435df3e06bcc89cbba10c2d821af687f4db2a1c2dbb4f6b68b8ea9d73ed10bd2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-25 15:58:22
Detected languages English - United Kingdom
English - United States
Debug artifacts C:\Work\Geneshift\VC++Stuff\x64\Release\SkillshotCity-17_55_57_220.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • Position.xyz
  • RetroUSB.com
  • discord.com
  • example.com
  • fogPointCloud.xyz
  • fogPointFixed.xyz
  • fogPointView.xyz
  • gmail.com
  • http://skillshotcity.com
  • https://curl.se
  • https://discord.com
  • https://discord.gg
  • https://qm.qq.com
  • https://qm.qq.com/cgi-bin/qm/qr?_wv
  • https://skillshotcity.com
  • https://store.steampowered.com
  • https://store.steampowered.com/app/2194030
  • https://store.steampowered.com/app/308600
  • https://store.steampowered.com/app/4172540
  • modelPos.xyz
  • qm.qq.com
  • raphnet.net
  • skillshotcity.com
  • steampowered.com
  • store.steampowered.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • LoadLibraryW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • CreateToolhelp32Snapshot
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteW
Uses Windows's Native API:
  • ntohl
  • ntohs
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptDestroyHash
  • CryptDestroyKey
  • CryptImportKey
  • CryptEncrypt
  • CryptAcquireContextW
  • CryptStringToBinaryW
  • CryptQueryObject
  • CryptDecodeObjectEx
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
Can take screenshots:
  • GetDC
  • FindWindowW
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 07cfd88e647c7732ae8471add258d59b 🔍
SHA1 e9f1f1be51e61ba44f7e50b8b6a945282aa71948 🔍
SHA256 435df3e06bcc89cbba10c2d821af687f4db2a1c2dbb4f6b68b8ea9d73ed10bd2 🔍
SHA3 bd830bc633f656436de686f318d7a9d2692cb8a30638174f79fb6e922acc5e4d 🔍
SSDeep 98304:vS77QlrrlSQN13CfHwYa3zqM7OdxA1pNulbKiF8lPgqMasWb/QIT/IgS2pcD:v2QVYQ33CIYMzqMW+1pgKU8l4sIghy 🔍
Imports Hash 848fd279f885fbeadd797f1d37f9a584 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2026-Sep-25 15:58:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xb7f800
SizeOfInitializedData 0x4e5000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000A84300 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1068000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 20892ea14b73c9516be7154007df1c72 🔍
SHA1 772e2485a5abcc4f18c5c6244f9e311657179f8c 🔍
SHA256 2ce6e26d5057312d3b7481aac9e2290c5ef4a235142e6dc3015431fc9f6f4a7f 🔍
SHA3 32bf264bc181a663bd9731b337b25763913f49858cec8295586f2583f8fdf537 🔍
VirtualSize 0xb7f7f0
VirtualAddress 0x1000
SizeOfRawData 0xb7f800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50917

.rdata

MD5 e066fec7534a297a12550615a5522e1c 🔍
SHA1 f2ab640c7ff0ff3bda507292ac142dd28345f8d9 🔍
SHA256 c1cf33bbc2f8de2b4422594faa4ba64966766e3f5490b4e1c9c76ce3211487ef 🔍
SHA3 60c8c1945703c2471d95597d5e7d21fc0cec569c22c9a520b48079e49c32854d 🔍
VirtualSize 0x25bf60
VirtualAddress 0xb81000
SizeOfRawData 0x25c000
PointerToRawData 0xb7fc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.91187

.data

MD5 17da16c7974b4b1690ac3732bd50ae2e 🔍
SHA1 20ba5bae4022fdea4d5ee1309edbee7e49b91d29 🔍
SHA256 73ec6c54272f2d1857d6484f7476003b7a47a7c1658b5d0bb656f56259409fd9 🔍
SHA3 a9449d603577146cfd1c20e099575da847efb4657b46ff465efae8436460b318 🔍
VirtualSize 0x1d3bb4
VirtualAddress 0xddd000
SizeOfRawData 0x7600
PointerToRawData 0xddbc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.55315

