72dc2ff0c1e38d5ff270224d6b019e38f9b5ca2f957d155f78ac898df602c486

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-28 15:07:38
Detected languages English - United Kingdom
English - United States
Debug artifacts D:\a\GameMaker\GameMaker\GameMaker\Runner\GMS2-Runner-Main\VC_Runner\x64\Release-Zeus\Runner.pdb
CompanyName YoYo Games Ltd
FileDescription A GameMaker Game
FileVersion 1.0.0.0
LegalCopyright
PrivateBuild 01.00.00.00
ProductName Created with GameMaker
ProductVersion 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • https://yoyogames.zendesk.com
  • https://yoyogames.zendesk.com/hc/en-us/articles/360002243797
  • sourceware.org
  • yoyogames.zendesk.com
  • zendesk.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowA
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptAcquireContextA
  • CryptGenRandom
Can create temporary files:
  • CreateFileW
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
  • CallNextHookEx
Has Internet access capabilities:
  • InternetCrackUrlA
  • InternetSetOptionA
  • InternetCloseHandle
  • InternetConnectA
  • InternetReadFile
  • InternetCanonicalizeUrlA
  • InternetOpenA
  • InternetGetConnectedState
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Enumerates local disk drives:
  • GetDriveTypeW
Can take screenshots:
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Safe VirusTotal score: 0/69 (Scanned on 2026-05-05 05:29:16) All the AVs think this file is safe.

Hashes

MD5 9dd2d9376ded8e187f355a7917b4292d 🔍
SHA1 8e746b0a9be5c1f10feaec6535003074d9ce5d41 🔍
SHA256 72dc2ff0c1e38d5ff270224d6b019e38f9b5ca2f957d155f78ac898df602c486 🔍
SHA3 0678145137fbfb79a20b222b36d9b59e1f0973470f7a683cf3719ec4d4d0db3e 🔍
SSDeep 98304:kX5FiqTqF30LplbTIBTNouM565ZN+e0MiMjo:kNE3ys1NouM565PMtco 🔍
Imports Hash f8405adb1a0cea05082318f659f76ced 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x138

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-28 15:07:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x4fde00
SizeOfInitializedData 0x280e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000004A8AF0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa65000
SizeOfHeaders 0x400
Checksum 0x783a7d
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1c5aaf6345ccac87ee00ee3f0fb799e5 🔍
SHA1 400e9c345122ee7d9cfcd1cc61c0af0f8cc2340a 🔍
SHA256 dc7a39b7a66cf89275d9bc85522f107416369d3e5b6b8604c87b41f4f7358b31 🔍
SHA3 102ce1092a86433720e89db853871d986d370123464473bd30a5dbaea2fb2a7f 🔍
VirtualSize 0x4fdc08
VirtualAddress 0x1000
SizeOfRawData 0x4fde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54365

.rdata

MD5 653c44fa9235d74436b0a5ae246813fd 🔍
SHA1 643c8ca8588a16a6013f3a2b646c48fb62edfa87 🔍
SHA256 53444f5dbe6a96b42e3cbae4827ea51028dba91e9e5ca1d041b0e4442884c974 🔍
SHA3 75a68cf938fe41b04b0dae235b4bac087e64bba0f4037fe05f36964999f63472 🔍
VirtualSize 0x1b7c44
VirtualAddress 0x4ff000
SizeOfRawData 0x1b7e00
PointerToRawData 0x4fe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.84473

.data

MD5 377a4bdb8eb73f7f2dc0be22393ed75d 🔍
SHA1 a612141d1c69b36963a14d2c58dd736757b2fe20 🔍
SHA256 de32ef382d91f4b192f9ecf8f86bd8983877a80c78e0e4cd2f667ef4d3fc967d 🔍
SHA3 9d9d477d17bb171ff2e0d1dfeff398d3b9d1ba2963c33996d9893ff99330c5f1 🔍
VirtualSize 0x365b1c
VirtualAddress 0x6b7000
SizeOfRawData 0x83800
PointerToRawData 0x6b6000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.47861

.pdata

MD5 eaea509cd1a4333da79dde3410fb51de 🔍
SHA1 d4c519ba0baf05a0453d898fe4564ebba6d95902 🔍
SHA256 f86ff6d3555be0c3becdb979c4767abff75626077d4fa6af6edd30a752efeabd 🔍
SHA3 32080e0ecb05a82d39c6f37b034dec07eeedd94214c26b740532672defc94694 🔍
VirtualSize 0x3a620
VirtualAddress 0xa1d000
SizeOfRawData 0x3a800
PointerToRawData 0x739800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.50256

