| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Oct-11 10:28:38 |
| Detected languages |
English - United Kingdom
English - United States |
| Debug artifacts |
D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb
|
| CompanyName | Airdorf Games LLC & New Blood Interactive |
| FileDescription | FAITH: The Unholy Trinity v1.5 |
| FileVersion | 1.5.0.0 |
| LegalCopyright | 2024 Airdorf Games LLC |
| PrivateBuild | 01.00.00.00 |
| ProductName | FAITH: The Unholy Trinity v1.5 |
| ProductVersion | 1.5.0.0 |
| Info | Matching compiler(s): | MASM/TASM - sig2(h) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: minATL
Unusual section name found: .mydata |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 50912 bytes of data starting at offset 0x6bfb20. |
| Safe | VirusTotal score: 0/69 (Scanned on 2026-07-07 06:29:44) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2023-Oct-11 10:28:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x466400 |
| SizeOfInitializedData | 0x265a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000003C86E4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x931000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x6c19b5 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| RPCRT4.dll |
UuidCreate
UuidToStringW |
|---|---|
| WININET.dll |
InternetOpenA
InternetWriteFile HttpOpenRequestA InternetConnectA InternetCloseHandle InternetCanonicalizeUrlA InternetCrackUrlA InternetReadFile HttpSendRequestA HttpEndRequestW HttpQueryInfoA InternetGetConnectedState |
| d3d11.dll |
D3D11CreateDevice
|
| dbghelp.dll |
SymInitialize
MiniDumpWriteDump SymFromAddr |
| WINMM.dll |
mciSendStringA
joyGetPosEx joyGetPos timeGetTime timeGetDevCaps timeBeginPeriod timeEndPeriod mciGetErrorStringA |
| WS2_32.dll |
setsockopt
sendto inet_ntop recvfrom recv listen inet_ntoa inet_addr getsockopt ioctlsocket gethostname closesocket bind accept getpeername select __WSAFDIsSet ntohs ntohl htons htonl socket WSAStartup WSACleanup WSAGetLastError WSAAddressToStringA getaddrinfo freeaddrinfo connect getsockname send |
| gdiplus.dll |
GdiplusStartup
GdiplusShutdown |
| COMCTL32.dll |
InitCommonControlsEx
|
| VERSION.dll |
GetFileVersionInfoW
VerQueryValueW GetFileVersionInfoSizeW |
| MFPlat.DLL |
MFCreateMediaType
MFShutdown MFStartup MFCreateSourceResolver |
| MF.dll |
MFCreateMediaSession
MFCreateSampleGrabberSinkActivate MFCreateAudioRendererActivate MFGetService MFCreateTopologyNode MFCreateTopology |
| KERNEL32.dll |
HeapReAlloc
GetTimeZoneInformation SetStdHandle ReadConsoleW SetFilePointerEx GetFileSizeEx GetConsoleMode GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW GetTempPathW SetConsoleCtrlHandler WriteFile GetStdHandle FreeLibraryAndExitThread ResumeThread ExitThread PeekNamedPipe GetFileType GetFileInformationByHandle IsValidCodePage FileTimeToSystemTime SystemTimeToTzSpecificLocalTime FindFirstFileExW MoveFileExW SetFileAttributesW GetFileAttributesExW GetModuleHandleExW HeapWalk HeapValidate RtlUnwind LoadLibraryExW InterlockedFlushSList InterlockedPushEntrySList RtlPcToFileHeader RtlUnwindEx VirtualQuery GetProcessHeap HeapFree HeapAlloc InitializeSListHead RaiseException GetStartupInfoW IsDebuggerPresent CreateEventW GetACP GetOEMCP ResetEvent SetEvent IsProcessorFeaturePresent TerminateProcess GetCommandLineA SetCurrentDirectoryW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW OutputDebugStringW SetEndOfFile HeapSize GetDriveTypeW RtlCaptureStackBackTrace EnterCriticalSection LeaveCriticalSection GetProcAddress LoadLibraryW WideCharToMultiByte GetLastError LoadLibraryA MultiByteToWideChar CloseHandle WaitForSingleObjectEx CreateEventExW OutputDebugStringA GetConsoleWindow GetCurrentDirectoryW DeleteFileW GetFullPathNameW SetLastError CreateThread GetExitCodeThread GetModuleHandleW LocalFree FormatMessageW SetCurrentDirectoryA GetCurrentDirectoryA CreateFileW GetFileAttributesW GetFileSize ReadFile SetFilePointer FreeLibrary FormatMessageA GetEnvironmentVariableW CreateDirectoryW FindClose FindFirstFileW FindNextFileW RemoveDirectoryW Sleep GetExitCodeProcess CreateProcessW QueryPerformanceCounter QueryPerformanceFrequency WaitForSingleObject SetWaitableTimer CreateWaitableTimerW GetTickCount64 GetCurrentProcess K32GetProcessMemoryInfo GetFileAttributesA GetCurrentThread SetThreadPriority SetPriorityClass GlobalAlloc GlobalUnlock GlobalLock GlobalMemoryStatusEx GetSystemInfo GetVersionExW GetLocaleInfoW VerSetConditionMask VerifyVersionInfoW