.pdata

MD5 6ac42c8c94684f55f1997240987c3a13 🔍
SHA1 587c91516fb94d1107c96203e36d109369b27efc 🔍
SHA256 ceeeed460901c142c6fc2aec793d6bf69c6343cad03f71c1dc1d7f7917b36950 🔍
SHA3 7f020c76de96c7567ca0fc7e9d30766418938f0e2255486ae4351b77e5c5ce04 🔍
VirtualSize 0x5ed70
VirtualAddress 0xfb1000
SizeOfRawData 0x5ee00
PointerToRawData 0xde3200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.17218

.gfids

MD5 26f40730d3ef74f9a1a48d5eb0926058 🔍
SHA1 17336272be4c2df859dde877d04db57d6efcbedd 🔍
SHA256 acaee4f59d735053efe07d7799eb450ca576a3ca1232cd310589fd32fc039097 🔍
SHA3 db7d5b2a1887bcd650b80cafde93c924fc61b66374ec914dc4a9752f894d167d 🔍
VirtualSize 0x878
VirtualAddress 0x1010000
SizeOfRawData 0xa00
PointerToRawData 0xe42000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.64775

.tls

MD5 1f354d76203061bfdd5a53dae48d5435 🔍
SHA1 aa0d33a0c854e073439067876e932688b65cb6a9 🔍
SHA256 4c6474903705cb450bb6434c29e8854f17d8324efca1fdb9ee9008599060883a 🔍
SHA3 991fbbd46bbd69198269fe6c247d440e0f8a7d38259b7a1e04b74790301d1d2b 🔍
VirtualSize 0x9
VirtualAddress 0x1011000
SizeOfRawData 0x200
PointerToRawData 0xe42a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0203931

_RDATA

MD5 c18d07739ac5893293efd163140ad374 🔍
SHA1 e35ae1da2e8612fd161e56490536a87571e7a20a 🔍
SHA256 6b145e9e30f2a8dfd085bcdb954209d233963badaea585b75ef20b6b0e30bdb2 🔍
SHA3 f444e39d128c7b343cc502c185521dc55d6e06bb5d302ea2f919bb8d474f0434 🔍
VirtualSize 0xb50
VirtualAddress 0x1012000
SizeOfRawData 0xc00
PointerToRawData 0xe42c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.65521

.rsrc

MD5 3ef6f85099bbc641e6f4bfee34de9041 🔍
SHA1 e33f7667a4d67b02dfec95fc58bc275684ff4a18 🔍
SHA256 a01940f9a88cee2f4a3a5b8db107c8452192a8e84d70fad06e59c52a6754b6d9 🔍
SHA3 4d788bedec814dac20ed958f8b123e197dd75ffd20d106e31af61415700e920f 🔍
VirtualSize 0x52ec8
VirtualAddress 0x1013000
SizeOfRawData 0x53000
PointerToRawData 0xe43800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.51106

.reloc

MD5 051eb2aa53c89d9b8e33fba17f229aaa 🔍
SHA1 e79faded6691a9e250b32b245ecc5a78cdee6d0f 🔍
SHA256 e0449adb3182691d131e6fda933153adcd42e951571af8c9dfae5578668d5ae2 🔍
SHA3 52be2df9130dfd1a0fcc7b48a45899cf690feeebec7830a70964496ba0f46652 🔍
VirtualSize 0x1c10
VirtualAddress 0x1066000
SizeOfRawData 0x1e00
PointerToRawData 0xe96800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.34957