_RDATA

MD5 77f8502d7a810e5eb2fc203806653f28 🔍
SHA1 3b7ea258c170a6ef3bebd195e53eb5dde036e45b 🔍
SHA256 de9b9e379c349172a196191a4107fde00c4b6355a8d7bcb7357e9c2f20e318dc 🔍
SHA3 2f30a9a2bbf472818901bf50c8cde48691dc15a3b4ac4b8ced0ce448ccce1bc7 🔍
VirtualSize 0xf4
VirtualAddress 0xa58000
SizeOfRawData 0x200
PointerToRawData 0x774000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.4648

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0xa59000
SizeOfRawData 0x200
PointerToRawData 0x774200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 f31ef77d9769d80ab815a81b33c86f63 🔍
SHA1 5f47e860c21e9a06ba98b3d2c45df6a114b9f54d 🔍
SHA256 038e20964a5ad3443935c9ec987591dc609351a51477bc94839aeb879a1e4b68 🔍
SHA3 4fe0caad600a8aa4fcb059ed573205552afcd2c3c848ee9de4b8827021c8e32f 🔍
VirtualSize 0xab20
VirtualAddress 0xa5a000
SizeOfRawData 0xac00
PointerToRawData 0x774400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.94189

Imports

RPCRT4.dll UuidCreate
UuidToStringW
WININET.dll InternetCrackUrlA
InternetSetOptionA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
InternetCanonicalizeUrlA
HttpOpenRequestA
HttpQueryInfoA
InternetOpenA
InternetGetConnectedState
d3d11.dll D3D11CreateDevice
dbghelp.dll MiniDumpWriteDump
WINMM.dll joyGetPosEx
joyGetPos
timeGetTime
timeGetDevCaps
timeEndPeriod
timeBeginPeriod
WS2_32.dll listen
bind
getaddrinfo
WSAStartup
WSAAddressToStringA
send
socket
ntohs
connect
recvfrom
recv
getsockopt
freeaddrinfo
sendto
ioctlsocket
setsockopt
WSAGetLastError
__WSAFDIsSet
select
getpeername
inet_ntop
getnameinfo
htons
closesocket
accept
inet_pton
gdiplus.dll GdiplusShutdown
GdiplusStartup
COMCTL32.dll InitCommonControlsEx
VERSION.dll VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
AVRT.dll AvSetMmThreadCharacteristicsA
PROPSYS.dll PropVariantToUInt32
PropVariantToInt64
IPHLPAPI.DLL GetAdaptersAddresses
NotifyIpInterfaceChange
api-ms-win-core-path-l1-1-0.dll PathCchCombine
KERNEL32.dll WriteFile
GetStdHandle
FreeLibraryAndExitThread
ExitThread
PeekNamedPipe
GetFileType
GetFileInformationByHandle
GetDriveTypeW
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
FindFirstFileExW
MoveFileExW
SetFileAttributesW
GetFileAttributesExW
GetModuleHandleExW
HeapWalk
HeapValidate
TlsFree
TlsSetValue
TlsAlloc
RtlUnwind
RtlPcToFileHeader
RtlUnwindEx
GetProcessHeap
HeapFree
HeapAlloc
TerminateProcess
SetFilePointerEx
GetConsoleMode
InitializeSListHead
IsProcessorFeaturePresent
GetStartupInfoW
UnhandledExceptionFilter
ReadConsoleW
FlushFileBuffers
GetConsoleOutputCP
GetFileSizeEx
SetStdHandle
GetDateFormatW
TlsGetValue
IsDebuggerPresent
RtlVirtualUnwind
Sleep
LoadLibraryW
GetProcAddress
MultiByteToWideChar
FreeLibrary
WideCharToMultiByte
GetLastError
LoadLibraryA
OutputDebugStringA
SetWaitableTimer
CreateWaitableTimerW
CloseHandle
GetConsoleWindow
SetLastError
GetFullPathNameW
GetExitCodeThread
FormatMessageW
DeleteFileW
CreateThread
GetCurrentDirectoryW
LocalFree
GetModuleHandleW
ReadFile
SetFilePointer
CreateFileW
GetFileAttributesW
GetFileSize
FormatMessageA
LoadLibraryExW
CreateDirectoryW
FindFirstFileW
FindNextFileW
RemoveDirectoryW
GetModuleFileNameW
FindClose
ResumeThread
GetTimeZoneInformation
CreateProcessW
CreateDirectoryA
WaitForSingleObject
GetTickCount64
CompareStringW
QueryPerformanceCounter
GetCurrentProcess
K32GetProcessMemoryInfo
GetCurrentDirectoryA
SetCurrentDirectoryA
