| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 1981-Jan-19 07:15:57 |
| Detected languages |
English - United States
|
| Debug artifacts |
D3DCompiler_47.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Direct3D HLSL Compiler for Redistribution |
| FileVersion | 10.0.20348.1 (WinBuild.160101.0800) |
| InternalName | d3dcompiler_47.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | d3dcompiler_47.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.20348.1 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Microsoft's Cryptography API |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010 |
| Safe | VirusTotal score: 0/68 (Scanned on 2026-08-10 18:24:13) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 1981-Jan-19 07:15:57 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x389000 |
| SizeOfInitializedData | 0x128000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000028F360 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4b2000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x4acd32 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteFile
FreeLibrary Sleep TlsAlloc TlsSetValue HeapDestroy TlsGetValue TlsFree GetFullPathNameW GetFullPathNameA GetEnvironmentVariableA VirtualFree VirtualAlloc GetSystemInfo GetProcAddress LoadLibraryExW SetLastError RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetCurrentThreadId GetStdHandle GetFileType GetStartupInfoW FlsAlloc FlsGetValue FlsSetValue FlsFree InitializeCriticalSectionAndSpinCount GetSystemTimeAsFileTime CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW ExitProcess GetModuleHandleW GetModuleHandleExW IsValidCodePage GetACP GetOEMCP GetCPInfo SetFilePointerEx GetStringTypeW SetStdHandle ReadFile FreeEnvironmentStringsW SetEnvironmentVariableW RaiseException FlushFileBuffers GetConsoleOutputCP GetConsoleMode GetModuleFileNameW ReadConsoleW HeapSize HeapReAlloc WriteConsoleW QueryPerformanceCounter GetCurrentProcessId InitializeSListHead RtlUnwindEx InterlockedFlushSList EncodePointer InitializeCriticalSectionEx RtlPcToFileHeader LocalAlloc LocalFree GetFileSizeEx GetLastError CreateFileW HeapFree GetProcessHeap UnmapViewOfFile GetFileSize CreateFileMappingW MapViewOfFile GetFileAttributesW SetFileAttributesW DeleteFileW SetEndOfFile DeviceIoControl MapViewOfFileEx CreateFileMappingA ExpandEnvironmentStringsW HeapAlloc OutputDebugStringA CloseHandle LeaveCriticalSection EnterCriticalSection lstrcmpiA HeapCreate GetModuleFileNameA CreateFileA DeleteCriticalSection InitializeCriticalSection WideCharToMultiByte FindClose FindFirstFileExW FindNextFileW GetCommandLineA GetCommandLineW GetDriveTypeW GetCurrentDirectoryW SetEvent ResetEvent WaitForSingleObjectEx CreateEventW MultiByteToWideChar GetEnvironmentStringsW DisableThreadLibraryCalls |
|---|---|
| ADVAPI32.dll |
CryptDestroyHash
CryptAcquireContextW RegQueryValueExA RegEnumKeyExA RegOpenKeyExA CryptGetHashParam CryptCreateHash CryptHashData RegQueryValueExW RegOpenKeyExW RegCloseKey CryptReleaseContext |
| RPCRT4.dll |
UuidCreate
|
| Ordinal | 1 |
|---|---|
| Address | 0xe8b50 |
| Ordinal | 2 |
|---|---|
| Address | 0x11fca0 |
| Ordinal | 3 |
|---|---|
| Address | 0xe8810 |
| Ordinal | 4 |
|---|---|
| Address | 0xe8890 |
| Ordinal | 5 |
|---|---|
| Address | 0xe89a0 |
| Ordinal | 6 |
|---|---|
| Address | 0xeb720 |
| Ordinal | 7 |
|---|---|
| Address | 0x80a0 |
| Ordinal | 8 |
|---|---|
| Address | 0x8280 |
| Ordinal | 9 |
|---|---|
| Address | 0x80b0 |
| Ordinal | 10 |
|---|---|
| Address | 0xeba90 |
| Ordinal | 11 |
|---|---|
| Address | 0x7c20 |
| Ordinal | 12 |
|---|---|
| Address | 0x17ff0 |
| Ordinal | 13 |
|---|---|
| Address | 0x7cf0 |
| Ordinal | 14 |
|---|---|
| Address | 0x7c60 |
| Ordinal | 15 |
|---|---|
| Address | 0xea3e0 |
| Ordinal | 16 |
|---|---|
| Address | 0xea9a0 |
| Ordinal | 17 |
|---|---|
| Address | 0xeaa30 |
| Ordinal | 18 |
|---|---|
| Address | 0xea9d0 |
| Ordinal | 19 |
|---|---|
| Address | 0xeaa00 |
| Ordinal | 20 |
|---|---|
| Address | 0x7cb0 |
| Ordinal | 21 |
|---|---|
| Address | 0x8160 |
| Ordinal | 22 |
|---|---|
| Address | 0xe9b10 |
| Ordinal | 23 |
|---|---|
| Address | 0xe6750 |
| Ordinal | 24 |
|---|---|
| Address | 0x7d30 |
| Ordinal | 25 |
|---|---|
| Address | 0x7ee0 |
| Ordinal | 26 |
|---|---|
| Address | 0xebca0 |
| Ordinal | 27 |
|---|---|
| Address | 0xea420 |
| Ordinal | 28 |
|---|---|
| Address | 0xeaa60 |
| Ordinal | 29 |
|---|---|
| Address | 0xe69c0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.20348.1 |
| ProductVersion | 10.0.20348.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Direct3D HLSL Compiler for Redistribution |
| FileVersion (#2) | 10.0.20348.1 (WinBuild.160101.0800) |
| InternalName | d3dcompiler_47.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | d3dcompiler_47.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.20348.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1981-Jan-19 07:15:57 |
| Version | 0.0 |
| SizeofData | 43 |
| AddressOfRawData | 0x447abc |
| PointerToRawData | 0x447abc |
| Referenced File | D3DCompiler_47.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1981-Jan-19 07:15:57 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0x447ae8 |
| PointerToRawData | 0x447ae8 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1981-Jan-19 07:15:57 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x447f24 |
| PointerToRawData | 0x447f24 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1981-Jan-19 07:15:57 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x447f48 |
| PointerToRawData | 0x447f48 |
| StartAddressOfRawData | 0x180447f70 |
|---|---|
| EndAddressOfRawData | 0x180447f78 |
| AddressOfIndex | 0x18047f7b0 |
| AddressOfCallbacks | 0x1803c0b90 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18047d1c0 |
| GuardCFCheckFunctionPointer | 6446385112 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xa1a463be |
|---|---|
| Unmarked objects | 0 |
| Imports (28900) | 2 |
| Total imports | 145 |
| Imports (VS2008 SP1 build 30729) | 5 |
| C++ objects (27316) | 60 |
| C objects (27316) | 1 |
| ASM objects (28900) | 30 |
| C++ objects (28900) | 220 |
| C objects (28900) | 55 |
| Exports (28900) | 1 |
| C objects (LTCG) (28900) | 136 |
| Resource objects (28900) | 1 |
| Linker (28900) | 1 |
No comments yet.