Imports

steam_api64.dll SteamInternal_SteamAPI_Init
SteamAPI_Shutdown
SteamAPI_RunCallbacks
SteamInternal_FindOrCreateUserInterface
SteamAPI_UnregisterCallResult
SteamAPI_RegisterCallback
SteamAPI_RegisterCallResult
SteamAPI_GetHSteamUser
SteamInternal_ContextInit
SteamAPI_UnregisterCallback
GLU32.dll gluBuild2DMipmaps
gluUnProject
openal32_x64.dll alGenSources
alGetSourcef
alSourceUnqueueBuffers
alSourcePlay
alGetSourcei
alcCreateContext
alGenBuffers
alSourceQueueBuffers
alSourcei
alSourcef
alcCloseDevice
alListener3f
alDeleteSources
alGetError
alBufferData
alDeleteBuffers
alSource3f
alSourceStop
alcOpenDevice
alDistanceModel
alcDestroyContext
alcMakeContextCurrent
alcGetError
alListenerfv
WS2_32.dll send
WSACloseEvent
getaddrinfo
recvfrom
freeaddrinfo
inet_addr
sendto
WSACleanup
__WSAFDIsSet
WSACreateEvent
bind
closesocket
gethostbyname
select
listen
WSASendTo
WSAStartup
getsockname
socket
connect
inet_ntoa
getsockopt
WSARecvFrom
ioctlsocket
setsockopt
WSAGetLastError
ntohl
ntohs
htonl
htons
WSAEnumNetworkEvents
WSAEventSelect
WSAResetEvent
WSAWaitForMultipleEvents
recv
getpeername
WSASetLastError
WSAIoctl
accept
gethostname
WINMM.dll timeEndPeriod
timeGetTime
timeBeginPeriod
USER32.dll EnumDisplaySettingsW
ChangeDisplaySettingsExW
GetRawInputDeviceList
GetRawInputDeviceInfoA
RegisterRawInputDevices
GetRawInputData
GetMonitorInfoW
MonitorFromWindow
LoadImageW
DestroyIcon
LoadCursorW
SetWindowLongW
GetWindowLongW
PtInRect
SetRect
WindowFromPoint
ScreenToClient
ClientToScreen
ClipCursor
GetCursorPos
SetCursor
EnumDisplaySettingsExW
AdjustWindowRectEx
GetClientRect
SetWindowTextW
RemovePropW
GetPropW
SetPropW
RedrawWindow
ReleaseDC
GetDC
SetForegroundWindow
ReleaseCapture
SetCapture
MapVirtualKeyW
GetKeyState
GetActiveWindow
SetFocus
EmptyClipboard
GetClipboardData
SetClipboardData
CloseClipboard
OpenClipboard
EnumDisplayDevicesW
EnumDisplayMonitors
RegisterDeviceNotificationW
UnregisterDeviceNotification
ToUnicode
SetCursorPos
GetGUIThreadInfo
ActivateKeyboardLayout
GetForegroundWindow
SendMessageW
GetWindowThreadProcessId
SystemParametersInfoW
FindWindowW
LoadIconW
LoadKeyboardLayoutW
GetKeyboardLayout
ShowWindow
GetWindowLongPtrW
GetKeyboardLayoutNameA
SetWindowLongPtrW
CallWindowProcW
TrackMouseEvent
TranslateMessage
DispatchMessageW
PeekMessageW
GetMessageTime
IsZoomed
BringWindowToTop
IsIconic
IsWindowVisible
SetWindowPlacement
GetWindowPlacement
SetWindowPos
SetLayeredWindowAttributes
DestroyWindow
CreateWindowExW
RegisterClassExW
UnregisterClassW
DefWindowProcW
KERNEL32.dll FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetTimeFormatW
GetDateFormatW
GetConsoleCP
ReadConsoleW
GetConsoleMode
GetACP
WriteFile
GetModuleFileNameA
ExitProcess
HeapFree
HeapReAlloc
HeapAlloc
SetFilePointerEx
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
GetDriveTypeW
GetFileAttributesExW
GetModuleHandleExW
DeleteFileW
ExitThread
CreateThread
LoadLibraryExW
RtlUnwindEx
RtlPcToFileHeader
InitializeSListHead
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetCPInfo
GetLocaleInfoW
LCMapStringW
CompareStringW
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
DecodePointer
EncodePointer
GetStringTypeW
GetFileSizeEx
VerifyVersionInfoW
PeekNamedPipe
ReadFile
GetFileType
GetStdHandle
WaitForSingleObjectEx
MoveFileExW
SetLastError
GetTickCount
GetSystemDirectoryW
SleepEx
InitializeCriticalSectionEx
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
GetTimeZoneInformation
GetExitCodeProcess
CreateProcessA
SetStdHandle
SetEndOfFile
GetCurrentDirectoryW
GetFullPathNameW
GetProcessHeap
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
WriteConsoleW
HeapSize
FreeLibraryAndExitThread
FormatMessageW
LoadLibraryA
VerSetConditionMask
SetThreadExecutionState
GlobalFree
GlobalUnlock
GlobalLock
GlobalAlloc
GetModuleHandleW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
RaiseException
GetModuleHandleA
GetEnvironmentVariableA
ResetEvent
SetEvent
CreateEventW
WaitForSingleObject
WaitForMultipleObjects
SetUnhandledExceptionFilter
GetCurrentProcessId
AddVectoredExceptionHandler
EnterCriticalSection
LeaveCriticalSection
MultiByteToWideChar
Sleep
LCMapStringEx
WideCharToMultiByte
CreateDirectoryW
GetCurrentProcess
InitializeCriticalSection
GetCurrentThreadId
RtlCaptureStackBackTrace
GetLastError
QueryPerformanceFrequency
GetSystemInfo
DeleteCriticalSection
SystemTimeToFileTime
GetSystemTime
QueryPerformanceCounter
MoveFileW
LoadLibraryW
GetProcAddress
FreeLibrary
FindFirstFileW
FindNextFileW
GetUserDefaultLocaleName
FindClose
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
CloseHandle
GetUserGeoID
SetPriorityClass
GetModuleFileNameW
CreateFileW
IMM32.dll ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
GDI32.dll CreateDCW
DeleteDC
GetDeviceCaps
SetDeviceGammaRamp
ChoosePixelFormat
DescribePixelFormat
SetPixelFormat
SwapBuffers
DeleteObject
CreateRectRgn
ADVAPI32.dll CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptHashData
CryptDestroyHash
CryptDestroyKey
CryptImportKey
CryptEncrypt
CryptAcquireContextW
SHELL32.dll DragFinish
DragQueryPoint
DragQueryFileW
Shell_NotifyIconW
ShellExecuteW
DragAcceptFiles
dbghelp.dll SymFromAddr
SymInitialize
SymGetLineFromAddr64
SymCleanup
SymSetOptions
bcrypt.dll BCryptGenRandom
WLDAP32.dll #73
#208
#41
#117
#26
#27
#219
#216
#14
#301
#147
#133
#79
#142
#167
#127
#46
#145
CRYPT32.dll PFXImportCertStore
CertAddCertificateContextToStore
CertFindExtension
CertGetNameStringW
CryptStringToBinaryW
CertFreeCertificateContext
CertFindCertificateInStore
CertEnumCertificatesInStore
CertCloseStore
CertOpenStore
CryptQueryObject
CertCreateCertificateChainEngine
CertFreeCertificateChainEngine
CertGetCertificateChain
CertFreeCertificateChain
CryptDecodeObjectEx

