5e91ada3aff91823d4f0040bd2ac9c7985fd3f866a2c1d03535a5e34c7b6870d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jul-30 16:51:26
Detected languages English - United States
Debug artifacts C:\Users\Vxmpire\Desktop\Dev\Cheat\Loader\build\example_win32_directx11.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • casedieresis.cn
  • casetilde.cn
  • commaaccentright.cn
  • cyrillictail.cn
  • cyrillictic.cn
  • github.com
  • http://scripts.sil.org
  • http://scripts.sil.org/OFLThis
  • http://scripts.sil.org/OFLhttps
  • https://github.com
  • https://indiantypefoundry.comNinad
  • https://rsms.me
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://youtu.be
  • koronisaccentleft.cn
  • scripts.sil.org
  • tildecross.cn
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Possibly launches other programs:
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • GetAsyncKeyState
  • GetForegroundWindow
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 6c7621a171d37549eef011f822e40d56
SHA1 c98af6563bf0d3b7936fb6443ddf0a37eee14bdd
SHA256 5e91ada3aff91823d4f0040bd2ac9c7985fd3f866a2c1d03535a5e34c7b6870d
SHA3 fe659dfb9202ce87c0913a156cffc6c3aa8b2bd7f42d60088a7b39d08d7e9f17
SSDeep 98304:WuLfLDplD7SFwfD6kVNAEyo8ZPX3v3thp95o:9L//8wfD97MHF/37p9i
Imports Hash 654e0762ebce75f6c922281061bb8f12

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-30 16:51:26
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xbb600
SizeOfInitializedData 0x3e9a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000BB430 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x4a8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c303bc86e4ca5659a39498570bee8d11
SHA1 6b942cedb125cb775997e9f6d4ce6f940862e8f0
SHA256 a0fc436b3f3cc73cd47356ca78da0a88642e559a9d0e6bde177b43faa60c3f5a
SHA3 7b9c06034cb6bf0535f771d9c88af9eee40cea2578eeea77c40ceeaf11767573
VirtualSize 0xbb527
VirtualAddress 0x1000
SizeOfRawData 0xbb600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51785

.rdata

MD5 d94b08094679089686e94838710cf493
SHA1 3ac438b60172b939a34cd6aa8857755581da0286
SHA256 8c0adc4df33b2cd99cd2ce4754a8418dbeb739f166d27097d81d198d16b66cd0
SHA3 48a97f9ddd0ad21644ddc2ed97c13b4120e4f1d0bd57313b81ed45868fbaff01
VirtualSize 0x38b80
VirtualAddress 0xbd000
SizeOfRawData 0x38c00
PointerToRawData 0xbba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.08204

.data

MD5 1a8af4c75569477272d3d42bd76f2c24
SHA1 dc36cdc8366a0a0d9baf1204875713adaaa21428
SHA256 48583f5e21b6dd40b0634ff6a2fa3391a8c10e4b0fd61ac7a906df3169b73bf0
SHA3 56d66e346be30e03ca00f6bc2c7e6e3d05d388777350dd5c30b986b8a76bb6c4
VirtualSize 0x3a6e28
VirtualAddress 0xf6000
SizeOfRawData 0x3a6e00
PointerToRawData 0xf4600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.9363

.pdata

MD5 e4fc3fac15465d422511deaf310c2c30
SHA1 32d6c7b1fb66f125fffa40bba5e391c5304207fc
SHA256 4447637f21ac761426aa6448f583b3ed12c7e4d10dc03a15577bb9ec97aa8f42
SHA3 18d71f9a38f61bcc212c0d5cca5160d6982bc378879063df098798fd8ef96769
VirtualSize 0x8c04
VirtualAddress 0x49d000
SizeOfRawData 0x8e00
PointerToRawData 0x49b400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.04637

.rsrc

MD5 740aefbab3f27fdbb2aaf53d14845256
SHA1 9fc3d8c96abafa093f923f2be4d901dea4ca7e5c
SHA256 a18a851fb88cff6cd43b5907a3d2b37a55445adcedb9b62a9a34717e18c8f11a
SHA3 2c37edd0e054a50e40df1677af51ece008568e9ab8c7ed854f6fb8460ec603de
VirtualSize 0x1e8
VirtualAddress 0x4a6000
SizeOfRawData 0x200
PointerToRawData 0x4a4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.76164

.reloc

MD5 e3e8ee641baad0a99f234e1397c478b7
SHA1 e6118878d218ed7f3f827c766598cd5a3793cb19
SHA256 85cd5861febd7ed19cef61c9ad1de6f85d10b67fead15975f94cbfce17bce159
SHA3 b9e3bcd731ef6cead0eed1fc1f12f0416dc7dc8ec0fef8f0868509f128d2543b
VirtualSize 0xcbc
VirtualAddress 0x4a7000
SizeOfRawData 0xe00
PointerToRawData 0x4a4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.21961

