3e4ae8bb6eb93d5d59af507fb14a3619ece6bcaa9cba87445eecdef4b65690e2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Feb-19 12:20:16
Debug artifacts D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName D4Companion
FileDescription D4Companion
FileVersion 5.1.7.0
InternalName D4Companion.dll
LegalCopyright Copyright © 2026
OriginalFilename D4Companion.dll
ProductName D4Companion
ProductVersion 5.1.7.0+7f2c0814ce44b8949383b15e7009b4b17d9203b3
Assembly Version 5.1.7.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
.NET DLL -> Microsoft
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • Virus
  • virus
Contains domain names:
  • ColorNames.de
  • D2Core.com
  • D4Companion.Localization.Resources.de
  • D4Companion.Localization.Resources.es
  • D4Companion.Localization.Resources.fr
  • Lang.ColorNames.de
  • Localization.Resources.de
  • Localization.Resources.es
  • Localization.Resources.fr
  • MahApps.Metro.Lang.ColorNames.de
  • Metro.Lang.ColorNames.de
  • Resources.de
  • Resources.es
  • Resources.fr
  • adobe.com
  • apache.org
  • api.github.com
  • bottom-c.top
  • c.bottom-c.top
  • cacerts.digicert.com
  • crl.microsoft.com
  • crl3.digicert.com
  • crl4.digicert.com
  • d2core.com
  • developer.microsoft.com
  • digicert.com
  • gameoverlay.net
  • github.com
  • githubusercontent.com
  • hardcodet.net
  • http://127.0.0.1
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
  • http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E
  • http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
  • http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0
  • http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
  • http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0
  • http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E
  • http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F
  • http://crl3.digicert.com/sha2-assured-cs-g1.crl05
  • http://crl3.digicert.com/sha2-assured-ts.crl02
  • http://crl4.digicert.com
  • http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L
  • http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0
  • http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
  • http://crl4.digicert.com/sha2-assured-ts.crl0
  • http://james.newtonking.com
  • http://james.newtonking.com/projects/json
  • http://metro.mahapps.com
  • http://metro.mahapps.com/winfx/xaml/controls
  • http://metro.mahapps.com/winfx/xaml/iconpacks
  • http://metro.mahapps.com/winfx/xaml/shared
  • http://ns.adobe.com
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/tiff/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://ocsp.digicert.com0K
  • http://ocsp.digicert.com0N
  • http://ocsp.digicert.com0O
  • http://ocsp.digicert.com0X
  • http://purl.org
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/expression/blend/2008
  • http://schemas.microsoft.com/winfx/2006/xaml
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation'
  • http://schemas.microsoft.com/winfx/2006/xaml/presentation/options
  • http://schemas.microsoft.com/xaml/behaviors
  • http://schemas.openxmlformats.org
  • http://schemas.openxmlformats.org/markup-compatibility/2006
  • http://www.apache.org
  • http://www.apache.org/licenses/LICENSE-2.0
  • http://www.digicert.com
  • http://www.digicert.com/CPS0
  • http://www.gimp.org
  • http://www.gimp.org/xmp/
  • http://www.hardcodet.net
  • http://www.hardcodet.net/projects/wpf-notifyicon
  • http://www.hardcodet.net/taskbar
  • http://www.microsoft.com
  • http://www.microsoft.com/PKI/docs/CPS/default.htm0
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
  • http://www.microsoft.com/pkiops/Docs/Repository.htm0
  • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
  • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
  • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010
  • http://www.microsoft.com/pkiops/docs/primarycps.htm0
  • http://www.microsoft.com/typography/fonts/Microsoft
  • http://www.microsoft.com0
  • http://www.mozilla.org
  • http://www.mozilla.org/2004/em-rdf#
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • http://www.w3.org/1999/xhtml
  • http://www.w3.org/2000/svg
  • http://www.w3.org/2000/xmlns/
  • http://www.w3.org/TR/html4/loose.dtd
  • http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
  • https://aka.ms
  • https://api.github.com
  • https://api.github.com/repos/josdemmers/diablo4Companion/releases
  • https://d4builds.gg
  • https://developer.microsoft.com
  • https://developer.microsoft.com/en-us/windows/uwp-community-toolkit
  • https://github.com
  • https://ko-fi.com
  • https://maxroll.gg
  • https://mobalytics.gg
  • https://nlog-project.org
  • https://pictogrammers.com
  • https://planners.maxroll.gg
  • https://planners.maxroll.gg/profiles/d4/
  • https://raw.githubusercontent.com
  • https://raw.githubusercontent.com/josdemmers/Diablo4Companion/master/downloads/systempresets/systempresets.json
  • https://www.d2core.com
  • https://www.d2core.com/d4/builds
  • https://www.d2core.com/d4/planner?bd
  • https://www.digicert.com
  • https://www.digicert.com/CPS0
  • https://www.newtonsoft.com
  • https://www.newtonsoft.com/json
  • https://www.newtonsoft.com/jsonschema
  • https://www.nuget.org
  • https://www.nuget.org/packages/NLog.Extensions.Logging
  • https://www.nuget.org/packages/NLog.Web.AspNetCore
  • https://www.nuget.org/packages/Newtonsoft.Json.Bson
  • https://www.selenium.dev
  • https://www.selenium.dev/documentation/webdriver/troubleshooting/errors
  • https://www.w3.org
  • https://www.w3.org/TR/webauthn-2/#enum-transport
  • https://www.w3.org/TR/webauthn-2/#sctn-automation-virtual-authenticators
  • inkscape.org
  • james.newtonking.com
  • ko-fi.com
  • mahapps.com
  • metro.mahapps.com
  • microsoft.com
  • mozilla.org
  • newtonking.com
  • newtonsoft.com
  • nlog-project.org
  • ns.adobe.com
  • nuget.org
  • openxmlformats.org
  • pictogrammers.com
  • project.org
  • raw.githubusercontent.com
  • schemas.microsoft.com
  • schemas.openxmlformats.org
  • www.apache.org
  • www.d2core.com
  • www.digicert.com
  • www.gimp.org
  • www.hardcodet.net
  • www.inkscape.org
  • www.microsoft.com
  • www.mozilla.org
  • www.newtonsoft.com
  • www.nuget.org
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegGetValueW
Possibly launches other programs:
  • ShellExecuteW
Suspicious The file contains overlay data. 22560752 bytes of data starting at offset 0x38400.
Overlay data amounts for 98.9891% of the executable.
Suspicious VirusTotal score: 1/71 (Scanned on 2026-03-30 09:57:41) APEX: Malicious