GlobalAlloc
GlobalLock
GlobalUnlock
GetLocaleInfoW
GetVersionExW
GetSystemInfo
VerSetConditionMask
VerifyVersionInfoW
GlobalFree
GetCurrentProcessId
DebugBreak
GetEnvironmentVariableA
ExitProcess
lstrlenA
GetVersion
SetEnvironmentVariableA
CreateFileMappingW
MapViewOfFile
MoveFileA
GetCommandLineW
ExpandEnvironmentStringsW
GetFinalPathNameByHandleW
SetErrorMode
GetCurrentThreadId
SetUnhandledExceptionFilter
WaitForSingleObjectEx
CreateEventExA
HeapReAlloc
RtlLookupFunctionEntry
RtlCaptureContext
CreateEventW
ResetEvent
SetEvent
GetStringTypeW
GetCPInfo
LCMapStringEx
DecodePointer
EncodePointer
GetSystemTimeAsFileTime
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetNativeSystemInfo
SleepConditionVariableSRW
WakeAllConditionVariable
TryEnterCriticalSection
InitializeCriticalSectionEx
InitializeConditionVariable
InitializeCriticalSection
SetThreadPriority
WakeConditionVariable
SleepConditionVariableCS
DeleteCriticalSection
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
EnterCriticalSection
InitializeSRWLock
LoadLibraryExA
VirtualQuery
VirtualProtect
RaiseException
GetTimeFormatW
LCMapStringW
IsValidLocale
GetUserDefaultLCID
QueryPerformanceFrequency
EnumSystemLocalesW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetEndOfFile
HeapSize
GetTempPathA
WriteConsoleW
USER32.dll MsgWaitForMultipleObjectsEx
EnumDisplaySettingsA
TranslateMessage
SetProcessDPIAware
SetDlgItemTextA
MessageBoxA
PeekMessageW
CloseClipboard
EmptyClipboard
GetForegroundWindow
GetClipboardData
SetClipboardData
IsClipboardFormatAvailable
IsDialogMessageW
DispatchMessageW
OpenClipboard
InvalidateRect
GetCursorPos
SetCursorPos
UpdateWindow
EnumDisplaySettingsW
GetMonitorInfoW
ShowWindow
GetSystemMetrics
SendMessageW
SetWindowLongPtrW
keybd_event
GetAsyncKeyState
IsWindowVisible
GetWindowLongPtrW
GetLayeredWindowAttributes
IntersectRect
MonitorFromWindow
SetWindowPos
GetWindowLongW
GetWindowPlacement
wsprintfW
GetActiveWindow
ClientToScreen
MapWindowPoints
MoveWindow
CreateDialogParamW
GetDC
EndDialog
SetWindowTextW
SetDlgItemTextW
GetDlgItemTextW
DrawTextW
DialogBoxParamW
ReleaseDC
DefWindowProcW
GetKeyState
PostMessageW
DestroyWindow
CreateWindowExW
ScreenToClient
CallNextHookEx
RegisterClassExW
FindWindowExA
SetWindowPlacement
UnhookWindowsHookEx
EnumWindows
SetLayeredWindowAttributes
SetFocus
BringWindowToTop
EnumDisplayDevicesW
LoadCursorW
SendMessageA
SetParent
SetCapture
SetWindowsHookExW
SetCursor
GetClientRect
FindWindowA
ReleaseCapture
SetForegroundWindow
LoadImageW
GetDlgItem
MessageBoxW
AdjustWindowRectEx
GetWindowRect
GDI32.dll DeleteObject
CombineRgn
GetRgnBox
GetDeviceCaps
CreateRectRgnIndirect
SelectObject
GetStockObject
COMDLG32.dll GetSaveFileNameW
GetOpenFileNameW
ADVAPI32.dll RegQueryValueExW
CryptReleaseContext
RegCloseKey
RegOpenKeyExW
CryptAcquireContextA
CryptGenRandom
SHELL32.dll ShellExecuteW
SHGetFolderPathW
ole32.dll CoInitialize
CoTaskMemFree
CoCreateFreeThreadedMarshaler
PropVariantClear
CoCreateInstance
dwmapi.dll DwmGetWindowAttribute
DwmSetWindowAttribute
DwmGetCompositionTimingInfo
IMM32.dll ImmAssociateContext
ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
MFPlat.DLL (delay-loaded) MFShutdown
MFCreateDXGIDeviceManager
MFCreateWaveFormatExFromMFMediaType
MFCreateMediaType
MFGetStrideForBitmapInfoHeader
MFCreateSourceResolver
MFCreateAttributes
MFStartup