GetCurrentProcessId DebugBreak GetEnvironmentVariableA ExitProcess lstrlenA GetCommandLineW ExpandEnvironmentStringsW GetFinalPathNameByHandleW SetUnhandledExceptionFilter SetErrorMode GetCurrentThreadId GetModuleFileNameW MoveFileA InitializeCriticalSectionAndSpinCount UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetStringTypeW GetLocaleInfoEx GetCPInfo CompareStringEx LCMapStringEx DecodePointer EncodePointer CreateSymbolicLinkW GetFileInformationByHandleEx CloseThreadpoolWait SetThreadpoolWait CreateThreadpoolWait CloseThreadpoolTimer WaitForThreadpoolTimerCallbacks SetThreadpoolTimer CreateThreadpoolTimer CloseThreadpoolWork SubmitThreadpoolWork CreateThreadpoolWork FreeLibraryWhenCallbackReturns GetSystemTimeAsFileTime GetCurrentProcessorNumber FlushProcessWriteBuffers CreateSemaphoreExW InitOnceExecuteOnce DeleteCriticalSection FlsFree FlsSetValue FlsGetValue FlsAlloc SetFileInformationByHandle GetNativeSystemInfo SwitchToThread SleepConditionVariableSRW SleepConditionVariableCS WakeAllConditionVariable WakeConditionVariable InitializeConditionVariable TryEnterCriticalSection InitializeCriticalSectionEx AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock TlsFree TlsSetValue TlsGetValue TlsAlloc WriteConsoleW |
| USER32.dll |
UpdateWindow
GetForegroundWindow SetProcessDPIAware SetWindowLongPtrW IsDialogMessageW PeekMessageW DispatchMessageW TranslateMessage MonitorFromWindow GetMonitorInfoW EnumDisplaySettingsA RegisterClassExW GetRawInputDeviceInfoA GetRawInputDeviceList MessageBoxW SendMessageW PostMessageW DefWindowProcW GetDlgItem CreateWindowExW DestroyWindow SetDlgItemTextA MessageBoxA GetFocus IsClipboardFormatAvailable EmptyClipboard GetClipboardData SetClipboardData CloseClipboard OpenClipboard keybd_event GetAsyncKeyState wsprintfW GetCursorPos GetActiveWindow EnumDisplayDevicesW EnumDisplaySettingsW MapWindowPoints ClientToScreen SetCursorPos MoveWindow SetWindowTextW ReleaseDC GetDC DrawTextW GetDlgItemTextW SetDlgItemTextW EndDialog DialogBoxParamW CreateDialogParamW LoadImageW LoadCursorW CallNextHookEx ScreenToClient SetCursor AdjustWindowRectEx GetWindowRect GetClientRect SetForegroundWindow GetSystemMetrics ReleaseCapture SetCapture GetKeyState SetFocus BringWindowToTop SetWindowPos ShowWindow |
| GDI32.dll |
GetDeviceCaps
SelectObject GetStockObject |
| COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW |
| ADVAPI32.dll |
RegCloseKey
RegQueryValueExW RegOpenKeyExW |
| SHELL32.dll |
ShellExecuteW
SHGetFolderPathW |
| ole32.dll |
CoCreateInstance
PropVariantClear CoInitialize CoTaskMemFree CoCreateFreeThreadedMarshaler |
| dwmapi.dll |
DwmGetCompositionTimingInfo
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.5.0.0 |
| ProductVersion | 1.5.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United Kingdom |
| CompanyName | Airdorf Games LLC & New Blood Interactive |
| FileDescription | FAITH: The Unholy Trinity v1.5 |
| FileVersion (#2) | 1.5.0.0 |
| LegalCopyright | 2024 Airdorf Games LLC |
| PrivateBuild | 01.00.00.00 |
| ProductName | FAITH: The Unholy Trinity v1.5 |
| ProductVersion (#2) | 1.5.0.0 |
| Resource LangID | English - United Kingdom |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-11 10:28:38 |
| Version | 0.0 |
| SizeofData | 104 |
| AddressOfRawData | 0x57acd0 |
| PointerToRawData | 0x5794d0 |
| Referenced File | D:\a\GameMaker\GameMaker\GameMaker\Runner\VC_Runner\x64\Release-Zeus\Runner.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-11 10:28:38 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x57ad38 |
| PointerToRawData | 0x579538 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2023-Oct-11 10:28:38 |
| Version | 0.0 |
| SizeofData | 1156 |
| AddressOfRawData | 0x57ad4c |
| PointerToRawData | 0x57954c |
| StartAddressOfRawData | 0x14057b200 |
|---|---|
| EndAddressOfRawData | 0x14057b208 |
| AddressOfIndex | 0x1408d1268 |
| AddressOfCallbacks | 0x140469000 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14066e1f8 |
| XOR Key | 0x18df31a6 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 30 |
| 253 (28518) | 8 |
| C objects (30034) | 20 |
| ASM objects (30034) | 12 |
| C++ objects (30034) | 93 |
| C objects (30795) | 48 |
| C++ objects (30795) | 222 |
| 173 (VS2010 build 30319) | 1 |
| Imports (21202) | 2 |
| Imports (30795) | 37 |
| Total imports | 350 |
| C objects (30152) | 177 |
| C++ objects (30152) | 373 |
| Resource objects (30152) | 1 |
| 151 | 1 |
| Linker (30152) | 1 |
No comments yet.