Hashes

MD5 0a482869d969ecec6cfa61db04cec3ad
SHA1 78c35b37f2242fe39d32333105c0be64d9978d2f
SHA256 3e4ae8bb6eb93d5d59af507fb14a3619ece6bcaa9cba87445eecdef4b65690e2
SHA3 fe57e1151c1c3c00bea20cdb9ddb7d4219d253166c595db7f0db7052eefbf720
SSDeep 98304:6bJYO5PQkTFrJ7o5q4bg/Eqne7ctZqXhPvE+RT/EcO9LKLL1y3kiG:iTny90be3hHE8Ixo54G
Imports Hash 53e4e12437621212a425d294842d0a96

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Feb-19 12:20:16
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18400
SizeOfInitializedData 0x20c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000013B80 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3d000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 46932c45ef12a371702ce0a36149c636
SHA1 9d4d25cbe80116dfbb68b8e9551a731729b1c87f
SHA256 4008ccbc404e89d3e807f84246d0b6130b22f56e6c2d6eb5417b900d1fad47ff
SHA3 ba9238c43040e27305f9a17105bbf5743b12954fd9f44cabd50ebce7d473eefd
VirtualSize 0x1839c
VirtualAddress 0x1000
SizeOfRawData 0x18400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36319

.rdata

MD5 132dd1c6d35f27ff505e2d41531db465
SHA1 a70ca07350c2d0a59f3878cc3c23ccf8d1edd086
SHA256 1c126ab14e74368d18ae46bec7f3f6dd5d84b0d4e35a4687a44ae4a6b57af6b2
SHA3 1d30ac6451a59e5797556933bbee775d9025f62f7ad0d004025543b5dc8d0e74
VirtualSize 0xc5fe
VirtualAddress 0x1a000
SizeOfRawData 0xc600
PointerToRawData 0x18800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84672

.data

MD5 e36f47b804c4a09ee256aa3af07a5935
SHA1 c4cb38b382180b68716eb043932b0a6364193c08
SHA256 175f1f6a02dd90d0ae249dd474763f2211860117b611ffe11ca09d3e8b216f17
SHA3 3d1d9fc703a1fc8f6769f972a3d2c6357ab2fada106d705746f1f0c1889b3ed7
VirtualSize 0x1a40
VirtualAddress 0x27000
SizeOfRawData 0xc00
PointerToRawData 0x24e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.24679

.pdata

MD5 145209890bbc2ecbc84762fcd08efd0b
SHA1 b977d1f04a2d16147d86562124dde273386113bc
SHA256 5fd25e8acfaad5694cf25ea9676bd7e8569b1d9689e1c363afbba3e2f5180860
SHA3 8f915a320403176e49869b53edef17d54c34f98d1f3d35ed9e055ac17e6cfd7b
VirtualSize 0x14c4
VirtualAddress 0x29000
SizeOfRawData 0x1600
PointerToRawData 0x25a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.92549

.reloc

MD5 013117ac819f8cbe20d402f784ee2731
SHA1 2f089ff04f134328ae06b14119155796239226aa
SHA256 f6bfd84f8de960552694e3ba178d8b40ea4a0ea893f4dfe14706415288487e4a
SHA3 a31b80535fd6738c1909a024a81da7b26e3dcca70b1f62a8a3c9ef72b219e1c9
VirtualSize 0x33c
VirtualAddress 0x2b000
SizeOfRawData 0x400
PointerToRawData 0x27000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80647