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0xddee7c

NvOptimusEnablement

Ordinal 2
Address 0xddee6c

1

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.87457
MD5 33b926c4b75541a42f46967ce3d84c06 🔍
SHA1 b8ac4ca0a4c1f0ec31b3fcd691a174c83c793144 🔍
SHA256 a7de03f1407bb71b326d7d2a730df5fb270788e34ae7f80eed79c35a7d755c2b 🔍
SHA3 e81044db516cbe65ee9bdb7949aa7b9dd529cf42cedb5ed712d742d4308a1c1b 🔍

2

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.43042
MD5 2b69059dfb1d22e71490b2a1de91f36a 🔍
SHA1 80364c538588db30f4dbf4e6a56ec28dc9e7f84c 🔍
SHA256 fea44caf13a83eea45f4e4cce3dff9729a8f54102e75b7839a4dad8e5f047312 🔍
SHA3 ae21bbf47923fc41ec52bad9e7d8bd019eec8a682e32c73f06cfb29e14ac75d5 🔍

3

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.86543
MD5 9a25f2c6fdd26d2c93048b3d298c2305 🔍
SHA1 6a76748a7d6b890de1e493db6091b39660ba7387 🔍
SHA256 fd3df09b4b87d8a6b2f5cbb5a21b0a095c516c9ba4d97a987478e79017a00fab 🔍
SHA3 4ba1bca704c48b9b34058122addf44ac7d0fdf5033efe78ea026a9f4f1cf0f6a 🔍

4

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.41152
MD5 32bf3319ccedaa99ad92ed97d14dc54f 🔍
SHA1 77d743b80098a4af27b87a8070c59303ed6666c9 🔍
SHA256 b701252cb18fda8a9aecdf2774c1725410aeefa25faa4ba520bd8f95b18e7b50 🔍
SHA3 b9fc2462ba167b250a0180ea203e8fbbd954992deea6e5b03ec6639be3791b5d 🔍

5

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0xb413
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97412
Detected Filetype PNG graphic file
MD5 f967a114772c00a4d4887eaea29ddda3 🔍
SHA1 b6f6fdc6f7ff5a15dd79ead71c4dd0b7e244f29d 🔍
SHA256 17e3eb7393f95d8aaf46d668331ba882842f98a5269345bddce6a8983f989ffd 🔍
SHA3 35fb9dadd73373f94f9e472d1e1b608a62f29cec27dd628f46dd60f148d526aa 🔍

