |
| FileDescription | Can you survive Five Nights at Frickbear's 3? |
| FileVersion (#2) | 1.0.0.0 |
| LegalCopyright | |
| PrivateBuild | 01.00.00.00 |
| ProductName | Created with GameMaker Studio 2 |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United Kingdom |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Dec-13 08:38:47 |
| Version | 0.0 |
| SizeofData | 104 |
| AddressOfRawData | 0xa28494 |
| PointerToRawData | 0xa27494 |
| Referenced File | D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Dec-13 08:38:47 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xa284fc |
| PointerToRawData | 0xa274fc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Dec-13 08:38:47 |
| Version | 0.0 |
| SizeofData | 1156 |
| AddressOfRawData | 0xa28510 |
| PointerToRawData | 0xa27510 |
| StartAddressOfRawData | 0x140a289c8 |
|---|---|
| EndAddressOfRawData | 0x140a289d0 |
| AddressOfIndex | 0x140b50e64 |
| AddressOfCallbacks | 0x1408d6160 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140ae33d8 |
| XOR Key | 0xff360641 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 35 |
| 253 (28518) | 8 |
| C objects (30034) | 20 |
| ASM objects (30034) | 12 |
| C++ objects (30034) | 93 |
| C++ objects (30153) | 40 |
| C++ objects (30795) | 223 |
| 173 (VS2010 build 30319) | 1 |
| C objects (30795) | 61 |
| Imports (21202) | 2 |
| C objects (30153) | 40 |
| Imports (30795) | 41 |
| Total imports | 382 |
| C++ objects (LTCG) (30153) | 467 |
| Resource objects (30153) | 1 |
| 151 | 1 |
| Linker (30153) | 1 |
No comments yet.