.rsrc

MD5 6fc67bc4eab5d3f815288d4e5fa914bf
SHA1 76096c0cd6a7601c3de0f457dadd7fec5ff7a921
SHA256 d93205168c97db4dcec34fda6d02498b8427f9b9aa28bb4fadca1c11a3e700c7
SHA3 f644ec0950d9dde3c244804a37f6f747d1950d055501bc71fbda858bf0c40c5a
VirtualSize 0x10ea4
VirtualAddress 0x2c000
SizeOfRawData 0x11000
PointerToRawData 0x27400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.06278

Imports

SHELL32.dll ShellExecuteW
ADVAPI32.dll RegCloseKey
ReportEventW
RegisterEventSourceW
RegOpenKeyExW
RegGetValueW
DeregisterEventSource
KERNEL32.dll TlsFree
CreateActCtxW
ActivateActCtx
GetLastError
FindResourceW
GetWindowsDirectoryW
GetProcAddress
GetModuleHandleW
FreeLibrary
LoadLibraryExW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetStdHandle
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
FindClose
GetFileAttributesW
MultiByteToWideChar
GetConsoleMode
GetFileAttributesExW
LoadLibraryA
WriteConsoleW
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
OutputDebugStringW
GetCurrentProcessId
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
api-ms-win-crt-runtime-l1-1-0.dll terminate
_register_thread_local_exe_atexit_callback
_c_exit
__p___wargv
__p___argc
_exit
exit
_initterm_e
_errno
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
abort
_invoke_watson
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
malloc
_callnewh
free
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64_s
wcsftime
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfwprintf
__p__commode
fputwc
__acrt_iob_func
__stdio_common_vswprintf
_set_fmode
_wfsopen
fflush
setvbuf
__stdio_common_vsnwprintf_s
api-ms-win-crt-locale-l1-1-0.dll _create_locale
___mb_cur_max_func
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_configthreadlocale
setlocale
_lock_locales
_free_locale
_unlock_locales
api-ms-win-crt-string-l1-1-0.dll strlen
strcmp
wcsncmp
toupper
strcpy_s
_wcsdup
wcsnlen
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.94009
MD5 f9ee58d5ce79066bdef0dc50595a45d0
SHA1 b4886c7e8f4ee9fdcb293be0a9c948092ace4075
SHA256 d85929d45d4e3043aa8cb61c9ce9c84bf8d143545ee8fcdb5b4c6eea539d0c41
SHA3 d3254ccf25d8f8c9e6d65005cd09f4e3ff83d36f552a214b76423cd505ba90bd

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98048
Detected Filetype Icon file
MD5 38388dda6548693f4d42f2241a4218d7
SHA1 78bedd12a20f97e31e58742381f3d0ca1edb4715
SHA256 cd0991dd595a1392452a8c7ccf089e73626bc6eed1fd3f54ee4c6aa7ffbaedba
SHA3 9ace1e9f008d60580379cdfdcd4119706c82d52d2e5fdb9e5745fa00864cc1a8

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43312
MD5 8894ae8cef325037fe45b5d3812d4832
SHA1 df53613f0f150934b7a811282f8d479036453563
SHA256 0ab963c6710885e4a97f1ce03b947ff7eeef611880280e2631205e689874525b
SHA3 8a8422ec0bc3d4b0d6797e03b1b690c9426d60715ad3b5f07a41acb66c6dcf9a

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 5.1.7.0
ProductVersion 5.1.7.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName D4Companion
FileDescription D4Companion
FileVersion (#2) 5.1.7.0
InternalName D4Companion.dll
LegalCopyright Copyright © 2026
OriginalFilename D4Companion.dll
ProductName D4Companion
ProductVersion (#2) 5.1.7.0+7f2c0814ce44b8949383b15e7009b4b17d9203b3
Assembly Version 5.1.7.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Feb-19 18:53:15
Version 0.0
SizeofData 121
AddressOfRawData 0x22e2c
PointerToRawData 0x2162c
Referenced File D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Feb-19 18:53:15
Version 0.0
SizeofData 20
AddressOfRawData 0x22ea8
PointerToRawData 0x216a8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Feb-19 18:53:15
Version 0.0
SizeofData 988
AddressOfRawData 0x22ebc
PointerToRawData 0x216bc

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Feb-19 18:53:15
Version 0.0
SizeofData 4
AddressOfRawData 0x232c0
PointerToRawData 0x21ac0

TLS Callbacks

StartAddressOfRawData 0x1400232e8
EndAddressOfRawData 0x1400232f8
AddressOfIndex 0x140028a28
AddressOfCallbacks 0x14001a518
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x1400270c0
GuardCFCheckFunctionPointer 5368816712
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x2c9dc778
Unmarked objects 0
ASM objects (35207) 10
C objects (35207) 13
C++ objects (35207) 86
Imports (VS2008 SP1 build 30729) 16
Imports (33145) 9
Total imports 212
C++ objects (LTCG) (35220) 10
Linker (35220) 1

Errors

Leave a comment

No comments yet.