Delayed Imports

Attributes 0x1
Name MFPlat.DLL
ModuleHandle 0x73a628
DelayImportAddressTable 0x73a5c8
DelayImportNameTable 0x6b44c8
BoundDelayImportTable 0x6b4608
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.07704
MD5 892f0f6732ef0f73cf6db51e62017a74 🔍
SHA1 7d4428613b8ec9c1380ed96e18d4f2d0c380c94a 🔍
SHA256 96c7b054d2e1d983e964da4f6749b7a8e4fe6296cb4803b5668bf61a1d5deda4 🔍
SHA3 aaff03cd3c772f9407539198680994d4b6303f226f27df7ddba46096d6373f36 🔍

2

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xb94
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.77657
Detected Filetype PNG graphic file
MD5 3081d85d3206bed95e153b77123cd0de 🔍
SHA1 b28f47d0042a62841aa69694176081ca1f3269d4 🔍
SHA256 4ff9fb0d9f2aeba8895ebf42fe0768c829ff1ae472c61ca484c895afd5b829fd 🔍
SHA3 a19984d4615a0e42e354bafde40ec9864cb799ccc1a5f2a6b090ccd0f34f8984 🔍

3

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89367
MD5 713948be21003dfb618ecdb185e50a59 🔍
SHA1 e1b814c0073be99d0f28e2ddb7d13b073f3dc67c 🔍
SHA256 f07f55d8a2d3e560f02673c49c8469b51a8d3548d7a1f0ee47355d6f080c9de8 🔍
SHA3 c1a3d3c7b76024fac53f24210b659a9bb52b0c6230589d095090e6b7e467fd2a 🔍

4

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x1628
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.36684
MD5 4b54f097cdb6fa39423033d47fa200db 🔍
SHA1 bde6c7a67f2b92f27aa875d4955999a9772ff2bf 🔍
SHA256 6a73143cfacd86719eecf2cc45bb66c23391ac62d0ffa167a1acda97b218a1a1 🔍
SHA3 2d1407d8b37f12533b8c67a507e830cf7c707f921c4f1dc2bb2f685733046eda 🔍

5

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x4c28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.04121
MD5 5862fb822647bb0222206552d93026f2 🔍
SHA1 c8df9419ceba783553fc9f5da52146a52d950867 🔍
SHA256 91b02dbfc7de3d446cfa0c582ffcd94754e063ab54450b8545e926755c301d9f 🔍
SHA3 00567047bfdf427cf64883cba41b3bee99520b33a6ad22c0d5d8f2108cee0d5e 🔍

6

Type RT_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x1ae3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86085
Detected Filetype PNG graphic file
MD5 e602c6a4d4ddd15813cc8ab00888f496 🔍
SHA1 60bf529178e5f05463719555bd52551798e6ac88 🔍
SHA256 22813a19603dfdabbc152571db92cadd0f0a4192d8cff8942baae650c820c808 🔍
SHA3 58da0492c870c76a71c95de41ddb4735f69f314788516ad71b50c190c14b3cb7 🔍

IDD_ERROR_CODE

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11903
MD5 ac3f07c5aa93e413823a32f659240ad1 🔍
SHA1 d78e110cb30ccff6366e410f6a16009383f8f2e9 🔍
SHA256 b45c6a3366adc913f8d1f3cd2289aeddc2b4dae28c0e39daa911009f50234c43 🔍
SHA3 89f27075d14968fef9bdad5097adf1e3f751b7238149ba82eec741da3e19086a 🔍

IDD_INPUTQUERY

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06903
MD5 c2624d0a67009076569b24ceaf5c25f0 🔍
SHA1 9430e62b31117c2a62b30d5067a9a485b2b92262 🔍
SHA256 6bd1990b830571c05426131c936352f081dbf227a5f1f8708be380bb68c0ef1e 🔍
SHA3 87c0e1470f39b15c7cde38546d123ea57c64a448bb9ec5e30e1582325f7d6497 🔍

IDD_LOGIN_ASYNC

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x13c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07583
MD5 6b0f04cd06a91ff5ee96decd8eb6dbc6 🔍
SHA1 240236f7e7f1c2cea21c1d5eac0bef98094eb18a 🔍
SHA256 28ae1807e280b537ef8a9b5df66942cd52adf418cd5a2e0b07ef48b25bd08955 🔍
SHA3 f3d6f5a0f7c6fb4bd8a283c4f8bfc9337364cb28e696784dcb8f543d9d79e89b 🔍