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
KERNEL32.dll WideCharToMultiByte
GlobalUnlock
GetModuleHandleA
GetLocaleInfoA
QueryPerformanceFrequency
QueryPerformanceCounter
Sleep
CreateFileMappingA
GlobalFree
MapViewOfFile
HeapFree
HeapAlloc
CloseHandle
ReadFile
GetFileSizeEx
CreateFileA
GetModuleHandleW
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GlobalLock
GlobalAlloc
MultiByteToWideChar
FreeLibrary
GetStartupInfoW
GetProcAddress
LoadLibraryA
SetUnhandledExceptionFilter
UnmapViewOfFile
USER32.dll LoadCursorA
GetMessageExtraInfo
DefWindowProcW
DispatchMessageA
DestroyWindow
CreateWindowExW
UnregisterClassW
RegisterClassExW
ShowWindow
SetLayeredWindowAttributes
TranslateMessage
ScreenToClient
PeekMessageA
UpdateWindow
GetSystemMetrics
MoveWindow
GetWindowRect
GetCapture
PostQuitMessage
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetAsyncKeyState
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
GetCursorPos
SetCursorPos
ReleaseCapture
IsWindowUnicode
GetClientRect
GetKeyState
SetCursor
SetCapture
GetForegroundWindow
SHELL32.dll ShellExecuteA
MSVCP140.dll ?_Xlength_error@std@@YAXPEBD@Z
d3dx11_43.dll D3DX11CreateShaderResourceViewFromMemory
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
dwmapi.dll DwmExtendFrameIntoClientArea
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __intrinsic_setjmp
_CxxThrowException
__current_exception
__current_exception_context
__C_specific_handler
memcmp
__std_terminate
memchr
__std_exception_destroy
__std_exception_copy
strstr
memset
strrchr
longjmp
memmove
memcpy
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-runtime-l1-1-0.dll _get_narrow_winmain_command_line
_initterm
_initterm_e
exit
_exit
_seh_filter_exe
_cexit
_register_thread_local_exe_atexit_callback
_crt_atexit
terminate
_wassert
_register_onexit_function
_initialize_onexit_table
_set_app_type
_initialize_narrow_environment
_configure_narrow_argv
_c_exit
api-ms-win-crt-heap-l1-1-0.dll _callnewh
_set_new_mode
free
malloc
api-ms-win-crt-math-l1-1-0.dll sinf
roundf
ceilf
sin
sqrtf
fmodf
pow
acosf
cosf
__setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll ftell
fflush
fwrite
__acrt_iob_func
fclose
__p__commode
_set_fmode
fseek
__stdio_common_vfprintf
_wfopen
__stdio_common_vsprintf
__stdio_common_vsscanf
fread
api-ms-win-crt-convert-l1-1-0.dll strtol
api-ms-win-crt-string-l1-1-0.dll strcmp
strncpy
strncmp
strlen
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x184
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91862
MD5 3250787fdcd75aa2587529b89c7738b2
SHA1 622b5627941ecee9cfe6179c3017bbf7b43fffaa
SHA256 8b0de2e560d8476fb0013b44f1e10c2789ae71e0353866890dc5f9c57fb1f44a
SHA3 6bf4f0eaf6795c219d4d808caa895dcb53f7fe9c81e92ce03da1db7841bfcd3d

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jul-30 16:51:26
Version 0.0
SizeofData 100
AddressOfRawData 0xe7bf0
PointerToRawData 0xe65f0
Referenced File C:\Users\Vxmpire\Desktop\Dev\Cheat\Loader\build\example_win32_directx11.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jul-30 16:51:26
Version 0.0
SizeofData 20
AddressOfRawData 0xe7c54
PointerToRawData 0xe6654

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-30 16:51:26
Version 0.0
SizeofData 892
AddressOfRawData 0xe7c68
PointerToRawData 0xe6668

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jul-30 16:51:26
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1400e8008
EndAddressOfRawData 0x1400e8010
AddressOfIndex 0x14049cd04
AddressOfCallbacks 0x1400bd5d8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400f6040

RICH Header

XOR Key 0x47af5513
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 20
Imports (35721) 6
253 (35721) 1
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 27
C objects (VS2022 Update 1 (17.1.6) compiler 31107) 26
Imports (35222) 12
Imports (21202) 7
Total imports 217
C++ objects (LTCG) (36252) 17
Resource objects (36252) 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.