| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jul-30 16:51:26 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Vxmpire\Desktop\Dev\Cheat\Loader\build\example_win32_directx11.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Jul-30 16:51:26 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xbb600 |
| SizeOfInitializedData | 0x3e9a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000BB430 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4a8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_43.dll |
D3DCompile
|
| KERNEL32.dll |
WideCharToMultiByte
GlobalUnlock GetModuleHandleA GetLocaleInfoA QueryPerformanceFrequency QueryPerformanceCounter Sleep CreateFileMappingA GlobalFree MapViewOfFile HeapFree HeapAlloc CloseHandle ReadFile GetFileSizeEx CreateFileA GetModuleHandleW GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead GlobalLock GlobalAlloc MultiByteToWideChar FreeLibrary GetStartupInfoW GetProcAddress LoadLibraryA SetUnhandledExceptionFilter UnmapViewOfFile |
| USER32.dll |
LoadCursorA
GetMessageExtraInfo DefWindowProcW DispatchMessageA DestroyWindow CreateWindowExW UnregisterClassW RegisterClassExW ShowWindow SetLayeredWindowAttributes TranslateMessage ScreenToClient PeekMessageA UpdateWindow GetSystemMetrics MoveWindow GetWindowRect GetCapture PostQuitMessage ClientToScreen TrackMouseEvent GetKeyboardLayout GetAsyncKeyState SetClipboardData GetClipboardData EmptyClipboard CloseClipboard OpenClipboard GetCursorPos SetCursorPos ReleaseCapture IsWindowUnicode GetClientRect GetKeyState SetCursor SetCapture GetForegroundWindow |
| SHELL32.dll |
ShellExecuteA
|
| MSVCP140.dll |
?_Xlength_error@std@@YAXPEBD@Z
|
| d3dx11_43.dll |
D3DX11CreateShaderResourceViewFromMemory
|
| IMM32.dll |
ImmSetCandidateWindow
ImmReleaseContext ImmGetContext ImmSetCompositionWindow |
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__intrinsic_setjmp
_CxxThrowException __current_exception __current_exception_context __C_specific_handler memcmp __std_terminate memchr __std_exception_destroy __std_exception_copy strstr memset strrchr longjmp memmove memcpy |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_get_narrow_winmain_command_line
_initterm _initterm_e exit _exit _seh_filter_exe _cexit _register_thread_local_exe_atexit_callback _crt_atexit terminate _wassert _register_onexit_function _initialize_onexit_table _set_app_type _initialize_narrow_environment _configure_narrow_argv _c_exit |
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
_set_new_mode free malloc |
| api-ms-win-crt-math-l1-1-0.dll |
sinf
roundf ceilf sin sqrtf fmodf pow acosf cosf __setusermatherr |
| api-ms-win-crt-stdio-l1-1-0.dll |
ftell
fflush fwrite __acrt_iob_func fclose __p__commode _set_fmode fseek __stdio_common_vfprintf _wfopen __stdio_common_vsprintf __stdio_common_vsscanf fread |
| api-ms-win-crt-convert-l1-1-0.dll |
strtol
|
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
strncpy strncmp strlen |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 16:51:26 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0xe7bf0 |
| PointerToRawData | 0xe65f0 |
| Referenced File | C:\Users\Vxmpire\Desktop\Dev\Cheat\Loader\build\example_win32_directx11.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 16:51:26 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xe7c54 |
| PointerToRawData | 0xe6654 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 16:51:26 |
| Version | 0.0 |
| SizeofData | 892 |
| AddressOfRawData | 0xe7c68 |
| PointerToRawData | 0xe6668 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jul-30 16:51:26 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1400e8008 |
|---|---|
| EndAddressOfRawData | 0x1400e8010 |
| AddressOfIndex | 0x14049cd04 |
| AddressOfCallbacks | 0x1400bd5d8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400f6040 |
| XOR Key | 0x47af5513 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| Imports (35721) | 6 |
| 253 (35721) | 1 |
| ASM objects (35721) | 4 |
| C objects (35721) | 10 |
| C++ objects (35721) | 27 |
| C objects (VS2022 Update 1 (17.1.6) compiler 31107) | 26 |
| Imports (35222) | 12 |
| Imports (21202) | 7 |
| Total imports | 217 |
| C++ objects (LTCG) (36252) | 17 |
| Resource objects (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.