IDD_MESSAGE_ASYNC

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00453
MD5 ed9d6ad0e3e5f287913a8c39386eb08e 🔍
SHA1 3856ad95adbb8ffdb971bd44a43e32ff7da10c9e 🔍
SHA256 09ae8082cc363799b57616423e47409390c11fc632c0958826d98420683aa83a 🔍
SHA3 19d277b2aea915c99d664198e3339347acae3070829ba1269eda8de02a6b820e 🔍

IDD_QUESTION

Type RT_DIALOG
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11344
MD5 c73c99bc6638f100b097bf7fcca8f264 🔍
SHA1 1713cd590521632bcfb0be68c27b18a740edec1c 🔍
SHA256 a0c9982c1806c9802b63ba6a73a9deedd2825fe0b7a6b86ec16c098d8422587d 🔍
SHA3 ac3b5ddd8e27e4d89cce23d9fd85784ffc8e1a7b827a762e384f4a9bb45b3f08 🔍

152

Type RT_GROUP_ICON
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.6789
Detected Filetype Icon file
MD5 52132647d1908c944ed02cf48bae2575 🔍
SHA1 b0de7e97c65c4bd58991a7e6b5389aa1250447e2 🔍
SHA256 f30bd63178064c66ba896cfd7688f5c82b66f67135bffbcf557ec5ba6eca7e5d 🔍
SHA3 86c9abdffeeb7e62df00d254852204d8a816d0f3d83d70dcc4f337bb94dec0c5 🔍

1 (#2)

Type RT_VERSION
Language English - United Kingdom
Codepage Latin 1 / Western European
Size 0x27c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30206
MD5 9cc64979ebebfc03be1b9f735093504b 🔍
SHA1 cf0dd8cb0c4b762e3f423b14c8c464d0bf976941 🔍
SHA256 40e6d50ea195255f7218df9f0a7576da2bd1d5cd313b85c05ddd6a9694699501 🔍
SHA3 9e10a25f26ea5cebdc632cc6f212d12663d1ca9b3634ad683e8d3228df50c0d1 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x340
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11335
MD5 291ed637ff774c565467127b4dc6f604 🔍
SHA1 b3712edf7e24864402805cf9fe5b1de2c6224489 🔍
SHA256 bbb722efa85a50eef34ff211a8f26cc6ec7c6d7e2db0a6958c7d2fbc693fe8d3 🔍
SHA3 1d912a13d46db4232b411c8ea0c84f02fac3cbce88ed013f399fdc999bd30983 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United Kingdom
CompanyName YoYo Games Ltd
FileDescription A GameMaker Game
FileVersion (#2) 1.0.0.0
LegalCopyright
PrivateBuild 01.00.00.00
ProductName Created with GameMaker
ProductVersion (#2) 1.0.0.0
Resource LangID English - United Kingdom

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-28 15:07:38
Version 0.0
SizeofData 121
AddressOfRawData 0x647ab0
PointerToRawData 0x646cb0
Referenced File D:\a\GameMaker\GameMaker\GameMaker\Runner\GMS2-Runner-Main\VC_Runner\x64\Release-Zeus\Runner.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-28 15:07:38
Version 0.0
SizeofData 20
AddressOfRawData 0x647b2c
PointerToRawData 0x646d2c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-28 15:07:38
Version 0.0
SizeofData 1168
AddressOfRawData 0x647b40
PointerToRawData 0x646d40

TLS Callbacks

StartAddressOfRawData 0x140648028
EndAddressOfRawData 0x140648044
AddressOfIndex 0x14073bea8
AddressOfCallbacks 0x1405000e0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1406cc1f8

RICH Header

XOR Key 0x59f12211
Unmarked objects 0
ASM objects (33145) 36
Unmarked objects (#2) 1
253 (28518) 8
C objects (30034) 20
ASM objects (30034) 12
C++ objects (30034) 96
C++ objects (30159) 47
Imports (VS2008 SP1 build 30729) 2
C++ objects (33145) 222
C objects (33145) 75
C objects (30159) 39
Imports (33145) 43
Total imports 392
C++ objects (LTCG) (30159) 479
Resource objects (30159) 1
151 1
Linker (30159) 1

Errors

[*] Warning: The PE's certificate directory is outside the file.
Leave a comment

No comments yet.