6

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.26656
MD5 a25b7732a91415dedd30603c7aec6e4a 🔍
SHA1 5b76bfedb9dc961284e70972f5dc1d9636f97bc1 🔍
SHA256 6cf022b2c1db40c35955b94c52e20945a2ecb460f20bfb30858cb022966d7888 🔍
SHA3 6a6b53f5cd22fdd2b319df1ac26481a2a7a3de75084b2f6a41ddc4830c17d7b0 🔍

7

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05831
MD5 914f7a0dc6c30475016a801c33c0191f 🔍
SHA1 c0b0028254d682f4a7b5c5f3f432496f157dd57a 🔍
SHA256 a35ee527594fad20bdbc3fbc0b408042084c1865aea6fa5b9337ed87f43f5da3 🔍
SHA3 44042fd4eb12abbb72b82c143a2693f02a6f76b1d379fbd91adc1c581c56fd1b 🔍

8

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00709
MD5 7e2cadf148e56ea14da8cc4ef3d9c99e 🔍
SHA1 765b43f6fd99cc69750c6582793c9a9781ccb97b 🔍
SHA256 279e9cf475d1db029b491d2053d13e3294cb95d641294a509d240949b4b7ba78 🔍
SHA3 a114b6191e963a82bb1b96bf0aa37c2c0b7765d0adee2c17b091287a82184ba0 🔍

9

Type RT_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.90689
MD5 e59e21e23b7efc6be313fbc3ef3ca860 🔍
SHA1 553575bd888138b954abdf46cd4d384877182b16 🔍
SHA256 acda50fe7ff50c5e7e352248e41cdc943493151e056caf5bd1b486b58b36ffa8 🔍
SHA3 15bfe0d882d16b0ff473247d6065e5f27dff5f77bc69fe8bed327606ff35eef7 🔍

GLFW_ICON

Type RT_GROUP_ICON
Language English - United Kingdom
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07075
Detected Filetype Icon file
MD5 dc07f6cc6693b33002495c0dd3569b35 🔍
SHA1 5f8552bafa5dfbc49244e7d8c570286263d866e6 🔍
SHA256 1b422fc8ef0345b92e752881b22b8201ec2f2d26713e7123df946e3cf7366d22 🔍
SHA3 00139b6df19014e0f4c72a92cd7769c449ed7b1ffb8df6eff276e83dd61ab867 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x245
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.0696
MD5 479efaa605da08019a9eb5d669d9e979 🔍
SHA1 93dc246ddd97b527f363661390fbbb9f09444780 🔍
SHA256 21dfa47b1f0905e2d77f42ed80ef88876ac21f82e0cb50b57bda833724977ba4 🔍
SHA3 f2547b2355188c53a4c27176c9702c7b8f9a616ef9aa4775949bf9c319db0a7e 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-25 15:58:22
Version 0.0
SizeofData 95
AddressOfRawData 0xc911ec
PointerToRawData 0xc8fdec
Referenced File C:\Work\Geneshift\VC++Stuff\x64\Release\SkillshotCity-17_55_57_220.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-25 15:58:22
Version 0.0
SizeofData 20
AddressOfRawData 0xc9124c
PointerToRawData 0xc8fe4c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-25 15:58:22
Version 0.0
SizeofData 1020
AddressOfRawData 0xc91260
PointerToRawData 0xc8fe60

TLS Callbacks

StartAddressOfRawData 0x141011000
EndAddressOfRawData 0x141011008
AddressOfIndex 0x140de7744
AddressOfCallbacks 0x140b81e08
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x94
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140dde2b8

RICH Header

XOR Key 0x3ea0c272
Unmarked objects 0
241 (40116) 26
243 (40116) 187
242 (40116) 45
199 (41118) 6
ASM objects (VS2015 UPD3 build 24123) 10
C++ objects (VS2015 UPD3 build 24123) 60
C objects (VS2015 UPD3 build 24123) 38
Imports (VS2015 UPD3.1 build 24215) 2
Imports (65501) 26
C objects (VS2015 UPD3.1 build 24215) 131
Imports (30148) 3
Total imports 397
C++ objects (LTCG) (VS2015 UPD3.1 build 24215) 41
Exports (VS2015 UPD3.1 build 24215) 1
Resource objects (VS2015 UPD3 build 24210) 1
151 1
Linker (VS2015 UPD3.1 build 24215) 1

Errors

Leave a comment

No comments yet.